From 427dbd977d600037acbb49efcf4d402b6c184bee Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 30 Nov 2024 05:17:05 +0000 Subject: [PATCH] Advisory Database Sync --- .../05/GHSA-rp7r-79rm-2758/GHSA-rp7r-79rm-2758.json | 4 +--- .../01/GHSA-4r2f-6fm9-2qgh/GHSA-4r2f-6fm9-2qgh.json | 4 +--- .../02/GHSA-26cp-j78f-2568/GHSA-26cp-j78f-2568.json | 8 ++------ .../02/GHSA-2gx5-p7gf-5xrc/GHSA-2gx5-p7gf-5xrc.json | 8 ++------ .../02/GHSA-3jrq-4wj8-868w/GHSA-3jrq-4wj8-868w.json | 8 ++------ .../02/GHSA-3v6x-9jmh-gp3w/GHSA-3v6x-9jmh-gp3w.json | 8 ++------ .../02/GHSA-4m96-r76q-68qp/GHSA-4m96-r76q-68qp.json | 8 ++------ .../02/GHSA-4x25-3w8p-m6r3/GHSA-4x25-3w8p-m6r3.json | 8 ++------ .../02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json | 8 ++------ .../02/GHSA-686w-6g2q-xqqm/GHSA-686w-6g2q-xqqm.json | 4 +--- .../02/GHSA-6929-2rrj-qg4c/GHSA-6929-2rrj-qg4c.json | 4 +--- .../02/GHSA-6h65-gfvx-7g45/GHSA-6h65-gfvx-7g45.json | 4 +--- .../02/GHSA-6hfv-x97p-vvg3/GHSA-6hfv-x97p-vvg3.json | 8 ++------ .../02/GHSA-88wr-wm4j-qgww/GHSA-88wr-wm4j-qgww.json | 4 +--- .../02/GHSA-8cwr-c3m7-p68g/GHSA-8cwr-c3m7-p68g.json | 4 +--- .../02/GHSA-95j3-jpcx-676c/GHSA-95j3-jpcx-676c.json | 4 +--- .../02/GHSA-9jrj-j4fv-jrw5/GHSA-9jrj-j4fv-jrw5.json | 4 +--- .../02/GHSA-c687-vfr7-48m9/GHSA-c687-vfr7-48m9.json | 4 +--- .../02/GHSA-c7h9-7hmq-v389/GHSA-c7h9-7hmq-v389.json | 4 +--- .../02/GHSA-fpv7-mhhr-h93x/GHSA-fpv7-mhhr-h93x.json | 4 +--- .../02/GHSA-g8ch-3jp7-hcm8/GHSA-g8ch-3jp7-hcm8.json | 8 ++------ .../02/GHSA-gh6g-9qgj-hq8v/GHSA-gh6g-9qgj-hq8v.json | 4 +--- .../02/GHSA-gw5x-mfp3-c35v/GHSA-gw5x-mfp3-c35v.json | 4 +--- .../02/GHSA-h874-8cgj-mc28/GHSA-h874-8cgj-mc28.json | 4 +--- .../02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json | 4 +--- .../02/GHSA-j2hv-f29h-c9g3/GHSA-j2hv-f29h-c9g3.json | 4 +--- .../02/GHSA-jfq8-f4p4-5mpx/GHSA-jfq8-f4p4-5mpx.json | 8 ++------ .../02/GHSA-m3mj-2hwv-qf3q/GHSA-m3mj-2hwv-qf3q.json | 4 +--- .../02/GHSA-m6c9-29mj-cjh4/GHSA-m6c9-29mj-cjh4.json | 4 +--- .../02/GHSA-m74m-wrhv-h6gc/GHSA-m74m-wrhv-h6gc.json | 4 +--- .../02/GHSA-p64x-c79m-m5mv/GHSA-p64x-c79m-m5mv.json | 4 +--- .../02/GHSA-ph25-g94c-mv3m/GHSA-ph25-g94c-mv3m.json | 4 +--- .../02/GHSA-phcp-hchw-q7wq/GHSA-phcp-hchw-q7wq.json | 4 +--- .../02/GHSA-q95j-mchg-p72p/GHSA-q95j-mchg-p72p.json | 8 ++------ .../02/GHSA-r8hj-jj45-xp7m/GHSA-r8hj-jj45-xp7m.json | 8 ++------ .../02/GHSA-rw8g-79g2-chq8/GHSA-rw8g-79g2-chq8.json | 8 ++------ .../02/GHSA-v486-mqfx-fv74/GHSA-v486-mqfx-fv74.json | 4 +--- .../02/GHSA-v84f-rwh8-v99h/GHSA-v84f-rwh8-v99h.json | 4 +--- .../02/GHSA-x6gv-8c9f-6r64/GHSA-x6gv-8c9f-6r64.json | 4 +--- .../05/GHSA-22m9-jhmf-fc7x/GHSA-22m9-jhmf-fc7x.json | 12 +++--------- .../05/GHSA-22wh-wq8h-xvf8/GHSA-22wh-wq8h-xvf8.json | 4 +--- .../05/GHSA-2334-4qc6-g6xv/GHSA-2334-4qc6-g6xv.json | 12 +++--------- .../05/GHSA-233r-fgcw-c6hw/GHSA-233r-fgcw-c6hw.json | 8 ++------ .../05/GHSA-2382-6vwc-h973/GHSA-2382-6vwc-h973.json | 8 ++------ .../05/GHSA-23f8-9p2x-67mg/GHSA-23f8-9p2x-67mg.json | 8 ++------ .../05/GHSA-23hc-wwmg-vgj2/GHSA-23hc-wwmg-vgj2.json | 12 +++--------- .../05/GHSA-23ph-6jx4-8p78/GHSA-23ph-6jx4-8p78.json | 12 +++--------- .../05/GHSA-23pj-4543-5g2f/GHSA-23pj-4543-5g2f.json | 4 +--- .../05/GHSA-23v9-8jvm-jh7q/GHSA-23v9-8jvm-jh7q.json | 4 +--- .../05/GHSA-243w-cr2g-7p8m/GHSA-243w-cr2g-7p8m.json | 8 ++------ .../05/GHSA-24rw-g98m-23fg/GHSA-24rw-g98m-23fg.json | 12 +++--------- .../05/GHSA-24xx-ff7h-g5rx/GHSA-24xx-ff7h-g5rx.json | 12 +++--------- .../05/GHSA-254f-c2wq-r664/GHSA-254f-c2wq-r664.json | 8 ++------ .../05/GHSA-25c5-5c5w-53xq/GHSA-25c5-5c5w-53xq.json | 12 +++--------- .../05/GHSA-25m9-4f22-2chr/GHSA-25m9-4f22-2chr.json | 8 ++------ .../05/GHSA-26c8-846h-xfjj/GHSA-26c8-846h-xfjj.json | 8 ++------ .../05/GHSA-26mp-rrff-g438/GHSA-26mp-rrff-g438.json | 8 ++------ .../05/GHSA-274j-j2jx-h7hf/GHSA-274j-j2jx-h7hf.json | 8 ++------ .../05/GHSA-27f3-4xcg-9c5m/GHSA-27f3-4xcg-9c5m.json | 12 +++--------- .../05/GHSA-27g9-862v-hv97/GHSA-27g9-862v-hv97.json | 12 +++--------- .../05/GHSA-282v-8gf3-6m78/GHSA-282v-8gf3-6m78.json | 12 +++--------- .../05/GHSA-28h9-hh7q-86j5/GHSA-28h9-hh7q-86j5.json | 12 +++--------- .../05/GHSA-28xr-x3rf-rhgr/GHSA-28xr-x3rf-rhgr.json | 12 +++--------- .../05/GHSA-29q2-x88c-692h/GHSA-29q2-x88c-692h.json | 8 ++------ .../05/GHSA-2ccq-96qh-p2c5/GHSA-2ccq-96qh-p2c5.json | 8 ++------ .../05/GHSA-2cf9-pjvx-rp3q/GHSA-2cf9-pjvx-rp3q.json | 12 +++--------- .../05/GHSA-2cr4-q4vr-2q6r/GHSA-2cr4-q4vr-2q6r.json | 8 ++------ .../05/GHSA-2cvc-v88v-w533/GHSA-2cvc-v88v-w533.json | 8 ++------ .../05/GHSA-2ffw-7qmf-mjg7/GHSA-2ffw-7qmf-mjg7.json | 8 ++------ .../05/GHSA-2fv9-9wxv-5vmh/GHSA-2fv9-9wxv-5vmh.json | 12 +++--------- .../05/GHSA-2h74-xcwf-23j7/GHSA-2h74-xcwf-23j7.json | 8 ++------ .../05/GHSA-2h9v-34wh-2q7g/GHSA-2h9v-34wh-2q7g.json | 8 ++------ .../05/GHSA-2mjq-2vv9-22pp/GHSA-2mjq-2vv9-22pp.json | 12 +++--------- .../05/GHSA-2p5c-r4xc-mhvw/GHSA-2p5c-r4xc-mhvw.json | 8 ++------ .../05/GHSA-2q4g-fw9r-2xxm/GHSA-2q4g-fw9r-2xxm.json | 12 +++--------- .../05/GHSA-2qff-4q86-c9p7/GHSA-2qff-4q86-c9p7.json | 12 +++--------- .../05/GHSA-2v2m-m9xc-2hp5/GHSA-2v2m-m9xc-2hp5.json | 12 +++--------- .../05/GHSA-2v73-62r7-82cv/GHSA-2v73-62r7-82cv.json | 8 ++------ .../05/GHSA-2vpj-c9hx-wv3q/GHSA-2vpj-c9hx-wv3q.json | 8 ++------ .../05/GHSA-2w2j-gfqg-fwgm/GHSA-2w2j-gfqg-fwgm.json | 8 ++------ .../05/GHSA-2wpp-hvf7-v98x/GHSA-2wpp-hvf7-v98x.json | 12 +++--------- .../05/GHSA-2wwq-c24x-xw9j/GHSA-2wwq-c24x-xw9j.json | 12 +++--------- .../05/GHSA-2xg8-gc3x-5wm4/GHSA-2xg8-gc3x-5wm4.json | 12 +++--------- .../05/GHSA-32gf-9929-gmj6/GHSA-32gf-9929-gmj6.json | 8 ++------ .../05/GHSA-333w-grm8-fgcg/GHSA-333w-grm8-fgcg.json | 8 ++------ .../05/GHSA-3367-6xxj-j9cg/GHSA-3367-6xxj-j9cg.json | 8 ++------ .../05/GHSA-3383-3582-42x2/GHSA-3383-3582-42x2.json | 8 ++------ .../05/GHSA-33fh-cmjr-7j9h/GHSA-33fh-cmjr-7j9h.json | 12 +++--------- .../05/GHSA-33v9-9rxf-3675/GHSA-33v9-9rxf-3675.json | 8 ++------ .../05/GHSA-353p-pq7h-22q6/GHSA-353p-pq7h-22q6.json | 12 +++--------- .../05/GHSA-35q7-q9hg-r69q/GHSA-35q7-q9hg-r69q.json | 12 +++--------- .../05/GHSA-35x5-8hjg-m53r/GHSA-35x5-8hjg-m53r.json | 8 ++------ .../05/GHSA-36hv-f25w-387h/GHSA-36hv-f25w-387h.json | 8 ++------ .../05/GHSA-36j5-c4mc-2jx6/GHSA-36j5-c4mc-2jx6.json | 12 +++--------- .../05/GHSA-3774-9hfm-h8pq/GHSA-3774-9hfm-h8pq.json | 8 ++------ .../05/GHSA-3782-4pq4-qwj2/GHSA-3782-4pq4-qwj2.json | 8 ++------ .../05/GHSA-378c-qrcg-vgq7/GHSA-378c-qrcg-vgq7.json | 8 ++------ .../05/GHSA-37f5-m753-pjhv/GHSA-37f5-m753-pjhv.json | 8 ++------ .../05/GHSA-37x4-xj4c-2664/GHSA-37x4-xj4c-2664.json | 12 +++--------- .../05/GHSA-382p-crwp-jf65/GHSA-382p-crwp-jf65.json | 8 ++------ .../05/GHSA-388x-f5qm-fvjg/GHSA-388x-f5qm-fvjg.json | 4 +--- .../05/GHSA-3897-x777-pgxc/GHSA-3897-x777-pgxc.json | 12 +++--------- .../05/GHSA-38fh-px4j-r2wx/GHSA-38fh-px4j-r2wx.json | 12 +++--------- .../05/GHSA-38h6-xf6r-fw6f/GHSA-38h6-xf6r-fw6f.json | 12 +++--------- .../05/GHSA-3932-qm3c-m9h6/GHSA-3932-qm3c-m9h6.json | 12 +++--------- .../05/GHSA-3c3m-qp4j-mgv8/GHSA-3c3m-qp4j-mgv8.json | 8 ++------ .../05/GHSA-3c52-7j8w-6f87/GHSA-3c52-7j8w-6f87.json | 8 ++------ .../05/GHSA-3cpr-wjhh-6mx6/GHSA-3cpr-wjhh-6mx6.json | 12 +++--------- .../05/GHSA-3cqf-cqxx-qphr/GHSA-3cqf-cqxx-qphr.json | 12 +++--------- .../05/GHSA-3crh-wfw6-p5f9/GHSA-3crh-wfw6-p5f9.json | 12 +++--------- .../05/GHSA-3f6p-4492-5fc4/GHSA-3f6p-4492-5fc4.json | 12 +++--------- .../05/GHSA-3f78-c2v3-p2xx/GHSA-3f78-c2v3-p2xx.json | 12 +++--------- .../05/GHSA-3fvf-wxcf-7v9q/GHSA-3fvf-wxcf-7v9q.json | 8 ++------ .../05/GHSA-3gjc-qgpj-p9mw/GHSA-3gjc-qgpj-p9mw.json | 8 ++------ .../05/GHSA-3gwm-cv7f-hm83/GHSA-3gwm-cv7f-hm83.json | 12 +++--------- .../05/GHSA-3gx3-vcjc-vm83/GHSA-3gx3-vcjc-vm83.json | 12 +++--------- .../05/GHSA-3hcq-vq68-gcc7/GHSA-3hcq-vq68-gcc7.json | 8 ++------ .../05/GHSA-3hh7-4gv3-gf58/GHSA-3hh7-4gv3-gf58.json | 12 +++--------- .../05/GHSA-3jf2-2rp2-p843/GHSA-3jf2-2rp2-p843.json | 12 +++--------- .../05/GHSA-3jh4-vm9g-v8q4/GHSA-3jh4-vm9g-v8q4.json | 8 ++------ .../05/GHSA-3m23-m58c-wrv4/GHSA-3m23-m58c-wrv4.json | 8 ++------ .../05/GHSA-3mc5-w7jh-66fj/GHSA-3mc5-w7jh-66fj.json | 12 +++--------- .../05/GHSA-3p4h-535g-5qjf/GHSA-3p4h-535g-5qjf.json | 8 ++------ .../05/GHSA-3p7q-wxm4-v8fp/GHSA-3p7q-wxm4-v8fp.json | 8 ++------ .../05/GHSA-3php-qpv3-6pw7/GHSA-3php-qpv3-6pw7.json | 12 +++--------- .../05/GHSA-3q58-fh6p-m7jw/GHSA-3q58-fh6p-m7jw.json | 12 +++--------- .../05/GHSA-3qqp-v6v2-x8v6/GHSA-3qqp-v6v2-x8v6.json | 8 ++------ .../05/GHSA-3qwx-85qr-mvqm/GHSA-3qwx-85qr-mvqm.json | 12 +++--------- .../05/GHSA-3r4j-6mx6-f47q/GHSA-3r4j-6mx6-f47q.json | 12 +++--------- .../05/GHSA-3rfh-rcxw-3xxf/GHSA-3rfh-rcxw-3xxf.json | 8 ++------ .../05/GHSA-3rhf-q6c8-mqq2/GHSA-3rhf-q6c8-mqq2.json | 8 ++------ .../05/GHSA-3rm9-4vp3-9x4r/GHSA-3rm9-4vp3-9x4r.json | 12 +++--------- .../05/GHSA-3rrr-cqqf-5xqm/GHSA-3rrr-cqqf-5xqm.json | 12 +++--------- .../05/GHSA-3v6h-ww3h-9h87/GHSA-3v6h-ww3h-9h87.json | 8 ++------ .../05/GHSA-3vhg-jg9c-c6r7/GHSA-3vhg-jg9c-c6r7.json | 4 +--- .../05/GHSA-3vq4-8jw3-cwr6/GHSA-3vq4-8jw3-cwr6.json | 8 ++------ .../05/GHSA-3vx6-hqv4-9pr7/GHSA-3vx6-hqv4-9pr7.json | 12 +++--------- .../05/GHSA-3x85-87vg-8622/GHSA-3x85-87vg-8622.json | 12 +++--------- .../05/GHSA-42pp-ccmj-xrg8/GHSA-42pp-ccmj-xrg8.json | 12 +++--------- .../05/GHSA-42xm-24j2-64jf/GHSA-42xm-24j2-64jf.json | 12 +++--------- .../05/GHSA-4387-c242-fcj2/GHSA-4387-c242-fcj2.json | 8 ++------ .../05/GHSA-438g-9pr9-j76p/GHSA-438g-9pr9-j76p.json | 12 +++--------- .../05/GHSA-439v-qhv3-9f5x/GHSA-439v-qhv3-9f5x.json | 8 ++------ .../05/GHSA-43mr-gg87-qwf3/GHSA-43mr-gg87-qwf3.json | 8 ++------ .../05/GHSA-442p-f25m-xr85/GHSA-442p-f25m-xr85.json | 8 ++------ .../05/GHSA-446j-vwvf-m2wj/GHSA-446j-vwvf-m2wj.json | 8 ++------ .../05/GHSA-4482-cr2p-675v/GHSA-4482-cr2p-675v.json | 12 +++--------- .../05/GHSA-44hp-8f85-hjrw/GHSA-44hp-8f85-hjrw.json | 12 +++--------- .../05/GHSA-44m9-8fq6-h94w/GHSA-44m9-8fq6-h94w.json | 8 ++------ .../05/GHSA-45v3-cf2w-246x/GHSA-45v3-cf2w-246x.json | 8 ++------ .../05/GHSA-4677-48q7-5jfp/GHSA-4677-48q7-5jfp.json | 12 +++--------- .../05/GHSA-4694-6229-fx5x/GHSA-4694-6229-fx5x.json | 12 +++--------- .../05/GHSA-479c-w72f-jfxf/GHSA-479c-w72f-jfxf.json | 12 +++--------- .../05/GHSA-48m3-fp26-hqqw/GHSA-48m3-fp26-hqqw.json | 12 +++--------- .../05/GHSA-48q8-3ggg-p434/GHSA-48q8-3ggg-p434.json | 12 +++--------- .../05/GHSA-495h-g8p3-vvq5/GHSA-495h-g8p3-vvq5.json | 8 ++------ .../05/GHSA-498v-8jr7-2hv8/GHSA-498v-8jr7-2hv8.json | 12 +++--------- .../05/GHSA-49j8-5rc9-gjc6/GHSA-49j8-5rc9-gjc6.json | 8 ++------ .../05/GHSA-49v3-47vp-q76c/GHSA-49v3-47vp-q76c.json | 8 ++------ .../05/GHSA-4c2f-99wj-9wvv/GHSA-4c2f-99wj-9wvv.json | 12 +++--------- .../05/GHSA-4cg6-r453-9frw/GHSA-4cg6-r453-9frw.json | 12 +++--------- .../05/GHSA-4cm7-26hr-cjq7/GHSA-4cm7-26hr-cjq7.json | 8 ++------ .../05/GHSA-4crx-48p2-6mjx/GHSA-4crx-48p2-6mjx.json | 8 ++------ .../05/GHSA-4cx3-gvx4-j3wg/GHSA-4cx3-gvx4-j3wg.json | 8 ++------ .../05/GHSA-4f93-cwh7-v69v/GHSA-4f93-cwh7-v69v.json | 8 ++------ .../05/GHSA-4g5r-47p7-6qm4/GHSA-4g5r-47p7-6qm4.json | 12 +++--------- .../05/GHSA-4g64-jfhc-95g2/GHSA-4g64-jfhc-95g2.json | 8 ++------ .../05/GHSA-4g6c-jv87-fj3x/GHSA-4g6c-jv87-fj3x.json | 8 ++------ .../05/GHSA-4grv-jw7c-q92p/GHSA-4grv-jw7c-q92p.json | 12 +++--------- .../05/GHSA-4h7j-8cv2-jpwj/GHSA-4h7j-8cv2-jpwj.json | 12 +++--------- .../05/GHSA-4hmg-5gr9-qvqw/GHSA-4hmg-5gr9-qvqw.json | 12 +++--------- .../05/GHSA-4hqw-3ggw-h3m4/GHSA-4hqw-3ggw-h3m4.json | 8 ++------ .../05/GHSA-4hv4-q965-54rg/GHSA-4hv4-q965-54rg.json | 8 ++------ .../05/GHSA-4j8h-3qv8-5cpm/GHSA-4j8h-3qv8-5cpm.json | 12 +++--------- .../05/GHSA-4mc9-vgjj-p3v5/GHSA-4mc9-vgjj-p3v5.json | 4 +--- .../05/GHSA-4mf2-c3h2-mq3p/GHSA-4mf2-c3h2-mq3p.json | 8 ++------ .../05/GHSA-4p7q-px7w-p3p9/GHSA-4p7q-px7w-p3p9.json | 8 ++------ .../05/GHSA-4p9w-rqv4-74j3/GHSA-4p9w-rqv4-74j3.json | 12 +++--------- .../05/GHSA-4q7p-3266-2mj7/GHSA-4q7p-3266-2mj7.json | 12 +++--------- .../05/GHSA-4q8v-hwx2-8gc2/GHSA-4q8v-hwx2-8gc2.json | 8 ++------ .../05/GHSA-4r52-ff3g-g952/GHSA-4r52-ff3g-g952.json | 12 +++--------- .../05/GHSA-4rj4-mjp8-mcgg/GHSA-4rj4-mjp8-mcgg.json | 12 +++--------- .../05/GHSA-4rx4-97jg-645p/GHSA-4rx4-97jg-645p.json | 12 +++--------- .../05/GHSA-4v3v-2c52-v3v9/GHSA-4v3v-2c52-v3v9.json | 8 ++------ .../05/GHSA-4wgh-rg45-9q3p/GHSA-4wgh-rg45-9q3p.json | 4 +--- .../05/GHSA-4wgj-77qr-7qgf/GHSA-4wgj-77qr-7qgf.json | 8 ++------ .../05/GHSA-52rv-hwx6-25rg/GHSA-52rv-hwx6-25rg.json | 12 +++--------- .../05/GHSA-537f-w6wj-gphx/GHSA-537f-w6wj-gphx.json | 8 ++------ .../05/GHSA-53f4-27hf-367h/GHSA-53f4-27hf-367h.json | 12 +++--------- .../05/GHSA-53h7-vpr4-87w8/GHSA-53h7-vpr4-87w8.json | 8 ++------ .../05/GHSA-542c-p7pq-534w/GHSA-542c-p7pq-534w.json | 8 ++------ .../05/GHSA-54pm-xxpg-8wgg/GHSA-54pm-xxpg-8wgg.json | 12 +++--------- .../05/GHSA-5523-jhw7-49q2/GHSA-5523-jhw7-49q2.json | 12 +++--------- .../05/GHSA-5656-pvjm-rmvr/GHSA-5656-pvjm-rmvr.json | 8 ++------ .../05/GHSA-56rm-phj6-xx36/GHSA-56rm-phj6-xx36.json | 8 ++------ .../05/GHSA-572w-75xw-3g5f/GHSA-572w-75xw-3g5f.json | 8 ++------ .../05/GHSA-573h-c24j-7p83/GHSA-573h-c24j-7p83.json | 8 ++------ .../05/GHSA-57j8-fw4m-qrrv/GHSA-57j8-fw4m-qrrv.json | 12 +++--------- .../05/GHSA-587q-w3p6-m55g/GHSA-587q-w3p6-m55g.json | 8 ++------ .../05/GHSA-58j9-3frf-c53r/GHSA-58j9-3frf-c53r.json | 8 ++------ .../05/GHSA-58qh-2fp2-v597/GHSA-58qh-2fp2-v597.json | 8 ++------ .../05/GHSA-593w-pcpp-m35w/GHSA-593w-pcpp-m35w.json | 12 +++--------- .../05/GHSA-59mh-243q-3prc/GHSA-59mh-243q-3prc.json | 8 ++------ .../05/GHSA-59r2-367p-xv4j/GHSA-59r2-367p-xv4j.json | 8 ++------ .../05/GHSA-5cg2-qm4w-wc65/GHSA-5cg2-qm4w-wc65.json | 12 +++--------- .../05/GHSA-5cqf-vv6j-6f4g/GHSA-5cqf-vv6j-6f4g.json | 4 +--- .../05/GHSA-5cv6-f7pr-xhrj/GHSA-5cv6-f7pr-xhrj.json | 8 ++------ .../05/GHSA-5f76-6475-7p9f/GHSA-5f76-6475-7p9f.json | 12 +++--------- .../05/GHSA-5fcm-588g-hv9p/GHSA-5fcm-588g-hv9p.json | 8 ++------ .../05/GHSA-5h3v-8m6q-48c4/GHSA-5h3v-8m6q-48c4.json | 4 +--- .../05/GHSA-5hqx-qwqq-6xmq/GHSA-5hqx-qwqq-6xmq.json | 8 ++------ .../05/GHSA-5jg4-gfhx-2rxm/GHSA-5jg4-gfhx-2rxm.json | 12 +++--------- .../05/GHSA-5mg8-9hx2-j7wf/GHSA-5mg8-9hx2-j7wf.json | 8 ++------ .../05/GHSA-5mgj-p8j2-rqx8/GHSA-5mgj-p8j2-rqx8.json | 8 ++------ .../05/GHSA-5p8c-8g3r-93fc/GHSA-5p8c-8g3r-93fc.json | 8 ++------ .../05/GHSA-5pc5-6r92-7p4x/GHSA-5pc5-6r92-7p4x.json | 12 +++--------- .../05/GHSA-5pcv-vxh7-3wg6/GHSA-5pcv-vxh7-3wg6.json | 8 ++------ .../05/GHSA-5phc-r9q3-639w/GHSA-5phc-r9q3-639w.json | 8 ++------ .../05/GHSA-5q7c-4cgc-gvcr/GHSA-5q7c-4cgc-gvcr.json | 12 +++--------- .../05/GHSA-5qh7-579r-4mp6/GHSA-5qh7-579r-4mp6.json | 8 ++------ .../05/GHSA-5r8p-h2wh-wvq8/GHSA-5r8p-h2wh-wvq8.json | 4 +--- .../05/GHSA-5v3j-6p4g-6p7m/GHSA-5v3j-6p4g-6p7m.json | 8 ++------ .../05/GHSA-5vc2-jrh2-gp8m/GHSA-5vc2-jrh2-gp8m.json | 8 ++------ .../05/GHSA-5w93-h7pq-72x6/GHSA-5w93-h7pq-72x6.json | 12 +++--------- .../05/GHSA-5wfx-xq56-qfv3/GHSA-5wfx-xq56-qfv3.json | 12 +++--------- .../05/GHSA-5wjp-4jpf-wmfh/GHSA-5wjp-4jpf-wmfh.json | 8 ++------ .../05/GHSA-5xf5-q9cr-gp59/GHSA-5xf5-q9cr-gp59.json | 8 ++------ .../05/GHSA-5xqj-h7c6-6746/GHSA-5xqj-h7c6-6746.json | 12 +++--------- .../05/GHSA-5xr9-4m9g-r278/GHSA-5xr9-4m9g-r278.json | 8 ++------ .../05/GHSA-62mh-7jc4-wf35/GHSA-62mh-7jc4-wf35.json | 8 ++------ .../05/GHSA-62mx-7v7h-w2g7/GHSA-62mx-7v7h-w2g7.json | 12 +++--------- .../05/GHSA-639r-p248-76hj/GHSA-639r-p248-76hj.json | 8 ++------ .../05/GHSA-63qq-8356-xpg6/GHSA-63qq-8356-xpg6.json | 8 ++------ .../05/GHSA-6465-hj2g-hj5x/GHSA-6465-hj2g-hj5x.json | 12 +++--------- .../05/GHSA-64pc-839w-44v4/GHSA-64pc-839w-44v4.json | 12 +++--------- .../05/GHSA-65mh-gj85-793w/GHSA-65mh-gj85-793w.json | 12 +++--------- .../05/GHSA-65wj-75vm-6g3g/GHSA-65wj-75vm-6g3g.json | 12 +++--------- .../05/GHSA-664f-hg94-2f9v/GHSA-664f-hg94-2f9v.json | 12 +++--------- .../05/GHSA-66cc-pqrw-3whx/GHSA-66cc-pqrw-3whx.json | 12 +++--------- .../05/GHSA-675m-x238-3mpf/GHSA-675m-x238-3mpf.json | 12 +++--------- .../05/GHSA-6767-7pjf-mxgf/GHSA-6767-7pjf-mxgf.json | 8 ++------ .../05/GHSA-67vg-8r27-8fjh/GHSA-67vg-8r27-8fjh.json | 8 ++------ .../05/GHSA-67xm-gwvc-jw56/GHSA-67xm-gwvc-jw56.json | 12 +++--------- .../05/GHSA-68gc-6j2c-jr3m/GHSA-68gc-6j2c-jr3m.json | 8 ++------ .../05/GHSA-68r9-qhv3-7fgg/GHSA-68r9-qhv3-7fgg.json | 8 ++------ .../05/GHSA-6936-h7xw-gfq3/GHSA-6936-h7xw-gfq3.json | 8 ++------ .../05/GHSA-69h3-7gjf-m5gx/GHSA-69h3-7gjf-m5gx.json | 8 ++------ .../05/GHSA-69q2-gvv3-f7cr/GHSA-69q2-gvv3-f7cr.json | 4 +--- .../05/GHSA-6c23-3vmv-9r2c/GHSA-6c23-3vmv-9r2c.json | 12 +++--------- .../05/GHSA-6cg9-w42p-2vh6/GHSA-6cg9-w42p-2vh6.json | 12 +++--------- .../05/GHSA-6cpp-45v5-cpgv/GHSA-6cpp-45v5-cpgv.json | 8 ++------ .../05/GHSA-6cpv-gpjr-7h64/GHSA-6cpv-gpjr-7h64.json | 8 ++------ .../05/GHSA-6fqw-r97c-866j/GHSA-6fqw-r97c-866j.json | 8 ++------ .../05/GHSA-6gc7-9r9m-q3wg/GHSA-6gc7-9r9m-q3wg.json | 8 ++------ .../05/GHSA-6h2j-xchg-wcx8/GHSA-6h2j-xchg-wcx8.json | 8 ++------ .../05/GHSA-6hcc-3gxp-hwgr/GHSA-6hcc-3gxp-hwgr.json | 12 +++--------- .../05/GHSA-6j5m-hrmm-wf49/GHSA-6j5m-hrmm-wf49.json | 12 +++--------- .../05/GHSA-6jvg-fx73-499w/GHSA-6jvg-fx73-499w.json | 8 ++------ .../05/GHSA-6m34-8ff3-6cj3/GHSA-6m34-8ff3-6cj3.json | 12 +++--------- .../05/GHSA-6p4q-73fv-qgx2/GHSA-6p4q-73fv-qgx2.json | 8 ++------ .../05/GHSA-6ph7-3cx8-q7xh/GHSA-6ph7-3cx8-q7xh.json | 8 ++------ .../05/GHSA-6prr-6x2x-fx8r/GHSA-6prr-6x2x-fx8r.json | 12 +++--------- .../05/GHSA-6q26-2pcr-954w/GHSA-6q26-2pcr-954w.json | 12 +++--------- .../05/GHSA-6qg5-vf7x-4fm3/GHSA-6qg5-vf7x-4fm3.json | 4 +--- .../05/GHSA-6qmj-48p6-crf2/GHSA-6qmj-48p6-crf2.json | 8 ++------ .../05/GHSA-6qqv-794g-frqv/GHSA-6qqv-794g-frqv.json | 12 +++--------- .../05/GHSA-6v6g-fc5r-ggpx/GHSA-6v6g-fc5r-ggpx.json | 12 +++--------- .../05/GHSA-6v6w-2hhj-2cm4/GHSA-6v6w-2hhj-2cm4.json | 12 +++--------- .../05/GHSA-6vfc-66x6-g85h/GHSA-6vfc-66x6-g85h.json | 8 ++------ .../05/GHSA-6vgx-633w-89g7/GHSA-6vgx-633w-89g7.json | 12 +++--------- .../05/GHSA-6vr7-vxmx-w9qg/GHSA-6vr7-vxmx-w9qg.json | 4 +--- .../05/GHSA-6vr9-mwp7-5pjm/GHSA-6vr9-mwp7-5pjm.json | 12 +++--------- .../05/GHSA-6vxp-v535-v5r9/GHSA-6vxp-v535-v5r9.json | 4 +--- .../05/GHSA-6w58-36f7-jcwp/GHSA-6w58-36f7-jcwp.json | 12 +++--------- .../05/GHSA-6wwm-42xv-cjjc/GHSA-6wwm-42xv-cjjc.json | 12 +++--------- .../05/GHSA-6x52-4rr6-8fw7/GHSA-6x52-4rr6-8fw7.json | 4 +--- .../05/GHSA-6x59-f29p-7vf6/GHSA-6x59-f29p-7vf6.json | 12 +++--------- .../05/GHSA-6xph-53h7-ghh2/GHSA-6xph-53h7-ghh2.json | 8 ++------ .../05/GHSA-722p-jr5h-rjqr/GHSA-722p-jr5h-rjqr.json | 12 +++--------- .../05/GHSA-727c-8vjf-pv2j/GHSA-727c-8vjf-pv2j.json | 12 +++--------- .../05/GHSA-728f-qcc4-8q48/GHSA-728f-qcc4-8q48.json | 8 ++------ .../05/GHSA-72fc-25pw-pqqj/GHSA-72fc-25pw-pqqj.json | 4 +--- .../05/GHSA-72qv-xgrv-898v/GHSA-72qv-xgrv-898v.json | 12 +++--------- .../05/GHSA-73g5-48xw-f45p/GHSA-73g5-48xw-f45p.json | 12 +++--------- .../05/GHSA-73j6-q65m-r8w4/GHSA-73j6-q65m-r8w4.json | 12 +++--------- .../05/GHSA-73p9-5hh7-3v53/GHSA-73p9-5hh7-3v53.json | 12 +++--------- .../05/GHSA-742w-p6j3-fcr9/GHSA-742w-p6j3-fcr9.json | 12 +++--------- .../05/GHSA-7443-9vrm-6986/GHSA-7443-9vrm-6986.json | 12 +++--------- .../05/GHSA-7446-x75g-7gmf/GHSA-7446-x75g-7gmf.json | 8 ++------ .../05/GHSA-74jf-rm92-m939/GHSA-74jf-rm92-m939.json | 12 +++--------- .../05/GHSA-74wg-mhc3-jxp5/GHSA-74wg-mhc3-jxp5.json | 8 ++------ .../05/GHSA-75j2-g376-x3q4/GHSA-75j2-g376-x3q4.json | 12 +++--------- .../05/GHSA-75wx-7fqq-f6pf/GHSA-75wx-7fqq-f6pf.json | 8 ++------ .../05/GHSA-7637-4x67-w26c/GHSA-7637-4x67-w26c.json | 8 ++------ .../05/GHSA-76cj-38jr-6rg5/GHSA-76cj-38jr-6rg5.json | 8 ++------ .../05/GHSA-76pj-fv2h-qvfg/GHSA-76pj-fv2h-qvfg.json | 8 ++------ .../05/GHSA-76q4-7268-9v4c/GHSA-76q4-7268-9v4c.json | 8 ++------ .../05/GHSA-76ww-rw5h-92jq/GHSA-76ww-rw5h-92jq.json | 12 +++--------- .../05/GHSA-7763-j2c2-xh5f/GHSA-7763-j2c2-xh5f.json | 12 +++--------- .../05/GHSA-7784-c7pr-562g/GHSA-7784-c7pr-562g.json | 12 +++--------- .../05/GHSA-77c8-7ffw-q7m9/GHSA-77c8-7ffw-q7m9.json | 8 ++------ .../05/GHSA-77g4-qr46-24gf/GHSA-77g4-qr46-24gf.json | 8 ++------ .../05/GHSA-793h-vw32-6xg7/GHSA-793h-vw32-6xg7.json | 12 +++--------- .../05/GHSA-79rq-pp6p-6hmr/GHSA-79rq-pp6p-6hmr.json | 4 +--- .../05/GHSA-7c52-ww2j-7v63/GHSA-7c52-ww2j-7v63.json | 8 ++------ .../05/GHSA-7cfr-6m37-9p2x/GHSA-7cfr-6m37-9p2x.json | 12 +++--------- .../05/GHSA-7cx8-j7qq-8w58/GHSA-7cx8-j7qq-8w58.json | 12 +++--------- .../05/GHSA-7f3j-x5jc-j32w/GHSA-7f3j-x5jc-j32w.json | 8 ++------ .../05/GHSA-7fm7-7gf5-94cr/GHSA-7fm7-7gf5-94cr.json | 12 +++--------- .../05/GHSA-7g44-2g66-w5fr/GHSA-7g44-2g66-w5fr.json | 8 ++------ .../05/GHSA-7h7v-g6g9-xc8m/GHSA-7h7v-g6g9-xc8m.json | 8 ++------ .../05/GHSA-7j29-8px4-p3vh/GHSA-7j29-8px4-p3vh.json | 12 +++--------- .../05/GHSA-7j4q-97pw-5p6r/GHSA-7j4q-97pw-5p6r.json | 8 ++------ .../05/GHSA-7jfp-wwch-7rgr/GHSA-7jfp-wwch-7rgr.json | 8 ++------ .../05/GHSA-7jgh-j4rc-4q2v/GHSA-7jgh-j4rc-4q2v.json | 8 ++------ .../05/GHSA-7m66-pvc3-h2x4/GHSA-7m66-pvc3-h2x4.json | 8 ++------ .../05/GHSA-7mh3-jvj6-47x5/GHSA-7mh3-jvj6-47x5.json | 8 ++------ .../05/GHSA-7p3q-vc66-rxmp/GHSA-7p3q-vc66-rxmp.json | 12 +++--------- .../05/GHSA-7pcr-5h9h-38rf/GHSA-7pcr-5h9h-38rf.json | 8 ++------ .../05/GHSA-7pm4-8h5h-6ch3/GHSA-7pm4-8h5h-6ch3.json | 12 +++--------- .../05/GHSA-7q63-mgr2-2p5j/GHSA-7q63-mgr2-2p5j.json | 8 ++------ .../05/GHSA-7q6c-727m-8m74/GHSA-7q6c-727m-8m74.json | 12 +++--------- .../05/GHSA-7qg6-74r3-86w6/GHSA-7qg6-74r3-86w6.json | 8 ++------ .../05/GHSA-7qqh-46f7-v7hc/GHSA-7qqh-46f7-v7hc.json | 8 ++------ .../05/GHSA-7rh8-6x72-2pcx/GHSA-7rh8-6x72-2pcx.json | 8 ++------ .../05/GHSA-7rjr-24cr-3hfx/GHSA-7rjr-24cr-3hfx.json | 12 +++--------- .../05/GHSA-7rqv-hpgx-m2wc/GHSA-7rqv-hpgx-m2wc.json | 12 +++--------- .../05/GHSA-7v7r-2p9m-p93q/GHSA-7v7r-2p9m-p93q.json | 12 +++--------- .../05/GHSA-7vhx-6x46-jv3p/GHSA-7vhx-6x46-jv3p.json | 8 ++------ .../05/GHSA-7wcr-cqmg-4vmr/GHSA-7wcr-cqmg-4vmr.json | 12 +++--------- .../05/GHSA-7x3c-7jfh-6j4c/GHSA-7x3c-7jfh-6j4c.json | 12 +++--------- .../05/GHSA-7x8j-m6q2-x954/GHSA-7x8j-m6q2-x954.json | 8 ++------ .../05/GHSA-7xg4-c3g7-r42r/GHSA-7xg4-c3g7-r42r.json | 8 ++------ .../05/GHSA-828q-cvff-pc4m/GHSA-828q-cvff-pc4m.json | 12 +++--------- .../05/GHSA-8327-8m8p-rw2w/GHSA-8327-8m8p-rw2w.json | 8 ++------ .../05/GHSA-84pv-q4h7-244g/GHSA-84pv-q4h7-244g.json | 8 ++------ .../05/GHSA-856m-7gh9-83gw/GHSA-856m-7gh9-83gw.json | 8 ++------ .../05/GHSA-86c3-4264-rwhv/GHSA-86c3-4264-rwhv.json | 8 ++------ .../05/GHSA-86j3-7436-wx4w/GHSA-86j3-7436-wx4w.json | 8 ++------ .../05/GHSA-86m8-rg37-85gx/GHSA-86m8-rg37-85gx.json | 8 ++------ .../05/GHSA-874c-9v93-83g8/GHSA-874c-9v93-83g8.json | 12 +++--------- .../05/GHSA-878w-3c3r-w7j4/GHSA-878w-3c3r-w7j4.json | 8 ++------ .../05/GHSA-88p5-j94v-hcpw/GHSA-88p5-j94v-hcpw.json | 8 ++------ .../05/GHSA-88x2-v352-g224/GHSA-88x2-v352-g224.json | 8 ++------ .../05/GHSA-898q-rv6w-247h/GHSA-898q-rv6w-247h.json | 12 +++--------- .../05/GHSA-89q9-wwr5-f2mf/GHSA-89q9-wwr5-f2mf.json | 12 +++--------- .../05/GHSA-89xh-mm48-p72f/GHSA-89xh-mm48-p72f.json | 4 +--- .../05/GHSA-8c3h-ggpx-cvjg/GHSA-8c3h-ggpx-cvjg.json | 12 +++--------- .../05/GHSA-8c59-7xj5-h2jh/GHSA-8c59-7xj5-h2jh.json | 8 ++------ .../05/GHSA-8cq5-h2jx-4m9x/GHSA-8cq5-h2jx-4m9x.json | 12 +++--------- .../05/GHSA-8f3c-5w2m-gp7j/GHSA-8f3c-5w2m-gp7j.json | 8 ++------ .../05/GHSA-8f7q-x4r8-9427/GHSA-8f7q-x4r8-9427.json | 8 ++------ .../05/GHSA-8f89-v95p-2ph8/GHSA-8f89-v95p-2ph8.json | 12 +++--------- .../05/GHSA-8fmp-8375-h4p6/GHSA-8fmp-8375-h4p6.json | 8 ++------ .../05/GHSA-8fqx-vvx3-hvxm/GHSA-8fqx-vvx3-hvxm.json | 12 +++--------- .../05/GHSA-8fr5-3m95-p6r9/GHSA-8fr5-3m95-p6r9.json | 8 ++------ .../05/GHSA-8gwc-9c4q-3rfx/GHSA-8gwc-9c4q-3rfx.json | 12 +++--------- .../05/GHSA-8h2v-2p8g-f36m/GHSA-8h2v-2p8g-f36m.json | 8 ++------ .../05/GHSA-8h3c-9j4w-wqxp/GHSA-8h3c-9j4w-wqxp.json | 8 ++------ .../05/GHSA-8h86-6q3w-5h6p/GHSA-8h86-6q3w-5h6p.json | 8 ++------ .../05/GHSA-8h8g-rw3h-79pw/GHSA-8h8g-rw3h-79pw.json | 12 +++--------- .../05/GHSA-8hjf-39rr-pc66/GHSA-8hjf-39rr-pc66.json | 8 ++------ .../05/GHSA-8hjp-hfjp-rw28/GHSA-8hjp-hfjp-rw28.json | 12 +++--------- .../05/GHSA-8jmg-vw84-q638/GHSA-8jmg-vw84-q638.json | 8 ++------ .../05/GHSA-8jpc-vcqh-2w24/GHSA-8jpc-vcqh-2w24.json | 12 +++--------- .../05/GHSA-8jv5-cjv4-rqhq/GHSA-8jv5-cjv4-rqhq.json | 12 +++--------- .../05/GHSA-8jw6-mfpx-fgw6/GHSA-8jw6-mfpx-fgw6.json | 8 ++------ .../05/GHSA-8m8j-89c8-3vh7/GHSA-8m8j-89c8-3vh7.json | 8 ++------ .../05/GHSA-8m8m-gx66-4856/GHSA-8m8m-gx66-4856.json | 12 +++--------- .../05/GHSA-8mp4-m9gc-q7v3/GHSA-8mp4-m9gc-q7v3.json | 12 +++--------- .../05/GHSA-8mq7-xqr4-2h23/GHSA-8mq7-xqr4-2h23.json | 12 +++--------- .../05/GHSA-8mqc-792p-mwg5/GHSA-8mqc-792p-mwg5.json | 8 ++------ .../05/GHSA-8mx8-xx88-x7gm/GHSA-8mx8-xx88-x7gm.json | 8 ++------ .../05/GHSA-8pj3-c92f-vjfj/GHSA-8pj3-c92f-vjfj.json | 12 +++--------- .../05/GHSA-8pmf-jxj3-wvvp/GHSA-8pmf-jxj3-wvvp.json | 12 +++--------- .../05/GHSA-8q6v-89xc-5g4w/GHSA-8q6v-89xc-5g4w.json | 8 ++------ .../05/GHSA-8qfc-4842-rrwj/GHSA-8qfc-4842-rrwj.json | 8 ++------ .../05/GHSA-8qhp-jq8m-c4m4/GHSA-8qhp-jq8m-c4m4.json | 4 +--- .../05/GHSA-8qj6-9gfw-v5pw/GHSA-8qj6-9gfw-v5pw.json | 12 +++--------- .../05/GHSA-8qq6-rp62-86qv/GHSA-8qq6-rp62-86qv.json | 8 ++------ .../05/GHSA-8qwx-m7r4-3mmg/GHSA-8qwx-m7r4-3mmg.json | 12 +++--------- .../05/GHSA-8r5x-26x3-9q3c/GHSA-8r5x-26x3-9q3c.json | 12 +++--------- .../05/GHSA-8v6f-rm23-9f27/GHSA-8v6f-rm23-9f27.json | 12 +++--------- .../05/GHSA-8vg7-hm2j-f2h5/GHSA-8vg7-hm2j-f2h5.json | 12 +++--------- .../05/GHSA-8wgc-q9r2-hg5h/GHSA-8wgc-q9r2-hg5h.json | 8 ++------ .../05/GHSA-8x7v-m8hq-cc5h/GHSA-8x7v-m8hq-cc5h.json | 12 +++--------- .../05/GHSA-8xgg-3858-cfqw/GHSA-8xgg-3858-cfqw.json | 12 +++--------- .../05/GHSA-922q-4mg4-99r8/GHSA-922q-4mg4-99r8.json | 8 ++------ .../05/GHSA-928h-wr4w-h6r7/GHSA-928h-wr4w-h6r7.json | 8 ++------ .../05/GHSA-92gc-4r2j-hf7p/GHSA-92gc-4r2j-hf7p.json | 8 ++------ .../05/GHSA-92h7-3mpg-68jh/GHSA-92h7-3mpg-68jh.json | 8 ++------ .../05/GHSA-9365-9qh8-mwx7/GHSA-9365-9qh8-mwx7.json | 8 ++------ .../05/GHSA-93hf-xxfj-6gx3/GHSA-93hf-xxfj-6gx3.json | 4 +--- .../05/GHSA-93mr-rvw5-gvpp/GHSA-93mr-rvw5-gvpp.json | 12 +++--------- .../05/GHSA-952f-vp9j-ch94/GHSA-952f-vp9j-ch94.json | 12 +++--------- .../05/GHSA-956q-95gc-c8rv/GHSA-956q-95gc-c8rv.json | 12 +++--------- .../05/GHSA-95f3-ph23-r8xm/GHSA-95f3-ph23-r8xm.json | 12 +++--------- .../05/GHSA-95jv-r6j9-p8xr/GHSA-95jv-r6j9-p8xr.json | 8 ++------ .../05/GHSA-96fj-j48j-g393/GHSA-96fj-j48j-g393.json | 12 +++--------- .../05/GHSA-96x7-cmg8-h727/GHSA-96x7-cmg8-h727.json | 12 +++--------- .../05/GHSA-96xp-3qc9-8xh8/GHSA-96xp-3qc9-8xh8.json | 8 ++------ .../05/GHSA-9772-8vcx-jgfq/GHSA-9772-8vcx-jgfq.json | 12 +++--------- .../05/GHSA-984p-q7w5-xvvg/GHSA-984p-q7w5-xvvg.json | 12 +++--------- .../05/GHSA-98pm-v23p-r2wf/GHSA-98pm-v23p-r2wf.json | 8 ++------ .../05/GHSA-996c-c433-w68x/GHSA-996c-c433-w68x.json | 8 ++------ .../05/GHSA-998v-vqg2-r4wf/GHSA-998v-vqg2-r4wf.json | 8 ++------ .../05/GHSA-9ccq-3mj2-hjgm/GHSA-9ccq-3mj2-hjgm.json | 12 +++--------- .../05/GHSA-9chm-qgqp-3whh/GHSA-9chm-qgqp-3whh.json | 12 +++--------- .../05/GHSA-9fcg-r3gc-jvhf/GHSA-9fcg-r3gc-jvhf.json | 8 ++------ .../05/GHSA-9g2p-74g4-rgg6/GHSA-9g2p-74g4-rgg6.json | 12 +++--------- .../05/GHSA-9g3f-pc53-92m7/GHSA-9g3f-pc53-92m7.json | 12 +++--------- .../05/GHSA-9g4w-cm4c-cch5/GHSA-9g4w-cm4c-cch5.json | 12 +++--------- .../05/GHSA-9gg2-729j-q89w/GHSA-9gg2-729j-q89w.json | 8 ++------ .../05/GHSA-9gj7-rxj4-7x46/GHSA-9gj7-rxj4-7x46.json | 12 +++--------- .../05/GHSA-9gpc-v9qx-3jf7/GHSA-9gpc-v9qx-3jf7.json | 12 +++--------- .../05/GHSA-9jjv-5r68-g5hv/GHSA-9jjv-5r68-g5hv.json | 12 +++--------- .../05/GHSA-9m7h-2ggv-4q9j/GHSA-9m7h-2ggv-4q9j.json | 12 +++--------- .../05/GHSA-9mm4-3grj-7cx7/GHSA-9mm4-3grj-7cx7.json | 12 +++--------- .../05/GHSA-9p3h-4f9c-6m6g/GHSA-9p3h-4f9c-6m6g.json | 12 +++--------- .../05/GHSA-9p5h-3x6c-gqmv/GHSA-9p5h-3x6c-gqmv.json | 12 +++--------- .../05/GHSA-9pf3-6896-gpp9/GHSA-9pf3-6896-gpp9.json | 8 ++------ .../05/GHSA-9pp6-qvvr-7j96/GHSA-9pp6-qvvr-7j96.json | 12 +++--------- .../05/GHSA-9pxv-cmxv-m9xh/GHSA-9pxv-cmxv-m9xh.json | 8 ++------ .../05/GHSA-9q47-75mf-qmf9/GHSA-9q47-75mf-qmf9.json | 8 ++------ .../05/GHSA-9qcg-p796-2q2v/GHSA-9qcg-p796-2q2v.json | 8 ++------ .../05/GHSA-9rvj-pj6p-4pj6/GHSA-9rvj-pj6p-4pj6.json | 12 +++--------- .../05/GHSA-9vjq-3gv6-2pf3/GHSA-9vjq-3gv6-2pf3.json | 12 +++--------- .../05/GHSA-9vv6-3gx7-ppxv/GHSA-9vv6-3gx7-ppxv.json | 12 +++--------- .../05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json | 4 +--- .../05/GHSA-9wv9-vhvp-xjxr/GHSA-9wv9-vhvp-xjxr.json | 8 ++------ .../05/GHSA-c24v-xf6x-r8cc/GHSA-c24v-xf6x-r8cc.json | 12 +++--------- .../05/GHSA-c25g-j43f-w7p8/GHSA-c25g-j43f-w7p8.json | 12 +++--------- .../05/GHSA-c2qg-83f7-xwcm/GHSA-c2qg-83f7-xwcm.json | 8 ++------ .../05/GHSA-c43r-86m8-rvrg/GHSA-c43r-86m8-rvrg.json | 8 ++------ .../05/GHSA-c4jw-7285-v92g/GHSA-c4jw-7285-v92g.json | 8 ++------ .../05/GHSA-c4rx-6458-242x/GHSA-c4rx-6458-242x.json | 8 ++------ .../05/GHSA-c4rx-vvj6-9gv8/GHSA-c4rx-vvj6-9gv8.json | 8 ++------ .../05/GHSA-c4xj-f6r4-75xg/GHSA-c4xj-f6r4-75xg.json | 8 ++------ .../05/GHSA-c4xx-wp4h-934r/GHSA-c4xx-wp4h-934r.json | 12 +++--------- .../05/GHSA-c568-3m8f-4r27/GHSA-c568-3m8f-4r27.json | 12 +++--------- .../05/GHSA-c56g-v92h-6fcq/GHSA-c56g-v92h-6fcq.json | 8 ++------ .../05/GHSA-c5c8-g6j3-w28m/GHSA-c5c8-g6j3-w28m.json | 8 ++------ .../05/GHSA-c6fh-hgf3-5q42/GHSA-c6fh-hgf3-5q42.json | 8 ++------ .../05/GHSA-c6gj-v86g-r7jw/GHSA-c6gj-v86g-r7jw.json | 8 ++------ .../05/GHSA-c7ph-w6p6-9qr2/GHSA-c7ph-w6p6-9qr2.json | 12 +++--------- .../05/GHSA-c847-r6f2-c2wj/GHSA-c847-r6f2-c2wj.json | 8 ++------ .../05/GHSA-c888-5pj4-79hc/GHSA-c888-5pj4-79hc.json | 8 ++------ .../05/GHSA-c8mv-2mvj-9jjp/GHSA-c8mv-2mvj-9jjp.json | 12 +++--------- .../05/GHSA-c8mx-ccv3-h6hj/GHSA-c8mx-ccv3-h6hj.json | 8 ++------ .../05/GHSA-c8q5-wpgp-c3rq/GHSA-c8q5-wpgp-c3rq.json | 12 +++--------- .../05/GHSA-c927-pmgv-cmrp/GHSA-c927-pmgv-cmrp.json | 12 +++--------- .../05/GHSA-c9cp-98m8-82j9/GHSA-c9cp-98m8-82j9.json | 4 +--- .../05/GHSA-c9wm-g9gh-22c7/GHSA-c9wm-g9gh-22c7.json | 12 +++--------- .../05/GHSA-cc2m-g7f7-hrg8/GHSA-cc2m-g7f7-hrg8.json | 12 +++--------- .../05/GHSA-ccqr-2cf6-h7p3/GHSA-ccqr-2cf6-h7p3.json | 8 ++------ .../05/GHSA-cfq8-fj46-w8p7/GHSA-cfq8-fj46-w8p7.json | 12 +++--------- .../05/GHSA-ch26-285q-m7w2/GHSA-ch26-285q-m7w2.json | 8 ++------ .../05/GHSA-ch32-3mmp-49c5/GHSA-ch32-3mmp-49c5.json | 4 +--- .../05/GHSA-ch42-xc83-q8gr/GHSA-ch42-xc83-q8gr.json | 12 +++--------- .../05/GHSA-chgv-x7cw-mxj6/GHSA-chgv-x7cw-mxj6.json | 12 +++--------- .../05/GHSA-chqg-r7hw-qc9v/GHSA-chqg-r7hw-qc9v.json | 8 ++------ .../05/GHSA-cj95-hc8g-66rx/GHSA-cj95-hc8g-66rx.json | 4 +--- .../05/GHSA-cmgq-6hm8-g996/GHSA-cmgq-6hm8-g996.json | 8 ++------ .../05/GHSA-cppw-2fwh-6pqg/GHSA-cppw-2fwh-6pqg.json | 8 ++------ .../05/GHSA-cpw3-xwrw-grxf/GHSA-cpw3-xwrw-grxf.json | 12 +++--------- .../05/GHSA-cq55-rgg6-wm49/GHSA-cq55-rgg6-wm49.json | 8 ++------ .../05/GHSA-cqrg-93mv-7q2g/GHSA-cqrg-93mv-7q2g.json | 8 ++------ .../05/GHSA-cqvh-8pgv-w877/GHSA-cqvh-8pgv-w877.json | 4 +--- .../05/GHSA-crpw-9pqh-hv2j/GHSA-crpw-9pqh-hv2j.json | 8 ++------ .../05/GHSA-f28h-hcxc-r39x/GHSA-f28h-hcxc-r39x.json | 8 ++------ .../05/GHSA-f3jw-jgmw-xx5m/GHSA-f3jw-jgmw-xx5m.json | 12 +++--------- .../05/GHSA-f3wq-6385-xjpf/GHSA-f3wq-6385-xjpf.json | 12 +++--------- .../05/GHSA-f428-825j-hwjh/GHSA-f428-825j-hwjh.json | 12 +++--------- .../05/GHSA-f42x-6gqm-cmqq/GHSA-f42x-6gqm-cmqq.json | 8 ++------ .../05/GHSA-f4g8-f2fm-f5pf/GHSA-f4g8-f2fm-f5pf.json | 8 ++------ .../05/GHSA-f4g8-pp7p-v4vp/GHSA-f4g8-pp7p-v4vp.json | 12 +++--------- .../05/GHSA-f4hr-8v6m-mr63/GHSA-f4hr-8v6m-mr63.json | 8 ++------ .../05/GHSA-f4j9-rcxm-4r4q/GHSA-f4j9-rcxm-4r4q.json | 12 +++--------- .../05/GHSA-f4qf-gvqg-chfr/GHSA-f4qf-gvqg-chfr.json | 4 +--- .../05/GHSA-f4xr-4383-7g29/GHSA-f4xr-4383-7g29.json | 12 +++--------- .../05/GHSA-f557-f73j-r5x2/GHSA-f557-f73j-r5x2.json | 8 ++------ .../05/GHSA-f5pc-r4f6-r2w2/GHSA-f5pc-r4f6-r2w2.json | 8 ++------ .../05/GHSA-f68w-6m4r-r3r6/GHSA-f68w-6m4r-r3r6.json | 12 +++--------- .../05/GHSA-f69c-x64c-x2rm/GHSA-f69c-x64c-x2rm.json | 8 ++------ .../05/GHSA-f6c4-jwcc-rf6r/GHSA-f6c4-jwcc-rf6r.json | 12 +++--------- .../05/GHSA-f6cr-f667-v5wq/GHSA-f6cr-f667-v5wq.json | 12 +++--------- .../05/GHSA-f7q2-fp95-rjmf/GHSA-f7q2-fp95-rjmf.json | 8 ++------ .../05/GHSA-f7vw-gv84-6jmf/GHSA-f7vw-gv84-6jmf.json | 12 +++--------- .../05/GHSA-f884-r5wp-g6v3/GHSA-f884-r5wp-g6v3.json | 8 ++------ .../05/GHSA-f9cc-wx9r-r8gm/GHSA-f9cc-wx9r-r8gm.json | 12 +++--------- .../05/GHSA-fc3r-8rf7-j47f/GHSA-fc3r-8rf7-j47f.json | 12 +++--------- .../05/GHSA-fcgr-2rmx-gwwf/GHSA-fcgr-2rmx-gwwf.json | 8 ++------ .../05/GHSA-fchg-vp85-h7h9/GHSA-fchg-vp85-h7h9.json | 8 ++------ .../05/GHSA-fcpv-47pc-7gw6/GHSA-fcpv-47pc-7gw6.json | 12 +++--------- .../05/GHSA-fcwx-wvr2-2xm2/GHSA-fcwx-wvr2-2xm2.json | 8 ++------ .../05/GHSA-ff76-wr66-r229/GHSA-ff76-wr66-r229.json | 12 +++--------- .../05/GHSA-fgg2-r72r-cjqw/GHSA-fgg2-r72r-cjqw.json | 8 ++------ .../05/GHSA-fgp9-p978-9f8x/GHSA-fgp9-p978-9f8x.json | 8 ++------ .../05/GHSA-fgxf-m96p-5m7q/GHSA-fgxf-m96p-5m7q.json | 4 +--- .../05/GHSA-fh4q-xjx9-cj52/GHSA-fh4q-xjx9-cj52.json | 12 +++--------- .../05/GHSA-fhcv-9prg-g289/GHSA-fhcv-9prg-g289.json | 8 ++------ .../05/GHSA-fhj6-mqf7-5g3c/GHSA-fhj6-mqf7-5g3c.json | 12 +++--------- .../05/GHSA-fj2h-4hhq-47f7/GHSA-fj2h-4hhq-47f7.json | 12 +++--------- .../05/GHSA-fj83-776g-wqqf/GHSA-fj83-776g-wqqf.json | 8 ++------ .../05/GHSA-fjcw-v25j-8w38/GHSA-fjcw-v25j-8w38.json | 8 ++------ .../05/GHSA-fmx8-cmcw-gqrw/GHSA-fmx8-cmcw-gqrw.json | 12 +++--------- .../05/GHSA-fq33-497v-4h5x/GHSA-fq33-497v-4h5x.json | 4 +--- .../05/GHSA-fqwx-8v72-4mq9/GHSA-fqwx-8v72-4mq9.json | 12 +++--------- .../05/GHSA-fr6v-96rj-pcv9/GHSA-fr6v-96rj-pcv9.json | 12 +++--------- .../05/GHSA-frfc-2472-vf85/GHSA-frfc-2472-vf85.json | 12 +++--------- .../05/GHSA-frq7-7xj9-2qfg/GHSA-frq7-7xj9-2qfg.json | 12 +++--------- .../05/GHSA-fv2j-64xc-r4hr/GHSA-fv2j-64xc-r4hr.json | 8 ++------ .../05/GHSA-fv2v-8v2v-g9q3/GHSA-fv2v-8v2v-g9q3.json | 8 ++------ .../05/GHSA-fvmx-f73c-vgqh/GHSA-fvmx-f73c-vgqh.json | 12 +++--------- .../05/GHSA-fvqf-8h9v-94f2/GHSA-fvqf-8h9v-94f2.json | 12 +++--------- .../05/GHSA-fw9q-rwpp-xcw5/GHSA-fw9q-rwpp-xcw5.json | 4 +--- .../05/GHSA-g25m-r8p8-98wq/GHSA-g25m-r8p8-98wq.json | 8 ++------ .../05/GHSA-g278-j36h-xmv9/GHSA-g278-j36h-xmv9.json | 8 ++------ .../05/GHSA-g28w-j5h7-v723/GHSA-g28w-j5h7-v723.json | 12 +++--------- .../05/GHSA-g34c-fgmm-m32p/GHSA-g34c-fgmm-m32p.json | 12 +++--------- .../05/GHSA-g3q2-x98w-36ww/GHSA-g3q2-x98w-36ww.json | 12 +++--------- .../05/GHSA-g5h8-hjh2-8m54/GHSA-g5h8-hjh2-8m54.json | 8 ++------ .../05/GHSA-g62q-jrgg-f5mw/GHSA-g62q-jrgg-f5mw.json | 12 +++--------- .../05/GHSA-g64f-mxrq-5h8c/GHSA-g64f-mxrq-5h8c.json | 8 ++------ .../05/GHSA-g6c8-gjr8-q3fr/GHSA-g6c8-gjr8-q3fr.json | 12 +++--------- .../05/GHSA-g6f7-wvh9-6cj8/GHSA-g6f7-wvh9-6cj8.json | 8 ++------ .../05/GHSA-g6p7-8xmm-rr6g/GHSA-g6p7-8xmm-rr6g.json | 12 +++--------- .../05/GHSA-g6q2-6x3v-j3cw/GHSA-g6q2-6x3v-j3cw.json | 12 +++--------- .../05/GHSA-g6qm-f66w-v42p/GHSA-g6qm-f66w-v42p.json | 12 +++--------- .../05/GHSA-g72w-qc26-qmpv/GHSA-g72w-qc26-qmpv.json | 8 ++------ .../05/GHSA-g7gg-fmmg-9gmr/GHSA-g7gg-fmmg-9gmr.json | 8 ++------ .../05/GHSA-g7qm-6xgj-wfh5/GHSA-g7qm-6xgj-wfh5.json | 12 +++--------- .../05/GHSA-g898-v75f-fp22/GHSA-g898-v75f-fp22.json | 12 +++--------- .../05/GHSA-g9r6-qhfx-9xcc/GHSA-g9r6-qhfx-9xcc.json | 8 ++------ .../05/GHSA-g9xx-m8f7-gx2c/GHSA-g9xx-m8f7-gx2c.json | 8 ++------ .../05/GHSA-gf8p-pg5p-7jm3/GHSA-gf8p-pg5p-7jm3.json | 8 ++------ .../05/GHSA-gg8c-wv43-x28x/GHSA-gg8c-wv43-x28x.json | 8 ++------ .../05/GHSA-gggx-f55h-83w3/GHSA-gggx-f55h-83w3.json | 8 ++------ .../05/GHSA-ggph-hp42-2f4h/GHSA-ggph-hp42-2f4h.json | 8 ++------ .../05/GHSA-ggvw-gcq7-rp4h/GHSA-ggvw-gcq7-rp4h.json | 12 +++--------- .../05/GHSA-gh89-2x3x-p7j7/GHSA-gh89-2x3x-p7j7.json | 4 +--- .../05/GHSA-ghvr-mv7w-8r6f/GHSA-ghvr-mv7w-8r6f.json | 12 +++--------- .../05/GHSA-gj3q-qghf-gf7p/GHSA-gj3q-qghf-gf7p.json | 12 +++--------- .../05/GHSA-gj8x-63v8-4x98/GHSA-gj8x-63v8-4x98.json | 12 +++--------- .../05/GHSA-gjgr-g54p-g5jh/GHSA-gjgr-g54p-g5jh.json | 12 +++--------- .../05/GHSA-gm68-2qf8-8pv7/GHSA-gm68-2qf8-8pv7.json | 12 +++--------- .../05/GHSA-gmp4-8xr6-896q/GHSA-gmp4-8xr6-896q.json | 12 +++--------- .../05/GHSA-gphc-6cvq-642v/GHSA-gphc-6cvq-642v.json | 12 +++--------- .../05/GHSA-gpjf-jjxr-m946/GHSA-gpjf-jjxr-m946.json | 12 +++--------- .../05/GHSA-gq57-694q-x523/GHSA-gq57-694q-x523.json | 8 ++------ .../05/GHSA-grg7-jq9x-hvf8/GHSA-grg7-jq9x-hvf8.json | 8 ++------ .../05/GHSA-grh8-hj9r-8r5x/GHSA-grh8-hj9r-8r5x.json | 12 +++--------- .../05/GHSA-gv3m-j4wj-2r64/GHSA-gv3m-j4wj-2r64.json | 12 +++--------- .../05/GHSA-gvhj-rrhv-wr5p/GHSA-gvhj-rrhv-wr5p.json | 12 +++--------- .../05/GHSA-gvpj-hm4g-j324/GHSA-gvpj-hm4g-j324.json | 12 +++--------- .../05/GHSA-gw4v-549p-9jgg/GHSA-gw4v-549p-9jgg.json | 12 +++--------- .../05/GHSA-gwgp-42rc-9p7h/GHSA-gwgp-42rc-9p7h.json | 12 +++--------- .../05/GHSA-gwhh-j9fr-4gcq/GHSA-gwhh-j9fr-4gcq.json | 12 +++--------- .../05/GHSA-gwmx-h2p5-m8jh/GHSA-gwmx-h2p5-m8jh.json | 12 +++--------- .../05/GHSA-gwp7-fg46-5fgw/GHSA-gwp7-fg46-5fgw.json | 8 ++------ .../05/GHSA-gx79-c5w9-r9rc/GHSA-gx79-c5w9-r9rc.json | 12 +++--------- .../05/GHSA-gxf2-f6v3-qm53/GHSA-gxf2-f6v3-qm53.json | 12 +++--------- .../05/GHSA-gxhc-x37q-m5qc/GHSA-gxhc-x37q-m5qc.json | 12 +++--------- .../05/GHSA-h24x-25vp-682x/GHSA-h24x-25vp-682x.json | 8 ++------ .../05/GHSA-h2xq-fv4r-5784/GHSA-h2xq-fv4r-5784.json | 8 ++------ .../05/GHSA-h37c-4pg2-6xq6/GHSA-h37c-4pg2-6xq6.json | 8 ++------ .../05/GHSA-h3w8-j4fj-qv4j/GHSA-h3w8-j4fj-qv4j.json | 12 +++--------- .../05/GHSA-h453-w69q-mm9j/GHSA-h453-w69q-mm9j.json | 8 ++------ .../05/GHSA-h4rr-q2q4-72r9/GHSA-h4rr-q2q4-72r9.json | 12 +++--------- .../05/GHSA-h4rw-rm6c-ghvc/GHSA-h4rw-rm6c-ghvc.json | 8 ++------ .../05/GHSA-h5vp-8vfv-4cgp/GHSA-h5vp-8vfv-4cgp.json | 8 ++------ .../05/GHSA-h5w8-c4g8-8ch6/GHSA-h5w8-c4g8-8ch6.json | 8 ++------ .../05/GHSA-h737-pm89-7j57/GHSA-h737-pm89-7j57.json | 12 +++--------- .../05/GHSA-h746-v282-j5wj/GHSA-h746-v282-j5wj.json | 8 ++------ .../05/GHSA-h7vp-qvfw-h2f3/GHSA-h7vp-qvfw-h2f3.json | 12 +++--------- .../05/GHSA-h84p-p4v5-gw25/GHSA-h84p-p4v5-gw25.json | 12 +++--------- .../05/GHSA-h938-qvmh-8rqv/GHSA-h938-qvmh-8rqv.json | 12 +++--------- .../05/GHSA-h98r-cwxp-2m8m/GHSA-h98r-cwxp-2m8m.json | 8 ++------ .../05/GHSA-h9fc-rg7x-48xg/GHSA-h9fc-rg7x-48xg.json | 8 ++------ .../05/GHSA-hc82-f9w8-5qqv/GHSA-hc82-f9w8-5qqv.json | 12 +++--------- .../05/GHSA-hchr-g8fg-g2r7/GHSA-hchr-g8fg-g2r7.json | 12 +++--------- .../05/GHSA-hcj7-753j-h8mf/GHSA-hcj7-753j-h8mf.json | 8 ++------ .../05/GHSA-hcq2-9985-7gxv/GHSA-hcq2-9985-7gxv.json | 8 ++------ .../05/GHSA-hcvx-9jxc-j8w3/GHSA-hcvx-9jxc-j8w3.json | 4 +--- .../05/GHSA-hcx3-h3xc-47cc/GHSA-hcx3-h3xc-47cc.json | 8 ++------ .../05/GHSA-hf4v-9m67-rprw/GHSA-hf4v-9m67-rprw.json | 8 ++------ .../05/GHSA-hfq3-j248-m7rx/GHSA-hfq3-j248-m7rx.json | 8 ++------ .../05/GHSA-hhcw-hw4m-h4v7/GHSA-hhcw-hw4m-h4v7.json | 12 +++--------- .../05/GHSA-hhm2-3v7q-xp8q/GHSA-hhm2-3v7q-xp8q.json | 12 +++--------- .../05/GHSA-hhp5-2m4q-mmrp/GHSA-hhp5-2m4q-mmrp.json | 8 ++------ .../05/GHSA-hjv5-g5g9-4cg4/GHSA-hjv5-g5g9-4cg4.json | 4 +--- .../05/GHSA-hm4g-g7fc-3qxj/GHSA-hm4g-g7fc-3qxj.json | 12 +++--------- .../05/GHSA-hp3w-wv98-497f/GHSA-hp3w-wv98-497f.json | 12 +++--------- .../05/GHSA-hp8r-3wgf-2x3x/GHSA-hp8r-3wgf-2x3x.json | 12 +++--------- .../05/GHSA-hpj4-vj9f-q9hf/GHSA-hpj4-vj9f-q9hf.json | 8 ++------ .../05/GHSA-hq44-653c-fqqh/GHSA-hq44-653c-fqqh.json | 12 +++--------- .../05/GHSA-hq64-63h4-3rpx/GHSA-hq64-63h4-3rpx.json | 12 +++--------- .../05/GHSA-hqcv-5gqh-jcfh/GHSA-hqcv-5gqh-jcfh.json | 8 ++------ .../05/GHSA-hqmc-p4j8-4rqc/GHSA-hqmc-p4j8-4rqc.json | 12 +++--------- .../05/GHSA-hqrg-vp62-hmj7/GHSA-hqrg-vp62-hmj7.json | 8 ++------ .../05/GHSA-hrv2-qc6c-j67q/GHSA-hrv2-qc6c-j67q.json | 12 +++--------- .../05/GHSA-hv27-4gff-hf2w/GHSA-hv27-4gff-hf2w.json | 12 +++--------- .../05/GHSA-hv4v-qgpx-4225/GHSA-hv4v-qgpx-4225.json | 8 ++------ .../05/GHSA-hw2j-hpjq-wvhv/GHSA-hw2j-hpjq-wvhv.json | 12 +++--------- .../05/GHSA-hw4w-cm9x-6hg5/GHSA-hw4w-cm9x-6hg5.json | 8 ++------ .../05/GHSA-j24v-hvrr-gw8v/GHSA-j24v-hvrr-gw8v.json | 8 ++------ .../05/GHSA-j269-fp7g-8w8w/GHSA-j269-fp7g-8w8w.json | 8 ++------ .../05/GHSA-j2pc-g7pm-qf6j/GHSA-j2pc-g7pm-qf6j.json | 12 +++--------- .../05/GHSA-j3qq-rrg5-j2xr/GHSA-j3qq-rrg5-j2xr.json | 8 ++------ .../05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json | 8 ++------ .../05/GHSA-j43m-hrxf-c3hp/GHSA-j43m-hrxf-c3hp.json | 8 ++------ .../05/GHSA-j4gg-fhrw-m69g/GHSA-j4gg-fhrw-m69g.json | 8 ++------ .../05/GHSA-j53v-j7wc-f9g9/GHSA-j53v-j7wc-f9g9.json | 8 ++------ .../05/GHSA-j54w-v35m-r2j7/GHSA-j54w-v35m-r2j7.json | 12 +++--------- .../05/GHSA-j56h-v988-6xx4/GHSA-j56h-v988-6xx4.json | 8 ++------ .../05/GHSA-j5cv-h8xh-gwcp/GHSA-j5cv-h8xh-gwcp.json | 8 ++------ .../05/GHSA-j5jc-fjph-vx57/GHSA-j5jc-fjph-vx57.json | 8 ++------ .../05/GHSA-j5qr-8rrw-8f9v/GHSA-j5qr-8rrw-8f9v.json | 8 ++------ .../05/GHSA-j5wq-jc5r-xp97/GHSA-j5wq-jc5r-xp97.json | 12 +++--------- .../05/GHSA-j6h9-6xvv-v8ph/GHSA-j6h9-6xvv-v8ph.json | 12 +++--------- .../05/GHSA-j7p2-mjw4-64cc/GHSA-j7p2-mjw4-64cc.json | 12 +++--------- .../05/GHSA-j86f-g83j-qw65/GHSA-j86f-g83j-qw65.json | 12 +++--------- .../05/GHSA-j8jm-5rrf-g8mp/GHSA-j8jm-5rrf-g8mp.json | 12 +++--------- .../05/GHSA-j985-mvrq-83h7/GHSA-j985-mvrq-83h7.json | 12 +++--------- .../05/GHSA-jc3j-r3vh-w677/GHSA-jc3j-r3vh-w677.json | 8 ++------ .../05/GHSA-jcg8-68f4-v6r7/GHSA-jcg8-68f4-v6r7.json | 12 +++--------- .../05/GHSA-jf53-8v78-xf68/GHSA-jf53-8v78-xf68.json | 8 ++------ .../05/GHSA-jfwc-rxqw-vvj6/GHSA-jfwc-rxqw-vvj6.json | 8 ++------ .../05/GHSA-jgp5-g26h-hfg8/GHSA-jgp5-g26h-hfg8.json | 12 +++--------- .../05/GHSA-jhgg-m334-7pxp/GHSA-jhgg-m334-7pxp.json | 8 ++------ .../05/GHSA-jmg8-fp8v-pc6j/GHSA-jmg8-fp8v-pc6j.json | 12 +++--------- .../05/GHSA-jpj8-cwj3-qpvw/GHSA-jpj8-cwj3-qpvw.json | 8 ++------ .../05/GHSA-jq7c-356h-gj6r/GHSA-jq7c-356h-gj6r.json | 12 +++--------- .../05/GHSA-jq8g-94vx-pgrm/GHSA-jq8g-94vx-pgrm.json | 8 ++------ .../05/GHSA-jqp4-j8cc-wx66/GHSA-jqp4-j8cc-wx66.json | 12 +++--------- .../05/GHSA-jv8r-v35h-qv47/GHSA-jv8r-v35h-qv47.json | 8 ++------ .../05/GHSA-jx59-j4wf-4x4h/GHSA-jx59-j4wf-4x4h.json | 12 +++--------- .../05/GHSA-jx74-m5hp-97vh/GHSA-jx74-m5hp-97vh.json | 12 +++--------- .../05/GHSA-m2c9-h2qv-35jc/GHSA-m2c9-h2qv-35jc.json | 12 +++--------- .../05/GHSA-m2jg-x6cx-w676/GHSA-m2jg-x6cx-w676.json | 12 +++--------- .../05/GHSA-m3xm-f262-69qm/GHSA-m3xm-f262-69qm.json | 12 +++--------- .../05/GHSA-m4ch-hx25-qfhf/GHSA-m4ch-hx25-qfhf.json | 8 ++------ .../05/GHSA-m4cm-qh2r-fvg3/GHSA-m4cm-qh2r-fvg3.json | 8 ++------ .../05/GHSA-m5fr-488c-22rq/GHSA-m5fr-488c-22rq.json | 8 ++------ .../05/GHSA-m5q8-vwxv-6f22/GHSA-m5q8-vwxv-6f22.json | 12 +++--------- .../05/GHSA-m66j-4hh4-r35x/GHSA-m66j-4hh4-r35x.json | 8 ++------ .../05/GHSA-m69p-8v8r-jhcc/GHSA-m69p-8v8r-jhcc.json | 8 ++------ .../05/GHSA-m8j8-p957-53f2/GHSA-m8j8-p957-53f2.json | 12 +++--------- .../05/GHSA-m8v8-j367-x35r/GHSA-m8v8-j367-x35r.json | 12 +++--------- .../05/GHSA-m929-2mf3-jfhp/GHSA-m929-2mf3-jfhp.json | 8 ++------ .../05/GHSA-m93p-78fx-rr4f/GHSA-m93p-78fx-rr4f.json | 12 +++--------- .../05/GHSA-m99p-58jq-4cf5/GHSA-m99p-58jq-4cf5.json | 12 +++--------- .../05/GHSA-m9pc-6vm2-63f5/GHSA-m9pc-6vm2-63f5.json | 8 ++------ .../05/GHSA-m9q7-8vm6-p246/GHSA-m9q7-8vm6-p246.json | 12 +++--------- .../05/GHSA-m9qv-c494-f247/GHSA-m9qv-c494-f247.json | 12 +++--------- .../05/GHSA-mc98-xj99-qf7r/GHSA-mc98-xj99-qf7r.json | 8 ++------ .../05/GHSA-mf8q-f3gh-r43c/GHSA-mf8q-f3gh-r43c.json | 12 +++--------- .../05/GHSA-mfg4-vc2f-7p24/GHSA-mfg4-vc2f-7p24.json | 12 +++--------- .../05/GHSA-mfhf-9pvp-rc65/GHSA-mfhf-9pvp-rc65.json | 12 +++--------- .../05/GHSA-mgw5-3cch-4hf5/GHSA-mgw5-3cch-4hf5.json | 8 ++------ .../05/GHSA-mh39-j6xw-g36j/GHSA-mh39-j6xw-g36j.json | 12 +++--------- .../05/GHSA-mh48-h49v-5m4j/GHSA-mh48-h49v-5m4j.json | 12 +++--------- .../05/GHSA-mhhp-9rv5-4266/GHSA-mhhp-9rv5-4266.json | 8 ++------ .../05/GHSA-mj4q-hgj9-6rmg/GHSA-mj4q-hgj9-6rmg.json | 8 ++------ .../05/GHSA-mjc7-fwvm-67h4/GHSA-mjc7-fwvm-67h4.json | 8 ++------ .../05/GHSA-mjpx-84wp-2wp6/GHSA-mjpx-84wp-2wp6.json | 8 ++------ .../05/GHSA-mjv7-394p-9g5m/GHSA-mjv7-394p-9g5m.json | 12 +++--------- .../05/GHSA-mm6g-wcmr-44mj/GHSA-mm6g-wcmr-44mj.json | 12 +++--------- .../05/GHSA-mmpm-58gf-7r28/GHSA-mmpm-58gf-7r28.json | 8 ++------ .../05/GHSA-mmrg-jwv9-9h53/GHSA-mmrg-jwv9-9h53.json | 8 ++------ .../05/GHSA-mpc2-3367-chhh/GHSA-mpc2-3367-chhh.json | 8 ++------ .../05/GHSA-mpxp-95jp-3f78/GHSA-mpxp-95jp-3f78.json | 12 +++--------- .../05/GHSA-mrfh-xqh8-3383/GHSA-mrfh-xqh8-3383.json | 8 ++------ .../05/GHSA-mrpf-h2p4-3gmm/GHSA-mrpf-h2p4-3gmm.json | 8 ++------ .../05/GHSA-mw4v-qjph-c794/GHSA-mw4v-qjph-c794.json | 12 +++--------- .../05/GHSA-mwwm-v9vx-c276/GHSA-mwwm-v9vx-c276.json | 8 ++------ .../05/GHSA-mx8g-w236-jgpq/GHSA-mx8g-w236-jgpq.json | 12 +++--------- .../05/GHSA-p2q5-v57c-8gw3/GHSA-p2q5-v57c-8gw3.json | 12 +++--------- .../05/GHSA-p35r-5hv5-759h/GHSA-p35r-5hv5-759h.json | 8 ++------ .../05/GHSA-p37h-9c34-5f75/GHSA-p37h-9c34-5f75.json | 12 +++--------- .../05/GHSA-p38p-vq33-v625/GHSA-p38p-vq33-v625.json | 12 +++--------- .../05/GHSA-p3px-x826-qqvw/GHSA-p3px-x826-qqvw.json | 8 ++------ .../05/GHSA-p3rg-43m7-g6rc/GHSA-p3rg-43m7-g6rc.json | 12 +++--------- .../05/GHSA-p48h-366j-m3qx/GHSA-p48h-366j-m3qx.json | 12 +++--------- .../05/GHSA-p4c6-ww6x-99rw/GHSA-p4c6-ww6x-99rw.json | 12 +++--------- .../05/GHSA-p4cx-89qv-3gc6/GHSA-p4cx-89qv-3gc6.json | 12 +++--------- .../05/GHSA-p4mm-wpp7-57hp/GHSA-p4mm-wpp7-57hp.json | 12 +++--------- .../05/GHSA-p52h-5fjj-x2pc/GHSA-p52h-5fjj-x2pc.json | 8 ++------ .../05/GHSA-p555-vm74-xq5v/GHSA-p555-vm74-xq5v.json | 8 ++------ .../05/GHSA-p57v-vh5w-35p2/GHSA-p57v-vh5w-35p2.json | 8 ++------ .../05/GHSA-p5p7-qgjw-w4rg/GHSA-p5p7-qgjw-w4rg.json | 8 ++------ .../05/GHSA-p6gw-7vqp-9wg3/GHSA-p6gw-7vqp-9wg3.json | 12 +++--------- .../05/GHSA-p754-7gx2-93gj/GHSA-p754-7gx2-93gj.json | 12 +++--------- .../05/GHSA-p772-c78g-qj2h/GHSA-p772-c78g-qj2h.json | 12 +++--------- .../05/GHSA-p79v-mj8v-c6p4/GHSA-p79v-mj8v-c6p4.json | 12 +++--------- .../05/GHSA-p7m4-g6v2-gff7/GHSA-p7m4-g6v2-gff7.json | 8 ++------ .../05/GHSA-p84g-xfc3-9fmr/GHSA-p84g-xfc3-9fmr.json | 12 +++--------- .../05/GHSA-p87c-w38q-5f93/GHSA-p87c-w38q-5f93.json | 8 ++------ .../05/GHSA-p8f4-g4x9-fc9w/GHSA-p8f4-g4x9-fc9w.json | 12 +++--------- .../05/GHSA-p947-hjgq-3459/GHSA-p947-hjgq-3459.json | 12 +++--------- .../05/GHSA-p99g-ppg4-hchg/GHSA-p99g-ppg4-hchg.json | 12 +++--------- .../05/GHSA-p9j7-43pr-jxf7/GHSA-p9j7-43pr-jxf7.json | 8 ++------ .../05/GHSA-pc87-fj52-xq29/GHSA-pc87-fj52-xq29.json | 12 +++--------- .../05/GHSA-pf68-x7c8-5h4p/GHSA-pf68-x7c8-5h4p.json | 12 +++--------- .../05/GHSA-pfqv-vjx4-pmxj/GHSA-pfqv-vjx4-pmxj.json | 12 +++--------- .../05/GHSA-pfwr-4phx-9q5j/GHSA-pfwr-4phx-9q5j.json | 12 +++--------- .../05/GHSA-pg3h-mxmj-rvc4/GHSA-pg3h-mxmj-rvc4.json | 8 ++------ .../05/GHSA-pgjp-28w5-m45g/GHSA-pgjp-28w5-m45g.json | 4 +--- .../05/GHSA-pgx2-pwxj-8wj5/GHSA-pgx2-pwxj-8wj5.json | 8 ++------ .../05/GHSA-ph3q-wqm6-3342/GHSA-ph3q-wqm6-3342.json | 12 +++--------- .../05/GHSA-phm6-mwmq-vphc/GHSA-phm6-mwmq-vphc.json | 12 +++--------- .../05/GHSA-pjhr-q582-mpq7/GHSA-pjhr-q582-mpq7.json | 8 ++------ .../05/GHSA-pjm3-59jq-w9qm/GHSA-pjm3-59jq-w9qm.json | 8 ++------ .../05/GHSA-pjp7-6p5m-9x45/GHSA-pjp7-6p5m-9x45.json | 8 ++------ .../05/GHSA-pjpj-c8p5-7mqj/GHSA-pjpj-c8p5-7mqj.json | 8 ++------ .../05/GHSA-pm94-gq37-wp9p/GHSA-pm94-gq37-wp9p.json | 12 +++--------- .../05/GHSA-pmfm-r4ww-m6w9/GHSA-pmfm-r4ww-m6w9.json | 12 +++--------- .../05/GHSA-pmhq-p9q2-mpcv/GHSA-pmhq-p9q2-mpcv.json | 8 ++------ .../05/GHSA-pp5r-cwfq-7whf/GHSA-pp5r-cwfq-7whf.json | 8 ++------ .../05/GHSA-pp6c-cmg4-3r6f/GHSA-pp6c-cmg4-3r6f.json | 8 ++------ .../05/GHSA-ppr8-xvjc-pg2w/GHSA-ppr8-xvjc-pg2w.json | 12 +++--------- .../05/GHSA-ppwx-w5v2-mfj6/GHSA-ppwx-w5v2-mfj6.json | 8 ++------ .../05/GHSA-ppxc-h6m6-m746/GHSA-ppxc-h6m6-m746.json | 8 ++------ .../05/GHSA-pq9r-2xxh-vvh7/GHSA-pq9r-2xxh-vvh7.json | 12 +++--------- .../05/GHSA-pqmh-m9r6-3v94/GHSA-pqmh-m9r6-3v94.json | 12 +++--------- .../05/GHSA-pqx2-mg4c-9g67/GHSA-pqx2-mg4c-9g67.json | 8 ++------ .../05/GHSA-pr4x-xmgg-hg68/GHSA-pr4x-xmgg-hg68.json | 8 ++------ .../05/GHSA-pr9v-gfw5-55x8/GHSA-pr9v-gfw5-55x8.json | 8 ++------ .../05/GHSA-prcf-pmh9-cp3p/GHSA-prcf-pmh9-cp3p.json | 12 +++--------- .../05/GHSA-prr6-w5h2-7x5j/GHSA-prr6-w5h2-7x5j.json | 12 +++--------- .../05/GHSA-pv6r-7cj8-5hg8/GHSA-pv6r-7cj8-5hg8.json | 12 +++--------- .../05/GHSA-pv7q-p55j-x95w/GHSA-pv7q-p55j-x95w.json | 12 +++--------- .../05/GHSA-pvhv-j9fj-f3fv/GHSA-pvhv-j9fj-f3fv.json | 8 ++------ .../05/GHSA-pvm8-7672-fw3w/GHSA-pvm8-7672-fw3w.json | 8 ++------ .../05/GHSA-pvx2-q7gm-49v5/GHSA-pvx2-q7gm-49v5.json | 8 ++------ .../05/GHSA-pw96-w628-c9h9/GHSA-pw96-w628-c9h9.json | 8 ++------ .../05/GHSA-px8j-vfm9-79mv/GHSA-px8j-vfm9-79mv.json | 8 ++------ .../05/GHSA-pxc2-7c94-q8j2/GHSA-pxc2-7c94-q8j2.json | 12 +++--------- .../05/GHSA-q24x-376x-hj43/GHSA-q24x-376x-hj43.json | 8 ++------ .../05/GHSA-q299-234g-2fcj/GHSA-q299-234g-2fcj.json | 12 +++--------- .../05/GHSA-q2mm-jgm5-f6mh/GHSA-q2mm-jgm5-f6mh.json | 12 +++--------- .../05/GHSA-q46j-qfxm-6h8p/GHSA-q46j-qfxm-6h8p.json | 8 ++------ .../05/GHSA-q49m-mm5c-vjj3/GHSA-q49m-mm5c-vjj3.json | 12 +++--------- .../05/GHSA-q4c3-5fjh-5v6h/GHSA-q4c3-5fjh-5v6h.json | 8 ++------ .../05/GHSA-q54g-x9rw-493w/GHSA-q54g-x9rw-493w.json | 12 +++--------- .../05/GHSA-q58x-g5cp-qvh7/GHSA-q58x-g5cp-qvh7.json | 12 +++--------- .../05/GHSA-q5h9-gx3c-p258/GHSA-q5h9-gx3c-p258.json | 8 ++------ .../05/GHSA-q6mr-262c-p36r/GHSA-q6mr-262c-p36r.json | 12 +++--------- .../05/GHSA-q6x3-c9cx-g347/GHSA-q6x3-c9cx-g347.json | 12 +++--------- .../05/GHSA-q73x-2fc7-9qwp/GHSA-q73x-2fc7-9qwp.json | 12 +++--------- .../05/GHSA-q94p-v87q-6wp8/GHSA-q94p-v87q-6wp8.json | 8 ++------ .../05/GHSA-q99f-3fh3-fpw2/GHSA-q99f-3fh3-fpw2.json | 12 +++--------- .../05/GHSA-q9j4-589p-rv63/GHSA-q9j4-589p-rv63.json | 12 +++--------- .../05/GHSA-qc7v-hc5r-fq4j/GHSA-qc7v-hc5r-fq4j.json | 8 ++------ .../05/GHSA-qg5j-588p-fv46/GHSA-qg5j-588p-fv46.json | 8 ++------ .../05/GHSA-qg93-hr7r-24gf/GHSA-qg93-hr7r-24gf.json | 8 ++------ .../05/GHSA-qgmf-8pww-37qx/GHSA-qgmf-8pww-37qx.json | 8 ++------ .../05/GHSA-qgrh-w8r5-c899/GHSA-qgrh-w8r5-c899.json | 12 +++--------- .../05/GHSA-qgrw-r3gv-hrmm/GHSA-qgrw-r3gv-hrmm.json | 12 +++--------- .../05/GHSA-qh87-5cc8-25g4/GHSA-qh87-5cc8-25g4.json | 8 ++------ .../05/GHSA-qmg8-cc8v-frfx/GHSA-qmg8-cc8v-frfx.json | 4 +--- .../05/GHSA-qmpc-fmq6-gf8j/GHSA-qmpc-fmq6-gf8j.json | 8 ++------ .../05/GHSA-qp52-95j5-r3g3/GHSA-qp52-95j5-r3g3.json | 8 ++------ .../05/GHSA-qrqj-373x-w46c/GHSA-qrqj-373x-w46c.json | 8 ++------ .../05/GHSA-qv5f-5wgj-j5qf/GHSA-qv5f-5wgj-j5qf.json | 8 ++------ .../05/GHSA-qvfc-hvww-w263/GHSA-qvfc-hvww-w263.json | 8 ++------ .../05/GHSA-qvjp-29px-qgvp/GHSA-qvjp-29px-qgvp.json | 12 +++--------- .../05/GHSA-qw54-4wxm-x2wr/GHSA-qw54-4wxm-x2wr.json | 12 +++--------- .../05/GHSA-qw5p-3fq9-8ggv/GHSA-qw5p-3fq9-8ggv.json | 4 +--- .../05/GHSA-qwpr-3q76-f8c4/GHSA-qwpr-3q76-f8c4.json | 8 ++------ .../05/GHSA-qx3r-96cr-cwr5/GHSA-qx3r-96cr-cwr5.json | 12 +++--------- .../05/GHSA-r26r-fhq6-5rh4/GHSA-r26r-fhq6-5rh4.json | 12 +++--------- .../05/GHSA-r28r-rc5p-jq6v/GHSA-r28r-rc5p-jq6v.json | 12 +++--------- .../05/GHSA-r2mj-75fm-qmqh/GHSA-r2mj-75fm-qmqh.json | 12 +++--------- .../05/GHSA-r35p-8r7c-fmpg/GHSA-r35p-8r7c-fmpg.json | 12 +++--------- .../05/GHSA-r3h6-x6q5-g5r4/GHSA-r3h6-x6q5-g5r4.json | 12 +++--------- .../05/GHSA-r468-mhg7-hr93/GHSA-r468-mhg7-hr93.json | 8 ++------ .../05/GHSA-r586-r9hc-jwq2/GHSA-r586-r9hc-jwq2.json | 8 ++------ .../05/GHSA-r5f7-f8rm-h8x4/GHSA-r5f7-f8rm-h8x4.json | 12 +++--------- .../05/GHSA-r5mj-2hhf-f733/GHSA-r5mj-2hhf-f733.json | 12 +++--------- .../05/GHSA-r5q2-69hv-8pr7/GHSA-r5q2-69hv-8pr7.json | 8 ++------ .../05/GHSA-r5rh-99gw-6c43/GHSA-r5rh-99gw-6c43.json | 12 +++--------- .../05/GHSA-r5vf-j7qp-fjrv/GHSA-r5vf-j7qp-fjrv.json | 12 +++--------- .../05/GHSA-r69j-r7vf-pfx7/GHSA-r69j-r7vf-pfx7.json | 8 ++------ .../05/GHSA-r6gm-mf7m-68qc/GHSA-r6gm-mf7m-68qc.json | 12 +++--------- .../05/GHSA-r6mg-w7qh-6wmq/GHSA-r6mg-w7qh-6wmq.json | 12 +++--------- .../05/GHSA-r73f-5m3v-4rx6/GHSA-r73f-5m3v-4rx6.json | 12 +++--------- .../05/GHSA-r744-c99h-q8c4/GHSA-r744-c99h-q8c4.json | 12 +++--------- .../05/GHSA-r7jp-c6qf-39xv/GHSA-r7jp-c6qf-39xv.json | 12 +++--------- .../05/GHSA-r7r4-mv2j-r29p/GHSA-r7r4-mv2j-r29p.json | 12 +++--------- .../05/GHSA-r7wx-4mj5-7j6j/GHSA-r7wx-4mj5-7j6j.json | 12 +++--------- .../05/GHSA-r858-gg25-px8p/GHSA-r858-gg25-px8p.json | 8 ++------ .../05/GHSA-r8j5-r375-6cxv/GHSA-r8j5-r375-6cxv.json | 8 ++------ .../05/GHSA-r8rx-jmjw-9g68/GHSA-r8rx-jmjw-9g68.json | 8 ++------ .../05/GHSA-r8xv-6hx2-jxhm/GHSA-r8xv-6hx2-jxhm.json | 12 +++--------- .../05/GHSA-r9rm-x4wh-r2gc/GHSA-r9rm-x4wh-r2gc.json | 12 +++--------- .../05/GHSA-r9wv-hpvc-6wj6/GHSA-r9wv-hpvc-6wj6.json | 8 ++------ .../05/GHSA-rg44-2579-ph4x/GHSA-rg44-2579-ph4x.json | 8 ++------ .../05/GHSA-rgj6-8mcc-fqgj/GHSA-rgj6-8mcc-fqgj.json | 12 +++--------- .../05/GHSA-rgjj-vq6w-2826/GHSA-rgjj-vq6w-2826.json | 12 +++--------- .../05/GHSA-rh42-ggpq-295x/GHSA-rh42-ggpq-295x.json | 8 ++------ .../05/GHSA-rhp4-4ff3-m4c6/GHSA-rhp4-4ff3-m4c6.json | 4 +--- .../05/GHSA-rj93-7769-mc4j/GHSA-rj93-7769-mc4j.json | 8 ++------ .../05/GHSA-rppx-3r2h-4mfr/GHSA-rppx-3r2h-4mfr.json | 8 ++------ .../05/GHSA-rpr9-97r4-fr4v/GHSA-rpr9-97r4-fr4v.json | 8 ++------ .../05/GHSA-rq4x-8357-2wpf/GHSA-rq4x-8357-2wpf.json | 12 +++--------- .../05/GHSA-rqxx-8p8c-6h26/GHSA-rqxx-8p8c-6h26.json | 8 ++------ .../05/GHSA-rv9q-r38w-4h48/GHSA-rv9q-r38w-4h48.json | 12 +++--------- .../05/GHSA-rvrw-7cfv-7x29/GHSA-rvrw-7cfv-7x29.json | 8 ++------ .../05/GHSA-rw97-q7v4-xhhq/GHSA-rw97-q7v4-xhhq.json | 4 +--- .../05/GHSA-rwcf-9qwj-85vw/GHSA-rwcf-9qwj-85vw.json | 12 +++--------- .../05/GHSA-rwfg-c7rv-75g7/GHSA-rwfg-c7rv-75g7.json | 8 ++------ .../05/GHSA-rwjf-4f53-289h/GHSA-rwjf-4f53-289h.json | 8 ++------ .../05/GHSA-rx2c-w2cr-c677/GHSA-rx2c-w2cr-c677.json | 8 ++------ .../05/GHSA-rx59-33mv-93w9/GHSA-rx59-33mv-93w9.json | 12 +++--------- .../05/GHSA-rx9m-2wvh-rvjf/GHSA-rx9m-2wvh-rvjf.json | 8 ++------ .../05/GHSA-rxgh-w4w6-hc2v/GHSA-rxgh-w4w6-hc2v.json | 12 +++--------- .../05/GHSA-v25v-x7cf-rjxx/GHSA-v25v-x7cf-rjxx.json | 12 +++--------- .../05/GHSA-v2cc-8mqc-vmq4/GHSA-v2cc-8mqc-vmq4.json | 8 ++------ .../05/GHSA-v45h-m83x-7564/GHSA-v45h-m83x-7564.json | 12 +++--------- .../05/GHSA-v472-q69q-pwf9/GHSA-v472-q69q-pwf9.json | 8 ++------ .../05/GHSA-v4m4-f9f5-pvcm/GHSA-v4m4-f9f5-pvcm.json | 12 +++--------- .../05/GHSA-v55p-34x8-pfvv/GHSA-v55p-34x8-pfvv.json | 8 ++------ .../05/GHSA-v5c4-pw5f-p9f7/GHSA-v5c4-pw5f-p9f7.json | 12 +++--------- .../05/GHSA-v5xc-jmcq-c9fm/GHSA-v5xc-jmcq-c9fm.json | 8 ++------ .../05/GHSA-v6gh-h6v7-p7r2/GHSA-v6gh-h6v7-p7r2.json | 8 ++------ .../05/GHSA-v6gr-qxpq-rwwc/GHSA-v6gr-qxpq-rwwc.json | 12 +++--------- .../05/GHSA-v6r9-9qj6-rrc4/GHSA-v6r9-9qj6-rrc4.json | 12 +++--------- .../05/GHSA-v6xv-gxfj-pv5f/GHSA-v6xv-gxfj-pv5f.json | 12 +++--------- .../05/GHSA-v82c-4hvx-qp92/GHSA-v82c-4hvx-qp92.json | 12 +++--------- .../05/GHSA-v85g-hrr5-4jw4/GHSA-v85g-hrr5-4jw4.json | 8 ++------ .../05/GHSA-v88h-3x82-jgxh/GHSA-v88h-3x82-jgxh.json | 12 +++--------- .../05/GHSA-v8h3-c8g3-cjh3/GHSA-v8h3-c8g3-cjh3.json | 8 ++------ .../05/GHSA-v9gx-j636-r322/GHSA-v9gx-j636-r322.json | 12 +++--------- .../05/GHSA-v9q6-5fj2-jrgh/GHSA-v9q6-5fj2-jrgh.json | 12 +++--------- .../05/GHSA-v9rh-hjph-hq2p/GHSA-v9rh-hjph-hq2p.json | 4 +--- .../05/GHSA-vcfm-2qwg-6qcj/GHSA-vcfm-2qwg-6qcj.json | 12 +++--------- .../05/GHSA-vf3f-4cmj-7ggp/GHSA-vf3f-4cmj-7ggp.json | 12 +++--------- .../05/GHSA-vfw5-ghx2-pfhf/GHSA-vfw5-ghx2-pfhf.json | 8 ++------ .../05/GHSA-vg2h-939c-4p88/GHSA-vg2h-939c-4p88.json | 8 ++------ .../05/GHSA-vhcm-f3gx-wghc/GHSA-vhcm-f3gx-wghc.json | 8 ++------ .../05/GHSA-vhmr-2r99-xhqw/GHSA-vhmr-2r99-xhqw.json | 8 ++------ .../05/GHSA-vm2x-mv9x-52v3/GHSA-vm2x-mv9x-52v3.json | 12 +++--------- .../05/GHSA-vm9v-hfwf-qw4q/GHSA-vm9v-hfwf-qw4q.json | 8 ++------ .../05/GHSA-vmj3-x582-v9f4/GHSA-vmj3-x582-v9f4.json | 8 ++------ .../05/GHSA-vp5m-f62h-hxrm/GHSA-vp5m-f62h-hxrm.json | 12 +++--------- .../05/GHSA-vpfp-r4p5-f5w5/GHSA-vpfp-r4p5-f5w5.json | 8 ++------ .../05/GHSA-vpwg-rrq8-85jp/GHSA-vpwg-rrq8-85jp.json | 12 +++--------- .../05/GHSA-vq47-f2jr-4vpm/GHSA-vq47-f2jr-4vpm.json | 12 +++--------- .../05/GHSA-vv7p-2mjf-r3h3/GHSA-vv7p-2mjf-r3h3.json | 8 ++------ .../05/GHSA-vvj5-mp2m-mfch/GHSA-vvj5-mp2m-mfch.json | 8 ++------ .../05/GHSA-vw9c-7wx5-4jpp/GHSA-vw9c-7wx5-4jpp.json | 8 ++------ .../05/GHSA-vwhg-5hvv-63v5/GHSA-vwhg-5hvv-63v5.json | 8 ++------ .../05/GHSA-vx4g-c7q3-585r/GHSA-vx4g-c7q3-585r.json | 12 +++--------- .../05/GHSA-vxhm-ccj3-8p4x/GHSA-vxhm-ccj3-8p4x.json | 12 +++--------- .../05/GHSA-vxqr-xvg4-5x6g/GHSA-vxqr-xvg4-5x6g.json | 8 ++------ .../05/GHSA-w223-cx42-24c9/GHSA-w223-cx42-24c9.json | 8 ++------ .../05/GHSA-w2gx-ph96-cxcc/GHSA-w2gx-ph96-cxcc.json | 8 ++------ .../05/GHSA-w35j-g472-jv3v/GHSA-w35j-g472-jv3v.json | 12 +++--------- .../05/GHSA-w3v7-hj7c-4j8f/GHSA-w3v7-hj7c-4j8f.json | 12 +++--------- .../05/GHSA-w43r-pcrq-vv2g/GHSA-w43r-pcrq-vv2g.json | 12 +++--------- .../05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json | 12 +++--------- .../05/GHSA-w53g-xqvq-mxh2/GHSA-w53g-xqvq-mxh2.json | 8 ++------ .../05/GHSA-w56q-wh4x-c2m7/GHSA-w56q-wh4x-c2m7.json | 8 ++------ .../05/GHSA-w5fh-xc33-v3f8/GHSA-w5fh-xc33-v3f8.json | 12 +++--------- .../05/GHSA-w5hm-7wh2-cc9c/GHSA-w5hm-7wh2-cc9c.json | 8 ++------ .../05/GHSA-w7g6-jv49-6cp7/GHSA-w7g6-jv49-6cp7.json | 8 ++------ .../05/GHSA-w7mg-q4hh-m9cq/GHSA-w7mg-q4hh-m9cq.json | 4 +--- .../05/GHSA-w84r-7vwm-vm7g/GHSA-w84r-7vwm-vm7g.json | 12 +++--------- .../05/GHSA-w8h2-jg46-g9xc/GHSA-w8h2-jg46-g9xc.json | 8 ++------ .../05/GHSA-w94w-cg39-6r6h/GHSA-w94w-cg39-6r6h.json | 8 ++------ .../05/GHSA-w9hr-wfmh-pm4j/GHSA-w9hr-wfmh-pm4j.json | 12 +++--------- .../05/GHSA-w9p6-rcg9-9vph/GHSA-w9p6-rcg9-9vph.json | 8 ++------ .../05/GHSA-w9xf-mr89-vp4r/GHSA-w9xf-mr89-vp4r.json | 8 ++------ .../05/GHSA-wj9q-3vrf-hwq5/GHSA-wj9q-3vrf-hwq5.json | 8 ++------ .../05/GHSA-wjg5-m2mm-fgxq/GHSA-wjg5-m2mm-fgxq.json | 12 +++--------- .../05/GHSA-wjmj-5m9r-gc4v/GHSA-wjmj-5m9r-gc4v.json | 12 +++--------- .../05/GHSA-wjxv-ccw6-j9xh/GHSA-wjxv-ccw6-j9xh.json | 8 ++------ .../05/GHSA-wmgh-vqmx-5rqc/GHSA-wmgh-vqmx-5rqc.json | 12 +++--------- .../05/GHSA-wp92-gm3h-j7wf/GHSA-wp92-gm3h-j7wf.json | 12 +++--------- .../05/GHSA-wpcw-xfjj-3ghr/GHSA-wpcw-xfjj-3ghr.json | 8 ++------ .../05/GHSA-wpfw-qhxf-9cj3/GHSA-wpfw-qhxf-9cj3.json | 8 ++------ .../05/GHSA-wqhf-5xw8-mmcg/GHSA-wqhf-5xw8-mmcg.json | 12 +++--------- .../05/GHSA-wrf6-c8xc-j546/GHSA-wrf6-c8xc-j546.json | 12 +++--------- .../05/GHSA-wrx8-cxgj-cgpv/GHSA-wrx8-cxgj-cgpv.json | 12 +++--------- .../05/GHSA-wvpq-xgwf-69c4/GHSA-wvpq-xgwf-69c4.json | 8 ++------ .../05/GHSA-wxr2-mrr4-q9hf/GHSA-wxr2-mrr4-q9hf.json | 12 +++--------- .../05/GHSA-x2cf-7hfw-w548/GHSA-x2cf-7hfw-w548.json | 12 +++--------- .../05/GHSA-x2gv-qh97-xh45/GHSA-x2gv-qh97-xh45.json | 8 ++------ .../05/GHSA-x2rx-8768-8678/GHSA-x2rx-8768-8678.json | 12 +++--------- .../05/GHSA-x3p7-g646-9j92/GHSA-x3p7-g646-9j92.json | 12 +++--------- .../05/GHSA-x3xc-8qqv-4cq8/GHSA-x3xc-8qqv-4cq8.json | 12 +++--------- .../05/GHSA-x46p-9wf3-mvmp/GHSA-x46p-9wf3-mvmp.json | 12 +++--------- .../05/GHSA-x4g6-37v9-377w/GHSA-x4g6-37v9-377w.json | 12 +++--------- .../05/GHSA-x53f-v73q-grpf/GHSA-x53f-v73q-grpf.json | 8 ++------ .../05/GHSA-x59g-h3vc-hf9j/GHSA-x59g-h3vc-hf9j.json | 12 +++--------- .../05/GHSA-x5cv-hcpc-5cg5/GHSA-x5cv-hcpc-5cg5.json | 8 ++------ .../05/GHSA-x674-v2h5-xvcx/GHSA-x674-v2h5-xvcx.json | 12 +++--------- .../05/GHSA-x6jw-v4hx-374p/GHSA-x6jw-v4hx-374p.json | 12 +++--------- .../05/GHSA-x6v6-9qqg-hhvf/GHSA-x6v6-9qqg-hhvf.json | 12 +++--------- .../05/GHSA-x75m-rrhq-6j68/GHSA-x75m-rrhq-6j68.json | 8 ++------ .../05/GHSA-x769-h2xc-fqfm/GHSA-x769-h2xc-fqfm.json | 8 ++------ .../05/GHSA-x76c-rg5r-5gmh/GHSA-x76c-rg5r-5gmh.json | 12 +++--------- .../05/GHSA-x7q6-g5fx-vhrw/GHSA-x7q6-g5fx-vhrw.json | 8 ++------ .../05/GHSA-x8c7-9c7c-54qw/GHSA-x8c7-9c7c-54qw.json | 8 ++------ .../05/GHSA-x8hm-6jcv-6xvm/GHSA-x8hm-6jcv-6xvm.json | 8 ++------ .../05/GHSA-x9h5-7586-77cw/GHSA-x9h5-7586-77cw.json | 8 ++------ .../05/GHSA-x9pw-33c7-c62h/GHSA-x9pw-33c7-c62h.json | 12 +++--------- .../05/GHSA-xc3q-g386-79q2/GHSA-xc3q-g386-79q2.json | 12 +++--------- .../05/GHSA-xc6m-h9mw-r768/GHSA-xc6m-h9mw-r768.json | 12 +++--------- .../05/GHSA-xc74-475v-6rmv/GHSA-xc74-475v-6rmv.json | 8 ++------ .../05/GHSA-xcwx-pcf9-m967/GHSA-xcwx-pcf9-m967.json | 12 +++--------- .../05/GHSA-xf53-rwx9-rc7p/GHSA-xf53-rwx9-rc7p.json | 12 +++--------- .../05/GHSA-xfc4-9c23-wc6x/GHSA-xfc4-9c23-wc6x.json | 12 +++--------- .../05/GHSA-xfmp-2r38-cvc9/GHSA-xfmp-2r38-cvc9.json | 12 +++--------- .../05/GHSA-xg34-xq74-8f84/GHSA-xg34-xq74-8f84.json | 8 ++------ .../05/GHSA-xg3v-w3xq-cxvq/GHSA-xg3v-w3xq-cxvq.json | 8 ++------ .../05/GHSA-xg59-cx23-x6f3/GHSA-xg59-cx23-x6f3.json | 8 ++------ .../05/GHSA-xg82-h5j4-q6gx/GHSA-xg82-h5j4-q6gx.json | 12 +++--------- .../05/GHSA-xg8c-mw7j-wcv9/GHSA-xg8c-mw7j-wcv9.json | 8 ++------ .../05/GHSA-xgh4-3f7c-mx5r/GHSA-xgh4-3f7c-mx5r.json | 8 ++------ .../05/GHSA-xgpq-2x7g-ffgx/GHSA-xgpq-2x7g-ffgx.json | 12 +++--------- .../05/GHSA-xj59-9qjv-fr54/GHSA-xj59-9qjv-fr54.json | 4 +--- .../05/GHSA-xj7g-89cx-mvvj/GHSA-xj7g-89cx-mvvj.json | 12 +++--------- .../05/GHSA-xj84-6q8f-qg2r/GHSA-xj84-6q8f-qg2r.json | 8 ++------ .../05/GHSA-xjc5-mpgm-fw42/GHSA-xjc5-mpgm-fw42.json | 12 +++--------- .../05/GHSA-xjfw-c7mm-g73f/GHSA-xjfw-c7mm-g73f.json | 8 ++------ .../05/GHSA-xjhh-xcpq-fjx4/GHSA-xjhh-xcpq-fjx4.json | 4 +--- .../05/GHSA-xjjw-7hwm-mx4p/GHSA-xjjw-7hwm-mx4p.json | 8 ++------ .../05/GHSA-xjq6-gc34-j23x/GHSA-xjq6-gc34-j23x.json | 12 +++--------- .../05/GHSA-xm59-x79v-w7q2/GHSA-xm59-x79v-w7q2.json | 8 ++------ .../05/GHSA-xmgm-2h3h-mxf9/GHSA-xmgm-2h3h-mxf9.json | 12 +++--------- .../05/GHSA-xpfg-jhxj-qw6x/GHSA-xpfg-jhxj-qw6x.json | 12 +++--------- .../05/GHSA-xq69-cxjh-f23r/GHSA-xq69-cxjh-f23r.json | 8 ++------ .../05/GHSA-xq7h-5h92-cwp8/GHSA-xq7h-5h92-cwp8.json | 4 +--- .../05/GHSA-xq9f-582r-p2j7/GHSA-xq9f-582r-p2j7.json | 12 +++--------- .../05/GHSA-xqm9-4fqc-qh7w/GHSA-xqm9-4fqc-qh7w.json | 8 ++------ .../05/GHSA-xqxh-7x7w-p8r9/GHSA-xqxh-7x7w-p8r9.json | 8 ++------ .../05/GHSA-xr3p-gm2p-7rx5/GHSA-xr3p-gm2p-7rx5.json | 8 ++------ .../05/GHSA-xv56-7cfh-4v8j/GHSA-xv56-7cfh-4v8j.json | 12 +++--------- .../05/GHSA-xv9c-g2v7-9668/GHSA-xv9c-g2v7-9668.json | 12 +++--------- .../05/GHSA-xvx9-w67v-7f8g/GHSA-xvx9-w67v-7f8g.json | 12 +++--------- .../05/GHSA-xwjq-2p97-r884/GHSA-xwjq-2p97-r884.json | 12 +++--------- .../05/GHSA-xwpw-2x24-24ff/GHSA-xwpw-2x24-24ff.json | 12 +++--------- .../05/GHSA-xwvm-8x4q-gmr9/GHSA-xwvm-8x4q-gmr9.json | 8 ++------ .../05/GHSA-xxj5-mhw2-jgp8/GHSA-xxj5-mhw2-jgp8.json | 12 +++--------- .../05/GHSA-xxmf-w3h3-38rf/GHSA-xxmf-w3h3-38rf.json | 8 ++------ .../07/GHSA-4m45-43xg-8rr7/GHSA-4m45-43xg-8rr7.json | 4 +--- .../10/GHSA-ph82-g2mr-p678/GHSA-ph82-g2mr-p678.json | 4 +--- .../01/GHSA-2p3f-3cj6-r8vv/GHSA-2p3f-3cj6-r8vv.json | 4 +--- .../01/GHSA-3c29-2h4x-fgg4/GHSA-3c29-2h4x-fgg4.json | 4 +--- .../01/GHSA-3f9r-qr29-wv82/GHSA-3f9r-qr29-wv82.json | 4 +--- .../01/GHSA-552w-fg8f-29x6/GHSA-552w-fg8f-29x6.json | 4 +--- .../01/GHSA-7v6p-hrxh-28hh/GHSA-7v6p-hrxh-28hh.json | 4 +--- .../01/GHSA-8phc-jhvp-25cw/GHSA-8phc-jhvp-25cw.json | 4 +--- .../01/GHSA-ch9p-8jp8-qjvq/GHSA-ch9p-8jp8-qjvq.json | 4 +--- .../01/GHSA-f632-r9w6-239m/GHSA-f632-r9w6-239m.json | 4 +--- .../01/GHSA-f6x7-q479-7278/GHSA-f6x7-q479-7278.json | 4 +--- .../01/GHSA-ghq7-9x63-pxqp/GHSA-ghq7-9x63-pxqp.json | 4 +--- .../01/GHSA-jpc4-x6x2-7pm8/GHSA-jpc4-x6x2-7pm8.json | 4 +--- .../01/GHSA-mqwr-55wx-37jr/GHSA-mqwr-55wx-37jr.json | 4 +--- .../01/GHSA-q9cw-p99m-h9cm/GHSA-q9cw-p99m-h9cm.json | 4 +--- .../01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json | 4 +--- .../05/GHSA-c538-wc3x-p8rv/GHSA-c538-wc3x-p8rv.json | 4 +--- .../06/GHSA-259f-xj2w-xw2m/GHSA-259f-xj2w-xw2m.json | 4 +--- .../06/GHSA-2vwm-3r62-68r6/GHSA-2vwm-3r62-68r6.json | 4 +--- .../06/GHSA-36cf-mq32-6x43/GHSA-36cf-mq32-6x43.json | 4 +--- .../06/GHSA-3cc8-7xhw-x4w6/GHSA-3cc8-7xhw-x4w6.json | 4 +--- .../06/GHSA-3vhf-gvj3-rcch/GHSA-3vhf-gvj3-rcch.json | 4 +--- .../06/GHSA-3w29-9x4p-299p/GHSA-3w29-9x4p-299p.json | 4 +--- .../06/GHSA-43w3-q4jr-pw7r/GHSA-43w3-q4jr-pw7r.json | 4 +--- .../06/GHSA-4xhv-7cw3-294h/GHSA-4xhv-7cw3-294h.json | 4 +--- .../06/GHSA-5578-g33f-6mjj/GHSA-5578-g33f-6mjj.json | 4 +--- .../06/GHSA-83pr-wj87-jf6x/GHSA-83pr-wj87-jf6x.json | 8 ++------ .../06/GHSA-89jq-r228-vm9c/GHSA-89jq-r228-vm9c.json | 4 +--- .../06/GHSA-97x2-r642-2777/GHSA-97x2-r642-2777.json | 4 +--- .../06/GHSA-9v84-f7vm-8f87/GHSA-9v84-f7vm-8f87.json | 4 +--- .../06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json | 4 +--- .../06/GHSA-cwpm-xghv-px2h/GHSA-cwpm-xghv-px2h.json | 12 +++--------- .../06/GHSA-f3x6-gr53-7hc5/GHSA-f3x6-gr53-7hc5.json | 4 +--- .../06/GHSA-gv35-xq5j-3wj5/GHSA-gv35-xq5j-3wj5.json | 4 +--- .../06/GHSA-h44r-7f3w-cmm3/GHSA-h44r-7f3w-cmm3.json | 4 +--- .../06/GHSA-j6mp-97gj-pg59/GHSA-j6mp-97gj-pg59.json | 4 +--- .../06/GHSA-j76w-hgqv-3vg4/GHSA-j76w-hgqv-3vg4.json | 8 ++------ .../06/GHSA-j9vm-x4wf-38gg/GHSA-j9vm-x4wf-38gg.json | 4 +--- .../06/GHSA-m388-cvx4-q52g/GHSA-m388-cvx4-q52g.json | 4 +--- .../06/GHSA-mjfj-95fm-27mx/GHSA-mjfj-95fm-27mx.json | 12 +++--------- .../06/GHSA-ph46-7fpg-mqx8/GHSA-ph46-7fpg-mqx8.json | 4 +--- .../06/GHSA-px27-wcgr-7gf5/GHSA-px27-wcgr-7gf5.json | 8 ++------ .../06/GHSA-q49m-qrh9-4jc8/GHSA-q49m-qrh9-4jc8.json | 8 ++------ .../06/GHSA-q9fc-6fvr-wxg5/GHSA-q9fc-6fvr-wxg5.json | 4 +--- .../06/GHSA-qm52-rrfg-jwc6/GHSA-qm52-rrfg-jwc6.json | 4 +--- .../06/GHSA-v9rm-3p9p-c283/GHSA-v9rm-3p9p-c283.json | 4 +--- .../06/GHSA-vhv4-j9cm-5cjx/GHSA-vhv4-j9cm-5cjx.json | 4 +--- .../06/GHSA-w2vq-f5f5-hrv8/GHSA-w2vq-f5f5-hrv8.json | 4 +--- .../06/GHSA-wp7r-cfw6-7758/GHSA-wp7r-cfw6-7758.json | 4 +--- .../06/GHSA-x6mf-qhjj-pcj9/GHSA-x6mf-qhjj-pcj9.json | 4 +--- 997 files changed, 2328 insertions(+), 6984 deletions(-) diff --git a/advisories/github-reviewed/2022/05/GHSA-rp7r-79rm-2758/GHSA-rp7r-79rm-2758.json b/advisories/github-reviewed/2022/05/GHSA-rp7r-79rm-2758/GHSA-rp7r-79rm-2758.json index c2ec9e5ddd2..373c5d28385 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rp7r-79rm-2758/GHSA-rp7r-79rm-2758.json +++ b/advisories/github-reviewed/2022/05/GHSA-rp7r-79rm-2758/GHSA-rp7r-79rm-2758.json @@ -8,9 +8,7 @@ ], "summary": "Apache Derby exposes user and password attributes", "details": "Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/01/GHSA-4r2f-6fm9-2qgh/GHSA-4r2f-6fm9-2qgh.json b/advisories/github-reviewed/2023/01/GHSA-4r2f-6fm9-2qgh/GHSA-4r2f-6fm9-2qgh.json index 1e7582a7965..d4ff0ff2be4 100644 --- a/advisories/github-reviewed/2023/01/GHSA-4r2f-6fm9-2qgh/GHSA-4r2f-6fm9-2qgh.json +++ b/advisories/github-reviewed/2023/01/GHSA-4r2f-6fm9-2qgh/GHSA-4r2f-6fm9-2qgh.json @@ -65,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-01-10T22:16:53Z", diff --git a/advisories/unreviewed/2022/02/GHSA-26cp-j78f-2568/GHSA-26cp-j78f-2568.json b/advisories/unreviewed/2022/02/GHSA-26cp-j78f-2568/GHSA-26cp-j78f-2568.json index a149a1f564d..7edfc81eb53 100644 --- a/advisories/unreviewed/2022/02/GHSA-26cp-j78f-2568/GHSA-26cp-j78f-2568.json +++ b/advisories/unreviewed/2022/02/GHSA-26cp-j78f-2568/GHSA-26cp-j78f-2568.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-2gx5-p7gf-5xrc/GHSA-2gx5-p7gf-5xrc.json b/advisories/unreviewed/2022/02/GHSA-2gx5-p7gf-5xrc/GHSA-2gx5-p7gf-5xrc.json index b3a4bd30f38..5ecd0ef2d1f 100644 --- a/advisories/unreviewed/2022/02/GHSA-2gx5-p7gf-5xrc/GHSA-2gx5-p7gf-5xrc.json +++ b/advisories/unreviewed/2022/02/GHSA-2gx5-p7gf-5xrc/GHSA-2gx5-p7gf-5xrc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-3jrq-4wj8-868w/GHSA-3jrq-4wj8-868w.json b/advisories/unreviewed/2022/02/GHSA-3jrq-4wj8-868w/GHSA-3jrq-4wj8-868w.json index 0564211966b..2fd1d188f7f 100644 --- a/advisories/unreviewed/2022/02/GHSA-3jrq-4wj8-868w/GHSA-3jrq-4wj8-868w.json +++ b/advisories/unreviewed/2022/02/GHSA-3jrq-4wj8-868w/GHSA-3jrq-4wj8-868w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-3v6x-9jmh-gp3w/GHSA-3v6x-9jmh-gp3w.json b/advisories/unreviewed/2022/02/GHSA-3v6x-9jmh-gp3w/GHSA-3v6x-9jmh-gp3w.json index 2493f06e77b..6df17c6a899 100644 --- a/advisories/unreviewed/2022/02/GHSA-3v6x-9jmh-gp3w/GHSA-3v6x-9jmh-gp3w.json +++ b/advisories/unreviewed/2022/02/GHSA-3v6x-9jmh-gp3w/GHSA-3v6x-9jmh-gp3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-4m96-r76q-68qp/GHSA-4m96-r76q-68qp.json b/advisories/unreviewed/2022/02/GHSA-4m96-r76q-68qp/GHSA-4m96-r76q-68qp.json index 131c35fe7af..8014ad6bc35 100644 --- a/advisories/unreviewed/2022/02/GHSA-4m96-r76q-68qp/GHSA-4m96-r76q-68qp.json +++ b/advisories/unreviewed/2022/02/GHSA-4m96-r76q-68qp/GHSA-4m96-r76q-68qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-4x25-3w8p-m6r3/GHSA-4x25-3w8p-m6r3.json b/advisories/unreviewed/2022/02/GHSA-4x25-3w8p-m6r3/GHSA-4x25-3w8p-m6r3.json index ff1ac58c37c..7b6ec4741b6 100644 --- a/advisories/unreviewed/2022/02/GHSA-4x25-3w8p-m6r3/GHSA-4x25-3w8p-m6r3.json +++ b/advisories/unreviewed/2022/02/GHSA-4x25-3w8p-m6r3/GHSA-4x25-3w8p-m6r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json b/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json index 662146b927a..45c72ca540f 100644 --- a/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json +++ b/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-686w-6g2q-xqqm/GHSA-686w-6g2q-xqqm.json b/advisories/unreviewed/2022/02/GHSA-686w-6g2q-xqqm/GHSA-686w-6g2q-xqqm.json index 62cea55f404..3d378d8e3fc 100644 --- a/advisories/unreviewed/2022/02/GHSA-686w-6g2q-xqqm/GHSA-686w-6g2q-xqqm.json +++ b/advisories/unreviewed/2022/02/GHSA-686w-6g2q-xqqm/GHSA-686w-6g2q-xqqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6929-2rrj-qg4c/GHSA-6929-2rrj-qg4c.json b/advisories/unreviewed/2022/02/GHSA-6929-2rrj-qg4c/GHSA-6929-2rrj-qg4c.json index bebc545bc0c..dbb2455fd90 100644 --- a/advisories/unreviewed/2022/02/GHSA-6929-2rrj-qg4c/GHSA-6929-2rrj-qg4c.json +++ b/advisories/unreviewed/2022/02/GHSA-6929-2rrj-qg4c/GHSA-6929-2rrj-qg4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6h65-gfvx-7g45/GHSA-6h65-gfvx-7g45.json b/advisories/unreviewed/2022/02/GHSA-6h65-gfvx-7g45/GHSA-6h65-gfvx-7g45.json index 4e090f5ed3d..6072d101a1c 100644 --- a/advisories/unreviewed/2022/02/GHSA-6h65-gfvx-7g45/GHSA-6h65-gfvx-7g45.json +++ b/advisories/unreviewed/2022/02/GHSA-6h65-gfvx-7g45/GHSA-6h65-gfvx-7g45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6hfv-x97p-vvg3/GHSA-6hfv-x97p-vvg3.json b/advisories/unreviewed/2022/02/GHSA-6hfv-x97p-vvg3/GHSA-6hfv-x97p-vvg3.json index e7167e1aa33..9776fb6ca6a 100644 --- a/advisories/unreviewed/2022/02/GHSA-6hfv-x97p-vvg3/GHSA-6hfv-x97p-vvg3.json +++ b/advisories/unreviewed/2022/02/GHSA-6hfv-x97p-vvg3/GHSA-6hfv-x97p-vvg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-88wr-wm4j-qgww/GHSA-88wr-wm4j-qgww.json b/advisories/unreviewed/2022/02/GHSA-88wr-wm4j-qgww/GHSA-88wr-wm4j-qgww.json index b645bbfab88..bd5b6ca54f1 100644 --- a/advisories/unreviewed/2022/02/GHSA-88wr-wm4j-qgww/GHSA-88wr-wm4j-qgww.json +++ b/advisories/unreviewed/2022/02/GHSA-88wr-wm4j-qgww/GHSA-88wr-wm4j-qgww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-8cwr-c3m7-p68g/GHSA-8cwr-c3m7-p68g.json b/advisories/unreviewed/2022/02/GHSA-8cwr-c3m7-p68g/GHSA-8cwr-c3m7-p68g.json index 2ef3f5b3882..c3da0c58821 100644 --- a/advisories/unreviewed/2022/02/GHSA-8cwr-c3m7-p68g/GHSA-8cwr-c3m7-p68g.json +++ b/advisories/unreviewed/2022/02/GHSA-8cwr-c3m7-p68g/GHSA-8cwr-c3m7-p68g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-95j3-jpcx-676c/GHSA-95j3-jpcx-676c.json b/advisories/unreviewed/2022/02/GHSA-95j3-jpcx-676c/GHSA-95j3-jpcx-676c.json index 52a4b2aa578..318d37a0a60 100644 --- a/advisories/unreviewed/2022/02/GHSA-95j3-jpcx-676c/GHSA-95j3-jpcx-676c.json +++ b/advisories/unreviewed/2022/02/GHSA-95j3-jpcx-676c/GHSA-95j3-jpcx-676c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-9jrj-j4fv-jrw5/GHSA-9jrj-j4fv-jrw5.json b/advisories/unreviewed/2022/02/GHSA-9jrj-j4fv-jrw5/GHSA-9jrj-j4fv-jrw5.json index 400b7fb0428..232df359291 100644 --- a/advisories/unreviewed/2022/02/GHSA-9jrj-j4fv-jrw5/GHSA-9jrj-j4fv-jrw5.json +++ b/advisories/unreviewed/2022/02/GHSA-9jrj-j4fv-jrw5/GHSA-9jrj-j4fv-jrw5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-c687-vfr7-48m9/GHSA-c687-vfr7-48m9.json b/advisories/unreviewed/2022/02/GHSA-c687-vfr7-48m9/GHSA-c687-vfr7-48m9.json index 9802a3b5261..801603b9ad7 100644 --- a/advisories/unreviewed/2022/02/GHSA-c687-vfr7-48m9/GHSA-c687-vfr7-48m9.json +++ b/advisories/unreviewed/2022/02/GHSA-c687-vfr7-48m9/GHSA-c687-vfr7-48m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-c7h9-7hmq-v389/GHSA-c7h9-7hmq-v389.json b/advisories/unreviewed/2022/02/GHSA-c7h9-7hmq-v389/GHSA-c7h9-7hmq-v389.json index 79842c91535..3c578ccb50c 100644 --- a/advisories/unreviewed/2022/02/GHSA-c7h9-7hmq-v389/GHSA-c7h9-7hmq-v389.json +++ b/advisories/unreviewed/2022/02/GHSA-c7h9-7hmq-v389/GHSA-c7h9-7hmq-v389.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-fpv7-mhhr-h93x/GHSA-fpv7-mhhr-h93x.json b/advisories/unreviewed/2022/02/GHSA-fpv7-mhhr-h93x/GHSA-fpv7-mhhr-h93x.json index 7621cddc799..247fa52d07c 100644 --- a/advisories/unreviewed/2022/02/GHSA-fpv7-mhhr-h93x/GHSA-fpv7-mhhr-h93x.json +++ b/advisories/unreviewed/2022/02/GHSA-fpv7-mhhr-h93x/GHSA-fpv7-mhhr-h93x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-g8ch-3jp7-hcm8/GHSA-g8ch-3jp7-hcm8.json b/advisories/unreviewed/2022/02/GHSA-g8ch-3jp7-hcm8/GHSA-g8ch-3jp7-hcm8.json index a98982a8c73..3f9b0f18a5a 100644 --- a/advisories/unreviewed/2022/02/GHSA-g8ch-3jp7-hcm8/GHSA-g8ch-3jp7-hcm8.json +++ b/advisories/unreviewed/2022/02/GHSA-g8ch-3jp7-hcm8/GHSA-g8ch-3jp7-hcm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-gh6g-9qgj-hq8v/GHSA-gh6g-9qgj-hq8v.json b/advisories/unreviewed/2022/02/GHSA-gh6g-9qgj-hq8v/GHSA-gh6g-9qgj-hq8v.json index 02498195aaa..fef3a02efd2 100644 --- a/advisories/unreviewed/2022/02/GHSA-gh6g-9qgj-hq8v/GHSA-gh6g-9qgj-hq8v.json +++ b/advisories/unreviewed/2022/02/GHSA-gh6g-9qgj-hq8v/GHSA-gh6g-9qgj-hq8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-gw5x-mfp3-c35v/GHSA-gw5x-mfp3-c35v.json b/advisories/unreviewed/2022/02/GHSA-gw5x-mfp3-c35v/GHSA-gw5x-mfp3-c35v.json index 54949120300..d0cb41db9be 100644 --- a/advisories/unreviewed/2022/02/GHSA-gw5x-mfp3-c35v/GHSA-gw5x-mfp3-c35v.json +++ b/advisories/unreviewed/2022/02/GHSA-gw5x-mfp3-c35v/GHSA-gw5x-mfp3-c35v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-h874-8cgj-mc28/GHSA-h874-8cgj-mc28.json b/advisories/unreviewed/2022/02/GHSA-h874-8cgj-mc28/GHSA-h874-8cgj-mc28.json index b54f3e7b9bb..2e1c544fa48 100644 --- a/advisories/unreviewed/2022/02/GHSA-h874-8cgj-mc28/GHSA-h874-8cgj-mc28.json +++ b/advisories/unreviewed/2022/02/GHSA-h874-8cgj-mc28/GHSA-h874-8cgj-mc28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json b/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json index a3cf7299899..363a0a516e1 100644 --- a/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json +++ b/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-j2hv-f29h-c9g3/GHSA-j2hv-f29h-c9g3.json b/advisories/unreviewed/2022/02/GHSA-j2hv-f29h-c9g3/GHSA-j2hv-f29h-c9g3.json index b88f976f36d..4e547646e8e 100644 --- a/advisories/unreviewed/2022/02/GHSA-j2hv-f29h-c9g3/GHSA-j2hv-f29h-c9g3.json +++ b/advisories/unreviewed/2022/02/GHSA-j2hv-f29h-c9g3/GHSA-j2hv-f29h-c9g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-jfq8-f4p4-5mpx/GHSA-jfq8-f4p4-5mpx.json b/advisories/unreviewed/2022/02/GHSA-jfq8-f4p4-5mpx/GHSA-jfq8-f4p4-5mpx.json index fed1d17097e..c85bee1a07e 100644 --- a/advisories/unreviewed/2022/02/GHSA-jfq8-f4p4-5mpx/GHSA-jfq8-f4p4-5mpx.json +++ b/advisories/unreviewed/2022/02/GHSA-jfq8-f4p4-5mpx/GHSA-jfq8-f4p4-5mpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-m3mj-2hwv-qf3q/GHSA-m3mj-2hwv-qf3q.json b/advisories/unreviewed/2022/02/GHSA-m3mj-2hwv-qf3q/GHSA-m3mj-2hwv-qf3q.json index e25ea0f2c92..228e9901708 100644 --- a/advisories/unreviewed/2022/02/GHSA-m3mj-2hwv-qf3q/GHSA-m3mj-2hwv-qf3q.json +++ b/advisories/unreviewed/2022/02/GHSA-m3mj-2hwv-qf3q/GHSA-m3mj-2hwv-qf3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-m6c9-29mj-cjh4/GHSA-m6c9-29mj-cjh4.json b/advisories/unreviewed/2022/02/GHSA-m6c9-29mj-cjh4/GHSA-m6c9-29mj-cjh4.json index 656b4846c3c..d700d4ceb2d 100644 --- a/advisories/unreviewed/2022/02/GHSA-m6c9-29mj-cjh4/GHSA-m6c9-29mj-cjh4.json +++ b/advisories/unreviewed/2022/02/GHSA-m6c9-29mj-cjh4/GHSA-m6c9-29mj-cjh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-m74m-wrhv-h6gc/GHSA-m74m-wrhv-h6gc.json b/advisories/unreviewed/2022/02/GHSA-m74m-wrhv-h6gc/GHSA-m74m-wrhv-h6gc.json index 9eefc38a6ee..ad7203c5ddf 100644 --- a/advisories/unreviewed/2022/02/GHSA-m74m-wrhv-h6gc/GHSA-m74m-wrhv-h6gc.json +++ b/advisories/unreviewed/2022/02/GHSA-m74m-wrhv-h6gc/GHSA-m74m-wrhv-h6gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-p64x-c79m-m5mv/GHSA-p64x-c79m-m5mv.json b/advisories/unreviewed/2022/02/GHSA-p64x-c79m-m5mv/GHSA-p64x-c79m-m5mv.json index 909ff5c0abc..c90c1de84fa 100644 --- a/advisories/unreviewed/2022/02/GHSA-p64x-c79m-m5mv/GHSA-p64x-c79m-m5mv.json +++ b/advisories/unreviewed/2022/02/GHSA-p64x-c79m-m5mv/GHSA-p64x-c79m-m5mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-ph25-g94c-mv3m/GHSA-ph25-g94c-mv3m.json b/advisories/unreviewed/2022/02/GHSA-ph25-g94c-mv3m/GHSA-ph25-g94c-mv3m.json index e3b7982b40f..1ca963e06e8 100644 --- a/advisories/unreviewed/2022/02/GHSA-ph25-g94c-mv3m/GHSA-ph25-g94c-mv3m.json +++ b/advisories/unreviewed/2022/02/GHSA-ph25-g94c-mv3m/GHSA-ph25-g94c-mv3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-phcp-hchw-q7wq/GHSA-phcp-hchw-q7wq.json b/advisories/unreviewed/2022/02/GHSA-phcp-hchw-q7wq/GHSA-phcp-hchw-q7wq.json index c1be1cc2116..1e9e50e74f0 100644 --- a/advisories/unreviewed/2022/02/GHSA-phcp-hchw-q7wq/GHSA-phcp-hchw-q7wq.json +++ b/advisories/unreviewed/2022/02/GHSA-phcp-hchw-q7wq/GHSA-phcp-hchw-q7wq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-q95j-mchg-p72p/GHSA-q95j-mchg-p72p.json b/advisories/unreviewed/2022/02/GHSA-q95j-mchg-p72p/GHSA-q95j-mchg-p72p.json index ab0204e28ad..d9e946907f1 100644 --- a/advisories/unreviewed/2022/02/GHSA-q95j-mchg-p72p/GHSA-q95j-mchg-p72p.json +++ b/advisories/unreviewed/2022/02/GHSA-q95j-mchg-p72p/GHSA-q95j-mchg-p72p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-r8hj-jj45-xp7m/GHSA-r8hj-jj45-xp7m.json b/advisories/unreviewed/2022/02/GHSA-r8hj-jj45-xp7m/GHSA-r8hj-jj45-xp7m.json index b09c1e96e16..fc0b1d0c82b 100644 --- a/advisories/unreviewed/2022/02/GHSA-r8hj-jj45-xp7m/GHSA-r8hj-jj45-xp7m.json +++ b/advisories/unreviewed/2022/02/GHSA-r8hj-jj45-xp7m/GHSA-r8hj-jj45-xp7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-rw8g-79g2-chq8/GHSA-rw8g-79g2-chq8.json b/advisories/unreviewed/2022/02/GHSA-rw8g-79g2-chq8/GHSA-rw8g-79g2-chq8.json index 1c3f3b02f28..0a17ef3d8bc 100644 --- a/advisories/unreviewed/2022/02/GHSA-rw8g-79g2-chq8/GHSA-rw8g-79g2-chq8.json +++ b/advisories/unreviewed/2022/02/GHSA-rw8g-79g2-chq8/GHSA-rw8g-79g2-chq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-v486-mqfx-fv74/GHSA-v486-mqfx-fv74.json b/advisories/unreviewed/2022/02/GHSA-v486-mqfx-fv74/GHSA-v486-mqfx-fv74.json index 5046305cf66..77657395812 100644 --- a/advisories/unreviewed/2022/02/GHSA-v486-mqfx-fv74/GHSA-v486-mqfx-fv74.json +++ b/advisories/unreviewed/2022/02/GHSA-v486-mqfx-fv74/GHSA-v486-mqfx-fv74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-v84f-rwh8-v99h/GHSA-v84f-rwh8-v99h.json b/advisories/unreviewed/2022/02/GHSA-v84f-rwh8-v99h/GHSA-v84f-rwh8-v99h.json index a9d9ea8fbbe..08739a944d3 100644 --- a/advisories/unreviewed/2022/02/GHSA-v84f-rwh8-v99h/GHSA-v84f-rwh8-v99h.json +++ b/advisories/unreviewed/2022/02/GHSA-v84f-rwh8-v99h/GHSA-v84f-rwh8-v99h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-x6gv-8c9f-6r64/GHSA-x6gv-8c9f-6r64.json b/advisories/unreviewed/2022/02/GHSA-x6gv-8c9f-6r64/GHSA-x6gv-8c9f-6r64.json index 5a8c73962b6..3bb45859eaa 100644 --- a/advisories/unreviewed/2022/02/GHSA-x6gv-8c9f-6r64/GHSA-x6gv-8c9f-6r64.json +++ b/advisories/unreviewed/2022/02/GHSA-x6gv-8c9f-6r64/GHSA-x6gv-8c9f-6r64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22m9-jhmf-fc7x/GHSA-22m9-jhmf-fc7x.json b/advisories/unreviewed/2022/05/GHSA-22m9-jhmf-fc7x/GHSA-22m9-jhmf-fc7x.json index a98e75f5e73..6e1c573d0e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-22m9-jhmf-fc7x/GHSA-22m9-jhmf-fc7x.json +++ b/advisories/unreviewed/2022/05/GHSA-22m9-jhmf-fc7x/GHSA-22m9-jhmf-fc7x.json @@ -7,12 +7,8 @@ "CVE-2005-4661" ], "details": "The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22wh-wq8h-xvf8/GHSA-22wh-wq8h-xvf8.json b/advisories/unreviewed/2022/05/GHSA-22wh-wq8h-xvf8/GHSA-22wh-wq8h-xvf8.json index 714afd0ebe3..091bf473bad 100644 --- a/advisories/unreviewed/2022/05/GHSA-22wh-wq8h-xvf8/GHSA-22wh-wq8h-xvf8.json +++ b/advisories/unreviewed/2022/05/GHSA-22wh-wq8h-xvf8/GHSA-22wh-wq8h-xvf8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2334-4qc6-g6xv/GHSA-2334-4qc6-g6xv.json b/advisories/unreviewed/2022/05/GHSA-2334-4qc6-g6xv/GHSA-2334-4qc6-g6xv.json index a53b0cafe21..20f1406ae4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2334-4qc6-g6xv/GHSA-2334-4qc6-g6xv.json +++ b/advisories/unreviewed/2022/05/GHSA-2334-4qc6-g6xv/GHSA-2334-4qc6-g6xv.json @@ -7,12 +7,8 @@ "CVE-2005-4766" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote attackers to read sensitive cluster synchronization messages by sniffing the multicast traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-233r-fgcw-c6hw/GHSA-233r-fgcw-c6hw.json b/advisories/unreviewed/2022/05/GHSA-233r-fgcw-c6hw/GHSA-233r-fgcw-c6hw.json index 63e515ee07b..146dc9930a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-233r-fgcw-c6hw/GHSA-233r-fgcw-c6hw.json +++ b/advisories/unreviewed/2022/05/GHSA-233r-fgcw-c6hw/GHSA-233r-fgcw-c6hw.json @@ -7,12 +7,8 @@ "CVE-2021-29818" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204345.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2382-6vwc-h973/GHSA-2382-6vwc-h973.json b/advisories/unreviewed/2022/05/GHSA-2382-6vwc-h973/GHSA-2382-6vwc-h973.json index 0a81b9e6b82..67d0d77754f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2382-6vwc-h973/GHSA-2382-6vwc-h973.json +++ b/advisories/unreviewed/2022/05/GHSA-2382-6vwc-h973/GHSA-2382-6vwc-h973.json @@ -7,12 +7,8 @@ "CVE-2021-38326" ], "details": "The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23f8-9p2x-67mg/GHSA-23f8-9p2x-67mg.json b/advisories/unreviewed/2022/05/GHSA-23f8-9p2x-67mg/GHSA-23f8-9p2x-67mg.json index 36657c6b2a2..19a682b1e72 100644 --- a/advisories/unreviewed/2022/05/GHSA-23f8-9p2x-67mg/GHSA-23f8-9p2x-67mg.json +++ b/advisories/unreviewed/2022/05/GHSA-23f8-9p2x-67mg/GHSA-23f8-9p2x-67mg.json @@ -7,12 +7,8 @@ "CVE-2021-39591" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23hc-wwmg-vgj2/GHSA-23hc-wwmg-vgj2.json b/advisories/unreviewed/2022/05/GHSA-23hc-wwmg-vgj2/GHSA-23hc-wwmg-vgj2.json index 0ae2bc6951d..0c947cc192b 100644 --- a/advisories/unreviewed/2022/05/GHSA-23hc-wwmg-vgj2/GHSA-23hc-wwmg-vgj2.json +++ b/advisories/unreviewed/2022/05/GHSA-23hc-wwmg-vgj2/GHSA-23hc-wwmg-vgj2.json @@ -7,12 +7,8 @@ "CVE-2005-4447" ], "details": "SQL injection vulnerability in articles\\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an \"ORDER BY\" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23ph-6jx4-8p78/GHSA-23ph-6jx4-8p78.json b/advisories/unreviewed/2022/05/GHSA-23ph-6jx4-8p78/GHSA-23ph-6jx4-8p78.json index 42251542a1a..c9790904f02 100644 --- a/advisories/unreviewed/2022/05/GHSA-23ph-6jx4-8p78/GHSA-23ph-6jx4-8p78.json +++ b/advisories/unreviewed/2022/05/GHSA-23ph-6jx4-8p78/GHSA-23ph-6jx4-8p78.json @@ -7,12 +7,8 @@ "CVE-2005-4769" ], "details": "SQL injection vulnerability in addrbook.php in Belchior Foundry vCard PRO 3.1 allows remote attackers to execute arbitrary SQL commands via the addr_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23pj-4543-5g2f/GHSA-23pj-4543-5g2f.json b/advisories/unreviewed/2022/05/GHSA-23pj-4543-5g2f/GHSA-23pj-4543-5g2f.json index de4ce36de2b..aef30d123e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-23pj-4543-5g2f/GHSA-23pj-4543-5g2f.json +++ b/advisories/unreviewed/2022/05/GHSA-23pj-4543-5g2f/GHSA-23pj-4543-5g2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23v9-8jvm-jh7q/GHSA-23v9-8jvm-jh7q.json b/advisories/unreviewed/2022/05/GHSA-23v9-8jvm-jh7q/GHSA-23v9-8jvm-jh7q.json index 2715b6e3716..b8d1f457108 100644 --- a/advisories/unreviewed/2022/05/GHSA-23v9-8jvm-jh7q/GHSA-23v9-8jvm-jh7q.json +++ b/advisories/unreviewed/2022/05/GHSA-23v9-8jvm-jh7q/GHSA-23v9-8jvm-jh7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-243w-cr2g-7p8m/GHSA-243w-cr2g-7p8m.json b/advisories/unreviewed/2022/05/GHSA-243w-cr2g-7p8m/GHSA-243w-cr2g-7p8m.json index c25ff8baae6..fefd25c214e 100644 --- a/advisories/unreviewed/2022/05/GHSA-243w-cr2g-7p8m/GHSA-243w-cr2g-7p8m.json +++ b/advisories/unreviewed/2022/05/GHSA-243w-cr2g-7p8m/GHSA-243w-cr2g-7p8m.json @@ -7,12 +7,8 @@ "CVE-2021-38349" ], "details": "The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24rw-g98m-23fg/GHSA-24rw-g98m-23fg.json b/advisories/unreviewed/2022/05/GHSA-24rw-g98m-23fg/GHSA-24rw-g98m-23fg.json index 0c7cb7b95ce..e078c360bc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-24rw-g98m-23fg/GHSA-24rw-g98m-23fg.json +++ b/advisories/unreviewed/2022/05/GHSA-24rw-g98m-23fg/GHSA-24rw-g98m-23fg.json @@ -7,12 +7,8 @@ "CVE-2005-4628" ], "details": "SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24xx-ff7h-g5rx/GHSA-24xx-ff7h-g5rx.json b/advisories/unreviewed/2022/05/GHSA-24xx-ff7h-g5rx/GHSA-24xx-ff7h-g5rx.json index c6b95f6afc5..27b54b6adb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-24xx-ff7h-g5rx/GHSA-24xx-ff7h-g5rx.json +++ b/advisories/unreviewed/2022/05/GHSA-24xx-ff7h-g5rx/GHSA-24xx-ff7h-g5rx.json @@ -7,12 +7,8 @@ "CVE-2005-4532" ], "details": "scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-254f-c2wq-r664/GHSA-254f-c2wq-r664.json b/advisories/unreviewed/2022/05/GHSA-254f-c2wq-r664/GHSA-254f-c2wq-r664.json index d74f03f702c..9e0c3767437 100644 --- a/advisories/unreviewed/2022/05/GHSA-254f-c2wq-r664/GHSA-254f-c2wq-r664.json +++ b/advisories/unreviewed/2022/05/GHSA-254f-c2wq-r664/GHSA-254f-c2wq-r664.json @@ -7,12 +7,8 @@ "CVE-2021-20377" ], "details": "IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25c5-5c5w-53xq/GHSA-25c5-5c5w-53xq.json b/advisories/unreviewed/2022/05/GHSA-25c5-5c5w-53xq/GHSA-25c5-5c5w-53xq.json index 6cb17e46f76..189bfa28b12 100644 --- a/advisories/unreviewed/2022/05/GHSA-25c5-5c5w-53xq/GHSA-25c5-5c5w-53xq.json +++ b/advisories/unreviewed/2022/05/GHSA-25c5-5c5w-53xq/GHSA-25c5-5c5w-53xq.json @@ -7,12 +7,8 @@ "CVE-2005-4680" ], "details": "Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25m9-4f22-2chr/GHSA-25m9-4f22-2chr.json b/advisories/unreviewed/2022/05/GHSA-25m9-4f22-2chr/GHSA-25m9-4f22-2chr.json index adddf9972d1..bcc80d72ab0 100644 --- a/advisories/unreviewed/2022/05/GHSA-25m9-4f22-2chr/GHSA-25m9-4f22-2chr.json +++ b/advisories/unreviewed/2022/05/GHSA-25m9-4f22-2chr/GHSA-25m9-4f22-2chr.json @@ -7,12 +7,8 @@ "CVE-2021-33362" ], "details": "Stack buffer overflow in the hevc_parse_vps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26c8-846h-xfjj/GHSA-26c8-846h-xfjj.json b/advisories/unreviewed/2022/05/GHSA-26c8-846h-xfjj/GHSA-26c8-846h-xfjj.json index 3ce40053f61..a72a1736733 100644 --- a/advisories/unreviewed/2022/05/GHSA-26c8-846h-xfjj/GHSA-26c8-846h-xfjj.json +++ b/advisories/unreviewed/2022/05/GHSA-26c8-846h-xfjj/GHSA-26c8-846h-xfjj.json @@ -7,12 +7,8 @@ "CVE-2021-39517" ], "details": "An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26mp-rrff-g438/GHSA-26mp-rrff-g438.json b/advisories/unreviewed/2022/05/GHSA-26mp-rrff-g438/GHSA-26mp-rrff-g438.json index d6bd4f017a3..ea0f3c772ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-26mp-rrff-g438/GHSA-26mp-rrff-g438.json +++ b/advisories/unreviewed/2022/05/GHSA-26mp-rrff-g438/GHSA-26mp-rrff-g438.json @@ -7,12 +7,8 @@ "CVE-2020-12082" ], "details": "A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-274j-j2jx-h7hf/GHSA-274j-j2jx-h7hf.json b/advisories/unreviewed/2022/05/GHSA-274j-j2jx-h7hf/GHSA-274j-j2jx-h7hf.json index 4eb674e9706..5f728481740 100644 --- a/advisories/unreviewed/2022/05/GHSA-274j-j2jx-h7hf/GHSA-274j-j2jx-h7hf.json +++ b/advisories/unreviewed/2022/05/GHSA-274j-j2jx-h7hf/GHSA-274j-j2jx-h7hf.json @@ -7,12 +7,8 @@ "CVE-2021-39523" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27f3-4xcg-9c5m/GHSA-27f3-4xcg-9c5m.json b/advisories/unreviewed/2022/05/GHSA-27f3-4xcg-9c5m/GHSA-27f3-4xcg-9c5m.json index ae0e878423b..c69dde45992 100644 --- a/advisories/unreviewed/2022/05/GHSA-27f3-4xcg-9c5m/GHSA-27f3-4xcg-9c5m.json +++ b/advisories/unreviewed/2022/05/GHSA-27f3-4xcg-9c5m/GHSA-27f3-4xcg-9c5m.json @@ -7,12 +7,8 @@ "CVE-2005-4885" ], "details": "Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27g9-862v-hv97/GHSA-27g9-862v-hv97.json b/advisories/unreviewed/2022/05/GHSA-27g9-862v-hv97/GHSA-27g9-862v-hv97.json index 777d14408bf..8d3c8ae558a 100644 --- a/advisories/unreviewed/2022/05/GHSA-27g9-862v-hv97/GHSA-27g9-862v-hv97.json +++ b/advisories/unreviewed/2022/05/GHSA-27g9-862v-hv97/GHSA-27g9-862v-hv97.json @@ -7,12 +7,8 @@ "CVE-2005-4698" ], "details": "Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the 91) q_IP (IP) or (2) q_Host (HOST) parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-282v-8gf3-6m78/GHSA-282v-8gf3-6m78.json b/advisories/unreviewed/2022/05/GHSA-282v-8gf3-6m78/GHSA-282v-8gf3-6m78.json index 1b8bce050b2..68241530d05 100644 --- a/advisories/unreviewed/2022/05/GHSA-282v-8gf3-6m78/GHSA-282v-8gf3-6m78.json +++ b/advisories/unreviewed/2022/05/GHSA-282v-8gf3-6m78/GHSA-282v-8gf3-6m78.json @@ -7,12 +7,8 @@ "CVE-2005-4450" ], "details": "Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28h9-hh7q-86j5/GHSA-28h9-hh7q-86j5.json b/advisories/unreviewed/2022/05/GHSA-28h9-hh7q-86j5/GHSA-28h9-hh7q-86j5.json index 336f669e880..e97e5e8472d 100644 --- a/advisories/unreviewed/2022/05/GHSA-28h9-hh7q-86j5/GHSA-28h9-hh7q-86j5.json +++ b/advisories/unreviewed/2022/05/GHSA-28h9-hh7q-86j5/GHSA-28h9-hh7q-86j5.json @@ -7,12 +7,8 @@ "CVE-2005-4808" ], "details": "Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28xr-x3rf-rhgr/GHSA-28xr-x3rf-rhgr.json b/advisories/unreviewed/2022/05/GHSA-28xr-x3rf-rhgr/GHSA-28xr-x3rf-rhgr.json index c67c66745a3..f7f5ec58e5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-28xr-x3rf-rhgr/GHSA-28xr-x3rf-rhgr.json +++ b/advisories/unreviewed/2022/05/GHSA-28xr-x3rf-rhgr/GHSA-28xr-x3rf-rhgr.json @@ -7,12 +7,8 @@ "CVE-2021-34696" ], "details": "A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29q2-x88c-692h/GHSA-29q2-x88c-692h.json b/advisories/unreviewed/2022/05/GHSA-29q2-x88c-692h/GHSA-29q2-x88c-692h.json index 157a2a2e6fc..cc8b0202fe3 100644 --- a/advisories/unreviewed/2022/05/GHSA-29q2-x88c-692h/GHSA-29q2-x88c-692h.json +++ b/advisories/unreviewed/2022/05/GHSA-29q2-x88c-692h/GHSA-29q2-x88c-692h.json @@ -7,12 +7,8 @@ "CVE-2020-21547" ], "details": "Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2ccq-96qh-p2c5/GHSA-2ccq-96qh-p2c5.json b/advisories/unreviewed/2022/05/GHSA-2ccq-96qh-p2c5/GHSA-2ccq-96qh-p2c5.json index 1024334fd74..fc96496049e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2ccq-96qh-p2c5/GHSA-2ccq-96qh-p2c5.json +++ b/advisories/unreviewed/2022/05/GHSA-2ccq-96qh-p2c5/GHSA-2ccq-96qh-p2c5.json @@ -7,12 +7,8 @@ "CVE-2020-19285" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cf9-pjvx-rp3q/GHSA-2cf9-pjvx-rp3q.json b/advisories/unreviewed/2022/05/GHSA-2cf9-pjvx-rp3q/GHSA-2cf9-pjvx-rp3q.json index 065393ef7e1..6ffdb8e6dd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cf9-pjvx-rp3q/GHSA-2cf9-pjvx-rp3q.json +++ b/advisories/unreviewed/2022/05/GHSA-2cf9-pjvx-rp3q/GHSA-2cf9-pjvx-rp3q.json @@ -7,12 +7,8 @@ "CVE-2005-4482" ], "details": "Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cr4-q4vr-2q6r/GHSA-2cr4-q4vr-2q6r.json b/advisories/unreviewed/2022/05/GHSA-2cr4-q4vr-2q6r/GHSA-2cr4-q4vr-2q6r.json index a394da5ce35..6acd7365d2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cr4-q4vr-2q6r/GHSA-2cr4-q4vr-2q6r.json +++ b/advisories/unreviewed/2022/05/GHSA-2cr4-q4vr-2q6r/GHSA-2cr4-q4vr-2q6r.json @@ -7,12 +7,8 @@ "CVE-2021-38156" ], "details": "In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cvc-v88v-w533/GHSA-2cvc-v88v-w533.json b/advisories/unreviewed/2022/05/GHSA-2cvc-v88v-w533/GHSA-2cvc-v88v-w533.json index 6db0aaf2a11..84f66ea2197 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cvc-v88v-w533/GHSA-2cvc-v88v-w533.json +++ b/advisories/unreviewed/2022/05/GHSA-2cvc-v88v-w533/GHSA-2cvc-v88v-w533.json @@ -7,12 +7,8 @@ "CVE-2021-39569" ], "details": "An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function OpAdvance() located in swfaction.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2ffw-7qmf-mjg7/GHSA-2ffw-7qmf-mjg7.json b/advisories/unreviewed/2022/05/GHSA-2ffw-7qmf-mjg7/GHSA-2ffw-7qmf-mjg7.json index 9dae664b6ca..af82d25fffe 100644 --- a/advisories/unreviewed/2022/05/GHSA-2ffw-7qmf-mjg7/GHSA-2ffw-7qmf-mjg7.json +++ b/advisories/unreviewed/2022/05/GHSA-2ffw-7qmf-mjg7/GHSA-2ffw-7qmf-mjg7.json @@ -7,12 +7,8 @@ "CVE-2021-26750" ], "details": "DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fv9-9wxv-5vmh/GHSA-2fv9-9wxv-5vmh.json b/advisories/unreviewed/2022/05/GHSA-2fv9-9wxv-5vmh/GHSA-2fv9-9wxv-5vmh.json index 83fa9032a4b..8b795cbf4a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fv9-9wxv-5vmh/GHSA-2fv9-9wxv-5vmh.json +++ b/advisories/unreviewed/2022/05/GHSA-2fv9-9wxv-5vmh/GHSA-2fv9-9wxv-5vmh.json @@ -7,12 +7,8 @@ "CVE-2005-4634" ], "details": "SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h74-xcwf-23j7/GHSA-2h74-xcwf-23j7.json b/advisories/unreviewed/2022/05/GHSA-2h74-xcwf-23j7/GHSA-2h74-xcwf-23j7.json index 08837d27650..806182482cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h74-xcwf-23j7/GHSA-2h74-xcwf-23j7.json +++ b/advisories/unreviewed/2022/05/GHSA-2h74-xcwf-23j7/GHSA-2h74-xcwf-23j7.json @@ -7,12 +7,8 @@ "CVE-2021-32285" ], "details": "An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function list_iterator_next() located in gravity_core.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h9v-34wh-2q7g/GHSA-2h9v-34wh-2q7g.json b/advisories/unreviewed/2022/05/GHSA-2h9v-34wh-2q7g/GHSA-2h9v-34wh-2q7g.json index 8e2a1a524d6..8724f22dd6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h9v-34wh-2q7g/GHSA-2h9v-34wh-2q7g.json +++ b/advisories/unreviewed/2022/05/GHSA-2h9v-34wh-2q7g/GHSA-2h9v-34wh-2q7g.json @@ -7,12 +7,8 @@ "CVE-2020-20893" ], "details": "Buffer Overflow vulnerability in function activate in libavfilter/af_afade.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mjq-2vv9-22pp/GHSA-2mjq-2vv9-22pp.json b/advisories/unreviewed/2022/05/GHSA-2mjq-2vv9-22pp/GHSA-2mjq-2vv9-22pp.json index ed29e677f66..bdd29caa774 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mjq-2vv9-22pp/GHSA-2mjq-2vv9-22pp.json +++ b/advisories/unreviewed/2022/05/GHSA-2mjq-2vv9-22pp/GHSA-2mjq-2vv9-22pp.json @@ -7,12 +7,8 @@ "CVE-2005-4512" ], "details": "Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2p5c-r4xc-mhvw/GHSA-2p5c-r4xc-mhvw.json b/advisories/unreviewed/2022/05/GHSA-2p5c-r4xc-mhvw/GHSA-2p5c-r4xc-mhvw.json index 59588eb3170..41549fa38de 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p5c-r4xc-mhvw/GHSA-2p5c-r4xc-mhvw.json +++ b/advisories/unreviewed/2022/05/GHSA-2p5c-r4xc-mhvw/GHSA-2p5c-r4xc-mhvw.json @@ -7,12 +7,8 @@ "CVE-2021-40965" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2q4g-fw9r-2xxm/GHSA-2q4g-fw9r-2xxm.json b/advisories/unreviewed/2022/05/GHSA-2q4g-fw9r-2xxm/GHSA-2q4g-fw9r-2xxm.json index 824f761f4b8..56a9e9119a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q4g-fw9r-2xxm/GHSA-2q4g-fw9r-2xxm.json +++ b/advisories/unreviewed/2022/05/GHSA-2q4g-fw9r-2xxm/GHSA-2q4g-fw9r-2xxm.json @@ -7,12 +7,8 @@ "CVE-2005-4816" ], "details": "Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qff-4q86-c9p7/GHSA-2qff-4q86-c9p7.json b/advisories/unreviewed/2022/05/GHSA-2qff-4q86-c9p7/GHSA-2qff-4q86-c9p7.json index 6bb9e842b79..4879fb622d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qff-4q86-c9p7/GHSA-2qff-4q86-c9p7.json +++ b/advisories/unreviewed/2022/05/GHSA-2qff-4q86-c9p7/GHSA-2qff-4q86-c9p7.json @@ -7,12 +7,8 @@ "CVE-2005-4815" ], "details": "SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the \"FX SAP R/3 gwrd vuln.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v2m-m9xc-2hp5/GHSA-2v2m-m9xc-2hp5.json b/advisories/unreviewed/2022/05/GHSA-2v2m-m9xc-2hp5/GHSA-2v2m-m9xc-2hp5.json index 59506204405..f9aa26640b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v2m-m9xc-2hp5/GHSA-2v2m-m9xc-2hp5.json +++ b/advisories/unreviewed/2022/05/GHSA-2v2m-m9xc-2hp5/GHSA-2v2m-m9xc-2hp5.json @@ -7,12 +7,8 @@ "CVE-2005-4446" ], "details": "Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v73-62r7-82cv/GHSA-2v73-62r7-82cv.json b/advisories/unreviewed/2022/05/GHSA-2v73-62r7-82cv/GHSA-2v73-62r7-82cv.json index f897f08dab0..9fd815b2e22 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v73-62r7-82cv/GHSA-2v73-62r7-82cv.json +++ b/advisories/unreviewed/2022/05/GHSA-2v73-62r7-82cv/GHSA-2v73-62r7-82cv.json @@ -7,12 +7,8 @@ "CVE-2005-4315" ], "details": "SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vpj-c9hx-wv3q/GHSA-2vpj-c9hx-wv3q.json b/advisories/unreviewed/2022/05/GHSA-2vpj-c9hx-wv3q/GHSA-2vpj-c9hx-wv3q.json index 610b25508a8..85e83c41f0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vpj-c9hx-wv3q/GHSA-2vpj-c9hx-wv3q.json +++ b/advisories/unreviewed/2022/05/GHSA-2vpj-c9hx-wv3q/GHSA-2vpj-c9hx-wv3q.json @@ -7,12 +7,8 @@ "CVE-2021-38328" ], "details": "The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w2j-gfqg-fwgm/GHSA-2w2j-gfqg-fwgm.json b/advisories/unreviewed/2022/05/GHSA-2w2j-gfqg-fwgm/GHSA-2w2j-gfqg-fwgm.json index 2e7d7f94087..7482130421f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w2j-gfqg-fwgm/GHSA-2w2j-gfqg-fwgm.json +++ b/advisories/unreviewed/2022/05/GHSA-2w2j-gfqg-fwgm/GHSA-2w2j-gfqg-fwgm.json @@ -7,12 +7,8 @@ "CVE-2005-4866" ], "details": "Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wpp-hvf7-v98x/GHSA-2wpp-hvf7-v98x.json b/advisories/unreviewed/2022/05/GHSA-2wpp-hvf7-v98x/GHSA-2wpp-hvf7-v98x.json index dff08cc9d00..486761acdc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wpp-hvf7-v98x/GHSA-2wpp-hvf7-v98x.json +++ b/advisories/unreviewed/2022/05/GHSA-2wpp-hvf7-v98x/GHSA-2wpp-hvf7-v98x.json @@ -7,12 +7,8 @@ "CVE-2005-4649" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wwq-c24x-xw9j/GHSA-2wwq-c24x-xw9j.json b/advisories/unreviewed/2022/05/GHSA-2wwq-c24x-xw9j/GHSA-2wwq-c24x-xw9j.json index 4bf905374ac..ffc669816ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wwq-c24x-xw9j/GHSA-2wwq-c24x-xw9j.json +++ b/advisories/unreviewed/2022/05/GHSA-2wwq-c24x-xw9j/GHSA-2wwq-c24x-xw9j.json @@ -7,12 +7,8 @@ "CVE-2005-4824" ], "details": "PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xg8-gc3x-5wm4/GHSA-2xg8-gc3x-5wm4.json b/advisories/unreviewed/2022/05/GHSA-2xg8-gc3x-5wm4/GHSA-2xg8-gc3x-5wm4.json index b2a1b54f875..1d3d293fb97 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xg8-gc3x-5wm4/GHSA-2xg8-gc3x-5wm4.json +++ b/advisories/unreviewed/2022/05/GHSA-2xg8-gc3x-5wm4/GHSA-2xg8-gc3x-5wm4.json @@ -7,12 +7,8 @@ "CVE-2005-4692" ], "details": "Unspecified vulnerability in mroovca stats (mroovcastats) before 0.4.5b has unknown attack vectors and impact, related to cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32gf-9929-gmj6/GHSA-32gf-9929-gmj6.json b/advisories/unreviewed/2022/05/GHSA-32gf-9929-gmj6/GHSA-32gf-9929-gmj6.json index 66838c2514f..59eea9f3fdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-32gf-9929-gmj6/GHSA-32gf-9929-gmj6.json +++ b/advisories/unreviewed/2022/05/GHSA-32gf-9929-gmj6/GHSA-32gf-9929-gmj6.json @@ -7,12 +7,8 @@ "CVE-2005-4600" ], "details": "Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-333w-grm8-fgcg/GHSA-333w-grm8-fgcg.json b/advisories/unreviewed/2022/05/GHSA-333w-grm8-fgcg/GHSA-333w-grm8-fgcg.json index 6ddec38c656..8a6f67998f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-333w-grm8-fgcg/GHSA-333w-grm8-fgcg.json +++ b/advisories/unreviewed/2022/05/GHSA-333w-grm8-fgcg/GHSA-333w-grm8-fgcg.json @@ -7,12 +7,8 @@ "CVE-2021-22276" ], "details": "The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3367-6xxj-j9cg/GHSA-3367-6xxj-j9cg.json b/advisories/unreviewed/2022/05/GHSA-3367-6xxj-j9cg/GHSA-3367-6xxj-j9cg.json index bbbf59f48f3..bfb7e737479 100644 --- a/advisories/unreviewed/2022/05/GHSA-3367-6xxj-j9cg/GHSA-3367-6xxj-j9cg.json +++ b/advisories/unreviewed/2022/05/GHSA-3367-6xxj-j9cg/GHSA-3367-6xxj-j9cg.json @@ -7,12 +7,8 @@ "CVE-2020-14124" ], "details": "There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3383-3582-42x2/GHSA-3383-3582-42x2.json b/advisories/unreviewed/2022/05/GHSA-3383-3582-42x2/GHSA-3383-3582-42x2.json index d86230cf8a9..27c3190cc59 100644 --- a/advisories/unreviewed/2022/05/GHSA-3383-3582-42x2/GHSA-3383-3582-42x2.json +++ b/advisories/unreviewed/2022/05/GHSA-3383-3582-42x2/GHSA-3383-3582-42x2.json @@ -7,12 +7,8 @@ "CVE-2021-32135" ], "details": "The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33fh-cmjr-7j9h/GHSA-33fh-cmjr-7j9h.json b/advisories/unreviewed/2022/05/GHSA-33fh-cmjr-7j9h/GHSA-33fh-cmjr-7j9h.json index ea488308850..997db72fd19 100644 --- a/advisories/unreviewed/2022/05/GHSA-33fh-cmjr-7j9h/GHSA-33fh-cmjr-7j9h.json +++ b/advisories/unreviewed/2022/05/GHSA-33fh-cmjr-7j9h/GHSA-33fh-cmjr-7j9h.json @@ -7,12 +7,8 @@ "CVE-2005-4443" ], "details": "Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33v9-9rxf-3675/GHSA-33v9-9rxf-3675.json b/advisories/unreviewed/2022/05/GHSA-33v9-9rxf-3675/GHSA-33v9-9rxf-3675.json index e85ea5b43d1..76b977cf8a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-33v9-9rxf-3675/GHSA-33v9-9rxf-3675.json +++ b/advisories/unreviewed/2022/05/GHSA-33v9-9rxf-3675/GHSA-33v9-9rxf-3675.json @@ -7,12 +7,8 @@ "CVE-2021-23028" ], "details": "On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Application Firewall (WAF)/BIG-IP ASM security policy and applied to a virtual server, undisclosed requests may cause the BIG-IP ASM bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-353p-pq7h-22q6/GHSA-353p-pq7h-22q6.json b/advisories/unreviewed/2022/05/GHSA-353p-pq7h-22q6/GHSA-353p-pq7h-22q6.json index 5c1e75eff5e..d5beee6cc73 100644 --- a/advisories/unreviewed/2022/05/GHSA-353p-pq7h-22q6/GHSA-353p-pq7h-22q6.json +++ b/advisories/unreviewed/2022/05/GHSA-353p-pq7h-22q6/GHSA-353p-pq7h-22q6.json @@ -7,12 +7,8 @@ "CVE-2005-4621" ], "details": "Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35q7-q9hg-r69q/GHSA-35q7-q9hg-r69q.json b/advisories/unreviewed/2022/05/GHSA-35q7-q9hg-r69q/GHSA-35q7-q9hg-r69q.json index ef4e7b81bfc..8c6c8f77678 100644 --- a/advisories/unreviewed/2022/05/GHSA-35q7-q9hg-r69q/GHSA-35q7-q9hg-r69q.json +++ b/advisories/unreviewed/2022/05/GHSA-35q7-q9hg-r69q/GHSA-35q7-q9hg-r69q.json @@ -7,12 +7,8 @@ "CVE-2005-4439" ], "details": "Buffer overflow in ELOG elogd 2.6.0-beta4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a URL with a long (1) cmd or (2) mode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35x5-8hjg-m53r/GHSA-35x5-8hjg-m53r.json b/advisories/unreviewed/2022/05/GHSA-35x5-8hjg-m53r/GHSA-35x5-8hjg-m53r.json index f2ca4141de5..840c2b62d96 100644 --- a/advisories/unreviewed/2022/05/GHSA-35x5-8hjg-m53r/GHSA-35x5-8hjg-m53r.json +++ b/advisories/unreviewed/2022/05/GHSA-35x5-8hjg-m53r/GHSA-35x5-8hjg-m53r.json @@ -7,12 +7,8 @@ "CVE-2005-4882" ], "details": "tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36hv-f25w-387h/GHSA-36hv-f25w-387h.json b/advisories/unreviewed/2022/05/GHSA-36hv-f25w-387h/GHSA-36hv-f25w-387h.json index af89d3ac957..efc15e5d1c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-36hv-f25w-387h/GHSA-36hv-f25w-387h.json +++ b/advisories/unreviewed/2022/05/GHSA-36hv-f25w-387h/GHSA-36hv-f25w-387h.json @@ -7,12 +7,8 @@ "CVE-2021-24640" ], "details": "The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36j5-c4mc-2jx6/GHSA-36j5-c4mc-2jx6.json b/advisories/unreviewed/2022/05/GHSA-36j5-c4mc-2jx6/GHSA-36j5-c4mc-2jx6.json index ee31609e10b..3c936e6772d 100644 --- a/advisories/unreviewed/2022/05/GHSA-36j5-c4mc-2jx6/GHSA-36j5-c4mc-2jx6.json +++ b/advisories/unreviewed/2022/05/GHSA-36j5-c4mc-2jx6/GHSA-36j5-c4mc-2jx6.json @@ -7,12 +7,8 @@ "CVE-2005-4604" ], "details": "Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3774-9hfm-h8pq/GHSA-3774-9hfm-h8pq.json b/advisories/unreviewed/2022/05/GHSA-3774-9hfm-h8pq/GHSA-3774-9hfm-h8pq.json index 4f1de59cff5..2388285619b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3774-9hfm-h8pq/GHSA-3774-9hfm-h8pq.json +++ b/advisories/unreviewed/2022/05/GHSA-3774-9hfm-h8pq/GHSA-3774-9hfm-h8pq.json @@ -7,12 +7,8 @@ "CVE-2021-39541" ], "details": "An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeXref() located in analyze.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3782-4pq4-qwj2/GHSA-3782-4pq4-qwj2.json b/advisories/unreviewed/2022/05/GHSA-3782-4pq4-qwj2/GHSA-3782-4pq4-qwj2.json index 28115ca23bb..b97a6308204 100644 --- a/advisories/unreviewed/2022/05/GHSA-3782-4pq4-qwj2/GHSA-3782-4pq4-qwj2.json +++ b/advisories/unreviewed/2022/05/GHSA-3782-4pq4-qwj2/GHSA-3782-4pq4-qwj2.json @@ -7,12 +7,8 @@ "CVE-2021-35493" ], "details": "The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO WebFOCUS Client: versions 8207.27.0 and below, TIBCO WebFOCUS Installer: versions 8207.27.0 and below, and TIBCO WebFOCUS Reporting Server: versions 8207.27.0 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-378c-qrcg-vgq7/GHSA-378c-qrcg-vgq7.json b/advisories/unreviewed/2022/05/GHSA-378c-qrcg-vgq7/GHSA-378c-qrcg-vgq7.json index 93b9011c706..110b648d7c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-378c-qrcg-vgq7/GHSA-378c-qrcg-vgq7.json +++ b/advisories/unreviewed/2022/05/GHSA-378c-qrcg-vgq7/GHSA-378c-qrcg-vgq7.json @@ -7,12 +7,8 @@ "CVE-2020-19293" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37f5-m753-pjhv/GHSA-37f5-m753-pjhv.json b/advisories/unreviewed/2022/05/GHSA-37f5-m753-pjhv/GHSA-37f5-m753-pjhv.json index 52f682f1bf4..b31a8158fd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-37f5-m753-pjhv/GHSA-37f5-m753-pjhv.json +++ b/advisories/unreviewed/2022/05/GHSA-37f5-m753-pjhv/GHSA-37f5-m753-pjhv.json @@ -7,12 +7,8 @@ "CVE-2021-32959" ], "details": "Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37x4-xj4c-2664/GHSA-37x4-xj4c-2664.json b/advisories/unreviewed/2022/05/GHSA-37x4-xj4c-2664/GHSA-37x4-xj4c-2664.json index 611c9932291..21e212576e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-37x4-xj4c-2664/GHSA-37x4-xj4c-2664.json +++ b/advisories/unreviewed/2022/05/GHSA-37x4-xj4c-2664/GHSA-37x4-xj4c-2664.json @@ -7,12 +7,8 @@ "CVE-2005-4611" ], "details": "SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-382p-crwp-jf65/GHSA-382p-crwp-jf65.json b/advisories/unreviewed/2022/05/GHSA-382p-crwp-jf65/GHSA-382p-crwp-jf65.json index f27ecf3c75e..b68c0fe7c1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-382p-crwp-jf65/GHSA-382p-crwp-jf65.json +++ b/advisories/unreviewed/2022/05/GHSA-382p-crwp-jf65/GHSA-382p-crwp-jf65.json @@ -7,12 +7,8 @@ "CVE-2021-20828" ], "details": "Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-388x-f5qm-fvjg/GHSA-388x-f5qm-fvjg.json b/advisories/unreviewed/2022/05/GHSA-388x-f5qm-fvjg/GHSA-388x-f5qm-fvjg.json index e562e57dca0..f6a0b67df63 100644 --- a/advisories/unreviewed/2022/05/GHSA-388x-f5qm-fvjg/GHSA-388x-f5qm-fvjg.json +++ b/advisories/unreviewed/2022/05/GHSA-388x-f5qm-fvjg/GHSA-388x-f5qm-fvjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3897-x777-pgxc/GHSA-3897-x777-pgxc.json b/advisories/unreviewed/2022/05/GHSA-3897-x777-pgxc/GHSA-3897-x777-pgxc.json index a855523ffe7..6615906aa8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3897-x777-pgxc/GHSA-3897-x777-pgxc.json +++ b/advisories/unreviewed/2022/05/GHSA-3897-x777-pgxc/GHSA-3897-x777-pgxc.json @@ -7,12 +7,8 @@ "CVE-2005-4564" ], "details": "The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38fh-px4j-r2wx/GHSA-38fh-px4j-r2wx.json b/advisories/unreviewed/2022/05/GHSA-38fh-px4j-r2wx/GHSA-38fh-px4j-r2wx.json index 0dcb4b5d4de..06817bd2d97 100644 --- a/advisories/unreviewed/2022/05/GHSA-38fh-px4j-r2wx/GHSA-38fh-px4j-r2wx.json +++ b/advisories/unreviewed/2022/05/GHSA-38fh-px4j-r2wx/GHSA-38fh-px4j-r2wx.json @@ -7,12 +7,8 @@ "CVE-2005-4523" ], "details": "Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38h6-xf6r-fw6f/GHSA-38h6-xf6r-fw6f.json b/advisories/unreviewed/2022/05/GHSA-38h6-xf6r-fw6f/GHSA-38h6-xf6r-fw6f.json index 6673a2c676c..87850db20f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-38h6-xf6r-fw6f/GHSA-38h6-xf6r-fw6f.json +++ b/advisories/unreviewed/2022/05/GHSA-38h6-xf6r-fw6f/GHSA-38h6-xf6r-fw6f.json @@ -7,12 +7,8 @@ "CVE-2005-4501" ], "details": "MediaWiki before 1.5.4 uses a hard-coded \"internal placeholder string\", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3932-qm3c-m9h6/GHSA-3932-qm3c-m9h6.json b/advisories/unreviewed/2022/05/GHSA-3932-qm3c-m9h6/GHSA-3932-qm3c-m9h6.json index d78b481dc05..707c84b6f9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3932-qm3c-m9h6/GHSA-3932-qm3c-m9h6.json +++ b/advisories/unreviewed/2022/05/GHSA-3932-qm3c-m9h6/GHSA-3932-qm3c-m9h6.json @@ -7,12 +7,8 @@ "CVE-2005-4721" ], "details": "Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER 3.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c3m-qp4j-mgv8/GHSA-3c3m-qp4j-mgv8.json b/advisories/unreviewed/2022/05/GHSA-3c3m-qp4j-mgv8/GHSA-3c3m-qp4j-mgv8.json index 62d9ad00336..9e3183944ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c3m-qp4j-mgv8/GHSA-3c3m-qp4j-mgv8.json +++ b/advisories/unreviewed/2022/05/GHSA-3c3m-qp4j-mgv8/GHSA-3c3m-qp4j-mgv8.json @@ -7,12 +7,8 @@ "CVE-2021-39547" ], "details": "An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function lpc::SampleGenerator::process() located in sample_generator.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c52-7j8w-6f87/GHSA-3c52-7j8w-6f87.json b/advisories/unreviewed/2022/05/GHSA-3c52-7j8w-6f87/GHSA-3c52-7j8w-6f87.json index a07aa8cb2a0..69e00124f6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c52-7j8w-6f87/GHSA-3c52-7j8w-6f87.json +++ b/advisories/unreviewed/2022/05/GHSA-3c52-7j8w-6f87/GHSA-3c52-7j8w-6f87.json @@ -7,12 +7,8 @@ "CVE-2021-39588" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cpr-wjhh-6mx6/GHSA-3cpr-wjhh-6mx6.json b/advisories/unreviewed/2022/05/GHSA-3cpr-wjhh-6mx6/GHSA-3cpr-wjhh-6mx6.json index ee0ccf66964..4eb6dfb5c1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cpr-wjhh-6mx6/GHSA-3cpr-wjhh-6mx6.json +++ b/advisories/unreviewed/2022/05/GHSA-3cpr-wjhh-6mx6/GHSA-3cpr-wjhh-6mx6.json @@ -7,12 +7,8 @@ "CVE-2005-4504" ], "details": "The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cqf-cqxx-qphr/GHSA-3cqf-cqxx-qphr.json b/advisories/unreviewed/2022/05/GHSA-3cqf-cqxx-qphr/GHSA-3cqf-cqxx-qphr.json index 2c617ed143f..710ca5eab0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cqf-cqxx-qphr/GHSA-3cqf-cqxx-qphr.json +++ b/advisories/unreviewed/2022/05/GHSA-3cqf-cqxx-qphr/GHSA-3cqf-cqxx-qphr.json @@ -7,12 +7,8 @@ "CVE-2005-4701" ], "details": "Unspecified vulnerability in Process File System (procfs) in Sun Solaris 10 allows local users to obtain sensitive information such as process working directories via unknown attack vectors, possibly pwdx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3crh-wfw6-p5f9/GHSA-3crh-wfw6-p5f9.json b/advisories/unreviewed/2022/05/GHSA-3crh-wfw6-p5f9/GHSA-3crh-wfw6-p5f9.json index b81180710b8..7f5f62b9000 100644 --- a/advisories/unreviewed/2022/05/GHSA-3crh-wfw6-p5f9/GHSA-3crh-wfw6-p5f9.json +++ b/advisories/unreviewed/2022/05/GHSA-3crh-wfw6-p5f9/GHSA-3crh-wfw6-p5f9.json @@ -7,12 +7,8 @@ "CVE-2005-4762" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier sometimes stores the boot password in the registry in cleartext, which might allow local users to gain administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f6p-4492-5fc4/GHSA-3f6p-4492-5fc4.json b/advisories/unreviewed/2022/05/GHSA-3f6p-4492-5fc4/GHSA-3f6p-4492-5fc4.json index 47d76f10305..6751cc3cea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f6p-4492-5fc4/GHSA-3f6p-4492-5fc4.json +++ b/advisories/unreviewed/2022/05/GHSA-3f6p-4492-5fc4/GHSA-3f6p-4492-5fc4.json @@ -7,12 +7,8 @@ "CVE-2005-4456" ], "details": "Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue described in CVE-2005-4402.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f78-c2v3-p2xx/GHSA-3f78-c2v3-p2xx.json b/advisories/unreviewed/2022/05/GHSA-3f78-c2v3-p2xx/GHSA-3f78-c2v3-p2xx.json index 308533fb56e..8f7aea2b21c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f78-c2v3-p2xx/GHSA-3f78-c2v3-p2xx.json +++ b/advisories/unreviewed/2022/05/GHSA-3f78-c2v3-p2xx/GHSA-3f78-c2v3-p2xx.json @@ -7,12 +7,8 @@ "CVE-2005-4641" ], "details": "SQL injection vulnerability in home.php in eazyCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fvf-wxcf-7v9q/GHSA-3fvf-wxcf-7v9q.json b/advisories/unreviewed/2022/05/GHSA-3fvf-wxcf-7v9q/GHSA-3fvf-wxcf-7v9q.json index b4cea9e9821..020991469df 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fvf-wxcf-7v9q/GHSA-3fvf-wxcf-7v9q.json +++ b/advisories/unreviewed/2022/05/GHSA-3fvf-wxcf-7v9q/GHSA-3fvf-wxcf-7v9q.json @@ -7,12 +7,8 @@ "CVE-2021-39521" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gjc-qgpj-p9mw/GHSA-3gjc-qgpj-p9mw.json b/advisories/unreviewed/2022/05/GHSA-3gjc-qgpj-p9mw/GHSA-3gjc-qgpj-p9mw.json index d6d2118175a..75e2fc11e4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gjc-qgpj-p9mw/GHSA-3gjc-qgpj-p9mw.json +++ b/advisories/unreviewed/2022/05/GHSA-3gjc-qgpj-p9mw/GHSA-3gjc-qgpj-p9mw.json @@ -7,12 +7,8 @@ "CVE-2021-22526" ], "details": "Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gwm-cv7f-hm83/GHSA-3gwm-cv7f-hm83.json b/advisories/unreviewed/2022/05/GHSA-3gwm-cv7f-hm83/GHSA-3gwm-cv7f-hm83.json index 59f2ad57871..fcfd0c997f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gwm-cv7f-hm83/GHSA-3gwm-cv7f-hm83.json +++ b/advisories/unreviewed/2022/05/GHSA-3gwm-cv7f-hm83/GHSA-3gwm-cv7f-hm83.json @@ -7,12 +7,8 @@ "CVE-2005-4467" ], "details": "Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_BASE_DIRECTORY parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gx3-vcjc-vm83/GHSA-3gx3-vcjc-vm83.json b/advisories/unreviewed/2022/05/GHSA-3gx3-vcjc-vm83/GHSA-3gx3-vcjc-vm83.json index 30d434984cb..2cdfd9485d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gx3-vcjc-vm83/GHSA-3gx3-vcjc-vm83.json +++ b/advisories/unreviewed/2022/05/GHSA-3gx3-vcjc-vm83/GHSA-3gx3-vcjc-vm83.json @@ -7,12 +7,8 @@ "CVE-2005-4734" ], "details": "Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hcq-vq68-gcc7/GHSA-3hcq-vq68-gcc7.json b/advisories/unreviewed/2022/05/GHSA-3hcq-vq68-gcc7/GHSA-3hcq-vq68-gcc7.json index 78091c31513..245e7144faa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hcq-vq68-gcc7/GHSA-3hcq-vq68-gcc7.json +++ b/advisories/unreviewed/2022/05/GHSA-3hcq-vq68-gcc7/GHSA-3hcq-vq68-gcc7.json @@ -7,12 +7,8 @@ "CVE-2021-37174" ], "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions < V2.14.1), RUGGEDCOM ROX RX1512 (All versions < V2.14.1), RUGGEDCOM ROX RX1524 (All versions < V2.14.1), RUGGEDCOM ROX RX1536 (All versions < V2.14.1), RUGGEDCOM ROX RX5000 (All versions < V2.14.1). The affected devices have a privilege escalation vulnerability, if exploited, an attacker could gain root user access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hh7-4gv3-gf58/GHSA-3hh7-4gv3-gf58.json b/advisories/unreviewed/2022/05/GHSA-3hh7-4gv3-gf58/GHSA-3hh7-4gv3-gf58.json index 689dc25517f..5d5d92026cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hh7-4gv3-gf58/GHSA-3hh7-4gv3-gf58.json +++ b/advisories/unreviewed/2022/05/GHSA-3hh7-4gv3-gf58/GHSA-3hh7-4gv3-gf58.json @@ -7,12 +7,8 @@ "CVE-2005-4550" ], "details": "The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jf2-2rp2-p843/GHSA-3jf2-2rp2-p843.json b/advisories/unreviewed/2022/05/GHSA-3jf2-2rp2-p843/GHSA-3jf2-2rp2-p843.json index ab106c62346..34282542d67 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jf2-2rp2-p843/GHSA-3jf2-2rp2-p843.json +++ b/advisories/unreviewed/2022/05/GHSA-3jf2-2rp2-p843/GHSA-3jf2-2rp2-p843.json @@ -7,12 +7,8 @@ "CVE-2005-4833" ], "details": "IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via \"a specific JSP URL,\" related to lack of normalization of the URL format.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jh4-vm9g-v8q4/GHSA-3jh4-vm9g-v8q4.json b/advisories/unreviewed/2022/05/GHSA-3jh4-vm9g-v8q4/GHSA-3jh4-vm9g-v8q4.json index 394fb8801b9..1ba44a66e21 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jh4-vm9g-v8q4/GHSA-3jh4-vm9g-v8q4.json +++ b/advisories/unreviewed/2022/05/GHSA-3jh4-vm9g-v8q4/GHSA-3jh4-vm9g-v8q4.json @@ -7,12 +7,8 @@ "CVE-2005-4879" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3m23-m58c-wrv4/GHSA-3m23-m58c-wrv4.json b/advisories/unreviewed/2022/05/GHSA-3m23-m58c-wrv4/GHSA-3m23-m58c-wrv4.json index 4b5e5400630..62acf733f86 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m23-m58c-wrv4/GHSA-3m23-m58c-wrv4.json +++ b/advisories/unreviewed/2022/05/GHSA-3m23-m58c-wrv4/GHSA-3m23-m58c-wrv4.json @@ -7,12 +7,8 @@ "CVE-2005-4617" ], "details": "SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mc5-w7jh-66fj/GHSA-3mc5-w7jh-66fj.json b/advisories/unreviewed/2022/05/GHSA-3mc5-w7jh-66fj/GHSA-3mc5-w7jh-66fj.json index cf1c3c37eda..46a06f620c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mc5-w7jh-66fj/GHSA-3mc5-w7jh-66fj.json +++ b/advisories/unreviewed/2022/05/GHSA-3mc5-w7jh-66fj/GHSA-3mc5-w7jh-66fj.json @@ -7,12 +7,8 @@ "CVE-2005-4760" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being \"fully protected.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3p4h-535g-5qjf/GHSA-3p4h-535g-5qjf.json b/advisories/unreviewed/2022/05/GHSA-3p4h-535g-5qjf/GHSA-3p4h-535g-5qjf.json index 2ac88394a50..50e8aa7728f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p4h-535g-5qjf/GHSA-3p4h-535g-5qjf.json +++ b/advisories/unreviewed/2022/05/GHSA-3p4h-535g-5qjf/GHSA-3p4h-535g-5qjf.json @@ -7,12 +7,8 @@ "CVE-2021-32286" ], "details": "An issue was discovered in hcxtools through 6.1.6. A global-buffer-overflow exists in the function pcapngoptionwalk located in hcxpcapngtool.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p7q-wxm4-v8fp/GHSA-3p7q-wxm4-v8fp.json b/advisories/unreviewed/2022/05/GHSA-3p7q-wxm4-v8fp/GHSA-3p7q-wxm4-v8fp.json index 5fbefdaa0f3..eac73d5e6a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p7q-wxm4-v8fp/GHSA-3p7q-wxm4-v8fp.json +++ b/advisories/unreviewed/2022/05/GHSA-3p7q-wxm4-v8fp/GHSA-3p7q-wxm4-v8fp.json @@ -7,12 +7,8 @@ "CVE-2020-19283" ], "details": "A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3php-qpv3-6pw7/GHSA-3php-qpv3-6pw7.json b/advisories/unreviewed/2022/05/GHSA-3php-qpv3-6pw7/GHSA-3php-qpv3-6pw7.json index 61f76849689..147183cc14b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3php-qpv3-6pw7/GHSA-3php-qpv3-6pw7.json +++ b/advisories/unreviewed/2022/05/GHSA-3php-qpv3-6pw7/GHSA-3php-qpv3-6pw7.json @@ -7,12 +7,8 @@ "CVE-2005-4818" ], "details": "Multiple SQL injection vulnerabilities in Copernicus Europa allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q58-fh6p-m7jw/GHSA-3q58-fh6p-m7jw.json b/advisories/unreviewed/2022/05/GHSA-3q58-fh6p-m7jw/GHSA-3q58-fh6p-m7jw.json index b712e7af87b..876ba31e9fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q58-fh6p-m7jw/GHSA-3q58-fh6p-m7jw.json +++ b/advisories/unreviewed/2022/05/GHSA-3q58-fh6p-m7jw/GHSA-3q58-fh6p-m7jw.json @@ -7,12 +7,8 @@ "CVE-2005-4748" ], "details": "PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary PHP code via unspecified attack vectors. NOTE: this issue has been referred to as XSS, but it is clear from the vendor description that it is a file inclusion problem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qqp-v6v2-x8v6/GHSA-3qqp-v6v2-x8v6.json b/advisories/unreviewed/2022/05/GHSA-3qqp-v6v2-x8v6/GHSA-3qqp-v6v2-x8v6.json index 06784b8a3d5..6639b537252 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qqp-v6v2-x8v6/GHSA-3qqp-v6v2-x8v6.json +++ b/advisories/unreviewed/2022/05/GHSA-3qqp-v6v2-x8v6/GHSA-3qqp-v6v2-x8v6.json @@ -7,12 +7,8 @@ "CVE-2020-20900" ], "details": "Buffer Overflow vulnerability in function gaussian_blur in libavfilter/vf_edgedetect.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qwx-85qr-mvqm/GHSA-3qwx-85qr-mvqm.json b/advisories/unreviewed/2022/05/GHSA-3qwx-85qr-mvqm/GHSA-3qwx-85qr-mvqm.json index 5113cde4c30..21826ba2185 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qwx-85qr-mvqm/GHSA-3qwx-85qr-mvqm.json +++ b/advisories/unreviewed/2022/05/GHSA-3qwx-85qr-mvqm/GHSA-3qwx-85qr-mvqm.json @@ -7,12 +7,8 @@ "CVE-2005-4663" ], "details": "Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r4j-6mx6-f47q/GHSA-3r4j-6mx6-f47q.json b/advisories/unreviewed/2022/05/GHSA-3r4j-6mx6-f47q/GHSA-3r4j-6mx6-f47q.json index 5d992c6cc1e..19737f1b8d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r4j-6mx6-f47q/GHSA-3r4j-6mx6-f47q.json +++ b/advisories/unreviewed/2022/05/GHSA-3r4j-6mx6-f47q/GHSA-3r4j-6mx6-f47q.json @@ -7,12 +7,8 @@ "CVE-2005-4596" ], "details": "Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rfh-rcxw-3xxf/GHSA-3rfh-rcxw-3xxf.json b/advisories/unreviewed/2022/05/GHSA-3rfh-rcxw-3xxf/GHSA-3rfh-rcxw-3xxf.json index e9ff247d858..8982ac52bec 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rfh-rcxw-3xxf/GHSA-3rfh-rcxw-3xxf.json +++ b/advisories/unreviewed/2022/05/GHSA-3rfh-rcxw-3xxf/GHSA-3rfh-rcxw-3xxf.json @@ -7,12 +7,8 @@ "CVE-2020-19287" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rhf-q6c8-mqq2/GHSA-3rhf-q6c8-mqq2.json b/advisories/unreviewed/2022/05/GHSA-3rhf-q6c8-mqq2/GHSA-3rhf-q6c8-mqq2.json index dda464a9c0c..c9aaf1a3fbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rhf-q6c8-mqq2/GHSA-3rhf-q6c8-mqq2.json +++ b/advisories/unreviewed/2022/05/GHSA-3rhf-q6c8-mqq2/GHSA-3rhf-q6c8-mqq2.json @@ -7,12 +7,8 @@ "CVE-2020-21483" ], "details": "An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rm9-4vp3-9x4r/GHSA-3rm9-4vp3-9x4r.json b/advisories/unreviewed/2022/05/GHSA-3rm9-4vp3-9x4r/GHSA-3rm9-4vp3-9x4r.json index 62a1170ec05..76dbb348bf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rm9-4vp3-9x4r/GHSA-3rm9-4vp3-9x4r.json +++ b/advisories/unreviewed/2022/05/GHSA-3rm9-4vp3-9x4r/GHSA-3rm9-4vp3-9x4r.json @@ -7,12 +7,8 @@ "CVE-2005-4804" ], "details": "Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rrr-cqqf-5xqm/GHSA-3rrr-cqqf-5xqm.json b/advisories/unreviewed/2022/05/GHSA-3rrr-cqqf-5xqm/GHSA-3rrr-cqqf-5xqm.json index 368d1a873f7..ff59ebc5e21 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rrr-cqqf-5xqm/GHSA-3rrr-cqqf-5xqm.json +++ b/advisories/unreviewed/2022/05/GHSA-3rrr-cqqf-5xqm/GHSA-3rrr-cqqf-5xqm.json @@ -7,12 +7,8 @@ "CVE-2005-4829" ], "details": "VirtueMart before 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v6h-ww3h-9h87/GHSA-3v6h-ww3h-9h87.json b/advisories/unreviewed/2022/05/GHSA-3v6h-ww3h-9h87/GHSA-3v6h-ww3h-9h87.json index f6bb2156738..2161373b6da 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v6h-ww3h-9h87/GHSA-3v6h-ww3h-9h87.json +++ b/advisories/unreviewed/2022/05/GHSA-3v6h-ww3h-9h87/GHSA-3v6h-ww3h-9h87.json @@ -7,12 +7,8 @@ "CVE-2005-4632" ], "details": "SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vhg-jg9c-c6r7/GHSA-3vhg-jg9c-c6r7.json b/advisories/unreviewed/2022/05/GHSA-3vhg-jg9c-c6r7/GHSA-3vhg-jg9c-c6r7.json index 16223c3ca66..ab42753cfd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vhg-jg9c-c6r7/GHSA-3vhg-jg9c-c6r7.json +++ b/advisories/unreviewed/2022/05/GHSA-3vhg-jg9c-c6r7/GHSA-3vhg-jg9c-c6r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vq4-8jw3-cwr6/GHSA-3vq4-8jw3-cwr6.json b/advisories/unreviewed/2022/05/GHSA-3vq4-8jw3-cwr6/GHSA-3vq4-8jw3-cwr6.json index 1eed803345a..48c7e2d0a9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vq4-8jw3-cwr6/GHSA-3vq4-8jw3-cwr6.json +++ b/advisories/unreviewed/2022/05/GHSA-3vq4-8jw3-cwr6/GHSA-3vq4-8jw3-cwr6.json @@ -7,12 +7,8 @@ "CVE-2020-21913" ], "details": "International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vx6-hqv4-9pr7/GHSA-3vx6-hqv4-9pr7.json b/advisories/unreviewed/2022/05/GHSA-3vx6-hqv4-9pr7/GHSA-3vx6-hqv4-9pr7.json index 298d142af57..398fa2b9635 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vx6-hqv4-9pr7/GHSA-3vx6-hqv4-9pr7.json +++ b/advisories/unreviewed/2022/05/GHSA-3vx6-hqv4-9pr7/GHSA-3vx6-hqv4-9pr7.json @@ -7,12 +7,8 @@ "CVE-2005-4789" ], "details": "resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, does not properly enforce class-specific exclude rules in some situations, which allows local users to bypass intended access restrictions for USB devices that set their class ID at the interface level.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x85-87vg-8622/GHSA-3x85-87vg-8622.json b/advisories/unreviewed/2022/05/GHSA-3x85-87vg-8622/GHSA-3x85-87vg-8622.json index aa5af7bdc01..27473f69025 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x85-87vg-8622/GHSA-3x85-87vg-8622.json +++ b/advisories/unreviewed/2022/05/GHSA-3x85-87vg-8622/GHSA-3x85-87vg-8622.json @@ -7,12 +7,8 @@ "CVE-2005-4587" ], "details": "Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted) via a long crafted string on (1) port 7800 (the GUI Server port) or (2) port 7801 (the Device Server port).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42pp-ccmj-xrg8/GHSA-42pp-ccmj-xrg8.json b/advisories/unreviewed/2022/05/GHSA-42pp-ccmj-xrg8/GHSA-42pp-ccmj-xrg8.json index 25482d1980c..3f4c15effb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-42pp-ccmj-xrg8/GHSA-42pp-ccmj-xrg8.json +++ b/advisories/unreviewed/2022/05/GHSA-42pp-ccmj-xrg8/GHSA-42pp-ccmj-xrg8.json @@ -7,12 +7,8 @@ "CVE-2021-22018" ], "details": "The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42xm-24j2-64jf/GHSA-42xm-24j2-64jf.json b/advisories/unreviewed/2022/05/GHSA-42xm-24j2-64jf/GHSA-42xm-24j2-64jf.json index 97f49a5ecdb..45fde05fc49 100644 --- a/advisories/unreviewed/2022/05/GHSA-42xm-24j2-64jf/GHSA-42xm-24j2-64jf.json +++ b/advisories/unreviewed/2022/05/GHSA-42xm-24j2-64jf/GHSA-42xm-24j2-64jf.json @@ -7,12 +7,8 @@ "CVE-2005-4792" ], "details": "SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute arbitrary SQL commands via the module parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4387-c242-fcj2/GHSA-4387-c242-fcj2.json b/advisories/unreviewed/2022/05/GHSA-4387-c242-fcj2/GHSA-4387-c242-fcj2.json index 2cff2c31679..976b8330e2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4387-c242-fcj2/GHSA-4387-c242-fcj2.json +++ b/advisories/unreviewed/2022/05/GHSA-4387-c242-fcj2/GHSA-4387-c242-fcj2.json @@ -7,12 +7,8 @@ "CVE-2021-39533" ], "details": "An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-438g-9pr9-j76p/GHSA-438g-9pr9-j76p.json b/advisories/unreviewed/2022/05/GHSA-438g-9pr9-j76p/GHSA-438g-9pr9-j76p.json index aebfaea5c64..d6aa4a0878a 100644 --- a/advisories/unreviewed/2022/05/GHSA-438g-9pr9-j76p/GHSA-438g-9pr9-j76p.json +++ b/advisories/unreviewed/2022/05/GHSA-438g-9pr9-j76p/GHSA-438g-9pr9-j76p.json @@ -7,12 +7,8 @@ "CVE-2021-22014" ], "details": "The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-439v-qhv3-9f5x/GHSA-439v-qhv3-9f5x.json b/advisories/unreviewed/2022/05/GHSA-439v-qhv3-9f5x/GHSA-439v-qhv3-9f5x.json index 18bfb838f89..9d3258cca1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-439v-qhv3-9f5x/GHSA-439v-qhv3-9f5x.json +++ b/advisories/unreviewed/2022/05/GHSA-439v-qhv3-9f5x/GHSA-439v-qhv3-9f5x.json @@ -7,12 +7,8 @@ "CVE-2005-4606" ], "details": "SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43mr-gg87-qwf3/GHSA-43mr-gg87-qwf3.json b/advisories/unreviewed/2022/05/GHSA-43mr-gg87-qwf3/GHSA-43mr-gg87-qwf3.json index 2d56600efae..def850d16d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-43mr-gg87-qwf3/GHSA-43mr-gg87-qwf3.json +++ b/advisories/unreviewed/2022/05/GHSA-43mr-gg87-qwf3/GHSA-43mr-gg87-qwf3.json @@ -7,12 +7,8 @@ "CVE-2021-29763" ], "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-442p-f25m-xr85/GHSA-442p-f25m-xr85.json b/advisories/unreviewed/2022/05/GHSA-442p-f25m-xr85/GHSA-442p-f25m-xr85.json index 3325d56c3a5..141839a723e 100644 --- a/advisories/unreviewed/2022/05/GHSA-442p-f25m-xr85/GHSA-442p-f25m-xr85.json +++ b/advisories/unreviewed/2022/05/GHSA-442p-f25m-xr85/GHSA-442p-f25m-xr85.json @@ -7,12 +7,8 @@ "CVE-2020-35340" ], "details": "A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-446j-vwvf-m2wj/GHSA-446j-vwvf-m2wj.json b/advisories/unreviewed/2022/05/GHSA-446j-vwvf-m2wj/GHSA-446j-vwvf-m2wj.json index 5f387fc4db7..2b9c38f00fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-446j-vwvf-m2wj/GHSA-446j-vwvf-m2wj.json +++ b/advisories/unreviewed/2022/05/GHSA-446j-vwvf-m2wj/GHSA-446j-vwvf-m2wj.json @@ -7,12 +7,8 @@ "CVE-2020-4803" ], "details": "IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189535.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4482-cr2p-675v/GHSA-4482-cr2p-675v.json b/advisories/unreviewed/2022/05/GHSA-4482-cr2p-675v/GHSA-4482-cr2p-675v.json index c7ec879b0e7..3904df52c20 100644 --- a/advisories/unreviewed/2022/05/GHSA-4482-cr2p-675v/GHSA-4482-cr2p-675v.json +++ b/advisories/unreviewed/2022/05/GHSA-4482-cr2p-675v/GHSA-4482-cr2p-675v.json @@ -7,12 +7,8 @@ "CVE-2005-4474" ], "details": "Buffer overflow in the \"Add to archive\" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking the user into adding a file whose filename contains a non-default code page and non-ANSI characters, as demonstrated using a Chinese filename, possibly due to buffer expansion when using the WideCharToMultiByte API. NOTE: it is not clear whether this problem can be exploited for code execution. If not, then perhaps the user-assisted nature of the attack should exclude the issue from inclusion in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44hp-8f85-hjrw/GHSA-44hp-8f85-hjrw.json b/advisories/unreviewed/2022/05/GHSA-44hp-8f85-hjrw/GHSA-44hp-8f85-hjrw.json index 62091e7295a..83027a29dd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-44hp-8f85-hjrw/GHSA-44hp-8f85-hjrw.json +++ b/advisories/unreviewed/2022/05/GHSA-44hp-8f85-hjrw/GHSA-44hp-8f85-hjrw.json @@ -7,12 +7,8 @@ "CVE-2005-4858" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters associated with the (1) name, (2) title, and (3) comment sections, as demonstrated by referencing a remote document through the SRC attribute of an IFRAME element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44m9-8fq6-h94w/GHSA-44m9-8fq6-h94w.json b/advisories/unreviewed/2022/05/GHSA-44m9-8fq6-h94w/GHSA-44m9-8fq6-h94w.json index 898e05b096b..7db28d940b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-44m9-8fq6-h94w/GHSA-44m9-8fq6-h94w.json +++ b/advisories/unreviewed/2022/05/GHSA-44m9-8fq6-h94w/GHSA-44m9-8fq6-h94w.json @@ -7,12 +7,8 @@ "CVE-2021-22013" ], "details": "The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45v3-cf2w-246x/GHSA-45v3-cf2w-246x.json b/advisories/unreviewed/2022/05/GHSA-45v3-cf2w-246x/GHSA-45v3-cf2w-246x.json index 6eb690bd28d..7ab118476c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-45v3-cf2w-246x/GHSA-45v3-cf2w-246x.json +++ b/advisories/unreviewed/2022/05/GHSA-45v3-cf2w-246x/GHSA-45v3-cf2w-246x.json @@ -7,12 +7,8 @@ "CVE-2021-38336" ], "details": "The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4677-48q7-5jfp/GHSA-4677-48q7-5jfp.json b/advisories/unreviewed/2022/05/GHSA-4677-48q7-5jfp/GHSA-4677-48q7-5jfp.json index 2138b963199..ad7e94d5a82 100644 --- a/advisories/unreviewed/2022/05/GHSA-4677-48q7-5jfp/GHSA-4677-48q7-5jfp.json +++ b/advisories/unreviewed/2022/05/GHSA-4677-48q7-5jfp/GHSA-4677-48q7-5jfp.json @@ -7,12 +7,8 @@ "CVE-2005-4720" ], "details": "Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, leading to an infinite loop of widget resizes and a corresponding large number of function calls on the stack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4694-6229-fx5x/GHSA-4694-6229-fx5x.json b/advisories/unreviewed/2022/05/GHSA-4694-6229-fx5x/GHSA-4694-6229-fx5x.json index eafbef3a181..230adbd5d28 100644 --- a/advisories/unreviewed/2022/05/GHSA-4694-6229-fx5x/GHSA-4694-6229-fx5x.json +++ b/advisories/unreviewed/2022/05/GHSA-4694-6229-fx5x/GHSA-4694-6229-fx5x.json @@ -7,12 +7,8 @@ "CVE-2005-4496" ], "details": "Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-479c-w72f-jfxf/GHSA-479c-w72f-jfxf.json b/advisories/unreviewed/2022/05/GHSA-479c-w72f-jfxf/GHSA-479c-w72f-jfxf.json index 2c372109169..2b300be108f 100644 --- a/advisories/unreviewed/2022/05/GHSA-479c-w72f-jfxf/GHSA-479c-w72f-jfxf.json +++ b/advisories/unreviewed/2022/05/GHSA-479c-w72f-jfxf/GHSA-479c-w72f-jfxf.json @@ -7,12 +7,8 @@ "CVE-2005-4409" ], "details": "Cross-site scripting (XSS) vulnerability in MMBase 1.7.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48m3-fp26-hqqw/GHSA-48m3-fp26-hqqw.json b/advisories/unreviewed/2022/05/GHSA-48m3-fp26-hqqw/GHSA-48m3-fp26-hqqw.json index 7afa67a6344..2ee16c6857c 100644 --- a/advisories/unreviewed/2022/05/GHSA-48m3-fp26-hqqw/GHSA-48m3-fp26-hqqw.json +++ b/advisories/unreviewed/2022/05/GHSA-48m3-fp26-hqqw/GHSA-48m3-fp26-hqqw.json @@ -7,12 +7,8 @@ "CVE-2005-4413" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscription, and the (4) Movie Name, (5) Movie Reviewer, and (6) Movie Review fields to (d) TechnologySamples/MovieReview2_1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48q8-3ggg-p434/GHSA-48q8-3ggg-p434.json b/advisories/unreviewed/2022/05/GHSA-48q8-3ggg-p434/GHSA-48q8-3ggg-p434.json index a1f2acf04d3..feb82d46a16 100644 --- a/advisories/unreviewed/2022/05/GHSA-48q8-3ggg-p434/GHSA-48q8-3ggg-p434.json +++ b/advisories/unreviewed/2022/05/GHSA-48q8-3ggg-p434/GHSA-48q8-3ggg-p434.json @@ -7,12 +7,8 @@ "CVE-2005-4823" ], "details": "Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-495h-g8p3-vvq5/GHSA-495h-g8p3-vvq5.json b/advisories/unreviewed/2022/05/GHSA-495h-g8p3-vvq5/GHSA-495h-g8p3-vvq5.json index 5ca59a3817a..c24fa1f68e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-495h-g8p3-vvq5/GHSA-495h-g8p3-vvq5.json +++ b/advisories/unreviewed/2022/05/GHSA-495h-g8p3-vvq5/GHSA-495h-g8p3-vvq5.json @@ -7,12 +7,8 @@ "CVE-2021-39597" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_dump2() located in code.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-498v-8jr7-2hv8/GHSA-498v-8jr7-2hv8.json b/advisories/unreviewed/2022/05/GHSA-498v-8jr7-2hv8/GHSA-498v-8jr7-2hv8.json index cf4a920dfb3..eda3aeb3de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-498v-8jr7-2hv8/GHSA-498v-8jr7-2hv8.json +++ b/advisories/unreviewed/2022/05/GHSA-498v-8jr7-2hv8/GHSA-498v-8jr7-2hv8.json @@ -7,12 +7,8 @@ "CVE-2021-23035" ], "details": "On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49j8-5rc9-gjc6/GHSA-49j8-5rc9-gjc6.json b/advisories/unreviewed/2022/05/GHSA-49j8-5rc9-gjc6/GHSA-49j8-5rc9-gjc6.json index 59506d6f221..899866a6292 100644 --- a/advisories/unreviewed/2022/05/GHSA-49j8-5rc9-gjc6/GHSA-49j8-5rc9-gjc6.json +++ b/advisories/unreviewed/2022/05/GHSA-49j8-5rc9-gjc6/GHSA-49j8-5rc9-gjc6.json @@ -7,12 +7,8 @@ "CVE-2021-32132" ], "details": "The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49v3-47vp-q76c/GHSA-49v3-47vp-q76c.json b/advisories/unreviewed/2022/05/GHSA-49v3-47vp-q76c/GHSA-49v3-47vp-q76c.json index b891c0bfa40..3e1b9a0e9d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-49v3-47vp-q76c/GHSA-49v3-47vp-q76c.json +++ b/advisories/unreviewed/2022/05/GHSA-49v3-47vp-q76c/GHSA-49v3-47vp-q76c.json @@ -7,12 +7,8 @@ "CVE-2020-20898" ], "details": "Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c2f-99wj-9wvv/GHSA-4c2f-99wj-9wvv.json b/advisories/unreviewed/2022/05/GHSA-4c2f-99wj-9wvv/GHSA-4c2f-99wj-9wvv.json index b6345a740ce..120c57c894c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c2f-99wj-9wvv/GHSA-4c2f-99wj-9wvv.json +++ b/advisories/unreviewed/2022/05/GHSA-4c2f-99wj-9wvv/GHSA-4c2f-99wj-9wvv.json @@ -7,12 +7,8 @@ "CVE-2005-4831" ], "details": "viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting (XSS) and other attacks, as demonstrated using (1) \"text/html\", or (2) \"image/jpeg\" with an image that is rendered as HTML by Internet Explorer, a different vulnerability than CVE-2004-1062. NOTE: it was later reported that 0.9.4 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cg6-r453-9frw/GHSA-4cg6-r453-9frw.json b/advisories/unreviewed/2022/05/GHSA-4cg6-r453-9frw/GHSA-4cg6-r453-9frw.json index 0fab3c8b5a0..0b44f995f93 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cg6-r453-9frw/GHSA-4cg6-r453-9frw.json +++ b/advisories/unreviewed/2022/05/GHSA-4cg6-r453-9frw/GHSA-4cg6-r453-9frw.json @@ -7,12 +7,8 @@ "CVE-2005-4620" ], "details": "Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cm7-26hr-cjq7/GHSA-4cm7-26hr-cjq7.json b/advisories/unreviewed/2022/05/GHSA-4cm7-26hr-cjq7/GHSA-4cm7-26hr-cjq7.json index 1ea3f475137..41cd92788b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cm7-26hr-cjq7/GHSA-4cm7-26hr-cjq7.json +++ b/advisories/unreviewed/2022/05/GHSA-4cm7-26hr-cjq7/GHSA-4cm7-26hr-cjq7.json @@ -7,12 +7,8 @@ "CVE-2021-38092" ], "details": "Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4crx-48p2-6mjx/GHSA-4crx-48p2-6mjx.json b/advisories/unreviewed/2022/05/GHSA-4crx-48p2-6mjx/GHSA-4crx-48p2-6mjx.json index 0f96cd2235f..fb039adcf1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4crx-48p2-6mjx/GHSA-4crx-48p2-6mjx.json +++ b/advisories/unreviewed/2022/05/GHSA-4crx-48p2-6mjx/GHSA-4crx-48p2-6mjx.json @@ -7,12 +7,8 @@ "CVE-2021-32284" ], "details": "An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cx3-gvx4-j3wg/GHSA-4cx3-gvx4-j3wg.json b/advisories/unreviewed/2022/05/GHSA-4cx3-gvx4-j3wg/GHSA-4cx3-gvx4-j3wg.json index 0a9d1755fea..1695f73fb2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cx3-gvx4-j3wg/GHSA-4cx3-gvx4-j3wg.json +++ b/advisories/unreviewed/2022/05/GHSA-4cx3-gvx4-j3wg/GHSA-4cx3-gvx4-j3wg.json @@ -7,12 +7,8 @@ "CVE-2021-22949" ], "details": "A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: \"Solar Security CMS Research Team\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f93-cwh7-v69v/GHSA-4f93-cwh7-v69v.json b/advisories/unreviewed/2022/05/GHSA-4f93-cwh7-v69v/GHSA-4f93-cwh7-v69v.json index 2ed59057750..ee0801d6a17 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f93-cwh7-v69v/GHSA-4f93-cwh7-v69v.json +++ b/advisories/unreviewed/2022/05/GHSA-4f93-cwh7-v69v/GHSA-4f93-cwh7-v69v.json @@ -7,12 +7,8 @@ "CVE-2021-39582" ], "details": "An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_GetPlaceObject() located in swfobject.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g5r-47p7-6qm4/GHSA-4g5r-47p7-6qm4.json b/advisories/unreviewed/2022/05/GHSA-4g5r-47p7-6qm4/GHSA-4g5r-47p7-6qm4.json index bd917403e1b..2d96ade3d69 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g5r-47p7-6qm4/GHSA-4g5r-47p7-6qm4.json +++ b/advisories/unreviewed/2022/05/GHSA-4g5r-47p7-6qm4/GHSA-4g5r-47p7-6qm4.json @@ -7,12 +7,8 @@ "CVE-2005-4687" ], "details": "PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than the TCP/IP stack, which allows remote attackers to misrepresent their IP address by sending a modified header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g64-jfhc-95g2/GHSA-4g64-jfhc-95g2.json b/advisories/unreviewed/2022/05/GHSA-4g64-jfhc-95g2/GHSA-4g64-jfhc-95g2.json index f103ca424b4..b9000ba23a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g64-jfhc-95g2/GHSA-4g64-jfhc-95g2.json +++ b/advisories/unreviewed/2022/05/GHSA-4g64-jfhc-95g2/GHSA-4g64-jfhc-95g2.json @@ -7,12 +7,8 @@ "CVE-2021-36872" ], "details": "Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g6c-jv87-fj3x/GHSA-4g6c-jv87-fj3x.json b/advisories/unreviewed/2022/05/GHSA-4g6c-jv87-fj3x/GHSA-4g6c-jv87-fj3x.json index 67ee55b1121..e9c3b0d2a03 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g6c-jv87-fj3x/GHSA-4g6c-jv87-fj3x.json +++ b/advisories/unreviewed/2022/05/GHSA-4g6c-jv87-fj3x/GHSA-4g6c-jv87-fj3x.json @@ -7,12 +7,8 @@ "CVE-2021-38089" ], "details": "Buffer Overflow vulnerability in function config_input in libavfilter/vf_bm3d.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4grv-jw7c-q92p/GHSA-4grv-jw7c-q92p.json b/advisories/unreviewed/2022/05/GHSA-4grv-jw7c-q92p/GHSA-4grv-jw7c-q92p.json index 990ed0b3c9d..14d69e288ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-4grv-jw7c-q92p/GHSA-4grv-jw7c-q92p.json +++ b/advisories/unreviewed/2022/05/GHSA-4grv-jw7c-q92p/GHSA-4grv-jw7c-q92p.json @@ -7,12 +7,8 @@ "CVE-2005-4715" ], "details": "Multiple SQL injection vulnerabilities in modules.php in PHP-Nuke 7.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) sid, and (3) pid parameters in a POST request, which bypasses security checks that are performed for GET requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4h7j-8cv2-jpwj/GHSA-4h7j-8cv2-jpwj.json b/advisories/unreviewed/2022/05/GHSA-4h7j-8cv2-jpwj/GHSA-4h7j-8cv2-jpwj.json index f750fa84a0c..80d89a550b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h7j-8cv2-jpwj/GHSA-4h7j-8cv2-jpwj.json +++ b/advisories/unreviewed/2022/05/GHSA-4h7j-8cv2-jpwj/GHSA-4h7j-8cv2-jpwj.json @@ -7,12 +7,8 @@ "CVE-2005-4436" ], "details": "Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS after 12.3(2), 12.3(3)B, and 12.3(2)T and other products, allows remote attackers to cause a denial of service by sending a \"spoofed neighbor announcement\" with (1) mismatched k values or (2) \"goodbye message\" Type-Length-Value (TLV).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hmg-5gr9-qvqw/GHSA-4hmg-5gr9-qvqw.json b/advisories/unreviewed/2022/05/GHSA-4hmg-5gr9-qvqw/GHSA-4hmg-5gr9-qvqw.json index 44cc56a5651..d6a06c5f665 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hmg-5gr9-qvqw/GHSA-4hmg-5gr9-qvqw.json +++ b/advisories/unreviewed/2022/05/GHSA-4hmg-5gr9-qvqw/GHSA-4hmg-5gr9-qvqw.json @@ -7,12 +7,8 @@ "CVE-2005-4786" ], "details": "Buffer overflow in the archive decompression library (vrAZMain.dll 5.8.22.137), as used in HAURI anti-virus products including (1) ViRobot Expert 4.0, (2) ViRobot Advanced Server, and (3) HAURI LiveCall, allows user-assisted attackers to execute arbitrary code via an ALZ archive containing a file with a long filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hqw-3ggw-h3m4/GHSA-4hqw-3ggw-h3m4.json b/advisories/unreviewed/2022/05/GHSA-4hqw-3ggw-h3m4/GHSA-4hqw-3ggw-h3m4.json index 2df7d75d208..9990a9487a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hqw-3ggw-h3m4/GHSA-4hqw-3ggw-h3m4.json +++ b/advisories/unreviewed/2022/05/GHSA-4hqw-3ggw-h3m4/GHSA-4hqw-3ggw-h3m4.json @@ -7,12 +7,8 @@ "CVE-2021-39555" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hv4-q965-54rg/GHSA-4hv4-q965-54rg.json b/advisories/unreviewed/2022/05/GHSA-4hv4-q965-54rg/GHSA-4hv4-q965-54rg.json index 0a3ee352be6..c7a67f11d62 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hv4-q965-54rg/GHSA-4hv4-q965-54rg.json +++ b/advisories/unreviewed/2022/05/GHSA-4hv4-q965-54rg/GHSA-4hv4-q965-54rg.json @@ -7,12 +7,8 @@ "CVE-2020-20899" ], "details": "Buffer Overflow vulnerability in function config_props in libavfilter/vf_bwdif.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j8h-3qv8-5cpm/GHSA-4j8h-3qv8-5cpm.json b/advisories/unreviewed/2022/05/GHSA-4j8h-3qv8-5cpm/GHSA-4j8h-3qv8-5cpm.json index 2b93fd1b4a0..9cb09adc466 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j8h-3qv8-5cpm/GHSA-4j8h-3qv8-5cpm.json +++ b/advisories/unreviewed/2022/05/GHSA-4j8h-3qv8-5cpm/GHSA-4j8h-3qv8-5cpm.json @@ -7,12 +7,8 @@ "CVE-2005-4656" ], "details": "SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mc9-vgjj-p3v5/GHSA-4mc9-vgjj-p3v5.json b/advisories/unreviewed/2022/05/GHSA-4mc9-vgjj-p3v5/GHSA-4mc9-vgjj-p3v5.json index bb552a3d278..d08122d7081 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mc9-vgjj-p3v5/GHSA-4mc9-vgjj-p3v5.json +++ b/advisories/unreviewed/2022/05/GHSA-4mc9-vgjj-p3v5/GHSA-4mc9-vgjj-p3v5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mf2-c3h2-mq3p/GHSA-4mf2-c3h2-mq3p.json b/advisories/unreviewed/2022/05/GHSA-4mf2-c3h2-mq3p/GHSA-4mf2-c3h2-mq3p.json index 7bcf89f2ef7..d53d3c0f512 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mf2-c3h2-mq3p/GHSA-4mf2-c3h2-mq3p.json +++ b/advisories/unreviewed/2022/05/GHSA-4mf2-c3h2-mq3p/GHSA-4mf2-c3h2-mq3p.json @@ -7,12 +7,8 @@ "CVE-2021-33695" ], "details": "Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p7q-px7w-p3p9/GHSA-4p7q-px7w-p3p9.json b/advisories/unreviewed/2022/05/GHSA-4p7q-px7w-p3p9/GHSA-4p7q-px7w-p3p9.json index b1a71b1598e..403131c4eb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p7q-px7w-p3p9/GHSA-4p7q-px7w-p3p9.json +++ b/advisories/unreviewed/2022/05/GHSA-4p7q-px7w-p3p9/GHSA-4p7q-px7w-p3p9.json @@ -7,12 +7,8 @@ "CVE-2021-33692" ], "details": "SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p9w-rqv4-74j3/GHSA-4p9w-rqv4-74j3.json b/advisories/unreviewed/2022/05/GHSA-4p9w-rqv4-74j3/GHSA-4p9w-rqv4-74j3.json index a760df851e6..8327e67e88a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p9w-rqv4-74j3/GHSA-4p9w-rqv4-74j3.json +++ b/advisories/unreviewed/2022/05/GHSA-4p9w-rqv4-74j3/GHSA-4p9w-rqv4-74j3.json @@ -7,12 +7,8 @@ "CVE-2005-4584" ], "details": "BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\\0) character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q7p-3266-2mj7/GHSA-4q7p-3266-2mj7.json b/advisories/unreviewed/2022/05/GHSA-4q7p-3266-2mj7/GHSA-4q7p-3266-2mj7.json index 6a87c282759..80d380e26a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q7p-3266-2mj7/GHSA-4q7p-3266-2mj7.json +++ b/advisories/unreviewed/2022/05/GHSA-4q7p-3266-2mj7/GHSA-4q7p-3266-2mj7.json @@ -7,12 +7,8 @@ "CVE-2005-4723" ], "details": "D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q8v-hwx2-8gc2/GHSA-4q8v-hwx2-8gc2.json b/advisories/unreviewed/2022/05/GHSA-4q8v-hwx2-8gc2/GHSA-4q8v-hwx2-8gc2.json index 06f98146eeb..c514667cccb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q8v-hwx2-8gc2/GHSA-4q8v-hwx2-8gc2.json +++ b/advisories/unreviewed/2022/05/GHSA-4q8v-hwx2-8gc2/GHSA-4q8v-hwx2-8gc2.json @@ -7,12 +7,8 @@ "CVE-2021-23034" ], "details": "On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r52-ff3g-g952/GHSA-4r52-ff3g-g952.json b/advisories/unreviewed/2022/05/GHSA-4r52-ff3g-g952/GHSA-4r52-ff3g-g952.json index 609ad0f85db..0b1602d08cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r52-ff3g-g952/GHSA-4r52-ff3g-g952.json +++ b/advisories/unreviewed/2022/05/GHSA-4r52-ff3g-g952/GHSA-4r52-ff3g-g952.json @@ -7,12 +7,8 @@ "CVE-2005-4835" ], "details": "The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rj4-mjp8-mcgg/GHSA-4rj4-mjp8-mcgg.json b/advisories/unreviewed/2022/05/GHSA-4rj4-mjp8-mcgg/GHSA-4rj4-mjp8-mcgg.json index fd9da376587..0c2b37f1afc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rj4-mjp8-mcgg/GHSA-4rj4-mjp8-mcgg.json +++ b/advisories/unreviewed/2022/05/GHSA-4rj4-mjp8-mcgg/GHSA-4rj4-mjp8-mcgg.json @@ -7,12 +7,8 @@ "CVE-2005-4442" ], "details": "Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rx4-97jg-645p/GHSA-4rx4-97jg-645p.json b/advisories/unreviewed/2022/05/GHSA-4rx4-97jg-645p/GHSA-4rx4-97jg-645p.json index 5e88c6fefce..d1c03adaafa 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rx4-97jg-645p/GHSA-4rx4-97jg-645p.json +++ b/advisories/unreviewed/2022/05/GHSA-4rx4-97jg-645p/GHSA-4rx4-97jg-645p.json @@ -7,12 +7,8 @@ "CVE-2005-4412" ], "details": "Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v3v-2c52-v3v9/GHSA-4v3v-2c52-v3v9.json b/advisories/unreviewed/2022/05/GHSA-4v3v-2c52-v3v9/GHSA-4v3v-2c52-v3v9.json index 63b94b0eba4..de6c525a747 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v3v-2c52-v3v9/GHSA-4v3v-2c52-v3v9.json +++ b/advisories/unreviewed/2022/05/GHSA-4v3v-2c52-v3v9/GHSA-4v3v-2c52-v3v9.json @@ -7,12 +7,8 @@ "CVE-2005-4851" ], "details": "eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wgh-rg45-9q3p/GHSA-4wgh-rg45-9q3p.json b/advisories/unreviewed/2022/05/GHSA-4wgh-rg45-9q3p/GHSA-4wgh-rg45-9q3p.json index 6889351b984..1d767d813a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wgh-rg45-9q3p/GHSA-4wgh-rg45-9q3p.json +++ b/advisories/unreviewed/2022/05/GHSA-4wgh-rg45-9q3p/GHSA-4wgh-rg45-9q3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wgj-77qr-7qgf/GHSA-4wgj-77qr-7qgf.json b/advisories/unreviewed/2022/05/GHSA-4wgj-77qr-7qgf/GHSA-4wgj-77qr-7qgf.json index e569b4eb879..2b1b3ef98dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wgj-77qr-7qgf/GHSA-4wgj-77qr-7qgf.json +++ b/advisories/unreviewed/2022/05/GHSA-4wgj-77qr-7qgf/GHSA-4wgj-77qr-7qgf.json @@ -7,12 +7,8 @@ "CVE-2021-39534" ], "details": "An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52rv-hwx6-25rg/GHSA-52rv-hwx6-25rg.json b/advisories/unreviewed/2022/05/GHSA-52rv-hwx6-25rg/GHSA-52rv-hwx6-25rg.json index fad6d811064..96dd6029c4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-52rv-hwx6-25rg/GHSA-52rv-hwx6-25rg.json +++ b/advisories/unreviewed/2022/05/GHSA-52rv-hwx6-25rg/GHSA-52rv-hwx6-25rg.json @@ -7,12 +7,8 @@ "CVE-2005-4817" ], "details": "Format string vulnerability in ui.c in Textbased MSN Client (TMSNC) before 0.2.5 allows attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors that cause format strings to be injected into the wprintw function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-537f-w6wj-gphx/GHSA-537f-w6wj-gphx.json b/advisories/unreviewed/2022/05/GHSA-537f-w6wj-gphx/GHSA-537f-w6wj-gphx.json index ecc3252eef0..5a58a7348f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-537f-w6wj-gphx/GHSA-537f-w6wj-gphx.json +++ b/advisories/unreviewed/2022/05/GHSA-537f-w6wj-gphx/GHSA-537f-w6wj-gphx.json @@ -7,12 +7,8 @@ "CVE-2021-34650" ], "details": "The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53f4-27hf-367h/GHSA-53f4-27hf-367h.json b/advisories/unreviewed/2022/05/GHSA-53f4-27hf-367h/GHSA-53f4-27hf-367h.json index 7150565f038..63e859914a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-53f4-27hf-367h/GHSA-53f4-27hf-367h.json +++ b/advisories/unreviewed/2022/05/GHSA-53f4-27hf-367h/GHSA-53f4-27hf-367h.json @@ -7,12 +7,8 @@ "CVE-2005-4791" ], "details": "Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) liferea or (2) banshee.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53h7-vpr4-87w8/GHSA-53h7-vpr4-87w8.json b/advisories/unreviewed/2022/05/GHSA-53h7-vpr4-87w8/GHSA-53h7-vpr4-87w8.json index c4541587b1b..eae43e6b3aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-53h7-vpr4-87w8/GHSA-53h7-vpr4-87w8.json +++ b/advisories/unreviewed/2022/05/GHSA-53h7-vpr4-87w8/GHSA-53h7-vpr4-87w8.json @@ -7,12 +7,8 @@ "CVE-2020-20672" ], "details": "An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-542c-p7pq-534w/GHSA-542c-p7pq-534w.json b/advisories/unreviewed/2022/05/GHSA-542c-p7pq-534w/GHSA-542c-p7pq-534w.json index 5794880693b..d9cd7008b4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-542c-p7pq-534w/GHSA-542c-p7pq-534w.json +++ b/advisories/unreviewed/2022/05/GHSA-542c-p7pq-534w/GHSA-542c-p7pq-534w.json @@ -7,12 +7,8 @@ "CVE-2021-24609" ], "details": "The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54pm-xxpg-8wgg/GHSA-54pm-xxpg-8wgg.json b/advisories/unreviewed/2022/05/GHSA-54pm-xxpg-8wgg/GHSA-54pm-xxpg-8wgg.json index affda5484b4..de720985e19 100644 --- a/advisories/unreviewed/2022/05/GHSA-54pm-xxpg-8wgg/GHSA-54pm-xxpg-8wgg.json +++ b/advisories/unreviewed/2022/05/GHSA-54pm-xxpg-8wgg/GHSA-54pm-xxpg-8wgg.json @@ -7,12 +7,8 @@ "CVE-2005-4708" ], "details": "Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5523-jhw7-49q2/GHSA-5523-jhw7-49q2.json b/advisories/unreviewed/2022/05/GHSA-5523-jhw7-49q2/GHSA-5523-jhw7-49q2.json index 1d2f682c721..b8075c185eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5523-jhw7-49q2/GHSA-5523-jhw7-49q2.json +++ b/advisories/unreviewed/2022/05/GHSA-5523-jhw7-49q2/GHSA-5523-jhw7-49q2.json @@ -7,12 +7,8 @@ "CVE-2005-4854" ], "details": "eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive information about changes to content in arbitrary folders.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5656-pvjm-rmvr/GHSA-5656-pvjm-rmvr.json b/advisories/unreviewed/2022/05/GHSA-5656-pvjm-rmvr/GHSA-5656-pvjm-rmvr.json index 89e03210262..f6221c955cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5656-pvjm-rmvr/GHSA-5656-pvjm-rmvr.json +++ b/advisories/unreviewed/2022/05/GHSA-5656-pvjm-rmvr/GHSA-5656-pvjm-rmvr.json @@ -7,12 +7,8 @@ "CVE-2021-29808" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204269.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56rm-phj6-xx36/GHSA-56rm-phj6-xx36.json b/advisories/unreviewed/2022/05/GHSA-56rm-phj6-xx36/GHSA-56rm-phj6-xx36.json index 21db2a89eab..aae0623aeaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-56rm-phj6-xx36/GHSA-56rm-phj6-xx36.json +++ b/advisories/unreviewed/2022/05/GHSA-56rm-phj6-xx36/GHSA-56rm-phj6-xx36.json @@ -7,12 +7,8 @@ "CVE-2005-4848" ], "details": "Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier before 20050607 might allow remote attackers to execute arbitrary code via certain data packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-572w-75xw-3g5f/GHSA-572w-75xw-3g5f.json b/advisories/unreviewed/2022/05/GHSA-572w-75xw-3g5f/GHSA-572w-75xw-3g5f.json index e32cea377c0..914b2c71fbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-572w-75xw-3g5f/GHSA-572w-75xw-3g5f.json +++ b/advisories/unreviewed/2022/05/GHSA-572w-75xw-3g5f/GHSA-572w-75xw-3g5f.json @@ -7,12 +7,8 @@ "CVE-2021-39595" ], "details": "An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function rfx_alloc() located in mem.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-573h-c24j-7p83/GHSA-573h-c24j-7p83.json b/advisories/unreviewed/2022/05/GHSA-573h-c24j-7p83/GHSA-573h-c24j-7p83.json index 52788fc90a5..d1b4b053c39 100644 --- a/advisories/unreviewed/2022/05/GHSA-573h-c24j-7p83/GHSA-573h-c24j-7p83.json +++ b/advisories/unreviewed/2022/05/GHSA-573h-c24j-7p83/GHSA-573h-c24j-7p83.json @@ -7,12 +7,8 @@ "CVE-2021-24490" ], "details": "The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57j8-fw4m-qrrv/GHSA-57j8-fw4m-qrrv.json b/advisories/unreviewed/2022/05/GHSA-57j8-fw4m-qrrv/GHSA-57j8-fw4m-qrrv.json index 04476072af9..ee904039ef7 100644 --- a/advisories/unreviewed/2022/05/GHSA-57j8-fw4m-qrrv/GHSA-57j8-fw4m-qrrv.json +++ b/advisories/unreviewed/2022/05/GHSA-57j8-fw4m-qrrv/GHSA-57j8-fw4m-qrrv.json @@ -7,12 +7,8 @@ "CVE-2005-4828" ], "details": "Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a \".\" in the wrong place, which causes kolabfilter to add another \".\", which might break clear-text signatures and attachments. NOTE: it is not clear whether this issue crosses privilege boundaries, so this might not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-587q-w3p6-m55g/GHSA-587q-w3p6-m55g.json b/advisories/unreviewed/2022/05/GHSA-587q-w3p6-m55g/GHSA-587q-w3p6-m55g.json index cdc8f98ce50..8e453a4f317 100644 --- a/advisories/unreviewed/2022/05/GHSA-587q-w3p6-m55g/GHSA-587q-w3p6-m55g.json +++ b/advisories/unreviewed/2022/05/GHSA-587q-w3p6-m55g/GHSA-587q-w3p6-m55g.json @@ -7,12 +7,8 @@ "CVE-2021-24636" ], "details": "The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58j9-3frf-c53r/GHSA-58j9-3frf-c53r.json b/advisories/unreviewed/2022/05/GHSA-58j9-3frf-c53r/GHSA-58j9-3frf-c53r.json index ddee3821f51..2a196da966b 100644 --- a/advisories/unreviewed/2022/05/GHSA-58j9-3frf-c53r/GHSA-58j9-3frf-c53r.json +++ b/advisories/unreviewed/2022/05/GHSA-58j9-3frf-c53r/GHSA-58j9-3frf-c53r.json @@ -7,12 +7,8 @@ "CVE-2021-24726" ], "details": "The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58qh-2fp2-v597/GHSA-58qh-2fp2-v597.json b/advisories/unreviewed/2022/05/GHSA-58qh-2fp2-v597/GHSA-58qh-2fp2-v597.json index 2981160285f..524e7be037f 100644 --- a/advisories/unreviewed/2022/05/GHSA-58qh-2fp2-v597/GHSA-58qh-2fp2-v597.json +++ b/advisories/unreviewed/2022/05/GHSA-58qh-2fp2-v597/GHSA-58qh-2fp2-v597.json @@ -7,12 +7,8 @@ "CVE-2021-39525" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-593w-pcpp-m35w/GHSA-593w-pcpp-m35w.json b/advisories/unreviewed/2022/05/GHSA-593w-pcpp-m35w/GHSA-593w-pcpp-m35w.json index a74a557e238..821fdbb77f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-593w-pcpp-m35w/GHSA-593w-pcpp-m35w.json +++ b/advisories/unreviewed/2022/05/GHSA-593w-pcpp-m35w/GHSA-593w-pcpp-m35w.json @@ -7,12 +7,8 @@ "CVE-2006-0046" ], "details": "squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59mh-243q-3prc/GHSA-59mh-243q-3prc.json b/advisories/unreviewed/2022/05/GHSA-59mh-243q-3prc/GHSA-59mh-243q-3prc.json index 607d29264a8..6aa94c0b3e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-59mh-243q-3prc/GHSA-59mh-243q-3prc.json +++ b/advisories/unreviewed/2022/05/GHSA-59mh-243q-3prc/GHSA-59mh-243q-3prc.json @@ -7,12 +7,8 @@ "CVE-2021-41391" ], "details": "In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59r2-367p-xv4j/GHSA-59r2-367p-xv4j.json b/advisories/unreviewed/2022/05/GHSA-59r2-367p-xv4j/GHSA-59r2-367p-xv4j.json index f6cdcfc3c5b..87eab48cd30 100644 --- a/advisories/unreviewed/2022/05/GHSA-59r2-367p-xv4j/GHSA-59r2-367p-xv4j.json +++ b/advisories/unreviewed/2022/05/GHSA-59r2-367p-xv4j/GHSA-59r2-367p-xv4j.json @@ -7,12 +7,8 @@ "CVE-2021-37173" ], "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions < V2.14.1), RUGGEDCOM ROX RX1512 (All versions < V2.14.1), RUGGEDCOM ROX RX1524 (All versions < V2.14.1), RUGGEDCOM ROX RX1536 (All versions < V2.14.1), RUGGEDCOM ROX RX5000 (All versions < V2.14.1). The affected devices have an exposure of sensitive information vulnerability, if exploited, it could allow an authenticated attacker to extract data via Secure Shell (SSH).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cg2-qm4w-wc65/GHSA-5cg2-qm4w-wc65.json b/advisories/unreviewed/2022/05/GHSA-5cg2-qm4w-wc65/GHSA-5cg2-qm4w-wc65.json index 4eacf3bf338..22b251e7d3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cg2-qm4w-wc65/GHSA-5cg2-qm4w-wc65.json +++ b/advisories/unreviewed/2022/05/GHSA-5cg2-qm4w-wc65/GHSA-5cg2-qm4w-wc65.json @@ -7,12 +7,8 @@ "CVE-2005-4654" ], "details": "Multiple unspecified vulnerabilities in Oracle for OpenView (OfO) 8.1.7, 9.1.01, and 9.2, and OfO for Linux, allow remote attackers to have an unknown impact via unknown attack vectors. NOTE: because of the lack of details in the vendor advisory, it is unclear which set of existing CVEs this advisory might refer to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cqf-vv6j-6f4g/GHSA-5cqf-vv6j-6f4g.json b/advisories/unreviewed/2022/05/GHSA-5cqf-vv6j-6f4g/GHSA-5cqf-vv6j-6f4g.json index 17dfc8abae4..f33f54f5e99 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cqf-vv6j-6f4g/GHSA-5cqf-vv6j-6f4g.json +++ b/advisories/unreviewed/2022/05/GHSA-5cqf-vv6j-6f4g/GHSA-5cqf-vv6j-6f4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cv6-f7pr-xhrj/GHSA-5cv6-f7pr-xhrj.json b/advisories/unreviewed/2022/05/GHSA-5cv6-f7pr-xhrj/GHSA-5cv6-f7pr-xhrj.json index 4b6243f920b..2a62149b217 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cv6-f7pr-xhrj/GHSA-5cv6-f7pr-xhrj.json +++ b/advisories/unreviewed/2022/05/GHSA-5cv6-f7pr-xhrj/GHSA-5cv6-f7pr-xhrj.json @@ -7,12 +7,8 @@ "CVE-2021-29819" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204346.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f76-6475-7p9f/GHSA-5f76-6475-7p9f.json b/advisories/unreviewed/2022/05/GHSA-5f76-6475-7p9f/GHSA-5f76-6475-7p9f.json index 83878420bc7..c10b6002995 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f76-6475-7p9f/GHSA-5f76-6475-7p9f.json +++ b/advisories/unreviewed/2022/05/GHSA-5f76-6475-7p9f/GHSA-5f76-6475-7p9f.json @@ -7,12 +7,8 @@ "CVE-2005-4626" ], "details": "The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fcm-588g-hv9p/GHSA-5fcm-588g-hv9p.json b/advisories/unreviewed/2022/05/GHSA-5fcm-588g-hv9p/GHSA-5fcm-588g-hv9p.json index bce65015170..7cc70a0d087 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fcm-588g-hv9p/GHSA-5fcm-588g-hv9p.json +++ b/advisories/unreviewed/2022/05/GHSA-5fcm-588g-hv9p/GHSA-5fcm-588g-hv9p.json @@ -7,12 +7,8 @@ "CVE-2021-39584" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function namespace_set_hash() located in pool.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h3v-8m6q-48c4/GHSA-5h3v-8m6q-48c4.json b/advisories/unreviewed/2022/05/GHSA-5h3v-8m6q-48c4/GHSA-5h3v-8m6q-48c4.json index e81467e7921..2896304feaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h3v-8m6q-48c4/GHSA-5h3v-8m6q-48c4.json +++ b/advisories/unreviewed/2022/05/GHSA-5h3v-8m6q-48c4/GHSA-5h3v-8m6q-48c4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hqx-qwqq-6xmq/GHSA-5hqx-qwqq-6xmq.json b/advisories/unreviewed/2022/05/GHSA-5hqx-qwqq-6xmq/GHSA-5hqx-qwqq-6xmq.json index e299e209b01..5e0852b5906 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hqx-qwqq-6xmq/GHSA-5hqx-qwqq-6xmq.json +++ b/advisories/unreviewed/2022/05/GHSA-5hqx-qwqq-6xmq/GHSA-5hqx-qwqq-6xmq.json @@ -7,12 +7,8 @@ "CVE-2021-24605" ], "details": "The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jg4-gfhx-2rxm/GHSA-5jg4-gfhx-2rxm.json b/advisories/unreviewed/2022/05/GHSA-5jg4-gfhx-2rxm/GHSA-5jg4-gfhx-2rxm.json index 6c0c14be106..9957ef27e36 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jg4-gfhx-2rxm/GHSA-5jg4-gfhx-2rxm.json +++ b/advisories/unreviewed/2022/05/GHSA-5jg4-gfhx-2rxm/GHSA-5jg4-gfhx-2rxm.json @@ -7,12 +7,8 @@ "CVE-2005-4648" ], "details": "Buffer overflow in Illustrate dBpowerAMP Music Converter 11.5 and earlier, possibly including (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe, allows user-assisted attackers to cause a denial of service or execute arbitrary code via a .m3u playlist with a long entry, possibly involving large field names, as demonstrated by SecuBox.Labs.m3u. NOTE: this issue might be the same as the .m3u vulnerability in CVE-2004-1569, but if so, then CD:SF-LOC suggests creating a different identifier since the .m3u issue would affect different versions than the .pls issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mg8-9hx2-j7wf/GHSA-5mg8-9hx2-j7wf.json b/advisories/unreviewed/2022/05/GHSA-5mg8-9hx2-j7wf/GHSA-5mg8-9hx2-j7wf.json index 72e60e05267..e90af0c45cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mg8-9hx2-j7wf/GHSA-5mg8-9hx2-j7wf.json +++ b/advisories/unreviewed/2022/05/GHSA-5mg8-9hx2-j7wf/GHSA-5mg8-9hx2-j7wf.json @@ -7,12 +7,8 @@ "CVE-2016-6555" ], "details": "OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mgj-p8j2-rqx8/GHSA-5mgj-p8j2-rqx8.json b/advisories/unreviewed/2022/05/GHSA-5mgj-p8j2-rqx8/GHSA-5mgj-p8j2-rqx8.json index ba73da84958..491f011db34 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mgj-p8j2-rqx8/GHSA-5mgj-p8j2-rqx8.json +++ b/advisories/unreviewed/2022/05/GHSA-5mgj-p8j2-rqx8/GHSA-5mgj-p8j2-rqx8.json @@ -7,12 +7,8 @@ "CVE-2021-38347" ], "details": "The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in the ~/views/edit.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p8c-8g3r-93fc/GHSA-5p8c-8g3r-93fc.json b/advisories/unreviewed/2022/05/GHSA-5p8c-8g3r-93fc/GHSA-5p8c-8g3r-93fc.json index 2744e337bdf..268cca9ed7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p8c-8g3r-93fc/GHSA-5p8c-8g3r-93fc.json +++ b/advisories/unreviewed/2022/05/GHSA-5p8c-8g3r-93fc/GHSA-5p8c-8g3r-93fc.json @@ -7,12 +7,8 @@ "CVE-2021-24725" ], "details": "The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pc5-6r92-7p4x/GHSA-5pc5-6r92-7p4x.json b/advisories/unreviewed/2022/05/GHSA-5pc5-6r92-7p4x/GHSA-5pc5-6r92-7p4x.json index 673852481f1..5bbd2fcf17b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pc5-6r92-7p4x/GHSA-5pc5-6r92-7p4x.json +++ b/advisories/unreviewed/2022/05/GHSA-5pc5-6r92-7p4x/GHSA-5pc5-6r92-7p4x.json @@ -7,12 +7,8 @@ "CVE-2005-4630" ], "details": "SQL injection vulnerability in index.php in ClientExec 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) billshowid, (2) billdetailid, (3) fuse, and (4) frmClientID parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pcv-vxh7-3wg6/GHSA-5pcv-vxh7-3wg6.json b/advisories/unreviewed/2022/05/GHSA-5pcv-vxh7-3wg6/GHSA-5pcv-vxh7-3wg6.json index cd1d33f0ccf..f12aeff19a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pcv-vxh7-3wg6/GHSA-5pcv-vxh7-3wg6.json +++ b/advisories/unreviewed/2022/05/GHSA-5pcv-vxh7-3wg6/GHSA-5pcv-vxh7-3wg6.json @@ -7,12 +7,8 @@ "CVE-2005-4583" ], "details": "Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows \"remote code execution in the Web browser\" via unspecified attack vectors, probably related to cross-site scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5phc-r9q3-639w/GHSA-5phc-r9q3-639w.json b/advisories/unreviewed/2022/05/GHSA-5phc-r9q3-639w/GHSA-5phc-r9q3-639w.json index b1101a44bea..cfcd00eae5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5phc-r9q3-639w/GHSA-5phc-r9q3-639w.json +++ b/advisories/unreviewed/2022/05/GHSA-5phc-r9q3-639w/GHSA-5phc-r9q3-639w.json @@ -7,12 +7,8 @@ "CVE-2021-32299" ], "details": "An issue was discovered in pbrt through 20200627. A stack-buffer-overflow exists in the function pbrt::ParamSet::ParamSet() located in paramset.h. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q7c-4cgc-gvcr/GHSA-5q7c-4cgc-gvcr.json b/advisories/unreviewed/2022/05/GHSA-5q7c-4cgc-gvcr/GHSA-5q7c-4cgc-gvcr.json index f2000517cc5..628faa221a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q7c-4cgc-gvcr/GHSA-5q7c-4cgc-gvcr.json +++ b/advisories/unreviewed/2022/05/GHSA-5q7c-4cgc-gvcr/GHSA-5q7c-4cgc-gvcr.json @@ -7,12 +7,8 @@ "CVE-2005-4688" ], "details": "PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qh7-579r-4mp6/GHSA-5qh7-579r-4mp6.json b/advisories/unreviewed/2022/05/GHSA-5qh7-579r-4mp6/GHSA-5qh7-579r-4mp6.json index 75d008a7978..b2f73d1bbf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qh7-579r-4mp6/GHSA-5qh7-579r-4mp6.json +++ b/advisories/unreviewed/2022/05/GHSA-5qh7-579r-4mp6/GHSA-5qh7-579r-4mp6.json @@ -7,12 +7,8 @@ "CVE-2021-40674" ], "details": "An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r8p-h2wh-wvq8/GHSA-5r8p-h2wh-wvq8.json b/advisories/unreviewed/2022/05/GHSA-5r8p-h2wh-wvq8/GHSA-5r8p-h2wh-wvq8.json index be03aca34b7..3b23e77ac7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r8p-h2wh-wvq8/GHSA-5r8p-h2wh-wvq8.json +++ b/advisories/unreviewed/2022/05/GHSA-5r8p-h2wh-wvq8/GHSA-5r8p-h2wh-wvq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v3j-6p4g-6p7m/GHSA-5v3j-6p4g-6p7m.json b/advisories/unreviewed/2022/05/GHSA-5v3j-6p4g-6p7m/GHSA-5v3j-6p4g-6p7m.json index 243e68070ab..cf46b1ef54a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v3j-6p4g-6p7m/GHSA-5v3j-6p4g-6p7m.json +++ b/advisories/unreviewed/2022/05/GHSA-5v3j-6p4g-6p7m/GHSA-5v3j-6p4g-6p7m.json @@ -7,12 +7,8 @@ "CVE-2020-19281" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vc2-jrh2-gp8m/GHSA-5vc2-jrh2-gp8m.json b/advisories/unreviewed/2022/05/GHSA-5vc2-jrh2-gp8m/GHSA-5vc2-jrh2-gp8m.json index 81b4dc7f8c5..6bb9bc1582a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vc2-jrh2-gp8m/GHSA-5vc2-jrh2-gp8m.json +++ b/advisories/unreviewed/2022/05/GHSA-5vc2-jrh2-gp8m/GHSA-5vc2-jrh2-gp8m.json @@ -7,12 +7,8 @@ "CVE-2021-27046" ], "details": "A Memory Corruption vulnerability for PDF files in Autodesk Navisworks 2019, 2020, 2021, 2022 may lead to code execution through maliciously crafted DLL files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w93-h7pq-72x6/GHSA-5w93-h7pq-72x6.json b/advisories/unreviewed/2022/05/GHSA-5w93-h7pq-72x6/GHSA-5w93-h7pq-72x6.json index bd865a67e00..5c0bad50f19 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w93-h7pq-72x6/GHSA-5w93-h7pq-72x6.json +++ b/advisories/unreviewed/2022/05/GHSA-5w93-h7pq-72x6/GHSA-5w93-h7pq-72x6.json @@ -7,12 +7,8 @@ "CVE-2005-4555" ], "details": "Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ENTER_ARTICLE_TITLE, (2) SPECIFY_ZONE, (3) ENTER_ARTICLE_HEADER, and (4) ENTER_ARTICLE_BODY indices in the language array parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wfx-xq56-qfv3/GHSA-5wfx-xq56-qfv3.json b/advisories/unreviewed/2022/05/GHSA-5wfx-xq56-qfv3/GHSA-5wfx-xq56-qfv3.json index 86bc0d410ec..ea1d4598f25 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wfx-xq56-qfv3/GHSA-5wfx-xq56-qfv3.json +++ b/advisories/unreviewed/2022/05/GHSA-5wfx-xq56-qfv3/GHSA-5wfx-xq56-qfv3.json @@ -7,12 +7,8 @@ "CVE-2005-4697" ], "details": "The Microsoft Wireless Zero Configuration system (WZCS) allows local users to access WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key via certain calls to the WZCQueryInterface API function in wzcsapi.dll.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wjp-4jpf-wmfh/GHSA-5wjp-4jpf-wmfh.json b/advisories/unreviewed/2022/05/GHSA-5wjp-4jpf-wmfh/GHSA-5wjp-4jpf-wmfh.json index 26519aa54d7..17a1fc96ef5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wjp-4jpf-wmfh/GHSA-5wjp-4jpf-wmfh.json +++ b/advisories/unreviewed/2022/05/GHSA-5wjp-4jpf-wmfh/GHSA-5wjp-4jpf-wmfh.json @@ -7,12 +7,8 @@ "CVE-2021-22148" ], "details": "Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xf5-q9cr-gp59/GHSA-5xf5-q9cr-gp59.json b/advisories/unreviewed/2022/05/GHSA-5xf5-q9cr-gp59/GHSA-5xf5-q9cr-gp59.json index 14c055fa4bd..a5e99e68292 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xf5-q9cr-gp59/GHSA-5xf5-q9cr-gp59.json +++ b/advisories/unreviewed/2022/05/GHSA-5xf5-q9cr-gp59/GHSA-5xf5-q9cr-gp59.json @@ -7,12 +7,8 @@ "CVE-2021-32287" ], "details": "An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xqj-h7c6-6746/GHSA-5xqj-h7c6-6746.json b/advisories/unreviewed/2022/05/GHSA-5xqj-h7c6-6746/GHSA-5xqj-h7c6-6746.json index 91a2abd3d82..af2539726a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xqj-h7c6-6746/GHSA-5xqj-h7c6-6746.json +++ b/advisories/unreviewed/2022/05/GHSA-5xqj-h7c6-6746/GHSA-5xqj-h7c6-6746.json @@ -7,12 +7,8 @@ "CVE-2005-4420" ], "details": "Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xr9-4m9g-r278/GHSA-5xr9-4m9g-r278.json b/advisories/unreviewed/2022/05/GHSA-5xr9-4m9g-r278/GHSA-5xr9-4m9g-r278.json index b822e9fbc96..4cc988af556 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xr9-4m9g-r278/GHSA-5xr9-4m9g-r278.json +++ b/advisories/unreviewed/2022/05/GHSA-5xr9-4m9g-r278/GHSA-5xr9-4m9g-r278.json @@ -7,12 +7,8 @@ "CVE-2020-19148" ], "details": "Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62mh-7jc4-wf35/GHSA-62mh-7jc4-wf35.json b/advisories/unreviewed/2022/05/GHSA-62mh-7jc4-wf35/GHSA-62mh-7jc4-wf35.json index b823075420c..b331e41b63f 100644 --- a/advisories/unreviewed/2022/05/GHSA-62mh-7jc4-wf35/GHSA-62mh-7jc4-wf35.json +++ b/advisories/unreviewed/2022/05/GHSA-62mh-7jc4-wf35/GHSA-62mh-7jc4-wf35.json @@ -7,12 +7,8 @@ "CVE-2021-37176" ], "details": "A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). The femap.exe application lacks proper validation of user-supplied data when parsing modfem files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14260)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62mx-7v7h-w2g7/GHSA-62mx-7v7h-w2g7.json b/advisories/unreviewed/2022/05/GHSA-62mx-7v7h-w2g7/GHSA-62mx-7v7h-w2g7.json index fee6504ea41..f8793ee1cbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-62mx-7v7h-w2g7/GHSA-62mx-7v7h-w2g7.json +++ b/advisories/unreviewed/2022/05/GHSA-62mx-7v7h-w2g7/GHSA-62mx-7v7h-w2g7.json @@ -7,12 +7,8 @@ "CVE-2021-41525" ], "details": "An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-639r-p248-76hj/GHSA-639r-p248-76hj.json b/advisories/unreviewed/2022/05/GHSA-639r-p248-76hj/GHSA-639r-p248-76hj.json index e5a261a70f1..90de56dcd10 100644 --- a/advisories/unreviewed/2022/05/GHSA-639r-p248-76hj/GHSA-639r-p248-76hj.json +++ b/advisories/unreviewed/2022/05/GHSA-639r-p248-76hj/GHSA-639r-p248-76hj.json @@ -7,12 +7,8 @@ "CVE-2005-4573" ], "details": "PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63qq-8356-xpg6/GHSA-63qq-8356-xpg6.json b/advisories/unreviewed/2022/05/GHSA-63qq-8356-xpg6/GHSA-63qq-8356-xpg6.json index c56d0fbd58b..72a99fe65a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-63qq-8356-xpg6/GHSA-63qq-8356-xpg6.json +++ b/advisories/unreviewed/2022/05/GHSA-63qq-8356-xpg6/GHSA-63qq-8356-xpg6.json @@ -7,12 +7,8 @@ "CVE-2005-4870" ], "details": "Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6465-hj2g-hj5x/GHSA-6465-hj2g-hj5x.json b/advisories/unreviewed/2022/05/GHSA-6465-hj2g-hj5x/GHSA-6465-hj2g-hj5x.json index 071749a2885..b3237377216 100644 --- a/advisories/unreviewed/2022/05/GHSA-6465-hj2g-hj5x/GHSA-6465-hj2g-hj5x.json +++ b/advisories/unreviewed/2022/05/GHSA-6465-hj2g-hj5x/GHSA-6465-hj2g-hj5x.json @@ -7,12 +7,8 @@ "CVE-2006-0045" ], "details": "crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64pc-839w-44v4/GHSA-64pc-839w-44v4.json b/advisories/unreviewed/2022/05/GHSA-64pc-839w-44v4/GHSA-64pc-839w-44v4.json index 077fba32f64..07dfc1b7fea 100644 --- a/advisories/unreviewed/2022/05/GHSA-64pc-839w-44v4/GHSA-64pc-839w-44v4.json +++ b/advisories/unreviewed/2022/05/GHSA-64pc-839w-44v4/GHSA-64pc-839w-44v4.json @@ -7,12 +7,8 @@ "CVE-2005-4887" ], "details": "NWFTPD.nlm before 5.06.05 in the FTP server in Novell NetWare 6.5 SP5 allows attackers to have an unspecified impact via vectors related to passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65mh-gj85-793w/GHSA-65mh-gj85-793w.json b/advisories/unreviewed/2022/05/GHSA-65mh-gj85-793w/GHSA-65mh-gj85-793w.json index 3b09a5ace1d..c8ac14d170a 100644 --- a/advisories/unreviewed/2022/05/GHSA-65mh-gj85-793w/GHSA-65mh-gj85-793w.json +++ b/advisories/unreviewed/2022/05/GHSA-65mh-gj85-793w/GHSA-65mh-gj85-793w.json @@ -7,12 +7,8 @@ "CVE-2005-4712" ], "details": "CRLF injection vulnerability in process_signup.php in PHP Handicapper allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the login parameter. NOTE: the vendor has disputed CVE-2005-3497, and it is possible that the dispute was intended to include this issue as well.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65wj-75vm-6g3g/GHSA-65wj-75vm-6g3g.json b/advisories/unreviewed/2022/05/GHSA-65wj-75vm-6g3g/GHSA-65wj-75vm-6g3g.json index 6baa319960e..551746c6239 100644 --- a/advisories/unreviewed/2022/05/GHSA-65wj-75vm-6g3g/GHSA-65wj-75vm-6g3g.json +++ b/advisories/unreviewed/2022/05/GHSA-65wj-75vm-6g3g/GHSA-65wj-75vm-6g3g.json @@ -7,12 +7,8 @@ "CVE-2005-4755" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key passphrase in cleartext (2) on a terminal or (3) in a log file, which might allow local users to obtain cryptographic keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-664f-hg94-2f9v/GHSA-664f-hg94-2f9v.json b/advisories/unreviewed/2022/05/GHSA-664f-hg94-2f9v/GHSA-664f-hg94-2f9v.json index ad04321653d..59262ca3795 100644 --- a/advisories/unreviewed/2022/05/GHSA-664f-hg94-2f9v/GHSA-664f-hg94-2f9v.json +++ b/advisories/unreviewed/2022/05/GHSA-664f-hg94-2f9v/GHSA-664f-hg94-2f9v.json @@ -7,12 +7,8 @@ "CVE-2005-4707" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-66cc-pqrw-3whx/GHSA-66cc-pqrw-3whx.json b/advisories/unreviewed/2022/05/GHSA-66cc-pqrw-3whx/GHSA-66cc-pqrw-3whx.json index 76d0a25fb54..06e7daa5822 100644 --- a/advisories/unreviewed/2022/05/GHSA-66cc-pqrw-3whx/GHSA-66cc-pqrw-3whx.json +++ b/advisories/unreviewed/2022/05/GHSA-66cc-pqrw-3whx/GHSA-66cc-pqrw-3whx.json @@ -7,12 +7,8 @@ "CVE-2005-4795" ], "details": "Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-675m-x238-3mpf/GHSA-675m-x238-3mpf.json b/advisories/unreviewed/2022/05/GHSA-675m-x238-3mpf/GHSA-675m-x238-3mpf.json index 9e3cf584960..1802e989bbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-675m-x238-3mpf/GHSA-675m-x238-3mpf.json +++ b/advisories/unreviewed/2022/05/GHSA-675m-x238-3mpf/GHSA-675m-x238-3mpf.json @@ -7,12 +7,8 @@ "CVE-2005-4432" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the err parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6767-7pjf-mxgf/GHSA-6767-7pjf-mxgf.json b/advisories/unreviewed/2022/05/GHSA-6767-7pjf-mxgf/GHSA-6767-7pjf-mxgf.json index 4ae1b3d5cbc..e2f791fb659 100644 --- a/advisories/unreviewed/2022/05/GHSA-6767-7pjf-mxgf/GHSA-6767-7pjf-mxgf.json +++ b/advisories/unreviewed/2022/05/GHSA-6767-7pjf-mxgf/GHSA-6767-7pjf-mxgf.json @@ -7,12 +7,8 @@ "CVE-2021-1622" ], "details": "A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit this vulnerability by sending COPS packets with high burst rates to an affected device. A successful exploit could allow the attacker to cause the CPU to consume excessive resources, which prevents other control plane processes from obtaining resources and results in a DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67vg-8r27-8fjh/GHSA-67vg-8r27-8fjh.json b/advisories/unreviewed/2022/05/GHSA-67vg-8r27-8fjh/GHSA-67vg-8r27-8fjh.json index 8a154cfa129..60ec2d27c86 100644 --- a/advisories/unreviewed/2022/05/GHSA-67vg-8r27-8fjh/GHSA-67vg-8r27-8fjh.json +++ b/advisories/unreviewed/2022/05/GHSA-67vg-8r27-8fjh/GHSA-67vg-8r27-8fjh.json @@ -7,12 +7,8 @@ "CVE-2021-39124" ], "details": "The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67xm-gwvc-jw56/GHSA-67xm-gwvc-jw56.json b/advisories/unreviewed/2022/05/GHSA-67xm-gwvc-jw56/GHSA-67xm-gwvc-jw56.json index c25d4f378d0..4ae21415b77 100644 --- a/advisories/unreviewed/2022/05/GHSA-67xm-gwvc-jw56/GHSA-67xm-gwvc-jw56.json +++ b/advisories/unreviewed/2022/05/GHSA-67xm-gwvc-jw56/GHSA-67xm-gwvc-jw56.json @@ -7,12 +7,8 @@ "CVE-2005-4752" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, might allow local users to gain privileges by using the run-as deployment descriptor element to change the privileges of a web application or EJB from the Deployer security role to the Admin security role.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-68gc-6j2c-jr3m/GHSA-68gc-6j2c-jr3m.json b/advisories/unreviewed/2022/05/GHSA-68gc-6j2c-jr3m/GHSA-68gc-6j2c-jr3m.json index 8e372b7e351..82881d27cd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-68gc-6j2c-jr3m/GHSA-68gc-6j2c-jr3m.json +++ b/advisories/unreviewed/2022/05/GHSA-68gc-6j2c-jr3m/GHSA-68gc-6j2c-jr3m.json @@ -7,12 +7,8 @@ "CVE-2021-24727" ], "details": "The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68r9-qhv3-7fgg/GHSA-68r9-qhv3-7fgg.json b/advisories/unreviewed/2022/05/GHSA-68r9-qhv3-7fgg/GHSA-68r9-qhv3-7fgg.json index 13c91f3863a..c6b939e1b4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-68r9-qhv3-7fgg/GHSA-68r9-qhv3-7fgg.json +++ b/advisories/unreviewed/2022/05/GHSA-68r9-qhv3-7fgg/GHSA-68r9-qhv3-7fgg.json @@ -7,12 +7,8 @@ "CVE-2021-24657" ], "details": "The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6936-h7xw-gfq3/GHSA-6936-h7xw-gfq3.json b/advisories/unreviewed/2022/05/GHSA-6936-h7xw-gfq3/GHSA-6936-h7xw-gfq3.json index e011428f5c7..23505546725 100644 --- a/advisories/unreviewed/2022/05/GHSA-6936-h7xw-gfq3/GHSA-6936-h7xw-gfq3.json +++ b/advisories/unreviewed/2022/05/GHSA-6936-h7xw-gfq3/GHSA-6936-h7xw-gfq3.json @@ -7,12 +7,8 @@ "CVE-2021-33719" ], "details": "A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP200 (All versions), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Specially crafted packets sent to port 4443/tcp could cause a Denial-of-Service condition or potential remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69h3-7gjf-m5gx/GHSA-69h3-7gjf-m5gx.json b/advisories/unreviewed/2022/05/GHSA-69h3-7gjf-m5gx/GHSA-69h3-7gjf-m5gx.json index 985ef349af8..1b2ec8c4564 100644 --- a/advisories/unreviewed/2022/05/GHSA-69h3-7gjf-m5gx/GHSA-69h3-7gjf-m5gx.json +++ b/advisories/unreviewed/2022/05/GHSA-69h3-7gjf-m5gx/GHSA-69h3-7gjf-m5gx.json @@ -7,12 +7,8 @@ "CVE-2019-10941" ], "details": "A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69q2-gvv3-f7cr/GHSA-69q2-gvv3-f7cr.json b/advisories/unreviewed/2022/05/GHSA-69q2-gvv3-f7cr/GHSA-69q2-gvv3-f7cr.json index e624c7c5691..85fc0995c5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-69q2-gvv3-f7cr/GHSA-69q2-gvv3-f7cr.json +++ b/advisories/unreviewed/2022/05/GHSA-69q2-gvv3-f7cr/GHSA-69q2-gvv3-f7cr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c23-3vmv-9r2c/GHSA-6c23-3vmv-9r2c.json b/advisories/unreviewed/2022/05/GHSA-6c23-3vmv-9r2c/GHSA-6c23-3vmv-9r2c.json index 918f2063734..742b82efbd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c23-3vmv-9r2c/GHSA-6c23-3vmv-9r2c.json +++ b/advisories/unreviewed/2022/05/GHSA-6c23-3vmv-9r2c/GHSA-6c23-3vmv-9r2c.json @@ -7,12 +7,8 @@ "CVE-2005-4728" ], "details": "Untrusted search path vulnerability (RPATH) in amaya 9.2.1 on Debian GNU/Linux allows local users to gain privileges via a malicious Mesa library in the /home/anand directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cg9-w42p-2vh6/GHSA-6cg9-w42p-2vh6.json b/advisories/unreviewed/2022/05/GHSA-6cg9-w42p-2vh6/GHSA-6cg9-w42p-2vh6.json index 35e1458ec8c..42c36b3cceb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cg9-w42p-2vh6/GHSA-6cg9-w42p-2vh6.json +++ b/advisories/unreviewed/2022/05/GHSA-6cg9-w42p-2vh6/GHSA-6cg9-w42p-2vh6.json @@ -7,12 +7,8 @@ "CVE-2005-4679" ], "details": "Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cpp-45v5-cpgv/GHSA-6cpp-45v5-cpgv.json b/advisories/unreviewed/2022/05/GHSA-6cpp-45v5-cpgv/GHSA-6cpp-45v5-cpgv.json index 07b5dff9c73..c00fb30e853 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cpp-45v5-cpgv/GHSA-6cpp-45v5-cpgv.json +++ b/advisories/unreviewed/2022/05/GHSA-6cpp-45v5-cpgv/GHSA-6cpp-45v5-cpgv.json @@ -7,12 +7,8 @@ "CVE-2021-34770" ], "details": "A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that occurs during the validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the affected device to crash and reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cpv-gpjr-7h64/GHSA-6cpv-gpjr-7h64.json b/advisories/unreviewed/2022/05/GHSA-6cpv-gpjr-7h64/GHSA-6cpv-gpjr-7h64.json index 43978a630e5..a989645f30e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cpv-gpjr-7h64/GHSA-6cpv-gpjr-7h64.json +++ b/advisories/unreviewed/2022/05/GHSA-6cpv-gpjr-7h64/GHSA-6cpv-gpjr-7h64.json @@ -7,12 +7,8 @@ "CVE-2020-14130" ], "details": "Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fqw-r97c-866j/GHSA-6fqw-r97c-866j.json b/advisories/unreviewed/2022/05/GHSA-6fqw-r97c-866j/GHSA-6fqw-r97c-866j.json index a91fd7e72a6..c3b33e48815 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fqw-r97c-866j/GHSA-6fqw-r97c-866j.json +++ b/advisories/unreviewed/2022/05/GHSA-6fqw-r97c-866j/GHSA-6fqw-r97c-866j.json @@ -7,12 +7,8 @@ "CVE-2021-32138" ], "details": "The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gc7-9r9m-q3wg/GHSA-6gc7-9r9m-q3wg.json b/advisories/unreviewed/2022/05/GHSA-6gc7-9r9m-q3wg/GHSA-6gc7-9r9m-q3wg.json index 1b6cab7cab4..54b6dc7e4d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gc7-9r9m-q3wg/GHSA-6gc7-9r9m-q3wg.json +++ b/advisories/unreviewed/2022/05/GHSA-6gc7-9r9m-q3wg/GHSA-6gc7-9r9m-q3wg.json @@ -7,12 +7,8 @@ "CVE-2020-19280" ], "details": "Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6h2j-xchg-wcx8/GHSA-6h2j-xchg-wcx8.json b/advisories/unreviewed/2022/05/GHSA-6h2j-xchg-wcx8/GHSA-6h2j-xchg-wcx8.json index 5a70069e020..fae0cce1bcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h2j-xchg-wcx8/GHSA-6h2j-xchg-wcx8.json +++ b/advisories/unreviewed/2022/05/GHSA-6h2j-xchg-wcx8/GHSA-6h2j-xchg-wcx8.json @@ -7,12 +7,8 @@ "CVE-2006-0005" ], "details": "Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hcc-3gxp-hwgr/GHSA-6hcc-3gxp-hwgr.json b/advisories/unreviewed/2022/05/GHSA-6hcc-3gxp-hwgr/GHSA-6hcc-3gxp-hwgr.json index d97155deb66..bd2f357cecb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hcc-3gxp-hwgr/GHSA-6hcc-3gxp-hwgr.json +++ b/advisories/unreviewed/2022/05/GHSA-6hcc-3gxp-hwgr/GHSA-6hcc-3gxp-hwgr.json @@ -7,12 +7,8 @@ "CVE-2005-4511" ], "details": "Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j5m-hrmm-wf49/GHSA-6j5m-hrmm-wf49.json b/advisories/unreviewed/2022/05/GHSA-6j5m-hrmm-wf49/GHSA-6j5m-hrmm-wf49.json index 9337c8b3cc0..7830c918f23 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j5m-hrmm-wf49/GHSA-6j5m-hrmm-wf49.json +++ b/advisories/unreviewed/2022/05/GHSA-6j5m-hrmm-wf49/GHSA-6j5m-hrmm-wf49.json @@ -7,12 +7,8 @@ "CVE-2005-4578" ], "details": "Multiple SQL injection vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6jvg-fx73-499w/GHSA-6jvg-fx73-499w.json b/advisories/unreviewed/2022/05/GHSA-6jvg-fx73-499w/GHSA-6jvg-fx73-499w.json index 4d7d7fe4b64..7a6bb5d184b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jvg-fx73-499w/GHSA-6jvg-fx73-499w.json +++ b/advisories/unreviewed/2022/05/GHSA-6jvg-fx73-499w/GHSA-6jvg-fx73-499w.json @@ -7,12 +7,8 @@ "CVE-2021-39593" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo() located in swftext.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m34-8ff3-6cj3/GHSA-6m34-8ff3-6cj3.json b/advisories/unreviewed/2022/05/GHSA-6m34-8ff3-6cj3/GHSA-6m34-8ff3-6cj3.json index c069089ec40..91bdaa44407 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m34-8ff3-6cj3/GHSA-6m34-8ff3-6cj3.json +++ b/advisories/unreviewed/2022/05/GHSA-6m34-8ff3-6cj3/GHSA-6m34-8ff3-6cj3.json @@ -7,12 +7,8 @@ "CVE-2005-4454" ], "details": "Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a \"\\\" (backslash) within a \"javascript\" scheme in a style property (such as \"javas\\cript\"), which bypasses the \"javascript\" check before the \"\\\" is stripped and then rendered in web browsers that allow scripting in style sheets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p4q-73fv-qgx2/GHSA-6p4q-73fv-qgx2.json b/advisories/unreviewed/2022/05/GHSA-6p4q-73fv-qgx2/GHSA-6p4q-73fv-qgx2.json index c96c41ede5e..74bcfd3125b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p4q-73fv-qgx2/GHSA-6p4q-73fv-qgx2.json +++ b/advisories/unreviewed/2022/05/GHSA-6p4q-73fv-qgx2/GHSA-6p4q-73fv-qgx2.json @@ -7,12 +7,8 @@ "CVE-2021-32268" ], "details": "Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac through 20200801, allows attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6ph7-3cx8-q7xh/GHSA-6ph7-3cx8-q7xh.json b/advisories/unreviewed/2022/05/GHSA-6ph7-3cx8-q7xh/GHSA-6ph7-3cx8-q7xh.json index 95473d9bb61..fe46dc36053 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ph7-3cx8-q7xh/GHSA-6ph7-3cx8-q7xh.json +++ b/advisories/unreviewed/2022/05/GHSA-6ph7-3cx8-q7xh/GHSA-6ph7-3cx8-q7xh.json @@ -7,12 +7,8 @@ "CVE-2021-27340" ], "details": "OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the \"opt\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6prr-6x2x-fx8r/GHSA-6prr-6x2x-fx8r.json b/advisories/unreviewed/2022/05/GHSA-6prr-6x2x-fx8r/GHSA-6prr-6x2x-fx8r.json index 175d1c57dee..fab04b0c25d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6prr-6x2x-fx8r/GHSA-6prr-6x2x-fx8r.json +++ b/advisories/unreviewed/2022/05/GHSA-6prr-6x2x-fx8r/GHSA-6prr-6x2x-fx8r.json @@ -7,12 +7,8 @@ "CVE-2005-4820" ], "details": "SMC Wireless Router model SMC7904WBRA allows remote attackers to cause a denial of service (reboot) by flooding the router with traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q26-2pcr-954w/GHSA-6q26-2pcr-954w.json b/advisories/unreviewed/2022/05/GHSA-6q26-2pcr-954w/GHSA-6q26-2pcr-954w.json index ed12e80153c..594910378a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q26-2pcr-954w/GHSA-6q26-2pcr-954w.json +++ b/advisories/unreviewed/2022/05/GHSA-6q26-2pcr-954w/GHSA-6q26-2pcr-954w.json @@ -7,12 +7,8 @@ "CVE-2005-4528" ], "details": "SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remote attackers to execute arbitrary SQL commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qg5-vf7x-4fm3/GHSA-6qg5-vf7x-4fm3.json b/advisories/unreviewed/2022/05/GHSA-6qg5-vf7x-4fm3/GHSA-6qg5-vf7x-4fm3.json index f756b30a287..378618d6f3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qg5-vf7x-4fm3/GHSA-6qg5-vf7x-4fm3.json +++ b/advisories/unreviewed/2022/05/GHSA-6qg5-vf7x-4fm3/GHSA-6qg5-vf7x-4fm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qmj-48p6-crf2/GHSA-6qmj-48p6-crf2.json b/advisories/unreviewed/2022/05/GHSA-6qmj-48p6-crf2/GHSA-6qmj-48p6-crf2.json index e51e398106d..03380107abe 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qmj-48p6-crf2/GHSA-6qmj-48p6-crf2.json +++ b/advisories/unreviewed/2022/05/GHSA-6qmj-48p6-crf2/GHSA-6qmj-48p6-crf2.json @@ -7,12 +7,8 @@ "CVE-2021-29800" ], "details": "IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qqv-794g-frqv/GHSA-6qqv-794g-frqv.json b/advisories/unreviewed/2022/05/GHSA-6qqv-794g-frqv/GHSA-6qqv-794g-frqv.json index 0fd72706c40..ebe668fe5a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qqv-794g-frqv/GHSA-6qqv-794g-frqv.json +++ b/advisories/unreviewed/2022/05/GHSA-6qqv-794g-frqv/GHSA-6qqv-794g-frqv.json @@ -7,12 +7,8 @@ "CVE-2005-4464" ], "details": "Ingate Firewall before 4.3.4 and SIParator before 4.3.4 allows remote attackers to cause a denial of service (kernel deadlock) by sending a SYN packet for a TCP stream, which requires an RST packet in response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v6g-fc5r-ggpx/GHSA-6v6g-fc5r-ggpx.json b/advisories/unreviewed/2022/05/GHSA-6v6g-fc5r-ggpx/GHSA-6v6g-fc5r-ggpx.json index af1355eb2a7..5e23cc4c893 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v6g-fc5r-ggpx/GHSA-6v6g-fc5r-ggpx.json +++ b/advisories/unreviewed/2022/05/GHSA-6v6g-fc5r-ggpx/GHSA-6v6g-fc5r-ggpx.json @@ -7,12 +7,8 @@ "CVE-2005-4705" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, which allows remote attackers to sniff the connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v6w-2hhj-2cm4/GHSA-6v6w-2hhj-2cm4.json b/advisories/unreviewed/2022/05/GHSA-6v6w-2hhj-2cm4/GHSA-6v6w-2hhj-2cm4.json index 0a448d0fc77..562fd663e30 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v6w-2hhj-2cm4/GHSA-6v6w-2hhj-2cm4.json +++ b/advisories/unreviewed/2022/05/GHSA-6v6w-2hhj-2cm4/GHSA-6v6w-2hhj-2cm4.json @@ -7,12 +7,8 @@ "CVE-2005-4646" ], "details": "Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vfc-66x6-g85h/GHSA-6vfc-66x6-g85h.json b/advisories/unreviewed/2022/05/GHSA-6vfc-66x6-g85h/GHSA-6vfc-66x6-g85h.json index e4cd152940e..e7e7ff076a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vfc-66x6-g85h/GHSA-6vfc-66x6-g85h.json +++ b/advisories/unreviewed/2022/05/GHSA-6vfc-66x6-g85h/GHSA-6vfc-66x6-g85h.json @@ -7,12 +7,8 @@ "CVE-2005-4711" ], "details": "SQL injection vulnerability in Neocrome Land Down Under (LDU) 801 allows remote attackers to execute arbitrary SQL commands via an HTTP Referer header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vgx-633w-89g7/GHSA-6vgx-633w-89g7.json b/advisories/unreviewed/2022/05/GHSA-6vgx-633w-89g7/GHSA-6vgx-633w-89g7.json index a694c12829d..41b9514ea77 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vgx-633w-89g7/GHSA-6vgx-633w-89g7.json +++ b/advisories/unreviewed/2022/05/GHSA-6vgx-633w-89g7/GHSA-6vgx-633w-89g7.json @@ -7,12 +7,8 @@ "CVE-2005-4475" ], "details": "Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vr7-vxmx-w9qg/GHSA-6vr7-vxmx-w9qg.json b/advisories/unreviewed/2022/05/GHSA-6vr7-vxmx-w9qg/GHSA-6vr7-vxmx-w9qg.json index 846a87b8fb5..99b57eb62db 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vr7-vxmx-w9qg/GHSA-6vr7-vxmx-w9qg.json +++ b/advisories/unreviewed/2022/05/GHSA-6vr7-vxmx-w9qg/GHSA-6vr7-vxmx-w9qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vr9-mwp7-5pjm/GHSA-6vr9-mwp7-5pjm.json b/advisories/unreviewed/2022/05/GHSA-6vr9-mwp7-5pjm/GHSA-6vr9-mwp7-5pjm.json index e35b163eab0..10eceb77aec 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vr9-mwp7-5pjm/GHSA-6vr9-mwp7-5pjm.json +++ b/advisories/unreviewed/2022/05/GHSA-6vr9-mwp7-5pjm/GHSA-6vr9-mwp7-5pjm.json @@ -7,12 +7,8 @@ "CVE-2005-4645" ], "details": "SQL injection vulnerability in index.php in 3CFR allows remote attackers to execute arbitrary SQL commands via the LangueID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vxp-v535-v5r9/GHSA-6vxp-v535-v5r9.json b/advisories/unreviewed/2022/05/GHSA-6vxp-v535-v5r9/GHSA-6vxp-v535-v5r9.json index 7535cc014df..7b8925ca058 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vxp-v535-v5r9/GHSA-6vxp-v535-v5r9.json +++ b/advisories/unreviewed/2022/05/GHSA-6vxp-v535-v5r9/GHSA-6vxp-v535-v5r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w58-36f7-jcwp/GHSA-6w58-36f7-jcwp.json b/advisories/unreviewed/2022/05/GHSA-6w58-36f7-jcwp/GHSA-6w58-36f7-jcwp.json index d8e35e84fbd..fce31e15920 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w58-36f7-jcwp/GHSA-6w58-36f7-jcwp.json +++ b/advisories/unreviewed/2022/05/GHSA-6w58-36f7-jcwp/GHSA-6w58-36f7-jcwp.json @@ -7,12 +7,8 @@ "CVE-2005-4468" ], "details": "PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wwm-42xv-cjjc/GHSA-6wwm-42xv-cjjc.json b/advisories/unreviewed/2022/05/GHSA-6wwm-42xv-cjjc/GHSA-6wwm-42xv-cjjc.json index adf59b24715..c4eb6d6f769 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wwm-42xv-cjjc/GHSA-6wwm-42xv-cjjc.json +++ b/advisories/unreviewed/2022/05/GHSA-6wwm-42xv-cjjc/GHSA-6wwm-42xv-cjjc.json @@ -7,12 +7,8 @@ "CVE-2005-4403" ], "details": "SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x52-4rr6-8fw7/GHSA-6x52-4rr6-8fw7.json b/advisories/unreviewed/2022/05/GHSA-6x52-4rr6-8fw7/GHSA-6x52-4rr6-8fw7.json index 910f41e2981..373d653a660 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x52-4rr6-8fw7/GHSA-6x52-4rr6-8fw7.json +++ b/advisories/unreviewed/2022/05/GHSA-6x52-4rr6-8fw7/GHSA-6x52-4rr6-8fw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x59-f29p-7vf6/GHSA-6x59-f29p-7vf6.json b/advisories/unreviewed/2022/05/GHSA-6x59-f29p-7vf6/GHSA-6x59-f29p-7vf6.json index 65bcf288d0f..fd02793bfcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x59-f29p-7vf6/GHSA-6x59-f29p-7vf6.json +++ b/advisories/unreviewed/2022/05/GHSA-6x59-f29p-7vf6/GHSA-6x59-f29p-7vf6.json @@ -7,12 +7,8 @@ "CVE-2005-4651" ], "details": "SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xph-53h7-ghh2/GHSA-6xph-53h7-ghh2.json b/advisories/unreviewed/2022/05/GHSA-6xph-53h7-ghh2/GHSA-6xph-53h7-ghh2.json index 436af0b7e77..b07ca581e7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xph-53h7-ghh2/GHSA-6xph-53h7-ghh2.json +++ b/advisories/unreviewed/2022/05/GHSA-6xph-53h7-ghh2/GHSA-6xph-53h7-ghh2.json @@ -7,12 +7,8 @@ "CVE-2021-29807" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204265.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-722p-jr5h-rjqr/GHSA-722p-jr5h-rjqr.json b/advisories/unreviewed/2022/05/GHSA-722p-jr5h-rjqr/GHSA-722p-jr5h-rjqr.json index d05111e1ba0..75cf336f162 100644 --- a/advisories/unreviewed/2022/05/GHSA-722p-jr5h-rjqr/GHSA-722p-jr5h-rjqr.json +++ b/advisories/unreviewed/2022/05/GHSA-722p-jr5h-rjqr/GHSA-722p-jr5h-rjqr.json @@ -7,12 +7,8 @@ "CVE-2005-4518" ], "details": "Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-727c-8vjf-pv2j/GHSA-727c-8vjf-pv2j.json b/advisories/unreviewed/2022/05/GHSA-727c-8vjf-pv2j/GHSA-727c-8vjf-pv2j.json index c4c039cb48d..722f5e7fe7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-727c-8vjf-pv2j/GHSA-727c-8vjf-pv2j.json +++ b/advisories/unreviewed/2022/05/GHSA-727c-8vjf-pv2j/GHSA-727c-8vjf-pv2j.json @@ -7,12 +7,8 @@ "CVE-2006-0053" ], "details": "Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-728f-qcc4-8q48/GHSA-728f-qcc4-8q48.json b/advisories/unreviewed/2022/05/GHSA-728f-qcc4-8q48/GHSA-728f-qcc4-8q48.json index e62ce4284a2..5e38351abc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-728f-qcc4-8q48/GHSA-728f-qcc4-8q48.json +++ b/advisories/unreviewed/2022/05/GHSA-728f-qcc4-8q48/GHSA-728f-qcc4-8q48.json @@ -7,12 +7,8 @@ "CVE-2021-24638" ], "details": "The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72fc-25pw-pqqj/GHSA-72fc-25pw-pqqj.json b/advisories/unreviewed/2022/05/GHSA-72fc-25pw-pqqj/GHSA-72fc-25pw-pqqj.json index 9daed05d34d..bae921d05fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-72fc-25pw-pqqj/GHSA-72fc-25pw-pqqj.json +++ b/advisories/unreviewed/2022/05/GHSA-72fc-25pw-pqqj/GHSA-72fc-25pw-pqqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72qv-xgrv-898v/GHSA-72qv-xgrv-898v.json b/advisories/unreviewed/2022/05/GHSA-72qv-xgrv-898v/GHSA-72qv-xgrv-898v.json index a852bff0768..1d47448c7ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-72qv-xgrv-898v/GHSA-72qv-xgrv-898v.json +++ b/advisories/unreviewed/2022/05/GHSA-72qv-xgrv-898v/GHSA-72qv-xgrv-898v.json @@ -7,12 +7,8 @@ "CVE-2005-4473" ], "details": "Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via \"a malformed URL.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73g5-48xw-f45p/GHSA-73g5-48xw-f45p.json b/advisories/unreviewed/2022/05/GHSA-73g5-48xw-f45p/GHSA-73g5-48xw-f45p.json index e464d42b72b..5b54b3f5796 100644 --- a/advisories/unreviewed/2022/05/GHSA-73g5-48xw-f45p/GHSA-73g5-48xw-f45p.json +++ b/advisories/unreviewed/2022/05/GHSA-73g5-48xw-f45p/GHSA-73g5-48xw-f45p.json @@ -7,12 +7,8 @@ "CVE-2005-4415" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73j6-q65m-r8w4/GHSA-73j6-q65m-r8w4.json b/advisories/unreviewed/2022/05/GHSA-73j6-q65m-r8w4/GHSA-73j6-q65m-r8w4.json index 61c9300f2a6..570f3db4f6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-73j6-q65m-r8w4/GHSA-73j6-q65m-r8w4.json +++ b/advisories/unreviewed/2022/05/GHSA-73j6-q65m-r8w4/GHSA-73j6-q65m-r8w4.json @@ -7,12 +7,8 @@ "CVE-2005-4825" ], "details": "Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP scripts, a related issue to CVE-2005-4332.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73p9-5hh7-3v53/GHSA-73p9-5hh7-3v53.json b/advisories/unreviewed/2022/05/GHSA-73p9-5hh7-3v53/GHSA-73p9-5hh7-3v53.json index f2619b14fe3..23899d152f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-73p9-5hh7-3v53/GHSA-73p9-5hh7-3v53.json +++ b/advisories/unreviewed/2022/05/GHSA-73p9-5hh7-3v53/GHSA-73p9-5hh7-3v53.json @@ -7,12 +7,8 @@ "CVE-2021-40881" ], "details": "An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-742w-p6j3-fcr9/GHSA-742w-p6j3-fcr9.json b/advisories/unreviewed/2022/05/GHSA-742w-p6j3-fcr9/GHSA-742w-p6j3-fcr9.json index 4d9d0465904..bc583bfcfd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-742w-p6j3-fcr9/GHSA-742w-p6j3-fcr9.json +++ b/advisories/unreviewed/2022/05/GHSA-742w-p6j3-fcr9/GHSA-742w-p6j3-fcr9.json @@ -7,12 +7,8 @@ "CVE-2005-4647" ], "details": "Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7443-9vrm-6986/GHSA-7443-9vrm-6986.json b/advisories/unreviewed/2022/05/GHSA-7443-9vrm-6986/GHSA-7443-9vrm-6986.json index fc8a747ff69..e74f788b96e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7443-9vrm-6986/GHSA-7443-9vrm-6986.json +++ b/advisories/unreviewed/2022/05/GHSA-7443-9vrm-6986/GHSA-7443-9vrm-6986.json @@ -7,12 +7,8 @@ "CVE-2005-4655" ], "details": "Cross-site scripting (XSS) vulnerability in submit.php in PHP-Fusion 6.0.204 allows remote attackers to inject arbitrary web script or HTML via nested tags in the news_body parameter, as demonstrated by elements such as \"ta\" and \"ript>\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7446-x75g-7gmf/GHSA-7446-x75g-7gmf.json b/advisories/unreviewed/2022/05/GHSA-7446-x75g-7gmf/GHSA-7446-x75g-7gmf.json index 7acbfb0acbd..1d4de1bee5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7446-x75g-7gmf/GHSA-7446-x75g-7gmf.json +++ b/advisories/unreviewed/2022/05/GHSA-7446-x75g-7gmf/GHSA-7446-x75g-7gmf.json @@ -7,12 +7,8 @@ "CVE-2020-27970" ], "details": "Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74jf-rm92-m939/GHSA-74jf-rm92-m939.json b/advisories/unreviewed/2022/05/GHSA-74jf-rm92-m939/GHSA-74jf-rm92-m939.json index faefce035b6..85e09e829d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-74jf-rm92-m939/GHSA-74jf-rm92-m939.json +++ b/advisories/unreviewed/2022/05/GHSA-74jf-rm92-m939/GHSA-74jf-rm92-m939.json @@ -7,12 +7,8 @@ "CVE-2006-0003" ], "details": "Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -136,9 +132,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74wg-mhc3-jxp5/GHSA-74wg-mhc3-jxp5.json b/advisories/unreviewed/2022/05/GHSA-74wg-mhc3-jxp5/GHSA-74wg-mhc3-jxp5.json index c94f9433672..068741a7a73 100644 --- a/advisories/unreviewed/2022/05/GHSA-74wg-mhc3-jxp5/GHSA-74wg-mhc3-jxp5.json +++ b/advisories/unreviewed/2022/05/GHSA-74wg-mhc3-jxp5/GHSA-74wg-mhc3-jxp5.json @@ -7,12 +7,8 @@ "CVE-2020-3960" ], "details": "VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75j2-g376-x3q4/GHSA-75j2-g376-x3q4.json b/advisories/unreviewed/2022/05/GHSA-75j2-g376-x3q4/GHSA-75j2-g376-x3q4.json index 7f74ea13bbc..b59ab3f8e09 100644 --- a/advisories/unreviewed/2022/05/GHSA-75j2-g376-x3q4/GHSA-75j2-g376-x3q4.json +++ b/advisories/unreviewed/2022/05/GHSA-75j2-g376-x3q4/GHSA-75j2-g376-x3q4.json @@ -7,12 +7,8 @@ "CVE-2006-0051" ], "details": "Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is \"fetching remote playlists\", which triggers the overflow in the http_peek function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75wx-7fqq-f6pf/GHSA-75wx-7fqq-f6pf.json b/advisories/unreviewed/2022/05/GHSA-75wx-7fqq-f6pf/GHSA-75wx-7fqq-f6pf.json index 34673802fde..7304d0ba87e 100644 --- a/advisories/unreviewed/2022/05/GHSA-75wx-7fqq-f6pf/GHSA-75wx-7fqq-f6pf.json +++ b/advisories/unreviewed/2022/05/GHSA-75wx-7fqq-f6pf/GHSA-75wx-7fqq-f6pf.json @@ -7,12 +7,8 @@ "CVE-2021-39518" ], "details": "An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7637-4x67-w26c/GHSA-7637-4x67-w26c.json b/advisories/unreviewed/2022/05/GHSA-7637-4x67-w26c/GHSA-7637-4x67-w26c.json index f6262f62e72..6d2003608d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7637-4x67-w26c/GHSA-7637-4x67-w26c.json +++ b/advisories/unreviewed/2022/05/GHSA-7637-4x67-w26c/GHSA-7637-4x67-w26c.json @@ -7,12 +7,8 @@ "CVE-2021-24397" ], "details": "The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76cj-38jr-6rg5/GHSA-76cj-38jr-6rg5.json b/advisories/unreviewed/2022/05/GHSA-76cj-38jr-6rg5/GHSA-76cj-38jr-6rg5.json index ba5539fe31d..18d204b9880 100644 --- a/advisories/unreviewed/2022/05/GHSA-76cj-38jr-6rg5/GHSA-76cj-38jr-6rg5.json +++ b/advisories/unreviewed/2022/05/GHSA-76cj-38jr-6rg5/GHSA-76cj-38jr-6rg5.json @@ -7,12 +7,8 @@ "CVE-2021-24530" ], "details": "The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76pj-fv2h-qvfg/GHSA-76pj-fv2h-qvfg.json b/advisories/unreviewed/2022/05/GHSA-76pj-fv2h-qvfg/GHSA-76pj-fv2h-qvfg.json index 30ebdecc045..b222917af82 100644 --- a/advisories/unreviewed/2022/05/GHSA-76pj-fv2h-qvfg/GHSA-76pj-fv2h-qvfg.json +++ b/advisories/unreviewed/2022/05/GHSA-76pj-fv2h-qvfg/GHSA-76pj-fv2h-qvfg.json @@ -7,12 +7,8 @@ "CVE-2021-33690" ], "details": "Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76q4-7268-9v4c/GHSA-76q4-7268-9v4c.json b/advisories/unreviewed/2022/05/GHSA-76q4-7268-9v4c/GHSA-76q4-7268-9v4c.json index 40fad9535e4..14394dde5b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-76q4-7268-9v4c/GHSA-76q4-7268-9v4c.json +++ b/advisories/unreviewed/2022/05/GHSA-76q4-7268-9v4c/GHSA-76q4-7268-9v4c.json @@ -7,12 +7,8 @@ "CVE-2021-39562" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream() located in Stream.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76ww-rw5h-92jq/GHSA-76ww-rw5h-92jq.json b/advisories/unreviewed/2022/05/GHSA-76ww-rw5h-92jq/GHSA-76ww-rw5h-92jq.json index bbe9ca71622..90049985f97 100644 --- a/advisories/unreviewed/2022/05/GHSA-76ww-rw5h-92jq/GHSA-76ww-rw5h-92jq.json +++ b/advisories/unreviewed/2022/05/GHSA-76ww-rw5h-92jq/GHSA-76ww-rw5h-92jq.json @@ -7,12 +7,8 @@ "CVE-2005-4684" ], "details": "Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7763-j2c2-xh5f/GHSA-7763-j2c2-xh5f.json b/advisories/unreviewed/2022/05/GHSA-7763-j2c2-xh5f/GHSA-7763-j2c2-xh5f.json index a2ad3c68135..deefc620ee5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7763-j2c2-xh5f/GHSA-7763-j2c2-xh5f.json +++ b/advisories/unreviewed/2022/05/GHSA-7763-j2c2-xh5f/GHSA-7763-j2c2-xh5f.json @@ -7,12 +7,8 @@ "CVE-2005-4608" ], "details": "SQL injection vulnerability in index.php in BugPort 1.147 allows remote attackers to execute arbitrary SQL commands via the (1) devWherePair[0], (2) orderBy, and (3) where parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7784-c7pr-562g/GHSA-7784-c7pr-562g.json b/advisories/unreviewed/2022/05/GHSA-7784-c7pr-562g/GHSA-7784-c7pr-562g.json index 1e462ddff7a..048e92add12 100644 --- a/advisories/unreviewed/2022/05/GHSA-7784-c7pr-562g/GHSA-7784-c7pr-562g.json +++ b/advisories/unreviewed/2022/05/GHSA-7784-c7pr-562g/GHSA-7784-c7pr-562g.json @@ -7,12 +7,8 @@ "CVE-2005-4709" ], "details": "The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an arbitrary previous client who had the same JBoss server thread.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77c8-7ffw-q7m9/GHSA-77c8-7ffw-q7m9.json b/advisories/unreviewed/2022/05/GHSA-77c8-7ffw-q7m9/GHSA-77c8-7ffw-q7m9.json index 8af723f9f15..be1d84b4d2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-77c8-7ffw-q7m9/GHSA-77c8-7ffw-q7m9.json +++ b/advisories/unreviewed/2022/05/GHSA-77c8-7ffw-q7m9/GHSA-77c8-7ffw-q7m9.json @@ -7,12 +7,8 @@ "CVE-2021-33700" ], "details": "SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take substantial control of the vulnerable application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77g4-qr46-24gf/GHSA-77g4-qr46-24gf.json b/advisories/unreviewed/2022/05/GHSA-77g4-qr46-24gf/GHSA-77g4-qr46-24gf.json index 2b0599fbdf1..957a039fd2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-77g4-qr46-24gf/GHSA-77g4-qr46-24gf.json +++ b/advisories/unreviewed/2022/05/GHSA-77g4-qr46-24gf/GHSA-77g4-qr46-24gf.json @@ -7,12 +7,8 @@ "CVE-2005-4863" ], "details": "Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-793h-vw32-6xg7/GHSA-793h-vw32-6xg7.json b/advisories/unreviewed/2022/05/GHSA-793h-vw32-6xg7/GHSA-793h-vw32-6xg7.json index 80cdc3cb232..815c04af5c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-793h-vw32-6xg7/GHSA-793h-vw32-6xg7.json +++ b/advisories/unreviewed/2022/05/GHSA-793h-vw32-6xg7/GHSA-793h-vw32-6xg7.json @@ -7,12 +7,8 @@ "CVE-2005-4465" ], "details": "The Internet Key Exchange version 1 (IKEv1) implementation in NEC UNIVERGE IX1000, IX2000, and IX3000 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79rq-pp6p-6hmr/GHSA-79rq-pp6p-6hmr.json b/advisories/unreviewed/2022/05/GHSA-79rq-pp6p-6hmr/GHSA-79rq-pp6p-6hmr.json index 2ccd800f355..c1595c84d03 100644 --- a/advisories/unreviewed/2022/05/GHSA-79rq-pp6p-6hmr/GHSA-79rq-pp6p-6hmr.json +++ b/advisories/unreviewed/2022/05/GHSA-79rq-pp6p-6hmr/GHSA-79rq-pp6p-6hmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c52-ww2j-7v63/GHSA-7c52-ww2j-7v63.json b/advisories/unreviewed/2022/05/GHSA-7c52-ww2j-7v63/GHSA-7c52-ww2j-7v63.json index 182bf316ee0..9c7633db9ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c52-ww2j-7v63/GHSA-7c52-ww2j-7v63.json +++ b/advisories/unreviewed/2022/05/GHSA-7c52-ww2j-7v63/GHSA-7c52-ww2j-7v63.json @@ -7,12 +7,8 @@ "CVE-2005-4873" ], "details": "Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long function parameters, as demonstrated by the cups_get_dest_options function in phpcups.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cfr-6m37-9p2x/GHSA-7cfr-6m37-9p2x.json b/advisories/unreviewed/2022/05/GHSA-7cfr-6m37-9p2x/GHSA-7cfr-6m37-9p2x.json index 61d1ca7e15d..f082b72c2c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cfr-6m37-9p2x/GHSA-7cfr-6m37-9p2x.json +++ b/advisories/unreviewed/2022/05/GHSA-7cfr-6m37-9p2x/GHSA-7cfr-6m37-9p2x.json @@ -7,12 +7,8 @@ "CVE-2005-4742" ], "details": "Unspecified vulnerability in Echelog 0.6.2 allows attackers to \"exploit function stacks on some architectures,\" with unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7cx8-j7qq-8w58/GHSA-7cx8-j7qq-8w58.json b/advisories/unreviewed/2022/05/GHSA-7cx8-j7qq-8w58/GHSA-7cx8-j7qq-8w58.json index 79176d3b268..dc99fa34bb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cx8-j7qq-8w58/GHSA-7cx8-j7qq-8w58.json +++ b/advisories/unreviewed/2022/05/GHSA-7cx8-j7qq-8w58/GHSA-7cx8-j7qq-8w58.json @@ -7,12 +7,8 @@ "CVE-2005-4797" ], "details": "Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via \"..\" sequences in an \"Unlink data file\" command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f3j-x5jc-j32w/GHSA-7f3j-x5jc-j32w.json b/advisories/unreviewed/2022/05/GHSA-7f3j-x5jc-j32w/GHSA-7f3j-x5jc-j32w.json index 3c63508ee1e..9f6cfa779ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f3j-x5jc-j32w/GHSA-7f3j-x5jc-j32w.json +++ b/advisories/unreviewed/2022/05/GHSA-7f3j-x5jc-j32w/GHSA-7f3j-x5jc-j32w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fm7-7gf5-94cr/GHSA-7fm7-7gf5-94cr.json b/advisories/unreviewed/2022/05/GHSA-7fm7-7gf5-94cr/GHSA-7fm7-7gf5-94cr.json index 2ab0d4005b6..e40d10ce36b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fm7-7gf5-94cr/GHSA-7fm7-7gf5-94cr.json +++ b/advisories/unreviewed/2022/05/GHSA-7fm7-7gf5-94cr/GHSA-7fm7-7gf5-94cr.json @@ -7,12 +7,8 @@ "CVE-2005-4480" ], "details": "Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7g44-2g66-w5fr/GHSA-7g44-2g66-w5fr.json b/advisories/unreviewed/2022/05/GHSA-7g44-2g66-w5fr/GHSA-7g44-2g66-w5fr.json index 85ae02b2833..2036dc2a46b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g44-2g66-w5fr/GHSA-7g44-2g66-w5fr.json +++ b/advisories/unreviewed/2022/05/GHSA-7g44-2g66-w5fr/GHSA-7g44-2g66-w5fr.json @@ -7,12 +7,8 @@ "CVE-2021-3751" ], "details": "libmobi is vulnerable to Out-of-bounds Write", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h7v-g6g9-xc8m/GHSA-7h7v-g6g9-xc8m.json b/advisories/unreviewed/2022/05/GHSA-7h7v-g6g9-xc8m/GHSA-7h7v-g6g9-xc8m.json index 570443d8e59..0ca93b2ed48 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h7v-g6g9-xc8m/GHSA-7h7v-g6g9-xc8m.json +++ b/advisories/unreviewed/2022/05/GHSA-7h7v-g6g9-xc8m/GHSA-7h7v-g6g9-xc8m.json @@ -7,12 +7,8 @@ "CVE-2019-9060" ], "details": "An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j29-8px4-p3vh/GHSA-7j29-8px4-p3vh.json b/advisories/unreviewed/2022/05/GHSA-7j29-8px4-p3vh/GHSA-7j29-8px4-p3vh.json index 031d70f5af4..61d4fb1befa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j29-8px4-p3vh/GHSA-7j29-8px4-p3vh.json +++ b/advisories/unreviewed/2022/05/GHSA-7j29-8px4-p3vh/GHSA-7j29-8px4-p3vh.json @@ -7,12 +7,8 @@ "CVE-2005-4579" ], "details": "Multiple HTTP response splitting vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to inject arbitrary HTTP headers via unknown attack vectors in an unspecified input form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j4q-97pw-5p6r/GHSA-7j4q-97pw-5p6r.json b/advisories/unreviewed/2022/05/GHSA-7j4q-97pw-5p6r/GHSA-7j4q-97pw-5p6r.json index 92ab703b800..aeafee80bb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j4q-97pw-5p6r/GHSA-7j4q-97pw-5p6r.json +++ b/advisories/unreviewed/2022/05/GHSA-7j4q-97pw-5p6r/GHSA-7j4q-97pw-5p6r.json @@ -7,12 +7,8 @@ "CVE-2021-39598" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function callcode() located in code.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jfp-wwch-7rgr/GHSA-7jfp-wwch-7rgr.json b/advisories/unreviewed/2022/05/GHSA-7jfp-wwch-7rgr/GHSA-7jfp-wwch-7rgr.json index 9a153ab4416..8da91e42717 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jfp-wwch-7rgr/GHSA-7jfp-wwch-7rgr.json +++ b/advisories/unreviewed/2022/05/GHSA-7jfp-wwch-7rgr/GHSA-7jfp-wwch-7rgr.json @@ -7,12 +7,8 @@ "CVE-2021-32134" ], "details": "The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jgh-j4rc-4q2v/GHSA-7jgh-j4rc-4q2v.json b/advisories/unreviewed/2022/05/GHSA-7jgh-j4rc-4q2v/GHSA-7jgh-j4rc-4q2v.json index 606a476dc07..526d7cad9cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jgh-j4rc-4q2v/GHSA-7jgh-j4rc-4q2v.json +++ b/advisories/unreviewed/2022/05/GHSA-7jgh-j4rc-4q2v/GHSA-7jgh-j4rc-4q2v.json @@ -7,12 +7,8 @@ "CVE-2021-29820" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204347.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m66-pvc3-h2x4/GHSA-7m66-pvc3-h2x4.json b/advisories/unreviewed/2022/05/GHSA-7m66-pvc3-h2x4/GHSA-7m66-pvc3-h2x4.json index af2a9bed45f..7fd51b7b221 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m66-pvc3-h2x4/GHSA-7m66-pvc3-h2x4.json +++ b/advisories/unreviewed/2022/05/GHSA-7m66-pvc3-h2x4/GHSA-7m66-pvc3-h2x4.json @@ -7,12 +7,8 @@ "CVE-2021-24600" ], "details": "The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mh3-jvj6-47x5/GHSA-7mh3-jvj6-47x5.json b/advisories/unreviewed/2022/05/GHSA-7mh3-jvj6-47x5/GHSA-7mh3-jvj6-47x5.json index c3a1a10f02d..607ee023718 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mh3-jvj6-47x5/GHSA-7mh3-jvj6-47x5.json +++ b/advisories/unreviewed/2022/05/GHSA-7mh3-jvj6-47x5/GHSA-7mh3-jvj6-47x5.json @@ -7,12 +7,8 @@ "CVE-2021-38090" ], "details": "Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p3q-vc66-rxmp/GHSA-7p3q-vc66-rxmp.json b/advisories/unreviewed/2022/05/GHSA-7p3q-vc66-rxmp/GHSA-7p3q-vc66-rxmp.json index 29a65eba06b..15096538470 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p3q-vc66-rxmp/GHSA-7p3q-vc66-rxmp.json +++ b/advisories/unreviewed/2022/05/GHSA-7p3q-vc66-rxmp/GHSA-7p3q-vc66-rxmp.json @@ -7,12 +7,8 @@ "CVE-2005-4753" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, in certain \"heavy usage\" scenarios, report incorrect severity levels for an audit event, which might allow attackers to perform unauthorized actions and avoid detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pcr-5h9h-38rf/GHSA-7pcr-5h9h-38rf.json b/advisories/unreviewed/2022/05/GHSA-7pcr-5h9h-38rf/GHSA-7pcr-5h9h-38rf.json index 76bc6a2ab3c..e2f25b852d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pcr-5h9h-38rf/GHSA-7pcr-5h9h-38rf.json +++ b/advisories/unreviewed/2022/05/GHSA-7pcr-5h9h-38rf/GHSA-7pcr-5h9h-38rf.json @@ -7,12 +7,8 @@ "CVE-2021-34768" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pm4-8h5h-6ch3/GHSA-7pm4-8h5h-6ch3.json b/advisories/unreviewed/2022/05/GHSA-7pm4-8h5h-6ch3/GHSA-7pm4-8h5h-6ch3.json index 7ffc9099ddb..eddf4441867 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pm4-8h5h-6ch3/GHSA-7pm4-8h5h-6ch3.json +++ b/advisories/unreviewed/2022/05/GHSA-7pm4-8h5h-6ch3/GHSA-7pm4-8h5h-6ch3.json @@ -7,12 +7,8 @@ "CVE-2005-4476" ], "details": "Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7q63-mgr2-2p5j/GHSA-7q63-mgr2-2p5j.json b/advisories/unreviewed/2022/05/GHSA-7q63-mgr2-2p5j/GHSA-7q63-mgr2-2p5j.json index 988ad03b084..e7d5bb565cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q63-mgr2-2p5j/GHSA-7q63-mgr2-2p5j.json +++ b/advisories/unreviewed/2022/05/GHSA-7q63-mgr2-2p5j/GHSA-7q63-mgr2-2p5j.json @@ -7,12 +7,8 @@ "CVE-2021-1947" ], "details": "Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7q6c-727m-8m74/GHSA-7q6c-727m-8m74.json b/advisories/unreviewed/2022/05/GHSA-7q6c-727m-8m74/GHSA-7q6c-727m-8m74.json index 042b0dda990..c44a106fb2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q6c-727m-8m74/GHSA-7q6c-727m-8m74.json +++ b/advisories/unreviewed/2022/05/GHSA-7q6c-727m-8m74/GHSA-7q6c-727m-8m74.json @@ -7,12 +7,8 @@ "CVE-2005-4642" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in HydroBB 1.0.0 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) search.php, (2) members.php, (3) stats.php, (4) viewforum.php, (5) register.php, (6) usercp.php, (7) groups.php, (8) pms.php, and (9) calendar.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qg6-74r3-86w6/GHSA-7qg6-74r3-86w6.json b/advisories/unreviewed/2022/05/GHSA-7qg6-74r3-86w6/GHSA-7qg6-74r3-86w6.json index f8223527bac..a89793e3b7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qg6-74r3-86w6/GHSA-7qg6-74r3-86w6.json +++ b/advisories/unreviewed/2022/05/GHSA-7qg6-74r3-86w6/GHSA-7qg6-74r3-86w6.json @@ -7,12 +7,8 @@ "CVE-2021-40156" ], "details": "A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to write beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qqh-46f7-v7hc/GHSA-7qqh-46f7-v7hc.json b/advisories/unreviewed/2022/05/GHSA-7qqh-46f7-v7hc/GHSA-7qqh-46f7-v7hc.json index 6c6a96a791a..d92a996f377 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qqh-46f7-v7hc/GHSA-7qqh-46f7-v7hc.json +++ b/advisories/unreviewed/2022/05/GHSA-7qqh-46f7-v7hc/GHSA-7qqh-46f7-v7hc.json @@ -7,12 +7,8 @@ "CVE-2005-4658" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rh8-6x72-2pcx/GHSA-7rh8-6x72-2pcx.json b/advisories/unreviewed/2022/05/GHSA-7rh8-6x72-2pcx/GHSA-7rh8-6x72-2pcx.json index 31f275fdb02..6b11ff8bf24 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rh8-6x72-2pcx/GHSA-7rh8-6x72-2pcx.json +++ b/advisories/unreviewed/2022/05/GHSA-7rh8-6x72-2pcx/GHSA-7rh8-6x72-2pcx.json @@ -7,12 +7,8 @@ "CVE-2021-24400" ], "details": "The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rjr-24cr-3hfx/GHSA-7rjr-24cr-3hfx.json b/advisories/unreviewed/2022/05/GHSA-7rjr-24cr-3hfx/GHSA-7rjr-24cr-3hfx.json index cae46bc99c1..838bc10f0d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rjr-24cr-3hfx/GHSA-7rjr-24cr-3hfx.json +++ b/advisories/unreviewed/2022/05/GHSA-7rjr-24cr-3hfx/GHSA-7rjr-24cr-3hfx.json @@ -7,12 +7,8 @@ "CVE-2005-4502" ], "details": "Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rqv-hpgx-m2wc/GHSA-7rqv-hpgx-m2wc.json b/advisories/unreviewed/2022/05/GHSA-7rqv-hpgx-m2wc/GHSA-7rqv-hpgx-m2wc.json index 312dc944596..023ec970204 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rqv-hpgx-m2wc/GHSA-7rqv-hpgx-m2wc.json +++ b/advisories/unreviewed/2022/05/GHSA-7rqv-hpgx-m2wc/GHSA-7rqv-hpgx-m2wc.json @@ -7,12 +7,8 @@ "CVE-2005-4693" ], "details": "Gaim-Encryption 2.38-1 on Debian Linux allows remote attackers to cause a denial of service (crash) via a crafted message from an ICQ buddy, possibly involving the GE_received_key function in keys.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v7r-2p9m-p93q/GHSA-7v7r-2p9m-p93q.json b/advisories/unreviewed/2022/05/GHSA-7v7r-2p9m-p93q/GHSA-7v7r-2p9m-p93q.json index d18407c714a..ab6ac59d112 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v7r-2p9m-p93q/GHSA-7v7r-2p9m-p93q.json +++ b/advisories/unreviewed/2022/05/GHSA-7v7r-2p9m-p93q/GHSA-7v7r-2p9m-p93q.json @@ -7,12 +7,8 @@ "CVE-2005-4526" ], "details": "Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vhx-6x46-jv3p/GHSA-7vhx-6x46-jv3p.json b/advisories/unreviewed/2022/05/GHSA-7vhx-6x46-jv3p/GHSA-7vhx-6x46-jv3p.json index 2a63d2c43d2..2a545d974d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vhx-6x46-jv3p/GHSA-7vhx-6x46-jv3p.json +++ b/advisories/unreviewed/2022/05/GHSA-7vhx-6x46-jv3p/GHSA-7vhx-6x46-jv3p.json @@ -7,12 +7,8 @@ "CVE-2021-29809" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204270.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wcr-cqmg-4vmr/GHSA-7wcr-cqmg-4vmr.json b/advisories/unreviewed/2022/05/GHSA-7wcr-cqmg-4vmr/GHSA-7wcr-cqmg-4vmr.json index 3ac24d3e1e3..356fe7337ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wcr-cqmg-4vmr/GHSA-7wcr-cqmg-4vmr.json +++ b/advisories/unreviewed/2022/05/GHSA-7wcr-cqmg-4vmr/GHSA-7wcr-cqmg-4vmr.json @@ -7,12 +7,8 @@ "CVE-2005-4653" ], "details": "Unspecified vulnerability in ss.php in AL-Caricatier 2.5 and earlier allows remote attackers to bypass login authentication by requesting view_caricatier.php, and then requesting any file in the admin directory with a cookie_username=admin argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x3c-7jfh-6j4c/GHSA-7x3c-7jfh-6j4c.json b/advisories/unreviewed/2022/05/GHSA-7x3c-7jfh-6j4c/GHSA-7x3c-7jfh-6j4c.json index adf9ddee577..f522acae7c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x3c-7jfh-6j4c/GHSA-7x3c-7jfh-6j4c.json +++ b/advisories/unreviewed/2022/05/GHSA-7x3c-7jfh-6j4c/GHSA-7x3c-7jfh-6j4c.json @@ -7,12 +7,8 @@ "CVE-2005-4732" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Tux Racer TuxBank 0.7x and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) description parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x8j-m6q2-x954/GHSA-7x8j-m6q2-x954.json b/advisories/unreviewed/2022/05/GHSA-7x8j-m6q2-x954/GHSA-7x8j-m6q2-x954.json index f064d23fbb0..236e5479bde 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x8j-m6q2-x954/GHSA-7x8j-m6q2-x954.json +++ b/advisories/unreviewed/2022/05/GHSA-7x8j-m6q2-x954/GHSA-7x8j-m6q2-x954.json @@ -7,12 +7,8 @@ "CVE-2021-34572" ], "details": "Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xg4-c3g7-r42r/GHSA-7xg4-c3g7-r42r.json b/advisories/unreviewed/2022/05/GHSA-7xg4-c3g7-r42r/GHSA-7xg4-c3g7-r42r.json index 2d157179865..82abb103b72 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xg4-c3g7-r42r/GHSA-7xg4-c3g7-r42r.json +++ b/advisories/unreviewed/2022/05/GHSA-7xg4-c3g7-r42r/GHSA-7xg4-c3g7-r42r.json @@ -7,12 +7,8 @@ "CVE-2021-24582" ], "details": "The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its \"Consumer key\" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-828q-cvff-pc4m/GHSA-828q-cvff-pc4m.json b/advisories/unreviewed/2022/05/GHSA-828q-cvff-pc4m/GHSA-828q-cvff-pc4m.json index 561137a886e..1ea7137ef2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-828q-cvff-pc4m/GHSA-828q-cvff-pc4m.json +++ b/advisories/unreviewed/2022/05/GHSA-828q-cvff-pc4m/GHSA-828q-cvff-pc4m.json @@ -7,12 +7,8 @@ "CVE-2005-4401" ], "details": "Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8327-8m8p-rw2w/GHSA-8327-8m8p-rw2w.json b/advisories/unreviewed/2022/05/GHSA-8327-8m8p-rw2w/GHSA-8327-8m8p-rw2w.json index 551fdd2f356..fd026cb6c39 100644 --- a/advisories/unreviewed/2022/05/GHSA-8327-8m8p-rw2w/GHSA-8327-8m8p-rw2w.json +++ b/advisories/unreviewed/2022/05/GHSA-8327-8m8p-rw2w/GHSA-8327-8m8p-rw2w.json @@ -7,12 +7,8 @@ "CVE-2021-32137" ], "details": "Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84pv-q4h7-244g/GHSA-84pv-q4h7-244g.json b/advisories/unreviewed/2022/05/GHSA-84pv-q4h7-244g/GHSA-84pv-q4h7-244g.json index 77ff15c3fa4..12df9885e35 100644 --- a/advisories/unreviewed/2022/05/GHSA-84pv-q4h7-244g/GHSA-84pv-q4h7-244g.json +++ b/advisories/unreviewed/2022/05/GHSA-84pv-q4h7-244g/GHSA-84pv-q4h7-244g.json @@ -7,12 +7,8 @@ "CVE-2021-23025" ], "details": "On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-856m-7gh9-83gw/GHSA-856m-7gh9-83gw.json b/advisories/unreviewed/2022/05/GHSA-856m-7gh9-83gw/GHSA-856m-7gh9-83gw.json index a531d16dc97..549a6ee11ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-856m-7gh9-83gw/GHSA-856m-7gh9-83gw.json +++ b/advisories/unreviewed/2022/05/GHSA-856m-7gh9-83gw/GHSA-856m-7gh9-83gw.json @@ -7,12 +7,8 @@ "CVE-2021-39519" ], "details": "An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86c3-4264-rwhv/GHSA-86c3-4264-rwhv.json b/advisories/unreviewed/2022/05/GHSA-86c3-4264-rwhv/GHSA-86c3-4264-rwhv.json index 1f59df2eca9..6650a3202ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-86c3-4264-rwhv/GHSA-86c3-4264-rwhv.json +++ b/advisories/unreviewed/2022/05/GHSA-86c3-4264-rwhv/GHSA-86c3-4264-rwhv.json @@ -7,12 +7,8 @@ "CVE-2021-39542" ], "details": "An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Font::Size() located in font.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86j3-7436-wx4w/GHSA-86j3-7436-wx4w.json b/advisories/unreviewed/2022/05/GHSA-86j3-7436-wx4w/GHSA-86j3-7436-wx4w.json index 158db9aa174..926ebf2e41f 100644 --- a/advisories/unreviewed/2022/05/GHSA-86j3-7436-wx4w/GHSA-86j3-7436-wx4w.json +++ b/advisories/unreviewed/2022/05/GHSA-86j3-7436-wx4w/GHSA-86j3-7436-wx4w.json @@ -7,12 +7,8 @@ "CVE-2021-39528" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86m8-rg37-85gx/GHSA-86m8-rg37-85gx.json b/advisories/unreviewed/2022/05/GHSA-86m8-rg37-85gx/GHSA-86m8-rg37-85gx.json index 30dedcfa4ec..a85300d869b 100644 --- a/advisories/unreviewed/2022/05/GHSA-86m8-rg37-85gx/GHSA-86m8-rg37-85gx.json +++ b/advisories/unreviewed/2022/05/GHSA-86m8-rg37-85gx/GHSA-86m8-rg37-85gx.json @@ -7,12 +7,8 @@ "CVE-2005-4478" ], "details": "Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-874c-9v93-83g8/GHSA-874c-9v93-83g8.json b/advisories/unreviewed/2022/05/GHSA-874c-9v93-83g8/GHSA-874c-9v93-83g8.json index 61f89a16937..c9e5c8f3e25 100644 --- a/advisories/unreviewed/2022/05/GHSA-874c-9v93-83g8/GHSA-874c-9v93-83g8.json +++ b/advisories/unreviewed/2022/05/GHSA-874c-9v93-83g8/GHSA-874c-9v93-83g8.json @@ -7,12 +7,8 @@ "CVE-2005-4576" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-878w-3c3r-w7j4/GHSA-878w-3c3r-w7j4.json b/advisories/unreviewed/2022/05/GHSA-878w-3c3r-w7j4/GHSA-878w-3c3r-w7j4.json index e94be8da68b..4c6d1401689 100644 --- a/advisories/unreviewed/2022/05/GHSA-878w-3c3r-w7j4/GHSA-878w-3c3r-w7j4.json +++ b/advisories/unreviewed/2022/05/GHSA-878w-3c3r-w7j4/GHSA-878w-3c3r-w7j4.json @@ -7,12 +7,8 @@ "CVE-2021-39538" ], "details": "An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::ObjNode::Value() located in objnode.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88p5-j94v-hcpw/GHSA-88p5-j94v-hcpw.json b/advisories/unreviewed/2022/05/GHSA-88p5-j94v-hcpw/GHSA-88p5-j94v-hcpw.json index 3096a1d8fb9..760cda1acdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-88p5-j94v-hcpw/GHSA-88p5-j94v-hcpw.json +++ b/advisories/unreviewed/2022/05/GHSA-88p5-j94v-hcpw/GHSA-88p5-j94v-hcpw.json @@ -7,12 +7,8 @@ "CVE-2021-38359" ], "details": "The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88x2-v352-g224/GHSA-88x2-v352-g224.json b/advisories/unreviewed/2022/05/GHSA-88x2-v352-g224/GHSA-88x2-v352-g224.json index 6100d852429..e1fa094949b 100644 --- a/advisories/unreviewed/2022/05/GHSA-88x2-v352-g224/GHSA-88x2-v352-g224.json +++ b/advisories/unreviewed/2022/05/GHSA-88x2-v352-g224/GHSA-88x2-v352-g224.json @@ -7,12 +7,8 @@ "CVE-2021-41390" ], "details": "In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-898q-rv6w-247h/GHSA-898q-rv6w-247h.json b/advisories/unreviewed/2022/05/GHSA-898q-rv6w-247h/GHSA-898q-rv6w-247h.json index dab2ccf5590..3daf1e06cc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-898q-rv6w-247h/GHSA-898q-rv6w-247h.json +++ b/advisories/unreviewed/2022/05/GHSA-898q-rv6w-247h/GHSA-898q-rv6w-247h.json @@ -7,12 +7,8 @@ "CVE-2005-4623" ], "details": "upload.exe in eFileGo 3.01 allows remote attackers to cause a denial of service (CPU consumption) via an argument with an invalid directory name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89q9-wwr5-f2mf/GHSA-89q9-wwr5-f2mf.json b/advisories/unreviewed/2022/05/GHSA-89q9-wwr5-f2mf/GHSA-89q9-wwr5-f2mf.json index 080b536d31d..0f60bcdf19c 100644 --- a/advisories/unreviewed/2022/05/GHSA-89q9-wwr5-f2mf/GHSA-89q9-wwr5-f2mf.json +++ b/advisories/unreviewed/2022/05/GHSA-89q9-wwr5-f2mf/GHSA-89q9-wwr5-f2mf.json @@ -7,12 +7,8 @@ "CVE-2005-4422" ], "details": "Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89xh-mm48-p72f/GHSA-89xh-mm48-p72f.json b/advisories/unreviewed/2022/05/GHSA-89xh-mm48-p72f/GHSA-89xh-mm48-p72f.json index b031b29a377..666e5497553 100644 --- a/advisories/unreviewed/2022/05/GHSA-89xh-mm48-p72f/GHSA-89xh-mm48-p72f.json +++ b/advisories/unreviewed/2022/05/GHSA-89xh-mm48-p72f/GHSA-89xh-mm48-p72f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c3h-ggpx-cvjg/GHSA-8c3h-ggpx-cvjg.json b/advisories/unreviewed/2022/05/GHSA-8c3h-ggpx-cvjg/GHSA-8c3h-ggpx-cvjg.json index 38331cfde37..b47637404ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c3h-ggpx-cvjg/GHSA-8c3h-ggpx-cvjg.json +++ b/advisories/unreviewed/2022/05/GHSA-8c3h-ggpx-cvjg/GHSA-8c3h-ggpx-cvjg.json @@ -7,12 +7,8 @@ "CVE-2005-4662" ], "details": "Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c59-7xj5-h2jh/GHSA-8c59-7xj5-h2jh.json b/advisories/unreviewed/2022/05/GHSA-8c59-7xj5-h2jh/GHSA-8c59-7xj5-h2jh.json index ff84374241b..e770954b901 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c59-7xj5-h2jh/GHSA-8c59-7xj5-h2jh.json +++ b/advisories/unreviewed/2022/05/GHSA-8c59-7xj5-h2jh/GHSA-8c59-7xj5-h2jh.json @@ -7,12 +7,8 @@ "CVE-2021-33696" ], "details": "SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cq5-h2jx-4m9x/GHSA-8cq5-h2jx-4m9x.json b/advisories/unreviewed/2022/05/GHSA-8cq5-h2jx-4m9x/GHSA-8cq5-h2jx-4m9x.json index 5f9e08bb2ac..32ebaa64607 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cq5-h2jx-4m9x/GHSA-8cq5-h2jx-4m9x.json +++ b/advisories/unreviewed/2022/05/GHSA-8cq5-h2jx-4m9x/GHSA-8cq5-h2jx-4m9x.json @@ -7,12 +7,8 @@ "CVE-2005-4499" ], "details": "The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS session, then using the password to log in to another device that uses CS ACS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8f3c-5w2m-gp7j/GHSA-8f3c-5w2m-gp7j.json b/advisories/unreviewed/2022/05/GHSA-8f3c-5w2m-gp7j/GHSA-8f3c-5w2m-gp7j.json index 83182699736..af9c33e1d35 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f3c-5w2m-gp7j/GHSA-8f3c-5w2m-gp7j.json +++ b/advisories/unreviewed/2022/05/GHSA-8f3c-5w2m-gp7j/GHSA-8f3c-5w2m-gp7j.json @@ -7,12 +7,8 @@ "CVE-2020-19950" ], "details": "A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f7q-x4r8-9427/GHSA-8f7q-x4r8-9427.json b/advisories/unreviewed/2022/05/GHSA-8f7q-x4r8-9427/GHSA-8f7q-x4r8-9427.json index 9e7deeff878..3f4da680ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f7q-x4r8-9427/GHSA-8f7q-x4r8-9427.json +++ b/advisories/unreviewed/2022/05/GHSA-8f7q-x4r8-9427/GHSA-8f7q-x4r8-9427.json @@ -7,12 +7,8 @@ "CVE-2021-27045" ], "details": "A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF file. This vulnerability can be exploited to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f89-v95p-2ph8/GHSA-8f89-v95p-2ph8.json b/advisories/unreviewed/2022/05/GHSA-8f89-v95p-2ph8/GHSA-8f89-v95p-2ph8.json index 2fc490a3c90..25e8647a92e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f89-v95p-2ph8/GHSA-8f89-v95p-2ph8.json +++ b/advisories/unreviewed/2022/05/GHSA-8f89-v95p-2ph8/GHSA-8f89-v95p-2ph8.json @@ -7,12 +7,8 @@ "CVE-2005-4636" ], "details": "OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fmp-8375-h4p6/GHSA-8fmp-8375-h4p6.json b/advisories/unreviewed/2022/05/GHSA-8fmp-8375-h4p6/GHSA-8fmp-8375-h4p6.json index b86aaa92866..5ddf470f327 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fmp-8375-h4p6/GHSA-8fmp-8375-h4p6.json +++ b/advisories/unreviewed/2022/05/GHSA-8fmp-8375-h4p6/GHSA-8fmp-8375-h4p6.json @@ -7,12 +7,8 @@ "CVE-2020-19294" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comments section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fqx-vvx3-hvxm/GHSA-8fqx-vvx3-hvxm.json b/advisories/unreviewed/2022/05/GHSA-8fqx-vvx3-hvxm/GHSA-8fqx-vvx3-hvxm.json index 09eee23f092..01645b598a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fqx-vvx3-hvxm/GHSA-8fqx-vvx3-hvxm.json +++ b/advisories/unreviewed/2022/05/GHSA-8fqx-vvx3-hvxm/GHSA-8fqx-vvx3-hvxm.json @@ -7,12 +7,8 @@ "CVE-2005-4437" ], "details": "MD5 Neighbor Authentication in Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS 11.3 and later, does not include the Message Authentication Code (MAC) in the checksum, which allows remote attackers to sniff message hashes and (1) replay EIGRP HELLO messages or (2) cause a denial of service by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fr5-3m95-p6r9/GHSA-8fr5-3m95-p6r9.json b/advisories/unreviewed/2022/05/GHSA-8fr5-3m95-p6r9/GHSA-8fr5-3m95-p6r9.json index 59aac49af7d..9990df7bdf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fr5-3m95-p6r9/GHSA-8fr5-3m95-p6r9.json +++ b/advisories/unreviewed/2022/05/GHSA-8fr5-3m95-p6r9/GHSA-8fr5-3m95-p6r9.json @@ -7,12 +7,8 @@ "CVE-2021-24623" ], "details": "The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gwc-9c4q-3rfx/GHSA-8gwc-9c4q-3rfx.json b/advisories/unreviewed/2022/05/GHSA-8gwc-9c4q-3rfx/GHSA-8gwc-9c4q-3rfx.json index 091f90091ed..cdc2527d8bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gwc-9c4q-3rfx/GHSA-8gwc-9c4q-3rfx.json +++ b/advisories/unreviewed/2022/05/GHSA-8gwc-9c4q-3rfx/GHSA-8gwc-9c4q-3rfx.json @@ -7,12 +7,8 @@ "CVE-2005-4434" ], "details": "Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h2v-2p8g-f36m/GHSA-8h2v-2p8g-f36m.json b/advisories/unreviewed/2022/05/GHSA-8h2v-2p8g-f36m/GHSA-8h2v-2p8g-f36m.json index 8c3119d7362..e805af59cf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h2v-2p8g-f36m/GHSA-8h2v-2p8g-f36m.json +++ b/advisories/unreviewed/2022/05/GHSA-8h2v-2p8g-f36m/GHSA-8h2v-2p8g-f36m.json @@ -7,12 +7,8 @@ "CVE-2005-4667" ], "details": "Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h3c-9j4w-wqxp/GHSA-8h3c-9j4w-wqxp.json b/advisories/unreviewed/2022/05/GHSA-8h3c-9j4w-wqxp/GHSA-8h3c-9j4w-wqxp.json index b7cbb74010a..d6f8e8a2f84 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h3c-9j4w-wqxp/GHSA-8h3c-9j4w-wqxp.json +++ b/advisories/unreviewed/2022/05/GHSA-8h3c-9j4w-wqxp/GHSA-8h3c-9j4w-wqxp.json @@ -7,12 +7,8 @@ "CVE-2020-21126" ], "details": "MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h86-6q3w-5h6p/GHSA-8h86-6q3w-5h6p.json b/advisories/unreviewed/2022/05/GHSA-8h86-6q3w-5h6p/GHSA-8h86-6q3w-5h6p.json index d9cef6b26a3..bec638ef82c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h86-6q3w-5h6p/GHSA-8h86-6q3w-5h6p.json +++ b/advisories/unreviewed/2022/05/GHSA-8h86-6q3w-5h6p/GHSA-8h86-6q3w-5h6p.json @@ -7,12 +7,8 @@ "CVE-2021-41392" ], "details": "static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h8g-rw3h-79pw/GHSA-8h8g-rw3h-79pw.json b/advisories/unreviewed/2022/05/GHSA-8h8g-rw3h-79pw/GHSA-8h8g-rw3h-79pw.json index 1e2d7debb88..45a3eeb020b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h8g-rw3h-79pw/GHSA-8h8g-rw3h-79pw.json +++ b/advisories/unreviewed/2022/05/GHSA-8h8g-rw3h-79pw/GHSA-8h8g-rw3h-79pw.json @@ -7,12 +7,8 @@ "CVE-2005-4609" ], "details": "index.php in BugPort 1.147 and earlier allows remote attackers to obtain sensitive information such as full path and system configuration via an invalid action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8hjf-39rr-pc66/GHSA-8hjf-39rr-pc66.json b/advisories/unreviewed/2022/05/GHSA-8hjf-39rr-pc66/GHSA-8hjf-39rr-pc66.json index bbe7f114064..39a0448f4fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hjf-39rr-pc66/GHSA-8hjf-39rr-pc66.json +++ b/advisories/unreviewed/2022/05/GHSA-8hjf-39rr-pc66/GHSA-8hjf-39rr-pc66.json @@ -7,12 +7,8 @@ "CVE-2020-19157" ], "details": "Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hjp-hfjp-rw28/GHSA-8hjp-hfjp-rw28.json b/advisories/unreviewed/2022/05/GHSA-8hjp-hfjp-rw28/GHSA-8hjp-hfjp-rw28.json index 206425584a0..509b153d2ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hjp-hfjp-rw28/GHSA-8hjp-hfjp-rw28.json +++ b/advisories/unreviewed/2022/05/GHSA-8hjp-hfjp-rw28/GHSA-8hjp-hfjp-rw28.json @@ -7,12 +7,8 @@ "CVE-2005-4582" ], "details": "Electric Sheep 2.6.3 does not require authentication or integrity checks from the server to the client, which allows remote attackers to download and display arbitrary MPEG movie files via (1) DNS spoofing, (2) a URL on the command line, or (3) a URL in the configuration file. NOTE: the same attack vectors apply to common web browsers that are able to communicate with untrusted web servers, and other problems related to DNS design issues. Therefore this may not be a specific vulnerability. However, a client would reasonably expect to receive content only from the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jmg-vw84-q638/GHSA-8jmg-vw84-q638.json b/advisories/unreviewed/2022/05/GHSA-8jmg-vw84-q638/GHSA-8jmg-vw84-q638.json index 0b31d0907dc..df6460e3935 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jmg-vw84-q638/GHSA-8jmg-vw84-q638.json +++ b/advisories/unreviewed/2022/05/GHSA-8jmg-vw84-q638/GHSA-8jmg-vw84-q638.json @@ -7,12 +7,8 @@ "CVE-2020-24327" ], "details": "Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jpc-vcqh-2w24/GHSA-8jpc-vcqh-2w24.json b/advisories/unreviewed/2022/05/GHSA-8jpc-vcqh-2w24/GHSA-8jpc-vcqh-2w24.json index 2b6f24331d5..3038e4edeec 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jpc-vcqh-2w24/GHSA-8jpc-vcqh-2w24.json +++ b/advisories/unreviewed/2022/05/GHSA-8jpc-vcqh-2w24/GHSA-8jpc-vcqh-2w24.json @@ -7,12 +7,8 @@ "CVE-2005-4718" ], "details": "Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file with a \"content: url(0);\" style attribute, a \"bodyA\" tag, a long string, and a \"u\" tag with a long attribute, as demonstrated by opera.html; and (2) a BGSOUND element with a \"margin:-99;\" STYLE attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jv5-cjv4-rqhq/GHSA-8jv5-cjv4-rqhq.json b/advisories/unreviewed/2022/05/GHSA-8jv5-cjv4-rqhq/GHSA-8jv5-cjv4-rqhq.json index 49aa6b47ed3..4e162ed7ea2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jv5-cjv4-rqhq/GHSA-8jv5-cjv4-rqhq.json +++ b/advisories/unreviewed/2022/05/GHSA-8jv5-cjv4-rqhq/GHSA-8jv5-cjv4-rqhq.json @@ -7,12 +7,8 @@ "CVE-2005-4549" ], "details": "Cross-site scripting (XSS) vulnerability in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to inject arbitrary web script or HTML via the (1) RowKeyValue parameter in the PORTAL schema; and the (2) title and (3) content input fields when creating an forum article.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jw6-mfpx-fgw6/GHSA-8jw6-mfpx-fgw6.json b/advisories/unreviewed/2022/05/GHSA-8jw6-mfpx-fgw6/GHSA-8jw6-mfpx-fgw6.json index b7978e375c2..128ff0447f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jw6-mfpx-fgw6/GHSA-8jw6-mfpx-fgw6.json +++ b/advisories/unreviewed/2022/05/GHSA-8jw6-mfpx-fgw6/GHSA-8jw6-mfpx-fgw6.json @@ -7,12 +7,8 @@ "CVE-2021-24621" ], "details": "The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m8j-89c8-3vh7/GHSA-8m8j-89c8-3vh7.json b/advisories/unreviewed/2022/05/GHSA-8m8j-89c8-3vh7/GHSA-8m8j-89c8-3vh7.json index 4b21e4187e5..dbb12569446 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m8j-89c8-3vh7/GHSA-8m8j-89c8-3vh7.json +++ b/advisories/unreviewed/2022/05/GHSA-8m8j-89c8-3vh7/GHSA-8m8j-89c8-3vh7.json @@ -7,12 +7,8 @@ "CVE-2005-4874" ], "details": "The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a \"Max-Forwards: 0\" header or (2) arbitrary local passwords on the web server that hosts this object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m8m-gx66-4856/GHSA-8m8m-gx66-4856.json b/advisories/unreviewed/2022/05/GHSA-8m8m-gx66-4856/GHSA-8m8m-gx66-4856.json index 43dd574e1cd..d2ff92c5a31 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m8m-gx66-4856/GHSA-8m8m-gx66-4856.json +++ b/advisories/unreviewed/2022/05/GHSA-8m8m-gx66-4856/GHSA-8m8m-gx66-4856.json @@ -7,12 +7,8 @@ "CVE-2005-4886" ], "details": "The selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the Linux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of service (OOPS) via vectors associated with an incorrect call to the ipv6_skip_exthdr function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mp4-m9gc-q7v3/GHSA-8mp4-m9gc-q7v3.json b/advisories/unreviewed/2022/05/GHSA-8mp4-m9gc-q7v3/GHSA-8mp4-m9gc-q7v3.json index c1611672ed9..6ee3e65c235 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mp4-m9gc-q7v3/GHSA-8mp4-m9gc-q7v3.json +++ b/advisories/unreviewed/2022/05/GHSA-8mp4-m9gc-q7v3/GHSA-8mp4-m9gc-q7v3.json @@ -7,12 +7,8 @@ "CVE-2005-4492" ], "details": "Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mq7-xqr4-2h23/GHSA-8mq7-xqr4-2h23.json b/advisories/unreviewed/2022/05/GHSA-8mq7-xqr4-2h23/GHSA-8mq7-xqr4-2h23.json index 3d277c69309..7281fd902c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mq7-xqr4-2h23/GHSA-8mq7-xqr4-2h23.json +++ b/advisories/unreviewed/2022/05/GHSA-8mq7-xqr4-2h23/GHSA-8mq7-xqr4-2h23.json @@ -7,12 +7,8 @@ "CVE-2005-4799" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Homepage field (aka the Website field) in an \"image-related comment\" and (2) the img_size field in view.php. NOTE: due to lack of details from the researcher, it is not clear whether the comment vector overlaps CVE-2005-1886.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mqc-792p-mwg5/GHSA-8mqc-792p-mwg5.json b/advisories/unreviewed/2022/05/GHSA-8mqc-792p-mwg5/GHSA-8mqc-792p-mwg5.json index f78928e7758..6c66fc5fc6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mqc-792p-mwg5/GHSA-8mqc-792p-mwg5.json +++ b/advisories/unreviewed/2022/05/GHSA-8mqc-792p-mwg5/GHSA-8mqc-792p-mwg5.json @@ -7,12 +7,8 @@ "CVE-2021-29833" ], "details": "IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204825.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mx8-xx88-x7gm/GHSA-8mx8-xx88-x7gm.json b/advisories/unreviewed/2022/05/GHSA-8mx8-xx88-x7gm/GHSA-8mx8-xx88-x7gm.json index 43b640155be..70f0a97b7f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mx8-xx88-x7gm/GHSA-8mx8-xx88-x7gm.json +++ b/advisories/unreviewed/2022/05/GHSA-8mx8-xx88-x7gm/GHSA-8mx8-xx88-x7gm.json @@ -7,12 +7,8 @@ "CVE-2020-19292" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pj3-c92f-vjfj/GHSA-8pj3-c92f-vjfj.json b/advisories/unreviewed/2022/05/GHSA-8pj3-c92f-vjfj/GHSA-8pj3-c92f-vjfj.json index 8b380c35410..3c1b1ffae39 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pj3-c92f-vjfj/GHSA-8pj3-c92f-vjfj.json +++ b/advisories/unreviewed/2022/05/GHSA-8pj3-c92f-vjfj/GHSA-8pj3-c92f-vjfj.json @@ -7,12 +7,8 @@ "CVE-2005-4426" ], "details": "Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in YaBB.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pmf-jxj3-wvvp/GHSA-8pmf-jxj3-wvvp.json b/advisories/unreviewed/2022/05/GHSA-8pmf-jxj3-wvvp/GHSA-8pmf-jxj3-wvvp.json index 37cc56b97f8..f4591d89b01 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pmf-jxj3-wvvp/GHSA-8pmf-jxj3-wvvp.json +++ b/advisories/unreviewed/2022/05/GHSA-8pmf-jxj3-wvvp/GHSA-8pmf-jxj3-wvvp.json @@ -7,12 +7,8 @@ "CVE-2021-41394" ], "details": "Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q6v-89xc-5g4w/GHSA-8q6v-89xc-5g4w.json b/advisories/unreviewed/2022/05/GHSA-8q6v-89xc-5g4w/GHSA-8q6v-89xc-5g4w.json index 17acacbc046..4caa734a65f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q6v-89xc-5g4w/GHSA-8q6v-89xc-5g4w.json +++ b/advisories/unreviewed/2022/05/GHSA-8q6v-89xc-5g4w/GHSA-8q6v-89xc-5g4w.json @@ -7,12 +7,8 @@ "CVE-2021-38340" ], "details": "The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qfc-4842-rrwj/GHSA-8qfc-4842-rrwj.json b/advisories/unreviewed/2022/05/GHSA-8qfc-4842-rrwj/GHSA-8qfc-4842-rrwj.json index 2cd55bdf231..648b586b487 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qfc-4842-rrwj/GHSA-8qfc-4842-rrwj.json +++ b/advisories/unreviewed/2022/05/GHSA-8qfc-4842-rrwj/GHSA-8qfc-4842-rrwj.json @@ -7,12 +7,8 @@ "CVE-2021-39559" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in GString.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qhp-jq8m-c4m4/GHSA-8qhp-jq8m-c4m4.json b/advisories/unreviewed/2022/05/GHSA-8qhp-jq8m-c4m4/GHSA-8qhp-jq8m-c4m4.json index 40651e9b66f..adac54f648a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qhp-jq8m-c4m4/GHSA-8qhp-jq8m-c4m4.json +++ b/advisories/unreviewed/2022/05/GHSA-8qhp-jq8m-c4m4/GHSA-8qhp-jq8m-c4m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qj6-9gfw-v5pw/GHSA-8qj6-9gfw-v5pw.json b/advisories/unreviewed/2022/05/GHSA-8qj6-9gfw-v5pw/GHSA-8qj6-9gfw-v5pw.json index d38969ed2e9..838a6b584d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qj6-9gfw-v5pw/GHSA-8qj6-9gfw-v5pw.json +++ b/advisories/unreviewed/2022/05/GHSA-8qj6-9gfw-v5pw/GHSA-8qj6-9gfw-v5pw.json @@ -7,12 +7,8 @@ "CVE-2005-4425" ], "details": "Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain RTSP streams.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qq6-rp62-86qv/GHSA-8qq6-rp62-86qv.json b/advisories/unreviewed/2022/05/GHSA-8qq6-rp62-86qv/GHSA-8qq6-rp62-86qv.json index eb06aa44bea..55edac2a27e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qq6-rp62-86qv/GHSA-8qq6-rp62-86qv.json +++ b/advisories/unreviewed/2022/05/GHSA-8qq6-rp62-86qv/GHSA-8qq6-rp62-86qv.json @@ -7,12 +7,8 @@ "CVE-2021-39539" ], "details": "An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::BDCNode::~BDCNode() located in bdcnode.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qwx-m7r4-3mmg/GHSA-8qwx-m7r4-3mmg.json b/advisories/unreviewed/2022/05/GHSA-8qwx-m7r4-3mmg/GHSA-8qwx-m7r4-3mmg.json index 0e7ac66fc75..6a06d0df6f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qwx-m7r4-3mmg/GHSA-8qwx-m7r4-3mmg.json +++ b/advisories/unreviewed/2022/05/GHSA-8qwx-m7r4-3mmg/GHSA-8qwx-m7r4-3mmg.json @@ -7,12 +7,8 @@ "CVE-2005-4517" ], "details": "SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratings parameter in multiple scripts, such as ratings_include.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r5x-26x3-9q3c/GHSA-8r5x-26x3-9q3c.json b/advisories/unreviewed/2022/05/GHSA-8r5x-26x3-9q3c/GHSA-8r5x-26x3-9q3c.json index 19c18d67c02..a935b47f940 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r5x-26x3-9q3c/GHSA-8r5x-26x3-9q3c.json +++ b/advisories/unreviewed/2022/05/GHSA-8r5x-26x3-9q3c/GHSA-8r5x-26x3-9q3c.json @@ -7,12 +7,8 @@ "CVE-2005-4702" ], "details": "SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, the demonstration code as used by third parties suggests that this might be a different type of vulnerability related to shell metacharacters. Finally, this could be a rediscovery of CVE-2004-1430.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v6f-rm23-9f27/GHSA-8v6f-rm23-9f27.json b/advisories/unreviewed/2022/05/GHSA-8v6f-rm23-9f27/GHSA-8v6f-rm23-9f27.json index 0a1f01c3603..8a6c3202f87 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v6f-rm23-9f27/GHSA-8v6f-rm23-9f27.json +++ b/advisories/unreviewed/2022/05/GHSA-8v6f-rm23-9f27/GHSA-8v6f-rm23-9f27.json @@ -7,12 +7,8 @@ "CVE-2005-4580" ], "details": "Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8vg7-hm2j-f2h5/GHSA-8vg7-hm2j-f2h5.json b/advisories/unreviewed/2022/05/GHSA-8vg7-hm2j-f2h5/GHSA-8vg7-hm2j-f2h5.json index 053b15e8ac6..afea1c142ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vg7-hm2j-f2h5/GHSA-8vg7-hm2j-f2h5.json +++ b/advisories/unreviewed/2022/05/GHSA-8vg7-hm2j-f2h5/GHSA-8vg7-hm2j-f2h5.json @@ -7,12 +7,8 @@ "CVE-2005-4869" ], "details": "The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wgc-q9r2-hg5h/GHSA-8wgc-q9r2-hg5h.json b/advisories/unreviewed/2022/05/GHSA-8wgc-q9r2-hg5h/GHSA-8wgc-q9r2-hg5h.json index 8adb7c86db9..e684ba860a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wgc-q9r2-hg5h/GHSA-8wgc-q9r2-hg5h.json +++ b/advisories/unreviewed/2022/05/GHSA-8wgc-q9r2-hg5h/GHSA-8wgc-q9r2-hg5h.json @@ -7,12 +7,8 @@ "CVE-2021-24597" ], "details": "The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x7v-m8hq-cc5h/GHSA-8x7v-m8hq-cc5h.json b/advisories/unreviewed/2022/05/GHSA-8x7v-m8hq-cc5h/GHSA-8x7v-m8hq-cc5h.json index 16a3e24e1ca..85c620432ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x7v-m8hq-cc5h/GHSA-8x7v-m8hq-cc5h.json +++ b/advisories/unreviewed/2022/05/GHSA-8x7v-m8hq-cc5h/GHSA-8x7v-m8hq-cc5h.json @@ -7,12 +7,8 @@ "CVE-2005-4574" ], "details": "Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xgg-3858-cfqw/GHSA-8xgg-3858-cfqw.json b/advisories/unreviewed/2022/05/GHSA-8xgg-3858-cfqw/GHSA-8xgg-3858-cfqw.json index 547f04d3bda..50cfe94c84b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xgg-3858-cfqw/GHSA-8xgg-3858-cfqw.json +++ b/advisories/unreviewed/2022/05/GHSA-8xgg-3858-cfqw/GHSA-8xgg-3858-cfqw.json @@ -7,12 +7,8 @@ "CVE-2005-4758" ], "details": "Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an \"internal servlet\" accessed through HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-922q-4mg4-99r8/GHSA-922q-4mg4-99r8.json b/advisories/unreviewed/2022/05/GHSA-922q-4mg4-99r8/GHSA-922q-4mg4-99r8.json index 875e4cee609..40bf08a336a 100644 --- a/advisories/unreviewed/2022/05/GHSA-922q-4mg4-99r8/GHSA-922q-4mg4-99r8.json +++ b/advisories/unreviewed/2022/05/GHSA-922q-4mg4-99r8/GHSA-922q-4mg4-99r8.json @@ -7,12 +7,8 @@ "CVE-2021-32289" ], "details": "An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-928h-wr4w-h6r7/GHSA-928h-wr4w-h6r7.json b/advisories/unreviewed/2022/05/GHSA-928h-wr4w-h6r7/GHSA-928h-wr4w-h6r7.json index edceac77983..eb0b2216bf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-928h-wr4w-h6r7/GHSA-928h-wr4w-h6r7.json +++ b/advisories/unreviewed/2022/05/GHSA-928h-wr4w-h6r7/GHSA-928h-wr4w-h6r7.json @@ -7,12 +7,8 @@ "CVE-2005-4883" ], "details": "Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid \"connect frames.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92gc-4r2j-hf7p/GHSA-92gc-4r2j-hf7p.json b/advisories/unreviewed/2022/05/GHSA-92gc-4r2j-hf7p/GHSA-92gc-4r2j-hf7p.json index 975ab4baf64..81472f97ec5 100644 --- a/advisories/unreviewed/2022/05/GHSA-92gc-4r2j-hf7p/GHSA-92gc-4r2j-hf7p.json +++ b/advisories/unreviewed/2022/05/GHSA-92gc-4r2j-hf7p/GHSA-92gc-4r2j-hf7p.json @@ -7,12 +7,8 @@ "CVE-2021-39551" ], "details": "An issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92h7-3mpg-68jh/GHSA-92h7-3mpg-68jh.json b/advisories/unreviewed/2022/05/GHSA-92h7-3mpg-68jh/GHSA-92h7-3mpg-68jh.json index a551c5ede64..2b920cdf67a 100644 --- a/advisories/unreviewed/2022/05/GHSA-92h7-3mpg-68jh/GHSA-92h7-3mpg-68jh.json +++ b/advisories/unreviewed/2022/05/GHSA-92h7-3mpg-68jh/GHSA-92h7-3mpg-68jh.json @@ -7,12 +7,8 @@ "CVE-2021-30137" ], "details": "Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9365-9qh8-mwx7/GHSA-9365-9qh8-mwx7.json b/advisories/unreviewed/2022/05/GHSA-9365-9qh8-mwx7/GHSA-9365-9qh8-mwx7.json index 7e8447072bb..89e4fec4245 100644 --- a/advisories/unreviewed/2022/05/GHSA-9365-9qh8-mwx7/GHSA-9365-9qh8-mwx7.json +++ b/advisories/unreviewed/2022/05/GHSA-9365-9qh8-mwx7/GHSA-9365-9qh8-mwx7.json @@ -7,12 +7,8 @@ "CVE-2021-32999" ], "details": "Improper handling of exceptional conditions in SuiteLink server while processing command 0x01", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93hf-xxfj-6gx3/GHSA-93hf-xxfj-6gx3.json b/advisories/unreviewed/2022/05/GHSA-93hf-xxfj-6gx3/GHSA-93hf-xxfj-6gx3.json index a70bc794a7b..b883dbb2ff7 100644 --- a/advisories/unreviewed/2022/05/GHSA-93hf-xxfj-6gx3/GHSA-93hf-xxfj-6gx3.json +++ b/advisories/unreviewed/2022/05/GHSA-93hf-xxfj-6gx3/GHSA-93hf-xxfj-6gx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93mr-rvw5-gvpp/GHSA-93mr-rvw5-gvpp.json b/advisories/unreviewed/2022/05/GHSA-93mr-rvw5-gvpp/GHSA-93mr-rvw5-gvpp.json index b4c37593ef9..dedf70a1e20 100644 --- a/advisories/unreviewed/2022/05/GHSA-93mr-rvw5-gvpp/GHSA-93mr-rvw5-gvpp.json +++ b/advisories/unreviewed/2022/05/GHSA-93mr-rvw5-gvpp/GHSA-93mr-rvw5-gvpp.json @@ -7,12 +7,8 @@ "CVE-2005-4402" ], "details": "Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary code via a long IMAP EXAMINE command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-952f-vp9j-ch94/GHSA-952f-vp9j-ch94.json b/advisories/unreviewed/2022/05/GHSA-952f-vp9j-ch94/GHSA-952f-vp9j-ch94.json index 9990ace42be..5062e37b093 100644 --- a/advisories/unreviewed/2022/05/GHSA-952f-vp9j-ch94/GHSA-952f-vp9j-ch94.json +++ b/advisories/unreviewed/2022/05/GHSA-952f-vp9j-ch94/GHSA-952f-vp9j-ch94.json @@ -7,12 +7,8 @@ "CVE-2005-4746" ], "details": "Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter module or (2) unknown vectors \"while expanding %t\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-956q-95gc-c8rv/GHSA-956q-95gc-c8rv.json b/advisories/unreviewed/2022/05/GHSA-956q-95gc-c8rv/GHSA-956q-95gc-c8rv.json index 32e106fbd9b..4deb0226375 100644 --- a/advisories/unreviewed/2022/05/GHSA-956q-95gc-c8rv/GHSA-956q-95gc-c8rv.json +++ b/advisories/unreviewed/2022/05/GHSA-956q-95gc-c8rv/GHSA-956q-95gc-c8rv.json @@ -7,12 +7,8 @@ "CVE-2005-4566" ], "details": "Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95f3-ph23-r8xm/GHSA-95f3-ph23-r8xm.json b/advisories/unreviewed/2022/05/GHSA-95f3-ph23-r8xm/GHSA-95f3-ph23-r8xm.json index 5f9642e62d4..e94e10172a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-95f3-ph23-r8xm/GHSA-95f3-ph23-r8xm.json +++ b/advisories/unreviewed/2022/05/GHSA-95f3-ph23-r8xm/GHSA-95f3-ph23-r8xm.json @@ -7,12 +7,8 @@ "CVE-2005-4490" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95jv-r6j9-p8xr/GHSA-95jv-r6j9-p8xr.json b/advisories/unreviewed/2022/05/GHSA-95jv-r6j9-p8xr/GHSA-95jv-r6j9-p8xr.json index 5570f779e2b..819cd61b886 100644 --- a/advisories/unreviewed/2022/05/GHSA-95jv-r6j9-p8xr/GHSA-95jv-r6j9-p8xr.json +++ b/advisories/unreviewed/2022/05/GHSA-95jv-r6j9-p8xr/GHSA-95jv-r6j9-p8xr.json @@ -7,12 +7,8 @@ "CVE-2021-41316" ], "details": "The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96fj-j48j-g393/GHSA-96fj-j48j-g393.json b/advisories/unreviewed/2022/05/GHSA-96fj-j48j-g393/GHSA-96fj-j48j-g393.json index ebb5329f7aa..c8744bb1142 100644 --- a/advisories/unreviewed/2022/05/GHSA-96fj-j48j-g393/GHSA-96fj-j48j-g393.json +++ b/advisories/unreviewed/2022/05/GHSA-96fj-j48j-g393/GHSA-96fj-j48j-g393.json @@ -7,12 +7,8 @@ "CVE-2005-4563" ], "details": "SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96x7-cmg8-h727/GHSA-96x7-cmg8-h727.json b/advisories/unreviewed/2022/05/GHSA-96x7-cmg8-h727/GHSA-96x7-cmg8-h727.json index e78bd1fd622..fb917356924 100644 --- a/advisories/unreviewed/2022/05/GHSA-96x7-cmg8-h727/GHSA-96x7-cmg8-h727.json +++ b/advisories/unreviewed/2022/05/GHSA-96x7-cmg8-h727/GHSA-96x7-cmg8-h727.json @@ -7,12 +7,8 @@ "CVE-2005-4809" ], "details": "Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96xp-3qc9-8xh8/GHSA-96xp-3qc9-8xh8.json b/advisories/unreviewed/2022/05/GHSA-96xp-3qc9-8xh8/GHSA-96xp-3qc9-8xh8.json index 2b868786a38..0ac24872a12 100644 --- a/advisories/unreviewed/2022/05/GHSA-96xp-3qc9-8xh8/GHSA-96xp-3qc9-8xh8.json +++ b/advisories/unreviewed/2022/05/GHSA-96xp-3qc9-8xh8/GHSA-96xp-3qc9-8xh8.json @@ -7,12 +7,8 @@ "CVE-2005-4861" ], "details": "functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing \"/login.php\" PHP_SELF value, which is not properly handled by the CHECK_AUTH function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9772-8vcx-jgfq/GHSA-9772-8vcx-jgfq.json b/advisories/unreviewed/2022/05/GHSA-9772-8vcx-jgfq/GHSA-9772-8vcx-jgfq.json index 0a1f869a042..f5090a23a3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9772-8vcx-jgfq/GHSA-9772-8vcx-jgfq.json +++ b/advisories/unreviewed/2022/05/GHSA-9772-8vcx-jgfq/GHSA-9772-8vcx-jgfq.json @@ -7,12 +7,8 @@ "CVE-2005-4510" ], "details": "Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via \"../\" sequences in the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-984p-q7w5-xvvg/GHSA-984p-q7w5-xvvg.json b/advisories/unreviewed/2022/05/GHSA-984p-q7w5-xvvg/GHSA-984p-q7w5-xvvg.json index 6a860f1ed95..531de7056c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-984p-q7w5-xvvg/GHSA-984p-q7w5-xvvg.json +++ b/advisories/unreviewed/2022/05/GHSA-984p-q7w5-xvvg/GHSA-984p-q7w5-xvvg.json @@ -7,12 +7,8 @@ "CVE-2005-4738" ], "details": "IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98pm-v23p-r2wf/GHSA-98pm-v23p-r2wf.json b/advisories/unreviewed/2022/05/GHSA-98pm-v23p-r2wf/GHSA-98pm-v23p-r2wf.json index cc6ff28e346..5a3e50ee9ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-98pm-v23p-r2wf/GHSA-98pm-v23p-r2wf.json +++ b/advisories/unreviewed/2022/05/GHSA-98pm-v23p-r2wf/GHSA-98pm-v23p-r2wf.json @@ -7,12 +7,8 @@ "CVE-2021-27391" ], "details": "A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-996c-c433-w68x/GHSA-996c-c433-w68x.json b/advisories/unreviewed/2022/05/GHSA-996c-c433-w68x/GHSA-996c-c433-w68x.json index 939807c6e90..c03058d07a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-996c-c433-w68x/GHSA-996c-c433-w68x.json +++ b/advisories/unreviewed/2022/05/GHSA-996c-c433-w68x/GHSA-996c-c433-w68x.json @@ -7,12 +7,8 @@ "CVE-2021-38330" ], "details": "The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-998v-vqg2-r4wf/GHSA-998v-vqg2-r4wf.json b/advisories/unreviewed/2022/05/GHSA-998v-vqg2-r4wf/GHSA-998v-vqg2-r4wf.json index d85cd6cf5fd..27c7ec51cee 100644 --- a/advisories/unreviewed/2022/05/GHSA-998v-vqg2-r4wf/GHSA-998v-vqg2-r4wf.json +++ b/advisories/unreviewed/2022/05/GHSA-998v-vqg2-r4wf/GHSA-998v-vqg2-r4wf.json @@ -7,12 +7,8 @@ "CVE-2021-32283" ], "details": "An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function gravity_string_to_value() located in gravity_value.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9ccq-3mj2-hjgm/GHSA-9ccq-3mj2-hjgm.json b/advisories/unreviewed/2022/05/GHSA-9ccq-3mj2-hjgm/GHSA-9ccq-3mj2-hjgm.json index a0f74e7f66a..5b5bba771ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ccq-3mj2-hjgm/GHSA-9ccq-3mj2-hjgm.json +++ b/advisories/unreviewed/2022/05/GHSA-9ccq-3mj2-hjgm/GHSA-9ccq-3mj2-hjgm.json @@ -7,12 +7,8 @@ "CVE-2005-4629" ], "details": "SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9chm-qgqp-3whh/GHSA-9chm-qgqp-3whh.json b/advisories/unreviewed/2022/05/GHSA-9chm-qgqp-3whh/GHSA-9chm-qgqp-3whh.json index 483c106e3c2..83c99c75052 100644 --- a/advisories/unreviewed/2022/05/GHSA-9chm-qgqp-3whh/GHSA-9chm-qgqp-3whh.json +++ b/advisories/unreviewed/2022/05/GHSA-9chm-qgqp-3whh/GHSA-9chm-qgqp-3whh.json @@ -7,12 +7,8 @@ "CVE-2005-4895" ], "details": "Multiple integer overflows in TCMalloc (tcmalloc.cc) in gperftools before 0.4 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fcg-r3gc-jvhf/GHSA-9fcg-r3gc-jvhf.json b/advisories/unreviewed/2022/05/GHSA-9fcg-r3gc-jvhf/GHSA-9fcg-r3gc-jvhf.json index 9a1d1aea352..fbb87b625db 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fcg-r3gc-jvhf/GHSA-9fcg-r3gc-jvhf.json +++ b/advisories/unreviewed/2022/05/GHSA-9fcg-r3gc-jvhf/GHSA-9fcg-r3gc-jvhf.json @@ -7,12 +7,8 @@ "CVE-2020-14119" ], "details": "There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g2p-74g4-rgg6/GHSA-9g2p-74g4-rgg6.json b/advisories/unreviewed/2022/05/GHSA-9g2p-74g4-rgg6/GHSA-9g2p-74g4-rgg6.json index dcba4f8143c..29832a0dbc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g2p-74g4-rgg6/GHSA-9g2p-74g4-rgg6.json +++ b/advisories/unreviewed/2022/05/GHSA-9g2p-74g4-rgg6/GHSA-9g2p-74g4-rgg6.json @@ -7,12 +7,8 @@ "CVE-2005-4484" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9g3f-pc53-92m7/GHSA-9g3f-pc53-92m7.json b/advisories/unreviewed/2022/05/GHSA-9g3f-pc53-92m7/GHSA-9g3f-pc53-92m7.json index e56802b1036..c0c850dbe20 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g3f-pc53-92m7/GHSA-9g3f-pc53-92m7.json +++ b/advisories/unreviewed/2022/05/GHSA-9g3f-pc53-92m7/GHSA-9g3f-pc53-92m7.json @@ -7,12 +7,8 @@ "CVE-2005-4441" ], "details": "The PVLAN protocol allows remote attackers to bypass network segmentation and spoof PVLAN traffic via a PVLAN message with a target MAC address that is set to a gateway router, which causes the packet to be sent to the router, where the source MAC is modified, aka \"Modification of the MAC spoofing PVLAN jumping attack,\" as demonstrated by pvlan.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9g4w-cm4c-cch5/GHSA-9g4w-cm4c-cch5.json b/advisories/unreviewed/2022/05/GHSA-9g4w-cm4c-cch5/GHSA-9g4w-cm4c-cch5.json index f241ad96c87..31c261dcb1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g4w-cm4c-cch5/GHSA-9g4w-cm4c-cch5.json +++ b/advisories/unreviewed/2022/05/GHSA-9g4w-cm4c-cch5/GHSA-9g4w-cm4c-cch5.json @@ -7,12 +7,8 @@ "CVE-2005-4888" ], "details": "NWFTPD.nlm before 5.06.04 in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (excessive stale connections) by establishing many FTP sessions, which persist in the Not-Logged-In state after each session is completed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gg2-729j-q89w/GHSA-9gg2-729j-q89w.json b/advisories/unreviewed/2022/05/GHSA-9gg2-729j-q89w/GHSA-9gg2-729j-q89w.json index 3cd2108dd96..931306a757c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gg2-729j-q89w/GHSA-9gg2-729j-q89w.json +++ b/advisories/unreviewed/2022/05/GHSA-9gg2-729j-q89w/GHSA-9gg2-729j-q89w.json @@ -7,12 +7,8 @@ "CVE-2021-29813" ], "details": "IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204331.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gj7-rxj4-7x46/GHSA-9gj7-rxj4-7x46.json b/advisories/unreviewed/2022/05/GHSA-9gj7-rxj4-7x46/GHSA-9gj7-rxj4-7x46.json index 6ac26933c0c..df9584a6d27 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gj7-rxj4-7x46/GHSA-9gj7-rxj4-7x46.json +++ b/advisories/unreviewed/2022/05/GHSA-9gj7-rxj4-7x46/GHSA-9gj7-rxj4-7x46.json @@ -7,12 +7,8 @@ "CVE-2005-4710" ], "details": "Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to \"gain inappropriate access to another local user's computer,\" aka ID DL5549329.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gpc-v9qx-3jf7/GHSA-9gpc-v9qx-3jf7.json b/advisories/unreviewed/2022/05/GHSA-9gpc-v9qx-3jf7/GHSA-9gpc-v9qx-3jf7.json index c3d9e55cd68..3c3347f959e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gpc-v9qx-3jf7/GHSA-9gpc-v9qx-3jf7.json +++ b/advisories/unreviewed/2022/05/GHSA-9gpc-v9qx-3jf7/GHSA-9gpc-v9qx-3jf7.json @@ -7,12 +7,8 @@ "CVE-2005-4683" ], "details": "PADL MigrationTools 46, when a failure occurs, stores contents of /etc/shadow in a world-readable /tmp/nis.$$.ldif file, and possibly other sensitive information in other temporary files, which are not properly managed by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migrate_all_netinfo_online.sh, (4) migrate_all_netinfo_offline.sh, (5) migrate_all_nis_online.sh, (6) migrate_all_nis_offline.sh, (7) migrate_all_nisplus_online.sh, and (8) migrate_all_nisplus_offline.sh.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jjv-5r68-g5hv/GHSA-9jjv-5r68-g5hv.json b/advisories/unreviewed/2022/05/GHSA-9jjv-5r68-g5hv/GHSA-9jjv-5r68-g5hv.json index d1ed145a8be..e7d9a63c17f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jjv-5r68-g5hv/GHSA-9jjv-5r68-g5hv.json +++ b/advisories/unreviewed/2022/05/GHSA-9jjv-5r68-g5hv/GHSA-9jjv-5r68-g5hv.json @@ -7,12 +7,8 @@ "CVE-2005-4794" ], "details": "Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9m7h-2ggv-4q9j/GHSA-9m7h-2ggv-4q9j.json b/advisories/unreviewed/2022/05/GHSA-9m7h-2ggv-4q9j/GHSA-9m7h-2ggv-4q9j.json index 883e4d9afb8..d9029b9164d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m7h-2ggv-4q9j/GHSA-9m7h-2ggv-4q9j.json +++ b/advisories/unreviewed/2022/05/GHSA-9m7h-2ggv-4q9j/GHSA-9m7h-2ggv-4q9j.json @@ -7,12 +7,8 @@ "CVE-2005-4659" ], "details": "IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by \"nobody\", then executing ipcoprscfg to restore from this backup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mm4-3grj-7cx7/GHSA-9mm4-3grj-7cx7.json b/advisories/unreviewed/2022/05/GHSA-9mm4-3grj-7cx7/GHSA-9mm4-3grj-7cx7.json index 9e0812c33ea..73ebc95d438 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mm4-3grj-7cx7/GHSA-9mm4-3grj-7cx7.json +++ b/advisories/unreviewed/2022/05/GHSA-9mm4-3grj-7cx7/GHSA-9mm4-3grj-7cx7.json @@ -7,12 +7,8 @@ "CVE-2005-4463" ], "details": "WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p3h-4f9c-6m6g/GHSA-9p3h-4f9c-6m6g.json b/advisories/unreviewed/2022/05/GHSA-9p3h-4f9c-6m6g/GHSA-9p3h-4f9c-6m6g.json index a44c0b109e5..5d8a2ca6a91 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p3h-4f9c-6m6g/GHSA-9p3h-4f9c-6m6g.json +++ b/advisories/unreviewed/2022/05/GHSA-9p3h-4f9c-6m6g/GHSA-9p3h-4f9c-6m6g.json @@ -7,12 +7,8 @@ "CVE-2005-4489" ], "details": "Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p5h-3x6c-gqmv/GHSA-9p5h-3x6c-gqmv.json b/advisories/unreviewed/2022/05/GHSA-9p5h-3x6c-gqmv/GHSA-9p5h-3x6c-gqmv.json index 5743775192b..c27954dce3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p5h-3x6c-gqmv/GHSA-9p5h-3x6c-gqmv.json +++ b/advisories/unreviewed/2022/05/GHSA-9p5h-3x6c-gqmv/GHSA-9p5h-3x6c-gqmv.json @@ -7,12 +7,8 @@ "CVE-2005-4519" ], "details": "Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prefix and (2) sort parameters to the manage user page (manage_user_page.php), or (3) the sort parameter to view_all_set.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pf3-6896-gpp9/GHSA-9pf3-6896-gpp9.json b/advisories/unreviewed/2022/05/GHSA-9pf3-6896-gpp9/GHSA-9pf3-6896-gpp9.json index 51b16a081ab..ac9c117d23c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pf3-6896-gpp9/GHSA-9pf3-6896-gpp9.json +++ b/advisories/unreviewed/2022/05/GHSA-9pf3-6896-gpp9/GHSA-9pf3-6896-gpp9.json @@ -7,12 +7,8 @@ "CVE-2020-19158" ], "details": "Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pp6-qvvr-7j96/GHSA-9pp6-qvvr-7j96.json b/advisories/unreviewed/2022/05/GHSA-9pp6-qvvr-7j96/GHSA-9pp6-qvvr-7j96.json index 84b4276a796..ec0437c08bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pp6-qvvr-7j96/GHSA-9pp6-qvvr-7j96.json +++ b/advisories/unreviewed/2022/05/GHSA-9pp6-qvvr-7j96/GHSA-9pp6-qvvr-7j96.json @@ -7,12 +7,8 @@ "CVE-2005-4678" ], "details": "Apple Safari 2.0.2 (aka 416.12) allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pxv-cmxv-m9xh/GHSA-9pxv-cmxv-m9xh.json b/advisories/unreviewed/2022/05/GHSA-9pxv-cmxv-m9xh/GHSA-9pxv-cmxv-m9xh.json index b28d006c2f1..ff5e89ebb31 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pxv-cmxv-m9xh/GHSA-9pxv-cmxv-m9xh.json +++ b/advisories/unreviewed/2022/05/GHSA-9pxv-cmxv-m9xh/GHSA-9pxv-cmxv-m9xh.json @@ -7,12 +7,8 @@ "CVE-2021-38334" ], "details": "The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q47-75mf-qmf9/GHSA-9q47-75mf-qmf9.json b/advisories/unreviewed/2022/05/GHSA-9q47-75mf-qmf9/GHSA-9q47-75mf-qmf9.json index f292db16db3..313740712e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q47-75mf-qmf9/GHSA-9q47-75mf-qmf9.json +++ b/advisories/unreviewed/2022/05/GHSA-9q47-75mf-qmf9/GHSA-9q47-75mf-qmf9.json @@ -7,12 +7,8 @@ "CVE-2021-41383" ], "details": "setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qcg-p796-2q2v/GHSA-9qcg-p796-2q2v.json b/advisories/unreviewed/2022/05/GHSA-9qcg-p796-2q2v/GHSA-9qcg-p796-2q2v.json index b259552d835..74588854de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qcg-p796-2q2v/GHSA-9qcg-p796-2q2v.json +++ b/advisories/unreviewed/2022/05/GHSA-9qcg-p796-2q2v/GHSA-9qcg-p796-2q2v.json @@ -7,12 +7,8 @@ "CVE-2021-23031" ], "details": "On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, an authenticated user may perform a privilege escalation on the BIG-IP Advanced WAF and ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rvj-pj6p-4pj6/GHSA-9rvj-pj6p-4pj6.json b/advisories/unreviewed/2022/05/GHSA-9rvj-pj6p-4pj6/GHSA-9rvj-pj6p-4pj6.json index 3f5a54ed5cf..7b23c5c1815 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rvj-pj6p-4pj6/GHSA-9rvj-pj6p-4pj6.json +++ b/advisories/unreviewed/2022/05/GHSA-9rvj-pj6p-4pj6/GHSA-9rvj-pj6p-4pj6.json @@ -7,12 +7,8 @@ "CVE-2005-4440" ], "details": "The 802.1q VLAN protocol allows remote attackers to bypass network segmentation and spoof VLAN traffic via a message with two 802.1q tags, which causes the second tag to be redirected from a downstream switch after the first tag has been stripped, as demonstrated by Yersinia, aka \"double-tagging VLAN jumping attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vjq-3gv6-2pf3/GHSA-9vjq-3gv6-2pf3.json b/advisories/unreviewed/2022/05/GHSA-9vjq-3gv6-2pf3/GHSA-9vjq-3gv6-2pf3.json index da239b62505..84eb1485c72 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vjq-3gv6-2pf3/GHSA-9vjq-3gv6-2pf3.json +++ b/advisories/unreviewed/2022/05/GHSA-9vjq-3gv6-2pf3/GHSA-9vjq-3gv6-2pf3.json @@ -7,12 +7,8 @@ "CVE-2005-4423" ], "details": "Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka \"upload phpshell.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vv6-3gx7-ppxv/GHSA-9vv6-3gx7-ppxv.json b/advisories/unreviewed/2022/05/GHSA-9vv6-3gx7-ppxv/GHSA-9vv6-3gx7-ppxv.json index adc578d2891..de33dec501f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vv6-3gx7-ppxv/GHSA-9vv6-3gx7-ppxv.json +++ b/advisories/unreviewed/2022/05/GHSA-9vv6-3gx7-ppxv/GHSA-9vv6-3gx7-ppxv.json @@ -7,12 +7,8 @@ "CVE-2005-4729" ], "details": "SQL injection vulnerability in show.php in VBZooM Forum allows remote attackers to execute arbitrary SQL commands via the SubjectID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json b/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json index 2fe98525431..a381ed81dce 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json +++ b/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wv9-vhvp-xjxr/GHSA-9wv9-vhvp-xjxr.json b/advisories/unreviewed/2022/05/GHSA-9wv9-vhvp-xjxr/GHSA-9wv9-vhvp-xjxr.json index 889ccb37a0e..4773cc8ffd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wv9-vhvp-xjxr/GHSA-9wv9-vhvp-xjxr.json +++ b/advisories/unreviewed/2022/05/GHSA-9wv9-vhvp-xjxr/GHSA-9wv9-vhvp-xjxr.json @@ -7,12 +7,8 @@ "CVE-2021-37912" ], "details": "The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c24v-xf6x-r8cc/GHSA-c24v-xf6x-r8cc.json b/advisories/unreviewed/2022/05/GHSA-c24v-xf6x-r8cc/GHSA-c24v-xf6x-r8cc.json index ef8230a0991..7ebbbc63181 100644 --- a/advisories/unreviewed/2022/05/GHSA-c24v-xf6x-r8cc/GHSA-c24v-xf6x-r8cc.json +++ b/advisories/unreviewed/2022/05/GHSA-c24v-xf6x-r8cc/GHSA-c24v-xf6x-r8cc.json @@ -7,12 +7,8 @@ "CVE-2005-4618" ], "details": "Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c25g-j43f-w7p8/GHSA-c25g-j43f-w7p8.json b/advisories/unreviewed/2022/05/GHSA-c25g-j43f-w7p8/GHSA-c25g-j43f-w7p8.json index 2ea88d2fae8..54231b9e97a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c25g-j43f-w7p8/GHSA-c25g-j43f-w7p8.json +++ b/advisories/unreviewed/2022/05/GHSA-c25g-j43f-w7p8/GHSA-c25g-j43f-w7p8.json @@ -7,12 +7,8 @@ "CVE-2005-4827" ], "details": "Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces. NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2qg-83f7-xwcm/GHSA-c2qg-83f7-xwcm.json b/advisories/unreviewed/2022/05/GHSA-c2qg-83f7-xwcm/GHSA-c2qg-83f7-xwcm.json index 53cb4633505..afce73e61fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2qg-83f7-xwcm/GHSA-c2qg-83f7-xwcm.json +++ b/advisories/unreviewed/2022/05/GHSA-c2qg-83f7-xwcm/GHSA-c2qg-83f7-xwcm.json @@ -7,12 +7,8 @@ "CVE-2021-22524" ], "details": "Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c43r-86m8-rvrg/GHSA-c43r-86m8-rvrg.json b/advisories/unreviewed/2022/05/GHSA-c43r-86m8-rvrg/GHSA-c43r-86m8-rvrg.json index ce188155fe1..60a9c45f4e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-c43r-86m8-rvrg/GHSA-c43r-86m8-rvrg.json +++ b/advisories/unreviewed/2022/05/GHSA-c43r-86m8-rvrg/GHSA-c43r-86m8-rvrg.json @@ -7,12 +7,8 @@ "CVE-2020-21121" ], "details": "Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4jw-7285-v92g/GHSA-c4jw-7285-v92g.json b/advisories/unreviewed/2022/05/GHSA-c4jw-7285-v92g/GHSA-c4jw-7285-v92g.json index 338c6669e8b..805c45977a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4jw-7285-v92g/GHSA-c4jw-7285-v92g.json +++ b/advisories/unreviewed/2022/05/GHSA-c4jw-7285-v92g/GHSA-c4jw-7285-v92g.json @@ -7,12 +7,8 @@ "CVE-2021-38341" ], "details": "The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4rx-6458-242x/GHSA-c4rx-6458-242x.json b/advisories/unreviewed/2022/05/GHSA-c4rx-6458-242x/GHSA-c4rx-6458-242x.json index 3942192cccc..5d3f9e14649 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4rx-6458-242x/GHSA-c4rx-6458-242x.json +++ b/advisories/unreviewed/2022/05/GHSA-c4rx-6458-242x/GHSA-c4rx-6458-242x.json @@ -7,12 +7,8 @@ "CVE-2021-24596" ], "details": "The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4rx-vvj6-9gv8/GHSA-c4rx-vvj6-9gv8.json b/advisories/unreviewed/2022/05/GHSA-c4rx-vvj6-9gv8/GHSA-c4rx-vvj6-9gv8.json index 9d3ccf355c1..7cafafbb05d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4rx-vvj6-9gv8/GHSA-c4rx-vvj6-9gv8.json +++ b/advisories/unreviewed/2022/05/GHSA-c4rx-vvj6-9gv8/GHSA-c4rx-vvj6-9gv8.json @@ -7,12 +7,8 @@ "CVE-2021-33011" ], "details": "All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4xj-f6r4-75xg/GHSA-c4xj-f6r4-75xg.json b/advisories/unreviewed/2022/05/GHSA-c4xj-f6r4-75xg/GHSA-c4xj-f6r4-75xg.json index cd6ed0950d0..a377493a43c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4xj-f6r4-75xg/GHSA-c4xj-f6r4-75xg.json +++ b/advisories/unreviewed/2022/05/GHSA-c4xj-f6r4-75xg/GHSA-c4xj-f6r4-75xg.json @@ -7,12 +7,8 @@ "CVE-2021-39546" ], "details": "An issue was discovered in sela through 20200412. rice::RiceDecoder::process() in rice_decoder.cpp has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4xx-wp4h-934r/GHSA-c4xx-wp4h-934r.json b/advisories/unreviewed/2022/05/GHSA-c4xx-wp4h-934r/GHSA-c4xx-wp4h-934r.json index 2f51a10e2e7..9a745ebaf14 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4xx-wp4h-934r/GHSA-c4xx-wp4h-934r.json +++ b/advisories/unreviewed/2022/05/GHSA-c4xx-wp4h-934r/GHSA-c4xx-wp4h-934r.json @@ -7,12 +7,8 @@ "CVE-2005-4713" ], "details": "Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c568-3m8f-4r27/GHSA-c568-3m8f-4r27.json b/advisories/unreviewed/2022/05/GHSA-c568-3m8f-4r27/GHSA-c568-3m8f-4r27.json index c66663211a6..e9e45961b7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c568-3m8f-4r27/GHSA-c568-3m8f-4r27.json +++ b/advisories/unreviewed/2022/05/GHSA-c568-3m8f-4r27/GHSA-c568-3m8f-4r27.json @@ -7,12 +7,8 @@ "CVE-2005-4672" ], "details": "Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c56g-v92h-6fcq/GHSA-c56g-v92h-6fcq.json b/advisories/unreviewed/2022/05/GHSA-c56g-v92h-6fcq/GHSA-c56g-v92h-6fcq.json index d0b22d60dd3..f8075891013 100644 --- a/advisories/unreviewed/2022/05/GHSA-c56g-v92h-6fcq/GHSA-c56g-v92h-6fcq.json +++ b/advisories/unreviewed/2022/05/GHSA-c56g-v92h-6fcq/GHSA-c56g-v92h-6fcq.json @@ -7,12 +7,8 @@ "CVE-2021-22953" ], "details": "A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: \"Solar Security Research Team\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5c8-g6j3-w28m/GHSA-c5c8-g6j3-w28m.json b/advisories/unreviewed/2022/05/GHSA-c5c8-g6j3-w28m/GHSA-c5c8-g6j3-w28m.json index 0f82efefe20..3937e14ce9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5c8-g6j3-w28m/GHSA-c5c8-g6j3-w28m.json +++ b/advisories/unreviewed/2022/05/GHSA-c5c8-g6j3-w28m/GHSA-c5c8-g6j3-w28m.json @@ -7,12 +7,8 @@ "CVE-2021-3145" ], "details": "In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6fh-hgf3-5q42/GHSA-c6fh-hgf3-5q42.json b/advisories/unreviewed/2022/05/GHSA-c6fh-hgf3-5q42/GHSA-c6fh-hgf3-5q42.json index 79bb66ac7fb..3df089db2a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6fh-hgf3-5q42/GHSA-c6fh-hgf3-5q42.json +++ b/advisories/unreviewed/2022/05/GHSA-c6fh-hgf3-5q42/GHSA-c6fh-hgf3-5q42.json @@ -7,12 +7,8 @@ "CVE-2021-39574" ], "details": "An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function pool_read() located in pool.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6gj-v86g-r7jw/GHSA-c6gj-v86g-r7jw.json b/advisories/unreviewed/2022/05/GHSA-c6gj-v86g-r7jw/GHSA-c6gj-v86g-r7jw.json index ebcd31c5391..afc35e6c592 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6gj-v86g-r7jw/GHSA-c6gj-v86g-r7jw.json +++ b/advisories/unreviewed/2022/05/GHSA-c6gj-v86g-r7jw/GHSA-c6gj-v86g-r7jw.json @@ -7,12 +7,8 @@ "CVE-2006-0047" ], "details": "packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7ph-w6p6-9qr2/GHSA-c7ph-w6p6-9qr2.json b/advisories/unreviewed/2022/05/GHSA-c7ph-w6p6-9qr2/GHSA-c7ph-w6p6-9qr2.json index be963071373..2297e04d15b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7ph-w6p6-9qr2/GHSA-c7ph-w6p6-9qr2.json +++ b/advisories/unreviewed/2022/05/GHSA-c7ph-w6p6-9qr2/GHSA-c7ph-w6p6-9qr2.json @@ -7,12 +7,8 @@ "CVE-2005-4722" ], "details": "_Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c847-r6f2-c2wj/GHSA-c847-r6f2-c2wj.json b/advisories/unreviewed/2022/05/GHSA-c847-r6f2-c2wj/GHSA-c847-r6f2-c2wj.json index 08b427cd627..1f0562a7450 100644 --- a/advisories/unreviewed/2022/05/GHSA-c847-r6f2-c2wj/GHSA-c847-r6f2-c2wj.json +++ b/advisories/unreviewed/2022/05/GHSA-c847-r6f2-c2wj/GHSA-c847-r6f2-c2wj.json @@ -7,12 +7,8 @@ "CVE-2021-24724" ], "details": "The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c888-5pj4-79hc/GHSA-c888-5pj4-79hc.json b/advisories/unreviewed/2022/05/GHSA-c888-5pj4-79hc/GHSA-c888-5pj4-79hc.json index 92c23b099a8..d986ac1ee05 100644 --- a/advisories/unreviewed/2022/05/GHSA-c888-5pj4-79hc/GHSA-c888-5pj4-79hc.json +++ b/advisories/unreviewed/2022/05/GHSA-c888-5pj4-79hc/GHSA-c888-5pj4-79hc.json @@ -7,12 +7,8 @@ "CVE-2021-30260" ], "details": "Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8mv-2mvj-9jjp/GHSA-c8mv-2mvj-9jjp.json b/advisories/unreviewed/2022/05/GHSA-c8mv-2mvj-9jjp/GHSA-c8mv-2mvj-9jjp.json index 55e12493847..d123c2223c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8mv-2mvj-9jjp/GHSA-c8mv-2mvj-9jjp.json +++ b/advisories/unreviewed/2022/05/GHSA-c8mv-2mvj-9jjp/GHSA-c8mv-2mvj-9jjp.json @@ -7,12 +7,8 @@ "CVE-2005-4756" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multiple PrincipalValidators, which might allow attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8mx-ccv3-h6hj/GHSA-c8mx-ccv3-h6hj.json b/advisories/unreviewed/2022/05/GHSA-c8mx-ccv3-h6hj/GHSA-c8mx-ccv3-h6hj.json index 1a20e3189d4..efaef873457 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8mx-ccv3-h6hj/GHSA-c8mx-ccv3-h6hj.json +++ b/advisories/unreviewed/2022/05/GHSA-c8mx-ccv3-h6hj/GHSA-c8mx-ccv3-h6hj.json @@ -7,12 +7,8 @@ "CVE-2021-39543" ], "details": "An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeRoot() located in analyze.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8q5-wpgp-c3rq/GHSA-c8q5-wpgp-c3rq.json b/advisories/unreviewed/2022/05/GHSA-c8q5-wpgp-c3rq/GHSA-c8q5-wpgp-c3rq.json index eaed9903d74..fd0e92c2cf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8q5-wpgp-c3rq/GHSA-c8q5-wpgp-c3rq.json +++ b/advisories/unreviewed/2022/05/GHSA-c8q5-wpgp-c3rq/GHSA-c8q5-wpgp-c3rq.json @@ -7,12 +7,8 @@ "CVE-2005-4884" ], "details": "Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allows remote authenticated attackers to affect availability via unknown vectors, aka DB02.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c927-pmgv-cmrp/GHSA-c927-pmgv-cmrp.json b/advisories/unreviewed/2022/05/GHSA-c927-pmgv-cmrp/GHSA-c927-pmgv-cmrp.json index 084be5379b7..c62fa66c476 100644 --- a/advisories/unreviewed/2022/05/GHSA-c927-pmgv-cmrp/GHSA-c927-pmgv-cmrp.json +++ b/advisories/unreviewed/2022/05/GHSA-c927-pmgv-cmrp/GHSA-c927-pmgv-cmrp.json @@ -7,12 +7,8 @@ "CVE-2005-4525" ], "details": "SmcGui.exe in Sygate Protection Agent 5.0 build 6144 allows local users to obtain management control over the agent by executing the GUI (SmcGui.exe) and then killing the process, which causes the privileged management GUI to launch.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9cp-98m8-82j9/GHSA-c9cp-98m8-82j9.json b/advisories/unreviewed/2022/05/GHSA-c9cp-98m8-82j9/GHSA-c9cp-98m8-82j9.json index db94f14fcf2..111542d8d40 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9cp-98m8-82j9/GHSA-c9cp-98m8-82j9.json +++ b/advisories/unreviewed/2022/05/GHSA-c9cp-98m8-82j9/GHSA-c9cp-98m8-82j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9wm-g9gh-22c7/GHSA-c9wm-g9gh-22c7.json b/advisories/unreviewed/2022/05/GHSA-c9wm-g9gh-22c7/GHSA-c9wm-g9gh-22c7.json index 065dc09c48b..0dbd4b2b8cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9wm-g9gh-22c7/GHSA-c9wm-g9gh-22c7.json +++ b/advisories/unreviewed/2022/05/GHSA-c9wm-g9gh-22c7/GHSA-c9wm-g9gh-22c7.json @@ -7,12 +7,8 @@ "CVE-2005-4507" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspecified user input fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc2m-g7f7-hrg8/GHSA-cc2m-g7f7-hrg8.json b/advisories/unreviewed/2022/05/GHSA-cc2m-g7f7-hrg8/GHSA-cc2m-g7f7-hrg8.json index 7196b317f7f..a1fbdff92f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc2m-g7f7-hrg8/GHSA-cc2m-g7f7-hrg8.json +++ b/advisories/unreviewed/2022/05/GHSA-cc2m-g7f7-hrg8/GHSA-cc2m-g7f7-hrg8.json @@ -7,12 +7,8 @@ "CVE-2005-4750" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier allow remote attackers to cause a denial of service (server thread hang) via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ccqr-2cf6-h7p3/GHSA-ccqr-2cf6-h7p3.json b/advisories/unreviewed/2022/05/GHSA-ccqr-2cf6-h7p3/GHSA-ccqr-2cf6-h7p3.json index 9a2f2d6a60c..d454268d62c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccqr-2cf6-h7p3/GHSA-ccqr-2cf6-h7p3.json +++ b/advisories/unreviewed/2022/05/GHSA-ccqr-2cf6-h7p3/GHSA-ccqr-2cf6-h7p3.json @@ -7,12 +7,8 @@ "CVE-2021-20434" ], "details": "IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfq8-fj46-w8p7/GHSA-cfq8-fj46-w8p7.json b/advisories/unreviewed/2022/05/GHSA-cfq8-fj46-w8p7/GHSA-cfq8-fj46-w8p7.json index e20f0a3ae92..78312484b2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfq8-fj46-w8p7/GHSA-cfq8-fj46-w8p7.json +++ b/advisories/unreviewed/2022/05/GHSA-cfq8-fj46-w8p7/GHSA-cfq8-fj46-w8p7.json @@ -7,12 +7,8 @@ "CVE-2005-4546" ], "details": "search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch26-285q-m7w2/GHSA-ch26-285q-m7w2.json b/advisories/unreviewed/2022/05/GHSA-ch26-285q-m7w2/GHSA-ch26-285q-m7w2.json index ecf1db420aa..24ec25a20e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch26-285q-m7w2/GHSA-ch26-285q-m7w2.json +++ b/advisories/unreviewed/2022/05/GHSA-ch26-285q-m7w2/GHSA-ch26-285q-m7w2.json @@ -7,12 +7,8 @@ "CVE-2021-31891" ], "details": "A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch32-3mmp-49c5/GHSA-ch32-3mmp-49c5.json b/advisories/unreviewed/2022/05/GHSA-ch32-3mmp-49c5/GHSA-ch32-3mmp-49c5.json index 35574768f66..f0dd5a86a9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch32-3mmp-49c5/GHSA-ch32-3mmp-49c5.json +++ b/advisories/unreviewed/2022/05/GHSA-ch32-3mmp-49c5/GHSA-ch32-3mmp-49c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch42-xc83-q8gr/GHSA-ch42-xc83-q8gr.json b/advisories/unreviewed/2022/05/GHSA-ch42-xc83-q8gr/GHSA-ch42-xc83-q8gr.json index 843df563293..af1d716a066 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch42-xc83-q8gr/GHSA-ch42-xc83-q8gr.json +++ b/advisories/unreviewed/2022/05/GHSA-ch42-xc83-q8gr/GHSA-ch42-xc83-q8gr.json @@ -7,12 +7,8 @@ "CVE-2005-4533" ], "details": "Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via \"getopt\" style argument specifications, which are not filtered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chgv-x7cw-mxj6/GHSA-chgv-x7cw-mxj6.json b/advisories/unreviewed/2022/05/GHSA-chgv-x7cw-mxj6/GHSA-chgv-x7cw-mxj6.json index eafb5bbb6cb..f7cf09fd58f 100644 --- a/advisories/unreviewed/2022/05/GHSA-chgv-x7cw-mxj6/GHSA-chgv-x7cw-mxj6.json +++ b/advisories/unreviewed/2022/05/GHSA-chgv-x7cw-mxj6/GHSA-chgv-x7cw-mxj6.json @@ -7,12 +7,8 @@ "CVE-2005-4421" ], "details": "Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chqg-r7hw-qc9v/GHSA-chqg-r7hw-qc9v.json b/advisories/unreviewed/2022/05/GHSA-chqg-r7hw-qc9v/GHSA-chqg-r7hw-qc9v.json index e22cc799636..4869614496c 100644 --- a/advisories/unreviewed/2022/05/GHSA-chqg-r7hw-qc9v/GHSA-chqg-r7hw-qc9v.json +++ b/advisories/unreviewed/2022/05/GHSA-chqg-r7hw-qc9v/GHSA-chqg-r7hw-qc9v.json @@ -7,12 +7,8 @@ "CVE-2021-39520" ], "details": "An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj95-hc8g-66rx/GHSA-cj95-hc8g-66rx.json b/advisories/unreviewed/2022/05/GHSA-cj95-hc8g-66rx/GHSA-cj95-hc8g-66rx.json index ed44aa0750b..0f1e759b46b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj95-hc8g-66rx/GHSA-cj95-hc8g-66rx.json +++ b/advisories/unreviewed/2022/05/GHSA-cj95-hc8g-66rx/GHSA-cj95-hc8g-66rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmgq-6hm8-g996/GHSA-cmgq-6hm8-g996.json b/advisories/unreviewed/2022/05/GHSA-cmgq-6hm8-g996/GHSA-cmgq-6hm8-g996.json index 135f8a12ac1..c90a562c685 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmgq-6hm8-g996/GHSA-cmgq-6hm8-g996.json +++ b/advisories/unreviewed/2022/05/GHSA-cmgq-6hm8-g996/GHSA-cmgq-6hm8-g996.json @@ -7,12 +7,8 @@ "CVE-2021-24491" ], "details": "The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, attackers could make a logged in administrator delete and upload arbitrary files via a CSRF attack", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cppw-2fwh-6pqg/GHSA-cppw-2fwh-6pqg.json b/advisories/unreviewed/2022/05/GHSA-cppw-2fwh-6pqg/GHSA-cppw-2fwh-6pqg.json index d4490213c0d..1137bb305fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cppw-2fwh-6pqg/GHSA-cppw-2fwh-6pqg.json +++ b/advisories/unreviewed/2022/05/GHSA-cppw-2fwh-6pqg/GHSA-cppw-2fwh-6pqg.json @@ -7,12 +7,8 @@ "CVE-2021-24398" ], "details": "The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpw3-xwrw-grxf/GHSA-cpw3-xwrw-grxf.json b/advisories/unreviewed/2022/05/GHSA-cpw3-xwrw-grxf/GHSA-cpw3-xwrw-grxf.json index 2aa43b54579..0526fbf931f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpw3-xwrw-grxf/GHSA-cpw3-xwrw-grxf.json +++ b/advisories/unreviewed/2022/05/GHSA-cpw3-xwrw-grxf/GHSA-cpw3-xwrw-grxf.json @@ -7,12 +7,8 @@ "CVE-2005-4509" ], "details": "SQL injection vulnerability in index.asp in pTools allows remote attackers to execute arbitrary SQL commands via the docID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq55-rgg6-wm49/GHSA-cq55-rgg6-wm49.json b/advisories/unreviewed/2022/05/GHSA-cq55-rgg6-wm49/GHSA-cq55-rgg6-wm49.json index 7ad6e778c0a..fc33fbdbd16 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq55-rgg6-wm49/GHSA-cq55-rgg6-wm49.json +++ b/advisories/unreviewed/2022/05/GHSA-cq55-rgg6-wm49/GHSA-cq55-rgg6-wm49.json @@ -7,12 +7,8 @@ "CVE-2021-28960" ], "details": "ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqrg-93mv-7q2g/GHSA-cqrg-93mv-7q2g.json b/advisories/unreviewed/2022/05/GHSA-cqrg-93mv-7q2g/GHSA-cqrg-93mv-7q2g.json index a8d55571f18..d14638239da 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqrg-93mv-7q2g/GHSA-cqrg-93mv-7q2g.json +++ b/advisories/unreviewed/2022/05/GHSA-cqrg-93mv-7q2g/GHSA-cqrg-93mv-7q2g.json @@ -7,12 +7,8 @@ "CVE-2020-19290" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqvh-8pgv-w877/GHSA-cqvh-8pgv-w877.json b/advisories/unreviewed/2022/05/GHSA-cqvh-8pgv-w877/GHSA-cqvh-8pgv-w877.json index 2c4397b9872..c94f44c09cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqvh-8pgv-w877/GHSA-cqvh-8pgv-w877.json +++ b/advisories/unreviewed/2022/05/GHSA-cqvh-8pgv-w877/GHSA-cqvh-8pgv-w877.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crpw-9pqh-hv2j/GHSA-crpw-9pqh-hv2j.json b/advisories/unreviewed/2022/05/GHSA-crpw-9pqh-hv2j/GHSA-crpw-9pqh-hv2j.json index b8de51a3d33..07b98308a93 100644 --- a/advisories/unreviewed/2022/05/GHSA-crpw-9pqh-hv2j/GHSA-crpw-9pqh-hv2j.json +++ b/advisories/unreviewed/2022/05/GHSA-crpw-9pqh-hv2j/GHSA-crpw-9pqh-hv2j.json @@ -7,12 +7,8 @@ "CVE-2006-0001" ], "details": "Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f28h-hcxc-r39x/GHSA-f28h-hcxc-r39x.json b/advisories/unreviewed/2022/05/GHSA-f28h-hcxc-r39x/GHSA-f28h-hcxc-r39x.json index 06584ea2af8..112cf9c9c5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f28h-hcxc-r39x/GHSA-f28h-hcxc-r39x.json +++ b/advisories/unreviewed/2022/05/GHSA-f28h-hcxc-r39x/GHSA-f28h-hcxc-r39x.json @@ -7,12 +7,8 @@ "CVE-2020-21124" ], "details": "UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3jw-jgmw-xx5m/GHSA-f3jw-jgmw-xx5m.json b/advisories/unreviewed/2022/05/GHSA-f3jw-jgmw-xx5m/GHSA-f3jw-jgmw-xx5m.json index a08c08b46f7..0c3dcc63687 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3jw-jgmw-xx5m/GHSA-f3jw-jgmw-xx5m.json +++ b/advisories/unreviewed/2022/05/GHSA-f3jw-jgmw-xx5m/GHSA-f3jw-jgmw-xx5m.json @@ -7,12 +7,8 @@ "CVE-2005-4448" ], "details": "FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3wq-6385-xjpf/GHSA-f3wq-6385-xjpf.json b/advisories/unreviewed/2022/05/GHSA-f3wq-6385-xjpf/GHSA-f3wq-6385-xjpf.json index ba82b4780ef..122cc748177 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3wq-6385-xjpf/GHSA-f3wq-6385-xjpf.json +++ b/advisories/unreviewed/2022/05/GHSA-f3wq-6385-xjpf/GHSA-f3wq-6385-xjpf.json @@ -7,12 +7,8 @@ "CVE-2005-4416" ], "details": "SQL injection vulnerability in index.php in TML CMS 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f428-825j-hwjh/GHSA-f428-825j-hwjh.json b/advisories/unreviewed/2022/05/GHSA-f428-825j-hwjh/GHSA-f428-825j-hwjh.json index efd34cd1c3c..ecb3c4e8e62 100644 --- a/advisories/unreviewed/2022/05/GHSA-f428-825j-hwjh/GHSA-f428-825j-hwjh.json +++ b/advisories/unreviewed/2022/05/GHSA-f428-825j-hwjh/GHSA-f428-825j-hwjh.json @@ -7,12 +7,8 @@ "CVE-2005-4668" ], "details": "The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f42x-6gqm-cmqq/GHSA-f42x-6gqm-cmqq.json b/advisories/unreviewed/2022/05/GHSA-f42x-6gqm-cmqq/GHSA-f42x-6gqm-cmqq.json index 6bce06fa936..24dfec78581 100644 --- a/advisories/unreviewed/2022/05/GHSA-f42x-6gqm-cmqq/GHSA-f42x-6gqm-cmqq.json +++ b/advisories/unreviewed/2022/05/GHSA-f42x-6gqm-cmqq/GHSA-f42x-6gqm-cmqq.json @@ -7,12 +7,8 @@ "CVE-2021-33694" ], "details": "SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4g8-f2fm-f5pf/GHSA-f4g8-f2fm-f5pf.json b/advisories/unreviewed/2022/05/GHSA-f4g8-f2fm-f5pf/GHSA-f4g8-f2fm-f5pf.json index 50f75109eb6..372a3226e14 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4g8-f2fm-f5pf/GHSA-f4g8-f2fm-f5pf.json +++ b/advisories/unreviewed/2022/05/GHSA-f4g8-f2fm-f5pf/GHSA-f4g8-f2fm-f5pf.json @@ -7,12 +7,8 @@ "CVE-2021-39592" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in pool.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4g8-pp7p-v4vp/GHSA-f4g8-pp7p-v4vp.json b/advisories/unreviewed/2022/05/GHSA-f4g8-pp7p-v4vp/GHSA-f4g8-pp7p-v4vp.json index 67db0b1a738..86544834caf 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4g8-pp7p-v4vp/GHSA-f4g8-pp7p-v4vp.json +++ b/advisories/unreviewed/2022/05/GHSA-f4g8-pp7p-v4vp/GHSA-f4g8-pp7p-v4vp.json @@ -7,12 +7,8 @@ "CVE-2005-4759" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about platform differences in URLResource case sensitivity, which might cause local users to inadvertently lose protection of Web Application pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4hr-8v6m-mr63/GHSA-f4hr-8v6m-mr63.json b/advisories/unreviewed/2022/05/GHSA-f4hr-8v6m-mr63/GHSA-f4hr-8v6m-mr63.json index ad87a5bd758..34193f124ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4hr-8v6m-mr63/GHSA-f4hr-8v6m-mr63.json +++ b/advisories/unreviewed/2022/05/GHSA-f4hr-8v6m-mr63/GHSA-f4hr-8v6m-mr63.json @@ -7,12 +7,8 @@ "CVE-2020-20896" ], "details": "An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4j9-rcxm-4r4q/GHSA-f4j9-rcxm-4r4q.json b/advisories/unreviewed/2022/05/GHSA-f4j9-rcxm-4r4q/GHSA-f4j9-rcxm-4r4q.json index 236f02fbb83..73efba821ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4j9-rcxm-4r4q/GHSA-f4j9-rcxm-4r4q.json +++ b/advisories/unreviewed/2022/05/GHSA-f4j9-rcxm-4r4q/GHSA-f4j9-rcxm-4r4q.json @@ -7,12 +7,8 @@ "CVE-2005-4640" ], "details": "SQL injection vulnerability in index.php in class-1 Poll Software 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) pollid or (2) previouspoll parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4qf-gvqg-chfr/GHSA-f4qf-gvqg-chfr.json b/advisories/unreviewed/2022/05/GHSA-f4qf-gvqg-chfr/GHSA-f4qf-gvqg-chfr.json index fa1a16932eb..3d7d68c53e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4qf-gvqg-chfr/GHSA-f4qf-gvqg-chfr.json +++ b/advisories/unreviewed/2022/05/GHSA-f4qf-gvqg-chfr/GHSA-f4qf-gvqg-chfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4xr-4383-7g29/GHSA-f4xr-4383-7g29.json b/advisories/unreviewed/2022/05/GHSA-f4xr-4383-7g29/GHSA-f4xr-4383-7g29.json index c5571d8c822..66576f7fbda 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4xr-4383-7g29/GHSA-f4xr-4383-7g29.json +++ b/advisories/unreviewed/2022/05/GHSA-f4xr-4383-7g29/GHSA-f4xr-4383-7g29.json @@ -7,12 +7,8 @@ "CVE-2005-4785" ], "details": "Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author (\"your name\") and (2) \"comment\" section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f557-f73j-r5x2/GHSA-f557-f73j-r5x2.json b/advisories/unreviewed/2022/05/GHSA-f557-f73j-r5x2/GHSA-f557-f73j-r5x2.json index 559428c58c0..288c065cd9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f557-f73j-r5x2/GHSA-f557-f73j-r5x2.json +++ b/advisories/unreviewed/2022/05/GHSA-f557-f73j-r5x2/GHSA-f557-f73j-r5x2.json @@ -7,12 +7,8 @@ "CVE-2021-39544" ], "details": "An issue was discovered in sela through 20200412. file::WavFile::writeToFile() in wav_file.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5pc-r4f6-r2w2/GHSA-f5pc-r4f6-r2w2.json b/advisories/unreviewed/2022/05/GHSA-f5pc-r4f6-r2w2/GHSA-f5pc-r4f6-r2w2.json index 13a6c4d8232..4a15fb54837 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5pc-r4f6-r2w2/GHSA-f5pc-r4f6-r2w2.json +++ b/advisories/unreviewed/2022/05/GHSA-f5pc-r4f6-r2w2/GHSA-f5pc-r4f6-r2w2.json @@ -7,12 +7,8 @@ "CVE-2020-21534" ], "details": "fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f68w-6m4r-r3r6/GHSA-f68w-6m4r-r3r6.json b/advisories/unreviewed/2022/05/GHSA-f68w-6m4r-r3r6/GHSA-f68w-6m4r-r3r6.json index 6dae6b236f2..2861c0238a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f68w-6m4r-r3r6/GHSA-f68w-6m4r-r3r6.json +++ b/advisories/unreviewed/2022/05/GHSA-f68w-6m4r-r3r6/GHSA-f68w-6m4r-r3r6.json @@ -7,12 +7,8 @@ "CVE-2005-4845" ], "details": "The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f69c-x64c-x2rm/GHSA-f69c-x64c-x2rm.json b/advisories/unreviewed/2022/05/GHSA-f69c-x64c-x2rm/GHSA-f69c-x64c-x2rm.json index 3c1fb716ebb..eb5be0fe8ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-f69c-x64c-x2rm/GHSA-f69c-x64c-x2rm.json +++ b/advisories/unreviewed/2022/05/GHSA-f69c-x64c-x2rm/GHSA-f69c-x64c-x2rm.json @@ -7,12 +7,8 @@ "CVE-2021-33698" ], "details": "SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file format validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6c4-jwcc-rf6r/GHSA-f6c4-jwcc-rf6r.json b/advisories/unreviewed/2022/05/GHSA-f6c4-jwcc-rf6r/GHSA-f6c4-jwcc-rf6r.json index 2ea1f628efd..652b5a56519 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6c4-jwcc-rf6r/GHSA-f6c4-jwcc-rf6r.json +++ b/advisories/unreviewed/2022/05/GHSA-f6c4-jwcc-rf6r/GHSA-f6c4-jwcc-rf6r.json @@ -7,12 +7,8 @@ "CVE-2005-4428" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f6cr-f667-v5wq/GHSA-f6cr-f667-v5wq.json b/advisories/unreviewed/2022/05/GHSA-f6cr-f667-v5wq/GHSA-f6cr-f667-v5wq.json index 860554c5e7d..7db15c910d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6cr-f667-v5wq/GHSA-f6cr-f667-v5wq.json +++ b/advisories/unreviewed/2022/05/GHSA-f6cr-f667-v5wq/GHSA-f6cr-f667-v5wq.json @@ -7,12 +7,8 @@ "CVE-2005-4768" ], "details": "SQL injection vulnerability in manage_account.php in Tux Racer TuxBank 0.7x and 0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter in a manageaccount action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7q2-fp95-rjmf/GHSA-f7q2-fp95-rjmf.json b/advisories/unreviewed/2022/05/GHSA-f7q2-fp95-rjmf/GHSA-f7q2-fp95-rjmf.json index 51cbf36e4cf..98be1adffab 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7q2-fp95-rjmf/GHSA-f7q2-fp95-rjmf.json +++ b/advisories/unreviewed/2022/05/GHSA-f7q2-fp95-rjmf/GHSA-f7q2-fp95-rjmf.json @@ -7,12 +7,8 @@ "CVE-2021-37422" ], "details": "Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7vw-gv84-6jmf/GHSA-f7vw-gv84-6jmf.json b/advisories/unreviewed/2022/05/GHSA-f7vw-gv84-6jmf/GHSA-f7vw-gv84-6jmf.json index 61fe80b1bcd..28b2406f959 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7vw-gv84-6jmf/GHSA-f7vw-gv84-6jmf.json +++ b/advisories/unreviewed/2022/05/GHSA-f7vw-gv84-6jmf/GHSA-f7vw-gv84-6jmf.json @@ -7,12 +7,8 @@ "CVE-2005-4586" ], "details": "Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid, (3) lid, (4) gid, and (5) token parameters in certain PHP scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f884-r5wp-g6v3/GHSA-f884-r5wp-g6v3.json b/advisories/unreviewed/2022/05/GHSA-f884-r5wp-g6v3/GHSA-f884-r5wp-g6v3.json index 04946dfac3d..09feec5fc5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f884-r5wp-g6v3/GHSA-f884-r5wp-g6v3.json +++ b/advisories/unreviewed/2022/05/GHSA-f884-r5wp-g6v3/GHSA-f884-r5wp-g6v3.json @@ -7,12 +7,8 @@ "CVE-2005-4807" ], "details": "Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9cc-wx9r-r8gm/GHSA-f9cc-wx9r-r8gm.json b/advisories/unreviewed/2022/05/GHSA-f9cc-wx9r-r8gm/GHSA-f9cc-wx9r-r8gm.json index 480d33cce35..5845122a43d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9cc-wx9r-r8gm/GHSA-f9cc-wx9r-r8gm.json +++ b/advisories/unreviewed/2022/05/GHSA-f9cc-wx9r-r8gm/GHSA-f9cc-wx9r-r8gm.json @@ -7,12 +7,8 @@ "CVE-2005-4508" ], "details": "Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a non-existent .dll file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc3r-8rf7-j47f/GHSA-fc3r-8rf7-j47f.json b/advisories/unreviewed/2022/05/GHSA-fc3r-8rf7-j47f/GHSA-fc3r-8rf7-j47f.json index adb937ffec8..fcd6aa4d0fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc3r-8rf7-j47f/GHSA-fc3r-8rf7-j47f.json +++ b/advisories/unreviewed/2022/05/GHSA-fc3r-8rf7-j47f/GHSA-fc3r-8rf7-j47f.json @@ -7,12 +7,8 @@ "CVE-2005-4453" ], "details": "UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_user_id parameters to UserProfile.aspx, then modifying the password field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcgr-2rmx-gwwf/GHSA-fcgr-2rmx-gwwf.json b/advisories/unreviewed/2022/05/GHSA-fcgr-2rmx-gwwf/GHSA-fcgr-2rmx-gwwf.json index ac735fe3212..37554490739 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcgr-2rmx-gwwf/GHSA-fcgr-2rmx-gwwf.json +++ b/advisories/unreviewed/2022/05/GHSA-fcgr-2rmx-gwwf/GHSA-fcgr-2rmx-gwwf.json @@ -7,12 +7,8 @@ "CVE-2020-19284" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments text field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fchg-vp85-h7h9/GHSA-fchg-vp85-h7h9.json b/advisories/unreviewed/2022/05/GHSA-fchg-vp85-h7h9/GHSA-fchg-vp85-h7h9.json index 05e8d648ef1..cad6f27c57d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fchg-vp85-h7h9/GHSA-fchg-vp85-h7h9.json +++ b/advisories/unreviewed/2022/05/GHSA-fchg-vp85-h7h9/GHSA-fchg-vp85-h7h9.json @@ -7,12 +7,8 @@ "CVE-2021-39589" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function parse_metadata() located in abc.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcpv-47pc-7gw6/GHSA-fcpv-47pc-7gw6.json b/advisories/unreviewed/2022/05/GHSA-fcpv-47pc-7gw6/GHSA-fcpv-47pc-7gw6.json index 81dd82475dc..8c85c791f74 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcpv-47pc-7gw6/GHSA-fcpv-47pc-7gw6.json +++ b/advisories/unreviewed/2022/05/GHSA-fcpv-47pc-7gw6/GHSA-fcpv-47pc-7gw6.json @@ -7,12 +7,8 @@ "CVE-2005-4624" ], "details": "The m_join function in channel.c for PTnet ircd 1.5 and 1.6 allows remote attackers to cause a denial of service (memory exhaustion that triggers a daemon restart) via a large number of requests to join a \"charmed channel\" such as PTnet, #PTnoticias and #*.log, which causes ircd to open the channel even though it does not have any valid users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcwx-wvr2-2xm2/GHSA-fcwx-wvr2-2xm2.json b/advisories/unreviewed/2022/05/GHSA-fcwx-wvr2-2xm2/GHSA-fcwx-wvr2-2xm2.json index 132fdcf23a8..4a353a212e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcwx-wvr2-2xm2/GHSA-fcwx-wvr2-2xm2.json +++ b/advisories/unreviewed/2022/05/GHSA-fcwx-wvr2-2xm2/GHSA-fcwx-wvr2-2xm2.json @@ -7,12 +7,8 @@ "CVE-2018-19957" ], "details": "A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff76-wr66-r229/GHSA-ff76-wr66-r229.json b/advisories/unreviewed/2022/05/GHSA-ff76-wr66-r229/GHSA-ff76-wr66-r229.json index 770347f5d51..1663cd5d483 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff76-wr66-r229/GHSA-ff76-wr66-r229.json +++ b/advisories/unreviewed/2022/05/GHSA-ff76-wr66-r229/GHSA-ff76-wr66-r229.json @@ -7,12 +7,8 @@ "CVE-2005-4802" ], "details": "Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgg2-r72r-cjqw/GHSA-fgg2-r72r-cjqw.json b/advisories/unreviewed/2022/05/GHSA-fgg2-r72r-cjqw/GHSA-fgg2-r72r-cjqw.json index d097bb9906a..fe427f14793 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgg2-r72r-cjqw/GHSA-fgg2-r72r-cjqw.json +++ b/advisories/unreviewed/2022/05/GHSA-fgg2-r72r-cjqw/GHSA-fgg2-r72r-cjqw.json @@ -7,12 +7,8 @@ "CVE-2021-29821" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204348.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgp9-p978-9f8x/GHSA-fgp9-p978-9f8x.json b/advisories/unreviewed/2022/05/GHSA-fgp9-p978-9f8x/GHSA-fgp9-p978-9f8x.json index 989010e7b26..54b5d985b3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgp9-p978-9f8x/GHSA-fgp9-p978-9f8x.json +++ b/advisories/unreviewed/2022/05/GHSA-fgp9-p978-9f8x/GHSA-fgp9-p978-9f8x.json @@ -7,12 +7,8 @@ "CVE-2021-38354" ], "details": "The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgxf-m96p-5m7q/GHSA-fgxf-m96p-5m7q.json b/advisories/unreviewed/2022/05/GHSA-fgxf-m96p-5m7q/GHSA-fgxf-m96p-5m7q.json index 8baa3a383f9..4cb30956fc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgxf-m96p-5m7q/GHSA-fgxf-m96p-5m7q.json +++ b/advisories/unreviewed/2022/05/GHSA-fgxf-m96p-5m7q/GHSA-fgxf-m96p-5m7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh4q-xjx9-cj52/GHSA-fh4q-xjx9-cj52.json b/advisories/unreviewed/2022/05/GHSA-fh4q-xjx9-cj52/GHSA-fh4q-xjx9-cj52.json index a54c96ca3b9..dbfdf2861ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh4q-xjx9-cj52/GHSA-fh4q-xjx9-cj52.json +++ b/advisories/unreviewed/2022/05/GHSA-fh4q-xjx9-cj52/GHSA-fh4q-xjx9-cj52.json @@ -7,12 +7,8 @@ "CVE-2005-4598" ], "details": "Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhcv-9prg-g289/GHSA-fhcv-9prg-g289.json b/advisories/unreviewed/2022/05/GHSA-fhcv-9prg-g289/GHSA-fhcv-9prg-g289.json index 84219b790cb..a9510a40735 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhcv-9prg-g289/GHSA-fhcv-9prg-g289.json +++ b/advisories/unreviewed/2022/05/GHSA-fhcv-9prg-g289/GHSA-fhcv-9prg-g289.json @@ -7,12 +7,8 @@ "CVE-2021-38331" ], "details": "The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhj6-mqf7-5g3c/GHSA-fhj6-mqf7-5g3c.json b/advisories/unreviewed/2022/05/GHSA-fhj6-mqf7-5g3c/GHSA-fhj6-mqf7-5g3c.json index 97b33d0f6fc..2d0c1164089 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhj6-mqf7-5g3c/GHSA-fhj6-mqf7-5g3c.json +++ b/advisories/unreviewed/2022/05/GHSA-fhj6-mqf7-5g3c/GHSA-fhj6-mqf7-5g3c.json @@ -7,12 +7,8 @@ "CVE-2005-4477" ], "details": "Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fj2h-4hhq-47f7/GHSA-fj2h-4hhq-47f7.json b/advisories/unreviewed/2022/05/GHSA-fj2h-4hhq-47f7/GHSA-fj2h-4hhq-47f7.json index 38935d9a7cc..0be9984d954 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj2h-4hhq-47f7/GHSA-fj2h-4hhq-47f7.json +++ b/advisories/unreviewed/2022/05/GHSA-fj2h-4hhq-47f7/GHSA-fj2h-4hhq-47f7.json @@ -7,12 +7,8 @@ "CVE-2021-22020" ], "details": "The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fj83-776g-wqqf/GHSA-fj83-776g-wqqf.json b/advisories/unreviewed/2022/05/GHSA-fj83-776g-wqqf/GHSA-fj83-776g-wqqf.json index 0ff4c78f61b..5c5331c89dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj83-776g-wqqf/GHSA-fj83-776g-wqqf.json +++ b/advisories/unreviewed/2022/05/GHSA-fj83-776g-wqqf/GHSA-fj83-776g-wqqf.json @@ -7,12 +7,8 @@ "CVE-2005-4485" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjcw-v25j-8w38/GHSA-fjcw-v25j-8w38.json b/advisories/unreviewed/2022/05/GHSA-fjcw-v25j-8w38/GHSA-fjcw-v25j-8w38.json index a9a1ed2fe8c..f4e452494eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjcw-v25j-8w38/GHSA-fjcw-v25j-8w38.json +++ b/advisories/unreviewed/2022/05/GHSA-fjcw-v25j-8w38/GHSA-fjcw-v25j-8w38.json @@ -7,12 +7,8 @@ "CVE-2020-20895" ], "details": "Buffer Overflow vulnerability in function filter_vertically_##name in libavfilter/vf_avgblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmx8-cmcw-gqrw/GHSA-fmx8-cmcw-gqrw.json b/advisories/unreviewed/2022/05/GHSA-fmx8-cmcw-gqrw/GHSA-fmx8-cmcw-gqrw.json index 43fc1693311..0d65206f65d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmx8-cmcw-gqrw/GHSA-fmx8-cmcw-gqrw.json +++ b/advisories/unreviewed/2022/05/GHSA-fmx8-cmcw-gqrw/GHSA-fmx8-cmcw-gqrw.json @@ -7,12 +7,8 @@ "CVE-2005-4717" ], "details": "Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq33-497v-4h5x/GHSA-fq33-497v-4h5x.json b/advisories/unreviewed/2022/05/GHSA-fq33-497v-4h5x/GHSA-fq33-497v-4h5x.json index 5296dd14f7f..3179c011259 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq33-497v-4h5x/GHSA-fq33-497v-4h5x.json +++ b/advisories/unreviewed/2022/05/GHSA-fq33-497v-4h5x/GHSA-fq33-497v-4h5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqwx-8v72-4mq9/GHSA-fqwx-8v72-4mq9.json b/advisories/unreviewed/2022/05/GHSA-fqwx-8v72-4mq9/GHSA-fqwx-8v72-4mq9.json index 54267962008..f4196640726 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqwx-8v72-4mq9/GHSA-fqwx-8v72-4mq9.json +++ b/advisories/unreviewed/2022/05/GHSA-fqwx-8v72-4mq9/GHSA-fqwx-8v72-4mq9.json @@ -7,12 +7,8 @@ "CVE-2005-4793" ], "details": "Multiple unspecified vulnerabilities in the web utility function in Hitachi Cm2/Network Node Manager and JP1/Cm2/Network Node Manager before 20050930 allow attackers to execute arbitrary commands, disable services, and \"exploit vulnerabilities.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr6v-96rj-pcv9/GHSA-fr6v-96rj-pcv9.json b/advisories/unreviewed/2022/05/GHSA-fr6v-96rj-pcv9/GHSA-fr6v-96rj-pcv9.json index bbfb43d8f63..9c2d01e3951 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr6v-96rj-pcv9/GHSA-fr6v-96rj-pcv9.json +++ b/advisories/unreviewed/2022/05/GHSA-fr6v-96rj-pcv9/GHSA-fr6v-96rj-pcv9.json @@ -7,12 +7,8 @@ "CVE-2005-4479" ], "details": "SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frfc-2472-vf85/GHSA-frfc-2472-vf85.json b/advisories/unreviewed/2022/05/GHSA-frfc-2472-vf85/GHSA-frfc-2472-vf85.json index 2eac06d0625..f947c452a2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-frfc-2472-vf85/GHSA-frfc-2472-vf85.json +++ b/advisories/unreviewed/2022/05/GHSA-frfc-2472-vf85/GHSA-frfc-2472-vf85.json @@ -7,12 +7,8 @@ "CVE-2005-4638" ], "details": "index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to obtain the full path via (1) _a and (2) newsid parameters in the news module, (3) downloaditemid parameter in the downloads module, and (4) kbarticleid parameter in the knowledgebase module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frq7-7xj9-2qfg/GHSA-frq7-7xj9-2qfg.json b/advisories/unreviewed/2022/05/GHSA-frq7-7xj9-2qfg/GHSA-frq7-7xj9-2qfg.json index b56b6f57448..c5e45067c18 100644 --- a/advisories/unreviewed/2022/05/GHSA-frq7-7xj9-2qfg/GHSA-frq7-7xj9-2qfg.json +++ b/advisories/unreviewed/2022/05/GHSA-frq7-7xj9-2qfg/GHSA-frq7-7xj9-2qfg.json @@ -7,12 +7,8 @@ "CVE-2005-4719" ], "details": "Multiple SQL injection vulnerabilities in Sysbotz Systems Panel 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in knowledgebase/index.php, (2) the aid parameter in knowledgebase/view.php, (3) the cid parameter in contact/update.php, (4) the letter parameter in links/index.php, (5) the mid parameter in messageboard/view.php, and (6) the tid parameter in tickets/view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv2j-64xc-r4hr/GHSA-fv2j-64xc-r4hr.json b/advisories/unreviewed/2022/05/GHSA-fv2j-64xc-r4hr/GHSA-fv2j-64xc-r4hr.json index 4cedc73a8df..6bc00a64f5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv2j-64xc-r4hr/GHSA-fv2j-64xc-r4hr.json +++ b/advisories/unreviewed/2022/05/GHSA-fv2j-64xc-r4hr/GHSA-fv2j-64xc-r4hr.json @@ -7,12 +7,8 @@ "CVE-2021-27662" ], "details": "The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv2v-8v2v-g9q3/GHSA-fv2v-8v2v-g9q3.json b/advisories/unreviewed/2022/05/GHSA-fv2v-8v2v-g9q3/GHSA-fv2v-8v2v-g9q3.json index 934849ab932..fe756d04380 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv2v-8v2v-g9q3/GHSA-fv2v-8v2v-g9q3.json +++ b/advisories/unreviewed/2022/05/GHSA-fv2v-8v2v-g9q3/GHSA-fv2v-8v2v-g9q3.json @@ -7,12 +7,8 @@ "CVE-2020-20902" ], "details": "A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvmx-f73c-vgqh/GHSA-fvmx-f73c-vgqh.json b/advisories/unreviewed/2022/05/GHSA-fvmx-f73c-vgqh/GHSA-fvmx-f73c-vgqh.json index fb367181b91..8de2c23d1cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvmx-f73c-vgqh/GHSA-fvmx-f73c-vgqh.json +++ b/advisories/unreviewed/2022/05/GHSA-fvmx-f73c-vgqh/GHSA-fvmx-f73c-vgqh.json @@ -7,12 +7,8 @@ "CVE-2005-4674" ], "details": "Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary SQL commands via the (1) c or (2) s parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvqf-8h9v-94f2/GHSA-fvqf-8h9v-94f2.json b/advisories/unreviewed/2022/05/GHSA-fvqf-8h9v-94f2/GHSA-fvqf-8h9v-94f2.json index 18738187199..a5e96b94063 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvqf-8h9v-94f2/GHSA-fvqf-8h9v-94f2.json +++ b/advisories/unreviewed/2022/05/GHSA-fvqf-8h9v-94f2/GHSA-fvqf-8h9v-94f2.json @@ -7,12 +7,8 @@ "CVE-2005-4745" ], "details": "SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw9q-rwpp-xcw5/GHSA-fw9q-rwpp-xcw5.json b/advisories/unreviewed/2022/05/GHSA-fw9q-rwpp-xcw5/GHSA-fw9q-rwpp-xcw5.json index b4e8d2bdb4b..7b2ca9cb392 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw9q-rwpp-xcw5/GHSA-fw9q-rwpp-xcw5.json +++ b/advisories/unreviewed/2022/05/GHSA-fw9q-rwpp-xcw5/GHSA-fw9q-rwpp-xcw5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g25m-r8p8-98wq/GHSA-g25m-r8p8-98wq.json b/advisories/unreviewed/2022/05/GHSA-g25m-r8p8-98wq/GHSA-g25m-r8p8-98wq.json index 6d0253e7ab0..651de86003d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g25m-r8p8-98wq/GHSA-g25m-r8p8-98wq.json +++ b/advisories/unreviewed/2022/05/GHSA-g25m-r8p8-98wq/GHSA-g25m-r8p8-98wq.json @@ -7,12 +7,8 @@ "CVE-2020-20891" ], "details": "Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g278-j36h-xmv9/GHSA-g278-j36h-xmv9.json b/advisories/unreviewed/2022/05/GHSA-g278-j36h-xmv9/GHSA-g278-j36h-xmv9.json index 005de6bf1a3..08f97f9cdf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-g278-j36h-xmv9/GHSA-g278-j36h-xmv9.json +++ b/advisories/unreviewed/2022/05/GHSA-g278-j36h-xmv9/GHSA-g278-j36h-xmv9.json @@ -7,12 +7,8 @@ "CVE-2020-19156" ], "details": "Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g28w-j5h7-v723/GHSA-g28w-j5h7-v723.json b/advisories/unreviewed/2022/05/GHSA-g28w-j5h7-v723/GHSA-g28w-j5h7-v723.json index 217dc73d414..46fe73002bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-g28w-j5h7-v723/GHSA-g28w-j5h7-v723.json +++ b/advisories/unreviewed/2022/05/GHSA-g28w-j5h7-v723/GHSA-g28w-j5h7-v723.json @@ -7,12 +7,8 @@ "CVE-2005-4726" ], "details": "MUTE 0.4 uses improper flood protection algorithms, which allows remote attackers to obtain sensitive information (privacy leak and search result data) by controlling a drop chain neighbor that is near the end of a message chain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g34c-fgmm-m32p/GHSA-g34c-fgmm-m32p.json b/advisories/unreviewed/2022/05/GHSA-g34c-fgmm-m32p/GHSA-g34c-fgmm-m32p.json index e060617f6b6..8623a87b29c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g34c-fgmm-m32p/GHSA-g34c-fgmm-m32p.json +++ b/advisories/unreviewed/2022/05/GHSA-g34c-fgmm-m32p/GHSA-g34c-fgmm-m32p.json @@ -7,12 +7,8 @@ "CVE-2005-4455" ], "details": "cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3q2-x98w-36ww/GHSA-g3q2-x98w-36ww.json b/advisories/unreviewed/2022/05/GHSA-g3q2-x98w-36ww/GHSA-g3q2-x98w-36ww.json index a6c701ce97a..60ee7539041 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3q2-x98w-36ww/GHSA-g3q2-x98w-36ww.json +++ b/advisories/unreviewed/2022/05/GHSA-g3q2-x98w-36ww/GHSA-g3q2-x98w-36ww.json @@ -7,12 +7,8 @@ "CVE-2005-4735" ], "details": "IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5h8-hjh2-8m54/GHSA-g5h8-hjh2-8m54.json b/advisories/unreviewed/2022/05/GHSA-g5h8-hjh2-8m54/GHSA-g5h8-hjh2-8m54.json index 18efde21dc7..ff78b0c38dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5h8-hjh2-8m54/GHSA-g5h8-hjh2-8m54.json +++ b/advisories/unreviewed/2022/05/GHSA-g5h8-hjh2-8m54/GHSA-g5h8-hjh2-8m54.json @@ -7,12 +7,8 @@ "CVE-2021-40670" ], "details": "SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g62q-jrgg-f5mw/GHSA-g62q-jrgg-f5mw.json b/advisories/unreviewed/2022/05/GHSA-g62q-jrgg-f5mw/GHSA-g62q-jrgg-f5mw.json index 49973584e6e..5c40cb2942b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g62q-jrgg-f5mw/GHSA-g62q-jrgg-f5mw.json +++ b/advisories/unreviewed/2022/05/GHSA-g62q-jrgg-f5mw/GHSA-g62q-jrgg-f5mw.json @@ -7,12 +7,8 @@ "CVE-2005-4796" ], "details": "Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g64f-mxrq-5h8c/GHSA-g64f-mxrq-5h8c.json b/advisories/unreviewed/2022/05/GHSA-g64f-mxrq-5h8c/GHSA-g64f-mxrq-5h8c.json index 15b4f1d1a68..9b2b0ac5da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-g64f-mxrq-5h8c/GHSA-g64f-mxrq-5h8c.json +++ b/advisories/unreviewed/2022/05/GHSA-g64f-mxrq-5h8c/GHSA-g64f-mxrq-5h8c.json @@ -7,12 +7,8 @@ "CVE-2021-34576" ], "details": "In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6c8-gjr8-q3fr/GHSA-g6c8-gjr8-q3fr.json b/advisories/unreviewed/2022/05/GHSA-g6c8-gjr8-q3fr/GHSA-g6c8-gjr8-q3fr.json index 505c40f0952..9958d1e9ba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6c8-gjr8-q3fr/GHSA-g6c8-gjr8-q3fr.json +++ b/advisories/unreviewed/2022/05/GHSA-g6c8-gjr8-q3fr/GHSA-g6c8-gjr8-q3fr.json @@ -7,12 +7,8 @@ "CVE-2005-4686" ], "details": "PunBB 1.2.9, when used alone or with F-ART BLOG:CMS, includes config.php before calling the unregister_globals function, which allows attackers to obtain unspecified sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6f7-wvh9-6cj8/GHSA-g6f7-wvh9-6cj8.json b/advisories/unreviewed/2022/05/GHSA-g6f7-wvh9-6cj8/GHSA-g6f7-wvh9-6cj8.json index d98c4ee674b..b6268205d1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6f7-wvh9-6cj8/GHSA-g6f7-wvh9-6cj8.json +++ b/advisories/unreviewed/2022/05/GHSA-g6f7-wvh9-6cj8/GHSA-g6f7-wvh9-6cj8.json @@ -7,12 +7,8 @@ "CVE-2020-19282" ], "details": "A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6p7-8xmm-rr6g/GHSA-g6p7-8xmm-rr6g.json b/advisories/unreviewed/2022/05/GHSA-g6p7-8xmm-rr6g/GHSA-g6p7-8xmm-rr6g.json index 0b136099b4b..5e1268a0fd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6p7-8xmm-rr6g/GHSA-g6p7-8xmm-rr6g.json +++ b/advisories/unreviewed/2022/05/GHSA-g6p7-8xmm-rr6g/GHSA-g6p7-8xmm-rr6g.json @@ -7,12 +7,8 @@ "CVE-2005-4666" ], "details": "Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6q2-6x3v-j3cw/GHSA-g6q2-6x3v-j3cw.json b/advisories/unreviewed/2022/05/GHSA-g6q2-6x3v-j3cw/GHSA-g6q2-6x3v-j3cw.json index 7e8dd16e2f4..704147563d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6q2-6x3v-j3cw/GHSA-g6q2-6x3v-j3cw.json +++ b/advisories/unreviewed/2022/05/GHSA-g6q2-6x3v-j3cw/GHSA-g6q2-6x3v-j3cw.json @@ -7,12 +7,8 @@ "CVE-2021-23033" ], "details": "On BIG-IP Advanced WAF and BIG-IP ASM version 16.x before 16.1.0x, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is configured on a virtual server, undisclosed requests can cause bd to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6qm-f66w-v42p/GHSA-g6qm-f66w-v42p.json b/advisories/unreviewed/2022/05/GHSA-g6qm-f66w-v42p/GHSA-g6qm-f66w-v42p.json index b599076c7ed..bbf7abdb528 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6qm-f66w-v42p/GHSA-g6qm-f66w-v42p.json +++ b/advisories/unreviewed/2022/05/GHSA-g6qm-f66w-v42p/GHSA-g6qm-f66w-v42p.json @@ -7,12 +7,8 @@ "CVE-2005-4614" ], "details": "Multiple SQL injection vulnerabilities in digiSHOP 3.1.17 and earlier allow remote attackers to execute arbitrary SQL commands or obtain the full installation path via (1) the c parameter in cart.php and (2) unspecified search module parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g72w-qc26-qmpv/GHSA-g72w-qc26-qmpv.json b/advisories/unreviewed/2022/05/GHSA-g72w-qc26-qmpv/GHSA-g72w-qc26-qmpv.json index 1abf30680bc..df67a1536ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-g72w-qc26-qmpv/GHSA-g72w-qc26-qmpv.json +++ b/advisories/unreviewed/2022/05/GHSA-g72w-qc26-qmpv/GHSA-g72w-qc26-qmpv.json @@ -7,12 +7,8 @@ "CVE-2021-38327" ], "details": "The YouTube Video Inserter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/adminUI/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7gg-fmmg-9gmr/GHSA-g7gg-fmmg-9gmr.json b/advisories/unreviewed/2022/05/GHSA-g7gg-fmmg-9gmr/GHSA-g7gg-fmmg-9gmr.json index 3356caeaa07..e87adbcd666 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7gg-fmmg-9gmr/GHSA-g7gg-fmmg-9gmr.json +++ b/advisories/unreviewed/2022/05/GHSA-g7gg-fmmg-9gmr/GHSA-g7gg-fmmg-9gmr.json @@ -7,12 +7,8 @@ "CVE-2021-32294" ], "details": "An issue was discovered in libgig through 20200507. A heap-buffer-overflow exists in the function RIFF::List::GetSubList located in RIFF.cpp. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7qm-6xgj-wfh5/GHSA-g7qm-6xgj-wfh5.json b/advisories/unreviewed/2022/05/GHSA-g7qm-6xgj-wfh5/GHSA-g7qm-6xgj-wfh5.json index ab79e879b62..88e72d48d81 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7qm-6xgj-wfh5/GHSA-g7qm-6xgj-wfh5.json +++ b/advisories/unreviewed/2022/05/GHSA-g7qm-6xgj-wfh5/GHSA-g7qm-6xgj-wfh5.json @@ -7,12 +7,8 @@ "CVE-2005-4597" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g898-v75f-fp22/GHSA-g898-v75f-fp22.json b/advisories/unreviewed/2022/05/GHSA-g898-v75f-fp22/GHSA-g898-v75f-fp22.json index 5249f78dc46..38086eed981 100644 --- a/advisories/unreviewed/2022/05/GHSA-g898-v75f-fp22/GHSA-g898-v75f-fp22.json +++ b/advisories/unreviewed/2022/05/GHSA-g898-v75f-fp22/GHSA-g898-v75f-fp22.json @@ -7,12 +7,8 @@ "CVE-2005-4830" ], "details": "CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g9r6-qhfx-9xcc/GHSA-g9r6-qhfx-9xcc.json b/advisories/unreviewed/2022/05/GHSA-g9r6-qhfx-9xcc/GHSA-g9r6-qhfx-9xcc.json index 8f75fc37336..2045e5e77c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9r6-qhfx-9xcc/GHSA-g9r6-qhfx-9xcc.json +++ b/advisories/unreviewed/2022/05/GHSA-g9r6-qhfx-9xcc/GHSA-g9r6-qhfx-9xcc.json @@ -7,12 +7,8 @@ "CVE-2021-39535" ], "details": "An issue was discovered in libxsmm through v1.16.1-93. A NULL pointer dereference exists in JIT code. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9xx-m8f7-gx2c/GHSA-g9xx-m8f7-gx2c.json b/advisories/unreviewed/2022/05/GHSA-g9xx-m8f7-gx2c/GHSA-g9xx-m8f7-gx2c.json index 4c65c9c87a3..d5d8eada6ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9xx-m8f7-gx2c/GHSA-g9xx-m8f7-gx2c.json +++ b/advisories/unreviewed/2022/05/GHSA-g9xx-m8f7-gx2c/GHSA-g9xx-m8f7-gx2c.json @@ -7,12 +7,8 @@ "CVE-2020-21482" ], "details": "A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf8p-pg5p-7jm3/GHSA-gf8p-pg5p-7jm3.json b/advisories/unreviewed/2022/05/GHSA-gf8p-pg5p-7jm3/GHSA-gf8p-pg5p-7jm3.json index bf31e6b9df9..7a04587260b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf8p-pg5p-7jm3/GHSA-gf8p-pg5p-7jm3.json +++ b/advisories/unreviewed/2022/05/GHSA-gf8p-pg5p-7jm3/GHSA-gf8p-pg5p-7jm3.json @@ -7,12 +7,8 @@ "CVE-2021-39516" ], "details": "An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in huffmandecoder.hpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg8c-wv43-x28x/GHSA-gg8c-wv43-x28x.json b/advisories/unreviewed/2022/05/GHSA-gg8c-wv43-x28x/GHSA-gg8c-wv43-x28x.json index fafc7522531..c9e9144d499 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg8c-wv43-x28x/GHSA-gg8c-wv43-x28x.json +++ b/advisories/unreviewed/2022/05/GHSA-gg8c-wv43-x28x/GHSA-gg8c-wv43-x28x.json @@ -7,12 +7,8 @@ "CVE-2021-24663" ], "details": "The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gggx-f55h-83w3/GHSA-gggx-f55h-83w3.json b/advisories/unreviewed/2022/05/GHSA-gggx-f55h-83w3/GHSA-gggx-f55h-83w3.json index fb8ee33512c..c56da9716c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gggx-f55h-83w3/GHSA-gggx-f55h-83w3.json +++ b/advisories/unreviewed/2022/05/GHSA-gggx-f55h-83w3/GHSA-gggx-f55h-83w3.json @@ -7,12 +7,8 @@ "CVE-2005-4840" ], "details": "The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggph-hp42-2f4h/GHSA-ggph-hp42-2f4h.json b/advisories/unreviewed/2022/05/GHSA-ggph-hp42-2f4h/GHSA-ggph-hp42-2f4h.json index 4e26bd64f93..faa6df33dfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggph-hp42-2f4h/GHSA-ggph-hp42-2f4h.json +++ b/advisories/unreviewed/2022/05/GHSA-ggph-hp42-2f4h/GHSA-ggph-hp42-2f4h.json @@ -7,12 +7,8 @@ "CVE-2021-39558" ], "details": "An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function VectorGraphicOutputDev::drawGeneralImage() located in VectorGraphicOutputDev.cc. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggvw-gcq7-rp4h/GHSA-ggvw-gcq7-rp4h.json b/advisories/unreviewed/2022/05/GHSA-ggvw-gcq7-rp4h/GHSA-ggvw-gcq7-rp4h.json index e3ef3c55030..b92d37eebb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggvw-gcq7-rp4h/GHSA-ggvw-gcq7-rp4h.json +++ b/advisories/unreviewed/2022/05/GHSA-ggvw-gcq7-rp4h/GHSA-ggvw-gcq7-rp4h.json @@ -7,12 +7,8 @@ "CVE-2005-4506" ], "details": "Nexus Concepts Dev Hound 2.24 and earlier stores username and password information in cleartext in the devhound.tdbd file, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh89-2x3x-p7j7/GHSA-gh89-2x3x-p7j7.json b/advisories/unreviewed/2022/05/GHSA-gh89-2x3x-p7j7/GHSA-gh89-2x3x-p7j7.json index c78dcdcf0b6..764bf2789ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh89-2x3x-p7j7/GHSA-gh89-2x3x-p7j7.json +++ b/advisories/unreviewed/2022/05/GHSA-gh89-2x3x-p7j7/GHSA-gh89-2x3x-p7j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghvr-mv7w-8r6f/GHSA-ghvr-mv7w-8r6f.json b/advisories/unreviewed/2022/05/GHSA-ghvr-mv7w-8r6f/GHSA-ghvr-mv7w-8r6f.json index 37ea8e72f05..ca62e17f46a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghvr-mv7w-8r6f/GHSA-ghvr-mv7w-8r6f.json +++ b/advisories/unreviewed/2022/05/GHSA-ghvr-mv7w-8r6f/GHSA-ghvr-mv7w-8r6f.json @@ -7,12 +7,8 @@ "CVE-2005-4581" ], "details": "Buffer overflow in Electric Sheep 2.6.3 client allows local users to execute arbitrary code via a long window-id parameter. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj3q-qghf-gf7p/GHSA-gj3q-qghf-gf7p.json b/advisories/unreviewed/2022/05/GHSA-gj3q-qghf-gf7p/GHSA-gj3q-qghf-gf7p.json index 6345bc17113..08b8f45fe31 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj3q-qghf-gf7p/GHSA-gj3q-qghf-gf7p.json +++ b/advisories/unreviewed/2022/05/GHSA-gj3q-qghf-gf7p/GHSA-gj3q-qghf-gf7p.json @@ -7,12 +7,8 @@ "CVE-2005-4811" ], "details": "The hugepage code (hugetlb.c) in Linux kernel 2.6, possibly 2.6.12 and 2.6.13, in certain configurations, allows local users to cause a denial of service (crash) by triggering an mmap error before a prefault, which causes an error in the unmap_hugepage_area function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj8x-63v8-4x98/GHSA-gj8x-63v8-4x98.json b/advisories/unreviewed/2022/05/GHSA-gj8x-63v8-4x98/GHSA-gj8x-63v8-4x98.json index e29a55b4b1a..3ac6fafd5bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj8x-63v8-4x98/GHSA-gj8x-63v8-4x98.json +++ b/advisories/unreviewed/2022/05/GHSA-gj8x-63v8-4x98/GHSA-gj8x-63v8-4x98.json @@ -7,12 +7,8 @@ "CVE-2005-4812" ], "details": "The SISCO OSI stack for Windows, as used by MMS-EASE 7.10 and earlier, AX-S4 MMS 5.01 and earlier, AX-S4 ICCP 3.0103 and earlier, and the ICCP Toolkit for MMS-EASE 4.10 and earlier, allows remote attackers to cause a denial of service (process crash) via certain network traffic, as demonstrated using a Nessus scan.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjgr-g54p-g5jh/GHSA-gjgr-g54p-g5jh.json b/advisories/unreviewed/2022/05/GHSA-gjgr-g54p-g5jh/GHSA-gjgr-g54p-g5jh.json index dd6154fe7d2..1941147a8ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjgr-g54p-g5jh/GHSA-gjgr-g54p-g5jh.json +++ b/advisories/unreviewed/2022/05/GHSA-gjgr-g54p-g5jh/GHSA-gjgr-g54p-g5jh.json @@ -7,12 +7,8 @@ "CVE-2005-4675" ], "details": "Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm68-2qf8-8pv7/GHSA-gm68-2qf8-8pv7.json b/advisories/unreviewed/2022/05/GHSA-gm68-2qf8-8pv7/GHSA-gm68-2qf8-8pv7.json index 3fc767f4925..8fcb6628336 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm68-2qf8-8pv7/GHSA-gm68-2qf8-8pv7.json +++ b/advisories/unreviewed/2022/05/GHSA-gm68-2qf8-8pv7/GHSA-gm68-2qf8-8pv7.json @@ -7,12 +7,8 @@ "CVE-2005-4534" ], "details": "The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gmp4-8xr6-896q/GHSA-gmp4-8xr6-896q.json b/advisories/unreviewed/2022/05/GHSA-gmp4-8xr6-896q/GHSA-gmp4-8xr6-896q.json index 11c25a74dca..513c2b3f627 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmp4-8xr6-896q/GHSA-gmp4-8xr6-896q.json +++ b/advisories/unreviewed/2022/05/GHSA-gmp4-8xr6-896q/GHSA-gmp4-8xr6-896q.json @@ -7,12 +7,8 @@ "CVE-2005-4625" ], "details": "Drivers for certain display adapters, including (1) an unspecified ATI driver and (2) an unspecified Intel driver, might allow remote attackers to cause a denial of service (system crash) via a large JPEG image, as demonstrated in Internet Explorer using stoopid.jpg with a width and height of 9999999.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gphc-6cvq-642v/GHSA-gphc-6cvq-642v.json b/advisories/unreviewed/2022/05/GHSA-gphc-6cvq-642v/GHSA-gphc-6cvq-642v.json index 95536aee87a..fc7e6efb829 100644 --- a/advisories/unreviewed/2022/05/GHSA-gphc-6cvq-642v/GHSA-gphc-6cvq-642v.json +++ b/advisories/unreviewed/2022/05/GHSA-gphc-6cvq-642v/GHSA-gphc-6cvq-642v.json @@ -7,12 +7,8 @@ "CVE-2005-4770" ], "details": "SQL injection vulnerability in an unspecified Accelerated Enterprise Solutions product, possibly Accelerated E Solutions, allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gpjf-jjxr-m946/GHSA-gpjf-jjxr-m946.json b/advisories/unreviewed/2022/05/GHSA-gpjf-jjxr-m946/GHSA-gpjf-jjxr-m946.json index adf4ee62882..4439d84f357 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpjf-jjxr-m946/GHSA-gpjf-jjxr-m946.json +++ b/advisories/unreviewed/2022/05/GHSA-gpjf-jjxr-m946/GHSA-gpjf-jjxr-m946.json @@ -7,12 +7,8 @@ "CVE-2005-4503" ], "details": "httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq57-694q-x523/GHSA-gq57-694q-x523.json b/advisories/unreviewed/2022/05/GHSA-gq57-694q-x523/GHSA-gq57-694q-x523.json index 8b41732c3ce..ed3f29b787f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq57-694q-x523/GHSA-gq57-694q-x523.json +++ b/advisories/unreviewed/2022/05/GHSA-gq57-694q-x523/GHSA-gq57-694q-x523.json @@ -7,12 +7,8 @@ "CVE-2021-25665" ], "details": "A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2021.2.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13700)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grg7-jq9x-hvf8/GHSA-grg7-jq9x-hvf8.json b/advisories/unreviewed/2022/05/GHSA-grg7-jq9x-hvf8/GHSA-grg7-jq9x-hvf8.json index 90ba10fb81f..37e85f6efc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-grg7-jq9x-hvf8/GHSA-grg7-jq9x-hvf8.json +++ b/advisories/unreviewed/2022/05/GHSA-grg7-jq9x-hvf8/GHSA-grg7-jq9x-hvf8.json @@ -7,12 +7,8 @@ "CVE-2020-20897" ], "details": "Buffer Overflow vulnerability in function filter_slice in libavfilter/vf_bm3d.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grh8-hj9r-8r5x/GHSA-grh8-hj9r-8r5x.json b/advisories/unreviewed/2022/05/GHSA-grh8-hj9r-8r5x/GHSA-grh8-hj9r-8r5x.json index 3ad4afe153f..2d7fc052ec3 100644 --- a/advisories/unreviewed/2022/05/GHSA-grh8-hj9r-8r5x/GHSA-grh8-hj9r-8r5x.json +++ b/advisories/unreviewed/2022/05/GHSA-grh8-hj9r-8r5x/GHSA-grh8-hj9r-8r5x.json @@ -7,12 +7,8 @@ "CVE-2005-4613" ], "details": "Cross-site scripting (XSS) vulnerability in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified fields in the user edit profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gv3m-j4wj-2r64/GHSA-gv3m-j4wj-2r64.json b/advisories/unreviewed/2022/05/GHSA-gv3m-j4wj-2r64/GHSA-gv3m-j4wj-2r64.json index 5fc71c6f40f..01e40795618 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv3m-j4wj-2r64/GHSA-gv3m-j4wj-2r64.json +++ b/advisories/unreviewed/2022/05/GHSA-gv3m-j4wj-2r64/GHSA-gv3m-j4wj-2r64.json @@ -7,12 +7,8 @@ "CVE-2005-4800" ], "details": "Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier to exploit due to a separate CSRF vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvhj-rrhv-wr5p/GHSA-gvhj-rrhv-wr5p.json b/advisories/unreviewed/2022/05/GHSA-gvhj-rrhv-wr5p/GHSA-gvhj-rrhv-wr5p.json index 555a79ff28d..d53800334b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvhj-rrhv-wr5p/GHSA-gvhj-rrhv-wr5p.json +++ b/advisories/unreviewed/2022/05/GHSA-gvhj-rrhv-wr5p/GHSA-gvhj-rrhv-wr5p.json @@ -7,12 +7,8 @@ "CVE-2005-4822" ], "details": "SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvpj-hm4g-j324/GHSA-gvpj-hm4g-j324.json b/advisories/unreviewed/2022/05/GHSA-gvpj-hm4g-j324/GHSA-gvpj-hm4g-j324.json index 0605d616333..f19b79f0498 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvpj-hm4g-j324/GHSA-gvpj-hm4g-j324.json +++ b/advisories/unreviewed/2022/05/GHSA-gvpj-hm4g-j324/GHSA-gvpj-hm4g-j324.json @@ -7,12 +7,8 @@ "CVE-2005-4616" ], "details": "SQL injection vulnerability in index.php in iSupport 1.06 allows remote attackers to execute arbitrary SQL commands via the include_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gw4v-549p-9jgg/GHSA-gw4v-549p-9jgg.json b/advisories/unreviewed/2022/05/GHSA-gw4v-549p-9jgg/GHSA-gw4v-549p-9jgg.json index f904b8d65bd..6a95e905f87 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw4v-549p-9jgg/GHSA-gw4v-549p-9jgg.json +++ b/advisories/unreviewed/2022/05/GHSA-gw4v-549p-9jgg/GHSA-gw4v-549p-9jgg.json @@ -7,12 +7,8 @@ "CVE-2005-4438" ], "details": "Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwgp-42rc-9p7h/GHSA-gwgp-42rc-9p7h.json b/advisories/unreviewed/2022/05/GHSA-gwgp-42rc-9p7h/GHSA-gwgp-42rc-9p7h.json index 289025902e3..fd3ab3e7624 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwgp-42rc-9p7h/GHSA-gwgp-42rc-9p7h.json +++ b/advisories/unreviewed/2022/05/GHSA-gwgp-42rc-9p7h/GHSA-gwgp-42rc-9p7h.json @@ -7,12 +7,8 @@ "CVE-2005-4593" ], "details": "PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwhh-j9fr-4gcq/GHSA-gwhh-j9fr-4gcq.json b/advisories/unreviewed/2022/05/GHSA-gwhh-j9fr-4gcq/GHSA-gwhh-j9fr-4gcq.json index 676c04a2aa2..65f4070bde6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwhh-j9fr-4gcq/GHSA-gwhh-j9fr-4gcq.json +++ b/advisories/unreviewed/2022/05/GHSA-gwhh-j9fr-4gcq/GHSA-gwhh-j9fr-4gcq.json @@ -7,12 +7,8 @@ "CVE-2005-4727" ], "details": "Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwmx-h2p5-m8jh/GHSA-gwmx-h2p5-m8jh.json b/advisories/unreviewed/2022/05/GHSA-gwmx-h2p5-m8jh/GHSA-gwmx-h2p5-m8jh.json index 6a1c648689d..47c7cd665d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwmx-h2p5-m8jh/GHSA-gwmx-h2p5-m8jh.json +++ b/advisories/unreviewed/2022/05/GHSA-gwmx-h2p5-m8jh/GHSA-gwmx-h2p5-m8jh.json @@ -7,12 +7,8 @@ "CVE-2005-4487" ], "details": "Cross-site scripting (XSS) vulnerability in RAMSite R|1 CMS 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwp7-fg46-5fgw/GHSA-gwp7-fg46-5fgw.json b/advisories/unreviewed/2022/05/GHSA-gwp7-fg46-5fgw/GHSA-gwp7-fg46-5fgw.json index 0efe8c0ed2a..b17ca90481a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwp7-fg46-5fgw/GHSA-gwp7-fg46-5fgw.json +++ b/advisories/unreviewed/2022/05/GHSA-gwp7-fg46-5fgw/GHSA-gwp7-fg46-5fgw.json @@ -7,12 +7,8 @@ "CVE-2021-27341" ], "details": "OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the \"filename\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx79-c5w9-r9rc/GHSA-gx79-c5w9-r9rc.json b/advisories/unreviewed/2022/05/GHSA-gx79-c5w9-r9rc/GHSA-gx79-c5w9-r9rc.json index 045a6b659c0..780c403dd4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx79-c5w9-r9rc/GHSA-gx79-c5w9-r9rc.json +++ b/advisories/unreviewed/2022/05/GHSA-gx79-c5w9-r9rc/GHSA-gx79-c5w9-r9rc.json @@ -7,12 +7,8 @@ "CVE-2005-4488" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxf2-f6v3-qm53/GHSA-gxf2-f6v3-qm53.json b/advisories/unreviewed/2022/05/GHSA-gxf2-f6v3-qm53/GHSA-gxf2-f6v3-qm53.json index 526d210e02c..65b474cbd14 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxf2-f6v3-qm53/GHSA-gxf2-f6v3-qm53.json +++ b/advisories/unreviewed/2022/05/GHSA-gxf2-f6v3-qm53/GHSA-gxf2-f6v3-qm53.json @@ -7,12 +7,8 @@ "CVE-2005-4779" ], "details": "verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxhc-x37q-m5qc/GHSA-gxhc-x37q-m5qc.json b/advisories/unreviewed/2022/05/GHSA-gxhc-x37q-m5qc/GHSA-gxhc-x37q-m5qc.json index 1db2304c82c..51e09346f7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxhc-x37q-m5qc/GHSA-gxhc-x37q-m5qc.json +++ b/advisories/unreviewed/2022/05/GHSA-gxhc-x37q-m5qc/GHSA-gxhc-x37q-m5qc.json @@ -7,12 +7,8 @@ "CVE-2005-4706" ], "details": "Unspecified vulnerability in the \"privilege management\" feature of Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors that trigger a null dereference in the secpolicy_fs_common function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h24x-25vp-682x/GHSA-h24x-25vp-682x.json b/advisories/unreviewed/2022/05/GHSA-h24x-25vp-682x/GHSA-h24x-25vp-682x.json index 3ec8ce1ed3e..344ae164831 100644 --- a/advisories/unreviewed/2022/05/GHSA-h24x-25vp-682x/GHSA-h24x-25vp-682x.json +++ b/advisories/unreviewed/2022/05/GHSA-h24x-25vp-682x/GHSA-h24x-25vp-682x.json @@ -7,12 +7,8 @@ "CVE-2021-38348" ], "details": "The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2xq-fv4r-5784/GHSA-h2xq-fv4r-5784.json b/advisories/unreviewed/2022/05/GHSA-h2xq-fv4r-5784/GHSA-h2xq-fv4r-5784.json index dd4319dfd3f..9505fa947f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2xq-fv4r-5784/GHSA-h2xq-fv4r-5784.json +++ b/advisories/unreviewed/2022/05/GHSA-h2xq-fv4r-5784/GHSA-h2xq-fv4r-5784.json @@ -7,12 +7,8 @@ "CVE-2021-24508" ], "details": "The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h37c-4pg2-6xq6/GHSA-h37c-4pg2-6xq6.json b/advisories/unreviewed/2022/05/GHSA-h37c-4pg2-6xq6/GHSA-h37c-4pg2-6xq6.json index 2d4a2bc50b2..4e20e574284 100644 --- a/advisories/unreviewed/2022/05/GHSA-h37c-4pg2-6xq6/GHSA-h37c-4pg2-6xq6.json +++ b/advisories/unreviewed/2022/05/GHSA-h37c-4pg2-6xq6/GHSA-h37c-4pg2-6xq6.json @@ -7,12 +7,8 @@ "CVE-2021-39514" ], "details": "An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3w8-j4fj-qv4j/GHSA-h3w8-j4fj-qv4j.json b/advisories/unreviewed/2022/05/GHSA-h3w8-j4fj-qv4j/GHSA-h3w8-j4fj-qv4j.json index e3207bd98d4..94961c596a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3w8-j4fj-qv4j/GHSA-h3w8-j4fj-qv4j.json +++ b/advisories/unreviewed/2022/05/GHSA-h3w8-j4fj-qv4j/GHSA-h3w8-j4fj-qv4j.json @@ -7,12 +7,8 @@ "CVE-2005-4737" ], "details": "IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by \"abnormally\" terminating a connection, which prevents db2agents from being properly cleared.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h453-w69q-mm9j/GHSA-h453-w69q-mm9j.json b/advisories/unreviewed/2022/05/GHSA-h453-w69q-mm9j/GHSA-h453-w69q-mm9j.json index 6a34a06e541..ff57ca296ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-h453-w69q-mm9j/GHSA-h453-w69q-mm9j.json +++ b/advisories/unreviewed/2022/05/GHSA-h453-w69q-mm9j/GHSA-h453-w69q-mm9j.json @@ -7,12 +7,8 @@ "CVE-2021-32281" ], "details": "An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in gravity_ast.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4rr-q2q4-72r9/GHSA-h4rr-q2q4-72r9.json b/advisories/unreviewed/2022/05/GHSA-h4rr-q2q4-72r9/GHSA-h4rr-q2q4-72r9.json index ca06a459f12..d312b2d2397 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4rr-q2q4-72r9/GHSA-h4rr-q2q4-72r9.json +++ b/advisories/unreviewed/2022/05/GHSA-h4rr-q2q4-72r9/GHSA-h4rr-q2q4-72r9.json @@ -7,12 +7,8 @@ "CVE-2005-4592" ], "details": "Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h4rw-rm6c-ghvc/GHSA-h4rw-rm6c-ghvc.json b/advisories/unreviewed/2022/05/GHSA-h4rw-rm6c-ghvc/GHSA-h4rw-rm6c-ghvc.json index 6f9c1ac13ca..8ce819ac34b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4rw-rm6c-ghvc/GHSA-h4rw-rm6c-ghvc.json +++ b/advisories/unreviewed/2022/05/GHSA-h4rw-rm6c-ghvc/GHSA-h4rw-rm6c-ghvc.json @@ -7,12 +7,8 @@ "CVE-2021-38332" ], "details": "The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5vp-8vfv-4cgp/GHSA-h5vp-8vfv-4cgp.json b/advisories/unreviewed/2022/05/GHSA-h5vp-8vfv-4cgp/GHSA-h5vp-8vfv-4cgp.json index 3b4f42fb7f3..29525f1c422 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5vp-8vfv-4cgp/GHSA-h5vp-8vfv-4cgp.json +++ b/advisories/unreviewed/2022/05/GHSA-h5vp-8vfv-4cgp/GHSA-h5vp-8vfv-4cgp.json @@ -7,12 +7,8 @@ "CVE-2021-33691" ], "details": "NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a victim. If the victim has an active session when the crafted script gets executed, the threat actor could compromise information in victims session, and gain access to some sensitive information also.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5w8-c4g8-8ch6/GHSA-h5w8-c4g8-8ch6.json b/advisories/unreviewed/2022/05/GHSA-h5w8-c4g8-8ch6/GHSA-h5w8-c4g8-8ch6.json index fe4b13f1eda..f42ccdd9688 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5w8-c4g8-8ch6/GHSA-h5w8-c4g8-8ch6.json +++ b/advisories/unreviewed/2022/05/GHSA-h5w8-c4g8-8ch6/GHSA-h5w8-c4g8-8ch6.json @@ -7,12 +7,8 @@ "CVE-2021-34343" ], "details": "A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210701 and later QuTScloud c4.5.6.1755 and later QuTS hero h4.5.4.1771 build 20210825 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h737-pm89-7j57/GHSA-h737-pm89-7j57.json b/advisories/unreviewed/2022/05/GHSA-h737-pm89-7j57/GHSA-h737-pm89-7j57.json index ea9d1252151..0a843a3f7d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-h737-pm89-7j57/GHSA-h737-pm89-7j57.json +++ b/advisories/unreviewed/2022/05/GHSA-h737-pm89-7j57/GHSA-h737-pm89-7j57.json @@ -7,12 +7,8 @@ "CVE-2005-4405" ], "details": "redqueen.cgi in Red Queen 1.02 and earlier allows remote attackers to obtain the full server path via invalid (1) yellowpage_id, (2) skin_id, (3) supplier_id, and (4) module parameters, which leaks the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h746-v282-j5wj/GHSA-h746-v282-j5wj.json b/advisories/unreviewed/2022/05/GHSA-h746-v282-j5wj/GHSA-h746-v282-j5wj.json index 9e7c3fdbb96..ed19081181f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h746-v282-j5wj/GHSA-h746-v282-j5wj.json +++ b/advisories/unreviewed/2022/05/GHSA-h746-v282-j5wj/GHSA-h746-v282-j5wj.json @@ -7,12 +7,8 @@ "CVE-2020-19915" ], "details": "Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7vp-qvfw-h2f3/GHSA-h7vp-qvfw-h2f3.json b/advisories/unreviewed/2022/05/GHSA-h7vp-qvfw-h2f3/GHSA-h7vp-qvfw-h2f3.json index 07958442f17..be0cb8deab5 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7vp-qvfw-h2f3/GHSA-h7vp-qvfw-h2f3.json +++ b/advisories/unreviewed/2022/05/GHSA-h7vp-qvfw-h2f3/GHSA-h7vp-qvfw-h2f3.json @@ -7,12 +7,8 @@ "CVE-2005-4536" ], "details": "Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h84p-p4v5-gw25/GHSA-h84p-p4v5-gw25.json b/advisories/unreviewed/2022/05/GHSA-h84p-p4v5-gw25/GHSA-h84p-p4v5-gw25.json index fb3fc205401..a0130ba4484 100644 --- a/advisories/unreviewed/2022/05/GHSA-h84p-p4v5-gw25/GHSA-h84p-p4v5-gw25.json +++ b/advisories/unreviewed/2022/05/GHSA-h84p-p4v5-gw25/GHSA-h84p-p4v5-gw25.json @@ -7,12 +7,8 @@ "CVE-2005-4417" ], "details": "The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send arbitrary audio and possibly eavesdrop using the microphone via the Hands Free Audio Gateway and Headset profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h938-qvmh-8rqv/GHSA-h938-qvmh-8rqv.json b/advisories/unreviewed/2022/05/GHSA-h938-qvmh-8rqv/GHSA-h938-qvmh-8rqv.json index 3eee600b7fc..db409d662f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h938-qvmh-8rqv/GHSA-h938-qvmh-8rqv.json +++ b/advisories/unreviewed/2022/05/GHSA-h938-qvmh-8rqv/GHSA-h938-qvmh-8rqv.json @@ -7,12 +7,8 @@ "CVE-2005-4670" ], "details": "Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h98r-cwxp-2m8m/GHSA-h98r-cwxp-2m8m.json b/advisories/unreviewed/2022/05/GHSA-h98r-cwxp-2m8m/GHSA-h98r-cwxp-2m8m.json index ec68b0b10eb..226093938ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-h98r-cwxp-2m8m/GHSA-h98r-cwxp-2m8m.json +++ b/advisories/unreviewed/2022/05/GHSA-h98r-cwxp-2m8m/GHSA-h98r-cwxp-2m8m.json @@ -7,12 +7,8 @@ "CVE-2021-33720" ], "details": "A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP200 (All versions), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Specially crafted packets sent to port 4443/tcp could cause a Denial-of-Service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9fc-rg7x-48xg/GHSA-h9fc-rg7x-48xg.json b/advisories/unreviewed/2022/05/GHSA-h9fc-rg7x-48xg/GHSA-h9fc-rg7x-48xg.json index 9a7d20a27e6..ab5af3bcfde 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9fc-rg7x-48xg/GHSA-h9fc-rg7x-48xg.json +++ b/advisories/unreviewed/2022/05/GHSA-h9fc-rg7x-48xg/GHSA-h9fc-rg7x-48xg.json @@ -7,12 +7,8 @@ "CVE-2021-39536" ], "details": "An issue was discovered in libxsmm through v1.16.1-93. The JIT code has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc82-f9w8-5qqv/GHSA-hc82-f9w8-5qqv.json b/advisories/unreviewed/2022/05/GHSA-hc82-f9w8-5qqv/GHSA-hc82-f9w8-5qqv.json index a755d043738..5fb8cccba83 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc82-f9w8-5qqv/GHSA-hc82-f9w8-5qqv.json +++ b/advisories/unreviewed/2022/05/GHSA-hc82-f9w8-5qqv/GHSA-hc82-f9w8-5qqv.json @@ -7,12 +7,8 @@ "CVE-2005-4660" ], "details": "Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by \"nobody\" but not yet encrypted, then executing ipcoprscfg to restore from this backup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hchr-g8fg-g2r7/GHSA-hchr-g8fg-g2r7.json b/advisories/unreviewed/2022/05/GHSA-hchr-g8fg-g2r7/GHSA-hchr-g8fg-g2r7.json index 2c9d0097fe4..125da9f5434 100644 --- a/advisories/unreviewed/2022/05/GHSA-hchr-g8fg-g2r7/GHSA-hchr-g8fg-g2r7.json +++ b/advisories/unreviewed/2022/05/GHSA-hchr-g8fg-g2r7/GHSA-hchr-g8fg-g2r7.json @@ -7,12 +7,8 @@ "CVE-2005-4832" ], "details": "SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcj7-753j-h8mf/GHSA-hcj7-753j-h8mf.json b/advisories/unreviewed/2022/05/GHSA-hcj7-753j-h8mf/GHSA-hcj7-753j-h8mf.json index 5c92ca19f50..c1f0e9f2c01 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcj7-753j-h8mf/GHSA-hcj7-753j-h8mf.json +++ b/advisories/unreviewed/2022/05/GHSA-hcj7-753j-h8mf/GHSA-hcj7-753j-h8mf.json @@ -7,12 +7,8 @@ "CVE-2021-24619" ], "details": "The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcq2-9985-7gxv/GHSA-hcq2-9985-7gxv.json b/advisories/unreviewed/2022/05/GHSA-hcq2-9985-7gxv/GHSA-hcq2-9985-7gxv.json index 58c0321a47d..ac9d7a32b4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcq2-9985-7gxv/GHSA-hcq2-9985-7gxv.json +++ b/advisories/unreviewed/2022/05/GHSA-hcq2-9985-7gxv/GHSA-hcq2-9985-7gxv.json @@ -7,12 +7,8 @@ "CVE-2021-38304" ], "details": "Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcvx-9jxc-j8w3/GHSA-hcvx-9jxc-j8w3.json b/advisories/unreviewed/2022/05/GHSA-hcvx-9jxc-j8w3/GHSA-hcvx-9jxc-j8w3.json index f6a30383dfa..783808fcebc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcvx-9jxc-j8w3/GHSA-hcvx-9jxc-j8w3.json +++ b/advisories/unreviewed/2022/05/GHSA-hcvx-9jxc-j8w3/GHSA-hcvx-9jxc-j8w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcx3-h3xc-47cc/GHSA-hcx3-h3xc-47cc.json b/advisories/unreviewed/2022/05/GHSA-hcx3-h3xc-47cc/GHSA-hcx3-h3xc-47cc.json index d99577e1ce4..5378d82a50a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcx3-h3xc-47cc/GHSA-hcx3-h3xc-47cc.json +++ b/advisories/unreviewed/2022/05/GHSA-hcx3-h3xc-47cc/GHSA-hcx3-h3xc-47cc.json @@ -7,12 +7,8 @@ "CVE-2021-1976" ], "details": "A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf4v-9m67-rprw/GHSA-hf4v-9m67-rprw.json b/advisories/unreviewed/2022/05/GHSA-hf4v-9m67-rprw/GHSA-hf4v-9m67-rprw.json index 09eb721589e..e11bb4690fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf4v-9m67-rprw/GHSA-hf4v-9m67-rprw.json +++ b/advisories/unreviewed/2022/05/GHSA-hf4v-9m67-rprw/GHSA-hf4v-9m67-rprw.json @@ -7,12 +7,8 @@ "CVE-2021-32987" ], "details": "Null pointer dereference in SuiteLink server while processing command 0x0b", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfq3-j248-m7rx/GHSA-hfq3-j248-m7rx.json b/advisories/unreviewed/2022/05/GHSA-hfq3-j248-m7rx/GHSA-hfq3-j248-m7rx.json index f245f4c635f..7b86ad99ff9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfq3-j248-m7rx/GHSA-hfq3-j248-m7rx.json +++ b/advisories/unreviewed/2022/05/GHSA-hfq3-j248-m7rx/GHSA-hfq3-j248-m7rx.json @@ -7,12 +7,8 @@ "CVE-2021-24403" ], "details": "The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhcw-hw4m-h4v7/GHSA-hhcw-hw4m-h4v7.json b/advisories/unreviewed/2022/05/GHSA-hhcw-hw4m-h4v7/GHSA-hhcw-hw4m-h4v7.json index ed8942fc4ce..d94eaaaba50 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhcw-hw4m-h4v7/GHSA-hhcw-hw4m-h4v7.json +++ b/advisories/unreviewed/2022/05/GHSA-hhcw-hw4m-h4v7/GHSA-hhcw-hw4m-h4v7.json @@ -7,12 +7,8 @@ "CVE-2005-4736" ], "details": "IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhm2-3v7q-xp8q/GHSA-hhm2-3v7q-xp8q.json b/advisories/unreviewed/2022/05/GHSA-hhm2-3v7q-xp8q/GHSA-hhm2-3v7q-xp8q.json index 9b26b54e9fc..420dc12b364 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhm2-3v7q-xp8q/GHSA-hhm2-3v7q-xp8q.json +++ b/advisories/unreviewed/2022/05/GHSA-hhm2-3v7q-xp8q/GHSA-hhm2-3v7q-xp8q.json @@ -7,12 +7,8 @@ "CVE-2005-4460" ], "details": "Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhp5-2m4q-mmrp/GHSA-hhp5-2m4q-mmrp.json b/advisories/unreviewed/2022/05/GHSA-hhp5-2m4q-mmrp/GHSA-hhp5-2m4q-mmrp.json index 0ce35f1318d..d9cc9fe08e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhp5-2m4q-mmrp/GHSA-hhp5-2m4q-mmrp.json +++ b/advisories/unreviewed/2022/05/GHSA-hhp5-2m4q-mmrp/GHSA-hhp5-2m4q-mmrp.json @@ -7,12 +7,8 @@ "CVE-2021-39590" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjv5-g5g9-4cg4/GHSA-hjv5-g5g9-4cg4.json b/advisories/unreviewed/2022/05/GHSA-hjv5-g5g9-4cg4/GHSA-hjv5-g5g9-4cg4.json index 8724a67a035..eb67fbca146 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjv5-g5g9-4cg4/GHSA-hjv5-g5g9-4cg4.json +++ b/advisories/unreviewed/2022/05/GHSA-hjv5-g5g9-4cg4/GHSA-hjv5-g5g9-4cg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hm4g-g7fc-3qxj/GHSA-hm4g-g7fc-3qxj.json b/advisories/unreviewed/2022/05/GHSA-hm4g-g7fc-3qxj/GHSA-hm4g-g7fc-3qxj.json index c5fafd50a7c..965cbc2d80b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm4g-g7fc-3qxj/GHSA-hm4g-g7fc-3qxj.json +++ b/advisories/unreviewed/2022/05/GHSA-hm4g-g7fc-3qxj/GHSA-hm4g-g7fc-3qxj.json @@ -7,12 +7,8 @@ "CVE-2005-4862" ], "details": "The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a search string that matches a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp3w-wv98-497f/GHSA-hp3w-wv98-497f.json b/advisories/unreviewed/2022/05/GHSA-hp3w-wv98-497f/GHSA-hp3w-wv98-497f.json index 6b09645d155..e18a88877a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp3w-wv98-497f/GHSA-hp3w-wv98-497f.json +++ b/advisories/unreviewed/2022/05/GHSA-hp3w-wv98-497f/GHSA-hp3w-wv98-497f.json @@ -7,12 +7,8 @@ "CVE-2005-4749" ], "details": "HTTP request smuggling vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allows remote attackers to inject arbitrary HTTP headers via unspecified attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp8r-3wgf-2x3x/GHSA-hp8r-3wgf-2x3x.json b/advisories/unreviewed/2022/05/GHSA-hp8r-3wgf-2x3x/GHSA-hp8r-3wgf-2x3x.json index 3d930bc6686..d76077ed1c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp8r-3wgf-2x3x/GHSA-hp8r-3wgf-2x3x.json +++ b/advisories/unreviewed/2022/05/GHSA-hp8r-3wgf-2x3x/GHSA-hp8r-3wgf-2x3x.json @@ -7,12 +7,8 @@ "CVE-2005-4652" ], "details": "SQL injection vulnerability in PHlyMail 3.02.01 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpj4-vj9f-q9hf/GHSA-hpj4-vj9f-q9hf.json b/advisories/unreviewed/2022/05/GHSA-hpj4-vj9f-q9hf/GHSA-hpj4-vj9f-q9hf.json index 9c10748b1ec..ab952d5486f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpj4-vj9f-q9hf/GHSA-hpj4-vj9f-q9hf.json +++ b/advisories/unreviewed/2022/05/GHSA-hpj4-vj9f-q9hf/GHSA-hpj4-vj9f-q9hf.json @@ -7,12 +7,8 @@ "CVE-2021-1612" ], "details": "A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on an affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq44-653c-fqqh/GHSA-hq44-653c-fqqh.json b/advisories/unreviewed/2022/05/GHSA-hq44-653c-fqqh/GHSA-hq44-653c-fqqh.json index 2f61a3ef4da..353a34a9965 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq44-653c-fqqh/GHSA-hq44-653c-fqqh.json +++ b/advisories/unreviewed/2022/05/GHSA-hq44-653c-fqqh/GHSA-hq44-653c-fqqh.json @@ -7,12 +7,8 @@ "CVE-2005-4778" ], "details": "The powersave daemon in SUSE Linux 10.0 before 20051007 has an unspecified \"configuration problem,\" which allows local users to suspend the computer and possibly perform certain other unauthorized actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq64-63h4-3rpx/GHSA-hq64-63h4-3rpx.json b/advisories/unreviewed/2022/05/GHSA-hq64-63h4-3rpx/GHSA-hq64-63h4-3rpx.json index 7fc13387875..5ff21cb3c75 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq64-63h4-3rpx/GHSA-hq64-63h4-3rpx.json +++ b/advisories/unreviewed/2022/05/GHSA-hq64-63h4-3rpx/GHSA-hq64-63h4-3rpx.json @@ -7,12 +7,8 @@ "CVE-2005-4852" ], "details": "The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (underscore), which allows remote attackers to bypass access restrictions by inserting certain characters in a URI, as demonstrated by a request for /admin:de, which matches a rule allowing only /admin_de to access /admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqcv-5gqh-jcfh/GHSA-hqcv-5gqh-jcfh.json b/advisories/unreviewed/2022/05/GHSA-hqcv-5gqh-jcfh/GHSA-hqcv-5gqh-jcfh.json index 909e92d1cbe..43b4ff7f4b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqcv-5gqh-jcfh/GHSA-hqcv-5gqh-jcfh.json +++ b/advisories/unreviewed/2022/05/GHSA-hqcv-5gqh-jcfh/GHSA-hqcv-5gqh-jcfh.json @@ -7,12 +7,8 @@ "CVE-2021-24614" ], "details": "The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqmc-p4j8-4rqc/GHSA-hqmc-p4j8-4rqc.json b/advisories/unreviewed/2022/05/GHSA-hqmc-p4j8-4rqc/GHSA-hqmc-p4j8-4rqc.json index 711e104d5b1..74003ef4732 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqmc-p4j8-4rqc/GHSA-hqmc-p4j8-4rqc.json +++ b/advisories/unreviewed/2022/05/GHSA-hqmc-p4j8-4rqc/GHSA-hqmc-p4j8-4rqc.json @@ -7,12 +7,8 @@ "CVE-2005-4493" ], "details": "Cross-site scripting (XSS) vulnerability in SpearTek 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqrg-vp62-hmj7/GHSA-hqrg-vp62-hmj7.json b/advisories/unreviewed/2022/05/GHSA-hqrg-vp62-hmj7/GHSA-hqrg-vp62-hmj7.json index 69150500567..62ea6ca5616 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqrg-vp62-hmj7/GHSA-hqrg-vp62-hmj7.json +++ b/advisories/unreviewed/2022/05/GHSA-hqrg-vp62-hmj7/GHSA-hqrg-vp62-hmj7.json @@ -7,12 +7,8 @@ "CVE-2021-3824" ], "details": "OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrv2-qc6c-j67q/GHSA-hrv2-qc6c-j67q.json b/advisories/unreviewed/2022/05/GHSA-hrv2-qc6c-j67q/GHSA-hrv2-qc6c-j67q.json index 4afb33bc78d..92590abe6eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrv2-qc6c-j67q/GHSA-hrv2-qc6c-j67q.json +++ b/advisories/unreviewed/2022/05/GHSA-hrv2-qc6c-j67q/GHSA-hrv2-qc6c-j67q.json @@ -7,12 +7,8 @@ "CVE-2005-4603" ], "details": "Cross-site scripting (XSS) vulnerability in printthread.php in MyBB 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a thread message, which is not properly sanitized in the print view of the thread.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv27-4gff-hf2w/GHSA-hv27-4gff-hf2w.json b/advisories/unreviewed/2022/05/GHSA-hv27-4gff-hf2w/GHSA-hv27-4gff-hf2w.json index 840bd99ffdc..65a6ce3e053 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv27-4gff-hf2w/GHSA-hv27-4gff-hf2w.json +++ b/advisories/unreviewed/2022/05/GHSA-hv27-4gff-hf2w/GHSA-hv27-4gff-hf2w.json @@ -7,12 +7,8 @@ "CVE-2005-4568" ], "details": "Multiple format string vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allow remote attackers to execute arbitrary code via format string specifiers in the (1) USER, (2) PASS, and (3) TOP commands to the POP3 server; and the (4) LIST and (5) AUTHENTICATE commands to the IMAP server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv4v-qgpx-4225/GHSA-hv4v-qgpx-4225.json b/advisories/unreviewed/2022/05/GHSA-hv4v-qgpx-4225/GHSA-hv4v-qgpx-4225.json index 83d3d504995..9d532041729 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv4v-qgpx-4225/GHSA-hv4v-qgpx-4225.json +++ b/advisories/unreviewed/2022/05/GHSA-hv4v-qgpx-4225/GHSA-hv4v-qgpx-4225.json @@ -7,12 +7,8 @@ "CVE-2005-4864" ], "details": "Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw2j-hpjq-wvhv/GHSA-hw2j-hpjq-wvhv.json b/advisories/unreviewed/2022/05/GHSA-hw2j-hpjq-wvhv/GHSA-hw2j-hpjq-wvhv.json index 95924b3fe65..54bb68d2b0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw2j-hpjq-wvhv/GHSA-hw2j-hpjq-wvhv.json +++ b/advisories/unreviewed/2022/05/GHSA-hw2j-hpjq-wvhv/GHSA-hw2j-hpjq-wvhv.json @@ -7,12 +7,8 @@ "CVE-2005-4730" ], "details": "Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to \"problematic seeding\" of the random number generator, possibly predictable seeds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw4w-cm9x-6hg5/GHSA-hw4w-cm9x-6hg5.json b/advisories/unreviewed/2022/05/GHSA-hw4w-cm9x-6hg5/GHSA-hw4w-cm9x-6hg5.json index 81f28b3d842..4d4b5cde942 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw4w-cm9x-6hg5/GHSA-hw4w-cm9x-6hg5.json +++ b/advisories/unreviewed/2022/05/GHSA-hw4w-cm9x-6hg5/GHSA-hw4w-cm9x-6hg5.json @@ -7,12 +7,8 @@ "CVE-2021-34769" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j24v-hvrr-gw8v/GHSA-j24v-hvrr-gw8v.json b/advisories/unreviewed/2022/05/GHSA-j24v-hvrr-gw8v/GHSA-j24v-hvrr-gw8v.json index 7418fddc26d..40ebf063ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j24v-hvrr-gw8v/GHSA-j24v-hvrr-gw8v.json +++ b/advisories/unreviewed/2022/05/GHSA-j24v-hvrr-gw8v/GHSA-j24v-hvrr-gw8v.json @@ -7,12 +7,8 @@ "CVE-2020-19147" ], "details": "Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j269-fp7g-8w8w/GHSA-j269-fp7g-8w8w.json b/advisories/unreviewed/2022/05/GHSA-j269-fp7g-8w8w/GHSA-j269-fp7g-8w8w.json index 85bcff64fd7..f1bca079e58 100644 --- a/advisories/unreviewed/2022/05/GHSA-j269-fp7g-8w8w/GHSA-j269-fp7g-8w8w.json +++ b/advisories/unreviewed/2022/05/GHSA-j269-fp7g-8w8w/GHSA-j269-fp7g-8w8w.json @@ -7,12 +7,8 @@ "CVE-2005-4491" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b) Request-call-back.html and (c) registration-form.html. NOTE: the vendor states \"This issue was resolved by a minor update to Sitekit CMS v6.6, sanitising the html code and eradicating related security issues.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2pc-g7pm-qf6j/GHSA-j2pc-g7pm-qf6j.json b/advisories/unreviewed/2022/05/GHSA-j2pc-g7pm-qf6j/GHSA-j2pc-g7pm-qf6j.json index d8993420138..64c81a6c178 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2pc-g7pm-qf6j/GHSA-j2pc-g7pm-qf6j.json +++ b/advisories/unreviewed/2022/05/GHSA-j2pc-g7pm-qf6j/GHSA-j2pc-g7pm-qf6j.json @@ -7,12 +7,8 @@ "CVE-2005-4554" ], "details": "Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j3qq-rrg5-j2xr/GHSA-j3qq-rrg5-j2xr.json b/advisories/unreviewed/2022/05/GHSA-j3qq-rrg5-j2xr/GHSA-j3qq-rrg5-j2xr.json index 93a3801549a..d9d6a6df7dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3qq-rrg5-j2xr/GHSA-j3qq-rrg5-j2xr.json +++ b/advisories/unreviewed/2022/05/GHSA-j3qq-rrg5-j2xr/GHSA-j3qq-rrg5-j2xr.json @@ -7,12 +7,8 @@ "CVE-2021-32971" ], "details": "Null pointer dereference in SuiteLink server while processing command 0x07", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json b/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json index eeb512d22e1..dece424049f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json +++ b/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json @@ -7,12 +7,8 @@ "CVE-2021-38406" ], "details": "Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j43m-hrxf-c3hp/GHSA-j43m-hrxf-c3hp.json b/advisories/unreviewed/2022/05/GHSA-j43m-hrxf-c3hp/GHSA-j43m-hrxf-c3hp.json index fa36c415eaf..1cd5ee98ad9 100644 --- a/advisories/unreviewed/2022/05/GHSA-j43m-hrxf-c3hp/GHSA-j43m-hrxf-c3hp.json +++ b/advisories/unreviewed/2022/05/GHSA-j43m-hrxf-c3hp/GHSA-j43m-hrxf-c3hp.json @@ -7,12 +7,8 @@ "CVE-2021-39583" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4gg-fhrw-m69g/GHSA-j4gg-fhrw-m69g.json b/advisories/unreviewed/2022/05/GHSA-j4gg-fhrw-m69g/GHSA-j4gg-fhrw-m69g.json index bf3822745ed..7d921cc7edf 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4gg-fhrw-m69g/GHSA-j4gg-fhrw-m69g.json +++ b/advisories/unreviewed/2022/05/GHSA-j4gg-fhrw-m69g/GHSA-j4gg-fhrw-m69g.json @@ -7,12 +7,8 @@ "CVE-2020-20671" ], "details": "A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j53v-j7wc-f9g9/GHSA-j53v-j7wc-f9g9.json b/advisories/unreviewed/2022/05/GHSA-j53v-j7wc-f9g9/GHSA-j53v-j7wc-f9g9.json index 30c86e0c155..98b75d4515c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j53v-j7wc-f9g9/GHSA-j53v-j7wc-f9g9.json +++ b/advisories/unreviewed/2022/05/GHSA-j53v-j7wc-f9g9/GHSA-j53v-j7wc-f9g9.json @@ -7,12 +7,8 @@ "CVE-2005-4867" ], "details": "Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j54w-v35m-r2j7/GHSA-j54w-v35m-r2j7.json b/advisories/unreviewed/2022/05/GHSA-j54w-v35m-r2j7/GHSA-j54w-v35m-r2j7.json index fd0ead89d2d..2cf1233c4e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j54w-v35m-r2j7/GHSA-j54w-v35m-r2j7.json +++ b/advisories/unreviewed/2022/05/GHSA-j54w-v35m-r2j7/GHSA-j54w-v35m-r2j7.json @@ -7,12 +7,8 @@ "CVE-2005-4411" ], "details": "Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j56h-v988-6xx4/GHSA-j56h-v988-6xx4.json b/advisories/unreviewed/2022/05/GHSA-j56h-v988-6xx4/GHSA-j56h-v988-6xx4.json index d8f52719775..7829bea90b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j56h-v988-6xx4/GHSA-j56h-v988-6xx4.json +++ b/advisories/unreviewed/2022/05/GHSA-j56h-v988-6xx4/GHSA-j56h-v988-6xx4.json @@ -7,12 +7,8 @@ "CVE-2021-39564" ], "details": "An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5cv-h8xh-gwcp/GHSA-j5cv-h8xh-gwcp.json b/advisories/unreviewed/2022/05/GHSA-j5cv-h8xh-gwcp/GHSA-j5cv-h8xh-gwcp.json index c92f08ddc7b..f560bb4563c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5cv-h8xh-gwcp/GHSA-j5cv-h8xh-gwcp.json +++ b/advisories/unreviewed/2022/05/GHSA-j5cv-h8xh-gwcp/GHSA-j5cv-h8xh-gwcp.json @@ -7,12 +7,8 @@ "CVE-2021-40214" ], "details": "Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5jc-fjph-vx57/GHSA-j5jc-fjph-vx57.json b/advisories/unreviewed/2022/05/GHSA-j5jc-fjph-vx57/GHSA-j5jc-fjph-vx57.json index 7eabe6b28a7..d7ce007ec00 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5jc-fjph-vx57/GHSA-j5jc-fjph-vx57.json +++ b/advisories/unreviewed/2022/05/GHSA-j5jc-fjph-vx57/GHSA-j5jc-fjph-vx57.json @@ -7,12 +7,8 @@ "CVE-2005-4878" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to inject arbitrary web script or HTML via the sig[1] parameter and possibly other parameters, a different vulnerability than CVE-2007-6156.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5qr-8rrw-8f9v/GHSA-j5qr-8rrw-8f9v.json b/advisories/unreviewed/2022/05/GHSA-j5qr-8rrw-8f9v/GHSA-j5qr-8rrw-8f9v.json index 30a881889d4..bdc16182f24 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5qr-8rrw-8f9v/GHSA-j5qr-8rrw-8f9v.json +++ b/advisories/unreviewed/2022/05/GHSA-j5qr-8rrw-8f9v/GHSA-j5qr-8rrw-8f9v.json @@ -7,12 +7,8 @@ "CVE-2021-1939" ], "details": "Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5wq-jc5r-xp97/GHSA-j5wq-jc5r-xp97.json b/advisories/unreviewed/2022/05/GHSA-j5wq-jc5r-xp97/GHSA-j5wq-jc5r-xp97.json index 835da568412..a7bb379920f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5wq-jc5r-xp97/GHSA-j5wq-jc5r-xp97.json +++ b/advisories/unreviewed/2022/05/GHSA-j5wq-jc5r-xp97/GHSA-j5wq-jc5r-xp97.json @@ -7,12 +7,8 @@ "CVE-2005-4461" ], "details": "SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6h9-6xvv-v8ph/GHSA-j6h9-6xvv-v8ph.json b/advisories/unreviewed/2022/05/GHSA-j6h9-6xvv-v8ph/GHSA-j6h9-6xvv-v8ph.json index 21dee39805f..3d05a965b42 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6h9-6xvv-v8ph/GHSA-j6h9-6xvv-v8ph.json +++ b/advisories/unreviewed/2022/05/GHSA-j6h9-6xvv-v8ph/GHSA-j6h9-6xvv-v8ph.json @@ -7,12 +7,8 @@ "CVE-2021-29856" ], "details": "IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBM X-Force ID: 205685.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j7p2-mjw4-64cc/GHSA-j7p2-mjw4-64cc.json b/advisories/unreviewed/2022/05/GHSA-j7p2-mjw4-64cc/GHSA-j7p2-mjw4-64cc.json index 4ea9d25b4cf..cc973fbc248 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7p2-mjw4-64cc/GHSA-j7p2-mjw4-64cc.json +++ b/advisories/unreviewed/2022/05/GHSA-j7p2-mjw4-64cc/GHSA-j7p2-mjw4-64cc.json @@ -7,12 +7,8 @@ "CVE-2005-4570" ], "details": "The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec attributes, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the vendor advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j86f-g83j-qw65/GHSA-j86f-g83j-qw65.json b/advisories/unreviewed/2022/05/GHSA-j86f-g83j-qw65/GHSA-j86f-g83j-qw65.json index ee4f6104bcf..556215736a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j86f-g83j-qw65/GHSA-j86f-g83j-qw65.json +++ b/advisories/unreviewed/2022/05/GHSA-j86f-g83j-qw65/GHSA-j86f-g83j-qw65.json @@ -7,12 +7,8 @@ "CVE-2005-4704" ], "details": "Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user credentials to be sent across the network in cleartext and allows remote attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8jm-5rrf-g8mp/GHSA-j8jm-5rrf-g8mp.json b/advisories/unreviewed/2022/05/GHSA-j8jm-5rrf-g8mp/GHSA-j8jm-5rrf-g8mp.json index 07f55e4865b..776b92cb8d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8jm-5rrf-g8mp/GHSA-j8jm-5rrf-g8mp.json +++ b/advisories/unreviewed/2022/05/GHSA-j8jm-5rrf-g8mp/GHSA-j8jm-5rrf-g8mp.json @@ -7,12 +7,8 @@ "CVE-2005-4483" ], "details": "Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j985-mvrq-83h7/GHSA-j985-mvrq-83h7.json b/advisories/unreviewed/2022/05/GHSA-j985-mvrq-83h7/GHSA-j985-mvrq-83h7.json index 2d10a117c2a..b453f193f18 100644 --- a/advisories/unreviewed/2022/05/GHSA-j985-mvrq-83h7/GHSA-j985-mvrq-83h7.json +++ b/advisories/unreviewed/2022/05/GHSA-j985-mvrq-83h7/GHSA-j985-mvrq-83h7.json @@ -7,12 +7,8 @@ "CVE-2005-4689" ], "details": "Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc3j-r3vh-w677/GHSA-jc3j-r3vh-w677.json b/advisories/unreviewed/2022/05/GHSA-jc3j-r3vh-w677/GHSA-jc3j-r3vh-w677.json index 29c845d5d47..33ecd965c8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc3j-r3vh-w677/GHSA-jc3j-r3vh-w677.json +++ b/advisories/unreviewed/2022/05/GHSA-jc3j-r3vh-w677/GHSA-jc3j-r3vh-w677.json @@ -7,12 +7,8 @@ "CVE-2021-38404" ], "details": "Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcg8-68f4-v6r7/GHSA-jcg8-68f4-v6r7.json b/advisories/unreviewed/2022/05/GHSA-jcg8-68f4-v6r7/GHSA-jcg8-68f4-v6r7.json index 3cf9db680bd..fe4810a365d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcg8-68f4-v6r7/GHSA-jcg8-68f4-v6r7.json +++ b/advisories/unreviewed/2022/05/GHSA-jcg8-68f4-v6r7/GHSA-jcg8-68f4-v6r7.json @@ -7,12 +7,8 @@ "CVE-2005-4757" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly \"constrain\" a \"/\" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf53-8v78-xf68/GHSA-jf53-8v78-xf68.json b/advisories/unreviewed/2022/05/GHSA-jf53-8v78-xf68/GHSA-jf53-8v78-xf68.json index 573e32c16c4..ae4e69f7be6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf53-8v78-xf68/GHSA-jf53-8v78-xf68.json +++ b/advisories/unreviewed/2022/05/GHSA-jf53-8v78-xf68/GHSA-jf53-8v78-xf68.json @@ -7,12 +7,8 @@ "CVE-2021-22016" ], "details": "The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfwc-rxqw-vvj6/GHSA-jfwc-rxqw-vvj6.json b/advisories/unreviewed/2022/05/GHSA-jfwc-rxqw-vvj6/GHSA-jfwc-rxqw-vvj6.json index 3ecdb21c097..08745558d6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfwc-rxqw-vvj6/GHSA-jfwc-rxqw-vvj6.json +++ b/advisories/unreviewed/2022/05/GHSA-jfwc-rxqw-vvj6/GHSA-jfwc-rxqw-vvj6.json @@ -7,12 +7,8 @@ "CVE-2005-4881" ], "details": "The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgp5-g26h-hfg8/GHSA-jgp5-g26h-hfg8.json b/advisories/unreviewed/2022/05/GHSA-jgp5-g26h-hfg8/GHSA-jgp5-g26h-hfg8.json index e4006d094d5..20bacfe7e03 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgp5-g26h-hfg8/GHSA-jgp5-g26h-hfg8.json +++ b/advisories/unreviewed/2022/05/GHSA-jgp5-g26h-hfg8/GHSA-jgp5-g26h-hfg8.json @@ -7,12 +7,8 @@ "CVE-2005-4669" ], "details": "SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhgg-m334-7pxp/GHSA-jhgg-m334-7pxp.json b/advisories/unreviewed/2022/05/GHSA-jhgg-m334-7pxp/GHSA-jhgg-m334-7pxp.json index cdc34489027..c749a194970 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhgg-m334-7pxp/GHSA-jhgg-m334-7pxp.json +++ b/advisories/unreviewed/2022/05/GHSA-jhgg-m334-7pxp/GHSA-jhgg-m334-7pxp.json @@ -7,12 +7,8 @@ "CVE-2021-39556" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmg8-fp8v-pc6j/GHSA-jmg8-fp8v-pc6j.json b/advisories/unreviewed/2022/05/GHSA-jmg8-fp8v-pc6j/GHSA-jmg8-fp8v-pc6j.json index fe0af5d7ef2..444dad38c2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmg8-fp8v-pc6j/GHSA-jmg8-fp8v-pc6j.json +++ b/advisories/unreviewed/2022/05/GHSA-jmg8-fp8v-pc6j/GHSA-jmg8-fp8v-pc6j.json @@ -7,12 +7,8 @@ "CVE-2005-4763" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier, when Internet Inter-ORB Protocol (IIOP) is used, sometimes include a password in an exception message that is sent to a client or stored in a log file, which might allow remote attackers to perform unauthorized actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jpj8-cwj3-qpvw/GHSA-jpj8-cwj3-qpvw.json b/advisories/unreviewed/2022/05/GHSA-jpj8-cwj3-qpvw/GHSA-jpj8-cwj3-qpvw.json index 49c3c2aef0a..f9cbe14702e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpj8-cwj3-qpvw/GHSA-jpj8-cwj3-qpvw.json +++ b/advisories/unreviewed/2022/05/GHSA-jpj8-cwj3-qpvw/GHSA-jpj8-cwj3-qpvw.json @@ -7,12 +7,8 @@ "CVE-2005-4876" ], "details": "Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.2.2, and possibly other versions before 2.3.0 Beta 2, allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-4877.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq7c-356h-gj6r/GHSA-jq7c-356h-gj6r.json b/advisories/unreviewed/2022/05/GHSA-jq7c-356h-gj6r/GHSA-jq7c-356h-gj6r.json index 2c2982e7912..40b42335895 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq7c-356h-gj6r/GHSA-jq7c-356h-gj6r.json +++ b/advisories/unreviewed/2022/05/GHSA-jq7c-356h-gj6r/GHSA-jq7c-356h-gj6r.json @@ -7,12 +7,8 @@ "CVE-2005-4850" ], "details": "eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jq8g-94vx-pgrm/GHSA-jq8g-94vx-pgrm.json b/advisories/unreviewed/2022/05/GHSA-jq8g-94vx-pgrm/GHSA-jq8g-94vx-pgrm.json index 3d38305d5c8..1b38c34fa71 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq8g-94vx-pgrm/GHSA-jq8g-94vx-pgrm.json +++ b/advisories/unreviewed/2022/05/GHSA-jq8g-94vx-pgrm/GHSA-jq8g-94vx-pgrm.json @@ -7,12 +7,8 @@ "CVE-2021-39585" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqp4-j8cc-wx66/GHSA-jqp4-j8cc-wx66.json b/advisories/unreviewed/2022/05/GHSA-jqp4-j8cc-wx66/GHSA-jqp4-j8cc-wx66.json index f9a6eaf47f3..8ba54b54a78 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqp4-j8cc-wx66/GHSA-jqp4-j8cc-wx66.json +++ b/advisories/unreviewed/2022/05/GHSA-jqp4-j8cc-wx66/GHSA-jqp4-j8cc-wx66.json @@ -7,12 +7,8 @@ "CVE-2021-22019" ], "details": "The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv8r-v35h-qv47/GHSA-jv8r-v35h-qv47.json b/advisories/unreviewed/2022/05/GHSA-jv8r-v35h-qv47/GHSA-jv8r-v35h-qv47.json index b345cf28a87..9b68726c3ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv8r-v35h-qv47/GHSA-jv8r-v35h-qv47.json +++ b/advisories/unreviewed/2022/05/GHSA-jv8r-v35h-qv47/GHSA-jv8r-v35h-qv47.json @@ -7,12 +7,8 @@ "CVE-2021-40238" ], "details": "A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-existent page, which is activated by administrators viewing the \"Error Log\" page. An attacker can leverage this to achieve Unauthenticated Remote Code Execution via the \"Cron Jobs\" functionality of Webuzo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx59-j4wf-4x4h/GHSA-jx59-j4wf-4x4h.json b/advisories/unreviewed/2022/05/GHSA-jx59-j4wf-4x4h/GHSA-jx59-j4wf-4x4h.json index 7532478d6b0..dccb1311ce9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx59-j4wf-4x4h/GHSA-jx59-j4wf-4x4h.json +++ b/advisories/unreviewed/2022/05/GHSA-jx59-j4wf-4x4h/GHSA-jx59-j4wf-4x4h.json @@ -7,12 +7,8 @@ "CVE-2005-4505" ], "details": "Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious \"program.exe\" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted \"Program Files\" path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jx74-m5hp-97vh/GHSA-jx74-m5hp-97vh.json b/advisories/unreviewed/2022/05/GHSA-jx74-m5hp-97vh/GHSA-jx74-m5hp-97vh.json index 9a542bd5af8..0ea0e1da3be 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx74-m5hp-97vh/GHSA-jx74-m5hp-97vh.json +++ b/advisories/unreviewed/2022/05/GHSA-jx74-m5hp-97vh/GHSA-jx74-m5hp-97vh.json @@ -7,12 +7,8 @@ "CVE-2005-4853" ], "details": "The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrary postings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2c9-h2qv-35jc/GHSA-m2c9-h2qv-35jc.json b/advisories/unreviewed/2022/05/GHSA-m2c9-h2qv-35jc/GHSA-m2c9-h2qv-35jc.json index 5a17ddf80f9..9a42d01a0be 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2c9-h2qv-35jc/GHSA-m2c9-h2qv-35jc.json +++ b/advisories/unreviewed/2022/05/GHSA-m2c9-h2qv-35jc/GHSA-m2c9-h2qv-35jc.json @@ -7,12 +7,8 @@ "CVE-2005-4844" ], "details": "The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2jg-x6cx-w676/GHSA-m2jg-x6cx-w676.json b/advisories/unreviewed/2022/05/GHSA-m2jg-x6cx-w676/GHSA-m2jg-x6cx-w676.json index f18f891c43a..38a8a9c0a5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2jg-x6cx-w676/GHSA-m2jg-x6cx-w676.json +++ b/advisories/unreviewed/2022/05/GHSA-m2jg-x6cx-w676/GHSA-m2jg-x6cx-w676.json @@ -7,12 +7,8 @@ "CVE-2005-4466" ], "details": "Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a REGISTER request with a SPI version number that contains a large number of space or tab characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3xm-f262-69qm/GHSA-m3xm-f262-69qm.json b/advisories/unreviewed/2022/05/GHSA-m3xm-f262-69qm/GHSA-m3xm-f262-69qm.json index 6be9b374a3b..2b5f6346033 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3xm-f262-69qm/GHSA-m3xm-f262-69qm.json +++ b/advisories/unreviewed/2022/05/GHSA-m3xm-f262-69qm/GHSA-m3xm-f262-69qm.json @@ -7,12 +7,8 @@ "CVE-2005-4837" ], "details": "snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4ch-hx25-qfhf/GHSA-m4ch-hx25-qfhf.json b/advisories/unreviewed/2022/05/GHSA-m4ch-hx25-qfhf/GHSA-m4ch-hx25-qfhf.json index df78345efd3..85412450d41 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4ch-hx25-qfhf/GHSA-m4ch-hx25-qfhf.json +++ b/advisories/unreviewed/2022/05/GHSA-m4ch-hx25-qfhf/GHSA-m4ch-hx25-qfhf.json @@ -7,12 +7,8 @@ "CVE-2021-38337" ], "details": "The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4cm-qh2r-fvg3/GHSA-m4cm-qh2r-fvg3.json b/advisories/unreviewed/2022/05/GHSA-m4cm-qh2r-fvg3/GHSA-m4cm-qh2r-fvg3.json index 01d8d01196e..555e71d0991 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4cm-qh2r-fvg3/GHSA-m4cm-qh2r-fvg3.json +++ b/advisories/unreviewed/2022/05/GHSA-m4cm-qh2r-fvg3/GHSA-m4cm-qh2r-fvg3.json @@ -7,12 +7,8 @@ "CVE-2021-24525" ], "details": "The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5fr-488c-22rq/GHSA-m5fr-488c-22rq.json b/advisories/unreviewed/2022/05/GHSA-m5fr-488c-22rq/GHSA-m5fr-488c-22rq.json index eb17d2d1202..7c616e40545 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5fr-488c-22rq/GHSA-m5fr-488c-22rq.json +++ b/advisories/unreviewed/2022/05/GHSA-m5fr-488c-22rq/GHSA-m5fr-488c-22rq.json @@ -7,12 +7,8 @@ "CVE-2019-16651" ], "details": "An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN implementations, this would decloak them).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5q8-vwxv-6f22/GHSA-m5q8-vwxv-6f22.json b/advisories/unreviewed/2022/05/GHSA-m5q8-vwxv-6f22/GHSA-m5q8-vwxv-6f22.json index 762a4397b77..552a0a7ebea 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5q8-vwxv-6f22/GHSA-m5q8-vwxv-6f22.json +++ b/advisories/unreviewed/2022/05/GHSA-m5q8-vwxv-6f22/GHSA-m5q8-vwxv-6f22.json @@ -7,12 +7,8 @@ "CVE-2005-4740" ], "details": "IBM DB2 Universal Database (UDB) 810 before version 8 FixPak 10 allows remote authenticated users to cause a denial of service (db2jd service crash) by \"connecting from a downlevel client.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m66j-4hh4-r35x/GHSA-m66j-4hh4-r35x.json b/advisories/unreviewed/2022/05/GHSA-m66j-4hh4-r35x/GHSA-m66j-4hh4-r35x.json index 0e95a32dc21..68d92d0d3c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-m66j-4hh4-r35x/GHSA-m66j-4hh4-r35x.json +++ b/advisories/unreviewed/2022/05/GHSA-m66j-4hh4-r35x/GHSA-m66j-4hh4-r35x.json @@ -7,12 +7,8 @@ "CVE-2021-39550" ], "details": "An issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.cpp has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m69p-8v8r-jhcc/GHSA-m69p-8v8r-jhcc.json b/advisories/unreviewed/2022/05/GHSA-m69p-8v8r-jhcc/GHSA-m69p-8v8r-jhcc.json index 0c20d326fab..5d7612e5111 100644 --- a/advisories/unreviewed/2022/05/GHSA-m69p-8v8r-jhcc/GHSA-m69p-8v8r-jhcc.json +++ b/advisories/unreviewed/2022/05/GHSA-m69p-8v8r-jhcc/GHSA-m69p-8v8r-jhcc.json @@ -7,12 +7,8 @@ "CVE-2021-1565" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8j8-p957-53f2/GHSA-m8j8-p957-53f2.json b/advisories/unreviewed/2022/05/GHSA-m8j8-p957-53f2/GHSA-m8j8-p957-53f2.json index a4e3e3379e7..74584421150 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8j8-p957-53f2/GHSA-m8j8-p957-53f2.json +++ b/advisories/unreviewed/2022/05/GHSA-m8j8-p957-53f2/GHSA-m8j8-p957-53f2.json @@ -7,12 +7,8 @@ "CVE-2005-4513" ], "details": "Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8v8-j367-x35r/GHSA-m8v8-j367-x35r.json b/advisories/unreviewed/2022/05/GHSA-m8v8-j367-x35r/GHSA-m8v8-j367-x35r.json index fd43df44fee..d68846113c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8v8-j367-x35r/GHSA-m8v8-j367-x35r.json +++ b/advisories/unreviewed/2022/05/GHSA-m8v8-j367-x35r/GHSA-m8v8-j367-x35r.json @@ -7,12 +7,8 @@ "CVE-2021-41382" ], "details": "Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m929-2mf3-jfhp/GHSA-m929-2mf3-jfhp.json b/advisories/unreviewed/2022/05/GHSA-m929-2mf3-jfhp/GHSA-m929-2mf3-jfhp.json index bf949a27f35..f3f4c6f4264 100644 --- a/advisories/unreviewed/2022/05/GHSA-m929-2mf3-jfhp/GHSA-m929-2mf3-jfhp.json +++ b/advisories/unreviewed/2022/05/GHSA-m929-2mf3-jfhp/GHSA-m929-2mf3-jfhp.json @@ -7,12 +7,8 @@ "CVE-2005-4500" ], "details": "SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m93p-78fx-rr4f/GHSA-m93p-78fx-rr4f.json b/advisories/unreviewed/2022/05/GHSA-m93p-78fx-rr4f/GHSA-m93p-78fx-rr4f.json index a00d0361209..aa8c04defbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-m93p-78fx-rr4f/GHSA-m93p-78fx-rr4f.json +++ b/advisories/unreviewed/2022/05/GHSA-m93p-78fx-rr4f/GHSA-m93p-78fx-rr4f.json @@ -7,12 +7,8 @@ "CVE-2005-4839" ], "details": "PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m99p-58jq-4cf5/GHSA-m99p-58jq-4cf5.json b/advisories/unreviewed/2022/05/GHSA-m99p-58jq-4cf5/GHSA-m99p-58jq-4cf5.json index f56740c1493..e9a15debba8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m99p-58jq-4cf5/GHSA-m99p-58jq-4cf5.json +++ b/advisories/unreviewed/2022/05/GHSA-m99p-58jq-4cf5/GHSA-m99p-58jq-4cf5.json @@ -7,12 +7,8 @@ "CVE-2005-4594" ], "details": "Stack-based buffer overflow in TUGZip 3.4.0.0 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9pc-6vm2-63f5/GHSA-m9pc-6vm2-63f5.json b/advisories/unreviewed/2022/05/GHSA-m9pc-6vm2-63f5/GHSA-m9pc-6vm2-63f5.json index 2da87113215..9aaaf175adf 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9pc-6vm2-63f5/GHSA-m9pc-6vm2-63f5.json +++ b/advisories/unreviewed/2022/05/GHSA-m9pc-6vm2-63f5/GHSA-m9pc-6vm2-63f5.json @@ -7,12 +7,8 @@ "CVE-2021-38833" ], "details": "SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9q7-8vm6-p246/GHSA-m9q7-8vm6-p246.json b/advisories/unreviewed/2022/05/GHSA-m9q7-8vm6-p246/GHSA-m9q7-8vm6-p246.json index 59ac053af98..bb86e81ee3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9q7-8vm6-p246/GHSA-m9q7-8vm6-p246.json +++ b/advisories/unreviewed/2022/05/GHSA-m9q7-8vm6-p246/GHSA-m9q7-8vm6-p246.json @@ -7,12 +7,8 @@ "CVE-2005-4404" ], "details": "SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9qv-c494-f247/GHSA-m9qv-c494-f247.json b/advisories/unreviewed/2022/05/GHSA-m9qv-c494-f247/GHSA-m9qv-c494-f247.json index d3eb0c98ed3..a6f52e83f05 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9qv-c494-f247/GHSA-m9qv-c494-f247.json +++ b/advisories/unreviewed/2022/05/GHSA-m9qv-c494-f247/GHSA-m9qv-c494-f247.json @@ -7,12 +7,8 @@ "CVE-2005-4767" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP5 and earlier, and 7.0 SP6 and earlier, when using username/password authentication, does not lock out a username after the maximum number of invalid login attempts, which makes it easier for remote attackers to guess the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mc98-xj99-qf7r/GHSA-mc98-xj99-qf7r.json b/advisories/unreviewed/2022/05/GHSA-mc98-xj99-qf7r/GHSA-mc98-xj99-qf7r.json index 0ee1d43df4b..491341ea641 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc98-xj99-qf7r/GHSA-mc98-xj99-qf7r.json +++ b/advisories/unreviewed/2022/05/GHSA-mc98-xj99-qf7r/GHSA-mc98-xj99-qf7r.json @@ -7,12 +7,8 @@ "CVE-2021-23036" ], "details": "On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf8q-f3gh-r43c/GHSA-mf8q-f3gh-r43c.json b/advisories/unreviewed/2022/05/GHSA-mf8q-f3gh-r43c/GHSA-mf8q-f3gh-r43c.json index b72b7a7272a..0cb09a8d530 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf8q-f3gh-r43c/GHSA-mf8q-f3gh-r43c.json +++ b/advisories/unreviewed/2022/05/GHSA-mf8q-f3gh-r43c/GHSA-mf8q-f3gh-r43c.json @@ -7,12 +7,8 @@ "CVE-2005-4843" ], "details": "The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfg4-vc2f-7p24/GHSA-mfg4-vc2f-7p24.json b/advisories/unreviewed/2022/05/GHSA-mfg4-vc2f-7p24/GHSA-mfg4-vc2f-7p24.json index 5d9c898406e..571d9f2ad28 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfg4-vc2f-7p24/GHSA-mfg4-vc2f-7p24.json +++ b/advisories/unreviewed/2022/05/GHSA-mfg4-vc2f-7p24/GHSA-mfg4-vc2f-7p24.json @@ -7,12 +7,8 @@ "CVE-2005-4803" ], "details": "graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files. NOTE: this issue was originally associated with a different CVE identifier, CVE-2005-2965, which had been used for multiple different issues. This is the correct identifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfhf-9pvp-rc65/GHSA-mfhf-9pvp-rc65.json b/advisories/unreviewed/2022/05/GHSA-mfhf-9pvp-rc65/GHSA-mfhf-9pvp-rc65.json index 2005fd99b7e..87e9972d248 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfhf-9pvp-rc65/GHSA-mfhf-9pvp-rc65.json +++ b/advisories/unreviewed/2022/05/GHSA-mfhf-9pvp-rc65/GHSA-mfhf-9pvp-rc65.json @@ -7,12 +7,8 @@ "CVE-2005-4577" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in an unspecified input form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgw5-3cch-4hf5/GHSA-mgw5-3cch-4hf5.json b/advisories/unreviewed/2022/05/GHSA-mgw5-3cch-4hf5/GHSA-mgw5-3cch-4hf5.json index 14c6852c4eb..331df87ffba 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgw5-3cch-4hf5/GHSA-mgw5-3cch-4hf5.json +++ b/advisories/unreviewed/2022/05/GHSA-mgw5-3cch-4hf5/GHSA-mgw5-3cch-4hf5.json @@ -7,12 +7,8 @@ "CVE-2020-21533" ], "details": "fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh39-j6xw-g36j/GHSA-mh39-j6xw-g36j.json b/advisories/unreviewed/2022/05/GHSA-mh39-j6xw-g36j/GHSA-mh39-j6xw-g36j.json index 2ae7abc1c2c..4b7e1931e1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh39-j6xw-g36j/GHSA-mh39-j6xw-g36j.json +++ b/advisories/unreviewed/2022/05/GHSA-mh39-j6xw-g36j/GHSA-mh39-j6xw-g36j.json @@ -7,12 +7,8 @@ "CVE-2005-4696" ], "details": "The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to process memory to steal the keys and access the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mh48-h49v-5m4j/GHSA-mh48-h49v-5m4j.json b/advisories/unreviewed/2022/05/GHSA-mh48-h49v-5m4j/GHSA-mh48-h49v-5m4j.json index 9793fde1b7f..b516b2e090b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh48-h49v-5m4j/GHSA-mh48-h49v-5m4j.json +++ b/advisories/unreviewed/2022/05/GHSA-mh48-h49v-5m4j/GHSA-mh48-h49v-5m4j.json @@ -7,12 +7,8 @@ "CVE-2005-4429" ], "details": "SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhhp-9rv5-4266/GHSA-mhhp-9rv5-4266.json b/advisories/unreviewed/2022/05/GHSA-mhhp-9rv5-4266/GHSA-mhhp-9rv5-4266.json index fc882a92302..3780137826a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhhp-9rv5-4266/GHSA-mhhp-9rv5-4266.json +++ b/advisories/unreviewed/2022/05/GHSA-mhhp-9rv5-4266/GHSA-mhhp-9rv5-4266.json @@ -7,12 +7,8 @@ "CVE-2021-32136" ], "details": "Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mj4q-hgj9-6rmg/GHSA-mj4q-hgj9-6rmg.json b/advisories/unreviewed/2022/05/GHSA-mj4q-hgj9-6rmg/GHSA-mj4q-hgj9-6rmg.json index 600a11af316..4ae4edd3a15 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj4q-hgj9-6rmg/GHSA-mj4q-hgj9-6rmg.json +++ b/advisories/unreviewed/2022/05/GHSA-mj4q-hgj9-6rmg/GHSA-mj4q-hgj9-6rmg.json @@ -7,12 +7,8 @@ "CVE-2021-38350" ], "details": "The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~/analyse/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjc7-fwvm-67h4/GHSA-mjc7-fwvm-67h4.json b/advisories/unreviewed/2022/05/GHSA-mjc7-fwvm-67h4/GHSA-mjc7-fwvm-67h4.json index 8237a9b0e74..0de9102b439 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjc7-fwvm-67h4/GHSA-mjc7-fwvm-67h4.json +++ b/advisories/unreviewed/2022/05/GHSA-mjc7-fwvm-67h4/GHSA-mjc7-fwvm-67h4.json @@ -7,12 +7,8 @@ "CVE-2021-41531" ], "details": "NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the RPKI data set, effectively disabling Route Origin Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjpx-84wp-2wp6/GHSA-mjpx-84wp-2wp6.json b/advisories/unreviewed/2022/05/GHSA-mjpx-84wp-2wp6/GHSA-mjpx-84wp-2wp6.json index 1841fb508bd..fe0776ff825 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjpx-84wp-2wp6/GHSA-mjpx-84wp-2wp6.json +++ b/advisories/unreviewed/2022/05/GHSA-mjpx-84wp-2wp6/GHSA-mjpx-84wp-2wp6.json @@ -7,12 +7,8 @@ "CVE-2021-38329" ], "details": "The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.7.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjv7-394p-9g5m/GHSA-mjv7-394p-9g5m.json b/advisories/unreviewed/2022/05/GHSA-mjv7-394p-9g5m/GHSA-mjv7-394p-9g5m.json index 6a24b1c0df7..30efe270260 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjv7-394p-9g5m/GHSA-mjv7-394p-9g5m.json +++ b/advisories/unreviewed/2022/05/GHSA-mjv7-394p-9g5m/GHSA-mjv7-394p-9g5m.json @@ -7,12 +7,8 @@ "CVE-2005-4557" ], "details": "dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm6g-wcmr-44mj/GHSA-mm6g-wcmr-44mj.json b/advisories/unreviewed/2022/05/GHSA-mm6g-wcmr-44mj/GHSA-mm6g-wcmr-44mj.json index 2290f22dbd0..903dc0ee221 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm6g-wcmr-44mj/GHSA-mm6g-wcmr-44mj.json +++ b/advisories/unreviewed/2022/05/GHSA-mm6g-wcmr-44mj/GHSA-mm6g-wcmr-44mj.json @@ -7,12 +7,8 @@ "CVE-2005-4610" ], "details": "Format string vulnerability in the server for Dopewars before 1.5.12, when running as an NT service, allows remote attackers to execute arbitrary code via unspecified attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmpm-58gf-7r28/GHSA-mmpm-58gf-7r28.json b/advisories/unreviewed/2022/05/GHSA-mmpm-58gf-7r28/GHSA-mmpm-58gf-7r28.json index 29d383ce89c..685043b9d71 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmpm-58gf-7r28/GHSA-mmpm-58gf-7r28.json +++ b/advisories/unreviewed/2022/05/GHSA-mmpm-58gf-7r28/GHSA-mmpm-58gf-7r28.json @@ -7,12 +7,8 @@ "CVE-2020-19295" ], "details": "A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmrg-jwv9-9h53/GHSA-mmrg-jwv9-9h53.json b/advisories/unreviewed/2022/05/GHSA-mmrg-jwv9-9h53/GHSA-mmrg-jwv9-9h53.json index ffc1daa03f5..7410d7aeb74 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmrg-jwv9-9h53/GHSA-mmrg-jwv9-9h53.json +++ b/advisories/unreviewed/2022/05/GHSA-mmrg-jwv9-9h53/GHSA-mmrg-jwv9-9h53.json @@ -7,12 +7,8 @@ "CVE-2021-34571" ], "details": "Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary can learn all information that is available in Enbra EWM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpc2-3367-chhh/GHSA-mpc2-3367-chhh.json b/advisories/unreviewed/2022/05/GHSA-mpc2-3367-chhh/GHSA-mpc2-3367-chhh.json index f406e611056..fbf9fab5d99 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpc2-3367-chhh/GHSA-mpc2-3367-chhh.json +++ b/advisories/unreviewed/2022/05/GHSA-mpc2-3367-chhh/GHSA-mpc2-3367-chhh.json @@ -7,12 +7,8 @@ "CVE-2021-33704" ], "details": "The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable function, no in-depth system knowledge is required. Once exploited via Network stack, the attacker may be able to read, modify or delete restricted data. The impact is that missing authorization can result of abuse of functionality usually restricted to specific users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpxp-95jp-3f78/GHSA-mpxp-95jp-3f78.json b/advisories/unreviewed/2022/05/GHSA-mpxp-95jp-3f78/GHSA-mpxp-95jp-3f78.json index 4044e593760..db8a7d0e7fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpxp-95jp-3f78/GHSA-mpxp-95jp-3f78.json +++ b/advisories/unreviewed/2022/05/GHSA-mpxp-95jp-3f78/GHSA-mpxp-95jp-3f78.json @@ -7,12 +7,8 @@ "CVE-2005-4545" ], "details": "Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrfh-xqh8-3383/GHSA-mrfh-xqh8-3383.json b/advisories/unreviewed/2022/05/GHSA-mrfh-xqh8-3383/GHSA-mrfh-xqh8-3383.json index fb7aaa6f781..f0f5fc4eed0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrfh-xqh8-3383/GHSA-mrfh-xqh8-3383.json +++ b/advisories/unreviewed/2022/05/GHSA-mrfh-xqh8-3383/GHSA-mrfh-xqh8-3383.json @@ -7,12 +7,8 @@ "CVE-2021-39531" ], "details": "An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrpf-h2p4-3gmm/GHSA-mrpf-h2p4-3gmm.json b/advisories/unreviewed/2022/05/GHSA-mrpf-h2p4-3gmm/GHSA-mrpf-h2p4-3gmm.json index c2a501a6901..47fc00ac262 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrpf-h2p4-3gmm/GHSA-mrpf-h2p4-3gmm.json +++ b/advisories/unreviewed/2022/05/GHSA-mrpf-h2p4-3gmm/GHSA-mrpf-h2p4-3gmm.json @@ -7,12 +7,8 @@ "CVE-2021-29806" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204264.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw4v-qjph-c794/GHSA-mw4v-qjph-c794.json b/advisories/unreviewed/2022/05/GHSA-mw4v-qjph-c794/GHSA-mw4v-qjph-c794.json index 0f2a5622b5e..300c5d66192 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw4v-qjph-c794/GHSA-mw4v-qjph-c794.json +++ b/advisories/unreviewed/2022/05/GHSA-mw4v-qjph-c794/GHSA-mw4v-qjph-c794.json @@ -7,12 +7,8 @@ "CVE-2005-4588" ], "details": "Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode tags. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwwm-v9vx-c276/GHSA-mwwm-v9vx-c276.json b/advisories/unreviewed/2022/05/GHSA-mwwm-v9vx-c276/GHSA-mwwm-v9vx-c276.json index 0a7546781d2..7e7d49ffe58 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwwm-v9vx-c276/GHSA-mwwm-v9vx-c276.json +++ b/advisories/unreviewed/2022/05/GHSA-mwwm-v9vx-c276/GHSA-mwwm-v9vx-c276.json @@ -7,12 +7,8 @@ "CVE-2021-38351" ], "details": "The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx8g-w236-jgpq/GHSA-mx8g-w236-jgpq.json b/advisories/unreviewed/2022/05/GHSA-mx8g-w236-jgpq/GHSA-mx8g-w236-jgpq.json index d4a4477a7cd..8eba61da023 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx8g-w236-jgpq/GHSA-mx8g-w236-jgpq.json +++ b/advisories/unreviewed/2022/05/GHSA-mx8g-w236-jgpq/GHSA-mx8g-w236-jgpq.json @@ -7,12 +7,8 @@ "CVE-2005-4801" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a logged-in user, as demonstrated by tricking the administrator to access a web page that performs a mod_info action in modify_gallery.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2q5-v57c-8gw3/GHSA-p2q5-v57c-8gw3.json b/advisories/unreviewed/2022/05/GHSA-p2q5-v57c-8gw3/GHSA-p2q5-v57c-8gw3.json index 9029df839ca..744d9ba68c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2q5-v57c-8gw3/GHSA-p2q5-v57c-8gw3.json +++ b/advisories/unreviewed/2022/05/GHSA-p2q5-v57c-8gw3/GHSA-p2q5-v57c-8gw3.json @@ -7,12 +7,8 @@ "CVE-2005-4764" ], "details": "BEA WebLogic Server and WebLogic Express 9.0, 8.1, and 7.0 lock out the admin user account after multiple incorrect password guesses, which allows remote attackers who know or guess the admin account name to cause a denial of service (blocked admin logins).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p35r-5hv5-759h/GHSA-p35r-5hv5-759h.json b/advisories/unreviewed/2022/05/GHSA-p35r-5hv5-759h/GHSA-p35r-5hv5-759h.json index 0daf54b21b0..deb4a8adcd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p35r-5hv5-759h/GHSA-p35r-5hv5-759h.json +++ b/advisories/unreviewed/2022/05/GHSA-p35r-5hv5-759h/GHSA-p35r-5hv5-759h.json @@ -7,12 +7,8 @@ "CVE-2021-34573" ], "details": "In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and \"no flow\" are not reconized or misinterpreted. This may lead to wrong values and missing events.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p37h-9c34-5f75/GHSA-p37h-9c34-5f75.json b/advisories/unreviewed/2022/05/GHSA-p37h-9c34-5f75/GHSA-p37h-9c34-5f75.json index cfbfd946f4f..bd86de9f7ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-p37h-9c34-5f75/GHSA-p37h-9c34-5f75.json +++ b/advisories/unreviewed/2022/05/GHSA-p37h-9c34-5f75/GHSA-p37h-9c34-5f75.json @@ -7,12 +7,8 @@ "CVE-2005-4814" ], "details": "Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p38p-vq33-v625/GHSA-p38p-vq33-v625.json b/advisories/unreviewed/2022/05/GHSA-p38p-vq33-v625/GHSA-p38p-vq33-v625.json index d5960e289ad..042f0691808 100644 --- a/advisories/unreviewed/2022/05/GHSA-p38p-vq33-v625/GHSA-p38p-vq33-v625.json +++ b/advisories/unreviewed/2022/05/GHSA-p38p-vq33-v625/GHSA-p38p-vq33-v625.json @@ -7,12 +7,8 @@ "CVE-2005-4591" ], "details": "Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via \"invalid input sequences\" that lead to heap corruption when bogofilter or bogolexer converts character sets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3px-x826-qqvw/GHSA-p3px-x826-qqvw.json b/advisories/unreviewed/2022/05/GHSA-p3px-x826-qqvw/GHSA-p3px-x826-qqvw.json index e8c2787d421..534cb16ae17 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3px-x826-qqvw/GHSA-p3px-x826-qqvw.json +++ b/advisories/unreviewed/2022/05/GHSA-p3px-x826-qqvw/GHSA-p3px-x826-qqvw.json @@ -7,12 +7,8 @@ "CVE-2021-39549" ], "details": "An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function file::WavFile::WavFile() located in wav_file.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3rg-43m7-g6rc/GHSA-p3rg-43m7-g6rc.json b/advisories/unreviewed/2022/05/GHSA-p3rg-43m7-g6rc/GHSA-p3rg-43m7-g6rc.json index 6e62621a6ae..02c8b1d0b6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3rg-43m7-g6rc/GHSA-p3rg-43m7-g6rc.json +++ b/advisories/unreviewed/2022/05/GHSA-p3rg-43m7-g6rc/GHSA-p3rg-43m7-g6rc.json @@ -7,12 +7,8 @@ "CVE-2005-4842" ], "details": "The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p48h-366j-m3qx/GHSA-p48h-366j-m3qx.json b/advisories/unreviewed/2022/05/GHSA-p48h-366j-m3qx/GHSA-p48h-366j-m3qx.json index 79b0380844b..8fc750a8d4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p48h-366j-m3qx/GHSA-p48h-366j-m3qx.json +++ b/advisories/unreviewed/2022/05/GHSA-p48h-366j-m3qx/GHSA-p48h-366j-m3qx.json @@ -7,12 +7,8 @@ "CVE-2005-4781" ], "details": "Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4c6-ww6x-99rw/GHSA-p4c6-ww6x-99rw.json b/advisories/unreviewed/2022/05/GHSA-p4c6-ww6x-99rw/GHSA-p4c6-ww6x-99rw.json index 83a0910706a..8366b609372 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4c6-ww6x-99rw/GHSA-p4c6-ww6x-99rw.json +++ b/advisories/unreviewed/2022/05/GHSA-p4c6-ww6x-99rw/GHSA-p4c6-ww6x-99rw.json @@ -7,12 +7,8 @@ "CVE-2005-4427" ], "details": "Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4cx-89qv-3gc6/GHSA-p4cx-89qv-3gc6.json b/advisories/unreviewed/2022/05/GHSA-p4cx-89qv-3gc6/GHSA-p4cx-89qv-3gc6.json index 49e92af830d..80948d16904 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4cx-89qv-3gc6/GHSA-p4cx-89qv-3gc6.json +++ b/advisories/unreviewed/2022/05/GHSA-p4cx-89qv-3gc6/GHSA-p4cx-89qv-3gc6.json @@ -7,12 +7,8 @@ "CVE-2005-4622" ], "details": "Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4mm-wpp7-57hp/GHSA-p4mm-wpp7-57hp.json b/advisories/unreviewed/2022/05/GHSA-p4mm-wpp7-57hp/GHSA-p4mm-wpp7-57hp.json index 6db224fdb0a..4b77dc21de5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4mm-wpp7-57hp/GHSA-p4mm-wpp7-57hp.json +++ b/advisories/unreviewed/2022/05/GHSA-p4mm-wpp7-57hp/GHSA-p4mm-wpp7-57hp.json @@ -7,12 +7,8 @@ "CVE-2005-4556" ], "details": "PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p52h-5fjj-x2pc/GHSA-p52h-5fjj-x2pc.json b/advisories/unreviewed/2022/05/GHSA-p52h-5fjj-x2pc/GHSA-p52h-5fjj-x2pc.json index 0c5d44bc679..292d5ae35d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p52h-5fjj-x2pc/GHSA-p52h-5fjj-x2pc.json +++ b/advisories/unreviewed/2022/05/GHSA-p52h-5fjj-x2pc/GHSA-p52h-5fjj-x2pc.json @@ -7,12 +7,8 @@ "CVE-2021-21993" ], "details": "The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p555-vm74-xq5v/GHSA-p555-vm74-xq5v.json b/advisories/unreviewed/2022/05/GHSA-p555-vm74-xq5v/GHSA-p555-vm74-xq5v.json index 29d76adc16c..a2bdeb2475e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p555-vm74-xq5v/GHSA-p555-vm74-xq5v.json +++ b/advisories/unreviewed/2022/05/GHSA-p555-vm74-xq5v/GHSA-p555-vm74-xq5v.json @@ -7,12 +7,8 @@ "CVE-2021-24604" ], "details": "The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p57v-vh5w-35p2/GHSA-p57v-vh5w-35p2.json b/advisories/unreviewed/2022/05/GHSA-p57v-vh5w-35p2/GHSA-p57v-vh5w-35p2.json index df08eb20882..51318c21470 100644 --- a/advisories/unreviewed/2022/05/GHSA-p57v-vh5w-35p2/GHSA-p57v-vh5w-35p2.json +++ b/advisories/unreviewed/2022/05/GHSA-p57v-vh5w-35p2/GHSA-p57v-vh5w-35p2.json @@ -7,12 +7,8 @@ "CVE-2021-33035" ], "details": "Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5p7-qgjw-w4rg/GHSA-p5p7-qgjw-w4rg.json b/advisories/unreviewed/2022/05/GHSA-p5p7-qgjw-w4rg/GHSA-p5p7-qgjw-w4rg.json index 4917ea23dd6..90bef291eee 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5p7-qgjw-w4rg/GHSA-p5p7-qgjw-w4rg.json +++ b/advisories/unreviewed/2022/05/GHSA-p5p7-qgjw-w4rg/GHSA-p5p7-qgjw-w4rg.json @@ -7,12 +7,8 @@ "CVE-2021-39557" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6gw-7vqp-9wg3/GHSA-p6gw-7vqp-9wg3.json b/advisories/unreviewed/2022/05/GHSA-p6gw-7vqp-9wg3/GHSA-p6gw-7vqp-9wg3.json index 8a4acd98fbb..50ab7ffe2cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6gw-7vqp-9wg3/GHSA-p6gw-7vqp-9wg3.json +++ b/advisories/unreviewed/2022/05/GHSA-p6gw-7vqp-9wg3/GHSA-p6gw-7vqp-9wg3.json @@ -7,12 +7,8 @@ "CVE-2005-4472" ], "details": "Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request that is not properly handled during conversion to wide characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p754-7gx2-93gj/GHSA-p754-7gx2-93gj.json b/advisories/unreviewed/2022/05/GHSA-p754-7gx2-93gj/GHSA-p754-7gx2-93gj.json index 351ce5f9cff..7bfb0f0caec 100644 --- a/advisories/unreviewed/2022/05/GHSA-p754-7gx2-93gj/GHSA-p754-7gx2-93gj.json +++ b/advisories/unreviewed/2022/05/GHSA-p754-7gx2-93gj/GHSA-p754-7gx2-93gj.json @@ -7,12 +7,8 @@ "CVE-2005-4567" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (Build 4.4.000 Oct 26 2005) allow remote attackers to inject arbitrary web script or HTML by sending (1) the href parameter to index.fts, or the param1 parameter to (2) /domains/index.fts, (3) /config/licence.fts, or (4) /config/systemacl.fts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p772-c78g-qj2h/GHSA-p772-c78g-qj2h.json b/advisories/unreviewed/2022/05/GHSA-p772-c78g-qj2h/GHSA-p772-c78g-qj2h.json index 132b30b11d7..e22b3068bc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p772-c78g-qj2h/GHSA-p772-c78g-qj2h.json +++ b/advisories/unreviewed/2022/05/GHSA-p772-c78g-qj2h/GHSA-p772-c78g-qj2h.json @@ -7,12 +7,8 @@ "CVE-2005-4498" ], "details": "Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p79v-mj8v-c6p4/GHSA-p79v-mj8v-c6p4.json b/advisories/unreviewed/2022/05/GHSA-p79v-mj8v-c6p4/GHSA-p79v-mj8v-c6p4.json index 0e88aee3d13..f74a17185c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p79v-mj8v-c6p4/GHSA-p79v-mj8v-c6p4.json +++ b/advisories/unreviewed/2022/05/GHSA-p79v-mj8v-c6p4/GHSA-p79v-mj8v-c6p4.json @@ -7,12 +7,8 @@ "CVE-2005-4700" ], "details": "TellMe 1.2 and earlier, when the Server (o_Server) and HEAD (o_Head) options are enabled, allows remote attackers to obtain sensitive information via an invalid q_Host parameter, which reveals the full pathname of the application in an fsockopen error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7m4-g6v2-gff7/GHSA-p7m4-g6v2-gff7.json b/advisories/unreviewed/2022/05/GHSA-p7m4-g6v2-gff7/GHSA-p7m4-g6v2-gff7.json index 9f21ce4dd3f..9ec4e7449e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7m4-g6v2-gff7/GHSA-p7m4-g6v2-gff7.json +++ b/advisories/unreviewed/2022/05/GHSA-p7m4-g6v2-gff7/GHSA-p7m4-g6v2-gff7.json @@ -7,12 +7,8 @@ "CVE-2020-19289" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p84g-xfc3-9fmr/GHSA-p84g-xfc3-9fmr.json b/advisories/unreviewed/2022/05/GHSA-p84g-xfc3-9fmr/GHSA-p84g-xfc3-9fmr.json index febd8832183..3c67ed42cf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p84g-xfc3-9fmr/GHSA-p84g-xfc3-9fmr.json +++ b/advisories/unreviewed/2022/05/GHSA-p84g-xfc3-9fmr/GHSA-p84g-xfc3-9fmr.json @@ -7,12 +7,8 @@ "CVE-2021-22006" ], "details": "The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p87c-w38q-5f93/GHSA-p87c-w38q-5f93.json b/advisories/unreviewed/2022/05/GHSA-p87c-w38q-5f93/GHSA-p87c-w38q-5f93.json index a9c03a7dc3f..ad6b709f2fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-p87c-w38q-5f93/GHSA-p87c-w38q-5f93.json +++ b/advisories/unreviewed/2022/05/GHSA-p87c-w38q-5f93/GHSA-p87c-w38q-5f93.json @@ -7,12 +7,8 @@ "CVE-2021-34344" ], "details": "A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 5.0: QUSBCam2 2.0.1 ( 2021/08/03 ) and later QTS 4.3.6: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 4.3.3: QUSBCam2 1.1.4 ( 2021/08/06 ) and later QuTS hero 4.5.3: QUSBCam2 1.1.4 ( 2021/07/30 ) and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8f4-g4x9-fc9w/GHSA-p8f4-g4x9-fc9w.json b/advisories/unreviewed/2022/05/GHSA-p8f4-g4x9-fc9w/GHSA-p8f4-g4x9-fc9w.json index c4244ff64f2..7257efcee8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8f4-g4x9-fc9w/GHSA-p8f4-g4x9-fc9w.json +++ b/advisories/unreviewed/2022/05/GHSA-p8f4-g4x9-fc9w/GHSA-p8f4-g4x9-fc9w.json @@ -7,12 +7,8 @@ "CVE-2020-21480" ], "details": "An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p947-hjgq-3459/GHSA-p947-hjgq-3459.json b/advisories/unreviewed/2022/05/GHSA-p947-hjgq-3459/GHSA-p947-hjgq-3459.json index 1b52120edd5..56b2a88748f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p947-hjgq-3459/GHSA-p947-hjgq-3459.json +++ b/advisories/unreviewed/2022/05/GHSA-p947-hjgq-3459/GHSA-p947-hjgq-3459.json @@ -7,12 +7,8 @@ "CVE-2005-4690" ], "details": "Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog's top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p99g-ppg4-hchg/GHSA-p99g-ppg4-hchg.json b/advisories/unreviewed/2022/05/GHSA-p99g-ppg4-hchg/GHSA-p99g-ppg4-hchg.json index a3c1f9797cd..f40b76248c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p99g-ppg4-hchg/GHSA-p99g-ppg4-hchg.json +++ b/advisories/unreviewed/2022/05/GHSA-p99g-ppg4-hchg/GHSA-p99g-ppg4-hchg.json @@ -7,12 +7,8 @@ "CVE-2005-4494" ], "details": "Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9j7-43pr-jxf7/GHSA-p9j7-43pr-jxf7.json b/advisories/unreviewed/2022/05/GHSA-p9j7-43pr-jxf7/GHSA-p9j7-43pr-jxf7.json index 7c4b5ded44f..7148c76b770 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9j7-43pr-jxf7/GHSA-p9j7-43pr-jxf7.json +++ b/advisories/unreviewed/2022/05/GHSA-p9j7-43pr-jxf7/GHSA-p9j7-43pr-jxf7.json @@ -7,12 +7,8 @@ "CVE-2020-19146" ], "details": "Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc87-fj52-xq29/GHSA-pc87-fj52-xq29.json b/advisories/unreviewed/2022/05/GHSA-pc87-fj52-xq29/GHSA-pc87-fj52-xq29.json index aea95b3dd12..1332759c60e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc87-fj52-xq29/GHSA-pc87-fj52-xq29.json +++ b/advisories/unreviewed/2022/05/GHSA-pc87-fj52-xq29/GHSA-pc87-fj52-xq29.json @@ -7,12 +7,8 @@ "CVE-2005-4406" ], "details": "SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pf68-x7c8-5h4p/GHSA-pf68-x7c8-5h4p.json b/advisories/unreviewed/2022/05/GHSA-pf68-x7c8-5h4p/GHSA-pf68-x7c8-5h4p.json index c4a62f75720..a7f572dc495 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf68-x7c8-5h4p/GHSA-pf68-x7c8-5h4p.json +++ b/advisories/unreviewed/2022/05/GHSA-pf68-x7c8-5h4p/GHSA-pf68-x7c8-5h4p.json @@ -7,12 +7,8 @@ "CVE-2005-4424" ], "details": "Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfqv-vjx4-pmxj/GHSA-pfqv-vjx4-pmxj.json b/advisories/unreviewed/2022/05/GHSA-pfqv-vjx4-pmxj/GHSA-pfqv-vjx4-pmxj.json index 239f0c40c5f..795f0c77064 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfqv-vjx4-pmxj/GHSA-pfqv-vjx4-pmxj.json +++ b/advisories/unreviewed/2022/05/GHSA-pfqv-vjx4-pmxj/GHSA-pfqv-vjx4-pmxj.json @@ -7,12 +7,8 @@ "CVE-2005-4889" ], "details": "lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfwr-4phx-9q5j/GHSA-pfwr-4phx-9q5j.json b/advisories/unreviewed/2022/05/GHSA-pfwr-4phx-9q5j/GHSA-pfwr-4phx-9q5j.json index ce0a0bb3f9d..b30f8e2dc62 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfwr-4phx-9q5j/GHSA-pfwr-4phx-9q5j.json +++ b/advisories/unreviewed/2022/05/GHSA-pfwr-4phx-9q5j/GHSA-pfwr-4phx-9q5j.json @@ -7,12 +7,8 @@ "CVE-2005-4724" ], "details": "SQL injection vulnerability in post.php in PhpTagCool 1.0.3 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field in an HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pg3h-mxmj-rvc4/GHSA-pg3h-mxmj-rvc4.json b/advisories/unreviewed/2022/05/GHSA-pg3h-mxmj-rvc4/GHSA-pg3h-mxmj-rvc4.json index 941fb774800..026378def3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg3h-mxmj-rvc4/GHSA-pg3h-mxmj-rvc4.json +++ b/advisories/unreviewed/2022/05/GHSA-pg3h-mxmj-rvc4/GHSA-pg3h-mxmj-rvc4.json @@ -7,12 +7,8 @@ "CVE-2021-24399" ], "details": "The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgjp-28w5-m45g/GHSA-pgjp-28w5-m45g.json b/advisories/unreviewed/2022/05/GHSA-pgjp-28w5-m45g/GHSA-pgjp-28w5-m45g.json index faacfc3c672..037e3b22238 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgjp-28w5-m45g/GHSA-pgjp-28w5-m45g.json +++ b/advisories/unreviewed/2022/05/GHSA-pgjp-28w5-m45g/GHSA-pgjp-28w5-m45g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgx2-pwxj-8wj5/GHSA-pgx2-pwxj-8wj5.json b/advisories/unreviewed/2022/05/GHSA-pgx2-pwxj-8wj5/GHSA-pgx2-pwxj-8wj5.json index ff0cffa2373..c7dc3947d73 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgx2-pwxj-8wj5/GHSA-pgx2-pwxj-8wj5.json +++ b/advisories/unreviewed/2022/05/GHSA-pgx2-pwxj-8wj5/GHSA-pgx2-pwxj-8wj5.json @@ -7,12 +7,8 @@ "CVE-2021-29817" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204343.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph3q-wqm6-3342/GHSA-ph3q-wqm6-3342.json b/advisories/unreviewed/2022/05/GHSA-ph3q-wqm6-3342/GHSA-ph3q-wqm6-3342.json index 6ce76d199b9..d4e01aa0066 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph3q-wqm6-3342/GHSA-ph3q-wqm6-3342.json +++ b/advisories/unreviewed/2022/05/GHSA-ph3q-wqm6-3342/GHSA-ph3q-wqm6-3342.json @@ -7,12 +7,8 @@ "CVE-2005-4435" ], "details": "Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phm6-mwmq-vphc/GHSA-phm6-mwmq-vphc.json b/advisories/unreviewed/2022/05/GHSA-phm6-mwmq-vphc/GHSA-phm6-mwmq-vphc.json index 5f3832308c9..662c6e274bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-phm6-mwmq-vphc/GHSA-phm6-mwmq-vphc.json +++ b/advisories/unreviewed/2022/05/GHSA-phm6-mwmq-vphc/GHSA-phm6-mwmq-vphc.json @@ -7,12 +7,8 @@ "CVE-2005-4725" ], "details": "Geeklog before 1.3.11sr3 allows remote attackers to bypass intended access restrictions and comment on an arbitrary story or topic by guessing the story ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pjhr-q582-mpq7/GHSA-pjhr-q582-mpq7.json b/advisories/unreviewed/2022/05/GHSA-pjhr-q582-mpq7/GHSA-pjhr-q582-mpq7.json index f637f564055..fc1e609d954 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjhr-q582-mpq7/GHSA-pjhr-q582-mpq7.json +++ b/advisories/unreviewed/2022/05/GHSA-pjhr-q582-mpq7/GHSA-pjhr-q582-mpq7.json @@ -7,12 +7,8 @@ "CVE-2021-41054" ], "details": "tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjm3-59jq-w9qm/GHSA-pjm3-59jq-w9qm.json b/advisories/unreviewed/2022/05/GHSA-pjm3-59jq-w9qm/GHSA-pjm3-59jq-w9qm.json index 03f86c677c3..45a997afdc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjm3-59jq-w9qm/GHSA-pjm3-59jq-w9qm.json +++ b/advisories/unreviewed/2022/05/GHSA-pjm3-59jq-w9qm/GHSA-pjm3-59jq-w9qm.json @@ -7,12 +7,8 @@ "CVE-2021-32288" ], "details": "An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjp7-6p5m-9x45/GHSA-pjp7-6p5m-9x45.json b/advisories/unreviewed/2022/05/GHSA-pjp7-6p5m-9x45/GHSA-pjp7-6p5m-9x45.json index 5b7ff93b69e..53f6b25d792 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjp7-6p5m-9x45/GHSA-pjp7-6p5m-9x45.json +++ b/advisories/unreviewed/2022/05/GHSA-pjp7-6p5m-9x45/GHSA-pjp7-6p5m-9x45.json @@ -7,12 +7,8 @@ "CVE-2021-29842" ], "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjpj-c8p5-7mqj/GHSA-pjpj-c8p5-7mqj.json b/advisories/unreviewed/2022/05/GHSA-pjpj-c8p5-7mqj/GHSA-pjpj-c8p5-7mqj.json index 81f829e6ff1..faf00efe1a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjpj-c8p5-7mqj/GHSA-pjpj-c8p5-7mqj.json +++ b/advisories/unreviewed/2022/05/GHSA-pjpj-c8p5-7mqj/GHSA-pjpj-c8p5-7mqj.json @@ -7,12 +7,8 @@ "CVE-2020-20892" ], "details": "An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm94-gq37-wp9p/GHSA-pm94-gq37-wp9p.json b/advisories/unreviewed/2022/05/GHSA-pm94-gq37-wp9p/GHSA-pm94-gq37-wp9p.json index ac978492e0a..22ad0ec35b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm94-gq37-wp9p/GHSA-pm94-gq37-wp9p.json +++ b/advisories/unreviewed/2022/05/GHSA-pm94-gq37-wp9p/GHSA-pm94-gq37-wp9p.json @@ -7,12 +7,8 @@ "CVE-2005-4857" ], "details": "eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a \"memory addressing error\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmfm-r4ww-m6w9/GHSA-pmfm-r4ww-m6w9.json b/advisories/unreviewed/2022/05/GHSA-pmfm-r4ww-m6w9/GHSA-pmfm-r4ww-m6w9.json index 39f77c701cd..7b601bf6a00 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmfm-r4ww-m6w9/GHSA-pmfm-r4ww-m6w9.json +++ b/advisories/unreviewed/2022/05/GHSA-pmfm-r4ww-m6w9/GHSA-pmfm-r4ww-m6w9.json @@ -7,12 +7,8 @@ "CVE-2021-3797" ], "details": "hestiacp is vulnerable to Use of Wrong Operator in String Comparison", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmhq-p9q2-mpcv/GHSA-pmhq-p9q2-mpcv.json b/advisories/unreviewed/2022/05/GHSA-pmhq-p9q2-mpcv/GHSA-pmhq-p9q2-mpcv.json index d969bbf3f00..0a4b9719dd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmhq-p9q2-mpcv/GHSA-pmhq-p9q2-mpcv.json +++ b/advisories/unreviewed/2022/05/GHSA-pmhq-p9q2-mpcv/GHSA-pmhq-p9q2-mpcv.json @@ -7,12 +7,8 @@ "CVE-2021-38402" ], "details": "Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp5r-cwfq-7whf/GHSA-pp5r-cwfq-7whf.json b/advisories/unreviewed/2022/05/GHSA-pp5r-cwfq-7whf/GHSA-pp5r-cwfq-7whf.json index 534587d71e6..86d7ec482fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp5r-cwfq-7whf/GHSA-pp5r-cwfq-7whf.json +++ b/advisories/unreviewed/2022/05/GHSA-pp5r-cwfq-7whf/GHSA-pp5r-cwfq-7whf.json @@ -7,12 +7,8 @@ "CVE-2021-28816" ], "details": "A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210701 and later QTS 4.3.3.1693 build 20210624 and later QTS 4.3.6.1750 build 20210730 and later QuTScloud c4.5.6.1755 and later QuTS hero h4.5.4.1771 build 20210825 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp6c-cmg4-3r6f/GHSA-pp6c-cmg4-3r6f.json b/advisories/unreviewed/2022/05/GHSA-pp6c-cmg4-3r6f/GHSA-pp6c-cmg4-3r6f.json index 44e27179ec0..5ee433c4821 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp6c-cmg4-3r6f/GHSA-pp6c-cmg4-3r6f.json +++ b/advisories/unreviewed/2022/05/GHSA-pp6c-cmg4-3r6f/GHSA-pp6c-cmg4-3r6f.json @@ -7,12 +7,8 @@ "CVE-2020-4941" ], "details": "IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppr8-xvjc-pg2w/GHSA-ppr8-xvjc-pg2w.json b/advisories/unreviewed/2022/05/GHSA-ppr8-xvjc-pg2w/GHSA-ppr8-xvjc-pg2w.json index f1bd766b807..f29a27bfc20 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppr8-xvjc-pg2w/GHSA-ppr8-xvjc-pg2w.json +++ b/advisories/unreviewed/2022/05/GHSA-ppr8-xvjc-pg2w/GHSA-ppr8-xvjc-pg2w.json @@ -7,12 +7,8 @@ "CVE-2005-4407" ], "details": "Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppwx-w5v2-mfj6/GHSA-ppwx-w5v2-mfj6.json b/advisories/unreviewed/2022/05/GHSA-ppwx-w5v2-mfj6/GHSA-ppwx-w5v2-mfj6.json index fe6398cbb8f..ae8709419fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppwx-w5v2-mfj6/GHSA-ppwx-w5v2-mfj6.json +++ b/advisories/unreviewed/2022/05/GHSA-ppwx-w5v2-mfj6/GHSA-ppwx-w5v2-mfj6.json @@ -7,12 +7,8 @@ "CVE-2021-39575" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppxc-h6m6-m746/GHSA-ppxc-h6m6-m746.json b/advisories/unreviewed/2022/05/GHSA-ppxc-h6m6-m746/GHSA-ppxc-h6m6-m746.json index bcce27d2e04..e0a6962141e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppxc-h6m6-m746/GHSA-ppxc-h6m6-m746.json +++ b/advisories/unreviewed/2022/05/GHSA-ppxc-h6m6-m746/GHSA-ppxc-h6m6-m746.json @@ -7,12 +7,8 @@ "CVE-2021-41428" ], "details": "Insecure permissions in Update Manager <= 5.8.0.2300 and DFL <= 12.5.1001.5 in DATEV programs v14.1 allows attacker to escalate privileges via insufficient configuration of service components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq9r-2xxh-vvh7/GHSA-pq9r-2xxh-vvh7.json b/advisories/unreviewed/2022/05/GHSA-pq9r-2xxh-vvh7/GHSA-pq9r-2xxh-vvh7.json index 1b0a2504535..8ca4fd51ae7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq9r-2xxh-vvh7/GHSA-pq9r-2xxh-vvh7.json +++ b/advisories/unreviewed/2022/05/GHSA-pq9r-2xxh-vvh7/GHSA-pq9r-2xxh-vvh7.json @@ -7,12 +7,8 @@ "CVE-2006-0002" ], "details": "Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqmh-m9r6-3v94/GHSA-pqmh-m9r6-3v94.json b/advisories/unreviewed/2022/05/GHSA-pqmh-m9r6-3v94/GHSA-pqmh-m9r6-3v94.json index 23576bf8deb..297371b5cc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqmh-m9r6-3v94/GHSA-pqmh-m9r6-3v94.json +++ b/advisories/unreviewed/2022/05/GHSA-pqmh-m9r6-3v94/GHSA-pqmh-m9r6-3v94.json @@ -7,12 +7,8 @@ "CVE-2005-4821" ], "details": "Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqx2-mg4c-9g67/GHSA-pqx2-mg4c-9g67.json b/advisories/unreviewed/2022/05/GHSA-pqx2-mg4c-9g67/GHSA-pqx2-mg4c-9g67.json index 0ef3fe89034..8b245f10667 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqx2-mg4c-9g67/GHSA-pqx2-mg4c-9g67.json +++ b/advisories/unreviewed/2022/05/GHSA-pqx2-mg4c-9g67/GHSA-pqx2-mg4c-9g67.json @@ -7,12 +7,8 @@ "CVE-2005-4459" ], "details": "Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr4x-xmgg-hg68/GHSA-pr4x-xmgg-hg68.json b/advisories/unreviewed/2022/05/GHSA-pr4x-xmgg-hg68/GHSA-pr4x-xmgg-hg68.json index c1fe643119f..7b1f7cd239e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr4x-xmgg-hg68/GHSA-pr4x-xmgg-hg68.json +++ b/advisories/unreviewed/2022/05/GHSA-pr4x-xmgg-hg68/GHSA-pr4x-xmgg-hg68.json @@ -7,12 +7,8 @@ "CVE-2021-32979" ], "details": "Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr9v-gfw5-55x8/GHSA-pr9v-gfw5-55x8.json b/advisories/unreviewed/2022/05/GHSA-pr9v-gfw5-55x8/GHSA-pr9v-gfw5-55x8.json index 428eacc6aa8..97f0496a209 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr9v-gfw5-55x8/GHSA-pr9v-gfw5-55x8.json +++ b/advisories/unreviewed/2022/05/GHSA-pr9v-gfw5-55x8/GHSA-pr9v-gfw5-55x8.json @@ -7,12 +7,8 @@ "CVE-2021-39545" ], "details": "An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function rice::RiceDecoder::process() located in rice_decoder.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prcf-pmh9-cp3p/GHSA-prcf-pmh9-cp3p.json b/advisories/unreviewed/2022/05/GHSA-prcf-pmh9-cp3p/GHSA-prcf-pmh9-cp3p.json index 08621e8a3e0..7158ffe8b54 100644 --- a/advisories/unreviewed/2022/05/GHSA-prcf-pmh9-cp3p/GHSA-prcf-pmh9-cp3p.json +++ b/advisories/unreviewed/2022/05/GHSA-prcf-pmh9-cp3p/GHSA-prcf-pmh9-cp3p.json @@ -7,12 +7,8 @@ "CVE-2005-4516" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web script or HTML via (1) the sortby parameter in members.php and (2) IMG tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prr6-w5h2-7x5j/GHSA-prr6-w5h2-7x5j.json b/advisories/unreviewed/2022/05/GHSA-prr6-w5h2-7x5j/GHSA-prr6-w5h2-7x5j.json index 9fd7c0d870d..7b7d5df312e 100644 --- a/advisories/unreviewed/2022/05/GHSA-prr6-w5h2-7x5j/GHSA-prr6-w5h2-7x5j.json +++ b/advisories/unreviewed/2022/05/GHSA-prr6-w5h2-7x5j/GHSA-prr6-w5h2-7x5j.json @@ -7,12 +7,8 @@ "CVE-2005-4783" ], "details": "kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv6r-7cj8-5hg8/GHSA-pv6r-7cj8-5hg8.json b/advisories/unreviewed/2022/05/GHSA-pv6r-7cj8-5hg8/GHSA-pv6r-7cj8-5hg8.json index 4bd4d7faddc..ca8e1f5035d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv6r-7cj8-5hg8/GHSA-pv6r-7cj8-5hg8.json +++ b/advisories/unreviewed/2022/05/GHSA-pv6r-7cj8-5hg8/GHSA-pv6r-7cj8-5hg8.json @@ -7,12 +7,8 @@ "CVE-2005-4430" ], "details": "SQL injection vulnerability in LogicBill 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) __mode and (2) __id parameters to helpdesk.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv7q-p55j-x95w/GHSA-pv7q-p55j-x95w.json b/advisories/unreviewed/2022/05/GHSA-pv7q-p55j-x95w/GHSA-pv7q-p55j-x95w.json index 0ec242dae88..76355bb1e8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv7q-p55j-x95w/GHSA-pv7q-p55j-x95w.json +++ b/advisories/unreviewed/2022/05/GHSA-pv7q-p55j-x95w/GHSA-pv7q-p55j-x95w.json @@ -7,12 +7,8 @@ "CVE-2005-4520" ], "details": "Unspecified \"port injection\" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack of relevant details in the vendor changelog, which is the source of this description, it is unclear whether this is a duplicate of another CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvhv-j9fj-f3fv/GHSA-pvhv-j9fj-f3fv.json b/advisories/unreviewed/2022/05/GHSA-pvhv-j9fj-f3fv/GHSA-pvhv-j9fj-f3fv.json index 4bed1de399c..83b676919fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvhv-j9fj-f3fv/GHSA-pvhv-j9fj-f3fv.json +++ b/advisories/unreviewed/2022/05/GHSA-pvhv-j9fj-f3fv/GHSA-pvhv-j9fj-f3fv.json @@ -7,12 +7,8 @@ "CVE-2021-38353" ], "details": "The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvm8-7672-fw3w/GHSA-pvm8-7672-fw3w.json b/advisories/unreviewed/2022/05/GHSA-pvm8-7672-fw3w/GHSA-pvm8-7672-fw3w.json index 7592887082b..c1b72494310 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvm8-7672-fw3w/GHSA-pvm8-7672-fw3w.json +++ b/advisories/unreviewed/2022/05/GHSA-pvm8-7672-fw3w/GHSA-pvm8-7672-fw3w.json @@ -7,12 +7,8 @@ "CVE-2021-40825" ], "details": "nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure SensorViewTM configuration and monitoring software and nECY to nECY communications. Impacted devices are at risk of exploitation. A remote attacker with IP access to an impacted device could submit lighting control commands to the nECY by leveraging the default key. A successful attack may result in the attacker gaining the ability to modify lighting conditions or gain the ability to update the software on lighting devices. The impacted key is referred to as the SensorView Password in the nECY nLight Explorer Interface and the Gateway Password in the SensorView application. An attacker cannot authenticate to or modify the configuration or software of the nECY system controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvx2-q7gm-49v5/GHSA-pvx2-q7gm-49v5.json b/advisories/unreviewed/2022/05/GHSA-pvx2-q7gm-49v5/GHSA-pvx2-q7gm-49v5.json index d80bd71f7a7..7fc50ad6a0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvx2-q7gm-49v5/GHSA-pvx2-q7gm-49v5.json +++ b/advisories/unreviewed/2022/05/GHSA-pvx2-q7gm-49v5/GHSA-pvx2-q7gm-49v5.json @@ -7,12 +7,8 @@ "CVE-2005-4444" ], "details": "Stack-based buffer overflow in the trace message functionality in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allow remote attackers to execute arbitrary code via a long POP3 reply.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw96-w628-c9h9/GHSA-pw96-w628-c9h9.json b/advisories/unreviewed/2022/05/GHSA-pw96-w628-c9h9/GHSA-pw96-w628-c9h9.json index 1c30f37c2fb..03669983c7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw96-w628-c9h9/GHSA-pw96-w628-c9h9.json +++ b/advisories/unreviewed/2022/05/GHSA-pw96-w628-c9h9/GHSA-pw96-w628-c9h9.json @@ -7,12 +7,8 @@ "CVE-2021-38338" ], "details": "The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter found in the ~/titan-framework/iframe-googlefont-preview.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-px8j-vfm9-79mv/GHSA-px8j-vfm9-79mv.json b/advisories/unreviewed/2022/05/GHSA-px8j-vfm9-79mv/GHSA-px8j-vfm9-79mv.json index 99807558d1d..f1a4a352259 100644 --- a/advisories/unreviewed/2022/05/GHSA-px8j-vfm9-79mv/GHSA-px8j-vfm9-79mv.json +++ b/advisories/unreviewed/2022/05/GHSA-px8j-vfm9-79mv/GHSA-px8j-vfm9-79mv.json @@ -7,12 +7,8 @@ "CVE-2020-21481" ], "details": "An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxc2-7c94-q8j2/GHSA-pxc2-7c94-q8j2.json b/advisories/unreviewed/2022/05/GHSA-pxc2-7c94-q8j2/GHSA-pxc2-7c94-q8j2.json index 0f0e2ad76eb..745ee20c456 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxc2-7c94-q8j2/GHSA-pxc2-7c94-q8j2.json +++ b/advisories/unreviewed/2022/05/GHSA-pxc2-7c94-q8j2/GHSA-pxc2-7c94-q8j2.json @@ -7,12 +7,8 @@ "CVE-2005-4761" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q24x-376x-hj43/GHSA-q24x-376x-hj43.json b/advisories/unreviewed/2022/05/GHSA-q24x-376x-hj43/GHSA-q24x-376x-hj43.json index 63b07a157b8..a4a5747fbe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q24x-376x-hj43/GHSA-q24x-376x-hj43.json +++ b/advisories/unreviewed/2022/05/GHSA-q24x-376x-hj43/GHSA-q24x-376x-hj43.json @@ -7,12 +7,8 @@ "CVE-2021-24511" ], "details": "The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q299-234g-2fcj/GHSA-q299-234g-2fcj.json b/advisories/unreviewed/2022/05/GHSA-q299-234g-2fcj/GHSA-q299-234g-2fcj.json index 5d10e9056cc..09ce73d209e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q299-234g-2fcj/GHSA-q299-234g-2fcj.json +++ b/advisories/unreviewed/2022/05/GHSA-q299-234g-2fcj/GHSA-q299-234g-2fcj.json @@ -7,12 +7,8 @@ "CVE-2005-4548" ], "details": "SQL injection vulnerability in the \"user area\" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2mm-jgm5-f6mh/GHSA-q2mm-jgm5-f6mh.json b/advisories/unreviewed/2022/05/GHSA-q2mm-jgm5-f6mh/GHSA-q2mm-jgm5-f6mh.json index 3f9a66b8e86..e76c1ffa767 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2mm-jgm5-f6mh/GHSA-q2mm-jgm5-f6mh.json +++ b/advisories/unreviewed/2022/05/GHSA-q2mm-jgm5-f6mh/GHSA-q2mm-jgm5-f6mh.json @@ -7,12 +7,8 @@ "CVE-2005-4775" ], "details": "Michael Scholz and Sebastian Stein Contineo 2.0, when the admin account lacks an e-mail address attribute, displays the password hash in a warning upon page reload, which might allow remote attackers to view the hash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q46j-qfxm-6h8p/GHSA-q46j-qfxm-6h8p.json b/advisories/unreviewed/2022/05/GHSA-q46j-qfxm-6h8p/GHSA-q46j-qfxm-6h8p.json index 37c7af4f54b..c8bfb6a1a33 100644 --- a/advisories/unreviewed/2022/05/GHSA-q46j-qfxm-6h8p/GHSA-q46j-qfxm-6h8p.json +++ b/advisories/unreviewed/2022/05/GHSA-q46j-qfxm-6h8p/GHSA-q46j-qfxm-6h8p.json @@ -7,12 +7,8 @@ "CVE-2021-39563" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q49m-mm5c-vjj3/GHSA-q49m-mm5c-vjj3.json b/advisories/unreviewed/2022/05/GHSA-q49m-mm5c-vjj3/GHSA-q49m-mm5c-vjj3.json index 6ebc30a249d..d0c55abba6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q49m-mm5c-vjj3/GHSA-q49m-mm5c-vjj3.json +++ b/advisories/unreviewed/2022/05/GHSA-q49m-mm5c-vjj3/GHSA-q49m-mm5c-vjj3.json @@ -7,12 +7,8 @@ "CVE-2005-4805" ], "details": "Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update 2 and earlier, allows remote attackers to obtain the source code for Java Server pages (JSP) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4c3-5fjh-5v6h/GHSA-q4c3-5fjh-5v6h.json b/advisories/unreviewed/2022/05/GHSA-q4c3-5fjh-5v6h/GHSA-q4c3-5fjh-5v6h.json index 48beced8b54..76e7f3c9717 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4c3-5fjh-5v6h/GHSA-q4c3-5fjh-5v6h.json +++ b/advisories/unreviewed/2022/05/GHSA-q4c3-5fjh-5v6h/GHSA-q4c3-5fjh-5v6h.json @@ -7,12 +7,8 @@ "CVE-2021-39325" ], "details": "The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.6.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q54g-x9rw-493w/GHSA-q54g-x9rw-493w.json b/advisories/unreviewed/2022/05/GHSA-q54g-x9rw-493w/GHSA-q54g-x9rw-493w.json index c16071fd693..d5940121f84 100644 --- a/advisories/unreviewed/2022/05/GHSA-q54g-x9rw-493w/GHSA-q54g-x9rw-493w.json +++ b/advisories/unreviewed/2022/05/GHSA-q54g-x9rw-493w/GHSA-q54g-x9rw-493w.json @@ -7,12 +7,8 @@ "CVE-2005-4471" ], "details": "POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q58x-g5cp-qvh7/GHSA-q58x-g5cp-qvh7.json b/advisories/unreviewed/2022/05/GHSA-q58x-g5cp-qvh7/GHSA-q58x-g5cp-qvh7.json index 179088389fc..b49e71acc9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q58x-g5cp-qvh7/GHSA-q58x-g5cp-qvh7.json +++ b/advisories/unreviewed/2022/05/GHSA-q58x-g5cp-qvh7/GHSA-q58x-g5cp-qvh7.json @@ -7,12 +7,8 @@ "CVE-2005-4855" ], "details": "Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q5h9-gx3c-p258/GHSA-q5h9-gx3c-p258.json b/advisories/unreviewed/2022/05/GHSA-q5h9-gx3c-p258/GHSA-q5h9-gx3c-p258.json index 0dae00fa8ee..e0b3fe62163 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5h9-gx3c-p258/GHSA-q5h9-gx3c-p258.json +++ b/advisories/unreviewed/2022/05/GHSA-q5h9-gx3c-p258/GHSA-q5h9-gx3c-p258.json @@ -7,12 +7,8 @@ "CVE-2021-39553" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function grealloc() located in gmem.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6mr-262c-p36r/GHSA-q6mr-262c-p36r.json b/advisories/unreviewed/2022/05/GHSA-q6mr-262c-p36r/GHSA-q6mr-262c-p36r.json index c2d0ed8e653..0c753dee2ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6mr-262c-p36r/GHSA-q6mr-262c-p36r.json +++ b/advisories/unreviewed/2022/05/GHSA-q6mr-262c-p36r/GHSA-q6mr-262c-p36r.json @@ -7,12 +7,8 @@ "CVE-2005-4754" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving \"network address translation.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6x3-c9cx-g347/GHSA-q6x3-c9cx-g347.json b/advisories/unreviewed/2022/05/GHSA-q6x3-c9cx-g347/GHSA-q6x3-c9cx-g347.json index 7987f47ca7e..503adb3c01b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6x3-c9cx-g347/GHSA-q6x3-c9cx-g347.json +++ b/advisories/unreviewed/2022/05/GHSA-q6x3-c9cx-g347/GHSA-q6x3-c9cx-g347.json @@ -7,12 +7,8 @@ "CVE-2005-4595" ], "details": "Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q73x-2fc7-9qwp/GHSA-q73x-2fc7-9qwp.json b/advisories/unreviewed/2022/05/GHSA-q73x-2fc7-9qwp/GHSA-q73x-2fc7-9qwp.json index 015da3df41d..10f7e0edcd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q73x-2fc7-9qwp/GHSA-q73x-2fc7-9qwp.json +++ b/advisories/unreviewed/2022/05/GHSA-q73x-2fc7-9qwp/GHSA-q73x-2fc7-9qwp.json @@ -7,12 +7,8 @@ "CVE-2005-4558" ], "details": "IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q94p-v87q-6wp8/GHSA-q94p-v87q-6wp8.json b/advisories/unreviewed/2022/05/GHSA-q94p-v87q-6wp8/GHSA-q94p-v87q-6wp8.json index 2b05a3b5821..609e4519a78 100644 --- a/advisories/unreviewed/2022/05/GHSA-q94p-v87q-6wp8/GHSA-q94p-v87q-6wp8.json +++ b/advisories/unreviewed/2022/05/GHSA-q94p-v87q-6wp8/GHSA-q94p-v87q-6wp8.json @@ -7,12 +7,8 @@ "CVE-2021-32275" ], "details": "An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q99f-3fh3-fpw2/GHSA-q99f-3fh3-fpw2.json b/advisories/unreviewed/2022/05/GHSA-q99f-3fh3-fpw2/GHSA-q99f-3fh3-fpw2.json index 5fa55d259f1..45ff1d5d014 100644 --- a/advisories/unreviewed/2022/05/GHSA-q99f-3fh3-fpw2/GHSA-q99f-3fh3-fpw2.json +++ b/advisories/unreviewed/2022/05/GHSA-q99f-3fh3-fpw2/GHSA-q99f-3fh3-fpw2.json @@ -7,12 +7,8 @@ "CVE-2005-4469" ], "details": "Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9j4-589p-rv63/GHSA-q9j4-589p-rv63.json b/advisories/unreviewed/2022/05/GHSA-q9j4-589p-rv63/GHSA-q9j4-589p-rv63.json index 3f70fee9895..2dbb2d366d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9j4-589p-rv63/GHSA-q9j4-589p-rv63.json +++ b/advisories/unreviewed/2022/05/GHSA-q9j4-589p-rv63/GHSA-q9j4-589p-rv63.json @@ -7,12 +7,8 @@ "CVE-2021-40864" ], "details": "The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc7v-hc5r-fq4j/GHSA-qc7v-hc5r-fq4j.json b/advisories/unreviewed/2022/05/GHSA-qc7v-hc5r-fq4j/GHSA-qc7v-hc5r-fq4j.json index bfbf03dc5d0..2e22848d3a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc7v-hc5r-fq4j/GHSA-qc7v-hc5r-fq4j.json +++ b/advisories/unreviewed/2022/05/GHSA-qc7v-hc5r-fq4j/GHSA-qc7v-hc5r-fq4j.json @@ -7,12 +7,8 @@ "CVE-2020-21321" ], "details": "emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg5j-588p-fv46/GHSA-qg5j-588p-fv46.json b/advisories/unreviewed/2022/05/GHSA-qg5j-588p-fv46/GHSA-qg5j-588p-fv46.json index 3c55b6d31e9..9bc1e532bf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg5j-588p-fv46/GHSA-qg5j-588p-fv46.json +++ b/advisories/unreviewed/2022/05/GHSA-qg5j-588p-fv46/GHSA-qg5j-588p-fv46.json @@ -7,12 +7,8 @@ "CVE-2021-40669" ], "details": "SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg93-hr7r-24gf/GHSA-qg93-hr7r-24gf.json b/advisories/unreviewed/2022/05/GHSA-qg93-hr7r-24gf/GHSA-qg93-hr7r-24gf.json index 8cb084f4bc9..25e8af97831 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg93-hr7r-24gf/GHSA-qg93-hr7r-24gf.json +++ b/advisories/unreviewed/2022/05/GHSA-qg93-hr7r-24gf/GHSA-qg93-hr7r-24gf.json @@ -7,12 +7,8 @@ "CVE-2021-41077" ], "details": "The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not specified by the customer-controlled .travis.yml file. In particular, the desired behavior (if .travis.yml has been created locally by a customer, and added to git) is for a Travis service to perform builds in a way that prevents public access to customer-specific secret environment data such as signing keys, access credentials, and API tokens. However, during the stated 8-day interval, secret data could be revealed to an unauthorized actor who forked a public repository and printed files during a build process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgmf-8pww-37qx/GHSA-qgmf-8pww-37qx.json b/advisories/unreviewed/2022/05/GHSA-qgmf-8pww-37qx/GHSA-qgmf-8pww-37qx.json index baaba429466..d7a1a1ef2e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgmf-8pww-37qx/GHSA-qgmf-8pww-37qx.json +++ b/advisories/unreviewed/2022/05/GHSA-qgmf-8pww-37qx/GHSA-qgmf-8pww-37qx.json @@ -7,12 +7,8 @@ "CVE-2020-4690" ], "details": "IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgrh-w8r5-c899/GHSA-qgrh-w8r5-c899.json b/advisories/unreviewed/2022/05/GHSA-qgrh-w8r5-c899/GHSA-qgrh-w8r5-c899.json index b7252c0efbb..642447cccce 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgrh-w8r5-c899/GHSA-qgrh-w8r5-c899.json +++ b/advisories/unreviewed/2022/05/GHSA-qgrh-w8r5-c899/GHSA-qgrh-w8r5-c899.json @@ -7,12 +7,8 @@ "CVE-2021-22011" ], "details": "vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgrw-r3gv-hrmm/GHSA-qgrw-r3gv-hrmm.json b/advisories/unreviewed/2022/05/GHSA-qgrw-r3gv-hrmm/GHSA-qgrw-r3gv-hrmm.json index 481ee724398..ef0f42f3de7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgrw-r3gv-hrmm/GHSA-qgrw-r3gv-hrmm.json +++ b/advisories/unreviewed/2022/05/GHSA-qgrw-r3gv-hrmm/GHSA-qgrw-r3gv-hrmm.json @@ -7,12 +7,8 @@ "CVE-2005-4615" ], "details": "SQL injection vulnerability in news.php in DapperDesk 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh87-5cc8-25g4/GHSA-qh87-5cc8-25g4.json b/advisories/unreviewed/2022/05/GHSA-qh87-5cc8-25g4/GHSA-qh87-5cc8-25g4.json index ac92fb613f9..a3453ff10cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh87-5cc8-25g4/GHSA-qh87-5cc8-25g4.json +++ b/advisories/unreviewed/2022/05/GHSA-qh87-5cc8-25g4/GHSA-qh87-5cc8-25g4.json @@ -7,12 +7,8 @@ "CVE-2021-38870" ], "details": "IBM Aspera Cloud is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208343.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmg8-cc8v-frfx/GHSA-qmg8-cc8v-frfx.json b/advisories/unreviewed/2022/05/GHSA-qmg8-cc8v-frfx/GHSA-qmg8-cc8v-frfx.json index 713264403a5..8fb14684f27 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmg8-cc8v-frfx/GHSA-qmg8-cc8v-frfx.json +++ b/advisories/unreviewed/2022/05/GHSA-qmg8-cc8v-frfx/GHSA-qmg8-cc8v-frfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmpc-fmq6-gf8j/GHSA-qmpc-fmq6-gf8j.json b/advisories/unreviewed/2022/05/GHSA-qmpc-fmq6-gf8j/GHSA-qmpc-fmq6-gf8j.json index 07724c20ab0..c18815ccd2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmpc-fmq6-gf8j/GHSA-qmpc-fmq6-gf8j.json +++ b/advisories/unreviewed/2022/05/GHSA-qmpc-fmq6-gf8j/GHSA-qmpc-fmq6-gf8j.json @@ -7,12 +7,8 @@ "CVE-2021-40373" ], "details": "playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp52-95j5-r3g3/GHSA-qp52-95j5-r3g3.json b/advisories/unreviewed/2022/05/GHSA-qp52-95j5-r3g3/GHSA-qp52-95j5-r3g3.json index f25df61933f..fb9bb401383 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp52-95j5-r3g3/GHSA-qp52-95j5-r3g3.json +++ b/advisories/unreviewed/2022/05/GHSA-qp52-95j5-r3g3/GHSA-qp52-95j5-r3g3.json @@ -7,12 +7,8 @@ "CVE-2021-40066" ], "details": "The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrqj-373x-w46c/GHSA-qrqj-373x-w46c.json b/advisories/unreviewed/2022/05/GHSA-qrqj-373x-w46c/GHSA-qrqj-373x-w46c.json index f584ec7c007..5220e543c02 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrqj-373x-w46c/GHSA-qrqj-373x-w46c.json +++ b/advisories/unreviewed/2022/05/GHSA-qrqj-373x-w46c/GHSA-qrqj-373x-w46c.json @@ -7,12 +7,8 @@ "CVE-2021-39532" ], "details": "An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv5f-5wgj-j5qf/GHSA-qv5f-5wgj-j5qf.json b/advisories/unreviewed/2022/05/GHSA-qv5f-5wgj-j5qf/GHSA-qv5f-5wgj-j5qf.json index 2ee21e6be4d..6987e93f472 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv5f-5wgj-j5qf/GHSA-qv5f-5wgj-j5qf.json +++ b/advisories/unreviewed/2022/05/GHSA-qv5f-5wgj-j5qf/GHSA-qv5f-5wgj-j5qf.json @@ -7,12 +7,8 @@ "CVE-2021-41315" ], "details": "The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvfc-hvww-w263/GHSA-qvfc-hvww-w263.json b/advisories/unreviewed/2022/05/GHSA-qvfc-hvww-w263/GHSA-qvfc-hvww-w263.json index a663b69bd1f..ad7b883eddd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvfc-hvww-w263/GHSA-qvfc-hvww-w263.json +++ b/advisories/unreviewed/2022/05/GHSA-qvfc-hvww-w263/GHSA-qvfc-hvww-w263.json @@ -7,12 +7,8 @@ "CVE-2021-39587" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvjp-29px-qgvp/GHSA-qvjp-29px-qgvp.json b/advisories/unreviewed/2022/05/GHSA-qvjp-29px-qgvp/GHSA-qvjp-29px-qgvp.json index e336771fe68..f65cb400f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvjp-29px-qgvp/GHSA-qvjp-29px-qgvp.json +++ b/advisories/unreviewed/2022/05/GHSA-qvjp-29px-qgvp/GHSA-qvjp-29px-qgvp.json @@ -7,12 +7,8 @@ "CVE-2005-4612" ], "details": "Multiple SQL injection vulnerabilities in VUBB alpha rc1 allow remote attackers to execute arbitrary SQL commands via the (1) f parameter to viewforum.php, (2) t parameter to viewtopic.php, and (3) view parameter to usercp.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw54-4wxm-x2wr/GHSA-qw54-4wxm-x2wr.json b/advisories/unreviewed/2022/05/GHSA-qw54-4wxm-x2wr/GHSA-qw54-4wxm-x2wr.json index 90b6c68ec85..9eb8038c533 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw54-4wxm-x2wr/GHSA-qw54-4wxm-x2wr.json +++ b/advisories/unreviewed/2022/05/GHSA-qw54-4wxm-x2wr/GHSA-qw54-4wxm-x2wr.json @@ -7,12 +7,8 @@ "CVE-2005-4716" ], "details": "Hitachi TP1/Server Base and TP1/NET/Library 2 on IBM AIX allow remote attackers to (1) cause a denial of service (OpenTP1 system outage) via invalid data to a port used by a system-server process, and (2) cause a denial of service (process failure) via invalid data to a port used by any of certain other processes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw5p-3fq9-8ggv/GHSA-qw5p-3fq9-8ggv.json b/advisories/unreviewed/2022/05/GHSA-qw5p-3fq9-8ggv/GHSA-qw5p-3fq9-8ggv.json index 994c0809331..4ed411afb0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw5p-3fq9-8ggv/GHSA-qw5p-3fq9-8ggv.json +++ b/advisories/unreviewed/2022/05/GHSA-qw5p-3fq9-8ggv/GHSA-qw5p-3fq9-8ggv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwpr-3q76-f8c4/GHSA-qwpr-3q76-f8c4.json b/advisories/unreviewed/2022/05/GHSA-qwpr-3q76-f8c4/GHSA-qwpr-3q76-f8c4.json index 0e1e488ab6c..899a9078c2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwpr-3q76-f8c4/GHSA-qwpr-3q76-f8c4.json +++ b/advisories/unreviewed/2022/05/GHSA-qwpr-3q76-f8c4/GHSA-qwpr-3q76-f8c4.json @@ -7,12 +7,8 @@ "CVE-2020-20894" ], "details": "Buffer Overflow vulnerability in function gaussian_blur in libavfilter/vf_edgedetect.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qx3r-96cr-cwr5/GHSA-qx3r-96cr-cwr5.json b/advisories/unreviewed/2022/05/GHSA-qx3r-96cr-cwr5/GHSA-qx3r-96cr-cwr5.json index 2e4c15037fc..c7852c244c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx3r-96cr-cwr5/GHSA-qx3r-96cr-cwr5.json +++ b/advisories/unreviewed/2022/05/GHSA-qx3r-96cr-cwr5/GHSA-qx3r-96cr-cwr5.json @@ -7,12 +7,8 @@ "CVE-2005-4685" ], "details": "Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r26r-fhq6-5rh4/GHSA-r26r-fhq6-5rh4.json b/advisories/unreviewed/2022/05/GHSA-r26r-fhq6-5rh4/GHSA-r26r-fhq6-5rh4.json index c3761dd3790..1a52a8b261c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r26r-fhq6-5rh4/GHSA-r26r-fhq6-5rh4.json +++ b/advisories/unreviewed/2022/05/GHSA-r26r-fhq6-5rh4/GHSA-r26r-fhq6-5rh4.json @@ -7,12 +7,8 @@ "CVE-2005-4682" ], "details": "Cross-site scripting (XSS) vulnerability in error.asp in AudienceView allows remote attackers to inject arbitrary web script or HTML via the TSerrorMessage parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r28r-rc5p-jq6v/GHSA-r28r-rc5p-jq6v.json b/advisories/unreviewed/2022/05/GHSA-r28r-rc5p-jq6v/GHSA-r28r-rc5p-jq6v.json index 7d19f2cf522..e6754d5abfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-r28r-rc5p-jq6v/GHSA-r28r-rc5p-jq6v.json +++ b/advisories/unreviewed/2022/05/GHSA-r28r-rc5p-jq6v/GHSA-r28r-rc5p-jq6v.json @@ -7,12 +7,8 @@ "CVE-2005-4414" ], "details": "Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to \"a menu security bug.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2mj-75fm-qmqh/GHSA-r2mj-75fm-qmqh.json b/advisories/unreviewed/2022/05/GHSA-r2mj-75fm-qmqh/GHSA-r2mj-75fm-qmqh.json index 84eac759112..ce74471784b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2mj-75fm-qmqh/GHSA-r2mj-75fm-qmqh.json +++ b/advisories/unreviewed/2022/05/GHSA-r2mj-75fm-qmqh/GHSA-r2mj-75fm-qmqh.json @@ -7,12 +7,8 @@ "CVE-2005-4452" ], "details": "Information Call Center stores the CallCenterData.mdb database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r35p-8r7c-fmpg/GHSA-r35p-8r7c-fmpg.json b/advisories/unreviewed/2022/05/GHSA-r35p-8r7c-fmpg/GHSA-r35p-8r7c-fmpg.json index 65a73d3ea29..df05da9c45e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r35p-8r7c-fmpg/GHSA-r35p-8r7c-fmpg.json +++ b/advisories/unreviewed/2022/05/GHSA-r35p-8r7c-fmpg/GHSA-r35p-8r7c-fmpg.json @@ -7,12 +7,8 @@ "CVE-2005-4773" ], "details": "The configuration of VMware ESX Server 2.x, 2.0.x, 2.1.x, and 2.5.x allows local users to cause a denial of service (shutdown) via the (1) halt, (2) poweroff, and (3) reboot scripts executed at the service console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3h6-x6q5-g5r4/GHSA-r3h6-x6q5-g5r4.json b/advisories/unreviewed/2022/05/GHSA-r3h6-x6q5-g5r4/GHSA-r3h6-x6q5-g5r4.json index 3784b1352d2..5515ff5418d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3h6-x6q5-g5r4/GHSA-r3h6-x6q5-g5r4.json +++ b/advisories/unreviewed/2022/05/GHSA-r3h6-x6q5-g5r4/GHSA-r3h6-x6q5-g5r4.json @@ -7,12 +7,8 @@ "CVE-2005-4449" ], "details": "verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into the body parameter. NOTE: if a FlatNuke administrator is normally assumed to be able to modify arbitrary content, then this issue does not cross privilege boundaries and would not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r468-mhg7-hr93/GHSA-r468-mhg7-hr93.json b/advisories/unreviewed/2022/05/GHSA-r468-mhg7-hr93/GHSA-r468-mhg7-hr93.json index 49d04690821..bcbe584b51e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r468-mhg7-hr93/GHSA-r468-mhg7-hr93.json +++ b/advisories/unreviewed/2022/05/GHSA-r468-mhg7-hr93/GHSA-r468-mhg7-hr93.json @@ -7,12 +7,8 @@ "CVE-2021-39527" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r586-r9hc-jwq2/GHSA-r586-r9hc-jwq2.json b/advisories/unreviewed/2022/05/GHSA-r586-r9hc-jwq2/GHSA-r586-r9hc-jwq2.json index fbd1cad59e4..6c80c70401b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r586-r9hc-jwq2/GHSA-r586-r9hc-jwq2.json +++ b/advisories/unreviewed/2022/05/GHSA-r586-r9hc-jwq2/GHSA-r586-r9hc-jwq2.json @@ -7,12 +7,8 @@ "CVE-2021-37913" ], "details": "The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5f7-f8rm-h8x4/GHSA-r5f7-f8rm-h8x4.json b/advisories/unreviewed/2022/05/GHSA-r5f7-f8rm-h8x4/GHSA-r5f7-f8rm-h8x4.json index 4d1cec320ac..2ca492bd430 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5f7-f8rm-h8x4/GHSA-r5f7-f8rm-h8x4.json +++ b/advisories/unreviewed/2022/05/GHSA-r5f7-f8rm-h8x4/GHSA-r5f7-f8rm-h8x4.json @@ -7,12 +7,8 @@ "CVE-2005-4530" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Enterprise 3.0 (formerly DoPays) allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters in (1) profile.htm, (2) card.htm, (3) bank.htm, (4) subscriptions.htm, (5) send.htm, (6) request.htm, (7) forgot.htm, (8) escrow.htm, (9) donations.htm, and (10) products.htm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5mj-2hhf-f733/GHSA-r5mj-2hhf-f733.json b/advisories/unreviewed/2022/05/GHSA-r5mj-2hhf-f733/GHSA-r5mj-2hhf-f733.json index 9b83e23f933..4bfd3834ebb 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5mj-2hhf-f733/GHSA-r5mj-2hhf-f733.json +++ b/advisories/unreviewed/2022/05/GHSA-r5mj-2hhf-f733/GHSA-r5mj-2hhf-f733.json @@ -7,12 +7,8 @@ "CVE-2005-4521" ], "details": "CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via (1) the return parameter in login_cookie_test.php and (2) ref parameter in login_select_proj_page.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5q2-69hv-8pr7/GHSA-r5q2-69hv-8pr7.json b/advisories/unreviewed/2022/05/GHSA-r5q2-69hv-8pr7/GHSA-r5q2-69hv-8pr7.json index 77b05316675..978776c4264 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5q2-69hv-8pr7/GHSA-r5q2-69hv-8pr7.json +++ b/advisories/unreviewed/2022/05/GHSA-r5q2-69hv-8pr7/GHSA-r5q2-69hv-8pr7.json @@ -7,12 +7,8 @@ "CVE-2020-19288" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5rh-99gw-6c43/GHSA-r5rh-99gw-6c43.json b/advisories/unreviewed/2022/05/GHSA-r5rh-99gw-6c43/GHSA-r5rh-99gw-6c43.json index ff8bc5ad492..d7bee4cf3d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5rh-99gw-6c43/GHSA-r5rh-99gw-6c43.json +++ b/advisories/unreviewed/2022/05/GHSA-r5rh-99gw-6c43/GHSA-r5rh-99gw-6c43.json @@ -7,12 +7,8 @@ "CVE-2005-4410" ], "details": "Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5vf-j7qp-fjrv/GHSA-r5vf-j7qp-fjrv.json b/advisories/unreviewed/2022/05/GHSA-r5vf-j7qp-fjrv/GHSA-r5vf-j7qp-fjrv.json index 1fe0b028494..7c4523f4f22 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5vf-j7qp-fjrv/GHSA-r5vf-j7qp-fjrv.json +++ b/advisories/unreviewed/2022/05/GHSA-r5vf-j7qp-fjrv/GHSA-r5vf-j7qp-fjrv.json @@ -7,12 +7,8 @@ "CVE-2005-4553" ], "details": "Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r69j-r7vf-pfx7/GHSA-r69j-r7vf-pfx7.json b/advisories/unreviewed/2022/05/GHSA-r69j-r7vf-pfx7/GHSA-r69j-r7vf-pfx7.json index afe4da223c8..96639e4ce58 100644 --- a/advisories/unreviewed/2022/05/GHSA-r69j-r7vf-pfx7/GHSA-r69j-r7vf-pfx7.json +++ b/advisories/unreviewed/2022/05/GHSA-r69j-r7vf-pfx7/GHSA-r69j-r7vf-pfx7.json @@ -7,12 +7,8 @@ "CVE-2021-39392" ], "details": "The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6gm-mf7m-68qc/GHSA-r6gm-mf7m-68qc.json b/advisories/unreviewed/2022/05/GHSA-r6gm-mf7m-68qc/GHSA-r6gm-mf7m-68qc.json index e042e3bcfac..64df871fddd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6gm-mf7m-68qc/GHSA-r6gm-mf7m-68qc.json +++ b/advisories/unreviewed/2022/05/GHSA-r6gm-mf7m-68qc/GHSA-r6gm-mf7m-68qc.json @@ -7,12 +7,8 @@ "CVE-2005-4772" ], "details": "liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6mg-w7qh-6wmq/GHSA-r6mg-w7qh-6wmq.json b/advisories/unreviewed/2022/05/GHSA-r6mg-w7qh-6wmq/GHSA-r6mg-w7qh-6wmq.json index b40d56737cb..b15976e06aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6mg-w7qh-6wmq/GHSA-r6mg-w7qh-6wmq.json +++ b/advisories/unreviewed/2022/05/GHSA-r6mg-w7qh-6wmq/GHSA-r6mg-w7qh-6wmq.json @@ -7,12 +7,8 @@ "CVE-2005-4607" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in BugPort 1.147 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ids[0], (2) action, (3) report_id, (4) devWherePair[1][1], and (5) binds[0] parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r73f-5m3v-4rx6/GHSA-r73f-5m3v-4rx6.json b/advisories/unreviewed/2022/05/GHSA-r73f-5m3v-4rx6/GHSA-r73f-5m3v-4rx6.json index 9afbe78e4ea..00f34280362 100644 --- a/advisories/unreviewed/2022/05/GHSA-r73f-5m3v-4rx6/GHSA-r73f-5m3v-4rx6.json +++ b/advisories/unreviewed/2022/05/GHSA-r73f-5m3v-4rx6/GHSA-r73f-5m3v-4rx6.json @@ -7,12 +7,8 @@ "CVE-2005-4841" ], "details": "The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r744-c99h-q8c4/GHSA-r744-c99h-q8c4.json b/advisories/unreviewed/2022/05/GHSA-r744-c99h-q8c4/GHSA-r744-c99h-q8c4.json index 4d0ffc5cddc..8e35c8e0260 100644 --- a/advisories/unreviewed/2022/05/GHSA-r744-c99h-q8c4/GHSA-r744-c99h-q8c4.json +++ b/advisories/unreviewed/2022/05/GHSA-r744-c99h-q8c4/GHSA-r744-c99h-q8c4.json @@ -7,12 +7,8 @@ "CVE-2005-4676" ], "details": "Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7jp-c6qf-39xv/GHSA-r7jp-c6qf-39xv.json b/advisories/unreviewed/2022/05/GHSA-r7jp-c6qf-39xv/GHSA-r7jp-c6qf-39xv.json index 3e19430a3fc..eef442e3295 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7jp-c6qf-39xv/GHSA-r7jp-c6qf-39xv.json +++ b/advisories/unreviewed/2022/05/GHSA-r7jp-c6qf-39xv/GHSA-r7jp-c6qf-39xv.json @@ -7,12 +7,8 @@ "CVE-2005-4665" ], "details": "Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7r4-mv2j-r29p/GHSA-r7r4-mv2j-r29p.json b/advisories/unreviewed/2022/05/GHSA-r7r4-mv2j-r29p/GHSA-r7r4-mv2j-r29p.json index e2704d174c5..a8b8645a5f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7r4-mv2j-r29p/GHSA-r7r4-mv2j-r29p.json +++ b/advisories/unreviewed/2022/05/GHSA-r7r4-mv2j-r29p/GHSA-r7r4-mv2j-r29p.json @@ -7,12 +7,8 @@ "CVE-2005-4673" ], "details": "ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7wx-4mj5-7j6j/GHSA-r7wx-4mj5-7j6j.json b/advisories/unreviewed/2022/05/GHSA-r7wx-4mj5-7j6j/GHSA-r7wx-4mj5-7j6j.json index af9f6f99e2e..9978faa9148 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7wx-4mj5-7j6j/GHSA-r7wx-4mj5-7j6j.json +++ b/advisories/unreviewed/2022/05/GHSA-r7wx-4mj5-7j6j/GHSA-r7wx-4mj5-7j6j.json @@ -7,12 +7,8 @@ "CVE-2005-4798" ], "details": "Buffer overflow in NFS readlink handling in the Linux Kernel 2.4 up to 2.4.31 allows remote NFS servers to cause a denial of service (crash) via a long symlink, which is not properly handled in (1) nfs2xdr.c or (2) nfs3xdr.c and causes a crash in the NFS client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r858-gg25-px8p/GHSA-r858-gg25-px8p.json b/advisories/unreviewed/2022/05/GHSA-r858-gg25-px8p/GHSA-r858-gg25-px8p.json index 76d0a5a98be..2501d49c180 100644 --- a/advisories/unreviewed/2022/05/GHSA-r858-gg25-px8p/GHSA-r858-gg25-px8p.json +++ b/advisories/unreviewed/2022/05/GHSA-r858-gg25-px8p/GHSA-r858-gg25-px8p.json @@ -7,12 +7,8 @@ "CVE-2021-39561" ], "details": "An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function Gfx::opSetFillColorN() located in Gfx.cc. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8j5-r375-6cxv/GHSA-r8j5-r375-6cxv.json b/advisories/unreviewed/2022/05/GHSA-r8j5-r375-6cxv/GHSA-r8j5-r375-6cxv.json index 6bc0ff532e4..fac612db64b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8j5-r375-6cxv/GHSA-r8j5-r375-6cxv.json +++ b/advisories/unreviewed/2022/05/GHSA-r8j5-r375-6cxv/GHSA-r8j5-r375-6cxv.json @@ -7,12 +7,8 @@ "CVE-2021-39579" ], "details": "An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function string_hash() located in q.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8rx-jmjw-9g68/GHSA-r8rx-jmjw-9g68.json b/advisories/unreviewed/2022/05/GHSA-r8rx-jmjw-9g68/GHSA-r8rx-jmjw-9g68.json index 77ad8b294d0..9eaf66669cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8rx-jmjw-9g68/GHSA-r8rx-jmjw-9g68.json +++ b/advisories/unreviewed/2022/05/GHSA-r8rx-jmjw-9g68/GHSA-r8rx-jmjw-9g68.json @@ -7,12 +7,8 @@ "CVE-2020-14109" ], "details": "There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8xv-6hx2-jxhm/GHSA-r8xv-6hx2-jxhm.json b/advisories/unreviewed/2022/05/GHSA-r8xv-6hx2-jxhm/GHSA-r8xv-6hx2-jxhm.json index c34a0c9d75f..7f2718596d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8xv-6hx2-jxhm/GHSA-r8xv-6hx2-jxhm.json +++ b/advisories/unreviewed/2022/05/GHSA-r8xv-6hx2-jxhm/GHSA-r8xv-6hx2-jxhm.json @@ -7,12 +7,8 @@ "CVE-2005-4880" ], "details": "Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9rm-x4wh-r2gc/GHSA-r9rm-x4wh-r2gc.json b/advisories/unreviewed/2022/05/GHSA-r9rm-x4wh-r2gc/GHSA-r9rm-x4wh-r2gc.json index 34cc5990262..dd5fad0e08e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9rm-x4wh-r2gc/GHSA-r9rm-x4wh-r2gc.json +++ b/advisories/unreviewed/2022/05/GHSA-r9rm-x4wh-r2gc/GHSA-r9rm-x4wh-r2gc.json @@ -7,12 +7,8 @@ "CVE-2005-4859" ], "details": "mimicboard2 (Mimic2) 086 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mimic2.dat.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9wv-hpvc-6wj6/GHSA-r9wv-hpvc-6wj6.json b/advisories/unreviewed/2022/05/GHSA-r9wv-hpvc-6wj6/GHSA-r9wv-hpvc-6wj6.json index 67e5caccf24..6847980b542 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9wv-hpvc-6wj6/GHSA-r9wv-hpvc-6wj6.json +++ b/advisories/unreviewed/2022/05/GHSA-r9wv-hpvc-6wj6/GHSA-r9wv-hpvc-6wj6.json @@ -7,12 +7,8 @@ "CVE-2021-39540" ], "details": "An issue was discovered in pdftools through 20200714. A stack-buffer-overflow exists in the function Analyze::AnalyzePages() located in analyze.cpp. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg44-2579-ph4x/GHSA-rg44-2579-ph4x.json b/advisories/unreviewed/2022/05/GHSA-rg44-2579-ph4x/GHSA-rg44-2579-ph4x.json index 76e7e592fe4..1664914e9b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg44-2579-ph4x/GHSA-rg44-2579-ph4x.json +++ b/advisories/unreviewed/2022/05/GHSA-rg44-2579-ph4x/GHSA-rg44-2579-ph4x.json @@ -7,12 +7,8 @@ "CVE-2020-19286" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field of the editor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgj6-8mcc-fqgj/GHSA-rgj6-8mcc-fqgj.json b/advisories/unreviewed/2022/05/GHSA-rgj6-8mcc-fqgj/GHSA-rgj6-8mcc-fqgj.json index 6a6fae2b568..a63be8864c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgj6-8mcc-fqgj/GHSA-rgj6-8mcc-fqgj.json +++ b/advisories/unreviewed/2022/05/GHSA-rgj6-8mcc-fqgj/GHSA-rgj6-8mcc-fqgj.json @@ -7,12 +7,8 @@ "CVE-2021-20433" ], "details": "IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rgjj-vq6w-2826/GHSA-rgjj-vq6w-2826.json b/advisories/unreviewed/2022/05/GHSA-rgjj-vq6w-2826/GHSA-rgjj-vq6w-2826.json index b64deb45f1b..e052b76a8b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgjj-vq6w-2826/GHSA-rgjj-vq6w-2826.json +++ b/advisories/unreviewed/2022/05/GHSA-rgjj-vq6w-2826/GHSA-rgjj-vq6w-2826.json @@ -7,12 +7,8 @@ "CVE-2005-4847" ], "details": "Unspecified vulnerability in Spey 0.3.3 has unknown impact and attack vectors related to \"A number of security holes which could lead to compromise,\" a different issue than CVE-2005-4846.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rh42-ggpq-295x/GHSA-rh42-ggpq-295x.json b/advisories/unreviewed/2022/05/GHSA-rh42-ggpq-295x/GHSA-rh42-ggpq-295x.json index 72dc454d799..1eb89e86ee3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh42-ggpq-295x/GHSA-rh42-ggpq-295x.json +++ b/advisories/unreviewed/2022/05/GHSA-rh42-ggpq-295x/GHSA-rh42-ggpq-295x.json @@ -7,12 +7,8 @@ "CVE-2021-39554" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhp4-4ff3-m4c6/GHSA-rhp4-4ff3-m4c6.json b/advisories/unreviewed/2022/05/GHSA-rhp4-4ff3-m4c6/GHSA-rhp4-4ff3-m4c6.json index 6255d39aa51..a36c594ffc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhp4-4ff3-m4c6/GHSA-rhp4-4ff3-m4c6.json +++ b/advisories/unreviewed/2022/05/GHSA-rhp4-4ff3-m4c6/GHSA-rhp4-4ff3-m4c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj93-7769-mc4j/GHSA-rj93-7769-mc4j.json b/advisories/unreviewed/2022/05/GHSA-rj93-7769-mc4j/GHSA-rj93-7769-mc4j.json index 4c4f4aab01f..66d35748c35 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj93-7769-mc4j/GHSA-rj93-7769-mc4j.json +++ b/advisories/unreviewed/2022/05/GHSA-rj93-7769-mc4j/GHSA-rj93-7769-mc4j.json @@ -7,12 +7,8 @@ "CVE-2021-24606" ], "details": "The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rppx-3r2h-4mfr/GHSA-rppx-3r2h-4mfr.json b/advisories/unreviewed/2022/05/GHSA-rppx-3r2h-4mfr/GHSA-rppx-3r2h-4mfr.json index b8ef11d2ce7..a73a67611e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rppx-3r2h-4mfr/GHSA-rppx-3r2h-4mfr.json +++ b/advisories/unreviewed/2022/05/GHSA-rppx-3r2h-4mfr/GHSA-rppx-3r2h-4mfr.json @@ -7,12 +7,8 @@ "CVE-2020-21127" ], "details": "MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpr9-97r4-fr4v/GHSA-rpr9-97r4-fr4v.json b/advisories/unreviewed/2022/05/GHSA-rpr9-97r4-fr4v/GHSA-rpr9-97r4-fr4v.json index 14ff2bfa9e5..9ad2b9c49c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpr9-97r4-fr4v/GHSA-rpr9-97r4-fr4v.json +++ b/advisories/unreviewed/2022/05/GHSA-rpr9-97r4-fr4v/GHSA-rpr9-97r4-fr4v.json @@ -7,12 +7,8 @@ "CVE-2021-39596" ], "details": "An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_parse() located in code.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq4x-8357-2wpf/GHSA-rq4x-8357-2wpf.json b/advisories/unreviewed/2022/05/GHSA-rq4x-8357-2wpf/GHSA-rq4x-8357-2wpf.json index 6ff106d06ff..7a71784dda0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq4x-8357-2wpf/GHSA-rq4x-8357-2wpf.json +++ b/advisories/unreviewed/2022/05/GHSA-rq4x-8357-2wpf/GHSA-rq4x-8357-2wpf.json @@ -7,12 +7,8 @@ "CVE-2005-4527" ], "details": "Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqxx-8p8c-6h26/GHSA-rqxx-8p8c-6h26.json b/advisories/unreviewed/2022/05/GHSA-rqxx-8p8c-6h26/GHSA-rqxx-8p8c-6h26.json index a197c6b90e3..721ed2964b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqxx-8p8c-6h26/GHSA-rqxx-8p8c-6h26.json +++ b/advisories/unreviewed/2022/05/GHSA-rqxx-8p8c-6h26/GHSA-rqxx-8p8c-6h26.json @@ -7,12 +7,8 @@ "CVE-2020-21548" ], "details": "Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv9q-r38w-4h48/GHSA-rv9q-r38w-4h48.json b/advisories/unreviewed/2022/05/GHSA-rv9q-r38w-4h48/GHSA-rv9q-r38w-4h48.json index 665959495af..3a38fe894d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv9q-r38w-4h48/GHSA-rv9q-r38w-4h48.json +++ b/advisories/unreviewed/2022/05/GHSA-rv9q-r38w-4h48/GHSA-rv9q-r38w-4h48.json @@ -7,12 +7,8 @@ "CVE-2005-4819" ], "details": "Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvrw-7cfv-7x29/GHSA-rvrw-7cfv-7x29.json b/advisories/unreviewed/2022/05/GHSA-rvrw-7cfv-7x29/GHSA-rvrw-7cfv-7x29.json index f2a8f8f85be..bb15f911f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvrw-7cfv-7x29/GHSA-rvrw-7cfv-7x29.json +++ b/advisories/unreviewed/2022/05/GHSA-rvrw-7cfv-7x29/GHSA-rvrw-7cfv-7x29.json @@ -7,12 +7,8 @@ "CVE-2021-32963" ], "details": "Null pointer dereference in SuiteLink server while processing commands 0x03/0x10", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rw97-q7v4-xhhq/GHSA-rw97-q7v4-xhhq.json b/advisories/unreviewed/2022/05/GHSA-rw97-q7v4-xhhq/GHSA-rw97-q7v4-xhhq.json index e77cbd9954e..3509af656b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw97-q7v4-xhhq/GHSA-rw97-q7v4-xhhq.json +++ b/advisories/unreviewed/2022/05/GHSA-rw97-q7v4-xhhq/GHSA-rw97-q7v4-xhhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwcf-9qwj-85vw/GHSA-rwcf-9qwj-85vw.json b/advisories/unreviewed/2022/05/GHSA-rwcf-9qwj-85vw/GHSA-rwcf-9qwj-85vw.json index 249b032ef6a..a1ef9668d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwcf-9qwj-85vw/GHSA-rwcf-9qwj-85vw.json +++ b/advisories/unreviewed/2022/05/GHSA-rwcf-9qwj-85vw/GHSA-rwcf-9qwj-85vw.json @@ -7,12 +7,8 @@ "CVE-2005-4599" ], "details": "Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwfg-c7rv-75g7/GHSA-rwfg-c7rv-75g7.json b/advisories/unreviewed/2022/05/GHSA-rwfg-c7rv-75g7/GHSA-rwfg-c7rv-75g7.json index 3abc1c3915a..a787f54a70b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwfg-c7rv-75g7/GHSA-rwfg-c7rv-75g7.json +++ b/advisories/unreviewed/2022/05/GHSA-rwfg-c7rv-75g7/GHSA-rwfg-c7rv-75g7.json @@ -7,12 +7,8 @@ "CVE-2021-39515" ], "details": "An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU() located in sampleinterleavedlsscan.cpp. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwjf-4f53-289h/GHSA-rwjf-4f53-289h.json b/advisories/unreviewed/2022/05/GHSA-rwjf-4f53-289h/GHSA-rwjf-4f53-289h.json index 5149a9e09f6..f4b06bc5f3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwjf-4f53-289h/GHSA-rwjf-4f53-289h.json +++ b/advisories/unreviewed/2022/05/GHSA-rwjf-4f53-289h/GHSA-rwjf-4f53-289h.json @@ -7,12 +7,8 @@ "CVE-2021-33705" ], "details": "The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a user can make any type of request (e.g. POST, GET) to any internal or external server. This can result in the accessing or modification of data accessible from the Portal but will not affect its availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx2c-w2cr-c677/GHSA-rx2c-w2cr-c677.json b/advisories/unreviewed/2022/05/GHSA-rx2c-w2cr-c677/GHSA-rx2c-w2cr-c677.json index bc99109c2d3..0f9eb80dfcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx2c-w2cr-c677/GHSA-rx2c-w2cr-c677.json +++ b/advisories/unreviewed/2022/05/GHSA-rx2c-w2cr-c677/GHSA-rx2c-w2cr-c677.json @@ -7,12 +7,8 @@ "CVE-2021-22950" ], "details": "Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: \"Solar Security Research Team\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx59-33mv-93w9/GHSA-rx59-33mv-93w9.json b/advisories/unreviewed/2022/05/GHSA-rx59-33mv-93w9/GHSA-rx59-33mv-93w9.json index 8b7d0520e01..bf5bab5b12b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx59-33mv-93w9/GHSA-rx59-33mv-93w9.json +++ b/advisories/unreviewed/2022/05/GHSA-rx59-33mv-93w9/GHSA-rx59-33mv-93w9.json @@ -7,12 +7,8 @@ "CVE-2005-4571" ], "details": "Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx9m-2wvh-rvjf/GHSA-rx9m-2wvh-rvjf.json b/advisories/unreviewed/2022/05/GHSA-rx9m-2wvh-rvjf/GHSA-rx9m-2wvh-rvjf.json index 58ee8b783d4..9fc0eed0b37 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx9m-2wvh-rvjf/GHSA-rx9m-2wvh-rvjf.json +++ b/advisories/unreviewed/2022/05/GHSA-rx9m-2wvh-rvjf/GHSA-rx9m-2wvh-rvjf.json @@ -7,12 +7,8 @@ "CVE-2005-4846" ], "details": "Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a syslog call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxgh-w4w6-hc2v/GHSA-rxgh-w4w6-hc2v.json b/advisories/unreviewed/2022/05/GHSA-rxgh-w4w6-hc2v/GHSA-rxgh-w4w6-hc2v.json index d847f727388..1c0526eb7a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxgh-w4w6-hc2v/GHSA-rxgh-w4w6-hc2v.json +++ b/advisories/unreviewed/2022/05/GHSA-rxgh-w4w6-hc2v/GHSA-rxgh-w4w6-hc2v.json @@ -7,12 +7,8 @@ "CVE-2005-4747" ], "details": "Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd Helm before 3.2.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors involving the default page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v25v-x7cf-rjxx/GHSA-v25v-x7cf-rjxx.json b/advisories/unreviewed/2022/05/GHSA-v25v-x7cf-rjxx/GHSA-v25v-x7cf-rjxx.json index 9098750c702..f225e5906bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-v25v-x7cf-rjxx/GHSA-v25v-x7cf-rjxx.json +++ b/advisories/unreviewed/2022/05/GHSA-v25v-x7cf-rjxx/GHSA-v25v-x7cf-rjxx.json @@ -7,12 +7,8 @@ "CVE-2005-4565" ], "details": "Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via format string specifiers in crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2cc-8mqc-vmq4/GHSA-v2cc-8mqc-vmq4.json b/advisories/unreviewed/2022/05/GHSA-v2cc-8mqc-vmq4/GHSA-v2cc-8mqc-vmq4.json index c0ea4db9a9e..3235436e1b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2cc-8mqc-vmq4/GHSA-v2cc-8mqc-vmq4.json +++ b/advisories/unreviewed/2022/05/GHSA-v2cc-8mqc-vmq4/GHSA-v2cc-8mqc-vmq4.json @@ -7,12 +7,8 @@ "CVE-2020-19151" ], "details": "Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v45h-m83x-7564/GHSA-v45h-m83x-7564.json b/advisories/unreviewed/2022/05/GHSA-v45h-m83x-7564/GHSA-v45h-m83x-7564.json index 2e387ae2e11..20bcdb18fa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-v45h-m83x-7564/GHSA-v45h-m83x-7564.json +++ b/advisories/unreviewed/2022/05/GHSA-v45h-m83x-7564/GHSA-v45h-m83x-7564.json @@ -7,12 +7,8 @@ "CVE-2005-4524" ], "details": "Mantis 1.0.0rc3 does not properly handle \"Make note private\" when a bug is being resolved, which has unknown impact and attack vectors, probably related to an information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v472-q69q-pwf9/GHSA-v472-q69q-pwf9.json b/advisories/unreviewed/2022/05/GHSA-v472-q69q-pwf9/GHSA-v472-q69q-pwf9.json index f6dd9f04061..0063d07f18a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v472-q69q-pwf9/GHSA-v472-q69q-pwf9.json +++ b/advisories/unreviewed/2022/05/GHSA-v472-q69q-pwf9/GHSA-v472-q69q-pwf9.json @@ -7,12 +7,8 @@ "CVE-2021-41317" ], "details": "XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4m4-f9f5-pvcm/GHSA-v4m4-f9f5-pvcm.json b/advisories/unreviewed/2022/05/GHSA-v4m4-f9f5-pvcm/GHSA-v4m4-f9f5-pvcm.json index e5ac9652c44..29a1acb315e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4m4-f9f5-pvcm/GHSA-v4m4-f9f5-pvcm.json +++ b/advisories/unreviewed/2022/05/GHSA-v4m4-f9f5-pvcm/GHSA-v4m4-f9f5-pvcm.json @@ -7,12 +7,8 @@ "CVE-2005-4559" ], "details": "mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired default_layout and layout_settings parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v55p-34x8-pfvv/GHSA-v55p-34x8-pfvv.json b/advisories/unreviewed/2022/05/GHSA-v55p-34x8-pfvv/GHSA-v55p-34x8-pfvv.json index db6d191a145..62f790b2962 100644 --- a/advisories/unreviewed/2022/05/GHSA-v55p-34x8-pfvv/GHSA-v55p-34x8-pfvv.json +++ b/advisories/unreviewed/2022/05/GHSA-v55p-34x8-pfvv/GHSA-v55p-34x8-pfvv.json @@ -7,12 +7,8 @@ "CVE-2021-39548" ], "details": "An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function frame::FrameDecoder::process() located in frame_decoder.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5c4-pw5f-p9f7/GHSA-v5c4-pw5f-p9f7.json b/advisories/unreviewed/2022/05/GHSA-v5c4-pw5f-p9f7/GHSA-v5c4-pw5f-p9f7.json index 51de41130e1..e959acf68f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5c4-pw5f-p9f7/GHSA-v5c4-pw5f-p9f7.json +++ b/advisories/unreviewed/2022/05/GHSA-v5c4-pw5f-p9f7/GHSA-v5c4-pw5f-p9f7.json @@ -7,12 +7,8 @@ "CVE-2005-4451" ], "details": "Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain access via unspecified attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5xc-jmcq-c9fm/GHSA-v5xc-jmcq-c9fm.json b/advisories/unreviewed/2022/05/GHSA-v5xc-jmcq-c9fm/GHSA-v5xc-jmcq-c9fm.json index a7f8e6dfb4f..e64b871df0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5xc-jmcq-c9fm/GHSA-v5xc-jmcq-c9fm.json +++ b/advisories/unreviewed/2022/05/GHSA-v5xc-jmcq-c9fm/GHSA-v5xc-jmcq-c9fm.json @@ -7,12 +7,8 @@ "CVE-2021-28813" ], "details": "A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6gh-h6v7-p7r2/GHSA-v6gh-h6v7-p7r2.json b/advisories/unreviewed/2022/05/GHSA-v6gh-h6v7-p7r2/GHSA-v6gh-h6v7-p7r2.json index 68dd81febde..a8897abdedb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6gh-h6v7-p7r2/GHSA-v6gh-h6v7-p7r2.json +++ b/advisories/unreviewed/2022/05/GHSA-v6gh-h6v7-p7r2/GHSA-v6gh-h6v7-p7r2.json @@ -7,12 +7,8 @@ "CVE-2021-38093" ], "details": "Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6gr-qxpq-rwwc/GHSA-v6gr-qxpq-rwwc.json b/advisories/unreviewed/2022/05/GHSA-v6gr-qxpq-rwwc/GHSA-v6gr-qxpq-rwwc.json index cd52faa3e8d..7b9a416d8e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6gr-qxpq-rwwc/GHSA-v6gr-qxpq-rwwc.json +++ b/advisories/unreviewed/2022/05/GHSA-v6gr-qxpq-rwwc/GHSA-v6gr-qxpq-rwwc.json @@ -7,12 +7,8 @@ "CVE-2005-4643" ], "details": "SQL injection vulnerability in index.php in Antharia OnContent // CMS allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it is not clear, but this might be an application service provider, in which case it might be excluded from CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6r9-9qj6-rrc4/GHSA-v6r9-9qj6-rrc4.json b/advisories/unreviewed/2022/05/GHSA-v6r9-9qj6-rrc4/GHSA-v6r9-9qj6-rrc4.json index 036d0f9c87f..4ebbbb13588 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6r9-9qj6-rrc4/GHSA-v6r9-9qj6-rrc4.json +++ b/advisories/unreviewed/2022/05/GHSA-v6r9-9qj6-rrc4/GHSA-v6r9-9qj6-rrc4.json @@ -7,12 +7,8 @@ "CVE-2005-4739" ], "details": "IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6xv-gxfj-pv5f/GHSA-v6xv-gxfj-pv5f.json b/advisories/unreviewed/2022/05/GHSA-v6xv-gxfj-pv5f/GHSA-v6xv-gxfj-pv5f.json index 0ba9fa9e039..5c6cef69a2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6xv-gxfj-pv5f/GHSA-v6xv-gxfj-pv5f.json +++ b/advisories/unreviewed/2022/05/GHSA-v6xv-gxfj-pv5f/GHSA-v6xv-gxfj-pv5f.json @@ -7,12 +7,8 @@ "CVE-2005-4657" ], "details": "Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v82c-4hvx-qp92/GHSA-v82c-4hvx-qp92.json b/advisories/unreviewed/2022/05/GHSA-v82c-4hvx-qp92/GHSA-v82c-4hvx-qp92.json index 58c5605e6d6..1335e9a98cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-v82c-4hvx-qp92/GHSA-v82c-4hvx-qp92.json +++ b/advisories/unreviewed/2022/05/GHSA-v82c-4hvx-qp92/GHSA-v82c-4hvx-qp92.json @@ -7,12 +7,8 @@ "CVE-2005-4431" ], "details": "SQL injection vulnerability in WowBB 1.65 allows remote attackers to execute arbitrary SQL commands via the q parameter to search.php. NOTE: the view_user.php/sort_by vector is already covered by CVE-2005-1554 and CVE-2004-2181.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v85g-hrr5-4jw4/GHSA-v85g-hrr5-4jw4.json b/advisories/unreviewed/2022/05/GHSA-v85g-hrr5-4jw4/GHSA-v85g-hrr5-4jw4.json index 801a2f2b70b..8eb2213e9eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v85g-hrr5-4jw4/GHSA-v85g-hrr5-4jw4.json +++ b/advisories/unreviewed/2022/05/GHSA-v85g-hrr5-4jw4/GHSA-v85g-hrr5-4jw4.json @@ -7,12 +7,8 @@ "CVE-2021-38339" ], "details": "The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.01.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v88h-3x82-jgxh/GHSA-v88h-3x82-jgxh.json b/advisories/unreviewed/2022/05/GHSA-v88h-3x82-jgxh/GHSA-v88h-3x82-jgxh.json index 6e7a61c9f1c..90cea858656 100644 --- a/advisories/unreviewed/2022/05/GHSA-v88h-3x82-jgxh/GHSA-v88h-3x82-jgxh.json +++ b/advisories/unreviewed/2022/05/GHSA-v88h-3x82-jgxh/GHSA-v88h-3x82-jgxh.json @@ -7,12 +7,8 @@ "CVE-2005-4834" ], "details": "IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8h3-c8g3-cjh3/GHSA-v8h3-c8g3-cjh3.json b/advisories/unreviewed/2022/05/GHSA-v8h3-c8g3-cjh3/GHSA-v8h3-c8g3-cjh3.json index 4c528e2a6f7..8ed3960de0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8h3-c8g3-cjh3/GHSA-v8h3-c8g3-cjh3.json +++ b/advisories/unreviewed/2022/05/GHSA-v8h3-c8g3-cjh3/GHSA-v8h3-c8g3-cjh3.json @@ -7,12 +7,8 @@ "CVE-2021-39594" ], "details": "Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in swftext.c. It allows an attacker to cause Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9gx-j636-r322/GHSA-v9gx-j636-r322.json b/advisories/unreviewed/2022/05/GHSA-v9gx-j636-r322/GHSA-v9gx-j636-r322.json index 810021d62b7..1c0f1fe7e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9gx-j636-r322/GHSA-v9gx-j636-r322.json +++ b/advisories/unreviewed/2022/05/GHSA-v9gx-j636-r322/GHSA-v9gx-j636-r322.json @@ -7,12 +7,8 @@ "CVE-2005-4529" ], "details": "The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to impersonate other users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9q6-5fj2-jrgh/GHSA-v9q6-5fj2-jrgh.json b/advisories/unreviewed/2022/05/GHSA-v9q6-5fj2-jrgh/GHSA-v9q6-5fj2-jrgh.json index f2e233fd4db..f377147de14 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9q6-5fj2-jrgh/GHSA-v9q6-5fj2-jrgh.json +++ b/advisories/unreviewed/2022/05/GHSA-v9q6-5fj2-jrgh/GHSA-v9q6-5fj2-jrgh.json @@ -7,12 +7,8 @@ "CVE-2005-4782" ], "details": "NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with \"options DIAGNOSTIC,\" allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9rh-hjph-hq2p/GHSA-v9rh-hjph-hq2p.json b/advisories/unreviewed/2022/05/GHSA-v9rh-hjph-hq2p/GHSA-v9rh-hjph-hq2p.json index fb9ccafd4c1..d7e895308ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9rh-hjph-hq2p/GHSA-v9rh-hjph-hq2p.json +++ b/advisories/unreviewed/2022/05/GHSA-v9rh-hjph-hq2p/GHSA-v9rh-hjph-hq2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcfm-2qwg-6qcj/GHSA-vcfm-2qwg-6qcj.json b/advisories/unreviewed/2022/05/GHSA-vcfm-2qwg-6qcj/GHSA-vcfm-2qwg-6qcj.json index 857bfdb7f4a..ca0c66c54b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcfm-2qwg-6qcj/GHSA-vcfm-2qwg-6qcj.json +++ b/advisories/unreviewed/2022/05/GHSA-vcfm-2qwg-6qcj/GHSA-vcfm-2qwg-6qcj.json @@ -7,12 +7,8 @@ "CVE-2020-21530" ], "details": "fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vf3f-4cmj-7ggp/GHSA-vf3f-4cmj-7ggp.json b/advisories/unreviewed/2022/05/GHSA-vf3f-4cmj-7ggp/GHSA-vf3f-4cmj-7ggp.json index 5272b0366f9..922e69734de 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf3f-4cmj-7ggp/GHSA-vf3f-4cmj-7ggp.json +++ b/advisories/unreviewed/2022/05/GHSA-vf3f-4cmj-7ggp/GHSA-vf3f-4cmj-7ggp.json @@ -7,12 +7,8 @@ "CVE-2005-4635" ], "details": "The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfw5-ghx2-pfhf/GHSA-vfw5-ghx2-pfhf.json b/advisories/unreviewed/2022/05/GHSA-vfw5-ghx2-pfhf/GHSA-vfw5-ghx2-pfhf.json index dc1ce5f17c5..d94d0f2513b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfw5-ghx2-pfhf/GHSA-vfw5-ghx2-pfhf.json +++ b/advisories/unreviewed/2022/05/GHSA-vfw5-ghx2-pfhf/GHSA-vfw5-ghx2-pfhf.json @@ -7,12 +7,8 @@ "CVE-2021-40067" ], "details": "The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg2h-939c-4p88/GHSA-vg2h-939c-4p88.json b/advisories/unreviewed/2022/05/GHSA-vg2h-939c-4p88/GHSA-vg2h-939c-4p88.json index fc9a9af455a..08f77f752a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg2h-939c-4p88/GHSA-vg2h-939c-4p88.json +++ b/advisories/unreviewed/2022/05/GHSA-vg2h-939c-4p88/GHSA-vg2h-939c-4p88.json @@ -7,12 +7,8 @@ "CVE-2021-22010" ], "details": "The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by VPXD service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhcm-f3gx-wghc/GHSA-vhcm-f3gx-wghc.json b/advisories/unreviewed/2022/05/GHSA-vhcm-f3gx-wghc/GHSA-vhcm-f3gx-wghc.json index 0bf177538a8..6bcda1ed44c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhcm-f3gx-wghc/GHSA-vhcm-f3gx-wghc.json +++ b/advisories/unreviewed/2022/05/GHSA-vhcm-f3gx-wghc/GHSA-vhcm-f3gx-wghc.json @@ -7,12 +7,8 @@ "CVE-2021-29750" ], "details": "IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhmr-2r99-xhqw/GHSA-vhmr-2r99-xhqw.json b/advisories/unreviewed/2022/05/GHSA-vhmr-2r99-xhqw/GHSA-vhmr-2r99-xhqw.json index 555183282ca..2bf59269807 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhmr-2r99-xhqw/GHSA-vhmr-2r99-xhqw.json +++ b/advisories/unreviewed/2022/05/GHSA-vhmr-2r99-xhqw/GHSA-vhmr-2r99-xhqw.json @@ -7,12 +7,8 @@ "CVE-2021-34345" ], "details": "A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm2x-mv9x-52v3/GHSA-vm2x-mv9x-52v3.json b/advisories/unreviewed/2022/05/GHSA-vm2x-mv9x-52v3/GHSA-vm2x-mv9x-52v3.json index 3ca1cfe3ab6..0c314b9d10e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm2x-mv9x-52v3/GHSA-vm2x-mv9x-52v3.json +++ b/advisories/unreviewed/2022/05/GHSA-vm2x-mv9x-52v3/GHSA-vm2x-mv9x-52v3.json @@ -7,12 +7,8 @@ "CVE-2005-4639" ], "details": "Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by \"reading more than 8 bytes into an 8 byte long array\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm9v-hfwf-qw4q/GHSA-vm9v-hfwf-qw4q.json b/advisories/unreviewed/2022/05/GHSA-vm9v-hfwf-qw4q/GHSA-vm9v-hfwf-qw4q.json index e17f0f9a343..c5c7ec09d4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm9v-hfwf-qw4q/GHSA-vm9v-hfwf-qw4q.json +++ b/advisories/unreviewed/2022/05/GHSA-vm9v-hfwf-qw4q/GHSA-vm9v-hfwf-qw4q.json @@ -7,12 +7,8 @@ "CVE-2021-24587" ], "details": "The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmj3-x582-v9f4/GHSA-vmj3-x582-v9f4.json b/advisories/unreviewed/2022/05/GHSA-vmj3-x582-v9f4/GHSA-vmj3-x582-v9f4.json index c80c55857f2..d50672b1900 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmj3-x582-v9f4/GHSA-vmj3-x582-v9f4.json +++ b/advisories/unreviewed/2022/05/GHSA-vmj3-x582-v9f4/GHSA-vmj3-x582-v9f4.json @@ -7,12 +7,8 @@ "CVE-2021-40966" ], "details": "A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp5m-f62h-hxrm/GHSA-vp5m-f62h-hxrm.json b/advisories/unreviewed/2022/05/GHSA-vp5m-f62h-hxrm/GHSA-vp5m-f62h-hxrm.json index 45cf0fe6e39..d4720e387e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp5m-f62h-hxrm/GHSA-vp5m-f62h-hxrm.json +++ b/advisories/unreviewed/2022/05/GHSA-vp5m-f62h-hxrm/GHSA-vp5m-f62h-hxrm.json @@ -7,12 +7,8 @@ "CVE-2005-4806" ], "details": "Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpfp-r4p5-f5w5/GHSA-vpfp-r4p5-f5w5.json b/advisories/unreviewed/2022/05/GHSA-vpfp-r4p5-f5w5/GHSA-vpfp-r4p5-f5w5.json index d172a0ce7f6..76a1a728717 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpfp-r4p5-f5w5/GHSA-vpfp-r4p5-f5w5.json +++ b/advisories/unreviewed/2022/05/GHSA-vpfp-r4p5-f5w5/GHSA-vpfp-r4p5-f5w5.json @@ -7,12 +7,8 @@ "CVE-2021-39530" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpwg-rrq8-85jp/GHSA-vpwg-rrq8-85jp.json b/advisories/unreviewed/2022/05/GHSA-vpwg-rrq8-85jp/GHSA-vpwg-rrq8-85jp.json index 22c16b3a669..7ac8fdf1bd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpwg-rrq8-85jp/GHSA-vpwg-rrq8-85jp.json +++ b/advisories/unreviewed/2022/05/GHSA-vpwg-rrq8-85jp/GHSA-vpwg-rrq8-85jp.json @@ -7,12 +7,8 @@ "CVE-2005-4694" ], "details": "Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute arbitrary code via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq47-f2jr-4vpm/GHSA-vq47-f2jr-4vpm.json b/advisories/unreviewed/2022/05/GHSA-vq47-f2jr-4vpm/GHSA-vq47-f2jr-4vpm.json index 776cb800495..7988c002ee0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq47-f2jr-4vpm/GHSA-vq47-f2jr-4vpm.json +++ b/advisories/unreviewed/2022/05/GHSA-vq47-f2jr-4vpm/GHSA-vq47-f2jr-4vpm.json @@ -7,12 +7,8 @@ "CVE-2005-4575" ], "details": "PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vv7p-2mjf-r3h3/GHSA-vv7p-2mjf-r3h3.json b/advisories/unreviewed/2022/05/GHSA-vv7p-2mjf-r3h3/GHSA-vv7p-2mjf-r3h3.json index a834fe07b0a..c5ba39a0826 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv7p-2mjf-r3h3/GHSA-vv7p-2mjf-r3h3.json +++ b/advisories/unreviewed/2022/05/GHSA-vv7p-2mjf-r3h3/GHSA-vv7p-2mjf-r3h3.json @@ -7,12 +7,8 @@ "CVE-2021-32139" ], "details": "The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvj5-mp2m-mfch/GHSA-vvj5-mp2m-mfch.json b/advisories/unreviewed/2022/05/GHSA-vvj5-mp2m-mfch/GHSA-vvj5-mp2m-mfch.json index 5bbb57bb8ad..6e64664d274 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvj5-mp2m-mfch/GHSA-vvj5-mp2m-mfch.json +++ b/advisories/unreviewed/2022/05/GHSA-vvj5-mp2m-mfch/GHSA-vvj5-mp2m-mfch.json @@ -7,12 +7,8 @@ "CVE-2021-20825" ], "details": "Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw9c-7wx5-4jpp/GHSA-vw9c-7wx5-4jpp.json b/advisories/unreviewed/2022/05/GHSA-vw9c-7wx5-4jpp/GHSA-vw9c-7wx5-4jpp.json index aec0d761370..31364cfcabb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw9c-7wx5-4jpp/GHSA-vw9c-7wx5-4jpp.json +++ b/advisories/unreviewed/2022/05/GHSA-vw9c-7wx5-4jpp/GHSA-vw9c-7wx5-4jpp.json @@ -7,12 +7,8 @@ "CVE-2021-24560" ], "details": "The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwhg-5hvv-63v5/GHSA-vwhg-5hvv-63v5.json b/advisories/unreviewed/2022/05/GHSA-vwhg-5hvv-63v5/GHSA-vwhg-5hvv-63v5.json index 2543a69ba3b..0e7025b0023 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwhg-5hvv-63v5/GHSA-vwhg-5hvv-63v5.json +++ b/advisories/unreviewed/2022/05/GHSA-vwhg-5hvv-63v5/GHSA-vwhg-5hvv-63v5.json @@ -7,12 +7,8 @@ "CVE-2020-27969" ], "details": "Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx4g-c7q3-585r/GHSA-vx4g-c7q3-585r.json b/advisories/unreviewed/2022/05/GHSA-vx4g-c7q3-585r/GHSA-vx4g-c7q3-585r.json index 49d6c4462f7..4b0c503bc09 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx4g-c7q3-585r/GHSA-vx4g-c7q3-585r.json +++ b/advisories/unreviewed/2022/05/GHSA-vx4g-c7q3-585r/GHSA-vx4g-c7q3-585r.json @@ -7,12 +7,8 @@ "CVE-2005-4457" ], "details": "MailEnable Enterprise 1.1 before patch ME-10009 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via several \"...\" (triple dot) sequences in a UID FETCH command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxhm-ccj3-8p4x/GHSA-vxhm-ccj3-8p4x.json b/advisories/unreviewed/2022/05/GHSA-vxhm-ccj3-8p4x/GHSA-vxhm-ccj3-8p4x.json index 3a18a8fcdb4..7a129d03678 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxhm-ccj3-8p4x/GHSA-vxhm-ccj3-8p4x.json +++ b/advisories/unreviewed/2022/05/GHSA-vxhm-ccj3-8p4x/GHSA-vxhm-ccj3-8p4x.json @@ -7,12 +7,8 @@ "CVE-2005-4664" ], "details": "SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxqr-xvg4-5x6g/GHSA-vxqr-xvg4-5x6g.json b/advisories/unreviewed/2022/05/GHSA-vxqr-xvg4-5x6g/GHSA-vxqr-xvg4-5x6g.json index 225ab3e4729..e62348546a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxqr-xvg4-5x6g/GHSA-vxqr-xvg4-5x6g.json +++ b/advisories/unreviewed/2022/05/GHSA-vxqr-xvg4-5x6g/GHSA-vxqr-xvg4-5x6g.json @@ -7,12 +7,8 @@ "CVE-2021-23030" ], "details": "On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is configured on a virtual server, undisclosed requests can cause bd to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w223-cx42-24c9/GHSA-w223-cx42-24c9.json b/advisories/unreviewed/2022/05/GHSA-w223-cx42-24c9/GHSA-w223-cx42-24c9.json index f1ac919bc31..692b00f126c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w223-cx42-24c9/GHSA-w223-cx42-24c9.json +++ b/advisories/unreviewed/2022/05/GHSA-w223-cx42-24c9/GHSA-w223-cx42-24c9.json @@ -7,12 +7,8 @@ "CVE-2021-29811" ], "details": "IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2gx-ph96-cxcc/GHSA-w2gx-ph96-cxcc.json b/advisories/unreviewed/2022/05/GHSA-w2gx-ph96-cxcc/GHSA-w2gx-ph96-cxcc.json index 33837bbed77..087e996f9de 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2gx-ph96-cxcc/GHSA-w2gx-ph96-cxcc.json +++ b/advisories/unreviewed/2022/05/GHSA-w2gx-ph96-cxcc/GHSA-w2gx-ph96-cxcc.json @@ -7,12 +7,8 @@ "CVE-2020-20670" ], "details": "An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w35j-g472-jv3v/GHSA-w35j-g472-jv3v.json b/advisories/unreviewed/2022/05/GHSA-w35j-g472-jv3v/GHSA-w35j-g472-jv3v.json index 26e8aea0c67..bcb69dd459a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w35j-g472-jv3v/GHSA-w35j-g472-jv3v.json +++ b/advisories/unreviewed/2022/05/GHSA-w35j-g472-jv3v/GHSA-w35j-g472-jv3v.json @@ -7,12 +7,8 @@ "CVE-2005-4788" ], "details": "resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass access control rules for USB devices via \"alternate syntax for specifying USB devices.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3v7-hj7c-4j8f/GHSA-w3v7-hj7c-4j8f.json b/advisories/unreviewed/2022/05/GHSA-w3v7-hj7c-4j8f/GHSA-w3v7-hj7c-4j8f.json index 20e7314523e..d3dbc7c6d84 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3v7-hj7c-4j8f/GHSA-w3v7-hj7c-4j8f.json +++ b/advisories/unreviewed/2022/05/GHSA-w3v7-hj7c-4j8f/GHSA-w3v7-hj7c-4j8f.json @@ -7,12 +7,8 @@ "CVE-2021-1625" ], "details": "A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP responder-to-initiator flows are not inspected when the Zone-Based Policy Firewall has either Unified Threat Defense (UTD) or Application Quality of Experience (AppQoE) configured. An attacker could exploit this vulnerability by attempting to send UDP or ICMP flows through the network. A successful exploit could allow the attacker to inject traffic through the Zone-Based Policy Firewall, resulting in traffic being dropped because it is incorrectly classified or in incorrect reporting figures being produced by high-speed logging (HSL).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w43r-pcrq-vv2g/GHSA-w43r-pcrq-vv2g.json b/advisories/unreviewed/2022/05/GHSA-w43r-pcrq-vv2g/GHSA-w43r-pcrq-vv2g.json index dd4566d0292..5f0461fc3d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w43r-pcrq-vv2g/GHSA-w43r-pcrq-vv2g.json +++ b/advisories/unreviewed/2022/05/GHSA-w43r-pcrq-vv2g/GHSA-w43r-pcrq-vv2g.json @@ -7,12 +7,8 @@ "CVE-2005-4552" ], "details": "The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json b/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json index 9cff0bd99f9..60077cde553 100644 --- a/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json +++ b/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json @@ -7,12 +7,8 @@ "CVE-2021-22017" ], "details": "Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w53g-xqvq-mxh2/GHSA-w53g-xqvq-mxh2.json b/advisories/unreviewed/2022/05/GHSA-w53g-xqvq-mxh2/GHSA-w53g-xqvq-mxh2.json index 3f9d236b7b7..624f18197f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w53g-xqvq-mxh2/GHSA-w53g-xqvq-mxh2.json +++ b/advisories/unreviewed/2022/05/GHSA-w53g-xqvq-mxh2/GHSA-w53g-xqvq-mxh2.json @@ -7,12 +7,8 @@ "CVE-2020-20901" ], "details": "Buffer Overflow vulnerability in function filter_frame in libavfilter/vf_fieldorder.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w56q-wh4x-c2m7/GHSA-w56q-wh4x-c2m7.json b/advisories/unreviewed/2022/05/GHSA-w56q-wh4x-c2m7/GHSA-w56q-wh4x-c2m7.json index b8aca39b891..179fafb4e4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w56q-wh4x-c2m7/GHSA-w56q-wh4x-c2m7.json +++ b/advisories/unreviewed/2022/05/GHSA-w56q-wh4x-c2m7/GHSA-w56q-wh4x-c2m7.json @@ -7,12 +7,8 @@ "CVE-2021-29643" ], "details": "PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5fh-xc33-v3f8/GHSA-w5fh-xc33-v3f8.json b/advisories/unreviewed/2022/05/GHSA-w5fh-xc33-v3f8/GHSA-w5fh-xc33-v3f8.json index 63c0acd6fde..91e0bc22ca9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5fh-xc33-v3f8/GHSA-w5fh-xc33-v3f8.json +++ b/advisories/unreviewed/2022/05/GHSA-w5fh-xc33-v3f8/GHSA-w5fh-xc33-v3f8.json @@ -7,12 +7,8 @@ "CVE-2005-4743" ], "details": "Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5hm-7wh2-cc9c/GHSA-w5hm-7wh2-cc9c.json b/advisories/unreviewed/2022/05/GHSA-w5hm-7wh2-cc9c/GHSA-w5hm-7wh2-cc9c.json index bf91c1b607f..574ff066ff0 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5hm-7wh2-cc9c/GHSA-w5hm-7wh2-cc9c.json +++ b/advisories/unreviewed/2022/05/GHSA-w5hm-7wh2-cc9c/GHSA-w5hm-7wh2-cc9c.json @@ -7,12 +7,8 @@ "CVE-2021-32298" ], "details": "An issue was discovered in libiff through 20190123. A global-buffer-overflow exists in the function IFF_errorId located in error.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7g6-jv49-6cp7/GHSA-w7g6-jv49-6cp7.json b/advisories/unreviewed/2022/05/GHSA-w7g6-jv49-6cp7/GHSA-w7g6-jv49-6cp7.json index 911d2590250..a3376b91d23 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7g6-jv49-6cp7/GHSA-w7g6-jv49-6cp7.json +++ b/advisories/unreviewed/2022/05/GHSA-w7g6-jv49-6cp7/GHSA-w7g6-jv49-6cp7.json @@ -7,12 +7,8 @@ "CVE-2021-30261" ], "details": "Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7mg-q4hh-m9cq/GHSA-w7mg-q4hh-m9cq.json b/advisories/unreviewed/2022/05/GHSA-w7mg-q4hh-m9cq/GHSA-w7mg-q4hh-m9cq.json index 32c75dc0aea..bbea22faf1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7mg-q4hh-m9cq/GHSA-w7mg-q4hh-m9cq.json +++ b/advisories/unreviewed/2022/05/GHSA-w7mg-q4hh-m9cq/GHSA-w7mg-q4hh-m9cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w84r-7vwm-vm7g/GHSA-w84r-7vwm-vm7g.json b/advisories/unreviewed/2022/05/GHSA-w84r-7vwm-vm7g/GHSA-w84r-7vwm-vm7g.json index ff1426f0215..3ec44d12444 100644 --- a/advisories/unreviewed/2022/05/GHSA-w84r-7vwm-vm7g/GHSA-w84r-7vwm-vm7g.json +++ b/advisories/unreviewed/2022/05/GHSA-w84r-7vwm-vm7g/GHSA-w84r-7vwm-vm7g.json @@ -7,12 +7,8 @@ "CVE-2005-4602" ], "details": "SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8h2-jg46-g9xc/GHSA-w8h2-jg46-g9xc.json b/advisories/unreviewed/2022/05/GHSA-w8h2-jg46-g9xc/GHSA-w8h2-jg46-g9xc.json index 4ee6a65aa0a..e9cf8f35084 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8h2-jg46-g9xc/GHSA-w8h2-jg46-g9xc.json +++ b/advisories/unreviewed/2022/05/GHSA-w8h2-jg46-g9xc/GHSA-w8h2-jg46-g9xc.json @@ -7,12 +7,8 @@ "CVE-2021-34346" ], "details": "A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w94w-cg39-6r6h/GHSA-w94w-cg39-6r6h.json b/advisories/unreviewed/2022/05/GHSA-w94w-cg39-6r6h/GHSA-w94w-cg39-6r6h.json index dd75b6d0a7d..6bf8431d3d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w94w-cg39-6r6h/GHSA-w94w-cg39-6r6h.json +++ b/advisories/unreviewed/2022/05/GHSA-w94w-cg39-6r6h/GHSA-w94w-cg39-6r6h.json @@ -7,12 +7,8 @@ "CVE-2005-4560" ], "details": "The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9hr-wfmh-pm4j/GHSA-w9hr-wfmh-pm4j.json b/advisories/unreviewed/2022/05/GHSA-w9hr-wfmh-pm4j/GHSA-w9hr-wfmh-pm4j.json index 0b5a9e535f4..d826fdbfa3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9hr-wfmh-pm4j/GHSA-w9hr-wfmh-pm4j.json +++ b/advisories/unreviewed/2022/05/GHSA-w9hr-wfmh-pm4j/GHSA-w9hr-wfmh-pm4j.json @@ -7,12 +7,8 @@ "CVE-2005-4547" ], "details": "Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9p6-rcg9-9vph/GHSA-w9p6-rcg9-9vph.json b/advisories/unreviewed/2022/05/GHSA-w9p6-rcg9-9vph/GHSA-w9p6-rcg9-9vph.json index 4eaa30b4734..db42e1213c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9p6-rcg9-9vph/GHSA-w9p6-rcg9-9vph.json +++ b/advisories/unreviewed/2022/05/GHSA-w9p6-rcg9-9vph/GHSA-w9p6-rcg9-9vph.json @@ -7,12 +7,8 @@ "CVE-2021-39577" ], "details": "An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function main() located in swfdump.c. It allows an attacker to cause code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9xf-mr89-vp4r/GHSA-w9xf-mr89-vp4r.json b/advisories/unreviewed/2022/05/GHSA-w9xf-mr89-vp4r/GHSA-w9xf-mr89-vp4r.json index 1197ba6da26..8d89ccf7cea 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9xf-mr89-vp4r/GHSA-w9xf-mr89-vp4r.json +++ b/advisories/unreviewed/2022/05/GHSA-w9xf-mr89-vp4r/GHSA-w9xf-mr89-vp4r.json @@ -7,12 +7,8 @@ "CVE-2020-4805" ], "details": "IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189539.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj9q-3vrf-hwq5/GHSA-wj9q-3vrf-hwq5.json b/advisories/unreviewed/2022/05/GHSA-wj9q-3vrf-hwq5/GHSA-wj9q-3vrf-hwq5.json index 53115bcf3bf..832e48584aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj9q-3vrf-hwq5/GHSA-wj9q-3vrf-hwq5.json +++ b/advisories/unreviewed/2022/05/GHSA-wj9q-3vrf-hwq5/GHSA-wj9q-3vrf-hwq5.json @@ -7,12 +7,8 @@ "CVE-2021-38357" ], "details": "The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/sms-ovh-sent.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjg5-m2mm-fgxq/GHSA-wjg5-m2mm-fgxq.json b/advisories/unreviewed/2022/05/GHSA-wjg5-m2mm-fgxq/GHSA-wjg5-m2mm-fgxq.json index 61ebe9068c2..73bcb53e1a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjg5-m2mm-fgxq/GHSA-wjg5-m2mm-fgxq.json +++ b/advisories/unreviewed/2022/05/GHSA-wjg5-m2mm-fgxq/GHSA-wjg5-m2mm-fgxq.json @@ -7,12 +7,8 @@ "CVE-2006-0008" ], "details": "The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the \"shell about dialog box\" and clicking the \"End-User License Agreement\" link, which executes Notepad with the privileges of the program that displays the about box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjmj-5m9r-gc4v/GHSA-wjmj-5m9r-gc4v.json b/advisories/unreviewed/2022/05/GHSA-wjmj-5m9r-gc4v/GHSA-wjmj-5m9r-gc4v.json index 4239e7dc03d..b9a9d4d4c2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjmj-5m9r-gc4v/GHSA-wjmj-5m9r-gc4v.json +++ b/advisories/unreviewed/2022/05/GHSA-wjmj-5m9r-gc4v/GHSA-wjmj-5m9r-gc4v.json @@ -7,12 +7,8 @@ "CVE-2005-4637" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) nav parameter in the downloads module, (2) Full Name and (3) Email fields in the core module, (4) Full Name, (5) Email, and (6) Subject fields in the tickets module, or (7) Registered Email field in the lostpassword feature in the core module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjxv-ccw6-j9xh/GHSA-wjxv-ccw6-j9xh.json b/advisories/unreviewed/2022/05/GHSA-wjxv-ccw6-j9xh/GHSA-wjxv-ccw6-j9xh.json index e985aff5ce7..4ba0ff78239 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjxv-ccw6-j9xh/GHSA-wjxv-ccw6-j9xh.json +++ b/advisories/unreviewed/2022/05/GHSA-wjxv-ccw6-j9xh/GHSA-wjxv-ccw6-j9xh.json @@ -7,12 +7,8 @@ "CVE-2021-24493" ], "details": "The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary files and leading to RCE", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmgh-vqmx-5rqc/GHSA-wmgh-vqmx-5rqc.json b/advisories/unreviewed/2022/05/GHSA-wmgh-vqmx-5rqc/GHSA-wmgh-vqmx-5rqc.json index 5ae925b4c85..29d6a2f816f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmgh-vqmx-5rqc/GHSA-wmgh-vqmx-5rqc.json +++ b/advisories/unreviewed/2022/05/GHSA-wmgh-vqmx-5rqc/GHSA-wmgh-vqmx-5rqc.json @@ -7,12 +7,8 @@ "CVE-2005-4714" ], "details": "Format string vulnerability in the vmps_log function in OpenVMPS (VLAN Management Policy Server) 1.3 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wp92-gm3h-j7wf/GHSA-wp92-gm3h-j7wf.json b/advisories/unreviewed/2022/05/GHSA-wp92-gm3h-j7wf/GHSA-wp92-gm3h-j7wf.json index db9fccaf515..2cedcadac73 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp92-gm3h-j7wf/GHSA-wp92-gm3h-j7wf.json +++ b/advisories/unreviewed/2022/05/GHSA-wp92-gm3h-j7wf/GHSA-wp92-gm3h-j7wf.json @@ -7,12 +7,8 @@ "CVE-2005-4419" ], "details": "Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpcw-xfjj-3ghr/GHSA-wpcw-xfjj-3ghr.json b/advisories/unreviewed/2022/05/GHSA-wpcw-xfjj-3ghr/GHSA-wpcw-xfjj-3ghr.json index f05354c770a..b21149d5432 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpcw-xfjj-3ghr/GHSA-wpcw-xfjj-3ghr.json +++ b/advisories/unreviewed/2022/05/GHSA-wpcw-xfjj-3ghr/GHSA-wpcw-xfjj-3ghr.json @@ -7,12 +7,8 @@ "CVE-2021-33693" ], "details": "SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpfw-qhxf-9cj3/GHSA-wpfw-qhxf-9cj3.json b/advisories/unreviewed/2022/05/GHSA-wpfw-qhxf-9cj3/GHSA-wpfw-qhxf-9cj3.json index e031b525f88..d85129549d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpfw-qhxf-9cj3/GHSA-wpfw-qhxf-9cj3.json +++ b/advisories/unreviewed/2022/05/GHSA-wpfw-qhxf-9cj3/GHSA-wpfw-qhxf-9cj3.json @@ -7,12 +7,8 @@ "CVE-2005-4865" ], "details": "Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqhf-5xw8-mmcg/GHSA-wqhf-5xw8-mmcg.json b/advisories/unreviewed/2022/05/GHSA-wqhf-5xw8-mmcg/GHSA-wqhf-5xw8-mmcg.json index ddd59bfae10..2e9e1639d60 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqhf-5xw8-mmcg/GHSA-wqhf-5xw8-mmcg.json +++ b/advisories/unreviewed/2022/05/GHSA-wqhf-5xw8-mmcg/GHSA-wqhf-5xw8-mmcg.json @@ -7,12 +7,8 @@ "CVE-2021-41395" ], "details": "Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrf6-c8xc-j546/GHSA-wrf6-c8xc-j546.json b/advisories/unreviewed/2022/05/GHSA-wrf6-c8xc-j546/GHSA-wrf6-c8xc-j546.json index f73bc1d69c5..027870026c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrf6-c8xc-j546/GHSA-wrf6-c8xc-j546.json +++ b/advisories/unreviewed/2022/05/GHSA-wrf6-c8xc-j546/GHSA-wrf6-c8xc-j546.json @@ -7,12 +7,8 @@ "CVE-2006-0050" ], "details": "snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrx8-cxgj-cgpv/GHSA-wrx8-cxgj-cgpv.json b/advisories/unreviewed/2022/05/GHSA-wrx8-cxgj-cgpv/GHSA-wrx8-cxgj-cgpv.json index c4eb7770811..b3c3cd8b9fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrx8-cxgj-cgpv/GHSA-wrx8-cxgj-cgpv.json +++ b/advisories/unreviewed/2022/05/GHSA-wrx8-cxgj-cgpv/GHSA-wrx8-cxgj-cgpv.json @@ -7,12 +7,8 @@ "CVE-2005-4619" ], "details": "SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvpq-xgwf-69c4/GHSA-wvpq-xgwf-69c4.json b/advisories/unreviewed/2022/05/GHSA-wvpq-xgwf-69c4/GHSA-wvpq-xgwf-69c4.json index f75952a1249..41cf998f9e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvpq-xgwf-69c4/GHSA-wvpq-xgwf-69c4.json +++ b/advisories/unreviewed/2022/05/GHSA-wvpq-xgwf-69c4/GHSA-wvpq-xgwf-69c4.json @@ -7,12 +7,8 @@ "CVE-2021-39522" ], "details": "An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxr2-mrr4-q9hf/GHSA-wxr2-mrr4-q9hf.json b/advisories/unreviewed/2022/05/GHSA-wxr2-mrr4-q9hf/GHSA-wxr2-mrr4-q9hf.json index d0a45cb4dd9..59b2056bb14 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxr2-mrr4-q9hf/GHSA-wxr2-mrr4-q9hf.json +++ b/advisories/unreviewed/2022/05/GHSA-wxr2-mrr4-q9hf/GHSA-wxr2-mrr4-q9hf.json @@ -7,12 +7,8 @@ "CVE-2005-4589" ], "details": "Spb Kiosk Engine 1.0.0.1 stores the administrator's passcode in the registry in plaintext, which allows local users to obtain the passcode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2cf-7hfw-w548/GHSA-x2cf-7hfw-w548.json b/advisories/unreviewed/2022/05/GHSA-x2cf-7hfw-w548/GHSA-x2cf-7hfw-w548.json index 2fe6c2b77ec..9d774f1d13e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2cf-7hfw-w548/GHSA-x2cf-7hfw-w548.json +++ b/advisories/unreviewed/2022/05/GHSA-x2cf-7hfw-w548/GHSA-x2cf-7hfw-w548.json @@ -7,12 +7,8 @@ "CVE-2005-4695" ], "details": "Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2gv-qh97-xh45/GHSA-x2gv-qh97-xh45.json b/advisories/unreviewed/2022/05/GHSA-x2gv-qh97-xh45/GHSA-x2gv-qh97-xh45.json index c3cec70bde9..08df7f0c72e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2gv-qh97-xh45/GHSA-x2gv-qh97-xh45.json +++ b/advisories/unreviewed/2022/05/GHSA-x2gv-qh97-xh45/GHSA-x2gv-qh97-xh45.json @@ -7,12 +7,8 @@ "CVE-2021-23027" ], "details": "On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2rx-8768-8678/GHSA-x2rx-8768-8678.json b/advisories/unreviewed/2022/05/GHSA-x2rx-8768-8678/GHSA-x2rx-8768-8678.json index 83dcf304eaa..c5fbc9b0f2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2rx-8768-8678/GHSA-x2rx-8768-8678.json +++ b/advisories/unreviewed/2022/05/GHSA-x2rx-8768-8678/GHSA-x2rx-8768-8678.json @@ -7,12 +7,8 @@ "CVE-2005-4826" ], "details": "Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CVE-2006-4774, CVE-2006-4775, and CVE-2006-4776.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3p7-g646-9j92/GHSA-x3p7-g646-9j92.json b/advisories/unreviewed/2022/05/GHSA-x3p7-g646-9j92/GHSA-x3p7-g646-9j92.json index 78a0f8ebe81..6790a8ebf42 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3p7-g646-9j92/GHSA-x3p7-g646-9j92.json +++ b/advisories/unreviewed/2022/05/GHSA-x3p7-g646-9j92/GHSA-x3p7-g646-9j92.json @@ -7,12 +7,8 @@ "CVE-2005-4470" ], "details": "Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3xc-8qqv-4cq8/GHSA-x3xc-8qqv-4cq8.json b/advisories/unreviewed/2022/05/GHSA-x3xc-8qqv-4cq8/GHSA-x3xc-8qqv-4cq8.json index fc81dc66b93..5a1243954ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3xc-8qqv-4cq8/GHSA-x3xc-8qqv-4cq8.json +++ b/advisories/unreviewed/2022/05/GHSA-x3xc-8qqv-4cq8/GHSA-x3xc-8qqv-4cq8.json @@ -7,12 +7,8 @@ "CVE-2005-4445" ], "details": "Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows remote attackers to execute arbitrary code via a long email message header, which triggers a one-byte buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x46p-9wf3-mvmp/GHSA-x46p-9wf3-mvmp.json b/advisories/unreviewed/2022/05/GHSA-x46p-9wf3-mvmp/GHSA-x46p-9wf3-mvmp.json index 6a45d964918..a31c2f41562 100644 --- a/advisories/unreviewed/2022/05/GHSA-x46p-9wf3-mvmp/GHSA-x46p-9wf3-mvmp.json +++ b/advisories/unreviewed/2022/05/GHSA-x46p-9wf3-mvmp/GHSA-x46p-9wf3-mvmp.json @@ -7,12 +7,8 @@ "CVE-2005-4569" ], "details": "Stack-based buffer overflow in index.fts in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allows remote attackers to execute arbitrary code via a long tzoffset value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4g6-37v9-377w/GHSA-x4g6-37v9-377w.json b/advisories/unreviewed/2022/05/GHSA-x4g6-37v9-377w/GHSA-x4g6-37v9-377w.json index 60430c8cab0..e8b193993b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4g6-37v9-377w/GHSA-x4g6-37v9-377w.json +++ b/advisories/unreviewed/2022/05/GHSA-x4g6-37v9-377w/GHSA-x4g6-37v9-377w.json @@ -7,12 +7,8 @@ "CVE-2021-23039" ], "details": "On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a negotiated Security Association, can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x53f-v73q-grpf/GHSA-x53f-v73q-grpf.json b/advisories/unreviewed/2022/05/GHSA-x53f-v73q-grpf/GHSA-x53f-v73q-grpf.json index b8a7d5d453e..fa78af5a125 100644 --- a/advisories/unreviewed/2022/05/GHSA-x53f-v73q-grpf/GHSA-x53f-v73q-grpf.json +++ b/advisories/unreviewed/2022/05/GHSA-x53f-v73q-grpf/GHSA-x53f-v73q-grpf.json @@ -7,12 +7,8 @@ "CVE-2021-24613" ], "details": "The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x59g-h3vc-hf9j/GHSA-x59g-h3vc-hf9j.json b/advisories/unreviewed/2022/05/GHSA-x59g-h3vc-hf9j/GHSA-x59g-h3vc-hf9j.json index 73ffe1b324e..993e93d218f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x59g-h3vc-hf9j/GHSA-x59g-h3vc-hf9j.json +++ b/advisories/unreviewed/2022/05/GHSA-x59g-h3vc-hf9j/GHSA-x59g-h3vc-hf9j.json @@ -7,12 +7,8 @@ "CVE-2005-4871" ], "details": "Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5cv-hcpc-5cg5/GHSA-x5cv-hcpc-5cg5.json b/advisories/unreviewed/2022/05/GHSA-x5cv-hcpc-5cg5/GHSA-x5cv-hcpc-5cg5.json index 7a5637b4a68..b9938ca9fb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5cv-hcpc-5cg5/GHSA-x5cv-hcpc-5cg5.json +++ b/advisories/unreviewed/2022/05/GHSA-x5cv-hcpc-5cg5/GHSA-x5cv-hcpc-5cg5.json @@ -7,12 +7,8 @@ "CVE-2021-38335" ], "details": "The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x674-v2h5-xvcx/GHSA-x674-v2h5-xvcx.json b/advisories/unreviewed/2022/05/GHSA-x674-v2h5-xvcx/GHSA-x674-v2h5-xvcx.json index 534454cdedd..10360cac411 100644 --- a/advisories/unreviewed/2022/05/GHSA-x674-v2h5-xvcx/GHSA-x674-v2h5-xvcx.json +++ b/advisories/unreviewed/2022/05/GHSA-x674-v2h5-xvcx/GHSA-x674-v2h5-xvcx.json @@ -7,12 +7,8 @@ "CVE-2005-4418" ], "details": "util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6jw-v4hx-374p/GHSA-x6jw-v4hx-374p.json b/advisories/unreviewed/2022/05/GHSA-x6jw-v4hx-374p/GHSA-x6jw-v4hx-374p.json index 35af6774423..8bbce5e1dd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6jw-v4hx-374p/GHSA-x6jw-v4hx-374p.json +++ b/advisories/unreviewed/2022/05/GHSA-x6jw-v4hx-374p/GHSA-x6jw-v4hx-374p.json @@ -7,12 +7,8 @@ "CVE-2005-4677" ], "details": "SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6v6-9qqg-hhvf/GHSA-x6v6-9qqg-hhvf.json b/advisories/unreviewed/2022/05/GHSA-x6v6-9qqg-hhvf/GHSA-x6v6-9qqg-hhvf.json index 79ef242ca45..c10136ebbae 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6v6-9qqg-hhvf/GHSA-x6v6-9qqg-hhvf.json +++ b/advisories/unreviewed/2022/05/GHSA-x6v6-9qqg-hhvf/GHSA-x6v6-9qqg-hhvf.json @@ -7,12 +7,8 @@ "CVE-2005-4631" ], "details": "SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x75m-rrhq-6j68/GHSA-x75m-rrhq-6j68.json b/advisories/unreviewed/2022/05/GHSA-x75m-rrhq-6j68/GHSA-x75m-rrhq-6j68.json index 3cbabe5b5bd..a1d3938205e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x75m-rrhq-6j68/GHSA-x75m-rrhq-6j68.json +++ b/advisories/unreviewed/2022/05/GHSA-x75m-rrhq-6j68/GHSA-x75m-rrhq-6j68.json @@ -7,12 +7,8 @@ "CVE-2021-40845" ], "details": "The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x769-h2xc-fqfm/GHSA-x769-h2xc-fqfm.json b/advisories/unreviewed/2022/05/GHSA-x769-h2xc-fqfm/GHSA-x769-h2xc-fqfm.json index a70d7acc1d4..4fd4ace834e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x769-h2xc-fqfm/GHSA-x769-h2xc-fqfm.json +++ b/advisories/unreviewed/2022/05/GHSA-x769-h2xc-fqfm/GHSA-x769-h2xc-fqfm.json @@ -7,12 +7,8 @@ "CVE-2021-24402" ], "details": "The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x76c-rg5r-5gmh/GHSA-x76c-rg5r-5gmh.json b/advisories/unreviewed/2022/05/GHSA-x76c-rg5r-5gmh/GHSA-x76c-rg5r-5gmh.json index fdd9e9c24be..04f723b4750 100644 --- a/advisories/unreviewed/2022/05/GHSA-x76c-rg5r-5gmh/GHSA-x76c-rg5r-5gmh.json +++ b/advisories/unreviewed/2022/05/GHSA-x76c-rg5r-5gmh/GHSA-x76c-rg5r-5gmh.json @@ -7,12 +7,8 @@ "CVE-2005-4522" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the view_filters_page.php filters script in Mantis 1.0.0rc3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view_type and (2) target_field parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7q6-g5fx-vhrw/GHSA-x7q6-g5fx-vhrw.json b/advisories/unreviewed/2022/05/GHSA-x7q6-g5fx-vhrw/GHSA-x7q6-g5fx-vhrw.json index 109c6cf33df..27ba1041c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7q6-g5fx-vhrw/GHSA-x7q6-g5fx-vhrw.json +++ b/advisories/unreviewed/2022/05/GHSA-x7q6-g5fx-vhrw/GHSA-x7q6-g5fx-vhrw.json @@ -7,12 +7,8 @@ "CVE-2021-38091" ], "details": "Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x8c7-9c7c-54qw/GHSA-x8c7-9c7c-54qw.json b/advisories/unreviewed/2022/05/GHSA-x8c7-9c7c-54qw/GHSA-x8c7-9c7c-54qw.json index 6c288014c0e..c1410b92286 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8c7-9c7c-54qw/GHSA-x8c7-9c7c-54qw.json +++ b/advisories/unreviewed/2022/05/GHSA-x8c7-9c7c-54qw/GHSA-x8c7-9c7c-54qw.json @@ -7,12 +7,8 @@ "CVE-2021-24637" ], "details": "The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x8hm-6jcv-6xvm/GHSA-x8hm-6jcv-6xvm.json b/advisories/unreviewed/2022/05/GHSA-x8hm-6jcv-6xvm/GHSA-x8hm-6jcv-6xvm.json index 455b589fee5..0d110d41bf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8hm-6jcv-6xvm/GHSA-x8hm-6jcv-6xvm.json +++ b/advisories/unreviewed/2022/05/GHSA-x8hm-6jcv-6xvm/GHSA-x8hm-6jcv-6xvm.json @@ -7,12 +7,8 @@ "CVE-2021-38333" ], "details": "The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9h5-7586-77cw/GHSA-x9h5-7586-77cw.json b/advisories/unreviewed/2022/05/GHSA-x9h5-7586-77cw/GHSA-x9h5-7586-77cw.json index de8387fe5a8..63fae2cff60 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9h5-7586-77cw/GHSA-x9h5-7586-77cw.json +++ b/advisories/unreviewed/2022/05/GHSA-x9h5-7586-77cw/GHSA-x9h5-7586-77cw.json @@ -7,12 +7,8 @@ "CVE-2021-39552" ], "details": "An issue was discovered in sela through 20200412. file::WavFile::readFromFile() in wav_file.c has a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9pw-33c7-c62h/GHSA-x9pw-33c7-c62h.json b/advisories/unreviewed/2022/05/GHSA-x9pw-33c7-c62h/GHSA-x9pw-33c7-c62h.json index 4bc6e5a4207..679c7720181 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9pw-33c7-c62h/GHSA-x9pw-33c7-c62h.json +++ b/advisories/unreviewed/2022/05/GHSA-x9pw-33c7-c62h/GHSA-x9pw-33c7-c62h.json @@ -7,12 +7,8 @@ "CVE-2005-4590" ], "details": "Spb Kiosk Engine 1.0.0.1 allows local users to bypass restrictions on allowed applications via (1) removable media containing a program that will execute because of the autorun setting and (2) applications that are able to invoke other applications, as demonstrated by a file: URL specifying a .exe file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc3q-g386-79q2/GHSA-xc3q-g386-79q2.json b/advisories/unreviewed/2022/05/GHSA-xc3q-g386-79q2/GHSA-xc3q-g386-79q2.json index 68bad407dff..aa0081685fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc3q-g386-79q2/GHSA-xc3q-g386-79q2.json +++ b/advisories/unreviewed/2022/05/GHSA-xc3q-g386-79q2/GHSA-xc3q-g386-79q2.json @@ -7,12 +7,8 @@ "CVE-2005-4777" ], "details": "Tashcom ASPEdit 2.9 stores the administration password (aka the FTP password) in cleartext in the registry, which might allow local users to view the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc6m-h9mw-r768/GHSA-xc6m-h9mw-r768.json b/advisories/unreviewed/2022/05/GHSA-xc6m-h9mw-r768/GHSA-xc6m-h9mw-r768.json index 2d28ac6d3eb..dfc871cef73 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc6m-h9mw-r768/GHSA-xc6m-h9mw-r768.json +++ b/advisories/unreviewed/2022/05/GHSA-xc6m-h9mw-r768/GHSA-xc6m-h9mw-r768.json @@ -7,12 +7,8 @@ "CVE-2005-4774" ], "details": "Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequence at the end of the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc74-475v-6rmv/GHSA-xc74-475v-6rmv.json b/advisories/unreviewed/2022/05/GHSA-xc74-475v-6rmv/GHSA-xc74-475v-6rmv.json index 59a3e05afc7..735af9f7fdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc74-475v-6rmv/GHSA-xc74-475v-6rmv.json +++ b/advisories/unreviewed/2022/05/GHSA-xc74-475v-6rmv/GHSA-xc74-475v-6rmv.json @@ -7,12 +7,8 @@ "CVE-2021-24401" ], "details": "The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcwx-pcf9-m967/GHSA-xcwx-pcf9-m967.json b/advisories/unreviewed/2022/05/GHSA-xcwx-pcf9-m967/GHSA-xcwx-pcf9-m967.json index b6e194c5fac..db882aa8d2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcwx-pcf9-m967/GHSA-xcwx-pcf9-m967.json +++ b/advisories/unreviewed/2022/05/GHSA-xcwx-pcf9-m967/GHSA-xcwx-pcf9-m967.json @@ -7,12 +7,8 @@ "CVE-2005-4765" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf53-rwx9-rc7p/GHSA-xf53-rwx9-rc7p.json b/advisories/unreviewed/2022/05/GHSA-xf53-rwx9-rc7p/GHSA-xf53-rwx9-rc7p.json index 69cff0f92eb..07f6b5ec596 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf53-rwx9-rc7p/GHSA-xf53-rwx9-rc7p.json +++ b/advisories/unreviewed/2022/05/GHSA-xf53-rwx9-rc7p/GHSA-xf53-rwx9-rc7p.json @@ -7,12 +7,8 @@ "CVE-2005-4771" ], "details": "Trusted Mobility Agent PC Policy in Trust Digital Trusted Mobility Suite provides a cancel button that bypasses the domain-authentication prompt, which allows local users to sync a handheld (PDA) device despite a policy setting that sync is unauthorized.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfc4-9c23-wc6x/GHSA-xfc4-9c23-wc6x.json b/advisories/unreviewed/2022/05/GHSA-xfc4-9c23-wc6x/GHSA-xfc4-9c23-wc6x.json index c73e12f83b9..e0baa9b565a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfc4-9c23-wc6x/GHSA-xfc4-9c23-wc6x.json +++ b/advisories/unreviewed/2022/05/GHSA-xfc4-9c23-wc6x/GHSA-xfc4-9c23-wc6x.json @@ -7,12 +7,8 @@ "CVE-2005-4572" ], "details": "Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfmp-2r38-cvc9/GHSA-xfmp-2r38-cvc9.json b/advisories/unreviewed/2022/05/GHSA-xfmp-2r38-cvc9/GHSA-xfmp-2r38-cvc9.json index 69dcce794e3..444b3dae6a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfmp-2r38-cvc9/GHSA-xfmp-2r38-cvc9.json +++ b/advisories/unreviewed/2022/05/GHSA-xfmp-2r38-cvc9/GHSA-xfmp-2r38-cvc9.json @@ -7,12 +7,8 @@ "CVE-2005-4784" ], "details": "Multiple buffer overflows in the POSIX readdir_r function, as used in multiple packages, allow local users to cause a denial of service and possibly execute arbitrary code via (1) a symlink attack that exploits a race condition between opendir and pathcon calls and changes the filesystem to one with a larger maximum directory-entry name length, or (2) possibly via programmer-introduced errors on operating systems with a small struct dirent, such as Solaris or BeOS, as demonstrated in packages including (a) gcj, (b) KDE, (c) libwww, (d) the Rudiments library, (e) teTeX, (f) xmail, (g) bfbtester, (h) ncftp, (i) netwib, (j) OpenOffice.org, (k) Pike, (l) reprepro, (m) Tcl, and (n) xgsmlib.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg34-xq74-8f84/GHSA-xg34-xq74-8f84.json b/advisories/unreviewed/2022/05/GHSA-xg34-xq74-8f84/GHSA-xg34-xq74-8f84.json index 132dca16b73..c30bf72aedc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg34-xq74-8f84/GHSA-xg34-xq74-8f84.json +++ b/advisories/unreviewed/2022/05/GHSA-xg34-xq74-8f84/GHSA-xg34-xq74-8f84.json @@ -7,12 +7,8 @@ "CVE-2021-24404" ], "details": "The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query ran twice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg3v-w3xq-cxvq/GHSA-xg3v-w3xq-cxvq.json b/advisories/unreviewed/2022/05/GHSA-xg3v-w3xq-cxvq/GHSA-xg3v-w3xq-cxvq.json index ce081032f7b..7edf6050285 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg3v-w3xq-cxvq/GHSA-xg3v-w3xq-cxvq.json +++ b/advisories/unreviewed/2022/05/GHSA-xg3v-w3xq-cxvq/GHSA-xg3v-w3xq-cxvq.json @@ -7,12 +7,8 @@ "CVE-2020-4809" ], "details": "IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189633.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg59-cx23-x6f3/GHSA-xg59-cx23-x6f3.json b/advisories/unreviewed/2022/05/GHSA-xg59-cx23-x6f3/GHSA-xg59-cx23-x6f3.json index 8957ae51b2e..294268e6cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg59-cx23-x6f3/GHSA-xg59-cx23-x6f3.json +++ b/advisories/unreviewed/2022/05/GHSA-xg59-cx23-x6f3/GHSA-xg59-cx23-x6f3.json @@ -7,12 +7,8 @@ "CVE-2021-28901" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows remote attackers to inject arbitrary web script or HTML via the (1) NOM_CLI , (2) ADRESSE , (3) ADRESSE2, (4) LOCALITE parameters to /eshop/products/json/aouCustomerAdresse; and the (5) nom_liste parameter to /eshop/products/json/addCustomerFavorite.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg82-h5j4-q6gx/GHSA-xg82-h5j4-q6gx.json b/advisories/unreviewed/2022/05/GHSA-xg82-h5j4-q6gx/GHSA-xg82-h5j4-q6gx.json index b43b03b9d07..7df90180f81 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg82-h5j4-q6gx/GHSA-xg82-h5j4-q6gx.json +++ b/advisories/unreviewed/2022/05/GHSA-xg82-h5j4-q6gx/GHSA-xg82-h5j4-q6gx.json @@ -7,12 +7,8 @@ "CVE-2005-4790" ], "details": "Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg8c-mw7j-wcv9/GHSA-xg8c-mw7j-wcv9.json b/advisories/unreviewed/2022/05/GHSA-xg8c-mw7j-wcv9/GHSA-xg8c-mw7j-wcv9.json index 8135e2ce925..33e70eda1c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg8c-mw7j-wcv9/GHSA-xg8c-mw7j-wcv9.json +++ b/advisories/unreviewed/2022/05/GHSA-xg8c-mw7j-wcv9/GHSA-xg8c-mw7j-wcv9.json @@ -7,12 +7,8 @@ "CVE-2021-23029" ], "details": "On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgh4-3f7c-mx5r/GHSA-xgh4-3f7c-mx5r.json b/advisories/unreviewed/2022/05/GHSA-xgh4-3f7c-mx5r/GHSA-xgh4-3f7c-mx5r.json index c4ca0c0affb..a66e998ec47 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgh4-3f7c-mx5r/GHSA-xgh4-3f7c-mx5r.json +++ b/advisories/unreviewed/2022/05/GHSA-xgh4-3f7c-mx5r/GHSA-xgh4-3f7c-mx5r.json @@ -7,12 +7,8 @@ "CVE-2005-4877" ], "details": "Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrary web script or HTML via Javascript events in the username parameter, a different vulnerability than CVE-2005-4876.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgpq-2x7g-ffgx/GHSA-xgpq-2x7g-ffgx.json b/advisories/unreviewed/2022/05/GHSA-xgpq-2x7g-ffgx/GHSA-xgpq-2x7g-ffgx.json index 1db9cb963b8..79e91b2bc49 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgpq-2x7g-ffgx/GHSA-xgpq-2x7g-ffgx.json +++ b/advisories/unreviewed/2022/05/GHSA-xgpq-2x7g-ffgx/GHSA-xgpq-2x7g-ffgx.json @@ -7,12 +7,8 @@ "CVE-2005-4408" ], "details": "Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xj59-9qjv-fr54/GHSA-xj59-9qjv-fr54.json b/advisories/unreviewed/2022/05/GHSA-xj59-9qjv-fr54/GHSA-xj59-9qjv-fr54.json index 87c64921030..333b7f954c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj59-9qjv-fr54/GHSA-xj59-9qjv-fr54.json +++ b/advisories/unreviewed/2022/05/GHSA-xj59-9qjv-fr54/GHSA-xj59-9qjv-fr54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj7g-89cx-mvvj/GHSA-xj7g-89cx-mvvj.json b/advisories/unreviewed/2022/05/GHSA-xj7g-89cx-mvvj/GHSA-xj7g-89cx-mvvj.json index 0d737b6c3b5..176f62dde13 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj7g-89cx-mvvj/GHSA-xj7g-89cx-mvvj.json +++ b/advisories/unreviewed/2022/05/GHSA-xj7g-89cx-mvvj/GHSA-xj7g-89cx-mvvj.json @@ -7,12 +7,8 @@ "CVE-2005-4497" ], "details": "Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xj84-6q8f-qg2r/GHSA-xj84-6q8f-qg2r.json b/advisories/unreviewed/2022/05/GHSA-xj84-6q8f-qg2r/GHSA-xj84-6q8f-qg2r.json index b4e736b433a..3b2bd1f3dce 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj84-6q8f-qg2r/GHSA-xj84-6q8f-qg2r.json +++ b/advisories/unreviewed/2022/05/GHSA-xj84-6q8f-qg2r/GHSA-xj84-6q8f-qg2r.json @@ -7,12 +7,8 @@ "CVE-2005-4875" ], "details": "TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjc5-mpgm-fw42/GHSA-xjc5-mpgm-fw42.json b/advisories/unreviewed/2022/05/GHSA-xjc5-mpgm-fw42/GHSA-xjc5-mpgm-fw42.json index 1f8983b4095..2e326dea05a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjc5-mpgm-fw42/GHSA-xjc5-mpgm-fw42.json +++ b/advisories/unreviewed/2022/05/GHSA-xjc5-mpgm-fw42/GHSA-xjc5-mpgm-fw42.json @@ -7,12 +7,8 @@ "CVE-2005-4462" ], "details": "PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjfw-c7mm-g73f/GHSA-xjfw-c7mm-g73f.json b/advisories/unreviewed/2022/05/GHSA-xjfw-c7mm-g73f/GHSA-xjfw-c7mm-g73f.json index 2d75aa7fd67..623c17b2e1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjfw-c7mm-g73f/GHSA-xjfw-c7mm-g73f.json +++ b/advisories/unreviewed/2022/05/GHSA-xjfw-c7mm-g73f/GHSA-xjfw-c7mm-g73f.json @@ -7,12 +7,8 @@ "CVE-2021-38094" ], "details": "Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjhh-xcpq-fjx4/GHSA-xjhh-xcpq-fjx4.json b/advisories/unreviewed/2022/05/GHSA-xjhh-xcpq-fjx4/GHSA-xjhh-xcpq-fjx4.json index c99b0556930..344e87061d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjhh-xcpq-fjx4/GHSA-xjhh-xcpq-fjx4.json +++ b/advisories/unreviewed/2022/05/GHSA-xjhh-xcpq-fjx4/GHSA-xjhh-xcpq-fjx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjjw-7hwm-mx4p/GHSA-xjjw-7hwm-mx4p.json b/advisories/unreviewed/2022/05/GHSA-xjjw-7hwm-mx4p/GHSA-xjjw-7hwm-mx4p.json index 82b91d24efd..95ea36fe6eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjjw-7hwm-mx4p/GHSA-xjjw-7hwm-mx4p.json +++ b/advisories/unreviewed/2022/05/GHSA-xjjw-7hwm-mx4p/GHSA-xjjw-7hwm-mx4p.json @@ -7,12 +7,8 @@ "CVE-2021-20829" ], "details": "Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjq6-gc34-j23x/GHSA-xjq6-gc34-j23x.json b/advisories/unreviewed/2022/05/GHSA-xjq6-gc34-j23x/GHSA-xjq6-gc34-j23x.json index 7c17831c9de..b1d1aba9055 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjq6-gc34-j23x/GHSA-xjq6-gc34-j23x.json +++ b/advisories/unreviewed/2022/05/GHSA-xjq6-gc34-j23x/GHSA-xjq6-gc34-j23x.json @@ -7,12 +7,8 @@ "CVE-2005-4433" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in Esselbach Storyteller CMS 1.8 allows remote attackers to inject arbitrary web script or HTML via the query parameter, which is used by the Search field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm59-x79v-w7q2/GHSA-xm59-x79v-w7q2.json b/advisories/unreviewed/2022/05/GHSA-xm59-x79v-w7q2/GHSA-xm59-x79v-w7q2.json index d7e04cc1d6c..53d1282e582 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm59-x79v-w7q2/GHSA-xm59-x79v-w7q2.json +++ b/advisories/unreviewed/2022/05/GHSA-xm59-x79v-w7q2/GHSA-xm59-x79v-w7q2.json @@ -7,12 +7,8 @@ "CVE-2021-24585" ], "details": "The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over the user_id", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmgm-2h3h-mxf9/GHSA-xmgm-2h3h-mxf9.json b/advisories/unreviewed/2022/05/GHSA-xmgm-2h3h-mxf9/GHSA-xmgm-2h3h-mxf9.json index f901ec3f564..3e16a0380e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmgm-2h3h-mxf9/GHSA-xmgm-2h3h-mxf9.json +++ b/advisories/unreviewed/2022/05/GHSA-xmgm-2h3h-mxf9/GHSA-xmgm-2h3h-mxf9.json @@ -7,12 +7,8 @@ "CVE-2005-4810" ], "details": "Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a \"text/html\" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpfg-jhxj-qw6x/GHSA-xpfg-jhxj-qw6x.json b/advisories/unreviewed/2022/05/GHSA-xpfg-jhxj-qw6x/GHSA-xpfg-jhxj-qw6x.json index e2e22be4ffa..bcc7ab2a53d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpfg-jhxj-qw6x/GHSA-xpfg-jhxj-qw6x.json +++ b/advisories/unreviewed/2022/05/GHSA-xpfg-jhxj-qw6x/GHSA-xpfg-jhxj-qw6x.json @@ -7,12 +7,8 @@ "CVE-2005-4731" ], "details": "The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xq69-cxjh-f23r/GHSA-xq69-cxjh-f23r.json b/advisories/unreviewed/2022/05/GHSA-xq69-cxjh-f23r/GHSA-xq69-cxjh-f23r.json index 8f33193df1c..c17fd18b696 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq69-cxjh-f23r/GHSA-xq69-cxjh-f23r.json +++ b/advisories/unreviewed/2022/05/GHSA-xq69-cxjh-f23r/GHSA-xq69-cxjh-f23r.json @@ -7,12 +7,8 @@ "CVE-2021-22528" ], "details": "Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq7h-5h92-cwp8/GHSA-xq7h-5h92-cwp8.json b/advisories/unreviewed/2022/05/GHSA-xq7h-5h92-cwp8/GHSA-xq7h-5h92-cwp8.json index 6b96897841b..54f36385487 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq7h-5h92-cwp8/GHSA-xq7h-5h92-cwp8.json +++ b/advisories/unreviewed/2022/05/GHSA-xq7h-5h92-cwp8/GHSA-xq7h-5h92-cwp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq9f-582r-p2j7/GHSA-xq9f-582r-p2j7.json b/advisories/unreviewed/2022/05/GHSA-xq9f-582r-p2j7/GHSA-xq9f-582r-p2j7.json index d8b62102dc8..2db639a6317 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq9f-582r-p2j7/GHSA-xq9f-582r-p2j7.json +++ b/advisories/unreviewed/2022/05/GHSA-xq9f-582r-p2j7/GHSA-xq9f-582r-p2j7.json @@ -7,12 +7,8 @@ "CVE-2005-4671" ], "details": "Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xqm9-4fqc-qh7w/GHSA-xqm9-4fqc-qh7w.json b/advisories/unreviewed/2022/05/GHSA-xqm9-4fqc-qh7w/GHSA-xqm9-4fqc-qh7w.json index 9f45ec7835b..b519b472f45 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqm9-4fqc-qh7w/GHSA-xqm9-4fqc-qh7w.json +++ b/advisories/unreviewed/2022/05/GHSA-xqm9-4fqc-qh7w/GHSA-xqm9-4fqc-qh7w.json @@ -7,12 +7,8 @@ "CVE-2021-23038" ], "details": "On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqxh-7x7w-p8r9/GHSA-xqxh-7x7w-p8r9.json b/advisories/unreviewed/2022/05/GHSA-xqxh-7x7w-p8r9/GHSA-xqxh-7x7w-p8r9.json index f7da472d8cb..a61ec674e30 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqxh-7x7w-p8r9/GHSA-xqxh-7x7w-p8r9.json +++ b/advisories/unreviewed/2022/05/GHSA-xqxh-7x7w-p8r9/GHSA-xqxh-7x7w-p8r9.json @@ -7,12 +7,8 @@ "CVE-2021-40155" ], "details": "A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr3p-gm2p-7rx5/GHSA-xr3p-gm2p-7rx5.json b/advisories/unreviewed/2022/05/GHSA-xr3p-gm2p-7rx5/GHSA-xr3p-gm2p-7rx5.json index b968ee01a10..bfb575b19bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr3p-gm2p-7rx5/GHSA-xr3p-gm2p-7rx5.json +++ b/advisories/unreviewed/2022/05/GHSA-xr3p-gm2p-7rx5/GHSA-xr3p-gm2p-7rx5.json @@ -7,12 +7,8 @@ "CVE-2021-24741" ], "details": "The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv56-7cfh-4v8j/GHSA-xv56-7cfh-4v8j.json b/advisories/unreviewed/2022/05/GHSA-xv56-7cfh-4v8j/GHSA-xv56-7cfh-4v8j.json index 78c2192f0d9..ee7433ebea9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv56-7cfh-4v8j/GHSA-xv56-7cfh-4v8j.json +++ b/advisories/unreviewed/2022/05/GHSA-xv56-7cfh-4v8j/GHSA-xv56-7cfh-4v8j.json @@ -7,12 +7,8 @@ "CVE-2005-4458" ], "details": "Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xv9c-g2v7-9668/GHSA-xv9c-g2v7-9668.json b/advisories/unreviewed/2022/05/GHSA-xv9c-g2v7-9668/GHSA-xv9c-g2v7-9668.json index 78af8e11f2c..0bd153e37ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv9c-g2v7-9668/GHSA-xv9c-g2v7-9668.json +++ b/advisories/unreviewed/2022/05/GHSA-xv9c-g2v7-9668/GHSA-xv9c-g2v7-9668.json @@ -7,12 +7,8 @@ "CVE-2005-4627" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvx9-w67v-7f8g/GHSA-xvx9-w67v-7f8g.json b/advisories/unreviewed/2022/05/GHSA-xvx9-w67v-7f8g/GHSA-xvx9-w67v-7f8g.json index 8325330404c..6e3bf2d7d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvx9-w67v-7f8g/GHSA-xvx9-w67v-7f8g.json +++ b/advisories/unreviewed/2022/05/GHSA-xvx9-w67v-7f8g/GHSA-xvx9-w67v-7f8g.json @@ -7,12 +7,8 @@ "CVE-2005-4813" ], "details": "Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service (application hang) via certain network traffic, possibly involving multiple simultaneous TCP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwjq-2p97-r884/GHSA-xwjq-2p97-r884.json b/advisories/unreviewed/2022/05/GHSA-xwjq-2p97-r884/GHSA-xwjq-2p97-r884.json index 7e81be7a1a7..f4b4b0952aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwjq-2p97-r884/GHSA-xwjq-2p97-r884.json +++ b/advisories/unreviewed/2022/05/GHSA-xwjq-2p97-r884/GHSA-xwjq-2p97-r884.json @@ -7,12 +7,8 @@ "CVE-2005-4751" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwpw-2x24-24ff/GHSA-xwpw-2x24-24ff.json b/advisories/unreviewed/2022/05/GHSA-xwpw-2x24-24ff/GHSA-xwpw-2x24-24ff.json index 692bf8f21fb..9d02b5ac94d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwpw-2x24-24ff/GHSA-xwpw-2x24-24ff.json +++ b/advisories/unreviewed/2022/05/GHSA-xwpw-2x24-24ff/GHSA-xwpw-2x24-24ff.json @@ -7,12 +7,8 @@ "CVE-2005-4551" ], "details": "Cross-site scripting (XSS) vulnerability in sign.php in codegrrl SimpBook 1.0, when html_enable is on, allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwvm-8x4q-gmr9/GHSA-xwvm-8x4q-gmr9.json b/advisories/unreviewed/2022/05/GHSA-xwvm-8x4q-gmr9/GHSA-xwvm-8x4q-gmr9.json index 6878e2015a0..9c1b6ab5f80 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwvm-8x4q-gmr9/GHSA-xwvm-8x4q-gmr9.json +++ b/advisories/unreviewed/2022/05/GHSA-xwvm-8x4q-gmr9/GHSA-xwvm-8x4q-gmr9.json @@ -7,12 +7,8 @@ "CVE-2021-34767" ], "details": "A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN. The vulnerability is due to a logic error when processing specific link-local IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet that would flow inbound through the wired interface of an affected device. A successful exploit could allow the attacker to cause traffic drops in the affected VLAN, thus triggering the DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxj5-mhw2-jgp8/GHSA-xxj5-mhw2-jgp8.json b/advisories/unreviewed/2022/05/GHSA-xxj5-mhw2-jgp8/GHSA-xxj5-mhw2-jgp8.json index 1cbb544326e..4993fbde78d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxj5-mhw2-jgp8/GHSA-xxj5-mhw2-jgp8.json +++ b/advisories/unreviewed/2022/05/GHSA-xxj5-mhw2-jgp8/GHSA-xxj5-mhw2-jgp8.json @@ -7,12 +7,8 @@ "CVE-2021-34705" ], "details": "A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces. An attacker could exploit this vulnerability by sending a malformed dial string to an affected device via either the ISDN protocol or SIP. A successful exploit could allow the attacker to conduct toll fraud, resulting in unexpected financial impact to affected customers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxmf-w3h3-38rf/GHSA-xxmf-w3h3-38rf.json b/advisories/unreviewed/2022/05/GHSA-xxmf-w3h3-38rf/GHSA-xxmf-w3h3-38rf.json index 6aef2b9657f..e82bf25c19b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxmf-w3h3-38rf/GHSA-xxmf-w3h3-38rf.json +++ b/advisories/unreviewed/2022/05/GHSA-xxmf-w3h3-38rf/GHSA-xxmf-w3h3-38rf.json @@ -7,12 +7,8 @@ "CVE-2021-23026" ], "details": "BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-4m45-43xg-8rr7/GHSA-4m45-43xg-8rr7.json b/advisories/unreviewed/2022/07/GHSA-4m45-43xg-8rr7/GHSA-4m45-43xg-8rr7.json index 7509748adbe..a6a9f5dc9d7 100644 --- a/advisories/unreviewed/2022/07/GHSA-4m45-43xg-8rr7/GHSA-4m45-43xg-8rr7.json +++ b/advisories/unreviewed/2022/07/GHSA-4m45-43xg-8rr7/GHSA-4m45-43xg-8rr7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-ph82-g2mr-p678/GHSA-ph82-g2mr-p678.json b/advisories/unreviewed/2022/10/GHSA-ph82-g2mr-p678/GHSA-ph82-g2mr-p678.json index f12c2460e79..67cc4753b4f 100644 --- a/advisories/unreviewed/2022/10/GHSA-ph82-g2mr-p678/GHSA-ph82-g2mr-p678.json +++ b/advisories/unreviewed/2022/10/GHSA-ph82-g2mr-p678/GHSA-ph82-g2mr-p678.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-2p3f-3cj6-r8vv/GHSA-2p3f-3cj6-r8vv.json b/advisories/unreviewed/2023/01/GHSA-2p3f-3cj6-r8vv/GHSA-2p3f-3cj6-r8vv.json index dfa71492da0..075a9e5a924 100644 --- a/advisories/unreviewed/2023/01/GHSA-2p3f-3cj6-r8vv/GHSA-2p3f-3cj6-r8vv.json +++ b/advisories/unreviewed/2023/01/GHSA-2p3f-3cj6-r8vv/GHSA-2p3f-3cj6-r8vv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-3c29-2h4x-fgg4/GHSA-3c29-2h4x-fgg4.json b/advisories/unreviewed/2023/01/GHSA-3c29-2h4x-fgg4/GHSA-3c29-2h4x-fgg4.json index 404092a35b5..940cee5e328 100644 --- a/advisories/unreviewed/2023/01/GHSA-3c29-2h4x-fgg4/GHSA-3c29-2h4x-fgg4.json +++ b/advisories/unreviewed/2023/01/GHSA-3c29-2h4x-fgg4/GHSA-3c29-2h4x-fgg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-3f9r-qr29-wv82/GHSA-3f9r-qr29-wv82.json b/advisories/unreviewed/2023/01/GHSA-3f9r-qr29-wv82/GHSA-3f9r-qr29-wv82.json index ca0f17cb72b..1f97627fead 100644 --- a/advisories/unreviewed/2023/01/GHSA-3f9r-qr29-wv82/GHSA-3f9r-qr29-wv82.json +++ b/advisories/unreviewed/2023/01/GHSA-3f9r-qr29-wv82/GHSA-3f9r-qr29-wv82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-552w-fg8f-29x6/GHSA-552w-fg8f-29x6.json b/advisories/unreviewed/2023/01/GHSA-552w-fg8f-29x6/GHSA-552w-fg8f-29x6.json index 65410a5356c..004e91abf4a 100644 --- a/advisories/unreviewed/2023/01/GHSA-552w-fg8f-29x6/GHSA-552w-fg8f-29x6.json +++ b/advisories/unreviewed/2023/01/GHSA-552w-fg8f-29x6/GHSA-552w-fg8f-29x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7v6p-hrxh-28hh/GHSA-7v6p-hrxh-28hh.json b/advisories/unreviewed/2023/01/GHSA-7v6p-hrxh-28hh/GHSA-7v6p-hrxh-28hh.json index e09b7f3ee41..c554770db06 100644 --- a/advisories/unreviewed/2023/01/GHSA-7v6p-hrxh-28hh/GHSA-7v6p-hrxh-28hh.json +++ b/advisories/unreviewed/2023/01/GHSA-7v6p-hrxh-28hh/GHSA-7v6p-hrxh-28hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8phc-jhvp-25cw/GHSA-8phc-jhvp-25cw.json b/advisories/unreviewed/2023/01/GHSA-8phc-jhvp-25cw/GHSA-8phc-jhvp-25cw.json index ad41cb7a0d9..06ee258c2f9 100644 --- a/advisories/unreviewed/2023/01/GHSA-8phc-jhvp-25cw/GHSA-8phc-jhvp-25cw.json +++ b/advisories/unreviewed/2023/01/GHSA-8phc-jhvp-25cw/GHSA-8phc-jhvp-25cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-ch9p-8jp8-qjvq/GHSA-ch9p-8jp8-qjvq.json b/advisories/unreviewed/2023/01/GHSA-ch9p-8jp8-qjvq/GHSA-ch9p-8jp8-qjvq.json index 2305ea8e2be..1af2c6a686d 100644 --- a/advisories/unreviewed/2023/01/GHSA-ch9p-8jp8-qjvq/GHSA-ch9p-8jp8-qjvq.json +++ b/advisories/unreviewed/2023/01/GHSA-ch9p-8jp8-qjvq/GHSA-ch9p-8jp8-qjvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-f632-r9w6-239m/GHSA-f632-r9w6-239m.json b/advisories/unreviewed/2023/01/GHSA-f632-r9w6-239m/GHSA-f632-r9w6-239m.json index 88bb0254b95..71aa802f2b3 100644 --- a/advisories/unreviewed/2023/01/GHSA-f632-r9w6-239m/GHSA-f632-r9w6-239m.json +++ b/advisories/unreviewed/2023/01/GHSA-f632-r9w6-239m/GHSA-f632-r9w6-239m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-f6x7-q479-7278/GHSA-f6x7-q479-7278.json b/advisories/unreviewed/2023/01/GHSA-f6x7-q479-7278/GHSA-f6x7-q479-7278.json index 525c388c491..1056e1df1cd 100644 --- a/advisories/unreviewed/2023/01/GHSA-f6x7-q479-7278/GHSA-f6x7-q479-7278.json +++ b/advisories/unreviewed/2023/01/GHSA-f6x7-q479-7278/GHSA-f6x7-q479-7278.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-ghq7-9x63-pxqp/GHSA-ghq7-9x63-pxqp.json b/advisories/unreviewed/2023/01/GHSA-ghq7-9x63-pxqp/GHSA-ghq7-9x63-pxqp.json index 349dbaee338..bf87c97d0a6 100644 --- a/advisories/unreviewed/2023/01/GHSA-ghq7-9x63-pxqp/GHSA-ghq7-9x63-pxqp.json +++ b/advisories/unreviewed/2023/01/GHSA-ghq7-9x63-pxqp/GHSA-ghq7-9x63-pxqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jpc4-x6x2-7pm8/GHSA-jpc4-x6x2-7pm8.json b/advisories/unreviewed/2023/01/GHSA-jpc4-x6x2-7pm8/GHSA-jpc4-x6x2-7pm8.json index e55c9f66ff7..8dfeb41a3ba 100644 --- a/advisories/unreviewed/2023/01/GHSA-jpc4-x6x2-7pm8/GHSA-jpc4-x6x2-7pm8.json +++ b/advisories/unreviewed/2023/01/GHSA-jpc4-x6x2-7pm8/GHSA-jpc4-x6x2-7pm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-mqwr-55wx-37jr/GHSA-mqwr-55wx-37jr.json b/advisories/unreviewed/2023/01/GHSA-mqwr-55wx-37jr/GHSA-mqwr-55wx-37jr.json index 3ded7c91626..61ed225b6ad 100644 --- a/advisories/unreviewed/2023/01/GHSA-mqwr-55wx-37jr/GHSA-mqwr-55wx-37jr.json +++ b/advisories/unreviewed/2023/01/GHSA-mqwr-55wx-37jr/GHSA-mqwr-55wx-37jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-q9cw-p99m-h9cm/GHSA-q9cw-p99m-h9cm.json b/advisories/unreviewed/2023/01/GHSA-q9cw-p99m-h9cm/GHSA-q9cw-p99m-h9cm.json index b27c16a55b0..562875b86e8 100644 --- a/advisories/unreviewed/2023/01/GHSA-q9cw-p99m-h9cm/GHSA-q9cw-p99m-h9cm.json +++ b/advisories/unreviewed/2023/01/GHSA-q9cw-p99m-h9cm/GHSA-q9cw-p99m-h9cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json b/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json index 5f580a32894..bb2e2fc9cab 100644 --- a/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json +++ b/advisories/unreviewed/2023/01/GHSA-q9vj-6cqq-wmgg/GHSA-q9vj-6cqq-wmgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-c538-wc3x-p8rv/GHSA-c538-wc3x-p8rv.json b/advisories/unreviewed/2024/05/GHSA-c538-wc3x-p8rv/GHSA-c538-wc3x-p8rv.json index 5f86a6222ec..65865bef5d6 100644 --- a/advisories/unreviewed/2024/05/GHSA-c538-wc3x-p8rv/GHSA-c538-wc3x-p8rv.json +++ b/advisories/unreviewed/2024/05/GHSA-c538-wc3x-p8rv/GHSA-c538-wc3x-p8rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-259f-xj2w-xw2m/GHSA-259f-xj2w-xw2m.json b/advisories/unreviewed/2024/06/GHSA-259f-xj2w-xw2m/GHSA-259f-xj2w-xw2m.json index e197123b32f..2205e186b4f 100644 --- a/advisories/unreviewed/2024/06/GHSA-259f-xj2w-xw2m/GHSA-259f-xj2w-xw2m.json +++ b/advisories/unreviewed/2024/06/GHSA-259f-xj2w-xw2m/GHSA-259f-xj2w-xw2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2vwm-3r62-68r6/GHSA-2vwm-3r62-68r6.json b/advisories/unreviewed/2024/06/GHSA-2vwm-3r62-68r6/GHSA-2vwm-3r62-68r6.json index e4f21517204..ad595e5a0e1 100644 --- a/advisories/unreviewed/2024/06/GHSA-2vwm-3r62-68r6/GHSA-2vwm-3r62-68r6.json +++ b/advisories/unreviewed/2024/06/GHSA-2vwm-3r62-68r6/GHSA-2vwm-3r62-68r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-36cf-mq32-6x43/GHSA-36cf-mq32-6x43.json b/advisories/unreviewed/2024/06/GHSA-36cf-mq32-6x43/GHSA-36cf-mq32-6x43.json index 750893de2fe..38fa87767b7 100644 --- a/advisories/unreviewed/2024/06/GHSA-36cf-mq32-6x43/GHSA-36cf-mq32-6x43.json +++ b/advisories/unreviewed/2024/06/GHSA-36cf-mq32-6x43/GHSA-36cf-mq32-6x43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3cc8-7xhw-x4w6/GHSA-3cc8-7xhw-x4w6.json b/advisories/unreviewed/2024/06/GHSA-3cc8-7xhw-x4w6/GHSA-3cc8-7xhw-x4w6.json index d2a04e25aba..e64c029b5b0 100644 --- a/advisories/unreviewed/2024/06/GHSA-3cc8-7xhw-x4w6/GHSA-3cc8-7xhw-x4w6.json +++ b/advisories/unreviewed/2024/06/GHSA-3cc8-7xhw-x4w6/GHSA-3cc8-7xhw-x4w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3vhf-gvj3-rcch/GHSA-3vhf-gvj3-rcch.json b/advisories/unreviewed/2024/06/GHSA-3vhf-gvj3-rcch/GHSA-3vhf-gvj3-rcch.json index 172c259be16..4012a46ea7a 100644 --- a/advisories/unreviewed/2024/06/GHSA-3vhf-gvj3-rcch/GHSA-3vhf-gvj3-rcch.json +++ b/advisories/unreviewed/2024/06/GHSA-3vhf-gvj3-rcch/GHSA-3vhf-gvj3-rcch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3w29-9x4p-299p/GHSA-3w29-9x4p-299p.json b/advisories/unreviewed/2024/06/GHSA-3w29-9x4p-299p/GHSA-3w29-9x4p-299p.json index cbdfb6e8c76..1f14d863749 100644 --- a/advisories/unreviewed/2024/06/GHSA-3w29-9x4p-299p/GHSA-3w29-9x4p-299p.json +++ b/advisories/unreviewed/2024/06/GHSA-3w29-9x4p-299p/GHSA-3w29-9x4p-299p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-43w3-q4jr-pw7r/GHSA-43w3-q4jr-pw7r.json b/advisories/unreviewed/2024/06/GHSA-43w3-q4jr-pw7r/GHSA-43w3-q4jr-pw7r.json index 42eaef5f49b..04abeea0123 100644 --- a/advisories/unreviewed/2024/06/GHSA-43w3-q4jr-pw7r/GHSA-43w3-q4jr-pw7r.json +++ b/advisories/unreviewed/2024/06/GHSA-43w3-q4jr-pw7r/GHSA-43w3-q4jr-pw7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4xhv-7cw3-294h/GHSA-4xhv-7cw3-294h.json b/advisories/unreviewed/2024/06/GHSA-4xhv-7cw3-294h/GHSA-4xhv-7cw3-294h.json index 0c393040234..4b6e83ca0c1 100644 --- a/advisories/unreviewed/2024/06/GHSA-4xhv-7cw3-294h/GHSA-4xhv-7cw3-294h.json +++ b/advisories/unreviewed/2024/06/GHSA-4xhv-7cw3-294h/GHSA-4xhv-7cw3-294h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5578-g33f-6mjj/GHSA-5578-g33f-6mjj.json b/advisories/unreviewed/2024/06/GHSA-5578-g33f-6mjj/GHSA-5578-g33f-6mjj.json index fec412b9eb9..e8d9feb2bb1 100644 --- a/advisories/unreviewed/2024/06/GHSA-5578-g33f-6mjj/GHSA-5578-g33f-6mjj.json +++ b/advisories/unreviewed/2024/06/GHSA-5578-g33f-6mjj/GHSA-5578-g33f-6mjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-83pr-wj87-jf6x/GHSA-83pr-wj87-jf6x.json b/advisories/unreviewed/2024/06/GHSA-83pr-wj87-jf6x/GHSA-83pr-wj87-jf6x.json index 768ed09db15..1b272ce6609 100644 --- a/advisories/unreviewed/2024/06/GHSA-83pr-wj87-jf6x/GHSA-83pr-wj87-jf6x.json +++ b/advisories/unreviewed/2024/06/GHSA-83pr-wj87-jf6x/GHSA-83pr-wj87-jf6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-89jq-r228-vm9c/GHSA-89jq-r228-vm9c.json b/advisories/unreviewed/2024/06/GHSA-89jq-r228-vm9c/GHSA-89jq-r228-vm9c.json index b589ca0e9d4..b043163b485 100644 --- a/advisories/unreviewed/2024/06/GHSA-89jq-r228-vm9c/GHSA-89jq-r228-vm9c.json +++ b/advisories/unreviewed/2024/06/GHSA-89jq-r228-vm9c/GHSA-89jq-r228-vm9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-97x2-r642-2777/GHSA-97x2-r642-2777.json b/advisories/unreviewed/2024/06/GHSA-97x2-r642-2777/GHSA-97x2-r642-2777.json index 2799772543f..32cd6f30408 100644 --- a/advisories/unreviewed/2024/06/GHSA-97x2-r642-2777/GHSA-97x2-r642-2777.json +++ b/advisories/unreviewed/2024/06/GHSA-97x2-r642-2777/GHSA-97x2-r642-2777.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9v84-f7vm-8f87/GHSA-9v84-f7vm-8f87.json b/advisories/unreviewed/2024/06/GHSA-9v84-f7vm-8f87/GHSA-9v84-f7vm-8f87.json index a2c64ff39d9..d6f0e6cf1d4 100644 --- a/advisories/unreviewed/2024/06/GHSA-9v84-f7vm-8f87/GHSA-9v84-f7vm-8f87.json +++ b/advisories/unreviewed/2024/06/GHSA-9v84-f7vm-8f87/GHSA-9v84-f7vm-8f87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json b/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json index 2362de856ee..8793e2b7116 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json +++ b/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cwpm-xghv-px2h/GHSA-cwpm-xghv-px2h.json b/advisories/unreviewed/2024/06/GHSA-cwpm-xghv-px2h/GHSA-cwpm-xghv-px2h.json index 44936da4062..e6899a82fd5 100644 --- a/advisories/unreviewed/2024/06/GHSA-cwpm-xghv-px2h/GHSA-cwpm-xghv-px2h.json +++ b/advisories/unreviewed/2024/06/GHSA-cwpm-xghv-px2h/GHSA-cwpm-xghv-px2h.json @@ -7,12 +7,8 @@ "CVE-2024-5927" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-f3x6-gr53-7hc5/GHSA-f3x6-gr53-7hc5.json b/advisories/unreviewed/2024/06/GHSA-f3x6-gr53-7hc5/GHSA-f3x6-gr53-7hc5.json index f6e0076504a..3d738002b50 100644 --- a/advisories/unreviewed/2024/06/GHSA-f3x6-gr53-7hc5/GHSA-f3x6-gr53-7hc5.json +++ b/advisories/unreviewed/2024/06/GHSA-f3x6-gr53-7hc5/GHSA-f3x6-gr53-7hc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-gv35-xq5j-3wj5/GHSA-gv35-xq5j-3wj5.json b/advisories/unreviewed/2024/06/GHSA-gv35-xq5j-3wj5/GHSA-gv35-xq5j-3wj5.json index 0a0a17fd3f5..3446c5947da 100644 --- a/advisories/unreviewed/2024/06/GHSA-gv35-xq5j-3wj5/GHSA-gv35-xq5j-3wj5.json +++ b/advisories/unreviewed/2024/06/GHSA-gv35-xq5j-3wj5/GHSA-gv35-xq5j-3wj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h44r-7f3w-cmm3/GHSA-h44r-7f3w-cmm3.json b/advisories/unreviewed/2024/06/GHSA-h44r-7f3w-cmm3/GHSA-h44r-7f3w-cmm3.json index 8a1851049a3..fbec915f1d5 100644 --- a/advisories/unreviewed/2024/06/GHSA-h44r-7f3w-cmm3/GHSA-h44r-7f3w-cmm3.json +++ b/advisories/unreviewed/2024/06/GHSA-h44r-7f3w-cmm3/GHSA-h44r-7f3w-cmm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j6mp-97gj-pg59/GHSA-j6mp-97gj-pg59.json b/advisories/unreviewed/2024/06/GHSA-j6mp-97gj-pg59/GHSA-j6mp-97gj-pg59.json index d9dd59bb8e8..47dc4b43e90 100644 --- a/advisories/unreviewed/2024/06/GHSA-j6mp-97gj-pg59/GHSA-j6mp-97gj-pg59.json +++ b/advisories/unreviewed/2024/06/GHSA-j6mp-97gj-pg59/GHSA-j6mp-97gj-pg59.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j76w-hgqv-3vg4/GHSA-j76w-hgqv-3vg4.json b/advisories/unreviewed/2024/06/GHSA-j76w-hgqv-3vg4/GHSA-j76w-hgqv-3vg4.json index dc4ef11f76f..e0f1f867903 100644 --- a/advisories/unreviewed/2024/06/GHSA-j76w-hgqv-3vg4/GHSA-j76w-hgqv-3vg4.json +++ b/advisories/unreviewed/2024/06/GHSA-j76w-hgqv-3vg4/GHSA-j76w-hgqv-3vg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-j9vm-x4wf-38gg/GHSA-j9vm-x4wf-38gg.json b/advisories/unreviewed/2024/06/GHSA-j9vm-x4wf-38gg/GHSA-j9vm-x4wf-38gg.json index f069c5fd92a..3112a513ad5 100644 --- a/advisories/unreviewed/2024/06/GHSA-j9vm-x4wf-38gg/GHSA-j9vm-x4wf-38gg.json +++ b/advisories/unreviewed/2024/06/GHSA-j9vm-x4wf-38gg/GHSA-j9vm-x4wf-38gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m388-cvx4-q52g/GHSA-m388-cvx4-q52g.json b/advisories/unreviewed/2024/06/GHSA-m388-cvx4-q52g/GHSA-m388-cvx4-q52g.json index 29c6e50f5bb..ae68cb56534 100644 --- a/advisories/unreviewed/2024/06/GHSA-m388-cvx4-q52g/GHSA-m388-cvx4-q52g.json +++ b/advisories/unreviewed/2024/06/GHSA-m388-cvx4-q52g/GHSA-m388-cvx4-q52g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mjfj-95fm-27mx/GHSA-mjfj-95fm-27mx.json b/advisories/unreviewed/2024/06/GHSA-mjfj-95fm-27mx/GHSA-mjfj-95fm-27mx.json index 41a2953ef0a..37407abfdff 100644 --- a/advisories/unreviewed/2024/06/GHSA-mjfj-95fm-27mx/GHSA-mjfj-95fm-27mx.json +++ b/advisories/unreviewed/2024/06/GHSA-mjfj-95fm-27mx/GHSA-mjfj-95fm-27mx.json @@ -7,12 +7,8 @@ "CVE-2021-4237" ], "details": "Rejected reason: reserved but not needed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-ph46-7fpg-mqx8/GHSA-ph46-7fpg-mqx8.json b/advisories/unreviewed/2024/06/GHSA-ph46-7fpg-mqx8/GHSA-ph46-7fpg-mqx8.json index 0ad8d43dbe1..ae1babec1a2 100644 --- a/advisories/unreviewed/2024/06/GHSA-ph46-7fpg-mqx8/GHSA-ph46-7fpg-mqx8.json +++ b/advisories/unreviewed/2024/06/GHSA-ph46-7fpg-mqx8/GHSA-ph46-7fpg-mqx8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-px27-wcgr-7gf5/GHSA-px27-wcgr-7gf5.json b/advisories/unreviewed/2024/06/GHSA-px27-wcgr-7gf5/GHSA-px27-wcgr-7gf5.json index 6dd318f844d..a82588ccce2 100644 --- a/advisories/unreviewed/2024/06/GHSA-px27-wcgr-7gf5/GHSA-px27-wcgr-7gf5.json +++ b/advisories/unreviewed/2024/06/GHSA-px27-wcgr-7gf5/GHSA-px27-wcgr-7gf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-q49m-qrh9-4jc8/GHSA-q49m-qrh9-4jc8.json b/advisories/unreviewed/2024/06/GHSA-q49m-qrh9-4jc8/GHSA-q49m-qrh9-4jc8.json index c5f5c635769..e4440f96288 100644 --- a/advisories/unreviewed/2024/06/GHSA-q49m-qrh9-4jc8/GHSA-q49m-qrh9-4jc8.json +++ b/advisories/unreviewed/2024/06/GHSA-q49m-qrh9-4jc8/GHSA-q49m-qrh9-4jc8.json @@ -7,12 +7,8 @@ "CVE-2024-38285" ], "details": "Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-q9fc-6fvr-wxg5/GHSA-q9fc-6fvr-wxg5.json b/advisories/unreviewed/2024/06/GHSA-q9fc-6fvr-wxg5/GHSA-q9fc-6fvr-wxg5.json index d927ae5a4fa..53673bfbef3 100644 --- a/advisories/unreviewed/2024/06/GHSA-q9fc-6fvr-wxg5/GHSA-q9fc-6fvr-wxg5.json +++ b/advisories/unreviewed/2024/06/GHSA-q9fc-6fvr-wxg5/GHSA-q9fc-6fvr-wxg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qm52-rrfg-jwc6/GHSA-qm52-rrfg-jwc6.json b/advisories/unreviewed/2024/06/GHSA-qm52-rrfg-jwc6/GHSA-qm52-rrfg-jwc6.json index e502a4bd684..a94410c5748 100644 --- a/advisories/unreviewed/2024/06/GHSA-qm52-rrfg-jwc6/GHSA-qm52-rrfg-jwc6.json +++ b/advisories/unreviewed/2024/06/GHSA-qm52-rrfg-jwc6/GHSA-qm52-rrfg-jwc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v9rm-3p9p-c283/GHSA-v9rm-3p9p-c283.json b/advisories/unreviewed/2024/06/GHSA-v9rm-3p9p-c283/GHSA-v9rm-3p9p-c283.json index 900078d3425..cb53056b567 100644 --- a/advisories/unreviewed/2024/06/GHSA-v9rm-3p9p-c283/GHSA-v9rm-3p9p-c283.json +++ b/advisories/unreviewed/2024/06/GHSA-v9rm-3p9p-c283/GHSA-v9rm-3p9p-c283.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vhv4-j9cm-5cjx/GHSA-vhv4-j9cm-5cjx.json b/advisories/unreviewed/2024/06/GHSA-vhv4-j9cm-5cjx/GHSA-vhv4-j9cm-5cjx.json index 909439d8ccf..84b6205c3ac 100644 --- a/advisories/unreviewed/2024/06/GHSA-vhv4-j9cm-5cjx/GHSA-vhv4-j9cm-5cjx.json +++ b/advisories/unreviewed/2024/06/GHSA-vhv4-j9cm-5cjx/GHSA-vhv4-j9cm-5cjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-w2vq-f5f5-hrv8/GHSA-w2vq-f5f5-hrv8.json b/advisories/unreviewed/2024/06/GHSA-w2vq-f5f5-hrv8/GHSA-w2vq-f5f5-hrv8.json index 964b840716c..7cdf9e8e316 100644 --- a/advisories/unreviewed/2024/06/GHSA-w2vq-f5f5-hrv8/GHSA-w2vq-f5f5-hrv8.json +++ b/advisories/unreviewed/2024/06/GHSA-w2vq-f5f5-hrv8/GHSA-w2vq-f5f5-hrv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wp7r-cfw6-7758/GHSA-wp7r-cfw6-7758.json b/advisories/unreviewed/2024/06/GHSA-wp7r-cfw6-7758/GHSA-wp7r-cfw6-7758.json index 018491358ed..07d77f50a1c 100644 --- a/advisories/unreviewed/2024/06/GHSA-wp7r-cfw6-7758/GHSA-wp7r-cfw6-7758.json +++ b/advisories/unreviewed/2024/06/GHSA-wp7r-cfw6-7758/GHSA-wp7r-cfw6-7758.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x6mf-qhjj-pcj9/GHSA-x6mf-qhjj-pcj9.json b/advisories/unreviewed/2024/06/GHSA-x6mf-qhjj-pcj9/GHSA-x6mf-qhjj-pcj9.json index 9a434e0ca50..27a860c2300 100644 --- a/advisories/unreviewed/2024/06/GHSA-x6mf-qhjj-pcj9/GHSA-x6mf-qhjj-pcj9.json +++ b/advisories/unreviewed/2024/06/GHSA-x6mf-qhjj-pcj9/GHSA-x6mf-qhjj-pcj9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",