From 3fb096e00695d76e0cf80778c85cab4553ac0689 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Dec 2024 05:03:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../12/GHSA-3w6p-8f82-gw8r/GHSA-3w6p-8f82-gw8r.json | 4 +--- .../12/GHSA-4jhc-wjr3-pwh2/GHSA-4jhc-wjr3-pwh2.json | 4 +--- .../12/GHSA-7fr2-94h7-ccg2/GHSA-7fr2-94h7-ccg2.json | 4 +--- .../12/GHSA-gjrj-9rj4-pgwx/GHSA-gjrj-9rj4-pgwx.json | 12 +++--------- .../12/GHSA-hwvm-vfw8-93mw/GHSA-hwvm-vfw8-93mw.json | 8 ++------ .../12/GHSA-j5qg-w9jg-3wg3/GHSA-j5qg-w9jg-3wg3.json | 8 ++------ .../12/GHSA-j7c3-96rf-jrrp/GHSA-j7c3-96rf-jrrp.json | 12 +++--------- .../12/GHSA-m4h3-7mc2-v295/GHSA-m4h3-7mc2-v295.json | 4 +--- .../02/GHSA-qq97-vm5h-rrhg/GHSA-qq97-vm5h-rrhg.json | 4 +--- .../05/GHSA-6xxq-j39w-g3f6/GHSA-6xxq-j39w-g3f6.json | 4 +--- .../05/GHSA-836p-6p4j-35cg/GHSA-836p-6p4j-35cg.json | 4 +--- .../05/GHSA-83c3-qx27-2rwr/GHSA-83c3-qx27-2rwr.json | 4 +--- .../05/GHSA-966r-962g-2jq5/GHSA-966r-962g-2jq5.json | 4 +--- .../05/GHSA-9cvr-8xq4-2m73/GHSA-9cvr-8xq4-2m73.json | 4 +--- .../05/GHSA-f866-m9mv-2xr3/GHSA-f866-m9mv-2xr3.json | 4 +--- .../05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json | 8 ++------ .../05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json | 4 +--- .../05/GHSA-xr96-7ccp-pg5c/GHSA-xr96-7ccp-pg5c.json | 4 +--- .../09/GHSA-qv98-3369-g364/GHSA-qv98-3369-g364.json | 12 +++--------- .../03/GHSA-rqm8-q8j9-662f/GHSA-rqm8-q8j9-662f.json | 4 +--- .../11/GHSA-ppq4-g8vp-2cv6/GHSA-ppq4-g8vp-2cv6.json | 4 +--- .../12/GHSA-22h8-jh78-8mgh/GHSA-22h8-jh78-8mgh.json | 4 +--- .../12/GHSA-267f-c3x2-429g/GHSA-267f-c3x2-429g.json | 8 ++------ .../12/GHSA-2872-89wh-3frc/GHSA-2872-89wh-3frc.json | 4 +--- .../12/GHSA-2c7g-2hgf-hxf7/GHSA-2c7g-2hgf-hxf7.json | 8 ++------ .../12/GHSA-2cr4-c7g7-hhc2/GHSA-2cr4-c7g7-hhc2.json | 8 ++------ .../12/GHSA-2g88-r927-2prg/GHSA-2g88-r927-2prg.json | 4 +--- .../12/GHSA-2mm8-gjg2-whmx/GHSA-2mm8-gjg2-whmx.json | 8 ++------ .../12/GHSA-2p93-h9hw-wqjg/GHSA-2p93-h9hw-wqjg.json | 8 ++------ .../12/GHSA-2r4h-m59f-x4w8/GHSA-2r4h-m59f-x4w8.json | 8 ++------ .../12/GHSA-2rmc-v2mp-gxq4/GHSA-2rmc-v2mp-gxq4.json | 8 ++------ .../12/GHSA-2w92-jpj9-jcf2/GHSA-2w92-jpj9-jcf2.json | 12 +++--------- .../12/GHSA-2wp3-q67h-9ppc/GHSA-2wp3-q67h-9ppc.json | 8 ++------ .../12/GHSA-325x-phgw-f22w/GHSA-325x-phgw-f22w.json | 8 ++------ .../12/GHSA-327j-hp5v-9289/GHSA-327j-hp5v-9289.json | 8 ++------ .../12/GHSA-32rc-rjrq-cq3g/GHSA-32rc-rjrq-cq3g.json | 8 ++------ .../12/GHSA-35cj-v3wc-rh8w/GHSA-35cj-v3wc-rh8w.json | 12 +++--------- .../12/GHSA-3845-9fvj-j226/GHSA-3845-9fvj-j226.json | 4 +--- .../12/GHSA-38xm-2fmf-66pq/GHSA-38xm-2fmf-66pq.json | 8 ++------ .../12/GHSA-39m3-57c4-f837/GHSA-39m3-57c4-f837.json | 8 ++------ .../12/GHSA-3jhq-49ph-54f5/GHSA-3jhq-49ph-54f5.json | 8 ++------ .../12/GHSA-3mmp-fjhh-4r72/GHSA-3mmp-fjhh-4r72.json | 12 +++--------- .../12/GHSA-3qwg-vch4-4r45/GHSA-3qwg-vch4-4r45.json | 4 +--- .../12/GHSA-46p5-mc5g-f2fg/GHSA-46p5-mc5g-f2fg.json | 8 ++------ .../12/GHSA-4hpv-f46m-r2m2/GHSA-4hpv-f46m-r2m2.json | 12 +++--------- .../12/GHSA-4m6r-mwr3-57wm/GHSA-4m6r-mwr3-57wm.json | 8 ++------ .../12/GHSA-4p5x-9rq5-6cgc/GHSA-4p5x-9rq5-6cgc.json | 8 ++------ .../12/GHSA-4v59-97h7-jh77/GHSA-4v59-97h7-jh77.json | 8 ++------ .../12/GHSA-4v6g-qjgf-vxhm/GHSA-4v6g-qjgf-vxhm.json | 8 ++------ .../12/GHSA-4xmj-j6vr-68q9/GHSA-4xmj-j6vr-68q9.json | 8 ++------ .../12/GHSA-52qv-5pm8-p78h/GHSA-52qv-5pm8-p78h.json | 8 ++------ .../12/GHSA-53f8-7jq7-5j37/GHSA-53f8-7jq7-5j37.json | 8 ++------ .../12/GHSA-56fq-7jc4-6x2c/GHSA-56fq-7jc4-6x2c.json | 12 +++--------- .../12/GHSA-56pm-22qm-mvhr/GHSA-56pm-22qm-mvhr.json | 12 +++--------- .../12/GHSA-58f3-gjmv-9j5x/GHSA-58f3-gjmv-9j5x.json | 8 ++------ .../12/GHSA-595h-f5rf-8jr4/GHSA-595h-f5rf-8jr4.json | 8 ++------ .../12/GHSA-59pc-8759-235m/GHSA-59pc-8759-235m.json | 8 ++------ .../12/GHSA-5mmw-5cmx-qrqm/GHSA-5mmw-5cmx-qrqm.json | 8 ++------ .../12/GHSA-5pfp-wg82-hvp6/GHSA-5pfp-wg82-hvp6.json | 8 ++------ .../12/GHSA-5x42-vcx9-5x6h/GHSA-5x42-vcx9-5x6h.json | 8 ++------ .../12/GHSA-64w3-4qx7-xq7r/GHSA-64w3-4qx7-xq7r.json | 8 ++------ .../12/GHSA-6624-25m9-qrx8/GHSA-6624-25m9-qrx8.json | 8 ++------ .../12/GHSA-67gr-4jjf-gh3j/GHSA-67gr-4jjf-gh3j.json | 4 +--- .../12/GHSA-6ch8-8fcc-pwjp/GHSA-6ch8-8fcc-pwjp.json | 8 ++------ .../12/GHSA-6cm8-m9g3-hrr7/GHSA-6cm8-m9g3-hrr7.json | 8 ++------ .../12/GHSA-6fcc-5qwj-946f/GHSA-6fcc-5qwj-946f.json | 8 ++------ .../12/GHSA-6fxv-wq7w-gjp3/GHSA-6fxv-wq7w-gjp3.json | 4 +--- .../12/GHSA-6h59-r2r7-vpx8/GHSA-6h59-r2r7-vpx8.json | 8 ++------ .../12/GHSA-6p2p-q3jg-qgwx/GHSA-6p2p-q3jg-qgwx.json | 8 ++------ .../12/GHSA-6wch-4f3v-5j78/GHSA-6wch-4f3v-5j78.json | 8 ++------ .../12/GHSA-72q8-mmpq-w97r/GHSA-72q8-mmpq-w97r.json | 8 ++------ .../12/GHSA-7523-wx28-g6xf/GHSA-7523-wx28-g6xf.json | 8 ++------ .../12/GHSA-75cm-2vvh-47g6/GHSA-75cm-2vvh-47g6.json | 12 +++--------- .../12/GHSA-75jr-j9jh-9937/GHSA-75jr-j9jh-9937.json | 8 ++------ .../12/GHSA-789w-f5ch-wrjq/GHSA-789w-f5ch-wrjq.json | 8 ++------ .../12/GHSA-78vg-94xf-59v9/GHSA-78vg-94xf-59v9.json | 8 ++------ .../12/GHSA-7957-q3ch-3v25/GHSA-7957-q3ch-3v25.json | 8 ++------ .../12/GHSA-7m86-pwq6-4p32/GHSA-7m86-pwq6-4p32.json | 8 ++------ .../12/GHSA-7m98-whf4-6699/GHSA-7m98-whf4-6699.json | 8 ++------ .../12/GHSA-7mr2-pfvw-49gg/GHSA-7mr2-pfvw-49gg.json | 8 ++------ .../12/GHSA-7r4j-45gp-phrj/GHSA-7r4j-45gp-phrj.json | 8 ++------ .../12/GHSA-7v3r-544j-x79h/GHSA-7v3r-544j-x79h.json | 8 ++------ .../12/GHSA-7v8f-grj8-36h8/GHSA-7v8f-grj8-36h8.json | 8 ++------ .../12/GHSA-7vq5-4m2m-qff6/GHSA-7vq5-4m2m-qff6.json | 8 ++------ .../12/GHSA-827c-f4fv-j8hr/GHSA-827c-f4fv-j8hr.json | 4 +--- .../12/GHSA-84fx-3wcm-55xp/GHSA-84fx-3wcm-55xp.json | 8 ++------ .../12/GHSA-86rj-5gm4-r5rg/GHSA-86rj-5gm4-r5rg.json | 4 +--- .../12/GHSA-89qw-2wgv-v7rj/GHSA-89qw-2wgv-v7rj.json | 8 ++------ .../12/GHSA-8gf6-jmpj-r5h7/GHSA-8gf6-jmpj-r5h7.json | 8 ++------ .../12/GHSA-8p36-m3pv-8wv3/GHSA-8p36-m3pv-8wv3.json | 8 ++------ .../12/GHSA-8wxh-27vw-26wh/GHSA-8wxh-27vw-26wh.json | 12 +++--------- .../12/GHSA-8xh3-3wj9-mjw4/GHSA-8xh3-3wj9-mjw4.json | 8 ++------ .../12/GHSA-96j7-8ppq-5hjv/GHSA-96j7-8ppq-5hjv.json | 12 +++--------- .../12/GHSA-97w5-ccgq-76pq/GHSA-97w5-ccgq-76pq.json | 8 ++------ .../12/GHSA-98f9-vw78-c4rg/GHSA-98f9-vw78-c4rg.json | 8 ++------ .../12/GHSA-9g5m-x9xw-j23f/GHSA-9g5m-x9xw-j23f.json | 4 +--- .../12/GHSA-9j4q-jq6x-2vv2/GHSA-9j4q-jq6x-2vv2.json | 8 ++------ .../12/GHSA-9j6h-6x9c-qmfv/GHSA-9j6h-6x9c-qmfv.json | 8 ++------ .../12/GHSA-9mr6-2c2v-735f/GHSA-9mr6-2c2v-735f.json | 8 ++------ .../12/GHSA-9p3v-445m-vf8m/GHSA-9p3v-445m-vf8m.json | 8 ++------ .../12/GHSA-9v55-ghc6-wfcw/GHSA-9v55-ghc6-wfcw.json | 8 ++------ .../12/GHSA-c5pv-rm96-f3q6/GHSA-c5pv-rm96-f3q6.json | 8 ++------ .../12/GHSA-c6qm-6524-j252/GHSA-c6qm-6524-j252.json | 8 ++------ .../12/GHSA-c8q7-8787-544x/GHSA-c8q7-8787-544x.json | 8 ++------ .../12/GHSA-c9rc-7w87-3h5x/GHSA-c9rc-7w87-3h5x.json | 8 ++------ .../12/GHSA-cfcf-x7x2-gpf8/GHSA-cfcf-x7x2-gpf8.json | 12 +++--------- .../12/GHSA-cm9v-3mpg-x2w6/GHSA-cm9v-3mpg-x2w6.json | 8 ++------ .../12/GHSA-cmxr-2mw4-8jjq/GHSA-cmxr-2mw4-8jjq.json | 8 ++------ .../12/GHSA-cqw3-jpf4-v74v/GHSA-cqw3-jpf4-v74v.json | 8 ++------ .../12/GHSA-f622-26hm-xgj8/GHSA-f622-26hm-xgj8.json | 8 ++------ .../12/GHSA-f66p-66fr-f5qm/GHSA-f66p-66fr-f5qm.json | 8 ++------ .../12/GHSA-f7f6-f2cj-m7m8/GHSA-f7f6-f2cj-m7m8.json | 8 ++------ .../12/GHSA-fc56-476w-j7fm/GHSA-fc56-476w-j7fm.json | 4 +--- .../12/GHSA-ffw4-h2r2-99hc/GHSA-ffw4-h2r2-99hc.json | 8 ++------ .../12/GHSA-fjr4-p4q2-8f3f/GHSA-fjr4-p4q2-8f3f.json | 4 +--- .../12/GHSA-fr6w-vm34-xj98/GHSA-fr6w-vm34-xj98.json | 8 ++------ .../12/GHSA-fr8p-hjhj-2qxg/GHSA-fr8p-hjhj-2qxg.json | 8 ++------ .../12/GHSA-fw5r-p8w4-82wr/GHSA-fw5r-p8w4-82wr.json | 8 ++------ .../12/GHSA-g4fj-qffq-f9vx/GHSA-g4fj-qffq-f9vx.json | 8 ++------ .../12/GHSA-g57r-4mv6-3958/GHSA-g57r-4mv6-3958.json | 4 +--- .../12/GHSA-g9x9-gxgx-rm88/GHSA-g9x9-gxgx-rm88.json | 4 +--- .../12/GHSA-ggw5-48gv-558x/GHSA-ggw5-48gv-558x.json | 4 +--- .../12/GHSA-ghxr-hx5p-73mx/GHSA-ghxr-hx5p-73mx.json | 8 ++------ .../12/GHSA-gqqh-5jqj-j85x/GHSA-gqqh-5jqj-j85x.json | 4 +--- .../12/GHSA-gqwv-ccm6-wr7j/GHSA-gqwv-ccm6-wr7j.json | 8 ++------ .../12/GHSA-gv3q-27qx-g2xh/GHSA-gv3q-27qx-g2xh.json | 8 ++------ .../12/GHSA-gw77-xfw7-7h69/GHSA-gw77-xfw7-7h69.json | 8 ++------ .../12/GHSA-gxh2-hp3g-6q5q/GHSA-gxh2-hp3g-6q5q.json | 8 ++------ .../12/GHSA-h2c3-ph7g-cmvq/GHSA-h2c3-ph7g-cmvq.json | 8 ++------ .../12/GHSA-h2j8-7rhq-g5mg/GHSA-h2j8-7rhq-g5mg.json | 8 ++------ .../12/GHSA-h42c-m8vj-q7px/GHSA-h42c-m8vj-q7px.json | 8 ++------ .../12/GHSA-h4h6-8v79-695g/GHSA-h4h6-8v79-695g.json | 4 +--- .../12/GHSA-h95g-226g-7wq6/GHSA-h95g-226g-7wq6.json | 8 ++------ .../12/GHSA-h98c-r5q9-prxg/GHSA-h98c-r5q9-prxg.json | 8 ++------ .../12/GHSA-h9hc-qgww-qvf4/GHSA-h9hc-qgww-qvf4.json | 8 ++------ .../12/GHSA-hccp-47wx-qw2w/GHSA-hccp-47wx-qw2w.json | 8 ++------ .../12/GHSA-hcfv-5p8h-vvh5/GHSA-hcfv-5p8h-vvh5.json | 8 ++------ .../12/GHSA-hh56-v5h3-g3f8/GHSA-hh56-v5h3-g3f8.json | 8 ++------ .../12/GHSA-hw66-wjmj-hwgg/GHSA-hw66-wjmj-hwgg.json | 4 +--- .../12/GHSA-hw7v-8wmv-m3mp/GHSA-hw7v-8wmv-m3mp.json | 8 ++------ .../12/GHSA-j268-c725-mvj8/GHSA-j268-c725-mvj8.json | 4 +--- .../12/GHSA-j2j3-53qc-jw45/GHSA-j2j3-53qc-jw45.json | 8 ++------ .../12/GHSA-j7vv-mph8-283v/GHSA-j7vv-mph8-283v.json | 4 +--- .../12/GHSA-jc4p-c854-mcwc/GHSA-jc4p-c854-mcwc.json | 8 ++------ .../12/GHSA-jf6w-775m-7xx9/GHSA-jf6w-775m-7xx9.json | 8 ++------ .../12/GHSA-jfmj-8mj4-rr8f/GHSA-jfmj-8mj4-rr8f.json | 8 ++------ .../12/GHSA-jq43-mcx6-wp6q/GHSA-jq43-mcx6-wp6q.json | 8 ++------ .../12/GHSA-jq98-jrfw-jv2j/GHSA-jq98-jrfw-jv2j.json | 4 +--- .../12/GHSA-jrhj-xj93-7gg6/GHSA-jrhj-xj93-7gg6.json | 8 ++------ .../12/GHSA-jvfh-j65v-3qc2/GHSA-jvfh-j65v-3qc2.json | 8 ++------ .../12/GHSA-jvq6-xpq3-8mch/GHSA-jvq6-xpq3-8mch.json | 8 ++------ .../12/GHSA-jw96-2pwp-84xm/GHSA-jw96-2pwp-84xm.json | 8 ++------ .../12/GHSA-jx33-88wc-7x75/GHSA-jx33-88wc-7x75.json | 8 ++------ .../12/GHSA-jx9r-hrmg-9q76/GHSA-jx9r-hrmg-9q76.json | 4 +--- .../12/GHSA-m3g9-6hxq-c8fj/GHSA-m3g9-6hxq-c8fj.json | 8 ++------ .../12/GHSA-m3p6-3gv6-4226/GHSA-m3p6-3gv6-4226.json | 8 ++------ .../12/GHSA-m3vj-6h83-w76q/GHSA-m3vj-6h83-w76q.json | 8 ++------ .../12/GHSA-m42q-f292-m7wq/GHSA-m42q-f292-m7wq.json | 8 ++------ .../12/GHSA-m4mf-6f9r-rfx5/GHSA-m4mf-6f9r-rfx5.json | 12 +++--------- .../12/GHSA-m55v-8766-rh84/GHSA-m55v-8766-rh84.json | 8 ++------ .../12/GHSA-m732-h63v-9gww/GHSA-m732-h63v-9gww.json | 8 ++------ .../12/GHSA-m7px-chfm-qxc5/GHSA-m7px-chfm-qxc5.json | 8 ++------ .../12/GHSA-m9hw-3qvv-6hxr/GHSA-m9hw-3qvv-6hxr.json | 4 +--- .../12/GHSA-m9vv-m88f-3xj8/GHSA-m9vv-m88f-3xj8.json | 4 +--- .../12/GHSA-mgq6-mjm8-39w4/GHSA-mgq6-mjm8-39w4.json | 8 ++------ .../12/GHSA-mgxh-hxcr-38x2/GHSA-mgxh-hxcr-38x2.json | 8 ++------ .../12/GHSA-mpg5-6753-g2p4/GHSA-mpg5-6753-g2p4.json | 8 ++------ .../12/GHSA-mpvr-2998-4q8g/GHSA-mpvr-2998-4q8g.json | 8 ++------ .../12/GHSA-mw63-q92x-5p9w/GHSA-mw63-q92x-5p9w.json | 8 ++------ .../12/GHSA-p462-h5xx-px29/GHSA-p462-h5xx-px29.json | 8 ++------ .../12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json | 12 +++--------- .../12/GHSA-pf4w-mhjv-g5wm/GHSA-pf4w-mhjv-g5wm.json | 4 +--- .../12/GHSA-pffm-c29w-9739/GHSA-pffm-c29w-9739.json | 8 ++------ .../12/GHSA-pgqq-qj76-fffj/GHSA-pgqq-qj76-fffj.json | 8 ++------ .../12/GHSA-pjj9-7rm3-86j3/GHSA-pjj9-7rm3-86j3.json | 8 ++------ .../12/GHSA-pq7c-f7ch-qfh7/GHSA-pq7c-f7ch-qfh7.json | 12 +++--------- .../12/GHSA-pq93-2733-562x/GHSA-pq93-2733-562x.json | 8 ++------ .../12/GHSA-pr2c-95ww-2xr3/GHSA-pr2c-95ww-2xr3.json | 8 ++------ .../12/GHSA-prj9-vfhq-9g4m/GHSA-prj9-vfhq-9g4m.json | 8 ++------ .../12/GHSA-pxmq-rrfv-xh8v/GHSA-pxmq-rrfv-xh8v.json | 4 +--- .../12/GHSA-q23q-8cgx-c4v7/GHSA-q23q-8cgx-c4v7.json | 8 ++------ .../12/GHSA-q33m-rrqm-6xhw/GHSA-q33m-rrqm-6xhw.json | 4 +--- .../12/GHSA-q5pv-569g-3p96/GHSA-q5pv-569g-3p96.json | 8 ++------ .../12/GHSA-q8m7-5gp8-mgvg/GHSA-q8m7-5gp8-mgvg.json | 8 ++------ .../12/GHSA-qcf6-6wf2-xmxg/GHSA-qcf6-6wf2-xmxg.json | 8 ++------ .../12/GHSA-qf34-j4vq-q329/GHSA-qf34-j4vq-q329.json | 8 ++------ .../12/GHSA-qfw2-4mg3-rwff/GHSA-qfw2-4mg3-rwff.json | 8 ++------ .../12/GHSA-qmgp-p6v2-662h/GHSA-qmgp-p6v2-662h.json | 4 +--- .../12/GHSA-qq94-59f9-hxxm/GHSA-qq94-59f9-hxxm.json | 8 ++------ .../12/GHSA-qvw4-2wj5-3r5w/GHSA-qvw4-2wj5-3r5w.json | 8 ++------ .../12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json | 4 +--- .../12/GHSA-r22f-rmv4-8q7h/GHSA-r22f-rmv4-8q7h.json | 8 ++------ .../12/GHSA-r39r-c554-xv77/GHSA-r39r-c554-xv77.json | 4 +--- .../12/GHSA-r3vg-939c-2mrm/GHSA-r3vg-939c-2mrm.json | 8 ++------ .../12/GHSA-r535-rfwp-fm57/GHSA-r535-rfwp-fm57.json | 8 ++------ .../12/GHSA-r5v3-6r2m-ww8f/GHSA-r5v3-6r2m-ww8f.json | 8 ++------ .../12/GHSA-r87m-52m7-4wpg/GHSA-r87m-52m7-4wpg.json | 8 ++------ .../12/GHSA-r945-wx68-4j73/GHSA-r945-wx68-4j73.json | 8 ++------ .../12/GHSA-rcrg-grjr-gmc3/GHSA-rcrg-grjr-gmc3.json | 8 ++------ .../12/GHSA-rg3w-x342-7q53/GHSA-rg3w-x342-7q53.json | 12 +++--------- .../12/GHSA-rgr9-47fx-rg94/GHSA-rgr9-47fx-rg94.json | 12 +++--------- .../12/GHSA-rh4p-q5vg-f37m/GHSA-rh4p-q5vg-f37m.json | 8 ++------ .../12/GHSA-rh4x-ccvq-jc34/GHSA-rh4x-ccvq-jc34.json | 4 +--- .../12/GHSA-rpgq-c954-jmg6/GHSA-rpgq-c954-jmg6.json | 8 ++------ .../12/GHSA-rqm9-c34w-wvxq/GHSA-rqm9-c34w-wvxq.json | 8 ++------ .../12/GHSA-rwp6-cpw3-hxxx/GHSA-rwp6-cpw3-hxxx.json | 8 ++------ .../12/GHSA-rxvx-2jq5-pc48/GHSA-rxvx-2jq5-pc48.json | 4 +--- .../12/GHSA-v7v2-vp57-589m/GHSA-v7v2-vp57-589m.json | 12 +++--------- .../12/GHSA-v8h7-57p4-wr4f/GHSA-v8h7-57p4-wr4f.json | 8 ++------ .../12/GHSA-v93v-fxgx-33qf/GHSA-v93v-fxgx-33qf.json | 8 ++------ .../12/GHSA-vf79-gh76-r26h/GHSA-vf79-gh76-r26h.json | 8 ++------ .../12/GHSA-vm48-354f-2w7j/GHSA-vm48-354f-2w7j.json | 8 ++------ .../12/GHSA-vp4x-j24m-6jjq/GHSA-vp4x-j24m-6jjq.json | 8 ++------ .../12/GHSA-vq7q-g9c7-hj87/GHSA-vq7q-g9c7-hj87.json | 8 ++------ .../12/GHSA-vr7j-j9jw-pjj7/GHSA-vr7j-j9jw-pjj7.json | 4 +--- .../12/GHSA-vv73-f455-9crg/GHSA-vv73-f455-9crg.json | 8 ++------ .../12/GHSA-vv96-jq6f-v366/GHSA-vv96-jq6f-v366.json | 8 ++------ .../12/GHSA-vx4g-4h4f-5cmg/GHSA-vx4g-4h4f-5cmg.json | 8 ++------ .../12/GHSA-vxh6-3w55-j34c/GHSA-vxh6-3w55-j34c.json | 12 +++--------- .../12/GHSA-w4mm-46pm-fmvh/GHSA-w4mm-46pm-fmvh.json | 8 ++------ .../12/GHSA-w8c2-mp5p-9g9q/GHSA-w8c2-mp5p-9g9q.json | 8 ++------ .../12/GHSA-wf58-48gj-3f44/GHSA-wf58-48gj-3f44.json | 8 ++------ .../12/GHSA-wgcg-wpg9-jq43/GHSA-wgcg-wpg9-jq43.json | 8 ++------ .../12/GHSA-wjr4-fpmr-3p4f/GHSA-wjr4-fpmr-3p4f.json | 4 +--- .../12/GHSA-wp8c-5j7q-j666/GHSA-wp8c-5j7q-j666.json | 8 ++------ .../12/GHSA-wphx-qm9g-v53m/GHSA-wphx-qm9g-v53m.json | 8 ++------ .../12/GHSA-wv3w-fcvm-p52v/GHSA-wv3w-fcvm-p52v.json | 8 ++------ .../12/GHSA-wv8m-chcw-6w78/GHSA-wv8m-chcw-6w78.json | 8 ++------ .../12/GHSA-wvxh-xchr-m6p5/GHSA-wvxh-xchr-m6p5.json | 8 ++------ .../12/GHSA-wwgj-pf6c-p6hc/GHSA-wwgj-pf6c-p6hc.json | 8 ++------ .../12/GHSA-x3gh-j7gq-pr86/GHSA-x3gh-j7gq-pr86.json | 8 ++------ .../12/GHSA-x4h8-mfxr-8358/GHSA-x4h8-mfxr-8358.json | 8 ++------ .../12/GHSA-x4wg-w7pm-7f26/GHSA-x4wg-w7pm-7f26.json | 8 ++------ .../12/GHSA-x5f4-jxc9-j6mv/GHSA-x5f4-jxc9-j6mv.json | 12 +++--------- .../12/GHSA-x5f7-m6j9-3793/GHSA-x5f7-m6j9-3793.json | 8 ++------ .../12/GHSA-x623-q82m-99x6/GHSA-x623-q82m-99x6.json | 8 ++------ .../12/GHSA-x6hf-2fv8-q6m6/GHSA-x6hf-2fv8-q6m6.json | 8 ++------ .../12/GHSA-x8jw-8x39-62fp/GHSA-x8jw-8x39-62fp.json | 8 ++------ .../12/GHSA-xf9j-qfgm-f8jm/GHSA-xf9j-qfgm-f8jm.json | 12 +++--------- .../12/GHSA-xg3h-r232-6rmw/GHSA-xg3h-r232-6rmw.json | 8 ++------ .../12/GHSA-xq54-j4gh-pm4j/GHSA-xq54-j4gh-pm4j.json | 8 ++------ .../12/GHSA-xvhr-qprg-rjpw/GHSA-xvhr-qprg-rjpw.json | 8 ++------ .../02/GHSA-254m-3cq9-8624/GHSA-254m-3cq9-8624.json | 4 +--- .../02/GHSA-2wx9-j8x2-r9vm/GHSA-2wx9-j8x2-r9vm.json | 4 +--- .../02/GHSA-7qcx-j2px-v82h/GHSA-7qcx-j2px-v82h.json | 4 +--- .../02/GHSA-8v55-rm6p-87p5/GHSA-8v55-rm6p-87p5.json | 4 +--- .../02/GHSA-945f-ph6w-hf2g/GHSA-945f-ph6w-hf2g.json | 4 +--- .../02/GHSA-969p-8qf6-mrvc/GHSA-969p-8qf6-mrvc.json | 4 +--- .../02/GHSA-fwqr-qx2m-vqxq/GHSA-fwqr-qx2m-vqxq.json | 4 +--- .../02/GHSA-hgh9-57mp-975h/GHSA-hgh9-57mp-975h.json | 4 +--- .../02/GHSA-j379-364f-696h/GHSA-j379-364f-696h.json | 4 +--- .../02/GHSA-vfmf-vjx2-868p/GHSA-vfmf-vjx2-868p.json | 4 +--- .../02/GHSA-wccv-r56q-vwmw/GHSA-wccv-r56q-vwmw.json | 4 +--- .../02/GHSA-wrf8-w7q7-mfr4/GHSA-wrf8-w7q7-mfr4.json | 4 +--- .../05/GHSA-247h-6fhv-4v2c/GHSA-247h-6fhv-4v2c.json | 12 +++--------- .../05/GHSA-24c9-7g9h-vmm8/GHSA-24c9-7g9h-vmm8.json | 8 ++------ .../05/GHSA-24h9-wwcg-r638/GHSA-24h9-wwcg-r638.json | 12 +++--------- .../05/GHSA-24hh-hrh3-7p5w/GHSA-24hh-hrh3-7p5w.json | 12 +++--------- .../05/GHSA-256q-r8jw-w2f7/GHSA-256q-r8jw-w2f7.json | 8 ++------ .../05/GHSA-25gf-7mcm-h7vj/GHSA-25gf-7mcm-h7vj.json | 4 +--- .../05/GHSA-265g-226q-c27c/GHSA-265g-226q-c27c.json | 12 +++--------- .../05/GHSA-26m7-h3mc-j98r/GHSA-26m7-h3mc-j98r.json | 8 ++------ .../05/GHSA-2775-52x6-3w7f/GHSA-2775-52x6-3w7f.json | 8 ++------ .../05/GHSA-2885-hmxc-wwgx/GHSA-2885-hmxc-wwgx.json | 12 +++--------- .../05/GHSA-2893-36vg-x3vj/GHSA-2893-36vg-x3vj.json | 8 ++------ .../05/GHSA-28gc-vvw4-44jg/GHSA-28gc-vvw4-44jg.json | 8 ++------ .../05/GHSA-28mc-4879-xh6f/GHSA-28mc-4879-xh6f.json | 8 ++------ .../05/GHSA-2fj2-4h38-3c72/GHSA-2fj2-4h38-3c72.json | 4 +--- .../05/GHSA-2fvh-4fwg-94q3/GHSA-2fvh-4fwg-94q3.json | 8 ++------ .../05/GHSA-2g3h-rvgj-6gh5/GHSA-2g3h-rvgj-6gh5.json | 12 +++--------- .../05/GHSA-2hgf-g4v8-3jqv/GHSA-2hgf-g4v8-3jqv.json | 8 ++------ .../05/GHSA-2hgw-48gj-v3wx/GHSA-2hgw-48gj-v3wx.json | 12 +++--------- .../05/GHSA-2jjp-v4x9-55gm/GHSA-2jjp-v4x9-55gm.json | 12 +++--------- .../05/GHSA-2m99-5fff-xf2f/GHSA-2m99-5fff-xf2f.json | 8 ++------ .../05/GHSA-2mp4-3r7m-mmg9/GHSA-2mp4-3r7m-mmg9.json | 8 ++------ .../05/GHSA-2ppv-95h6-36pf/GHSA-2ppv-95h6-36pf.json | 12 +++--------- .../05/GHSA-2qgv-pgxc-xh7j/GHSA-2qgv-pgxc-xh7j.json | 12 +++--------- .../05/GHSA-2r73-5g3g-pvhw/GHSA-2r73-5g3g-pvhw.json | 8 ++------ .../05/GHSA-2v43-c695-wqxw/GHSA-2v43-c695-wqxw.json | 8 ++------ .../05/GHSA-2v75-jgr3-vhp6/GHSA-2v75-jgr3-vhp6.json | 12 +++--------- .../05/GHSA-2w9j-55xj-gcp3/GHSA-2w9j-55xj-gcp3.json | 4 +--- .../05/GHSA-2w9x-8fmc-q598/GHSA-2w9x-8fmc-q598.json | 8 ++------ .../05/GHSA-323p-4v5q-w32p/GHSA-323p-4v5q-w32p.json | 8 ++------ .../05/GHSA-34rg-qhv9-9cpx/GHSA-34rg-qhv9-9cpx.json | 4 +--- .../05/GHSA-34xh-g8p4-g947/GHSA-34xh-g8p4-g947.json | 12 +++--------- .../05/GHSA-3566-jfm7-38ph/GHSA-3566-jfm7-38ph.json | 8 ++------ .../05/GHSA-35jw-93qg-qxgw/GHSA-35jw-93qg-qxgw.json | 12 +++--------- .../05/GHSA-35w3-85xv-8x6w/GHSA-35w3-85xv-8x6w.json | 8 ++------ .../05/GHSA-365m-rf96-qxh8/GHSA-365m-rf96-qxh8.json | 8 ++------ .../05/GHSA-377x-3gqm-h467/GHSA-377x-3gqm-h467.json | 8 ++------ .../05/GHSA-383f-wq2v-q529/GHSA-383f-wq2v-q529.json | 8 ++------ .../05/GHSA-38p9-xg79-q3f9/GHSA-38p9-xg79-q3f9.json | 4 +--- .../05/GHSA-39cj-q7jm-v7pc/GHSA-39cj-q7jm-v7pc.json | 8 ++------ .../05/GHSA-39mh-9qg5-7gh4/GHSA-39mh-9qg5-7gh4.json | 8 ++------ .../05/GHSA-3cp9-95xq-76hw/GHSA-3cp9-95xq-76hw.json | 8 ++------ .../05/GHSA-3f7f-2hr4-47jj/GHSA-3f7f-2hr4-47jj.json | 8 ++------ .../05/GHSA-3gm7-8cfv-p8h9/GHSA-3gm7-8cfv-p8h9.json | 4 +--- .../05/GHSA-3gm8-9xxm-pmhh/GHSA-3gm8-9xxm-pmhh.json | 4 +--- .../05/GHSA-3gmw-m22w-rmhw/GHSA-3gmw-m22w-rmhw.json | 12 +++--------- .../05/GHSA-3gr2-8v6p-pjf9/GHSA-3gr2-8v6p-pjf9.json | 8 ++------ .../05/GHSA-3hhh-hv27-4gjh/GHSA-3hhh-hv27-4gjh.json | 4 +--- .../05/GHSA-3hq9-j8x9-925r/GHSA-3hq9-j8x9-925r.json | 8 ++------ .../05/GHSA-3j5v-hj4j-5rm9/GHSA-3j5v-hj4j-5rm9.json | 12 +++--------- .../05/GHSA-3jfw-8phg-9vp8/GHSA-3jfw-8phg-9vp8.json | 8 ++------ .../05/GHSA-3p47-jqhp-gxp9/GHSA-3p47-jqhp-gxp9.json | 12 +++--------- .../05/GHSA-3pw2-f952-6q7c/GHSA-3pw2-f952-6q7c.json | 12 +++--------- .../05/GHSA-3r45-7993-xcwr/GHSA-3r45-7993-xcwr.json | 8 ++------ .../05/GHSA-3r52-23hx-qw5v/GHSA-3r52-23hx-qw5v.json | 12 +++--------- .../05/GHSA-3v2j-hm2p-q5qg/GHSA-3v2j-hm2p-q5qg.json | 12 +++--------- .../05/GHSA-3w34-xv7m-phqr/GHSA-3w34-xv7m-phqr.json | 4 +--- .../05/GHSA-3w8c-hmvh-m87g/GHSA-3w8c-hmvh-m87g.json | 12 +++--------- .../05/GHSA-3wq7-2q97-v54v/GHSA-3wq7-2q97-v54v.json | 12 +++--------- .../05/GHSA-3ww4-hpff-r8mv/GHSA-3ww4-hpff-r8mv.json | 8 ++------ .../05/GHSA-3ww7-mpcv-cwwh/GHSA-3ww7-mpcv-cwwh.json | 4 +--- .../05/GHSA-3x4w-3pwj-2297/GHSA-3x4w-3pwj-2297.json | 8 ++------ .../05/GHSA-3xmp-37v6-x52p/GHSA-3xmp-37v6-x52p.json | 8 ++------ .../05/GHSA-3xrf-3v7w-582w/GHSA-3xrf-3v7w-582w.json | 12 +++--------- .../05/GHSA-429c-wjm9-c577/GHSA-429c-wjm9-c577.json | 8 ++------ .../05/GHSA-4349-2x5x-f444/GHSA-4349-2x5x-f444.json | 8 ++------ .../05/GHSA-438x-56gx-w64g/GHSA-438x-56gx-w64g.json | 12 +++--------- .../05/GHSA-43f9-pjg6-9rw4/GHSA-43f9-pjg6-9rw4.json | 8 ++------ .../05/GHSA-43vf-866m-gxw3/GHSA-43vf-866m-gxw3.json | 12 +++--------- .../05/GHSA-4438-jh32-8rr9/GHSA-4438-jh32-8rr9.json | 8 ++------ .../05/GHSA-44pw-f9wr-w46w/GHSA-44pw-f9wr-w46w.json | 8 ++------ .../05/GHSA-458j-vj9v-25r8/GHSA-458j-vj9v-25r8.json | 12 +++--------- .../05/GHSA-476g-xp34-4rj3/GHSA-476g-xp34-4rj3.json | 4 +--- .../05/GHSA-478q-7xf2-cxcp/GHSA-478q-7xf2-cxcp.json | 8 ++------ .../05/GHSA-479j-8mrp-jf68/GHSA-479j-8mrp-jf68.json | 12 +++--------- .../05/GHSA-47gr-pfr8-r958/GHSA-47gr-pfr8-r958.json | 8 ++------ .../05/GHSA-47pm-rhm6-w3xc/GHSA-47pm-rhm6-w3xc.json | 8 ++------ .../05/GHSA-47wf-g7rm-46qq/GHSA-47wf-g7rm-46qq.json | 12 +++--------- .../05/GHSA-48p6-fq4x-274j/GHSA-48p6-fq4x-274j.json | 8 ++------ .../05/GHSA-48q7-r6r9-rhx2/GHSA-48q7-r6r9-rhx2.json | 8 ++------ .../05/GHSA-49c9-9c2p-h2gm/GHSA-49c9-9c2p-h2gm.json | 8 ++------ .../05/GHSA-4c32-x28m-p8h3/GHSA-4c32-x28m-p8h3.json | 8 ++------ .../05/GHSA-4fq8-mjrf-79qc/GHSA-4fq8-mjrf-79qc.json | 8 ++------ .../05/GHSA-4gfg-32rq-7753/GHSA-4gfg-32rq-7753.json | 8 ++------ .../05/GHSA-4hfj-x2gr-q83x/GHSA-4hfj-x2gr-q83x.json | 12 +++--------- .../05/GHSA-4hgr-hf94-2xj2/GHSA-4hgr-hf94-2xj2.json | 8 ++------ .../05/GHSA-4hjr-2692-85gm/GHSA-4hjr-2692-85gm.json | 8 ++------ .../05/GHSA-4hwc-m82x-xf7x/GHSA-4hwc-m82x-xf7x.json | 8 ++------ .../05/GHSA-4jr8-gq3p-6jg6/GHSA-4jr8-gq3p-6jg6.json | 8 ++------ .../05/GHSA-4mxh-q2pf-wp5x/GHSA-4mxh-q2pf-wp5x.json | 12 +++--------- .../05/GHSA-4p9f-r8qj-23xf/GHSA-4p9f-r8qj-23xf.json | 8 ++------ .../05/GHSA-4q3c-jxc9-rf75/GHSA-4q3c-jxc9-rf75.json | 12 +++--------- .../05/GHSA-4q5h-m3w9-x569/GHSA-4q5h-m3w9-x569.json | 8 ++------ .../05/GHSA-4qp4-ccmr-483g/GHSA-4qp4-ccmr-483g.json | 4 +--- .../05/GHSA-4rff-c4p8-c56p/GHSA-4rff-c4p8-c56p.json | 12 +++--------- .../05/GHSA-4rvg-9g3m-4m9p/GHSA-4rvg-9g3m-4m9p.json | 8 ++------ .../05/GHSA-4rwr-62pp-84mp/GHSA-4rwr-62pp-84mp.json | 8 ++------ .../05/GHSA-4vp8-fm4w-fw2f/GHSA-4vp8-fm4w-fw2f.json | 8 ++------ .../05/GHSA-4vq9-9g4j-pgg4/GHSA-4vq9-9g4j-pgg4.json | 12 +++--------- .../05/GHSA-4wf2-8957-vf9x/GHSA-4wf2-8957-vf9x.json | 8 ++------ .../05/GHSA-4wp5-gx3f-rhgh/GHSA-4wp5-gx3f-rhgh.json | 12 +++--------- .../05/GHSA-52p4-92p5-7qfq/GHSA-52p4-92p5-7qfq.json | 8 ++------ .../05/GHSA-53g5-x4w6-f3r7/GHSA-53g5-x4w6-f3r7.json | 8 ++------ .../05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json | 4 +--- .../05/GHSA-53q6-pfcm-jvjp/GHSA-53q6-pfcm-jvjp.json | 8 ++------ .../05/GHSA-545v-887v-vf85/GHSA-545v-887v-vf85.json | 8 ++------ .../05/GHSA-546g-4wj5-vp4x/GHSA-546g-4wj5-vp4x.json | 4 +--- .../05/GHSA-54cg-rgh7-pj5q/GHSA-54cg-rgh7-pj5q.json | 8 ++------ .../05/GHSA-54r7-jqjw-9p94/GHSA-54r7-jqjw-9p94.json | 4 +--- .../05/GHSA-55hp-jcxq-hgwc/GHSA-55hp-jcxq-hgwc.json | 8 ++------ .../05/GHSA-56ww-7836-2fcq/GHSA-56ww-7836-2fcq.json | 4 +--- .../05/GHSA-575w-rwc7-4259/GHSA-575w-rwc7-4259.json | 12 +++--------- .../05/GHSA-576r-h2rw-fh3f/GHSA-576r-h2rw-fh3f.json | 8 ++------ .../05/GHSA-58gm-g38v-xch5/GHSA-58gm-g38v-xch5.json | 8 ++------ .../05/GHSA-58jj-372m-hm97/GHSA-58jj-372m-hm97.json | 12 +++--------- .../05/GHSA-5956-hhvq-fv53/GHSA-5956-hhvq-fv53.json | 12 +++--------- .../05/GHSA-59fg-mjcp-w8r4/GHSA-59fg-mjcp-w8r4.json | 8 ++------ .../05/GHSA-59p8-gqqx-vfr6/GHSA-59p8-gqqx-vfr6.json | 8 ++------ .../05/GHSA-59w3-gq45-h2m8/GHSA-59w3-gq45-h2m8.json | 8 ++------ .../05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json | 4 +--- .../05/GHSA-5c6q-9638-267m/GHSA-5c6q-9638-267m.json | 4 +--- .../05/GHSA-5cph-mc6w-g6xg/GHSA-5cph-mc6w-g6xg.json | 12 +++--------- .../05/GHSA-5h56-9gpv-f6cx/GHSA-5h56-9gpv-f6cx.json | 8 ++------ .../05/GHSA-5jj7-6jx2-x56m/GHSA-5jj7-6jx2-x56m.json | 12 +++--------- .../05/GHSA-5jx7-7v29-v3mc/GHSA-5jx7-7v29-v3mc.json | 12 +++--------- .../05/GHSA-5m9w-mc2w-2vgj/GHSA-5m9w-mc2w-2vgj.json | 8 ++------ .../05/GHSA-5p8v-454h-7rv7/GHSA-5p8v-454h-7rv7.json | 8 ++------ .../05/GHSA-5pq2-2975-f8c8/GHSA-5pq2-2975-f8c8.json | 12 +++--------- .../05/GHSA-5r4q-84cw-cpwc/GHSA-5r4q-84cw-cpwc.json | 8 ++------ .../05/GHSA-5vqg-4pw8-x3vj/GHSA-5vqg-4pw8-x3vj.json | 8 ++------ .../05/GHSA-5vxp-j78v-p6qp/GHSA-5vxp-j78v-p6qp.json | 8 ++------ .../05/GHSA-5w95-m5g4-hrhx/GHSA-5w95-m5g4-hrhx.json | 8 ++------ .../05/GHSA-5wcj-3w9q-9gp9/GHSA-5wcj-3w9q-9gp9.json | 8 ++------ .../05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json | 4 +--- .../05/GHSA-5x7c-p595-fhwh/GHSA-5x7c-p595-fhwh.json | 12 +++--------- .../05/GHSA-5xfg-3m42-q8mv/GHSA-5xfg-3m42-q8mv.json | 12 +++--------- .../05/GHSA-62wr-q7q7-4f5m/GHSA-62wr-q7q7-4f5m.json | 12 +++--------- .../05/GHSA-637x-5jgj-26w6/GHSA-637x-5jgj-26w6.json | 8 ++------ .../05/GHSA-6384-2w9h-qw8w/GHSA-6384-2w9h-qw8w.json | 12 +++--------- .../05/GHSA-63pv-4q6j-7pxp/GHSA-63pv-4q6j-7pxp.json | 8 ++------ .../05/GHSA-6476-7f65-cc4m/GHSA-6476-7f65-cc4m.json | 4 +--- .../05/GHSA-65m7-qc75-24vh/GHSA-65m7-qc75-24vh.json | 8 ++------ .../05/GHSA-66v9-pvqf-v3jj/GHSA-66v9-pvqf-v3jj.json | 8 ++------ .../05/GHSA-687w-xp39-q584/GHSA-687w-xp39-q584.json | 4 +--- .../05/GHSA-69p6-c7wv-2f89/GHSA-69p6-c7wv-2f89.json | 12 +++--------- .../05/GHSA-6c46-7rvf-rgx4/GHSA-6c46-7rvf-rgx4.json | 8 ++------ .../05/GHSA-6cf4-r7qc-3553/GHSA-6cf4-r7qc-3553.json | 8 ++------ .../05/GHSA-6cmv-j38v-h7wc/GHSA-6cmv-j38v-h7wc.json | 8 ++------ .../05/GHSA-6f53-c85c-88pq/GHSA-6f53-c85c-88pq.json | 8 ++------ .../05/GHSA-6f74-rcv9-9q87/GHSA-6f74-rcv9-9q87.json | 12 +++--------- .../05/GHSA-6g6p-2rvm-4c95/GHSA-6g6p-2rvm-4c95.json | 8 ++------ .../05/GHSA-6g82-jmg8-h26c/GHSA-6g82-jmg8-h26c.json | 12 +++--------- .../05/GHSA-6hxv-37vc-85r6/GHSA-6hxv-37vc-85r6.json | 8 ++------ .../05/GHSA-6j26-gcxp-q5qw/GHSA-6j26-gcxp-q5qw.json | 8 ++------ .../05/GHSA-6j49-3xhq-p58w/GHSA-6j49-3xhq-p58w.json | 8 ++------ .../05/GHSA-6jvf-r79g-h3f2/GHSA-6jvf-r79g-h3f2.json | 8 ++------ .../05/GHSA-6mxq-8h76-443w/GHSA-6mxq-8h76-443w.json | 8 ++------ .../05/GHSA-6p2r-x9m6-65cq/GHSA-6p2r-x9m6-65cq.json | 12 +++--------- .../05/GHSA-6p5c-44cm-r9m8/GHSA-6p5c-44cm-r9m8.json | 12 +++--------- .../05/GHSA-6p6p-2fm3-6874/GHSA-6p6p-2fm3-6874.json | 12 +++--------- .../05/GHSA-6phm-2qcc-r8vp/GHSA-6phm-2qcc-r8vp.json | 8 ++------ .../05/GHSA-6pj7-7hg8-7vr5/GHSA-6pj7-7hg8-7vr5.json | 8 ++------ .../05/GHSA-6qwv-phcw-fvw8/GHSA-6qwv-phcw-fvw8.json | 8 ++------ .../05/GHSA-6r2f-63wm-774p/GHSA-6r2f-63wm-774p.json | 12 +++--------- .../05/GHSA-6v2v-v7qj-rp8x/GHSA-6v2v-v7qj-rp8x.json | 8 ++------ .../05/GHSA-6v4j-2r9w-m853/GHSA-6v4j-2r9w-m853.json | 12 +++--------- .../05/GHSA-6x9q-9h2v-cmc6/GHSA-6x9q-9h2v-cmc6.json | 8 ++------ .../05/GHSA-6xqh-rgjg-4vg5/GHSA-6xqh-rgjg-4vg5.json | 12 +++--------- .../05/GHSA-72c6-xxgm-523f/GHSA-72c6-xxgm-523f.json | 8 ++------ .../05/GHSA-7399-c2fj-2jg3/GHSA-7399-c2fj-2jg3.json | 8 ++------ .../05/GHSA-73pf-mvfq-rghp/GHSA-73pf-mvfq-rghp.json | 8 ++------ .../05/GHSA-7499-pwh5-6vh8/GHSA-7499-pwh5-6vh8.json | 12 +++--------- .../05/GHSA-74jj-5cp3-vhx3/GHSA-74jj-5cp3-vhx3.json | 12 +++--------- .../05/GHSA-75w6-c37p-69v3/GHSA-75w6-c37p-69v3.json | 12 +++--------- .../05/GHSA-79cm-5mpx-ff74/GHSA-79cm-5mpx-ff74.json | 12 +++--------- .../05/GHSA-79g3-3mvq-3m6x/GHSA-79g3-3mvq-3m6x.json | 8 ++------ .../05/GHSA-79mh-428r-c849/GHSA-79mh-428r-c849.json | 8 ++------ .../05/GHSA-7c94-52c6-8hwg/GHSA-7c94-52c6-8hwg.json | 8 ++------ .../05/GHSA-7chx-66rj-q7wh/GHSA-7chx-66rj-q7wh.json | 4 +--- .../05/GHSA-7gm5-vg78-248m/GHSA-7gm5-vg78-248m.json | 12 +++--------- .../05/GHSA-7h3v-6p66-cfwj/GHSA-7h3v-6p66-cfwj.json | 8 ++------ .../05/GHSA-7jfh-mfwx-qffg/GHSA-7jfh-mfwx-qffg.json | 8 ++------ .../05/GHSA-7p6w-2mrq-wqmv/GHSA-7p6w-2mrq-wqmv.json | 8 ++------ .../05/GHSA-7p99-vvwg-793p/GHSA-7p99-vvwg-793p.json | 8 ++------ .../05/GHSA-7p9v-555g-5hgg/GHSA-7p9v-555g-5hgg.json | 4 +--- .../05/GHSA-7phm-f5vw-fc7p/GHSA-7phm-f5vw-fc7p.json | 8 ++------ .../05/GHSA-7pmf-v687-c5v4/GHSA-7pmf-v687-c5v4.json | 4 +--- .../05/GHSA-7pwr-jgrg-q23m/GHSA-7pwr-jgrg-q23m.json | 12 +++--------- .../05/GHSA-7q7f-994w-22j8/GHSA-7q7f-994w-22j8.json | 8 ++------ .../05/GHSA-7r3c-83p4-h28h/GHSA-7r3c-83p4-h28h.json | 8 ++------ .../05/GHSA-7rpp-hwhj-9hv8/GHSA-7rpp-hwhj-9hv8.json | 4 +--- .../05/GHSA-7v72-p9gx-28vj/GHSA-7v72-p9gx-28vj.json | 12 +++--------- .../05/GHSA-7vcr-gg86-5p2j/GHSA-7vcr-gg86-5p2j.json | 8 ++------ .../05/GHSA-7vx4-j5mm-h4p8/GHSA-7vx4-j5mm-h4p8.json | 12 +++--------- .../05/GHSA-7x5f-m83q-6f4q/GHSA-7x5f-m83q-6f4q.json | 8 ++------ .../05/GHSA-7xjp-xgmc-5vc9/GHSA-7xjp-xgmc-5vc9.json | 12 +++--------- .../05/GHSA-822h-vphc-4mvf/GHSA-822h-vphc-4mvf.json | 12 +++--------- .../05/GHSA-827c-j6w2-8fg4/GHSA-827c-j6w2-8fg4.json | 8 ++------ .../05/GHSA-82q2-xf4j-jj8g/GHSA-82q2-xf4j-jj8g.json | 8 ++------ .../05/GHSA-83r5-gpg4-8mv5/GHSA-83r5-gpg4-8mv5.json | 8 ++------ .../05/GHSA-848g-j7cv-9644/GHSA-848g-j7cv-9644.json | 8 ++------ .../05/GHSA-84vv-6fh8-r3gv/GHSA-84vv-6fh8-r3gv.json | 8 ++------ .../05/GHSA-854c-mqcx-rhcc/GHSA-854c-mqcx-rhcc.json | 12 +++--------- .../05/GHSA-88g5-782g-r7xp/GHSA-88g5-782g-r7xp.json | 8 ++------ .../05/GHSA-88vx-49vv-gcx2/GHSA-88vx-49vv-gcx2.json | 12 +++--------- .../05/GHSA-8f49-c882-385m/GHSA-8f49-c882-385m.json | 8 ++------ .../05/GHSA-8g86-cfmw-cfgc/GHSA-8g86-cfmw-cfgc.json | 8 ++------ .../05/GHSA-8h6j-f8rw-25pv/GHSA-8h6j-f8rw-25pv.json | 8 ++------ .../05/GHSA-8hhx-c6j2-6m2w/GHSA-8hhx-c6j2-6m2w.json | 8 ++------ .../05/GHSA-8m5p-57f4-m897/GHSA-8m5p-57f4-m897.json | 8 ++------ .../05/GHSA-8mh4-cq82-8r3x/GHSA-8mh4-cq82-8r3x.json | 8 ++------ .../05/GHSA-8pr7-f78m-qwfx/GHSA-8pr7-f78m-qwfx.json | 8 ++------ .../05/GHSA-8pvv-4x3j-fgh9/GHSA-8pvv-4x3j-fgh9.json | 12 +++--------- .../05/GHSA-8q5p-rpfq-gjc9/GHSA-8q5p-rpfq-gjc9.json | 12 +++--------- .../05/GHSA-8v55-2h3g-6wvr/GHSA-8v55-2h3g-6wvr.json | 12 +++--------- .../05/GHSA-8v93-c335-x4h3/GHSA-8v93-c335-x4h3.json | 4 +--- .../05/GHSA-8wg5-pm5f-vw86/GHSA-8wg5-pm5f-vw86.json | 8 ++------ .../05/GHSA-8wjm-mwjv-j295/GHSA-8wjm-mwjv-j295.json | 8 ++------ .../05/GHSA-8x3f-mp7c-vfgm/GHSA-8x3f-mp7c-vfgm.json | 8 ++------ .../05/GHSA-8xjx-475c-5hjg/GHSA-8xjx-475c-5hjg.json | 12 +++--------- .../05/GHSA-9272-j67v-qf39/GHSA-9272-j67v-qf39.json | 12 +++--------- .../05/GHSA-92jq-w79w-2g5c/GHSA-92jq-w79w-2g5c.json | 8 ++------ .../05/GHSA-92jw-w2rc-xwxg/GHSA-92jw-w2rc-xwxg.json | 12 +++--------- .../05/GHSA-93qv-2hpr-4mmc/GHSA-93qv-2hpr-4mmc.json | 12 +++--------- .../05/GHSA-94gc-q6xg-j8wh/GHSA-94gc-q6xg-j8wh.json | 8 ++------ .../05/GHSA-9579-x24g-29q6/GHSA-9579-x24g-29q6.json | 12 +++--------- .../05/GHSA-968q-p5w6-ghj4/GHSA-968q-p5w6-ghj4.json | 12 +++--------- .../05/GHSA-975h-h4pp-737q/GHSA-975h-h4pp-737q.json | 12 +++--------- .../05/GHSA-9776-m3xf-335w/GHSA-9776-m3xf-335w.json | 8 ++------ .../05/GHSA-97c2-mgrq-5254/GHSA-97c2-mgrq-5254.json | 8 ++------ .../05/GHSA-9cmg-www5-3gxx/GHSA-9cmg-www5-3gxx.json | 8 ++------ .../05/GHSA-9f37-2v5p-xv7g/GHSA-9f37-2v5p-xv7g.json | 8 ++------ .../05/GHSA-9f6q-qf7p-473x/GHSA-9f6q-qf7p-473x.json | 8 ++------ .../05/GHSA-9fm7-cmvm-vvjr/GHSA-9fm7-cmvm-vvjr.json | 4 +--- .../05/GHSA-9g4q-3qcf-mvw9/GHSA-9g4q-3qcf-mvw9.json | 8 ++------ .../05/GHSA-9g58-r5gj-vhr9/GHSA-9g58-r5gj-vhr9.json | 8 ++------ .../05/GHSA-9g6q-jjw5-x5fw/GHSA-9g6q-jjw5-x5fw.json | 8 ++------ .../05/GHSA-9gh5-vff3-cwrr/GHSA-9gh5-vff3-cwrr.json | 8 ++------ .../05/GHSA-9hf2-x6cm-637r/GHSA-9hf2-x6cm-637r.json | 8 ++------ .../05/GHSA-9jg7-472x-vxf4/GHSA-9jg7-472x-vxf4.json | 12 +++--------- .../05/GHSA-9m2v-w6qp-58wr/GHSA-9m2v-w6qp-58wr.json | 12 +++--------- .../05/GHSA-9m3w-j6gp-86c9/GHSA-9m3w-j6gp-86c9.json | 8 ++------ .../05/GHSA-9q5f-7fh4-3hgx/GHSA-9q5f-7fh4-3hgx.json | 8 ++------ .../05/GHSA-9r76-mhm8-f3q4/GHSA-9r76-mhm8-f3q4.json | 12 +++--------- .../05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json | 12 +++--------- .../05/GHSA-9w8p-xcg8-8w62/GHSA-9w8p-xcg8-8w62.json | 8 ++------ .../05/GHSA-9xgp-phf8-4m42/GHSA-9xgp-phf8-4m42.json | 8 ++------ .../05/GHSA-9xh5-5qwr-3g4w/GHSA-9xh5-5qwr-3g4w.json | 8 ++------ .../05/GHSA-c2c8-3mgj-74jc/GHSA-c2c8-3mgj-74jc.json | 8 ++------ .../05/GHSA-c3w4-m4vr-9g7g/GHSA-c3w4-m4vr-9g7g.json | 8 ++------ .../05/GHSA-c4gw-w6f2-29hh/GHSA-c4gw-w6f2-29hh.json | 4 +--- .../05/GHSA-c4q8-68wp-mg94/GHSA-c4q8-68wp-mg94.json | 8 ++------ .../05/GHSA-c588-rhc6-9hw7/GHSA-c588-rhc6-9hw7.json | 12 +++--------- .../05/GHSA-c5xx-mwc6-vw82/GHSA-c5xx-mwc6-vw82.json | 8 ++------ .../05/GHSA-c856-7jr3-wm6x/GHSA-c856-7jr3-wm6x.json | 8 ++------ .../05/GHSA-cf72-mxxr-2628/GHSA-cf72-mxxr-2628.json | 12 +++--------- .../05/GHSA-cg66-88cp-whx8/GHSA-cg66-88cp-whx8.json | 12 +++--------- .../05/GHSA-cg85-44qc-39mw/GHSA-cg85-44qc-39mw.json | 4 +--- .../05/GHSA-cgf9-7f38-5j6c/GHSA-cgf9-7f38-5j6c.json | 8 ++------ .../05/GHSA-cgjm-832j-ch4g/GHSA-cgjm-832j-ch4g.json | 12 +++--------- .../05/GHSA-ch6v-3x5q-gm5j/GHSA-ch6v-3x5q-gm5j.json | 4 +--- .../05/GHSA-cjh5-6x4r-74cw/GHSA-cjh5-6x4r-74cw.json | 8 ++------ .../05/GHSA-cq3q-q7wq-586q/GHSA-cq3q-q7wq-586q.json | 8 ++------ .../05/GHSA-cqgg-3gcf-cxj8/GHSA-cqgg-3gcf-cxj8.json | 8 ++------ .../05/GHSA-cqvc-98g2-g2j9/GHSA-cqvc-98g2-g2j9.json | 4 +--- .../05/GHSA-crgw-fph4-cgrp/GHSA-crgw-fph4-cgrp.json | 8 ++------ .../05/GHSA-crpf-mqjx-74x8/GHSA-crpf-mqjx-74x8.json | 12 +++--------- .../05/GHSA-cv7m-77hj-cr43/GHSA-cv7m-77hj-cr43.json | 8 ++------ .../05/GHSA-cwqc-w7f5-59qr/GHSA-cwqc-w7f5-59qr.json | 12 +++--------- .../05/GHSA-cx8q-2cc9-5r23/GHSA-cx8q-2cc9-5r23.json | 8 ++------ .../05/GHSA-cxxh-cfm2-r8pj/GHSA-cxxh-cfm2-r8pj.json | 4 +--- .../05/GHSA-f3f7-w28x-9vg3/GHSA-f3f7-w28x-9vg3.json | 8 ++------ .../05/GHSA-f3mm-jx3m-92v4/GHSA-f3mm-jx3m-92v4.json | 8 ++------ .../05/GHSA-f5vq-4rpj-3x2w/GHSA-f5vq-4rpj-3x2w.json | 8 ++------ .../05/GHSA-f6j4-cwrp-j9m3/GHSA-f6j4-cwrp-j9m3.json | 4 +--- .../05/GHSA-f7fv-7rmr-mpcf/GHSA-f7fv-7rmr-mpcf.json | 12 +++--------- .../05/GHSA-f7wh-x2jr-33hx/GHSA-f7wh-x2jr-33hx.json | 4 +--- .../05/GHSA-f9gp-292p-73gh/GHSA-f9gp-292p-73gh.json | 12 +++--------- .../05/GHSA-fcp9-xcgr-hwj9/GHSA-fcp9-xcgr-hwj9.json | 8 ++------ .../05/GHSA-fcvr-5v45-3j27/GHSA-fcvr-5v45-3j27.json | 12 +++--------- .../05/GHSA-fgmw-jj4f-5935/GHSA-fgmw-jj4f-5935.json | 8 ++------ .../05/GHSA-fh97-6p2x-5xf9/GHSA-fh97-6p2x-5xf9.json | 12 +++--------- .../05/GHSA-fhmg-6ffp-g88h/GHSA-fhmg-6ffp-g88h.json | 8 ++------ .../05/GHSA-fj6c-w79g-p5j2/GHSA-fj6c-w79g-p5j2.json | 8 ++------ .../05/GHSA-fj7w-ffmj-x9r8/GHSA-fj7w-ffmj-x9r8.json | 8 ++------ .../05/GHSA-fmwc-77fh-hm65/GHSA-fmwc-77fh-hm65.json | 8 ++------ .../05/GHSA-fp4m-4h58-h9px/GHSA-fp4m-4h58-h9px.json | 8 ++------ .../05/GHSA-fp73-6h6h-9v4h/GHSA-fp73-6h6h-9v4h.json | 12 +++--------- .../05/GHSA-fr9x-v3mj-475j/GHSA-fr9x-v3mj-475j.json | 8 ++------ .../05/GHSA-frr9-jpgq-8xqf/GHSA-frr9-jpgq-8xqf.json | 8 ++------ .../05/GHSA-fv2m-h6jj-865v/GHSA-fv2m-h6jj-865v.json | 8 ++------ .../05/GHSA-fv6g-4qmw-v3mm/GHSA-fv6g-4qmw-v3mm.json | 8 ++------ .../05/GHSA-fv76-2mqf-62hg/GHSA-fv76-2mqf-62hg.json | 12 +++--------- .../05/GHSA-fw69-82m4-fgm7/GHSA-fw69-82m4-fgm7.json | 8 ++------ .../05/GHSA-fwxh-8jc9-j26p/GHSA-fwxh-8jc9-j26p.json | 4 +--- .../05/GHSA-g23p-47j7-w4hw/GHSA-g23p-47j7-w4hw.json | 12 +++--------- .../05/GHSA-g2qc-659r-mxpm/GHSA-g2qc-659r-mxpm.json | 8 ++------ .../05/GHSA-g3p6-v3g4-rgjw/GHSA-g3p6-v3g4-rgjw.json | 8 ++------ .../05/GHSA-g4p9-28wh-x3gp/GHSA-g4p9-28wh-x3gp.json | 12 +++--------- .../05/GHSA-g4vp-9w9q-qppx/GHSA-g4vp-9w9q-qppx.json | 12 +++--------- .../05/GHSA-g577-wwxq-6x73/GHSA-g577-wwxq-6x73.json | 12 +++--------- .../05/GHSA-g5jm-7h4m-pp3x/GHSA-g5jm-7h4m-pp3x.json | 8 ++------ .../05/GHSA-g5r9-wgq9-7qh8/GHSA-g5r9-wgq9-7qh8.json | 8 ++------ .../05/GHSA-g6v8-4wjh-hhw3/GHSA-g6v8-4wjh-hhw3.json | 8 ++------ .../05/GHSA-g6x6-w452-43rx/GHSA-g6x6-w452-43rx.json | 8 ++------ .../05/GHSA-g88p-pxmv-gq5w/GHSA-g88p-pxmv-gq5w.json | 8 ++------ .../05/GHSA-g8j4-g47v-j89j/GHSA-g8j4-g47v-j89j.json | 8 ++------ .../05/GHSA-g996-fh92-mcqv/GHSA-g996-fh92-mcqv.json | 8 ++------ .../05/GHSA-gc2m-m9rw-7phm/GHSA-gc2m-m9rw-7phm.json | 8 ++------ .../05/GHSA-gf9w-mffq-c45p/GHSA-gf9w-mffq-c45p.json | 12 +++--------- .../05/GHSA-gfq6-4prx-wrrm/GHSA-gfq6-4prx-wrrm.json | 12 +++--------- .../05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json | 4 +--- .../05/GHSA-gggg-8p94-c53f/GHSA-gggg-8p94-c53f.json | 8 ++------ .../05/GHSA-gj3g-3mmj-f53j/GHSA-gj3g-3mmj-f53j.json | 12 +++--------- .../05/GHSA-gj4q-m5q3-4wfq/GHSA-gj4q-m5q3-4wfq.json | 8 ++------ .../05/GHSA-gm75-mfx6-2q8j/GHSA-gm75-mfx6-2q8j.json | 12 +++--------- .../05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json | 4 +--- .../05/GHSA-grfh-h2j5-w2h2/GHSA-grfh-h2j5-w2h2.json | 8 ++------ .../05/GHSA-gv2v-72f9-437h/GHSA-gv2v-72f9-437h.json | 8 ++------ .../05/GHSA-gwr5-2w8p-gpfx/GHSA-gwr5-2w8p-gpfx.json | 12 +++--------- .../05/GHSA-gxp5-vj8w-vjmw/GHSA-gxp5-vj8w-vjmw.json | 4 +--- .../05/GHSA-h2c2-gc59-r4j2/GHSA-h2c2-gc59-r4j2.json | 4 +--- .../05/GHSA-h2jh-pqwh-qf23/GHSA-h2jh-pqwh-qf23.json | 12 +++--------- .../05/GHSA-h362-962g-jw74/GHSA-h362-962g-jw74.json | 12 +++--------- .../05/GHSA-h6wf-q4gf-3q3w/GHSA-h6wf-q4gf-3q3w.json | 8 ++------ .../05/GHSA-h99v-q69f-4grg/GHSA-h99v-q69f-4grg.json | 12 +++--------- .../05/GHSA-h9qh-wvqp-pffp/GHSA-h9qh-wvqp-pffp.json | 8 ++------ .../05/GHSA-h9wp-p7qf-4j48/GHSA-h9wp-p7qf-4j48.json | 8 ++------ .../05/GHSA-hc4m-gmh3-4vxp/GHSA-hc4m-gmh3-4vxp.json | 8 ++------ .../05/GHSA-hf35-fq38-46hh/GHSA-hf35-fq38-46hh.json | 8 ++------ .../05/GHSA-hf5h-vf88-c9cq/GHSA-hf5h-vf88-c9cq.json | 8 ++------ .../05/GHSA-hfjj-9f59-p559/GHSA-hfjj-9f59-p559.json | 12 +++--------- .../05/GHSA-hh2x-4qph-x5hf/GHSA-hh2x-4qph-x5hf.json | 8 ++------ .../05/GHSA-hh76-773h-vqh2/GHSA-hh76-773h-vqh2.json | 8 ++------ .../05/GHSA-hp4h-hxwc-hg5v/GHSA-hp4h-hxwc-hg5v.json | 8 ++------ .../05/GHSA-hpcf-9656-v2qr/GHSA-hpcf-9656-v2qr.json | 12 +++--------- .../05/GHSA-hq3w-qjwj-w8fp/GHSA-hq3w-qjwj-w8fp.json | 12 +++--------- .../05/GHSA-hq8v-m2gf-pmhf/GHSA-hq8v-m2gf-pmhf.json | 8 ++------ .../05/GHSA-hqp5-7hf2-3rq4/GHSA-hqp5-7hf2-3rq4.json | 8 ++------ .../05/GHSA-hvhw-fj22-frwp/GHSA-hvhw-fj22-frwp.json | 8 ++------ .../05/GHSA-hvmf-6hr8-vcpv/GHSA-hvmf-6hr8-vcpv.json | 8 ++------ .../05/GHSA-hw4x-hf25-fgp2/GHSA-hw4x-hf25-fgp2.json | 8 ++------ .../05/GHSA-hwrc-w5gg-f335/GHSA-hwrc-w5gg-f335.json | 8 ++------ .../05/GHSA-j329-567w-c6x2/GHSA-j329-567w-c6x2.json | 8 ++------ .../05/GHSA-j32g-6wjv-jxxr/GHSA-j32g-6wjv-jxxr.json | 12 +++--------- .../05/GHSA-j35h-hvq7-g6h8/GHSA-j35h-hvq7-g6h8.json | 8 ++------ .../05/GHSA-j3wh-59pg-frxr/GHSA-j3wh-59pg-frxr.json | 12 +++--------- .../05/GHSA-j4gj-mw2c-mqx6/GHSA-j4gj-mw2c-mqx6.json | 12 +++--------- .../05/GHSA-j4q4-qv6g-h5fv/GHSA-j4q4-qv6g-h5fv.json | 8 ++------ .../05/GHSA-j4qr-rm2m-q3vr/GHSA-j4qr-rm2m-q3vr.json | 8 ++------ .../05/GHSA-j533-79wr-cfgh/GHSA-j533-79wr-cfgh.json | 12 +++--------- .../05/GHSA-j6h4-qf23-62qw/GHSA-j6h4-qf23-62qw.json | 8 ++------ .../05/GHSA-j6mr-2j2f-gxh9/GHSA-j6mr-2j2f-gxh9.json | 8 ++------ .../05/GHSA-j6qp-fmgx-hf26/GHSA-j6qp-fmgx-hf26.json | 8 ++------ .../05/GHSA-j6wx-wmhj-cffc/GHSA-j6wx-wmhj-cffc.json | 4 +--- .../05/GHSA-j863-f9rp-wc8m/GHSA-j863-f9rp-wc8m.json | 8 ++------ .../05/GHSA-j9f8-x89j-pw9j/GHSA-j9f8-x89j-pw9j.json | 8 ++------ .../05/GHSA-j9ww-5pqv-frw4/GHSA-j9ww-5pqv-frw4.json | 8 ++------ .../05/GHSA-jc9g-5ggm-9q3r/GHSA-jc9g-5ggm-9q3r.json | 8 ++------ .../05/GHSA-jc9j-c739-vr4w/GHSA-jc9j-c739-vr4w.json | 12 +++--------- .../05/GHSA-jcj3-vgfw-m9gq/GHSA-jcj3-vgfw-m9gq.json | 8 ++------ .../05/GHSA-jgv9-qp9j-c2cr/GHSA-jgv9-qp9j-c2cr.json | 12 +++--------- .../05/GHSA-jj42-mvx7-fq6m/GHSA-jj42-mvx7-fq6m.json | 8 ++------ .../05/GHSA-jjm3-8pvp-p9w4/GHSA-jjm3-8pvp-p9w4.json | 8 ++------ .../05/GHSA-jp8c-xxwg-85wj/GHSA-jp8c-xxwg-85wj.json | 8 ++------ .../05/GHSA-jp8r-43r2-mgmg/GHSA-jp8r-43r2-mgmg.json | 8 ++------ .../05/GHSA-jq5g-93fw-pqwp/GHSA-jq5g-93fw-pqwp.json | 8 ++------ .../05/GHSA-jq75-2m55-f6cv/GHSA-jq75-2m55-f6cv.json | 8 ++------ .../05/GHSA-jq7h-9pm6-x65q/GHSA-jq7h-9pm6-x65q.json | 12 +++--------- .../05/GHSA-jq84-chq4-ww9x/GHSA-jq84-chq4-ww9x.json | 8 ++------ .../05/GHSA-jqgm-6w4j-7734/GHSA-jqgm-6w4j-7734.json | 8 ++------ .../05/GHSA-m267-v543-w956/GHSA-m267-v543-w956.json | 12 +++--------- .../05/GHSA-m3g3-2r98-q7m9/GHSA-m3g3-2r98-q7m9.json | 8 ++------ .../05/GHSA-m3p7-jqjp-g7pp/GHSA-m3p7-jqjp-g7pp.json | 8 ++------ .../05/GHSA-m3rg-cpqq-v3gm/GHSA-m3rg-cpqq-v3gm.json | 8 ++------ .../05/GHSA-m4g6-59fc-77gp/GHSA-m4g6-59fc-77gp.json | 8 ++------ .../05/GHSA-m4j7-w5vj-fwff/GHSA-m4j7-w5vj-fwff.json | 12 +++--------- .../05/GHSA-m57q-6hfr-75q7/GHSA-m57q-6hfr-75q7.json | 8 ++------ .../05/GHSA-m587-5g57-rrrf/GHSA-m587-5g57-rrrf.json | 12 +++--------- .../05/GHSA-m5f4-ppqh-p8pq/GHSA-m5f4-ppqh-p8pq.json | 12 +++--------- .../05/GHSA-m5q8-rhfq-gjv4/GHSA-m5q8-rhfq-gjv4.json | 8 ++------ .../05/GHSA-m68p-v7vm-cp2m/GHSA-m68p-v7vm-cp2m.json | 12 +++--------- .../05/GHSA-m69v-4j9p-4g78/GHSA-m69v-4j9p-4g78.json | 8 ++------ .../05/GHSA-m6wm-vrh8-3v8h/GHSA-m6wm-vrh8-3v8h.json | 8 ++------ .../05/GHSA-m7c3-gvjv-4h47/GHSA-m7c3-gvjv-4h47.json | 12 +++--------- .../05/GHSA-m9x4-cr95-4r8p/GHSA-m9x4-cr95-4r8p.json | 12 +++--------- .../05/GHSA-m9x6-7vfc-3xx6/GHSA-m9x6-7vfc-3xx6.json | 8 ++------ .../05/GHSA-mcgw-mh98-rxj2/GHSA-mcgw-mh98-rxj2.json | 8 ++------ .../05/GHSA-mfmx-3jxx-p7cq/GHSA-mfmx-3jxx-p7cq.json | 8 ++------ .../05/GHSA-mfxv-c9xh-c4qp/GHSA-mfxv-c9xh-c4qp.json | 4 +--- .../05/GHSA-mg93-8qx5-rwmv/GHSA-mg93-8qx5-rwmv.json | 8 ++------ .../05/GHSA-mjxv-j6j2-hpmv/GHSA-mjxv-j6j2-hpmv.json | 12 +++--------- .../05/GHSA-mm3r-85wp-99j8/GHSA-mm3r-85wp-99j8.json | 4 +--- .../05/GHSA-mmqq-hhjg-3252/GHSA-mmqq-hhjg-3252.json | 8 ++------ .../05/GHSA-mphw-3jw4-55gq/GHSA-mphw-3jw4-55gq.json | 12 +++--------- .../05/GHSA-mpjr-rv63-f738/GHSA-mpjr-rv63-f738.json | 8 ++------ .../05/GHSA-mppx-c427-qv84/GHSA-mppx-c427-qv84.json | 8 ++------ .../05/GHSA-mvhx-xp5x-9v28/GHSA-mvhx-xp5x-9v28.json | 8 ++------ .../05/GHSA-mvxf-hjhv-qqhv/GHSA-mvxf-hjhv-qqhv.json | 8 ++------ .../05/GHSA-mw96-29xv-5ppf/GHSA-mw96-29xv-5ppf.json | 8 ++------ .../05/GHSA-mxjg-fcq7-wmwq/GHSA-mxjg-fcq7-wmwq.json | 8 ++------ .../05/GHSA-p29x-jjv6-hfrh/GHSA-p29x-jjv6-hfrh.json | 8 ++------ .../05/GHSA-p2fr-jrwq-q4c4/GHSA-p2fr-jrwq-q4c4.json | 8 ++------ .../05/GHSA-p2jj-p9xc-7g6j/GHSA-p2jj-p9xc-7g6j.json | 4 +--- .../05/GHSA-p46q-pmw2-55mw/GHSA-p46q-pmw2-55mw.json | 8 ++------ .../05/GHSA-p548-q955-gcwg/GHSA-p548-q955-gcwg.json | 8 ++------ .../05/GHSA-p5fj-j53f-3gwv/GHSA-p5fj-j53f-3gwv.json | 8 ++------ .../05/GHSA-p99q-5p87-w6pr/GHSA-p99q-5p87-w6pr.json | 12 +++--------- .../05/GHSA-pcw5-cxvf-xpqx/GHSA-pcw5-cxvf-xpqx.json | 8 ++------ .../05/GHSA-pf8f-326c-hmr7/GHSA-pf8f-326c-hmr7.json | 8 ++------ .../05/GHSA-pfqq-qpv2-v6q9/GHSA-pfqq-qpv2-v6q9.json | 8 ++------ .../05/GHSA-pg4r-46vf-5wr2/GHSA-pg4r-46vf-5wr2.json | 8 ++------ .../05/GHSA-pgr8-g488-4xf7/GHSA-pgr8-g488-4xf7.json | 4 +--- .../05/GHSA-pgvx-9xhm-x4w5/GHSA-pgvx-9xhm-x4w5.json | 8 ++------ .../05/GHSA-ph72-5jfg-vmr3/GHSA-ph72-5jfg-vmr3.json | 8 ++------ .../05/GHSA-pj4x-5742-w9p8/GHSA-pj4x-5742-w9p8.json | 12 +++--------- .../05/GHSA-pj82-fpwx-65j3/GHSA-pj82-fpwx-65j3.json | 8 ++------ .../05/GHSA-pmgg-w4jv-72xw/GHSA-pmgg-w4jv-72xw.json | 8 ++------ .../05/GHSA-pr23-m3vh-wq7x/GHSA-pr23-m3vh-wq7x.json | 8 ++------ .../05/GHSA-pr3m-646v-qvfc/GHSA-pr3m-646v-qvfc.json | 12 +++--------- .../05/GHSA-prcv-xr7q-82jv/GHSA-prcv-xr7q-82jv.json | 8 ++------ .../05/GHSA-prxp-8xr8-7qv2/GHSA-prxp-8xr8-7qv2.json | 12 +++--------- .../05/GHSA-pvmh-7h9v-f5xr/GHSA-pvmh-7h9v-f5xr.json | 12 +++--------- .../05/GHSA-pvrv-v6wr-f2vv/GHSA-pvrv-v6wr-f2vv.json | 4 +--- .../05/GHSA-pvvp-vj5f-7cc6/GHSA-pvvp-vj5f-7cc6.json | 12 +++--------- .../05/GHSA-pxpf-f7wc-5qvm/GHSA-pxpf-f7wc-5qvm.json | 8 ++------ .../05/GHSA-pxx3-gfm4-5cpx/GHSA-pxx3-gfm4-5cpx.json | 8 ++------ .../05/GHSA-q26p-2pjc-36qx/GHSA-q26p-2pjc-36qx.json | 8 ++------ .../05/GHSA-q2fp-fcx5-hff3/GHSA-q2fp-fcx5-hff3.json | 12 +++--------- .../05/GHSA-q3jv-68wf-2323/GHSA-q3jv-68wf-2323.json | 8 ++------ .../05/GHSA-q4fm-44gw-552r/GHSA-q4fm-44gw-552r.json | 8 ++------ .../05/GHSA-q4vm-f4m8-3m9q/GHSA-q4vm-f4m8-3m9q.json | 8 ++------ .../05/GHSA-q4x6-q4p5-f5jw/GHSA-q4x6-q4p5-f5jw.json | 8 ++------ .../05/GHSA-q52p-3m33-w676/GHSA-q52p-3m33-w676.json | 8 ++------ .../05/GHSA-q56w-5m9j-r836/GHSA-q56w-5m9j-r836.json | 4 +--- .../05/GHSA-q64c-hf5x-986j/GHSA-q64c-hf5x-986j.json | 12 +++--------- .../05/GHSA-q64r-wvx9-6g34/GHSA-q64r-wvx9-6g34.json | 8 ++------ .../05/GHSA-q792-q593-g5f3/GHSA-q792-q593-g5f3.json | 8 ++------ .../05/GHSA-q7c9-wj3v-qrj7/GHSA-q7c9-wj3v-qrj7.json | 8 ++------ .../05/GHSA-q7xv-685x-6h27/GHSA-q7xv-685x-6h27.json | 4 +--- .../05/GHSA-q85c-chj5-jqwc/GHSA-q85c-chj5-jqwc.json | 8 ++------ .../05/GHSA-q92w-3cc7-2r4g/GHSA-q92w-3cc7-2r4g.json | 12 +++--------- .../05/GHSA-qf6w-75pv-5q59/GHSA-qf6w-75pv-5q59.json | 8 ++------ .../05/GHSA-qghh-4hvq-fj66/GHSA-qghh-4hvq-fj66.json | 12 +++--------- .../05/GHSA-qhg6-w2fh-6xfg/GHSA-qhg6-w2fh-6xfg.json | 8 ++------ .../05/GHSA-qhv5-5rhr-mqc5/GHSA-qhv5-5rhr-mqc5.json | 8 ++------ .../05/GHSA-qj49-mwf8-445r/GHSA-qj49-mwf8-445r.json | 8 ++------ .../05/GHSA-qj63-c77f-88gh/GHSA-qj63-c77f-88gh.json | 4 +--- .../05/GHSA-qmjr-fgvm-qpvq/GHSA-qmjr-fgvm-qpvq.json | 8 ++------ .../05/GHSA-qmm6-9733-43x2/GHSA-qmm6-9733-43x2.json | 8 ++------ .../05/GHSA-qmw2-mxpf-x4wp/GHSA-qmw2-mxpf-x4wp.json | 8 ++------ .../05/GHSA-qp5r-g6cm-fm8x/GHSA-qp5r-g6cm-fm8x.json | 12 +++--------- .../05/GHSA-qq2h-777w-7rg7/GHSA-qq2h-777w-7rg7.json | 8 ++------ .../05/GHSA-qv4m-mw37-hvg2/GHSA-qv4m-mw37-hvg2.json | 12 +++--------- .../05/GHSA-qv88-c9vm-fw8p/GHSA-qv88-c9vm-fw8p.json | 8 ++------ .../05/GHSA-qwh8-647p-vcqr/GHSA-qwh8-647p-vcqr.json | 8 ++------ .../05/GHSA-qwm4-r696-wpp8/GHSA-qwm4-r696-wpp8.json | 8 ++------ .../05/GHSA-qwwm-9hv9-2pvh/GHSA-qwwm-9hv9-2pvh.json | 8 ++------ .../05/GHSA-qx79-r9pg-rjj7/GHSA-qx79-r9pg-rjj7.json | 12 +++--------- .../05/GHSA-qxpm-m6jm-3crx/GHSA-qxpm-m6jm-3crx.json | 8 ++------ .../05/GHSA-qxvj-qxhq-9v8w/GHSA-qxvj-qxhq-9v8w.json | 8 ++------ .../05/GHSA-r367-2c67-wh49/GHSA-r367-2c67-wh49.json | 8 ++------ .../05/GHSA-r389-f2jh-h9wp/GHSA-r389-f2jh-h9wp.json | 8 ++------ .../05/GHSA-r4x3-gx46-8jpq/GHSA-r4x3-gx46-8jpq.json | 8 ++------ .../05/GHSA-r4xr-x22c-68gg/GHSA-r4xr-x22c-68gg.json | 12 +++--------- .../05/GHSA-r549-2q8f-3qqw/GHSA-r549-2q8f-3qqw.json | 8 ++------ .../05/GHSA-r5gf-w27r-jjqq/GHSA-r5gf-w27r-jjqq.json | 8 ++------ .../05/GHSA-r64c-q5mp-r47f/GHSA-r64c-q5mp-r47f.json | 12 +++--------- .../05/GHSA-r6hj-55cr-38hq/GHSA-r6hj-55cr-38hq.json | 8 ++------ .../05/GHSA-r6ww-vw3x-xp48/GHSA-r6ww-vw3x-xp48.json | 12 +++--------- .../05/GHSA-r79x-qr5q-j845/GHSA-r79x-qr5q-j845.json | 8 ++------ .../05/GHSA-r7jg-rv4q-6j69/GHSA-r7jg-rv4q-6j69.json | 8 ++------ .../05/GHSA-r84h-43q6-4fgm/GHSA-r84h-43q6-4fgm.json | 8 ++------ .../05/GHSA-r8hf-cmf8-86j7/GHSA-r8hf-cmf8-86j7.json | 8 ++------ .../05/GHSA-r983-27x9-gfq4/GHSA-r983-27x9-gfq4.json | 8 ++------ .../05/GHSA-r9p4-2pvr-hr3h/GHSA-r9p4-2pvr-hr3h.json | 8 ++------ .../05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json | 4 +--- .../05/GHSA-rgc3-jjp2-xqh3/GHSA-rgc3-jjp2-xqh3.json | 8 ++------ .../05/GHSA-rh98-7gwj-78xf/GHSA-rh98-7gwj-78xf.json | 4 +--- .../05/GHSA-rmqp-6xmv-vxjx/GHSA-rmqp-6xmv-vxjx.json | 8 ++------ .../05/GHSA-rp39-cm7q-xq66/GHSA-rp39-cm7q-xq66.json | 8 ++------ .../05/GHSA-rpw9-pxq9-mqx6/GHSA-rpw9-pxq9-mqx6.json | 8 ++------ .../05/GHSA-rq78-g3q7-3xqv/GHSA-rq78-g3q7-3xqv.json | 12 +++--------- .../05/GHSA-rqrm-6x63-2h8x/GHSA-rqrm-6x63-2h8x.json | 8 ++------ .../05/GHSA-rr4h-jj83-5hcw/GHSA-rr4h-jj83-5hcw.json | 8 ++------ .../05/GHSA-rvcc-mqg5-gqq5/GHSA-rvcc-mqg5-gqq5.json | 8 ++------ .../05/GHSA-rvww-62fw-gjm8/GHSA-rvww-62fw-gjm8.json | 12 +++--------- .../05/GHSA-rw9x-33p6-vp3q/GHSA-rw9x-33p6-vp3q.json | 8 ++------ .../05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json | 8 ++------ .../05/GHSA-rxh4-4wmm-564x/GHSA-rxh4-4wmm-564x.json | 8 ++------ .../05/GHSA-v2mm-g69c-c43h/GHSA-v2mm-g69c-c43h.json | 8 ++------ .../05/GHSA-v2rj-r82f-7qw2/GHSA-v2rj-r82f-7qw2.json | 8 ++------ .../05/GHSA-v2xr-6qx5-hp38/GHSA-v2xr-6qx5-hp38.json | 8 ++------ .../05/GHSA-v564-86mx-r49f/GHSA-v564-86mx-r49f.json | 8 ++------ .../05/GHSA-v59f-mhqw-x2vc/GHSA-v59f-mhqw-x2vc.json | 4 +--- .../05/GHSA-v5cq-7jp3-qf4w/GHSA-v5cq-7jp3-qf4w.json | 8 ++------ .../05/GHSA-v6mq-p8pv-vq8r/GHSA-v6mq-p8pv-vq8r.json | 8 ++------ .../05/GHSA-v82w-f9vr-j64c/GHSA-v82w-f9vr-j64c.json | 8 ++------ .../05/GHSA-v89m-75xw-x3cc/GHSA-v89m-75xw-x3cc.json | 4 +--- .../05/GHSA-vcwp-h637-px5r/GHSA-vcwp-h637-px5r.json | 12 +++--------- .../05/GHSA-vf29-8mcc-9rw6/GHSA-vf29-8mcc-9rw6.json | 8 ++------ .../05/GHSA-vfrc-8p6x-x2rc/GHSA-vfrc-8p6x-x2rc.json | 12 +++--------- .../05/GHSA-vgwm-jp52-gpmr/GHSA-vgwm-jp52-gpmr.json | 12 +++--------- .../05/GHSA-vj66-fqfw-pvg4/GHSA-vj66-fqfw-pvg4.json | 8 ++------ .../05/GHSA-vj7x-rvh3-72c5/GHSA-vj7x-rvh3-72c5.json | 12 +++--------- .../05/GHSA-vj8h-wj7f-5mcf/GHSA-vj8h-wj7f-5mcf.json | 12 +++--------- .../05/GHSA-vjg8-mp98-7f39/GHSA-vjg8-mp98-7f39.json | 8 ++------ .../05/GHSA-vm8q-pgwg-rc22/GHSA-vm8q-pgwg-rc22.json | 12 +++--------- .../05/GHSA-vmg6-7v27-vwrg/GHSA-vmg6-7v27-vwrg.json | 12 +++--------- .../05/GHSA-vp33-c9pr-hxcq/GHSA-vp33-c9pr-hxcq.json | 8 ++------ .../05/GHSA-vp78-g43w-3482/GHSA-vp78-g43w-3482.json | 8 ++------ .../05/GHSA-vph7-v96r-wc7m/GHSA-vph7-v96r-wc7m.json | 8 ++------ .../05/GHSA-vphm-8x59-c77v/GHSA-vphm-8x59-c77v.json | 8 ++------ .../05/GHSA-vpr4-7gh6-67c2/GHSA-vpr4-7gh6-67c2.json | 8 ++------ .../05/GHSA-vq38-j6m4-jpjp/GHSA-vq38-j6m4-jpjp.json | 12 +++--------- .../05/GHSA-vqm6-65fg-mvcv/GHSA-vqm6-65fg-mvcv.json | 12 +++--------- .../05/GHSA-vrc3-p99x-fxh5/GHSA-vrc3-p99x-fxh5.json | 8 ++------ .../05/GHSA-vrx6-hjcm-g3jh/GHSA-vrx6-hjcm-g3jh.json | 8 ++------ .../05/GHSA-vv54-q9fx-xmv2/GHSA-vv54-q9fx-xmv2.json | 8 ++------ .../05/GHSA-vvqg-rc4c-3qfj/GHSA-vvqg-rc4c-3qfj.json | 12 +++--------- .../05/GHSA-vw2m-wgch-f8g3/GHSA-vw2m-wgch-f8g3.json | 4 +--- .../05/GHSA-vw8g-8f3r-fj8m/GHSA-vw8g-8f3r-fj8m.json | 8 ++------ .../05/GHSA-vwqh-mhgj-p4m8/GHSA-vwqh-mhgj-p4m8.json | 4 +--- .../05/GHSA-w2rh-7p2w-889c/GHSA-w2rh-7p2w-889c.json | 12 +++--------- .../05/GHSA-w3pg-w64r-37j8/GHSA-w3pg-w64r-37j8.json | 12 +++--------- .../05/GHSA-w434-cfjj-45h2/GHSA-w434-cfjj-45h2.json | 8 ++------ .../05/GHSA-w4hh-c225-9vx5/GHSA-w4hh-c225-9vx5.json | 8 ++------ .../05/GHSA-w532-9px6-hv54/GHSA-w532-9px6-hv54.json | 12 +++--------- .../05/GHSA-w5rm-2969-2w83/GHSA-w5rm-2969-2w83.json | 8 ++------ .../05/GHSA-w5v3-f8xv-j94c/GHSA-w5v3-f8xv-j94c.json | 8 ++------ .../05/GHSA-w6gf-8h7h-2hmw/GHSA-w6gf-8h7h-2hmw.json | 8 ++------ .../05/GHSA-w757-mvqp-v98h/GHSA-w757-mvqp-v98h.json | 12 +++--------- .../05/GHSA-w8xw-mv63-4c7q/GHSA-w8xw-mv63-4c7q.json | 8 ++------ .../05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json | 8 ++------ .../05/GHSA-wcgf-h42q-fhqj/GHSA-wcgf-h42q-fhqj.json | 8 ++------ .../05/GHSA-wf53-3973-wc7h/GHSA-wf53-3973-wc7h.json | 8 ++------ .../05/GHSA-wg2f-5gm7-v7mx/GHSA-wg2f-5gm7-v7mx.json | 8 ++------ .../05/GHSA-wg4x-xc3p-qhqj/GHSA-wg4x-xc3p-qhqj.json | 8 ++------ .../05/GHSA-wgqh-fmw6-rm93/GHSA-wgqh-fmw6-rm93.json | 8 ++------ .../05/GHSA-wh74-7r5x-2v2m/GHSA-wh74-7r5x-2v2m.json | 8 ++------ .../05/GHSA-whx9-88h6-g65q/GHSA-whx9-88h6-g65q.json | 8 ++------ .../05/GHSA-wj9q-fjc4-6whp/GHSA-wj9q-fjc4-6whp.json | 12 +++--------- .../05/GHSA-wq8g-hgwc-7q56/GHSA-wq8g-hgwc-7q56.json | 8 ++------ .../05/GHSA-wr5r-74rp-qh45/GHSA-wr5r-74rp-qh45.json | 4 +--- .../05/GHSA-wr76-gg23-hq72/GHSA-wr76-gg23-hq72.json | 12 +++--------- .../05/GHSA-wr9p-hcgm-x262/GHSA-wr9p-hcgm-x262.json | 8 ++------ .../05/GHSA-wrwm-4qrx-hh9h/GHSA-wrwm-4qrx-hh9h.json | 8 ++------ .../05/GHSA-wv5f-6cvh-7g9m/GHSA-wv5f-6cvh-7g9m.json | 8 ++------ .../05/GHSA-wvh2-7875-xq75/GHSA-wvh2-7875-xq75.json | 12 +++--------- .../05/GHSA-wwp4-jfvw-r542/GHSA-wwp4-jfvw-r542.json | 8 ++------ .../05/GHSA-wwq8-rpxh-fwjj/GHSA-wwq8-rpxh-fwjj.json | 8 ++------ .../05/GHSA-wxhf-r74j-fmh8/GHSA-wxhf-r74j-fmh8.json | 8 ++------ .../05/GHSA-wxvm-56x8-m8c9/GHSA-wxvm-56x8-m8c9.json | 8 ++------ .../05/GHSA-x325-6h4w-24jp/GHSA-x325-6h4w-24jp.json | 8 ++------ .../05/GHSA-x352-m5w7-xq9q/GHSA-x352-m5w7-xq9q.json | 4 +--- .../05/GHSA-x38j-xvp2-94qj/GHSA-x38j-xvp2-94qj.json | 8 ++------ .../05/GHSA-x3c4-8cgr-5j45/GHSA-x3c4-8cgr-5j45.json | 8 ++------ .../05/GHSA-x42x-4h68-vrr4/GHSA-x42x-4h68-vrr4.json | 8 ++------ .../05/GHSA-x4r6-h7xv-w7r4/GHSA-x4r6-h7xv-w7r4.json | 8 ++------ .../05/GHSA-x4rr-pfq7-hjf5/GHSA-x4rr-pfq7-hjf5.json | 8 ++------ .../05/GHSA-x4vw-32x4-hm2p/GHSA-x4vw-32x4-hm2p.json | 4 +--- .../05/GHSA-x57m-fjm7-96hr/GHSA-x57m-fjm7-96hr.json | 8 ++------ .../05/GHSA-x6gp-hg9r-wh46/GHSA-x6gp-hg9r-wh46.json | 4 +--- .../05/GHSA-x732-h974-48gx/GHSA-x732-h974-48gx.json | 4 +--- .../05/GHSA-x76g-hhwp-675p/GHSA-x76g-hhwp-675p.json | 8 ++------ .../05/GHSA-x7vj-6hfr-gqfh/GHSA-x7vj-6hfr-gqfh.json | 12 +++--------- .../05/GHSA-x96g-vp28-xf6f/GHSA-x96g-vp28-xf6f.json | 8 ++------ .../05/GHSA-x99w-r7p7-9cww/GHSA-x99w-r7p7-9cww.json | 8 ++------ .../05/GHSA-x9r7-5c46-9x5p/GHSA-x9r7-5c46-9x5p.json | 4 +--- .../05/GHSA-xf2c-ccw7-485g/GHSA-xf2c-ccw7-485g.json | 8 ++------ .../05/GHSA-xf3g-8p9v-323q/GHSA-xf3g-8p9v-323q.json | 8 ++------ .../05/GHSA-xf88-gp54-xgc2/GHSA-xf88-gp54-xgc2.json | 8 ++------ .../05/GHSA-xgf9-6xh9-8mvh/GHSA-xgf9-6xh9-8mvh.json | 8 ++------ .../05/GHSA-xgrc-85pp-86cg/GHSA-xgrc-85pp-86cg.json | 12 +++--------- .../05/GHSA-xhhx-8xfw-c2vh/GHSA-xhhx-8xfw-c2vh.json | 8 ++------ .../05/GHSA-xhpm-r2g2-c7vg/GHSA-xhpm-r2g2-c7vg.json | 12 +++--------- .../05/GHSA-xhr7-hgf3-h7pr/GHSA-xhr7-hgf3-h7pr.json | 4 +--- .../05/GHSA-xjpc-m35x-gfvr/GHSA-xjpc-m35x-gfvr.json | 8 ++------ .../05/GHSA-xjwr-69c4-g9rc/GHSA-xjwr-69c4-g9rc.json | 4 +--- .../05/GHSA-xm9f-jp6r-h9h7/GHSA-xm9f-jp6r-h9h7.json | 8 ++------ .../05/GHSA-xrcj-j2px-vg49/GHSA-xrcj-j2px-vg49.json | 12 +++--------- .../05/GHSA-xrqq-rjw2-jp5x/GHSA-xrqq-rjw2-jp5x.json | 8 ++------ .../05/GHSA-xw2f-57pj-jjw5/GHSA-xw2f-57pj-jjw5.json | 8 ++------ .../05/GHSA-xx29-p5f4-mwr8/GHSA-xx29-p5f4-mwr8.json | 4 +--- .../05/GHSA-xxv2-p56v-rf8g/GHSA-xxv2-p56v-rf8g.json | 12 +++--------- .../08/GHSA-v9x5-7566-775w/GHSA-v9x5-7566-775w.json | 8 ++------ .../09/GHSA-4vrg-gm73-c852/GHSA-4vrg-gm73-c852.json | 4 +--- .../11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json | 4 +--- .../11/GHSA-mrh2-5fx2-7rv8/GHSA-mrh2-5fx2-7rv8.json | 8 ++------ .../12/GHSA-4wvf-2vqw-mj6r/GHSA-4wvf-2vqw-mj6r.json | 4 +--- .../12/GHSA-mqqf-3x7j-j33m/GHSA-mqqf-3x7j-j33m.json | 4 +--- .../02/GHSA-c6qh-28m2-rfvf/GHSA-c6qh-28m2-rfvf.json | 4 +--- .../02/GHSA-gr7g-5rvj-cf96/GHSA-gr7g-5rvj-cf96.json | 4 +--- .../03/GHSA-g658-w8fr-782c/GHSA-g658-w8fr-782c.json | 4 +--- .../03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json | 4 +--- .../03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json | 8 ++------ .../03/GHSA-rh9w-mh4f-p3x9/GHSA-rh9w-mh4f-p3x9.json | 4 +--- .../04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json | 8 ++------ .../04/GHSA-3wfh-qwcv-pvx7/GHSA-3wfh-qwcv-pvx7.json | 4 +--- .../04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json | 4 +--- .../04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json | 4 +--- .../04/GHSA-5f37-m2hf-qphr/GHSA-5f37-m2hf-qphr.json | 4 +--- .../04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json | 4 +--- .../04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json | 4 +--- .../04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json | 4 +--- .../04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json | 4 +--- .../04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json | 4 +--- .../04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json | 4 +--- .../04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json | 4 +--- .../04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json | 4 +--- .../04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json | 4 +--- .../04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json | 4 +--- .../04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json | 4 +--- .../04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json | 4 +--- .../04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json | 4 +--- .../04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json | 4 +--- .../04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json | 4 +--- .../04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json | 4 +--- .../04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json | 4 +--- .../04/GHSA-m928-3f5w-85qx/GHSA-m928-3f5w-85qx.json | 4 +--- .../04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json | 4 +--- .../04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json | 4 +--- .../04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json | 4 +--- .../04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json | 4 +--- .../04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json | 4 +--- .../04/GHSA-r6p9-mgqc-wrwp/GHSA-r6p9-mgqc-wrwp.json | 4 +--- .../04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json | 4 +--- .../04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json | 8 ++------ .../04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json | 4 +--- .../04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json | 4 +--- .../04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json | 4 +--- .../04/GHSA-xq4j-j5qp-3mfq/GHSA-xq4j-j5qp-3mfq.json | 8 ++------ .../05/GHSA-9942-rg4x-mcpv/GHSA-9942-rg4x-mcpv.json | 4 +--- .../05/GHSA-ffmm-jx9r-2g49/GHSA-ffmm-jx9r-2g49.json | 4 +--- .../09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json | 4 +--- .../11/GHSA-4rvq-6825-fp99/GHSA-4rvq-6825-fp99.json | 8 ++------ .../01/GHSA-38xm-rj5r-36vx/GHSA-38xm-rj5r-36vx.json | 4 +--- .../01/GHSA-7qmq-34hq-j5mx/GHSA-7qmq-34hq-j5mx.json | 4 +--- .../01/GHSA-9mx7-g5mq-8w76/GHSA-9mx7-g5mq-8w76.json | 4 +--- .../01/GHSA-f6q2-w2qh-v5fp/GHSA-f6q2-w2qh-v5fp.json | 4 +--- .../01/GHSA-qphp-945f-h9m7/GHSA-qphp-945f-h9m7.json | 4 +--- .../01/GHSA-r57r-jrhh-4x69/GHSA-r57r-jrhh-4x69.json | 4 +--- .../01/GHSA-wfg2-9rj3-4vf4/GHSA-wfg2-9rj3-4vf4.json | 4 +--- .../01/GHSA-xqqg-x653-vrx5/GHSA-xqqg-x653-vrx5.json | 4 +--- .../04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json | 12 +++--------- .../04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json | 4 +--- .../04/GHSA-8v52-4x8q-99vg/GHSA-8v52-4x8q-99vg.json | 4 +--- .../04/GHSA-95fq-qfw9-w29v/GHSA-95fq-qfw9-w29v.json | 12 +++--------- .../04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json | 12 +++--------- .../04/GHSA-x5jv-pxjq-575r/GHSA-x5jv-pxjq-575r.json | 4 +--- .../07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json | 4 +--- .../07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json | 4 +--- .../07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json | 4 +--- .../07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json | 8 ++------ .../07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json | 8 ++------ .../07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json | 4 +--- .../07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json | 4 +--- .../07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json | 4 +--- .../07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json | 4 +--- .../07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json | 4 +--- .../07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json | 4 +--- .../07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json | 4 +--- .../07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json | 4 +--- .../08/GHSA-5qxq-95fv-whxm/GHSA-5qxq-95fv-whxm.json | 4 +--- .../08/GHSA-5wfc-h7w4-43mx/GHSA-5wfc-h7w4-43mx.json | 4 +--- .../08/GHSA-7pcw-pq39-gmc3/GHSA-7pcw-pq39-gmc3.json | 4 +--- .../08/GHSA-8p8r-qjjp-c996/GHSA-8p8r-qjjp-c996.json | 4 +--- .../08/GHSA-8v9c-gh64-hq64/GHSA-8v9c-gh64-hq64.json | 4 +--- .../08/GHSA-9347-hgff-8mjv/GHSA-9347-hgff-8mjv.json | 4 +--- .../08/GHSA-cfrq-8q2f-rp46/GHSA-cfrq-8q2f-rp46.json | 4 +--- .../08/GHSA-f3wr-j648-3c97/GHSA-f3wr-j648-3c97.json | 4 +--- .../08/GHSA-pmwj-r76w-m8f7/GHSA-pmwj-r76w-m8f7.json | 4 +--- .../08/GHSA-q4pc-gw9h-vxg4/GHSA-q4pc-gw9h-vxg4.json | 4 +--- .../08/GHSA-qvhh-qrj8-5g7c/GHSA-qvhh-qrj8-5g7c.json | 4 +--- .../08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json | 4 +--- .../08/GHSA-rc9p-g2q3-x488/GHSA-rc9p-g2q3-x488.json | 4 +--- .../08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json | 4 +--- .../08/GHSA-w58g-789j-fj58/GHSA-w58g-789j-fj58.json | 12 +++--------- .../08/GHSA-xxr7-33fp-84c2/GHSA-xxr7-33fp-84c2.json | 4 +--- 932 files changed, 1847 insertions(+), 5541 deletions(-) diff --git a/advisories/github-reviewed/2021/12/GHSA-3w6p-8f82-gw8r/GHSA-3w6p-8f82-gw8r.json b/advisories/github-reviewed/2021/12/GHSA-3w6p-8f82-gw8r/GHSA-3w6p-8f82-gw8r.json index 4b1c21a4b7d..1f9116de562 100644 --- a/advisories/github-reviewed/2021/12/GHSA-3w6p-8f82-gw8r/GHSA-3w6p-8f82-gw8r.json +++ b/advisories/github-reviewed/2021/12/GHSA-3w6p-8f82-gw8r/GHSA-3w6p-8f82-gw8r.json @@ -3,9 +3,7 @@ "id": "GHSA-3w6p-8f82-gw8r", "modified": "2021-12-17T20:34:04Z", "published": "2021-12-17T20:42:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "Using JMSAppender in log4j configuration may lead to deserialization of untrusted data", "details": "### Impact\n\nClickHouse JDBC Bridge uses [slf4j-log4j12 1.7.32](https://repo1.maven.org/maven2/org/slf4j/slf4j-log4j12/1.7.32/), which depends on [log4j 1.2.17](https://repo1.maven.org/maven2/log4j/log4j/1.2.17/). It allows a remote attacker to execute code on the server, if you changed default log4j configuration by adding JMSAppender and an insecure JMS broker.\n\n### Patches\n\nThe patch version `2.0.7` removed log4j dependency by replacing `slf4j-log4j12` to `slf4j-jdk14`. Logging configuration is also changed from `log4j.properties` to `logging.properties`.\n\n### Workarounds\n\n1. Do NOT change log4j configuration to use JMSAppender along with insecure JMS broker\n2. Alternatively, you can issue below command to remove `JMSAppender.class`:\n\n```(bash)\n# install zip command if you don't have\napt-get update && apt-get install -y zip\n# remove the class\nzip -d clickhouse-jdbc-bridge*.jar ru/yandex/clickhouse/jdbcbridge/internal/log4j/net/JMSAppender.class\n```\n\n### References\n\nPlease refer to [CVE-2021-4104](https://access.redhat.com/security/cve/CVE-2021-4104) to read more.\n\n### For more information\n\nIf you have any questions or comments about this advisory, please feel free to open an issue in the repository.\n", "severity": [ diff --git a/advisories/github-reviewed/2021/12/GHSA-4jhc-wjr3-pwh2/GHSA-4jhc-wjr3-pwh2.json b/advisories/github-reviewed/2021/12/GHSA-4jhc-wjr3-pwh2/GHSA-4jhc-wjr3-pwh2.json index 13096c9f592..acfbc6a8469 100644 --- a/advisories/github-reviewed/2021/12/GHSA-4jhc-wjr3-pwh2/GHSA-4jhc-wjr3-pwh2.json +++ b/advisories/github-reviewed/2021/12/GHSA-4jhc-wjr3-pwh2/GHSA-4jhc-wjr3-pwh2.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-12-17T18:48:40Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-7fr2-94h7-ccg2/GHSA-7fr2-94h7-ccg2.json b/advisories/github-reviewed/2021/12/GHSA-7fr2-94h7-ccg2/GHSA-7fr2-94h7-ccg2.json index 15863735ccd..5af60c9c5bb 100644 --- a/advisories/github-reviewed/2021/12/GHSA-7fr2-94h7-ccg2/GHSA-7fr2-94h7-ccg2.json +++ b/advisories/github-reviewed/2021/12/GHSA-7fr2-94h7-ccg2/GHSA-7fr2-94h7-ccg2.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-12-17T18:40:51Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-gjrj-9rj4-pgwx/GHSA-gjrj-9rj4-pgwx.json b/advisories/github-reviewed/2021/12/GHSA-gjrj-9rj4-pgwx/GHSA-gjrj-9rj4-pgwx.json index fba8e71a401..ac656fb760f 100644 --- a/advisories/github-reviewed/2021/12/GHSA-gjrj-9rj4-pgwx/GHSA-gjrj-9rj4-pgwx.json +++ b/advisories/github-reviewed/2021/12/GHSA-gjrj-9rj4-pgwx/GHSA-gjrj-9rj4-pgwx.json @@ -3,14 +3,10 @@ "id": "GHSA-gjrj-9rj4-pgwx", "modified": "2021-12-17T19:33:49Z", "published": "2021-12-15T22:51:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "DoS Vulnerability from Upstream Actix Web Issues", "details": "### Impact\nThis vulnerability affects all users of the `perseus deploy` functionality who have not exported their sites to static files. If you are using the inbuilt Perseus server in production, there is a memory leak in Actix Web stemming from [this upstream issue](https://github.com/actix/actix-web/issues/1780) which can allow even a single user to cause the process to exhaust its memory on low-memory servers by continuously reloading the page. Note that this issue does not affect all Actix Web applications, but rather results from certain usage patterns which appear to be present in Perseus' server mechanics.\n\n### Patches\nThis vulnerability is addressed in all versions after Perseus `v0.3.0-beta.21`, which temporarily discontinues the use of `perseus-actix-web` (until the upstream bug is fixed) and switches to `perseus-warp` instead, which utilizes [Warp](https://github.com/seanmonstar/warp).\n\nAdditionally, as of Perseus `v0.3.0-beta.22`, the Actix Web integration has been upgraded to use the latest unstable beta version of Actix Web, which appears to partially resolve this issue (the severity of the memory leak is reduced). However, due to the instability of this version, the default integration will remain Warp for now, and a warning will appear if you attempt to use the Actix Web integration.\n\n
\nUsing the Actix Web integration\n\nIf the instability of the latest beta version of Actix Web is not a concern for you, you can use this integration by adding `-i actix-web` to `perseus serve` and the like. This will print a warning about instability, and will then operate with the beta version. Please report any failures in functionality that are not security-related to the Perseus team by [opening an issue on the repository](https://github.com/arctic-hen7/perseus/issues/new/choose).\n\nNote however that switching to the Warp integration requires no code changes whatsoever unless you've ejected, so there are very few disadvantages to this change.\n\n
\n\n### Workarounds\nDue to significant infrastructural changes within other Perseus packages that were needed to support Warp, this integration is not backward-compatible with any previous version of Perseus, meaning there are no easily feasible workarounds. If you're only in development though, this vulnerability is irrelevant until you push to production.\n\n### CVE Status\n\nDue to GitHub's requirements, a CVE can't be issued for this security advisory because the issue is technically one with Actix Web (though it's only in combination with certain mechanics in the Perseus server that this problem arises).\n\n### References\nSee [this upstream issue](https://github.com/actix/actix-web/issues/1780) in Actix Web.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue on this repository\n* Email me at [arctic_hen7@pm.me](mailto:arctic_hen7@pm.me)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -50,9 +46,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-12-15T21:42:48Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-hwvm-vfw8-93mw/GHSA-hwvm-vfw8-93mw.json b/advisories/github-reviewed/2021/12/GHSA-hwvm-vfw8-93mw/GHSA-hwvm-vfw8-93mw.json index dfd11284cf3..938eec32ae6 100644 --- a/advisories/github-reviewed/2021/12/GHSA-hwvm-vfw8-93mw/GHSA-hwvm-vfw8-93mw.json +++ b/advisories/github-reviewed/2021/12/GHSA-hwvm-vfw8-93mw/GHSA-hwvm-vfw8-93mw.json @@ -3,9 +3,7 @@ "id": "GHSA-hwvm-vfw8-93mw", "modified": "2021-12-16T18:40:26Z", "published": "2021-12-16T18:53:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Vulnerable dependency in XTDB connector", "details": "### Impact\n\nThe impacted portion of the XTDB connector is its connectivity to S3 as a backing store: this is the only portion of the connector that uses this vulnerable `httpclient` dependency. Per the description, the vulnerability regards URIs that may be misinterpreted, which given the area of impact within the connector we understand to be any URI used to configure connectivity to S3. Note therefore that if you do not use or configure S3 as a backing store in your use of the connector, you should not be exposed to any vulnerability from this component.\n\n### Patches\n\nThe problem has been addressed in version 4.5.13 of the httpclient library, which is included as a replacement dependency version for the build of the XTDB connector from release 3.5 onwards. Therefore, using release 3.5 (or newer) of the connector will include the fixes to address this CVE.\n\n### Workarounds\n\nWe have not investigated specific workarounds, but per the description of the issue it seems likely that ensuring the proper URIs are used for any S3 connectivity used by the connector (and ensuring there are appropriate controls around modifying such URIs in the connector's configuration) would be the first point of investigation.\n\n### References\n\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-13956", "severity": [ @@ -54,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-12-16T18:40:26Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-j5qg-w9jg-3wg3/GHSA-j5qg-w9jg-3wg3.json b/advisories/github-reviewed/2021/12/GHSA-j5qg-w9jg-3wg3/GHSA-j5qg-w9jg-3wg3.json index 2f2be8311c5..5f45bd5b619 100644 --- a/advisories/github-reviewed/2021/12/GHSA-j5qg-w9jg-3wg3/GHSA-j5qg-w9jg-3wg3.json +++ b/advisories/github-reviewed/2021/12/GHSA-j5qg-w9jg-3wg3/GHSA-j5qg-w9jg-3wg3.json @@ -3,9 +3,7 @@ "id": "GHSA-j5qg-w9jg-3wg3", "modified": "2021-12-16T15:47:47Z", "published": "2021-12-16T18:53:57Z", - "aliases": [ - - ], + "aliases": [], "summary": "Inability to de-op players if listed in ops.txt with non-lowercase letters", "details": "### Impact\nOriginally reported in iTXTech/Genisys#1188\n\n```txt\nPotterHarry98\npotterharry98\n```\n\n`deop PotterHarry98`\n\nwill remove `potterharry98` from the ops.txt but not `PotterHarry98`.\n\nOperator permissions are checked using `Config->exists()` with `lowercase=true`, which will result in a match:\nhttps://github.com/pmmp/PocketMine-MP/blob/22bb1ce8e03dba57173debf0415390511d68e045/src/utils/Config.php#L449\n\nThis means that it's possible to make yourself impossible to de-op (using commands) by adding your name to ops.txt with uppercase letters.\n\n### Patches\n4d37b79ff7f9d9452e988387f97919a9a1c4954e\n\n### Workarounds\nThis can be easily addressed by removing the offending lines from ops.txt manually.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [pmmp/PocketMine-MP](https://github.com/pmmp/PocketMine-MP)\n* Email us at [team@pmmp.io](mailto:team@pmmp.io)\n", "severity": [ @@ -58,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-12-16T15:47:47Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-j7c3-96rf-jrrp/GHSA-j7c3-96rf-jrrp.json b/advisories/github-reviewed/2021/12/GHSA-j7c3-96rf-jrrp/GHSA-j7c3-96rf-jrrp.json index 20224f62be4..e572d628bb8 100644 --- a/advisories/github-reviewed/2021/12/GHSA-j7c3-96rf-jrrp/GHSA-j7c3-96rf-jrrp.json +++ b/advisories/github-reviewed/2021/12/GHSA-j7c3-96rf-jrrp/GHSA-j7c3-96rf-jrrp.json @@ -3,14 +3,10 @@ "id": "GHSA-j7c3-96rf-jrrp", "modified": "2021-12-16T18:57:47Z", "published": "2021-12-16T21:01:51Z", - "aliases": [ - - ], + "aliases": [], "summary": "Critical vulnerability in log4j may affect generated PEAR projects", "details": "### Impact\nUIMA PEAR projects that have been generated with the `de.averbis.textanalysis:pear-archetype ` version `2.0.0` have a maven dependency with scope `test` to` log4j 2.8.2` and might be affected by CVE-2021-44228.\n\n### Patches\n- The issue has been resolved in `de.averbis.textanalysis:pear-archetype ` version `2.0.1`. Please make sure to use `de.averbis.textanalysis:pear-archetype ` version >= `2.0.1` for generating new PEAR projects.\n\n- Existing maven PEAR projects can be patched by manually upgrading to `log4j` >= `2.16.0` in `pom.xml`.\n\n\n### References\nhttps://www.lunasec.io/docs/blog/log4j-zero-day/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/averbis/pear-archetype/issues\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -50,9 +46,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-12-16T18:57:47Z", diff --git a/advisories/github-reviewed/2021/12/GHSA-m4h3-7mc2-v295/GHSA-m4h3-7mc2-v295.json b/advisories/github-reviewed/2021/12/GHSA-m4h3-7mc2-v295/GHSA-m4h3-7mc2-v295.json index 116f8c10a52..397b2083233 100644 --- a/advisories/github-reviewed/2021/12/GHSA-m4h3-7mc2-v295/GHSA-m4h3-7mc2-v295.json +++ b/advisories/github-reviewed/2021/12/GHSA-m4h3-7mc2-v295/GHSA-m4h3-7mc2-v295.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-12-17T19:11:26Z", diff --git a/advisories/github-reviewed/2022/02/GHSA-qq97-vm5h-rrhg/GHSA-qq97-vm5h-rrhg.json b/advisories/github-reviewed/2022/02/GHSA-qq97-vm5h-rrhg/GHSA-qq97-vm5h-rrhg.json index a19581ee6e8..3f93f6d710a 100644 --- a/advisories/github-reviewed/2022/02/GHSA-qq97-vm5h-rrhg/GHSA-qq97-vm5h-rrhg.json +++ b/advisories/github-reviewed/2022/02/GHSA-qq97-vm5h-rrhg/GHSA-qq97-vm5h-rrhg.json @@ -3,9 +3,7 @@ "id": "GHSA-qq97-vm5h-rrhg", "modified": "2023-02-09T15:29:32Z", "published": "2022-02-08T18:53:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "OCI Manifest Type Confusion Issue", "details": "### Impact\n\nSystems that rely on digest equivalence for image attestations may be vulnerable to type confusion.\n\n### Patches\n\nUpgrade to at least `v2.8.0-beta.1` if you are running `v2.x` release. If you use the code from the `main` branch, update at least to the commit after [b59a6f827947f9e0e67df0cfb571046de4733586](https://github.com/distribution/distribution/commit/b59a6f827947f9e0e67df0cfb571046de4733586).\n\n### Workarounds\n\nThere is no way to work around this issue without patching.\n\n### References\n\nDue to [an oversight in the OCI Image Specification](https://github.com/opencontainers/image-spec/pull/411) that removed the embedded `mediaType` field from manifests, a maliciously crafted OCI Container Image can cause registry clients to parse the same image in two different ways without modifying the image’s digest by modifying the `Content-Type` header returned by a registry. This can invalidate a common pattern of relying on container image digests for equivalence.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [distribution](https://github.com/distribution/distribution) \n* Open an issue in [distribution-spec](https://github.com/opencontainers/distribution-spec) \n* Email us at [cncf-distribution-security@lists.cncf.io](mailto:cncf-distribution-security@lists.cncf.io)\n", "severity": [ diff --git a/advisories/github-reviewed/2022/05/GHSA-6xxq-j39w-g3f6/GHSA-6xxq-j39w-g3f6.json b/advisories/github-reviewed/2022/05/GHSA-6xxq-j39w-g3f6/GHSA-6xxq-j39w-g3f6.json index e24d0cc71ee..b763ef8060c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-6xxq-j39w-g3f6/GHSA-6xxq-j39w-g3f6.json +++ b/advisories/github-reviewed/2022/05/GHSA-6xxq-j39w-g3f6/GHSA-6xxq-j39w-g3f6.json @@ -8,9 +8,7 @@ ], "summary": "Puppet Arbitrary Command Execution", "details": "Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-836p-6p4j-35cg/GHSA-836p-6p4j-35cg.json b/advisories/github-reviewed/2022/05/GHSA-836p-6p4j-35cg/GHSA-836p-6p4j-35cg.json index 6024413c746..fa7e7634bc7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-836p-6p4j-35cg/GHSA-836p-6p4j-35cg.json +++ b/advisories/github-reviewed/2022/05/GHSA-836p-6p4j-35cg/GHSA-836p-6p4j-35cg.json @@ -165,9 +165,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-31T23:00:10Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-83c3-qx27-2rwr/GHSA-83c3-qx27-2rwr.json b/advisories/github-reviewed/2022/05/GHSA-83c3-qx27-2rwr/GHSA-83c3-qx27-2rwr.json index b210b0e6139..f5e4c166ced 100644 --- a/advisories/github-reviewed/2022/05/GHSA-83c3-qx27-2rwr/GHSA-83c3-qx27-2rwr.json +++ b/advisories/github-reviewed/2022/05/GHSA-83c3-qx27-2rwr/GHSA-83c3-qx27-2rwr.json @@ -8,9 +8,7 @@ ], "summary": "Symfony Allows URI Restrictions Bypass Via Double-Encoded String", "details": "On the Symfony 2.0.x version, there's a security issue that allows access to routes protected by a firewall even when the user is not logged in.\n\nBoth the Routing component and the Security component uses the path returned by `getPathInfo()` to match a Request. The `getPathInfo()` returns a decoded path, but the Routing component (`Symfony\\Component\\Routing\\Matcher\\UrlMatcher`) decodes the path a second time; whereas the Security component, `Symfony\\Component\\HttpFoundation\\RequestMatcher`, does not.\n\nThis difference causes Symfony 2.0 to be vulnerable to double encoding attacks.\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-966r-962g-2jq5/GHSA-966r-962g-2jq5.json b/advisories/github-reviewed/2022/05/GHSA-966r-962g-2jq5/GHSA-966r-962g-2jq5.json index 9f2561b0dab..35950c74f8e 100644 --- a/advisories/github-reviewed/2022/05/GHSA-966r-962g-2jq5/GHSA-966r-962g-2jq5.json +++ b/advisories/github-reviewed/2022/05/GHSA-966r-962g-2jq5/GHSA-966r-962g-2jq5.json @@ -8,9 +8,7 @@ ], "summary": "Mortbay Jetty CRLF Injection Vulnerability", "details": "CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-9cvr-8xq4-2m73/GHSA-9cvr-8xq4-2m73.json b/advisories/github-reviewed/2022/05/GHSA-9cvr-8xq4-2m73/GHSA-9cvr-8xq4-2m73.json index 78fe716b89a..32538ddd7a6 100644 --- a/advisories/github-reviewed/2022/05/GHSA-9cvr-8xq4-2m73/GHSA-9cvr-8xq4-2m73.json +++ b/advisories/github-reviewed/2022/05/GHSA-9cvr-8xq4-2m73/GHSA-9cvr-8xq4-2m73.json @@ -8,9 +8,7 @@ ], "summary": "Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ", "details": "Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-f866-m9mv-2xr3/GHSA-f866-m9mv-2xr3.json b/advisories/github-reviewed/2022/05/GHSA-f866-m9mv-2xr3/GHSA-f866-m9mv-2xr3.json index c376ce38e98..5919064d699 100644 --- a/advisories/github-reviewed/2022/05/GHSA-f866-m9mv-2xr3/GHSA-f866-m9mv-2xr3.json +++ b/advisories/github-reviewed/2022/05/GHSA-f866-m9mv-2xr3/GHSA-f866-m9mv-2xr3.json @@ -8,9 +8,7 @@ ], "summary": "Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data", "details": "Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json b/advisories/github-reviewed/2022/05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json index c537e527ce9..e35d2bf3624 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json +++ b/advisories/github-reviewed/2022/05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json @@ -8,9 +8,7 @@ ], "summary": "XXE in SabreDAV", "details": "SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -74,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-07T19:42:46Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json b/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json index 0509081766b..28a9a7e2dd4 100644 --- a/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json +++ b/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json @@ -8,9 +8,7 @@ ], "summary": "TYPO3 Flow Cross-site scripting (XSS) vulnerability", "details": "Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in TYPO3 Flow (formerly FLOW3) 1.1.x before 1.1.1 and 2.0.x before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-xr96-7ccp-pg5c/GHSA-xr96-7ccp-pg5c.json b/advisories/github-reviewed/2022/05/GHSA-xr96-7ccp-pg5c/GHSA-xr96-7ccp-pg5c.json index d0de7d7302b..248a4a84cb1 100644 --- a/advisories/github-reviewed/2022/05/GHSA-xr96-7ccp-pg5c/GHSA-xr96-7ccp-pg5c.json +++ b/advisories/github-reviewed/2022/05/GHSA-xr96-7ccp-pg5c/GHSA-xr96-7ccp-pg5c.json @@ -8,9 +8,7 @@ ], "summary": "DotNetNuke Vulnerable to XSS in Pass-Through Values", "details": "Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN), caused by improper validation of user-supplied input by an unspecified script. Pass through values were not getting filtered, leaving them vulnerable to XSS. A remote attacker could exploit this vulnerability using various parameters in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/09/GHSA-qv98-3369-g364/GHSA-qv98-3369-g364.json b/advisories/github-reviewed/2022/09/GHSA-qv98-3369-g364/GHSA-qv98-3369-g364.json index 6fe57311832..9e3bc44aba9 100644 --- a/advisories/github-reviewed/2022/09/GHSA-qv98-3369-g364/GHSA-qv98-3369-g364.json +++ b/advisories/github-reviewed/2022/09/GHSA-qv98-3369-g364/GHSA-qv98-3369-g364.json @@ -3,14 +3,10 @@ "id": "GHSA-qv98-3369-g364", "modified": "2022-09-15T03:20:35Z", "published": "2022-09-15T03:20:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "KubeVirt vulnerable to arbitrary file read on host", "details": "### Impact\n\nUsers with the permission to create VMIs can construct VMI specs which allow them to read arbitrary files on the host. There are three main attack vectors:\n\n1. Some path fields on the VMI spec were not properly validated and allowed passing in relative paths which would have been mounted into the virt-launcher pod. The fields are: `spec.domain.firmware.kernelBoot.container.kernelPath`, `spec.domain.firmware.kernelBoot.container.initrdPath` as well as `spec.volumes[*].containerDisk.path`.\n\nExample:\n\n```yaml\napiVersion: [kubevirt.io/v1](http://kubevirt.io/v1)\nkind: VirtualMachineInstance\nmetadata:\n name: vmi-fedora\nspec:\n domain:\n devices:\n disks:\n - disk:\n bus: virtio\n name: containerdisk\n - disk:\n bus: virtio\n name: cloudinitdisk\n - disk:\n bus: virtio\n name: containerdisk1\n rng: {}\n resources:\n requests:\n memory: 1024M\n terminationGracePeriodSeconds: 0\n volumes:\n - containerDisk:\n image: [quay.io/kubevirt/cirros-container-disk-demo:v0.52.0](http://quay.io/kubevirt/cirros-container-disk-demo:v0.52.0)\n name: containerdisk\n - containerDisk:\n image: [quay.io/kubevirt/cirros-container-disk-demo:v0.52.0](http://quay.io/kubevirt/cirros-container-disk-demo:v0.52.0)\n path: test3/../../../../../../../../etc/passwd\n name: containerdisk1\n - cloudInitNoCloud:\n userData: |\n #!/bin/sh\n echo 'just something to make cirros happy'\n name: cloudinitdisk\n```\n\n2. Instead of passing in relative links on the API, using malicious links in the containerDisk itself can have the same effect:\n\n```Dockerfile\nFROM \nRUN mkdir -p /etc/ && touch /etc/passwd\nRUN mkdir -p /disks/ && ln -s /etc/passwd /disks/disk.img\n```\n\n3. KubeVirt allows PVC hotplugging. The hotplugged PVC is under user-control and it is possible to place absolute links there. Since containerDisk and hotplug code use the same mechanism to provide the disk to the virt-launcher pod, it can be used too to do arbitrary host file reads.\n\nIn all three cases it is then possible to at lest read any host file:\n\n```\n$ sudo cat /dev/vdc\nroot:x:0:0:root:/root:/bin/bash\nbin:x:1:1:bin:/bin:/sbin/nologin\ndaemon:x:2:2:daemon:/sbin:/sbin/nologin\nadm:x:3:4:adm:/var/adm:/sbin/nologin\nlp:x:4:7:lp:/var/spool/lpd:/sbin/nologin\n[...]\n```\n\n\n### Patches\n\nKubeVirt 0.55.1 provides patches to fix the vulnerability.\n\n\n### Workarounds\n\n* Ensure that the `HotplugVolumes` feature-gate is disabled\n* ContainerDisk support can't be disabled. The only known way to mitigate this issue is create with e.g. policy controller a conditiontemplate which ensures that no containerDisk gets added and that `spec.domain.firmware.kernelBoot` is not used on VirtualMachineInstances.|\n* Ensure that SELinux is enabled. It blocks most attempts to read host files but does not provide a 100% guarantee (like vm-to-vm read may still work).\n\n### References\n\n\nDisclosure notice form the discovering party: https://github.com/google/security-research/security/advisories/GHSA-cvx8-ppmc-78hm\n\n### For more information\n\nFor interested vendors which have to provide a fix for their supported versions, the following PRs are providing the fix:\n\n * https://github.com/kubevirt/kubevirt/pull/8198\n * https://github.com/kubevirt/kubevirt/pull/8268\n \n### Credits\nOliver Brooks and James Klopchic of NCC Group\nDiane Dubois and Roman Mohr of Google\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -55,9 +51,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-09-15T03:20:35Z", diff --git a/advisories/github-reviewed/2023/03/GHSA-rqm8-q8j9-662f/GHSA-rqm8-q8j9-662f.json b/advisories/github-reviewed/2023/03/GHSA-rqm8-q8j9-662f/GHSA-rqm8-q8j9-662f.json index 8993e020e54..fece4dd0665 100644 --- a/advisories/github-reviewed/2023/03/GHSA-rqm8-q8j9-662f/GHSA-rqm8-q8j9-662f.json +++ b/advisories/github-reviewed/2023/03/GHSA-rqm8-q8j9-662f/GHSA-rqm8-q8j9-662f.json @@ -53,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-03-14T18:02:16Z", diff --git a/advisories/unreviewed/2021/11/GHSA-ppq4-g8vp-2cv6/GHSA-ppq4-g8vp-2cv6.json b/advisories/unreviewed/2021/11/GHSA-ppq4-g8vp-2cv6/GHSA-ppq4-g8vp-2cv6.json index 54264af54cc..e19c8877bbb 100644 --- a/advisories/unreviewed/2021/11/GHSA-ppq4-g8vp-2cv6/GHSA-ppq4-g8vp-2cv6.json +++ b/advisories/unreviewed/2021/11/GHSA-ppq4-g8vp-2cv6/GHSA-ppq4-g8vp-2cv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-22h8-jh78-8mgh/GHSA-22h8-jh78-8mgh.json b/advisories/unreviewed/2021/12/GHSA-22h8-jh78-8mgh/GHSA-22h8-jh78-8mgh.json index 09dcf4a2c49..1ada27d44e2 100644 --- a/advisories/unreviewed/2021/12/GHSA-22h8-jh78-8mgh/GHSA-22h8-jh78-8mgh.json +++ b/advisories/unreviewed/2021/12/GHSA-22h8-jh78-8mgh/GHSA-22h8-jh78-8mgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-267f-c3x2-429g/GHSA-267f-c3x2-429g.json b/advisories/unreviewed/2021/12/GHSA-267f-c3x2-429g/GHSA-267f-c3x2-429g.json index 3080d95985b..849bf84b35a 100644 --- a/advisories/unreviewed/2021/12/GHSA-267f-c3x2-429g/GHSA-267f-c3x2-429g.json +++ b/advisories/unreviewed/2021/12/GHSA-267f-c3x2-429g/GHSA-267f-c3x2-429g.json @@ -7,12 +7,8 @@ "CVE-2021-1038" ], "details": "In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-183411279", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2872-89wh-3frc/GHSA-2872-89wh-3frc.json b/advisories/unreviewed/2021/12/GHSA-2872-89wh-3frc/GHSA-2872-89wh-3frc.json index 3a42129dbb1..b2510f63e2a 100644 --- a/advisories/unreviewed/2021/12/GHSA-2872-89wh-3frc/GHSA-2872-89wh-3frc.json +++ b/advisories/unreviewed/2021/12/GHSA-2872-89wh-3frc/GHSA-2872-89wh-3frc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2c7g-2hgf-hxf7/GHSA-2c7g-2hgf-hxf7.json b/advisories/unreviewed/2021/12/GHSA-2c7g-2hgf-hxf7/GHSA-2c7g-2hgf-hxf7.json index a5d02734231..31cfed9362f 100644 --- a/advisories/unreviewed/2021/12/GHSA-2c7g-2hgf-hxf7/GHSA-2c7g-2hgf-hxf7.json +++ b/advisories/unreviewed/2021/12/GHSA-2c7g-2hgf-hxf7/GHSA-2c7g-2hgf-hxf7.json @@ -7,12 +7,8 @@ "CVE-2021-1012" ], "details": "In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195412179", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2cr4-c7g7-hhc2/GHSA-2cr4-c7g7-hhc2.json b/advisories/unreviewed/2021/12/GHSA-2cr4-c7g7-hhc2/GHSA-2cr4-c7g7-hhc2.json index 9e08dbefc0e..758cd42eae5 100644 --- a/advisories/unreviewed/2021/12/GHSA-2cr4-c7g7-hhc2/GHSA-2cr4-c7g7-hhc2.json +++ b/advisories/unreviewed/2021/12/GHSA-2cr4-c7g7-hhc2/GHSA-2cr4-c7g7-hhc2.json @@ -7,12 +7,8 @@ "CVE-2021-0927" ], "details": "In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-189824175", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2g88-r927-2prg/GHSA-2g88-r927-2prg.json b/advisories/unreviewed/2021/12/GHSA-2g88-r927-2prg/GHSA-2g88-r927-2prg.json index ef68d20483e..799b7a4ef1a 100644 --- a/advisories/unreviewed/2021/12/GHSA-2g88-r927-2prg/GHSA-2g88-r927-2prg.json +++ b/advisories/unreviewed/2021/12/GHSA-2g88-r927-2prg/GHSA-2g88-r927-2prg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2mm8-gjg2-whmx/GHSA-2mm8-gjg2-whmx.json b/advisories/unreviewed/2021/12/GHSA-2mm8-gjg2-whmx/GHSA-2mm8-gjg2-whmx.json index c9f41c53814..671904eb742 100644 --- a/advisories/unreviewed/2021/12/GHSA-2mm8-gjg2-whmx/GHSA-2mm8-gjg2-whmx.json +++ b/advisories/unreviewed/2021/12/GHSA-2mm8-gjg2-whmx/GHSA-2mm8-gjg2-whmx.json @@ -7,12 +7,8 @@ "CVE-2021-39312" ], "details": "The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2p93-h9hw-wqjg/GHSA-2p93-h9hw-wqjg.json b/advisories/unreviewed/2021/12/GHSA-2p93-h9hw-wqjg/GHSA-2p93-h9hw-wqjg.json index 5093c1973b7..993e246be2d 100644 --- a/advisories/unreviewed/2021/12/GHSA-2p93-h9hw-wqjg/GHSA-2p93-h9hw-wqjg.json +++ b/advisories/unreviewed/2021/12/GHSA-2p93-h9hw-wqjg/GHSA-2p93-h9hw-wqjg.json @@ -7,12 +7,8 @@ "CVE-2021-41028" ], "details": "A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2r4h-m59f-x4w8/GHSA-2r4h-m59f-x4w8.json b/advisories/unreviewed/2021/12/GHSA-2r4h-m59f-x4w8/GHSA-2r4h-m59f-x4w8.json index fb96577c25d..5b4cb1bee2d 100644 --- a/advisories/unreviewed/2021/12/GHSA-2r4h-m59f-x4w8/GHSA-2r4h-m59f-x4w8.json +++ b/advisories/unreviewed/2021/12/GHSA-2r4h-m59f-x4w8/GHSA-2r4h-m59f-x4w8.json @@ -7,12 +7,8 @@ "CVE-2021-39647" ], "details": "In mon_smc_load_sp of gs101-sc/plat/samsung/exynos/soc/exynos9845/smc_booting.S, there is a possible reinitialization of TEE due to improper locking. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198713939References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2rmc-v2mp-gxq4/GHSA-2rmc-v2mp-gxq4.json b/advisories/unreviewed/2021/12/GHSA-2rmc-v2mp-gxq4/GHSA-2rmc-v2mp-gxq4.json index 3e104114053..fbb86289a84 100644 --- a/advisories/unreviewed/2021/12/GHSA-2rmc-v2mp-gxq4/GHSA-2rmc-v2mp-gxq4.json +++ b/advisories/unreviewed/2021/12/GHSA-2rmc-v2mp-gxq4/GHSA-2rmc-v2mp-gxq4.json @@ -7,12 +7,8 @@ "CVE-2021-0970" ], "details": "In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196970023", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2w92-jpj9-jcf2/GHSA-2w92-jpj9-jcf2.json b/advisories/unreviewed/2021/12/GHSA-2w92-jpj9-jcf2/GHSA-2w92-jpj9-jcf2.json index 2546690a06a..2d9c03f7969 100644 --- a/advisories/unreviewed/2021/12/GHSA-2w92-jpj9-jcf2/GHSA-2w92-jpj9-jcf2.json +++ b/advisories/unreviewed/2021/12/GHSA-2w92-jpj9-jcf2/GHSA-2w92-jpj9-jcf2.json @@ -7,12 +7,8 @@ "CVE-2021-1043" ], "details": "In TBD of TBD, there is a possible downgrade attack due to under utilized anti-rollback protections. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194697257References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-2wp3-q67h-9ppc/GHSA-2wp3-q67h-9ppc.json b/advisories/unreviewed/2021/12/GHSA-2wp3-q67h-9ppc/GHSA-2wp3-q67h-9ppc.json index 8d55c2afc11..cbafe88817f 100644 --- a/advisories/unreviewed/2021/12/GHSA-2wp3-q67h-9ppc/GHSA-2wp3-q67h-9ppc.json +++ b/advisories/unreviewed/2021/12/GHSA-2wp3-q67h-9ppc/GHSA-2wp3-q67h-9ppc.json @@ -7,12 +7,8 @@ "CVE-2021-0987" ], "details": "In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-190619791", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-325x-phgw-f22w/GHSA-325x-phgw-f22w.json b/advisories/unreviewed/2021/12/GHSA-325x-phgw-f22w/GHSA-325x-phgw-f22w.json index 17b106ef694..980490e1de4 100644 --- a/advisories/unreviewed/2021/12/GHSA-325x-phgw-f22w/GHSA-325x-phgw-f22w.json +++ b/advisories/unreviewed/2021/12/GHSA-325x-phgw-f22w/GHSA-325x-phgw-f22w.json @@ -7,12 +7,8 @@ "CVE-2021-1013" ], "details": "In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186404356", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-327j-hp5v-9289/GHSA-327j-hp5v-9289.json b/advisories/unreviewed/2021/12/GHSA-327j-hp5v-9289/GHSA-327j-hp5v-9289.json index 02832e45615..7e15ef7140d 100644 --- a/advisories/unreviewed/2021/12/GHSA-327j-hp5v-9289/GHSA-327j-hp5v-9289.json +++ b/advisories/unreviewed/2021/12/GHSA-327j-hp5v-9289/GHSA-327j-hp5v-9289.json @@ -7,12 +7,8 @@ "CVE-2021-1009" ], "details": "In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189858128", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-32rc-rjrq-cq3g/GHSA-32rc-rjrq-cq3g.json b/advisories/unreviewed/2021/12/GHSA-32rc-rjrq-cq3g/GHSA-32rc-rjrq-cq3g.json index 7b4222a32ea..dc706581fba 100644 --- a/advisories/unreviewed/2021/12/GHSA-32rc-rjrq-cq3g/GHSA-32rc-rjrq-cq3g.json +++ b/advisories/unreviewed/2021/12/GHSA-32rc-rjrq-cq3g/GHSA-32rc-rjrq-cq3g.json @@ -7,12 +7,8 @@ "CVE-2021-44441" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14913)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-35cj-v3wc-rh8w/GHSA-35cj-v3wc-rh8w.json b/advisories/unreviewed/2021/12/GHSA-35cj-v3wc-rh8w/GHSA-35cj-v3wc-rh8w.json index a4096d758ec..3c465f1facc 100644 --- a/advisories/unreviewed/2021/12/GHSA-35cj-v3wc-rh8w/GHSA-35cj-v3wc-rh8w.json +++ b/advisories/unreviewed/2021/12/GHSA-35cj-v3wc-rh8w/GHSA-35cj-v3wc-rh8w.json @@ -7,12 +7,8 @@ "CVE-2021-0932" ], "details": "In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-3845-9fvj-j226/GHSA-3845-9fvj-j226.json b/advisories/unreviewed/2021/12/GHSA-3845-9fvj-j226/GHSA-3845-9fvj-j226.json index d455d2bdf32..070f6b1259e 100644 --- a/advisories/unreviewed/2021/12/GHSA-3845-9fvj-j226/GHSA-3845-9fvj-j226.json +++ b/advisories/unreviewed/2021/12/GHSA-3845-9fvj-j226/GHSA-3845-9fvj-j226.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-38xm-2fmf-66pq/GHSA-38xm-2fmf-66pq.json b/advisories/unreviewed/2021/12/GHSA-38xm-2fmf-66pq/GHSA-38xm-2fmf-66pq.json index 2c8c5a0b8db..8cd492109a5 100644 --- a/advisories/unreviewed/2021/12/GHSA-38xm-2fmf-66pq/GHSA-38xm-2fmf-66pq.json +++ b/advisories/unreviewed/2021/12/GHSA-38xm-2fmf-66pq/GHSA-38xm-2fmf-66pq.json @@ -7,12 +7,8 @@ "CVE-2021-0989" ], "details": "In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194105812", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-39m3-57c4-f837/GHSA-39m3-57c4-f837.json b/advisories/unreviewed/2021/12/GHSA-39m3-57c4-f837/GHSA-39m3-57c4-f837.json index 451f1db5867..c8881cd8ac1 100644 --- a/advisories/unreviewed/2021/12/GHSA-39m3-57c4-f837/GHSA-39m3-57c4-f837.json +++ b/advisories/unreviewed/2021/12/GHSA-39m3-57c4-f837/GHSA-39m3-57c4-f837.json @@ -7,12 +7,8 @@ "CVE-2021-1002" ], "details": "In WT_Interpolate of eas_wtengine.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194533433", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3jhq-49ph-54f5/GHSA-3jhq-49ph-54f5.json b/advisories/unreviewed/2021/12/GHSA-3jhq-49ph-54f5/GHSA-3jhq-49ph-54f5.json index 13f9b80840a..5883c3c0685 100644 --- a/advisories/unreviewed/2021/12/GHSA-3jhq-49ph-54f5/GHSA-3jhq-49ph-54f5.json +++ b/advisories/unreviewed/2021/12/GHSA-3jhq-49ph-54f5/GHSA-3jhq-49ph-54f5.json @@ -7,12 +7,8 @@ "CVE-2021-0991" ], "details": "In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-3mmp-fjhh-4r72/GHSA-3mmp-fjhh-4r72.json b/advisories/unreviewed/2021/12/GHSA-3mmp-fjhh-4r72/GHSA-3mmp-fjhh-4r72.json index babdb7fc6d0..93a54b19536 100644 --- a/advisories/unreviewed/2021/12/GHSA-3mmp-fjhh-4r72/GHSA-3mmp-fjhh-4r72.json +++ b/advisories/unreviewed/2021/12/GHSA-3mmp-fjhh-4r72/GHSA-3mmp-fjhh-4r72.json @@ -7,12 +7,8 @@ "CVE-2020-23545" ], "details": "IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-3qwg-vch4-4r45/GHSA-3qwg-vch4-4r45.json b/advisories/unreviewed/2021/12/GHSA-3qwg-vch4-4r45/GHSA-3qwg-vch4-4r45.json index ede7a20da70..444a2ea9b42 100644 --- a/advisories/unreviewed/2021/12/GHSA-3qwg-vch4-4r45/GHSA-3qwg-vch4-4r45.json +++ b/advisories/unreviewed/2021/12/GHSA-3qwg-vch4-4r45/GHSA-3qwg-vch4-4r45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-46p5-mc5g-f2fg/GHSA-46p5-mc5g-f2fg.json b/advisories/unreviewed/2021/12/GHSA-46p5-mc5g-f2fg/GHSA-46p5-mc5g-f2fg.json index 650bdcef7d5..6fa7233c52b 100644 --- a/advisories/unreviewed/2021/12/GHSA-46p5-mc5g-f2fg/GHSA-46p5-mc5g-f2fg.json +++ b/advisories/unreviewed/2021/12/GHSA-46p5-mc5g-f2fg/GHSA-46p5-mc5g-f2fg.json @@ -7,12 +7,8 @@ "CVE-2021-1029" ], "details": "In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193034677", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4hpv-f46m-r2m2/GHSA-4hpv-f46m-r2m2.json b/advisories/unreviewed/2021/12/GHSA-4hpv-f46m-r2m2/GHSA-4hpv-f46m-r2m2.json index 5f0ccae5deb..69befdf3afc 100644 --- a/advisories/unreviewed/2021/12/GHSA-4hpv-f46m-r2m2/GHSA-4hpv-f46m-r2m2.json +++ b/advisories/unreviewed/2021/12/GHSA-4hpv-f46m-r2m2/GHSA-4hpv-f46m-r2m2.json @@ -7,12 +7,8 @@ "CVE-2021-43892" ], "details": "Microsoft BizTalk ESB Toolkit Spoofing Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-4m6r-mwr3-57wm/GHSA-4m6r-mwr3-57wm.json b/advisories/unreviewed/2021/12/GHSA-4m6r-mwr3-57wm/GHSA-4m6r-mwr3-57wm.json index 6ffe5b06d3d..071ff7d95ae 100644 --- a/advisories/unreviewed/2021/12/GHSA-4m6r-mwr3-57wm/GHSA-4m6r-mwr3-57wm.json +++ b/advisories/unreviewed/2021/12/GHSA-4m6r-mwr3-57wm/GHSA-4m6r-mwr3-57wm.json @@ -7,12 +7,8 @@ "CVE-2021-0979" ], "details": "In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191772737", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4p5x-9rq5-6cgc/GHSA-4p5x-9rq5-6cgc.json b/advisories/unreviewed/2021/12/GHSA-4p5x-9rq5-6cgc/GHSA-4p5x-9rq5-6cgc.json index e31cb5b9a39..7fb3bf002b0 100644 --- a/advisories/unreviewed/2021/12/GHSA-4p5x-9rq5-6cgc/GHSA-4p5x-9rq5-6cgc.json +++ b/advisories/unreviewed/2021/12/GHSA-4p5x-9rq5-6cgc/GHSA-4p5x-9rq5-6cgc.json @@ -7,12 +7,8 @@ "CVE-2021-44005" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted TIFF files. This could allow an attacker to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4v59-97h7-jh77/GHSA-4v59-97h7-jh77.json b/advisories/unreviewed/2021/12/GHSA-4v59-97h7-jh77/GHSA-4v59-97h7-jh77.json index fdac3e8ee60..98b5fc65d29 100644 --- a/advisories/unreviewed/2021/12/GHSA-4v59-97h7-jh77/GHSA-4v59-97h7-jh77.json +++ b/advisories/unreviewed/2021/12/GHSA-4v59-97h7-jh77/GHSA-4v59-97h7-jh77.json @@ -7,12 +7,8 @@ "CVE-2021-0971" ], "details": "In MPEG4Source::read of MPEG4Extractor.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-188893559", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4v6g-qjgf-vxhm/GHSA-4v6g-qjgf-vxhm.json b/advisories/unreviewed/2021/12/GHSA-4v6g-qjgf-vxhm/GHSA-4v6g-qjgf-vxhm.json index 24703ec7916..86ffa6ce8b1 100644 --- a/advisories/unreviewed/2021/12/GHSA-4v6g-qjgf-vxhm/GHSA-4v6g-qjgf-vxhm.json +++ b/advisories/unreviewed/2021/12/GHSA-4v6g-qjgf-vxhm/GHSA-4v6g-qjgf-vxhm.json @@ -7,12 +7,8 @@ "CVE-2021-1040" ], "details": "In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182810085", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-4xmj-j6vr-68q9/GHSA-4xmj-j6vr-68q9.json b/advisories/unreviewed/2021/12/GHSA-4xmj-j6vr-68q9/GHSA-4xmj-j6vr-68q9.json index bc5cdcf7afb..97a1d08306d 100644 --- a/advisories/unreviewed/2021/12/GHSA-4xmj-j6vr-68q9/GHSA-4xmj-j6vr-68q9.json +++ b/advisories/unreviewed/2021/12/GHSA-4xmj-j6vr-68q9/GHSA-4xmj-j6vr-68q9.json @@ -7,12 +7,8 @@ "CVE-2021-40850" ], "details": "TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-52qv-5pm8-p78h/GHSA-52qv-5pm8-p78h.json b/advisories/unreviewed/2021/12/GHSA-52qv-5pm8-p78h/GHSA-52qv-5pm8-p78h.json index e8467cbccb2..768185c3efc 100644 --- a/advisories/unreviewed/2021/12/GHSA-52qv-5pm8-p78h/GHSA-52qv-5pm8-p78h.json +++ b/advisories/unreviewed/2021/12/GHSA-52qv-5pm8-p78h/GHSA-52qv-5pm8-p78h.json @@ -7,12 +7,8 @@ "CVE-2021-0973" ], "details": "In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-53f8-7jq7-5j37/GHSA-53f8-7jq7-5j37.json b/advisories/unreviewed/2021/12/GHSA-53f8-7jq7-5j37/GHSA-53f8-7jq7-5j37.json index 54b52fa3d56..edfdee1a784 100644 --- a/advisories/unreviewed/2021/12/GHSA-53f8-7jq7-5j37/GHSA-53f8-7jq7-5j37.json +++ b/advisories/unreviewed/2021/12/GHSA-53f8-7jq7-5j37/GHSA-53f8-7jq7-5j37.json @@ -7,12 +7,8 @@ "CVE-2021-0968" ], "details": "In osi_malloc and osi_calloc of allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-197868577", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-56fq-7jc4-6x2c/GHSA-56fq-7jc4-6x2c.json b/advisories/unreviewed/2021/12/GHSA-56fq-7jc4-6x2c/GHSA-56fq-7jc4-6x2c.json index 8bcae5e31b7..c3e3ffb9e4d 100644 --- a/advisories/unreviewed/2021/12/GHSA-56fq-7jc4-6x2c/GHSA-56fq-7jc4-6x2c.json +++ b/advisories/unreviewed/2021/12/GHSA-56fq-7jc4-6x2c/GHSA-56fq-7jc4-6x2c.json @@ -7,12 +7,8 @@ "CVE-2021-0889" ], "details": "In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-56pm-22qm-mvhr/GHSA-56pm-22qm-mvhr.json b/advisories/unreviewed/2021/12/GHSA-56pm-22qm-mvhr/GHSA-56pm-22qm-mvhr.json index 5e93e295205..a315ddb0ecf 100644 --- a/advisories/unreviewed/2021/12/GHSA-56pm-22qm-mvhr/GHSA-56pm-22qm-mvhr.json +++ b/advisories/unreviewed/2021/12/GHSA-56pm-22qm-mvhr/GHSA-56pm-22qm-mvhr.json @@ -7,12 +7,8 @@ "CVE-2021-0958" ], "details": "In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-200041882", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-58f3-gjmv-9j5x/GHSA-58f3-gjmv-9j5x.json b/advisories/unreviewed/2021/12/GHSA-58f3-gjmv-9j5x/GHSA-58f3-gjmv-9j5x.json index 4d06b5c42df..bf831f1ab8c 100644 --- a/advisories/unreviewed/2021/12/GHSA-58f3-gjmv-9j5x/GHSA-58f3-gjmv-9j5x.json +++ b/advisories/unreviewed/2021/12/GHSA-58f3-gjmv-9j5x/GHSA-58f3-gjmv-9j5x.json @@ -7,12 +7,8 @@ "CVE-2021-1026" ], "details": "In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194798757", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-595h-f5rf-8jr4/GHSA-595h-f5rf-8jr4.json b/advisories/unreviewed/2021/12/GHSA-595h-f5rf-8jr4/GHSA-595h-f5rf-8jr4.json index 50cf48deb09..ba5a187ab5f 100644 --- a/advisories/unreviewed/2021/12/GHSA-595h-f5rf-8jr4/GHSA-595h-f5rf-8jr4.json +++ b/advisories/unreviewed/2021/12/GHSA-595h-f5rf-8jr4/GHSA-595h-f5rf-8jr4.json @@ -7,12 +7,8 @@ "CVE-2021-38883" ], "details": "IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209165.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-59pc-8759-235m/GHSA-59pc-8759-235m.json b/advisories/unreviewed/2021/12/GHSA-59pc-8759-235m/GHSA-59pc-8759-235m.json index 9ab5f475b21..c2b3aebd341 100644 --- a/advisories/unreviewed/2021/12/GHSA-59pc-8759-235m/GHSA-59pc-8759-235m.json +++ b/advisories/unreviewed/2021/12/GHSA-59pc-8759-235m/GHSA-59pc-8759-235m.json @@ -7,12 +7,8 @@ "CVE-2021-0921" ], "details": "In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-195962697", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5mmw-5cmx-qrqm/GHSA-5mmw-5cmx-qrqm.json b/advisories/unreviewed/2021/12/GHSA-5mmw-5cmx-qrqm/GHSA-5mmw-5cmx-qrqm.json index aaa97f82f2e..2a1a19df03d 100644 --- a/advisories/unreviewed/2021/12/GHSA-5mmw-5cmx-qrqm/GHSA-5mmw-5cmx-qrqm.json +++ b/advisories/unreviewed/2021/12/GHSA-5mmw-5cmx-qrqm/GHSA-5mmw-5cmx-qrqm.json @@ -7,12 +7,8 @@ "CVE-2021-41557" ], "details": "Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders). The XSS payload is in the work order number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5pfp-wg82-hvp6/GHSA-5pfp-wg82-hvp6.json b/advisories/unreviewed/2021/12/GHSA-5pfp-wg82-hvp6/GHSA-5pfp-wg82-hvp6.json index ce7ddc6860b..eefcb885997 100644 --- a/advisories/unreviewed/2021/12/GHSA-5pfp-wg82-hvp6/GHSA-5pfp-wg82-hvp6.json +++ b/advisories/unreviewed/2021/12/GHSA-5pfp-wg82-hvp6/GHSA-5pfp-wg82-hvp6.json @@ -7,12 +7,8 @@ "CVE-2021-1022" ], "details": "In btif_in_hf_client_generic_evt of btif_hf_client.cc, there is a possible Bluetooth service crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-180420059", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-5x42-vcx9-5x6h/GHSA-5x42-vcx9-5x6h.json b/advisories/unreviewed/2021/12/GHSA-5x42-vcx9-5x6h/GHSA-5x42-vcx9-5x6h.json index 5e517197584..7a79db5dcfd 100644 --- a/advisories/unreviewed/2021/12/GHSA-5x42-vcx9-5x6h/GHSA-5x42-vcx9-5x6h.json +++ b/advisories/unreviewed/2021/12/GHSA-5x42-vcx9-5x6h/GHSA-5x42-vcx9-5x6h.json @@ -7,12 +7,8 @@ "CVE-2021-1032" ], "details": "In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-184745603", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-64w3-4qx7-xq7r/GHSA-64w3-4qx7-xq7r.json b/advisories/unreviewed/2021/12/GHSA-64w3-4qx7-xq7r/GHSA-64w3-4qx7-xq7r.json index 5ada93ce5e4..ba3b66a7714 100644 --- a/advisories/unreviewed/2021/12/GHSA-64w3-4qx7-xq7r/GHSA-64w3-4qx7-xq7r.json +++ b/advisories/unreviewed/2021/12/GHSA-64w3-4qx7-xq7r/GHSA-64w3-4qx7-xq7r.json @@ -7,12 +7,8 @@ "CVE-2021-0990" ], "details": "In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-185591180", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6624-25m9-qrx8/GHSA-6624-25m9-qrx8.json b/advisories/unreviewed/2021/12/GHSA-6624-25m9-qrx8/GHSA-6624-25m9-qrx8.json index f128a96d18b..4c5695382fa 100644 --- a/advisories/unreviewed/2021/12/GHSA-6624-25m9-qrx8/GHSA-6624-25m9-qrx8.json +++ b/advisories/unreviewed/2021/12/GHSA-6624-25m9-qrx8/GHSA-6624-25m9-qrx8.json @@ -7,12 +7,8 @@ "CVE-2021-38244" ], "details": "A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to /ProteinArraySignificanceTest.json.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-67gr-4jjf-gh3j/GHSA-67gr-4jjf-gh3j.json b/advisories/unreviewed/2021/12/GHSA-67gr-4jjf-gh3j/GHSA-67gr-4jjf-gh3j.json index f78578f6986..e1cd88ebbc5 100644 --- a/advisories/unreviewed/2021/12/GHSA-67gr-4jjf-gh3j/GHSA-67gr-4jjf-gh3j.json +++ b/advisories/unreviewed/2021/12/GHSA-67gr-4jjf-gh3j/GHSA-67gr-4jjf-gh3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6ch8-8fcc-pwjp/GHSA-6ch8-8fcc-pwjp.json b/advisories/unreviewed/2021/12/GHSA-6ch8-8fcc-pwjp/GHSA-6ch8-8fcc-pwjp.json index 51ba0b4bbc7..9797db1eafd 100644 --- a/advisories/unreviewed/2021/12/GHSA-6ch8-8fcc-pwjp/GHSA-6ch8-8fcc-pwjp.json +++ b/advisories/unreviewed/2021/12/GHSA-6ch8-8fcc-pwjp/GHSA-6ch8-8fcc-pwjp.json @@ -7,12 +7,8 @@ "CVE-2021-1007" ], "details": "In btu_hcif_process_event of btu_hcif.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-167759047", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6cm8-m9g3-hrr7/GHSA-6cm8-m9g3-hrr7.json b/advisories/unreviewed/2021/12/GHSA-6cm8-m9g3-hrr7/GHSA-6cm8-m9g3-hrr7.json index e2fe293a0e6..acbebf0fc89 100644 --- a/advisories/unreviewed/2021/12/GHSA-6cm8-m9g3-hrr7/GHSA-6cm8-m9g3-hrr7.json +++ b/advisories/unreviewed/2021/12/GHSA-6cm8-m9g3-hrr7/GHSA-6cm8-m9g3-hrr7.json @@ -7,12 +7,8 @@ "CVE-2021-0967" ], "details": "In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199065614", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6fcc-5qwj-946f/GHSA-6fcc-5qwj-946f.json b/advisories/unreviewed/2021/12/GHSA-6fcc-5qwj-946f/GHSA-6fcc-5qwj-946f.json index 4f0a6c0519d..efd5540f328 100644 --- a/advisories/unreviewed/2021/12/GHSA-6fcc-5qwj-946f/GHSA-6fcc-5qwj-946f.json +++ b/advisories/unreviewed/2021/12/GHSA-6fcc-5qwj-946f/GHSA-6fcc-5qwj-946f.json @@ -7,12 +7,8 @@ "CVE-2021-44442" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14995)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6fxv-wq7w-gjp3/GHSA-6fxv-wq7w-gjp3.json b/advisories/unreviewed/2021/12/GHSA-6fxv-wq7w-gjp3/GHSA-6fxv-wq7w-gjp3.json index 14581ebfb3b..1ebb3947052 100644 --- a/advisories/unreviewed/2021/12/GHSA-6fxv-wq7w-gjp3/GHSA-6fxv-wq7w-gjp3.json +++ b/advisories/unreviewed/2021/12/GHSA-6fxv-wq7w-gjp3/GHSA-6fxv-wq7w-gjp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6h59-r2r7-vpx8/GHSA-6h59-r2r7-vpx8.json b/advisories/unreviewed/2021/12/GHSA-6h59-r2r7-vpx8/GHSA-6h59-r2r7-vpx8.json index 8c3591764f9..3dd744c262f 100644 --- a/advisories/unreviewed/2021/12/GHSA-6h59-r2r7-vpx8/GHSA-6h59-r2r7-vpx8.json +++ b/advisories/unreviewed/2021/12/GHSA-6h59-r2r7-vpx8/GHSA-6h59-r2r7-vpx8.json @@ -7,12 +7,8 @@ "CVE-2021-42945" ], "details": "A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6p2p-q3jg-qgwx/GHSA-6p2p-q3jg-qgwx.json b/advisories/unreviewed/2021/12/GHSA-6p2p-q3jg-qgwx/GHSA-6p2p-q3jg-qgwx.json index c07b4ed4afe..e868283660c 100644 --- a/advisories/unreviewed/2021/12/GHSA-6p2p-q3jg-qgwx/GHSA-6p2p-q3jg-qgwx.json +++ b/advisories/unreviewed/2021/12/GHSA-6p2p-q3jg-qgwx/GHSA-6p2p-q3jg-qgwx.json @@ -7,12 +7,8 @@ "CVE-2021-44448" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14843, ZDI-CAN-15051)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6wch-4f3v-5j78/GHSA-6wch-4f3v-5j78.json b/advisories/unreviewed/2021/12/GHSA-6wch-4f3v-5j78/GHSA-6wch-4f3v-5j78.json index a94e9e1449d..2a971ada383 100644 --- a/advisories/unreviewed/2021/12/GHSA-6wch-4f3v-5j78/GHSA-6wch-4f3v-5j78.json +++ b/advisories/unreviewed/2021/12/GHSA-6wch-4f3v-5j78/GHSA-6wch-4f3v-5j78.json @@ -7,12 +7,8 @@ "CVE-2021-44440" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to memory corruption condition while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14912)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-72q8-mmpq-w97r/GHSA-72q8-mmpq-w97r.json b/advisories/unreviewed/2021/12/GHSA-72q8-mmpq-w97r/GHSA-72q8-mmpq-w97r.json index 200b518f475..7efadfe1219 100644 --- a/advisories/unreviewed/2021/12/GHSA-72q8-mmpq-w97r/GHSA-72q8-mmpq-w97r.json +++ b/advisories/unreviewed/2021/12/GHSA-72q8-mmpq-w97r/GHSA-72q8-mmpq-w97r.json @@ -7,12 +7,8 @@ "CVE-2021-0955" ], "details": "In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-192085766", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7523-wx28-g6xf/GHSA-7523-wx28-g6xf.json b/advisories/unreviewed/2021/12/GHSA-7523-wx28-g6xf/GHSA-7523-wx28-g6xf.json index 7ed64daecab..c12aa7044b8 100644 --- a/advisories/unreviewed/2021/12/GHSA-7523-wx28-g6xf/GHSA-7523-wx28-g6xf.json +++ b/advisories/unreviewed/2021/12/GHSA-7523-wx28-g6xf/GHSA-7523-wx28-g6xf.json @@ -7,12 +7,8 @@ "CVE-2021-37863" ], "details": "Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-75cm-2vvh-47g6/GHSA-75cm-2vvh-47g6.json b/advisories/unreviewed/2021/12/GHSA-75cm-2vvh-47g6/GHSA-75cm-2vvh-47g6.json index 2cc21418b23..2cbb97622d7 100644 --- a/advisories/unreviewed/2021/12/GHSA-75cm-2vvh-47g6/GHSA-75cm-2vvh-47g6.json +++ b/advisories/unreviewed/2021/12/GHSA-75cm-2vvh-47g6/GHSA-75cm-2vvh-47g6.json @@ -7,12 +7,8 @@ "CVE-2021-40835" ], "details": "An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from another. This is performed by using a very long username part of the url so that user cannot see the domain name. A remote attacker can leverage this to perform url address bar spoofing attack. The fix is, browser no longer shows the user name part in address bar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-75jr-j9jh-9937/GHSA-75jr-j9jh-9937.json b/advisories/unreviewed/2021/12/GHSA-75jr-j9jh-9937/GHSA-75jr-j9jh-9937.json index b42eeac77a4..f02621fdefa 100644 --- a/advisories/unreviewed/2021/12/GHSA-75jr-j9jh-9937/GHSA-75jr-j9jh-9937.json +++ b/advisories/unreviewed/2021/12/GHSA-75jr-j9jh-9937/GHSA-75jr-j9jh-9937.json @@ -7,12 +7,8 @@ "CVE-2021-39652" ], "details": "In sec_ts_parsing_cmds of (TBD), there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194499021References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-789w-f5ch-wrjq/GHSA-789w-f5ch-wrjq.json b/advisories/unreviewed/2021/12/GHSA-789w-f5ch-wrjq/GHSA-789w-f5ch-wrjq.json index 10436009d00..6e021f38b45 100644 --- a/advisories/unreviewed/2021/12/GHSA-789w-f5ch-wrjq/GHSA-789w-f5ch-wrjq.json +++ b/advisories/unreviewed/2021/12/GHSA-789w-f5ch-wrjq/GHSA-789w-f5ch-wrjq.json @@ -7,12 +7,8 @@ "CVE-2021-26800" ], "details": "Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-78vg-94xf-59v9/GHSA-78vg-94xf-59v9.json b/advisories/unreviewed/2021/12/GHSA-78vg-94xf-59v9/GHSA-78vg-94xf-59v9.json index cef3933d47a..98bbb2f5c6a 100644 --- a/advisories/unreviewed/2021/12/GHSA-78vg-94xf-59v9/GHSA-78vg-94xf-59v9.json +++ b/advisories/unreviewed/2021/12/GHSA-78vg-94xf-59v9/GHSA-78vg-94xf-59v9.json @@ -7,12 +7,8 @@ "CVE-2021-0998" ], "details": "In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193442575", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7957-q3ch-3v25/GHSA-7957-q3ch-3v25.json b/advisories/unreviewed/2021/12/GHSA-7957-q3ch-3v25/GHSA-7957-q3ch-3v25.json index c1a9152ff09..a3feb51fc6b 100644 --- a/advisories/unreviewed/2021/12/GHSA-7957-q3ch-3v25/GHSA-7957-q3ch-3v25.json +++ b/advisories/unreviewed/2021/12/GHSA-7957-q3ch-3v25/GHSA-7957-q3ch-3v25.json @@ -7,12 +7,8 @@ "CVE-2021-45014" ], "details": "There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&id=26", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7m86-pwq6-4p32/GHSA-7m86-pwq6-4p32.json b/advisories/unreviewed/2021/12/GHSA-7m86-pwq6-4p32/GHSA-7m86-pwq6-4p32.json index fe4352cafd2..8017a5bfb57 100644 --- a/advisories/unreviewed/2021/12/GHSA-7m86-pwq6-4p32/GHSA-7m86-pwq6-4p32.json +++ b/advisories/unreviewed/2021/12/GHSA-7m86-pwq6-4p32/GHSA-7m86-pwq6-4p32.json @@ -7,12 +7,8 @@ "CVE-2021-0977" ], "details": "In phNxpNHal_DtaUpdate of phNxpNciHal_dta.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-183487770", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7m98-whf4-6699/GHSA-7m98-whf4-6699.json b/advisories/unreviewed/2021/12/GHSA-7m98-whf4-6699/GHSA-7m98-whf4-6699.json index 0c5c0d795c7..8ea5ada18e6 100644 --- a/advisories/unreviewed/2021/12/GHSA-7m98-whf4-6699/GHSA-7m98-whf4-6699.json +++ b/advisories/unreviewed/2021/12/GHSA-7m98-whf4-6699/GHSA-7m98-whf4-6699.json @@ -7,12 +7,8 @@ "CVE-2021-44524" ], "details": "A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7mr2-pfvw-49gg/GHSA-7mr2-pfvw-49gg.json b/advisories/unreviewed/2021/12/GHSA-7mr2-pfvw-49gg/GHSA-7mr2-pfvw-49gg.json index 47e4292171c..00307e21058 100644 --- a/advisories/unreviewed/2021/12/GHSA-7mr2-pfvw-49gg/GHSA-7mr2-pfvw-49gg.json +++ b/advisories/unreviewed/2021/12/GHSA-7mr2-pfvw-49gg/GHSA-7mr2-pfvw-49gg.json @@ -7,12 +7,8 @@ "CVE-2021-39650" ], "details": "In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-169763055References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7r4j-45gp-phrj/GHSA-7r4j-45gp-phrj.json b/advisories/unreviewed/2021/12/GHSA-7r4j-45gp-phrj/GHSA-7r4j-45gp-phrj.json index 414bf840674..c50d0681140 100644 --- a/advisories/unreviewed/2021/12/GHSA-7r4j-45gp-phrj/GHSA-7r4j-45gp-phrj.json +++ b/advisories/unreviewed/2021/12/GHSA-7r4j-45gp-phrj/GHSA-7r4j-45gp-phrj.json @@ -7,12 +7,8 @@ "CVE-2021-39656" ], "details": "In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174049066References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7v3r-544j-x79h/GHSA-7v3r-544j-x79h.json b/advisories/unreviewed/2021/12/GHSA-7v3r-544j-x79h/GHSA-7v3r-544j-x79h.json index ca8a45fb372..cb01ca2ee27 100644 --- a/advisories/unreviewed/2021/12/GHSA-7v3r-544j-x79h/GHSA-7v3r-544j-x79h.json +++ b/advisories/unreviewed/2021/12/GHSA-7v3r-544j-x79h/GHSA-7v3r-544j-x79h.json @@ -7,12 +7,8 @@ "CVE-2021-44430" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14829)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7v8f-grj8-36h8/GHSA-7v8f-grj8-36h8.json b/advisories/unreviewed/2021/12/GHSA-7v8f-grj8-36h8/GHSA-7v8f-grj8-36h8.json index efa80ddc1d0..1d43e5f7b8b 100644 --- a/advisories/unreviewed/2021/12/GHSA-7v8f-grj8-36h8/GHSA-7v8f-grj8-36h8.json +++ b/advisories/unreviewed/2021/12/GHSA-7v8f-grj8-36h8/GHSA-7v8f-grj8-36h8.json @@ -7,12 +7,8 @@ "CVE-2021-1044" ], "details": "In eicOpsDecryptAes128Gcm of acropora/app/identity/identity_support.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195570681References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7vq5-4m2m-qff6/GHSA-7vq5-4m2m-qff6.json b/advisories/unreviewed/2021/12/GHSA-7vq5-4m2m-qff6/GHSA-7vq5-4m2m-qff6.json index b06047c45ca..6fa3fdf70f2 100644 --- a/advisories/unreviewed/2021/12/GHSA-7vq5-4m2m-qff6/GHSA-7vq5-4m2m-qff6.json +++ b/advisories/unreviewed/2021/12/GHSA-7vq5-4m2m-qff6/GHSA-7vq5-4m2m-qff6.json @@ -7,12 +7,8 @@ "CVE-2021-39309" ], "details": "The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parameter due to a var_dump() on $_POST variables found in the ~/vendor/dpsoft/parsian-payment/sample/rollback-payment.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-827c-f4fv-j8hr/GHSA-827c-f4fv-j8hr.json b/advisories/unreviewed/2021/12/GHSA-827c-f4fv-j8hr/GHSA-827c-f4fv-j8hr.json index cd9d5572783..672536aecce 100644 --- a/advisories/unreviewed/2021/12/GHSA-827c-f4fv-j8hr/GHSA-827c-f4fv-j8hr.json +++ b/advisories/unreviewed/2021/12/GHSA-827c-f4fv-j8hr/GHSA-827c-f4fv-j8hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-84fx-3wcm-55xp/GHSA-84fx-3wcm-55xp.json b/advisories/unreviewed/2021/12/GHSA-84fx-3wcm-55xp/GHSA-84fx-3wcm-55xp.json index f6e8da09916..a2fc75514b9 100644 --- a/advisories/unreviewed/2021/12/GHSA-84fx-3wcm-55xp/GHSA-84fx-3wcm-55xp.json +++ b/advisories/unreviewed/2021/12/GHSA-84fx-3wcm-55xp/GHSA-84fx-3wcm-55xp.json @@ -7,12 +7,8 @@ "CVE-2021-1046" ], "details": "In lwis_dpm_update_clock of lwis_device_dpm.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195609074References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-86rj-5gm4-r5rg/GHSA-86rj-5gm4-r5rg.json b/advisories/unreviewed/2021/12/GHSA-86rj-5gm4-r5rg/GHSA-86rj-5gm4-r5rg.json index 572d37f62c8..eda451a1c55 100644 --- a/advisories/unreviewed/2021/12/GHSA-86rj-5gm4-r5rg/GHSA-86rj-5gm4-r5rg.json +++ b/advisories/unreviewed/2021/12/GHSA-86rj-5gm4-r5rg/GHSA-86rj-5gm4-r5rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-89qw-2wgv-v7rj/GHSA-89qw-2wgv-v7rj.json b/advisories/unreviewed/2021/12/GHSA-89qw-2wgv-v7rj/GHSA-89qw-2wgv-v7rj.json index 2e783822375..28040aa231a 100644 --- a/advisories/unreviewed/2021/12/GHSA-89qw-2wgv-v7rj/GHSA-89qw-2wgv-v7rj.json +++ b/advisories/unreviewed/2021/12/GHSA-89qw-2wgv-v7rj/GHSA-89qw-2wgv-v7rj.json @@ -7,12 +7,8 @@ "CVE-2021-44439" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14908)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8gf6-jmpj-r5h7/GHSA-8gf6-jmpj-r5h7.json b/advisories/unreviewed/2021/12/GHSA-8gf6-jmpj-r5h7/GHSA-8gf6-jmpj-r5h7.json index 54f68322498..8518c5c4f17 100644 --- a/advisories/unreviewed/2021/12/GHSA-8gf6-jmpj-r5h7/GHSA-8gf6-jmpj-r5h7.json +++ b/advisories/unreviewed/2021/12/GHSA-8gf6-jmpj-r5h7/GHSA-8gf6-jmpj-r5h7.json @@ -7,12 +7,8 @@ "CVE-2021-0963" ], "details": "In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199754277", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8p36-m3pv-8wv3/GHSA-8p36-m3pv-8wv3.json b/advisories/unreviewed/2021/12/GHSA-8p36-m3pv-8wv3/GHSA-8p36-m3pv-8wv3.json index 3b028e9474c..6e46388504d 100644 --- a/advisories/unreviewed/2021/12/GHSA-8p36-m3pv-8wv3/GHSA-8p36-m3pv-8wv3.json +++ b/advisories/unreviewed/2021/12/GHSA-8p36-m3pv-8wv3/GHSA-8p36-m3pv-8wv3.json @@ -7,12 +7,8 @@ "CVE-2021-39642" ], "details": "In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195731663References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-8wxh-27vw-26wh/GHSA-8wxh-27vw-26wh.json b/advisories/unreviewed/2021/12/GHSA-8wxh-27vw-26wh/GHSA-8wxh-27vw-26wh.json index 1a9e56747eb..fd13b94c4bc 100644 --- a/advisories/unreviewed/2021/12/GHSA-8wxh-27vw-26wh/GHSA-8wxh-27vw-26wh.json +++ b/advisories/unreviewed/2021/12/GHSA-8wxh-27vw-26wh/GHSA-8wxh-27vw-26wh.json @@ -7,12 +7,8 @@ "CVE-2021-29847" ], "details": "BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-8xh3-3wj9-mjw4/GHSA-8xh3-3wj9-mjw4.json b/advisories/unreviewed/2021/12/GHSA-8xh3-3wj9-mjw4/GHSA-8xh3-3wj9-mjw4.json index db4914516cf..9b9230223f0 100644 --- a/advisories/unreviewed/2021/12/GHSA-8xh3-3wj9-mjw4/GHSA-8xh3-3wj9-mjw4.json +++ b/advisories/unreviewed/2021/12/GHSA-8xh3-3wj9-mjw4/GHSA-8xh3-3wj9-mjw4.json @@ -7,12 +7,8 @@ "CVE-2021-44432" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to stack based buffer overflow while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14845)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-96j7-8ppq-5hjv/GHSA-96j7-8ppq-5hjv.json b/advisories/unreviewed/2021/12/GHSA-96j7-8ppq-5hjv/GHSA-96j7-8ppq-5hjv.json index dfda93b9bfd..5bdba90ef27 100644 --- a/advisories/unreviewed/2021/12/GHSA-96j7-8ppq-5hjv/GHSA-96j7-8ppq-5hjv.json +++ b/advisories/unreviewed/2021/12/GHSA-96j7-8ppq-5hjv/GHSA-96j7-8ppq-5hjv.json @@ -7,12 +7,8 @@ "CVE-2021-1008" ], "details": "In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197327688", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-97w5-ccgq-76pq/GHSA-97w5-ccgq-76pq.json b/advisories/unreviewed/2021/12/GHSA-97w5-ccgq-76pq/GHSA-97w5-ccgq-76pq.json index eb98bb7aac7..c369d1fa465 100644 --- a/advisories/unreviewed/2021/12/GHSA-97w5-ccgq-76pq/GHSA-97w5-ccgq-76pq.json +++ b/advisories/unreviewed/2021/12/GHSA-97w5-ccgq-76pq/GHSA-97w5-ccgq-76pq.json @@ -7,12 +7,8 @@ "CVE-2021-39638" ], "details": "In periodic_io_work_func of lwis_periodic_io.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195607566References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-98f9-vw78-c4rg/GHSA-98f9-vw78-c4rg.json b/advisories/unreviewed/2021/12/GHSA-98f9-vw78-c4rg/GHSA-98f9-vw78-c4rg.json index 4a4011aa696..a2e50cb3197 100644 --- a/advisories/unreviewed/2021/12/GHSA-98f9-vw78-c4rg/GHSA-98f9-vw78-c4rg.json +++ b/advisories/unreviewed/2021/12/GHSA-98f9-vw78-c4rg/GHSA-98f9-vw78-c4rg.json @@ -7,12 +7,8 @@ "CVE-2021-44433" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains a use after free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14900)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9g5m-x9xw-j23f/GHSA-9g5m-x9xw-j23f.json b/advisories/unreviewed/2021/12/GHSA-9g5m-x9xw-j23f/GHSA-9g5m-x9xw-j23f.json index 5b9a6761849..4695ffbbb11 100644 --- a/advisories/unreviewed/2021/12/GHSA-9g5m-x9xw-j23f/GHSA-9g5m-x9xw-j23f.json +++ b/advisories/unreviewed/2021/12/GHSA-9g5m-x9xw-j23f/GHSA-9g5m-x9xw-j23f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9j4q-jq6x-2vv2/GHSA-9j4q-jq6x-2vv2.json b/advisories/unreviewed/2021/12/GHSA-9j4q-jq6x-2vv2/GHSA-9j4q-jq6x-2vv2.json index d365057d419..e910f4db6f5 100644 --- a/advisories/unreviewed/2021/12/GHSA-9j4q-jq6x-2vv2/GHSA-9j4q-jq6x-2vv2.json +++ b/advisories/unreviewed/2021/12/GHSA-9j4q-jq6x-2vv2/GHSA-9j4q-jq6x-2vv2.json @@ -7,12 +7,8 @@ "CVE-2021-1014" ], "details": "In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186776740", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9j6h-6x9c-qmfv/GHSA-9j6h-6x9c-qmfv.json b/advisories/unreviewed/2021/12/GHSA-9j6h-6x9c-qmfv/GHSA-9j6h-6x9c-qmfv.json index 62f3b815c6b..eb27dede079 100644 --- a/advisories/unreviewed/2021/12/GHSA-9j6h-6x9c-qmfv/GHSA-9j6h-6x9c-qmfv.json +++ b/advisories/unreviewed/2021/12/GHSA-9j6h-6x9c-qmfv/GHSA-9j6h-6x9c-qmfv.json @@ -7,12 +7,8 @@ "CVE-2021-39313" ], "details": "The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9mr6-2c2v-735f/GHSA-9mr6-2c2v-735f.json b/advisories/unreviewed/2021/12/GHSA-9mr6-2c2v-735f/GHSA-9mr6-2c2v-735f.json index 89fdc38209c..b311a000c39 100644 --- a/advisories/unreviewed/2021/12/GHSA-9mr6-2c2v-735f/GHSA-9mr6-2c2v-735f.json +++ b/advisories/unreviewed/2021/12/GHSA-9mr6-2c2v-735f/GHSA-9mr6-2c2v-735f.json @@ -7,12 +7,8 @@ "CVE-2021-0961" ], "details": "In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196046570References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9p3v-445m-vf8m/GHSA-9p3v-445m-vf8m.json b/advisories/unreviewed/2021/12/GHSA-9p3v-445m-vf8m/GHSA-9p3v-445m-vf8m.json index c97ff605d55..43da4ae912f 100644 --- a/advisories/unreviewed/2021/12/GHSA-9p3v-445m-vf8m/GHSA-9p3v-445m-vf8m.json +++ b/advisories/unreviewed/2021/12/GHSA-9p3v-445m-vf8m/GHSA-9p3v-445m-vf8m.json @@ -7,12 +7,8 @@ "CVE-2021-41871" ], "details": "An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9v55-ghc6-wfcw/GHSA-9v55-ghc6-wfcw.json b/advisories/unreviewed/2021/12/GHSA-9v55-ghc6-wfcw/GHSA-9v55-ghc6-wfcw.json index 0cd51516295..55cdbffd89d 100644 --- a/advisories/unreviewed/2021/12/GHSA-9v55-ghc6-wfcw/GHSA-9v55-ghc6-wfcw.json +++ b/advisories/unreviewed/2021/12/GHSA-9v55-ghc6-wfcw/GHSA-9v55-ghc6-wfcw.json @@ -7,12 +7,8 @@ "CVE-2021-40827" ], "details": "Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move, affecting the MP3 file parsing functionality at memcpy+0x265. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary code execution in the context of the current logged-in Windows user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c5pv-rm96-f3q6/GHSA-c5pv-rm96-f3q6.json b/advisories/unreviewed/2021/12/GHSA-c5pv-rm96-f3q6/GHSA-c5pv-rm96-f3q6.json index 44061fb9017..482f7b181b8 100644 --- a/advisories/unreviewed/2021/12/GHSA-c5pv-rm96-f3q6/GHSA-c5pv-rm96-f3q6.json +++ b/advisories/unreviewed/2021/12/GHSA-c5pv-rm96-f3q6/GHSA-c5pv-rm96-f3q6.json @@ -7,12 +7,8 @@ "CVE-2021-43325" ], "details": "Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c6qm-6524-j252/GHSA-c6qm-6524-j252.json b/advisories/unreviewed/2021/12/GHSA-c6qm-6524-j252/GHSA-c6qm-6524-j252.json index f1f04a1a2c7..f3392856f49 100644 --- a/advisories/unreviewed/2021/12/GHSA-c6qm-6524-j252/GHSA-c6qm-6524-j252.json +++ b/advisories/unreviewed/2021/12/GHSA-c6qm-6524-j252/GHSA-c6qm-6524-j252.json @@ -7,12 +7,8 @@ "CVE-2021-1020" ], "details": "In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195111725", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c8q7-8787-544x/GHSA-c8q7-8787-544x.json b/advisories/unreviewed/2021/12/GHSA-c8q7-8787-544x/GHSA-c8q7-8787-544x.json index 24dd4cd85b8..2d3e0ed869d 100644 --- a/advisories/unreviewed/2021/12/GHSA-c8q7-8787-544x/GHSA-c8q7-8787-544x.json +++ b/advisories/unreviewed/2021/12/GHSA-c8q7-8787-544x/GHSA-c8q7-8787-544x.json @@ -7,12 +7,8 @@ "CVE-2021-45017" ], "details": "Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c9rc-7w87-3h5x/GHSA-c9rc-7w87-3h5x.json b/advisories/unreviewed/2021/12/GHSA-c9rc-7w87-3h5x/GHSA-c9rc-7w87-3h5x.json index 1e350a1747e..8305150d4d0 100644 --- a/advisories/unreviewed/2021/12/GHSA-c9rc-7w87-3h5x/GHSA-c9rc-7w87-3h5x.json +++ b/advisories/unreviewed/2021/12/GHSA-c9rc-7w87-3h5x/GHSA-c9rc-7w87-3h5x.json @@ -7,12 +7,8 @@ "CVE-2021-41560" ], "details": "OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cfcf-x7x2-gpf8/GHSA-cfcf-x7x2-gpf8.json b/advisories/unreviewed/2021/12/GHSA-cfcf-x7x2-gpf8/GHSA-cfcf-x7x2-gpf8.json index 32ee2d4f055..863c63ee85b 100644 --- a/advisories/unreviewed/2021/12/GHSA-cfcf-x7x2-gpf8/GHSA-cfcf-x7x2-gpf8.json +++ b/advisories/unreviewed/2021/12/GHSA-cfcf-x7x2-gpf8/GHSA-cfcf-x7x2-gpf8.json @@ -7,12 +7,8 @@ "CVE-2021-45098" ], "details": "An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-cm9v-3mpg-x2w6/GHSA-cm9v-3mpg-x2w6.json b/advisories/unreviewed/2021/12/GHSA-cm9v-3mpg-x2w6/GHSA-cm9v-3mpg-x2w6.json index b241acca5e9..8dcb96c796f 100644 --- a/advisories/unreviewed/2021/12/GHSA-cm9v-3mpg-x2w6/GHSA-cm9v-3mpg-x2w6.json +++ b/advisories/unreviewed/2021/12/GHSA-cm9v-3mpg-x2w6/GHSA-cm9v-3mpg-x2w6.json @@ -7,12 +7,8 @@ "CVE-2021-44007" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an off-by-one error in the heap while parsing specially crafted TIFF files. This could allow an attacker to cause a denial-of-service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cmxr-2mw4-8jjq/GHSA-cmxr-2mw4-8jjq.json b/advisories/unreviewed/2021/12/GHSA-cmxr-2mw4-8jjq/GHSA-cmxr-2mw4-8jjq.json index 8c9da80cd23..62bb5e939d1 100644 --- a/advisories/unreviewed/2021/12/GHSA-cmxr-2mw4-8jjq/GHSA-cmxr-2mw4-8jjq.json +++ b/advisories/unreviewed/2021/12/GHSA-cmxr-2mw4-8jjq/GHSA-cmxr-2mw4-8jjq.json @@ -7,12 +7,8 @@ "CVE-2021-40852" ], "details": "TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cqw3-jpf4-v74v/GHSA-cqw3-jpf4-v74v.json b/advisories/unreviewed/2021/12/GHSA-cqw3-jpf4-v74v/GHSA-cqw3-jpf4-v74v.json index ee1baa961e7..8e8ece34c50 100644 --- a/advisories/unreviewed/2021/12/GHSA-cqw3-jpf4-v74v/GHSA-cqw3-jpf4-v74v.json +++ b/advisories/unreviewed/2021/12/GHSA-cqw3-jpf4-v74v/GHSA-cqw3-jpf4-v74v.json @@ -7,12 +7,8 @@ "CVE-2021-41870" ], "details": "An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f622-26hm-xgj8/GHSA-f622-26hm-xgj8.json b/advisories/unreviewed/2021/12/GHSA-f622-26hm-xgj8/GHSA-f622-26hm-xgj8.json index 8e271f3ee46..a0363e8566c 100644 --- a/advisories/unreviewed/2021/12/GHSA-f622-26hm-xgj8/GHSA-f622-26hm-xgj8.json +++ b/advisories/unreviewed/2021/12/GHSA-f622-26hm-xgj8/GHSA-f622-26hm-xgj8.json @@ -7,12 +7,8 @@ "CVE-2021-3959" ], "details": "A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f66p-66fr-f5qm/GHSA-f66p-66fr-f5qm.json b/advisories/unreviewed/2021/12/GHSA-f66p-66fr-f5qm/GHSA-f66p-66fr-f5qm.json index 284dc37de0b..c10bccc7d1a 100644 --- a/advisories/unreviewed/2021/12/GHSA-f66p-66fr-f5qm/GHSA-f66p-66fr-f5qm.json +++ b/advisories/unreviewed/2021/12/GHSA-f66p-66fr-f5qm/GHSA-f66p-66fr-f5qm.json @@ -7,12 +7,8 @@ "CVE-2021-41962" ], "details": "Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-f7f6-f2cj-m7m8/GHSA-f7f6-f2cj-m7m8.json b/advisories/unreviewed/2021/12/GHSA-f7f6-f2cj-m7m8/GHSA-f7f6-f2cj-m7m8.json index 093f2ed4e6f..e57f3a15345 100644 --- a/advisories/unreviewed/2021/12/GHSA-f7f6-f2cj-m7m8/GHSA-f7f6-f2cj-m7m8.json +++ b/advisories/unreviewed/2021/12/GHSA-f7f6-f2cj-m7m8/GHSA-f7f6-f2cj-m7m8.json @@ -7,12 +7,8 @@ "CVE-2021-0926" ], "details": "In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-191053931", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fc56-476w-j7fm/GHSA-fc56-476w-j7fm.json b/advisories/unreviewed/2021/12/GHSA-fc56-476w-j7fm/GHSA-fc56-476w-j7fm.json index 28ff2a670a8..808953bb5b4 100644 --- a/advisories/unreviewed/2021/12/GHSA-fc56-476w-j7fm/GHSA-fc56-476w-j7fm.json +++ b/advisories/unreviewed/2021/12/GHSA-fc56-476w-j7fm/GHSA-fc56-476w-j7fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-ffw4-h2r2-99hc/GHSA-ffw4-h2r2-99hc.json b/advisories/unreviewed/2021/12/GHSA-ffw4-h2r2-99hc/GHSA-ffw4-h2r2-99hc.json index 98644c2672e..19a7cd906cb 100644 --- a/advisories/unreviewed/2021/12/GHSA-ffw4-h2r2-99hc/GHSA-ffw4-h2r2-99hc.json +++ b/advisories/unreviewed/2021/12/GHSA-ffw4-h2r2-99hc/GHSA-ffw4-h2r2-99hc.json @@ -7,12 +7,8 @@ "CVE-2021-45018" ], "details": "Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fjr4-p4q2-8f3f/GHSA-fjr4-p4q2-8f3f.json b/advisories/unreviewed/2021/12/GHSA-fjr4-p4q2-8f3f/GHSA-fjr4-p4q2-8f3f.json index bd2f2aed97e..85e7f4e3143 100644 --- a/advisories/unreviewed/2021/12/GHSA-fjr4-p4q2-8f3f/GHSA-fjr4-p4q2-8f3f.json +++ b/advisories/unreviewed/2021/12/GHSA-fjr4-p4q2-8f3f/GHSA-fjr4-p4q2-8f3f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fr6w-vm34-xj98/GHSA-fr6w-vm34-xj98.json b/advisories/unreviewed/2021/12/GHSA-fr6w-vm34-xj98/GHSA-fr6w-vm34-xj98.json index 3bbd4c4f005..8eeb6088fac 100644 --- a/advisories/unreviewed/2021/12/GHSA-fr6w-vm34-xj98/GHSA-fr6w-vm34-xj98.json +++ b/advisories/unreviewed/2021/12/GHSA-fr6w-vm34-xj98/GHSA-fr6w-vm34-xj98.json @@ -7,12 +7,8 @@ "CVE-2021-27859" ], "details": "A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. This does not appear to be a CSRF vulnerability. The FatPipe advisory identifier for this vulnerability is FPSA005.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fr8p-hjhj-2qxg/GHSA-fr8p-hjhj-2qxg.json b/advisories/unreviewed/2021/12/GHSA-fr8p-hjhj-2qxg/GHSA-fr8p-hjhj-2qxg.json index 5f4033f3fa1..c0d4de6c43c 100644 --- a/advisories/unreviewed/2021/12/GHSA-fr8p-hjhj-2qxg/GHSA-fr8p-hjhj-2qxg.json +++ b/advisories/unreviewed/2021/12/GHSA-fr8p-hjhj-2qxg/GHSA-fr8p-hjhj-2qxg.json @@ -7,12 +7,8 @@ "CVE-2021-44436" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14905)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-fw5r-p8w4-82wr/GHSA-fw5r-p8w4-82wr.json b/advisories/unreviewed/2021/12/GHSA-fw5r-p8w4-82wr/GHSA-fw5r-p8w4-82wr.json index 9a38cc2b1f1..c715fa4d3d5 100644 --- a/advisories/unreviewed/2021/12/GHSA-fw5r-p8w4-82wr/GHSA-fw5r-p8w4-82wr.json +++ b/advisories/unreviewed/2021/12/GHSA-fw5r-p8w4-82wr/GHSA-fw5r-p8w4-82wr.json @@ -7,12 +7,8 @@ "CVE-2021-36450" ], "details": "Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g4fj-qffq-f9vx/GHSA-g4fj-qffq-f9vx.json b/advisories/unreviewed/2021/12/GHSA-g4fj-qffq-f9vx/GHSA-g4fj-qffq-f9vx.json index 90aa7a0ab35..e4795189d09 100644 --- a/advisories/unreviewed/2021/12/GHSA-g4fj-qffq-f9vx/GHSA-g4fj-qffq-f9vx.json +++ b/advisories/unreviewed/2021/12/GHSA-g4fj-qffq-f9vx/GHSA-g4fj-qffq-f9vx.json @@ -7,12 +7,8 @@ "CVE-2021-0929" ], "details": "In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-187527909References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g57r-4mv6-3958/GHSA-g57r-4mv6-3958.json b/advisories/unreviewed/2021/12/GHSA-g57r-4mv6-3958/GHSA-g57r-4mv6-3958.json index 810c3cd4583..c78d610342d 100644 --- a/advisories/unreviewed/2021/12/GHSA-g57r-4mv6-3958/GHSA-g57r-4mv6-3958.json +++ b/advisories/unreviewed/2021/12/GHSA-g57r-4mv6-3958/GHSA-g57r-4mv6-3958.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g9x9-gxgx-rm88/GHSA-g9x9-gxgx-rm88.json b/advisories/unreviewed/2021/12/GHSA-g9x9-gxgx-rm88/GHSA-g9x9-gxgx-rm88.json index 99977e50523..3083c054d9b 100644 --- a/advisories/unreviewed/2021/12/GHSA-g9x9-gxgx-rm88/GHSA-g9x9-gxgx-rm88.json +++ b/advisories/unreviewed/2021/12/GHSA-g9x9-gxgx-rm88/GHSA-g9x9-gxgx-rm88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-ggw5-48gv-558x/GHSA-ggw5-48gv-558x.json b/advisories/unreviewed/2021/12/GHSA-ggw5-48gv-558x/GHSA-ggw5-48gv-558x.json index b79e22ac303..22c0c720bbf 100644 --- a/advisories/unreviewed/2021/12/GHSA-ggw5-48gv-558x/GHSA-ggw5-48gv-558x.json +++ b/advisories/unreviewed/2021/12/GHSA-ggw5-48gv-558x/GHSA-ggw5-48gv-558x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-ghxr-hx5p-73mx/GHSA-ghxr-hx5p-73mx.json b/advisories/unreviewed/2021/12/GHSA-ghxr-hx5p-73mx/GHSA-ghxr-hx5p-73mx.json index 3fb8de19f7e..7cac04c7c73 100644 --- a/advisories/unreviewed/2021/12/GHSA-ghxr-hx5p-73mx/GHSA-ghxr-hx5p-73mx.json +++ b/advisories/unreviewed/2021/12/GHSA-ghxr-hx5p-73mx/GHSA-ghxr-hx5p-73mx.json @@ -7,12 +7,8 @@ "CVE-2021-1031" ], "details": "In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194697004", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gqqh-5jqj-j85x/GHSA-gqqh-5jqj-j85x.json b/advisories/unreviewed/2021/12/GHSA-gqqh-5jqj-j85x/GHSA-gqqh-5jqj-j85x.json index 03d08cdf481..c4ac415e834 100644 --- a/advisories/unreviewed/2021/12/GHSA-gqqh-5jqj-j85x/GHSA-gqqh-5jqj-j85x.json +++ b/advisories/unreviewed/2021/12/GHSA-gqqh-5jqj-j85x/GHSA-gqqh-5jqj-j85x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gqwv-ccm6-wr7j/GHSA-gqwv-ccm6-wr7j.json b/advisories/unreviewed/2021/12/GHSA-gqwv-ccm6-wr7j/GHSA-gqwv-ccm6-wr7j.json index 42b26328928..88b9834bba9 100644 --- a/advisories/unreviewed/2021/12/GHSA-gqwv-ccm6-wr7j/GHSA-gqwv-ccm6-wr7j.json +++ b/advisories/unreviewed/2021/12/GHSA-gqwv-ccm6-wr7j/GHSA-gqwv-ccm6-wr7j.json @@ -7,12 +7,8 @@ "CVE-2021-1005" ], "details": "In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186530889", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gv3q-27qx-g2xh/GHSA-gv3q-27qx-g2xh.json b/advisories/unreviewed/2021/12/GHSA-gv3q-27qx-g2xh/GHSA-gv3q-27qx-g2xh.json index 8ba721a9a0a..38d60ffcc4d 100644 --- a/advisories/unreviewed/2021/12/GHSA-gv3q-27qx-g2xh/GHSA-gv3q-27qx-g2xh.json +++ b/advisories/unreviewed/2021/12/GHSA-gv3q-27qx-g2xh/GHSA-gv3q-27qx-g2xh.json @@ -7,12 +7,8 @@ "CVE-2021-4124" ], "details": "janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gw77-xfw7-7h69/GHSA-gw77-xfw7-7h69.json b/advisories/unreviewed/2021/12/GHSA-gw77-xfw7-7h69/GHSA-gw77-xfw7-7h69.json index a507cdf456a..c8cd609ac37 100644 --- a/advisories/unreviewed/2021/12/GHSA-gw77-xfw7-7h69/GHSA-gw77-xfw7-7h69.json +++ b/advisories/unreviewed/2021/12/GHSA-gw77-xfw7-7h69/GHSA-gw77-xfw7-7h69.json @@ -7,12 +7,8 @@ "CVE-2021-0924" ], "details": "In xhci_vendor_get_ops of xhci.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194461020References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-gxh2-hp3g-6q5q/GHSA-gxh2-hp3g-6q5q.json b/advisories/unreviewed/2021/12/GHSA-gxh2-hp3g-6q5q/GHSA-gxh2-hp3g-6q5q.json index 35445e7739f..e0e2db96840 100644 --- a/advisories/unreviewed/2021/12/GHSA-gxh2-hp3g-6q5q/GHSA-gxh2-hp3g-6q5q.json +++ b/advisories/unreviewed/2021/12/GHSA-gxh2-hp3g-6q5q/GHSA-gxh2-hp3g-6q5q.json @@ -7,12 +7,8 @@ "CVE-2021-1023" ], "details": "In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195963373", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h2c3-ph7g-cmvq/GHSA-h2c3-ph7g-cmvq.json b/advisories/unreviewed/2021/12/GHSA-h2c3-ph7g-cmvq/GHSA-h2c3-ph7g-cmvq.json index 258995cd1f9..242686e8ecd 100644 --- a/advisories/unreviewed/2021/12/GHSA-h2c3-ph7g-cmvq/GHSA-h2c3-ph7g-cmvq.json +++ b/advisories/unreviewed/2021/12/GHSA-h2c3-ph7g-cmvq/GHSA-h2c3-ph7g-cmvq.json @@ -7,12 +7,8 @@ "CVE-2021-3960" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior to 3.3.8.272", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h2j8-7rhq-g5mg/GHSA-h2j8-7rhq-g5mg.json b/advisories/unreviewed/2021/12/GHSA-h2j8-7rhq-g5mg/GHSA-h2j8-7rhq-g5mg.json index 4f51be0a72a..7b75727d224 100644 --- a/advisories/unreviewed/2021/12/GHSA-h2j8-7rhq-g5mg/GHSA-h2j8-7rhq-g5mg.json +++ b/advisories/unreviewed/2021/12/GHSA-h2j8-7rhq-g5mg/GHSA-h2j8-7rhq-g5mg.json @@ -7,12 +7,8 @@ "CVE-2021-44006" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted TIFF files. This could allow an attacker to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h42c-m8vj-q7px/GHSA-h42c-m8vj-q7px.json b/advisories/unreviewed/2021/12/GHSA-h42c-m8vj-q7px/GHSA-h42c-m8vj-q7px.json index a6362cf41c3..880b7d12273 100644 --- a/advisories/unreviewed/2021/12/GHSA-h42c-m8vj-q7px/GHSA-h42c-m8vj-q7px.json +++ b/advisories/unreviewed/2021/12/GHSA-h42c-m8vj-q7px/GHSA-h42c-m8vj-q7px.json @@ -7,12 +7,8 @@ "CVE-2021-1015" ], "details": "In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186530496", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h4h6-8v79-695g/GHSA-h4h6-8v79-695g.json b/advisories/unreviewed/2021/12/GHSA-h4h6-8v79-695g/GHSA-h4h6-8v79-695g.json index 64928cfda61..7c14b2f8ceb 100644 --- a/advisories/unreviewed/2021/12/GHSA-h4h6-8v79-695g/GHSA-h4h6-8v79-695g.json +++ b/advisories/unreviewed/2021/12/GHSA-h4h6-8v79-695g/GHSA-h4h6-8v79-695g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h95g-226g-7wq6/GHSA-h95g-226g-7wq6.json b/advisories/unreviewed/2021/12/GHSA-h95g-226g-7wq6/GHSA-h95g-226g-7wq6.json index 79a0924f919..63c2b994e73 100644 --- a/advisories/unreviewed/2021/12/GHSA-h95g-226g-7wq6/GHSA-h95g-226g-7wq6.json +++ b/advisories/unreviewed/2021/12/GHSA-h95g-226g-7wq6/GHSA-h95g-226g-7wq6.json @@ -7,12 +7,8 @@ "CVE-2020-18985" ], "details": "An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h98c-r5q9-prxg/GHSA-h98c-r5q9-prxg.json b/advisories/unreviewed/2021/12/GHSA-h98c-r5q9-prxg/GHSA-h98c-r5q9-prxg.json index ac1d265a7bd..6501fe70417 100644 --- a/advisories/unreviewed/2021/12/GHSA-h98c-r5q9-prxg/GHSA-h98c-r5q9-prxg.json +++ b/advisories/unreviewed/2021/12/GHSA-h98c-r5q9-prxg/GHSA-h98c-r5q9-prxg.json @@ -7,12 +7,8 @@ "CVE-2021-44935" ], "details": "glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h9hc-qgww-qvf4/GHSA-h9hc-qgww-qvf4.json b/advisories/unreviewed/2021/12/GHSA-h9hc-qgww-qvf4/GHSA-h9hc-qgww-qvf4.json index 89a48c0df94..a6271c5aabc 100644 --- a/advisories/unreviewed/2021/12/GHSA-h9hc-qgww-qvf4/GHSA-h9hc-qgww-qvf4.json +++ b/advisories/unreviewed/2021/12/GHSA-h9hc-qgww-qvf4/GHSA-h9hc-qgww-qvf4.json @@ -7,12 +7,8 @@ "CVE-2021-0918" ], "details": "In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197536150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hccp-47wx-qw2w/GHSA-hccp-47wx-qw2w.json b/advisories/unreviewed/2021/12/GHSA-hccp-47wx-qw2w/GHSA-hccp-47wx-qw2w.json index 7ddb7294679..cf9fa2c3656 100644 --- a/advisories/unreviewed/2021/12/GHSA-hccp-47wx-qw2w/GHSA-hccp-47wx-qw2w.json +++ b/advisories/unreviewed/2021/12/GHSA-hccp-47wx-qw2w/GHSA-hccp-47wx-qw2w.json @@ -7,12 +7,8 @@ "CVE-2021-0930" ], "details": "In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-181660091", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hcfv-5p8h-vvh5/GHSA-hcfv-5p8h-vvh5.json b/advisories/unreviewed/2021/12/GHSA-hcfv-5p8h-vvh5/GHSA-hcfv-5p8h-vvh5.json index 30542d6dcaf..d1b90729215 100644 --- a/advisories/unreviewed/2021/12/GHSA-hcfv-5p8h-vvh5/GHSA-hcfv-5p8h-vvh5.json +++ b/advisories/unreviewed/2021/12/GHSA-hcfv-5p8h-vvh5/GHSA-hcfv-5p8h-vvh5.json @@ -7,12 +7,8 @@ "CVE-2021-42912" ], "details": "FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hh56-v5h3-g3f8/GHSA-hh56-v5h3-g3f8.json b/advisories/unreviewed/2021/12/GHSA-hh56-v5h3-g3f8/GHSA-hh56-v5h3-g3f8.json index 0a65e340a70..95b39ede034 100644 --- a/advisories/unreviewed/2021/12/GHSA-hh56-v5h3-g3f8/GHSA-hh56-v5h3-g3f8.json +++ b/advisories/unreviewed/2021/12/GHSA-hh56-v5h3-g3f8/GHSA-hh56-v5h3-g3f8.json @@ -7,12 +7,8 @@ "CVE-2021-0704" ], "details": "In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-179338675", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hw66-wjmj-hwgg/GHSA-hw66-wjmj-hwgg.json b/advisories/unreviewed/2021/12/GHSA-hw66-wjmj-hwgg/GHSA-hw66-wjmj-hwgg.json index 6e54f80a13c..1dce4d10107 100644 --- a/advisories/unreviewed/2021/12/GHSA-hw66-wjmj-hwgg/GHSA-hw66-wjmj-hwgg.json +++ b/advisories/unreviewed/2021/12/GHSA-hw66-wjmj-hwgg/GHSA-hw66-wjmj-hwgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hw7v-8wmv-m3mp/GHSA-hw7v-8wmv-m3mp.json b/advisories/unreviewed/2021/12/GHSA-hw7v-8wmv-m3mp/GHSA-hw7v-8wmv-m3mp.json index ad6e33113e2..c211be737a8 100644 --- a/advisories/unreviewed/2021/12/GHSA-hw7v-8wmv-m3mp/GHSA-hw7v-8wmv-m3mp.json +++ b/advisories/unreviewed/2021/12/GHSA-hw7v-8wmv-m3mp/GHSA-hw7v-8wmv-m3mp.json @@ -7,12 +7,8 @@ "CVE-2021-0996" ], "details": "In nfaHciCallback of HciEventManager.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181346545", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-j268-c725-mvj8/GHSA-j268-c725-mvj8.json b/advisories/unreviewed/2021/12/GHSA-j268-c725-mvj8/GHSA-j268-c725-mvj8.json index ad420409ace..c4bf54a8a28 100644 --- a/advisories/unreviewed/2021/12/GHSA-j268-c725-mvj8/GHSA-j268-c725-mvj8.json +++ b/advisories/unreviewed/2021/12/GHSA-j268-c725-mvj8/GHSA-j268-c725-mvj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-j2j3-53qc-jw45/GHSA-j2j3-53qc-jw45.json b/advisories/unreviewed/2021/12/GHSA-j2j3-53qc-jw45/GHSA-j2j3-53qc-jw45.json index 954f9970699..0bd1e13f08b 100644 --- a/advisories/unreviewed/2021/12/GHSA-j2j3-53qc-jw45/GHSA-j2j3-53qc-jw45.json +++ b/advisories/unreviewed/2021/12/GHSA-j2j3-53qc-jw45/GHSA-j2j3-53qc-jw45.json @@ -7,12 +7,8 @@ "CVE-2021-1006" ], "details": "In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-183961974", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-j7vv-mph8-283v/GHSA-j7vv-mph8-283v.json b/advisories/unreviewed/2021/12/GHSA-j7vv-mph8-283v/GHSA-j7vv-mph8-283v.json index fdb52ef67e9..18bb5649dfa 100644 --- a/advisories/unreviewed/2021/12/GHSA-j7vv-mph8-283v/GHSA-j7vv-mph8-283v.json +++ b/advisories/unreviewed/2021/12/GHSA-j7vv-mph8-283v/GHSA-j7vv-mph8-283v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jc4p-c854-mcwc/GHSA-jc4p-c854-mcwc.json b/advisories/unreviewed/2021/12/GHSA-jc4p-c854-mcwc/GHSA-jc4p-c854-mcwc.json index 80ecb06dba1..73863c8adab 100644 --- a/advisories/unreviewed/2021/12/GHSA-jc4p-c854-mcwc/GHSA-jc4p-c854-mcwc.json +++ b/advisories/unreviewed/2021/12/GHSA-jc4p-c854-mcwc/GHSA-jc4p-c854-mcwc.json @@ -7,12 +7,8 @@ "CVE-2021-44438" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14907)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jf6w-775m-7xx9/GHSA-jf6w-775m-7xx9.json b/advisories/unreviewed/2021/12/GHSA-jf6w-775m-7xx9/GHSA-jf6w-775m-7xx9.json index dd295d7727e..8b273e5b8db 100644 --- a/advisories/unreviewed/2021/12/GHSA-jf6w-775m-7xx9/GHSA-jf6w-775m-7xx9.json +++ b/advisories/unreviewed/2021/12/GHSA-jf6w-775m-7xx9/GHSA-jf6w-775m-7xx9.json @@ -7,12 +7,8 @@ "CVE-2021-42051" ], "details": "An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jfmj-8mj4-rr8f/GHSA-jfmj-8mj4-rr8f.json b/advisories/unreviewed/2021/12/GHSA-jfmj-8mj4-rr8f/GHSA-jfmj-8mj4-rr8f.json index 4c4ee9b43a1..0d10c9c633e 100644 --- a/advisories/unreviewed/2021/12/GHSA-jfmj-8mj4-rr8f/GHSA-jfmj-8mj4-rr8f.json +++ b/advisories/unreviewed/2021/12/GHSA-jfmj-8mj4-rr8f/GHSA-jfmj-8mj4-rr8f.json @@ -7,12 +7,8 @@ "CVE-2021-1028" ], "details": "In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193034683", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jq43-mcx6-wp6q/GHSA-jq43-mcx6-wp6q.json b/advisories/unreviewed/2021/12/GHSA-jq43-mcx6-wp6q/GHSA-jq43-mcx6-wp6q.json index ff26f855d4e..0228e4bacbb 100644 --- a/advisories/unreviewed/2021/12/GHSA-jq43-mcx6-wp6q/GHSA-jq43-mcx6-wp6q.json +++ b/advisories/unreviewed/2021/12/GHSA-jq43-mcx6-wp6q/GHSA-jq43-mcx6-wp6q.json @@ -7,12 +7,8 @@ "CVE-2021-44450" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-15055, ZDI-CAN-14915, ZDI-CAN-14865)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jq98-jrfw-jv2j/GHSA-jq98-jrfw-jv2j.json b/advisories/unreviewed/2021/12/GHSA-jq98-jrfw-jv2j/GHSA-jq98-jrfw-jv2j.json index 4452d1df66b..cdc97135479 100644 --- a/advisories/unreviewed/2021/12/GHSA-jq98-jrfw-jv2j/GHSA-jq98-jrfw-jv2j.json +++ b/advisories/unreviewed/2021/12/GHSA-jq98-jrfw-jv2j/GHSA-jq98-jrfw-jv2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jrhj-xj93-7gg6/GHSA-jrhj-xj93-7gg6.json b/advisories/unreviewed/2021/12/GHSA-jrhj-xj93-7gg6/GHSA-jrhj-xj93-7gg6.json index de52a80ddef..1405f95509d 100644 --- a/advisories/unreviewed/2021/12/GHSA-jrhj-xj93-7gg6/GHSA-jrhj-xj93-7gg6.json +++ b/advisories/unreviewed/2021/12/GHSA-jrhj-xj93-7gg6/GHSA-jrhj-xj93-7gg6.json @@ -7,12 +7,8 @@ "CVE-2021-1017" ], "details": "In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-182583850", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jvfh-j65v-3qc2/GHSA-jvfh-j65v-3qc2.json b/advisories/unreviewed/2021/12/GHSA-jvfh-j65v-3qc2/GHSA-jvfh-j65v-3qc2.json index 27b17a16ad7..6f57e11abd9 100644 --- a/advisories/unreviewed/2021/12/GHSA-jvfh-j65v-3qc2/GHSA-jvfh-j65v-3qc2.json +++ b/advisories/unreviewed/2021/12/GHSA-jvfh-j65v-3qc2/GHSA-jvfh-j65v-3qc2.json @@ -7,12 +7,8 @@ "CVE-2021-0925" ], "details": "In rw_t4t_sm_detect_ndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure due to a limited change in behavior based on the out of bounds data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191444150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jvq6-xpq3-8mch/GHSA-jvq6-xpq3-8mch.json b/advisories/unreviewed/2021/12/GHSA-jvq6-xpq3-8mch/GHSA-jvq6-xpq3-8mch.json index a70a840a6ba..55ce82e8fa8 100644 --- a/advisories/unreviewed/2021/12/GHSA-jvq6-xpq3-8mch/GHSA-jvq6-xpq3-8mch.json +++ b/advisories/unreviewed/2021/12/GHSA-jvq6-xpq3-8mch/GHSA-jvq6-xpq3-8mch.json @@ -7,12 +7,8 @@ "CVE-2021-0956" ], "details": "In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-189942532", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jw96-2pwp-84xm/GHSA-jw96-2pwp-84xm.json b/advisories/unreviewed/2021/12/GHSA-jw96-2pwp-84xm/GHSA-jw96-2pwp-84xm.json index c5dec872ef6..21e06d15985 100644 --- a/advisories/unreviewed/2021/12/GHSA-jw96-2pwp-84xm/GHSA-jw96-2pwp-84xm.json +++ b/advisories/unreviewed/2021/12/GHSA-jw96-2pwp-84xm/GHSA-jw96-2pwp-84xm.json @@ -7,12 +7,8 @@ "CVE-2021-44434" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14902, ZDI-CAN-14866)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jx33-88wc-7x75/GHSA-jx33-88wc-7x75.json b/advisories/unreviewed/2021/12/GHSA-jx33-88wc-7x75/GHSA-jx33-88wc-7x75.json index fc7f12f3df3..fe6eaa50611 100644 --- a/advisories/unreviewed/2021/12/GHSA-jx33-88wc-7x75/GHSA-jx33-88wc-7x75.json +++ b/advisories/unreviewed/2021/12/GHSA-jx33-88wc-7x75/GHSA-jx33-88wc-7x75.json @@ -7,12 +7,8 @@ "CVE-2021-44023" ], "details": "A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jx9r-hrmg-9q76/GHSA-jx9r-hrmg-9q76.json b/advisories/unreviewed/2021/12/GHSA-jx9r-hrmg-9q76/GHSA-jx9r-hrmg-9q76.json index b88e80e3516..d361a47a127 100644 --- a/advisories/unreviewed/2021/12/GHSA-jx9r-hrmg-9q76/GHSA-jx9r-hrmg-9q76.json +++ b/advisories/unreviewed/2021/12/GHSA-jx9r-hrmg-9q76/GHSA-jx9r-hrmg-9q76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m3g9-6hxq-c8fj/GHSA-m3g9-6hxq-c8fj.json b/advisories/unreviewed/2021/12/GHSA-m3g9-6hxq-c8fj/GHSA-m3g9-6hxq-c8fj.json index c77d0cc77ff..8801ec4cdb4 100644 --- a/advisories/unreviewed/2021/12/GHSA-m3g9-6hxq-c8fj/GHSA-m3g9-6hxq-c8fj.json +++ b/advisories/unreviewed/2021/12/GHSA-m3g9-6hxq-c8fj/GHSA-m3g9-6hxq-c8fj.json @@ -7,12 +7,8 @@ "CVE-2021-26787" ], "details": "A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m3p6-3gv6-4226/GHSA-m3p6-3gv6-4226.json b/advisories/unreviewed/2021/12/GHSA-m3p6-3gv6-4226/GHSA-m3p6-3gv6-4226.json index 9dd9f8110ae..7be3b3be422 100644 --- a/advisories/unreviewed/2021/12/GHSA-m3p6-3gv6-4226/GHSA-m3p6-3gv6-4226.json +++ b/advisories/unreviewed/2021/12/GHSA-m3p6-3gv6-4226/GHSA-m3p6-3gv6-4226.json @@ -7,12 +7,8 @@ "CVE-2020-18984" ], "details": "A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m3vj-6h83-w76q/GHSA-m3vj-6h83-w76q.json b/advisories/unreviewed/2021/12/GHSA-m3vj-6h83-w76q/GHSA-m3vj-6h83-w76q.json index b929551b572..66a3501c176 100644 --- a/advisories/unreviewed/2021/12/GHSA-m3vj-6h83-w76q/GHSA-m3vj-6h83-w76q.json +++ b/advisories/unreviewed/2021/12/GHSA-m3vj-6h83-w76q/GHSA-m3vj-6h83-w76q.json @@ -7,12 +7,8 @@ "CVE-2021-0919" ], "details": "In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-197336441", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m42q-f292-m7wq/GHSA-m42q-f292-m7wq.json b/advisories/unreviewed/2021/12/GHSA-m42q-f292-m7wq/GHSA-m42q-f292-m7wq.json index 86688994f16..fc9f2393296 100644 --- a/advisories/unreviewed/2021/12/GHSA-m42q-f292-m7wq/GHSA-m42q-f292-m7wq.json +++ b/advisories/unreviewed/2021/12/GHSA-m42q-f292-m7wq/GHSA-m42q-f292-m7wq.json @@ -7,12 +7,8 @@ "CVE-2021-1003" ], "details": "In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189857506", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m4mf-6f9r-rfx5/GHSA-m4mf-6f9r-rfx5.json b/advisories/unreviewed/2021/12/GHSA-m4mf-6f9r-rfx5/GHSA-m4mf-6f9r-rfx5.json index a8ec2956627..f8d9663d7af 100644 --- a/advisories/unreviewed/2021/12/GHSA-m4mf-6f9r-rfx5/GHSA-m4mf-6f9r-rfx5.json +++ b/advisories/unreviewed/2021/12/GHSA-m4mf-6f9r-rfx5/GHSA-m4mf-6f9r-rfx5.json @@ -7,12 +7,8 @@ "CVE-2021-43908" ], "details": "Visual Studio Code Spoofing Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-m55v-8766-rh84/GHSA-m55v-8766-rh84.json b/advisories/unreviewed/2021/12/GHSA-m55v-8766-rh84/GHSA-m55v-8766-rh84.json index 69e5729afda..ec990938cf4 100644 --- a/advisories/unreviewed/2021/12/GHSA-m55v-8766-rh84/GHSA-m55v-8766-rh84.json +++ b/advisories/unreviewed/2021/12/GHSA-m55v-8766-rh84/GHSA-m55v-8766-rh84.json @@ -7,12 +7,8 @@ "CVE-2021-42024" ], "details": "A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < 2021.3.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m732-h63v-9gww/GHSA-m732-h63v-9gww.json b/advisories/unreviewed/2021/12/GHSA-m732-h63v-9gww/GHSA-m732-h63v-9gww.json index 72669ffd366..f7130368a1e 100644 --- a/advisories/unreviewed/2021/12/GHSA-m732-h63v-9gww/GHSA-m732-h63v-9gww.json +++ b/advisories/unreviewed/2021/12/GHSA-m732-h63v-9gww/GHSA-m732-h63v-9gww.json @@ -7,12 +7,8 @@ "CVE-2021-1039" ], "details": "In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182808318", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m7px-chfm-qxc5/GHSA-m7px-chfm-qxc5.json b/advisories/unreviewed/2021/12/GHSA-m7px-chfm-qxc5/GHSA-m7px-chfm-qxc5.json index 44d98ee3897..e7ea655f6df 100644 --- a/advisories/unreviewed/2021/12/GHSA-m7px-chfm-qxc5/GHSA-m7px-chfm-qxc5.json +++ b/advisories/unreviewed/2021/12/GHSA-m7px-chfm-qxc5/GHSA-m7px-chfm-qxc5.json @@ -7,12 +7,8 @@ "CVE-2021-38701" ], "details": "Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m9hw-3qvv-6hxr/GHSA-m9hw-3qvv-6hxr.json b/advisories/unreviewed/2021/12/GHSA-m9hw-3qvv-6hxr/GHSA-m9hw-3qvv-6hxr.json index f3aeac6e338..89ad243d202 100644 --- a/advisories/unreviewed/2021/12/GHSA-m9hw-3qvv-6hxr/GHSA-m9hw-3qvv-6hxr.json +++ b/advisories/unreviewed/2021/12/GHSA-m9hw-3qvv-6hxr/GHSA-m9hw-3qvv-6hxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m9vv-m88f-3xj8/GHSA-m9vv-m88f-3xj8.json b/advisories/unreviewed/2021/12/GHSA-m9vv-m88f-3xj8/GHSA-m9vv-m88f-3xj8.json index e7e3c8bba1b..febbb7fea47 100644 --- a/advisories/unreviewed/2021/12/GHSA-m9vv-m88f-3xj8/GHSA-m9vv-m88f-3xj8.json +++ b/advisories/unreviewed/2021/12/GHSA-m9vv-m88f-3xj8/GHSA-m9vv-m88f-3xj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mgq6-mjm8-39w4/GHSA-mgq6-mjm8-39w4.json b/advisories/unreviewed/2021/12/GHSA-mgq6-mjm8-39w4/GHSA-mgq6-mjm8-39w4.json index eb8d8acb7e0..ffbfa61d512 100644 --- a/advisories/unreviewed/2021/12/GHSA-mgq6-mjm8-39w4/GHSA-mgq6-mjm8-39w4.json +++ b/advisories/unreviewed/2021/12/GHSA-mgq6-mjm8-39w4/GHSA-mgq6-mjm8-39w4.json @@ -7,12 +7,8 @@ "CVE-2021-0954" ], "details": "In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-143559931", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mgxh-hxcr-38x2/GHSA-mgxh-hxcr-38x2.json b/advisories/unreviewed/2021/12/GHSA-mgxh-hxcr-38x2/GHSA-mgxh-hxcr-38x2.json index d088a012c7f..123dd18c9d8 100644 --- a/advisories/unreviewed/2021/12/GHSA-mgxh-hxcr-38x2/GHSA-mgxh-hxcr-38x2.json +++ b/advisories/unreviewed/2021/12/GHSA-mgxh-hxcr-38x2/GHSA-mgxh-hxcr-38x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-mpg5-6753-g2p4/GHSA-mpg5-6753-g2p4.json b/advisories/unreviewed/2021/12/GHSA-mpg5-6753-g2p4/GHSA-mpg5-6753-g2p4.json index 9e608bd8d10..2f4301db525 100644 --- a/advisories/unreviewed/2021/12/GHSA-mpg5-6753-g2p4/GHSA-mpg5-6753-g2p4.json +++ b/advisories/unreviewed/2021/12/GHSA-mpg5-6753-g2p4/GHSA-mpg5-6753-g2p4.json @@ -7,12 +7,8 @@ "CVE-2021-39308" ], "details": "The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientref parameter found in the ~/processresponse.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mpvr-2998-4q8g/GHSA-mpvr-2998-4q8g.json b/advisories/unreviewed/2021/12/GHSA-mpvr-2998-4q8g/GHSA-mpvr-2998-4q8g.json index 28a40d484ba..3a9f32f297f 100644 --- a/advisories/unreviewed/2021/12/GHSA-mpvr-2998-4q8g/GHSA-mpvr-2998-4q8g.json +++ b/advisories/unreviewed/2021/12/GHSA-mpvr-2998-4q8g/GHSA-mpvr-2998-4q8g.json @@ -7,12 +7,8 @@ "CVE-2021-44010" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to an out of bounds read past the end of an allocated buffer when parsing TIFF files. An attacker could leverage this vulnerability to leak information in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mw63-q92x-5p9w/GHSA-mw63-q92x-5p9w.json b/advisories/unreviewed/2021/12/GHSA-mw63-q92x-5p9w/GHSA-mw63-q92x-5p9w.json index 781083c0ec1..7675cc0ccdd 100644 --- a/advisories/unreviewed/2021/12/GHSA-mw63-q92x-5p9w/GHSA-mw63-q92x-5p9w.json +++ b/advisories/unreviewed/2021/12/GHSA-mw63-q92x-5p9w/GHSA-mw63-q92x-5p9w.json @@ -7,12 +7,8 @@ "CVE-2021-0976" ], "details": "In toBARK of floor0.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-199680600", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p462-h5xx-px29/GHSA-p462-h5xx-px29.json b/advisories/unreviewed/2021/12/GHSA-p462-h5xx-px29/GHSA-p462-h5xx-px29.json index e0dd4ab6a28..67a66141b3a 100644 --- a/advisories/unreviewed/2021/12/GHSA-p462-h5xx-px29/GHSA-p462-h5xx-px29.json +++ b/advisories/unreviewed/2021/12/GHSA-p462-h5xx-px29/GHSA-p462-h5xx-px29.json @@ -7,12 +7,8 @@ "CVE-2021-42022" ], "details": "A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading files, the affected systems do not properly neutralize special elements within the pathname. An attacker could then cause the pathname to resolve to a location outside of the restricted directory on the server and read unexpected critical files. The affected file download function is disabled by default.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json b/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json index 3a7bb2f6d37..9d6960e1222 100644 --- a/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json +++ b/advisories/unreviewed/2021/12/GHSA-p5c8-x5qh-v2mv/GHSA-p5c8-x5qh-v2mv.json @@ -7,12 +7,8 @@ "CVE-2021-43905" ], "details": "Microsoft Office app Remote Code Execution Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-pf4w-mhjv-g5wm/GHSA-pf4w-mhjv-g5wm.json b/advisories/unreviewed/2021/12/GHSA-pf4w-mhjv-g5wm/GHSA-pf4w-mhjv-g5wm.json index ef80a557b39..0d59ea5835e 100644 --- a/advisories/unreviewed/2021/12/GHSA-pf4w-mhjv-g5wm/GHSA-pf4w-mhjv-g5wm.json +++ b/advisories/unreviewed/2021/12/GHSA-pf4w-mhjv-g5wm/GHSA-pf4w-mhjv-g5wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pffm-c29w-9739/GHSA-pffm-c29w-9739.json b/advisories/unreviewed/2021/12/GHSA-pffm-c29w-9739/GHSA-pffm-c29w-9739.json index 7f6c1436a25..2d9f832f65f 100644 --- a/advisories/unreviewed/2021/12/GHSA-pffm-c29w-9739/GHSA-pffm-c29w-9739.json +++ b/advisories/unreviewed/2021/12/GHSA-pffm-c29w-9739/GHSA-pffm-c29w-9739.json @@ -7,12 +7,8 @@ "CVE-2021-44443" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15039)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pgqq-qj76-fffj/GHSA-pgqq-qj76-fffj.json b/advisories/unreviewed/2021/12/GHSA-pgqq-qj76-fffj/GHSA-pgqq-qj76-fffj.json index 2241a02b671..539e9c5888c 100644 --- a/advisories/unreviewed/2021/12/GHSA-pgqq-qj76-fffj/GHSA-pgqq-qj76-fffj.json +++ b/advisories/unreviewed/2021/12/GHSA-pgqq-qj76-fffj/GHSA-pgqq-qj76-fffj.json @@ -7,12 +7,8 @@ "CVE-2021-1030" ], "details": "In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194697001", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pjj9-7rm3-86j3/GHSA-pjj9-7rm3-86j3.json b/advisories/unreviewed/2021/12/GHSA-pjj9-7rm3-86j3/GHSA-pjj9-7rm3-86j3.json index 8adee1a0e2b..f2be2a8dbeb 100644 --- a/advisories/unreviewed/2021/12/GHSA-pjj9-7rm3-86j3/GHSA-pjj9-7rm3-86j3.json +++ b/advisories/unreviewed/2021/12/GHSA-pjj9-7rm3-86j3/GHSA-pjj9-7rm3-86j3.json @@ -7,12 +7,8 @@ "CVE-2021-0922" ], "details": "In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-195630721", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pq7c-f7ch-qfh7/GHSA-pq7c-f7ch-qfh7.json b/advisories/unreviewed/2021/12/GHSA-pq7c-f7ch-qfh7/GHSA-pq7c-f7ch-qfh7.json index e231f1fb21b..16477cd5cdd 100644 --- a/advisories/unreviewed/2021/12/GHSA-pq7c-f7ch-qfh7/GHSA-pq7c-f7ch-qfh7.json +++ b/advisories/unreviewed/2021/12/GHSA-pq7c-f7ch-qfh7/GHSA-pq7c-f7ch-qfh7.json @@ -7,12 +7,8 @@ "CVE-2021-43907" ], "details": "Visual Studio Code WSL Extension Remote Code Execution Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-pq93-2733-562x/GHSA-pq93-2733-562x.json b/advisories/unreviewed/2021/12/GHSA-pq93-2733-562x/GHSA-pq93-2733-562x.json index 0897d9bea45..bf0f1265e12 100644 --- a/advisories/unreviewed/2021/12/GHSA-pq93-2733-562x/GHSA-pq93-2733-562x.json +++ b/advisories/unreviewed/2021/12/GHSA-pq93-2733-562x/GHSA-pq93-2733-562x.json @@ -7,12 +7,8 @@ "CVE-2021-40170" ], "details": "An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30.20181117, allows an attacker to trigger arbitrary system functionality by replaying previously recorded signals. This lets an adversary, among other things, disarm an armed system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pr2c-95ww-2xr3/GHSA-pr2c-95ww-2xr3.json b/advisories/unreviewed/2021/12/GHSA-pr2c-95ww-2xr3/GHSA-pr2c-95ww-2xr3.json index 1ec596e4ac9..26387c39385 100644 --- a/advisories/unreviewed/2021/12/GHSA-pr2c-95ww-2xr3/GHSA-pr2c-95ww-2xr3.json +++ b/advisories/unreviewed/2021/12/GHSA-pr2c-95ww-2xr3/GHSA-pr2c-95ww-2xr3.json @@ -7,12 +7,8 @@ "CVE-2021-39315" ], "details": "The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-prj9-vfhq-9g4m/GHSA-prj9-vfhq-9g4m.json b/advisories/unreviewed/2021/12/GHSA-prj9-vfhq-9g4m/GHSA-prj9-vfhq-9g4m.json index a40c0b00a36..f0bba0e7e70 100644 --- a/advisories/unreviewed/2021/12/GHSA-prj9-vfhq-9g4m/GHSA-prj9-vfhq-9g4m.json +++ b/advisories/unreviewed/2021/12/GHSA-prj9-vfhq-9g4m/GHSA-prj9-vfhq-9g4m.json @@ -7,12 +7,8 @@ "CVE-2021-44447" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14911)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pxmq-rrfv-xh8v/GHSA-pxmq-rrfv-xh8v.json b/advisories/unreviewed/2021/12/GHSA-pxmq-rrfv-xh8v/GHSA-pxmq-rrfv-xh8v.json index 235a9a29c61..400f00bbca5 100644 --- a/advisories/unreviewed/2021/12/GHSA-pxmq-rrfv-xh8v/GHSA-pxmq-rrfv-xh8v.json +++ b/advisories/unreviewed/2021/12/GHSA-pxmq-rrfv-xh8v/GHSA-pxmq-rrfv-xh8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q23q-8cgx-c4v7/GHSA-q23q-8cgx-c4v7.json b/advisories/unreviewed/2021/12/GHSA-q23q-8cgx-c4v7/GHSA-q23q-8cgx-c4v7.json index 1648c1691e8..fe5213b7e6c 100644 --- a/advisories/unreviewed/2021/12/GHSA-q23q-8cgx-c4v7/GHSA-q23q-8cgx-c4v7.json +++ b/advisories/unreviewed/2021/12/GHSA-q23q-8cgx-c4v7/GHSA-q23q-8cgx-c4v7.json @@ -7,12 +7,8 @@ "CVE-2021-3179" ], "details": "GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q33m-rrqm-6xhw/GHSA-q33m-rrqm-6xhw.json b/advisories/unreviewed/2021/12/GHSA-q33m-rrqm-6xhw/GHSA-q33m-rrqm-6xhw.json index 0a3a7591801..1ae81e8bd26 100644 --- a/advisories/unreviewed/2021/12/GHSA-q33m-rrqm-6xhw/GHSA-q33m-rrqm-6xhw.json +++ b/advisories/unreviewed/2021/12/GHSA-q33m-rrqm-6xhw/GHSA-q33m-rrqm-6xhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q5pv-569g-3p96/GHSA-q5pv-569g-3p96.json b/advisories/unreviewed/2021/12/GHSA-q5pv-569g-3p96/GHSA-q5pv-569g-3p96.json index 94f56ae5090..89f8c04b516 100644 --- a/advisories/unreviewed/2021/12/GHSA-q5pv-569g-3p96/GHSA-q5pv-569g-3p96.json +++ b/advisories/unreviewed/2021/12/GHSA-q5pv-569g-3p96/GHSA-q5pv-569g-3p96.json @@ -7,12 +7,8 @@ "CVE-2021-44008" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to an out of bounds read past the end of an allocated buffer when parsing TIFF files. An attacker could leverage this vulnerability to leak information in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q8m7-5gp8-mgvg/GHSA-q8m7-5gp8-mgvg.json b/advisories/unreviewed/2021/12/GHSA-q8m7-5gp8-mgvg/GHSA-q8m7-5gp8-mgvg.json index 42fb00bbe30..38b92d94597 100644 --- a/advisories/unreviewed/2021/12/GHSA-q8m7-5gp8-mgvg/GHSA-q8m7-5gp8-mgvg.json +++ b/advisories/unreviewed/2021/12/GHSA-q8m7-5gp8-mgvg/GHSA-q8m7-5gp8-mgvg.json @@ -7,12 +7,8 @@ "CVE-2021-39314" ], "details": "The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter found in the ~/includes/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qcf6-6wf2-xmxg/GHSA-qcf6-6wf2-xmxg.json b/advisories/unreviewed/2021/12/GHSA-qcf6-6wf2-xmxg/GHSA-qcf6-6wf2-xmxg.json index 1c4a11613fa..da832efad13 100644 --- a/advisories/unreviewed/2021/12/GHSA-qcf6-6wf2-xmxg/GHSA-qcf6-6wf2-xmxg.json +++ b/advisories/unreviewed/2021/12/GHSA-qcf6-6wf2-xmxg/GHSA-qcf6-6wf2-xmxg.json @@ -7,12 +7,8 @@ "CVE-2021-0953" ], "details": "In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-184046278", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qf34-j4vq-q329/GHSA-qf34-j4vq-q329.json b/advisories/unreviewed/2021/12/GHSA-qf34-j4vq-q329/GHSA-qf34-j4vq-q329.json index dcede8d1872..e07986c7867 100644 --- a/advisories/unreviewed/2021/12/GHSA-qf34-j4vq-q329/GHSA-qf34-j4vq-q329.json +++ b/advisories/unreviewed/2021/12/GHSA-qf34-j4vq-q329/GHSA-qf34-j4vq-q329.json @@ -7,12 +7,8 @@ "CVE-2021-42027" ], "details": "A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly validate the server certificate when initiating a TLS connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between the client and the intended server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qfw2-4mg3-rwff/GHSA-qfw2-4mg3-rwff.json b/advisories/unreviewed/2021/12/GHSA-qfw2-4mg3-rwff/GHSA-qfw2-4mg3-rwff.json index a6c8a1d8f41..af9dce4c9ea 100644 --- a/advisories/unreviewed/2021/12/GHSA-qfw2-4mg3-rwff/GHSA-qfw2-4mg3-rwff.json +++ b/advisories/unreviewed/2021/12/GHSA-qfw2-4mg3-rwff/GHSA-qfw2-4mg3-rwff.json @@ -7,12 +7,8 @@ "CVE-2021-37262" ], "details": "JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qmgp-p6v2-662h/GHSA-qmgp-p6v2-662h.json b/advisories/unreviewed/2021/12/GHSA-qmgp-p6v2-662h/GHSA-qmgp-p6v2-662h.json index 6d7368f2dac..d79c14dd854 100644 --- a/advisories/unreviewed/2021/12/GHSA-qmgp-p6v2-662h/GHSA-qmgp-p6v2-662h.json +++ b/advisories/unreviewed/2021/12/GHSA-qmgp-p6v2-662h/GHSA-qmgp-p6v2-662h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qq94-59f9-hxxm/GHSA-qq94-59f9-hxxm.json b/advisories/unreviewed/2021/12/GHSA-qq94-59f9-hxxm/GHSA-qq94-59f9-hxxm.json index 2123709ec5a..7956244a861 100644 --- a/advisories/unreviewed/2021/12/GHSA-qq94-59f9-hxxm/GHSA-qq94-59f9-hxxm.json +++ b/advisories/unreviewed/2021/12/GHSA-qq94-59f9-hxxm/GHSA-qq94-59f9-hxxm.json @@ -7,12 +7,8 @@ "CVE-2021-39311" ], "details": "The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found in the ~/llm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qvw4-2wj5-3r5w/GHSA-qvw4-2wj5-3r5w.json b/advisories/unreviewed/2021/12/GHSA-qvw4-2wj5-3r5w/GHSA-qvw4-2wj5-3r5w.json index 3a4e8b2bbe1..dfc022932cd 100644 --- a/advisories/unreviewed/2021/12/GHSA-qvw4-2wj5-3r5w/GHSA-qvw4-2wj5-3r5w.json +++ b/advisories/unreviewed/2021/12/GHSA-qvw4-2wj5-3r5w/GHSA-qvw4-2wj5-3r5w.json @@ -7,12 +7,8 @@ "CVE-2021-44446" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14828, ZDI-CAN-14898)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json b/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json index 35ca1ce70ec..2b31d14811f 100644 --- a/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json +++ b/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r22f-rmv4-8q7h/GHSA-r22f-rmv4-8q7h.json b/advisories/unreviewed/2021/12/GHSA-r22f-rmv4-8q7h/GHSA-r22f-rmv4-8q7h.json index 3734bee00b3..4c294abd6e7 100644 --- a/advisories/unreviewed/2021/12/GHSA-r22f-rmv4-8q7h/GHSA-r22f-rmv4-8q7h.json +++ b/advisories/unreviewed/2021/12/GHSA-r22f-rmv4-8q7h/GHSA-r22f-rmv4-8q7h.json @@ -7,12 +7,8 @@ "CVE-2021-0997" ], "details": "In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191086488", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r39r-c554-xv77/GHSA-r39r-c554-xv77.json b/advisories/unreviewed/2021/12/GHSA-r39r-c554-xv77/GHSA-r39r-c554-xv77.json index d3647449a85..0c9c97f2f4d 100644 --- a/advisories/unreviewed/2021/12/GHSA-r39r-c554-xv77/GHSA-r39r-c554-xv77.json +++ b/advisories/unreviewed/2021/12/GHSA-r39r-c554-xv77/GHSA-r39r-c554-xv77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r3vg-939c-2mrm/GHSA-r3vg-939c-2mrm.json b/advisories/unreviewed/2021/12/GHSA-r3vg-939c-2mrm/GHSA-r3vg-939c-2mrm.json index bd9aed2b76b..f0851823f88 100644 --- a/advisories/unreviewed/2021/12/GHSA-r3vg-939c-2mrm/GHSA-r3vg-939c-2mrm.json +++ b/advisories/unreviewed/2021/12/GHSA-r3vg-939c-2mrm/GHSA-r3vg-939c-2mrm.json @@ -7,12 +7,8 @@ "CVE-2021-4007" ], "details": "Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at \"C:\\DLLs\\python3.dll,\" which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 3.1.2.35. This vulnerability is a regression of CVE-2019-5629.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r535-rfwp-fm57/GHSA-r535-rfwp-fm57.json b/advisories/unreviewed/2021/12/GHSA-r535-rfwp-fm57/GHSA-r535-rfwp-fm57.json index 244b08d5d33..cb34776a266 100644 --- a/advisories/unreviewed/2021/12/GHSA-r535-rfwp-fm57/GHSA-r535-rfwp-fm57.json +++ b/advisories/unreviewed/2021/12/GHSA-r535-rfwp-fm57/GHSA-r535-rfwp-fm57.json @@ -7,12 +7,8 @@ "CVE-2021-1048" ], "details": "In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r5v3-6r2m-ww8f/GHSA-r5v3-6r2m-ww8f.json b/advisories/unreviewed/2021/12/GHSA-r5v3-6r2m-ww8f/GHSA-r5v3-6r2m-ww8f.json index 5dbc91fe9c3..4c6ce96d4af 100644 --- a/advisories/unreviewed/2021/12/GHSA-r5v3-6r2m-ww8f/GHSA-r5v3-6r2m-ww8f.json +++ b/advisories/unreviewed/2021/12/GHSA-r5v3-6r2m-ww8f/GHSA-r5v3-6r2m-ww8f.json @@ -7,12 +7,8 @@ "CVE-2021-1018" ], "details": "In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194110891", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r87m-52m7-4wpg/GHSA-r87m-52m7-4wpg.json b/advisories/unreviewed/2021/12/GHSA-r87m-52m7-4wpg/GHSA-r87m-52m7-4wpg.json index 8f5eba82c66..7d2fc5e48d1 100644 --- a/advisories/unreviewed/2021/12/GHSA-r87m-52m7-4wpg/GHSA-r87m-52m7-4wpg.json +++ b/advisories/unreviewed/2021/12/GHSA-r87m-52m7-4wpg/GHSA-r87m-52m7-4wpg.json @@ -7,12 +7,8 @@ "CVE-2021-42050" ], "details": "An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-r945-wx68-4j73/GHSA-r945-wx68-4j73.json b/advisories/unreviewed/2021/12/GHSA-r945-wx68-4j73/GHSA-r945-wx68-4j73.json index 66f431bc2e7..2c08aa09279 100644 --- a/advisories/unreviewed/2021/12/GHSA-r945-wx68-4j73/GHSA-r945-wx68-4j73.json +++ b/advisories/unreviewed/2021/12/GHSA-r945-wx68-4j73/GHSA-r945-wx68-4j73.json @@ -7,12 +7,8 @@ "CVE-2021-39637" ], "details": "In CreateDeviceInfo of trusty_remote_provisioning_context.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-193579873References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rcrg-grjr-gmc3/GHSA-rcrg-grjr-gmc3.json b/advisories/unreviewed/2021/12/GHSA-rcrg-grjr-gmc3/GHSA-rcrg-grjr-gmc3.json index c4ef93ef1e1..afc3566364a 100644 --- a/advisories/unreviewed/2021/12/GHSA-rcrg-grjr-gmc3/GHSA-rcrg-grjr-gmc3.json +++ b/advisories/unreviewed/2021/12/GHSA-rcrg-grjr-gmc3/GHSA-rcrg-grjr-gmc3.json @@ -7,12 +7,8 @@ "CVE-2021-44009" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to an out of bounds read past the end of an allocated buffer when parsing TIFF files. An attacker could leverage this vulnerability to leak information in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rg3w-x342-7q53/GHSA-rg3w-x342-7q53.json b/advisories/unreviewed/2021/12/GHSA-rg3w-x342-7q53/GHSA-rg3w-x342-7q53.json index d2674f5a8ec..518e72b4a7f 100644 --- a/advisories/unreviewed/2021/12/GHSA-rg3w-x342-7q53/GHSA-rg3w-x342-7q53.json +++ b/advisories/unreviewed/2021/12/GHSA-rg3w-x342-7q53/GHSA-rg3w-x342-7q53.json @@ -7,12 +7,8 @@ "CVE-2021-0952" ], "details": "In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-195748381", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-rgr9-47fx-rg94/GHSA-rgr9-47fx-rg94.json b/advisories/unreviewed/2021/12/GHSA-rgr9-47fx-rg94/GHSA-rgr9-47fx-rg94.json index fe4a0076d43..d4308b9e9ee 100644 --- a/advisories/unreviewed/2021/12/GHSA-rgr9-47fx-rg94/GHSA-rgr9-47fx-rg94.json +++ b/advisories/unreviewed/2021/12/GHSA-rgr9-47fx-rg94/GHSA-rgr9-47fx-rg94.json @@ -7,12 +7,8 @@ "CVE-2021-1024" ], "details": "In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191283525", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-rh4p-q5vg-f37m/GHSA-rh4p-q5vg-f37m.json b/advisories/unreviewed/2021/12/GHSA-rh4p-q5vg-f37m/GHSA-rh4p-q5vg-f37m.json index aabf87f0377..fd06061239a 100644 --- a/advisories/unreviewed/2021/12/GHSA-rh4p-q5vg-f37m/GHSA-rh4p-q5vg-f37m.json +++ b/advisories/unreviewed/2021/12/GHSA-rh4p-q5vg-f37m/GHSA-rh4p-q5vg-f37m.json @@ -7,12 +7,8 @@ "CVE-2021-1047" ], "details": "In valid_ipc_dram_addr of cm_access_control.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197966306References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rh4x-ccvq-jc34/GHSA-rh4x-ccvq-jc34.json b/advisories/unreviewed/2021/12/GHSA-rh4x-ccvq-jc34/GHSA-rh4x-ccvq-jc34.json index d5863ded902..23878dcce77 100644 --- a/advisories/unreviewed/2021/12/GHSA-rh4x-ccvq-jc34/GHSA-rh4x-ccvq-jc34.json +++ b/advisories/unreviewed/2021/12/GHSA-rh4x-ccvq-jc34/GHSA-rh4x-ccvq-jc34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rpgq-c954-jmg6/GHSA-rpgq-c954-jmg6.json b/advisories/unreviewed/2021/12/GHSA-rpgq-c954-jmg6/GHSA-rpgq-c954-jmg6.json index 5ebe3e82423..3aa60f26421 100644 --- a/advisories/unreviewed/2021/12/GHSA-rpgq-c954-jmg6/GHSA-rpgq-c954-jmg6.json +++ b/advisories/unreviewed/2021/12/GHSA-rpgq-c954-jmg6/GHSA-rpgq-c954-jmg6.json @@ -7,12 +7,8 @@ "CVE-2021-39657" ], "details": "In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rqm9-c34w-wvxq/GHSA-rqm9-c34w-wvxq.json b/advisories/unreviewed/2021/12/GHSA-rqm9-c34w-wvxq/GHSA-rqm9-c34w-wvxq.json index 5adf44a2895..5be28382d06 100644 --- a/advisories/unreviewed/2021/12/GHSA-rqm9-c34w-wvxq/GHSA-rqm9-c34w-wvxq.json +++ b/advisories/unreviewed/2021/12/GHSA-rqm9-c34w-wvxq/GHSA-rqm9-c34w-wvxq.json @@ -7,12 +7,8 @@ "CVE-2021-1041" ], "details": "In (TBD) of (TBD), there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-182950799References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rwp6-cpw3-hxxx/GHSA-rwp6-cpw3-hxxx.json b/advisories/unreviewed/2021/12/GHSA-rwp6-cpw3-hxxx/GHSA-rwp6-cpw3-hxxx.json index c91841bebbc..5dd7e292fb7 100644 --- a/advisories/unreviewed/2021/12/GHSA-rwp6-cpw3-hxxx/GHSA-rwp6-cpw3-hxxx.json +++ b/advisories/unreviewed/2021/12/GHSA-rwp6-cpw3-hxxx/GHSA-rwp6-cpw3-hxxx.json @@ -7,12 +7,8 @@ "CVE-2021-44165" ], "details": "A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41). The affected firmware contains a buffer overflow vulnerability in the web application that could allow a remote attacker with engineer or admin priviliges to potentially perform remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rxvx-2jq5-pc48/GHSA-rxvx-2jq5-pc48.json b/advisories/unreviewed/2021/12/GHSA-rxvx-2jq5-pc48/GHSA-rxvx-2jq5-pc48.json index fc2d27c444c..7b7c1e7121c 100644 --- a/advisories/unreviewed/2021/12/GHSA-rxvx-2jq5-pc48/GHSA-rxvx-2jq5-pc48.json +++ b/advisories/unreviewed/2021/12/GHSA-rxvx-2jq5-pc48/GHSA-rxvx-2jq5-pc48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-v7v2-vp57-589m/GHSA-v7v2-vp57-589m.json b/advisories/unreviewed/2021/12/GHSA-v7v2-vp57-589m/GHSA-v7v2-vp57-589m.json index 426c9729419..7bcf62ab6b6 100644 --- a/advisories/unreviewed/2021/12/GHSA-v7v2-vp57-589m/GHSA-v7v2-vp57-589m.json +++ b/advisories/unreviewed/2021/12/GHSA-v7v2-vp57-589m/GHSA-v7v2-vp57-589m.json @@ -7,12 +7,8 @@ "CVE-2019-19138" ], "details": "Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-v8h7-57p4-wr4f/GHSA-v8h7-57p4-wr4f.json b/advisories/unreviewed/2021/12/GHSA-v8h7-57p4-wr4f/GHSA-v8h7-57p4-wr4f.json index 1a3b5a8f4bb..70ef435aa19 100644 --- a/advisories/unreviewed/2021/12/GHSA-v8h7-57p4-wr4f/GHSA-v8h7-57p4-wr4f.json +++ b/advisories/unreviewed/2021/12/GHSA-v8h7-57p4-wr4f/GHSA-v8h7-57p4-wr4f.json @@ -7,12 +7,8 @@ "CVE-2021-1021" ], "details": "In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195031703", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-v93v-fxgx-33qf/GHSA-v93v-fxgx-33qf.json b/advisories/unreviewed/2021/12/GHSA-v93v-fxgx-33qf/GHSA-v93v-fxgx-33qf.json index 6f214d91c5b..9e1b4f2ffb0 100644 --- a/advisories/unreviewed/2021/12/GHSA-v93v-fxgx-33qf/GHSA-v93v-fxgx-33qf.json +++ b/advisories/unreviewed/2021/12/GHSA-v93v-fxgx-33qf/GHSA-v93v-fxgx-33qf.json @@ -7,12 +7,8 @@ "CVE-2021-1016" ], "details": "In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-183610267", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vf79-gh76-r26h/GHSA-vf79-gh76-r26h.json b/advisories/unreviewed/2021/12/GHSA-vf79-gh76-r26h/GHSA-vf79-gh76-r26h.json index f5901b66f40..f59e17e3444 100644 --- a/advisories/unreviewed/2021/12/GHSA-vf79-gh76-r26h/GHSA-vf79-gh76-r26h.json +++ b/advisories/unreviewed/2021/12/GHSA-vf79-gh76-r26h/GHSA-vf79-gh76-r26h.json @@ -7,12 +7,8 @@ "CVE-2021-38361" ], "details": "The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in the ~/htaccess-redirect.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.3.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vm48-354f-2w7j/GHSA-vm48-354f-2w7j.json b/advisories/unreviewed/2021/12/GHSA-vm48-354f-2w7j/GHSA-vm48-354f-2w7j.json index 7cbf80ef3c3..fe45d0482dd 100644 --- a/advisories/unreviewed/2021/12/GHSA-vm48-354f-2w7j/GHSA-vm48-354f-2w7j.json +++ b/advisories/unreviewed/2021/12/GHSA-vm48-354f-2w7j/GHSA-vm48-354f-2w7j.json @@ -7,12 +7,8 @@ "CVE-2021-0995" ], "details": "In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197536547", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vp4x-j24m-6jjq/GHSA-vp4x-j24m-6jjq.json b/advisories/unreviewed/2021/12/GHSA-vp4x-j24m-6jjq/GHSA-vp4x-j24m-6jjq.json index 505dbf513f8..daf13337096 100644 --- a/advisories/unreviewed/2021/12/GHSA-vp4x-j24m-6jjq/GHSA-vp4x-j24m-6jjq.json +++ b/advisories/unreviewed/2021/12/GHSA-vp4x-j24m-6jjq/GHSA-vp4x-j24m-6jjq.json @@ -7,12 +7,8 @@ "CVE-2021-44431" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14841)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vq7q-g9c7-hj87/GHSA-vq7q-g9c7-hj87.json b/advisories/unreviewed/2021/12/GHSA-vq7q-g9c7-hj87/GHSA-vq7q-g9c7-hj87.json index 5ada1242f23..7e074838531 100644 --- a/advisories/unreviewed/2021/12/GHSA-vq7q-g9c7-hj87/GHSA-vq7q-g9c7-hj87.json +++ b/advisories/unreviewed/2021/12/GHSA-vq7q-g9c7-hj87/GHSA-vq7q-g9c7-hj87.json @@ -7,12 +7,8 @@ "CVE-2021-1042" ], "details": "In dsi_panel_debugfs_read_cmdset of dsi_panel.c, there is a possible disclosure of freed kernel heap memory due to a use after free. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-187851056References: N/A", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vr7j-j9jw-pjj7/GHSA-vr7j-j9jw-pjj7.json b/advisories/unreviewed/2021/12/GHSA-vr7j-j9jw-pjj7/GHSA-vr7j-j9jw-pjj7.json index 66c2a00d4ec..6e65c1b5123 100644 --- a/advisories/unreviewed/2021/12/GHSA-vr7j-j9jw-pjj7/GHSA-vr7j-j9jw-pjj7.json +++ b/advisories/unreviewed/2021/12/GHSA-vr7j-j9jw-pjj7/GHSA-vr7j-j9jw-pjj7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vv73-f455-9crg/GHSA-vv73-f455-9crg.json b/advisories/unreviewed/2021/12/GHSA-vv73-f455-9crg/GHSA-vv73-f455-9crg.json index 1a96c24d957..70e45d667f9 100644 --- a/advisories/unreviewed/2021/12/GHSA-vv73-f455-9crg/GHSA-vv73-f455-9crg.json +++ b/advisories/unreviewed/2021/12/GHSA-vv73-f455-9crg/GHSA-vv73-f455-9crg.json @@ -7,12 +7,8 @@ "CVE-2021-44435" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to stack based buffer overflow while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14903)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vv96-jq6f-v366/GHSA-vv96-jq6f-v366.json b/advisories/unreviewed/2021/12/GHSA-vv96-jq6f-v366/GHSA-vv96-jq6f-v366.json index a1e3cf88eeb..2c18292b98c 100644 --- a/advisories/unreviewed/2021/12/GHSA-vv96-jq6f-v366/GHSA-vv96-jq6f-v366.json +++ b/advisories/unreviewed/2021/12/GHSA-vv96-jq6f-v366/GHSA-vv96-jq6f-v366.json @@ -7,12 +7,8 @@ "CVE-2021-45086" ], "details": "XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vx4g-4h4f-5cmg/GHSA-vx4g-4h4f-5cmg.json b/advisories/unreviewed/2021/12/GHSA-vx4g-4h4f-5cmg/GHSA-vx4g-4h4f-5cmg.json index c82cc1ec0a1..fbfa41cd417 100644 --- a/advisories/unreviewed/2021/12/GHSA-vx4g-4h4f-5cmg/GHSA-vx4g-4h4f-5cmg.json +++ b/advisories/unreviewed/2021/12/GHSA-vx4g-4h4f-5cmg/GHSA-vx4g-4h4f-5cmg.json @@ -7,12 +7,8 @@ "CVE-2021-0923" ], "details": "In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195338390", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-vxh6-3w55-j34c/GHSA-vxh6-3w55-j34c.json b/advisories/unreviewed/2021/12/GHSA-vxh6-3w55-j34c/GHSA-vxh6-3w55-j34c.json index 20a2c3ee85f..8e890ab3eb7 100644 --- a/advisories/unreviewed/2021/12/GHSA-vxh6-3w55-j34c/GHSA-vxh6-3w55-j34c.json +++ b/advisories/unreviewed/2021/12/GHSA-vxh6-3w55-j34c/GHSA-vxh6-3w55-j34c.json @@ -7,12 +7,8 @@ "CVE-2021-43243" ], "details": "VP9 Video Extensions Information Disclosure Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-w4mm-46pm-fmvh/GHSA-w4mm-46pm-fmvh.json b/advisories/unreviewed/2021/12/GHSA-w4mm-46pm-fmvh/GHSA-w4mm-46pm-fmvh.json index 194de4b7fa7..382dd6a877c 100644 --- a/advisories/unreviewed/2021/12/GHSA-w4mm-46pm-fmvh/GHSA-w4mm-46pm-fmvh.json +++ b/advisories/unreviewed/2021/12/GHSA-w4mm-46pm-fmvh/GHSA-w4mm-46pm-fmvh.json @@ -7,12 +7,8 @@ "CVE-2021-0969" ], "details": "In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check. This could lead to remote denial of service if a proximal Wi-Fi AP provides invalid information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-199922685", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-w8c2-mp5p-9g9q/GHSA-w8c2-mp5p-9g9q.json b/advisories/unreviewed/2021/12/GHSA-w8c2-mp5p-9g9q/GHSA-w8c2-mp5p-9g9q.json index f9461f045d6..9905ff93043 100644 --- a/advisories/unreviewed/2021/12/GHSA-w8c2-mp5p-9g9q/GHSA-w8c2-mp5p-9g9q.json +++ b/advisories/unreviewed/2021/12/GHSA-w8c2-mp5p-9g9q/GHSA-w8c2-mp5p-9g9q.json @@ -7,12 +7,8 @@ "CVE-2021-44437" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14906)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wf58-48gj-3f44/GHSA-wf58-48gj-3f44.json b/advisories/unreviewed/2021/12/GHSA-wf58-48gj-3f44/GHSA-wf58-48gj-3f44.json index 3ad925010c5..239a3127482 100644 --- a/advisories/unreviewed/2021/12/GHSA-wf58-48gj-3f44/GHSA-wf58-48gj-3f44.json +++ b/advisories/unreviewed/2021/12/GHSA-wf58-48gj-3f44/GHSA-wf58-48gj-3f44.json @@ -7,12 +7,8 @@ "CVE-2021-44523" ], "details": "A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wgcg-wpg9-jq43/GHSA-wgcg-wpg9-jq43.json b/advisories/unreviewed/2021/12/GHSA-wgcg-wpg9-jq43/GHSA-wgcg-wpg9-jq43.json index 9046a173ccf..35d87d88eef 100644 --- a/advisories/unreviewed/2021/12/GHSA-wgcg-wpg9-jq43/GHSA-wgcg-wpg9-jq43.json +++ b/advisories/unreviewed/2021/12/GHSA-wgcg-wpg9-jq43/GHSA-wgcg-wpg9-jq43.json @@ -7,12 +7,8 @@ "CVE-2021-27857" ], "details": "A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA003.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wjr4-fpmr-3p4f/GHSA-wjr4-fpmr-3p4f.json b/advisories/unreviewed/2021/12/GHSA-wjr4-fpmr-3p4f/GHSA-wjr4-fpmr-3p4f.json index 91731216824..daea3be035c 100644 --- a/advisories/unreviewed/2021/12/GHSA-wjr4-fpmr-3p4f/GHSA-wjr4-fpmr-3p4f.json +++ b/advisories/unreviewed/2021/12/GHSA-wjr4-fpmr-3p4f/GHSA-wjr4-fpmr-3p4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wp8c-5j7q-j666/GHSA-wp8c-5j7q-j666.json b/advisories/unreviewed/2021/12/GHSA-wp8c-5j7q-j666/GHSA-wp8c-5j7q-j666.json index 972ce21f23f..49f0823fc5d 100644 --- a/advisories/unreviewed/2021/12/GHSA-wp8c-5j7q-j666/GHSA-wp8c-5j7q-j666.json +++ b/advisories/unreviewed/2021/12/GHSA-wp8c-5j7q-j666/GHSA-wp8c-5j7q-j666.json @@ -7,12 +7,8 @@ "CVE-2021-44445" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15054)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wphx-qm9g-v53m/GHSA-wphx-qm9g-v53m.json b/advisories/unreviewed/2021/12/GHSA-wphx-qm9g-v53m/GHSA-wphx-qm9g-v53m.json index 690e1c15fa8..9ac18e5ad93 100644 --- a/advisories/unreviewed/2021/12/GHSA-wphx-qm9g-v53m/GHSA-wphx-qm9g-v53m.json +++ b/advisories/unreviewed/2021/12/GHSA-wphx-qm9g-v53m/GHSA-wphx-qm9g-v53m.json @@ -7,12 +7,8 @@ "CVE-2021-45043" ], "details": "HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wv3w-fcvm-p52v/GHSA-wv3w-fcvm-p52v.json b/advisories/unreviewed/2021/12/GHSA-wv3w-fcvm-p52v/GHSA-wv3w-fcvm-p52v.json index f283f107ba8..d43bfe99e58 100644 --- a/advisories/unreviewed/2021/12/GHSA-wv3w-fcvm-p52v/GHSA-wv3w-fcvm-p52v.json +++ b/advisories/unreviewed/2021/12/GHSA-wv3w-fcvm-p52v/GHSA-wv3w-fcvm-p52v.json @@ -7,12 +7,8 @@ "CVE-2021-44522" ], "details": "A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal message broker system. This could allow an unauthenticated remote attacker to subscribe to arbitrary message queues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wv8m-chcw-6w78/GHSA-wv8m-chcw-6w78.json b/advisories/unreviewed/2021/12/GHSA-wv8m-chcw-6w78/GHSA-wv8m-chcw-6w78.json index b6b9b7fcf5d..ccb5d4e4e1f 100644 --- a/advisories/unreviewed/2021/12/GHSA-wv8m-chcw-6w78/GHSA-wv8m-chcw-6w78.json +++ b/advisories/unreviewed/2021/12/GHSA-wv8m-chcw-6w78/GHSA-wv8m-chcw-6w78.json @@ -7,12 +7,8 @@ "CVE-2021-27858" ], "details": "A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL \"/fpui/jsp/index.jsp\" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wvxh-xchr-m6p5/GHSA-wvxh-xchr-m6p5.json b/advisories/unreviewed/2021/12/GHSA-wvxh-xchr-m6p5/GHSA-wvxh-xchr-m6p5.json index 0274927f736..3eca9330ca2 100644 --- a/advisories/unreviewed/2021/12/GHSA-wvxh-xchr-m6p5/GHSA-wvxh-xchr-m6p5.json +++ b/advisories/unreviewed/2021/12/GHSA-wvxh-xchr-m6p5/GHSA-wvxh-xchr-m6p5.json @@ -7,12 +7,8 @@ "CVE-2021-0988" ], "details": "In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191954233", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wwgj-pf6c-p6hc/GHSA-wwgj-pf6c-p6hc.json b/advisories/unreviewed/2021/12/GHSA-wwgj-pf6c-p6hc/GHSA-wwgj-pf6c-p6hc.json index bc916a07f96..001549e1a9e 100644 --- a/advisories/unreviewed/2021/12/GHSA-wwgj-pf6c-p6hc/GHSA-wwgj-pf6c-p6hc.json +++ b/advisories/unreviewed/2021/12/GHSA-wwgj-pf6c-p6hc/GHSA-wwgj-pf6c-p6hc.json @@ -7,12 +7,8 @@ "CVE-2021-45102" ], "details": "An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x3gh-j7gq-pr86/GHSA-x3gh-j7gq-pr86.json b/advisories/unreviewed/2021/12/GHSA-x3gh-j7gq-pr86/GHSA-x3gh-j7gq-pr86.json index ec6419cb0bb..5334ad5ac50 100644 --- a/advisories/unreviewed/2021/12/GHSA-x3gh-j7gq-pr86/GHSA-x3gh-j7gq-pr86.json +++ b/advisories/unreviewed/2021/12/GHSA-x3gh-j7gq-pr86/GHSA-x3gh-j7gq-pr86.json @@ -7,12 +7,8 @@ "CVE-2021-44449" ], "details": "A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14830)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x4h8-mfxr-8358/GHSA-x4h8-mfxr-8358.json b/advisories/unreviewed/2021/12/GHSA-x4h8-mfxr-8358/GHSA-x4h8-mfxr-8358.json index 9cd9d598de0..01b011b2e68 100644 --- a/advisories/unreviewed/2021/12/GHSA-x4h8-mfxr-8358/GHSA-x4h8-mfxr-8358.json +++ b/advisories/unreviewed/2021/12/GHSA-x4h8-mfxr-8358/GHSA-x4h8-mfxr-8358.json @@ -7,12 +7,8 @@ "CVE-2021-44004" ], "details": "A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to an out of bounds read past the end of an allocated buffer when parsing TIFF files. An attacker could leverage this vulnerability to leak information in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x4wg-w7pm-7f26/GHSA-x4wg-w7pm-7f26.json b/advisories/unreviewed/2021/12/GHSA-x4wg-w7pm-7f26/GHSA-x4wg-w7pm-7f26.json index 036f06b3027..0054c7af509 100644 --- a/advisories/unreviewed/2021/12/GHSA-x4wg-w7pm-7f26/GHSA-x4wg-w7pm-7f26.json +++ b/advisories/unreviewed/2021/12/GHSA-x4wg-w7pm-7f26/GHSA-x4wg-w7pm-7f26.json @@ -7,12 +7,8 @@ "CVE-2021-41547" ], "details": "A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3). The application contains an unsafe unzipping pattern that could lead to a zip path traversal attack. This could allow and attacker to execute a remote shell with admin rights.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x5f4-jxc9-j6mv/GHSA-x5f4-jxc9-j6mv.json b/advisories/unreviewed/2021/12/GHSA-x5f4-jxc9-j6mv/GHSA-x5f4-jxc9-j6mv.json index e33a903c598..b99be19139c 100644 --- a/advisories/unreviewed/2021/12/GHSA-x5f4-jxc9-j6mv/GHSA-x5f4-jxc9-j6mv.json +++ b/advisories/unreviewed/2021/12/GHSA-x5f4-jxc9-j6mv/GHSA-x5f4-jxc9-j6mv.json @@ -7,12 +7,8 @@ "CVE-2021-43255" ], "details": "Microsoft Office Trust Center Spoofing Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-x5f7-m6j9-3793/GHSA-x5f7-m6j9-3793.json b/advisories/unreviewed/2021/12/GHSA-x5f7-m6j9-3793/GHSA-x5f7-m6j9-3793.json index bd27a32d9d4..01d36f9792b 100644 --- a/advisories/unreviewed/2021/12/GHSA-x5f7-m6j9-3793/GHSA-x5f7-m6j9-3793.json +++ b/advisories/unreviewed/2021/12/GHSA-x5f7-m6j9-3793/GHSA-x5f7-m6j9-3793.json @@ -7,12 +7,8 @@ "CVE-2021-40851" ], "details": "TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x623-q82m-99x6/GHSA-x623-q82m-99x6.json b/advisories/unreviewed/2021/12/GHSA-x623-q82m-99x6/GHSA-x623-q82m-99x6.json index 05e7095a4a8..c282c550336 100644 --- a/advisories/unreviewed/2021/12/GHSA-x623-q82m-99x6/GHSA-x623-q82m-99x6.json +++ b/advisories/unreviewed/2021/12/GHSA-x623-q82m-99x6/GHSA-x623-q82m-99x6.json @@ -7,12 +7,8 @@ "CVE-2021-39310" ], "details": "The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/real-wysiwyg.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x6hf-2fv8-q6m6/GHSA-x6hf-2fv8-q6m6.json b/advisories/unreviewed/2021/12/GHSA-x6hf-2fv8-q6m6/GHSA-x6hf-2fv8-q6m6.json index d8268767338..93eae0fa978 100644 --- a/advisories/unreviewed/2021/12/GHSA-x6hf-2fv8-q6m6/GHSA-x6hf-2fv8-q6m6.json +++ b/advisories/unreviewed/2021/12/GHSA-x6hf-2fv8-q6m6/GHSA-x6hf-2fv8-q6m6.json @@ -7,12 +7,8 @@ "CVE-2021-0650" ], "details": "In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-190286685", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-x8jw-8x39-62fp/GHSA-x8jw-8x39-62fp.json b/advisories/unreviewed/2021/12/GHSA-x8jw-8x39-62fp/GHSA-x8jw-8x39-62fp.json index 67fdc904735..6595b6966bc 100644 --- a/advisories/unreviewed/2021/12/GHSA-x8jw-8x39-62fp/GHSA-x8jw-8x39-62fp.json +++ b/advisories/unreviewed/2021/12/GHSA-x8jw-8x39-62fp/GHSA-x8jw-8x39-62fp.json @@ -7,12 +7,8 @@ "CVE-2021-42023" ], "details": "A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys that are required to decrypt electronic intellectual property (IP) data in accordance with the IEEE 1735 recommended practice. This could allow a sophisticated attacker to discover the keys, bypassing the protection intended by the IEEE 1735 recommended practice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xf9j-qfgm-f8jm/GHSA-xf9j-qfgm-f8jm.json b/advisories/unreviewed/2021/12/GHSA-xf9j-qfgm-f8jm/GHSA-xf9j-qfgm-f8jm.json index 5b2ed220373..9e2c8aa32bb 100644 --- a/advisories/unreviewed/2021/12/GHSA-xf9j-qfgm-f8jm/GHSA-xf9j-qfgm-f8jm.json +++ b/advisories/unreviewed/2021/12/GHSA-xf9j-qfgm-f8jm/GHSA-xf9j-qfgm-f8jm.json @@ -7,12 +7,8 @@ "CVE-2021-43256" ], "details": "Microsoft Excel Remote Code Execution Vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-xg3h-r232-6rmw/GHSA-xg3h-r232-6rmw.json b/advisories/unreviewed/2021/12/GHSA-xg3h-r232-6rmw/GHSA-xg3h-r232-6rmw.json index eabd4a9ca75..7820d189aa8 100644 --- a/advisories/unreviewed/2021/12/GHSA-xg3h-r232-6rmw/GHSA-xg3h-r232-6rmw.json +++ b/advisories/unreviewed/2021/12/GHSA-xg3h-r232-6rmw/GHSA-xg3h-r232-6rmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-xq54-j4gh-pm4j/GHSA-xq54-j4gh-pm4j.json b/advisories/unreviewed/2021/12/GHSA-xq54-j4gh-pm4j/GHSA-xq54-j4gh-pm4j.json index c661a844785..dfb21275dc6 100644 --- a/advisories/unreviewed/2021/12/GHSA-xq54-j4gh-pm4j/GHSA-xq54-j4gh-pm4j.json +++ b/advisories/unreviewed/2021/12/GHSA-xq54-j4gh-pm4j/GHSA-xq54-j4gh-pm4j.json @@ -7,12 +7,8 @@ "CVE-2021-3831" ], "details": "gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xvhr-qprg-rjpw/GHSA-xvhr-qprg-rjpw.json b/advisories/unreviewed/2021/12/GHSA-xvhr-qprg-rjpw/GHSA-xvhr-qprg-rjpw.json index 7a5cb25927b..b39f9bbf525 100644 --- a/advisories/unreviewed/2021/12/GHSA-xvhr-qprg-rjpw/GHSA-xvhr-qprg-rjpw.json +++ b/advisories/unreviewed/2021/12/GHSA-xvhr-qprg-rjpw/GHSA-xvhr-qprg-rjpw.json @@ -7,12 +7,8 @@ "CVE-2021-4110" ], "details": "mruby is vulnerable to NULL Pointer Dereference", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-254m-3cq9-8624/GHSA-254m-3cq9-8624.json b/advisories/unreviewed/2022/02/GHSA-254m-3cq9-8624/GHSA-254m-3cq9-8624.json index 77c490f8294..cd694b85411 100644 --- a/advisories/unreviewed/2022/02/GHSA-254m-3cq9-8624/GHSA-254m-3cq9-8624.json +++ b/advisories/unreviewed/2022/02/GHSA-254m-3cq9-8624/GHSA-254m-3cq9-8624.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-2wx9-j8x2-r9vm/GHSA-2wx9-j8x2-r9vm.json b/advisories/unreviewed/2022/02/GHSA-2wx9-j8x2-r9vm/GHSA-2wx9-j8x2-r9vm.json index d6c6fde55e9..bd9bcbae296 100644 --- a/advisories/unreviewed/2022/02/GHSA-2wx9-j8x2-r9vm/GHSA-2wx9-j8x2-r9vm.json +++ b/advisories/unreviewed/2022/02/GHSA-2wx9-j8x2-r9vm/GHSA-2wx9-j8x2-r9vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-7qcx-j2px-v82h/GHSA-7qcx-j2px-v82h.json b/advisories/unreviewed/2022/02/GHSA-7qcx-j2px-v82h/GHSA-7qcx-j2px-v82h.json index ae418101cfd..054c9a1738b 100644 --- a/advisories/unreviewed/2022/02/GHSA-7qcx-j2px-v82h/GHSA-7qcx-j2px-v82h.json +++ b/advisories/unreviewed/2022/02/GHSA-7qcx-j2px-v82h/GHSA-7qcx-j2px-v82h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-8v55-rm6p-87p5/GHSA-8v55-rm6p-87p5.json b/advisories/unreviewed/2022/02/GHSA-8v55-rm6p-87p5/GHSA-8v55-rm6p-87p5.json index 9a759b80087..812c6d85507 100644 --- a/advisories/unreviewed/2022/02/GHSA-8v55-rm6p-87p5/GHSA-8v55-rm6p-87p5.json +++ b/advisories/unreviewed/2022/02/GHSA-8v55-rm6p-87p5/GHSA-8v55-rm6p-87p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-945f-ph6w-hf2g/GHSA-945f-ph6w-hf2g.json b/advisories/unreviewed/2022/02/GHSA-945f-ph6w-hf2g/GHSA-945f-ph6w-hf2g.json index 9e25a1eaed0..1893ae39a5e 100644 --- a/advisories/unreviewed/2022/02/GHSA-945f-ph6w-hf2g/GHSA-945f-ph6w-hf2g.json +++ b/advisories/unreviewed/2022/02/GHSA-945f-ph6w-hf2g/GHSA-945f-ph6w-hf2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-969p-8qf6-mrvc/GHSA-969p-8qf6-mrvc.json b/advisories/unreviewed/2022/02/GHSA-969p-8qf6-mrvc/GHSA-969p-8qf6-mrvc.json index 8c8c49db1a3..a976c28e7d0 100644 --- a/advisories/unreviewed/2022/02/GHSA-969p-8qf6-mrvc/GHSA-969p-8qf6-mrvc.json +++ b/advisories/unreviewed/2022/02/GHSA-969p-8qf6-mrvc/GHSA-969p-8qf6-mrvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-fwqr-qx2m-vqxq/GHSA-fwqr-qx2m-vqxq.json b/advisories/unreviewed/2022/02/GHSA-fwqr-qx2m-vqxq/GHSA-fwqr-qx2m-vqxq.json index 5bb37ebe7b8..4ad18e7d013 100644 --- a/advisories/unreviewed/2022/02/GHSA-fwqr-qx2m-vqxq/GHSA-fwqr-qx2m-vqxq.json +++ b/advisories/unreviewed/2022/02/GHSA-fwqr-qx2m-vqxq/GHSA-fwqr-qx2m-vqxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-hgh9-57mp-975h/GHSA-hgh9-57mp-975h.json b/advisories/unreviewed/2022/02/GHSA-hgh9-57mp-975h/GHSA-hgh9-57mp-975h.json index 27a47e29994..31036d17a6b 100644 --- a/advisories/unreviewed/2022/02/GHSA-hgh9-57mp-975h/GHSA-hgh9-57mp-975h.json +++ b/advisories/unreviewed/2022/02/GHSA-hgh9-57mp-975h/GHSA-hgh9-57mp-975h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-j379-364f-696h/GHSA-j379-364f-696h.json b/advisories/unreviewed/2022/02/GHSA-j379-364f-696h/GHSA-j379-364f-696h.json index 55e105a6471..5bc6e9848b3 100644 --- a/advisories/unreviewed/2022/02/GHSA-j379-364f-696h/GHSA-j379-364f-696h.json +++ b/advisories/unreviewed/2022/02/GHSA-j379-364f-696h/GHSA-j379-364f-696h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-vfmf-vjx2-868p/GHSA-vfmf-vjx2-868p.json b/advisories/unreviewed/2022/02/GHSA-vfmf-vjx2-868p/GHSA-vfmf-vjx2-868p.json index ef51e4f467d..e310cd2dad5 100644 --- a/advisories/unreviewed/2022/02/GHSA-vfmf-vjx2-868p/GHSA-vfmf-vjx2-868p.json +++ b/advisories/unreviewed/2022/02/GHSA-vfmf-vjx2-868p/GHSA-vfmf-vjx2-868p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-wccv-r56q-vwmw/GHSA-wccv-r56q-vwmw.json b/advisories/unreviewed/2022/02/GHSA-wccv-r56q-vwmw/GHSA-wccv-r56q-vwmw.json index 8d77478b83c..5793dc7bbd4 100644 --- a/advisories/unreviewed/2022/02/GHSA-wccv-r56q-vwmw/GHSA-wccv-r56q-vwmw.json +++ b/advisories/unreviewed/2022/02/GHSA-wccv-r56q-vwmw/GHSA-wccv-r56q-vwmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-wrf8-w7q7-mfr4/GHSA-wrf8-w7q7-mfr4.json b/advisories/unreviewed/2022/02/GHSA-wrf8-w7q7-mfr4/GHSA-wrf8-w7q7-mfr4.json index 0b59d5a3890..0c7bb969532 100644 --- a/advisories/unreviewed/2022/02/GHSA-wrf8-w7q7-mfr4/GHSA-wrf8-w7q7-mfr4.json +++ b/advisories/unreviewed/2022/02/GHSA-wrf8-w7q7-mfr4/GHSA-wrf8-w7q7-mfr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-247h-6fhv-4v2c/GHSA-247h-6fhv-4v2c.json b/advisories/unreviewed/2022/05/GHSA-247h-6fhv-4v2c/GHSA-247h-6fhv-4v2c.json index 9e57f6035b9..6f801613cff 100644 --- a/advisories/unreviewed/2022/05/GHSA-247h-6fhv-4v2c/GHSA-247h-6fhv-4v2c.json +++ b/advisories/unreviewed/2022/05/GHSA-247h-6fhv-4v2c/GHSA-247h-6fhv-4v2c.json @@ -7,12 +7,8 @@ "CVE-2009-3586" ], "details": "Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2007-4060.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24c9-7g9h-vmm8/GHSA-24c9-7g9h-vmm8.json b/advisories/unreviewed/2022/05/GHSA-24c9-7g9h-vmm8/GHSA-24c9-7g9h-vmm8.json index d79dc88f63d..74fdbcd30a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-24c9-7g9h-vmm8/GHSA-24c9-7g9h-vmm8.json +++ b/advisories/unreviewed/2022/05/GHSA-24c9-7g9h-vmm8/GHSA-24c9-7g9h-vmm8.json @@ -7,12 +7,8 @@ "CVE-2009-3536" ], "details": "Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24h9-wwcg-r638/GHSA-24h9-wwcg-r638.json b/advisories/unreviewed/2022/05/GHSA-24h9-wwcg-r638/GHSA-24h9-wwcg-r638.json index b1f0a0320c2..3f22099da87 100644 --- a/advisories/unreviewed/2022/05/GHSA-24h9-wwcg-r638/GHSA-24h9-wwcg-r638.json +++ b/advisories/unreviewed/2022/05/GHSA-24h9-wwcg-r638/GHSA-24h9-wwcg-r638.json @@ -7,12 +7,8 @@ "CVE-2009-3387" ], "details": "Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24hh-hrh3-7p5w/GHSA-24hh-hrh3-7p5w.json b/advisories/unreviewed/2022/05/GHSA-24hh-hrh3-7p5w/GHSA-24hh-hrh3-7p5w.json index f44606b858a..dff3a60988c 100644 --- a/advisories/unreviewed/2022/05/GHSA-24hh-hrh3-7p5w/GHSA-24hh-hrh3-7p5w.json +++ b/advisories/unreviewed/2022/05/GHSA-24hh-hrh3-7p5w/GHSA-24hh-hrh3-7p5w.json @@ -7,12 +7,8 @@ "CVE-2009-3677" ], "details": "The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka \"MS-CHAP Authentication Bypass Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-256q-r8jw-w2f7/GHSA-256q-r8jw-w2f7.json b/advisories/unreviewed/2022/05/GHSA-256q-r8jw-w2f7/GHSA-256q-r8jw-w2f7.json index be75a724b36..0d870281cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-256q-r8jw-w2f7/GHSA-256q-r8jw-w2f7.json +++ b/advisories/unreviewed/2022/05/GHSA-256q-r8jw-w2f7/GHSA-256q-r8jw-w2f7.json @@ -7,12 +7,8 @@ "CVE-2009-3324" ], "details": "PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25gf-7mcm-h7vj/GHSA-25gf-7mcm-h7vj.json b/advisories/unreviewed/2022/05/GHSA-25gf-7mcm-h7vj/GHSA-25gf-7mcm-h7vj.json index 2f45e94f5c0..0635386c641 100644 --- a/advisories/unreviewed/2022/05/GHSA-25gf-7mcm-h7vj/GHSA-25gf-7mcm-h7vj.json +++ b/advisories/unreviewed/2022/05/GHSA-25gf-7mcm-h7vj/GHSA-25gf-7mcm-h7vj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-265g-226q-c27c/GHSA-265g-226q-c27c.json b/advisories/unreviewed/2022/05/GHSA-265g-226q-c27c/GHSA-265g-226q-c27c.json index fb39705fc5c..2c854f152fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-265g-226q-c27c/GHSA-265g-226q-c27c.json +++ b/advisories/unreviewed/2022/05/GHSA-265g-226q-c27c/GHSA-265g-226q-c27c.json @@ -7,12 +7,8 @@ "CVE-2009-3692" ], "details": "Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26m7-h3mc-j98r/GHSA-26m7-h3mc-j98r.json b/advisories/unreviewed/2022/05/GHSA-26m7-h3mc-j98r/GHSA-26m7-h3mc-j98r.json index 3a2f02e50fc..4b199574860 100644 --- a/advisories/unreviewed/2022/05/GHSA-26m7-h3mc-j98r/GHSA-26m7-h3mc-j98r.json +++ b/advisories/unreviewed/2022/05/GHSA-26m7-h3mc-j98r/GHSA-26m7-h3mc-j98r.json @@ -7,12 +7,8 @@ "CVE-2009-3504" ], "details": "SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2775-52x6-3w7f/GHSA-2775-52x6-3w7f.json b/advisories/unreviewed/2022/05/GHSA-2775-52x6-3w7f/GHSA-2775-52x6-3w7f.json index 99706860147..14d0ac80dd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2775-52x6-3w7f/GHSA-2775-52x6-3w7f.json +++ b/advisories/unreviewed/2022/05/GHSA-2775-52x6-3w7f/GHSA-2775-52x6-3w7f.json @@ -7,12 +7,8 @@ "CVE-2009-3742" ], "details": "Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the p_p_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2885-hmxc-wwgx/GHSA-2885-hmxc-wwgx.json b/advisories/unreviewed/2022/05/GHSA-2885-hmxc-wwgx/GHSA-2885-hmxc-wwgx.json index 79f1ebd55cb..36998a5d47f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2885-hmxc-wwgx/GHSA-2885-hmxc-wwgx.json +++ b/advisories/unreviewed/2022/05/GHSA-2885-hmxc-wwgx/GHSA-2885-hmxc-wwgx.json @@ -7,12 +7,8 @@ "CVE-2009-3344" ], "details": "Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2893-36vg-x3vj/GHSA-2893-36vg-x3vj.json b/advisories/unreviewed/2022/05/GHSA-2893-36vg-x3vj/GHSA-2893-36vg-x3vj.json index bc9bd97a4d5..1d6982c6ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2893-36vg-x3vj/GHSA-2893-36vg-x3vj.json +++ b/advisories/unreviewed/2022/05/GHSA-2893-36vg-x3vj/GHSA-2893-36vg-x3vj.json @@ -7,12 +7,8 @@ "CVE-2009-3483" ], "details": "Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a site list containing an entry with a long label.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28gc-vvw4-44jg/GHSA-28gc-vvw4-44jg.json b/advisories/unreviewed/2022/05/GHSA-28gc-vvw4-44jg/GHSA-28gc-vvw4-44jg.json index 138a1b01ba0..e6cee2e62fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-28gc-vvw4-44jg/GHSA-28gc-vvw4-44jg.json +++ b/advisories/unreviewed/2022/05/GHSA-28gc-vvw4-44jg/GHSA-28gc-vvw4-44jg.json @@ -7,12 +7,8 @@ "CVE-2009-3787" ], "details": "files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with \"logs/\" in between two . (dot) characters, which is filtered into a \"../\" sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28mc-4879-xh6f/GHSA-28mc-4879-xh6f.json b/advisories/unreviewed/2022/05/GHSA-28mc-4879-xh6f/GHSA-28mc-4879-xh6f.json index 69d6ac56380..2127426e733 100644 --- a/advisories/unreviewed/2022/05/GHSA-28mc-4879-xh6f/GHSA-28mc-4879-xh6f.json +++ b/advisories/unreviewed/2022/05/GHSA-28mc-4879-xh6f/GHSA-28mc-4879-xh6f.json @@ -7,12 +7,8 @@ "CVE-2009-3311" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fj2-4h38-3c72/GHSA-2fj2-4h38-3c72.json b/advisories/unreviewed/2022/05/GHSA-2fj2-4h38-3c72/GHSA-2fj2-4h38-3c72.json index 881693e8c40..4c02ff02a89 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fj2-4h38-3c72/GHSA-2fj2-4h38-3c72.json +++ b/advisories/unreviewed/2022/05/GHSA-2fj2-4h38-3c72/GHSA-2fj2-4h38-3c72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fvh-4fwg-94q3/GHSA-2fvh-4fwg-94q3.json b/advisories/unreviewed/2022/05/GHSA-2fvh-4fwg-94q3/GHSA-2fvh-4fwg-94q3.json index 116d720f878..bd4c4e56217 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fvh-4fwg-94q3/GHSA-2fvh-4fwg-94q3.json +++ b/advisories/unreviewed/2022/05/GHSA-2fvh-4fwg-94q3/GHSA-2fvh-4fwg-94q3.json @@ -7,12 +7,8 @@ "CVE-2009-3345" ], "details": "Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g3h-rvgj-6gh5/GHSA-2g3h-rvgj-6gh5.json b/advisories/unreviewed/2022/05/GHSA-2g3h-rvgj-6gh5/GHSA-2g3h-rvgj-6gh5.json index 01da987a61a..9fd2a1e9a97 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g3h-rvgj-6gh5/GHSA-2g3h-rvgj-6gh5.json +++ b/advisories/unreviewed/2022/05/GHSA-2g3h-rvgj-6gh5/GHSA-2g3h-rvgj-6gh5.json @@ -7,12 +7,8 @@ "CVE-2009-3575" ], "details": "Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hgf-g4v8-3jqv/GHSA-2hgf-g4v8-3jqv.json b/advisories/unreviewed/2022/05/GHSA-2hgf-g4v8-3jqv/GHSA-2hgf-g4v8-3jqv.json index b306b9c326e..d6a8e9e6a7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hgf-g4v8-3jqv/GHSA-2hgf-g4v8-3jqv.json +++ b/advisories/unreviewed/2022/05/GHSA-2hgf-g4v8-3jqv/GHSA-2hgf-g4v8-3jqv.json @@ -7,12 +7,8 @@ "CVE-2009-3115" ], "details": "SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hgw-48gj-v3wx/GHSA-2hgw-48gj-v3wx.json b/advisories/unreviewed/2022/05/GHSA-2hgw-48gj-v3wx/GHSA-2hgw-48gj-v3wx.json index 768d434962c..731d437faf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hgw-48gj-v3wx/GHSA-2hgw-48gj-v3wx.json +++ b/advisories/unreviewed/2022/05/GHSA-2hgw-48gj-v3wx/GHSA-2hgw-48gj-v3wx.json @@ -7,12 +7,8 @@ "CVE-2009-3455" ], "details": "Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jjp-v4x9-55gm/GHSA-2jjp-v4x9-55gm.json b/advisories/unreviewed/2022/05/GHSA-2jjp-v4x9-55gm/GHSA-2jjp-v4x9-55gm.json index df6e89cfb24..9fb7cb26d0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jjp-v4x9-55gm/GHSA-2jjp-v4x9-55gm.json +++ b/advisories/unreviewed/2022/05/GHSA-2jjp-v4x9-55gm/GHSA-2jjp-v4x9-55gm.json @@ -7,12 +7,8 @@ "CVE-2009-3276" ], "details": "Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a \"ReDoS\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m99-5fff-xf2f/GHSA-2m99-5fff-xf2f.json b/advisories/unreviewed/2022/05/GHSA-2m99-5fff-xf2f/GHSA-2m99-5fff-xf2f.json index 97aeb9bb222..7464a1ddf1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m99-5fff-xf2f/GHSA-2m99-5fff-xf2f.json +++ b/advisories/unreviewed/2022/05/GHSA-2m99-5fff-xf2f/GHSA-2m99-5fff-xf2f.json @@ -7,12 +7,8 @@ "CVE-2009-3307" ], "details": "Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mp4-3r7m-mmg9/GHSA-2mp4-3r7m-mmg9.json b/advisories/unreviewed/2022/05/GHSA-2mp4-3r7m-mmg9/GHSA-2mp4-3r7m-mmg9.json index ce69355c82b..51b3a0c22ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mp4-3r7m-mmg9/GHSA-2mp4-3r7m-mmg9.json +++ b/advisories/unreviewed/2022/05/GHSA-2mp4-3r7m-mmg9/GHSA-2mp4-3r7m-mmg9.json @@ -7,12 +7,8 @@ "CVE-2009-3512" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2ppv-95h6-36pf/GHSA-2ppv-95h6-36pf.json b/advisories/unreviewed/2022/05/GHSA-2ppv-95h6-36pf/GHSA-2ppv-95h6-36pf.json index ee588cfeaf7..6edd1466b97 100644 --- a/advisories/unreviewed/2022/05/GHSA-2ppv-95h6-36pf/GHSA-2ppv-95h6-36pf.json +++ b/advisories/unreviewed/2022/05/GHSA-2ppv-95h6-36pf/GHSA-2ppv-95h6-36pf.json @@ -7,12 +7,8 @@ "CVE-2009-3473" ], "details": "IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qgv-pgxc-xh7j/GHSA-2qgv-pgxc-xh7j.json b/advisories/unreviewed/2022/05/GHSA-2qgv-pgxc-xh7j/GHSA-2qgv-pgxc-xh7j.json index 5951e590cee..94397fe03f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qgv-pgxc-xh7j/GHSA-2qgv-pgxc-xh7j.json +++ b/advisories/unreviewed/2022/05/GHSA-2qgv-pgxc-xh7j/GHSA-2qgv-pgxc-xh7j.json @@ -7,12 +7,8 @@ "CVE-2009-3122" ], "details": "The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2r73-5g3g-pvhw/GHSA-2r73-5g3g-pvhw.json b/advisories/unreviewed/2022/05/GHSA-2r73-5g3g-pvhw/GHSA-2r73-5g3g-pvhw.json index 7695db9dd36..df7d2745706 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r73-5g3g-pvhw/GHSA-2r73-5g3g-pvhw.json +++ b/advisories/unreviewed/2022/05/GHSA-2r73-5g3g-pvhw/GHSA-2r73-5g3g-pvhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v43-c695-wqxw/GHSA-2v43-c695-wqxw.json b/advisories/unreviewed/2022/05/GHSA-2v43-c695-wqxw/GHSA-2v43-c695-wqxw.json index 1723653314e..ab7d8ca3fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v43-c695-wqxw/GHSA-2v43-c695-wqxw.json +++ b/advisories/unreviewed/2022/05/GHSA-2v43-c695-wqxw/GHSA-2v43-c695-wqxw.json @@ -7,12 +7,8 @@ "CVE-2009-3457" ], "details": "Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v75-jgr3-vhp6/GHSA-2v75-jgr3-vhp6.json b/advisories/unreviewed/2022/05/GHSA-2v75-jgr3-vhp6/GHSA-2v75-jgr3-vhp6.json index 51a29295f5a..2d5ee27949c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v75-jgr3-vhp6/GHSA-2v75-jgr3-vhp6.json +++ b/advisories/unreviewed/2022/05/GHSA-2v75-jgr3-vhp6/GHSA-2v75-jgr3-vhp6.json @@ -7,12 +7,8 @@ "CVE-2009-3410" ], "details": "Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w9j-55xj-gcp3/GHSA-2w9j-55xj-gcp3.json b/advisories/unreviewed/2022/05/GHSA-2w9j-55xj-gcp3/GHSA-2w9j-55xj-gcp3.json index 1460303aaf5..1e66a207724 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w9j-55xj-gcp3/GHSA-2w9j-55xj-gcp3.json +++ b/advisories/unreviewed/2022/05/GHSA-2w9j-55xj-gcp3/GHSA-2w9j-55xj-gcp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w9x-8fmc-q598/GHSA-2w9x-8fmc-q598.json b/advisories/unreviewed/2022/05/GHSA-2w9x-8fmc-q598/GHSA-2w9x-8fmc-q598.json index e61e0e587f4..8426c52a656 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w9x-8fmc-q598/GHSA-2w9x-8fmc-q598.json +++ b/advisories/unreviewed/2022/05/GHSA-2w9x-8fmc-q598/GHSA-2w9x-8fmc-q598.json @@ -7,12 +7,8 @@ "CVE-2009-3651" ], "details": "Cross-site scripting (XSS) vulnerability in the \"Monitor browsers' feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-323p-4v5q-w32p/GHSA-323p-4v5q-w32p.json b/advisories/unreviewed/2022/05/GHSA-323p-4v5q-w32p/GHSA-323p-4v5q-w32p.json index 34c048f22cf..1a611445964 100644 --- a/advisories/unreviewed/2022/05/GHSA-323p-4v5q-w32p/GHSA-323p-4v5q-w32p.json +++ b/advisories/unreviewed/2022/05/GHSA-323p-4v5q-w32p/GHSA-323p-4v5q-w32p.json @@ -7,12 +7,8 @@ "CVE-2009-3332" ], "details": "SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34rg-qhv9-9cpx/GHSA-34rg-qhv9-9cpx.json b/advisories/unreviewed/2022/05/GHSA-34rg-qhv9-9cpx/GHSA-34rg-qhv9-9cpx.json index 1ecf0c4627b..8cbd10f8543 100644 --- a/advisories/unreviewed/2022/05/GHSA-34rg-qhv9-9cpx/GHSA-34rg-qhv9-9cpx.json +++ b/advisories/unreviewed/2022/05/GHSA-34rg-qhv9-9cpx/GHSA-34rg-qhv9-9cpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34xh-g8p4-g947/GHSA-34xh-g8p4-g947.json b/advisories/unreviewed/2022/05/GHSA-34xh-g8p4-g947/GHSA-34xh-g8p4-g947.json index 2af6f74d56e..fdcbf6e228a 100644 --- a/advisories/unreviewed/2022/05/GHSA-34xh-g8p4-g947/GHSA-34xh-g8p4-g947.json +++ b/advisories/unreviewed/2022/05/GHSA-34xh-g8p4-g947/GHSA-34xh-g8p4-g947.json @@ -7,12 +7,8 @@ "CVE-2009-3570" ], "details": "Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3566-jfm7-38ph/GHSA-3566-jfm7-38ph.json b/advisories/unreviewed/2022/05/GHSA-3566-jfm7-38ph/GHSA-3566-jfm7-38ph.json index 442cc0e2c20..9ffe744ae42 100644 --- a/advisories/unreviewed/2022/05/GHSA-3566-jfm7-38ph/GHSA-3566-jfm7-38ph.json +++ b/advisories/unreviewed/2022/05/GHSA-3566-jfm7-38ph/GHSA-3566-jfm7-38ph.json @@ -7,12 +7,8 @@ "CVE-2009-3188" ], "details": "PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35jw-93qg-qxgw/GHSA-35jw-93qg-qxgw.json b/advisories/unreviewed/2022/05/GHSA-35jw-93qg-qxgw/GHSA-35jw-93qg-qxgw.json index dfb462cfda0..06ec13161b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-35jw-93qg-qxgw/GHSA-35jw-93qg-qxgw.json +++ b/advisories/unreviewed/2022/05/GHSA-35jw-93qg-qxgw/GHSA-35jw-93qg-qxgw.json @@ -7,12 +7,8 @@ "CVE-2009-3400" ], "details": "Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35w3-85xv-8x6w/GHSA-35w3-85xv-8x6w.json b/advisories/unreviewed/2022/05/GHSA-35w3-85xv-8x6w/GHSA-35w3-85xv-8x6w.json index 4d2d8b0c31e..e88a6c1c246 100644 --- a/advisories/unreviewed/2022/05/GHSA-35w3-85xv-8x6w/GHSA-35w3-85xv-8x6w.json +++ b/advisories/unreviewed/2022/05/GHSA-35w3-85xv-8x6w/GHSA-35w3-85xv-8x6w.json @@ -7,12 +7,8 @@ "CVE-2009-3452" ], "details": "WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-365m-rf96-qxh8/GHSA-365m-rf96-qxh8.json b/advisories/unreviewed/2022/05/GHSA-365m-rf96-qxh8/GHSA-365m-rf96-qxh8.json index db854ecb82c..59c50fa8693 100644 --- a/advisories/unreviewed/2022/05/GHSA-365m-rf96-qxh8/GHSA-365m-rf96-qxh8.json +++ b/advisories/unreviewed/2022/05/GHSA-365m-rf96-qxh8/GHSA-365m-rf96-qxh8.json @@ -7,12 +7,8 @@ "CVE-2009-3792" ], "details": "Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-377x-3gqm-h467/GHSA-377x-3gqm-h467.json b/advisories/unreviewed/2022/05/GHSA-377x-3gqm-h467/GHSA-377x-3gqm-h467.json index c194db03c15..9ef79a81759 100644 --- a/advisories/unreviewed/2022/05/GHSA-377x-3gqm-h467/GHSA-377x-3gqm-h467.json +++ b/advisories/unreviewed/2022/05/GHSA-377x-3gqm-h467/GHSA-377x-3gqm-h467.json @@ -7,12 +7,8 @@ "CVE-2009-3642" ], "details": "Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-383f-wq2v-q529/GHSA-383f-wq2v-q529.json b/advisories/unreviewed/2022/05/GHSA-383f-wq2v-q529/GHSA-383f-wq2v-q529.json index 0abaf90fa49..e6996800777 100644 --- a/advisories/unreviewed/2022/05/GHSA-383f-wq2v-q529/GHSA-383f-wq2v-q529.json +++ b/advisories/unreviewed/2022/05/GHSA-383f-wq2v-q529/GHSA-383f-wq2v-q529.json @@ -7,12 +7,8 @@ "CVE-2009-3754" ], "details": "Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action to advancedsearch.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38p9-xg79-q3f9/GHSA-38p9-xg79-q3f9.json b/advisories/unreviewed/2022/05/GHSA-38p9-xg79-q3f9/GHSA-38p9-xg79-q3f9.json index 1fb7359e888..41751ba3997 100644 --- a/advisories/unreviewed/2022/05/GHSA-38p9-xg79-q3f9/GHSA-38p9-xg79-q3f9.json +++ b/advisories/unreviewed/2022/05/GHSA-38p9-xg79-q3f9/GHSA-38p9-xg79-q3f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39cj-q7jm-v7pc/GHSA-39cj-q7jm-v7pc.json b/advisories/unreviewed/2022/05/GHSA-39cj-q7jm-v7pc/GHSA-39cj-q7jm-v7pc.json index 89d4a999e3c..10f2055b158 100644 --- a/advisories/unreviewed/2022/05/GHSA-39cj-q7jm-v7pc/GHSA-39cj-q7jm-v7pc.json +++ b/advisories/unreviewed/2022/05/GHSA-39cj-q7jm-v7pc/GHSA-39cj-q7jm-v7pc.json @@ -7,12 +7,8 @@ "CVE-2009-3650" ], "details": "Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39mh-9qg5-7gh4/GHSA-39mh-9qg5-7gh4.json b/advisories/unreviewed/2022/05/GHSA-39mh-9qg5-7gh4/GHSA-39mh-9qg5-7gh4.json index 3f14f0a136b..7b8ec94afcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-39mh-9qg5-7gh4/GHSA-39mh-9qg5-7gh4.json +++ b/advisories/unreviewed/2022/05/GHSA-39mh-9qg5-7gh4/GHSA-39mh-9qg5-7gh4.json @@ -7,12 +7,8 @@ "CVE-2009-3192" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in LinkorCMS 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the searchstr parameter in a search action; or the (2) nikname, (3) realname, (4) homepage, or (5) city parameter in a registration action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cp9-95xq-76hw/GHSA-3cp9-95xq-76hw.json b/advisories/unreviewed/2022/05/GHSA-3cp9-95xq-76hw/GHSA-3cp9-95xq-76hw.json index ee94320a43c..428f7e74fc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cp9-95xq-76hw/GHSA-3cp9-95xq-76hw.json +++ b/advisories/unreviewed/2022/05/GHSA-3cp9-95xq-76hw/GHSA-3cp9-95xq-76hw.json @@ -7,12 +7,8 @@ "CVE-2009-3212" ], "details": "SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f7f-2hr4-47jj/GHSA-3f7f-2hr4-47jj.json b/advisories/unreviewed/2022/05/GHSA-3f7f-2hr4-47jj/GHSA-3f7f-2hr4-47jj.json index 8a3083836c5..01e090a9b13 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f7f-2hr4-47jj/GHSA-3f7f-2hr4-47jj.json +++ b/advisories/unreviewed/2022/05/GHSA-3f7f-2hr4-47jj/GHSA-3f7f-2hr4-47jj.json @@ -7,12 +7,8 @@ "CVE-2009-3751" ], "details": "Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gm7-8cfv-p8h9/GHSA-3gm7-8cfv-p8h9.json b/advisories/unreviewed/2022/05/GHSA-3gm7-8cfv-p8h9/GHSA-3gm7-8cfv-p8h9.json index 1762f8bdcf3..96024d16a2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gm7-8cfv-p8h9/GHSA-3gm7-8cfv-p8h9.json +++ b/advisories/unreviewed/2022/05/GHSA-3gm7-8cfv-p8h9/GHSA-3gm7-8cfv-p8h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gm8-9xxm-pmhh/GHSA-3gm8-9xxm-pmhh.json b/advisories/unreviewed/2022/05/GHSA-3gm8-9xxm-pmhh/GHSA-3gm8-9xxm-pmhh.json index 522e48dd5d5..fedfb7d3702 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gm8-9xxm-pmhh/GHSA-3gm8-9xxm-pmhh.json +++ b/advisories/unreviewed/2022/05/GHSA-3gm8-9xxm-pmhh/GHSA-3gm8-9xxm-pmhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gmw-m22w-rmhw/GHSA-3gmw-m22w-rmhw.json b/advisories/unreviewed/2022/05/GHSA-3gmw-m22w-rmhw/GHSA-3gmw-m22w-rmhw.json index 25e049aab41..31465ef25a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gmw-m22w-rmhw/GHSA-3gmw-m22w-rmhw.json +++ b/advisories/unreviewed/2022/05/GHSA-3gmw-m22w-rmhw/GHSA-3gmw-m22w-rmhw.json @@ -7,12 +7,8 @@ "CVE-2009-3678" ], "details": "Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using \"Browse with Irfanview\" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka \"Canonical Display Driver Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gr2-8v6p-pjf9/GHSA-3gr2-8v6p-pjf9.json b/advisories/unreviewed/2022/05/GHSA-3gr2-8v6p-pjf9/GHSA-3gr2-8v6p-pjf9.json index 576bd0f5088..4cb86eb07d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gr2-8v6p-pjf9/GHSA-3gr2-8v6p-pjf9.json +++ b/advisories/unreviewed/2022/05/GHSA-3gr2-8v6p-pjf9/GHSA-3gr2-8v6p-pjf9.json @@ -7,12 +7,8 @@ "CVE-2009-3187" ], "details": "Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hhh-hv27-4gjh/GHSA-3hhh-hv27-4gjh.json b/advisories/unreviewed/2022/05/GHSA-3hhh-hv27-4gjh/GHSA-3hhh-hv27-4gjh.json index d3afec134d8..bffac56a62e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hhh-hv27-4gjh/GHSA-3hhh-hv27-4gjh.json +++ b/advisories/unreviewed/2022/05/GHSA-3hhh-hv27-4gjh/GHSA-3hhh-hv27-4gjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hq9-j8x9-925r/GHSA-3hq9-j8x9-925r.json b/advisories/unreviewed/2022/05/GHSA-3hq9-j8x9-925r/GHSA-3hq9-j8x9-925r.json index 3149aaef476..8f823156e8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hq9-j8x9-925r/GHSA-3hq9-j8x9-925r.json +++ b/advisories/unreviewed/2022/05/GHSA-3hq9-j8x9-925r/GHSA-3hq9-j8x9-925r.json @@ -7,12 +7,8 @@ "CVE-2009-3304" ], "details": "GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j5v-hj4j-5rm9/GHSA-3j5v-hj4j-5rm9.json b/advisories/unreviewed/2022/05/GHSA-3j5v-hj4j-5rm9/GHSA-3j5v-hj4j-5rm9.json index d6a46c0a555..d791edb6dd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j5v-hj4j-5rm9/GHSA-3j5v-hj4j-5rm9.json +++ b/advisories/unreviewed/2022/05/GHSA-3j5v-hj4j-5rm9/GHSA-3j5v-hj4j-5rm9.json @@ -7,12 +7,8 @@ "CVE-2009-3392" ], "details": "Unspecified vulnerability in the Agile Engineering Data Management (EDM) component in Oracle E-Business Suite 6.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jfw-8phg-9vp8/GHSA-3jfw-8phg-9vp8.json b/advisories/unreviewed/2022/05/GHSA-3jfw-8phg-9vp8/GHSA-3jfw-8phg-9vp8.json index 98e4cbe5abd..b14ed701460 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jfw-8phg-9vp8/GHSA-3jfw-8phg-9vp8.json +++ b/advisories/unreviewed/2022/05/GHSA-3jfw-8phg-9vp8/GHSA-3jfw-8phg-9vp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3p47-jqhp-gxp9/GHSA-3p47-jqhp-gxp9.json b/advisories/unreviewed/2022/05/GHSA-3p47-jqhp-gxp9/GHSA-3p47-jqhp-gxp9.json index 03f7456dc3b..a14db4a8765 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p47-jqhp-gxp9/GHSA-3p47-jqhp-gxp9.json +++ b/advisories/unreviewed/2022/05/GHSA-3p47-jqhp-gxp9/GHSA-3p47-jqhp-gxp9.json @@ -7,12 +7,8 @@ "CVE-2009-3743" ], "details": "Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3pw2-f952-6q7c/GHSA-3pw2-f952-6q7c.json b/advisories/unreviewed/2022/05/GHSA-3pw2-f952-6q7c/GHSA-3pw2-f952-6q7c.json index ef34dd38845..57ae7f4fdfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pw2-f952-6q7c/GHSA-3pw2-f952-6q7c.json +++ b/advisories/unreviewed/2022/05/GHSA-3pw2-f952-6q7c/GHSA-3pw2-f952-6q7c.json @@ -7,12 +7,8 @@ "CVE-2009-3112" ], "details": "Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r45-7993-xcwr/GHSA-3r45-7993-xcwr.json b/advisories/unreviewed/2022/05/GHSA-3r45-7993-xcwr/GHSA-3r45-7993-xcwr.json index 73d5e561eb7..0ed06649545 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r45-7993-xcwr/GHSA-3r45-7993-xcwr.json +++ b/advisories/unreviewed/2022/05/GHSA-3r45-7993-xcwr/GHSA-3r45-7993-xcwr.json @@ -7,12 +7,8 @@ "CVE-2009-3522" ], "details": "Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r52-23hx-qw5v/GHSA-3r52-23hx-qw5v.json b/advisories/unreviewed/2022/05/GHSA-3r52-23hx-qw5v/GHSA-3r52-23hx-qw5v.json index 8ed75e1375e..995e2220c1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r52-23hx-qw5v/GHSA-3r52-23hx-qw5v.json +++ b/advisories/unreviewed/2022/05/GHSA-3r52-23hx-qw5v/GHSA-3r52-23hx-qw5v.json @@ -7,12 +7,8 @@ "CVE-2009-3351" ], "details": "Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v2j-hm2p-q5qg/GHSA-3v2j-hm2p-q5qg.json b/advisories/unreviewed/2022/05/GHSA-3v2j-hm2p-q5qg/GHSA-3v2j-hm2p-q5qg.json index dc9bd196859..e8ba8addab6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v2j-hm2p-q5qg/GHSA-3v2j-hm2p-q5qg.json +++ b/advisories/unreviewed/2022/05/GHSA-3v2j-hm2p-q5qg/GHSA-3v2j-hm2p-q5qg.json @@ -7,12 +7,8 @@ "CVE-2009-3675" ], "details": "LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka \"Local Security Authority Subsystem Service Resource Exhaustion Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w34-xv7m-phqr/GHSA-3w34-xv7m-phqr.json b/advisories/unreviewed/2022/05/GHSA-3w34-xv7m-phqr/GHSA-3w34-xv7m-phqr.json index dafe52b0bd6..b8cd7454538 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w34-xv7m-phqr/GHSA-3w34-xv7m-phqr.json +++ b/advisories/unreviewed/2022/05/GHSA-3w34-xv7m-phqr/GHSA-3w34-xv7m-phqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w8c-hmvh-m87g/GHSA-3w8c-hmvh-m87g.json b/advisories/unreviewed/2022/05/GHSA-3w8c-hmvh-m87g/GHSA-3w8c-hmvh-m87g.json index 16138e72d2e..3143dbd58dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w8c-hmvh-m87g/GHSA-3w8c-hmvh-m87g.json +++ b/advisories/unreviewed/2022/05/GHSA-3w8c-hmvh-m87g/GHSA-3w8c-hmvh-m87g.json @@ -7,12 +7,8 @@ "CVE-2009-3674" ], "details": "Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"Uninitialized Memory Corruption Vulnerability,\" a different vulnerability than CVE-2009-3671.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wq7-2q97-v54v/GHSA-3wq7-2q97-v54v.json b/advisories/unreviewed/2022/05/GHSA-3wq7-2q97-v54v/GHSA-3wq7-2q97-v54v.json index f3d9d2b57a9..da68869bb06 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wq7-2q97-v54v/GHSA-3wq7-2q97-v54v.json +++ b/advisories/unreviewed/2022/05/GHSA-3wq7-2q97-v54v/GHSA-3wq7-2q97-v54v.json @@ -7,12 +7,8 @@ "CVE-2009-3584" ], "details": "SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3ww4-hpff-r8mv/GHSA-3ww4-hpff-r8mv.json b/advisories/unreviewed/2022/05/GHSA-3ww4-hpff-r8mv/GHSA-3ww4-hpff-r8mv.json index e0ce2de574a..94b4a60b292 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ww4-hpff-r8mv/GHSA-3ww4-hpff-r8mv.json +++ b/advisories/unreviewed/2022/05/GHSA-3ww4-hpff-r8mv/GHSA-3ww4-hpff-r8mv.json @@ -7,12 +7,8 @@ "CVE-2009-3190" ], "details": "Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3ww7-mpcv-cwwh/GHSA-3ww7-mpcv-cwwh.json b/advisories/unreviewed/2022/05/GHSA-3ww7-mpcv-cwwh/GHSA-3ww7-mpcv-cwwh.json index 21478ef6733..76a14c7abb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ww7-mpcv-cwwh/GHSA-3ww7-mpcv-cwwh.json +++ b/advisories/unreviewed/2022/05/GHSA-3ww7-mpcv-cwwh/GHSA-3ww7-mpcv-cwwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3x4w-3pwj-2297/GHSA-3x4w-3pwj-2297.json b/advisories/unreviewed/2022/05/GHSA-3x4w-3pwj-2297/GHSA-3x4w-3pwj-2297.json index 4baece0dcd2..2341c97cf96 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x4w-3pwj-2297/GHSA-3x4w-3pwj-2297.json +++ b/advisories/unreviewed/2022/05/GHSA-3x4w-3pwj-2297/GHSA-3x4w-3pwj-2297.json @@ -7,12 +7,8 @@ "CVE-2009-3221" ], "details": "Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xmp-37v6-x52p/GHSA-3xmp-37v6-x52p.json b/advisories/unreviewed/2022/05/GHSA-3xmp-37v6-x52p/GHSA-3xmp-37v6-x52p.json index 07afd2598ab..85f3c83221c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xmp-37v6-x52p/GHSA-3xmp-37v6-x52p.json +++ b/advisories/unreviewed/2022/05/GHSA-3xmp-37v6-x52p/GHSA-3xmp-37v6-x52p.json @@ -7,12 +7,8 @@ "CVE-2009-3312" ], "details": "PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xrf-3v7w-582w/GHSA-3xrf-3v7w-582w.json b/advisories/unreviewed/2022/05/GHSA-3xrf-3v7w-582w/GHSA-3xrf-3v7w-582w.json index fca7f9e59d6..8a9b791a13f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xrf-3v7w-582w/GHSA-3xrf-3v7w-582w.json +++ b/advisories/unreviewed/2022/05/GHSA-3xrf-3v7w-582w/GHSA-3xrf-3v7w-582w.json @@ -7,12 +7,8 @@ "CVE-2009-3602" ], "details": "Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-429c-wjm9-c577/GHSA-429c-wjm9-c577.json b/advisories/unreviewed/2022/05/GHSA-429c-wjm9-c577/GHSA-429c-wjm9-c577.json index cb3e4120091..1592801b2ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-429c-wjm9-c577/GHSA-429c-wjm9-c577.json +++ b/advisories/unreviewed/2022/05/GHSA-429c-wjm9-c577/GHSA-429c-wjm9-c577.json @@ -7,12 +7,8 @@ "CVE-2009-3373" ], "details": "Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4349-2x5x-f444/GHSA-4349-2x5x-f444.json b/advisories/unreviewed/2022/05/GHSA-4349-2x5x-f444/GHSA-4349-2x5x-f444.json index 933bdd09513..77a66381e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4349-2x5x-f444/GHSA-4349-2x5x-f444.json +++ b/advisories/unreviewed/2022/05/GHSA-4349-2x5x-f444/GHSA-4349-2x5x-f444.json @@ -7,12 +7,8 @@ "CVE-2009-3510" ], "details": "SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-438x-56gx-w64g/GHSA-438x-56gx-w64g.json b/advisories/unreviewed/2022/05/GHSA-438x-56gx-w64g/GHSA-438x-56gx-w64g.json index d14f0f5608c..68352eff89a 100644 --- a/advisories/unreviewed/2022/05/GHSA-438x-56gx-w64g/GHSA-438x-56gx-w64g.json +++ b/advisories/unreviewed/2022/05/GHSA-438x-56gx-w64g/GHSA-438x-56gx-w64g.json @@ -7,12 +7,8 @@ "CVE-2009-3369" ], "details": "CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43f9-pjg6-9rw4/GHSA-43f9-pjg6-9rw4.json b/advisories/unreviewed/2022/05/GHSA-43f9-pjg6-9rw4/GHSA-43f9-pjg6-9rw4.json index 0737d643a9c..71319b939f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-43f9-pjg6-9rw4/GHSA-43f9-pjg6-9rw4.json +++ b/advisories/unreviewed/2022/05/GHSA-43f9-pjg6-9rw4/GHSA-43f9-pjg6-9rw4.json @@ -7,12 +7,8 @@ "CVE-2009-3204" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43vf-866m-gxw3/GHSA-43vf-866m-gxw3.json b/advisories/unreviewed/2022/05/GHSA-43vf-866m-gxw3/GHSA-43vf-866m-gxw3.json index ab09b737a57..7dc20ecb8e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-43vf-866m-gxw3/GHSA-43vf-866m-gxw3.json +++ b/advisories/unreviewed/2022/05/GHSA-43vf-866m-gxw3/GHSA-43vf-866m-gxw3.json @@ -7,12 +7,8 @@ "CVE-2009-3339" ], "details": "Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4438-jh32-8rr9/GHSA-4438-jh32-8rr9.json b/advisories/unreviewed/2022/05/GHSA-4438-jh32-8rr9/GHSA-4438-jh32-8rr9.json index 8dcaa0699ef..0a1be91bf83 100644 --- a/advisories/unreviewed/2022/05/GHSA-4438-jh32-8rr9/GHSA-4438-jh32-8rr9.json +++ b/advisories/unreviewed/2022/05/GHSA-4438-jh32-8rr9/GHSA-4438-jh32-8rr9.json @@ -7,12 +7,8 @@ "CVE-2009-3668" ], "details": "Cross-site scripting (XSS) vulnerability in ardguest.php in Ardguest 1.8 allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44pw-f9wr-w46w/GHSA-44pw-f9wr-w46w.json b/advisories/unreviewed/2022/05/GHSA-44pw-f9wr-w46w/GHSA-44pw-f9wr-w46w.json index ce42163dabf..7ad917b705e 100644 --- a/advisories/unreviewed/2022/05/GHSA-44pw-f9wr-w46w/GHSA-44pw-f9wr-w46w.json +++ b/advisories/unreviewed/2022/05/GHSA-44pw-f9wr-w46w/GHSA-44pw-f9wr-w46w.json @@ -7,12 +7,8 @@ "CVE-2009-3465" ], "details": "Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an \"invalid pointer vulnerability,\" a different issue than CVE-2009-3464. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-458j-vj9v-25r8/GHSA-458j-vj9v-25r8.json b/advisories/unreviewed/2022/05/GHSA-458j-vj9v-25r8/GHSA-458j-vj9v-25r8.json index b7a3584c8bc..fbd9f8ed332 100644 --- a/advisories/unreviewed/2022/05/GHSA-458j-vj9v-25r8/GHSA-458j-vj9v-25r8.json +++ b/advisories/unreviewed/2022/05/GHSA-458j-vj9v-25r8/GHSA-458j-vj9v-25r8.json @@ -7,12 +7,8 @@ "CVE-2009-3353" ], "details": "Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-476g-xp34-4rj3/GHSA-476g-xp34-4rj3.json b/advisories/unreviewed/2022/05/GHSA-476g-xp34-4rj3/GHSA-476g-xp34-4rj3.json index fec12ade4a6..1b64e7f990c 100644 --- a/advisories/unreviewed/2022/05/GHSA-476g-xp34-4rj3/GHSA-476g-xp34-4rj3.json +++ b/advisories/unreviewed/2022/05/GHSA-476g-xp34-4rj3/GHSA-476g-xp34-4rj3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-478q-7xf2-cxcp/GHSA-478q-7xf2-cxcp.json b/advisories/unreviewed/2022/05/GHSA-478q-7xf2-cxcp/GHSA-478q-7xf2-cxcp.json index 22fbddb6fad..353732a7c7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-478q-7xf2-cxcp/GHSA-478q-7xf2-cxcp.json +++ b/advisories/unreviewed/2022/05/GHSA-478q-7xf2-cxcp/GHSA-478q-7xf2-cxcp.json @@ -7,12 +7,8 @@ "CVE-2009-3567" ], "details": "Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a different vector than CVE-2007-1145.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-479j-8mrp-jf68/GHSA-479j-8mrp-jf68.json b/advisories/unreviewed/2022/05/GHSA-479j-8mrp-jf68/GHSA-479j-8mrp-jf68.json index f2834642dc5..4e6d8dbcb5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-479j-8mrp-jf68/GHSA-479j-8mrp-jf68.json +++ b/advisories/unreviewed/2022/05/GHSA-479j-8mrp-jf68/GHSA-479j-8mrp-jf68.json @@ -7,12 +7,8 @@ "CVE-2009-3725" ], "details": "The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47gr-pfr8-r958/GHSA-47gr-pfr8-r958.json b/advisories/unreviewed/2022/05/GHSA-47gr-pfr8-r958/GHSA-47gr-pfr8-r958.json index ec157fbd7bd..0a2a5863df1 100644 --- a/advisories/unreviewed/2022/05/GHSA-47gr-pfr8-r958/GHSA-47gr-pfr8-r958.json +++ b/advisories/unreviewed/2022/05/GHSA-47gr-pfr8-r958/GHSA-47gr-pfr8-r958.json @@ -7,12 +7,8 @@ "CVE-2009-3518" ], "details": "Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47pm-rhm6-w3xc/GHSA-47pm-rhm6-w3xc.json b/advisories/unreviewed/2022/05/GHSA-47pm-rhm6-w3xc/GHSA-47pm-rhm6-w3xc.json index 6699ef67a09..df3a1c49d27 100644 --- a/advisories/unreviewed/2022/05/GHSA-47pm-rhm6-w3xc/GHSA-47pm-rhm6-w3xc.json +++ b/advisories/unreviewed/2022/05/GHSA-47pm-rhm6-w3xc/GHSA-47pm-rhm6-w3xc.json @@ -7,12 +7,8 @@ "CVE-2009-3707" ], "details": "VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \\x25\\xFF sequence in the USER and PASS commands, related to a \"format string DoS\" issue. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47wf-g7rm-46qq/GHSA-47wf-g7rm-46qq.json b/advisories/unreviewed/2022/05/GHSA-47wf-g7rm-46qq/GHSA-47wf-g7rm-46qq.json index 532b6982381..df6e8eac8ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-47wf-g7rm-46qq/GHSA-47wf-g7rm-46qq.json +++ b/advisories/unreviewed/2022/05/GHSA-47wf-g7rm-46qq/GHSA-47wf-g7rm-46qq.json @@ -7,12 +7,8 @@ "CVE-2009-3103" ], "details": "Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka \"SMBv2 Negotiation Vulnerability.\" NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48p6-fq4x-274j/GHSA-48p6-fq4x-274j.json b/advisories/unreviewed/2022/05/GHSA-48p6-fq4x-274j/GHSA-48p6-fq4x-274j.json index d2ee2911668..d7bff9c6cf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-48p6-fq4x-274j/GHSA-48p6-fq4x-274j.json +++ b/advisories/unreviewed/2022/05/GHSA-48p6-fq4x-274j/GHSA-48p6-fq4x-274j.json @@ -7,12 +7,8 @@ "CVE-2009-3284" ], "details": "Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48q7-r6r9-rhx2/GHSA-48q7-r6r9-rhx2.json b/advisories/unreviewed/2022/05/GHSA-48q7-r6r9-rhx2/GHSA-48q7-r6r9-rhx2.json index 67edacc6636..52407b6d50a 100644 --- a/advisories/unreviewed/2022/05/GHSA-48q7-r6r9-rhx2/GHSA-48q7-r6r9-rhx2.json +++ b/advisories/unreviewed/2022/05/GHSA-48q7-r6r9-rhx2/GHSA-48q7-r6r9-rhx2.json @@ -7,12 +7,8 @@ "CVE-2009-3664" ], "details": "Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (dot dot) in the (1) p and (2) s parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49c9-9c2p-h2gm/GHSA-49c9-9c2p-h2gm.json b/advisories/unreviewed/2022/05/GHSA-49c9-9c2p-h2gm/GHSA-49c9-9c2p-h2gm.json index 021c2781169..47dd4fe1789 100644 --- a/advisories/unreviewed/2022/05/GHSA-49c9-9c2p-h2gm/GHSA-49c9-9c2p-h2gm.json +++ b/advisories/unreviewed/2022/05/GHSA-49c9-9c2p-h2gm/GHSA-49c9-9c2p-h2gm.json @@ -7,12 +7,8 @@ "CVE-2009-3796" ], "details": "Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a \"data injection vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c32-x28m-p8h3/GHSA-4c32-x28m-p8h3.json b/advisories/unreviewed/2022/05/GHSA-4c32-x28m-p8h3/GHSA-4c32-x28m-p8h3.json index 6b8783c4eae..7fd363ca113 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c32-x28m-p8h3/GHSA-4c32-x28m-p8h3.json +++ b/advisories/unreviewed/2022/05/GHSA-4c32-x28m-p8h3/GHSA-4c32-x28m-p8h3.json @@ -7,12 +7,8 @@ "CVE-2009-3527" ], "details": "Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fq8-mjrf-79qc/GHSA-4fq8-mjrf-79qc.json b/advisories/unreviewed/2022/05/GHSA-4fq8-mjrf-79qc/GHSA-4fq8-mjrf-79qc.json index 611ab2d06d2..b1ed651e17c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fq8-mjrf-79qc/GHSA-4fq8-mjrf-79qc.json +++ b/advisories/unreviewed/2022/05/GHSA-4fq8-mjrf-79qc/GHSA-4fq8-mjrf-79qc.json @@ -7,12 +7,8 @@ "CVE-2009-3203" ], "details": "SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gfg-32rq-7753/GHSA-4gfg-32rq-7753.json b/advisories/unreviewed/2022/05/GHSA-4gfg-32rq-7753/GHSA-4gfg-32rq-7753.json index 26eb2c2c508..2c82fd70454 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gfg-32rq-7753/GHSA-4gfg-32rq-7753.json +++ b/advisories/unreviewed/2022/05/GHSA-4gfg-32rq-7753/GHSA-4gfg-32rq-7753.json @@ -7,12 +7,8 @@ "CVE-2009-3590" ], "details": "SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hfj-x2gr-q83x/GHSA-4hfj-x2gr-q83x.json b/advisories/unreviewed/2022/05/GHSA-4hfj-x2gr-q83x/GHSA-4hfj-x2gr-q83x.json index 61e36b3b89c..aa2b2f7ce5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hfj-x2gr-q83x/GHSA-4hfj-x2gr-q83x.json +++ b/advisories/unreviewed/2022/05/GHSA-4hfj-x2gr-q83x/GHSA-4hfj-x2gr-q83x.json @@ -7,12 +7,8 @@ "CVE-2009-3433" ], "details": "Unspecified vulnerability in clsetup in the configuration utility in Sun Solaris Cluster 3.2 allows local users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hgr-hf94-2xj2/GHSA-4hgr-hf94-2xj2.json b/advisories/unreviewed/2022/05/GHSA-4hgr-hf94-2xj2/GHSA-4hgr-hf94-2xj2.json index 5c718667ae6..fe2e6ecd6a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hgr-hf94-2xj2/GHSA-4hgr-hf94-2xj2.json +++ b/advisories/unreviewed/2022/05/GHSA-4hgr-hf94-2xj2/GHSA-4hgr-hf94-2xj2.json @@ -7,12 +7,8 @@ "CVE-2009-3105" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 211.241 for Domino 8.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR EZEL7UURYC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hjr-2692-85gm/GHSA-4hjr-2692-85gm.json b/advisories/unreviewed/2022/05/GHSA-4hjr-2692-85gm/GHSA-4hjr-2692-85gm.json index d4d7fb867ce..cf5d399cae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hjr-2692-85gm/GHSA-4hjr-2692-85gm.json +++ b/advisories/unreviewed/2022/05/GHSA-4hjr-2692-85gm/GHSA-4hjr-2692-85gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hwc-m82x-xf7x/GHSA-4hwc-m82x-xf7x.json b/advisories/unreviewed/2022/05/GHSA-4hwc-m82x-xf7x/GHSA-4hwc-m82x-xf7x.json index 3d9be189c00..53e83b7364a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hwc-m82x-xf7x/GHSA-4hwc-m82x-xf7x.json +++ b/advisories/unreviewed/2022/05/GHSA-4hwc-m82x-xf7x/GHSA-4hwc-m82x-xf7x.json @@ -7,12 +7,8 @@ "CVE-2009-3578" ], "details": "Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to \"Script Nodes.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jr8-gq3p-6jg6/GHSA-4jr8-gq3p-6jg6.json b/advisories/unreviewed/2022/05/GHSA-4jr8-gq3p-6jg6/GHSA-4jr8-gq3p-6jg6.json index 2f86b9c0ea8..16ac136e735 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jr8-gq3p-6jg6/GHSA-4jr8-gq3p-6jg6.json +++ b/advisories/unreviewed/2022/05/GHSA-4jr8-gq3p-6jg6/GHSA-4jr8-gq3p-6jg6.json @@ -7,12 +7,8 @@ "CVE-2009-3538" ], "details": "Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mxh-q2pf-wp5x/GHSA-4mxh-q2pf-wp5x.json b/advisories/unreviewed/2022/05/GHSA-4mxh-q2pf-wp5x/GHSA-4mxh-q2pf-wp5x.json index 95f3e9eb325..fd32fc48bfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mxh-q2pf-wp5x/GHSA-4mxh-q2pf-wp5x.json +++ b/advisories/unreviewed/2022/05/GHSA-4mxh-q2pf-wp5x/GHSA-4mxh-q2pf-wp5x.json @@ -7,12 +7,8 @@ "CVE-2009-3092" ], "details": "Buffer overflow on the ASUS WL-500W wireless router has unknown impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p9f-r8qj-23xf/GHSA-4p9f-r8qj-23xf.json b/advisories/unreviewed/2022/05/GHSA-4p9f-r8qj-23xf/GHSA-4p9f-r8qj-23xf.json index 0b47475fdd1..b924abadbaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p9f-r8qj-23xf/GHSA-4p9f-r8qj-23xf.json +++ b/advisories/unreviewed/2022/05/GHSA-4p9f-r8qj-23xf/GHSA-4p9f-r8qj-23xf.json @@ -7,12 +7,8 @@ "CVE-2009-3801" ], "details": "SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4q3c-jxc9-rf75/GHSA-4q3c-jxc9-rf75.json b/advisories/unreviewed/2022/05/GHSA-4q3c-jxc9-rf75/GHSA-4q3c-jxc9-rf75.json index 4948d7ee697..291785b94a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q3c-jxc9-rf75/GHSA-4q3c-jxc9-rf75.json +++ b/advisories/unreviewed/2022/05/GHSA-4q3c-jxc9-rf75/GHSA-4q3c-jxc9-rf75.json @@ -7,12 +7,8 @@ "CVE-2009-3762" ], "details": "Unspecified vulnerability in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q5h-m3w9-x569/GHSA-4q5h-m3w9-x569.json b/advisories/unreviewed/2022/05/GHSA-4q5h-m3w9-x569/GHSA-4q5h-m3w9-x569.json index a0f0afbef15..c5e4d64c92d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q5h-m3w9-x569/GHSA-4q5h-m3w9-x569.json +++ b/advisories/unreviewed/2022/05/GHSA-4q5h-m3w9-x569/GHSA-4q5h-m3w9-x569.json @@ -7,12 +7,8 @@ "CVE-2009-3528" ], "details": "SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qp4-ccmr-483g/GHSA-4qp4-ccmr-483g.json b/advisories/unreviewed/2022/05/GHSA-4qp4-ccmr-483g/GHSA-4qp4-ccmr-483g.json index a60bdf5db09..0333270fc49 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qp4-ccmr-483g/GHSA-4qp4-ccmr-483g.json +++ b/advisories/unreviewed/2022/05/GHSA-4qp4-ccmr-483g/GHSA-4qp4-ccmr-483g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rff-c4p8-c56p/GHSA-4rff-c4p8-c56p.json b/advisories/unreviewed/2022/05/GHSA-4rff-c4p8-c56p/GHSA-4rff-c4p8-c56p.json index adffd48b691..1fd14d40926 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rff-c4p8-c56p/GHSA-4rff-c4p8-c56p.json +++ b/advisories/unreviewed/2022/05/GHSA-4rff-c4p8-c56p/GHSA-4rff-c4p8-c56p.json @@ -7,12 +7,8 @@ "CVE-2009-3113" ], "details": "Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allows remote attackers to gain write access to product reviews via a crafted parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rvg-9g3m-4m9p/GHSA-4rvg-9g3m-4m9p.json b/advisories/unreviewed/2022/05/GHSA-4rvg-9g3m-4m9p/GHSA-4rvg-9g3m-4m9p.json index 110fa89ac50..4848c0fdf1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rvg-9g3m-4m9p/GHSA-4rvg-9g3m-4m9p.json +++ b/advisories/unreviewed/2022/05/GHSA-4rvg-9g3m-4m9p/GHSA-4rvg-9g3m-4m9p.json @@ -7,12 +7,8 @@ "CVE-2009-3645" ], "details": "SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rwr-62pp-84mp/GHSA-4rwr-62pp-84mp.json b/advisories/unreviewed/2022/05/GHSA-4rwr-62pp-84mp/GHSA-4rwr-62pp-84mp.json index 931ffc08873..0cbfecedaad 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rwr-62pp-84mp/GHSA-4rwr-62pp-84mp.json +++ b/advisories/unreviewed/2022/05/GHSA-4rwr-62pp-84mp/GHSA-4rwr-62pp-84mp.json @@ -7,12 +7,8 @@ "CVE-2009-3338" ], "details": "Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vp8-fm4w-fw2f/GHSA-4vp8-fm4w-fw2f.json b/advisories/unreviewed/2022/05/GHSA-4vp8-fm4w-fw2f/GHSA-4vp8-fm4w-fw2f.json index e5737e4c088..7691cde81da 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vp8-fm4w-fw2f/GHSA-4vp8-fm4w-fw2f.json +++ b/advisories/unreviewed/2022/05/GHSA-4vp8-fm4w-fw2f/GHSA-4vp8-fm4w-fw2f.json @@ -7,12 +7,8 @@ "CVE-2009-3501" ], "details": "SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vq9-9g4j-pgg4/GHSA-4vq9-9g4j-pgg4.json b/advisories/unreviewed/2022/05/GHSA-4vq9-9g4j-pgg4/GHSA-4vq9-9g4j-pgg4.json index 313e024972d..2ea7bad2d57 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vq9-9g4j-pgg4/GHSA-4vq9-9g4j-pgg4.json +++ b/advisories/unreviewed/2022/05/GHSA-4vq9-9g4j-pgg4/GHSA-4vq9-9g4j-pgg4.json @@ -7,12 +7,8 @@ "CVE-2009-3639" ], "details": "The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wf2-8957-vf9x/GHSA-4wf2-8957-vf9x.json b/advisories/unreviewed/2022/05/GHSA-4wf2-8957-vf9x/GHSA-4wf2-8957-vf9x.json index cbcfb9e57b0..bccdb1a055f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wf2-8957-vf9x/GHSA-4wf2-8957-vf9x.json +++ b/advisories/unreviewed/2022/05/GHSA-4wf2-8957-vf9x/GHSA-4wf2-8957-vf9x.json @@ -7,12 +7,8 @@ "CVE-2009-3128" ], "details": "Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka \"Excel SxView Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wp5-gx3f-rhgh/GHSA-4wp5-gx3f-rhgh.json b/advisories/unreviewed/2022/05/GHSA-4wp5-gx3f-rhgh/GHSA-4wp5-gx3f-rhgh.json index 2e922bbedcf..d85ab5d8dac 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wp5-gx3f-rhgh/GHSA-4wp5-gx3f-rhgh.json +++ b/advisories/unreviewed/2022/05/GHSA-4wp5-gx3f-rhgh/GHSA-4wp5-gx3f-rhgh.json @@ -7,12 +7,8 @@ "CVE-2009-3691" ], "details": "Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52p4-92p5-7qfq/GHSA-52p4-92p5-7qfq.json b/advisories/unreviewed/2022/05/GHSA-52p4-92p5-7qfq/GHSA-52p4-92p5-7qfq.json index 485a5f8c4cd..826c86d39b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-52p4-92p5-7qfq/GHSA-52p4-92p5-7qfq.json +++ b/advisories/unreviewed/2022/05/GHSA-52p4-92p5-7qfq/GHSA-52p4-92p5-7qfq.json @@ -7,12 +7,8 @@ "CVE-2009-3529" ], "details": "SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than CVE-2005-1074.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53g5-x4w6-f3r7/GHSA-53g5-x4w6-f3r7.json b/advisories/unreviewed/2022/05/GHSA-53g5-x4w6-f3r7/GHSA-53g5-x4w6-f3r7.json index 959c80e077b..cf8b7ab5eae 100644 --- a/advisories/unreviewed/2022/05/GHSA-53g5-x4w6-f3r7/GHSA-53g5-x4w6-f3r7.json +++ b/advisories/unreviewed/2022/05/GHSA-53g5-x4w6-f3r7/GHSA-53g5-x4w6-f3r7.json @@ -7,12 +7,8 @@ "CVE-2009-3669" ], "details": "SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json b/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json index 5b55cf64b39..97e33a7a534 100644 --- a/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json +++ b/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53q6-pfcm-jvjp/GHSA-53q6-pfcm-jvjp.json b/advisories/unreviewed/2022/05/GHSA-53q6-pfcm-jvjp/GHSA-53q6-pfcm-jvjp.json index 2b7308181d0..99d9c4b772f 100644 --- a/advisories/unreviewed/2022/05/GHSA-53q6-pfcm-jvjp/GHSA-53q6-pfcm-jvjp.json +++ b/advisories/unreviewed/2022/05/GHSA-53q6-pfcm-jvjp/GHSA-53q6-pfcm-jvjp.json @@ -7,12 +7,8 @@ "CVE-2009-3593" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter to post_resume.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-545v-887v-vf85/GHSA-545v-887v-vf85.json b/advisories/unreviewed/2022/05/GHSA-545v-887v-vf85/GHSA-545v-887v-vf85.json index c9f202783c4..0fce042406f 100644 --- a/advisories/unreviewed/2022/05/GHSA-545v-887v-vf85/GHSA-545v-887v-vf85.json +++ b/advisories/unreviewed/2022/05/GHSA-545v-887v-vf85/GHSA-545v-887v-vf85.json @@ -7,12 +7,8 @@ "CVE-2009-3714" ], "details": "Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-546g-4wj5-vp4x/GHSA-546g-4wj5-vp4x.json b/advisories/unreviewed/2022/05/GHSA-546g-4wj5-vp4x/GHSA-546g-4wj5-vp4x.json index e2ffb8981ce..c278be6ce99 100644 --- a/advisories/unreviewed/2022/05/GHSA-546g-4wj5-vp4x/GHSA-546g-4wj5-vp4x.json +++ b/advisories/unreviewed/2022/05/GHSA-546g-4wj5-vp4x/GHSA-546g-4wj5-vp4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54cg-rgh7-pj5q/GHSA-54cg-rgh7-pj5q.json b/advisories/unreviewed/2022/05/GHSA-54cg-rgh7-pj5q/GHSA-54cg-rgh7-pj5q.json index f3df500c5e1..d1808f1c4e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-54cg-rgh7-pj5q/GHSA-54cg-rgh7-pj5q.json +++ b/advisories/unreviewed/2022/05/GHSA-54cg-rgh7-pj5q/GHSA-54cg-rgh7-pj5q.json @@ -7,12 +7,8 @@ "CVE-2009-3728" ], "details": "Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54r7-jqjw-9p94/GHSA-54r7-jqjw-9p94.json b/advisories/unreviewed/2022/05/GHSA-54r7-jqjw-9p94/GHSA-54r7-jqjw-9p94.json index 36a0cea7434..f6e03a65a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-54r7-jqjw-9p94/GHSA-54r7-jqjw-9p94.json +++ b/advisories/unreviewed/2022/05/GHSA-54r7-jqjw-9p94/GHSA-54r7-jqjw-9p94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55hp-jcxq-hgwc/GHSA-55hp-jcxq-hgwc.json b/advisories/unreviewed/2022/05/GHSA-55hp-jcxq-hgwc/GHSA-55hp-jcxq-hgwc.json index eb624370bf5..2719f3da564 100644 --- a/advisories/unreviewed/2022/05/GHSA-55hp-jcxq-hgwc/GHSA-55hp-jcxq-hgwc.json +++ b/advisories/unreviewed/2022/05/GHSA-55hp-jcxq-hgwc/GHSA-55hp-jcxq-hgwc.json @@ -7,12 +7,8 @@ "CVE-2009-3634" ], "details": "Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56ww-7836-2fcq/GHSA-56ww-7836-2fcq.json b/advisories/unreviewed/2022/05/GHSA-56ww-7836-2fcq/GHSA-56ww-7836-2fcq.json index 37313acf255..cef2c03624d 100644 --- a/advisories/unreviewed/2022/05/GHSA-56ww-7836-2fcq/GHSA-56ww-7836-2fcq.json +++ b/advisories/unreviewed/2022/05/GHSA-56ww-7836-2fcq/GHSA-56ww-7836-2fcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-575w-rwc7-4259/GHSA-575w-rwc7-4259.json b/advisories/unreviewed/2022/05/GHSA-575w-rwc7-4259/GHSA-575w-rwc7-4259.json index af1ab0b1719..282c28a5226 100644 --- a/advisories/unreviewed/2022/05/GHSA-575w-rwc7-4259/GHSA-575w-rwc7-4259.json +++ b/advisories/unreviewed/2022/05/GHSA-575w-rwc7-4259/GHSA-575w-rwc7-4259.json @@ -7,12 +7,8 @@ "CVE-2009-3474" ], "details": "OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-576r-h2rw-fh3f/GHSA-576r-h2rw-fh3f.json b/advisories/unreviewed/2022/05/GHSA-576r-h2rw-fh3f/GHSA-576r-h2rw-fh3f.json index 55fcc13aecf..f7fe15839a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-576r-h2rw-fh3f/GHSA-576r-h2rw-fh3f.json +++ b/advisories/unreviewed/2022/05/GHSA-576r-h2rw-fh3f/GHSA-576r-h2rw-fh3f.json @@ -7,12 +7,8 @@ "CVE-2009-3342" ], "details": "SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58gm-g38v-xch5/GHSA-58gm-g38v-xch5.json b/advisories/unreviewed/2022/05/GHSA-58gm-g38v-xch5/GHSA-58gm-g38v-xch5.json index 0e0d63f9123..4b20e979c53 100644 --- a/advisories/unreviewed/2022/05/GHSA-58gm-g38v-xch5/GHSA-58gm-g38v-xch5.json +++ b/advisories/unreviewed/2022/05/GHSA-58gm-g38v-xch5/GHSA-58gm-g38v-xch5.json @@ -7,12 +7,8 @@ "CVE-2009-3451" ], "details": "Directory traversal vulnerability in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to read arbitrary files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58jj-372m-hm97/GHSA-58jj-372m-hm97.json b/advisories/unreviewed/2022/05/GHSA-58jj-372m-hm97/GHSA-58jj-372m-hm97.json index 576bd213a95..cbf0620aba9 100644 --- a/advisories/unreviewed/2022/05/GHSA-58jj-372m-hm97/GHSA-58jj-372m-hm97.json +++ b/advisories/unreviewed/2022/05/GHSA-58jj-372m-hm97/GHSA-58jj-372m-hm97.json @@ -7,12 +7,8 @@ "CVE-2009-3460" ], "details": "Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5956-hhvq-fv53/GHSA-5956-hhvq-fv53.json b/advisories/unreviewed/2022/05/GHSA-5956-hhvq-fv53/GHSA-5956-hhvq-fv53.json index c68dd7cc27f..3c9d2cd7072 100644 --- a/advisories/unreviewed/2022/05/GHSA-5956-hhvq-fv53/GHSA-5956-hhvq-fv53.json +++ b/advisories/unreviewed/2022/05/GHSA-5956-hhvq-fv53/GHSA-5956-hhvq-fv53.json @@ -7,12 +7,8 @@ "CVE-2009-3106" ], "details": "The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59fg-mjcp-w8r4/GHSA-59fg-mjcp-w8r4.json b/advisories/unreviewed/2022/05/GHSA-59fg-mjcp-w8r4/GHSA-59fg-mjcp-w8r4.json index da78f4d3bb0..b3477068cbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-59fg-mjcp-w8r4/GHSA-59fg-mjcp-w8r4.json +++ b/advisories/unreviewed/2022/05/GHSA-59fg-mjcp-w8r4/GHSA-59fg-mjcp-w8r4.json @@ -7,12 +7,8 @@ "CVE-2009-3367" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59p8-gqqx-vfr6/GHSA-59p8-gqqx-vfr6.json b/advisories/unreviewed/2022/05/GHSA-59p8-gqqx-vfr6/GHSA-59p8-gqqx-vfr6.json index e6822ced163..942ca1f0a2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-59p8-gqqx-vfr6/GHSA-59p8-gqqx-vfr6.json +++ b/advisories/unreviewed/2022/05/GHSA-59p8-gqqx-vfr6/GHSA-59p8-gqqx-vfr6.json @@ -7,12 +7,8 @@ "CVE-2009-3574" ], "details": "Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a .pls playlist file, possibly a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59w3-gq45-h2m8/GHSA-59w3-gq45-h2m8.json b/advisories/unreviewed/2022/05/GHSA-59w3-gq45-h2m8/GHSA-59w3-gq45-h2m8.json index b3c5fd842f6..d8f7364fbe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-59w3-gq45-h2m8/GHSA-59w3-gq45-h2m8.json +++ b/advisories/unreviewed/2022/05/GHSA-59w3-gq45-h2m8/GHSA-59w3-gq45-h2m8.json @@ -7,12 +7,8 @@ "CVE-2009-3600" ], "details": "HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json b/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json index 69edaa49d09..2ce8f66a313 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json +++ b/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c6q-9638-267m/GHSA-5c6q-9638-267m.json b/advisories/unreviewed/2022/05/GHSA-5c6q-9638-267m/GHSA-5c6q-9638-267m.json index 60016cd4dd2..a3268ca5a37 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c6q-9638-267m/GHSA-5c6q-9638-267m.json +++ b/advisories/unreviewed/2022/05/GHSA-5c6q-9638-267m/GHSA-5c6q-9638-267m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cph-mc6w-g6xg/GHSA-5cph-mc6w-g6xg.json b/advisories/unreviewed/2022/05/GHSA-5cph-mc6w-g6xg/GHSA-5cph-mc6w-g6xg.json index b4ce930219b..fa6fd151058 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cph-mc6w-g6xg/GHSA-5cph-mc6w-g6xg.json +++ b/advisories/unreviewed/2022/05/GHSA-5cph-mc6w-g6xg/GHSA-5cph-mc6w-g6xg.json @@ -7,12 +7,8 @@ "CVE-2009-3470" ], "details": "IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a denial of service (memory corruption, assertion failure, and daemon crash) by sending a long password over a JDBC connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h56-9gpv-f6cx/GHSA-5h56-9gpv-f6cx.json b/advisories/unreviewed/2022/05/GHSA-5h56-9gpv-f6cx/GHSA-5h56-9gpv-f6cx.json index 44698b21fe8..fba6d473651 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h56-9gpv-f6cx/GHSA-5h56-9gpv-f6cx.json +++ b/advisories/unreviewed/2022/05/GHSA-5h56-9gpv-f6cx/GHSA-5h56-9gpv-f6cx.json @@ -7,12 +7,8 @@ "CVE-2009-3222" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jj7-6jx2-x56m/GHSA-5jj7-6jx2-x56m.json b/advisories/unreviewed/2022/05/GHSA-5jj7-6jx2-x56m/GHSA-5jj7-6jx2-x56m.json index 259399f8804..9423df41158 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jj7-6jx2-x56m/GHSA-5jj7-6jx2-x56m.json +++ b/advisories/unreviewed/2022/05/GHSA-5jj7-6jx2-x56m/GHSA-5jj7-6jx2-x56m.json @@ -7,12 +7,8 @@ "CVE-2009-3716" ], "details": "Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jx7-7v29-v3mc/GHSA-5jx7-7v29-v3mc.json b/advisories/unreviewed/2022/05/GHSA-5jx7-7v29-v3mc/GHSA-5jx7-7v29-v3mc.json index d58ca264e21..cee4ba604a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jx7-7v29-v3mc/GHSA-5jx7-7v29-v3mc.json +++ b/advisories/unreviewed/2022/05/GHSA-5jx7-7v29-v3mc/GHSA-5jx7-7v29-v3mc.json @@ -7,12 +7,8 @@ "CVE-2009-3409" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5m9w-mc2w-2vgj/GHSA-5m9w-mc2w-2vgj.json b/advisories/unreviewed/2022/05/GHSA-5m9w-mc2w-2vgj/GHSA-5m9w-mc2w-2vgj.json index 57d9a27ef95..f58dc0212a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m9w-mc2w-2vgj/GHSA-5m9w-mc2w-2vgj.json +++ b/advisories/unreviewed/2022/05/GHSA-5m9w-mc2w-2vgj/GHSA-5m9w-mc2w-2vgj.json @@ -7,12 +7,8 @@ "CVE-2009-3673" ], "details": "Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p8v-454h-7rv7/GHSA-5p8v-454h-7rv7.json b/advisories/unreviewed/2022/05/GHSA-5p8v-454h-7rv7/GHSA-5p8v-454h-7rv7.json index e8ea6bc1f1d..343b8737640 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p8v-454h-7rv7/GHSA-5p8v-454h-7rv7.json +++ b/advisories/unreviewed/2022/05/GHSA-5p8v-454h-7rv7/GHSA-5p8v-454h-7rv7.json @@ -7,12 +7,8 @@ "CVE-2009-3660" ], "details": "PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pq2-2975-f8c8/GHSA-5pq2-2975-f8c8.json b/advisories/unreviewed/2022/05/GHSA-5pq2-2975-f8c8/GHSA-5pq2-2975-f8c8.json index 5e9462a4579..d838189213e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pq2-2975-f8c8/GHSA-5pq2-2975-f8c8.json +++ b/advisories/unreviewed/2022/05/GHSA-5pq2-2975-f8c8/GHSA-5pq2-2975-f8c8.json @@ -7,12 +7,8 @@ "CVE-2009-3619" ], "details": "Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to \"printing illegal parameter names and values.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r4q-84cw-cpwc/GHSA-5r4q-84cw-cpwc.json b/advisories/unreviewed/2022/05/GHSA-5r4q-84cw-cpwc/GHSA-5r4q-84cw-cpwc.json index 0382feddd4a..97b2c0c48aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r4q-84cw-cpwc/GHSA-5r4q-84cw-cpwc.json +++ b/advisories/unreviewed/2022/05/GHSA-5r4q-84cw-cpwc/GHSA-5r4q-84cw-cpwc.json @@ -7,12 +7,8 @@ "CVE-2009-3226" ], "details": "SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vqg-4pw8-x3vj/GHSA-5vqg-4pw8-x3vj.json b/advisories/unreviewed/2022/05/GHSA-5vqg-4pw8-x3vj/GHSA-5vqg-4pw8-x3vj.json index 70e490f749a..1981b21ef49 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vqg-4pw8-x3vj/GHSA-5vqg-4pw8-x3vj.json +++ b/advisories/unreviewed/2022/05/GHSA-5vqg-4pw8-x3vj/GHSA-5vqg-4pw8-x3vj.json @@ -7,12 +7,8 @@ "CVE-2009-3315" ], "details": "SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vxp-j78v-p6qp/GHSA-5vxp-j78v-p6qp.json b/advisories/unreviewed/2022/05/GHSA-5vxp-j78v-p6qp/GHSA-5vxp-j78v-p6qp.json index 915d701b2d2..be157fa0ecf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vxp-j78v-p6qp/GHSA-5vxp-j78v-p6qp.json +++ b/advisories/unreviewed/2022/05/GHSA-5vxp-j78v-p6qp/GHSA-5vxp-j78v-p6qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w95-m5g4-hrhx/GHSA-5w95-m5g4-hrhx.json b/advisories/unreviewed/2022/05/GHSA-5w95-m5g4-hrhx/GHSA-5w95-m5g4-hrhx.json index b38bd4f3b5f..bc58827e92b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w95-m5g4-hrhx/GHSA-5w95-m5g4-hrhx.json +++ b/advisories/unreviewed/2022/05/GHSA-5w95-m5g4-hrhx/GHSA-5w95-m5g4-hrhx.json @@ -7,12 +7,8 @@ "CVE-2009-3130" ], "details": "Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka \"Excel Document Parsing Heap Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wcj-3w9q-9gp9/GHSA-5wcj-3w9q-9gp9.json b/advisories/unreviewed/2022/05/GHSA-5wcj-3w9q-9gp9/GHSA-5wcj-3w9q-9gp9.json index e45f012639c..e61c9893f67 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wcj-3w9q-9gp9/GHSA-5wcj-3w9q-9gp9.json +++ b/advisories/unreviewed/2022/05/GHSA-5wcj-3w9q-9gp9/GHSA-5wcj-3w9q-9gp9.json @@ -7,12 +7,8 @@ "CVE-2009-3661" ], "details": "Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json b/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json index 45d33e0929b..2af34d89d1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json +++ b/advisories/unreviewed/2022/05/GHSA-5wvr-c5h8-vf7f/GHSA-5wvr-c5h8-vf7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x7c-p595-fhwh/GHSA-5x7c-p595-fhwh.json b/advisories/unreviewed/2022/05/GHSA-5x7c-p595-fhwh/GHSA-5x7c-p595-fhwh.json index cc506cd9fb1..2f2904cfdd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x7c-p595-fhwh/GHSA-5x7c-p595-fhwh.json +++ b/advisories/unreviewed/2022/05/GHSA-5x7c-p595-fhwh/GHSA-5x7c-p595-fhwh.json @@ -7,12 +7,8 @@ "CVE-2009-3281" ], "details": "The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xfg-3m42-q8mv/GHSA-5xfg-3m42-q8mv.json b/advisories/unreviewed/2022/05/GHSA-5xfg-3m42-q8mv/GHSA-5xfg-3m42-q8mv.json index 23f0c716c0b..670e8fd9a9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xfg-3m42-q8mv/GHSA-5xfg-3m42-q8mv.json +++ b/advisories/unreviewed/2022/05/GHSA-5xfg-3m42-q8mv/GHSA-5xfg-3m42-q8mv.json @@ -7,12 +7,8 @@ "CVE-2009-3461" ], "details": "Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62wr-q7q7-4f5m/GHSA-62wr-q7q7-4f5m.json b/advisories/unreviewed/2022/05/GHSA-62wr-q7q7-4f5m/GHSA-62wr-q7q7-4f5m.json index c34dad01088..a85ada48f7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-62wr-q7q7-4f5m/GHSA-62wr-q7q7-4f5m.json +++ b/advisories/unreviewed/2022/05/GHSA-62wr-q7q7-4f5m/GHSA-62wr-q7q7-4f5m.json @@ -7,12 +7,8 @@ "CVE-2009-3568" ], "details": "Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-637x-5jgj-26w6/GHSA-637x-5jgj-26w6.json b/advisories/unreviewed/2022/05/GHSA-637x-5jgj-26w6/GHSA-637x-5jgj-26w6.json index 4c08c01d6e6..5a6649ab3d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-637x-5jgj-26w6/GHSA-637x-5jgj-26w6.json +++ b/advisories/unreviewed/2022/05/GHSA-637x-5jgj-26w6/GHSA-637x-5jgj-26w6.json @@ -7,12 +7,8 @@ "CVE-2009-3493" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6384-2w9h-qw8w/GHSA-6384-2w9h-qw8w.json b/advisories/unreviewed/2022/05/GHSA-6384-2w9h-qw8w/GHSA-6384-2w9h-qw8w.json index 778786c8775..1d2cd97250e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6384-2w9h-qw8w/GHSA-6384-2w9h-qw8w.json +++ b/advisories/unreviewed/2022/05/GHSA-6384-2w9h-qw8w/GHSA-6384-2w9h-qw8w.json @@ -7,12 +7,8 @@ "CVE-2009-3564" ], "details": "puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63pv-4q6j-7pxp/GHSA-63pv-4q6j-7pxp.json b/advisories/unreviewed/2022/05/GHSA-63pv-4q6j-7pxp/GHSA-63pv-4q6j-7pxp.json index f1ff780cd91..5597319f146 100644 --- a/advisories/unreviewed/2022/05/GHSA-63pv-4q6j-7pxp/GHSA-63pv-4q6j-7pxp.json +++ b/advisories/unreviewed/2022/05/GHSA-63pv-4q6j-7pxp/GHSA-63pv-4q6j-7pxp.json @@ -7,12 +7,8 @@ "CVE-2009-3362" ], "details": "PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6476-7f65-cc4m/GHSA-6476-7f65-cc4m.json b/advisories/unreviewed/2022/05/GHSA-6476-7f65-cc4m/GHSA-6476-7f65-cc4m.json index 802cac92267..443c81b57ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-6476-7f65-cc4m/GHSA-6476-7f65-cc4m.json +++ b/advisories/unreviewed/2022/05/GHSA-6476-7f65-cc4m/GHSA-6476-7f65-cc4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65m7-qc75-24vh/GHSA-65m7-qc75-24vh.json b/advisories/unreviewed/2022/05/GHSA-65m7-qc75-24vh/GHSA-65m7-qc75-24vh.json index 3583c385cb4..7ef2384d433 100644 --- a/advisories/unreviewed/2022/05/GHSA-65m7-qc75-24vh/GHSA-65m7-qc75-24vh.json +++ b/advisories/unreviewed/2022/05/GHSA-65m7-qc75-24vh/GHSA-65m7-qc75-24vh.json @@ -7,12 +7,8 @@ "CVE-2009-3523" ], "details": "aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66v9-pvqf-v3jj/GHSA-66v9-pvqf-v3jj.json b/advisories/unreviewed/2022/05/GHSA-66v9-pvqf-v3jj/GHSA-66v9-pvqf-v3jj.json index d2c96815144..a36cc56b842 100644 --- a/advisories/unreviewed/2022/05/GHSA-66v9-pvqf-v3jj/GHSA-66v9-pvqf-v3jj.json +++ b/advisories/unreviewed/2022/05/GHSA-66v9-pvqf-v3jj/GHSA-66v9-pvqf-v3jj.json @@ -7,12 +7,8 @@ "CVE-2009-3807" ], "details": "Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-687w-xp39-q584/GHSA-687w-xp39-q584.json b/advisories/unreviewed/2022/05/GHSA-687w-xp39-q584/GHSA-687w-xp39-q584.json index 4f9e91d594e..7ec0c3543a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-687w-xp39-q584/GHSA-687w-xp39-q584.json +++ b/advisories/unreviewed/2022/05/GHSA-687w-xp39-q584/GHSA-687w-xp39-q584.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69p6-c7wv-2f89/GHSA-69p6-c7wv-2f89.json b/advisories/unreviewed/2022/05/GHSA-69p6-c7wv-2f89/GHSA-69p6-c7wv-2f89.json index 6b021b56185..eed2f4c384e 100644 --- a/advisories/unreviewed/2022/05/GHSA-69p6-c7wv-2f89/GHSA-69p6-c7wv-2f89.json +++ b/advisories/unreviewed/2022/05/GHSA-69p6-c7wv-2f89/GHSA-69p6-c7wv-2f89.json @@ -7,12 +7,8 @@ "CVE-2009-3415" ], "details": "Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c46-7rvf-rgx4/GHSA-6c46-7rvf-rgx4.json b/advisories/unreviewed/2022/05/GHSA-6c46-7rvf-rgx4/GHSA-6c46-7rvf-rgx4.json index 45f7283ca11..bfcfd692a8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c46-7rvf-rgx4/GHSA-6c46-7rvf-rgx4.json +++ b/advisories/unreviewed/2022/05/GHSA-6c46-7rvf-rgx4/GHSA-6c46-7rvf-rgx4.json @@ -7,12 +7,8 @@ "CVE-2009-3422" ], "details": "login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cf4-r7qc-3553/GHSA-6cf4-r7qc-3553.json b/advisories/unreviewed/2022/05/GHSA-6cf4-r7qc-3553/GHSA-6cf4-r7qc-3553.json index 99174175bce..529bc35ab02 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cf4-r7qc-3553/GHSA-6cf4-r7qc-3553.json +++ b/advisories/unreviewed/2022/05/GHSA-6cf4-r7qc-3553/GHSA-6cf4-r7qc-3553.json @@ -7,12 +7,8 @@ "CVE-2009-3599" ], "details": "Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitrary web script or HTML via the bid_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cmv-j38v-h7wc/GHSA-6cmv-j38v-h7wc.json b/advisories/unreviewed/2022/05/GHSA-6cmv-j38v-h7wc/GHSA-6cmv-j38v-h7wc.json index d7bec01b8f0..68ebf0ffe45 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cmv-j38v-h7wc/GHSA-6cmv-j38v-h7wc.json +++ b/advisories/unreviewed/2022/05/GHSA-6cmv-j38v-h7wc/GHSA-6cmv-j38v-h7wc.json @@ -7,12 +7,8 @@ "CVE-2009-3672" ], "details": "Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method for the STYLE tag name, selection of the single element in the returned list, and a change to the outerHTML property of this element, related to Cascading Style Sheets (CSS) and mshtml.dll, aka \"HTML Object Memory Corruption Vulnerability.\" NOTE: some of these details are obtained from third party information. NOTE: this issue was originally assigned CVE-2009-4054, but Microsoft assigned a duplicate identifier of CVE-2009-3672. CVE consumers should use this identifier instead of CVE-2009-4054.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f53-c85c-88pq/GHSA-6f53-c85c-88pq.json b/advisories/unreviewed/2022/05/GHSA-6f53-c85c-88pq/GHSA-6f53-c85c-88pq.json index caf91628f62..1177c2cf878 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f53-c85c-88pq/GHSA-6f53-c85c-88pq.json +++ b/advisories/unreviewed/2022/05/GHSA-6f53-c85c-88pq/GHSA-6f53-c85c-88pq.json @@ -7,12 +7,8 @@ "CVE-2009-3359" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f74-rcv9-9q87/GHSA-6f74-rcv9-9q87.json b/advisories/unreviewed/2022/05/GHSA-6f74-rcv9-9q87/GHSA-6f74-rcv9-9q87.json index 9b07ade3f82..3d19a978067 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f74-rcv9-9q87/GHSA-6f74-rcv9-9q87.json +++ b/advisories/unreviewed/2022/05/GHSA-6f74-rcv9-9q87/GHSA-6f74-rcv9-9q87.json @@ -7,12 +7,8 @@ "CVE-2009-3408" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g6p-2rvm-4c95/GHSA-6g6p-2rvm-4c95.json b/advisories/unreviewed/2022/05/GHSA-6g6p-2rvm-4c95/GHSA-6g6p-2rvm-4c95.json index 4e1af3e5123..ddf7d7bc91b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g6p-2rvm-4c95/GHSA-6g6p-2rvm-4c95.json +++ b/advisories/unreviewed/2022/05/GHSA-6g6p-2rvm-4c95/GHSA-6g6p-2rvm-4c95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g82-jmg8-h26c/GHSA-6g82-jmg8-h26c.json b/advisories/unreviewed/2022/05/GHSA-6g82-jmg8-h26c/GHSA-6g82-jmg8-h26c.json index bba8f7b8238..a0d5a9c8fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g82-jmg8-h26c/GHSA-6g82-jmg8-h26c.json +++ b/advisories/unreviewed/2022/05/GHSA-6g82-jmg8-h26c/GHSA-6g82-jmg8-h26c.json @@ -7,12 +7,8 @@ "CVE-2009-3477" ], "details": "The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle \"hidden\" characters including a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hxv-37vc-85r6/GHSA-6hxv-37vc-85r6.json b/advisories/unreviewed/2022/05/GHSA-6hxv-37vc-85r6/GHSA-6hxv-37vc-85r6.json index 4148111aef9..4fd8ce0d07e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hxv-37vc-85r6/GHSA-6hxv-37vc-85r6.json +++ b/advisories/unreviewed/2022/05/GHSA-6hxv-37vc-85r6/GHSA-6hxv-37vc-85r6.json @@ -7,12 +7,8 @@ "CVE-2009-3788" ], "details": "SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j26-gcxp-q5qw/GHSA-6j26-gcxp-q5qw.json b/advisories/unreviewed/2022/05/GHSA-6j26-gcxp-q5qw/GHSA-6j26-gcxp-q5qw.json index 8ad7013e853..69d990c69b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j26-gcxp-q5qw/GHSA-6j26-gcxp-q5qw.json +++ b/advisories/unreviewed/2022/05/GHSA-6j26-gcxp-q5qw/GHSA-6j26-gcxp-q5qw.json @@ -7,12 +7,8 @@ "CVE-2009-3186" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to forum.php, (2) profile_name parameter to profile.php, and (3) p parameter to view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j49-3xhq-p58w/GHSA-6j49-3xhq-p58w.json b/advisories/unreviewed/2022/05/GHSA-6j49-3xhq-p58w/GHSA-6j49-3xhq-p58w.json index 3026b28206a..9597aa4866a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j49-3xhq-p58w/GHSA-6j49-3xhq-p58w.json +++ b/advisories/unreviewed/2022/05/GHSA-6j49-3xhq-p58w/GHSA-6j49-3xhq-p58w.json @@ -7,12 +7,8 @@ "CVE-2009-3368" ], "details": "Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jvf-r79g-h3f2/GHSA-6jvf-r79g-h3f2.json b/advisories/unreviewed/2022/05/GHSA-6jvf-r79g-h3f2/GHSA-6jvf-r79g-h3f2.json index 9843091c406..0b354d54072 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jvf-r79g-h3f2/GHSA-6jvf-r79g-h3f2.json +++ b/advisories/unreviewed/2022/05/GHSA-6jvf-r79g-h3f2/GHSA-6jvf-r79g-h3f2.json @@ -7,12 +7,8 @@ "CVE-2009-3478" ], "details": "Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP users to cause victims to alter permissions, delete, download, or move the wrong file via a filename containing \" (double quotes), which is not properly filtered or encoded when FireFTP constructs the command to send to psftp.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mxq-8h76-443w/GHSA-6mxq-8h76-443w.json b/advisories/unreviewed/2022/05/GHSA-6mxq-8h76-443w/GHSA-6mxq-8h76-443w.json index 519864b9178..47f6fbb8c48 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mxq-8h76-443w/GHSA-6mxq-8h76-443w.json +++ b/advisories/unreviewed/2022/05/GHSA-6mxq-8h76-443w/GHSA-6mxq-8h76-443w.json @@ -7,12 +7,8 @@ "CVE-2009-3280" ], "details": "Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel before 2.6.31.1-rc1 allows remote attackers to cause a denial of service (soft lockup) via malformed packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p2r-x9m6-65cq/GHSA-6p2r-x9m6-65cq.json b/advisories/unreviewed/2022/05/GHSA-6p2r-x9m6-65cq/GHSA-6p2r-x9m6-65cq.json index 513a93fe1eb..338c7556e3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p2r-x9m6-65cq/GHSA-6p2r-x9m6-65cq.json +++ b/advisories/unreviewed/2022/05/GHSA-6p2r-x9m6-65cq/GHSA-6p2r-x9m6-65cq.json @@ -7,12 +7,8 @@ "CVE-2009-3557" ], "details": "The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p5c-44cm-r9m8/GHSA-6p5c-44cm-r9m8.json b/advisories/unreviewed/2022/05/GHSA-6p5c-44cm-r9m8/GHSA-6p5c-44cm-r9m8.json index 73a3c9b9d3a..6dc5d0ae9c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p5c-44cm-r9m8/GHSA-6p5c-44cm-r9m8.json +++ b/advisories/unreviewed/2022/05/GHSA-6p5c-44cm-r9m8/GHSA-6p5c-44cm-r9m8.json @@ -7,12 +7,8 @@ "CVE-2009-3490" ], "details": "GNU Wget before 1.12 does not properly handle a '\\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p6p-2fm3-6874/GHSA-6p6p-2fm3-6874.json b/advisories/unreviewed/2022/05/GHSA-6p6p-2fm3-6874/GHSA-6p6p-2fm3-6874.json index 820c6e4657c..b3783f588ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p6p-2fm3-6874/GHSA-6p6p-2fm3-6874.json +++ b/advisories/unreviewed/2022/05/GHSA-6p6p-2fm3-6874/GHSA-6p6p-2fm3-6874.json @@ -7,12 +7,8 @@ "CVE-2009-3698" ], "details": "An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6phm-2qcc-r8vp/GHSA-6phm-2qcc-r8vp.json b/advisories/unreviewed/2022/05/GHSA-6phm-2qcc-r8vp/GHSA-6phm-2qcc-r8vp.json index 67403544eba..9ab4db7ad09 100644 --- a/advisories/unreviewed/2022/05/GHSA-6phm-2qcc-r8vp/GHSA-6phm-2qcc-r8vp.json +++ b/advisories/unreviewed/2022/05/GHSA-6phm-2qcc-r8vp/GHSA-6phm-2qcc-r8vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6pj7-7hg8-7vr5/GHSA-6pj7-7hg8-7vr5.json b/advisories/unreviewed/2022/05/GHSA-6pj7-7hg8-7vr5/GHSA-6pj7-7hg8-7vr5.json index 6d6475e14ec..ca01b1ce8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pj7-7hg8-7vr5/GHSA-6pj7-7hg8-7vr5.json +++ b/advisories/unreviewed/2022/05/GHSA-6pj7-7hg8-7vr5/GHSA-6pj7-7hg8-7vr5.json @@ -7,12 +7,8 @@ "CVE-2009-3804" ], "details": "Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qwv-phcw-fvw8/GHSA-6qwv-phcw-fvw8.json b/advisories/unreviewed/2022/05/GHSA-6qwv-phcw-fvw8/GHSA-6qwv-phcw-fvw8.json index 6b7da4726a6..65bb6bd3a44 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qwv-phcw-fvw8/GHSA-6qwv-phcw-fvw8.json +++ b/advisories/unreviewed/2022/05/GHSA-6qwv-phcw-fvw8/GHSA-6qwv-phcw-fvw8.json @@ -7,12 +7,8 @@ "CVE-2009-3427" ], "details": "Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote attackers to inject arbitrary web script or HTML via the subject field in a ticket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r2f-63wm-774p/GHSA-6r2f-63wm-774p.json b/advisories/unreviewed/2022/05/GHSA-6r2f-63wm-774p/GHSA-6r2f-63wm-774p.json index d5bd2e79047..4654fc4bf43 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r2f-63wm-774p/GHSA-6r2f-63wm-774p.json +++ b/advisories/unreviewed/2022/05/GHSA-6r2f-63wm-774p/GHSA-6r2f-63wm-774p.json @@ -7,12 +7,8 @@ "CVE-2009-3269" ], "details": "Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic submissions of a form containing a KEYGEN element, a related issue to CVE-2009-1828.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v2v-v7qj-rp8x/GHSA-6v2v-v7qj-rp8x.json b/advisories/unreviewed/2022/05/GHSA-6v2v-v7qj-rp8x/GHSA-6v2v-v7qj-rp8x.json index afd57312a8b..bda7a0939f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v2v-v7qj-rp8x/GHSA-6v2v-v7qj-rp8x.json +++ b/advisories/unreviewed/2022/05/GHSA-6v2v-v7qj-rp8x/GHSA-6v2v-v7qj-rp8x.json @@ -7,12 +7,8 @@ "CVE-2009-3213" ], "details": "Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .mp3 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v4j-2r9w-m853/GHSA-6v4j-2r9w-m853.json b/advisories/unreviewed/2022/05/GHSA-6v4j-2r9w-m853/GHSA-6v4j-2r9w-m853.json index 5c3f8e645da..4d90319999a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v4j-2r9w-m853/GHSA-6v4j-2r9w-m853.json +++ b/advisories/unreviewed/2022/05/GHSA-6v4j-2r9w-m853/GHSA-6v4j-2r9w-m853.json @@ -7,12 +7,8 @@ "CVE-2009-3411" ], "details": "Unspecified vulnerability in the Oracle Data Pump component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x9q-9h2v-cmc6/GHSA-6x9q-9h2v-cmc6.json b/advisories/unreviewed/2022/05/GHSA-6x9q-9h2v-cmc6/GHSA-6x9q-9h2v-cmc6.json index 1249ba2f5f2..929f76d4f35 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x9q-9h2v-cmc6/GHSA-6x9q-9h2v-cmc6.json +++ b/advisories/unreviewed/2022/05/GHSA-6x9q-9h2v-cmc6/GHSA-6x9q-9h2v-cmc6.json @@ -7,12 +7,8 @@ "CVE-2009-3697" ], "details": "SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xqh-rgjg-4vg5/GHSA-6xqh-rgjg-4vg5.json b/advisories/unreviewed/2022/05/GHSA-6xqh-rgjg-4vg5/GHSA-6xqh-rgjg-4vg5.json index 0c93c666be0..be9326f1618 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xqh-rgjg-4vg5/GHSA-6xqh-rgjg-4vg5.json +++ b/advisories/unreviewed/2022/05/GHSA-6xqh-rgjg-4vg5/GHSA-6xqh-rgjg-4vg5.json @@ -7,12 +7,8 @@ "CVE-2009-3466" ], "details": "Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an \"invalid string length vulnerability.\" NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72c6-xxgm-523f/GHSA-72c6-xxgm-523f.json b/advisories/unreviewed/2022/05/GHSA-72c6-xxgm-523f/GHSA-72c6-xxgm-523f.json index 5af2946e90a..871fae2ae36 100644 --- a/advisories/unreviewed/2022/05/GHSA-72c6-xxgm-523f/GHSA-72c6-xxgm-523f.json +++ b/advisories/unreviewed/2022/05/GHSA-72c6-xxgm-523f/GHSA-72c6-xxgm-523f.json @@ -7,12 +7,8 @@ "CVE-2009-3132" ], "details": "Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed formula, related to a \"pointer corruption\" issue, aka \"Excel Index Parsing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7399-c2fj-2jg3/GHSA-7399-c2fj-2jg3.json b/advisories/unreviewed/2022/05/GHSA-7399-c2fj-2jg3/GHSA-7399-c2fj-2jg3.json index fbc88d90b55..c3dc665058d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7399-c2fj-2jg3/GHSA-7399-c2fj-2jg3.json +++ b/advisories/unreviewed/2022/05/GHSA-7399-c2fj-2jg3/GHSA-7399-c2fj-2jg3.json @@ -7,12 +7,8 @@ "CVE-2009-3507" ], "details": "Directory traversal vulnerability in modules.php in CMSphp 0.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73pf-mvfq-rghp/GHSA-73pf-mvfq-rghp.json b/advisories/unreviewed/2022/05/GHSA-73pf-mvfq-rghp/GHSA-73pf-mvfq-rghp.json index 5e78e1aa959..2e8b15dca5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-73pf-mvfq-rghp/GHSA-73pf-mvfq-rghp.json +++ b/advisories/unreviewed/2022/05/GHSA-73pf-mvfq-rghp/GHSA-73pf-mvfq-rghp.json @@ -7,12 +7,8 @@ "CVE-2009-3270" ], "details": "Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a \"printing DoS attack,\" possibly a related issue to CVE-2009-0821.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7499-pwh5-6vh8/GHSA-7499-pwh5-6vh8.json b/advisories/unreviewed/2022/05/GHSA-7499-pwh5-6vh8/GHSA-7499-pwh5-6vh8.json index bfa4883ad6e..275827b9488 100644 --- a/advisories/unreviewed/2022/05/GHSA-7499-pwh5-6vh8/GHSA-7499-pwh5-6vh8.json +++ b/advisories/unreviewed/2022/05/GHSA-7499-pwh5-6vh8/GHSA-7499-pwh5-6vh8.json @@ -7,12 +7,8 @@ "CVE-2009-3517" ], "details": "nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74jj-5cp3-vhx3/GHSA-74jj-5cp3-vhx3.json b/advisories/unreviewed/2022/05/GHSA-74jj-5cp3-vhx3/GHSA-74jj-5cp3-vhx3.json index f37d7cf8b1e..7b3178fa39f 100644 --- a/advisories/unreviewed/2022/05/GHSA-74jj-5cp3-vhx3/GHSA-74jj-5cp3-vhx3.json +++ b/advisories/unreviewed/2022/05/GHSA-74jj-5cp3-vhx3/GHSA-74jj-5cp3-vhx3.json @@ -7,12 +7,8 @@ "CVE-2009-3372" ], "details": "Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75w6-c37p-69v3/GHSA-75w6-c37p-69v3.json b/advisories/unreviewed/2022/05/GHSA-75w6-c37p-69v3/GHSA-75w6-c37p-69v3.json index da2b3f73410..5bb83533fa3 100644 --- a/advisories/unreviewed/2022/05/GHSA-75w6-c37p-69v3/GHSA-75w6-c37p-69v3.json +++ b/advisories/unreviewed/2022/05/GHSA-75w6-c37p-69v3/GHSA-75w6-c37p-69v3.json @@ -7,12 +7,8 @@ "CVE-2006-1542" ], "details": "Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a \"stack overflow,\" and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79cm-5mpx-ff74/GHSA-79cm-5mpx-ff74.json b/advisories/unreviewed/2022/05/GHSA-79cm-5mpx-ff74/GHSA-79cm-5mpx-ff74.json index c965e21fcad..47a321ce36e 100644 --- a/advisories/unreviewed/2022/05/GHSA-79cm-5mpx-ff74/GHSA-79cm-5mpx-ff74.json +++ b/advisories/unreviewed/2022/05/GHSA-79cm-5mpx-ff74/GHSA-79cm-5mpx-ff74.json @@ -7,12 +7,8 @@ "CVE-2009-3472" ], "details": "IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79g3-3mvq-3m6x/GHSA-79g3-3mvq-3m6x.json b/advisories/unreviewed/2022/05/GHSA-79g3-3mvq-3m6x/GHSA-79g3-3mvq-3m6x.json index 8481494c291..1bb1b439505 100644 --- a/advisories/unreviewed/2022/05/GHSA-79g3-3mvq-3m6x/GHSA-79g3-3mvq-3m6x.json +++ b/advisories/unreviewed/2022/05/GHSA-79g3-3mvq-3m6x/GHSA-79g3-3mvq-3m6x.json @@ -7,12 +7,8 @@ "CVE-2009-3348" ], "details": "Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79mh-428r-c849/GHSA-79mh-428r-c849.json b/advisories/unreviewed/2022/05/GHSA-79mh-428r-c849/GHSA-79mh-428r-c849.json index 5e4a63e3888..22b702a7a40 100644 --- a/advisories/unreviewed/2022/05/GHSA-79mh-428r-c849/GHSA-79mh-428r-c849.json +++ b/advisories/unreviewed/2022/05/GHSA-79mh-428r-c849/GHSA-79mh-428r-c849.json @@ -7,12 +7,8 @@ "CVE-2009-3491" ], "details": "SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c94-52c6-8hwg/GHSA-7c94-52c6-8hwg.json b/advisories/unreviewed/2022/05/GHSA-7c94-52c6-8hwg/GHSA-7c94-52c6-8hwg.json index 1f7d421979c..7b9755dce48 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c94-52c6-8hwg/GHSA-7c94-52c6-8hwg.json +++ b/advisories/unreviewed/2022/05/GHSA-7c94-52c6-8hwg/GHSA-7c94-52c6-8hwg.json @@ -7,12 +7,8 @@ "CVE-2009-3582" ], "details": "Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL commands via the (1) id and possibly (2) db parameters in a Delete action to the output of a Vendors>Reports>Search search operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7chx-66rj-q7wh/GHSA-7chx-66rj-q7wh.json b/advisories/unreviewed/2022/05/GHSA-7chx-66rj-q7wh/GHSA-7chx-66rj-q7wh.json index e61f8b1f650..c2a9dac4c30 100644 --- a/advisories/unreviewed/2022/05/GHSA-7chx-66rj-q7wh/GHSA-7chx-66rj-q7wh.json +++ b/advisories/unreviewed/2022/05/GHSA-7chx-66rj-q7wh/GHSA-7chx-66rj-q7wh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gm5-vg78-248m/GHSA-7gm5-vg78-248m.json b/advisories/unreviewed/2022/05/GHSA-7gm5-vg78-248m/GHSA-7gm5-vg78-248m.json index 5e3ce164574..beb10a64df9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gm5-vg78-248m/GHSA-7gm5-vg78-248m.json +++ b/advisories/unreviewed/2022/05/GHSA-7gm5-vg78-248m/GHSA-7gm5-vg78-248m.json @@ -7,12 +7,8 @@ "CVE-2009-3798" ], "details": "Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7h3v-6p66-cfwj/GHSA-7h3v-6p66-cfwj.json b/advisories/unreviewed/2022/05/GHSA-7h3v-6p66-cfwj/GHSA-7h3v-6p66-cfwj.json index e68f6d1609d..ae2950c5da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h3v-6p66-cfwj/GHSA-7h3v-6p66-cfwj.json +++ b/advisories/unreviewed/2022/05/GHSA-7h3v-6p66-cfwj/GHSA-7h3v-6p66-cfwj.json @@ -7,12 +7,8 @@ "CVE-2009-3760" ], "details": "Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jfh-mfwx-qffg/GHSA-7jfh-mfwx-qffg.json b/advisories/unreviewed/2022/05/GHSA-7jfh-mfwx-qffg/GHSA-7jfh-mfwx-qffg.json index 1dc12def039..b052a00a2b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jfh-mfwx-qffg/GHSA-7jfh-mfwx-qffg.json +++ b/advisories/unreviewed/2022/05/GHSA-7jfh-mfwx-qffg/GHSA-7jfh-mfwx-qffg.json @@ -7,12 +7,8 @@ "CVE-2009-3448" ], "details": "npvmgr.exe in BakBone NetVault Backup 8.22 Build 29 allows remote attackers to cause a denial of service (daemon crash) via a packet to (1) TCP or (2) UDP port 20031 with a large value in an unspecified size field, which is not properly handled in a malloc operation. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p6w-2mrq-wqmv/GHSA-7p6w-2mrq-wqmv.json b/advisories/unreviewed/2022/05/GHSA-7p6w-2mrq-wqmv/GHSA-7p6w-2mrq-wqmv.json index d869a0d0950..0d451a569ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p6w-2mrq-wqmv/GHSA-7p6w-2mrq-wqmv.json +++ b/advisories/unreviewed/2022/05/GHSA-7p6w-2mrq-wqmv/GHSA-7p6w-2mrq-wqmv.json @@ -7,12 +7,8 @@ "CVE-2009-3488" ], "details": "Cross-site scripting (XSS) vulnerability in the Bibliography (aka Biblio) module 6.x-1.6 for Drupal allows remote authenticated users, with certain content-creation privileges, to inject arbitrary web script or HTML via the Title field, probably a different vulnerability than CVE-2009-3479.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p99-vvwg-793p/GHSA-7p99-vvwg-793p.json b/advisories/unreviewed/2022/05/GHSA-7p99-vvwg-793p/GHSA-7p99-vvwg-793p.json index 1e44ed61342..4a510c47be7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p99-vvwg-793p/GHSA-7p99-vvwg-793p.json +++ b/advisories/unreviewed/2022/05/GHSA-7p99-vvwg-793p/GHSA-7p99-vvwg-793p.json @@ -7,12 +7,8 @@ "CVE-2009-3652" ], "details": "Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or HTML via the User-Agent HTTP header, a different issue than CVE-2008-3095.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p9v-555g-5hgg/GHSA-7p9v-555g-5hgg.json b/advisories/unreviewed/2022/05/GHSA-7p9v-555g-5hgg/GHSA-7p9v-555g-5hgg.json index b2ce2e87cb8..180fe710b95 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p9v-555g-5hgg/GHSA-7p9v-555g-5hgg.json +++ b/advisories/unreviewed/2022/05/GHSA-7p9v-555g-5hgg/GHSA-7p9v-555g-5hgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7phm-f5vw-fc7p/GHSA-7phm-f5vw-fc7p.json b/advisories/unreviewed/2022/05/GHSA-7phm-f5vw-fc7p/GHSA-7phm-f5vw-fc7p.json index 3bd25162801..76780dd8967 100644 --- a/advisories/unreviewed/2022/05/GHSA-7phm-f5vw-fc7p/GHSA-7phm-f5vw-fc7p.json +++ b/advisories/unreviewed/2022/05/GHSA-7phm-f5vw-fc7p/GHSA-7phm-f5vw-fc7p.json @@ -7,12 +7,8 @@ "CVE-2009-3431" ], "details": "Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pmf-v687-c5v4/GHSA-7pmf-v687-c5v4.json b/advisories/unreviewed/2022/05/GHSA-7pmf-v687-c5v4/GHSA-7pmf-v687-c5v4.json index e908d35563a..79ef37df82a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pmf-v687-c5v4/GHSA-7pmf-v687-c5v4.json +++ b/advisories/unreviewed/2022/05/GHSA-7pmf-v687-c5v4/GHSA-7pmf-v687-c5v4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pwr-jgrg-q23m/GHSA-7pwr-jgrg-q23m.json b/advisories/unreviewed/2022/05/GHSA-7pwr-jgrg-q23m/GHSA-7pwr-jgrg-q23m.json index 849f1296871..70d256a3285 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pwr-jgrg-q23m/GHSA-7pwr-jgrg-q23m.json +++ b/advisories/unreviewed/2022/05/GHSA-7pwr-jgrg-q23m/GHSA-7pwr-jgrg-q23m.json @@ -7,12 +7,8 @@ "CVE-2009-3744" ], "details": "rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted packet to TCP port 7144.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7q7f-994w-22j8/GHSA-7q7f-994w-22j8.json b/advisories/unreviewed/2022/05/GHSA-7q7f-994w-22j8/GHSA-7q7f-994w-22j8.json index 51e34a252eb..620c83fcf15 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q7f-994w-22j8/GHSA-7q7f-994w-22j8.json +++ b/advisories/unreviewed/2022/05/GHSA-7q7f-994w-22j8/GHSA-7q7f-994w-22j8.json @@ -7,12 +7,8 @@ "CVE-2009-3267" ], "details": "Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r3c-83p4-h28h/GHSA-7r3c-83p4-h28h.json b/advisories/unreviewed/2022/05/GHSA-7r3c-83p4-h28h/GHSA-7r3c-83p4-h28h.json index c085dc1a742..c543b75f7dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r3c-83p4-h28h/GHSA-7r3c-83p4-h28h.json +++ b/advisories/unreviewed/2022/05/GHSA-7r3c-83p4-h28h/GHSA-7r3c-83p4-h28h.json @@ -7,12 +7,8 @@ "CVE-2009-3211" ], "details": "Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rpp-hwhj-9hv8/GHSA-7rpp-hwhj-9hv8.json b/advisories/unreviewed/2022/05/GHSA-7rpp-hwhj-9hv8/GHSA-7rpp-hwhj-9hv8.json index 052390d3fd1..e5551851b10 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rpp-hwhj-9hv8/GHSA-7rpp-hwhj-9hv8.json +++ b/advisories/unreviewed/2022/05/GHSA-7rpp-hwhj-9hv8/GHSA-7rpp-hwhj-9hv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7v72-p9gx-28vj/GHSA-7v72-p9gx-28vj.json b/advisories/unreviewed/2022/05/GHSA-7v72-p9gx-28vj/GHSA-7v72-p9gx-28vj.json index 3da50593112..3b0456f277b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v72-p9gx-28vj/GHSA-7v72-p9gx-28vj.json +++ b/advisories/unreviewed/2022/05/GHSA-7v72-p9gx-28vj/GHSA-7v72-p9gx-28vj.json @@ -7,12 +7,8 @@ "CVE-2009-3516" ], "details": "gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vcr-gg86-5p2j/GHSA-7vcr-gg86-5p2j.json b/advisories/unreviewed/2022/05/GHSA-7vcr-gg86-5p2j/GHSA-7vcr-gg86-5p2j.json index 2307e68ff63..37db5712a47 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vcr-gg86-5p2j/GHSA-7vcr-gg86-5p2j.json +++ b/advisories/unreviewed/2022/05/GHSA-7vcr-gg86-5p2j/GHSA-7vcr-gg86-5p2j.json @@ -7,12 +7,8 @@ "CVE-2009-3514" ], "details": "Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vx4-j5mm-h4p8/GHSA-7vx4-j5mm-h4p8.json b/advisories/unreviewed/2022/05/GHSA-7vx4-j5mm-h4p8/GHSA-7vx4-j5mm-h4p8.json index 57cfcc5cced..2f1a1d9cdb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vx4-j5mm-h4p8/GHSA-7vx4-j5mm-h4p8.json +++ b/advisories/unreviewed/2022/05/GHSA-7vx4-j5mm-h4p8/GHSA-7vx4-j5mm-h4p8.json @@ -7,12 +7,8 @@ "CVE-2009-3799" ], "details": "Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to \"generation of ActionScript exception handlers.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -116,9 +112,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x5f-m83q-6f4q/GHSA-7x5f-m83q-6f4q.json b/advisories/unreviewed/2022/05/GHSA-7x5f-m83q-6f4q/GHSA-7x5f-m83q-6f4q.json index 09458033ece..0affaaf57d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x5f-m83q-6f4q/GHSA-7x5f-m83q-6f4q.json +++ b/advisories/unreviewed/2022/05/GHSA-7x5f-m83q-6f4q/GHSA-7x5f-m83q-6f4q.json @@ -7,12 +7,8 @@ "CVE-2009-3325" ], "details": "SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xjp-xgmc-5vc9/GHSA-7xjp-xgmc-5vc9.json b/advisories/unreviewed/2022/05/GHSA-7xjp-xgmc-5vc9/GHSA-7xjp-xgmc-5vc9.json index b493bcd5a50..26964e0970d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xjp-xgmc-5vc9/GHSA-7xjp-xgmc-5vc9.json +++ b/advisories/unreviewed/2022/05/GHSA-7xjp-xgmc-5vc9/GHSA-7xjp-xgmc-5vc9.json @@ -7,12 +7,8 @@ "CVE-2009-3764" ], "details": "Unspecified vulnerability in the OpenSSO component in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-822h-vphc-4mvf/GHSA-822h-vphc-4mvf.json b/advisories/unreviewed/2022/05/GHSA-822h-vphc-4mvf/GHSA-822h-vphc-4mvf.json index 02698708e2d..a134a1b306a 100644 --- a/advisories/unreviewed/2022/05/GHSA-822h-vphc-4mvf/GHSA-822h-vphc-4mvf.json +++ b/advisories/unreviewed/2022/05/GHSA-822h-vphc-4mvf/GHSA-822h-vphc-4mvf.json @@ -7,12 +7,8 @@ "CVE-2009-3405" ], "details": "Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.98.1.4 allows remote authenticated users to affect integrity and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-827c-j6w2-8fg4/GHSA-827c-j6w2-8fg4.json b/advisories/unreviewed/2022/05/GHSA-827c-j6w2-8fg4/GHSA-827c-j6w2-8fg4.json index 69b6f2d69de..41b8d9f6cb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-827c-j6w2-8fg4/GHSA-827c-j6w2-8fg4.json +++ b/advisories/unreviewed/2022/05/GHSA-827c-j6w2-8fg4/GHSA-827c-j6w2-8fg4.json @@ -7,12 +7,8 @@ "CVE-2009-3727" ], "details": "Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames via multiple crafted REGISTER messages with inconsistent usernames in the URI in the To header and the Digest in the Authorization header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82q2-xf4j-jj8g/GHSA-82q2-xf4j-jj8g.json b/advisories/unreviewed/2022/05/GHSA-82q2-xf4j-jj8g/GHSA-82q2-xf4j-jj8g.json index bb16d04f38c..e47605c1d94 100644 --- a/advisories/unreviewed/2022/05/GHSA-82q2-xf4j-jj8g/GHSA-82q2-xf4j-jj8g.json +++ b/advisories/unreviewed/2022/05/GHSA-82q2-xf4j-jj8g/GHSA-82q2-xf4j-jj8g.json @@ -7,12 +7,8 @@ "CVE-2009-3535" ], "details": "Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the researcher also suggests an analogous PHP remote file inclusion vulnerability, but this may be incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83r5-gpg4-8mv5/GHSA-83r5-gpg4-8mv5.json b/advisories/unreviewed/2022/05/GHSA-83r5-gpg4-8mv5/GHSA-83r5-gpg4-8mv5.json index 17f104ce315..86cb256168d 100644 --- a/advisories/unreviewed/2022/05/GHSA-83r5-gpg4-8mv5/GHSA-83r5-gpg4-8mv5.json +++ b/advisories/unreviewed/2022/05/GHSA-83r5-gpg4-8mv5/GHSA-83r5-gpg4-8mv5.json @@ -7,12 +7,8 @@ "CVE-2009-3331" ], "details": "Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submitted.php, and (4) autosubmitter/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-848g-j7cv-9644/GHSA-848g-j7cv-9644.json b/advisories/unreviewed/2022/05/GHSA-848g-j7cv-9644/GHSA-848g-j7cv-9644.json index 4a3cbfa453e..d4f989700ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-848g-j7cv-9644/GHSA-848g-j7cv-9644.json +++ b/advisories/unreviewed/2022/05/GHSA-848g-j7cv-9644/GHSA-848g-j7cv-9644.json @@ -7,12 +7,8 @@ "CVE-2009-3756" ], "details": "phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84vv-6fh8-r3gv/GHSA-84vv-6fh8-r3gv.json b/advisories/unreviewed/2022/05/GHSA-84vv-6fh8-r3gv/GHSA-84vv-6fh8-r3gv.json index 6252a8b863e..208b29e056f 100644 --- a/advisories/unreviewed/2022/05/GHSA-84vv-6fh8-r3gv/GHSA-84vv-6fh8-r3gv.json +++ b/advisories/unreviewed/2022/05/GHSA-84vv-6fh8-r3gv/GHSA-84vv-6fh8-r3gv.json @@ -7,12 +7,8 @@ "CVE-2009-3196" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-854c-mqcx-rhcc/GHSA-854c-mqcx-rhcc.json b/advisories/unreviewed/2022/05/GHSA-854c-mqcx-rhcc/GHSA-854c-mqcx-rhcc.json index f1205a09a40..136e86968bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-854c-mqcx-rhcc/GHSA-854c-mqcx-rhcc.json +++ b/advisories/unreviewed/2022/05/GHSA-854c-mqcx-rhcc/GHSA-854c-mqcx-rhcc.json @@ -7,12 +7,8 @@ "CVE-2009-3290" ], "details": "The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions before 2.6.31, when running on x86 systems, does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to cause a denial of service (guest kernel crash) and read or write guest kernel memory via unspecified \"random addresses.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88g5-782g-r7xp/GHSA-88g5-782g-r7xp.json b/advisories/unreviewed/2022/05/GHSA-88g5-782g-r7xp/GHSA-88g5-782g-r7xp.json index 14bf38bc030..01463585bae 100644 --- a/advisories/unreviewed/2022/05/GHSA-88g5-782g-r7xp/GHSA-88g5-782g-r7xp.json +++ b/advisories/unreviewed/2022/05/GHSA-88g5-782g-r7xp/GHSA-88g5-782g-r7xp.json @@ -7,12 +7,8 @@ "CVE-2009-3225" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88vx-49vv-gcx2/GHSA-88vx-49vv-gcx2.json b/advisories/unreviewed/2022/05/GHSA-88vx-49vv-gcx2/GHSA-88vx-49vv-gcx2.json index b57ed362d59..d37a32e5626 100644 --- a/advisories/unreviewed/2022/05/GHSA-88vx-49vv-gcx2/GHSA-88vx-49vv-gcx2.json +++ b/advisories/unreviewed/2022/05/GHSA-88vx-49vv-gcx2/GHSA-88vx-49vv-gcx2.json @@ -7,12 +7,8 @@ "CVE-2009-3277" ], "details": "DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of an [ (open bracket) followed by many commas, related to a certain regular expression, aka a \"ReDoS\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8f49-c882-385m/GHSA-8f49-c882-385m.json b/advisories/unreviewed/2022/05/GHSA-8f49-c882-385m/GHSA-8f49-c882-385m.json index 619665ad8a6..cff8b6887cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f49-c882-385m/GHSA-8f49-c882-385m.json +++ b/advisories/unreviewed/2022/05/GHSA-8f49-c882-385m/GHSA-8f49-c882-385m.json @@ -7,12 +7,8 @@ "CVE-2009-3508" ], "details": "Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and the (2) url parameter to install/install.php; and allow remote authenticated administrators to read arbitrary files via a .. (dot dot) in the (3) _htmlfile parameter to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g86-cfmw-cfgc/GHSA-8g86-cfmw-cfgc.json b/advisories/unreviewed/2022/05/GHSA-8g86-cfmw-cfgc/GHSA-8g86-cfmw-cfgc.json index ecd3d227b1f..600ab7da75f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g86-cfmw-cfgc/GHSA-8g86-cfmw-cfgc.json +++ b/advisories/unreviewed/2022/05/GHSA-8g86-cfmw-cfgc/GHSA-8g86-cfmw-cfgc.json @@ -7,12 +7,8 @@ "CVE-2009-3717" ], "details": "Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h6j-f8rw-25pv/GHSA-8h6j-f8rw-25pv.json b/advisories/unreviewed/2022/05/GHSA-8h6j-f8rw-25pv/GHSA-8h6j-f8rw-25pv.json index e5ba2483cd6..ac8b1b92437 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h6j-f8rw-25pv/GHSA-8h6j-f8rw-25pv.json +++ b/advisories/unreviewed/2022/05/GHSA-8h6j-f8rw-25pv/GHSA-8h6j-f8rw-25pv.json @@ -7,12 +7,8 @@ "CVE-2009-3218" ], "details": "SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hhx-c6j2-6m2w/GHSA-8hhx-c6j2-6m2w.json b/advisories/unreviewed/2022/05/GHSA-8hhx-c6j2-6m2w/GHSA-8hhx-c6j2-6m2w.json index 1f0f0a2695e..ca8d4e06b54 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hhx-c6j2-6m2w/GHSA-8hhx-c6j2-6m2w.json +++ b/advisories/unreviewed/2022/05/GHSA-8hhx-c6j2-6m2w/GHSA-8hhx-c6j2-6m2w.json @@ -7,12 +7,8 @@ "CVE-2009-3349" ], "details": "SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m5p-57f4-m897/GHSA-8m5p-57f4-m897.json b/advisories/unreviewed/2022/05/GHSA-8m5p-57f4-m897/GHSA-8m5p-57f4-m897.json index 3b63474432e..f42d31aba59 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m5p-57f4-m897/GHSA-8m5p-57f4-m897.json +++ b/advisories/unreviewed/2022/05/GHSA-8m5p-57f4-m897/GHSA-8m5p-57f4-m897.json @@ -7,12 +7,8 @@ "CVE-2009-3283" ], "details": "Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mh4-cq82-8r3x/GHSA-8mh4-cq82-8r3x.json b/advisories/unreviewed/2022/05/GHSA-8mh4-cq82-8r3x/GHSA-8mh4-cq82-8r3x.json index 3d6827115f1..cf9e82ea16e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mh4-cq82-8r3x/GHSA-8mh4-cq82-8r3x.json +++ b/advisories/unreviewed/2022/05/GHSA-8mh4-cq82-8r3x/GHSA-8mh4-cq82-8r3x.json @@ -7,12 +7,8 @@ "CVE-2009-3632" ], "details": "SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pr7-f78m-qwfx/GHSA-8pr7-f78m-qwfx.json b/advisories/unreviewed/2022/05/GHSA-8pr7-f78m-qwfx/GHSA-8pr7-f78m-qwfx.json index 39bdde7a23c..f21fa0b30d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pr7-f78m-qwfx/GHSA-8pr7-f78m-qwfx.json +++ b/advisories/unreviewed/2022/05/GHSA-8pr7-f78m-qwfx/GHSA-8pr7-f78m-qwfx.json @@ -7,12 +7,8 @@ "CVE-2009-3601" ], "details": "Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pvv-4x3j-fgh9/GHSA-8pvv-4x3j-fgh9.json b/advisories/unreviewed/2022/05/GHSA-8pvv-4x3j-fgh9/GHSA-8pvv-4x3j-fgh9.json index 31f43089018..4c2eb620ebe 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pvv-4x3j-fgh9/GHSA-8pvv-4x3j-fgh9.json +++ b/advisories/unreviewed/2022/05/GHSA-8pvv-4x3j-fgh9/GHSA-8pvv-4x3j-fgh9.json @@ -7,12 +7,8 @@ "CVE-2009-3432" ], "details": "Unspecified vulnerability in xscreensaver in Sun Solaris 10, and OpenSolaris before snv_112, when Xorg or Xnewt is used and RandR is enabled, allows physically proximate attackers to read a locked screen via unknown vectors related to XRandR resize events.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q5p-rpfq-gjc9/GHSA-8q5p-rpfq-gjc9.json b/advisories/unreviewed/2022/05/GHSA-8q5p-rpfq-gjc9/GHSA-8q5p-rpfq-gjc9.json index 2a25f782e13..3f59d285226 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q5p-rpfq-gjc9/GHSA-8q5p-rpfq-gjc9.json +++ b/advisories/unreviewed/2022/05/GHSA-8q5p-rpfq-gjc9/GHSA-8q5p-rpfq-gjc9.json @@ -7,12 +7,8 @@ "CVE-2009-3676" ], "details": "The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka \"SMB Client Incomplete Response Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v55-2h3g-6wvr/GHSA-8v55-2h3g-6wvr.json b/advisories/unreviewed/2022/05/GHSA-8v55-2h3g-6wvr/GHSA-8v55-2h3g-6wvr.json index 1b1483824d5..cc69d7e9a3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v55-2h3g-6wvr/GHSA-8v55-2h3g-6wvr.json +++ b/advisories/unreviewed/2022/05/GHSA-8v55-2h3g-6wvr/GHSA-8v55-2h3g-6wvr.json @@ -7,12 +7,8 @@ "CVE-2009-3797" ], "details": "Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v93-c335-x4h3/GHSA-8v93-c335-x4h3.json b/advisories/unreviewed/2022/05/GHSA-8v93-c335-x4h3/GHSA-8v93-c335-x4h3.json index c829ae0a102..f3fe0b953ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v93-c335-x4h3/GHSA-8v93-c335-x4h3.json +++ b/advisories/unreviewed/2022/05/GHSA-8v93-c335-x4h3/GHSA-8v93-c335-x4h3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wg5-pm5f-vw86/GHSA-8wg5-pm5f-vw86.json b/advisories/unreviewed/2022/05/GHSA-8wg5-pm5f-vw86/GHSA-8wg5-pm5f-vw86.json index aabaa87d42f..63275bc4cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wg5-pm5f-vw86/GHSA-8wg5-pm5f-vw86.json +++ b/advisories/unreviewed/2022/05/GHSA-8wg5-pm5f-vw86/GHSA-8wg5-pm5f-vw86.json @@ -7,12 +7,8 @@ "CVE-2009-3562" ], "details": "Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wjm-mwjv-j295/GHSA-8wjm-mwjv-j295.json b/advisories/unreviewed/2022/05/GHSA-8wjm-mwjv-j295/GHSA-8wjm-mwjv-j295.json index 82f47326f67..38a699debe2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wjm-mwjv-j295/GHSA-8wjm-mwjv-j295.json +++ b/advisories/unreviewed/2022/05/GHSA-8wjm-mwjv-j295/GHSA-8wjm-mwjv-j295.json @@ -7,12 +7,8 @@ "CVE-2009-3802" ], "details": "Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname (\"%%%\") to _admin/index.php, which reveals the installation path and other information in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x3f-mp7c-vfgm/GHSA-8x3f-mp7c-vfgm.json b/advisories/unreviewed/2022/05/GHSA-8x3f-mp7c-vfgm/GHSA-8x3f-mp7c-vfgm.json index 4df8778d144..1da1cb149b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x3f-mp7c-vfgm/GHSA-8x3f-mp7c-vfgm.json +++ b/advisories/unreviewed/2022/05/GHSA-8x3f-mp7c-vfgm/GHSA-8x3f-mp7c-vfgm.json @@ -7,12 +7,8 @@ "CVE-2009-3537" ], "details": "Multiple stack-based buffer overflows in EpicDJSoftware EpicDJ 1.3.9.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xjx-475c-5hjg/GHSA-8xjx-475c-5hjg.json b/advisories/unreviewed/2022/05/GHSA-8xjx-475c-5hjg/GHSA-8xjx-475c-5hjg.json index a2c30345390..e142867b433 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xjx-475c-5hjg/GHSA-8xjx-475c-5hjg.json +++ b/advisories/unreviewed/2022/05/GHSA-8xjx-475c-5hjg/GHSA-8xjx-475c-5hjg.json @@ -7,12 +7,8 @@ "CVE-2009-3525" ], "details": "The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9272-j67v-qf39/GHSA-9272-j67v-qf39.json b/advisories/unreviewed/2022/05/GHSA-9272-j67v-qf39/GHSA-9272-j67v-qf39.json index bc25d403198..63b12080cb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9272-j67v-qf39/GHSA-9272-j67v-qf39.json +++ b/advisories/unreviewed/2022/05/GHSA-9272-j67v-qf39/GHSA-9272-j67v-qf39.json @@ -7,12 +7,8 @@ "CVE-2009-3109" ], "details": "Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending \"alternate commands\" before the handshake is completed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92jq-w79w-2g5c/GHSA-92jq-w79w-2g5c.json b/advisories/unreviewed/2022/05/GHSA-92jq-w79w-2g5c/GHSA-92jq-w79w-2g5c.json index fed3c988f96..f578fadcaad 100644 --- a/advisories/unreviewed/2022/05/GHSA-92jq-w79w-2g5c/GHSA-92jq-w79w-2g5c.json +++ b/advisories/unreviewed/2022/05/GHSA-92jq-w79w-2g5c/GHSA-92jq-w79w-2g5c.json @@ -7,12 +7,8 @@ "CVE-2009-3202" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92jw-w2rc-xwxg/GHSA-92jw-w2rc-xwxg.json b/advisories/unreviewed/2022/05/GHSA-92jw-w2rc-xwxg/GHSA-92jw-w2rc-xwxg.json index 4fd253f42ba..97787386f79 100644 --- a/advisories/unreviewed/2022/05/GHSA-92jw-w2rc-xwxg/GHSA-92jw-w2rc-xwxg.json +++ b/advisories/unreviewed/2022/05/GHSA-92jw-w2rc-xwxg/GHSA-92jw-w2rc-xwxg.json @@ -7,12 +7,8 @@ "CVE-2009-3766" ], "details": "mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93qv-2hpr-4mmc/GHSA-93qv-2hpr-4mmc.json b/advisories/unreviewed/2022/05/GHSA-93qv-2hpr-4mmc/GHSA-93qv-2hpr-4mmc.json index d84f51e7b63..3b0806f79da 100644 --- a/advisories/unreviewed/2022/05/GHSA-93qv-2hpr-4mmc/GHSA-93qv-2hpr-4mmc.json +++ b/advisories/unreviewed/2022/05/GHSA-93qv-2hpr-4mmc/GHSA-93qv-2hpr-4mmc.json @@ -7,12 +7,8 @@ "CVE-2009-3407" ], "details": "Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-0983.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-94gc-q6xg-j8wh/GHSA-94gc-q6xg-j8wh.json b/advisories/unreviewed/2022/05/GHSA-94gc-q6xg-j8wh/GHSA-94gc-q6xg-j8wh.json index 8177cdc35f1..336fb02eb1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-94gc-q6xg-j8wh/GHSA-94gc-q6xg-j8wh.json +++ b/advisories/unreviewed/2022/05/GHSA-94gc-q6xg-j8wh/GHSA-94gc-q6xg-j8wh.json @@ -7,12 +7,8 @@ "CVE-2009-3424" ], "details": "Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) is_projectPath parameter to includes/InstantSite/inc.is_root.php; GLOBALS[thCMS_root] parameter to (2) classes/class.Tree.php, (3) includes/inc.thcms_admin_mediamanager.php, and (4) modul/mod.rssreader.php; is_path parameter to (5) class.tasklist.php, (6) class.thcms.php, (7) class.thcms_content.php, (8) class.thcms_modul_parent.php, (9) class.thcms_page.php, and (10) class.thcsm_user.php in classes/; and (11) includes/InstantSite/class.Tree.php; and thCMS_root parameter to (12) classes/class.thcms_modul.php; (13) inc.page_edit_tasklist.php, (14) inc.thcms_admin_overview_backup.php, and (15) inc.thcms_edit_content.php in includes/; and (16) class.thcms_modul_parent_xml.php, (17) mod.cmstranslator.php, (18) mod.download.php, (19) mod.faq.php, (20) mod.guestbook.php, (21) mod.html.php, (22) mod.menu.php, (23) mod.news.php, (24) mod.newsticker.php, (25) mod.rss.php, (26) mod.search.php, (27) mod.sendtofriend.php, (28) mod.sitemap.php, (29) mod.tagdoc.php, (30) mod.template.php, (31) mod.test.php, (32) mod.text.php, (33) mod.upload.php, and (34) mod.users.php in modul/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9579-x24g-29q6/GHSA-9579-x24g-29q6.json b/advisories/unreviewed/2022/05/GHSA-9579-x24g-29q6/GHSA-9579-x24g-29q6.json index 68b64930f9d..4839e2dc73d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9579-x24g-29q6/GHSA-9579-x24g-29q6.json +++ b/advisories/unreviewed/2022/05/GHSA-9579-x24g-29q6/GHSA-9579-x24g-29q6.json @@ -7,12 +7,8 @@ "CVE-2009-3179" ], "details": "Multiple unspecified vulnerabilities in Symantec Altiris Deployment Solution 6.9 might allow remote attackers to execute arbitrary code via unknown client-side attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.17, as identified by (1) \"Symantec Altiris Deployment Solution 6.9 exploit, (2) \"Symantec Altiris Deployment Solution 6.9 exploit (II),\" and (3) \"Symantec Altiris Deployment Solution 6.9 exploit (III).\" NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-968q-p5w6-ghj4/GHSA-968q-p5w6-ghj4.json b/advisories/unreviewed/2022/05/GHSA-968q-p5w6-ghj4/GHSA-968q-p5w6-ghj4.json index cae711eb227..23fc7de7884 100644 --- a/advisories/unreviewed/2022/05/GHSA-968q-p5w6-ghj4/GHSA-968q-p5w6-ghj4.json +++ b/advisories/unreviewed/2022/05/GHSA-968q-p5w6-ghj4/GHSA-968q-p5w6-ghj4.json @@ -7,12 +7,8 @@ "CVE-2009-3100" ], "details": "xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain Solaris and OpenSolaris patches.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-975h-h4pp-737q/GHSA-975h-h4pp-737q.json b/advisories/unreviewed/2022/05/GHSA-975h-h4pp-737q/GHSA-975h-h4pp-737q.json index e80a5b26345..d4b728cf812 100644 --- a/advisories/unreviewed/2022/05/GHSA-975h-h4pp-737q/GHSA-975h-h4pp-737q.json +++ b/advisories/unreviewed/2022/05/GHSA-975h-h4pp-737q/GHSA-975h-h4pp-737q.json @@ -7,12 +7,8 @@ "CVE-2009-3548" ], "details": "The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9776-m3xf-335w/GHSA-9776-m3xf-335w.json b/advisories/unreviewed/2022/05/GHSA-9776-m3xf-335w/GHSA-9776-m3xf-335w.json index 4a0b8ed9041..8dd03836c22 100644 --- a/advisories/unreviewed/2022/05/GHSA-9776-m3xf-335w/GHSA-9776-m3xf-335w.json +++ b/advisories/unreviewed/2022/05/GHSA-9776-m3xf-335w/GHSA-9776-m3xf-335w.json @@ -7,12 +7,8 @@ "CVE-2009-3119" ], "details": "SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97c2-mgrq-5254/GHSA-97c2-mgrq-5254.json b/advisories/unreviewed/2022/05/GHSA-97c2-mgrq-5254/GHSA-97c2-mgrq-5254.json index f5ac9cbe0c3..f5b6e878d8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-97c2-mgrq-5254/GHSA-97c2-mgrq-5254.json +++ b/advisories/unreviewed/2022/05/GHSA-97c2-mgrq-5254/GHSA-97c2-mgrq-5254.json @@ -7,12 +7,8 @@ "CVE-2009-3434" ], "details": "SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cmg-www5-3gxx/GHSA-9cmg-www5-3gxx.json b/advisories/unreviewed/2022/05/GHSA-9cmg-www5-3gxx/GHSA-9cmg-www5-3gxx.json index 6a33f65a776..5d5e4c47ce8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cmg-www5-3gxx/GHSA-9cmg-www5-3gxx.json +++ b/advisories/unreviewed/2022/05/GHSA-9cmg-www5-3gxx/GHSA-9cmg-www5-3gxx.json @@ -7,12 +7,8 @@ "CVE-2009-3341" ], "details": "Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f37-2v5p-xv7g/GHSA-9f37-2v5p-xv7g.json b/advisories/unreviewed/2022/05/GHSA-9f37-2v5p-xv7g/GHSA-9f37-2v5p-xv7g.json index c104aa28304..9597875a43e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f37-2v5p-xv7g/GHSA-9f37-2v5p-xv7g.json +++ b/advisories/unreviewed/2022/05/GHSA-9f37-2v5p-xv7g/GHSA-9f37-2v5p-xv7g.json @@ -7,12 +7,8 @@ "CVE-2009-3266" ], "details": "Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as \"scripted content.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f6q-qf7p-473x/GHSA-9f6q-qf7p-473x.json b/advisories/unreviewed/2022/05/GHSA-9f6q-qf7p-473x/GHSA-9f6q-qf7p-473x.json index c9795009693..9b831d40d24 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f6q-qf7p-473x/GHSA-9f6q-qf7p-473x.json +++ b/advisories/unreviewed/2022/05/GHSA-9f6q-qf7p-473x/GHSA-9f6q-qf7p-473x.json @@ -7,12 +7,8 @@ "CVE-2009-3464" ], "details": "Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an \"invalid pointer vulnerability,\" a different issue than CVE-2009-3465. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fm7-cmvm-vvjr/GHSA-9fm7-cmvm-vvjr.json b/advisories/unreviewed/2022/05/GHSA-9fm7-cmvm-vvjr/GHSA-9fm7-cmvm-vvjr.json index 517ee508fa0..e9ace97dad6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fm7-cmvm-vvjr/GHSA-9fm7-cmvm-vvjr.json +++ b/advisories/unreviewed/2022/05/GHSA-9fm7-cmvm-vvjr/GHSA-9fm7-cmvm-vvjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g4q-3qcf-mvw9/GHSA-9g4q-3qcf-mvw9.json b/advisories/unreviewed/2022/05/GHSA-9g4q-3qcf-mvw9/GHSA-9g4q-3qcf-mvw9.json index b2dee4d9564..2ed61969e61 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g4q-3qcf-mvw9/GHSA-9g4q-3qcf-mvw9.json +++ b/advisories/unreviewed/2022/05/GHSA-9g4q-3qcf-mvw9/GHSA-9g4q-3qcf-mvw9.json @@ -7,12 +7,8 @@ "CVE-2009-3430" ], "details": "SQL injection vulnerability in login.php in Allomani Mobile 2.5 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g58-r5gj-vhr9/GHSA-9g58-r5gj-vhr9.json b/advisories/unreviewed/2022/05/GHSA-9g58-r5gj-vhr9/GHSA-9g58-r5gj-vhr9.json index 9edc2a2c980..7a3299a3dfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g58-r5gj-vhr9/GHSA-9g58-r5gj-vhr9.json +++ b/advisories/unreviewed/2022/05/GHSA-9g58-r5gj-vhr9/GHSA-9g58-r5gj-vhr9.json @@ -7,12 +7,8 @@ "CVE-2009-3356" ], "details": "SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g6q-jjw5-x5fw/GHSA-9g6q-jjw5-x5fw.json b/advisories/unreviewed/2022/05/GHSA-9g6q-jjw5-x5fw/GHSA-9g6q-jjw5-x5fw.json index 44b2d26fa30..9e6d4d7037f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g6q-jjw5-x5fw/GHSA-9g6q-jjw5-x5fw.json +++ b/advisories/unreviewed/2022/05/GHSA-9g6q-jjw5-x5fw/GHSA-9g6q-jjw5-x5fw.json @@ -7,12 +7,8 @@ "CVE-2009-3779" ], "details": "Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gh5-vff3-cwrr/GHSA-9gh5-vff3-cwrr.json b/advisories/unreviewed/2022/05/GHSA-9gh5-vff3-cwrr/GHSA-9gh5-vff3-cwrr.json index b8e303c8ea2..26ff87b29ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gh5-vff3-cwrr/GHSA-9gh5-vff3-cwrr.json +++ b/advisories/unreviewed/2022/05/GHSA-9gh5-vff3-cwrr/GHSA-9gh5-vff3-cwrr.json @@ -7,12 +7,8 @@ "CVE-2009-3581" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or HTML via (1) the DCN Description field in the Accounts Receivables menu item for Add Transaction, (2) the Description field in the Accounts Payable menu item for Add Transaction, or the name field in (3) the Customers menu item for Add Customer or (4) the Vendor menu item for Add Vendor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hf2-x6cm-637r/GHSA-9hf2-x6cm-637r.json b/advisories/unreviewed/2022/05/GHSA-9hf2-x6cm-637r/GHSA-9hf2-x6cm-637r.json index ebba7923e06..0deba4dd706 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hf2-x6cm-637r/GHSA-9hf2-x6cm-637r.json +++ b/advisories/unreviewed/2022/05/GHSA-9hf2-x6cm-637r/GHSA-9hf2-x6cm-637r.json @@ -7,12 +7,8 @@ "CVE-2009-3327" ], "details": "Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jg7-472x-vxf4/GHSA-9jg7-472x-vxf4.json b/advisories/unreviewed/2022/05/GHSA-9jg7-472x-vxf4/GHSA-9jg7-472x-vxf4.json index 4b6b8c1611f..1ce17d5ab7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jg7-472x-vxf4/GHSA-9jg7-472x-vxf4.json +++ b/advisories/unreviewed/2022/05/GHSA-9jg7-472x-vxf4/GHSA-9jg7-472x-vxf4.json @@ -7,12 +7,8 @@ "CVE-2009-3402" ], "details": "Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9m2v-w6qp-58wr/GHSA-9m2v-w6qp-58wr.json b/advisories/unreviewed/2022/05/GHSA-9m2v-w6qp-58wr/GHSA-9m2v-w6qp-58wr.json index b66b0aedd3c..97179cf08f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m2v-w6qp-58wr/GHSA-9m2v-w6qp-58wr.json +++ b/advisories/unreviewed/2022/05/GHSA-9m2v-w6qp-58wr/GHSA-9m2v-w6qp-58wr.json @@ -7,12 +7,8 @@ "CVE-2009-3395" ], "details": "Unspecified vulnerability in the AutoVue component in Oracle E-Business Suite 19.3.2 allows remote attackers to affect availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9m3w-j6gp-86c9/GHSA-9m3w-j6gp-86c9.json b/advisories/unreviewed/2022/05/GHSA-9m3w-j6gp-86c9/GHSA-9m3w-j6gp-86c9.json index 90d903a5bc9..eb511eab36a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m3w-j6gp-86c9/GHSA-9m3w-j6gp-86c9.json +++ b/advisories/unreviewed/2022/05/GHSA-9m3w-j6gp-86c9/GHSA-9m3w-j6gp-86c9.json @@ -7,12 +7,8 @@ "CVE-2009-3120" ], "details": "Cross-site scripting (XSS) vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q5f-7fh4-3hgx/GHSA-9q5f-7fh4-3hgx.json b/advisories/unreviewed/2022/05/GHSA-9q5f-7fh4-3hgx/GHSA-9q5f-7fh4-3hgx.json index 7c200682e3d..c3b779a875f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q5f-7fh4-3hgx/GHSA-9q5f-7fh4-3hgx.json +++ b/advisories/unreviewed/2022/05/GHSA-9q5f-7fh4-3hgx/GHSA-9q5f-7fh4-3hgx.json @@ -7,12 +7,8 @@ "CVE-2009-3333" ], "details": "PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r76-mhm8-f3q4/GHSA-9r76-mhm8-f3q4.json b/advisories/unreviewed/2022/05/GHSA-9r76-mhm8-f3q4/GHSA-9r76-mhm8-f3q4.json index e42b286c78d..987d0003692 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r76-mhm8-f3q4/GHSA-9r76-mhm8-f3q4.json +++ b/advisories/unreviewed/2022/05/GHSA-9r76-mhm8-f3q4/GHSA-9r76-mhm8-f3q4.json @@ -7,12 +7,8 @@ "CVE-2009-3403" ], "details": "Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json b/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json index d73324500d6..fcd8efce1aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json +++ b/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json @@ -7,12 +7,8 @@ "CVE-2009-3791" ], "details": "Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w8p-xcg8-8w62/GHSA-9w8p-xcg8-8w62.json b/advisories/unreviewed/2022/05/GHSA-9w8p-xcg8-8w62/GHSA-9w8p-xcg8-8w62.json index d18b895cfc1..b9eeaeccb09 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w8p-xcg8-8w62/GHSA-9w8p-xcg8-8w62.json +++ b/advisories/unreviewed/2022/05/GHSA-9w8p-xcg8-8w62/GHSA-9w8p-xcg8-8w62.json @@ -7,12 +7,8 @@ "CVE-2009-3487" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision parameter in a rollback action to the configuration program; the m[] parameter to the (6) monitor, (7) manage, (8) events, (9) configuration, or (10) alarms program; (11) the m[] parameter to the default URI; (12) the m[] parameter in a browse action to the default URI; (13) the wizard-next parameter in an https action to the configuration program; or the (14) Contact Information, (15) System Description, (16) Local Engine ID, (17) System Location, or (18) System Name Override SNMP parameter, related to the configuration program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xgp-phf8-4m42/GHSA-9xgp-phf8-4m42.json b/advisories/unreviewed/2022/05/GHSA-9xgp-phf8-4m42/GHSA-9xgp-phf8-4m42.json index fbd517ce859..9de76761388 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xgp-phf8-4m42/GHSA-9xgp-phf8-4m42.json +++ b/advisories/unreviewed/2022/05/GHSA-9xgp-phf8-4m42/GHSA-9xgp-phf8-4m42.json @@ -7,12 +7,8 @@ "CVE-2009-3337" ], "details": "SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xh5-5qwr-3g4w/GHSA-9xh5-5qwr-3g4w.json b/advisories/unreviewed/2022/05/GHSA-9xh5-5qwr-3g4w/GHSA-9xh5-5qwr-3g4w.json index 7097c4d5a05..ac489b7e52f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xh5-5qwr-3g4w/GHSA-9xh5-5qwr-3g4w.json +++ b/advisories/unreviewed/2022/05/GHSA-9xh5-5qwr-3g4w/GHSA-9xh5-5qwr-3g4w.json @@ -7,12 +7,8 @@ "CVE-2009-3343" ], "details": "SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2c8-3mgj-74jc/GHSA-c2c8-3mgj-74jc.json b/advisories/unreviewed/2022/05/GHSA-c2c8-3mgj-74jc/GHSA-c2c8-3mgj-74jc.json index 7d1819a8681..825a669d0a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2c8-3mgj-74jc/GHSA-c2c8-3mgj-74jc.json +++ b/advisories/unreviewed/2022/05/GHSA-c2c8-3mgj-74jc/GHSA-c2c8-3mgj-74jc.json @@ -7,12 +7,8 @@ "CVE-2009-3647" ], "details": "Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3w4-m4vr-9g7g/GHSA-c3w4-m4vr-9g7g.json b/advisories/unreviewed/2022/05/GHSA-c3w4-m4vr-9g7g/GHSA-c3w4-m4vr-9g7g.json index 18d41335d45..cc7ff58529e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3w4-m4vr-9g7g/GHSA-c3w4-m4vr-9g7g.json +++ b/advisories/unreviewed/2022/05/GHSA-c3w4-m4vr-9g7g/GHSA-c3w4-m4vr-9g7g.json @@ -7,12 +7,8 @@ "CVE-2009-3110" ], "details": "Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4gw-w6f2-29hh/GHSA-c4gw-w6f2-29hh.json b/advisories/unreviewed/2022/05/GHSA-c4gw-w6f2-29hh/GHSA-c4gw-w6f2-29hh.json index c1bd4d1d5b6..13ddbc37ff1 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4gw-w6f2-29hh/GHSA-c4gw-w6f2-29hh.json +++ b/advisories/unreviewed/2022/05/GHSA-c4gw-w6f2-29hh/GHSA-c4gw-w6f2-29hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4q8-68wp-mg94/GHSA-c4q8-68wp-mg94.json b/advisories/unreviewed/2022/05/GHSA-c4q8-68wp-mg94/GHSA-c4q8-68wp-mg94.json index 353940fcd77..3f3c8d58bea 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4q8-68wp-mg94/GHSA-c4q8-68wp-mg94.json +++ b/advisories/unreviewed/2022/05/GHSA-c4q8-68wp-mg94/GHSA-c4q8-68wp-mg94.json @@ -7,12 +7,8 @@ "CVE-2009-3511" ], "details": "Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c588-rhc6-9hw7/GHSA-c588-rhc6-9hw7.json b/advisories/unreviewed/2022/05/GHSA-c588-rhc6-9hw7/GHSA-c588-rhc6-9hw7.json index 07ecf20be25..6e696646a39 100644 --- a/advisories/unreviewed/2022/05/GHSA-c588-rhc6-9hw7/GHSA-c588-rhc6-9hw7.json +++ b/advisories/unreviewed/2022/05/GHSA-c588-rhc6-9hw7/GHSA-c588-rhc6-9hw7.json @@ -7,12 +7,8 @@ "CVE-2009-3390" ], "details": "Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris snv_28 through snv_109, allow local users with certain RBAC execution profiles to gain privileges via unknown vectors related to the libima library.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5xx-mwc6-vw82/GHSA-c5xx-mwc6-vw82.json b/advisories/unreviewed/2022/05/GHSA-c5xx-mwc6-vw82/GHSA-c5xx-mwc6-vw82.json index a506d469782..15765584073 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5xx-mwc6-vw82/GHSA-c5xx-mwc6-vw82.json +++ b/advisories/unreviewed/2022/05/GHSA-c5xx-mwc6-vw82/GHSA-c5xx-mwc6-vw82.json @@ -7,12 +7,8 @@ "CVE-2009-3637" ], "details": "Stack-based buffer overflow in the M_AddToServerList function in client/menu.c in Red Planet Arena Alien Arena 7.30 allows remote attackers to execute arbitrary code via a packet with a crafted server description to UDP port 27901 followed by a packet with a long print command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c856-7jr3-wm6x/GHSA-c856-7jr3-wm6x.json b/advisories/unreviewed/2022/05/GHSA-c856-7jr3-wm6x/GHSA-c856-7jr3-wm6x.json index 5855a9024cb..f8cfeddcb21 100644 --- a/advisories/unreviewed/2022/05/GHSA-c856-7jr3-wm6x/GHSA-c856-7jr3-wm6x.json +++ b/advisories/unreviewed/2022/05/GHSA-c856-7jr3-wm6x/GHSA-c856-7jr3-wm6x.json @@ -7,12 +7,8 @@ "CVE-2009-3439" ], "details": "Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2) repository_links.php, and (3) repository_editdocument.php in repository/; the (4) group parameter to policy/getpolicy.php; the name parameter to (5) host/newhostgroupform.php and (6) net/modifynetform.php; and unspecified other vectors related to the policy menu.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf72-mxxr-2628/GHSA-cf72-mxxr-2628.json b/advisories/unreviewed/2022/05/GHSA-cf72-mxxr-2628/GHSA-cf72-mxxr-2628.json index a7d8316d31e..51e63c6f882 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf72-mxxr-2628/GHSA-cf72-mxxr-2628.json +++ b/advisories/unreviewed/2022/05/GHSA-cf72-mxxr-2628/GHSA-cf72-mxxr-2628.json @@ -7,12 +7,8 @@ "CVE-2009-3445" ], "details": "Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cg66-88cp-whx8/GHSA-cg66-88cp-whx8.json b/advisories/unreviewed/2022/05/GHSA-cg66-88cp-whx8/GHSA-cg66-88cp-whx8.json index a2cd3c73ca1..6929121f100 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg66-88cp-whx8/GHSA-cg66-88cp-whx8.json +++ b/advisories/unreviewed/2022/05/GHSA-cg66-88cp-whx8/GHSA-cg66-88cp-whx8.json @@ -7,12 +7,8 @@ "CVE-2009-3654" ], "details": "Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot directories via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cg85-44qc-39mw/GHSA-cg85-44qc-39mw.json b/advisories/unreviewed/2022/05/GHSA-cg85-44qc-39mw/GHSA-cg85-44qc-39mw.json index 6c10be25de2..7f74b8fecf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg85-44qc-39mw/GHSA-cg85-44qc-39mw.json +++ b/advisories/unreviewed/2022/05/GHSA-cg85-44qc-39mw/GHSA-cg85-44qc-39mw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgf9-7f38-5j6c/GHSA-cgf9-7f38-5j6c.json b/advisories/unreviewed/2022/05/GHSA-cgf9-7f38-5j6c/GHSA-cgf9-7f38-5j6c.json index 0239fecccdd..b5c90fd7930 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgf9-7f38-5j6c/GHSA-cgf9-7f38-5j6c.json +++ b/advisories/unreviewed/2022/05/GHSA-cgf9-7f38-5j6c/GHSA-cgf9-7f38-5j6c.json @@ -7,12 +7,8 @@ "CVE-2009-3513" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgjm-832j-ch4g/GHSA-cgjm-832j-ch4g.json b/advisories/unreviewed/2022/05/GHSA-cgjm-832j-ch4g/GHSA-cgjm-832j-ch4g.json index 8c33e3a5d27..3767a2d77d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgjm-832j-ch4g/GHSA-cgjm-832j-ch4g.json +++ b/advisories/unreviewed/2022/05/GHSA-cgjm-832j-ch4g/GHSA-cgjm-832j-ch4g.json @@ -7,12 +7,8 @@ "CVE-2009-3662" ], "details": "FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafted NOOP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch6v-3x5q-gm5j/GHSA-ch6v-3x5q-gm5j.json b/advisories/unreviewed/2022/05/GHSA-ch6v-3x5q-gm5j/GHSA-ch6v-3x5q-gm5j.json index f4b663dfab5..f7d12737740 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch6v-3x5q-gm5j/GHSA-ch6v-3x5q-gm5j.json +++ b/advisories/unreviewed/2022/05/GHSA-ch6v-3x5q-gm5j/GHSA-ch6v-3x5q-gm5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjh5-6x4r-74cw/GHSA-cjh5-6x4r-74cw.json b/advisories/unreviewed/2022/05/GHSA-cjh5-6x4r-74cw/GHSA-cjh5-6x4r-74cw.json index 0a0e4688549..1f6a07978ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjh5-6x4r-74cw/GHSA-cjh5-6x4r-74cw.json +++ b/advisories/unreviewed/2022/05/GHSA-cjh5-6x4r-74cw/GHSA-cjh5-6x4r-74cw.json @@ -7,12 +7,8 @@ "CVE-2009-3667" ], "details": "SQL injection vulnerability in admin/index.php in AdsDX 3.05 allows remote attackers to execute arbitrary SQL commands via the Username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq3q-q7wq-586q/GHSA-cq3q-q7wq-586q.json b/advisories/unreviewed/2022/05/GHSA-cq3q-q7wq-586q/GHSA-cq3q-q7wq-586q.json index 33b2a7197e0..7af4f2088fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq3q-q7wq-586q/GHSA-cq3q-q7wq-586q.json +++ b/advisories/unreviewed/2022/05/GHSA-cq3q-q7wq-586q/GHSA-cq3q-q7wq-586q.json @@ -7,12 +7,8 @@ "CVE-2009-3783" ], "details": "Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqgg-3gcf-cxj8/GHSA-cqgg-3gcf-cxj8.json b/advisories/unreviewed/2022/05/GHSA-cqgg-3gcf-cxj8/GHSA-cqgg-3gcf-cxj8.json index 558426f0bc6..b2515a00745 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqgg-3gcf-cxj8/GHSA-cqgg-3gcf-cxj8.json +++ b/advisories/unreviewed/2022/05/GHSA-cqgg-3gcf-cxj8/GHSA-cqgg-3gcf-cxj8.json @@ -7,12 +7,8 @@ "CVE-2009-3425" ], "details": "Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via directory traversal sequences in the thCMS_root parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqvc-98g2-g2j9/GHSA-cqvc-98g2-g2j9.json b/advisories/unreviewed/2022/05/GHSA-cqvc-98g2-g2j9/GHSA-cqvc-98g2-g2j9.json index 2b1ec76ca80..bc8da031830 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqvc-98g2-g2j9/GHSA-cqvc-98g2-g2j9.json +++ b/advisories/unreviewed/2022/05/GHSA-cqvc-98g2-g2j9/GHSA-cqvc-98g2-g2j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crgw-fph4-cgrp/GHSA-crgw-fph4-cgrp.json b/advisories/unreviewed/2022/05/GHSA-crgw-fph4-cgrp/GHSA-crgw-fph4-cgrp.json index c8a7510d70d..4716422b502 100644 --- a/advisories/unreviewed/2022/05/GHSA-crgw-fph4-cgrp/GHSA-crgw-fph4-cgrp.json +++ b/advisories/unreviewed/2022/05/GHSA-crgw-fph4-cgrp/GHSA-crgw-fph4-cgrp.json @@ -7,12 +7,8 @@ "CVE-2009-3133" ], "details": "Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to \"loading Excel records,\" aka \"Excel Document Parsing Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crpf-mqjx-74x8/GHSA-crpf-mqjx-74x8.json b/advisories/unreviewed/2022/05/GHSA-crpf-mqjx-74x8/GHSA-crpf-mqjx-74x8.json index dad6d693b8d..8389b0c7bfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-crpf-mqjx-74x8/GHSA-crpf-mqjx-74x8.json +++ b/advisories/unreviewed/2022/05/GHSA-crpf-mqjx-74x8/GHSA-crpf-mqjx-74x8.json @@ -7,12 +7,8 @@ "CVE-2009-3596" ], "details": "JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypass authentication and gain administrative access via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cv7m-77hj-cr43/GHSA-cv7m-77hj-cr43.json b/advisories/unreviewed/2022/05/GHSA-cv7m-77hj-cr43/GHSA-cv7m-77hj-cr43.json index ca2efa497f7..27e38cc0e3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv7m-77hj-cr43/GHSA-cv7m-77hj-cr43.json +++ b/advisories/unreviewed/2022/05/GHSA-cv7m-77hj-cr43/GHSA-cv7m-77hj-cr43.json @@ -7,12 +7,8 @@ "CVE-2009-3745" ], "details": "Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to inject arbitrary web script or HTML via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwqc-w7f5-59qr/GHSA-cwqc-w7f5-59qr.json b/advisories/unreviewed/2022/05/GHSA-cwqc-w7f5-59qr/GHSA-cwqc-w7f5-59qr.json index a4d804f17d9..7a702fd6c8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwqc-w7f5-59qr/GHSA-cwqc-w7f5-59qr.json +++ b/advisories/unreviewed/2022/05/GHSA-cwqc-w7f5-59qr/GHSA-cwqc-w7f5-59qr.json @@ -7,12 +7,8 @@ "CVE-2009-3350" ], "details": "Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx8q-2cc9-5r23/GHSA-cx8q-2cc9-5r23.json b/advisories/unreviewed/2022/05/GHSA-cx8q-2cc9-5r23/GHSA-cx8q-2cc9-5r23.json index 15a8c92f842..dd0e8d8a255 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx8q-2cc9-5r23/GHSA-cx8q-2cc9-5r23.json +++ b/advisories/unreviewed/2022/05/GHSA-cx8q-2cc9-5r23/GHSA-cx8q-2cc9-5r23.json @@ -7,12 +7,8 @@ "CVE-2009-3224" ], "details": "SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxxh-cfm2-r8pj/GHSA-cxxh-cfm2-r8pj.json b/advisories/unreviewed/2022/05/GHSA-cxxh-cfm2-r8pj/GHSA-cxxh-cfm2-r8pj.json index fcce4defb45..8ff828646a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxxh-cfm2-r8pj/GHSA-cxxh-cfm2-r8pj.json +++ b/advisories/unreviewed/2022/05/GHSA-cxxh-cfm2-r8pj/GHSA-cxxh-cfm2-r8pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3f7-w28x-9vg3/GHSA-f3f7-w28x-9vg3.json b/advisories/unreviewed/2022/05/GHSA-f3f7-w28x-9vg3/GHSA-f3f7-w28x-9vg3.json index 3259db65b8b..070a894ef9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3f7-w28x-9vg3/GHSA-f3f7-w28x-9vg3.json +++ b/advisories/unreviewed/2022/05/GHSA-f3f7-w28x-9vg3/GHSA-f3f7-w28x-9vg3.json @@ -7,12 +7,8 @@ "CVE-2009-3492" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathToIndex parameter to (1) Calendar.php, (2) Comment.php, (3) Rss.php and (4) Trackback.php in lib/Loggix/Module/; and (5) modules/downloads/lib/LM_Downloads.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3mm-jx3m-92v4/GHSA-f3mm-jx3m-92v4.json b/advisories/unreviewed/2022/05/GHSA-f3mm-jx3m-92v4/GHSA-f3mm-jx3m-92v4.json index 34addb57f5d..e1a92f529a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3mm-jx3m-92v4/GHSA-f3mm-jx3m-92v4.json +++ b/advisories/unreviewed/2022/05/GHSA-f3mm-jx3m-92v4/GHSA-f3mm-jx3m-92v4.json @@ -7,12 +7,8 @@ "CVE-2009-3428" ], "details": "Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5vq-4rpj-3x2w/GHSA-f5vq-4rpj-3x2w.json b/advisories/unreviewed/2022/05/GHSA-f5vq-4rpj-3x2w/GHSA-f5vq-4rpj-3x2w.json index d59bc186350..99e86df6765 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5vq-4rpj-3x2w/GHSA-f5vq-4rpj-3x2w.json +++ b/advisories/unreviewed/2022/05/GHSA-f5vq-4rpj-3x2w/GHSA-f5vq-4rpj-3x2w.json @@ -7,12 +7,8 @@ "CVE-2009-3521" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6j4-cwrp-j9m3/GHSA-f6j4-cwrp-j9m3.json b/advisories/unreviewed/2022/05/GHSA-f6j4-cwrp-j9m3/GHSA-f6j4-cwrp-j9m3.json index b6aefefd7d5..12de22c1ca3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6j4-cwrp-j9m3/GHSA-f6j4-cwrp-j9m3.json +++ b/advisories/unreviewed/2022/05/GHSA-f6j4-cwrp-j9m3/GHSA-f6j4-cwrp-j9m3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7fv-7rmr-mpcf/GHSA-f7fv-7rmr-mpcf.json b/advisories/unreviewed/2022/05/GHSA-f7fv-7rmr-mpcf/GHSA-f7fv-7rmr-mpcf.json index 30896ec1f53..2d78ebfbdc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7fv-7rmr-mpcf/GHSA-f7fv-7rmr-mpcf.json +++ b/advisories/unreviewed/2022/05/GHSA-f7fv-7rmr-mpcf/GHSA-f7fv-7rmr-mpcf.json @@ -7,12 +7,8 @@ "CVE-2009-3379" ], "details": "Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7wh-x2jr-33hx/GHSA-f7wh-x2jr-33hx.json b/advisories/unreviewed/2022/05/GHSA-f7wh-x2jr-33hx/GHSA-f7wh-x2jr-33hx.json index 17cd7bd57f2..73eb7b433fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7wh-x2jr-33hx/GHSA-f7wh-x2jr-33hx.json +++ b/advisories/unreviewed/2022/05/GHSA-f7wh-x2jr-33hx/GHSA-f7wh-x2jr-33hx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9gp-292p-73gh/GHSA-f9gp-292p-73gh.json b/advisories/unreviewed/2022/05/GHSA-f9gp-292p-73gh/GHSA-f9gp-292p-73gh.json index 1cc04ba4e18..9c40e087c56 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9gp-292p-73gh/GHSA-f9gp-292p-73gh.json +++ b/advisories/unreviewed/2022/05/GHSA-f9gp-292p-73gh/GHSA-f9gp-292p-73gh.json @@ -7,12 +7,8 @@ "CVE-2009-3401" ], "details": "Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows local users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcp9-xcgr-hwj9/GHSA-fcp9-xcgr-hwj9.json b/advisories/unreviewed/2022/05/GHSA-fcp9-xcgr-hwj9/GHSA-fcp9-xcgr-hwj9.json index 9b2c3e218b1..54016ee2fb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcp9-xcgr-hwj9/GHSA-fcp9-xcgr-hwj9.json +++ b/advisories/unreviewed/2022/05/GHSA-fcp9-xcgr-hwj9/GHSA-fcp9-xcgr-hwj9.json @@ -7,12 +7,8 @@ "CVE-2009-3117" ], "details": "SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcvr-5v45-3j27/GHSA-fcvr-5v45-3j27.json b/advisories/unreviewed/2022/05/GHSA-fcvr-5v45-3j27/GHSA-fcvr-5v45-3j27.json index 120530fb1e6..87a9e19e35e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcvr-5v45-3j27/GHSA-fcvr-5v45-3j27.json +++ b/advisories/unreviewed/2022/05/GHSA-fcvr-5v45-3j27/GHSA-fcvr-5v45-3j27.json @@ -7,12 +7,8 @@ "CVE-2009-3749" ], "details": "The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgmw-jj4f-5935/GHSA-fgmw-jj4f-5935.json b/advisories/unreviewed/2022/05/GHSA-fgmw-jj4f-5935/GHSA-fgmw-jj4f-5935.json index 765e2c7cd19..ae02835ef4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgmw-jj4f-5935/GHSA-fgmw-jj4f-5935.json +++ b/advisories/unreviewed/2022/05/GHSA-fgmw-jj4f-5935/GHSA-fgmw-jj4f-5935.json @@ -7,12 +7,8 @@ "CVE-2009-3502" ], "details": "SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh97-6p2x-5xf9/GHSA-fh97-6p2x-5xf9.json b/advisories/unreviewed/2022/05/GHSA-fh97-6p2x-5xf9/GHSA-fh97-6p2x-5xf9.json index 053580c14e8..a3178d938c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh97-6p2x-5xf9/GHSA-fh97-6p2x-5xf9.json +++ b/advisories/unreviewed/2022/05/GHSA-fh97-6p2x-5xf9/GHSA-fh97-6p2x-5xf9.json @@ -7,12 +7,8 @@ "CVE-2009-3293" ], "details": "Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect \"sanity check for the color index.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhmg-6ffp-g88h/GHSA-fhmg-6ffp-g88h.json b/advisories/unreviewed/2022/05/GHSA-fhmg-6ffp-g88h/GHSA-fhmg-6ffp-g88h.json index 4b4d74a7bf1..1f1592c6a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhmg-6ffp-g88h/GHSA-fhmg-6ffp-g88h.json +++ b/advisories/unreviewed/2022/05/GHSA-fhmg-6ffp-g88h/GHSA-fhmg-6ffp-g88h.json @@ -7,12 +7,8 @@ "CVE-2009-3320" ], "details": "Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj6c-w79g-p5j2/GHSA-fj6c-w79g-p5j2.json b/advisories/unreviewed/2022/05/GHSA-fj6c-w79g-p5j2/GHSA-fj6c-w79g-p5j2.json index 2d7f37a55db..425e857ceea 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj6c-w79g-p5j2/GHSA-fj6c-w79g-p5j2.json +++ b/advisories/unreviewed/2022/05/GHSA-fj6c-w79g-p5j2/GHSA-fj6c-w79g-p5j2.json @@ -7,12 +7,8 @@ "CVE-2009-3708" ], "details": "Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to execute arbitrary code via a long value in a (1) description or (2) keyword META tag. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj7w-ffmj-x9r8/GHSA-fj7w-ffmj-x9r8.json b/advisories/unreviewed/2022/05/GHSA-fj7w-ffmj-x9r8/GHSA-fj7w-ffmj-x9r8.json index 5596e3b563b..c62bbb45f45 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj7w-ffmj-x9r8/GHSA-fj7w-ffmj-x9r8.json +++ b/advisories/unreviewed/2022/05/GHSA-fj7w-ffmj-x9r8/GHSA-fj7w-ffmj-x9r8.json @@ -7,12 +7,8 @@ "CVE-2009-3719" ], "details": "Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or HTML via a comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmwc-77fh-hm65/GHSA-fmwc-77fh-hm65.json b/advisories/unreviewed/2022/05/GHSA-fmwc-77fh-hm65/GHSA-fmwc-77fh-hm65.json index aec87ed32e7..ca20e16c8c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmwc-77fh-hm65/GHSA-fmwc-77fh-hm65.json +++ b/advisories/unreviewed/2022/05/GHSA-fmwc-77fh-hm65/GHSA-fmwc-77fh-hm65.json @@ -7,12 +7,8 @@ "CVE-2009-3509" ], "details": "Cross-site scripting (XSS) vulnerability in admin/admin_index.php in CJ Dynamic Poll PRO 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp4m-4h58-h9px/GHSA-fp4m-4h58-h9px.json b/advisories/unreviewed/2022/05/GHSA-fp4m-4h58-h9px/GHSA-fp4m-4h58-h9px.json index 53b7fd08055..1036b199ea1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp4m-4h58-h9px/GHSA-fp4m-4h58-h9px.json +++ b/advisories/unreviewed/2022/05/GHSA-fp4m-4h58-h9px/GHSA-fp4m-4h58-h9px.json @@ -7,12 +7,8 @@ "CVE-2009-3750" ], "details": "SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp73-6h6h-9v4h/GHSA-fp73-6h6h-9v4h.json b/advisories/unreviewed/2022/05/GHSA-fp73-6h6h-9v4h/GHSA-fp73-6h6h-9v4h.json index cb9c5b82c8c..702ea543e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp73-6h6h-9v4h/GHSA-fp73-6h6h-9v4h.json +++ b/advisories/unreviewed/2022/05/GHSA-fp73-6h6h-9v4h/GHSA-fp73-6h6h-9v4h.json @@ -7,12 +7,8 @@ "CVE-2009-3765" ], "details": "mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr9x-v3mj-475j/GHSA-fr9x-v3mj-475j.json b/advisories/unreviewed/2022/05/GHSA-fr9x-v3mj-475j/GHSA-fr9x-v3mj-475j.json index 0694bd1cd5a..b6725420c1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr9x-v3mj-475j/GHSA-fr9x-v3mj-475j.json +++ b/advisories/unreviewed/2022/05/GHSA-fr9x-v3mj-475j/GHSA-fr9x-v3mj-475j.json @@ -7,12 +7,8 @@ "CVE-2009-3271" ], "details": "Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frr9-jpgq-8xqf/GHSA-frr9-jpgq-8xqf.json b/advisories/unreviewed/2022/05/GHSA-frr9-jpgq-8xqf/GHSA-frr9-jpgq-8xqf.json index 140beb68836..06ec64690ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-frr9-jpgq-8xqf/GHSA-frr9-jpgq-8xqf.json +++ b/advisories/unreviewed/2022/05/GHSA-frr9-jpgq-8xqf/GHSA-frr9-jpgq-8xqf.json @@ -7,12 +7,8 @@ "CVE-2009-3709" ], "details": "Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to execute arbitrary code via a long value in a TITLE tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv2m-h6jj-865v/GHSA-fv2m-h6jj-865v.json b/advisories/unreviewed/2022/05/GHSA-fv2m-h6jj-865v/GHSA-fv2m-h6jj-865v.json index 128fd62cd4c..72bd7030173 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv2m-h6jj-865v/GHSA-fv2m-h6jj-865v.json +++ b/advisories/unreviewed/2022/05/GHSA-fv2m-h6jj-865v/GHSA-fv2m-h6jj-865v.json @@ -7,12 +7,8 @@ "CVE-2009-3530" ], "details": "Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv6g-4qmw-v3mm/GHSA-fv6g-4qmw-v3mm.json b/advisories/unreviewed/2022/05/GHSA-fv6g-4qmw-v3mm/GHSA-fv6g-4qmw-v3mm.json index 261c77a1c73..708a0c50985 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv6g-4qmw-v3mm/GHSA-fv6g-4qmw-v3mm.json +++ b/advisories/unreviewed/2022/05/GHSA-fv6g-4qmw-v3mm/GHSA-fv6g-4qmw-v3mm.json @@ -7,12 +7,8 @@ "CVE-2009-3205" ], "details": "SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv76-2mqf-62hg/GHSA-fv76-2mqf-62hg.json b/advisories/unreviewed/2022/05/GHSA-fv76-2mqf-62hg/GHSA-fv76-2mqf-62hg.json index 455b7e91761..8dfa591f731 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv76-2mqf-62hg/GHSA-fv76-2mqf-62hg.json +++ b/advisories/unreviewed/2022/05/GHSA-fv76-2mqf-62hg/GHSA-fv76-2mqf-62hg.json @@ -7,12 +7,8 @@ "CVE-2009-3655" ], "details": "Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the \"SITE SET TRANSFERPROGRESS ON\" FTP command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw69-82m4-fgm7/GHSA-fw69-82m4-fgm7.json b/advisories/unreviewed/2022/05/GHSA-fw69-82m4-fgm7/GHSA-fw69-82m4-fgm7.json index 666d746364f..9db707ff80e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw69-82m4-fgm7/GHSA-fw69-82m4-fgm7.json +++ b/advisories/unreviewed/2022/05/GHSA-fw69-82m4-fgm7/GHSA-fw69-82m4-fgm7.json @@ -7,12 +7,8 @@ "CVE-2009-3183" ], "details": "Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwxh-8jc9-j26p/GHSA-fwxh-8jc9-j26p.json b/advisories/unreviewed/2022/05/GHSA-fwxh-8jc9-j26p/GHSA-fwxh-8jc9-j26p.json index 1e267ea50e2..d10a61732f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwxh-8jc9-j26p/GHSA-fwxh-8jc9-j26p.json +++ b/advisories/unreviewed/2022/05/GHSA-fwxh-8jc9-j26p/GHSA-fwxh-8jc9-j26p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g23p-47j7-w4hw/GHSA-g23p-47j7-w4hw.json b/advisories/unreviewed/2022/05/GHSA-g23p-47j7-w4hw/GHSA-g23p-47j7-w4hw.json index f91099af4d4..335b9b50d5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g23p-47j7-w4hw/GHSA-g23p-47j7-w4hw.json +++ b/advisories/unreviewed/2022/05/GHSA-g23p-47j7-w4hw/GHSA-g23p-47j7-w4hw.json @@ -7,12 +7,8 @@ "CVE-2009-3475" ], "details": "Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2qc-659r-mxpm/GHSA-g2qc-659r-mxpm.json b/advisories/unreviewed/2022/05/GHSA-g2qc-659r-mxpm/GHSA-g2qc-659r-mxpm.json index 80e1afb8fec..3e1d9a72030 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2qc-659r-mxpm/GHSA-g2qc-659r-mxpm.json +++ b/advisories/unreviewed/2022/05/GHSA-g2qc-659r-mxpm/GHSA-g2qc-659r-mxpm.json @@ -7,12 +7,8 @@ "CVE-2009-3314" ], "details": "SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3p6-v3g4-rgjw/GHSA-g3p6-v3g4-rgjw.json b/advisories/unreviewed/2022/05/GHSA-g3p6-v3g4-rgjw/GHSA-g3p6-v3g4-rgjw.json index 9b3f530b7c8..007826cca87 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3p6-v3g4-rgjw/GHSA-g3p6-v3g4-rgjw.json +++ b/advisories/unreviewed/2022/05/GHSA-g3p6-v3g4-rgjw/GHSA-g3p6-v3g4-rgjw.json @@ -7,12 +7,8 @@ "CVE-2009-3335" ], "details": "SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4p9-28wh-x3gp/GHSA-g4p9-28wh-x3gp.json b/advisories/unreviewed/2022/05/GHSA-g4p9-28wh-x3gp/GHSA-g4p9-28wh-x3gp.json index 46040381891..f7d93468de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4p9-28wh-x3gp/GHSA-g4p9-28wh-x3gp.json +++ b/advisories/unreviewed/2022/05/GHSA-g4p9-28wh-x3gp/GHSA-g4p9-28wh-x3gp.json @@ -7,12 +7,8 @@ "CVE-2009-3383" ], "details": "Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g4vp-9w9q-qppx/GHSA-g4vp-9w9q-qppx.json b/advisories/unreviewed/2022/05/GHSA-g4vp-9w9q-qppx/GHSA-g4vp-9w9q-qppx.json index 445fbc9780c..9f85fce11e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4vp-9w9q-qppx/GHSA-g4vp-9w9q-qppx.json +++ b/advisories/unreviewed/2022/05/GHSA-g4vp-9w9q-qppx/GHSA-g4vp-9w9q-qppx.json @@ -7,12 +7,8 @@ "CVE-2009-3413" ], "details": "Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3414.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g577-wwxq-6x73/GHSA-g577-wwxq-6x73.json b/advisories/unreviewed/2022/05/GHSA-g577-wwxq-6x73/GHSA-g577-wwxq-6x73.json index 79f9ca8bc31..9b0a332d8c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g577-wwxq-6x73/GHSA-g577-wwxq-6x73.json +++ b/advisories/unreviewed/2022/05/GHSA-g577-wwxq-6x73/GHSA-g577-wwxq-6x73.json @@ -7,12 +7,8 @@ "CVE-2009-3381" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5jm-7h4m-pp3x/GHSA-g5jm-7h4m-pp3x.json b/advisories/unreviewed/2022/05/GHSA-g5jm-7h4m-pp3x/GHSA-g5jm-7h4m-pp3x.json index 7f601236928..da4da68c276 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5jm-7h4m-pp3x/GHSA-g5jm-7h4m-pp3x.json +++ b/advisories/unreviewed/2022/05/GHSA-g5jm-7h4m-pp3x/GHSA-g5jm-7h4m-pp3x.json @@ -7,12 +7,8 @@ "CVE-2009-3329" ], "details": "Stack-based buffer overflow in Winplot 1.25.0.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Plot2D (.wp2) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5r9-wgq9-7qh8/GHSA-g5r9-wgq9-7qh8.json b/advisories/unreviewed/2022/05/GHSA-g5r9-wgq9-7qh8/GHSA-g5r9-wgq9-7qh8.json index 5aa74b42fb8..43bf80351f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5r9-wgq9-7qh8/GHSA-g5r9-wgq9-7qh8.json +++ b/advisories/unreviewed/2022/05/GHSA-g5r9-wgq9-7qh8/GHSA-g5r9-wgq9-7qh8.json @@ -7,12 +7,8 @@ "CVE-2009-3503" ], "details": "Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6v8-4wjh-hhw3/GHSA-g6v8-4wjh-hhw3.json b/advisories/unreviewed/2022/05/GHSA-g6v8-4wjh-hhw3/GHSA-g6v8-4wjh-hhw3.json index 6c7c88021d7..856f0a32a8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6v8-4wjh-hhw3/GHSA-g6v8-4wjh-hhw3.json +++ b/advisories/unreviewed/2022/05/GHSA-g6v8-4wjh-hhw3/GHSA-g6v8-4wjh-hhw3.json @@ -7,12 +7,8 @@ "CVE-2009-3330" ], "details": "SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6x6-w452-43rx/GHSA-g6x6-w452-43rx.json b/advisories/unreviewed/2022/05/GHSA-g6x6-w452-43rx/GHSA-g6x6-w452-43rx.json index 1e8052a6ff7..83f250da216 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6x6-w452-43rx/GHSA-g6x6-w452-43rx.json +++ b/advisories/unreviewed/2022/05/GHSA-g6x6-w452-43rx/GHSA-g6x6-w452-43rx.json @@ -7,12 +7,8 @@ "CVE-2009-3185" ], "details": "SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g88p-pxmv-gq5w/GHSA-g88p-pxmv-gq5w.json b/advisories/unreviewed/2022/05/GHSA-g88p-pxmv-gq5w/GHSA-g88p-pxmv-gq5w.json index 55da93300f3..4573fcd3b25 100644 --- a/advisories/unreviewed/2022/05/GHSA-g88p-pxmv-gq5w/GHSA-g88p-pxmv-gq5w.json +++ b/advisories/unreviewed/2022/05/GHSA-g88p-pxmv-gq5w/GHSA-g88p-pxmv-gq5w.json @@ -7,12 +7,8 @@ "CVE-2009-3208" ], "details": "Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to permalink.php and (2) year parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8j4-g47v-j89j/GHSA-g8j4-g47v-j89j.json b/advisories/unreviewed/2022/05/GHSA-g8j4-g47v-j89j/GHSA-g8j4-g47v-j89j.json index 91e3179f344..6de699dac03 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8j4-g47v-j89j/GHSA-g8j4-g47v-j89j.json +++ b/advisories/unreviewed/2022/05/GHSA-g8j4-g47v-j89j/GHSA-g8j4-g47v-j89j.json @@ -7,12 +7,8 @@ "CVE-2009-3417" ], "details": "SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g996-fh92-mcqv/GHSA-g996-fh92-mcqv.json b/advisories/unreviewed/2022/05/GHSA-g996-fh92-mcqv/GHSA-g996-fh92-mcqv.json index d22be10ef47..6647d95fc93 100644 --- a/advisories/unreviewed/2022/05/GHSA-g996-fh92-mcqv/GHSA-g996-fh92-mcqv.json +++ b/advisories/unreviewed/2022/05/GHSA-g996-fh92-mcqv/GHSA-g996-fh92-mcqv.json @@ -7,12 +7,8 @@ "CVE-2009-3446" ], "details": "SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc2m-m9rw-7phm/GHSA-gc2m-m9rw-7phm.json b/advisories/unreviewed/2022/05/GHSA-gc2m-m9rw-7phm/GHSA-gc2m-m9rw-7phm.json index 4a52b6b8b72..d0e3a08a680 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc2m-m9rw-7phm/GHSA-gc2m-m9rw-7phm.json +++ b/advisories/unreviewed/2022/05/GHSA-gc2m-m9rw-7phm/GHSA-gc2m-m9rw-7phm.json @@ -7,12 +7,8 @@ "CVE-2009-3497" ], "details": "SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf9w-mffq-c45p/GHSA-gf9w-mffq-c45p.json b/advisories/unreviewed/2022/05/GHSA-gf9w-mffq-c45p/GHSA-gf9w-mffq-c45p.json index a2c9a014b33..c0f5e39b00f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf9w-mffq-c45p/GHSA-gf9w-mffq-c45p.json +++ b/advisories/unreviewed/2022/05/GHSA-gf9w-mffq-c45p/GHSA-gf9w-mffq-c45p.json @@ -7,12 +7,8 @@ "CVE-2009-3704" ], "details": "ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gfq6-4prx-wrrm/GHSA-gfq6-4prx-wrrm.json b/advisories/unreviewed/2022/05/GHSA-gfq6-4prx-wrrm/GHSA-gfq6-4prx-wrrm.json index 9777c453b82..aba4f38a078 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfq6-4prx-wrrm/GHSA-gfq6-4prx-wrrm.json +++ b/advisories/unreviewed/2022/05/GHSA-gfq6-4prx-wrrm/GHSA-gfq6-4prx-wrrm.json @@ -7,12 +7,8 @@ "CVE-2009-3108" ], "details": "The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json b/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json index cd5338032c2..4aa73ae9cdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json +++ b/advisories/unreviewed/2022/05/GHSA-gg87-xrj2-3r8m/GHSA-gg87-xrj2-3r8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gggg-8p94-c53f/GHSA-gggg-8p94-c53f.json b/advisories/unreviewed/2022/05/GHSA-gggg-8p94-c53f/GHSA-gggg-8p94-c53f.json index 6a0823575f3..cd407ace6e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gggg-8p94-c53f/GHSA-gggg-8p94-c53f.json +++ b/advisories/unreviewed/2022/05/GHSA-gggg-8p94-c53f/GHSA-gggg-8p94-c53f.json @@ -7,12 +7,8 @@ "CVE-2009-3125" ], "details": "SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj3g-3mmj-f53j/GHSA-gj3g-3mmj-f53j.json b/advisories/unreviewed/2022/05/GHSA-gj3g-3mmj-f53j/GHSA-gj3g-3mmj-f53j.json index d6eef35089a..156dd1d62a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj3g-3mmj-f53j/GHSA-gj3g-3mmj-f53j.json +++ b/advisories/unreviewed/2022/05/GHSA-gj3g-3mmj-f53j/GHSA-gj3g-3mmj-f53j.json @@ -7,12 +7,8 @@ "CVE-2009-3377" ], "details": "Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj4q-m5q3-4wfq/GHSA-gj4q-m5q3-4wfq.json b/advisories/unreviewed/2022/05/GHSA-gj4q-m5q3-4wfq/GHSA-gj4q-m5q3-4wfq.json index 29a26f6bf65..d8907acb242 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj4q-m5q3-4wfq/GHSA-gj4q-m5q3-4wfq.json +++ b/advisories/unreviewed/2022/05/GHSA-gj4q-m5q3-4wfq/GHSA-gj4q-m5q3-4wfq.json @@ -7,12 +7,8 @@ "CVE-2009-3663" ], "details": "Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm75-mfx6-2q8j/GHSA-gm75-mfx6-2q8j.json b/advisories/unreviewed/2022/05/GHSA-gm75-mfx6-2q8j/GHSA-gm75-mfx6-2q8j.json index 434ce63fbb6..63f8f9733f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm75-mfx6-2q8j/GHSA-gm75-mfx6-2q8j.json +++ b/advisories/unreviewed/2022/05/GHSA-gm75-mfx6-2q8j/GHSA-gm75-mfx6-2q8j.json @@ -7,12 +7,8 @@ "CVE-2009-3746" ], "details": "XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json b/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json index b4c7936af0b..5244a4b0e78 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json +++ b/advisories/unreviewed/2022/05/GHSA-gpq7-5wgv-cqmg/GHSA-gpq7-5wgv-cqmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grfh-h2j5-w2h2/GHSA-grfh-h2j5-w2h2.json b/advisories/unreviewed/2022/05/GHSA-grfh-h2j5-w2h2/GHSA-grfh-h2j5-w2h2.json index e24abc6fd90..4f28fbfd8a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-grfh-h2j5-w2h2/GHSA-grfh-h2j5-w2h2.json +++ b/advisories/unreviewed/2022/05/GHSA-grfh-h2j5-w2h2/GHSA-grfh-h2j5-w2h2.json @@ -7,12 +7,8 @@ "CVE-2009-3214" ], "details": "Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv2v-72f9-437h/GHSA-gv2v-72f9-437h.json b/advisories/unreviewed/2022/05/GHSA-gv2v-72f9-437h/GHSA-gv2v-72f9-437h.json index 4bc8d54ef7d..8db04e0c70f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv2v-72f9-437h/GHSA-gv2v-72f9-437h.json +++ b/advisories/unreviewed/2022/05/GHSA-gv2v-72f9-437h/GHSA-gv2v-72f9-437h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwr5-2w8p-gpfx/GHSA-gwr5-2w8p-gpfx.json b/advisories/unreviewed/2022/05/GHSA-gwr5-2w8p-gpfx/GHSA-gwr5-2w8p-gpfx.json index 2f01fedb93c..c74e25194b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwr5-2w8p-gpfx/GHSA-gwr5-2w8p-gpfx.json +++ b/advisories/unreviewed/2022/05/GHSA-gwr5-2w8p-gpfx/GHSA-gwr5-2w8p-gpfx.json @@ -7,12 +7,8 @@ "CVE-2009-3388" ], "details": "liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to \"memory safety issues.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxp5-vj8w-vjmw/GHSA-gxp5-vj8w-vjmw.json b/advisories/unreviewed/2022/05/GHSA-gxp5-vj8w-vjmw/GHSA-gxp5-vj8w-vjmw.json index d40367f3856..f1382919927 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxp5-vj8w-vjmw/GHSA-gxp5-vj8w-vjmw.json +++ b/advisories/unreviewed/2022/05/GHSA-gxp5-vj8w-vjmw/GHSA-gxp5-vj8w-vjmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2c2-gc59-r4j2/GHSA-h2c2-gc59-r4j2.json b/advisories/unreviewed/2022/05/GHSA-h2c2-gc59-r4j2/GHSA-h2c2-gc59-r4j2.json index 7762782e142..bf1ae3ceda2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2c2-gc59-r4j2/GHSA-h2c2-gc59-r4j2.json +++ b/advisories/unreviewed/2022/05/GHSA-h2c2-gc59-r4j2/GHSA-h2c2-gc59-r4j2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2jh-pqwh-qf23/GHSA-h2jh-pqwh-qf23.json b/advisories/unreviewed/2022/05/GHSA-h2jh-pqwh-qf23/GHSA-h2jh-pqwh-qf23.json index 969678f7891..a90db7dd6f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2jh-pqwh-qf23/GHSA-h2jh-pqwh-qf23.json +++ b/advisories/unreviewed/2022/05/GHSA-h2jh-pqwh-qf23/GHSA-h2jh-pqwh-qf23.json @@ -7,12 +7,8 @@ "CVE-2009-3268" ], "details": "Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h362-962g-jw74/GHSA-h362-962g-jw74.json b/advisories/unreviewed/2022/05/GHSA-h362-962g-jw74/GHSA-h362-962g-jw74.json index ece3c11262e..368ee7d5f49 100644 --- a/advisories/unreviewed/2022/05/GHSA-h362-962g-jw74/GHSA-h362-962g-jw74.json +++ b/advisories/unreviewed/2022/05/GHSA-h362-962g-jw74/GHSA-h362-962g-jw74.json @@ -7,12 +7,8 @@ "CVE-2009-3322" ], "details": "The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6wf-q4gf-3q3w/GHSA-h6wf-q4gf-3q3w.json b/advisories/unreviewed/2022/05/GHSA-h6wf-q4gf-3q3w/GHSA-h6wf-q4gf-3q3w.json index ec6106b88de..598836a42db 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wf-q4gf-3q3w/GHSA-h6wf-q4gf-3q3w.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wf-q4gf-3q3w/GHSA-h6wf-q4gf-3q3w.json @@ -7,12 +7,8 @@ "CVE-2009-3124" ], "details": "Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h99v-q69f-4grg/GHSA-h99v-q69f-4grg.json b/advisories/unreviewed/2022/05/GHSA-h99v-q69f-4grg/GHSA-h99v-q69f-4grg.json index 7418c25d168..6543d2385dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-h99v-q69f-4grg/GHSA-h99v-q69f-4grg.json +++ b/advisories/unreviewed/2022/05/GHSA-h99v-q69f-4grg/GHSA-h99v-q69f-4grg.json @@ -7,12 +7,8 @@ "CVE-2009-3397" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9qh-wvqp-pffp/GHSA-h9qh-wvqp-pffp.json b/advisories/unreviewed/2022/05/GHSA-h9qh-wvqp-pffp/GHSA-h9qh-wvqp-pffp.json index ab1d4fa1c41..263b0db170a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9qh-wvqp-pffp/GHSA-h9qh-wvqp-pffp.json +++ b/advisories/unreviewed/2022/05/GHSA-h9qh-wvqp-pffp/GHSA-h9qh-wvqp-pffp.json @@ -7,12 +7,8 @@ "CVE-2009-3665" ], "details": "Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) i parameter or (2) v parameters in a register action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9wp-p7qf-4j48/GHSA-h9wp-p7qf-4j48.json b/advisories/unreviewed/2022/05/GHSA-h9wp-p7qf-4j48/GHSA-h9wp-p7qf-4j48.json index 4e586eac69a..48e855f6730 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9wp-p7qf-4j48/GHSA-h9wp-p7qf-4j48.json +++ b/advisories/unreviewed/2022/05/GHSA-h9wp-p7qf-4j48/GHSA-h9wp-p7qf-4j48.json @@ -7,12 +7,8 @@ "CVE-2009-3097" ], "details": "Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc4m-gmh3-4vxp/GHSA-hc4m-gmh3-4vxp.json b/advisories/unreviewed/2022/05/GHSA-hc4m-gmh3-4vxp/GHSA-hc4m-gmh3-4vxp.json index a30ece5ae16..1bf67016016 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc4m-gmh3-4vxp/GHSA-hc4m-gmh3-4vxp.json +++ b/advisories/unreviewed/2022/05/GHSA-hc4m-gmh3-4vxp/GHSA-hc4m-gmh3-4vxp.json @@ -7,12 +7,8 @@ "CVE-2009-3767" ], "details": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf35-fq38-46hh/GHSA-hf35-fq38-46hh.json b/advisories/unreviewed/2022/05/GHSA-hf35-fq38-46hh/GHSA-hf35-fq38-46hh.json index ce1f32c04ba..d43dc90ce6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf35-fq38-46hh/GHSA-hf35-fq38-46hh.json +++ b/advisories/unreviewed/2022/05/GHSA-hf35-fq38-46hh/GHSA-hf35-fq38-46hh.json @@ -7,12 +7,8 @@ "CVE-2009-3423" ], "details": "login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf5h-vf88-c9cq/GHSA-hf5h-vf88-c9cq.json b/advisories/unreviewed/2022/05/GHSA-hf5h-vf88-c9cq/GHSA-hf5h-vf88-c9cq.json index 044a3e9492d..05fc7082817 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf5h-vf88-c9cq/GHSA-hf5h-vf88-c9cq.json +++ b/advisories/unreviewed/2022/05/GHSA-hf5h-vf88-c9cq/GHSA-hf5h-vf88-c9cq.json @@ -7,12 +7,8 @@ "CVE-2009-3780" ], "details": "Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1 and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfjj-9f59-p559/GHSA-hfjj-9f59-p559.json b/advisories/unreviewed/2022/05/GHSA-hfjj-9f59-p559/GHSA-hfjj-9f59-p559.json index c665c8cf90b..c32969e03b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfjj-9f59-p559/GHSA-hfjj-9f59-p559.json +++ b/advisories/unreviewed/2022/05/GHSA-hfjj-9f59-p559/GHSA-hfjj-9f59-p559.json @@ -7,12 +7,8 @@ "CVE-2009-3573" ], "details": "Multiple insecure method vulnerabilities in the PDIControl.PDI.1 ActiveX control (PDIControl.dll) 2.2.3160.0 in EMC Captiva PixTools Distributed Imaging 2.2 allow remote attackers to create or overwrite arbitrary files via the (1) SetLogFileName and (2) WriteToLog methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh2x-4qph-x5hf/GHSA-hh2x-4qph-x5hf.json b/advisories/unreviewed/2022/05/GHSA-hh2x-4qph-x5hf/GHSA-hh2x-4qph-x5hf.json index 60603b06882..ab4625e6b10 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh2x-4qph-x5hf/GHSA-hh2x-4qph-x5hf.json +++ b/advisories/unreviewed/2022/05/GHSA-hh2x-4qph-x5hf/GHSA-hh2x-4qph-x5hf.json @@ -7,12 +7,8 @@ "CVE-2009-3737" ], "details": "The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh76-773h-vqh2/GHSA-hh76-773h-vqh2.json b/advisories/unreviewed/2022/05/GHSA-hh76-773h-vqh2/GHSA-hh76-773h-vqh2.json index 7a9c89b150d..a55b0526d4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh76-773h-vqh2/GHSA-hh76-773h-vqh2.json +++ b/advisories/unreviewed/2022/05/GHSA-hh76-773h-vqh2/GHSA-hh76-773h-vqh2.json @@ -7,12 +7,8 @@ "CVE-2009-3653" ], "details": "Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with \"administer site configuration\" permission, to inject arbitrary web script or HTML via unspecified vectors, related to link path output.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp4h-hxwc-hg5v/GHSA-hp4h-hxwc-hg5v.json b/advisories/unreviewed/2022/05/GHSA-hp4h-hxwc-hg5v/GHSA-hp4h-hxwc-hg5v.json index 5ab7e0263ce..f73132f0ea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp4h-hxwc-hg5v/GHSA-hp4h-hxwc-hg5v.json +++ b/advisories/unreviewed/2022/05/GHSA-hp4h-hxwc-hg5v/GHSA-hp4h-hxwc-hg5v.json @@ -7,12 +7,8 @@ "CVE-2009-3206" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated users, with \"administer imagecache\" permissions, to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpcf-9656-v2qr/GHSA-hpcf-9656-v2qr.json b/advisories/unreviewed/2022/05/GHSA-hpcf-9656-v2qr/GHSA-hpcf-9656-v2qr.json index 12528cd8d10..69fa54b212b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpcf-9656-v2qr/GHSA-hpcf-9656-v2qr.json +++ b/advisories/unreviewed/2022/05/GHSA-hpcf-9656-v2qr/GHSA-hpcf-9656-v2qr.json @@ -7,12 +7,8 @@ "CVE-2009-3201" ], "details": "Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007-4940.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq3w-qjwj-w8fp/GHSA-hq3w-qjwj-w8fp.json b/advisories/unreviewed/2022/05/GHSA-hq3w-qjwj-w8fp/GHSA-hq3w-qjwj-w8fp.json index c43f6fbbf77..b312712ee0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq3w-qjwj-w8fp/GHSA-hq3w-qjwj-w8fp.json +++ b/advisories/unreviewed/2022/05/GHSA-hq3w-qjwj-w8fp/GHSA-hq3w-qjwj-w8fp.json @@ -7,12 +7,8 @@ "CVE-2009-3371" ], "details": "Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq8v-m2gf-pmhf/GHSA-hq8v-m2gf-pmhf.json b/advisories/unreviewed/2022/05/GHSA-hq8v-m2gf-pmhf/GHSA-hq8v-m2gf-pmhf.json index 27bcfb07ec9..7ec7d77cf72 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq8v-m2gf-pmhf/GHSA-hq8v-m2gf-pmhf.json +++ b/advisories/unreviewed/2022/05/GHSA-hq8v-m2gf-pmhf/GHSA-hq8v-m2gf-pmhf.json @@ -7,12 +7,8 @@ "CVE-2009-3545" ], "details": "DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqp5-7hf2-3rq4/GHSA-hqp5-7hf2-3rq4.json b/advisories/unreviewed/2022/05/GHSA-hqp5-7hf2-3rq4/GHSA-hqp5-7hf2-3rq4.json index c1866d353f0..89a36ee7412 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqp5-7hf2-3rq4/GHSA-hqp5-7hf2-3rq4.json +++ b/advisories/unreviewed/2022/05/GHSA-hqp5-7hf2-3rq4/GHSA-hqp5-7hf2-3rq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvhw-fj22-frwp/GHSA-hvhw-fj22-frwp.json b/advisories/unreviewed/2022/05/GHSA-hvhw-fj22-frwp/GHSA-hvhw-fj22-frwp.json index 771f173723c..c755cbeae0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvhw-fj22-frwp/GHSA-hvhw-fj22-frwp.json +++ b/advisories/unreviewed/2022/05/GHSA-hvhw-fj22-frwp/GHSA-hvhw-fj22-frwp.json @@ -7,12 +7,8 @@ "CVE-2009-3328" ], "details": "Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvmf-6hr8-vcpv/GHSA-hvmf-6hr8-vcpv.json b/advisories/unreviewed/2022/05/GHSA-hvmf-6hr8-vcpv/GHSA-hvmf-6hr8-vcpv.json index df9a35b8014..9013f125dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvmf-6hr8-vcpv/GHSA-hvmf-6hr8-vcpv.json +++ b/advisories/unreviewed/2022/05/GHSA-hvmf-6hr8-vcpv/GHSA-hvmf-6hr8-vcpv.json @@ -7,12 +7,8 @@ "CVE-2009-3476" ], "details": "Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw4x-hf25-fgp2/GHSA-hw4x-hf25-fgp2.json b/advisories/unreviewed/2022/05/GHSA-hw4x-hf25-fgp2/GHSA-hw4x-hf25-fgp2.json index 2f1ef7c782b..5a170a6ae43 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw4x-hf25-fgp2/GHSA-hw4x-hf25-fgp2.json +++ b/advisories/unreviewed/2022/05/GHSA-hw4x-hf25-fgp2/GHSA-hw4x-hf25-fgp2.json @@ -7,12 +7,8 @@ "CVE-2009-3579" ], "details": "Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwrc-w5gg-f335/GHSA-hwrc-w5gg-f335.json b/advisories/unreviewed/2022/05/GHSA-hwrc-w5gg-f335/GHSA-hwrc-w5gg-f335.json index 9dcad0e4ab3..f63ffa6add2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwrc-w5gg-f335/GHSA-hwrc-w5gg-f335.json +++ b/advisories/unreviewed/2022/05/GHSA-hwrc-w5gg-f335/GHSA-hwrc-w5gg-f335.json @@ -7,12 +7,8 @@ "CVE-2009-3635" ], "details": "The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j329-567w-c6x2/GHSA-j329-567w-c6x2.json b/advisories/unreviewed/2022/05/GHSA-j329-567w-c6x2/GHSA-j329-567w-c6x2.json index 8457180f134..7ac9edd13a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j329-567w-c6x2/GHSA-j329-567w-c6x2.json +++ b/advisories/unreviewed/2022/05/GHSA-j329-567w-c6x2/GHSA-j329-567w-c6x2.json @@ -7,12 +7,8 @@ "CVE-2009-3789" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j32g-6wjv-jxxr/GHSA-j32g-6wjv-jxxr.json b/advisories/unreviewed/2022/05/GHSA-j32g-6wjv-jxxr/GHSA-j32g-6wjv-jxxr.json index 64c2d30c784..e080a7bbe12 100644 --- a/advisories/unreviewed/2022/05/GHSA-j32g-6wjv-jxxr/GHSA-j32g-6wjv-jxxr.json +++ b/advisories/unreviewed/2022/05/GHSA-j32g-6wjv-jxxr/GHSA-j32g-6wjv-jxxr.json @@ -7,12 +7,8 @@ "CVE-2009-3384" ], "details": "Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j35h-hvq7-g6h8/GHSA-j35h-hvq7-g6h8.json b/advisories/unreviewed/2022/05/GHSA-j35h-hvq7-g6h8/GHSA-j35h-hvq7-g6h8.json index 520e39072e7..e97ff6201ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-j35h-hvq7-g6h8/GHSA-j35h-hvq7-g6h8.json +++ b/advisories/unreviewed/2022/05/GHSA-j35h-hvq7-g6h8/GHSA-j35h-hvq7-g6h8.json @@ -7,12 +7,8 @@ "CVE-2009-3803" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message body of a (21) forum, (22) guestbook, or (23) comment; (24) the content of an avatar file, which is not properly handled by Internet Explorer; and (25) the loginname parameter (aka username) in _admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3wh-59pg-frxr/GHSA-j3wh-59pg-frxr.json b/advisories/unreviewed/2022/05/GHSA-j3wh-59pg-frxr/GHSA-j3wh-59pg-frxr.json index 2a5a13cdc49..8504e389127 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3wh-59pg-frxr/GHSA-j3wh-59pg-frxr.json +++ b/advisories/unreviewed/2022/05/GHSA-j3wh-59pg-frxr/GHSA-j3wh-59pg-frxr.json @@ -7,12 +7,8 @@ "CVE-2009-3354" ], "details": "Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4gj-mw2c-mqx6/GHSA-j4gj-mw2c-mqx6.json b/advisories/unreviewed/2022/05/GHSA-j4gj-mw2c-mqx6/GHSA-j4gj-mw2c-mqx6.json index 657999f0489..8883fbec8b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4gj-mw2c-mqx6/GHSA-j4gj-mw2c-mqx6.json +++ b/advisories/unreviewed/2022/05/GHSA-j4gj-mw2c-mqx6/GHSA-j4gj-mw2c-mqx6.json @@ -7,12 +7,8 @@ "CVE-2009-3104" ], "details": "Unspecified vulnerability in Symantec Norton AntiVirus 2005 through 2008; Norton Internet Security 2005 through 2008; AntiVirus Corporate Edition 9.0 before MR7, 10.0, 10.1 before MR8, and 10.2 before MR3; and Client Security 2.0 before MR7, 3.0, and 3.1 before MR8; when Internet Email Scanning is installed and enabled, allows remote attackers to cause a denial of service (CPU consumption and persistent connection loss) via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4q4-qv6g-h5fv/GHSA-j4q4-qv6g-h5fv.json b/advisories/unreviewed/2022/05/GHSA-j4q4-qv6g-h5fv/GHSA-j4q4-qv6g-h5fv.json index eb5f599c14a..ba29c5ab8e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4q4-qv6g-h5fv/GHSA-j4q4-qv6g-h5fv.json +++ b/advisories/unreviewed/2022/05/GHSA-j4q4-qv6g-h5fv/GHSA-j4q4-qv6g-h5fv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4qr-rm2m-q3vr/GHSA-j4qr-rm2m-q3vr.json b/advisories/unreviewed/2022/05/GHSA-j4qr-rm2m-q3vr/GHSA-j4qr-rm2m-q3vr.json index d084cc0a902..180fb07017b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4qr-rm2m-q3vr/GHSA-j4qr-rm2m-q3vr.json +++ b/advisories/unreviewed/2022/05/GHSA-j4qr-rm2m-q3vr/GHSA-j4qr-rm2m-q3vr.json @@ -7,12 +7,8 @@ "CVE-2009-3318" ], "details": "Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j533-79wr-cfgh/GHSA-j533-79wr-cfgh.json b/advisories/unreviewed/2022/05/GHSA-j533-79wr-cfgh/GHSA-j533-79wr-cfgh.json index bb7c56b36a0..c140434bd75 100644 --- a/advisories/unreviewed/2022/05/GHSA-j533-79wr-cfgh/GHSA-j533-79wr-cfgh.json +++ b/advisories/unreviewed/2022/05/GHSA-j533-79wr-cfgh/GHSA-j533-79wr-cfgh.json @@ -7,12 +7,8 @@ "CVE-2009-3462" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a \"format bug.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6h4-qf23-62qw/GHSA-j6h4-qf23-62qw.json b/advisories/unreviewed/2022/05/GHSA-j6h4-qf23-62qw/GHSA-j6h4-qf23-62qw.json index 7439df2eac3..17663bb8860 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6h4-qf23-62qw/GHSA-j6h4-qf23-62qw.json +++ b/advisories/unreviewed/2022/05/GHSA-j6h4-qf23-62qw/GHSA-j6h4-qf23-62qw.json @@ -7,12 +7,8 @@ "CVE-2009-3481" ], "details": "A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6mr-2j2f-gxh9/GHSA-j6mr-2j2f-gxh9.json b/advisories/unreviewed/2022/05/GHSA-j6mr-2j2f-gxh9/GHSA-j6mr-2j2f-gxh9.json index a1d6c02634c..8f04e6b1545 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6mr-2j2f-gxh9/GHSA-j6mr-2j2f-gxh9.json +++ b/advisories/unreviewed/2022/05/GHSA-j6mr-2j2f-gxh9/GHSA-j6mr-2j2f-gxh9.json @@ -7,12 +7,8 @@ "CVE-2014-4699" ], "details": "The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6qp-fmgx-hf26/GHSA-j6qp-fmgx-hf26.json b/advisories/unreviewed/2022/05/GHSA-j6qp-fmgx-hf26/GHSA-j6qp-fmgx-hf26.json index f316bf6c92f..ece06773c45 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6qp-fmgx-hf26/GHSA-j6qp-fmgx-hf26.json +++ b/advisories/unreviewed/2022/05/GHSA-j6qp-fmgx-hf26/GHSA-j6qp-fmgx-hf26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6wx-wmhj-cffc/GHSA-j6wx-wmhj-cffc.json b/advisories/unreviewed/2022/05/GHSA-j6wx-wmhj-cffc/GHSA-j6wx-wmhj-cffc.json index dc18ad03ad0..8a9ff4e6b71 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6wx-wmhj-cffc/GHSA-j6wx-wmhj-cffc.json +++ b/advisories/unreviewed/2022/05/GHSA-j6wx-wmhj-cffc/GHSA-j6wx-wmhj-cffc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j863-f9rp-wc8m/GHSA-j863-f9rp-wc8m.json b/advisories/unreviewed/2022/05/GHSA-j863-f9rp-wc8m/GHSA-j863-f9rp-wc8m.json index f03d78e1458..124e62f14d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-j863-f9rp-wc8m/GHSA-j863-f9rp-wc8m.json +++ b/advisories/unreviewed/2022/05/GHSA-j863-f9rp-wc8m/GHSA-j863-f9rp-wc8m.json @@ -7,12 +7,8 @@ "CVE-2009-3275" ], "details": "Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many \\ (backslash) characters followed by a \" (double quote), related to a certain regular expression, aka a \"ReDoS\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9f8-x89j-pw9j/GHSA-j9f8-x89j-pw9j.json b/advisories/unreviewed/2022/05/GHSA-j9f8-x89j-pw9j/GHSA-j9f8-x89j-pw9j.json index 3be9b568658..5e125dafe65 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9f8-x89j-pw9j/GHSA-j9f8-x89j-pw9j.json +++ b/advisories/unreviewed/2022/05/GHSA-j9f8-x89j-pw9j/GHSA-j9f8-x89j-pw9j.json @@ -7,12 +7,8 @@ "CVE-2007-6677" ], "details": "Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9ww-5pqv-frw4/GHSA-j9ww-5pqv-frw4.json b/advisories/unreviewed/2022/05/GHSA-j9ww-5pqv-frw4/GHSA-j9ww-5pqv-frw4.json index 9501236898f..e19cbf3ca8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9ww-5pqv-frw4/GHSA-j9ww-5pqv-frw4.json +++ b/advisories/unreviewed/2022/05/GHSA-j9ww-5pqv-frw4/GHSA-j9ww-5pqv-frw4.json @@ -7,12 +7,8 @@ "CVE-2009-3595" ], "details": "SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter, a different vector than CVE-2009-3590.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc9g-5ggm-9q3r/GHSA-jc9g-5ggm-9q3r.json b/advisories/unreviewed/2022/05/GHSA-jc9g-5ggm-9q3r/GHSA-jc9g-5ggm-9q3r.json index 7d6bd5b5229..eef212f1181 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc9g-5ggm-9q3r/GHSA-jc9g-5ggm-9q3r.json +++ b/advisories/unreviewed/2022/05/GHSA-jc9g-5ggm-9q3r/GHSA-jc9g-5ggm-9q3r.json @@ -7,12 +7,8 @@ "CVE-2009-3699" ], "details": "Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc9j-c739-vr4w/GHSA-jc9j-c739-vr4w.json b/advisories/unreviewed/2022/05/GHSA-jc9j-c739-vr4w/GHSA-jc9j-c739-vr4w.json index 08d31dfc0c7..c317971ff2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc9j-c739-vr4w/GHSA-jc9j-c739-vr4w.json +++ b/advisories/unreviewed/2022/05/GHSA-jc9j-c739-vr4w/GHSA-jc9j-c739-vr4w.json @@ -7,12 +7,8 @@ "CVE-2009-3572" ], "details": "OpenBSD 4.4, 4.5, and 4.6, when running on an i386 kernel, does not properly handle XMM exceptions, which allows local users to cause a denial of service (kernel panic) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcj3-vgfw-m9gq/GHSA-jcj3-vgfw-m9gq.json b/advisories/unreviewed/2022/05/GHSA-jcj3-vgfw-m9gq/GHSA-jcj3-vgfw-m9gq.json index 6d71482cb54..d203ccf2058 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcj3-vgfw-m9gq/GHSA-jcj3-vgfw-m9gq.json +++ b/advisories/unreviewed/2022/05/GHSA-jcj3-vgfw-m9gq/GHSA-jcj3-vgfw-m9gq.json @@ -7,12 +7,8 @@ "CVE-2009-3441" ], "details": "Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2) host/draw_tree.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgv9-qp9j-c2cr/GHSA-jgv9-qp9j-c2cr.json b/advisories/unreviewed/2022/05/GHSA-jgv9-qp9j-c2cr/GHSA-jgv9-qp9j-c2cr.json index 0c7bf1eae6c..97a7bc16862 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgv9-qp9j-c2cr/GHSA-jgv9-qp9j-c2cr.json +++ b/advisories/unreviewed/2022/05/GHSA-jgv9-qp9j-c2cr/GHSA-jgv9-qp9j-c2cr.json @@ -7,12 +7,8 @@ "CVE-2009-3710" ], "details": "RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj42-mvx7-fq6m/GHSA-jj42-mvx7-fq6m.json b/advisories/unreviewed/2022/05/GHSA-jj42-mvx7-fq6m/GHSA-jj42-mvx7-fq6m.json index b27dca9ebd1..490dbf01333 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj42-mvx7-fq6m/GHSA-jj42-mvx7-fq6m.json +++ b/advisories/unreviewed/2022/05/GHSA-jj42-mvx7-fq6m/GHSA-jj42-mvx7-fq6m.json @@ -7,12 +7,8 @@ "CVE-2009-3316" ], "details": "SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjm3-8pvp-p9w4/GHSA-jjm3-8pvp-p9w4.json b/advisories/unreviewed/2022/05/GHSA-jjm3-8pvp-p9w4/GHSA-jjm3-8pvp-p9w4.json index e05a08a92d3..6f4abd79802 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjm3-8pvp-p9w4/GHSA-jjm3-8pvp-p9w4.json +++ b/advisories/unreviewed/2022/05/GHSA-jjm3-8pvp-p9w4/GHSA-jjm3-8pvp-p9w4.json @@ -7,12 +7,8 @@ "CVE-2009-3778" ], "details": "SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp8c-xxwg-85wj/GHSA-jp8c-xxwg-85wj.json b/advisories/unreviewed/2022/05/GHSA-jp8c-xxwg-85wj/GHSA-jp8c-xxwg-85wj.json index ea618485375..265710ed40d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp8c-xxwg-85wj/GHSA-jp8c-xxwg-85wj.json +++ b/advisories/unreviewed/2022/05/GHSA-jp8c-xxwg-85wj/GHSA-jp8c-xxwg-85wj.json @@ -7,12 +7,8 @@ "CVE-2009-3323" ], "details": "Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path parameter to (2) lib_users.php, (3) lib_stats.php, and (4) lib_slots.php in include/lib/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp8r-43r2-mgmg/GHSA-jp8r-43r2-mgmg.json b/advisories/unreviewed/2022/05/GHSA-jp8r-43r2-mgmg/GHSA-jp8r-43r2-mgmg.json index 3b83d4c0f67..639b3311365 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp8r-43r2-mgmg/GHSA-jp8r-43r2-mgmg.json +++ b/advisories/unreviewed/2022/05/GHSA-jp8r-43r2-mgmg/GHSA-jp8r-43r2-mgmg.json @@ -7,12 +7,8 @@ "CVE-2009-3484" ], "details": "Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq5g-93fw-pqwp/GHSA-jq5g-93fw-pqwp.json b/advisories/unreviewed/2022/05/GHSA-jq5g-93fw-pqwp/GHSA-jq5g-93fw-pqwp.json index 597153a7208..0181e598d33 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq5g-93fw-pqwp/GHSA-jq5g-93fw-pqwp.json +++ b/advisories/unreviewed/2022/05/GHSA-jq5g-93fw-pqwp/GHSA-jq5g-93fw-pqwp.json @@ -7,12 +7,8 @@ "CVE-2009-3519" ], "details": "Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq75-2m55-f6cv/GHSA-jq75-2m55-f6cv.json b/advisories/unreviewed/2022/05/GHSA-jq75-2m55-f6cv/GHSA-jq75-2m55-f6cv.json index 0d6e5cf1aa7..64f8051d56e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq75-2m55-f6cv/GHSA-jq75-2m55-f6cv.json +++ b/advisories/unreviewed/2022/05/GHSA-jq75-2m55-f6cv/GHSA-jq75-2m55-f6cv.json @@ -7,12 +7,8 @@ "CVE-2009-3479" ], "details": "Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows remote attackers, with \"create content displayed by the Bibliography module\" permissions, to inject arbitrary web script or HTML via a title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq7h-9pm6-x65q/GHSA-jq7h-9pm6-x65q.json b/advisories/unreviewed/2022/05/GHSA-jq7h-9pm6-x65q/GHSA-jq7h-9pm6-x65q.json index 631fd7de271..d499ffa07b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq7h-9pm6-x65q/GHSA-jq7h-9pm6-x65q.json +++ b/advisories/unreviewed/2022/05/GHSA-jq7h-9pm6-x65q/GHSA-jq7h-9pm6-x65q.json @@ -7,12 +7,8 @@ "CVE-2009-3380" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jq84-chq4-ww9x/GHSA-jq84-chq4-ww9x.json b/advisories/unreviewed/2022/05/GHSA-jq84-chq4-ww9x/GHSA-jq84-chq4-ww9x.json index 441aee50cba..3483addddd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq84-chq4-ww9x/GHSA-jq84-chq4-ww9x.json +++ b/advisories/unreviewed/2022/05/GHSA-jq84-chq4-ww9x/GHSA-jq84-chq4-ww9x.json @@ -7,12 +7,8 @@ "CVE-2009-3288" ], "details": "The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstrated by using xcdroast to duplicate a CD. NOTE: this is only exploitable by users who can open the cdrom device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqgm-6w4j-7734/GHSA-jqgm-6w4j-7734.json b/advisories/unreviewed/2022/05/GHSA-jqgm-6w4j-7734/GHSA-jqgm-6w4j-7734.json index f659376f31f..8561c284479 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqgm-6w4j-7734/GHSA-jqgm-6w4j-7734.json +++ b/advisories/unreviewed/2022/05/GHSA-jqgm-6w4j-7734/GHSA-jqgm-6w4j-7734.json @@ -7,12 +7,8 @@ "CVE-2009-3648" ], "details": "Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m267-v543-w956/GHSA-m267-v543-w956.json b/advisories/unreviewed/2022/05/GHSA-m267-v543-w956/GHSA-m267-v543-w956.json index 3b1e5c6d4e6..8e92f5fbc7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m267-v543-w956/GHSA-m267-v543-w956.json +++ b/advisories/unreviewed/2022/05/GHSA-m267-v543-w956/GHSA-m267-v543-w956.json @@ -7,12 +7,8 @@ "CVE-2009-3406" ], "details": "Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.98.2.1 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3g3-2r98-q7m9/GHSA-m3g3-2r98-q7m9.json b/advisories/unreviewed/2022/05/GHSA-m3g3-2r98-q7m9/GHSA-m3g3-2r98-q7m9.json index 12f84f6f410..a89ca537dee 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3g3-2r98-q7m9/GHSA-m3g3-2r98-q7m9.json +++ b/advisories/unreviewed/2022/05/GHSA-m3g3-2r98-q7m9/GHSA-m3g3-2r98-q7m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3p7-jqjp-g7pp/GHSA-m3p7-jqjp-g7pp.json b/advisories/unreviewed/2022/05/GHSA-m3p7-jqjp-g7pp/GHSA-m3p7-jqjp-g7pp.json index 3457cf5e150..cd7c9cef02d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3p7-jqjp-g7pp/GHSA-m3p7-jqjp-g7pp.json +++ b/advisories/unreviewed/2022/05/GHSA-m3p7-jqjp-g7pp/GHSA-m3p7-jqjp-g7pp.json @@ -7,12 +7,8 @@ "CVE-2009-3194" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3rg-cpqq-v3gm/GHSA-m3rg-cpqq-v3gm.json b/advisories/unreviewed/2022/05/GHSA-m3rg-cpqq-v3gm/GHSA-m3rg-cpqq-v3gm.json index de7e98211f3..ed6514ed404 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3rg-cpqq-v3gm/GHSA-m3rg-cpqq-v3gm.json +++ b/advisories/unreviewed/2022/05/GHSA-m3rg-cpqq-v3gm/GHSA-m3rg-cpqq-v3gm.json @@ -7,12 +7,8 @@ "CVE-2009-3440" ], "details": "Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4g6-59fc-77gp/GHSA-m4g6-59fc-77gp.json b/advisories/unreviewed/2022/05/GHSA-m4g6-59fc-77gp/GHSA-m4g6-59fc-77gp.json index b96830892b2..5871cf8d118 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4g6-59fc-77gp/GHSA-m4g6-59fc-77gp.json +++ b/advisories/unreviewed/2022/05/GHSA-m4g6-59fc-77gp/GHSA-m4g6-59fc-77gp.json @@ -7,12 +7,8 @@ "CVE-2009-3748" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and (6) MessagePart parameters to web/msgList/viewmsg/actions/msgAnalyse.asp; the (7) Queue, (8) FileName, (9) IsolatedMessageID, and (10) ServerName parameters to actions/msgForwardToRiskFilter.asp and viewHeaders.asp in web/msgList/viewmsg/; and (11) the subject in an e-mail message that is held in a Queue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4j7-w5vj-fwff/GHSA-m4j7-w5vj-fwff.json b/advisories/unreviewed/2022/05/GHSA-m4j7-w5vj-fwff/GHSA-m4j7-w5vj-fwff.json index 9a2c26672d4..833b3e0db3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4j7-w5vj-fwff/GHSA-m4j7-w5vj-fwff.json +++ b/advisories/unreviewed/2022/05/GHSA-m4j7-w5vj-fwff/GHSA-m4j7-w5vj-fwff.json @@ -7,12 +7,8 @@ "CVE-2009-3622" ], "details": "Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated \"UTF-8\" substrings, related to the mb_convert_encoding function in PHP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m57q-6hfr-75q7/GHSA-m57q-6hfr-75q7.json b/advisories/unreviewed/2022/05/GHSA-m57q-6hfr-75q7/GHSA-m57q-6hfr-75q7.json index f4028be7bc3..42cc4b7627f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m57q-6hfr-75q7/GHSA-m57q-6hfr-75q7.json +++ b/advisories/unreviewed/2022/05/GHSA-m57q-6hfr-75q7/GHSA-m57q-6hfr-75q7.json @@ -7,12 +7,8 @@ "CVE-2009-3666" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog 0.1.2 allows remote attackers to inject arbitrary web script or HTML via the e parameter in an error action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m587-5g57-rrrf/GHSA-m587-5g57-rrrf.json b/advisories/unreviewed/2022/05/GHSA-m587-5g57-rrrf/GHSA-m587-5g57-rrrf.json index 00564ae66d0..f092135fc61 100644 --- a/advisories/unreviewed/2022/05/GHSA-m587-5g57-rrrf/GHSA-m587-5g57-rrrf.json +++ b/advisories/unreviewed/2022/05/GHSA-m587-5g57-rrrf/GHSA-m587-5g57-rrrf.json @@ -7,12 +7,8 @@ "CVE-2009-3412" ], "details": "Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5; and Oracle Application Server 10.1.2.3; allows local users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5f4-ppqh-p8pq/GHSA-m5f4-ppqh-p8pq.json b/advisories/unreviewed/2022/05/GHSA-m5f4-ppqh-p8pq/GHSA-m5f4-ppqh-p8pq.json index 7bd8a91ab63..c1ca81db6c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5f4-ppqh-p8pq/GHSA-m5f4-ppqh-p8pq.json +++ b/advisories/unreviewed/2022/05/GHSA-m5f4-ppqh-p8pq/GHSA-m5f4-ppqh-p8pq.json @@ -7,12 +7,8 @@ "CVE-2009-3099" ], "details": "Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a \"Remote exploit,\" as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2007-3872. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5q8-rhfq-gjv4/GHSA-m5q8-rhfq-gjv4.json b/advisories/unreviewed/2022/05/GHSA-m5q8-rhfq-gjv4/GHSA-m5q8-rhfq-gjv4.json index 226d5e4820d..e865b280bf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5q8-rhfq-gjv4/GHSA-m5q8-rhfq-gjv4.json +++ b/advisories/unreviewed/2022/05/GHSA-m5q8-rhfq-gjv4/GHSA-m5q8-rhfq-gjv4.json @@ -7,12 +7,8 @@ "CVE-2009-3735" ], "details": "The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m68p-v7vm-cp2m/GHSA-m68p-v7vm-cp2m.json b/advisories/unreviewed/2022/05/GHSA-m68p-v7vm-cp2m/GHSA-m68p-v7vm-cp2m.json index 97788a1a5bc..fda53544ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m68p-v7vm-cp2m/GHSA-m68p-v7vm-cp2m.json +++ b/advisories/unreviewed/2022/05/GHSA-m68p-v7vm-cp2m/GHSA-m68p-v7vm-cp2m.json @@ -7,12 +7,8 @@ "CVE-2009-3295" ], "details": "The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m69v-4j9p-4g78/GHSA-m69v-4j9p-4g78.json b/advisories/unreviewed/2022/05/GHSA-m69v-4j9p-4g78/GHSA-m69v-4j9p-4g78.json index ea3660dbf0e..3ef9f023f0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m69v-4j9p-4g78/GHSA-m69v-4j9p-4g78.json +++ b/advisories/unreviewed/2022/05/GHSA-m69v-4j9p-4g78/GHSA-m69v-4j9p-4g78.json @@ -7,12 +7,8 @@ "CVE-2009-3480" ], "details": "SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p3 parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6wm-vrh8-3v8h/GHSA-m6wm-vrh8-3v8h.json b/advisories/unreviewed/2022/05/GHSA-m6wm-vrh8-3v8h/GHSA-m6wm-vrh8-3v8h.json index a97c22ea949..f1a2e0dfa4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6wm-vrh8-3v8h/GHSA-m6wm-vrh8-3v8h.json +++ b/advisories/unreviewed/2022/05/GHSA-m6wm-vrh8-3v8h/GHSA-m6wm-vrh8-3v8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7c3-gvjv-4h47/GHSA-m7c3-gvjv-4h47.json b/advisories/unreviewed/2022/05/GHSA-m7c3-gvjv-4h47/GHSA-m7c3-gvjv-4h47.json index d46f3c7cea9..063266b02e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7c3-gvjv-4h47/GHSA-m7c3-gvjv-4h47.json +++ b/advisories/unreviewed/2022/05/GHSA-m7c3-gvjv-4h47/GHSA-m7c3-gvjv-4h47.json @@ -7,12 +7,8 @@ "CVE-2009-3286" ], "details": "NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9x4-cr95-4r8p/GHSA-m9x4-cr95-4r8p.json b/advisories/unreviewed/2022/05/GHSA-m9x4-cr95-4r8p/GHSA-m9x4-cr95-4r8p.json index 6e75702f44e..4e42b754e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9x4-cr95-4r8p/GHSA-m9x4-cr95-4r8p.json +++ b/advisories/unreviewed/2022/05/GHSA-m9x4-cr95-4r8p/GHSA-m9x4-cr95-4r8p.json @@ -7,12 +7,8 @@ "CVE-2009-3370" ], "details": "Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9x6-7vfc-3xx6/GHSA-m9x6-7vfc-3xx6.json b/advisories/unreviewed/2022/05/GHSA-m9x6-7vfc-3xx6/GHSA-m9x6-7vfc-3xx6.json index 0d7fe005c30..8c2f53707be 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9x6-7vfc-3xx6/GHSA-m9x6-7vfc-3xx6.json +++ b/advisories/unreviewed/2022/05/GHSA-m9x6-7vfc-3xx6/GHSA-m9x6-7vfc-3xx6.json @@ -7,12 +7,8 @@ "CVE-2009-3659" ], "details": "SQL injection vulnerability in file/stats.php in BS Counter 2.5.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcgw-mh98-rxj2/GHSA-mcgw-mh98-rxj2.json b/advisories/unreviewed/2022/05/GHSA-mcgw-mh98-rxj2/GHSA-mcgw-mh98-rxj2.json index 92a34c02340..7fe0008d077 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcgw-mh98-rxj2/GHSA-mcgw-mh98-rxj2.json +++ b/advisories/unreviewed/2022/05/GHSA-mcgw-mh98-rxj2/GHSA-mcgw-mh98-rxj2.json @@ -7,12 +7,8 @@ "CVE-2009-3747" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter. NOTE: this was originally reported for tbmnet.php, but that program does not exist in the TBmnetCMS 1.0 distribution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfmx-3jxx-p7cq/GHSA-mfmx-3jxx-p7cq.json b/advisories/unreviewed/2022/05/GHSA-mfmx-3jxx-p7cq/GHSA-mfmx-3jxx-p7cq.json index 0a11dd5dce4..a7cd945ffa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfmx-3jxx-p7cq/GHSA-mfmx-3jxx-p7cq.json +++ b/advisories/unreviewed/2022/05/GHSA-mfmx-3jxx-p7cq/GHSA-mfmx-3jxx-p7cq.json @@ -7,12 +7,8 @@ "CVE-2009-3580" ], "details": "Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users for requests that change a password via the login, new_password, and confirm_password parameters in a preferences action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfxv-c9xh-c4qp/GHSA-mfxv-c9xh-c4qp.json b/advisories/unreviewed/2022/05/GHSA-mfxv-c9xh-c4qp/GHSA-mfxv-c9xh-c4qp.json index b73e88fb763..02d071a026c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfxv-c9xh-c4qp/GHSA-mfxv-c9xh-c4qp.json +++ b/advisories/unreviewed/2022/05/GHSA-mfxv-c9xh-c4qp/GHSA-mfxv-c9xh-c4qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg93-8qx5-rwmv/GHSA-mg93-8qx5-rwmv.json b/advisories/unreviewed/2022/05/GHSA-mg93-8qx5-rwmv/GHSA-mg93-8qx5-rwmv.json index 5a208c4f248..26cb8aa96f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg93-8qx5-rwmv/GHSA-mg93-8qx5-rwmv.json +++ b/advisories/unreviewed/2022/05/GHSA-mg93-8qx5-rwmv/GHSA-mg93-8qx5-rwmv.json @@ -7,12 +7,8 @@ "CVE-2009-3209" ], "details": "SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjxv-j6j2-hpmv/GHSA-mjxv-j6j2-hpmv.json b/advisories/unreviewed/2022/05/GHSA-mjxv-j6j2-hpmv/GHSA-mjxv-j6j2-hpmv.json index 0356bbf3ca8..614ea54f2e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjxv-j6j2-hpmv/GHSA-mjxv-j6j2-hpmv.json +++ b/advisories/unreviewed/2022/05/GHSA-mjxv-j6j2-hpmv/GHSA-mjxv-j6j2-hpmv.json @@ -7,12 +7,8 @@ "CVE-2009-3558" ], "details": "The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm3r-85wp-99j8/GHSA-mm3r-85wp-99j8.json b/advisories/unreviewed/2022/05/GHSA-mm3r-85wp-99j8/GHSA-mm3r-85wp-99j8.json index ede41628382..73910b27fa8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm3r-85wp-99j8/GHSA-mm3r-85wp-99j8.json +++ b/advisories/unreviewed/2022/05/GHSA-mm3r-85wp-99j8/GHSA-mm3r-85wp-99j8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmqq-hhjg-3252/GHSA-mmqq-hhjg-3252.json b/advisories/unreviewed/2022/05/GHSA-mmqq-hhjg-3252/GHSA-mmqq-hhjg-3252.json index 5cbbc985561..fd02d918315 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmqq-hhjg-3252/GHSA-mmqq-hhjg-3252.json +++ b/advisories/unreviewed/2022/05/GHSA-mmqq-hhjg-3252/GHSA-mmqq-hhjg-3252.json @@ -7,12 +7,8 @@ "CVE-2009-3752" ], "details": "SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mphw-3jw4-55gq/GHSA-mphw-3jw4-55gq.json b/advisories/unreviewed/2022/05/GHSA-mphw-3jw4-55gq/GHSA-mphw-3jw4-55gq.json index 8b9d2029031..422b23da27b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mphw-3jw4-55gq/GHSA-mphw-3jw4-55gq.json +++ b/advisories/unreviewed/2022/05/GHSA-mphw-3jw4-55gq/GHSA-mphw-3jw4-55gq.json @@ -7,12 +7,8 @@ "CVE-2009-3404" ], "details": "Unspecified vulnerability in the PeopleSoft PeopleTools & Enterprise Portal component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.23 allows remote authenticated users to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpjr-rv63-f738/GHSA-mpjr-rv63-f738.json b/advisories/unreviewed/2022/05/GHSA-mpjr-rv63-f738/GHSA-mpjr-rv63-f738.json index f3586aa7fd0..c33d976a378 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpjr-rv63-f738/GHSA-mpjr-rv63-f738.json +++ b/advisories/unreviewed/2022/05/GHSA-mpjr-rv63-f738/GHSA-mpjr-rv63-f738.json @@ -7,12 +7,8 @@ "CVE-2009-3731" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mppx-c427-qv84/GHSA-mppx-c427-qv84.json b/advisories/unreviewed/2022/05/GHSA-mppx-c427-qv84/GHSA-mppx-c427-qv84.json index 0adb33f5050..77436e03def 100644 --- a/advisories/unreviewed/2022/05/GHSA-mppx-c427-qv84/GHSA-mppx-c427-qv84.json +++ b/advisories/unreviewed/2022/05/GHSA-mppx-c427-qv84/GHSA-mppx-c427-qv84.json @@ -7,12 +7,8 @@ "CVE-2009-3419" ], "details": "SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvhx-xp5x-9v28/GHSA-mvhx-xp5x-9v28.json b/advisories/unreviewed/2022/05/GHSA-mvhx-xp5x-9v28/GHSA-mvhx-xp5x-9v28.json index ae9eeb7db80..b04ecc413e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvhx-xp5x-9v28/GHSA-mvhx-xp5x-9v28.json +++ b/advisories/unreviewed/2022/05/GHSA-mvhx-xp5x-9v28/GHSA-mvhx-xp5x-9v28.json @@ -7,12 +7,8 @@ "CVE-2009-3544" ], "details": "Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvxf-hjhv-qqhv/GHSA-mvxf-hjhv-qqhv.json b/advisories/unreviewed/2022/05/GHSA-mvxf-hjhv-qqhv/GHSA-mvxf-hjhv-qqhv.json index f53e5bf6537..807b9ffff30 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvxf-hjhv-qqhv/GHSA-mvxf-hjhv-qqhv.json +++ b/advisories/unreviewed/2022/05/GHSA-mvxf-hjhv-qqhv/GHSA-mvxf-hjhv-qqhv.json @@ -7,12 +7,8 @@ "CVE-2009-3310" ], "details": "SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw96-29xv-5ppf/GHSA-mw96-29xv-5ppf.json b/advisories/unreviewed/2022/05/GHSA-mw96-29xv-5ppf/GHSA-mw96-29xv-5ppf.json index 36fecbad9ee..e867e489a01 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw96-29xv-5ppf/GHSA-mw96-29xv-5ppf.json +++ b/advisories/unreviewed/2022/05/GHSA-mw96-29xv-5ppf/GHSA-mw96-29xv-5ppf.json @@ -7,12 +7,8 @@ "CVE-2009-3732" ], "details": "Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mxjg-fcq7-wmwq/GHSA-mxjg-fcq7-wmwq.json b/advisories/unreviewed/2022/05/GHSA-mxjg-fcq7-wmwq/GHSA-mxjg-fcq7-wmwq.json index 46846cd35ea..62a3578b795 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxjg-fcq7-wmwq/GHSA-mxjg-fcq7-wmwq.json +++ b/advisories/unreviewed/2022/05/GHSA-mxjg-fcq7-wmwq/GHSA-mxjg-fcq7-wmwq.json @@ -7,12 +7,8 @@ "CVE-2009-3458" ], "details": "Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p29x-jjv6-hfrh/GHSA-p29x-jjv6-hfrh.json b/advisories/unreviewed/2022/05/GHSA-p29x-jjv6-hfrh/GHSA-p29x-jjv6-hfrh.json index 42c21ff6775..7b745bac0c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p29x-jjv6-hfrh/GHSA-p29x-jjv6-hfrh.json +++ b/advisories/unreviewed/2022/05/GHSA-p29x-jjv6-hfrh/GHSA-p29x-jjv6-hfrh.json @@ -7,12 +7,8 @@ "CVE-2009-3357" ], "details": "Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2fr-jrwq-q4c4/GHSA-p2fr-jrwq-q4c4.json b/advisories/unreviewed/2022/05/GHSA-p2fr-jrwq-q4c4/GHSA-p2fr-jrwq-q4c4.json index da975564da3..8fb2b3d8ddc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2fr-jrwq-q4c4/GHSA-p2fr-jrwq-q4c4.json +++ b/advisories/unreviewed/2022/05/GHSA-p2fr-jrwq-q4c4/GHSA-p2fr-jrwq-q4c4.json @@ -7,12 +7,8 @@ "CVE-2009-3363" ], "details": "Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the \"plain textarea editor.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2jj-p9xc-7g6j/GHSA-p2jj-p9xc-7g6j.json b/advisories/unreviewed/2022/05/GHSA-p2jj-p9xc-7g6j/GHSA-p2jj-p9xc-7g6j.json index 609e6198c7a..a6ee4145ea6 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2jj-p9xc-7g6j/GHSA-p2jj-p9xc-7g6j.json +++ b/advisories/unreviewed/2022/05/GHSA-p2jj-p9xc-7g6j/GHSA-p2jj-p9xc-7g6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p46q-pmw2-55mw/GHSA-p46q-pmw2-55mw.json b/advisories/unreviewed/2022/05/GHSA-p46q-pmw2-55mw/GHSA-p46q-pmw2-55mw.json index 321ad9149e3..e262453c26b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p46q-pmw2-55mw/GHSA-p46q-pmw2-55mw.json +++ b/advisories/unreviewed/2022/05/GHSA-p46q-pmw2-55mw/GHSA-p46q-pmw2-55mw.json @@ -7,12 +7,8 @@ "CVE-2009-3554" ], "details": "Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p548-q955-gcwg/GHSA-p548-q955-gcwg.json b/advisories/unreviewed/2022/05/GHSA-p548-q955-gcwg/GHSA-p548-q955-gcwg.json index e0574e0c418..de975584d33 100644 --- a/advisories/unreviewed/2022/05/GHSA-p548-q955-gcwg/GHSA-p548-q955-gcwg.json +++ b/advisories/unreviewed/2022/05/GHSA-p548-q955-gcwg/GHSA-p548-q955-gcwg.json @@ -7,12 +7,8 @@ "CVE-2009-3114" ], "details": "The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5fj-j53f-3gwv/GHSA-p5fj-j53f-3gwv.json b/advisories/unreviewed/2022/05/GHSA-p5fj-j53f-3gwv/GHSA-p5fj-j53f-3gwv.json index 4f57b2e471c..d1e7ce5df7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5fj-j53f-3gwv/GHSA-p5fj-j53f-3gwv.json +++ b/advisories/unreviewed/2022/05/GHSA-p5fj-j53f-3gwv/GHSA-p5fj-j53f-3gwv.json @@ -7,12 +7,8 @@ "CVE-2009-3450" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p99q-5p87-w6pr/GHSA-p99q-5p87-w6pr.json b/advisories/unreviewed/2022/05/GHSA-p99q-5p87-w6pr/GHSA-p99q-5p87-w6pr.json index 666143d5087..b964ffb6d0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p99q-5p87-w6pr/GHSA-p99q-5p87-w6pr.json +++ b/advisories/unreviewed/2022/05/GHSA-p99q-5p87-w6pr/GHSA-p99q-5p87-w6pr.json @@ -7,12 +7,8 @@ "CVE-2009-3524" ], "details": "Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pcw5-cxvf-xpqx/GHSA-pcw5-cxvf-xpqx.json b/advisories/unreviewed/2022/05/GHSA-pcw5-cxvf-xpqx/GHSA-pcw5-cxvf-xpqx.json index 0af60ec4f69..527d11b9371 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcw5-cxvf-xpqx/GHSA-pcw5-cxvf-xpqx.json +++ b/advisories/unreviewed/2022/05/GHSA-pcw5-cxvf-xpqx/GHSA-pcw5-cxvf-xpqx.json @@ -7,12 +7,8 @@ "CVE-2009-3786" ], "details": "Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf8f-326c-hmr7/GHSA-pf8f-326c-hmr7.json b/advisories/unreviewed/2022/05/GHSA-pf8f-326c-hmr7/GHSA-pf8f-326c-hmr7.json index df9ae28a1e1..c05eaba07fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf8f-326c-hmr7/GHSA-pf8f-326c-hmr7.json +++ b/advisories/unreviewed/2022/05/GHSA-pf8f-326c-hmr7/GHSA-pf8f-326c-hmr7.json @@ -7,12 +7,8 @@ "CVE-2009-3718" ], "details": "SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfqq-qpv2-v6q9/GHSA-pfqq-qpv2-v6q9.json b/advisories/unreviewed/2022/05/GHSA-pfqq-qpv2-v6q9/GHSA-pfqq-qpv2-v6q9.json index 5bdfce0a204..af5338e17eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfqq-qpv2-v6q9/GHSA-pfqq-qpv2-v6q9.json +++ b/advisories/unreviewed/2022/05/GHSA-pfqq-qpv2-v6q9/GHSA-pfqq-qpv2-v6q9.json @@ -7,12 +7,8 @@ "CVE-2009-3790" ], "details": "Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg4r-46vf-5wr2/GHSA-pg4r-46vf-5wr2.json b/advisories/unreviewed/2022/05/GHSA-pg4r-46vf-5wr2/GHSA-pg4r-46vf-5wr2.json index 3219a6aedad..f9d613f4c89 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg4r-46vf-5wr2/GHSA-pg4r-46vf-5wr2.json +++ b/advisories/unreviewed/2022/05/GHSA-pg4r-46vf-5wr2/GHSA-pg4r-46vf-5wr2.json @@ -7,12 +7,8 @@ "CVE-2009-3700" ], "details": "Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to \"emergency mode.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgr8-g488-4xf7/GHSA-pgr8-g488-4xf7.json b/advisories/unreviewed/2022/05/GHSA-pgr8-g488-4xf7/GHSA-pgr8-g488-4xf7.json index 20fdcf53e63..3abe1c4297a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgr8-g488-4xf7/GHSA-pgr8-g488-4xf7.json +++ b/advisories/unreviewed/2022/05/GHSA-pgr8-g488-4xf7/GHSA-pgr8-g488-4xf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgvx-9xhm-x4w5/GHSA-pgvx-9xhm-x4w5.json b/advisories/unreviewed/2022/05/GHSA-pgvx-9xhm-x4w5/GHSA-pgvx-9xhm-x4w5.json index 29ea9bca3ab..66b3ab966f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgvx-9xhm-x4w5/GHSA-pgvx-9xhm-x4w5.json +++ b/advisories/unreviewed/2022/05/GHSA-pgvx-9xhm-x4w5/GHSA-pgvx-9xhm-x4w5.json @@ -7,12 +7,8 @@ "CVE-2009-3426" ], "details": "PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code via a URL in the fm_includes_special parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph72-5jfg-vmr3/GHSA-ph72-5jfg-vmr3.json b/advisories/unreviewed/2022/05/GHSA-ph72-5jfg-vmr3/GHSA-ph72-5jfg-vmr3.json index fc6215f346f..72429195acf 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph72-5jfg-vmr3/GHSA-ph72-5jfg-vmr3.json +++ b/advisories/unreviewed/2022/05/GHSA-ph72-5jfg-vmr3/GHSA-ph72-5jfg-vmr3.json @@ -7,12 +7,8 @@ "CVE-2009-3334" ], "details": "SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj4x-5742-w9p8/GHSA-pj4x-5742-w9p8.json b/advisories/unreviewed/2022/05/GHSA-pj4x-5742-w9p8/GHSA-pj4x-5742-w9p8.json index 53e3f416e0a..578074b5582 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj4x-5742-w9p8/GHSA-pj4x-5742-w9p8.json +++ b/advisories/unreviewed/2022/05/GHSA-pj4x-5742-w9p8/GHSA-pj4x-5742-w9p8.json @@ -7,12 +7,8 @@ "CVE-2009-3396" ], "details": "Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2.3, 10.0.1, and 10.3 allows remote attackers to affect integrity, related to WLS Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj82-fpwx-65j3/GHSA-pj82-fpwx-65j3.json b/advisories/unreviewed/2022/05/GHSA-pj82-fpwx-65j3/GHSA-pj82-fpwx-65j3.json index e4192447f03..b11c64fc572 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj82-fpwx-65j3/GHSA-pj82-fpwx-65j3.json +++ b/advisories/unreviewed/2022/05/GHSA-pj82-fpwx-65j3/GHSA-pj82-fpwx-65j3.json @@ -7,12 +7,8 @@ "CVE-2009-3291" ], "details": "The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmgg-w4jv-72xw/GHSA-pmgg-w4jv-72xw.json b/advisories/unreviewed/2022/05/GHSA-pmgg-w4jv-72xw/GHSA-pmgg-w4jv-72xw.json index ae4d120da50..743c5c46e05 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmgg-w4jv-72xw/GHSA-pmgg-w4jv-72xw.json +++ b/advisories/unreviewed/2022/05/GHSA-pmgg-w4jv-72xw/GHSA-pmgg-w4jv-72xw.json @@ -7,12 +7,8 @@ "CVE-2009-3420" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr23-m3vh-wq7x/GHSA-pr23-m3vh-wq7x.json b/advisories/unreviewed/2022/05/GHSA-pr23-m3vh-wq7x/GHSA-pr23-m3vh-wq7x.json index 8e33a2ad806..45221440029 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr23-m3vh-wq7x/GHSA-pr23-m3vh-wq7x.json +++ b/advisories/unreviewed/2022/05/GHSA-pr23-m3vh-wq7x/GHSA-pr23-m3vh-wq7x.json @@ -7,12 +7,8 @@ "CVE-2009-3306" ], "details": "PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr3m-646v-qvfc/GHSA-pr3m-646v-qvfc.json b/advisories/unreviewed/2022/05/GHSA-pr3m-646v-qvfc/GHSA-pr3m-646v-qvfc.json index 83ef7d08f99..33aabe90337 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr3m-646v-qvfc/GHSA-pr3m-646v-qvfc.json +++ b/advisories/unreviewed/2022/05/GHSA-pr3m-646v-qvfc/GHSA-pr3m-646v-qvfc.json @@ -7,12 +7,8 @@ "CVE-2009-3626" ], "details": "Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prcv-xr7q-82jv/GHSA-prcv-xr7q-82jv.json b/advisories/unreviewed/2022/05/GHSA-prcv-xr7q-82jv/GHSA-prcv-xr7q-82jv.json index 437d87e9c42..d7b03ead735 100644 --- a/advisories/unreviewed/2022/05/GHSA-prcv-xr7q-82jv/GHSA-prcv-xr7q-82jv.json +++ b/advisories/unreviewed/2022/05/GHSA-prcv-xr7q-82jv/GHSA-prcv-xr7q-82jv.json @@ -7,12 +7,8 @@ "CVE-2009-3217" ], "details": "SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prxp-8xr8-7qv2/GHSA-prxp-8xr8-7qv2.json b/advisories/unreviewed/2022/05/GHSA-prxp-8xr8-7qv2/GHSA-prxp-8xr8-7qv2.json index d1f9cd29955..056a6232350 100644 --- a/advisories/unreviewed/2022/05/GHSA-prxp-8xr8-7qv2/GHSA-prxp-8xr8-7qv2.json +++ b/advisories/unreviewed/2022/05/GHSA-prxp-8xr8-7qv2/GHSA-prxp-8xr8-7qv2.json @@ -7,12 +7,8 @@ "CVE-2009-3449" ], "details": "MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvmh-7h9v-f5xr/GHSA-pvmh-7h9v-f5xr.json b/advisories/unreviewed/2022/05/GHSA-pvmh-7h9v-f5xr/GHSA-pvmh-7h9v-f5xr.json index 3d5cca03a9f..f4712749f5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvmh-7h9v-f5xr/GHSA-pvmh-7h9v-f5xr.json +++ b/advisories/unreviewed/2022/05/GHSA-pvmh-7h9v-f5xr/GHSA-pvmh-7h9v-f5xr.json @@ -7,12 +7,8 @@ "CVE-2009-3282" ], "details": "Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvrv-v6wr-f2vv/GHSA-pvrv-v6wr-f2vv.json b/advisories/unreviewed/2022/05/GHSA-pvrv-v6wr-f2vv/GHSA-pvrv-v6wr-f2vv.json index 59e20564b6d..350ac74a2cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvrv-v6wr-f2vv/GHSA-pvrv-v6wr-f2vv.json +++ b/advisories/unreviewed/2022/05/GHSA-pvrv-v6wr-f2vv/GHSA-pvrv-v6wr-f2vv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvvp-vj5f-7cc6/GHSA-pvvp-vj5f-7cc6.json b/advisories/unreviewed/2022/05/GHSA-pvvp-vj5f-7cc6/GHSA-pvvp-vj5f-7cc6.json index d58377c2fa5..3beb10f24b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvvp-vj5f-7cc6/GHSA-pvvp-vj5f-7cc6.json +++ b/advisories/unreviewed/2022/05/GHSA-pvvp-vj5f-7cc6/GHSA-pvvp-vj5f-7cc6.json @@ -7,12 +7,8 @@ "CVE-2009-3292" ], "details": "Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to \"missing sanity checks around exif processing.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxpf-f7wc-5qvm/GHSA-pxpf-f7wc-5qvm.json b/advisories/unreviewed/2022/05/GHSA-pxpf-f7wc-5qvm/GHSA-pxpf-f7wc-5qvm.json index 4a805860136..270ea80bce8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxpf-f7wc-5qvm/GHSA-pxpf-f7wc-5qvm.json +++ b/advisories/unreviewed/2022/05/GHSA-pxpf-f7wc-5qvm/GHSA-pxpf-f7wc-5qvm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxx3-gfm4-5cpx/GHSA-pxx3-gfm4-5cpx.json b/advisories/unreviewed/2022/05/GHSA-pxx3-gfm4-5cpx/GHSA-pxx3-gfm4-5cpx.json index a7c6620c828..c83f3135a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxx3-gfm4-5cpx/GHSA-pxx3-gfm4-5cpx.json +++ b/advisories/unreviewed/2022/05/GHSA-pxx3-gfm4-5cpx/GHSA-pxx3-gfm4-5cpx.json @@ -7,12 +7,8 @@ "CVE-2009-3649" ], "details": "Cross-site scripting (XSS) vulnerability in forums/index.php in Power Bulletin Board (PBBoard) 2.0.2 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a new_topic action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q26p-2pjc-36qx/GHSA-q26p-2pjc-36qx.json b/advisories/unreviewed/2022/05/GHSA-q26p-2pjc-36qx/GHSA-q26p-2pjc-36qx.json index c25918cf8f7..6c707c8a339 100644 --- a/advisories/unreviewed/2022/05/GHSA-q26p-2pjc-36qx/GHSA-q26p-2pjc-36qx.json +++ b/advisories/unreviewed/2022/05/GHSA-q26p-2pjc-36qx/GHSA-q26p-2pjc-36qx.json @@ -7,12 +7,8 @@ "CVE-2009-3319" ], "details": "SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sec list action, a different vector than CVE-2006-1018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2fp-fcx5-hff3/GHSA-q2fp-fcx5-hff3.json b/advisories/unreviewed/2022/05/GHSA-q2fp-fcx5-hff3/GHSA-q2fp-fcx5-hff3.json index 1e4f2789bf9..8f0b922b715 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2fp-fcx5-hff3/GHSA-q2fp-fcx5-hff3.json +++ b/advisories/unreviewed/2022/05/GHSA-q2fp-fcx5-hff3/GHSA-q2fp-fcx5-hff3.json @@ -7,12 +7,8 @@ "CVE-2009-3111" ], "details": "The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3jv-68wf-2323/GHSA-q3jv-68wf-2323.json b/advisories/unreviewed/2022/05/GHSA-q3jv-68wf-2323/GHSA-q3jv-68wf-2323.json index 7afee3bec2d..63b3a85cb0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3jv-68wf-2323/GHSA-q3jv-68wf-2323.json +++ b/advisories/unreviewed/2022/05/GHSA-q3jv-68wf-2323/GHSA-q3jv-68wf-2323.json @@ -7,12 +7,8 @@ "CVE-2009-3321" ], "details": "SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4fm-44gw-552r/GHSA-q4fm-44gw-552r.json b/advisories/unreviewed/2022/05/GHSA-q4fm-44gw-552r/GHSA-q4fm-44gw-552r.json index f11a59a4c52..03883dc148b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4fm-44gw-552r/GHSA-q4fm-44gw-552r.json +++ b/advisories/unreviewed/2022/05/GHSA-q4fm-44gw-552r/GHSA-q4fm-44gw-552r.json @@ -7,12 +7,8 @@ "CVE-2009-3123" ], "details": "Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4vm-f4m8-3m9q/GHSA-q4vm-f4m8-3m9q.json b/advisories/unreviewed/2022/05/GHSA-q4vm-f4m8-3m9q/GHSA-q4vm-f4m8-3m9q.json index dd86a3724c4..0c77c36db46 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4vm-f4m8-3m9q/GHSA-q4vm-f4m8-3m9q.json +++ b/advisories/unreviewed/2022/05/GHSA-q4vm-f4m8-3m9q/GHSA-q4vm-f4m8-3m9q.json @@ -7,12 +7,8 @@ "CVE-2009-3561" ], "details": "Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4x6-q4p5-f5jw/GHSA-q4x6-q4p5-f5jw.json b/advisories/unreviewed/2022/05/GHSA-q4x6-q4p5-f5jw/GHSA-q4x6-q4p5-f5jw.json index f46f64e90e2..fb2be84037f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4x6-q4p5-f5jw/GHSA-q4x6-q4p5-f5jw.json +++ b/advisories/unreviewed/2022/05/GHSA-q4x6-q4p5-f5jw/GHSA-q4x6-q4p5-f5jw.json @@ -7,12 +7,8 @@ "CVE-2009-3806" ], "details": "SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q52p-3m33-w676/GHSA-q52p-3m33-w676.json b/advisories/unreviewed/2022/05/GHSA-q52p-3m33-w676/GHSA-q52p-3m33-w676.json index 237727e56a8..e6151659506 100644 --- a/advisories/unreviewed/2022/05/GHSA-q52p-3m33-w676/GHSA-q52p-3m33-w676.json +++ b/advisories/unreviewed/2022/05/GHSA-q52p-3m33-w676/GHSA-q52p-3m33-w676.json @@ -7,12 +7,8 @@ "CVE-2009-3459" ], "details": "Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q56w-5m9j-r836/GHSA-q56w-5m9j-r836.json b/advisories/unreviewed/2022/05/GHSA-q56w-5m9j-r836/GHSA-q56w-5m9j-r836.json index 5045fdf8499..94339c028ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-q56w-5m9j-r836/GHSA-q56w-5m9j-r836.json +++ b/advisories/unreviewed/2022/05/GHSA-q56w-5m9j-r836/GHSA-q56w-5m9j-r836.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q64c-hf5x-986j/GHSA-q64c-hf5x-986j.json b/advisories/unreviewed/2022/05/GHSA-q64c-hf5x-986j/GHSA-q64c-hf5x-986j.json index f6d14dc0653..6f85867f9a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q64c-hf5x-986j/GHSA-q64c-hf5x-986j.json +++ b/advisories/unreviewed/2022/05/GHSA-q64c-hf5x-986j/GHSA-q64c-hf5x-986j.json @@ -7,12 +7,8 @@ "CVE-2009-3587" ], "details": "Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q64r-wvx9-6g34/GHSA-q64r-wvx9-6g34.json b/advisories/unreviewed/2022/05/GHSA-q64r-wvx9-6g34/GHSA-q64r-wvx9-6g34.json index 6ca0b90e1fc..e18ce6065d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q64r-wvx9-6g34/GHSA-q64r-wvx9-6g34.json +++ b/advisories/unreviewed/2022/05/GHSA-q64r-wvx9-6g34/GHSA-q64r-wvx9-6g34.json @@ -7,12 +7,8 @@ "CVE-2009-3618" ], "details": "Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the view parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q792-q593-g5f3/GHSA-q792-q593-g5f3.json b/advisories/unreviewed/2022/05/GHSA-q792-q593-g5f3/GHSA-q792-q593-g5f3.json index 28c62f3b531..9f1dcb69940 100644 --- a/advisories/unreviewed/2022/05/GHSA-q792-q593-g5f3/GHSA-q792-q593-g5f3.json +++ b/advisories/unreviewed/2022/05/GHSA-q792-q593-g5f3/GHSA-q792-q593-g5f3.json @@ -7,12 +7,8 @@ "CVE-2009-3223" ], "details": "SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7c9-wj3v-qrj7/GHSA-q7c9-wj3v-qrj7.json b/advisories/unreviewed/2022/05/GHSA-q7c9-wj3v-qrj7/GHSA-q7c9-wj3v-qrj7.json index c8c8e51dd3c..7f2f5ca8a6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7c9-wj3v-qrj7/GHSA-q7c9-wj3v-qrj7.json +++ b/advisories/unreviewed/2022/05/GHSA-q7c9-wj3v-qrj7/GHSA-q7c9-wj3v-qrj7.json @@ -7,12 +7,8 @@ "CVE-2009-3358" ], "details": "SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to execute arbitrary SQL commands via the user_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7xv-685x-6h27/GHSA-q7xv-685x-6h27.json b/advisories/unreviewed/2022/05/GHSA-q7xv-685x-6h27/GHSA-q7xv-685x-6h27.json index e334570f543..40b2b0636df 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7xv-685x-6h27/GHSA-q7xv-685x-6h27.json +++ b/advisories/unreviewed/2022/05/GHSA-q7xv-685x-6h27/GHSA-q7xv-685x-6h27.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q85c-chj5-jqwc/GHSA-q85c-chj5-jqwc.json b/advisories/unreviewed/2022/05/GHSA-q85c-chj5-jqwc/GHSA-q85c-chj5-jqwc.json index d2d347dcde5..aa3c4250f01 100644 --- a/advisories/unreviewed/2022/05/GHSA-q85c-chj5-jqwc/GHSA-q85c-chj5-jqwc.json +++ b/advisories/unreviewed/2022/05/GHSA-q85c-chj5-jqwc/GHSA-q85c-chj5-jqwc.json @@ -7,12 +7,8 @@ "CVE-2009-3347" ], "details": "Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q92w-3cc7-2r4g/GHSA-q92w-3cc7-2r4g.json b/advisories/unreviewed/2022/05/GHSA-q92w-3cc7-2r4g/GHSA-q92w-3cc7-2r4g.json index 5f27de96cc2..8e0b71e6497 100644 --- a/advisories/unreviewed/2022/05/GHSA-q92w-3cc7-2r4g/GHSA-q92w-3cc7-2r4g.json +++ b/advisories/unreviewed/2022/05/GHSA-q92w-3cc7-2r4g/GHSA-q92w-3cc7-2r4g.json @@ -7,12 +7,8 @@ "CVE-2009-3393" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qf6w-75pv-5q59/GHSA-qf6w-75pv-5q59.json b/advisories/unreviewed/2022/05/GHSA-qf6w-75pv-5q59/GHSA-qf6w-75pv-5q59.json index 67195ad86ed..e30756ae0c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf6w-75pv-5q59/GHSA-qf6w-75pv-5q59.json +++ b/advisories/unreviewed/2022/05/GHSA-qf6w-75pv-5q59/GHSA-qf6w-75pv-5q59.json @@ -7,12 +7,8 @@ "CVE-2009-3443" ], "details": "SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qghh-4hvq-fj66/GHSA-qghh-4hvq-fj66.json b/advisories/unreviewed/2022/05/GHSA-qghh-4hvq-fj66/GHSA-qghh-4hvq-fj66.json index 3db3597b5de..a02f6f2237b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qghh-4hvq-fj66/GHSA-qghh-4hvq-fj66.json +++ b/advisories/unreviewed/2022/05/GHSA-qghh-4hvq-fj66/GHSA-qghh-4hvq-fj66.json @@ -7,12 +7,8 @@ "CVE-2009-3729" ], "details": "Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash) via a certain test suite, aka Bug Id 6815780.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qhg6-w2fh-6xfg/GHSA-qhg6-w2fh-6xfg.json b/advisories/unreviewed/2022/05/GHSA-qhg6-w2fh-6xfg/GHSA-qhg6-w2fh-6xfg.json index 34ac84dc061..b3e4ce02c91 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhg6-w2fh-6xfg/GHSA-qhg6-w2fh-6xfg.json +++ b/advisories/unreviewed/2022/05/GHSA-qhg6-w2fh-6xfg/GHSA-qhg6-w2fh-6xfg.json @@ -7,12 +7,8 @@ "CVE-2009-3785" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhv5-5rhr-mqc5/GHSA-qhv5-5rhr-mqc5.json b/advisories/unreviewed/2022/05/GHSA-qhv5-5rhr-mqc5/GHSA-qhv5-5rhr-mqc5.json index 05c202c4e72..45ba0696be1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhv5-5rhr-mqc5/GHSA-qhv5-5rhr-mqc5.json +++ b/advisories/unreviewed/2022/05/GHSA-qhv5-5rhr-mqc5/GHSA-qhv5-5rhr-mqc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj49-mwf8-445r/GHSA-qj49-mwf8-445r.json b/advisories/unreviewed/2022/05/GHSA-qj49-mwf8-445r/GHSA-qj49-mwf8-445r.json index a3f567b3175..fbe063a4d95 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj49-mwf8-445r/GHSA-qj49-mwf8-445r.json +++ b/advisories/unreviewed/2022/05/GHSA-qj49-mwf8-445r/GHSA-qj49-mwf8-445r.json @@ -7,12 +7,8 @@ "CVE-2009-3360" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj63-c77f-88gh/GHSA-qj63-c77f-88gh.json b/advisories/unreviewed/2022/05/GHSA-qj63-c77f-88gh/GHSA-qj63-c77f-88gh.json index 6a50c62007a..7469b5d8cf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj63-c77f-88gh/GHSA-qj63-c77f-88gh.json +++ b/advisories/unreviewed/2022/05/GHSA-qj63-c77f-88gh/GHSA-qj63-c77f-88gh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmjr-fgvm-qpvq/GHSA-qmjr-fgvm-qpvq.json b/advisories/unreviewed/2022/05/GHSA-qmjr-fgvm-qpvq/GHSA-qmjr-fgvm-qpvq.json index 8879b26b495..a8782932799 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmjr-fgvm-qpvq/GHSA-qmjr-fgvm-qpvq.json +++ b/advisories/unreviewed/2022/05/GHSA-qmjr-fgvm-qpvq/GHSA-qmjr-fgvm-qpvq.json @@ -7,12 +7,8 @@ "CVE-2009-3571" ], "details": "Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka \"Client-side exploit.\" NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmm6-9733-43x2/GHSA-qmm6-9733-43x2.json b/advisories/unreviewed/2022/05/GHSA-qmm6-9733-43x2/GHSA-qmm6-9733-43x2.json index 90e09e234d7..4f4686ae166 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmm6-9733-43x2/GHSA-qmm6-9733-43x2.json +++ b/advisories/unreviewed/2022/05/GHSA-qmm6-9733-43x2/GHSA-qmm6-9733-43x2.json @@ -7,12 +7,8 @@ "CVE-2009-3506" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmw2-mxpf-x4wp/GHSA-qmw2-mxpf-x4wp.json b/advisories/unreviewed/2022/05/GHSA-qmw2-mxpf-x4wp/GHSA-qmw2-mxpf-x4wp.json index 6ecfe058136..0803c4654c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmw2-mxpf-x4wp/GHSA-qmw2-mxpf-x4wp.json +++ b/advisories/unreviewed/2022/05/GHSA-qmw2-mxpf-x4wp/GHSA-qmw2-mxpf-x4wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp5r-g6cm-fm8x/GHSA-qp5r-g6cm-fm8x.json b/advisories/unreviewed/2022/05/GHSA-qp5r-g6cm-fm8x/GHSA-qp5r-g6cm-fm8x.json index 4621aa2fabc..11373eba55c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp5r-g6cm-fm8x/GHSA-qp5r-g6cm-fm8x.json +++ b/advisories/unreviewed/2022/05/GHSA-qp5r-g6cm-fm8x/GHSA-qp5r-g6cm-fm8x.json @@ -7,12 +7,8 @@ "CVE-2009-3200" ], "details": "The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qq2h-777w-7rg7/GHSA-qq2h-777w-7rg7.json b/advisories/unreviewed/2022/05/GHSA-qq2h-777w-7rg7/GHSA-qq2h-777w-7rg7.json index a0d94eff88b..990d46a6d48 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq2h-777w-7rg7/GHSA-qq2h-777w-7rg7.json +++ b/advisories/unreviewed/2022/05/GHSA-qq2h-777w-7rg7/GHSA-qq2h-777w-7rg7.json @@ -7,12 +7,8 @@ "CVE-2009-3134" ], "details": "Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka \"Excel Field Sanitization Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv4m-mw37-hvg2/GHSA-qv4m-mw37-hvg2.json b/advisories/unreviewed/2022/05/GHSA-qv4m-mw37-hvg2/GHSA-qv4m-mw37-hvg2.json index 2cb6ceec2bf..aefce91cf41 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv4m-mw37-hvg2/GHSA-qv4m-mw37-hvg2.json +++ b/advisories/unreviewed/2022/05/GHSA-qv4m-mw37-hvg2/GHSA-qv4m-mw37-hvg2.json @@ -7,12 +7,8 @@ "CVE-2009-3706" ], "details": "Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv_100 through snv_117, allows local users to bypass intended limitations of the file_chown_self privilege via certain uses of the chown system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qv88-c9vm-fw8p/GHSA-qv88-c9vm-fw8p.json b/advisories/unreviewed/2022/05/GHSA-qv88-c9vm-fw8p/GHSA-qv88-c9vm-fw8p.json index 39e485dd5a6..4f17d2d6942 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv88-c9vm-fw8p/GHSA-qv88-c9vm-fw8p.json +++ b/advisories/unreviewed/2022/05/GHSA-qv88-c9vm-fw8p/GHSA-qv88-c9vm-fw8p.json @@ -7,12 +7,8 @@ "CVE-2009-3576" ], "details": "Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwh8-647p-vcqr/GHSA-qwh8-647p-vcqr.json b/advisories/unreviewed/2022/05/GHSA-qwh8-647p-vcqr/GHSA-qwh8-647p-vcqr.json index dca1dabaeb8..c61c286f41d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwh8-647p-vcqr/GHSA-qwh8-647p-vcqr.json +++ b/advisories/unreviewed/2022/05/GHSA-qwh8-647p-vcqr/GHSA-qwh8-647p-vcqr.json @@ -7,12 +7,8 @@ "CVE-2009-3784" ], "details": "Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwm4-r696-wpp8/GHSA-qwm4-r696-wpp8.json b/advisories/unreviewed/2022/05/GHSA-qwm4-r696-wpp8/GHSA-qwm4-r696-wpp8.json index 58fc70701c6..5b0745ca80e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwm4-r696-wpp8/GHSA-qwm4-r696-wpp8.json +++ b/advisories/unreviewed/2022/05/GHSA-qwm4-r696-wpp8/GHSA-qwm4-r696-wpp8.json @@ -7,12 +7,8 @@ "CVE-2009-3585" ], "details": "Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages a second web server within the same domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwwm-9hv9-2pvh/GHSA-qwwm-9hv9-2pvh.json b/advisories/unreviewed/2022/05/GHSA-qwwm-9hv9-2pvh/GHSA-qwwm-9hv9-2pvh.json index cc24987396f..37cea2c29aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwwm-9hv9-2pvh/GHSA-qwwm-9hv9-2pvh.json +++ b/advisories/unreviewed/2022/05/GHSA-qwwm-9hv9-2pvh/GHSA-qwwm-9hv9-2pvh.json @@ -7,12 +7,8 @@ "CVE-2009-3598" ], "details": "Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qx79-r9pg-rjj7/GHSA-qx79-r9pg-rjj7.json b/advisories/unreviewed/2022/05/GHSA-qx79-r9pg-rjj7/GHSA-qx79-r9pg-rjj7.json index 733e3a43d6b..9a452c68529 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx79-r9pg-rjj7/GHSA-qx79-r9pg-rjj7.json +++ b/advisories/unreviewed/2022/05/GHSA-qx79-r9pg-rjj7/GHSA-qx79-r9pg-rjj7.json @@ -7,12 +7,8 @@ "CVE-2009-3416" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxpm-m6jm-3crx/GHSA-qxpm-m6jm-3crx.json b/advisories/unreviewed/2022/05/GHSA-qxpm-m6jm-3crx/GHSA-qxpm-m6jm-3crx.json index 11b97982e51..2a05a591123 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxpm-m6jm-3crx/GHSA-qxpm-m6jm-3crx.json +++ b/advisories/unreviewed/2022/05/GHSA-qxpm-m6jm-3crx/GHSA-qxpm-m6jm-3crx.json @@ -7,12 +7,8 @@ "CVE-2009-3566" ], "details": "McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxvj-qxhq-9v8w/GHSA-qxvj-qxhq-9v8w.json b/advisories/unreviewed/2022/05/GHSA-qxvj-qxhq-9v8w/GHSA-qxvj-qxhq-9v8w.json index c77f2a8e245..b38330510cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxvj-qxhq-9v8w/GHSA-qxvj-qxhq-9v8w.json +++ b/advisories/unreviewed/2022/05/GHSA-qxvj-qxhq-9v8w/GHSA-qxvj-qxhq-9v8w.json @@ -7,12 +7,8 @@ "CVE-2009-3438" ], "details": "SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r367-2c67-wh49/GHSA-r367-2c67-wh49.json b/advisories/unreviewed/2022/05/GHSA-r367-2c67-wh49/GHSA-r367-2c67-wh49.json index 706e43c199b..d3488221e55 100644 --- a/advisories/unreviewed/2022/05/GHSA-r367-2c67-wh49/GHSA-r367-2c67-wh49.json +++ b/advisories/unreviewed/2022/05/GHSA-r367-2c67-wh49/GHSA-r367-2c67-wh49.json @@ -7,12 +7,8 @@ "CVE-2009-3494" ], "details": "Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a delete_category action, (2) the name parameter in an update_category action, and other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r389-f2jh-h9wp/GHSA-r389-f2jh-h9wp.json b/advisories/unreviewed/2022/05/GHSA-r389-f2jh-h9wp/GHSA-r389-f2jh-h9wp.json index 4526fcc0e25..03179e5d03e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r389-f2jh-h9wp/GHSA-r389-f2jh-h9wp.json +++ b/advisories/unreviewed/2022/05/GHSA-r389-f2jh-h9wp/GHSA-r389-f2jh-h9wp.json @@ -7,12 +7,8 @@ "CVE-2009-3317" ], "details": "PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4x3-gx46-8jpq/GHSA-r4x3-gx46-8jpq.json b/advisories/unreviewed/2022/05/GHSA-r4x3-gx46-8jpq/GHSA-r4x3-gx46-8jpq.json index fe90c784e63..62dcf275e50 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4x3-gx46-8jpq/GHSA-r4x3-gx46-8jpq.json +++ b/advisories/unreviewed/2022/05/GHSA-r4x3-gx46-8jpq/GHSA-r4x3-gx46-8jpq.json @@ -7,12 +7,8 @@ "CVE-2009-3594" ], "details": "Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog System before 1.2 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4xr-x22c-68gg/GHSA-r4xr-x22c-68gg.json b/advisories/unreviewed/2022/05/GHSA-r4xr-x22c-68gg/GHSA-r4xr-x22c-68gg.json index 3580154fb47..e0ac87b3fa8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4xr-x22c-68gg/GHSA-r4xr-x22c-68gg.json +++ b/advisories/unreviewed/2022/05/GHSA-r4xr-x22c-68gg/GHSA-r4xr-x22c-68gg.json @@ -7,12 +7,8 @@ "CVE-2009-3456" ], "details": "Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r549-2q8f-3qqw/GHSA-r549-2q8f-3qqw.json b/advisories/unreviewed/2022/05/GHSA-r549-2q8f-3qqw/GHSA-r549-2q8f-3qqw.json index 80ea46924d4..3cfd7b31366 100644 --- a/advisories/unreviewed/2022/05/GHSA-r549-2q8f-3qqw/GHSA-r549-2q8f-3qqw.json +++ b/advisories/unreviewed/2022/05/GHSA-r549-2q8f-3qqw/GHSA-r549-2q8f-3qqw.json @@ -7,12 +7,8 @@ "CVE-2009-3210" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x before 6.x-1.8, a module for Drupal, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5gf-w27r-jjqq/GHSA-r5gf-w27r-jjqq.json b/advisories/unreviewed/2022/05/GHSA-r5gf-w27r-jjqq/GHSA-r5gf-w27r-jjqq.json index 31b5ea3e9ee..7c8003eaec9 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5gf-w27r-jjqq/GHSA-r5gf-w27r-jjqq.json +++ b/advisories/unreviewed/2022/05/GHSA-r5gf-w27r-jjqq/GHSA-r5gf-w27r-jjqq.json @@ -7,12 +7,8 @@ "CVE-2009-3365" ], "details": "PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the AURORA_MODULES_FOLDER parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r64c-q5mp-r47f/GHSA-r64c-q5mp-r47f.json b/advisories/unreviewed/2022/05/GHSA-r64c-q5mp-r47f/GHSA-r64c-q5mp-r47f.json index e4698f489bf..b024f2725f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r64c-q5mp-r47f/GHSA-r64c-q5mp-r47f.json +++ b/advisories/unreviewed/2022/05/GHSA-r64c-q5mp-r47f/GHSA-r64c-q5mp-r47f.json @@ -7,12 +7,8 @@ "CVE-2009-3279" ], "details": "The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6hj-55cr-38hq/GHSA-r6hj-55cr-38hq.json b/advisories/unreviewed/2022/05/GHSA-r6hj-55cr-38hq/GHSA-r6hj-55cr-38hq.json index 49ce06d5c56..8ff5a3b05a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6hj-55cr-38hq/GHSA-r6hj-55cr-38hq.json +++ b/advisories/unreviewed/2022/05/GHSA-r6hj-55cr-38hq/GHSA-r6hj-55cr-38hq.json @@ -7,12 +7,8 @@ "CVE-2009-3693" ], "details": "Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \\.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6ww-vw3x-xp48/GHSA-r6ww-vw3x-xp48.json b/advisories/unreviewed/2022/05/GHSA-r6ww-vw3x-xp48/GHSA-r6ww-vw3x-xp48.json index b336e307b82..a5ee45b8432 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6ww-vw3x-xp48/GHSA-r6ww-vw3x-xp48.json +++ b/advisories/unreviewed/2022/05/GHSA-r6ww-vw3x-xp48/GHSA-r6ww-vw3x-xp48.json @@ -7,12 +7,8 @@ "CVE-2009-3274" ], "details": "Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r79x-qr5q-j845/GHSA-r79x-qr5q-j845.json b/advisories/unreviewed/2022/05/GHSA-r79x-qr5q-j845/GHSA-r79x-qr5q-j845.json index 5ffc7d4a8c8..c64b31de3a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r79x-qr5q-j845/GHSA-r79x-qr5q-j845.json +++ b/advisories/unreviewed/2022/05/GHSA-r79x-qr5q-j845/GHSA-r79x-qr5q-j845.json @@ -7,12 +7,8 @@ "CVE-2009-3364" ], "details": "Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7jg-rv4q-6j69/GHSA-r7jg-rv4q-6j69.json b/advisories/unreviewed/2022/05/GHSA-r7jg-rv4q-6j69/GHSA-r7jg-rv4q-6j69.json index 6791672eb63..4d0ec5151f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7jg-rv4q-6j69/GHSA-r7jg-rv4q-6j69.json +++ b/advisories/unreviewed/2022/05/GHSA-r7jg-rv4q-6j69/GHSA-r7jg-rv4q-6j69.json @@ -7,12 +7,8 @@ "CVE-2009-3496" ], "details": "Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to inject arbitrary web script or HTML via the mag_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r84h-43q6-4fgm/GHSA-r84h-43q6-4fgm.json b/advisories/unreviewed/2022/05/GHSA-r84h-43q6-4fgm/GHSA-r84h-43q6-4fgm.json index 76e4b957f83..8590a161247 100644 --- a/advisories/unreviewed/2022/05/GHSA-r84h-43q6-4fgm/GHSA-r84h-43q6-4fgm.json +++ b/advisories/unreviewed/2022/05/GHSA-r84h-43q6-4fgm/GHSA-r84h-43q6-4fgm.json @@ -7,12 +7,8 @@ "CVE-2009-3569" ], "details": "Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka \"Client-side stack overflow exploit.\" NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8hf-cmf8-86j7/GHSA-r8hf-cmf8-86j7.json b/advisories/unreviewed/2022/05/GHSA-r8hf-cmf8-86j7/GHSA-r8hf-cmf8-86j7.json index 9f402165570..d7c1b189605 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8hf-cmf8-86j7/GHSA-r8hf-cmf8-86j7.json +++ b/advisories/unreviewed/2022/05/GHSA-r8hf-cmf8-86j7/GHSA-r8hf-cmf8-86j7.json @@ -7,12 +7,8 @@ "CVE-2009-3703" ], "details": "Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the search_max parameter in a search action to the default URI, related to wpf.class.php; (2) the forum parameter to an unspecified component, related to wpf.class.php; (3) the topic parameter in a viewforum action to the default URI, related to the remove_topic function in wpf.class.php; or the id parameter in a (4) editpost or (5) viewtopic action to the default URI, related to wpf-post.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r983-27x9-gfq4/GHSA-r983-27x9-gfq4.json b/advisories/unreviewed/2022/05/GHSA-r983-27x9-gfq4/GHSA-r983-27x9-gfq4.json index 4ae55ba6b09..b756c6b7073 100644 --- a/advisories/unreviewed/2022/05/GHSA-r983-27x9-gfq4/GHSA-r983-27x9-gfq4.json +++ b/advisories/unreviewed/2022/05/GHSA-r983-27x9-gfq4/GHSA-r983-27x9-gfq4.json @@ -7,12 +7,8 @@ "CVE-2009-3627" ], "details": "The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9p4-2pvr-hr3h/GHSA-r9p4-2pvr-hr3h.json b/advisories/unreviewed/2022/05/GHSA-r9p4-2pvr-hr3h/GHSA-r9p4-2pvr-hr3h.json index aaa2c6037d6..c25b7dc209c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9p4-2pvr-hr3h/GHSA-r9p4-2pvr-hr3h.json +++ b/advisories/unreviewed/2022/05/GHSA-r9p4-2pvr-hr3h/GHSA-r9p4-2pvr-hr3h.json @@ -7,12 +7,8 @@ "CVE-2009-3429" ], "details": "Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json b/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json index cda1d20ca49..1ea182c8b7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json +++ b/advisories/unreviewed/2022/05/GHSA-rf35-pm73-38q6/GHSA-rf35-pm73-38q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgc3-jjp2-xqh3/GHSA-rgc3-jjp2-xqh3.json b/advisories/unreviewed/2022/05/GHSA-rgc3-jjp2-xqh3/GHSA-rgc3-jjp2-xqh3.json index 64fad8cde68..228c08e8374 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgc3-jjp2-xqh3/GHSA-rgc3-jjp2-xqh3.json +++ b/advisories/unreviewed/2022/05/GHSA-rgc3-jjp2-xqh3/GHSA-rgc3-jjp2-xqh3.json @@ -7,12 +7,8 @@ "CVE-2009-3500" ], "details": "Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh98-7gwj-78xf/GHSA-rh98-7gwj-78xf.json b/advisories/unreviewed/2022/05/GHSA-rh98-7gwj-78xf/GHSA-rh98-7gwj-78xf.json index 35a5c60b56a..5209715c770 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh98-7gwj-78xf/GHSA-rh98-7gwj-78xf.json +++ b/advisories/unreviewed/2022/05/GHSA-rh98-7gwj-78xf/GHSA-rh98-7gwj-78xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmqp-6xmv-vxjx/GHSA-rmqp-6xmv-vxjx.json b/advisories/unreviewed/2022/05/GHSA-rmqp-6xmv-vxjx/GHSA-rmqp-6xmv-vxjx.json index f629f75b319..309a8c67fd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmqp-6xmv-vxjx/GHSA-rmqp-6xmv-vxjx.json +++ b/advisories/unreviewed/2022/05/GHSA-rmqp-6xmv-vxjx/GHSA-rmqp-6xmv-vxjx.json @@ -7,12 +7,8 @@ "CVE-2009-3591" ], "details": "Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rp39-cm7q-xq66/GHSA-rp39-cm7q-xq66.json b/advisories/unreviewed/2022/05/GHSA-rp39-cm7q-xq66/GHSA-rp39-cm7q-xq66.json index e818e49eff1..bc0d0ae996c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp39-cm7q-xq66/GHSA-rp39-cm7q-xq66.json +++ b/advisories/unreviewed/2022/05/GHSA-rp39-cm7q-xq66/GHSA-rp39-cm7q-xq66.json @@ -7,12 +7,8 @@ "CVE-2009-3715" ], "details": "Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpw9-pxq9-mqx6/GHSA-rpw9-pxq9-mqx6.json b/advisories/unreviewed/2022/05/GHSA-rpw9-pxq9-mqx6/GHSA-rpw9-pxq9-mqx6.json index 3f93a817484..dd6be3497d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpw9-pxq9-mqx6/GHSA-rpw9-pxq9-mqx6.json +++ b/advisories/unreviewed/2022/05/GHSA-rpw9-pxq9-mqx6/GHSA-rpw9-pxq9-mqx6.json @@ -7,12 +7,8 @@ "CVE-2009-3121" ], "details": "Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq78-g3q7-3xqv/GHSA-rq78-g3q7-3xqv.json b/advisories/unreviewed/2022/05/GHSA-rq78-g3q7-3xqv/GHSA-rq78-g3q7-3xqv.json index 8e5b6d38211..ed96087f46c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq78-g3q7-3xqv/GHSA-rq78-g3q7-3xqv.json +++ b/advisories/unreviewed/2022/05/GHSA-rq78-g3q7-3xqv/GHSA-rq78-g3q7-3xqv.json @@ -7,12 +7,8 @@ "CVE-2009-3091" ], "details": "Unspecified vulnerability on the ASUS WL-330gE has unknown impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqrm-6x63-2h8x/GHSA-rqrm-6x63-2h8x.json b/advisories/unreviewed/2022/05/GHSA-rqrm-6x63-2h8x/GHSA-rqrm-6x63-2h8x.json index 28203912ecb..b4e73dc4dbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqrm-6x63-2h8x/GHSA-rqrm-6x63-2h8x.json +++ b/advisories/unreviewed/2022/05/GHSA-rqrm-6x63-2h8x/GHSA-rqrm-6x63-2h8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rr4h-jj83-5hcw/GHSA-rr4h-jj83-5hcw.json b/advisories/unreviewed/2022/05/GHSA-rr4h-jj83-5hcw/GHSA-rr4h-jj83-5hcw.json index 9cc58d4b100..1b07af39a66 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr4h-jj83-5hcw/GHSA-rr4h-jj83-5hcw.json +++ b/advisories/unreviewed/2022/05/GHSA-rr4h-jj83-5hcw/GHSA-rr4h-jj83-5hcw.json @@ -7,12 +7,8 @@ "CVE-2009-3534" ], "details": "Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvcc-mqg5-gqq5/GHSA-rvcc-mqg5-gqq5.json b/advisories/unreviewed/2022/05/GHSA-rvcc-mqg5-gqq5/GHSA-rvcc-mqg5-gqq5.json index 2e2f65bb111..0442ea32aee 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvcc-mqg5-gqq5/GHSA-rvcc-mqg5-gqq5.json +++ b/advisories/unreviewed/2022/05/GHSA-rvcc-mqg5-gqq5/GHSA-rvcc-mqg5-gqq5.json @@ -7,12 +7,8 @@ "CVE-2009-3437" ], "details": "Cross-site scripting (XSS) vulnerability in the live preview feature in the Markdown Preview module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via \"Markdown input.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvww-62fw-gjm8/GHSA-rvww-62fw-gjm8.json b/advisories/unreviewed/2022/05/GHSA-rvww-62fw-gjm8/GHSA-rvww-62fw-gjm8.json index fe1de119616..872599b872d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvww-62fw-gjm8/GHSA-rvww-62fw-gjm8.json +++ b/advisories/unreviewed/2022/05/GHSA-rvww-62fw-gjm8/GHSA-rvww-62fw-gjm8.json @@ -7,12 +7,8 @@ "CVE-2009-3442" ], "details": "The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rw9x-33p6-vp3q/GHSA-rw9x-33p6-vp3q.json b/advisories/unreviewed/2022/05/GHSA-rw9x-33p6-vp3q/GHSA-rw9x-33p6-vp3q.json index 974763619a5..47746bd049a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw9x-33p6-vp3q/GHSA-rw9x-33p6-vp3q.json +++ b/advisories/unreviewed/2022/05/GHSA-rw9x-33p6-vp3q/GHSA-rw9x-33p6-vp3q.json @@ -7,12 +7,8 @@ "CVE-2009-3644" ], "details": "SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json b/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json index 367a2976e2d..5b52da6c58f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json +++ b/advisories/unreviewed/2022/05/GHSA-rwf8-4gv4-8fmw/GHSA-rwf8-4gv4-8fmw.json @@ -7,12 +7,8 @@ "CVE-2015-2666" ], "details": "Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxh4-4wmm-564x/GHSA-rxh4-4wmm-564x.json b/advisories/unreviewed/2022/05/GHSA-rxh4-4wmm-564x/GHSA-rxh4-4wmm-564x.json index 96958eb386e..aff27ef9835 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxh4-4wmm-564x/GHSA-rxh4-4wmm-564x.json +++ b/advisories/unreviewed/2022/05/GHSA-rxh4-4wmm-564x/GHSA-rxh4-4wmm-564x.json @@ -7,12 +7,8 @@ "CVE-2009-3794" ], "details": "Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2mm-g69c-c43h/GHSA-v2mm-g69c-c43h.json b/advisories/unreviewed/2022/05/GHSA-v2mm-g69c-c43h/GHSA-v2mm-g69c-c43h.json index 6df7f4c9fba..29f7dbdb300 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2mm-g69c-c43h/GHSA-v2mm-g69c-c43h.json +++ b/advisories/unreviewed/2022/05/GHSA-v2mm-g69c-c43h/GHSA-v2mm-g69c-c43h.json @@ -7,12 +7,8 @@ "CVE-2009-3305" ], "details": "Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2rj-r82f-7qw2/GHSA-v2rj-r82f-7qw2.json b/advisories/unreviewed/2022/05/GHSA-v2rj-r82f-7qw2/GHSA-v2rj-r82f-7qw2.json index 39ca4ab14a3..19fc276987d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2rj-r82f-7qw2/GHSA-v2rj-r82f-7qw2.json +++ b/advisories/unreviewed/2022/05/GHSA-v2rj-r82f-7qw2/GHSA-v2rj-r82f-7qw2.json @@ -7,12 +7,8 @@ "CVE-2009-3191" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2xr-6qx5-hp38/GHSA-v2xr-6qx5-hp38.json b/advisories/unreviewed/2022/05/GHSA-v2xr-6qx5-hp38/GHSA-v2xr-6qx5-hp38.json index d69fcfca2f9..b5235fdc4e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2xr-6qx5-hp38/GHSA-v2xr-6qx5-hp38.json +++ b/advisories/unreviewed/2022/05/GHSA-v2xr-6qx5-hp38/GHSA-v2xr-6qx5-hp38.json @@ -7,12 +7,8 @@ "CVE-2009-3453" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote attackers to inject arbitrary web script or HTML via the filename of a .odt file in a Lotus Quickr place, related to the Library template.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v564-86mx-r49f/GHSA-v564-86mx-r49f.json b/advisories/unreviewed/2022/05/GHSA-v564-86mx-r49f/GHSA-v564-86mx-r49f.json index f5f132bb9d4..8e87aa6c69f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v564-86mx-r49f/GHSA-v564-86mx-r49f.json +++ b/advisories/unreviewed/2022/05/GHSA-v564-86mx-r49f/GHSA-v564-86mx-r49f.json @@ -7,12 +7,8 @@ "CVE-2009-3366" ], "details": "Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v59f-mhqw-x2vc/GHSA-v59f-mhqw-x2vc.json b/advisories/unreviewed/2022/05/GHSA-v59f-mhqw-x2vc/GHSA-v59f-mhqw-x2vc.json index eb5e391ddd3..3b60997f956 100644 --- a/advisories/unreviewed/2022/05/GHSA-v59f-mhqw-x2vc/GHSA-v59f-mhqw-x2vc.json +++ b/advisories/unreviewed/2022/05/GHSA-v59f-mhqw-x2vc/GHSA-v59f-mhqw-x2vc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5cq-7jp3-qf4w/GHSA-v5cq-7jp3-qf4w.json b/advisories/unreviewed/2022/05/GHSA-v5cq-7jp3-qf4w/GHSA-v5cq-7jp3-qf4w.json index 4d034a1ccef..16efce49edc 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5cq-7jp3-qf4w/GHSA-v5cq-7jp3-qf4w.json +++ b/advisories/unreviewed/2022/05/GHSA-v5cq-7jp3-qf4w/GHSA-v5cq-7jp3-qf4w.json @@ -7,12 +7,8 @@ "CVE-2009-3532" ], "details": "Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6mq-p8pv-vq8r/GHSA-v6mq-p8pv-vq8r.json b/advisories/unreviewed/2022/05/GHSA-v6mq-p8pv-vq8r/GHSA-v6mq-p8pv-vq8r.json index 8ec814a350e..03c6799fd65 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6mq-p8pv-vq8r/GHSA-v6mq-p8pv-vq8r.json +++ b/advisories/unreviewed/2022/05/GHSA-v6mq-p8pv-vq8r/GHSA-v6mq-p8pv-vq8r.json @@ -7,12 +7,8 @@ "CVE-2009-3549" ], "details": "packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v82w-f9vr-j64c/GHSA-v82w-f9vr-j64c.json b/advisories/unreviewed/2022/05/GHSA-v82w-f9vr-j64c/GHSA-v82w-f9vr-j64c.json index 0baa32bdc31..423b792f3a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v82w-f9vr-j64c/GHSA-v82w-f9vr-j64c.json +++ b/advisories/unreviewed/2022/05/GHSA-v82w-f9vr-j64c/GHSA-v82w-f9vr-j64c.json @@ -7,12 +7,8 @@ "CVE-2009-3533" ], "details": "SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v89m-75xw-x3cc/GHSA-v89m-75xw-x3cc.json b/advisories/unreviewed/2022/05/GHSA-v89m-75xw-x3cc/GHSA-v89m-75xw-x3cc.json index ca9a8b5fef8..179e885d27d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v89m-75xw-x3cc/GHSA-v89m-75xw-x3cc.json +++ b/advisories/unreviewed/2022/05/GHSA-v89m-75xw-x3cc/GHSA-v89m-75xw-x3cc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcwp-h637-px5r/GHSA-vcwp-h637-px5r.json b/advisories/unreviewed/2022/05/GHSA-vcwp-h637-px5r/GHSA-vcwp-h637-px5r.json index 851e8c64df3..b9e944c66ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcwp-h637-px5r/GHSA-vcwp-h637-px5r.json +++ b/advisories/unreviewed/2022/05/GHSA-vcwp-h637-px5r/GHSA-vcwp-h637-px5r.json @@ -7,12 +7,8 @@ "CVE-2009-3378" ], "details": "The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vf29-8mcc-9rw6/GHSA-vf29-8mcc-9rw6.json b/advisories/unreviewed/2022/05/GHSA-vf29-8mcc-9rw6/GHSA-vf29-8mcc-9rw6.json index 57722186f15..bd7e396f819 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf29-8mcc-9rw6/GHSA-vf29-8mcc-9rw6.json +++ b/advisories/unreviewed/2022/05/GHSA-vf29-8mcc-9rw6/GHSA-vf29-8mcc-9rw6.json @@ -7,12 +7,8 @@ "CVE-2009-3336" ], "details": "SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfrc-8p6x-x2rc/GHSA-vfrc-8p6x-x2rc.json b/advisories/unreviewed/2022/05/GHSA-vfrc-8p6x-x2rc/GHSA-vfrc-8p6x-x2rc.json index 7e4a7c7ac67..c4efb2f511a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfrc-8p6x-x2rc/GHSA-vfrc-8p6x-x2rc.json +++ b/advisories/unreviewed/2022/05/GHSA-vfrc-8p6x-x2rc/GHSA-vfrc-8p6x-x2rc.json @@ -7,12 +7,8 @@ "CVE-2009-3468" ], "details": "Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgwm-jp52-gpmr/GHSA-vgwm-jp52-gpmr.json b/advisories/unreviewed/2022/05/GHSA-vgwm-jp52-gpmr/GHSA-vgwm-jp52-gpmr.json index a34935e2fc7..31d35024bf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgwm-jp52-gpmr/GHSA-vgwm-jp52-gpmr.json +++ b/advisories/unreviewed/2022/05/GHSA-vgwm-jp52-gpmr/GHSA-vgwm-jp52-gpmr.json @@ -7,12 +7,8 @@ "CVE-2009-3346" ], "details": "Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj66-fqfw-pvg4/GHSA-vj66-fqfw-pvg4.json b/advisories/unreviewed/2022/05/GHSA-vj66-fqfw-pvg4/GHSA-vj66-fqfw-pvg4.json index b1c0e0e3ece..933813d80d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj66-fqfw-pvg4/GHSA-vj66-fqfw-pvg4.json +++ b/advisories/unreviewed/2022/05/GHSA-vj66-fqfw-pvg4/GHSA-vj66-fqfw-pvg4.json @@ -7,12 +7,8 @@ "CVE-2009-3198" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj7x-rvh3-72c5/GHSA-vj7x-rvh3-72c5.json b/advisories/unreviewed/2022/05/GHSA-vj7x-rvh3-72c5/GHSA-vj7x-rvh3-72c5.json index 85bdf572a30..cf0f477fdcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj7x-rvh3-72c5/GHSA-vj7x-rvh3-72c5.json +++ b/advisories/unreviewed/2022/05/GHSA-vj7x-rvh3-72c5/GHSA-vj7x-rvh3-72c5.json @@ -7,12 +7,8 @@ "CVE-2009-3101" ], "details": "xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 10, and OpenSolaris snv_109 through snv_122, does not properly handle Trusted Extensions, which allows local users to cause a denial of service (CPU consumption and console hang) by locking the screen, related to a regression in certain Solaris and OpenSolaris patches.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj8h-wj7f-5mcf/GHSA-vj8h-wj7f-5mcf.json b/advisories/unreviewed/2022/05/GHSA-vj8h-wj7f-5mcf/GHSA-vj8h-wj7f-5mcf.json index 3ebb3940a49..3b1bbc9d670 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj8h-wj7f-5mcf/GHSA-vj8h-wj7f-5mcf.json +++ b/advisories/unreviewed/2022/05/GHSA-vj8h-wj7f-5mcf/GHSA-vj8h-wj7f-5mcf.json @@ -7,12 +7,8 @@ "CVE-2009-3615" ], "details": "The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjg8-mp98-7f39/GHSA-vjg8-mp98-7f39.json b/advisories/unreviewed/2022/05/GHSA-vjg8-mp98-7f39/GHSA-vjg8-mp98-7f39.json index 21ca242a0fc..9e3971e7e58 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjg8-mp98-7f39/GHSA-vjg8-mp98-7f39.json +++ b/advisories/unreviewed/2022/05/GHSA-vjg8-mp98-7f39/GHSA-vjg8-mp98-7f39.json @@ -7,12 +7,8 @@ "CVE-2009-3499" ], "details": "SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm8q-pgwg-rc22/GHSA-vm8q-pgwg-rc22.json b/advisories/unreviewed/2022/05/GHSA-vm8q-pgwg-rc22/GHSA-vm8q-pgwg-rc22.json index 73655b36150..da22adc6eea 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm8q-pgwg-rc22/GHSA-vm8q-pgwg-rc22.json +++ b/advisories/unreviewed/2022/05/GHSA-vm8q-pgwg-rc22/GHSA-vm8q-pgwg-rc22.json @@ -7,12 +7,8 @@ "CVE-2009-3207" ], "details": "The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote attackers to view arbitrary images via a request that specifies an image's filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmg6-7v27-vwrg/GHSA-vmg6-7v27-vwrg.json b/advisories/unreviewed/2022/05/GHSA-vmg6-7v27-vwrg/GHSA-vmg6-7v27-vwrg.json index 6c982a1a57d..6ee38bb481c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmg6-7v27-vwrg/GHSA-vmg6-7v27-vwrg.json +++ b/advisories/unreviewed/2022/05/GHSA-vmg6-7v27-vwrg/GHSA-vmg6-7v27-vwrg.json @@ -7,12 +7,8 @@ "CVE-2009-3272" ], "details": "Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vp33-c9pr-hxcq/GHSA-vp33-c9pr-hxcq.json b/advisories/unreviewed/2022/05/GHSA-vp33-c9pr-hxcq/GHSA-vp33-c9pr-hxcq.json index 3e9e6c757cb..f21adc00634 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp33-c9pr-hxcq/GHSA-vp33-c9pr-hxcq.json +++ b/advisories/unreviewed/2022/05/GHSA-vp33-c9pr-hxcq/GHSA-vp33-c9pr-hxcq.json @@ -7,12 +7,8 @@ "CVE-2009-3219" ], "details": "Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp78-g43w-3482/GHSA-vp78-g43w-3482.json b/advisories/unreviewed/2022/05/GHSA-vp78-g43w-3482/GHSA-vp78-g43w-3482.json index dbdffd5bb8c..012f8ff8f04 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp78-g43w-3482/GHSA-vp78-g43w-3482.json +++ b/advisories/unreviewed/2022/05/GHSA-vp78-g43w-3482/GHSA-vp78-g43w-3482.json @@ -7,12 +7,8 @@ "CVE-2009-3195" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vph7-v96r-wc7m/GHSA-vph7-v96r-wc7m.json b/advisories/unreviewed/2022/05/GHSA-vph7-v96r-wc7m/GHSA-vph7-v96r-wc7m.json index a512f5731b1..363ccdc3f23 100644 --- a/advisories/unreviewed/2022/05/GHSA-vph7-v96r-wc7m/GHSA-vph7-v96r-wc7m.json +++ b/advisories/unreviewed/2022/05/GHSA-vph7-v96r-wc7m/GHSA-vph7-v96r-wc7m.json @@ -7,12 +7,8 @@ "CVE-2009-3486" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program; the (4) wizard-ids or (5) pager-new-identifier parameter in a firewall-filters action to the configuration program; (6) the cos-physical-interface-name parameter in a cos-physical-interfaces-edit action to the configuration program; the (7) wizard-args or (8) wizard-ids parameter in an snmp action to the configuration program; the (9) username or (10) fullname parameter in a users action to the configuration program; or the (11) certname or (12) certbody parameter in a local-cert (aka https) action to the configuration program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vphm-8x59-c77v/GHSA-vphm-8x59-c77v.json b/advisories/unreviewed/2022/05/GHSA-vphm-8x59-c77v/GHSA-vphm-8x59-c77v.json index 7b15c2418ad..49e68edb7d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vphm-8x59-c77v/GHSA-vphm-8x59-c77v.json +++ b/advisories/unreviewed/2022/05/GHSA-vphm-8x59-c77v/GHSA-vphm-8x59-c77v.json @@ -7,12 +7,8 @@ "CVE-2009-3694" ], "details": "Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpr4-7gh6-67c2/GHSA-vpr4-7gh6-67c2.json b/advisories/unreviewed/2022/05/GHSA-vpr4-7gh6-67c2/GHSA-vpr4-7gh6-67c2.json index 2a76adc46bb..2246370e780 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpr4-7gh6-67c2/GHSA-vpr4-7gh6-67c2.json +++ b/advisories/unreviewed/2022/05/GHSA-vpr4-7gh6-67c2/GHSA-vpr4-7gh6-67c2.json @@ -7,12 +7,8 @@ "CVE-2009-3326" ], "details": "SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq38-j6m4-jpjp/GHSA-vq38-j6m4-jpjp.json b/advisories/unreviewed/2022/05/GHSA-vq38-j6m4-jpjp/GHSA-vq38-j6m4-jpjp.json index 0865e726cf2..1951366bb43 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq38-j6m4-jpjp/GHSA-vq38-j6m4-jpjp.json +++ b/advisories/unreviewed/2022/05/GHSA-vq38-j6m4-jpjp/GHSA-vq38-j6m4-jpjp.json @@ -7,12 +7,8 @@ "CVE-2009-3589" ], "details": "incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vqm6-65fg-mvcv/GHSA-vqm6-65fg-mvcv.json b/advisories/unreviewed/2022/05/GHSA-vqm6-65fg-mvcv/GHSA-vqm6-65fg-mvcv.json index 49c3a277b35..7a74405fb39 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqm6-65fg-mvcv/GHSA-vqm6-65fg-mvcv.json +++ b/advisories/unreviewed/2022/05/GHSA-vqm6-65fg-mvcv/GHSA-vqm6-65fg-mvcv.json @@ -7,12 +7,8 @@ "CVE-2009-3739" ], "details": "Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controllers allow remote attackers to obtain privileged access or cause a denial of service (halt) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrc3-p99x-fxh5/GHSA-vrc3-p99x-fxh5.json b/advisories/unreviewed/2022/05/GHSA-vrc3-p99x-fxh5/GHSA-vrc3-p99x-fxh5.json index e386cd505f0..1679a9eff69 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrc3-p99x-fxh5/GHSA-vrc3-p99x-fxh5.json +++ b/advisories/unreviewed/2022/05/GHSA-vrc3-p99x-fxh5/GHSA-vrc3-p99x-fxh5.json @@ -7,12 +7,8 @@ "CVE-2009-3193" ], "details": "SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrx6-hjcm-g3jh/GHSA-vrx6-hjcm-g3jh.json b/advisories/unreviewed/2022/05/GHSA-vrx6-hjcm-g3jh/GHSA-vrx6-hjcm-g3jh.json index 972654447f6..e36d7f41007 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrx6-hjcm-g3jh/GHSA-vrx6-hjcm-g3jh.json +++ b/advisories/unreviewed/2022/05/GHSA-vrx6-hjcm-g3jh/GHSA-vrx6-hjcm-g3jh.json @@ -7,12 +7,8 @@ "CVE-2009-3435" ], "details": "Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a variable name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv54-q9fx-xmv2/GHSA-vv54-q9fx-xmv2.json b/advisories/unreviewed/2022/05/GHSA-vv54-q9fx-xmv2/GHSA-vv54-q9fx-xmv2.json index 185dfacdc5b..9008564e9d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv54-q9fx-xmv2/GHSA-vv54-q9fx-xmv2.json +++ b/advisories/unreviewed/2022/05/GHSA-vv54-q9fx-xmv2/GHSA-vv54-q9fx-xmv2.json @@ -7,12 +7,8 @@ "CVE-2009-3713" ], "details": "SQL injection vulnerability in fichero.php in MorcegoCMS 1.7.6 and earlier allows remote attackers to execute arbitrary SQL commands via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvqg-rc4c-3qfj/GHSA-vvqg-rc4c-3qfj.json b/advisories/unreviewed/2022/05/GHSA-vvqg-rc4c-3qfj/GHSA-vvqg-rc4c-3qfj.json index 5752cf0870c..9051d78f484 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvqg-rc4c-3qfj/GHSA-vvqg-rc4c-3qfj.json +++ b/advisories/unreviewed/2022/05/GHSA-vvqg-rc4c-3qfj/GHSA-vvqg-rc4c-3qfj.json @@ -7,12 +7,8 @@ "CVE-2009-3389" ], "details": "Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw2m-wgch-f8g3/GHSA-vw2m-wgch-f8g3.json b/advisories/unreviewed/2022/05/GHSA-vw2m-wgch-f8g3/GHSA-vw2m-wgch-f8g3.json index f80401dc260..18f843b42fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw2m-wgch-f8g3/GHSA-vw2m-wgch-f8g3.json +++ b/advisories/unreviewed/2022/05/GHSA-vw2m-wgch-f8g3/GHSA-vw2m-wgch-f8g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw8g-8f3r-fj8m/GHSA-vw8g-8f3r-fj8m.json b/advisories/unreviewed/2022/05/GHSA-vw8g-8f3r-fj8m/GHSA-vw8g-8f3r-fj8m.json index 14b646a6758..22aa762e72a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw8g-8f3r-fj8m/GHSA-vw8g-8f3r-fj8m.json +++ b/advisories/unreviewed/2022/05/GHSA-vw8g-8f3r-fj8m/GHSA-vw8g-8f3r-fj8m.json @@ -7,12 +7,8 @@ "CVE-2009-3565" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwqh-mhgj-p4m8/GHSA-vwqh-mhgj-p4m8.json b/advisories/unreviewed/2022/05/GHSA-vwqh-mhgj-p4m8/GHSA-vwqh-mhgj-p4m8.json index a35ef6494d2..9303137c857 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwqh-mhgj-p4m8/GHSA-vwqh-mhgj-p4m8.json +++ b/advisories/unreviewed/2022/05/GHSA-vwqh-mhgj-p4m8/GHSA-vwqh-mhgj-p4m8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2rh-7p2w-889c/GHSA-w2rh-7p2w-889c.json b/advisories/unreviewed/2022/05/GHSA-w2rh-7p2w-889c/GHSA-w2rh-7p2w-889c.json index e68b8ca1632..39a65942ae4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2rh-7p2w-889c/GHSA-w2rh-7p2w-889c.json +++ b/advisories/unreviewed/2022/05/GHSA-w2rh-7p2w-889c/GHSA-w2rh-7p2w-889c.json @@ -7,12 +7,8 @@ "CVE-2005-0089" ], "details": "The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3pg-w64r-37j8/GHSA-w3pg-w64r-37j8.json b/advisories/unreviewed/2022/05/GHSA-w3pg-w64r-37j8/GHSA-w3pg-w64r-37j8.json index 21724935f62..23ce8e377bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3pg-w64r-37j8/GHSA-w3pg-w64r-37j8.json +++ b/advisories/unreviewed/2022/05/GHSA-w3pg-w64r-37j8/GHSA-w3pg-w64r-37j8.json @@ -7,12 +7,8 @@ "CVE-2009-3414" ], "details": "Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3413.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w434-cfjj-45h2/GHSA-w434-cfjj-45h2.json b/advisories/unreviewed/2022/05/GHSA-w434-cfjj-45h2/GHSA-w434-cfjj-45h2.json index 49e4303b8d2..707d6755109 100644 --- a/advisories/unreviewed/2022/05/GHSA-w434-cfjj-45h2/GHSA-w434-cfjj-45h2.json +++ b/advisories/unreviewed/2022/05/GHSA-w434-cfjj-45h2/GHSA-w434-cfjj-45h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4hh-c225-9vx5/GHSA-w4hh-c225-9vx5.json b/advisories/unreviewed/2022/05/GHSA-w4hh-c225-9vx5/GHSA-w4hh-c225-9vx5.json index cf8221388a6..559bb716a93 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4hh-c225-9vx5/GHSA-w4hh-c225-9vx5.json +++ b/advisories/unreviewed/2022/05/GHSA-w4hh-c225-9vx5/GHSA-w4hh-c225-9vx5.json @@ -7,12 +7,8 @@ "CVE-2009-3469" ], "details": "Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w532-9px6-hv54/GHSA-w532-9px6-hv54.json b/advisories/unreviewed/2022/05/GHSA-w532-9px6-hv54/GHSA-w532-9px6-hv54.json index 9e4a6b65134..8ffd432478a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w532-9px6-hv54/GHSA-w532-9px6-hv54.json +++ b/advisories/unreviewed/2022/05/GHSA-w532-9px6-hv54/GHSA-w532-9px6-hv54.json @@ -7,12 +7,8 @@ "CVE-2009-3095" ], "details": "The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -176,9 +172,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5rm-2969-2w83/GHSA-w5rm-2969-2w83.json b/advisories/unreviewed/2022/05/GHSA-w5rm-2969-2w83/GHSA-w5rm-2969-2w83.json index dfa6aea3616..1055c09c748 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5rm-2969-2w83/GHSA-w5rm-2969-2w83.json +++ b/advisories/unreviewed/2022/05/GHSA-w5rm-2969-2w83/GHSA-w5rm-2969-2w83.json @@ -7,12 +7,8 @@ "CVE-2009-3592" ], "details": "Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbitrary web script or HTML via the email parameter in a subscribed action, a different vector than CVE-2005-1823.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5v3-f8xv-j94c/GHSA-w5v3-f8xv-j94c.json b/advisories/unreviewed/2022/05/GHSA-w5v3-f8xv-j94c/GHSA-w5v3-f8xv-j94c.json index 576ec087472..e7ef18e80ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5v3-f8xv-j94c/GHSA-w5v3-f8xv-j94c.json +++ b/advisories/unreviewed/2022/05/GHSA-w5v3-f8xv-j94c/GHSA-w5v3-f8xv-j94c.json @@ -7,12 +7,8 @@ "CVE-2009-3577" ], "details": "Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to \"application callbacks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6gf-8h7h-2hmw/GHSA-w6gf-8h7h-2hmw.json b/advisories/unreviewed/2022/05/GHSA-w6gf-8h7h-2hmw/GHSA-w6gf-8h7h-2hmw.json index 192d6877faa..4e56d6c3994 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6gf-8h7h-2hmw/GHSA-w6gf-8h7h-2hmw.json +++ b/advisories/unreviewed/2022/05/GHSA-w6gf-8h7h-2hmw/GHSA-w6gf-8h7h-2hmw.json @@ -7,12 +7,8 @@ "CVE-2009-3485" ], "details": "Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w757-mvqp-v98h/GHSA-w757-mvqp-v98h.json b/advisories/unreviewed/2022/05/GHSA-w757-mvqp-v98h/GHSA-w757-mvqp-v98h.json index b6b943ddfac..cb4e0e1bd6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w757-mvqp-v98h/GHSA-w757-mvqp-v98h.json +++ b/advisories/unreviewed/2022/05/GHSA-w757-mvqp-v98h/GHSA-w757-mvqp-v98h.json @@ -7,12 +7,8 @@ "CVE-2009-3375" ], "details": "content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8xw-mv63-4c7q/GHSA-w8xw-mv63-4c7q.json b/advisories/unreviewed/2022/05/GHSA-w8xw-mv63-4c7q/GHSA-w8xw-mv63-4c7q.json index 84ad537ca53..b568856db19 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8xw-mv63-4c7q/GHSA-w8xw-mv63-4c7q.json +++ b/advisories/unreviewed/2022/05/GHSA-w8xw-mv63-4c7q/GHSA-w8xw-mv63-4c7q.json @@ -7,12 +7,8 @@ "CVE-2009-3215" ], "details": "SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json b/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json index 57f6474972f..966d92c1a4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json +++ b/advisories/unreviewed/2022/05/GHSA-wc9w-8x8g-533g/GHSA-wc9w-8x8g-533g.json @@ -7,12 +7,8 @@ "CVE-2014-9529" ], "details": "Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcgf-h42q-fhqj/GHSA-wcgf-h42q-fhqj.json b/advisories/unreviewed/2022/05/GHSA-wcgf-h42q-fhqj/GHSA-wcgf-h42q-fhqj.json index a6be33e8c89..246d093ae74 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcgf-h42q-fhqj/GHSA-wcgf-h42q-fhqj.json +++ b/advisories/unreviewed/2022/05/GHSA-wcgf-h42q-fhqj/GHSA-wcgf-h42q-fhqj.json @@ -7,12 +7,8 @@ "CVE-2009-3498" ], "details": "SQL injection vulnerability in php/update_article_hits.php in HBcms 1.7 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf53-3973-wc7h/GHSA-wf53-3973-wc7h.json b/advisories/unreviewed/2022/05/GHSA-wf53-3973-wc7h/GHSA-wf53-3973-wc7h.json index 8c3359b48f9..97d438e2868 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf53-3973-wc7h/GHSA-wf53-3973-wc7h.json +++ b/advisories/unreviewed/2022/05/GHSA-wf53-3973-wc7h/GHSA-wf53-3973-wc7h.json @@ -7,12 +7,8 @@ "CVE-2009-3782" ], "details": "Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with \"View own userpoints\" permissions to read the userpoint data of arbitrary users via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg2f-5gm7-v7mx/GHSA-wg2f-5gm7-v7mx.json b/advisories/unreviewed/2022/05/GHSA-wg2f-5gm7-v7mx/GHSA-wg2f-5gm7-v7mx.json index 24c9f48b3c2..b3c41673233 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg2f-5gm7-v7mx/GHSA-wg2f-5gm7-v7mx.json +++ b/advisories/unreviewed/2022/05/GHSA-wg2f-5gm7-v7mx/GHSA-wg2f-5gm7-v7mx.json @@ -7,12 +7,8 @@ "CVE-2009-3313" ], "details": "Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg4x-xc3p-qhqj/GHSA-wg4x-xc3p-qhqj.json b/advisories/unreviewed/2022/05/GHSA-wg4x-xc3p-qhqj/GHSA-wg4x-xc3p-qhqj.json index b5f9956fb1a..ee5a5419210 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg4x-xc3p-qhqj/GHSA-wg4x-xc3p-qhqj.json +++ b/advisories/unreviewed/2022/05/GHSA-wg4x-xc3p-qhqj/GHSA-wg4x-xc3p-qhqj.json @@ -7,12 +7,8 @@ "CVE-2009-3505" ], "details": "SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgqh-fmw6-rm93/GHSA-wgqh-fmw6-rm93.json b/advisories/unreviewed/2022/05/GHSA-wgqh-fmw6-rm93/GHSA-wgqh-fmw6-rm93.json index bfbbeb56ed8..322710f0488 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgqh-fmw6-rm93/GHSA-wgqh-fmw6-rm93.json +++ b/advisories/unreviewed/2022/05/GHSA-wgqh-fmw6-rm93/GHSA-wgqh-fmw6-rm93.json @@ -7,12 +7,8 @@ "CVE-2009-3711" ], "details": "Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh74-7r5x-2v2m/GHSA-wh74-7r5x-2v2m.json b/advisories/unreviewed/2022/05/GHSA-wh74-7r5x-2v2m/GHSA-wh74-7r5x-2v2m.json index 1a8685f9e36..fd9151f80f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh74-7r5x-2v2m/GHSA-wh74-7r5x-2v2m.json +++ b/advisories/unreviewed/2022/05/GHSA-wh74-7r5x-2v2m/GHSA-wh74-7r5x-2v2m.json @@ -7,12 +7,8 @@ "CVE-2009-3583" ], "details": "Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the countrycode field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whx9-88h6-g65q/GHSA-whx9-88h6-g65q.json b/advisories/unreviewed/2022/05/GHSA-whx9-88h6-g65q/GHSA-whx9-88h6-g65q.json index 9a28f3badba..f3a06bd86d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-whx9-88h6-g65q/GHSA-whx9-88h6-g65q.json +++ b/advisories/unreviewed/2022/05/GHSA-whx9-88h6-g65q/GHSA-whx9-88h6-g65q.json @@ -7,12 +7,8 @@ "CVE-2009-3189" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj9q-fjc4-6whp/GHSA-wj9q-fjc4-6whp.json b/advisories/unreviewed/2022/05/GHSA-wj9q-fjc4-6whp/GHSA-wj9q-fjc4-6whp.json index 38ac103c643..a9a17cb4844 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj9q-fjc4-6whp/GHSA-wj9q-fjc4-6whp.json +++ b/advisories/unreviewed/2022/05/GHSA-wj9q-fjc4-6whp/GHSA-wj9q-fjc4-6whp.json @@ -7,12 +7,8 @@ "CVE-2009-3385" ], "details": "The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq8g-hgwc-7q56/GHSA-wq8g-hgwc-7q56.json b/advisories/unreviewed/2022/05/GHSA-wq8g-hgwc-7q56/GHSA-wq8g-hgwc-7q56.json index 14dbbfc01ee..a76e1fc023d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq8g-hgwc-7q56/GHSA-wq8g-hgwc-7q56.json +++ b/advisories/unreviewed/2022/05/GHSA-wq8g-hgwc-7q56/GHSA-wq8g-hgwc-7q56.json @@ -7,12 +7,8 @@ "CVE-2009-3515" ], "details": "Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr5r-74rp-qh45/GHSA-wr5r-74rp-qh45.json b/advisories/unreviewed/2022/05/GHSA-wr5r-74rp-qh45/GHSA-wr5r-74rp-qh45.json index bf07d3e0849..368c3a3e10c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr5r-74rp-qh45/GHSA-wr5r-74rp-qh45.json +++ b/advisories/unreviewed/2022/05/GHSA-wr5r-74rp-qh45/GHSA-wr5r-74rp-qh45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr76-gg23-hq72/GHSA-wr76-gg23-hq72.json b/advisories/unreviewed/2022/05/GHSA-wr76-gg23-hq72/GHSA-wr76-gg23-hq72.json index 0fe554cf6f2..c3318d82d2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr76-gg23-hq72/GHSA-wr76-gg23-hq72.json +++ b/advisories/unreviewed/2022/05/GHSA-wr76-gg23-hq72/GHSA-wr76-gg23-hq72.json @@ -7,12 +7,8 @@ "CVE-2009-3374" ], "details": "The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to \"doubly-wrapped objects.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr9p-hcgm-x262/GHSA-wr9p-hcgm-x262.json b/advisories/unreviewed/2022/05/GHSA-wr9p-hcgm-x262/GHSA-wr9p-hcgm-x262.json index 409b76aa783..33a0d4982a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr9p-hcgm-x262/GHSA-wr9p-hcgm-x262.json +++ b/advisories/unreviewed/2022/05/GHSA-wr9p-hcgm-x262/GHSA-wr9p-hcgm-x262.json @@ -7,12 +7,8 @@ "CVE-2009-3531" ], "details": "SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrwm-4qrx-hh9h/GHSA-wrwm-4qrx-hh9h.json b/advisories/unreviewed/2022/05/GHSA-wrwm-4qrx-hh9h/GHSA-wrwm-4qrx-hh9h.json index 014142e691a..f7d4c266d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrwm-4qrx-hh9h/GHSA-wrwm-4qrx-hh9h.json +++ b/advisories/unreviewed/2022/05/GHSA-wrwm-4qrx-hh9h/GHSA-wrwm-4qrx-hh9h.json @@ -7,12 +7,8 @@ "CVE-2009-3216" ], "details": "Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the admin module, reachable through index.php; or (2) the module parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv5f-6cvh-7g9m/GHSA-wv5f-6cvh-7g9m.json b/advisories/unreviewed/2022/05/GHSA-wv5f-6cvh-7g9m/GHSA-wv5f-6cvh-7g9m.json index d2fd8b87cc3..6a9a71b1b32 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv5f-6cvh-7g9m/GHSA-wv5f-6cvh-7g9m.json +++ b/advisories/unreviewed/2022/05/GHSA-wv5f-6cvh-7g9m/GHSA-wv5f-6cvh-7g9m.json @@ -7,12 +7,8 @@ "CVE-2009-3355" ], "details": "Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvh2-7875-xq75/GHSA-wvh2-7875-xq75.json b/advisories/unreviewed/2022/05/GHSA-wvh2-7875-xq75/GHSA-wvh2-7875-xq75.json index b6d7320c6af..431d9d55a02 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvh2-7875-xq75/GHSA-wvh2-7875-xq75.json +++ b/advisories/unreviewed/2022/05/GHSA-wvh2-7875-xq75/GHSA-wvh2-7875-xq75.json @@ -7,12 +7,8 @@ "CVE-2009-3352" ], "details": "Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwp4-jfvw-r542/GHSA-wwp4-jfvw-r542.json b/advisories/unreviewed/2022/05/GHSA-wwp4-jfvw-r542/GHSA-wwp4-jfvw-r542.json index cd062c5ded4..2f6087a55e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwp4-jfvw-r542/GHSA-wwp4-jfvw-r542.json +++ b/advisories/unreviewed/2022/05/GHSA-wwp4-jfvw-r542/GHSA-wwp4-jfvw-r542.json @@ -7,12 +7,8 @@ "CVE-2009-3447" ], "details": "Unrestricted file upload vulnerability in RADactive I-Load before 2008.2.5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, and then sending a request for a predictable filename during a short time window.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwq8-rpxh-fwjj/GHSA-wwq8-rpxh-fwjj.json b/advisories/unreviewed/2022/05/GHSA-wwq8-rpxh-fwjj/GHSA-wwq8-rpxh-fwjj.json index 55d35778c54..8be294721cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwq8-rpxh-fwjj/GHSA-wwq8-rpxh-fwjj.json +++ b/advisories/unreviewed/2022/05/GHSA-wwq8-rpxh-fwjj/GHSA-wwq8-rpxh-fwjj.json @@ -7,12 +7,8 @@ "CVE-2009-3467" ], "details": "Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxhf-r74j-fmh8/GHSA-wxhf-r74j-fmh8.json b/advisories/unreviewed/2022/05/GHSA-wxhf-r74j-fmh8/GHSA-wxhf-r74j-fmh8.json index 55076ca3d28..0cbb02fded8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxhf-r74j-fmh8/GHSA-wxhf-r74j-fmh8.json +++ b/advisories/unreviewed/2022/05/GHSA-wxhf-r74j-fmh8/GHSA-wxhf-r74j-fmh8.json @@ -7,12 +7,8 @@ "CVE-2009-3116" ], "details": "SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxvm-56x8-m8c9/GHSA-wxvm-56x8-m8c9.json b/advisories/unreviewed/2022/05/GHSA-wxvm-56x8-m8c9/GHSA-wxvm-56x8-m8c9.json index 16a75499a5e..f864ae8a0b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxvm-56x8-m8c9/GHSA-wxvm-56x8-m8c9.json +++ b/advisories/unreviewed/2022/05/GHSA-wxvm-56x8-m8c9/GHSA-wxvm-56x8-m8c9.json @@ -7,12 +7,8 @@ "CVE-2009-3646" ], "details": "InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x325-6h4w-24jp/GHSA-x325-6h4w-24jp.json b/advisories/unreviewed/2022/05/GHSA-x325-6h4w-24jp/GHSA-x325-6h4w-24jp.json index f98baceb92b..6e1ec890dbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-x325-6h4w-24jp/GHSA-x325-6h4w-24jp.json +++ b/advisories/unreviewed/2022/05/GHSA-x325-6h4w-24jp/GHSA-x325-6h4w-24jp.json @@ -7,12 +7,8 @@ "CVE-2009-3361" ], "details": "SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x352-m5w7-xq9q/GHSA-x352-m5w7-xq9q.json b/advisories/unreviewed/2022/05/GHSA-x352-m5w7-xq9q/GHSA-x352-m5w7-xq9q.json index 069af107f92..561c99c94e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x352-m5w7-xq9q/GHSA-x352-m5w7-xq9q.json +++ b/advisories/unreviewed/2022/05/GHSA-x352-m5w7-xq9q/GHSA-x352-m5w7-xq9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x38j-xvp2-94qj/GHSA-x38j-xvp2-94qj.json b/advisories/unreviewed/2022/05/GHSA-x38j-xvp2-94qj/GHSA-x38j-xvp2-94qj.json index f944b9c59dc..9a268830200 100644 --- a/advisories/unreviewed/2022/05/GHSA-x38j-xvp2-94qj/GHSA-x38j-xvp2-94qj.json +++ b/advisories/unreviewed/2022/05/GHSA-x38j-xvp2-94qj/GHSA-x38j-xvp2-94qj.json @@ -7,12 +7,8 @@ "CVE-2009-3657" ], "details": "Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3c4-8cgr-5j45/GHSA-x3c4-8cgr-5j45.json b/advisories/unreviewed/2022/05/GHSA-x3c4-8cgr-5j45/GHSA-x3c4-8cgr-5j45.json index 3851c269db0..f391881dea0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3c4-8cgr-5j45/GHSA-x3c4-8cgr-5j45.json +++ b/advisories/unreviewed/2022/05/GHSA-x3c4-8cgr-5j45/GHSA-x3c4-8cgr-5j45.json @@ -7,12 +7,8 @@ "CVE-2009-3227" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to inject arbitrary web script or HTML via the city parameter in a search action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x42x-4h68-vrr4/GHSA-x42x-4h68-vrr4.json b/advisories/unreviewed/2022/05/GHSA-x42x-4h68-vrr4/GHSA-x42x-4h68-vrr4.json index b144414cc1f..2b4cdb742c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x42x-4h68-vrr4/GHSA-x42x-4h68-vrr4.json +++ b/advisories/unreviewed/2022/05/GHSA-x42x-4h68-vrr4/GHSA-x42x-4h68-vrr4.json @@ -7,12 +7,8 @@ "CVE-2009-3102" ], "details": "The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving a crafted $MYSQL_BINPATH variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4r6-h7xv-w7r4/GHSA-x4r6-h7xv-w7r4.json b/advisories/unreviewed/2022/05/GHSA-x4r6-h7xv-w7r4/GHSA-x4r6-h7xv-w7r4.json index e2d98991c76..50e16ac7dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4r6-h7xv-w7r4/GHSA-x4r6-h7xv-w7r4.json +++ b/advisories/unreviewed/2022/05/GHSA-x4r6-h7xv-w7r4/GHSA-x4r6-h7xv-w7r4.json @@ -7,12 +7,8 @@ "CVE-2009-3309" ], "details": "SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4rr-pfq7-hjf5/GHSA-x4rr-pfq7-hjf5.json b/advisories/unreviewed/2022/05/GHSA-x4rr-pfq7-hjf5/GHSA-x4rr-pfq7-hjf5.json index fc172a1e1c9..8c94f535920 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4rr-pfq7-hjf5/GHSA-x4rr-pfq7-hjf5.json +++ b/advisories/unreviewed/2022/05/GHSA-x4rr-pfq7-hjf5/GHSA-x4rr-pfq7-hjf5.json @@ -7,12 +7,8 @@ "CVE-2009-3444" ], "details": "Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4vw-32x4-hm2p/GHSA-x4vw-32x4-hm2p.json b/advisories/unreviewed/2022/05/GHSA-x4vw-32x4-hm2p/GHSA-x4vw-32x4-hm2p.json index 2183bccf8d7..f73fa7a72fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4vw-32x4-hm2p/GHSA-x4vw-32x4-hm2p.json +++ b/advisories/unreviewed/2022/05/GHSA-x4vw-32x4-hm2p/GHSA-x4vw-32x4-hm2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x57m-fjm7-96hr/GHSA-x57m-fjm7-96hr.json b/advisories/unreviewed/2022/05/GHSA-x57m-fjm7-96hr/GHSA-x57m-fjm7-96hr.json index 245a3380985..8c2876ade20 100644 --- a/advisories/unreviewed/2022/05/GHSA-x57m-fjm7-96hr/GHSA-x57m-fjm7-96hr.json +++ b/advisories/unreviewed/2022/05/GHSA-x57m-fjm7-96hr/GHSA-x57m-fjm7-96hr.json @@ -7,12 +7,8 @@ "CVE-2009-3220" ], "details": "PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6gp-hg9r-wh46/GHSA-x6gp-hg9r-wh46.json b/advisories/unreviewed/2022/05/GHSA-x6gp-hg9r-wh46/GHSA-x6gp-hg9r-wh46.json index 2897accb45e..236b2cfc8fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6gp-hg9r-wh46/GHSA-x6gp-hg9r-wh46.json +++ b/advisories/unreviewed/2022/05/GHSA-x6gp-hg9r-wh46/GHSA-x6gp-hg9r-wh46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x732-h974-48gx/GHSA-x732-h974-48gx.json b/advisories/unreviewed/2022/05/GHSA-x732-h974-48gx/GHSA-x732-h974-48gx.json index 1335f83b12b..7e5a5065950 100644 --- a/advisories/unreviewed/2022/05/GHSA-x732-h974-48gx/GHSA-x732-h974-48gx.json +++ b/advisories/unreviewed/2022/05/GHSA-x732-h974-48gx/GHSA-x732-h974-48gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x76g-hhwp-675p/GHSA-x76g-hhwp-675p.json b/advisories/unreviewed/2022/05/GHSA-x76g-hhwp-675p/GHSA-x76g-hhwp-675p.json index fcecfda7799..b7699e5082f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x76g-hhwp-675p/GHSA-x76g-hhwp-675p.json +++ b/advisories/unreviewed/2022/05/GHSA-x76g-hhwp-675p/GHSA-x76g-hhwp-675p.json @@ -7,12 +7,8 @@ "CVE-2009-3199" ], "details": "Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7vj-6hfr-gqfh/GHSA-x7vj-6hfr-gqfh.json b/advisories/unreviewed/2022/05/GHSA-x7vj-6hfr-gqfh/GHSA-x7vj-6hfr-gqfh.json index 6da2d31be6b..251b5c7bb0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7vj-6hfr-gqfh/GHSA-x7vj-6hfr-gqfh.json +++ b/advisories/unreviewed/2022/05/GHSA-x7vj-6hfr-gqfh/GHSA-x7vj-6hfr-gqfh.json @@ -7,12 +7,8 @@ "CVE-2009-3399" ], "details": "Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0.6 and 8.1.5 allows remote attackers to affect integrity, related to WLS Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x96g-vp28-xf6f/GHSA-x96g-vp28-xf6f.json b/advisories/unreviewed/2022/05/GHSA-x96g-vp28-xf6f/GHSA-x96g-vp28-xf6f.json index f6404aff9e3..404f5fb6dd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x96g-vp28-xf6f/GHSA-x96g-vp28-xf6f.json +++ b/advisories/unreviewed/2022/05/GHSA-x96g-vp28-xf6f/GHSA-x96g-vp28-xf6f.json @@ -7,12 +7,8 @@ "CVE-2009-3436" ], "details": "Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x99w-r7p7-9cww/GHSA-x99w-r7p7-9cww.json b/advisories/unreviewed/2022/05/GHSA-x99w-r7p7-9cww/GHSA-x99w-r7p7-9cww.json index fe20650431b..c5d9465214b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x99w-r7p7-9cww/GHSA-x99w-r7p7-9cww.json +++ b/advisories/unreviewed/2022/05/GHSA-x99w-r7p7-9cww/GHSA-x99w-r7p7-9cww.json @@ -7,12 +7,8 @@ "CVE-2009-3418" ], "details": "Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9r7-5c46-9x5p/GHSA-x9r7-5c46-9x5p.json b/advisories/unreviewed/2022/05/GHSA-x9r7-5c46-9x5p/GHSA-x9r7-5c46-9x5p.json index ec2e55cd642..e8cb55b9904 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9r7-5c46-9x5p/GHSA-x9r7-5c46-9x5p.json +++ b/advisories/unreviewed/2022/05/GHSA-x9r7-5c46-9x5p/GHSA-x9r7-5c46-9x5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf2c-ccw7-485g/GHSA-xf2c-ccw7-485g.json b/advisories/unreviewed/2022/05/GHSA-xf2c-ccw7-485g/GHSA-xf2c-ccw7-485g.json index 595ad037fb4..1aaf2250914 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf2c-ccw7-485g/GHSA-xf2c-ccw7-485g.json +++ b/advisories/unreviewed/2022/05/GHSA-xf2c-ccw7-485g/GHSA-xf2c-ccw7-485g.json @@ -7,12 +7,8 @@ "CVE-2009-3118" ], "details": "SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization in base/danneo.function.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf3g-8p9v-323q/GHSA-xf3g-8p9v-323q.json b/advisories/unreviewed/2022/05/GHSA-xf3g-8p9v-323q/GHSA-xf3g-8p9v-323q.json index ba9a2c0d512..2f4c8a24781 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf3g-8p9v-323q/GHSA-xf3g-8p9v-323q.json +++ b/advisories/unreviewed/2022/05/GHSA-xf3g-8p9v-323q/GHSA-xf3g-8p9v-323q.json @@ -7,12 +7,8 @@ "CVE-2009-3197" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech PHP Calendars Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf88-gp54-xgc2/GHSA-xf88-gp54-xgc2.json b/advisories/unreviewed/2022/05/GHSA-xf88-gp54-xgc2/GHSA-xf88-gp54-xgc2.json index 2ed0425ff90..aea63731158 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf88-gp54-xgc2/GHSA-xf88-gp54-xgc2.json +++ b/advisories/unreviewed/2022/05/GHSA-xf88-gp54-xgc2/GHSA-xf88-gp54-xgc2.json @@ -7,12 +7,8 @@ "CVE-2009-3386" ], "details": "Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgf9-6xh9-8mvh/GHSA-xgf9-6xh9-8mvh.json b/advisories/unreviewed/2022/05/GHSA-xgf9-6xh9-8mvh/GHSA-xgf9-6xh9-8mvh.json index e9b3539ee2a..9bb2182be5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgf9-6xh9-8mvh/GHSA-xgf9-6xh9-8mvh.json +++ b/advisories/unreviewed/2022/05/GHSA-xgf9-6xh9-8mvh/GHSA-xgf9-6xh9-8mvh.json @@ -7,12 +7,8 @@ "CVE-2009-3463" ], "details": "Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgrc-85pp-86cg/GHSA-xgrc-85pp-86cg.json b/advisories/unreviewed/2022/05/GHSA-xgrc-85pp-86cg/GHSA-xgrc-85pp-86cg.json index af5f5659678..5a00fcc6fd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgrc-85pp-86cg/GHSA-xgrc-85pp-86cg.json +++ b/advisories/unreviewed/2022/05/GHSA-xgrc-85pp-86cg/GHSA-xgrc-85pp-86cg.json @@ -7,12 +7,8 @@ "CVE-2009-3376" ], "details": "Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xhhx-8xfw-c2vh/GHSA-xhhx-8xfw-c2vh.json b/advisories/unreviewed/2022/05/GHSA-xhhx-8xfw-c2vh/GHSA-xhhx-8xfw-c2vh.json index b2f4c170829..f60a572bd9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhhx-8xfw-c2vh/GHSA-xhhx-8xfw-c2vh.json +++ b/advisories/unreviewed/2022/05/GHSA-xhhx-8xfw-c2vh/GHSA-xhhx-8xfw-c2vh.json @@ -7,12 +7,8 @@ "CVE-2009-3670" ], "details": "Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhpm-r2g2-c7vg/GHSA-xhpm-r2g2-c7vg.json b/advisories/unreviewed/2022/05/GHSA-xhpm-r2g2-c7vg/GHSA-xhpm-r2g2-c7vg.json index 1d32b01286a..3614c6c888c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhpm-r2g2-c7vg/GHSA-xhpm-r2g2-c7vg.json +++ b/advisories/unreviewed/2022/05/GHSA-xhpm-r2g2-c7vg/GHSA-xhpm-r2g2-c7vg.json @@ -7,12 +7,8 @@ "CVE-2009-3588" ], "details": "Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xhr7-hgf3-h7pr/GHSA-xhr7-hgf3-h7pr.json b/advisories/unreviewed/2022/05/GHSA-xhr7-hgf3-h7pr/GHSA-xhr7-hgf3-h7pr.json index d78c98cbd85..18c72f5e759 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhr7-hgf3-h7pr/GHSA-xhr7-hgf3-h7pr.json +++ b/advisories/unreviewed/2022/05/GHSA-xhr7-hgf3-h7pr/GHSA-xhr7-hgf3-h7pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjpc-m35x-gfvr/GHSA-xjpc-m35x-gfvr.json b/advisories/unreviewed/2022/05/GHSA-xjpc-m35x-gfvr/GHSA-xjpc-m35x-gfvr.json index eada0cc926f..f627d81a505 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjpc-m35x-gfvr/GHSA-xjpc-m35x-gfvr.json +++ b/advisories/unreviewed/2022/05/GHSA-xjpc-m35x-gfvr/GHSA-xjpc-m35x-gfvr.json @@ -7,12 +7,8 @@ "CVE-2009-3656" ], "details": "Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjwr-69c4-g9rc/GHSA-xjwr-69c4-g9rc.json b/advisories/unreviewed/2022/05/GHSA-xjwr-69c4-g9rc/GHSA-xjwr-69c4-g9rc.json index 97d9a616607..840f86cc5a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjwr-69c4-g9rc/GHSA-xjwr-69c4-g9rc.json +++ b/advisories/unreviewed/2022/05/GHSA-xjwr-69c4-g9rc/GHSA-xjwr-69c4-g9rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm9f-jp6r-h9h7/GHSA-xm9f-jp6r-h9h7.json b/advisories/unreviewed/2022/05/GHSA-xm9f-jp6r-h9h7/GHSA-xm9f-jp6r-h9h7.json index 5fca536b6d7..bcef9d04992 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm9f-jp6r-h9h7/GHSA-xm9f-jp6r-h9h7.json +++ b/advisories/unreviewed/2022/05/GHSA-xm9f-jp6r-h9h7/GHSA-xm9f-jp6r-h9h7.json @@ -7,12 +7,8 @@ "CVE-2009-3753" ], "details": "Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrcj-j2px-vg49/GHSA-xrcj-j2px-vg49.json b/advisories/unreviewed/2022/05/GHSA-xrcj-j2px-vg49/GHSA-xrcj-j2px-vg49.json index 275da47a29a..be73f6af03a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrcj-j2px-vg49/GHSA-xrcj-j2px-vg49.json +++ b/advisories/unreviewed/2022/05/GHSA-xrcj-j2px-vg49/GHSA-xrcj-j2px-vg49.json @@ -7,12 +7,8 @@ "CVE-2009-3382" ], "details": "layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xrqq-rjw2-jp5x/GHSA-xrqq-rjw2-jp5x.json b/advisories/unreviewed/2022/05/GHSA-xrqq-rjw2-jp5x/GHSA-xrqq-rjw2-jp5x.json index 936db5a741a..699bc1c0896 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrqq-rjw2-jp5x/GHSA-xrqq-rjw2-jp5x.json +++ b/advisories/unreviewed/2022/05/GHSA-xrqq-rjw2-jp5x/GHSA-xrqq-rjw2-jp5x.json @@ -7,12 +7,8 @@ "CVE-2009-3495" ], "details": "SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw2f-57pj-jjw5/GHSA-xw2f-57pj-jjw5.json b/advisories/unreviewed/2022/05/GHSA-xw2f-57pj-jjw5/GHSA-xw2f-57pj-jjw5.json index e649652496b..b928366f03a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw2f-57pj-jjw5/GHSA-xw2f-57pj-jjw5.json +++ b/advisories/unreviewed/2022/05/GHSA-xw2f-57pj-jjw5/GHSA-xw2f-57pj-jjw5.json @@ -7,12 +7,8 @@ "CVE-2009-3757" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xx29-p5f4-mwr8/GHSA-xx29-p5f4-mwr8.json b/advisories/unreviewed/2022/05/GHSA-xx29-p5f4-mwr8/GHSA-xx29-p5f4-mwr8.json index 95d0ea3b602..012537961a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx29-p5f4-mwr8/GHSA-xx29-p5f4-mwr8.json +++ b/advisories/unreviewed/2022/05/GHSA-xx29-p5f4-mwr8/GHSA-xx29-p5f4-mwr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxv2-p56v-rf8g/GHSA-xxv2-p56v-rf8g.json b/advisories/unreviewed/2022/05/GHSA-xxv2-p56v-rf8g/GHSA-xxv2-p56v-rf8g.json index 85f2abcc7d7..e24e07fa52a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxv2-p56v-rf8g/GHSA-xxv2-p56v-rf8g.json +++ b/advisories/unreviewed/2022/05/GHSA-xxv2-p56v-rf8g/GHSA-xxv2-p56v-rf8g.json @@ -7,12 +7,8 @@ "CVE-2009-3340" ], "details": "Unspecified vulnerability in FreeSSHD 1.2.4 allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-v9x5-7566-775w/GHSA-v9x5-7566-775w.json b/advisories/unreviewed/2022/08/GHSA-v9x5-7566-775w/GHSA-v9x5-7566-775w.json index b8d53632b76..2db35b0d5b5 100644 --- a/advisories/unreviewed/2022/08/GHSA-v9x5-7566-775w/GHSA-v9x5-7566-775w.json +++ b/advisories/unreviewed/2022/08/GHSA-v9x5-7566-775w/GHSA-v9x5-7566-775w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-4vrg-gm73-c852/GHSA-4vrg-gm73-c852.json b/advisories/unreviewed/2022/09/GHSA-4vrg-gm73-c852/GHSA-4vrg-gm73-c852.json index 7d22eed35a8..aab13de4453 100644 --- a/advisories/unreviewed/2022/09/GHSA-4vrg-gm73-c852/GHSA-4vrg-gm73-c852.json +++ b/advisories/unreviewed/2022/09/GHSA-4vrg-gm73-c852/GHSA-4vrg-gm73-c852.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json b/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json index 96479771eb4..b1a11331f79 100644 --- a/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json +++ b/advisories/unreviewed/2022/11/GHSA-cjp4-p28m-9gvx/GHSA-cjp4-p28m-9gvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mrh2-5fx2-7rv8/GHSA-mrh2-5fx2-7rv8.json b/advisories/unreviewed/2022/11/GHSA-mrh2-5fx2-7rv8/GHSA-mrh2-5fx2-7rv8.json index 74ef7a01921..2e202c6d893 100644 --- a/advisories/unreviewed/2022/11/GHSA-mrh2-5fx2-7rv8/GHSA-mrh2-5fx2-7rv8.json +++ b/advisories/unreviewed/2022/11/GHSA-mrh2-5fx2-7rv8/GHSA-mrh2-5fx2-7rv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4wvf-2vqw-mj6r/GHSA-4wvf-2vqw-mj6r.json b/advisories/unreviewed/2022/12/GHSA-4wvf-2vqw-mj6r/GHSA-4wvf-2vqw-mj6r.json index 624161d1647..9f60e1a81b7 100644 --- a/advisories/unreviewed/2022/12/GHSA-4wvf-2vqw-mj6r/GHSA-4wvf-2vqw-mj6r.json +++ b/advisories/unreviewed/2022/12/GHSA-4wvf-2vqw-mj6r/GHSA-4wvf-2vqw-mj6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-mqqf-3x7j-j33m/GHSA-mqqf-3x7j-j33m.json b/advisories/unreviewed/2022/12/GHSA-mqqf-3x7j-j33m/GHSA-mqqf-3x7j-j33m.json index ac7f668db49..e15b22596b8 100644 --- a/advisories/unreviewed/2022/12/GHSA-mqqf-3x7j-j33m/GHSA-mqqf-3x7j-j33m.json +++ b/advisories/unreviewed/2022/12/GHSA-mqqf-3x7j-j33m/GHSA-mqqf-3x7j-j33m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-c6qh-28m2-rfvf/GHSA-c6qh-28m2-rfvf.json b/advisories/unreviewed/2023/02/GHSA-c6qh-28m2-rfvf/GHSA-c6qh-28m2-rfvf.json index fdf9d7fdd6b..5472d9ac1bc 100644 --- a/advisories/unreviewed/2023/02/GHSA-c6qh-28m2-rfvf/GHSA-c6qh-28m2-rfvf.json +++ b/advisories/unreviewed/2023/02/GHSA-c6qh-28m2-rfvf/GHSA-c6qh-28m2-rfvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-gr7g-5rvj-cf96/GHSA-gr7g-5rvj-cf96.json b/advisories/unreviewed/2023/02/GHSA-gr7g-5rvj-cf96/GHSA-gr7g-5rvj-cf96.json index 87d3df1c3f3..94be39225aa 100644 --- a/advisories/unreviewed/2023/02/GHSA-gr7g-5rvj-cf96/GHSA-gr7g-5rvj-cf96.json +++ b/advisories/unreviewed/2023/02/GHSA-gr7g-5rvj-cf96/GHSA-gr7g-5rvj-cf96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-g658-w8fr-782c/GHSA-g658-w8fr-782c.json b/advisories/unreviewed/2023/03/GHSA-g658-w8fr-782c/GHSA-g658-w8fr-782c.json index 2ab700000c1..22826c11a4b 100644 --- a/advisories/unreviewed/2023/03/GHSA-g658-w8fr-782c/GHSA-g658-w8fr-782c.json +++ b/advisories/unreviewed/2023/03/GHSA-g658-w8fr-782c/GHSA-g658-w8fr-782c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json b/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json index dc6cae600b7..8f0a7b4dc84 100644 --- a/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json +++ b/advisories/unreviewed/2023/03/GHSA-mrcj-939x-ph52/GHSA-mrcj-939x-ph52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json b/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json index b8303453937..efa5c9030aa 100644 --- a/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json +++ b/advisories/unreviewed/2023/03/GHSA-p9xg-3j9r-v8jf/GHSA-p9xg-3j9r-v8jf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-rh9w-mh4f-p3x9/GHSA-rh9w-mh4f-p3x9.json b/advisories/unreviewed/2023/03/GHSA-rh9w-mh4f-p3x9/GHSA-rh9w-mh4f-p3x9.json index 1e72c8c7ac0..6401742edcb 100644 --- a/advisories/unreviewed/2023/03/GHSA-rh9w-mh4f-p3x9/GHSA-rh9w-mh4f-p3x9.json +++ b/advisories/unreviewed/2023/03/GHSA-rh9w-mh4f-p3x9/GHSA-rh9w-mh4f-p3x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json b/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json index 3b1677b3b7a..97eace375c4 100644 --- a/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json +++ b/advisories/unreviewed/2023/04/GHSA-2jm2-q946-gq54/GHSA-2jm2-q946-gq54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-3wfh-qwcv-pvx7/GHSA-3wfh-qwcv-pvx7.json b/advisories/unreviewed/2023/04/GHSA-3wfh-qwcv-pvx7/GHSA-3wfh-qwcv-pvx7.json index 4ad02669bbd..b082f1d8582 100644 --- a/advisories/unreviewed/2023/04/GHSA-3wfh-qwcv-pvx7/GHSA-3wfh-qwcv-pvx7.json +++ b/advisories/unreviewed/2023/04/GHSA-3wfh-qwcv-pvx7/GHSA-3wfh-qwcv-pvx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json b/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json index 51f2371d344..39593044c97 100644 --- a/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json +++ b/advisories/unreviewed/2023/04/GHSA-4rmp-wcvv-c8xm/GHSA-4rmp-wcvv-c8xm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json b/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json index 38147d33a9e..be55c2dbfe6 100644 --- a/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json +++ b/advisories/unreviewed/2023/04/GHSA-4x5j-gwp5-7hgh/GHSA-4x5j-gwp5-7hgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-5f37-m2hf-qphr/GHSA-5f37-m2hf-qphr.json b/advisories/unreviewed/2023/04/GHSA-5f37-m2hf-qphr/GHSA-5f37-m2hf-qphr.json index 771e5c58387..33e67163728 100644 --- a/advisories/unreviewed/2023/04/GHSA-5f37-m2hf-qphr/GHSA-5f37-m2hf-qphr.json +++ b/advisories/unreviewed/2023/04/GHSA-5f37-m2hf-qphr/GHSA-5f37-m2hf-qphr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json b/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json index a3947a1c4b3..a8df075edf1 100644 --- a/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json +++ b/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json b/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json index 92f816689c1..2b8249c7010 100644 --- a/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json +++ b/advisories/unreviewed/2023/04/GHSA-7rjh-2m62-75vm/GHSA-7rjh-2m62-75vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json b/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json index be801d89bf7..1768c36cf49 100644 --- a/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json +++ b/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json b/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json index 4767575b7f8..0861c5fd9a3 100644 --- a/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json +++ b/advisories/unreviewed/2023/04/GHSA-88w6-3m63-r5j7/GHSA-88w6-3m63-r5j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json b/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json index 78692f08ca6..c85c1908f6d 100644 --- a/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json +++ b/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json b/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json index 67fd42f501b..814922bef7c 100644 --- a/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json +++ b/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json b/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json index 477d8bf12a1..3c136ebbd2f 100644 --- a/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json +++ b/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json b/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json index b385f40f43c..a1a20edebda 100644 --- a/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json +++ b/advisories/unreviewed/2023/04/GHSA-c9fv-v7xm-mfrf/GHSA-c9fv-v7xm-mfrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json b/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json index d9123a17874..0001793017f 100644 --- a/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json +++ b/advisories/unreviewed/2023/04/GHSA-ch7j-864f-m7r5/GHSA-ch7j-864f-m7r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json b/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json index 1970fe60615..730310ef310 100644 --- a/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json +++ b/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json b/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json index 68b97353fa3..2b108316770 100644 --- a/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json +++ b/advisories/unreviewed/2023/04/GHSA-fcmf-jqfc-733w/GHSA-fcmf-jqfc-733w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json b/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json index cc06065b768..e9e6b84aa2d 100644 --- a/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json +++ b/advisories/unreviewed/2023/04/GHSA-g23c-4prh-q9fg/GHSA-g23c-4prh-q9fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json b/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json index b9a3d3abf34..731ea7eb54c 100644 --- a/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json +++ b/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json b/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json index c7b3b70560c..7a1f6a4bedd 100644 --- a/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json +++ b/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json b/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json index 806442351b1..84d5f3cb7a4 100644 --- a/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json +++ b/advisories/unreviewed/2023/04/GHSA-h639-737x-65xp/GHSA-h639-737x-65xp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json b/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json index 3d0734301f9..b421e6b01d3 100644 --- a/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json +++ b/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json b/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json index 4701670c788..5de3edbfa3a 100644 --- a/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json +++ b/advisories/unreviewed/2023/04/GHSA-m6x9-6mp2-f49x/GHSA-m6x9-6mp2-f49x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m928-3f5w-85qx/GHSA-m928-3f5w-85qx.json b/advisories/unreviewed/2023/04/GHSA-m928-3f5w-85qx/GHSA-m928-3f5w-85qx.json index 1b66507d036..464a692fbe0 100644 --- a/advisories/unreviewed/2023/04/GHSA-m928-3f5w-85qx/GHSA-m928-3f5w-85qx.json +++ b/advisories/unreviewed/2023/04/GHSA-m928-3f5w-85qx/GHSA-m928-3f5w-85qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json b/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json index 311fbea54ab..813c9676180 100644 --- a/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json +++ b/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json b/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json index 8942ecb0268..096ceee4b2b 100644 --- a/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json +++ b/advisories/unreviewed/2023/04/GHSA-ppr5-6jwg-4jm4/GHSA-ppr5-6jwg-4jm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json b/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json index 4587acc7974..7f3bb13d7a7 100644 --- a/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json +++ b/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json b/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json index 73414abc16f..2556c15f3e7 100644 --- a/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json +++ b/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json b/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json index fbc03c0b7a7..1355a8d9208 100644 --- a/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json +++ b/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-r6p9-mgqc-wrwp/GHSA-r6p9-mgqc-wrwp.json b/advisories/unreviewed/2023/04/GHSA-r6p9-mgqc-wrwp/GHSA-r6p9-mgqc-wrwp.json index b6d5ddbf0e6..04d00c9631c 100644 --- a/advisories/unreviewed/2023/04/GHSA-r6p9-mgqc-wrwp/GHSA-r6p9-mgqc-wrwp.json +++ b/advisories/unreviewed/2023/04/GHSA-r6p9-mgqc-wrwp/GHSA-r6p9-mgqc-wrwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json b/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json index 8d7141ed921..acab2305139 100644 --- a/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json +++ b/advisories/unreviewed/2023/04/GHSA-rff5-9cw2-46c6/GHSA-rff5-9cw2-46c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json b/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json index 8c78fdf1f9b..79a7a3cf22e 100644 --- a/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json +++ b/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json b/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json index e498bb89f9a..2557dbe484f 100644 --- a/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json +++ b/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json b/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json index a1b25394630..105aa142932 100644 --- a/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json +++ b/advisories/unreviewed/2023/04/GHSA-x57h-h95f-93cr/GHSA-x57h-h95f-93cr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json b/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json index 9923dac9a2a..812f20ecfe9 100644 --- a/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json +++ b/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-xq4j-j5qp-3mfq/GHSA-xq4j-j5qp-3mfq.json b/advisories/unreviewed/2023/04/GHSA-xq4j-j5qp-3mfq/GHSA-xq4j-j5qp-3mfq.json index 9ccdc97a1d4..b41f4f5d22e 100644 --- a/advisories/unreviewed/2023/04/GHSA-xq4j-j5qp-3mfq/GHSA-xq4j-j5qp-3mfq.json +++ b/advisories/unreviewed/2023/04/GHSA-xq4j-j5qp-3mfq/GHSA-xq4j-j5qp-3mfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-9942-rg4x-mcpv/GHSA-9942-rg4x-mcpv.json b/advisories/unreviewed/2023/05/GHSA-9942-rg4x-mcpv/GHSA-9942-rg4x-mcpv.json index 27c70a5f2dc..569b73adb89 100644 --- a/advisories/unreviewed/2023/05/GHSA-9942-rg4x-mcpv/GHSA-9942-rg4x-mcpv.json +++ b/advisories/unreviewed/2023/05/GHSA-9942-rg4x-mcpv/GHSA-9942-rg4x-mcpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-ffmm-jx9r-2g49/GHSA-ffmm-jx9r-2g49.json b/advisories/unreviewed/2023/05/GHSA-ffmm-jx9r-2g49/GHSA-ffmm-jx9r-2g49.json index 3c0d5542034..23ca949e734 100644 --- a/advisories/unreviewed/2023/05/GHSA-ffmm-jx9r-2g49/GHSA-ffmm-jx9r-2g49.json +++ b/advisories/unreviewed/2023/05/GHSA-ffmm-jx9r-2g49/GHSA-ffmm-jx9r-2g49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json b/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json index 5ca2bf0ecd5..71ec82f0982 100644 --- a/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json +++ b/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-4rvq-6825-fp99/GHSA-4rvq-6825-fp99.json b/advisories/unreviewed/2023/11/GHSA-4rvq-6825-fp99/GHSA-4rvq-6825-fp99.json index 3151c77751a..131991ceefd 100644 --- a/advisories/unreviewed/2023/11/GHSA-4rvq-6825-fp99/GHSA-4rvq-6825-fp99.json +++ b/advisories/unreviewed/2023/11/GHSA-4rvq-6825-fp99/GHSA-4rvq-6825-fp99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-38xm-rj5r-36vx/GHSA-38xm-rj5r-36vx.json b/advisories/unreviewed/2024/01/GHSA-38xm-rj5r-36vx/GHSA-38xm-rj5r-36vx.json index 074510535ae..64515ab72fa 100644 --- a/advisories/unreviewed/2024/01/GHSA-38xm-rj5r-36vx/GHSA-38xm-rj5r-36vx.json +++ b/advisories/unreviewed/2024/01/GHSA-38xm-rj5r-36vx/GHSA-38xm-rj5r-36vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-7qmq-34hq-j5mx/GHSA-7qmq-34hq-j5mx.json b/advisories/unreviewed/2024/01/GHSA-7qmq-34hq-j5mx/GHSA-7qmq-34hq-j5mx.json index 37ec87a8bf8..f62bb75d61c 100644 --- a/advisories/unreviewed/2024/01/GHSA-7qmq-34hq-j5mx/GHSA-7qmq-34hq-j5mx.json +++ b/advisories/unreviewed/2024/01/GHSA-7qmq-34hq-j5mx/GHSA-7qmq-34hq-j5mx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-9mx7-g5mq-8w76/GHSA-9mx7-g5mq-8w76.json b/advisories/unreviewed/2024/01/GHSA-9mx7-g5mq-8w76/GHSA-9mx7-g5mq-8w76.json index 229d9c57d51..b3be7398891 100644 --- a/advisories/unreviewed/2024/01/GHSA-9mx7-g5mq-8w76/GHSA-9mx7-g5mq-8w76.json +++ b/advisories/unreviewed/2024/01/GHSA-9mx7-g5mq-8w76/GHSA-9mx7-g5mq-8w76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-f6q2-w2qh-v5fp/GHSA-f6q2-w2qh-v5fp.json b/advisories/unreviewed/2024/01/GHSA-f6q2-w2qh-v5fp/GHSA-f6q2-w2qh-v5fp.json index 5ec711bf607..5b85e41353a 100644 --- a/advisories/unreviewed/2024/01/GHSA-f6q2-w2qh-v5fp/GHSA-f6q2-w2qh-v5fp.json +++ b/advisories/unreviewed/2024/01/GHSA-f6q2-w2qh-v5fp/GHSA-f6q2-w2qh-v5fp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-qphp-945f-h9m7/GHSA-qphp-945f-h9m7.json b/advisories/unreviewed/2024/01/GHSA-qphp-945f-h9m7/GHSA-qphp-945f-h9m7.json index e5494f76a06..54109d8531a 100644 --- a/advisories/unreviewed/2024/01/GHSA-qphp-945f-h9m7/GHSA-qphp-945f-h9m7.json +++ b/advisories/unreviewed/2024/01/GHSA-qphp-945f-h9m7/GHSA-qphp-945f-h9m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-r57r-jrhh-4x69/GHSA-r57r-jrhh-4x69.json b/advisories/unreviewed/2024/01/GHSA-r57r-jrhh-4x69/GHSA-r57r-jrhh-4x69.json index fbb507b80eb..cbdb551ea81 100644 --- a/advisories/unreviewed/2024/01/GHSA-r57r-jrhh-4x69/GHSA-r57r-jrhh-4x69.json +++ b/advisories/unreviewed/2024/01/GHSA-r57r-jrhh-4x69/GHSA-r57r-jrhh-4x69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-wfg2-9rj3-4vf4/GHSA-wfg2-9rj3-4vf4.json b/advisories/unreviewed/2024/01/GHSA-wfg2-9rj3-4vf4/GHSA-wfg2-9rj3-4vf4.json index 27959106859..00cf2562477 100644 --- a/advisories/unreviewed/2024/01/GHSA-wfg2-9rj3-4vf4/GHSA-wfg2-9rj3-4vf4.json +++ b/advisories/unreviewed/2024/01/GHSA-wfg2-9rj3-4vf4/GHSA-wfg2-9rj3-4vf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-xqqg-x653-vrx5/GHSA-xqqg-x653-vrx5.json b/advisories/unreviewed/2024/01/GHSA-xqqg-x653-vrx5/GHSA-xqqg-x653-vrx5.json index 1d2d6d3cfa8..f33ddbe3796 100644 --- a/advisories/unreviewed/2024/01/GHSA-xqqg-x653-vrx5/GHSA-xqqg-x653-vrx5.json +++ b/advisories/unreviewed/2024/01/GHSA-xqqg-x653-vrx5/GHSA-xqqg-x653-vrx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json b/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json index 1a5d7f2eb0f..32172780b94 100644 --- a/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json +++ b/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json @@ -7,12 +7,8 @@ "CVE-2023-48906" ], "details": "Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json b/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json index 9a12e25a0b5..71d6f655e13 100644 --- a/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json +++ b/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8v52-4x8q-99vg/GHSA-8v52-4x8q-99vg.json b/advisories/unreviewed/2024/04/GHSA-8v52-4x8q-99vg/GHSA-8v52-4x8q-99vg.json index e79661334e6..d06167b5d1d 100644 --- a/advisories/unreviewed/2024/04/GHSA-8v52-4x8q-99vg/GHSA-8v52-4x8q-99vg.json +++ b/advisories/unreviewed/2024/04/GHSA-8v52-4x8q-99vg/GHSA-8v52-4x8q-99vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-95fq-qfw9-w29v/GHSA-95fq-qfw9-w29v.json b/advisories/unreviewed/2024/04/GHSA-95fq-qfw9-w29v/GHSA-95fq-qfw9-w29v.json index 2f2a9efb730..2a0b3d6ea82 100644 --- a/advisories/unreviewed/2024/04/GHSA-95fq-qfw9-w29v/GHSA-95fq-qfw9-w29v.json +++ b/advisories/unreviewed/2024/04/GHSA-95fq-qfw9-w29v/GHSA-95fq-qfw9-w29v.json @@ -7,12 +7,8 @@ "CVE-2024-30864" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json b/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json index fd4b92a7440..de0ec5a3614 100644 --- a/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json +++ b/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json @@ -7,12 +7,8 @@ "CVE-2024-1526" ], "details": "The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x5jv-pxjq-575r/GHSA-x5jv-pxjq-575r.json b/advisories/unreviewed/2024/04/GHSA-x5jv-pxjq-575r/GHSA-x5jv-pxjq-575r.json index d72e8be7fee..c27db26e4e0 100644 --- a/advisories/unreviewed/2024/04/GHSA-x5jv-pxjq-575r/GHSA-x5jv-pxjq-575r.json +++ b/advisories/unreviewed/2024/04/GHSA-x5jv-pxjq-575r/GHSA-x5jv-pxjq-575r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json b/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json index 3900e5bfe56..b8a745a5ccf 100644 --- a/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json +++ b/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json b/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json index f668e88863c..3adfb4b998f 100644 --- a/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json +++ b/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json b/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json index 418396e2993..5c16b9ee409 100644 --- a/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json +++ b/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json b/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json index 15f07b8a438..a257fdb6bf1 100644 --- a/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json +++ b/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json b/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json index fe9eedb6be4..fc436f38b39 100644 --- a/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json +++ b/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json b/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json index a647e0072c8..cb3599dbd82 100644 --- a/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json +++ b/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json b/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json index c2fcc761bed..6a5d98280aa 100644 --- a/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json +++ b/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json b/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json index bf4613c3503..c9de7914ae5 100644 --- a/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json +++ b/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json b/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json index fe3a68cb1a3..40fd2e9e7d2 100644 --- a/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json +++ b/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json b/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json index 6f16093d343..6d29eebb7ee 100644 --- a/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json +++ b/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json b/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json index 48f582fa81a..e0a41c0e9b2 100644 --- a/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json +++ b/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json b/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json index 40193d9de13..2fb9fe366e5 100644 --- a/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json +++ b/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json b/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json index d3092c2cab8..e635aa8a173 100644 --- a/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json +++ b/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5qxq-95fv-whxm/GHSA-5qxq-95fv-whxm.json b/advisories/unreviewed/2024/08/GHSA-5qxq-95fv-whxm/GHSA-5qxq-95fv-whxm.json index 55194cab315..00631166470 100644 --- a/advisories/unreviewed/2024/08/GHSA-5qxq-95fv-whxm/GHSA-5qxq-95fv-whxm.json +++ b/advisories/unreviewed/2024/08/GHSA-5qxq-95fv-whxm/GHSA-5qxq-95fv-whxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5wfc-h7w4-43mx/GHSA-5wfc-h7w4-43mx.json b/advisories/unreviewed/2024/08/GHSA-5wfc-h7w4-43mx/GHSA-5wfc-h7w4-43mx.json index c7db9f27efb..0bbc0bf79e0 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wfc-h7w4-43mx/GHSA-5wfc-h7w4-43mx.json +++ b/advisories/unreviewed/2024/08/GHSA-5wfc-h7w4-43mx/GHSA-5wfc-h7w4-43mx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7pcw-pq39-gmc3/GHSA-7pcw-pq39-gmc3.json b/advisories/unreviewed/2024/08/GHSA-7pcw-pq39-gmc3/GHSA-7pcw-pq39-gmc3.json index 92ae5594bdd..3ae4b22b010 100644 --- a/advisories/unreviewed/2024/08/GHSA-7pcw-pq39-gmc3/GHSA-7pcw-pq39-gmc3.json +++ b/advisories/unreviewed/2024/08/GHSA-7pcw-pq39-gmc3/GHSA-7pcw-pq39-gmc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-8p8r-qjjp-c996/GHSA-8p8r-qjjp-c996.json b/advisories/unreviewed/2024/08/GHSA-8p8r-qjjp-c996/GHSA-8p8r-qjjp-c996.json index ae570b6c804..90dccf4a9b9 100644 --- a/advisories/unreviewed/2024/08/GHSA-8p8r-qjjp-c996/GHSA-8p8r-qjjp-c996.json +++ b/advisories/unreviewed/2024/08/GHSA-8p8r-qjjp-c996/GHSA-8p8r-qjjp-c996.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-8v9c-gh64-hq64/GHSA-8v9c-gh64-hq64.json b/advisories/unreviewed/2024/08/GHSA-8v9c-gh64-hq64/GHSA-8v9c-gh64-hq64.json index e2dc86d2428..de8b6d8b1da 100644 --- a/advisories/unreviewed/2024/08/GHSA-8v9c-gh64-hq64/GHSA-8v9c-gh64-hq64.json +++ b/advisories/unreviewed/2024/08/GHSA-8v9c-gh64-hq64/GHSA-8v9c-gh64-hq64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-9347-hgff-8mjv/GHSA-9347-hgff-8mjv.json b/advisories/unreviewed/2024/08/GHSA-9347-hgff-8mjv/GHSA-9347-hgff-8mjv.json index 285a37d2521..de1740beedb 100644 --- a/advisories/unreviewed/2024/08/GHSA-9347-hgff-8mjv/GHSA-9347-hgff-8mjv.json +++ b/advisories/unreviewed/2024/08/GHSA-9347-hgff-8mjv/GHSA-9347-hgff-8mjv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cfrq-8q2f-rp46/GHSA-cfrq-8q2f-rp46.json b/advisories/unreviewed/2024/08/GHSA-cfrq-8q2f-rp46/GHSA-cfrq-8q2f-rp46.json index bc4457334f9..c2b7259e067 100644 --- a/advisories/unreviewed/2024/08/GHSA-cfrq-8q2f-rp46/GHSA-cfrq-8q2f-rp46.json +++ b/advisories/unreviewed/2024/08/GHSA-cfrq-8q2f-rp46/GHSA-cfrq-8q2f-rp46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-f3wr-j648-3c97/GHSA-f3wr-j648-3c97.json b/advisories/unreviewed/2024/08/GHSA-f3wr-j648-3c97/GHSA-f3wr-j648-3c97.json index 230d8bce6fe..7ae22520180 100644 --- a/advisories/unreviewed/2024/08/GHSA-f3wr-j648-3c97/GHSA-f3wr-j648-3c97.json +++ b/advisories/unreviewed/2024/08/GHSA-f3wr-j648-3c97/GHSA-f3wr-j648-3c97.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-pmwj-r76w-m8f7/GHSA-pmwj-r76w-m8f7.json b/advisories/unreviewed/2024/08/GHSA-pmwj-r76w-m8f7/GHSA-pmwj-r76w-m8f7.json index 89975857a35..9aafb7e8f55 100644 --- a/advisories/unreviewed/2024/08/GHSA-pmwj-r76w-m8f7/GHSA-pmwj-r76w-m8f7.json +++ b/advisories/unreviewed/2024/08/GHSA-pmwj-r76w-m8f7/GHSA-pmwj-r76w-m8f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-q4pc-gw9h-vxg4/GHSA-q4pc-gw9h-vxg4.json b/advisories/unreviewed/2024/08/GHSA-q4pc-gw9h-vxg4/GHSA-q4pc-gw9h-vxg4.json index 3d5f0d8bf20..9d6a4779b4d 100644 --- a/advisories/unreviewed/2024/08/GHSA-q4pc-gw9h-vxg4/GHSA-q4pc-gw9h-vxg4.json +++ b/advisories/unreviewed/2024/08/GHSA-q4pc-gw9h-vxg4/GHSA-q4pc-gw9h-vxg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qvhh-qrj8-5g7c/GHSA-qvhh-qrj8-5g7c.json b/advisories/unreviewed/2024/08/GHSA-qvhh-qrj8-5g7c/GHSA-qvhh-qrj8-5g7c.json index 53b64fa762c..a5773ee3bbc 100644 --- a/advisories/unreviewed/2024/08/GHSA-qvhh-qrj8-5g7c/GHSA-qvhh-qrj8-5g7c.json +++ b/advisories/unreviewed/2024/08/GHSA-qvhh-qrj8-5g7c/GHSA-qvhh-qrj8-5g7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json b/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json index 7c310a3f07e..9ad12ec6b23 100644 --- a/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json +++ b/advisories/unreviewed/2024/08/GHSA-rc6x-q5fh-8f53/GHSA-rc6x-q5fh-8f53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rc9p-g2q3-x488/GHSA-rc9p-g2q3-x488.json b/advisories/unreviewed/2024/08/GHSA-rc9p-g2q3-x488/GHSA-rc9p-g2q3-x488.json index 600caa25b36..19f56e57a3a 100644 --- a/advisories/unreviewed/2024/08/GHSA-rc9p-g2q3-x488/GHSA-rc9p-g2q3-x488.json +++ b/advisories/unreviewed/2024/08/GHSA-rc9p-g2q3-x488/GHSA-rc9p-g2q3-x488.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json b/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json index 954b25845c1..6825b725383 100644 --- a/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json +++ b/advisories/unreviewed/2024/08/GHSA-v382-g65v-f2p8/GHSA-v382-g65v-f2p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-w58g-789j-fj58/GHSA-w58g-789j-fj58.json b/advisories/unreviewed/2024/08/GHSA-w58g-789j-fj58/GHSA-w58g-789j-fj58.json index 416c501567b..4ab6fd40922 100644 --- a/advisories/unreviewed/2024/08/GHSA-w58g-789j-fj58/GHSA-w58g-789j-fj58.json +++ b/advisories/unreviewed/2024/08/GHSA-w58g-789j-fj58/GHSA-w58g-789j-fj58.json @@ -7,12 +7,8 @@ "CVE-2024-45193" ], "details": "An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-xxr7-33fp-84c2/GHSA-xxr7-33fp-84c2.json b/advisories/unreviewed/2024/08/GHSA-xxr7-33fp-84c2/GHSA-xxr7-33fp-84c2.json index 439dc0268c2..3a8cd39b8d6 100644 --- a/advisories/unreviewed/2024/08/GHSA-xxr7-33fp-84c2/GHSA-xxr7-33fp-84c2.json +++ b/advisories/unreviewed/2024/08/GHSA-xxr7-33fp-84c2/GHSA-xxr7-33fp-84c2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",