diff --git a/advisories/github-reviewed/2021/08/GHSA-26rr-v2j2-25fh/GHSA-26rr-v2j2-25fh.json b/advisories/github-reviewed/2021/08/GHSA-26rr-v2j2-25fh/GHSA-26rr-v2j2-25fh.json index 564f64b0eda..a47a2d0226e 100644 --- a/advisories/github-reviewed/2021/08/GHSA-26rr-v2j2-25fh/GHSA-26rr-v2j2-25fh.json +++ b/advisories/github-reviewed/2021/08/GHSA-26rr-v2j2-25fh/GHSA-26rr-v2j2-25fh.json @@ -8,9 +8,7 @@ ], "summary": "Layout XML Arbitrary Code Fix ", "details": "### Impact\nLayout XML enabled admin users to execute arbitrary commands via block methods.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/08/GHSA-xm9f-vxmx-4m58/GHSA-xm9f-vxmx-4m58.json b/advisories/github-reviewed/2021/08/GHSA-xm9f-vxmx-4m58/GHSA-xm9f-vxmx-4m58.json index bc6c90ddd19..ae9fbc9ead7 100644 --- a/advisories/github-reviewed/2021/08/GHSA-xm9f-vxmx-4m58/GHSA-xm9f-vxmx-4m58.json +++ b/advisories/github-reviewed/2021/08/GHSA-xm9f-vxmx-4m58/GHSA-xm9f-vxmx-4m58.json @@ -8,9 +8,7 @@ ], "summary": "Data Flow Sanitation Issue Fix ", "details": "### Impact\nDue to missing sanitation in data flow it was possible for admin users to upload arbitrary executable files to the server.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-2c83-wfv3-q25f/GHSA-2c83-wfv3-q25f.json b/advisories/github-reviewed/2021/09/GHSA-2c83-wfv3-q25f/GHSA-2c83-wfv3-q25f.json index 6df06f9477a..95ec1704f0a 100644 --- a/advisories/github-reviewed/2021/09/GHSA-2c83-wfv3-q25f/GHSA-2c83-wfv3-q25f.json +++ b/advisories/github-reviewed/2021/09/GHSA-2c83-wfv3-q25f/GHSA-2c83-wfv3-q25f.json @@ -3,14 +3,10 @@ "id": "GHSA-2c83-wfv3-q25f", "modified": "2021-09-07T14:04:47Z", "published": "2021-09-07T23:07:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ZMarkdown", "details": "### Impact\n\nA Remote Command Execution vulnerability was found in the rebber module,\nwhich allowed execution of arbitrary commands. The reported problem came\nfrom CodeBlocks, which could be escaped to insert malicious LaTeX.\n\nAnyone using `rebber` without sanitation of code content or a custom\nmacro is impacted by this vulnerability. Here is an example of a Markdown\ncontent that will exploit the vulnerability:\n\n````markdown\n```\n\\end{CodeBlock}\n\n\\immediate\\write18{COMMAND > outputrce}\n\\input{outputrce}\n\n\\begin{CodeBlock}{text}\n```\n````\n\nWill insert into the generated LaTeX the result of executing\n`COMMAND` on the system.\n\n### Patches\n\nThe vulnerability has been patched in version 5.2.1.\nIf impacted, you should update to this version as soon as possible.\n\n### Workarounds\n\nIt is possible to mitigate the vulnerability without upgrading by using a\ncustom code macro. Please make sure this custom macro escapes your\nclosing LaTeX sequence. For the example above, use:\n\n```javascript\nconst escaped = content.replace(new RegExp('\\\\\\\\end\\\\s*{CodeBlock}', 'g'), '')\n```\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [ZMarkdown](https://github.com/zestedesavoir/zmarkdown/issues).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-2rh5-jvgx-pgw3/GHSA-2rh5-jvgx-pgw3.json b/advisories/github-reviewed/2021/09/GHSA-2rh5-jvgx-pgw3/GHSA-2rh5-jvgx-pgw3.json index ea97cbfa450..038801e92f7 100644 --- a/advisories/github-reviewed/2021/09/GHSA-2rh5-jvgx-pgw3/GHSA-2rh5-jvgx-pgw3.json +++ b/advisories/github-reviewed/2021/09/GHSA-2rh5-jvgx-pgw3/GHSA-2rh5-jvgx-pgw3.json @@ -3,14 +3,10 @@ "id": "GHSA-2rh5-jvgx-pgw3", "modified": "2021-09-14T18:35:38Z", "published": "2021-09-14T20:25:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Any storage file can be downloaded from p.sh if full server path is known", "details": "The default configuration for platform.sh (.platform.app.yaml) allows access to uploaded files if you know or can guess their location, regardless of whether roles grant content read access to the content containing those files. If you're using Legacy Bridge, the default configuration also allows access to certain legacy files that should not be readable, including the legacy var directory and extension directories.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-36mj-6r7r-mqhf/GHSA-36mj-6r7r-mqhf.json b/advisories/github-reviewed/2021/09/GHSA-36mj-6r7r-mqhf/GHSA-36mj-6r7r-mqhf.json index f5681a44ba0..6ec34d41a56 100644 --- a/advisories/github-reviewed/2021/09/GHSA-36mj-6r7r-mqhf/GHSA-36mj-6r7r-mqhf.json +++ b/advisories/github-reviewed/2021/09/GHSA-36mj-6r7r-mqhf/GHSA-36mj-6r7r-mqhf.json @@ -3,14 +3,10 @@ "id": "GHSA-36mj-6r7r-mqhf", "modified": "2021-09-28T21:21:08Z", "published": "2021-09-29T17:09:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "User can obtain JWT token even if account is disabled", "details": "Users can authenticate this way even if their user account is disabled. This is a high risk vulnerability when account disabling is used to block users' access to the system. (Someone who never had an account cannot exploit this vulnerability.) The fix ensures tokens are generated only for enabled user accounts, and is distributed via Composer as ezsystems/ezplatform-rest v1.3.8", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-593v-wcqx-hq2w/GHSA-593v-wcqx-hq2w.json b/advisories/github-reviewed/2021/09/GHSA-593v-wcqx-hq2w/GHSA-593v-wcqx-hq2w.json index e117de0d865..cfd526c8f74 100644 --- a/advisories/github-reviewed/2021/09/GHSA-593v-wcqx-hq2w/GHSA-593v-wcqx-hq2w.json +++ b/advisories/github-reviewed/2021/09/GHSA-593v-wcqx-hq2w/GHSA-593v-wcqx-hq2w.json @@ -3,14 +3,10 @@ "id": "GHSA-593v-wcqx-hq2w", "modified": "2021-09-03T21:34:00Z", "published": "2021-09-07T22:57:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Incorrect version tags linked to external repository", "details": "### Impact\nA security incident caused a number of incorrect version tags to be pushed to the Parse Server repository. These version tags linked to a personal fork of a contributor who had write access to the repository. The code to which these tags linked has not been reviewed or approved by Parse Platform. Even though no releases were published with these incorrect versions, it was possible to define a Parse Server dependency that pointed to these version tags, for example if you defined this dependency: \n```js\n\"parse-server\": \"git@github.com:parse-community/parse-server.git#4.9.3\"\n```\n\nWe have since deleted the incorrect version tags, but they may still show up in your personal fork on GitHub or locally. We do not know when these tags have been pushed to the Parse Server repository, but we first became aware of this issue on July 21, 2021. We are not aware of any malicious code or concerns related to privacy, security or legality (e.g. proprietary code). However, it has been reported that some functionality does not work as expected and the introduction of security vulnerabilities cannot be ruled out.\n\nYou may be also affected if you used the Bitnami image for Parse Server. Bitnami picked up the incorrect version tag `4.9.3` and published a new Bitnami image for Parse Server. \n \n**If you are using any of the affected versions, we urgently recommend to upgrade to version `4.10.0`.**\n\n\nThese are the incorrect tags:\n```\n4.0.0-beta1\n4.0.0-beta2\n4.0.0-beta3\n4.0.0-beta4\n4.0.0-beta5\n4.0.0-beta6\n4.0.10\n4.0.11\n4.0.12\n4.0.13\n4.0.14\n4.0.3\n4.0.4\n4.0.6\n4.0.7\n4.0.8\n4.0.9\n4.6.0\n4.6.0-beta\n4.7.0\n4.8.0\n4.8.1\n4.8.2\n4.8.3\n4.8.4\n4.8.5\n4.9.0\n4.9.1\n4.9.2\n4.9.3\n```\n\n### Patches\nUpgrade to version `4.10.0`.\n\n### Workarounds\nDowngrade to version `4.5.2`.\n\n### References\nn/a", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -62,9 +58,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-09-03T21:34:00Z", diff --git a/advisories/github-reviewed/2021/09/GHSA-65p7-pjj8-ggmr/GHSA-65p7-pjj8-ggmr.json b/advisories/github-reviewed/2021/09/GHSA-65p7-pjj8-ggmr/GHSA-65p7-pjj8-ggmr.json index a8060dadbed..97fac6c1a01 100644 --- a/advisories/github-reviewed/2021/09/GHSA-65p7-pjj8-ggmr/GHSA-65p7-pjj8-ggmr.json +++ b/advisories/github-reviewed/2021/09/GHSA-65p7-pjj8-ggmr/GHSA-65p7-pjj8-ggmr.json @@ -3,9 +3,7 @@ "id": "GHSA-65p7-pjj8-ggmr", "modified": "2021-09-23T21:14:22Z", "published": "2021-09-23T23:18:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Member account takeover", "details": "### Impact\n\nAn error in the implementation of the member email change functionality allows unauthenticated users to change the email address of arbitrary member accounts to one they control by crafting a request to the relevant API endpoint, and validating the new address via magic link sent to the new email address.\n\nGhost(Pro) has already been patched. Self-hosters are impacted if running Ghost a version between 3.18.0 and 4.15.0 with members functionality enabled.\n\n### Patches\n\nFixed in 4.15.1, all 4.x sites should upgrade as soon as possible.\nFixed in 3.42.6, all 3.x sites should upgrade as soon as possible.\n\n### Workarounds\n\nThe patch in 4.15.1 and 3.42.6 adds a new authenticated endpoint for updating member email addresses. Updating Ghost is the quickest complete solution.\n\nAs a workaround, if for any reason you cannot update your Ghost instance, you can block the `POST /members/api/send-magic-link/` endpoint, which will also disable member login and signup for your site.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n", "severity": [ @@ -65,9 +63,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-09-23T21:14:22Z", diff --git a/advisories/github-reviewed/2021/09/GHSA-6q3p-36f4-cwxv/GHSA-6q3p-36f4-cwxv.json b/advisories/github-reviewed/2021/09/GHSA-6q3p-36f4-cwxv/GHSA-6q3p-36f4-cwxv.json index 53d612c3e1d..a0ddd742585 100644 --- a/advisories/github-reviewed/2021/09/GHSA-6q3p-36f4-cwxv/GHSA-6q3p-36f4-cwxv.json +++ b/advisories/github-reviewed/2021/09/GHSA-6q3p-36f4-cwxv/GHSA-6q3p-36f4-cwxv.json @@ -8,9 +8,7 @@ ], "summary": "Server-Side Request Forgery in UReport", "details": "UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-7rp6-w7mg-h8rw/GHSA-7rp6-w7mg-h8rw.json b/advisories/github-reviewed/2021/09/GHSA-7rp6-w7mg-h8rw/GHSA-7rp6-w7mg-h8rw.json index 3ba24e4f196..9e1fdd78063 100644 --- a/advisories/github-reviewed/2021/09/GHSA-7rp6-w7mg-h8rw/GHSA-7rp6-w7mg-h8rw.json +++ b/advisories/github-reviewed/2021/09/GHSA-7rp6-w7mg-h8rw/GHSA-7rp6-w7mg-h8rw.json @@ -8,9 +8,7 @@ ], "summary": "XML External Entity Reference in Apache Jena", "details": "A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-84p7-fh9c-6g8h/GHSA-84p7-fh9c-6g8h.json b/advisories/github-reviewed/2021/09/GHSA-84p7-fh9c-6g8h/GHSA-84p7-fh9c-6g8h.json index a5546a73488..218058eb14c 100644 --- a/advisories/github-reviewed/2021/09/GHSA-84p7-fh9c-6g8h/GHSA-84p7-fh9c-6g8h.json +++ b/advisories/github-reviewed/2021/09/GHSA-84p7-fh9c-6g8h/GHSA-84p7-fh9c-6g8h.json @@ -3,14 +3,10 @@ "id": "GHSA-84p7-fh9c-6g8h", "modified": "2021-09-16T21:30:18Z", "published": "2021-09-20T19:52:24Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in mixme", "details": "### Impact\nWhen copying properties from a source object to a target object, the target object can gain access to certain properties of the source object and modify their content.\n\n### Patches\nThe problem was patch with a more agressive discovery of secured properties to filter out.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-8r4g-cg4m-x23c/GHSA-8r4g-cg4m-x23c.json b/advisories/github-reviewed/2021/09/GHSA-8r4g-cg4m-x23c/GHSA-8r4g-cg4m-x23c.json index c57b08c647e..4f5d098a674 100644 --- a/advisories/github-reviewed/2021/09/GHSA-8r4g-cg4m-x23c/GHSA-8r4g-cg4m-x23c.json +++ b/advisories/github-reviewed/2021/09/GHSA-8r4g-cg4m-x23c/GHSA-8r4g-cg4m-x23c.json @@ -3,14 +3,10 @@ "id": "GHSA-8r4g-cg4m-x23c", "modified": "2021-12-20T22:16:43Z", "published": "2021-09-22T18:22:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "Denial of Service in node-static", "details": "All versions of node-static are vulnerable to a Denial of Service. The package fails to catch an exception when user input includes null bytes. This allows attackers to access `http://host/%00` and crash the server.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-99px-7724-484v/GHSA-99px-7724-484v.json b/advisories/github-reviewed/2021/09/GHSA-99px-7724-484v/GHSA-99px-7724-484v.json index f798fb1fcab..41283b1244a 100644 --- a/advisories/github-reviewed/2021/09/GHSA-99px-7724-484v/GHSA-99px-7724-484v.json +++ b/advisories/github-reviewed/2021/09/GHSA-99px-7724-484v/GHSA-99px-7724-484v.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-09-13T19:31:57Z", diff --git a/advisories/github-reviewed/2021/09/GHSA-f3rf-v9qm-9c89/GHSA-f3rf-v9qm-9c89.json b/advisories/github-reviewed/2021/09/GHSA-f3rf-v9qm-9c89/GHSA-f3rf-v9qm-9c89.json index 7c7cbb7eadd..e114837f3ff 100644 --- a/advisories/github-reviewed/2021/09/GHSA-f3rf-v9qm-9c89/GHSA-f3rf-v9qm-9c89.json +++ b/advisories/github-reviewed/2021/09/GHSA-f3rf-v9qm-9c89/GHSA-f3rf-v9qm-9c89.json @@ -8,9 +8,7 @@ ], "summary": "Cross-site Scripting in the femanager TYPO3 extension", "details": "The extension allows by default to upload SVG files when a logged in frontend user uploads a new profile image. This may lead to Cross-Site Scripting, when the uploaded SVG image is used as is on the website.\n\nNote: If SVG uploads are required, it is recommended to use the TYPO3 extension svg_sanitizer (added to TYPO3 core since versions 9.5.28, 10.4.18 and 11.3.0) to prevent upload of malicious SVG files or to set up a strict Content Security Policy for the destination folder of uploaded images.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-gqcf-83rq-gpfr/GHSA-gqcf-83rq-gpfr.json b/advisories/github-reviewed/2021/09/GHSA-gqcf-83rq-gpfr/GHSA-gqcf-83rq-gpfr.json index 92588e4a431..741d62c8062 100644 --- a/advisories/github-reviewed/2021/09/GHSA-gqcf-83rq-gpfr/GHSA-gqcf-83rq-gpfr.json +++ b/advisories/github-reviewed/2021/09/GHSA-gqcf-83rq-gpfr/GHSA-gqcf-83rq-gpfr.json @@ -3,14 +3,10 @@ "id": "GHSA-gqcf-83rq-gpfr", "modified": "2021-09-14T18:35:35Z", "published": "2021-09-14T20:24:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Any storage file can be downloaded from p.sh if full server path is known", "details": "The default configuration for platform.sh (.platform.app.yaml) allows access to uploaded files if you know or can guess their location, regardless of whether roles grant content read access to the content containing those files. If you're using Legacy Bridge, the default configuration also allows access to certain legacy files that should not be readable, including the legacy var directory and extension directories.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-jpwx-ffjq-wr4w/GHSA-jpwx-ffjq-wr4w.json b/advisories/github-reviewed/2021/09/GHSA-jpwx-ffjq-wr4w/GHSA-jpwx-ffjq-wr4w.json index fc4aaf3a8a2..08737aab36d 100644 --- a/advisories/github-reviewed/2021/09/GHSA-jpwx-ffjq-wr4w/GHSA-jpwx-ffjq-wr4w.json +++ b/advisories/github-reviewed/2021/09/GHSA-jpwx-ffjq-wr4w/GHSA-jpwx-ffjq-wr4w.json @@ -3,14 +3,10 @@ "id": "GHSA-jpwx-ffjq-wr4w", "modified": "2021-09-03T20:10:38Z", "published": "2021-09-07T22:54:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Content object state fetch functions open to SQL injection", "details": "### Impact\nThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible.\n\n### Patches\nThe fix is distributed via Composer, see \"Patched versions\".\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-m489-xr35-fjxr/GHSA-m489-xr35-fjxr.json b/advisories/github-reviewed/2021/09/GHSA-m489-xr35-fjxr/GHSA-m489-xr35-fjxr.json index aeec82c352a..0a5abb3db15 100644 --- a/advisories/github-reviewed/2021/09/GHSA-m489-xr35-fjxr/GHSA-m489-xr35-fjxr.json +++ b/advisories/github-reviewed/2021/09/GHSA-m489-xr35-fjxr/GHSA-m489-xr35-fjxr.json @@ -3,14 +3,10 @@ "id": "GHSA-m489-xr35-fjxr", "modified": "2021-09-22T20:34:42Z", "published": "2021-09-22T20:35:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "Regular Expression Denial of Service in millisecond", "details": "Versions of `millisecond` prior to 0.1.2 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.\n\n\n## Proof of concept\n```\nvar ms = require('millisecond');\nvar genstr = function (len, chr) {\n var result = \"\";\n for (i=0; i<=len; i++) {\n result = result + chr;\n }\n\n return result;\n}\n\nms(genstr(process.argv[2], \"5\") + \" minutea\");\n```\n\n\n## Recommendation\n\nUpdate to version 0.1.2 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/09/GHSA-q4h9-46xg-m3x9/GHSA-q4h9-46xg-m3x9.json b/advisories/github-reviewed/2021/09/GHSA-q4h9-46xg-m3x9/GHSA-q4h9-46xg-m3x9.json index 1bb6ab6d0ab..31e579adf0c 100644 --- a/advisories/github-reviewed/2021/09/GHSA-q4h9-46xg-m3x9/GHSA-q4h9-46xg-m3x9.json +++ b/advisories/github-reviewed/2021/09/GHSA-q4h9-46xg-m3x9/GHSA-q4h9-46xg-m3x9.json @@ -3,14 +3,10 @@ "id": "GHSA-q4h9-46xg-m3x9", "modified": "2021-09-14T22:17:40Z", "published": "2021-09-15T20:22:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeable", "details": "### Impact\n\nUpgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. We will update this advisory with more information soon.\n\n### Patches\n\nA fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`.\n\n### Workarounds\n\nInitialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301).\n\n### References\n\nA post-mortem will be published in a few days in the [OpenZeppelin Forum](https://forum.openzeppelin.com/).\n\n### For more information\n\nIf you have any questions or comments about this advisory, or need assistance executing the mitigation, email us at security@openzeppelin.com.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-09-14T22:17:40Z", diff --git a/advisories/github-reviewed/2021/09/GHSA-rf3w-29h3-r636/GHSA-rf3w-29h3-r636.json b/advisories/github-reviewed/2021/09/GHSA-rf3w-29h3-r636/GHSA-rf3w-29h3-r636.json index 31fecc32413..c726c57d2ce 100644 --- a/advisories/github-reviewed/2021/09/GHSA-rf3w-29h3-r636/GHSA-rf3w-29h3-r636.json +++ b/advisories/github-reviewed/2021/09/GHSA-rf3w-29h3-r636/GHSA-rf3w-29h3-r636.json @@ -8,9 +8,7 @@ ], "summary": "Arbitrary Code Execution in feehi/cms", "details": "An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/10/GHSA-3r9x-mjrm-2725/GHSA-3r9x-mjrm-2725.json b/advisories/github-reviewed/2021/10/GHSA-3r9x-mjrm-2725/GHSA-3r9x-mjrm-2725.json index c483db915bb..f3c7d99ae1a 100644 --- a/advisories/github-reviewed/2021/10/GHSA-3r9x-mjrm-2725/GHSA-3r9x-mjrm-2725.json +++ b/advisories/github-reviewed/2021/10/GHSA-3r9x-mjrm-2725/GHSA-3r9x-mjrm-2725.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-10-08T22:09:39Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-7c7g-72q7-4xhm/GHSA-7c7g-72q7-4xhm.json b/advisories/github-reviewed/2021/10/GHSA-7c7g-72q7-4xhm/GHSA-7c7g-72q7-4xhm.json index b0c5ed40bd4..5a615d60ac5 100644 --- a/advisories/github-reviewed/2021/10/GHSA-7c7g-72q7-4xhm/GHSA-7c7g-72q7-4xhm.json +++ b/advisories/github-reviewed/2021/10/GHSA-7c7g-72q7-4xhm/GHSA-7c7g-72q7-4xhm.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-10-08T22:15:48Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-fr58-2xhv-qp3w/GHSA-fr58-2xhv-qp3w.json b/advisories/github-reviewed/2021/10/GHSA-fr58-2xhv-qp3w/GHSA-fr58-2xhv-qp3w.json index 03cda33cb42..2b575bd7c62 100644 --- a/advisories/github-reviewed/2021/10/GHSA-fr58-2xhv-qp3w/GHSA-fr58-2xhv-qp3w.json +++ b/advisories/github-reviewed/2021/10/GHSA-fr58-2xhv-qp3w/GHSA-fr58-2xhv-qp3w.json @@ -95,9 +95,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-10-08T14:44:47Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-j23j-q57m-63v3/GHSA-j23j-q57m-63v3.json b/advisories/github-reviewed/2021/10/GHSA-j23j-q57m-63v3/GHSA-j23j-q57m-63v3.json index f52e9e0a1ed..52a4f1b1a9c 100644 --- a/advisories/github-reviewed/2021/10/GHSA-j23j-q57m-63v3/GHSA-j23j-q57m-63v3.json +++ b/advisories/github-reviewed/2021/10/GHSA-j23j-q57m-63v3/GHSA-j23j-q57m-63v3.json @@ -3,9 +3,7 @@ "id": "GHSA-j23j-q57m-63v3", "modified": "2021-10-13T17:39:25Z", "published": "2021-10-13T18:54:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Denial of service in DataCommunicator class in Vaadin 8", "details": "Missing check in `DataCommunicator` class in `com.vaadin:vaadin-server` versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.", "severity": [ diff --git a/advisories/github-reviewed/2021/10/GHSA-m5v7-pr32-mjx2/GHSA-m5v7-pr32-mjx2.json b/advisories/github-reviewed/2021/10/GHSA-m5v7-pr32-mjx2/GHSA-m5v7-pr32-mjx2.json index d26eab18ea1..acbaafd971f 100644 --- a/advisories/github-reviewed/2021/10/GHSA-m5v7-pr32-mjx2/GHSA-m5v7-pr32-mjx2.json +++ b/advisories/github-reviewed/2021/10/GHSA-m5v7-pr32-mjx2/GHSA-m5v7-pr32-mjx2.json @@ -81,9 +81,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-10-08T22:26:02Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-m6m5-pp4g-fcc8/GHSA-m6m5-pp4g-fcc8.json b/advisories/github-reviewed/2021/10/GHSA-m6m5-pp4g-fcc8/GHSA-m6m5-pp4g-fcc8.json index eb654016031..2906ee818ec 100644 --- a/advisories/github-reviewed/2021/10/GHSA-m6m5-pp4g-fcc8/GHSA-m6m5-pp4g-fcc8.json +++ b/advisories/github-reviewed/2021/10/GHSA-m6m5-pp4g-fcc8/GHSA-m6m5-pp4g-fcc8.json @@ -3,9 +3,7 @@ "id": "GHSA-m6m5-pp4g-fcc8", "modified": "2021-10-06T16:48:49Z", "published": "2021-10-06T17:47:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "S3 storage write is not aborted on errors leading to unbounded memory usage", "details": "### Impact\n\nAnyone using storage.blob.s3 introduced in 0.5.0 with storage.imapsql.\n```\nstorage.imapsql local_mailboxes {\n ...\n msg_store s3 {\n ...\n }\n}\n```\n\n### Patches\n\nThe relevant commit is pushed to master and will be included in the 0.5.1 release.\n\nNo special handling of the issue has been done due to the small amount of affected users.\n\n### Workarounds\n\nNone.\n\n### References\n\n* Original report: https://github.com/foxcpp/maddy/issues/395\n* Fix: https://github.com/foxcpp/maddy/commit/07c8495ee4394fabbf5aac4df8aebeafb2fb29d8", "severity": [ diff --git a/advisories/github-reviewed/2021/10/GHSA-mcwm-2wmc-6hv4/GHSA-mcwm-2wmc-6hv4.json b/advisories/github-reviewed/2021/10/GHSA-mcwm-2wmc-6hv4/GHSA-mcwm-2wmc-6hv4.json index 81932a98e04..a77724395db 100644 --- a/advisories/github-reviewed/2021/10/GHSA-mcwm-2wmc-6hv4/GHSA-mcwm-2wmc-6hv4.json +++ b/advisories/github-reviewed/2021/10/GHSA-mcwm-2wmc-6hv4/GHSA-mcwm-2wmc-6hv4.json @@ -90,9 +90,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-10-05T19:41:18Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-pqjj-6f5q-gqph/GHSA-pqjj-6f5q-gqph.json b/advisories/github-reviewed/2021/10/GHSA-pqjj-6f5q-gqph/GHSA-pqjj-6f5q-gqph.json index 6192aa2bc6b..1632eb8aca5 100644 --- a/advisories/github-reviewed/2021/10/GHSA-pqjj-6f5q-gqph/GHSA-pqjj-6f5q-gqph.json +++ b/advisories/github-reviewed/2021/10/GHSA-pqjj-6f5q-gqph/GHSA-pqjj-6f5q-gqph.json @@ -87,9 +87,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-10-08T14:35:41Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-q324-q795-2q5p/GHSA-q324-q795-2q5p.json b/advisories/github-reviewed/2021/10/GHSA-q324-q795-2q5p/GHSA-q324-q795-2q5p.json index 75a936518a1..edb44745f38 100644 --- a/advisories/github-reviewed/2021/10/GHSA-q324-q795-2q5p/GHSA-q324-q795-2q5p.json +++ b/advisories/github-reviewed/2021/10/GHSA-q324-q795-2q5p/GHSA-q324-q795-2q5p.json @@ -3,14 +3,10 @@ "id": "GHSA-q324-q795-2q5p", "modified": "2021-10-11T18:40:44Z", "published": "2021-10-12T16:05:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Path traversal when using `preview-docs` when working dir contains files with question mark `?` in name", "details": "### Impact\n`preview-docs` command allows path traversal if current working dir contains files with question mark `?` in name and attacker knows the name.\n\n### Patches\nIt was patched starting from 1.0.0-beta.59\n\n### Workarounds\nDo not run openapi-cli preview-docs command in the folder which contains files with question mark `?` in name.\n\n### References\nhttps://github.com/Redocly/openapi-cli/pull/347\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [@redocly/openapi-cli](https://github.com/Redocly/openapi-cli)\n* Email us at [security@redocly.com](mailto:security@redocly.com)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -50,9 +46,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-10-11T18:40:44Z", diff --git a/advisories/github-reviewed/2021/10/GHSA-qh54-9vc5-m9fg/GHSA-qh54-9vc5-m9fg.json b/advisories/github-reviewed/2021/10/GHSA-qh54-9vc5-m9fg/GHSA-qh54-9vc5-m9fg.json index d49261f19eb..288b1dc9d0d 100644 --- a/advisories/github-reviewed/2021/10/GHSA-qh54-9vc5-m9fg/GHSA-qh54-9vc5-m9fg.json +++ b/advisories/github-reviewed/2021/10/GHSA-qh54-9vc5-m9fg/GHSA-qh54-9vc5-m9fg.json @@ -3,9 +3,7 @@ "id": "GHSA-qh54-9vc5-m9fg", "modified": "2021-10-11T21:16:02Z", "published": "2021-10-12T16:06:30Z", - "aliases": [ - - ], + "aliases": [], "summary": "MD5 hash support in github.com/foxcpp/maddy", "details": "### Impact\n\nThis vulnerability affects maddy 0.5.1, 0.5.0 users using auth.shadow module\nand an extremely outdated system that still allows MD5 hashes in \n/etc/shadows.\n\n### Patches\n\nPatch is available as part of the 0.5.2 release.\n\n### Workarounds\n\nEnsure MD5 hashes are not present in /etc/shadow.\n", "severity": [ diff --git a/advisories/github-reviewed/2021/10/GHSA-xrpj-f9v6-2332/GHSA-xrpj-f9v6-2332.json b/advisories/github-reviewed/2021/10/GHSA-xrpj-f9v6-2332/GHSA-xrpj-f9v6-2332.json index d2284a2ea5f..0a977e29c83 100644 --- a/advisories/github-reviewed/2021/10/GHSA-xrpj-f9v6-2332/GHSA-xrpj-f9v6-2332.json +++ b/advisories/github-reviewed/2021/10/GHSA-xrpj-f9v6-2332/GHSA-xrpj-f9v6-2332.json @@ -4,9 +4,7 @@ "modified": "2021-10-18T19:08:54Z", "published": "2021-10-04T20:12:45Z", "withdrawn": "2021-10-18T19:05:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "CSV injection in Craft CMS", "details": "# Withdrawn \n\nDuplicate of GHSA-h7vq-5qgw-jwwq", "severity": [ diff --git a/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json b/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json index eaab47a8e73..40f9b8289f1 100644 --- a/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json +++ b/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json @@ -8,9 +8,7 @@ ], "summary": "Information disclosure vulnerability in OnionShare", "details": "An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature. ", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-q886-75m2-vff8/GHSA-q886-75m2-vff8.json b/advisories/github-reviewed/2022/05/GHSA-q886-75m2-vff8/GHSA-q886-75m2-vff8.json index b7734a91721..4c7275ad92f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-q886-75m2-vff8/GHSA-q886-75m2-vff8.json +++ b/advisories/github-reviewed/2022/05/GHSA-q886-75m2-vff8/GHSA-q886-75m2-vff8.json @@ -4,9 +4,7 @@ "modified": "2024-04-29T09:49:55Z", "published": "2022-05-24T17:32:30Z", "withdrawn": "2024-04-29T09:49:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: Unauthorized privilege escalation in Mod module", "details": "# Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-mp9m-g7qj-6vqr. This link is maintained to preserve external references.\n\n# Original Description\n\nRed Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a high privilege level within the guild to bypass hierarchy checks when the application is in a specific condition that is beyond that user's control. By abusing this exploit, it is possible to perform destructive actions within the guild the user has high privileges in. This exploit has been fixed in version 3.4.1. As a workaround, unloading the Mod module with unload mod or, disabling the massban command with command disable global massban can render this exploit not accessible. We still highly recommend updating to 3.4.1 to completely patch this issue.", "severity": [ diff --git a/advisories/github-reviewed/2022/10/GHSA-2qc6-mcvw-92cw/GHSA-2qc6-mcvw-92cw.json b/advisories/github-reviewed/2022/10/GHSA-2qc6-mcvw-92cw/GHSA-2qc6-mcvw-92cw.json index b37bb8b8b4d..2c586b8ccd9 100644 --- a/advisories/github-reviewed/2022/10/GHSA-2qc6-mcvw-92cw/GHSA-2qc6-mcvw-92cw.json +++ b/advisories/github-reviewed/2022/10/GHSA-2qc6-mcvw-92cw/GHSA-2qc6-mcvw-92cw.json @@ -3,14 +3,10 @@ "id": "GHSA-2qc6-mcvw-92cw", "modified": "2022-10-18T18:13:48Z", "published": "2022-10-18T18:12:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "Update bundled libxml2 to v2.10.3 to resolve multiple CVEs", "details": "### Summary\n\nNokogiri v1.13.9 upgrades the packaged version of its dependency libxml2 to [v2.10.3](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.3) from v2.9.14.\n\nlibxml2 v2.10.3 addresses the following known vulnerabilities:\n\n- [CVE-2022-2309](https://nvd.nist.gov/vuln/detail/CVE-2022-2309)\n- [CVE-2022-40304](https://nvd.nist.gov/vuln/detail/CVE-2022-40304)\n- [CVE-2022-40303](https://nvd.nist.gov/vuln/detail/CVE-2022-40303)\n\nPlease note that this advisory only applies to the CRuby implementation of Nokogiri `< 1.13.9`, and only if the _packaged_ libraries are being used. If you've overridden defaults at installation time to use _system_ libraries instead of packaged libraries, you should instead pay attention to your distro's `libxml2` release announcements.\n\n\n### Mitigation\n\nUpgrade to Nokogiri `>= 1.13.9`.\n\nUsers who are unable to upgrade Nokogiri may also choose a more complicated mitigation: compile and link Nokogiri against external libraries libxml2 `>= 2.10.3` which will also address these same issues.\n\n\n### Impact\n\n#### libxml2 [CVE-2022-2309](https://nvd.nist.gov/vuln/detail/CVE-2022-2309)\n\n- **CVSS3 score**: Under evaluation\n- **Type**: Denial of service\n- **Description**: NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.\n\nNokogiri maintainers investigated at #2620 and determined this CVE does not affect Nokogiri users.\n\n\n#### libxml2 [CVE-2022-40304](https://nvd.nist.gov/vuln/detail/CVE-2022-40304)\n\n- **CVSS3 score**: Unspecified upstream\n- **Type**: Data corruption, denial of service\n- **Description**: When an entity reference cycle is detected, the entity content is cleared by setting its first byte to zero. But the entity content might be allocated from a dict. In this case, the dict entry becomes corrupted leading to all kinds of logic errors, including memory errors like double-frees.\n\nSee https://gitlab.gnome.org/GNOME/libxml2/-/commit/644a89e080bced793295f61f18aac8cfad6bece2\n\n\n#### libxml2 [CVE-2022-40303](https://nvd.nist.gov/vuln/detail/CVE-2022-40303)\n\n- **CVSS3 score**: Unspecified upstream\n- **Type**: Integer overflow\n- **Description**: Integer overflows with XML_PARSE_HUGE\n\nSee https://gitlab.gnome.org/GNOME/libxml2/-/commit/c846986356fc149915a74972bf198abc266bc2c0\n\n\n### References\n\n- [libxml2 release notes](https://gitlab.gnome.org/GNOME/libxml2/-/releases)\n- [CVE-2022-2309](https://nvd.nist.gov/vuln/detail/CVE-2022-2309)\n- [CVE-2022-40304](https://nvd.nist.gov/vuln/detail/CVE-2022-40304)\n- [CVE-2022-40303](https://nvd.nist.gov/vuln/detail/CVE-2022-40303)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-10-18T18:12:31Z", diff --git a/advisories/github-reviewed/2022/10/GHSA-j92c-mmf7-j5x5/GHSA-j92c-mmf7-j5x5.json b/advisories/github-reviewed/2022/10/GHSA-j92c-mmf7-j5x5/GHSA-j92c-mmf7-j5x5.json index e61096f107f..f4ce65639ee 100644 --- a/advisories/github-reviewed/2022/10/GHSA-j92c-mmf7-j5x5/GHSA-j92c-mmf7-j5x5.json +++ b/advisories/github-reviewed/2022/10/GHSA-j92c-mmf7-j5x5/GHSA-j92c-mmf7-j5x5.json @@ -3,14 +3,10 @@ "id": "GHSA-j92c-mmf7-j5x5", "modified": "2022-10-18T17:27:36Z", "published": "2022-10-18T17:27:36Z", - "aliases": [ - - ], + "aliases": [], "summary": "Potential inter-blockchain communication (IBC) protocol compromise via \"Dragonberry\" vulnerability in cheqd", "details": "### Impact\nThis vulnerability affects IBC transfers due to a security vulnerability dubbed \"Dragonberry\" upstream in [Cosmos SDK](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9). The vulnerability could allow malicious attackers to compromise chain-to-chain IBC transfers.\n\nThere is no vulnerability in the DID/resource modules for cheqd-node.\n\n### Patches\nNode operators are requested to upgrade to [cheqd-node v0.6.9](https://github.com/cheqd/cheqd-node/releases/tag/0.6.9) as soon as possible. Installation instructions are in the release notes. Please do not install any beta/pre-release versions.\n\n### Workarounds\nNo. The patch takes effect when more than 2/3rds of the voting power of the cheqd network has upgraded to this patch.\n\nAn emergency hotfix was released previously under v0.6.8 but this is now deprecated since [Cosmos SDK v0.45.9](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9) officially fixes this upstream.\n\n### References\n- [IBC Security Advisory on \"Dragonberry\"](https://forum.cosmos.network/t/ibc-security-advisory-dragonberry/7702/1) (and [associated security vulnerability \"Dragonfruit\"](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-dragonfruit/7614))\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [cheqd-node repo](https://github.com/cheqd/cheqd-node/issues)\n* Email us at [security-github@cheqd.io](mailto:security-github@cheqd.io)\n* Message us on our community [Slack](http://cheqd.link/join-cheqd-slack) or [Discord](http://cheqd.link/discord-github)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-10-18T17:27:36Z", diff --git a/advisories/github-reviewed/2022/11/GHSA-394j-x37r-2q27/GHSA-394j-x37r-2q27.json b/advisories/github-reviewed/2022/11/GHSA-394j-x37r-2q27/GHSA-394j-x37r-2q27.json index 2c50ff5dd4a..546de53023c 100644 --- a/advisories/github-reviewed/2022/11/GHSA-394j-x37r-2q27/GHSA-394j-x37r-2q27.json +++ b/advisories/github-reviewed/2022/11/GHSA-394j-x37r-2q27/GHSA-394j-x37r-2q27.json @@ -3,14 +3,10 @@ "id": "GHSA-394j-x37r-2q27", "modified": "2022-11-10T23:54:04Z", "published": "2022-11-10T23:54:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Ibexa DXP users with the Company admin role can assign any role to any user", "details": "Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.\n\nThe role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-11-10T23:54:04Z", diff --git a/advisories/github-reviewed/2022/11/GHSA-3p7g-wrgg-wq45/GHSA-3p7g-wrgg-wq45.json b/advisories/github-reviewed/2022/11/GHSA-3p7g-wrgg-wq45/GHSA-3p7g-wrgg-wq45.json index cf1bcaa8606..cdb246876e7 100644 --- a/advisories/github-reviewed/2022/11/GHSA-3p7g-wrgg-wq45/GHSA-3p7g-wrgg-wq45.json +++ b/advisories/github-reviewed/2022/11/GHSA-3p7g-wrgg-wq45/GHSA-3p7g-wrgg-wq45.json @@ -3,14 +3,10 @@ "id": "GHSA-3p7g-wrgg-wq45", "modified": "2022-11-10T21:35:49Z", "published": "2022-11-10T21:35:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "GraphQL queries can expose password hashes", "details": "### Impact\nUnauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically but not necessarily limited to administrators and editors.\n\n### Patches\nAffected versions: Ibexa DXP v3.3.\\*, v4.2.\\*, eZ Platform v2.5.\\*\nResolving versions: Ibexa DXP v3.3.28, v4.2.3, eZ Platform v2.5.31\n\n### Workarounds\nRemove the \"passwordHash\" entry from \"src/bundle/Resources/config/graphql/User.types.yaml\" in the GraphQL package, and other properties like hash type, email, login if you prefer.\n\n### References\n\nThis issue was reported to us by Philippe Tranca (\"trancap\") of the company Lexfo. We are very grateful for their research, and responsible disclosure to us of this critical vulnerability. \n\n### For more information\nIf you have any questions or comments about this advisory, please contact Support via your service portal.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/11/GHSA-3qmc-2r76-4rqp/GHSA-3qmc-2r76-4rqp.json b/advisories/github-reviewed/2022/11/GHSA-3qmc-2r76-4rqp/GHSA-3qmc-2r76-4rqp.json index 6f24ade1ee1..032d198b7ef 100644 --- a/advisories/github-reviewed/2022/11/GHSA-3qmc-2r76-4rqp/GHSA-3qmc-2r76-4rqp.json +++ b/advisories/github-reviewed/2022/11/GHSA-3qmc-2r76-4rqp/GHSA-3qmc-2r76-4rqp.json @@ -3,9 +3,7 @@ "id": "GHSA-3qmc-2r76-4rqp", "modified": "2022-11-10T15:51:01Z", "published": "2022-11-10T15:51:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "Redwood is vulnerable to account takeover via dbAuth \"forgot-password\" ", "details": "# Impact\n\n_What kind of vulnerability is it? Who is impacted?_\n\nThis is an API vulnerability in Redwood's [dbAuth], specifically the dbAuth forgot password feature:\n- only projects with the dbAuth \"forgot password\" feature are affected\n- this vulnerability was introduced in v0.38.0\n\n## User Accounts are Vulnerable to Takeover (Hijacking)\n\nA reset token for any user can be obtained given knowledge of their username or email via the forgot-password API. With the leaked reset token, a malicious user could request to reset a user's password, changing their credentials and gaining access to their account.\n\n## How to Determine if Projects have been Attacked\n\nTo determine if a project has been attacked, we recommend checking logs for suspicious activity; namely, the volume of requests to the forgot-password API using emails that don't exist. Another indication is if users inform you that they can't access their accounts.\n\nIf you have question or concerns, reach out via the \"For More Information\" section below.\n\n# Patch Releases Available\n\n**The problem has been patched on the v3 and v2 release lines.** Users should upgrade to **v3.3.1+** or **v2.2.5+** respectively.\n\n## Workarounds\n\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nWe recommend upgrading to the Patch Releases above. If upgrading is not possible, there are several workarounds:\n\n### Manually strip out `resetToken` and `resetTokenExpiresAt` in the `forgotPassword.handler()`\n\nUsers on all release lines can have their `forgotPassword.handler()` function strip out the sensitive fields manually before returning\n\n```js\nhandler: (user) => {\n // your code to notify/email user of the link to reset their password...\n\n const = { resetToken, resetTokenExpiresAt, ...rest }\n\n return rest\n}\n```\n\n### Use `yarn patch` to manually apply the fix\n\nUsers on v3 and v2 can use [`yarn patch`] to apply the fix if they're using yarn v3. See the dbAuth \"forgot-password\" Account Takeover Vulnerability high gist for instructions. \n\n### Disable the forgot password flow entirely v3 only\n\nUsers on v3 can disable the forgot password flow entirely.", "severity": [ @@ -81,9 +79,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-11-10T15:51:01Z", diff --git a/advisories/github-reviewed/2022/11/GHSA-58h5-h554-429q/GHSA-58h5-h554-429q.json b/advisories/github-reviewed/2022/11/GHSA-58h5-h554-429q/GHSA-58h5-h554-429q.json index da4460b51ec..d3fa5e978ff 100644 --- a/advisories/github-reviewed/2022/11/GHSA-58h5-h554-429q/GHSA-58h5-h554-429q.json +++ b/advisories/github-reviewed/2022/11/GHSA-58h5-h554-429q/GHSA-58h5-h554-429q.json @@ -3,14 +3,10 @@ "id": "GHSA-58h5-h554-429q", "modified": "2022-11-10T21:42:09Z", "published": "2022-11-10T21:42:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "ezplatform-admin-ui vulnerable to Cross-Site Scripting (XSS) ", "details": "It is possible to inject JavaScript XSS in the content type entries \"name\" and \"short name\". To exploit this, one must already have permission to edit content types, which limits it in many cases to people who are already administrators. However, please verify which users have this permission. The fix ensures any injections are escaped.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/11/GHSA-7644-cxp8-h23r/GHSA-7644-cxp8-h23r.json b/advisories/github-reviewed/2022/11/GHSA-7644-cxp8-h23r/GHSA-7644-cxp8-h23r.json index 1f2b3fbb761..9f9bf1141ff 100644 --- a/advisories/github-reviewed/2022/11/GHSA-7644-cxp8-h23r/GHSA-7644-cxp8-h23r.json +++ b/advisories/github-reviewed/2022/11/GHSA-7644-cxp8-h23r/GHSA-7644-cxp8-h23r.json @@ -3,14 +3,10 @@ "id": "GHSA-7644-cxp8-h23r", "modified": "2022-11-10T23:52:31Z", "published": "2022-11-10T23:52:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "ibexa/admin-ui vulnerable to Cross-site Scripting in content type name/shortname", "details": "Critical severity. It is possible to inject JavaScript XSS in the content type entries \"name\" and \"short name\". To exploit this, one must already have permission to edit content types, which limits it in many cases to people who are already administrators. However, please verify which users have this permission. The fix ensures any injections are escaped.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-11-10T23:52:31Z", diff --git a/advisories/github-reviewed/2022/11/GHSA-98pf-gfh3-x3mp/GHSA-98pf-gfh3-x3mp.json b/advisories/github-reviewed/2022/11/GHSA-98pf-gfh3-x3mp/GHSA-98pf-gfh3-x3mp.json index 0c0ce7254b2..31f7047ac2f 100644 --- a/advisories/github-reviewed/2022/11/GHSA-98pf-gfh3-x3mp/GHSA-98pf-gfh3-x3mp.json +++ b/advisories/github-reviewed/2022/11/GHSA-98pf-gfh3-x3mp/GHSA-98pf-gfh3-x3mp.json @@ -3,14 +3,10 @@ "id": "GHSA-98pf-gfh3-x3mp", "modified": "2022-11-10T16:02:51Z", "published": "2022-11-10T16:02:51Z", - "aliases": [ - - ], + "aliases": [], "summary": "Read the Docs vulnerable to Cross-Site Scripting (XSS)", "details": "### Impact\n\nThis vulnerability allowed a malicious user to serve arbitrary HTML files from the main application domain (readthedocs[.]org/readthedocs[.]com) by exploiting a vulnerability in the code that serves downloadable content from a project. \n\nExploiting this would have required the attacker to get a logged-in user to visit the malicious URL, which would have allowed the attacker to take control of the user's session with JavaScript (making requests to the API/site on behalf of the user). This URL would have looked something like `hxxps[:]//readthedocs[.]org/projects/attacker-project/downloads/html/version-with-javascript-attack/`.\n\n### Patches\n\nThis issue has been patched in our 8.8.1 release.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/11/GHSA-g6jc-xrc3-4wwq/GHSA-g6jc-xrc3-4wwq.json b/advisories/github-reviewed/2022/11/GHSA-g6jc-xrc3-4wwq/GHSA-g6jc-xrc3-4wwq.json index 2877dc462be..c27724f22ea 100644 --- a/advisories/github-reviewed/2022/11/GHSA-g6jc-xrc3-4wwq/GHSA-g6jc-xrc3-4wwq.json +++ b/advisories/github-reviewed/2022/11/GHSA-g6jc-xrc3-4wwq/GHSA-g6jc-xrc3-4wwq.json @@ -3,14 +3,10 @@ "id": "GHSA-g6jc-xrc3-4wwq", "modified": "2022-11-10T23:56:13Z", "published": "2022-11-10T23:56:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Ibexa DXP users with the Company admin role can assign any role to any user", "details": "Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.\n\nThe role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-11-10T23:56:13Z", diff --git a/advisories/github-reviewed/2022/11/GHSA-r4jg-5v89-9v62/GHSA-r4jg-5v89-9v62.json b/advisories/github-reviewed/2022/11/GHSA-r4jg-5v89-9v62/GHSA-r4jg-5v89-9v62.json index d157680e548..96d06830e78 100644 --- a/advisories/github-reviewed/2022/11/GHSA-r4jg-5v89-9v62/GHSA-r4jg-5v89-9v62.json +++ b/advisories/github-reviewed/2022/11/GHSA-r4jg-5v89-9v62/GHSA-r4jg-5v89-9v62.json @@ -9,9 +9,7 @@ ], "summary": "Withdrawn: Octocat.js vulnerable to code injection", "details": "## Withdrawn\n\nThis advisory has been withdrawn because it is a test.\n\n## Original Description\n\n### Impact\nUsers can include their own images for accessories via provided URLs. These URLs are not validated and can result in execution of injected code.\n\n### Patches\nThis vulnerability was fixed in version 1.2 of octocat.js\n\n### Workarounds\nDirectly exposing rendered images to a website can introduce the vulnerability to users. To avoid, writing an image to disk then using that image in an image element in HTML mitigates the risk.\n\n### References\nTo render the file correctly, see documentation at `readme.md`\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the octo.js repository](http://github.com/octocademy/octocat.js/issues)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2022/05/GHSA-223m-fhfm-47hr/GHSA-223m-fhfm-47hr.json b/advisories/unreviewed/2022/05/GHSA-223m-fhfm-47hr/GHSA-223m-fhfm-47hr.json index e5d5e9488e2..de3a982a6e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-223m-fhfm-47hr/GHSA-223m-fhfm-47hr.json +++ b/advisories/unreviewed/2022/05/GHSA-223m-fhfm-47hr/GHSA-223m-fhfm-47hr.json @@ -7,12 +7,8 @@ "CVE-2009-0572" ], "details": "PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22hh-m93w-hpjq/GHSA-22hh-m93w-hpjq.json b/advisories/unreviewed/2022/05/GHSA-22hh-m93w-hpjq/GHSA-22hh-m93w-hpjq.json index 6e27a5e50c2..baca00c4548 100644 --- a/advisories/unreviewed/2022/05/GHSA-22hh-m93w-hpjq/GHSA-22hh-m93w-hpjq.json +++ b/advisories/unreviewed/2022/05/GHSA-22hh-m93w-hpjq/GHSA-22hh-m93w-hpjq.json @@ -7,12 +7,8 @@ "CVE-2009-0391" ], "details": "Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22jq-22rq-52q5/GHSA-22jq-22rq-52q5.json b/advisories/unreviewed/2022/05/GHSA-22jq-22rq-52q5/GHSA-22jq-22rq-52q5.json index 97c03f0f47f..cf65f2395be 100644 --- a/advisories/unreviewed/2022/05/GHSA-22jq-22rq-52q5/GHSA-22jq-22rq-52q5.json +++ b/advisories/unreviewed/2022/05/GHSA-22jq-22rq-52q5/GHSA-22jq-22rq-52q5.json @@ -7,12 +7,8 @@ "CVE-2009-0633" ], "details": "Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22q3-mmfp-g262/GHSA-22q3-mmfp-g262.json b/advisories/unreviewed/2022/05/GHSA-22q3-mmfp-g262/GHSA-22q3-mmfp-g262.json index c74f606558c..271385ab61e 100644 --- a/advisories/unreviewed/2022/05/GHSA-22q3-mmfp-g262/GHSA-22q3-mmfp-g262.json +++ b/advisories/unreviewed/2022/05/GHSA-22q3-mmfp-g262/GHSA-22q3-mmfp-g262.json @@ -7,12 +7,8 @@ "CVE-2009-0918" ], "details": "Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) \"external tools\" or (2) a crafted forensic image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-239r-c744-9rfp/GHSA-239r-c744-9rfp.json b/advisories/unreviewed/2022/05/GHSA-239r-c744-9rfp/GHSA-239r-c744-9rfp.json index b7d2f393869..39cc52313a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-239r-c744-9rfp/GHSA-239r-c744-9rfp.json +++ b/advisories/unreviewed/2022/05/GHSA-239r-c744-9rfp/GHSA-239r-c744-9rfp.json @@ -7,12 +7,8 @@ "CVE-2009-0505" ], "details": "The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23xg-g252-mcgr/GHSA-23xg-g252-mcgr.json b/advisories/unreviewed/2022/05/GHSA-23xg-g252-mcgr/GHSA-23xg-g252-mcgr.json index 0ed50635274..3356e73ab8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-23xg-g252-mcgr/GHSA-23xg-g252-mcgr.json +++ b/advisories/unreviewed/2022/05/GHSA-23xg-g252-mcgr/GHSA-23xg-g252-mcgr.json @@ -7,12 +7,8 @@ "CVE-2009-0302" ], "details": "SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-247g-wrq8-c568/GHSA-247g-wrq8-c568.json b/advisories/unreviewed/2022/05/GHSA-247g-wrq8-c568/GHSA-247g-wrq8-c568.json index aa41a3a9f2f..56b559f1323 100644 --- a/advisories/unreviewed/2022/05/GHSA-247g-wrq8-c568/GHSA-247g-wrq8-c568.json +++ b/advisories/unreviewed/2022/05/GHSA-247g-wrq8-c568/GHSA-247g-wrq8-c568.json @@ -7,12 +7,8 @@ "CVE-2009-0109" ], "details": "SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-249w-vq92-qr37/GHSA-249w-vq92-qr37.json b/advisories/unreviewed/2022/05/GHSA-249w-vq92-qr37/GHSA-249w-vq92-qr37.json index 6ac27120479..830e8a51d05 100644 --- a/advisories/unreviewed/2022/05/GHSA-249w-vq92-qr37/GHSA-249w-vq92-qr37.json +++ b/advisories/unreviewed/2022/05/GHSA-249w-vq92-qr37/GHSA-249w-vq92-qr37.json @@ -7,12 +7,8 @@ "CVE-2009-0716" ], "details": "Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service or obtain \"access\" via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24qg-x6r4-72m5/GHSA-24qg-x6r4-72m5.json b/advisories/unreviewed/2022/05/GHSA-24qg-x6r4-72m5/GHSA-24qg-x6r4-72m5.json index 0a2504b28c8..e6a081fbfe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-24qg-x6r4-72m5/GHSA-24qg-x6r4-72m5.json +++ b/advisories/unreviewed/2022/05/GHSA-24qg-x6r4-72m5/GHSA-24qg-x6r4-72m5.json @@ -7,12 +7,8 @@ "CVE-2009-0419" ], "details": "Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24w5-cg9p-q68p/GHSA-24w5-cg9p-q68p.json b/advisories/unreviewed/2022/05/GHSA-24w5-cg9p-q68p/GHSA-24w5-cg9p-q68p.json index f1e997ca1f1..b97ee253474 100644 --- a/advisories/unreviewed/2022/05/GHSA-24w5-cg9p-q68p/GHSA-24w5-cg9p-q68p.json +++ b/advisories/unreviewed/2022/05/GHSA-24w5-cg9p-q68p/GHSA-24w5-cg9p-q68p.json @@ -7,12 +7,8 @@ "CVE-2009-0389" ], "details": "Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2586-6m27-6w97/GHSA-2586-6m27-6w97.json b/advisories/unreviewed/2022/05/GHSA-2586-6m27-6w97/GHSA-2586-6m27-6w97.json index 8ec993a660a..74adf9c52ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-2586-6m27-6w97/GHSA-2586-6m27-6w97.json +++ b/advisories/unreviewed/2022/05/GHSA-2586-6m27-6w97/GHSA-2586-6m27-6w97.json @@ -7,12 +7,8 @@ "CVE-2009-0659" ], "details": "Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a long email field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25c8-fmh2-q3pg/GHSA-25c8-fmh2-q3pg.json b/advisories/unreviewed/2022/05/GHSA-25c8-fmh2-q3pg/GHSA-25c8-fmh2-q3pg.json index 56440345f8d..6b4415eb8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-25c8-fmh2-q3pg/GHSA-25c8-fmh2-q3pg.json +++ b/advisories/unreviewed/2022/05/GHSA-25c8-fmh2-q3pg/GHSA-25c8-fmh2-q3pg.json @@ -7,12 +7,8 @@ "CVE-2009-0503" ], "details": "IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25m5-7vr5-mvcx/GHSA-25m5-7vr5-mvcx.json b/advisories/unreviewed/2022/05/GHSA-25m5-7vr5-mvcx/GHSA-25m5-7vr5-mvcx.json index dbbd45a3ee0..cfd9334dd65 100644 --- a/advisories/unreviewed/2022/05/GHSA-25m5-7vr5-mvcx/GHSA-25m5-7vr5-mvcx.json +++ b/advisories/unreviewed/2022/05/GHSA-25m5-7vr5-mvcx/GHSA-25m5-7vr5-mvcx.json @@ -7,12 +7,8 @@ "CVE-2009-0471" ], "details": "Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-285r-jf89-jj3c/GHSA-285r-jf89-jj3c.json b/advisories/unreviewed/2022/05/GHSA-285r-jf89-jj3c/GHSA-285r-jf89-jj3c.json index 546661be1b9..6282b1308c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-285r-jf89-jj3c/GHSA-285r-jf89-jj3c.json +++ b/advisories/unreviewed/2022/05/GHSA-285r-jf89-jj3c/GHSA-285r-jf89-jj3c.json @@ -7,12 +7,8 @@ "CVE-2009-0904" ], "details": "The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via \"XML fuzzing attacks\" sent through SOAP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28gr-8m4j-v4j7/GHSA-28gr-8m4j-v4j7.json b/advisories/unreviewed/2022/05/GHSA-28gr-8m4j-v4j7/GHSA-28gr-8m4j-v4j7.json index 724c82685bb..91a137a0dca 100644 --- a/advisories/unreviewed/2022/05/GHSA-28gr-8m4j-v4j7/GHSA-28gr-8m4j-v4j7.json +++ b/advisories/unreviewed/2022/05/GHSA-28gr-8m4j-v4j7/GHSA-28gr-8m4j-v4j7.json @@ -7,12 +7,8 @@ "CVE-2009-0518" ], "details": "VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28h6-mgpp-9243/GHSA-28h6-mgpp-9243.json b/advisories/unreviewed/2022/05/GHSA-28h6-mgpp-9243/GHSA-28h6-mgpp-9243.json index 1331777acdd..b1583047a66 100644 --- a/advisories/unreviewed/2022/05/GHSA-28h6-mgpp-9243/GHSA-28h6-mgpp-9243.json +++ b/advisories/unreviewed/2022/05/GHSA-28h6-mgpp-9243/GHSA-28h6-mgpp-9243.json @@ -7,12 +7,8 @@ "CVE-2009-0513" ], "details": "Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-292m-835f-5m2c/GHSA-292m-835f-5m2c.json b/advisories/unreviewed/2022/05/GHSA-292m-835f-5m2c/GHSA-292m-835f-5m2c.json index 68192a0d28b..ccbb155f57e 100644 --- a/advisories/unreviewed/2022/05/GHSA-292m-835f-5m2c/GHSA-292m-835f-5m2c.json +++ b/advisories/unreviewed/2022/05/GHSA-292m-835f-5m2c/GHSA-292m-835f-5m2c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c6q-2f39-j65x/GHSA-2c6q-2f39-j65x.json b/advisories/unreviewed/2022/05/GHSA-2c6q-2f39-j65x/GHSA-2c6q-2f39-j65x.json index c7378ba4aa5..676604a008e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c6q-2f39-j65x/GHSA-2c6q-2f39-j65x.json +++ b/advisories/unreviewed/2022/05/GHSA-2c6q-2f39-j65x/GHSA-2c6q-2f39-j65x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2crq-wx4p-2m52/GHSA-2crq-wx4p-2m52.json b/advisories/unreviewed/2022/05/GHSA-2crq-wx4p-2m52/GHSA-2crq-wx4p-2m52.json index d69d2142743..a50b83d9560 100644 --- a/advisories/unreviewed/2022/05/GHSA-2crq-wx4p-2m52/GHSA-2crq-wx4p-2m52.json +++ b/advisories/unreviewed/2022/05/GHSA-2crq-wx4p-2m52/GHSA-2crq-wx4p-2m52.json @@ -7,12 +7,8 @@ "CVE-2009-0618" ], "details": "Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by reading configuration files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cw3-c36j-jxjj/GHSA-2cw3-c36j-jxjj.json b/advisories/unreviewed/2022/05/GHSA-2cw3-c36j-jxjj/GHSA-2cw3-c36j-jxjj.json index 2f48bd11072..df3f042db71 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cw3-c36j-jxjj/GHSA-2cw3-c36j-jxjj.json +++ b/advisories/unreviewed/2022/05/GHSA-2cw3-c36j-jxjj/GHSA-2cw3-c36j-jxjj.json @@ -7,12 +7,8 @@ "CVE-2009-0293" ], "details": "SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fxr-hrff-7m5h/GHSA-2fxr-hrff-7m5h.json b/advisories/unreviewed/2022/05/GHSA-2fxr-hrff-7m5h/GHSA-2fxr-hrff-7m5h.json index ab03824aeda..48c4cc9fed0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fxr-hrff-7m5h/GHSA-2fxr-hrff-7m5h.json +++ b/advisories/unreviewed/2022/05/GHSA-2fxr-hrff-7m5h/GHSA-2fxr-hrff-7m5h.json @@ -7,12 +7,8 @@ "CVE-2009-0639" ], "details": "PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2j6r-x87g-9p2g/GHSA-2j6r-x87g-9p2g.json b/advisories/unreviewed/2022/05/GHSA-2j6r-x87g-9p2g/GHSA-2j6r-x87g-9p2g.json index 2604d1a5ae4..d07b47fe7a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j6r-x87g-9p2g/GHSA-2j6r-x87g-9p2g.json +++ b/advisories/unreviewed/2022/05/GHSA-2j6r-x87g-9p2g/GHSA-2j6r-x87g-9p2g.json @@ -7,12 +7,8 @@ "CVE-2009-1008" ], "details": "Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jq8-xw89-gcg8/GHSA-2jq8-xw89-gcg8.json b/advisories/unreviewed/2022/05/GHSA-2jq8-xw89-gcg8/GHSA-2jq8-xw89-gcg8.json index 62f1640a3db..3f2a2f33695 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jq8-xw89-gcg8/GHSA-2jq8-xw89-gcg8.json +++ b/advisories/unreviewed/2022/05/GHSA-2jq8-xw89-gcg8/GHSA-2jq8-xw89-gcg8.json @@ -7,12 +7,8 @@ "CVE-2009-0311" ], "details": "The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m33-x3vv-rx8x/GHSA-2m33-x3vv-rx8x.json b/advisories/unreviewed/2022/05/GHSA-2m33-x3vv-rx8x/GHSA-2m33-x3vv-rx8x.json index e4ab173faf2..acfb95af885 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m33-x3vv-rx8x/GHSA-2m33-x3vv-rx8x.json +++ b/advisories/unreviewed/2022/05/GHSA-2m33-x3vv-rx8x/GHSA-2m33-x3vv-rx8x.json @@ -7,12 +7,8 @@ "CVE-2009-0609" ], "details": "Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mcr-hvvf-8r3g/GHSA-2mcr-hvvf-8r3g.json b/advisories/unreviewed/2022/05/GHSA-2mcr-hvvf-8r3g/GHSA-2mcr-hvvf-8r3g.json index b00383178be..58e20fb8d8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mcr-hvvf-8r3g/GHSA-2mcr-hvvf-8r3g.json +++ b/advisories/unreviewed/2022/05/GHSA-2mcr-hvvf-8r3g/GHSA-2mcr-hvvf-8r3g.json @@ -7,12 +7,8 @@ "CVE-2009-0346" ], "details": "The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2prp-j8qg-9534/GHSA-2prp-j8qg-9534.json b/advisories/unreviewed/2022/05/GHSA-2prp-j8qg-9534/GHSA-2prp-j8qg-9534.json index 37b18855884..1b057e9a5d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2prp-j8qg-9534/GHSA-2prp-j8qg-9534.json +++ b/advisories/unreviewed/2022/05/GHSA-2prp-j8qg-9534/GHSA-2prp-j8qg-9534.json @@ -7,12 +7,8 @@ "CVE-2009-0718" ], "details": "Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qf3-2mv6-pggh/GHSA-2qf3-2mv6-pggh.json b/advisories/unreviewed/2022/05/GHSA-2qf3-2mv6-pggh/GHSA-2qf3-2mv6-pggh.json index bfd5a9c796e..cd85d34b913 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qf3-2mv6-pggh/GHSA-2qf3-2mv6-pggh.json +++ b/advisories/unreviewed/2022/05/GHSA-2qf3-2mv6-pggh/GHSA-2qf3-2mv6-pggh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w2q-4rr5-39fw/GHSA-2w2q-4rr5-39fw.json b/advisories/unreviewed/2022/05/GHSA-2w2q-4rr5-39fw/GHSA-2w2q-4rr5-39fw.json index 5393797057f..dfdb93166ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w2q-4rr5-39fw/GHSA-2w2q-4rr5-39fw.json +++ b/advisories/unreviewed/2022/05/GHSA-2w2q-4rr5-39fw/GHSA-2w2q-4rr5-39fw.json @@ -7,12 +7,8 @@ "CVE-2009-0766" ], "details": "Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xwh-g8m2-c95g/GHSA-2xwh-g8m2-c95g.json b/advisories/unreviewed/2022/05/GHSA-2xwh-g8m2-c95g/GHSA-2xwh-g8m2-c95g.json index 233dacff7fb..95a1f478e35 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xwh-g8m2-c95g/GHSA-2xwh-g8m2-c95g.json +++ b/advisories/unreviewed/2022/05/GHSA-2xwh-g8m2-c95g/GHSA-2xwh-g8m2-c95g.json @@ -7,12 +7,8 @@ "CVE-2009-1007" ], "details": "Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xxm-3j3x-786w/GHSA-2xxm-3j3x-786w.json b/advisories/unreviewed/2022/05/GHSA-2xxm-3j3x-786w/GHSA-2xxm-3j3x-786w.json index c90f690bde4..fede071d9d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xxm-3j3x-786w/GHSA-2xxm-3j3x-786w.json +++ b/advisories/unreviewed/2022/05/GHSA-2xxm-3j3x-786w/GHSA-2xxm-3j3x-786w.json @@ -7,12 +7,8 @@ "CVE-2009-0390" ], "details": "Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3368-gjw8-34fq/GHSA-3368-gjw8-34fq.json b/advisories/unreviewed/2022/05/GHSA-3368-gjw8-34fq/GHSA-3368-gjw8-34fq.json index 9c238d82004..9a850315127 100644 --- a/advisories/unreviewed/2022/05/GHSA-3368-gjw8-34fq/GHSA-3368-gjw8-34fq.json +++ b/advisories/unreviewed/2022/05/GHSA-3368-gjw8-34fq/GHSA-3368-gjw8-34fq.json @@ -7,12 +7,8 @@ "CVE-2009-0906" ], "details": "The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-337w-wx22-4g94/GHSA-337w-wx22-4g94.json b/advisories/unreviewed/2022/05/GHSA-337w-wx22-4g94/GHSA-337w-wx22-4g94.json index 46dc3e256e8..1961b95b9d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-337w-wx22-4g94/GHSA-337w-wx22-4g94.json +++ b/advisories/unreviewed/2022/05/GHSA-337w-wx22-4g94/GHSA-337w-wx22-4g94.json @@ -7,12 +7,8 @@ "CVE-2009-0818" ], "details": "Cross-site scripting (XSS) vulnerability in the taxonomy_theme_admin_table_builder function (taxonomy_theme_admin.inc) in Taxonomy Theme module before 5.x-1.2, a module for Drupal, allows remote authenticated users with the \"administer taxonomy\" permission, or the ability to create pages when tagging is enabled, to inject arbitrary web script or HTML via the Vocabulary name (name parameter) to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-338x-rqm6-3p3h/GHSA-338x-rqm6-3p3h.json b/advisories/unreviewed/2022/05/GHSA-338x-rqm6-3p3h/GHSA-338x-rqm6-3p3h.json index a821f6924c3..57a2a7ec60a 100644 --- a/advisories/unreviewed/2022/05/GHSA-338x-rqm6-3p3h/GHSA-338x-rqm6-3p3h.json +++ b/advisories/unreviewed/2022/05/GHSA-338x-rqm6-3p3h/GHSA-338x-rqm6-3p3h.json @@ -7,12 +7,8 @@ "CVE-2009-0510" ], "details": "Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34jv-9f93-hq2f/GHSA-34jv-9f93-hq2f.json b/advisories/unreviewed/2022/05/GHSA-34jv-9f93-hq2f/GHSA-34jv-9f93-hq2f.json index f4051787f7c..8c3e5aa61b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-34jv-9f93-hq2f/GHSA-34jv-9f93-hq2f.json +++ b/advisories/unreviewed/2022/05/GHSA-34jv-9f93-hq2f/GHSA-34jv-9f93-hq2f.json @@ -7,12 +7,8 @@ "CVE-2009-0560" ], "details": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"Field Sanitization Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34xj-9w8p-f4vf/GHSA-34xj-9w8p-f4vf.json b/advisories/unreviewed/2022/05/GHSA-34xj-9w8p-f4vf/GHSA-34xj-9w8p-f4vf.json index 36844812588..4087dc567b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-34xj-9w8p-f4vf/GHSA-34xj-9w8p-f4vf.json +++ b/advisories/unreviewed/2022/05/GHSA-34xj-9w8p-f4vf/GHSA-34xj-9w8p-f4vf.json @@ -7,12 +7,8 @@ "CVE-2009-0637" ], "details": "The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35wm-rx84-28c3/GHSA-35wm-rx84-28c3.json b/advisories/unreviewed/2022/05/GHSA-35wm-rx84-28c3/GHSA-35wm-rx84-28c3.json index 7586114a964..6f7a7204819 100644 --- a/advisories/unreviewed/2022/05/GHSA-35wm-rx84-28c3/GHSA-35wm-rx84-28c3.json +++ b/advisories/unreviewed/2022/05/GHSA-35wm-rx84-28c3/GHSA-35wm-rx84-28c3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36x2-5xhq-cc55/GHSA-36x2-5xhq-cc55.json b/advisories/unreviewed/2022/05/GHSA-36x2-5xhq-cc55/GHSA-36x2-5xhq-cc55.json index b6bab1391a1..d555e50c07f 100644 --- a/advisories/unreviewed/2022/05/GHSA-36x2-5xhq-cc55/GHSA-36x2-5xhq-cc55.json +++ b/advisories/unreviewed/2022/05/GHSA-36x2-5xhq-cc55/GHSA-36x2-5xhq-cc55.json @@ -7,12 +7,8 @@ "CVE-2009-0336" ], "details": "Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-372q-vf52-472r/GHSA-372q-vf52-472r.json b/advisories/unreviewed/2022/05/GHSA-372q-vf52-472r/GHSA-372q-vf52-472r.json index 08c45147a36..d70f911a3f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-372q-vf52-472r/GHSA-372q-vf52-472r.json +++ b/advisories/unreviewed/2022/05/GHSA-372q-vf52-472r/GHSA-372q-vf52-472r.json @@ -7,12 +7,8 @@ "CVE-2009-0825" ], "details": "SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-373w-8gf3-3hvx/GHSA-373w-8gf3-3hvx.json b/advisories/unreviewed/2022/05/GHSA-373w-8gf3-3hvx/GHSA-373w-8gf3-3hvx.json index 45d1e289ad0..1dbb8b8843c 100644 --- a/advisories/unreviewed/2022/05/GHSA-373w-8gf3-3hvx/GHSA-373w-8gf3-3hvx.json +++ b/advisories/unreviewed/2022/05/GHSA-373w-8gf3-3hvx/GHSA-373w-8gf3-3hvx.json @@ -7,12 +7,8 @@ "CVE-2009-0555" ], "details": "Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media Speech codec, aka \"Windows Media Runtime Voice Sample Rate Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3969-vr99-qg5h/GHSA-3969-vr99-qg5h.json b/advisories/unreviewed/2022/05/GHSA-3969-vr99-qg5h/GHSA-3969-vr99-qg5h.json index e8a82a15c88..654c5b6256e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3969-vr99-qg5h/GHSA-3969-vr99-qg5h.json +++ b/advisories/unreviewed/2022/05/GHSA-3969-vr99-qg5h/GHSA-3969-vr99-qg5h.json @@ -7,12 +7,8 @@ "CVE-2009-0098" ], "details": "Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka \"Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39p5-5r55-6gg5/GHSA-39p5-5r55-6gg5.json b/advisories/unreviewed/2022/05/GHSA-39p5-5r55-6gg5/GHSA-39p5-5r55-6gg5.json index e95612d96df..9ca4df6fab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-39p5-5r55-6gg5/GHSA-39p5-5r55-6gg5.json +++ b/advisories/unreviewed/2022/05/GHSA-39p5-5r55-6gg5/GHSA-39p5-5r55-6gg5.json @@ -7,12 +7,8 @@ "CVE-2009-0892" ], "details": "The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in \"specific scenarios\" related to a forced logout.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39qj-vvc5-79wf/GHSA-39qj-vvc5-79wf.json b/advisories/unreviewed/2022/05/GHSA-39qj-vvc5-79wf/GHSA-39qj-vvc5-79wf.json index f6c3afe2829..0511d0b8681 100644 --- a/advisories/unreviewed/2022/05/GHSA-39qj-vvc5-79wf/GHSA-39qj-vvc5-79wf.json +++ b/advisories/unreviewed/2022/05/GHSA-39qj-vvc5-79wf/GHSA-39qj-vvc5-79wf.json @@ -7,12 +7,8 @@ "CVE-2009-0654" ], "details": "Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design \"accepted end-to-end correlation as an attack that is too expensive to solve.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cj4-7pqc-pf46/GHSA-3cj4-7pqc-pf46.json b/advisories/unreviewed/2022/05/GHSA-3cj4-7pqc-pf46/GHSA-3cj4-7pqc-pf46.json index 990582b1a28..524e1e010ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cj4-7pqc-pf46/GHSA-3cj4-7pqc-pf46.json +++ b/advisories/unreviewed/2022/05/GHSA-3cj4-7pqc-pf46/GHSA-3cj4-7pqc-pf46.json @@ -7,12 +7,8 @@ "CVE-2009-0857" ], "details": "Cross-site scripting (XSS) vulnerability in /prm/reports in the Performance Reporting Module (PRM) for Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: this can be leveraged for access to the SunMC Web Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cqq-q3c4-9jg6/GHSA-3cqq-q3c4-9jg6.json b/advisories/unreviewed/2022/05/GHSA-3cqq-q3c4-9jg6/GHSA-3cqq-q3c4-9jg6.json index 255ba2cbf19..9723db74e4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cqq-q3c4-9jg6/GHSA-3cqq-q3c4-9jg6.json +++ b/advisories/unreviewed/2022/05/GHSA-3cqq-q3c4-9jg6/GHSA-3cqq-q3c4-9jg6.json @@ -7,12 +7,8 @@ "CVE-2009-0872" ], "details": "The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cv7-5j4c-h696/GHSA-3cv7-5j4c-h696.json b/advisories/unreviewed/2022/05/GHSA-3cv7-5j4c-h696/GHSA-3cv7-5j4c-h696.json index 7298b700966..07c10ede479 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cv7-5j4c-h696/GHSA-3cv7-5j4c-h696.json +++ b/advisories/unreviewed/2022/05/GHSA-3cv7-5j4c-h696/GHSA-3cv7-5j4c-h696.json @@ -7,12 +7,8 @@ "CVE-2009-0834" ], "details": "The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -176,9 +172,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cwm-mjh6-3hwq/GHSA-3cwm-mjh6-3hwq.json b/advisories/unreviewed/2022/05/GHSA-3cwm-mjh6-3hwq/GHSA-3cwm-mjh6-3hwq.json index ec555a3e544..24b5160ec45 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cwm-mjh6-3hwq/GHSA-3cwm-mjh6-3hwq.json +++ b/advisories/unreviewed/2022/05/GHSA-3cwm-mjh6-3hwq/GHSA-3cwm-mjh6-3hwq.json @@ -7,12 +7,8 @@ "CVE-2009-0584" ], "details": "icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -184,9 +180,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f83-v3jg-8cf4/GHSA-3f83-v3jg-8cf4.json b/advisories/unreviewed/2022/05/GHSA-3f83-v3jg-8cf4/GHSA-3f83-v3jg-8cf4.json index c6679e789e6..4faa6ac99af 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f83-v3jg-8cf4/GHSA-3f83-v3jg-8cf4.json +++ b/advisories/unreviewed/2022/05/GHSA-3f83-v3jg-8cf4/GHSA-3f83-v3jg-8cf4.json @@ -7,12 +7,8 @@ "CVE-2009-0463" ], "details": "PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fc6-gf75-vvc3/GHSA-3fc6-gf75-vvc3.json b/advisories/unreviewed/2022/05/GHSA-3fc6-gf75-vvc3/GHSA-3fc6-gf75-vvc3.json index c0884dd318c..118e64ffeef 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fc6-gf75-vvc3/GHSA-3fc6-gf75-vvc3.json +++ b/advisories/unreviewed/2022/05/GHSA-3fc6-gf75-vvc3/GHSA-3fc6-gf75-vvc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3ffv-92x5-v3q9/GHSA-3ffv-92x5-v3q9.json b/advisories/unreviewed/2022/05/GHSA-3ffv-92x5-v3q9/GHSA-3ffv-92x5-v3q9.json index 420c9d6306e..30a4cf0e893 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ffv-92x5-v3q9/GHSA-3ffv-92x5-v3q9.json +++ b/advisories/unreviewed/2022/05/GHSA-3ffv-92x5-v3q9/GHSA-3ffv-92x5-v3q9.json @@ -7,12 +7,8 @@ "CVE-2009-0713" ], "details": "Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fh9-9x39-q9qw/GHSA-3fh9-9x39-q9qw.json b/advisories/unreviewed/2022/05/GHSA-3fh9-9x39-q9qw/GHSA-3fh9-9x39-q9qw.json index 449b0c1ff27..46064cad05f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fh9-9x39-q9qw/GHSA-3fh9-9x39-q9qw.json +++ b/advisories/unreviewed/2022/05/GHSA-3fh9-9x39-q9qw/GHSA-3fh9-9x39-q9qw.json @@ -7,12 +7,8 @@ "CVE-2009-0342" ], "details": "Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h66-68qg-wvwr/GHSA-3h66-68qg-wvwr.json b/advisories/unreviewed/2022/05/GHSA-3h66-68qg-wvwr/GHSA-3h66-68qg-wvwr.json index 5c4f5ef0d39..db3c6a7e514 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h66-68qg-wvwr/GHSA-3h66-68qg-wvwr.json +++ b/advisories/unreviewed/2022/05/GHSA-3h66-68qg-wvwr/GHSA-3h66-68qg-wvwr.json @@ -7,12 +7,8 @@ "CVE-2009-0378" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h77-q235-f88g/GHSA-3h77-q235-f88g.json b/advisories/unreviewed/2022/05/GHSA-3h77-q235-f88g/GHSA-3h77-q235-f88g.json index e1bcd49e6f4..6badb650058 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h77-q235-f88g/GHSA-3h77-q235-f88g.json +++ b/advisories/unreviewed/2022/05/GHSA-3h77-q235-f88g/GHSA-3h77-q235-f88g.json @@ -7,12 +7,8 @@ "CVE-2009-0997" ], "details": "Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jvr-7h6f-xpmw/GHSA-3jvr-7h6f-xpmw.json b/advisories/unreviewed/2022/05/GHSA-3jvr-7h6f-xpmw/GHSA-3jvr-7h6f-xpmw.json index 632a518468d..e1ab49a8af3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jvr-7h6f-xpmw/GHSA-3jvr-7h6f-xpmw.json +++ b/advisories/unreviewed/2022/05/GHSA-3jvr-7h6f-xpmw/GHSA-3jvr-7h6f-xpmw.json @@ -7,12 +7,8 @@ "CVE-2009-0929" ], "details": "Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pjh-hjmx-5pvh/GHSA-3pjh-hjmx-5pvh.json b/advisories/unreviewed/2022/05/GHSA-3pjh-hjmx-5pvh/GHSA-3pjh-hjmx-5pvh.json index eb40ee3a02f..11922b62f23 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pjh-hjmx-5pvh/GHSA-3pjh-hjmx-5pvh.json +++ b/advisories/unreviewed/2022/05/GHSA-3pjh-hjmx-5pvh/GHSA-3pjh-hjmx-5pvh.json @@ -7,12 +7,8 @@ "CVE-2009-0558" ], "details": "Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"Array Indexing Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pvr-773m-5pcf/GHSA-3pvr-773m-5pcf.json b/advisories/unreviewed/2022/05/GHSA-3pvr-773m-5pcf/GHSA-3pvr-773m-5pcf.json index 638e5a7baf4..9a36b97a407 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pvr-773m-5pcf/GHSA-3pvr-773m-5pcf.json +++ b/advisories/unreviewed/2022/05/GHSA-3pvr-773m-5pcf/GHSA-3pvr-773m-5pcf.json @@ -7,12 +7,8 @@ "CVE-2009-0813" ], "details": "Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qf8-484m-mg4f/GHSA-3qf8-484m-mg4f.json b/advisories/unreviewed/2022/05/GHSA-3qf8-484m-mg4f/GHSA-3qf8-484m-mg4f.json index 83d63ff7547..9dd1faa35ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qf8-484m-mg4f/GHSA-3qf8-484m-mg4f.json +++ b/advisories/unreviewed/2022/05/GHSA-3qf8-484m-mg4f/GHSA-3qf8-484m-mg4f.json @@ -7,12 +7,8 @@ "CVE-2009-0719" ], "details": "Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qqr-wq7g-hxwh/GHSA-3qqr-wq7g-hxwh.json b/advisories/unreviewed/2022/05/GHSA-3qqr-wq7g-hxwh/GHSA-3qqr-wq7g-hxwh.json index 5c70e5f861a..9640b6b2b3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qqr-wq7g-hxwh/GHSA-3qqr-wq7g-hxwh.json +++ b/advisories/unreviewed/2022/05/GHSA-3qqr-wq7g-hxwh/GHSA-3qqr-wq7g-hxwh.json @@ -7,12 +7,8 @@ "CVE-2009-0543" ], "details": "ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qv7-rvwv-j55x/GHSA-3qv7-rvwv-j55x.json b/advisories/unreviewed/2022/05/GHSA-3qv7-rvwv-j55x/GHSA-3qv7-rvwv-j55x.json index ae214ea0ba9..ebaac53c839 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qv7-rvwv-j55x/GHSA-3qv7-rvwv-j55x.json +++ b/advisories/unreviewed/2022/05/GHSA-3qv7-rvwv-j55x/GHSA-3qv7-rvwv-j55x.json @@ -7,12 +7,8 @@ "CVE-2009-0395" ], "details": "SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r5w-g4xg-c8cv/GHSA-3r5w-g4xg-c8cv.json b/advisories/unreviewed/2022/05/GHSA-3r5w-g4xg-c8cv/GHSA-3r5w-g4xg-c8cv.json index 04d56fd079a..b9d9bee05f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r5w-g4xg-c8cv/GHSA-3r5w-g4xg-c8cv.json +++ b/advisories/unreviewed/2022/05/GHSA-3r5w-g4xg-c8cv/GHSA-3r5w-g4xg-c8cv.json @@ -7,12 +7,8 @@ "CVE-2009-0499" ], "details": "Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rg2-hc5h-p32j/GHSA-3rg2-hc5h-p32j.json b/advisories/unreviewed/2022/05/GHSA-3rg2-hc5h-p32j/GHSA-3rg2-hc5h-p32j.json index e65177c4b61..6adc5a3fa16 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rg2-hc5h-p32j/GHSA-3rg2-hc5h-p32j.json +++ b/advisories/unreviewed/2022/05/GHSA-3rg2-hc5h-p32j/GHSA-3rg2-hc5h-p32j.json @@ -7,12 +7,8 @@ "CVE-2009-0549" ], "details": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Microsoft Office Excel Viewer 2003 SP3 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"Record Pointer Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v7f-ppjx-349f/GHSA-3v7f-ppjx-349f.json b/advisories/unreviewed/2022/05/GHSA-3v7f-ppjx-349f/GHSA-3v7f-ppjx-349f.json index 502ac1fbc9a..d7f9f4fde1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v7f-ppjx-349f/GHSA-3v7f-ppjx-349f.json +++ b/advisories/unreviewed/2022/05/GHSA-3v7f-ppjx-349f/GHSA-3v7f-ppjx-349f.json @@ -7,12 +7,8 @@ "CVE-2009-0804" ], "details": "Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v8f-pqw4-37vx/GHSA-3v8f-pqw4-37vx.json b/advisories/unreviewed/2022/05/GHSA-3v8f-pqw4-37vx/GHSA-3v8f-pqw4-37vx.json index d2f2932be02..b44ebe41331 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v8f-pqw4-37vx/GHSA-3v8f-pqw4-37vx.json +++ b/advisories/unreviewed/2022/05/GHSA-3v8f-pqw4-37vx/GHSA-3v8f-pqw4-37vx.json @@ -7,12 +7,8 @@ "CVE-2009-0603" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with \"administer content types\" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vgx-qgcc-j6g8/GHSA-3vgx-qgcc-j6g8.json b/advisories/unreviewed/2022/05/GHSA-3vgx-qgcc-j6g8/GHSA-3vgx-qgcc-j6g8.json index 331bf420afb..c845afa0207 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vgx-qgcc-j6g8/GHSA-3vgx-qgcc-j6g8.json +++ b/advisories/unreviewed/2022/05/GHSA-3vgx-qgcc-j6g8/GHSA-3vgx-qgcc-j6g8.json @@ -7,12 +7,8 @@ "CVE-2009-0541" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w86-j9mv-8fpr/GHSA-3w86-j9mv-8fpr.json b/advisories/unreviewed/2022/05/GHSA-3w86-j9mv-8fpr/GHSA-3w86-j9mv-8fpr.json index 987463e09bd..f8cb913ba50 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w86-j9mv-8fpr/GHSA-3w86-j9mv-8fpr.json +++ b/advisories/unreviewed/2022/05/GHSA-3w86-j9mv-8fpr/GHSA-3w86-j9mv-8fpr.json @@ -7,12 +7,8 @@ "CVE-2009-0674" ], "details": "images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43gp-2vcj-4vxj/GHSA-43gp-2vcj-4vxj.json b/advisories/unreviewed/2022/05/GHSA-43gp-2vcj-4vxj/GHSA-43gp-2vcj-4vxj.json index 4a0bea7c183..c2de2656093 100644 --- a/advisories/unreviewed/2022/05/GHSA-43gp-2vcj-4vxj/GHSA-43gp-2vcj-4vxj.json +++ b/advisories/unreviewed/2022/05/GHSA-43gp-2vcj-4vxj/GHSA-43gp-2vcj-4vxj.json @@ -7,12 +7,8 @@ "CVE-2009-0601" ], "details": "Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4443-73qg-vxgj/GHSA-4443-73qg-vxgj.json b/advisories/unreviewed/2022/05/GHSA-4443-73qg-vxgj/GHSA-4443-73qg-vxgj.json index 28199cdfa54..4d24ff742e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4443-73qg-vxgj/GHSA-4443-73qg-vxgj.json +++ b/advisories/unreviewed/2022/05/GHSA-4443-73qg-vxgj/GHSA-4443-73qg-vxgj.json @@ -7,12 +7,8 @@ "CVE-2009-0852" ], "details": "showme.php in CelerBB 0.0.2 allows remote attackers to obtain \"reserved information\" via the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-444h-qfvw-6mmm/GHSA-444h-qfvw-6mmm.json b/advisories/unreviewed/2022/05/GHSA-444h-qfvw-6mmm/GHSA-444h-qfvw-6mmm.json index 21560a89f8c..788dfc5cca5 100644 --- a/advisories/unreviewed/2022/05/GHSA-444h-qfvw-6mmm/GHSA-444h-qfvw-6mmm.json +++ b/advisories/unreviewed/2022/05/GHSA-444h-qfvw-6mmm/GHSA-444h-qfvw-6mmm.json @@ -7,12 +7,8 @@ "CVE-2009-0320" ], "details": "Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a \"benchmarking attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4564-2f76-rv6p/GHSA-4564-2f76-rv6p.json b/advisories/unreviewed/2022/05/GHSA-4564-2f76-rv6p/GHSA-4564-2f76-rv6p.json index 5b0db0bbf20..ea8fa5d5530 100644 --- a/advisories/unreviewed/2022/05/GHSA-4564-2f76-rv6p/GHSA-4564-2f76-rv6p.json +++ b/advisories/unreviewed/2022/05/GHSA-4564-2f76-rv6p/GHSA-4564-2f76-rv6p.json @@ -7,12 +7,8 @@ "CVE-2009-0566" ], "details": "Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka \"Pointer Dereference Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-456v-pf94-8wmr/GHSA-456v-pf94-8wmr.json b/advisories/unreviewed/2022/05/GHSA-456v-pf94-8wmr/GHSA-456v-pf94-8wmr.json index 3f8e02950c5..6246f2e4979 100644 --- a/advisories/unreviewed/2022/05/GHSA-456v-pf94-8wmr/GHSA-456v-pf94-8wmr.json +++ b/advisories/unreviewed/2022/05/GHSA-456v-pf94-8wmr/GHSA-456v-pf94-8wmr.json @@ -7,12 +7,8 @@ "CVE-2009-0900" ], "details": "Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45w4-h5x7-85w7/GHSA-45w4-h5x7-85w7.json b/advisories/unreviewed/2022/05/GHSA-45w4-h5x7-85w7/GHSA-45w4-h5x7-85w7.json index c449613a660..f6b2aa73386 100644 --- a/advisories/unreviewed/2022/05/GHSA-45w4-h5x7-85w7/GHSA-45w4-h5x7-85w7.json +++ b/advisories/unreviewed/2022/05/GHSA-45w4-h5x7-85w7/GHSA-45w4-h5x7-85w7.json @@ -7,12 +7,8 @@ "CVE-2009-0912" ], "details": "perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via \"special characters\" in unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46h9-fmgf-5h2p/GHSA-46h9-fmgf-5h2p.json b/advisories/unreviewed/2022/05/GHSA-46h9-fmgf-5h2p/GHSA-46h9-fmgf-5h2p.json index d2ba6e8e3b1..a451bdec404 100644 --- a/advisories/unreviewed/2022/05/GHSA-46h9-fmgf-5h2p/GHSA-46h9-fmgf-5h2p.json +++ b/advisories/unreviewed/2022/05/GHSA-46h9-fmgf-5h2p/GHSA-46h9-fmgf-5h2p.json @@ -7,12 +7,8 @@ "CVE-2009-0304" ], "details": "The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an \"insufficient validation security vulnerability,\" as demonstrated by SunOSipv6.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46r2-f8xg-hrvq/GHSA-46r2-f8xg-hrvq.json b/advisories/unreviewed/2022/05/GHSA-46r2-f8xg-hrvq/GHSA-46r2-f8xg-hrvq.json index a35f311c663..ee9b3c80922 100644 --- a/advisories/unreviewed/2022/05/GHSA-46r2-f8xg-hrvq/GHSA-46r2-f8xg-hrvq.json +++ b/advisories/unreviewed/2022/05/GHSA-46r2-f8xg-hrvq/GHSA-46r2-f8xg-hrvq.json @@ -7,12 +7,8 @@ "CVE-2009-0930" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4777-fq3m-4ghg/GHSA-4777-fq3m-4ghg.json b/advisories/unreviewed/2022/05/GHSA-4777-fq3m-4ghg/GHSA-4777-fq3m-4ghg.json index b4adfe085c4..c2f63c443df 100644 --- a/advisories/unreviewed/2022/05/GHSA-4777-fq3m-4ghg/GHSA-4777-fq3m-4ghg.json +++ b/advisories/unreviewed/2022/05/GHSA-4777-fq3m-4ghg/GHSA-4777-fq3m-4ghg.json @@ -7,12 +7,8 @@ "CVE-2009-0575" ], "details": "Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to node titles. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47cc-x9rh-39h6/GHSA-47cc-x9rh-39h6.json b/advisories/unreviewed/2022/05/GHSA-47cc-x9rh-39h6/GHSA-47cc-x9rh-39h6.json index 1ff62ef2d0d..5c3b6e3b54a 100644 --- a/advisories/unreviewed/2022/05/GHSA-47cc-x9rh-39h6/GHSA-47cc-x9rh-39h6.json +++ b/advisories/unreviewed/2022/05/GHSA-47cc-x9rh-39h6/GHSA-47cc-x9rh-39h6.json @@ -7,12 +7,8 @@ "CVE-2009-0924" ], "details": "Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47vf-p6gg-7gh5/GHSA-47vf-p6gg-7gh5.json b/advisories/unreviewed/2022/05/GHSA-47vf-p6gg-7gh5/GHSA-47vf-p6gg-7gh5.json index 91b25186298..fe902c48e0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-47vf-p6gg-7gh5/GHSA-47vf-p6gg-7gh5.json +++ b/advisories/unreviewed/2022/05/GHSA-47vf-p6gg-7gh5/GHSA-47vf-p6gg-7gh5.json @@ -7,12 +7,8 @@ "CVE-2009-0655" ], "details": "Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a \"plain image\" of the authorized user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48fp-j3fc-gqvx/GHSA-48fp-j3fc-gqvx.json b/advisories/unreviewed/2022/05/GHSA-48fp-j3fc-gqvx/GHSA-48fp-j3fc-gqvx.json index 42717023abc..efa7383c9d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-48fp-j3fc-gqvx/GHSA-48fp-j3fc-gqvx.json +++ b/advisories/unreviewed/2022/05/GHSA-48fp-j3fc-gqvx/GHSA-48fp-j3fc-gqvx.json @@ -7,12 +7,8 @@ "CVE-2009-0895" ], "details": "Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c3c-6q2f-43vf/GHSA-4c3c-6q2f-43vf.json b/advisories/unreviewed/2022/05/GHSA-4c3c-6q2f-43vf/GHSA-4c3c-6q2f-43vf.json index fc702f1fd99..d8a5c11c4ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c3c-6q2f-43vf/GHSA-4c3c-6q2f-43vf.json +++ b/advisories/unreviewed/2022/05/GHSA-4c3c-6q2f-43vf/GHSA-4c3c-6q2f-43vf.json @@ -7,12 +7,8 @@ "CVE-2009-0842" ], "details": "mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c44-843m-j2x2/GHSA-4c44-843m-j2x2.json b/advisories/unreviewed/2022/05/GHSA-4c44-843m-j2x2/GHSA-4c44-843m-j2x2.json index 10caeacd709..89c31dcd4b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c44-843m-j2x2/GHSA-4c44-843m-j2x2.json +++ b/advisories/unreviewed/2022/05/GHSA-4c44-843m-j2x2/GHSA-4c44-843m-j2x2.json @@ -7,12 +7,8 @@ "CVE-2009-0400" ], "details": "SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c58-qj3v-wwf5/GHSA-4c58-qj3v-wwf5.json b/advisories/unreviewed/2022/05/GHSA-4c58-qj3v-wwf5/GHSA-4c58-qj3v-wwf5.json index 71dbb64ce49..a9a7931dc7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c58-qj3v-wwf5/GHSA-4c58-qj3v-wwf5.json +++ b/advisories/unreviewed/2022/05/GHSA-4c58-qj3v-wwf5/GHSA-4c58-qj3v-wwf5.json @@ -7,12 +7,8 @@ "CVE-2009-0617" ], "details": "Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f74-wg9f-2vfm/GHSA-4f74-wg9f-2vfm.json b/advisories/unreviewed/2022/05/GHSA-4f74-wg9f-2vfm/GHSA-4f74-wg9f-2vfm.json index 4fa7a9629db..f90958ffb31 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f74-wg9f-2vfm/GHSA-4f74-wg9f-2vfm.json +++ b/advisories/unreviewed/2022/05/GHSA-4f74-wg9f-2vfm/GHSA-4f74-wg9f-2vfm.json @@ -7,12 +7,8 @@ "CVE-2009-0319" ], "details": "Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to \"xdr processing problems.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gvm-4mw2-9fpv/GHSA-4gvm-4mw2-9fpv.json b/advisories/unreviewed/2022/05/GHSA-4gvm-4mw2-9fpv/GHSA-4gvm-4mw2-9fpv.json index dc7e48c1ac5..d3cee63b9e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gvm-4mw2-9fpv/GHSA-4gvm-4mw2-9fpv.json +++ b/advisories/unreviewed/2022/05/GHSA-4gvm-4mw2-9fpv/GHSA-4gvm-4mw2-9fpv.json @@ -7,12 +7,8 @@ "CVE-2009-0642" ], "details": "ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h8p-gqwx-mmw3/GHSA-4h8p-gqwx-mmw3.json b/advisories/unreviewed/2022/05/GHSA-4h8p-gqwx-mmw3/GHSA-4h8p-gqwx-mmw3.json index dcb76e44b23..bd47cc79729 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h8p-gqwx-mmw3/GHSA-4h8p-gqwx-mmw3.json +++ b/advisories/unreviewed/2022/05/GHSA-4h8p-gqwx-mmw3/GHSA-4h8p-gqwx-mmw3.json @@ -7,12 +7,8 @@ "CVE-2009-0844" ], "details": "The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j7f-pc38-35rv/GHSA-4j7f-pc38-35rv.json b/advisories/unreviewed/2022/05/GHSA-4j7f-pc38-35rv/GHSA-4j7f-pc38-35rv.json index 7cd4a993f86..61f45a96b1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j7f-pc38-35rv/GHSA-4j7f-pc38-35rv.json +++ b/advisories/unreviewed/2022/05/GHSA-4j7f-pc38-35rv/GHSA-4j7f-pc38-35rv.json @@ -7,12 +7,8 @@ "CVE-2009-0631" ], "details": "Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level Agreements (SLAs) Responder, (2) Session Initiation Protocol (SIP), (3) H.323 Annex E Call Signaling Transport, or (4) Media Gateway Control Protocol (MGCP) allows remote attackers to cause a denial of service (blocked input queue on the inbound interface) via a crafted UDP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jgf-3vrv-w8gc/GHSA-4jgf-3vrv-w8gc.json b/advisories/unreviewed/2022/05/GHSA-4jgf-3vrv-w8gc/GHSA-4jgf-3vrv-w8gc.json index 760c58aaa2a..96f858aadd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jgf-3vrv-w8gc/GHSA-4jgf-3vrv-w8gc.json +++ b/advisories/unreviewed/2022/05/GHSA-4jgf-3vrv-w8gc/GHSA-4jgf-3vrv-w8gc.json @@ -7,12 +7,8 @@ "CVE-2009-0651" ], "details": "Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Server 5.x, 6.0 before MP7 SP1, and 6.5 before 6.5.3.1 allows remote attackers to execute arbitrary code via unknown vectors related to \"initial communications setup.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m4r-xmfg-wvf5/GHSA-4m4r-xmfg-wvf5.json b/advisories/unreviewed/2022/05/GHSA-4m4r-xmfg-wvf5/GHSA-4m4r-xmfg-wvf5.json index dfbfec0ac98..bfa66267251 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m4r-xmfg-wvf5/GHSA-4m4r-xmfg-wvf5.json +++ b/advisories/unreviewed/2022/05/GHSA-4m4r-xmfg-wvf5/GHSA-4m4r-xmfg-wvf5.json @@ -7,12 +7,8 @@ "CVE-2009-0313" ], "details": "winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m9h-7gmv-8qc2/GHSA-4m9h-7gmv-8qc2.json b/advisories/unreviewed/2022/05/GHSA-4m9h-7gmv-8qc2/GHSA-4m9h-7gmv-8qc2.json index 3f4b5652ca5..baca6e51a09 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m9h-7gmv-8qc2/GHSA-4m9h-7gmv-8qc2.json +++ b/advisories/unreviewed/2022/05/GHSA-4m9h-7gmv-8qc2/GHSA-4m9h-7gmv-8qc2.json @@ -7,12 +7,8 @@ "CVE-2009-0707" ], "details": "SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m9h-cpwq-g6hj/GHSA-4m9h-cpwq-g6hj.json b/advisories/unreviewed/2022/05/GHSA-4m9h-cpwq-g6hj/GHSA-4m9h-cpwq-g6hj.json index 80b924ab6ae..8e39073efa7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m9h-cpwq-g6hj/GHSA-4m9h-cpwq-g6hj.json +++ b/advisories/unreviewed/2022/05/GHSA-4m9h-cpwq-g6hj/GHSA-4m9h-cpwq-g6hj.json @@ -7,12 +7,8 @@ "CVE-2009-0102" ], "details": "Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka \"Project Memory Validation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pjg-hm2r-rj25/GHSA-4pjg-hm2r-rj25.json b/advisories/unreviewed/2022/05/GHSA-4pjg-hm2r-rj25/GHSA-4pjg-hm2r-rj25.json index af0f63516aa..094fd8116cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pjg-hm2r-rj25/GHSA-4pjg-hm2r-rj25.json +++ b/advisories/unreviewed/2022/05/GHSA-4pjg-hm2r-rj25/GHSA-4pjg-hm2r-rj25.json @@ -7,12 +7,8 @@ "CVE-2009-0742" ], "details": "The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r2h-hc45-gpwj/GHSA-4r2h-hc45-gpwj.json b/advisories/unreviewed/2022/05/GHSA-4r2h-hc45-gpwj/GHSA-4r2h-hc45-gpwj.json index 49e0a818721..1594438048a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r2h-hc45-gpwj/GHSA-4r2h-hc45-gpwj.json +++ b/advisories/unreviewed/2022/05/GHSA-4r2h-hc45-gpwj/GHSA-4r2h-hc45-gpwj.json @@ -7,12 +7,8 @@ "CVE-2009-0406" ], "details": "SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r77-3p2f-hv57/GHSA-4r77-3p2f-hv57.json b/advisories/unreviewed/2022/05/GHSA-4r77-3p2f-hv57/GHSA-4r77-3p2f-hv57.json index 38567d5b930..d8b0dc3d71b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r77-3p2f-hv57/GHSA-4r77-3p2f-hv57.json +++ b/advisories/unreviewed/2022/05/GHSA-4r77-3p2f-hv57/GHSA-4r77-3p2f-hv57.json @@ -7,12 +7,8 @@ "CVE-2009-0596" ], "details": "Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the TplSuffix parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4v97-9crm-p348/GHSA-4v97-9crm-p348.json b/advisories/unreviewed/2022/05/GHSA-4v97-9crm-p348/GHSA-4v97-9crm-p348.json index 08cc67796ef..ba72a46326f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v97-9crm-p348/GHSA-4v97-9crm-p348.json +++ b/advisories/unreviewed/2022/05/GHSA-4v97-9crm-p348/GHSA-4v97-9crm-p348.json @@ -7,12 +7,8 @@ "CVE-2009-0939" ], "details": "Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to \"Spec conformance,\" as demonstrated using 192.168.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wf2-v7f9-h3wp/GHSA-4wf2-v7f9-h3wp.json b/advisories/unreviewed/2022/05/GHSA-4wf2-v7f9-h3wp/GHSA-4wf2-v7f9-h3wp.json index 498740c48ae..b374eadbd76 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wf2-v7f9-h3wp/GHSA-4wf2-v7f9-h3wp.json +++ b/advisories/unreviewed/2022/05/GHSA-4wf2-v7f9-h3wp/GHSA-4wf2-v7f9-h3wp.json @@ -7,12 +7,8 @@ "CVE-2009-0720" ], "details": "Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5258-76v6-37c2/GHSA-5258-76v6-37c2.json b/advisories/unreviewed/2022/05/GHSA-5258-76v6-37c2/GHSA-5258-76v6-37c2.json index ba88240f1a2..b94b5f46355 100644 --- a/advisories/unreviewed/2022/05/GHSA-5258-76v6-37c2/GHSA-5258-76v6-37c2.json +++ b/advisories/unreviewed/2022/05/GHSA-5258-76v6-37c2/GHSA-5258-76v6-37c2.json @@ -7,12 +7,8 @@ "CVE-2009-0533" ], "details": "Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-526v-hfw3-w58p/GHSA-526v-hfw3-w58p.json b/advisories/unreviewed/2022/05/GHSA-526v-hfw3-w58p/GHSA-526v-hfw3-w58p.json index 7d92782e0c7..50afda00f59 100644 --- a/advisories/unreviewed/2022/05/GHSA-526v-hfw3-w58p/GHSA-526v-hfw3-w58p.json +++ b/advisories/unreviewed/2022/05/GHSA-526v-hfw3-w58p/GHSA-526v-hfw3-w58p.json @@ -7,12 +7,8 @@ "CVE-2009-0824" ], "details": "Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53rh-gvx6-42x8/GHSA-53rh-gvx6-42x8.json b/advisories/unreviewed/2022/05/GHSA-53rh-gvx6-42x8/GHSA-53rh-gvx6-42x8.json index 628491225bf..67fa3eec8e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-53rh-gvx6-42x8/GHSA-53rh-gvx6-42x8.json +++ b/advisories/unreviewed/2022/05/GHSA-53rh-gvx6-42x8/GHSA-53rh-gvx6-42x8.json @@ -7,12 +7,8 @@ "CVE-2009-0840" ], "details": "Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-549h-27j9-7hx3/GHSA-549h-27j9-7hx3.json b/advisories/unreviewed/2022/05/GHSA-549h-27j9-7hx3/GHSA-549h-27j9-7hx3.json index 0457ed389d2..81d603e5954 100644 --- a/advisories/unreviewed/2022/05/GHSA-549h-27j9-7hx3/GHSA-549h-27j9-7hx3.json +++ b/advisories/unreviewed/2022/05/GHSA-549h-27j9-7hx3/GHSA-549h-27j9-7hx3.json @@ -7,12 +7,8 @@ "CVE-2009-0211" ], "details": "Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54mg-3vfg-x9mp/GHSA-54mg-3vfg-x9mp.json b/advisories/unreviewed/2022/05/GHSA-54mg-3vfg-x9mp/GHSA-54mg-3vfg-x9mp.json index 1054ef740b6..5d0bd0ec441 100644 --- a/advisories/unreviewed/2022/05/GHSA-54mg-3vfg-x9mp/GHSA-54mg-3vfg-x9mp.json +++ b/advisories/unreviewed/2022/05/GHSA-54mg-3vfg-x9mp/GHSA-54mg-3vfg-x9mp.json @@ -7,12 +7,8 @@ "CVE-2009-0710" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-567f-qrxh-f46c/GHSA-567f-qrxh-f46c.json b/advisories/unreviewed/2022/05/GHSA-567f-qrxh-f46c/GHSA-567f-qrxh-f46c.json index 5236de45c84..7b1068510f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-567f-qrxh-f46c/GHSA-567f-qrxh-f46c.json +++ b/advisories/unreviewed/2022/05/GHSA-567f-qrxh-f46c/GHSA-567f-qrxh-f46c.json @@ -7,12 +7,8 @@ "CVE-2009-0279" ], "details": "SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56h7-99r3-xgmr/GHSA-56h7-99r3-xgmr.json b/advisories/unreviewed/2022/05/GHSA-56h7-99r3-xgmr/GHSA-56h7-99r3-xgmr.json index 8dc3f055b00..536ac6a3ae0 100644 --- a/advisories/unreviewed/2022/05/GHSA-56h7-99r3-xgmr/GHSA-56h7-99r3-xgmr.json +++ b/advisories/unreviewed/2022/05/GHSA-56h7-99r3-xgmr/GHSA-56h7-99r3-xgmr.json @@ -7,12 +7,8 @@ "CVE-2009-0360" ], "details": "Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57qc-2cx2-pm35/GHSA-57qc-2cx2-pm35.json b/advisories/unreviewed/2022/05/GHSA-57qc-2cx2-pm35/GHSA-57qc-2cx2-pm35.json index 1bc3d3818c6..7f3259cd974 100644 --- a/advisories/unreviewed/2022/05/GHSA-57qc-2cx2-pm35/GHSA-57qc-2cx2-pm35.json +++ b/advisories/unreviewed/2022/05/GHSA-57qc-2cx2-pm35/GHSA-57qc-2cx2-pm35.json @@ -7,12 +7,8 @@ "CVE-2009-0553" ], "details": "Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59q5-7wr3-p34p/GHSA-59q5-7wr3-p34p.json b/advisories/unreviewed/2022/05/GHSA-59q5-7wr3-p34p/GHSA-59q5-7wr3-p34p.json index 0a677268a01..31a41e59dc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-59q5-7wr3-p34p/GHSA-59q5-7wr3-p34p.json +++ b/advisories/unreviewed/2022/05/GHSA-59q5-7wr3-p34p/GHSA-59q5-7wr3-p34p.json @@ -7,12 +7,8 @@ "CVE-2009-0289" ], "details": "k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59v4-7p7v-xmg9/GHSA-59v4-7p7v-xmg9.json b/advisories/unreviewed/2022/05/GHSA-59v4-7p7v-xmg9/GHSA-59v4-7p7v-xmg9.json index bf512693a92..bdcfb894732 100644 --- a/advisories/unreviewed/2022/05/GHSA-59v4-7p7v-xmg9/GHSA-59v4-7p7v-xmg9.json +++ b/advisories/unreviewed/2022/05/GHSA-59v4-7p7v-xmg9/GHSA-59v4-7p7v-xmg9.json @@ -7,12 +7,8 @@ "CVE-2009-0919" ], "details": "XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the \"lampp\" default password for the \"nobody\" account within the included ProFTPD installation, (2) a blank default password for the \"root\" account within the included MySQL installation, (3) a blank default password for the \"pma\" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with \"no contact from / to internet.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c64-7m9p-wp5p/GHSA-5c64-7m9p-wp5p.json b/advisories/unreviewed/2022/05/GHSA-5c64-7m9p-wp5p/GHSA-5c64-7m9p-wp5p.json index 967b83a4d2a..92f98ce8ca7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c64-7m9p-wp5p/GHSA-5c64-7m9p-wp5p.json +++ b/advisories/unreviewed/2022/05/GHSA-5c64-7m9p-wp5p/GHSA-5c64-7m9p-wp5p.json @@ -7,12 +7,8 @@ "CVE-2009-0413" ], "details": "Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gc8-v95q-vq8h/GHSA-5gc8-v95q-vq8h.json b/advisories/unreviewed/2022/05/GHSA-5gc8-v95q-vq8h/GHSA-5gc8-v95q-vq8h.json index e42e7f998d9..9866f2af779 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gc8-v95q-vq8h/GHSA-5gc8-v95q-vq8h.json +++ b/advisories/unreviewed/2022/05/GHSA-5gc8-v95q-vq8h/GHSA-5gc8-v95q-vq8h.json @@ -7,12 +7,8 @@ "CVE-2009-0294" ], "details": "Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3) comments.php, and (4) news.php; (5) News.php, (6) SendFriend.php, (7) Archive.php, and (8) Comments.php in base/; and possibly other components, different vectors than CVE-2007-1288.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mv3-qrx8-v8x3/GHSA-5mv3-qrx8-v8x3.json b/advisories/unreviewed/2022/05/GHSA-5mv3-qrx8-v8x3/GHSA-5mv3-qrx8-v8x3.json index 988a3ecd6f8..67380141b7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mv3-qrx8-v8x3/GHSA-5mv3-qrx8-v8x3.json +++ b/advisories/unreviewed/2022/05/GHSA-5mv3-qrx8-v8x3/GHSA-5mv3-qrx8-v8x3.json @@ -7,12 +7,8 @@ "CVE-2009-0931" ], "details": "Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p4c-rp79-gv64/GHSA-5p4c-rp79-gv64.json b/advisories/unreviewed/2022/05/GHSA-5p4c-rp79-gv64/GHSA-5p4c-rp79-gv64.json index a26a585dbb3..089a8fa2c5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p4c-rp79-gv64/GHSA-5p4c-rp79-gv64.json +++ b/advisories/unreviewed/2022/05/GHSA-5p4c-rp79-gv64/GHSA-5p4c-rp79-gv64.json @@ -7,12 +7,8 @@ "CVE-2009-0648" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (aka Falt4 Extreme) RC4 allow remote attackers to hijack the authentication of administrators for requests that change passwords via the (1) edit and (2) edit_now actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p97-rmc7-hqwc/GHSA-5p97-rmc7-hqwc.json b/advisories/unreviewed/2022/05/GHSA-5p97-rmc7-hqwc/GHSA-5p97-rmc7-hqwc.json index 30d247da30d..f5b9de6139f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p97-rmc7-hqwc/GHSA-5p97-rmc7-hqwc.json +++ b/advisories/unreviewed/2022/05/GHSA-5p97-rmc7-hqwc/GHSA-5p97-rmc7-hqwc.json @@ -7,12 +7,8 @@ "CVE-2009-0287" ], "details": "SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5ppx-563r-592f/GHSA-5ppx-563r-592f.json b/advisories/unreviewed/2022/05/GHSA-5ppx-563r-592f/GHSA-5ppx-563r-592f.json index 820e4941a6a..03779e107ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-5ppx-563r-592f/GHSA-5ppx-563r-592f.json +++ b/advisories/unreviewed/2022/05/GHSA-5ppx-563r-592f/GHSA-5ppx-563r-592f.json @@ -7,12 +7,8 @@ "CVE-2009-0643" ], "details": "Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q7x-rmh4-jxrr/GHSA-5q7x-rmh4-jxrr.json b/advisories/unreviewed/2022/05/GHSA-5q7x-rmh4-jxrr/GHSA-5q7x-rmh4-jxrr.json index d8fc3e5ca8d..c59744b45d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q7x-rmh4-jxrr/GHSA-5q7x-rmh4-jxrr.json +++ b/advisories/unreviewed/2022/05/GHSA-5q7x-rmh4-jxrr/GHSA-5q7x-rmh4-jxrr.json @@ -7,12 +7,8 @@ "CVE-2009-0561" ], "details": "Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Microsoft Office SharePoint Server 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via an Excel file with a Shared String Table (SST) record with a numeric field that specifies an invalid number of unique strings, which triggers a heap-based buffer overflow, aka \"Record Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q85-2xfh-7gpf/GHSA-5q85-2xfh-7gpf.json b/advisories/unreviewed/2022/05/GHSA-5q85-2xfh-7gpf/GHSA-5q85-2xfh-7gpf.json index d216e8b7356..279b0e390a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q85-2xfh-7gpf/GHSA-5q85-2xfh-7gpf.json +++ b/advisories/unreviewed/2022/05/GHSA-5q85-2xfh-7gpf/GHSA-5q85-2xfh-7gpf.json @@ -7,12 +7,8 @@ "CVE-2009-0901" ], "details": "The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka \"ATL Uninitialized Object Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qcx-2phc-98rc/GHSA-5qcx-2phc-98rc.json b/advisories/unreviewed/2022/05/GHSA-5qcx-2phc-98rc/GHSA-5qcx-2phc-98rc.json index 45c2c59f986..fcfac42dcab 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qcx-2phc-98rc/GHSA-5qcx-2phc-98rc.json +++ b/advisories/unreviewed/2022/05/GHSA-5qcx-2phc-98rc/GHSA-5qcx-2phc-98rc.json @@ -7,12 +7,8 @@ "CVE-2009-0882" ], "details": "Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qgm-hgjh-hj48/GHSA-5qgm-hgjh-hj48.json b/advisories/unreviewed/2022/05/GHSA-5qgm-hgjh-hj48/GHSA-5qgm-hgjh-hj48.json index 389512afe9d..91ce37a4d95 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qgm-hgjh-hj48/GHSA-5qgm-hgjh-hj48.json +++ b/advisories/unreviewed/2022/05/GHSA-5qgm-hgjh-hj48/GHSA-5qgm-hgjh-hj48.json @@ -7,12 +7,8 @@ "CVE-2009-0414" ], "details": "Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qrr-868h-qmgv/GHSA-5qrr-868h-qmgv.json b/advisories/unreviewed/2022/05/GHSA-5qrr-868h-qmgv/GHSA-5qrr-868h-qmgv.json index 013f4635f0d..91d71304ba1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qrr-868h-qmgv/GHSA-5qrr-868h-qmgv.json +++ b/advisories/unreviewed/2022/05/GHSA-5qrr-868h-qmgv/GHSA-5qrr-868h-qmgv.json @@ -7,12 +7,8 @@ "CVE-2009-0296" ], "details": "SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vvp-mjcx-6cg5/GHSA-5vvp-mjcx-6cg5.json b/advisories/unreviewed/2022/05/GHSA-5vvp-mjcx-6cg5/GHSA-5vvp-mjcx-6cg5.json index 849d4a560a6..3f9967008df 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vvp-mjcx-6cg5/GHSA-5vvp-mjcx-6cg5.json +++ b/advisories/unreviewed/2022/05/GHSA-5vvp-mjcx-6cg5/GHSA-5vvp-mjcx-6cg5.json @@ -7,12 +7,8 @@ "CVE-2009-0641" ], "details": "sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wqq-m5rv-mrc8/GHSA-5wqq-m5rv-mrc8.json b/advisories/unreviewed/2022/05/GHSA-5wqq-m5rv-mrc8/GHSA-5wqq-m5rv-mrc8.json index 31db48958ff..2a8df752517 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wqq-m5rv-mrc8/GHSA-5wqq-m5rv-mrc8.json +++ b/advisories/unreviewed/2022/05/GHSA-5wqq-m5rv-mrc8/GHSA-5wqq-m5rv-mrc8.json @@ -7,12 +7,8 @@ "CVE-2009-0512" ], "details": "Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0888, and CVE-2009-0889.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-629c-fg8h-8j2m/GHSA-629c-fg8h-8j2m.json b/advisories/unreviewed/2022/05/GHSA-629c-fg8h-8j2m/GHSA-629c-fg8h-8j2m.json index 1be50e87625..aff1ca86d0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-629c-fg8h-8j2m/GHSA-629c-fg8h-8j2m.json +++ b/advisories/unreviewed/2022/05/GHSA-629c-fg8h-8j2m/GHSA-629c-fg8h-8j2m.json @@ -7,12 +7,8 @@ "CVE-2009-0608" ], "details": "Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62pj-38xh-r8r2/GHSA-62pj-38xh-r8r2.json b/advisories/unreviewed/2022/05/GHSA-62pj-38xh-r8r2/GHSA-62pj-38xh-r8r2.json index 3688978f001..d9009c6de2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-62pj-38xh-r8r2/GHSA-62pj-38xh-r8r2.json +++ b/advisories/unreviewed/2022/05/GHSA-62pj-38xh-r8r2/GHSA-62pj-38xh-r8r2.json @@ -7,12 +7,8 @@ "CVE-2009-0405" ], "details": "SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6357-ggmh-cwxm/GHSA-6357-ggmh-cwxm.json b/advisories/unreviewed/2022/05/GHSA-6357-ggmh-cwxm/GHSA-6357-ggmh-cwxm.json index c57324b843c..137f7138f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-6357-ggmh-cwxm/GHSA-6357-ggmh-cwxm.json +++ b/advisories/unreviewed/2022/05/GHSA-6357-ggmh-cwxm/GHSA-6357-ggmh-cwxm.json @@ -7,12 +7,8 @@ "CVE-2009-0925" ], "details": "Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through snv_85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6425723.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63q6-wgcf-8ppf/GHSA-63q6-wgcf-8ppf.json b/advisories/unreviewed/2022/05/GHSA-63q6-wgcf-8ppf/GHSA-63q6-wgcf-8ppf.json index a72657799df..0d28ff799a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-63q6-wgcf-8ppf/GHSA-63q6-wgcf-8ppf.json +++ b/advisories/unreviewed/2022/05/GHSA-63q6-wgcf-8ppf/GHSA-63q6-wgcf-8ppf.json @@ -7,12 +7,8 @@ "CVE-2009-0853" ], "details": "login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63w6-9m53-953q/GHSA-63w6-9m53-953q.json b/advisories/unreviewed/2022/05/GHSA-63w6-9m53-953q/GHSA-63w6-9m53-953q.json index 3433967f6cc..8ee5af6e4ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-63w6-9m53-953q/GHSA-63w6-9m53-953q.json +++ b/advisories/unreviewed/2022/05/GHSA-63w6-9m53-953q/GHSA-63w6-9m53-953q.json @@ -7,12 +7,8 @@ "CVE-2009-0714" ], "details": "Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65gq-25hv-4hvc/GHSA-65gq-25hv-4hvc.json b/advisories/unreviewed/2022/05/GHSA-65gq-25hv-4hvc/GHSA-65gq-25hv-4hvc.json index 8b2a54a38d1..346f5bc6175 100644 --- a/advisories/unreviewed/2022/05/GHSA-65gq-25hv-4hvc/GHSA-65gq-25hv-4hvc.json +++ b/advisories/unreviewed/2022/05/GHSA-65gq-25hv-4hvc/GHSA-65gq-25hv-4hvc.json @@ -7,12 +7,8 @@ "CVE-2009-0363" ], "details": "Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65p6-fh67-gpcv/GHSA-65p6-fh67-gpcv.json b/advisories/unreviewed/2022/05/GHSA-65p6-fh67-gpcv/GHSA-65p6-fh67-gpcv.json index 4522cf120e0..86da61a0806 100644 --- a/advisories/unreviewed/2022/05/GHSA-65p6-fh67-gpcv/GHSA-65p6-fh67-gpcv.json +++ b/advisories/unreviewed/2022/05/GHSA-65p6-fh67-gpcv/GHSA-65p6-fh67-gpcv.json @@ -7,12 +7,8 @@ "CVE-2009-0604" ], "details": "SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65vq-x599-5xrg/GHSA-65vq-x599-5xrg.json b/advisories/unreviewed/2022/05/GHSA-65vq-x599-5xrg/GHSA-65vq-x599-5xrg.json index 02249082450..01f52d792ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-65vq-x599-5xrg/GHSA-65vq-x599-5xrg.json +++ b/advisories/unreviewed/2022/05/GHSA-65vq-x599-5xrg/GHSA-65vq-x599-5xrg.json @@ -7,12 +7,8 @@ "CVE-2009-0616" ], "details": "Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to \"default user credentials during installation.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-66w7-536g-p527/GHSA-66w7-536g-p527.json b/advisories/unreviewed/2022/05/GHSA-66w7-536g-p527/GHSA-66w7-536g-p527.json index f9484e9a4e1..78f1e9df524 100644 --- a/advisories/unreviewed/2022/05/GHSA-66w7-536g-p527/GHSA-66w7-536g-p527.json +++ b/advisories/unreviewed/2022/05/GHSA-66w7-536g-p527/GHSA-66w7-536g-p527.json @@ -7,12 +7,8 @@ "CVE-2009-0407" ], "details": "SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67h2-fpx6-p4gv/GHSA-67h2-fpx6-p4gv.json b/advisories/unreviewed/2022/05/GHSA-67h2-fpx6-p4gv/GHSA-67h2-fpx6-p4gv.json index 047f8f98099..70ad9cc8ca6 100644 --- a/advisories/unreviewed/2022/05/GHSA-67h2-fpx6-p4gv/GHSA-67h2-fpx6-p4gv.json +++ b/advisories/unreviewed/2022/05/GHSA-67h2-fpx6-p4gv/GHSA-67h2-fpx6-p4gv.json @@ -7,12 +7,8 @@ "CVE-2009-0507" ], "details": "IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-688x-7w25-gh2x/GHSA-688x-7w25-gh2x.json b/advisories/unreviewed/2022/05/GHSA-688x-7w25-gh2x/GHSA-688x-7w25-gh2x.json index 15504c9feda..495acb6cfdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-688x-7w25-gh2x/GHSA-688x-7w25-gh2x.json +++ b/advisories/unreviewed/2022/05/GHSA-688x-7w25-gh2x/GHSA-688x-7w25-gh2x.json @@ -7,12 +7,8 @@ "CVE-2009-0788" ], "details": "Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68wh-jxh5-cwrj/GHSA-68wh-jxh5-cwrj.json b/advisories/unreviewed/2022/05/GHSA-68wh-jxh5-cwrj/GHSA-68wh-jxh5-cwrj.json index 848d65a6a5f..4fec4b286c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-68wh-jxh5-cwrj/GHSA-68wh-jxh5-cwrj.json +++ b/advisories/unreviewed/2022/05/GHSA-68wh-jxh5-cwrj/GHSA-68wh-jxh5-cwrj.json @@ -7,12 +7,8 @@ "CVE-2009-0397" ], "details": "Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-699h-75ph-9vh2/GHSA-699h-75ph-9vh2.json b/advisories/unreviewed/2022/05/GHSA-699h-75ph-9vh2/GHSA-699h-75ph-9vh2.json index 31f467a338d..0a5d6285d7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-699h-75ph-9vh2/GHSA-699h-75ph-9vh2.json +++ b/advisories/unreviewed/2022/05/GHSA-699h-75ph-9vh2/GHSA-699h-75ph-9vh2.json @@ -7,12 +7,8 @@ "CVE-2009-0851" ], "details": "Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewforum.php and (2) viewtopic.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c5j-6f9w-rg72/GHSA-6c5j-6f9w-rg72.json b/advisories/unreviewed/2022/05/GHSA-6c5j-6f9w-rg72/GHSA-6c5j-6f9w-rg72.json index f262564c1b8..1e0d892a84c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c5j-6f9w-rg72/GHSA-6c5j-6f9w-rg72.json +++ b/advisories/unreviewed/2022/05/GHSA-6c5j-6f9w-rg72/GHSA-6c5j-6f9w-rg72.json @@ -7,12 +7,8 @@ "CVE-2009-0921" ], "details": "Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww.so.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cj3-ff8f-838h/GHSA-6cj3-ff8f-838h.json b/advisories/unreviewed/2022/05/GHSA-6cj3-ff8f-838h/GHSA-6cj3-ff8f-838h.json index 7a46d5a2e21..d249f70fd56 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cj3-ff8f-838h/GHSA-6cj3-ff8f-838h.json +++ b/advisories/unreviewed/2022/05/GHSA-6cj3-ff8f-838h/GHSA-6cj3-ff8f-838h.json @@ -7,12 +7,8 @@ "CVE-2009-0599" ], "details": "Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6g4h-xrx8-p9xf/GHSA-6g4h-xrx8-p9xf.json b/advisories/unreviewed/2022/05/GHSA-6g4h-xrx8-p9xf/GHSA-6g4h-xrx8-p9xf.json index be8a2be0370..232409e6d53 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g4h-xrx8-p9xf/GHSA-6g4h-xrx8-p9xf.json +++ b/advisories/unreviewed/2022/05/GHSA-6g4h-xrx8-p9xf/GHSA-6g4h-xrx8-p9xf.json @@ -7,12 +7,8 @@ "CVE-2009-0850" ], "details": "Cross-site scripting (XSS) vulnerability in BitDefender Internet Security 2009 allows user-assisted remote attackers to inject arbitrary web script or HTML via the filename of a virus-infected file, as demonstrated by a filename inside a (1) rar or (2) zip archive file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6g59-hqmc-85v2/GHSA-6g59-hqmc-85v2.json b/advisories/unreviewed/2022/05/GHSA-6g59-hqmc-85v2/GHSA-6g59-hqmc-85v2.json index 3ea03a1aa5a..dd73d3f953b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g59-hqmc-85v2/GHSA-6g59-hqmc-85v2.json +++ b/advisories/unreviewed/2022/05/GHSA-6g59-hqmc-85v2/GHSA-6g59-hqmc-85v2.json @@ -7,12 +7,8 @@ "CVE-2009-0619" ], "details": "Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gm9-px3f-3pgc/GHSA-6gm9-px3f-3pgc.json b/advisories/unreviewed/2022/05/GHSA-6gm9-px3f-3pgc/GHSA-6gm9-px3f-3pgc.json index 001397f3e49..18b27f79410 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gm9-px3f-3pgc/GHSA-6gm9-px3f-3pgc.json +++ b/advisories/unreviewed/2022/05/GHSA-6gm9-px3f-3pgc/GHSA-6gm9-px3f-3pgc.json @@ -7,12 +7,8 @@ "CVE-2009-0295" ], "details": "SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6grp-pppg-p8xh/GHSA-6grp-pppg-p8xh.json b/advisories/unreviewed/2022/05/GHSA-6grp-pppg-p8xh/GHSA-6grp-pppg-p8xh.json index 48f2f5265e9..43f4f58c6bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6grp-pppg-p8xh/GHSA-6grp-pppg-p8xh.json +++ b/advisories/unreviewed/2022/05/GHSA-6grp-pppg-p8xh/GHSA-6grp-pppg-p8xh.json @@ -7,12 +7,8 @@ "CVE-2009-0409" ], "details": "SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6h2q-7gh7-pc6c/GHSA-6h2q-7gh7-pc6c.json b/advisories/unreviewed/2022/05/GHSA-6h2q-7gh7-pc6c/GHSA-6h2q-7gh7-pc6c.json index 51e97f5fd0f..c6a30750235 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h2q-7gh7-pc6c/GHSA-6h2q-7gh7-pc6c.json +++ b/advisories/unreviewed/2022/05/GHSA-6h2q-7gh7-pc6c/GHSA-6h2q-7gh7-pc6c.json @@ -7,12 +7,8 @@ "CVE-2009-0700" ], "details": "Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hf5-95q4-x9mh/GHSA-6hf5-95q4-x9mh.json b/advisories/unreviewed/2022/05/GHSA-6hf5-95q4-x9mh/GHSA-6hf5-95q4-x9mh.json index 908511ab15b..fc55577297b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hf5-95q4-x9mh/GHSA-6hf5-95q4-x9mh.json +++ b/advisories/unreviewed/2022/05/GHSA-6hf5-95q4-x9mh/GHSA-6hf5-95q4-x9mh.json @@ -7,12 +7,8 @@ "CVE-2009-0798" ], "details": "ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hjc-gh3h-8f6c/GHSA-6hjc-gh3h-8f6c.json b/advisories/unreviewed/2022/05/GHSA-6hjc-gh3h-8f6c/GHSA-6hjc-gh3h-8f6c.json index 280e85e4543..f1e2a78f975 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hjc-gh3h-8f6c/GHSA-6hjc-gh3h-8f6c.json +++ b/advisories/unreviewed/2022/05/GHSA-6hjc-gh3h-8f6c/GHSA-6hjc-gh3h-8f6c.json @@ -7,12 +7,8 @@ "CVE-2009-0646" ], "details": "Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hjp-v6xr-4vrm/GHSA-6hjp-v6xr-4vrm.json b/advisories/unreviewed/2022/05/GHSA-6hjp-v6xr-4vrm/GHSA-6hjp-v6xr-4vrm.json index d504a453a03..c08168f0c64 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hjp-v6xr-4vrm/GHSA-6hjp-v6xr-4vrm.json +++ b/advisories/unreviewed/2022/05/GHSA-6hjp-v6xr-4vrm/GHSA-6hjp-v6xr-4vrm.json @@ -7,12 +7,8 @@ "CVE-2009-0303" ], "details": "Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to \"encoded JavaScript\" and Helpdesk.woa.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j4j-c9wg-pj7g/GHSA-6j4j-c9wg-pj7g.json b/advisories/unreviewed/2022/05/GHSA-6j4j-c9wg-pj7g/GHSA-6j4j-c9wg-pj7g.json index f549398bb71..0c80dfd39ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j4j-c9wg-pj7g/GHSA-6j4j-c9wg-pj7g.json +++ b/advisories/unreviewed/2022/05/GHSA-6j4j-c9wg-pj7g/GHSA-6j4j-c9wg-pj7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mqx-jrfc-9wx3/GHSA-6mqx-jrfc-9wx3.json b/advisories/unreviewed/2022/05/GHSA-6mqx-jrfc-9wx3/GHSA-6mqx-jrfc-9wx3.json index 534e4ba80e5..fbdd0605fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mqx-jrfc-9wx3/GHSA-6mqx-jrfc-9wx3.json +++ b/advisories/unreviewed/2022/05/GHSA-6mqx-jrfc-9wx3/GHSA-6mqx-jrfc-9wx3.json @@ -7,12 +7,8 @@ "CVE-2009-0849" ], "details": "Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a long username field during backup domain authentication, related to nnwindtb.dll. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pw8-f2m7-3gww/GHSA-6pw8-f2m7-3gww.json b/advisories/unreviewed/2022/05/GHSA-6pw8-f2m7-3gww/GHSA-6pw8-f2m7-3gww.json index a185f90a6e2..24beccfed18 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pw8-f2m7-3gww/GHSA-6pw8-f2m7-3gww.json +++ b/advisories/unreviewed/2022/05/GHSA-6pw8-f2m7-3gww/GHSA-6pw8-f2m7-3gww.json @@ -7,12 +7,8 @@ "CVE-2009-0206" ], "details": "Unspecified vulnerability in NFS in HP ONCplus B.11.31.05 and earlier for HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qh3-3xvg-2wvc/GHSA-6qh3-3xvg-2wvc.json b/advisories/unreviewed/2022/05/GHSA-6qh3-3xvg-2wvc/GHSA-6qh3-3xvg-2wvc.json index 97ce8e6eae7..633b81fc380 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qh3-3xvg-2wvc/GHSA-6qh3-3xvg-2wvc.json +++ b/advisories/unreviewed/2022/05/GHSA-6qh3-3xvg-2wvc/GHSA-6qh3-3xvg-2wvc.json @@ -7,12 +7,8 @@ "CVE-2009-0398" ], "details": "Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qm6-486q-42ch/GHSA-6qm6-486q-42ch.json b/advisories/unreviewed/2022/05/GHSA-6qm6-486q-42ch/GHSA-6qm6-486q-42ch.json index 13be78df776..4cbb078e162 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qm6-486q-42ch/GHSA-6qm6-486q-42ch.json +++ b/advisories/unreviewed/2022/05/GHSA-6qm6-486q-42ch/GHSA-6qm6-486q-42ch.json @@ -7,12 +7,8 @@ "CVE-2009-0330" ], "details": "Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qmq-f9pv-3jqp/GHSA-6qmq-f9pv-3jqp.json b/advisories/unreviewed/2022/05/GHSA-6qmq-f9pv-3jqp/GHSA-6qmq-f9pv-3jqp.json index ce7896b85a5..20798f12bf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qmq-f9pv-3jqp/GHSA-6qmq-f9pv-3jqp.json +++ b/advisories/unreviewed/2022/05/GHSA-6qmq-f9pv-3jqp/GHSA-6qmq-f9pv-3jqp.json @@ -7,12 +7,8 @@ "CVE-2009-0878" ], "details": "The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a map with a large (1) width or (2) height.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6r84-xg63-3468/GHSA-6r84-xg63-3468.json b/advisories/unreviewed/2022/05/GHSA-6r84-xg63-3468/GHSA-6r84-xg63-3468.json index 6d6fdcfbafe..eb3b63d8198 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r84-xg63-3468/GHSA-6r84-xg63-3468.json +++ b/advisories/unreviewed/2022/05/GHSA-6r84-xg63-3468/GHSA-6r84-xg63-3468.json @@ -7,12 +7,8 @@ "CVE-2009-0763" ], "details": "Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rg3-f36h-w236/GHSA-6rg3-f36h-w236.json b/advisories/unreviewed/2022/05/GHSA-6rg3-f36h-w236/GHSA-6rg3-f36h-w236.json index 55129350175..dbcba570f7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rg3-f36h-w236/GHSA-6rg3-f36h-w236.json +++ b/advisories/unreviewed/2022/05/GHSA-6rg3-f36h-w236/GHSA-6rg3-f36h-w236.json @@ -7,12 +7,8 @@ "CVE-2009-0418" ], "details": "The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v4f-j7rm-7833/GHSA-6v4f-j7rm-7833.json b/advisories/unreviewed/2022/05/GHSA-6v4f-j7rm-7833/GHSA-6v4f-j7rm-7833.json index 26cbc954134..33fd6eb2853 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v4f-j7rm-7833/GHSA-6v4f-j7rm-7833.json +++ b/advisories/unreviewed/2022/05/GHSA-6v4f-j7rm-7833/GHSA-6v4f-j7rm-7833.json @@ -7,12 +7,8 @@ "CVE-2009-0307" ], "details": "Cross-site scripting (XSS) vulnerability in the \"Customize Statistics Page\" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v56-36fg-xxj3/GHSA-6v56-36fg-xxj3.json b/advisories/unreviewed/2022/05/GHSA-6v56-36fg-xxj3/GHSA-6v56-36fg-xxj3.json index ec8b01c4b56..a83f1f56add 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v56-36fg-xxj3/GHSA-6v56-36fg-xxj3.json +++ b/advisories/unreviewed/2022/05/GHSA-6v56-36fg-xxj3/GHSA-6v56-36fg-xxj3.json @@ -7,12 +7,8 @@ "CVE-2009-0285" ], "details": "Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vj2-4wv8-fm3g/GHSA-6vj2-4wv8-fm3g.json b/advisories/unreviewed/2022/05/GHSA-6vj2-4wv8-fm3g/GHSA-6vj2-4wv8-fm3g.json index e84c11b3f0e..cd171dfb635 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vj2-4wv8-fm3g/GHSA-6vj2-4wv8-fm3g.json +++ b/advisories/unreviewed/2022/05/GHSA-6vj2-4wv8-fm3g/GHSA-6vj2-4wv8-fm3g.json @@ -7,12 +7,8 @@ "CVE-2009-0820" ], "details": "Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vqj-526f-m92q/GHSA-6vqj-526f-m92q.json b/advisories/unreviewed/2022/05/GHSA-6vqj-526f-m92q/GHSA-6vqj-526f-m92q.json index be8bd1dbd97..fcb571d76f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vqj-526f-m92q/GHSA-6vqj-526f-m92q.json +++ b/advisories/unreviewed/2022/05/GHSA-6vqj-526f-m92q/GHSA-6vqj-526f-m92q.json @@ -7,12 +7,8 @@ "CVE-2009-0807" ], "details": "zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w49-wgp5-56q8/GHSA-6w49-wgp5-56q8.json b/advisories/unreviewed/2022/05/GHSA-6w49-wgp5-56q8/GHSA-6w49-wgp5-56q8.json index c0f843fff4c..5ab46a13cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w49-wgp5-56q8/GHSA-6w49-wgp5-56q8.json +++ b/advisories/unreviewed/2022/05/GHSA-6w49-wgp5-56q8/GHSA-6w49-wgp5-56q8.json @@ -7,12 +7,8 @@ "CVE-2014-3872" ], "details": "Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xjj-mf3v-63p8/GHSA-6xjj-mf3v-63p8.json b/advisories/unreviewed/2022/05/GHSA-6xjj-mf3v-63p8/GHSA-6xjj-mf3v-63p8.json index 4f8116a5b4a..666e2058971 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xjj-mf3v-63p8/GHSA-6xjj-mf3v-63p8.json +++ b/advisories/unreviewed/2022/05/GHSA-6xjj-mf3v-63p8/GHSA-6xjj-mf3v-63p8.json @@ -7,12 +7,8 @@ "CVE-2009-0898" ], "details": "Stack-based buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-724h-r536-pwch/GHSA-724h-r536-pwch.json b/advisories/unreviewed/2022/05/GHSA-724h-r536-pwch/GHSA-724h-r536-pwch.json index dd452883371..28083848488 100644 --- a/advisories/unreviewed/2022/05/GHSA-724h-r536-pwch/GHSA-724h-r536-pwch.json +++ b/advisories/unreviewed/2022/05/GHSA-724h-r536-pwch/GHSA-724h-r536-pwch.json @@ -7,12 +7,8 @@ "CVE-2009-0509" ], "details": "Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to execute arbitrary code via a crafted file that triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72rg-w9mr-2x25/GHSA-72rg-w9mr-2x25.json b/advisories/unreviewed/2022/05/GHSA-72rg-w9mr-2x25/GHSA-72rg-w9mr-2x25.json index 9a85bc66f7e..f56aa601b24 100644 --- a/advisories/unreviewed/2022/05/GHSA-72rg-w9mr-2x25/GHSA-72rg-w9mr-2x25.json +++ b/advisories/unreviewed/2022/05/GHSA-72rg-w9mr-2x25/GHSA-72rg-w9mr-2x25.json @@ -7,12 +7,8 @@ "CVE-2009-0744" ], "details": "Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (caret), (5) ` (backquote), or (6) | (pipe) character, followed by an & (ampersand) character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-732f-w5mf-w62p/GHSA-732f-w5mf-w62p.json b/advisories/unreviewed/2022/05/GHSA-732f-w5mf-w62p/GHSA-732f-w5mf-w62p.json index ccf35445bf2..7c53347bbd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-732f-w5mf-w62p/GHSA-732f-w5mf-w62p.json +++ b/advisories/unreviewed/2022/05/GHSA-732f-w5mf-w62p/GHSA-732f-w5mf-w62p.json @@ -7,12 +7,8 @@ "CVE-2009-0830" ], "details": "Cross-site scripting (XSS) vulnerability in QuoteBook allows remote attackers to inject arbitrary web script or HTML via the (1) QuoteName and (2) QuoteText parameters to quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7366-2x8r-hhqr/GHSA-7366-2x8r-hhqr.json b/advisories/unreviewed/2022/05/GHSA-7366-2x8r-hhqr/GHSA-7366-2x8r-hhqr.json index e70a66bdfb0..a41c98f4d9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7366-2x8r-hhqr/GHSA-7366-2x8r-hhqr.json +++ b/advisories/unreviewed/2022/05/GHSA-7366-2x8r-hhqr/GHSA-7366-2x8r-hhqr.json @@ -7,12 +7,8 @@ "CVE-2009-0774" ], "details": "The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73cm-gq9q-9ccx/GHSA-73cm-gq9q-9ccx.json b/advisories/unreviewed/2022/05/GHSA-73cm-gq9q-9ccx/GHSA-73cm-gq9q-9ccx.json index 43883951865..3c05e7036ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-73cm-gq9q-9ccx/GHSA-73cm-gq9q-9ccx.json +++ b/advisories/unreviewed/2022/05/GHSA-73cm-gq9q-9ccx/GHSA-73cm-gq9q-9ccx.json @@ -7,12 +7,8 @@ "CVE-2009-0650" ], "details": "Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73xr-2cwg-3qcx/GHSA-73xr-2cwg-3qcx.json b/advisories/unreviewed/2022/05/GHSA-73xr-2cwg-3qcx/GHSA-73xr-2cwg-3qcx.json index 4abf935496a..a6f9b4ca547 100644 --- a/advisories/unreviewed/2022/05/GHSA-73xr-2cwg-3qcx/GHSA-73xr-2cwg-3qcx.json +++ b/advisories/unreviewed/2022/05/GHSA-73xr-2cwg-3qcx/GHSA-73xr-2cwg-3qcx.json @@ -7,12 +7,8 @@ "CVE-2009-0681" ], "details": "PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-747j-qg37-4w6x/GHSA-747j-qg37-4w6x.json b/advisories/unreviewed/2022/05/GHSA-747j-qg37-4w6x/GHSA-747j-qg37-4w6x.json index a50917afc75..821e0e91a18 100644 --- a/advisories/unreviewed/2022/05/GHSA-747j-qg37-4w6x/GHSA-747j-qg37-4w6x.json +++ b/advisories/unreviewed/2022/05/GHSA-747j-qg37-4w6x/GHSA-747j-qg37-4w6x.json @@ -7,12 +7,8 @@ "CVE-2009-0622" ], "details": "Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8a) allows remote authenticated users to execute arbitrary operating-system commands through a command line interface (CLI).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74gr-5fw9-9jj5/GHSA-74gr-5fw9-9jj5.json b/advisories/unreviewed/2022/05/GHSA-74gr-5fw9-9jj5/GHSA-74gr-5fw9-9jj5.json index 769f020380e..217487b9495 100644 --- a/advisories/unreviewed/2022/05/GHSA-74gr-5fw9-9jj5/GHSA-74gr-5fw9-9jj5.json +++ b/advisories/unreviewed/2022/05/GHSA-74gr-5fw9-9jj5/GHSA-74gr-5fw9-9jj5.json @@ -7,12 +7,8 @@ "CVE-2009-0845" ], "details": "The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75wq-h3mv-pj8q/GHSA-75wq-h3mv-pj8q.json b/advisories/unreviewed/2022/05/GHSA-75wq-h3mv-pj8q/GHSA-75wq-h3mv-pj8q.json index a36a9bff704..068fee62631 100644 --- a/advisories/unreviewed/2022/05/GHSA-75wq-h3mv-pj8q/GHSA-75wq-h3mv-pj8q.json +++ b/advisories/unreviewed/2022/05/GHSA-75wq-h3mv-pj8q/GHSA-75wq-h3mv-pj8q.json @@ -7,12 +7,8 @@ "CVE-2009-0569" ], "details": "Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7679-3vhm-rqqc/GHSA-7679-3vhm-rqqc.json b/advisories/unreviewed/2022/05/GHSA-7679-3vhm-rqqc/GHSA-7679-3vhm-rqqc.json index 0a2f078c60c..e34baf252a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7679-3vhm-rqqc/GHSA-7679-3vhm-rqqc.json +++ b/advisories/unreviewed/2022/05/GHSA-7679-3vhm-rqqc/GHSA-7679-3vhm-rqqc.json @@ -7,12 +7,8 @@ "CVE-2009-0649" ], "details": "The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76ch-p3g6-5mg2/GHSA-76ch-p3g6-5mg2.json b/advisories/unreviewed/2022/05/GHSA-76ch-p3g6-5mg2/GHSA-76ch-p3g6-5mg2.json index e8a8fd04c62..ba82c18e393 100644 --- a/advisories/unreviewed/2022/05/GHSA-76ch-p3g6-5mg2/GHSA-76ch-p3g6-5mg2.json +++ b/advisories/unreviewed/2022/05/GHSA-76ch-p3g6-5mg2/GHSA-76ch-p3g6-5mg2.json @@ -7,12 +7,8 @@ "CVE-2009-0691" ], "details": "The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an invalid memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77qm-m87c-hvv8/GHSA-77qm-m87c-hvv8.json b/advisories/unreviewed/2022/05/GHSA-77qm-m87c-hvv8/GHSA-77qm-m87c-hvv8.json index f6102a42f0e..a1262eda91b 100644 --- a/advisories/unreviewed/2022/05/GHSA-77qm-m87c-hvv8/GHSA-77qm-m87c-hvv8.json +++ b/advisories/unreviewed/2022/05/GHSA-77qm-m87c-hvv8/GHSA-77qm-m87c-hvv8.json @@ -7,12 +7,8 @@ "CVE-2009-0496" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-786q-qmm3-7c5g/GHSA-786q-qmm3-7c5g.json b/advisories/unreviewed/2022/05/GHSA-786q-qmm3-7c5g/GHSA-786q-qmm3-7c5g.json index 29f3cb6357e..6c4012d7490 100644 --- a/advisories/unreviewed/2022/05/GHSA-786q-qmm3-7c5g/GHSA-786q-qmm3-7c5g.json +++ b/advisories/unreviewed/2022/05/GHSA-786q-qmm3-7c5g/GHSA-786q-qmm3-7c5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-788f-pv3h-g3rp/GHSA-788f-pv3h-g3rp.json b/advisories/unreviewed/2022/05/GHSA-788f-pv3h-g3rp/GHSA-788f-pv3h-g3rp.json index 62631918ebd..b442ed2cf09 100644 --- a/advisories/unreviewed/2022/05/GHSA-788f-pv3h-g3rp/GHSA-788f-pv3h-g3rp.json +++ b/advisories/unreviewed/2022/05/GHSA-788f-pv3h-g3rp/GHSA-788f-pv3h-g3rp.json @@ -7,12 +7,8 @@ "CVE-2009-0369" ], "details": "Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a \"Clickjacking\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-789c-jr5q-44hq/GHSA-789c-jr5q-44hq.json b/advisories/unreviewed/2022/05/GHSA-789c-jr5q-44hq/GHSA-789c-jr5q-44hq.json index ee355261fc0..539edcbf682 100644 --- a/advisories/unreviewed/2022/05/GHSA-789c-jr5q-44hq/GHSA-789c-jr5q-44hq.json +++ b/advisories/unreviewed/2022/05/GHSA-789c-jr5q-44hq/GHSA-789c-jr5q-44hq.json @@ -7,12 +7,8 @@ "CVE-2009-0493" ], "details": "SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7938-4cxw-mxw7/GHSA-7938-4cxw-mxw7.json b/advisories/unreviewed/2022/05/GHSA-7938-4cxw-mxw7/GHSA-7938-4cxw-mxw7.json index 58d56368f80..53493dc1cb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7938-4cxw-mxw7/GHSA-7938-4cxw-mxw7.json +++ b/advisories/unreviewed/2022/05/GHSA-7938-4cxw-mxw7/GHSA-7938-4cxw-mxw7.json @@ -7,12 +7,8 @@ "CVE-2009-0817" ], "details": "Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with \"administer site configuration\" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f62-x26q-v865/GHSA-7f62-x26q-v865.json b/advisories/unreviewed/2022/05/GHSA-7f62-x26q-v865/GHSA-7f62-x26q-v865.json index 0a31692a802..cd592962a98 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f62-x26q-v865/GHSA-7f62-x26q-v865.json +++ b/advisories/unreviewed/2022/05/GHSA-7f62-x26q-v865/GHSA-7f62-x26q-v865.json @@ -7,12 +7,8 @@ "CVE-2009-0910" ], "details": "Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ghv-3prv-p3qv/GHSA-7ghv-3prv-p3qv.json b/advisories/unreviewed/2022/05/GHSA-7ghv-3prv-p3qv/GHSA-7ghv-3prv-p3qv.json index d4a0de8300d..e79dbf42b62 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ghv-3prv-p3qv/GHSA-7ghv-3prv-p3qv.json +++ b/advisories/unreviewed/2022/05/GHSA-7ghv-3prv-p3qv/GHSA-7ghv-3prv-p3qv.json @@ -7,12 +7,8 @@ "CVE-2009-0680" ], "details": "cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hwp-g756-phj4/GHSA-7hwp-g756-phj4.json b/advisories/unreviewed/2022/05/GHSA-7hwp-g756-phj4/GHSA-7hwp-g756-phj4.json index 4e5324697ef..466326925e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hwp-g756-phj4/GHSA-7hwp-g756-phj4.json +++ b/advisories/unreviewed/2022/05/GHSA-7hwp-g756-phj4/GHSA-7hwp-g756-phj4.json @@ -7,12 +7,8 @@ "CVE-2009-0888" ], "details": "Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0512, and CVE-2009-0889.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j84-q23m-fvj4/GHSA-7j84-q23m-fvj4.json b/advisories/unreviewed/2022/05/GHSA-7j84-q23m-fvj4/GHSA-7j84-q23m-fvj4.json index f7c7d709d01..d940d8b254e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j84-q23m-fvj4/GHSA-7j84-q23m-fvj4.json +++ b/advisories/unreviewed/2022/05/GHSA-7j84-q23m-fvj4/GHSA-7j84-q23m-fvj4.json @@ -7,12 +7,8 @@ "CVE-2009-0933" ], "details": "Cross-site scripting (XSS) vulnerability in the administrative interface in Dotclear before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jv8-gg36-9gq4/GHSA-7jv8-gg36-9gq4.json b/advisories/unreviewed/2022/05/GHSA-7jv8-gg36-9gq4/GHSA-7jv8-gg36-9gq4.json index 082b5df20a0..0d995b7b97f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jv8-gg36-9gq4/GHSA-7jv8-gg36-9gq4.json +++ b/advisories/unreviewed/2022/05/GHSA-7jv8-gg36-9gq4/GHSA-7jv8-gg36-9gq4.json @@ -7,12 +7,8 @@ "CVE-2009-0535" ], "details": "Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m94-2cc2-pg52/GHSA-7m94-2cc2-pg52.json b/advisories/unreviewed/2022/05/GHSA-7m94-2cc2-pg52/GHSA-7m94-2cc2-pg52.json index c693fde642d..89e45f1dff3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m94-2cc2-pg52/GHSA-7m94-2cc2-pg52.json +++ b/advisories/unreviewed/2022/05/GHSA-7m94-2cc2-pg52/GHSA-7m94-2cc2-pg52.json @@ -7,12 +7,8 @@ "CVE-2009-0210" ], "details": "Buffer overflow in the MLF application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service (system crash) via unspecified vectors, aka PD28578.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pq5-74v8-5639/GHSA-7pq5-74v8-5639.json b/advisories/unreviewed/2022/05/GHSA-7pq5-74v8-5639/GHSA-7pq5-74v8-5639.json index d04750ab2d3..353088c3512 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pq5-74v8-5639/GHSA-7pq5-74v8-5639.json +++ b/advisories/unreviewed/2022/05/GHSA-7pq5-74v8-5639/GHSA-7pq5-74v8-5639.json @@ -7,12 +7,8 @@ "CVE-2009-0110" ], "details": "SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pvv-47jc-4xmm/GHSA-7pvv-47jc-4xmm.json b/advisories/unreviewed/2022/05/GHSA-7pvv-47jc-4xmm/GHSA-7pvv-47jc-4xmm.json index 190736fd7f1..80d95f2105c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pvv-47jc-4xmm/GHSA-7pvv-47jc-4xmm.json +++ b/advisories/unreviewed/2022/05/GHSA-7pvv-47jc-4xmm/GHSA-7pvv-47jc-4xmm.json @@ -7,12 +7,8 @@ "CVE-2009-0299" ], "details": "SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7q9j-2fg6-cx58/GHSA-7q9j-2fg6-cx58.json b/advisories/unreviewed/2022/05/GHSA-7q9j-2fg6-cx58/GHSA-7q9j-2fg6-cx58.json index 60e09a46f4f..f63b3e4cb12 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q9j-2fg6-cx58/GHSA-7q9j-2fg6-cx58.json +++ b/advisories/unreviewed/2022/05/GHSA-7q9j-2fg6-cx58/GHSA-7q9j-2fg6-cx58.json @@ -7,12 +7,8 @@ "CVE-2009-0282" ], "details": "Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qq7-4qxq-r23r/GHSA-7qq7-4qxq-r23r.json b/advisories/unreviewed/2022/05/GHSA-7qq7-4qxq-r23r/GHSA-7qq7-4qxq-r23r.json index ac8880acb4b..3e70ef21fb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qq7-4qxq-r23r/GHSA-7qq7-4qxq-r23r.json +++ b/advisories/unreviewed/2022/05/GHSA-7qq7-4qxq-r23r/GHSA-7qq7-4qxq-r23r.json @@ -7,12 +7,8 @@ "CVE-2009-0492" ], "details": "Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an \"auth vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vjp-w5h4-xj49/GHSA-7vjp-w5h4-xj49.json b/advisories/unreviewed/2022/05/GHSA-7vjp-w5h4-xj49/GHSA-7vjp-w5h4-xj49.json index 9570bf5108d..ae780964b8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vjp-w5h4-xj49/GHSA-7vjp-w5h4-xj49.json +++ b/advisories/unreviewed/2022/05/GHSA-7vjp-w5h4-xj49/GHSA-7vjp-w5h4-xj49.json @@ -7,12 +7,8 @@ "CVE-2009-0412" ], "details": "The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vm5-9rp5-9rv3/GHSA-7vm5-9rp5-9rv3.json b/advisories/unreviewed/2022/05/GHSA-7vm5-9rp5-9rv3/GHSA-7vm5-9rp5-9rv3.json index fc94ded7845..10b9669bcba 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vm5-9rp5-9rv3/GHSA-7vm5-9rp5-9rv3.json +++ b/advisories/unreviewed/2022/05/GHSA-7vm5-9rp5-9rv3/GHSA-7vm5-9rp5-9rv3.json @@ -7,12 +7,8 @@ "CVE-2009-0880" ], "details": "Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wfg-2ggr-wcjc/GHSA-7wfg-2ggr-wcjc.json b/advisories/unreviewed/2022/05/GHSA-7wfg-2ggr-wcjc/GHSA-7wfg-2ggr-wcjc.json index 96259f4f58e..ac573143442 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wfg-2ggr-wcjc/GHSA-7wfg-2ggr-wcjc.json +++ b/advisories/unreviewed/2022/05/GHSA-7wfg-2ggr-wcjc/GHSA-7wfg-2ggr-wcjc.json @@ -7,12 +7,8 @@ "CVE-2009-0314" ], "details": "Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wmx-6crp-mv2f/GHSA-7wmx-6crp-mv2f.json b/advisories/unreviewed/2022/05/GHSA-7wmx-6crp-mv2f/GHSA-7wmx-6crp-mv2f.json index 8f43123d6d4..d99b501e619 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wmx-6crp-mv2f/GHSA-7wmx-6crp-mv2f.json +++ b/advisories/unreviewed/2022/05/GHSA-7wmx-6crp-mv2f/GHSA-7wmx-6crp-mv2f.json @@ -7,12 +7,8 @@ "CVE-2009-0703" ], "details": "SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xjg-w54g-978r/GHSA-7xjg-w54g-978r.json b/advisories/unreviewed/2022/05/GHSA-7xjg-w54g-978r/GHSA-7xjg-w54g-978r.json index e269ca99e7d..3bf47d939f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xjg-w54g-978r/GHSA-7xjg-w54g-978r.json +++ b/advisories/unreviewed/2022/05/GHSA-7xjg-w54g-978r/GHSA-7xjg-w54g-978r.json @@ -7,12 +7,8 @@ "CVE-2009-0867" ], "details": "The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via unspecified requests in a client connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82c9-gp53-cwg2/GHSA-82c9-gp53-cwg2.json b/advisories/unreviewed/2022/05/GHSA-82c9-gp53-cwg2/GHSA-82c9-gp53-cwg2.json index 4852939424a..b84585569c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-82c9-gp53-cwg2/GHSA-82c9-gp53-cwg2.json +++ b/advisories/unreviewed/2022/05/GHSA-82c9-gp53-cwg2/GHSA-82c9-gp53-cwg2.json @@ -7,12 +7,8 @@ "CVE-2009-0884" ], "details": "Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82gw-2j49-6gcc/GHSA-82gw-2j49-6gcc.json b/advisories/unreviewed/2022/05/GHSA-82gw-2j49-6gcc/GHSA-82gw-2j49-6gcc.json index 1b6c630e23e..66eba8ea3ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-82gw-2j49-6gcc/GHSA-82gw-2j49-6gcc.json +++ b/advisories/unreviewed/2022/05/GHSA-82gw-2j49-6gcc/GHSA-82gw-2j49-6gcc.json @@ -7,12 +7,8 @@ "CVE-2009-0394" ], "details": "SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to execute arbitrary SQL commands via the school parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8388-69rw-fpx2/GHSA-8388-69rw-fpx2.json b/advisories/unreviewed/2022/05/GHSA-8388-69rw-fpx2/GHSA-8388-69rw-fpx2.json index fa7cb1fb802..96f15e6c8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8388-69rw-fpx2/GHSA-8388-69rw-fpx2.json +++ b/advisories/unreviewed/2022/05/GHSA-8388-69rw-fpx2/GHSA-8388-69rw-fpx2.json @@ -7,12 +7,8 @@ "CVE-2009-0334" ], "details": "SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the day parameter in an archive action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-854q-8mcq-42vw/GHSA-854q-8mcq-42vw.json b/advisories/unreviewed/2022/05/GHSA-854q-8mcq-42vw/GHSA-854q-8mcq-42vw.json index 334c5bb05d7..4f19d1686b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-854q-8mcq-42vw/GHSA-854q-8mcq-42vw.json +++ b/advisories/unreviewed/2022/05/GHSA-854q-8mcq-42vw/GHSA-854q-8mcq-42vw.json @@ -7,12 +7,8 @@ "CVE-2009-0286" ], "details": "Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85m6-r5vh-hcwp/GHSA-85m6-r5vh-hcwp.json b/advisories/unreviewed/2022/05/GHSA-85m6-r5vh-hcwp/GHSA-85m6-r5vh-hcwp.json index 3c4c57ecf1e..9f021566985 100644 --- a/advisories/unreviewed/2022/05/GHSA-85m6-r5vh-hcwp/GHSA-85m6-r5vh-hcwp.json +++ b/advisories/unreviewed/2022/05/GHSA-85m6-r5vh-hcwp/GHSA-85m6-r5vh-hcwp.json @@ -7,12 +7,8 @@ "CVE-2009-0715" ], "details": "Unspecified vulnerability in Secure NaviCLI in HP Storage Essentials 6.0.2 through 6.0.4 allows remote authenticated users to obtain \"access\" or \"extended privileges\" via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85v8-w5rg-xpmj/GHSA-85v8-w5rg-xpmj.json b/advisories/unreviewed/2022/05/GHSA-85v8-w5rg-xpmj/GHSA-85v8-w5rg-xpmj.json index 315573ae5e7..f74f9ac8922 100644 --- a/advisories/unreviewed/2022/05/GHSA-85v8-w5rg-xpmj/GHSA-85v8-w5rg-xpmj.json +++ b/advisories/unreviewed/2022/05/GHSA-85v8-w5rg-xpmj/GHSA-85v8-w5rg-xpmj.json @@ -7,12 +7,8 @@ "CVE-2009-0770" ], "details": "dkim-milter 2.6.0 through 2.8.0 allows remote attackers to cause a denial of service (crash) by signing a message with a key that has been revoked in DNS, which triggers an assertion error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85x9-prqr-42fq/GHSA-85x9-prqr-42fq.json b/advisories/unreviewed/2022/05/GHSA-85x9-prqr-42fq/GHSA-85x9-prqr-42fq.json index 606c61ea980..d7188ba4320 100644 --- a/advisories/unreviewed/2022/05/GHSA-85x9-prqr-42fq/GHSA-85x9-prqr-42fq.json +++ b/advisories/unreviewed/2022/05/GHSA-85x9-prqr-42fq/GHSA-85x9-prqr-42fq.json @@ -7,12 +7,8 @@ "CVE-2009-0384" ], "details": "SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-863c-wrq8-v36v/GHSA-863c-wrq8-v36v.json b/advisories/unreviewed/2022/05/GHSA-863c-wrq8-v36v/GHSA-863c-wrq8-v36v.json index 5071a6d03e2..39a2c5526b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-863c-wrq8-v36v/GHSA-863c-wrq8-v36v.json +++ b/advisories/unreviewed/2022/05/GHSA-863c-wrq8-v36v/GHSA-863c-wrq8-v36v.json @@ -7,12 +7,8 @@ "CVE-2009-0676" ], "details": "The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87w6-pr52-6h6x/GHSA-87w6-pr52-6h6x.json b/advisories/unreviewed/2022/05/GHSA-87w6-pr52-6h6x/GHSA-87w6-pr52-6h6x.json index b620658db21..471dd7ff244 100644 --- a/advisories/unreviewed/2022/05/GHSA-87w6-pr52-6h6x/GHSA-87w6-pr52-6h6x.json +++ b/advisories/unreviewed/2022/05/GHSA-87w6-pr52-6h6x/GHSA-87w6-pr52-6h6x.json @@ -7,12 +7,8 @@ "CVE-2009-0292" ], "details": "SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88v3-j5hc-8hcq/GHSA-88v3-j5hc-8hcq.json b/advisories/unreviewed/2022/05/GHSA-88v3-j5hc-8hcq/GHSA-88v3-j5hc-8hcq.json index 10956e7eb46..6f6275393e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-88v3-j5hc-8hcq/GHSA-88v3-j5hc-8hcq.json +++ b/advisories/unreviewed/2022/05/GHSA-88v3-j5hc-8hcq/GHSA-88v3-j5hc-8hcq.json @@ -7,12 +7,8 @@ "CVE-2009-0329" ], "details": "SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-897v-gpqx-r9g2/GHSA-897v-gpqx-r9g2.json b/advisories/unreviewed/2022/05/GHSA-897v-gpqx-r9g2/GHSA-897v-gpqx-r9g2.json index 06d6905c6f1..0522870d91a 100644 --- a/advisories/unreviewed/2022/05/GHSA-897v-gpqx-r9g2/GHSA-897v-gpqx-r9g2.json +++ b/advisories/unreviewed/2022/05/GHSA-897v-gpqx-r9g2/GHSA-897v-gpqx-r9g2.json @@ -7,12 +7,8 @@ "CVE-2009-0885" ], "details": "Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c72-8hfr-rwfp/GHSA-8c72-8hfr-rwfp.json b/advisories/unreviewed/2022/05/GHSA-8c72-8hfr-rwfp/GHSA-8c72-8hfr-rwfp.json index 0e989248901..e650adc9258 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c72-8hfr-rwfp/GHSA-8c72-8hfr-rwfp.json +++ b/advisories/unreviewed/2022/05/GHSA-8c72-8hfr-rwfp/GHSA-8c72-8hfr-rwfp.json @@ -7,12 +7,8 @@ "CVE-2009-0540" ], "details": "Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and possibly other versions before 5.5 SP1, allows remote attackers to inject arbitrary web script or HTML via the search term field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8ccp-gg5r-vjf4/GHSA-8ccp-gg5r-vjf4.json b/advisories/unreviewed/2022/05/GHSA-8ccp-gg5r-vjf4/GHSA-8ccp-gg5r-vjf4.json index b76a654ae8e..d09090d0ba6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ccp-gg5r-vjf4/GHSA-8ccp-gg5r-vjf4.json +++ b/advisories/unreviewed/2022/05/GHSA-8ccp-gg5r-vjf4/GHSA-8ccp-gg5r-vjf4.json @@ -7,12 +7,8 @@ "CVE-2009-0582" ], "details": "The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cmf-vm53-gmwg/GHSA-8cmf-vm53-gmwg.json b/advisories/unreviewed/2022/05/GHSA-8cmf-vm53-gmwg/GHSA-8cmf-vm53-gmwg.json index bc27e2d225d..6648e166f69 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cmf-vm53-gmwg/GHSA-8cmf-vm53-gmwg.json +++ b/advisories/unreviewed/2022/05/GHSA-8cmf-vm53-gmwg/GHSA-8cmf-vm53-gmwg.json @@ -7,12 +7,8 @@ "CVE-2009-0705" ], "details": "SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f8x-6454-8222/GHSA-8f8x-6454-8222.json b/advisories/unreviewed/2022/05/GHSA-8f8x-6454-8222/GHSA-8f8x-6454-8222.json index 9cf6f47f65a..03de91533b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f8x-6454-8222/GHSA-8f8x-6454-8222.json +++ b/advisories/unreviewed/2022/05/GHSA-8f8x-6454-8222/GHSA-8f8x-6454-8222.json @@ -7,12 +7,8 @@ "CVE-2009-0490" ], "details": "Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fg6-6hjr-4whj/GHSA-8fg6-6hjr-4whj.json b/advisories/unreviewed/2022/05/GHSA-8fg6-6hjr-4whj/GHSA-8fg6-6hjr-4whj.json index 1fb33959c14..b8f4277c7b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fg6-6hjr-4whj/GHSA-8fg6-6hjr-4whj.json +++ b/advisories/unreviewed/2022/05/GHSA-8fg6-6hjr-4whj/GHSA-8fg6-6hjr-4whj.json @@ -7,12 +7,8 @@ "CVE-2009-0905" ], "details": "IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fmr-hfvg-xqm4/GHSA-8fmr-hfvg-xqm4.json b/advisories/unreviewed/2022/05/GHSA-8fmr-hfvg-xqm4/GHSA-8fmr-hfvg-xqm4.json index d921fef7f0d..90bd8cd48c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fmr-hfvg-xqm4/GHSA-8fmr-hfvg-xqm4.json +++ b/advisories/unreviewed/2022/05/GHSA-8fmr-hfvg-xqm4/GHSA-8fmr-hfvg-xqm4.json @@ -7,12 +7,8 @@ "CVE-2009-0520" ], "details": "Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a \"buffer overflow issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fv4-9pp2-8r8q/GHSA-8fv4-9pp2-8r8q.json b/advisories/unreviewed/2022/05/GHSA-8fv4-9pp2-8r8q/GHSA-8fv4-9pp2-8r8q.json index 957b42ecf7c..40415042331 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fv4-9pp2-8r8q/GHSA-8fv4-9pp2-8r8q.json +++ b/advisories/unreviewed/2022/05/GHSA-8fv4-9pp2-8r8q/GHSA-8fv4-9pp2-8r8q.json @@ -7,12 +7,8 @@ "CVE-2009-0517" ], "details": "Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g22-g786-9c82/GHSA-8g22-g786-9c82.json b/advisories/unreviewed/2022/05/GHSA-8g22-g786-9c82/GHSA-8g22-g786-9c82.json index 038598bdf1a..0302a30d628 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g22-g786-9c82/GHSA-8g22-g786-9c82.json +++ b/advisories/unreviewed/2022/05/GHSA-8g22-g786-9c82/GHSA-8g22-g786-9c82.json @@ -7,12 +7,8 @@ "CVE-2009-0660" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g6v-7hg5-2pqq/GHSA-8g6v-7hg5-2pqq.json b/advisories/unreviewed/2022/05/GHSA-8g6v-7hg5-2pqq/GHSA-8g6v-7hg5-2pqq.json index 5d9a469686e..9182325db03 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g6v-7hg5-2pqq/GHSA-8g6v-7hg5-2pqq.json +++ b/advisories/unreviewed/2022/05/GHSA-8g6v-7hg5-2pqq/GHSA-8g6v-7hg5-2pqq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hfh-gr25-4jc6/GHSA-8hfh-gr25-4jc6.json b/advisories/unreviewed/2022/05/GHSA-8hfh-gr25-4jc6/GHSA-8hfh-gr25-4jc6.json index 58f1defc966..f680ce08087 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hfh-gr25-4jc6/GHSA-8hfh-gr25-4jc6.json +++ b/advisories/unreviewed/2022/05/GHSA-8hfh-gr25-4jc6/GHSA-8hfh-gr25-4jc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jw7-5cpq-xfq7/GHSA-8jw7-5cpq-xfq7.json b/advisories/unreviewed/2022/05/GHSA-8jw7-5cpq-xfq7/GHSA-8jw7-5cpq-xfq7.json index 8aaf8c99f63..915a1a28167 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jw7-5cpq-xfq7/GHSA-8jw7-5cpq-xfq7.json +++ b/advisories/unreviewed/2022/05/GHSA-8jw7-5cpq-xfq7/GHSA-8jw7-5cpq-xfq7.json @@ -7,12 +7,8 @@ "CVE-2009-0750" ], "details": "SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mfv-v727-h99v/GHSA-8mfv-v727-h99v.json b/advisories/unreviewed/2022/05/GHSA-8mfv-v727-h99v/GHSA-8mfv-v727-h99v.json index 8e1d5643e53..58ce38ca2f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mfv-v727-h99v/GHSA-8mfv-v727-h99v.json +++ b/advisories/unreviewed/2022/05/GHSA-8mfv-v727-h99v/GHSA-8mfv-v727-h99v.json @@ -7,12 +7,8 @@ "CVE-2009-0690" ], "details": "The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mg6-gv3c-64f4/GHSA-8mg6-gv3c-64f4.json b/advisories/unreviewed/2022/05/GHSA-8mg6-gv3c-64f4/GHSA-8mg6-gv3c-64f4.json index b1695ad275e..e456e9b1577 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mg6-gv3c-64f4/GHSA-8mg6-gv3c-64f4.json +++ b/advisories/unreviewed/2022/05/GHSA-8mg6-gv3c-64f4/GHSA-8mg6-gv3c-64f4.json @@ -7,12 +7,8 @@ "CVE-2009-0764" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm parameter to (1) index.php and (2) kipper.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q6c-cq42-3qq7/GHSA-8q6c-cq42-3qq7.json b/advisories/unreviewed/2022/05/GHSA-8q6c-cq42-3qq7/GHSA-8q6c-cq42-3qq7.json index c5ec8802fa0..7aa5e5ac79f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q6c-cq42-3qq7/GHSA-8q6c-cq42-3qq7.json +++ b/advisories/unreviewed/2022/05/GHSA-8q6c-cq42-3qq7/GHSA-8q6c-cq42-3qq7.json @@ -7,12 +7,8 @@ "CVE-2009-0588" ], "details": "agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qpf-c75v-7fh9/GHSA-8qpf-c75v-7fh9.json b/advisories/unreviewed/2022/05/GHSA-8qpf-c75v-7fh9/GHSA-8qpf-c75v-7fh9.json index 6ca8d252241..4ab7ffe0f95 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qpf-c75v-7fh9/GHSA-8qpf-c75v-7fh9.json +++ b/advisories/unreviewed/2022/05/GHSA-8qpf-c75v-7fh9/GHSA-8qpf-c75v-7fh9.json @@ -7,12 +7,8 @@ "CVE-2009-0424" ], "details": "Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8v83-6g9r-rxp5/GHSA-8v83-6g9r-rxp5.json b/advisories/unreviewed/2022/05/GHSA-8v83-6g9r-rxp5/GHSA-8v83-6g9r-rxp5.json index d55c69946ce..5787a3ae43e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v83-6g9r-rxp5/GHSA-8v83-6g9r-rxp5.json +++ b/advisories/unreviewed/2022/05/GHSA-8v83-6g9r-rxp5/GHSA-8v83-6g9r-rxp5.json @@ -7,12 +7,8 @@ "CVE-2009-0854" ], "details": "Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x5r-7wjh-26cm/GHSA-8x5r-7wjh-26cm.json b/advisories/unreviewed/2022/05/GHSA-8x5r-7wjh-26cm/GHSA-8x5r-7wjh-26cm.json index 571167a8de9..88354b31b92 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x5r-7wjh-26cm/GHSA-8x5r-7wjh-26cm.json +++ b/advisories/unreviewed/2022/05/GHSA-8x5r-7wjh-26cm/GHSA-8x5r-7wjh-26cm.json @@ -7,12 +7,8 @@ "CVE-2009-0757" ], "details": "Multiple buffer overflows in GNU MPFR 2.4.0 allow context-dependent attackers to cause a denial of service (crash) via the (1) mpfr_snprintf and (2) mpfr_vsnprintf functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92hf-cqpg-w65p/GHSA-92hf-cqpg-w65p.json b/advisories/unreviewed/2022/05/GHSA-92hf-cqpg-w65p/GHSA-92hf-cqpg-w65p.json index 6c0643d11aa..c4a948370e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-92hf-cqpg-w65p/GHSA-92hf-cqpg-w65p.json +++ b/advisories/unreviewed/2022/05/GHSA-92hf-cqpg-w65p/GHSA-92hf-cqpg-w65p.json @@ -7,12 +7,8 @@ "CVE-2009-0923" ], "details": "Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-942f-9q46-rv64/GHSA-942f-9q46-rv64.json b/advisories/unreviewed/2022/05/GHSA-942f-9q46-rv64/GHSA-942f-9q46-rv64.json index 569228d81e1..d10c32eb70a 100644 --- a/advisories/unreviewed/2022/05/GHSA-942f-9q46-rv64/GHSA-942f-9q46-rv64.json +++ b/advisories/unreviewed/2022/05/GHSA-942f-9q46-rv64/GHSA-942f-9q46-rv64.json @@ -7,12 +7,8 @@ "CVE-2009-0913" ], "details": "Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-953q-pp3w-6gv5/GHSA-953q-pp3w-6gv5.json b/advisories/unreviewed/2022/05/GHSA-953q-pp3w-6gv5/GHSA-953q-pp3w-6gv5.json index 80ca3aab066..40c957df83e 100644 --- a/advisories/unreviewed/2022/05/GHSA-953q-pp3w-6gv5/GHSA-953q-pp3w-6gv5.json +++ b/advisories/unreviewed/2022/05/GHSA-953q-pp3w-6gv5/GHSA-953q-pp3w-6gv5.json @@ -7,12 +7,8 @@ "CVE-2009-0508" ], "details": "The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-966f-qj79-3q6f/GHSA-966f-qj79-3q6f.json b/advisories/unreviewed/2022/05/GHSA-966f-qj79-3q6f/GHSA-966f-qj79-3q6f.json index f89b7fc2963..10f9f20ee98 100644 --- a/advisories/unreviewed/2022/05/GHSA-966f-qj79-3q6f/GHSA-966f-qj79-3q6f.json +++ b/advisories/unreviewed/2022/05/GHSA-966f-qj79-3q6f/GHSA-966f-qj79-3q6f.json @@ -7,12 +7,8 @@ "CVE-2009-0862" ], "details": "Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96h4-6356-rcwf/GHSA-96h4-6356-rcwf.json b/advisories/unreviewed/2022/05/GHSA-96h4-6356-rcwf/GHSA-96h4-6356-rcwf.json index 965517bd153..20d030d102b 100644 --- a/advisories/unreviewed/2022/05/GHSA-96h4-6356-rcwf/GHSA-96h4-6356-rcwf.json +++ b/advisories/unreviewed/2022/05/GHSA-96h4-6356-rcwf/GHSA-96h4-6356-rcwf.json @@ -7,12 +7,8 @@ "CVE-2009-0673" ], "details": "Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary PHP code via the ID Field Name box in a yaCustomFields action to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97mm-h3hh-grcf/GHSA-97mm-h3hh-grcf.json b/advisories/unreviewed/2022/05/GHSA-97mm-h3hh-grcf/GHSA-97mm-h3hh-grcf.json index 420555de863..e7a2d631c5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-97mm-h3hh-grcf/GHSA-97mm-h3hh-grcf.json +++ b/advisories/unreviewed/2022/05/GHSA-97mm-h3hh-grcf/GHSA-97mm-h3hh-grcf.json @@ -7,12 +7,8 @@ "CVE-2009-0702" ], "details": "SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-985c-hrh4-r66m/GHSA-985c-hrh4-r66m.json b/advisories/unreviewed/2022/05/GHSA-985c-hrh4-r66m/GHSA-985c-hrh4-r66m.json index 85606c74eff..21eb60c07a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-985c-hrh4-r66m/GHSA-985c-hrh4-r66m.json +++ b/advisories/unreviewed/2022/05/GHSA-985c-hrh4-r66m/GHSA-985c-hrh4-r66m.json @@ -7,12 +7,8 @@ "CVE-2009-0848" ], "details": "Untrusted search path vulnerability in GTK2 in OpenSUSE 11.0 and 11.1 allows local users to execute arbitrary code via a Trojan horse GTK module in an unspecified \"relative search path.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98gw-95vg-gmj8/GHSA-98gw-95vg-gmj8.json b/advisories/unreviewed/2022/05/GHSA-98gw-95vg-gmj8/GHSA-98gw-95vg-gmj8.json index cf585a2d57d..81954cbe569 100644 --- a/advisories/unreviewed/2022/05/GHSA-98gw-95vg-gmj8/GHSA-98gw-95vg-gmj8.json +++ b/advisories/unreviewed/2022/05/GHSA-98gw-95vg-gmj8/GHSA-98gw-95vg-gmj8.json @@ -7,12 +7,8 @@ "CVE-2009-0516" ], "details": "SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98mm-h5qc-pfvj/GHSA-98mm-h5qc-pfvj.json b/advisories/unreviewed/2022/05/GHSA-98mm-h5qc-pfvj/GHSA-98mm-h5qc-pfvj.json index 8f9a598092e..e1a64e70089 100644 --- a/advisories/unreviewed/2022/05/GHSA-98mm-h5qc-pfvj/GHSA-98mm-h5qc-pfvj.json +++ b/advisories/unreviewed/2022/05/GHSA-98mm-h5qc-pfvj/GHSA-98mm-h5qc-pfvj.json @@ -7,12 +7,8 @@ "CVE-2009-0833" ], "details": "Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98mq-jm9g-w68j/GHSA-98mq-jm9g-w68j.json b/advisories/unreviewed/2022/05/GHSA-98mq-jm9g-w68j/GHSA-98mq-jm9g-w68j.json index d812c2db91f..7b179889df0 100644 --- a/advisories/unreviewed/2022/05/GHSA-98mq-jm9g-w68j/GHSA-98mq-jm9g-w68j.json +++ b/advisories/unreviewed/2022/05/GHSA-98mq-jm9g-w68j/GHSA-98mq-jm9g-w68j.json @@ -7,12 +7,8 @@ "CVE-2009-0723" ], "details": "Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9964-6v8v-vcrv/GHSA-9964-6v8v-vcrv.json b/advisories/unreviewed/2022/05/GHSA-9964-6v8v-vcrv/GHSA-9964-6v8v-vcrv.json index 68b68ba9932..c1e6bdc120d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9964-6v8v-vcrv/GHSA-9964-6v8v-vcrv.json +++ b/advisories/unreviewed/2022/05/GHSA-9964-6v8v-vcrv/GHSA-9964-6v8v-vcrv.json @@ -7,12 +7,8 @@ "CVE-2009-0488" ], "details": "Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99g2-gvrx-c624/GHSA-99g2-gvrx-c624.json b/advisories/unreviewed/2022/05/GHSA-99g2-gvrx-c624/GHSA-99g2-gvrx-c624.json index d3228ec797f..f38f4068169 100644 --- a/advisories/unreviewed/2022/05/GHSA-99g2-gvrx-c624/GHSA-99g2-gvrx-c624.json +++ b/advisories/unreviewed/2022/05/GHSA-99g2-gvrx-c624/GHSA-99g2-gvrx-c624.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99jp-rppc-jgcm/GHSA-99jp-rppc-jgcm.json b/advisories/unreviewed/2022/05/GHSA-99jp-rppc-jgcm/GHSA-99jp-rppc-jgcm.json index 28fc76dba93..d78ec75dd9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-99jp-rppc-jgcm/GHSA-99jp-rppc-jgcm.json +++ b/advisories/unreviewed/2022/05/GHSA-99jp-rppc-jgcm/GHSA-99jp-rppc-jgcm.json @@ -7,12 +7,8 @@ "CVE-2009-0689" ], "details": "Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99px-4qq2-5h8w/GHSA-99px-4qq2-5h8w.json b/advisories/unreviewed/2022/05/GHSA-99px-4qq2-5h8w/GHSA-99px-4qq2-5h8w.json index f426206a3af..c1bbd95a490 100644 --- a/advisories/unreviewed/2022/05/GHSA-99px-4qq2-5h8w/GHSA-99px-4qq2-5h8w.json +++ b/advisories/unreviewed/2022/05/GHSA-99px-4qq2-5h8w/GHSA-99px-4qq2-5h8w.json @@ -7,12 +7,8 @@ "CVE-2009-0664" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in a user view.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c86-vmgf-xhff/GHSA-9c86-vmgf-xhff.json b/advisories/unreviewed/2022/05/GHSA-9c86-vmgf-xhff/GHSA-9c86-vmgf-xhff.json index 9f0e94065f9..fd317fc78b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c86-vmgf-xhff/GHSA-9c86-vmgf-xhff.json +++ b/advisories/unreviewed/2022/05/GHSA-9c86-vmgf-xhff/GHSA-9c86-vmgf-xhff.json @@ -7,12 +7,8 @@ "CVE-2009-0592" ], "details": "Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_words.php, (2) admin_groups_reapir.php, (3) admin_smilies.php, (4) admin_ranks.php, (5) admin_styles.php, and (6) admin_users.php in admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cm7-h72q-68c2/GHSA-9cm7-h72q-68c2.json b/advisories/unreviewed/2022/05/GHSA-9cm7-h72q-68c2/GHSA-9cm7-h72q-68c2.json index 90128bfe023..86b580e4de4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cm7-h72q-68c2/GHSA-9cm7-h72q-68c2.json +++ b/advisories/unreviewed/2022/05/GHSA-9cm7-h72q-68c2/GHSA-9cm7-h72q-68c2.json @@ -7,12 +7,8 @@ "CVE-2009-0515" ], "details": "Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cr7-r39p-2mx5/GHSA-9cr7-r39p-2mx5.json b/advisories/unreviewed/2022/05/GHSA-9cr7-r39p-2mx5/GHSA-9cr7-r39p-2mx5.json index e2565586cbf..9e8a55942eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cr7-r39p-2mx5/GHSA-9cr7-r39p-2mx5.json +++ b/advisories/unreviewed/2022/05/GHSA-9cr7-r39p-2mx5/GHSA-9cr7-r39p-2mx5.json @@ -7,12 +7,8 @@ "CVE-2009-0318" ], "details": "Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9f5h-hg7j-7q6j/GHSA-9f5h-hg7j-7q6j.json b/advisories/unreviewed/2022/05/GHSA-9f5h-hg7j-7q6j/GHSA-9f5h-hg7j-7q6j.json index 643907fc1c0..714438a0b5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f5h-hg7j-7q6j/GHSA-9f5h-hg7j-7q6j.json +++ b/advisories/unreviewed/2022/05/GHSA-9f5h-hg7j-7q6j/GHSA-9f5h-hg7j-7q6j.json @@ -7,12 +7,8 @@ "CVE-2009-0324" ], "details": "Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fg3-9fvv-rq8q/GHSA-9fg3-9fvv-rq8q.json b/advisories/unreviewed/2022/05/GHSA-9fg3-9fvv-rq8q/GHSA-9fg3-9fvv-rq8q.json index 7a661c9a1b8..35fbb7e6633 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fg3-9fvv-rq8q/GHSA-9fg3-9fvv-rq8q.json +++ b/advisories/unreviewed/2022/05/GHSA-9fg3-9fvv-rq8q/GHSA-9fg3-9fvv-rq8q.json @@ -7,12 +7,8 @@ "CVE-2009-0915" ], "details": "Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fjq-qvpr-gcq2/GHSA-9fjq-qvpr-gcq2.json b/advisories/unreviewed/2022/05/GHSA-9fjq-qvpr-gcq2/GHSA-9fjq-qvpr-gcq2.json index c46fc2d1a35..877ce2ad59f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fjq-qvpr-gcq2/GHSA-9fjq-qvpr-gcq2.json +++ b/advisories/unreviewed/2022/05/GHSA-9fjq-qvpr-gcq2/GHSA-9fjq-qvpr-gcq2.json @@ -7,12 +7,8 @@ "CVE-2009-0537" ], "details": "Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hp4-phw8-8rq6/GHSA-9hp4-phw8-8rq6.json b/advisories/unreviewed/2022/05/GHSA-9hp4-phw8-8rq6/GHSA-9hp4-phw8-8rq6.json index a3182a61b6d..113a1c47455 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hp4-phw8-8rq6/GHSA-9hp4-phw8-8rq6.json +++ b/advisories/unreviewed/2022/05/GHSA-9hp4-phw8-8rq6/GHSA-9hp4-phw8-8rq6.json @@ -7,12 +7,8 @@ "CVE-2009-0625" ], "details": "Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8.0) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv3 packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hwp-r56m-3mcm/GHSA-9hwp-r56m-3mcm.json b/advisories/unreviewed/2022/05/GHSA-9hwp-r56m-3mcm/GHSA-9hwp-r56m-3mcm.json index 2600a8d6301..3631a7c8f1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hwp-r56m-3mcm/GHSA-9hwp-r56m-3mcm.json +++ b/advisories/unreviewed/2022/05/GHSA-9hwp-r56m-3mcm/GHSA-9hwp-r56m-3mcm.json @@ -7,12 +7,8 @@ "CVE-2009-0598" ], "details": "SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mrj-942p-5339/GHSA-9mrj-942p-5339.json b/advisories/unreviewed/2022/05/GHSA-9mrj-942p-5339/GHSA-9mrj-942p-5339.json index ceec2418f6b..c9cf15e105a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mrj-942p-5339/GHSA-9mrj-942p-5339.json +++ b/advisories/unreviewed/2022/05/GHSA-9mrj-942p-5339/GHSA-9mrj-942p-5339.json @@ -7,12 +7,8 @@ "CVE-2009-0738" ], "details": "SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p53-hww6-pm2p/GHSA-9p53-hww6-pm2p.json b/advisories/unreviewed/2022/05/GHSA-9p53-hww6-pm2p/GHSA-9p53-hww6-pm2p.json index d239cfb1609..1e51fa81012 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p53-hww6-pm2p/GHSA-9p53-hww6-pm2p.json +++ b/advisories/unreviewed/2022/05/GHSA-9p53-hww6-pm2p/GHSA-9p53-hww6-pm2p.json @@ -7,12 +7,8 @@ "CVE-2009-0545" ], "details": "cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q83-cv5j-75hv/GHSA-9q83-cv5j-75hv.json b/advisories/unreviewed/2022/05/GHSA-9q83-cv5j-75hv/GHSA-9q83-cv5j-75hv.json index 0601bff1e60..1ab24f2999f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q83-cv5j-75hv/GHSA-9q83-cv5j-75hv.json +++ b/advisories/unreviewed/2022/05/GHSA-9q83-cv5j-75hv/GHSA-9q83-cv5j-75hv.json @@ -7,12 +7,8 @@ "CVE-2009-0103" ], "details": "Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q9q-525p-x46x/GHSA-9q9q-525p-x46x.json b/advisories/unreviewed/2022/05/GHSA-9q9q-525p-x46x/GHSA-9q9q-525p-x46x.json index 0870a23bd93..f493b46bfee 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q9q-525p-x46x/GHSA-9q9q-525p-x46x.json +++ b/advisories/unreviewed/2022/05/GHSA-9q9q-525p-x46x/GHSA-9q9q-525p-x46x.json @@ -7,12 +7,8 @@ "CVE-2009-0777" ], "details": "Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r5g-wj95-f57q/GHSA-9r5g-wj95-f57q.json b/advisories/unreviewed/2022/05/GHSA-9r5g-wj95-f57q/GHSA-9r5g-wj95-f57q.json index e8f90ffaa64..37ab25c11bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r5g-wj95-f57q/GHSA-9r5g-wj95-f57q.json +++ b/advisories/unreviewed/2022/05/GHSA-9r5g-wj95-f57q/GHSA-9r5g-wj95-f57q.json @@ -7,12 +7,8 @@ "CVE-2009-0839" ], "details": "Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rm9-22p9-f7rc/GHSA-9rm9-22p9-f7rc.json b/advisories/unreviewed/2022/05/GHSA-9rm9-22p9-f7rc/GHSA-9rm9-22p9-f7rc.json index 588c0ac0b15..1f1468bd67d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rm9-22p9-f7rc/GHSA-9rm9-22p9-f7rc.json +++ b/advisories/unreviewed/2022/05/GHSA-9rm9-22p9-f7rc/GHSA-9rm9-22p9-f7rc.json @@ -7,12 +7,8 @@ "CVE-2009-0612" ], "details": "Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v7v-7ff8-chr8/GHSA-9v7v-7ff8-chr8.json b/advisories/unreviewed/2022/05/GHSA-9v7v-7ff8-chr8/GHSA-9v7v-7ff8-chr8.json index 224313ffbc5..ecc3417031e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v7v-7ff8-chr8/GHSA-9v7v-7ff8-chr8.json +++ b/advisories/unreviewed/2022/05/GHSA-9v7v-7ff8-chr8/GHSA-9v7v-7ff8-chr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c22j-84c7-cm77/GHSA-c22j-84c7-cm77.json b/advisories/unreviewed/2022/05/GHSA-c22j-84c7-cm77/GHSA-c22j-84c7-cm77.json index d64af72a4cf..e627e89e539 100644 --- a/advisories/unreviewed/2022/05/GHSA-c22j-84c7-cm77/GHSA-c22j-84c7-cm77.json +++ b/advisories/unreviewed/2022/05/GHSA-c22j-84c7-cm77/GHSA-c22j-84c7-cm77.json @@ -7,12 +7,8 @@ "CVE-2009-0815" ], "details": "The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2px-jjjp-g9r6/GHSA-c2px-jjjp-g9r6.json b/advisories/unreviewed/2022/05/GHSA-c2px-jjjp-g9r6/GHSA-c2px-jjjp-g9r6.json index c687128cb1b..625125945d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2px-jjjp-g9r6/GHSA-c2px-jjjp-g9r6.json +++ b/advisories/unreviewed/2022/05/GHSA-c2px-jjjp-g9r6/GHSA-c2px-jjjp-g9r6.json @@ -7,12 +7,8 @@ "CVE-2009-0769" ], "details": "QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\\rtf\\pict\\&&} message. NOTE: the vulnerability may be in Sergey Tkachenko TRichView. If so, then this should not be treated as a vulnerability in QIP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2r9-f55m-3283/GHSA-c2r9-f55m-3283.json b/advisories/unreviewed/2022/05/GHSA-c2r9-f55m-3283/GHSA-c2r9-f55m-3283.json index f79ed825399..a23dde75ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2r9-f55m-3283/GHSA-c2r9-f55m-3283.json +++ b/advisories/unreviewed/2022/05/GHSA-c2r9-f55m-3283/GHSA-c2r9-f55m-3283.json @@ -7,12 +7,8 @@ "CVE-2009-0399" ], "details": "Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c435-2cgx-2393/GHSA-c435-2cgx-2393.json b/advisories/unreviewed/2022/05/GHSA-c435-2cgx-2393/GHSA-c435-2cgx-2393.json index f51e27de81c..d5fec553817 100644 --- a/advisories/unreviewed/2022/05/GHSA-c435-2cgx-2393/GHSA-c435-2cgx-2393.json +++ b/advisories/unreviewed/2022/05/GHSA-c435-2cgx-2393/GHSA-c435-2cgx-2393.json @@ -7,12 +7,8 @@ "CVE-2009-0538" ], "details": "Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4wq-484p-4fxv/GHSA-c4wq-484p-4fxv.json b/advisories/unreviewed/2022/05/GHSA-c4wq-484p-4fxv/GHSA-c4wq-484p-4fxv.json index 63223361bd6..d9311521025 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4wq-484p-4fxv/GHSA-c4wq-484p-4fxv.json +++ b/advisories/unreviewed/2022/05/GHSA-c4wq-484p-4fxv/GHSA-c4wq-484p-4fxv.json @@ -7,12 +7,8 @@ "CVE-2009-0926" ], "details": "Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5h4-7vc8-8w5m/GHSA-c5h4-7vc8-8w5m.json b/advisories/unreviewed/2022/05/GHSA-c5h4-7vc8-8w5m/GHSA-c5h4-7vc8-8w5m.json index a75ba15f2d5..dd2289b1728 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5h4-7vc8-8w5m/GHSA-c5h4-7vc8-8w5m.json +++ b/advisories/unreviewed/2022/05/GHSA-c5h4-7vc8-8w5m/GHSA-c5h4-7vc8-8w5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c866-v92q-4c7x/GHSA-c866-v92q-4c7x.json b/advisories/unreviewed/2022/05/GHSA-c866-v92q-4c7x/GHSA-c866-v92q-4c7x.json index ec8cfd659b9..f1a1609916e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c866-v92q-4c7x/GHSA-c866-v92q-4c7x.json +++ b/advisories/unreviewed/2022/05/GHSA-c866-v92q-4c7x/GHSA-c866-v92q-4c7x.json @@ -7,12 +7,8 @@ "CVE-2009-0832" ], "details": "SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c877-3vrh-rhqh/GHSA-c877-3vrh-rhqh.json b/advisories/unreviewed/2022/05/GHSA-c877-3vrh-rhqh/GHSA-c877-3vrh-rhqh.json index 211ff011525..f31257e7ab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c877-3vrh-rhqh/GHSA-c877-3vrh-rhqh.json +++ b/advisories/unreviewed/2022/05/GHSA-c877-3vrh-rhqh/GHSA-c877-3vrh-rhqh.json @@ -7,12 +7,8 @@ "CVE-2009-0682" ], "details": "vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys before 9.0.0.184 in Internet Security Suite r4, and vetmonnt.sys before 10.0.0.217 in Internet Security Suite r5 do not properly verify IOCTL calls, which allows local users to cause a denial of service (system crash) via a crafted call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8w3-hh73-w2mx/GHSA-c8w3-hh73-w2mx.json b/advisories/unreviewed/2022/05/GHSA-c8w3-hh73-w2mx/GHSA-c8w3-hh73-w2mx.json index e0476f3dd38..57d15c0b99c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8w3-hh73-w2mx/GHSA-c8w3-hh73-w2mx.json +++ b/advisories/unreviewed/2022/05/GHSA-c8w3-hh73-w2mx/GHSA-c8w3-hh73-w2mx.json @@ -7,12 +7,8 @@ "CVE-2009-0753" ], "details": "Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading \"//\" (double slash) in the filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccw3-9mr4-px9j/GHSA-ccw3-9mr4-px9j.json b/advisories/unreviewed/2022/05/GHSA-ccw3-9mr4-px9j/GHSA-ccw3-9mr4-px9j.json index 96ca9202e45..a803dd0eda3 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccw3-9mr4-px9j/GHSA-ccw3-9mr4-px9j.json +++ b/advisories/unreviewed/2022/05/GHSA-ccw3-9mr4-px9j/GHSA-ccw3-9mr4-px9j.json @@ -7,12 +7,8 @@ "CVE-2009-0202" ], "details": "Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified \"layout information\" that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfrx-jj8w-q779/GHSA-cfrx-jj8w-q779.json b/advisories/unreviewed/2022/05/GHSA-cfrx-jj8w-q779/GHSA-cfrx-jj8w-q779.json index a758ceda4e4..570fca12388 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfrx-jj8w-q779/GHSA-cfrx-jj8w-q779.json +++ b/advisories/unreviewed/2022/05/GHSA-cfrx-jj8w-q779/GHSA-cfrx-jj8w-q779.json @@ -7,12 +7,8 @@ "CVE-2009-0632" ], "details": "The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cg2r-qprp-qch8/GHSA-cg2r-qprp-qch8.json b/advisories/unreviewed/2022/05/GHSA-cg2r-qprp-qch8/GHSA-cg2r-qprp-qch8.json index a8edd61bb41..b2dd343c215 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg2r-qprp-qch8/GHSA-cg2r-qprp-qch8.json +++ b/advisories/unreviewed/2022/05/GHSA-cg2r-qprp-qch8/GHSA-cg2r-qprp-qch8.json @@ -7,12 +7,8 @@ "CVE-2009-0864" ], "details": "S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg8c-5wpg-6v3r/GHSA-cg8c-5wpg-6v3r.json b/advisories/unreviewed/2022/05/GHSA-cg8c-5wpg-6v3r/GHSA-cg8c-5wpg-6v3r.json index 73f8eed9927..d62f3e146c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg8c-5wpg-6v3r/GHSA-cg8c-5wpg-6v3r.json +++ b/advisories/unreviewed/2022/05/GHSA-cg8c-5wpg-6v3r/GHSA-cg8c-5wpg-6v3r.json @@ -7,12 +7,8 @@ "CVE-2009-0349" ], "details": "Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code via a long string in a licensing key (aka .key) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg9g-rv3x-h9hh/GHSA-cg9g-rv3x-h9hh.json b/advisories/unreviewed/2022/05/GHSA-cg9g-rv3x-h9hh/GHSA-cg9g-rv3x-h9hh.json index 4450af949f9..9960487f30b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg9g-rv3x-h9hh/GHSA-cg9g-rv3x-h9hh.json +++ b/advisories/unreviewed/2022/05/GHSA-cg9g-rv3x-h9hh/GHSA-cg9g-rv3x-h9hh.json @@ -7,12 +7,8 @@ "CVE-2009-0615" ], "details": "Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to \"invalid directory permissions.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgqc-3hp2-g8cm/GHSA-cgqc-3hp2-g8cm.json b/advisories/unreviewed/2022/05/GHSA-cgqc-3hp2-g8cm/GHSA-cgqc-3hp2-g8cm.json index 7f4057398b7..ce1df23b394 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgqc-3hp2-g8cm/GHSA-cgqc-3hp2-g8cm.json +++ b/advisories/unreviewed/2022/05/GHSA-cgqc-3hp2-g8cm/GHSA-cgqc-3hp2-g8cm.json @@ -7,12 +7,8 @@ "CVE-2009-0393" ], "details": "Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch2p-q2rq-mx89/GHSA-ch2p-q2rq-mx89.json b/advisories/unreviewed/2022/05/GHSA-ch2p-q2rq-mx89/GHSA-ch2p-q2rq-mx89.json index ae6640a3c28..7d264a029d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch2p-q2rq-mx89/GHSA-ch2p-q2rq-mx89.json +++ b/advisories/unreviewed/2022/05/GHSA-ch2p-q2rq-mx89/GHSA-ch2p-q2rq-mx89.json @@ -7,12 +7,8 @@ "CVE-2009-0382" ], "details": "Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with \"translate node\" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chpx-8rvc-g3x2/GHSA-chpx-8rvc-g3x2.json b/advisories/unreviewed/2022/05/GHSA-chpx-8rvc-g3x2/GHSA-chpx-8rvc-g3x2.json index a2d3d2f7f0d..3b0407da33e 100644 --- a/advisories/unreviewed/2022/05/GHSA-chpx-8rvc-g3x2/GHSA-chpx-8rvc-g3x2.json +++ b/advisories/unreviewed/2022/05/GHSA-chpx-8rvc-g3x2/GHSA-chpx-8rvc-g3x2.json @@ -7,12 +7,8 @@ "CVE-2009-0717" ], "details": "Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjw8-pp44-m8v2/GHSA-cjw8-pp44-m8v2.json b/advisories/unreviewed/2022/05/GHSA-cjw8-pp44-m8v2/GHSA-cjw8-pp44-m8v2.json index d2179bc6b35..6cd4740fe71 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjw8-pp44-m8v2/GHSA-cjw8-pp44-m8v2.json +++ b/advisories/unreviewed/2022/05/GHSA-cjw8-pp44-m8v2/GHSA-cjw8-pp44-m8v2.json @@ -7,12 +7,8 @@ "CVE-2009-0692" ], "details": "Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmhq-wv7c-g9x5/GHSA-cmhq-wv7c-g9x5.json b/advisories/unreviewed/2022/05/GHSA-cmhq-wv7c-g9x5/GHSA-cmhq-wv7c-g9x5.json index 31c0c1466d4..3ae62d48b2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmhq-wv7c-g9x5/GHSA-cmhq-wv7c-g9x5.json +++ b/advisories/unreviewed/2022/05/GHSA-cmhq-wv7c-g9x5/GHSA-cmhq-wv7c-g9x5.json @@ -7,12 +7,8 @@ "CVE-2009-0640" ], "details": "Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by reading the vy_netman.cfg file that contains passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqgv-w6qr-qjjg/GHSA-cqgv-w6qr-qjjg.json b/advisories/unreviewed/2022/05/GHSA-cqgv-w6qr-qjjg/GHSA-cqgv-w6qr-qjjg.json index 667982538d7..8950f1e7263 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqgv-w6qr-qjjg/GHSA-cqgv-w6qr-qjjg.json +++ b/advisories/unreviewed/2022/05/GHSA-cqgv-w6qr-qjjg/GHSA-cqgv-w6qr-qjjg.json @@ -7,12 +7,8 @@ "CVE-2009-0472" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crvg-x5wh-vfgr/GHSA-crvg-x5wh-vfgr.json b/advisories/unreviewed/2022/05/GHSA-crvg-x5wh-vfgr/GHSA-crvg-x5wh-vfgr.json index 05cc2f09551..a06cdeaf86b 100644 --- a/advisories/unreviewed/2022/05/GHSA-crvg-x5wh-vfgr/GHSA-crvg-x5wh-vfgr.json +++ b/advisories/unreviewed/2022/05/GHSA-crvg-x5wh-vfgr/GHSA-crvg-x5wh-vfgr.json @@ -7,12 +7,8 @@ "CVE-2009-0595" ], "details": "PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv5g-5rc7-m952/GHSA-cv5g-5rc7-m952.json b/advisories/unreviewed/2022/05/GHSA-cv5g-5rc7-m952/GHSA-cv5g-5rc7-m952.json index b8b74c3804b..ee785beb844 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv5g-5rc7-m952/GHSA-cv5g-5rc7-m952.json +++ b/advisories/unreviewed/2022/05/GHSA-cv5g-5rc7-m952/GHSA-cv5g-5rc7-m952.json @@ -7,12 +7,8 @@ "CVE-2009-0607" ], "details": "Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvqw-r6hp-64wg/GHSA-cvqw-r6hp-64wg.json b/advisories/unreviewed/2022/05/GHSA-cvqw-r6hp-64wg/GHSA-cvqw-r6hp-64wg.json index fe713d28cde..3a452f6665c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvqw-r6hp-64wg/GHSA-cvqw-r6hp-64wg.json +++ b/advisories/unreviewed/2022/05/GHSA-cvqw-r6hp-64wg/GHSA-cvqw-r6hp-64wg.json @@ -7,12 +7,8 @@ "CVE-2009-0914" ], "details": "Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx98-m4w9-fjjw/GHSA-cx98-m4w9-fjjw.json b/advisories/unreviewed/2022/05/GHSA-cx98-m4w9-fjjw/GHSA-cx98-m4w9-fjjw.json index 66bb7bdeba8..b0d7c1f31c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx98-m4w9-fjjw/GHSA-cx98-m4w9-fjjw.json +++ b/advisories/unreviewed/2022/05/GHSA-cx98-m4w9-fjjw/GHSA-cx98-m4w9-fjjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxq6-6473-qf7m/GHSA-cxq6-6473-qf7m.json b/advisories/unreviewed/2022/05/GHSA-cxq6-6473-qf7m/GHSA-cxq6-6473-qf7m.json index cf6e04576f0..0c448aad014 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxq6-6473-qf7m/GHSA-cxq6-6473-qf7m.json +++ b/advisories/unreviewed/2022/05/GHSA-cxq6-6473-qf7m/GHSA-cxq6-6473-qf7m.json @@ -7,12 +7,8 @@ "CVE-2009-0829" ], "details": "Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxxf-wj3r-6r8r/GHSA-cxxf-wj3r-6r8r.json b/advisories/unreviewed/2022/05/GHSA-cxxf-wj3r-6r8r/GHSA-cxxf-wj3r-6r8r.json index ace17c22256..6c51b012b4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxxf-wj3r-6r8r/GHSA-cxxf-wj3r-6r8r.json +++ b/advisories/unreviewed/2022/05/GHSA-cxxf-wj3r-6r8r/GHSA-cxxf-wj3r-6r8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f296-f6r3-pgjg/GHSA-f296-f6r3-pgjg.json b/advisories/unreviewed/2022/05/GHSA-f296-f6r3-pgjg/GHSA-f296-f6r3-pgjg.json index 124ed96011c..47b70f1b58c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f296-f6r3-pgjg/GHSA-f296-f6r3-pgjg.json +++ b/advisories/unreviewed/2022/05/GHSA-f296-f6r3-pgjg/GHSA-f296-f6r3-pgjg.json @@ -7,12 +7,8 @@ "CVE-2009-0858" ], "details": "The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2gm-jjfh-hrpg/GHSA-f2gm-jjfh-hrpg.json b/advisories/unreviewed/2022/05/GHSA-f2gm-jjfh-hrpg/GHSA-f2gm-jjfh-hrpg.json index 24ae5b3fd16..b0030ab8690 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2gm-jjfh-hrpg/GHSA-f2gm-jjfh-hrpg.json +++ b/advisories/unreviewed/2022/05/GHSA-f2gm-jjfh-hrpg/GHSA-f2gm-jjfh-hrpg.json @@ -7,12 +7,8 @@ "CVE-2009-0106" ], "details": "SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2r4-w89x-fvh9/GHSA-f2r4-w89x-fvh9.json b/advisories/unreviewed/2022/05/GHSA-f2r4-w89x-fvh9/GHSA-f2r4-w89x-fvh9.json index 23b318eb5df..be264ef539e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2r4-w89x-fvh9/GHSA-f2r4-w89x-fvh9.json +++ b/advisories/unreviewed/2022/05/GHSA-f2r4-w89x-fvh9/GHSA-f2r4-w89x-fvh9.json @@ -7,12 +7,8 @@ "CVE-2009-0315" ], "details": "Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4m4-7v69-w894/GHSA-f4m4-7v69-w894.json b/advisories/unreviewed/2022/05/GHSA-f4m4-7v69-w894/GHSA-f4m4-7v69-w894.json index 10338fc42e7..fba02ac0813 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4m4-7v69-w894/GHSA-f4m4-7v69-w894.json +++ b/advisories/unreviewed/2022/05/GHSA-f4m4-7v69-w894/GHSA-f4m4-7v69-w894.json @@ -7,12 +7,8 @@ "CVE-2009-0806" ], "details": "Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f594-w3vj-gf5c/GHSA-f594-w3vj-gf5c.json b/advisories/unreviewed/2022/05/GHSA-f594-w3vj-gf5c/GHSA-f594-w3vj-gf5c.json index fa4b06c1c9c..7f46af11cdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f594-w3vj-gf5c/GHSA-f594-w3vj-gf5c.json +++ b/advisories/unreviewed/2022/05/GHSA-f594-w3vj-gf5c/GHSA-f594-w3vj-gf5c.json @@ -7,12 +7,8 @@ "CVE-2009-0759" ], "details": "Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json b/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json index f8e0fffdcf3..7d50dcea26f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json +++ b/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json @@ -7,12 +7,8 @@ "CVE-2009-0563" ], "details": "Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka \"Word Buffer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f66m-xgc7-9g7w/GHSA-f66m-xgc7-9g7w.json b/advisories/unreviewed/2022/05/GHSA-f66m-xgc7-9g7w/GHSA-f66m-xgc7-9g7w.json index 8668fe826ba..1cea1081d9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f66m-xgc7-9g7w/GHSA-f66m-xgc7-9g7w.json +++ b/advisories/unreviewed/2022/05/GHSA-f66m-xgc7-9g7w/GHSA-f66m-xgc7-9g7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f692-3m5j-78fw/GHSA-f692-3m5j-78fw.json b/advisories/unreviewed/2022/05/GHSA-f692-3m5j-78fw/GHSA-f692-3m5j-78fw.json index bcc5e18f26d..2737d8f5a9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f692-3m5j-78fw/GHSA-f692-3m5j-78fw.json +++ b/advisories/unreviewed/2022/05/GHSA-f692-3m5j-78fw/GHSA-f692-3m5j-78fw.json @@ -7,12 +7,8 @@ "CVE-2009-0528" ], "details": "SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6h6-jfpf-wgvv/GHSA-f6h6-jfpf-wgvv.json b/advisories/unreviewed/2022/05/GHSA-f6h6-jfpf-wgvv/GHSA-f6h6-jfpf-wgvv.json index ba061e790ea..6183ee0c691 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6h6-jfpf-wgvv/GHSA-f6h6-jfpf-wgvv.json +++ b/advisories/unreviewed/2022/05/GHSA-f6h6-jfpf-wgvv/GHSA-f6h6-jfpf-wgvv.json @@ -7,12 +7,8 @@ "CVE-2009-0352" ], "details": "Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -212,9 +208,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f6hj-q6pv-h6q9/GHSA-f6hj-q6pv-h6q9.json b/advisories/unreviewed/2022/05/GHSA-f6hj-q6pv-h6q9/GHSA-f6hj-q6pv-h6q9.json index fb57fa225c0..fdadb95d9f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6hj-q6pv-h6q9/GHSA-f6hj-q6pv-h6q9.json +++ b/advisories/unreviewed/2022/05/GHSA-f6hj-q6pv-h6q9/GHSA-f6hj-q6pv-h6q9.json @@ -7,12 +7,8 @@ "CVE-2009-0306" ], "details": "Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6rw-7p6g-pxcm/GHSA-f6rw-7p6g-pxcm.json b/advisories/unreviewed/2022/05/GHSA-f6rw-7p6g-pxcm/GHSA-f6rw-7p6g-pxcm.json index cd0e0796922..e949dcfe145 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6rw-7p6g-pxcm/GHSA-f6rw-7p6g-pxcm.json +++ b/advisories/unreviewed/2022/05/GHSA-f6rw-7p6g-pxcm/GHSA-f6rw-7p6g-pxcm.json @@ -7,12 +7,8 @@ "CVE-2009-0416" ], "details": "The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /var/tmp/key.pem, (2) /var/tmp/cert.pem, and (3) /var/tmp/ssl.cnf temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f798-xfgv-r47g/GHSA-f798-xfgv-r47g.json b/advisories/unreviewed/2022/05/GHSA-f798-xfgv-r47g/GHSA-f798-xfgv-r47g.json index fbbe352a92f..88ed029e801 100644 --- a/advisories/unreviewed/2022/05/GHSA-f798-xfgv-r47g/GHSA-f798-xfgv-r47g.json +++ b/advisories/unreviewed/2022/05/GHSA-f798-xfgv-r47g/GHSA-f798-xfgv-r47g.json @@ -7,12 +7,8 @@ "CVE-2009-0212" ], "details": "Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32020.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7h8-wx9v-q768/GHSA-f7h8-wx9v-q768.json b/advisories/unreviewed/2022/05/GHSA-f7h8-wx9v-q768/GHSA-f7h8-wx9v-q768.json index 110e76ff6ce..5fdefa31d39 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7h8-wx9v-q768/GHSA-f7h8-wx9v-q768.json +++ b/advisories/unreviewed/2022/05/GHSA-f7h8-wx9v-q768/GHSA-f7h8-wx9v-q768.json @@ -7,12 +7,8 @@ "CVE-2009-0762" ], "details": "Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f83x-qcw9-92pv/GHSA-f83x-qcw9-92pv.json b/advisories/unreviewed/2022/05/GHSA-f83x-qcw9-92pv/GHSA-f83x-qcw9-92pv.json index c7975e1427a..bc3db1f2c85 100644 --- a/advisories/unreviewed/2022/05/GHSA-f83x-qcw9-92pv/GHSA-f83x-qcw9-92pv.json +++ b/advisories/unreviewed/2022/05/GHSA-f83x-qcw9-92pv/GHSA-f83x-qcw9-92pv.json @@ -7,12 +7,8 @@ "CVE-2009-0903" ], "details": "IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff4x-j9gr-p42f/GHSA-ff4x-j9gr-p42f.json b/advisories/unreviewed/2022/05/GHSA-ff4x-j9gr-p42f/GHSA-ff4x-j9gr-p42f.json index 03ae75442dc..d2f916965a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff4x-j9gr-p42f/GHSA-ff4x-j9gr-p42f.json +++ b/advisories/unreviewed/2022/05/GHSA-ff4x-j9gr-p42f/GHSA-ff4x-j9gr-p42f.json @@ -7,12 +7,8 @@ "CVE-2009-0875" ], "details": "Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff6f-5595-v5f4/GHSA-ff6f-5595-v5f4.json b/advisories/unreviewed/2022/05/GHSA-ff6f-5595-v5f4/GHSA-ff6f-5595-v5f4.json index 1086aee9f93..66936612fd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff6f-5595-v5f4/GHSA-ff6f-5595-v5f4.json +++ b/advisories/unreviewed/2022/05/GHSA-ff6f-5595-v5f4/GHSA-ff6f-5595-v5f4.json @@ -7,12 +7,8 @@ "CVE-2009-0623" ], "details": "Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SSH packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhvg-9c67-jcf4/GHSA-fhvg-9c67-jcf4.json b/advisories/unreviewed/2022/05/GHSA-fhvg-9c67-jcf4/GHSA-fhvg-9c67-jcf4.json index 78836cae285..b4e6a94ac79 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhvg-9c67-jcf4/GHSA-fhvg-9c67-jcf4.json +++ b/advisories/unreviewed/2022/05/GHSA-fhvg-9c67-jcf4/GHSA-fhvg-9c67-jcf4.json @@ -7,12 +7,8 @@ "CVE-2009-0780" ], "details": "The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of service (application crash) via an Autonomous System (AS) advertisement containing a long AS path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fj47-2vxw-632j/GHSA-fj47-2vxw-632j.json b/advisories/unreviewed/2022/05/GHSA-fj47-2vxw-632j/GHSA-fj47-2vxw-632j.json index 6fd47cf8019..b79b6a04a16 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj47-2vxw-632j/GHSA-fj47-2vxw-632j.json +++ b/advisories/unreviewed/2022/05/GHSA-fj47-2vxw-632j/GHSA-fj47-2vxw-632j.json @@ -7,12 +7,8 @@ "CVE-2009-0922" ], "details": "PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -116,9 +112,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm5j-vjr3-jf4v/GHSA-fm5j-vjr3-jf4v.json b/advisories/unreviewed/2022/05/GHSA-fm5j-vjr3-jf4v/GHSA-fm5j-vjr3-jf4v.json index 0da600e2dc7..aaf4d2e87de 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm5j-vjr3-jf4v/GHSA-fm5j-vjr3-jf4v.json +++ b/advisories/unreviewed/2022/05/GHSA-fm5j-vjr3-jf4v/GHSA-fm5j-vjr3-jf4v.json @@ -7,12 +7,8 @@ "CVE-2009-0756" ], "details": "The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json b/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json index 372e03de41e..388d1d88692 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json +++ b/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json @@ -7,12 +7,8 @@ "CVE-2009-0557" ], "details": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"Object Record Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmg5-3x35-8gfc/GHSA-fmg5-3x35-8gfc.json b/advisories/unreviewed/2022/05/GHSA-fmg5-3x35-8gfc/GHSA-fmg5-3x35-8gfc.json index 18028666cbe..23090192a4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmg5-3x35-8gfc/GHSA-fmg5-3x35-8gfc.json +++ b/advisories/unreviewed/2022/05/GHSA-fmg5-3x35-8gfc/GHSA-fmg5-3x35-8gfc.json @@ -7,12 +7,8 @@ "CVE-2009-0322" ], "details": "drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -148,9 +144,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fph9-w7c9-jgwv/GHSA-fph9-w7c9-jgwv.json b/advisories/unreviewed/2022/05/GHSA-fph9-w7c9-jgwv/GHSA-fph9-w7c9-jgwv.json index 6b8c9218d07..5d7819cc352 100644 --- a/advisories/unreviewed/2022/05/GHSA-fph9-w7c9-jgwv/GHSA-fph9-w7c9-jgwv.json +++ b/advisories/unreviewed/2022/05/GHSA-fph9-w7c9-jgwv/GHSA-fph9-w7c9-jgwv.json @@ -7,12 +7,8 @@ "CVE-2009-0525" ], "details": "Cross-site scripting (XSS) vulnerability in the sajax_get_common_js function in php/Sajax.php in Sajax 0.12 allows remote attackers to inject arbitrary web script or HTML via the URL parameter, which is not properly handled when using browsers that do not URL-encode requests, such as Internet Explorer 6. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqq3-4hpj-9cxh/GHSA-fqq3-4hpj-9cxh.json b/advisories/unreviewed/2022/05/GHSA-fqq3-4hpj-9cxh/GHSA-fqq3-4hpj-9cxh.json index 07054fd5f13..6e04d9a8ab4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqq3-4hpj-9cxh/GHSA-fqq3-4hpj-9cxh.json +++ b/advisories/unreviewed/2022/05/GHSA-fqq3-4hpj-9cxh/GHSA-fqq3-4hpj-9cxh.json @@ -7,12 +7,8 @@ "CVE-2009-0773" ], "details": "The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains \"some non-set elements,\" which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -140,9 +136,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvf6-8j9x-f6g8/GHSA-fvf6-8j9x-f6g8.json b/advisories/unreviewed/2022/05/GHSA-fvf6-8j9x-f6g8/GHSA-fvf6-8j9x-f6g8.json index 4c2198eab09..1af4cab31d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvf6-8j9x-f6g8/GHSA-fvf6-8j9x-f6g8.json +++ b/advisories/unreviewed/2022/05/GHSA-fvf6-8j9x-f6g8/GHSA-fvf6-8j9x-f6g8.json @@ -7,12 +7,8 @@ "CVE-2009-0491" ], "details": "Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwhg-cj3c-8hvv/GHSA-fwhg-cj3c-8hvv.json b/advisories/unreviewed/2022/05/GHSA-fwhg-cj3c-8hvv/GHSA-fwhg-cj3c-8hvv.json index c12b5cfa176..b50ecb86b9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwhg-cj3c-8hvv/GHSA-fwhg-cj3c-8hvv.json +++ b/advisories/unreviewed/2022/05/GHSA-fwhg-cj3c-8hvv/GHSA-fwhg-cj3c-8hvv.json @@ -7,12 +7,8 @@ "CVE-2009-0498" ], "details": "Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwm8-q9v7-h6xw/GHSA-fwm8-q9v7-h6xw.json b/advisories/unreviewed/2022/05/GHSA-fwm8-q9v7-h6xw/GHSA-fwm8-q9v7-h6xw.json index 298438ad508..2b373ecf60f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwm8-q9v7-h6xw/GHSA-fwm8-q9v7-h6xw.json +++ b/advisories/unreviewed/2022/05/GHSA-fwm8-q9v7-h6xw/GHSA-fwm8-q9v7-h6xw.json @@ -7,12 +7,8 @@ "CVE-2009-0760" ], "details": "Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxj6-x384-78f9/GHSA-fxj6-x384-78f9.json b/advisories/unreviewed/2022/05/GHSA-fxj6-x384-78f9/GHSA-fxj6-x384-78f9.json index d2ecb59add8..37ed887043a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxj6-x384-78f9/GHSA-fxj6-x384-78f9.json +++ b/advisories/unreviewed/2022/05/GHSA-fxj6-x384-78f9/GHSA-fxj6-x384-78f9.json @@ -7,12 +7,8 @@ "CVE-2009-0772" ], "details": "The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g25p-689r-962m/GHSA-g25p-689r-962m.json b/advisories/unreviewed/2022/05/GHSA-g25p-689r-962m/GHSA-g25p-689r-962m.json index e65d96b6896..faee3d50e3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g25p-689r-962m/GHSA-g25p-689r-962m.json +++ b/advisories/unreviewed/2022/05/GHSA-g25p-689r-962m/GHSA-g25p-689r-962m.json @@ -7,12 +7,8 @@ "CVE-2009-0571" ], "details": "admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2fw-vq9p-rrf2/GHSA-g2fw-vq9p-rrf2.json b/advisories/unreviewed/2022/05/GHSA-g2fw-vq9p-rrf2/GHSA-g2fw-vq9p-rrf2.json index 7d275bc2ae8..d65839b4e38 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2fw-vq9p-rrf2/GHSA-g2fw-vq9p-rrf2.json +++ b/advisories/unreviewed/2022/05/GHSA-g2fw-vq9p-rrf2/GHSA-g2fw-vq9p-rrf2.json @@ -7,12 +7,8 @@ "CVE-2009-0656" ], "details": "Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass \"security functions\" by presenting an image with a modified viewpoint that matches the posture of a stored image of the authorized notebook user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g39p-x3r3-qgmh/GHSA-g39p-x3r3-qgmh.json b/advisories/unreviewed/2022/05/GHSA-g39p-x3r3-qgmh/GHSA-g39p-x3r3-qgmh.json index f72136b4210..2da3acc8b81 100644 --- a/advisories/unreviewed/2022/05/GHSA-g39p-x3r3-qgmh/GHSA-g39p-x3r3-qgmh.json +++ b/advisories/unreviewed/2022/05/GHSA-g39p-x3r3-qgmh/GHSA-g39p-x3r3-qgmh.json @@ -7,12 +7,8 @@ "CVE-2009-0828" ], "details": "QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3qf-xr97-56vj/GHSA-g3qf-xr97-56vj.json b/advisories/unreviewed/2022/05/GHSA-g3qf-xr97-56vj/GHSA-g3qf-xr97-56vj.json index 242255e65a9..e263465ead9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3qf-xr97-56vj/GHSA-g3qf-xr97-56vj.json +++ b/advisories/unreviewed/2022/05/GHSA-g3qf-xr97-56vj/GHSA-g3qf-xr97-56vj.json @@ -7,12 +7,8 @@ "CVE-2009-0693" ], "details": "Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g46g-49jm-3qmj/GHSA-g46g-49jm-3qmj.json b/advisories/unreviewed/2022/05/GHSA-g46g-49jm-3qmj/GHSA-g46g-49jm-3qmj.json index bf6e8d3e110..ca96ec9aae5 100644 --- a/advisories/unreviewed/2022/05/GHSA-g46g-49jm-3qmj/GHSA-g46g-49jm-3qmj.json +++ b/advisories/unreviewed/2022/05/GHSA-g46g-49jm-3qmj/GHSA-g46g-49jm-3qmj.json @@ -7,12 +7,8 @@ "CVE-2009-0504" ], "details": "WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4cg-2w9f-97j7/GHSA-g4cg-2w9f-97j7.json b/advisories/unreviewed/2022/05/GHSA-g4cg-2w9f-97j7/GHSA-g4cg-2w9f-97j7.json index 5a5d9150253..88ca2ea3335 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4cg-2w9f-97j7/GHSA-g4cg-2w9f-97j7.json +++ b/advisories/unreviewed/2022/05/GHSA-g4cg-2w9f-97j7/GHSA-g4cg-2w9f-97j7.json @@ -7,12 +7,8 @@ "CVE-2009-0468" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping packets, (3) enable network services, (4) configure a proxy server, and (5) modify other settings via parameters in the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6p4-39x9-9m48/GHSA-g6p4-39x9-9m48.json b/advisories/unreviewed/2022/05/GHSA-g6p4-39x9-9m48/GHSA-g6p4-39x9-9m48.json index 7f1ea1ee9a1..ffb60d85f62 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6p4-39x9-9m48/GHSA-g6p4-39x9-9m48.json +++ b/advisories/unreviewed/2022/05/GHSA-g6p4-39x9-9m48/GHSA-g6p4-39x9-9m48.json @@ -7,12 +7,8 @@ "CVE-2009-0417" ], "details": "Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7f8-4qm9-qgg5/GHSA-g7f8-4qm9-qgg5.json b/advisories/unreviewed/2022/05/GHSA-g7f8-4qm9-qgg5/GHSA-g7f8-4qm9-qgg5.json index 935ea01e3f6..727a4bbfd3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7f8-4qm9-qgg5/GHSA-g7f8-4qm9-qgg5.json +++ b/advisories/unreviewed/2022/05/GHSA-g7f8-4qm9-qgg5/GHSA-g7f8-4qm9-qgg5.json @@ -7,12 +7,8 @@ "CVE-2009-0758" ], "details": "The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7r6-hv8w-2mjr/GHSA-g7r6-hv8w-2mjr.json b/advisories/unreviewed/2022/05/GHSA-g7r6-hv8w-2mjr/GHSA-g7r6-hv8w-2mjr.json index f608cc48fc1..d6ae331a7c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7r6-hv8w-2mjr/GHSA-g7r6-hv8w-2mjr.json +++ b/advisories/unreviewed/2022/05/GHSA-g7r6-hv8w-2mjr/GHSA-g7r6-hv8w-2mjr.json @@ -7,12 +7,8 @@ "CVE-2009-0614" ], "details": "Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote attackers to bypass authentication and obtain administrative access via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7rv-f739-g87w/GHSA-g7rv-f739-g87w.json b/advisories/unreviewed/2022/05/GHSA-g7rv-f739-g87w/GHSA-g7rv-f739-g87w.json index 2000fcf4383..ec353d68431 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7rv-f739-g87w/GHSA-g7rv-f739-g87w.json +++ b/advisories/unreviewed/2022/05/GHSA-g7rv-f739-g87w/GHSA-g7rv-f739-g87w.json @@ -7,12 +7,8 @@ "CVE-2009-0861" ], "details": "Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g82w-w4fh-33xc/GHSA-g82w-w4fh-33xc.json b/advisories/unreviewed/2022/05/GHSA-g82w-w4fh-33xc/GHSA-g82w-w4fh-33xc.json index fda5b0f4904..f6c45054a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-g82w-w4fh-33xc/GHSA-g82w-w4fh-33xc.json +++ b/advisories/unreviewed/2022/05/GHSA-g82w-w4fh-33xc/GHSA-g82w-w4fh-33xc.json @@ -7,12 +7,8 @@ "CVE-2009-0946" ], "details": "Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g839-wg6g-gpxq/GHSA-g839-wg6g-gpxq.json b/advisories/unreviewed/2022/05/GHSA-g839-wg6g-gpxq/GHSA-g839-wg6g-gpxq.json index 57356be7547..0f66768aae6 100644 --- a/advisories/unreviewed/2022/05/GHSA-g839-wg6g-gpxq/GHSA-g839-wg6g-gpxq.json +++ b/advisories/unreviewed/2022/05/GHSA-g839-wg6g-gpxq/GHSA-g839-wg6g-gpxq.json @@ -7,12 +7,8 @@ "CVE-2009-0531" ], "details": "SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8fp-55h8-4vmg/GHSA-g8fp-55h8-4vmg.json b/advisories/unreviewed/2022/05/GHSA-g8fp-55h8-4vmg/GHSA-g8fp-55h8-4vmg.json index c8a3088cc2c..8652a04194c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8fp-55h8-4vmg/GHSA-g8fp-55h8-4vmg.json +++ b/advisories/unreviewed/2022/05/GHSA-g8fp-55h8-4vmg/GHSA-g8fp-55h8-4vmg.json @@ -7,12 +7,8 @@ "CVE-2009-0678" ], "details": "images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8mc-vv53-7r46/GHSA-g8mc-vv53-7r46.json b/advisories/unreviewed/2022/05/GHSA-g8mc-vv53-7r46/GHSA-g8mc-vv53-7r46.json index 459ab89b89b..612c941a9b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8mc-vv53-7r46/GHSA-g8mc-vv53-7r46.json +++ b/advisories/unreviewed/2022/05/GHSA-g8mc-vv53-7r46/GHSA-g8mc-vv53-7r46.json @@ -7,12 +7,8 @@ "CVE-2009-0410" ], "details": "Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g937-p2qx-pqgp/GHSA-g937-p2qx-pqgp.json b/advisories/unreviewed/2022/05/GHSA-g937-p2qx-pqgp/GHSA-g937-p2qx-pqgp.json index 8f8facb3cd3..47238c3cd3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g937-p2qx-pqgp/GHSA-g937-p2qx-pqgp.json +++ b/advisories/unreviewed/2022/05/GHSA-g937-p2qx-pqgp/GHSA-g937-p2qx-pqgp.json @@ -7,12 +7,8 @@ "CVE-2009-0570" ], "details": "Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g998-mr8q-m629/GHSA-g998-mr8q-m629.json b/advisories/unreviewed/2022/05/GHSA-g998-mr8q-m629/GHSA-g998-mr8q-m629.json index d229448352a..007ed297dc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g998-mr8q-m629/GHSA-g998-mr8q-m629.json +++ b/advisories/unreviewed/2022/05/GHSA-g998-mr8q-m629/GHSA-g998-mr8q-m629.json @@ -7,12 +7,8 @@ "CVE-2009-0404" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) expressions in the style attribute, which is processed by Internet Explorer 7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9cc-xw8r-hj44/GHSA-g9cc-xw8r-hj44.json b/advisories/unreviewed/2022/05/GHSA-g9cc-xw8r-hj44/GHSA-g9cc-xw8r-hj44.json index 6bbae990390..0d5bf9273a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9cc-xw8r-hj44/GHSA-g9cc-xw8r-hj44.json +++ b/advisories/unreviewed/2022/05/GHSA-g9cc-xw8r-hj44/GHSA-g9cc-xw8r-hj44.json @@ -7,12 +7,8 @@ "CVE-2009-0837" ], "details": "Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the \"Open/Execute a file\" action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf25-57ph-f552/GHSA-gf25-57ph-f552.json b/advisories/unreviewed/2022/05/GHSA-gf25-57ph-f552/GHSA-gf25-57ph-f552.json index 61a8e2ae565..db470f3dc7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf25-57ph-f552/GHSA-gf25-57ph-f552.json +++ b/advisories/unreviewed/2022/05/GHSA-gf25-57ph-f552/GHSA-gf25-57ph-f552.json @@ -7,12 +7,8 @@ "CVE-2009-0408" ], "details": "Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfhg-7w8w-j26f/GHSA-gfhg-7w8w-j26f.json b/advisories/unreviewed/2022/05/GHSA-gfhg-7w8w-j26f/GHSA-gfhg-7w8w-j26f.json index b9b991c523d..b2b5f7e190a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfhg-7w8w-j26f/GHSA-gfhg-7w8w-j26f.json +++ b/advisories/unreviewed/2022/05/GHSA-gfhg-7w8w-j26f/GHSA-gfhg-7w8w-j26f.json @@ -7,12 +7,8 @@ "CVE-2009-0686" ], "details": "The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \\Device\\tmactmon that overwrites memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh45-8v48-w5xv/GHSA-gh45-8v48-w5xv.json b/advisories/unreviewed/2022/05/GHSA-gh45-8v48-w5xv/GHSA-gh45-8v48-w5xv.json index 3d26af206a6..f8b66919b16 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh45-8v48-w5xv/GHSA-gh45-8v48-w5xv.json +++ b/advisories/unreviewed/2022/05/GHSA-gh45-8v48-w5xv/GHSA-gh45-8v48-w5xv.json @@ -7,12 +7,8 @@ "CVE-2009-0810" ], "details": "SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj63-3383-h48m/GHSA-gj63-3383-h48m.json b/advisories/unreviewed/2022/05/GHSA-gj63-3383-h48m/GHSA-gj63-3383-h48m.json index 7f51b67029d..3ecd8894d60 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj63-3383-h48m/GHSA-gj63-3383-h48m.json +++ b/advisories/unreviewed/2022/05/GHSA-gj63-3383-h48m/GHSA-gj63-3383-h48m.json @@ -7,12 +7,8 @@ "CVE-2009-0653" ], "details": "OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmh4-4335-52gp/GHSA-gmh4-4335-52gp.json b/advisories/unreviewed/2022/05/GHSA-gmh4-4335-52gp/GHSA-gmh4-4335-52gp.json index 69db5694c5b..be696a03d14 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmh4-4335-52gp/GHSA-gmh4-4335-52gp.json +++ b/advisories/unreviewed/2022/05/GHSA-gmh4-4335-52gp/GHSA-gmh4-4335-52gp.json @@ -7,12 +7,8 @@ "CVE-2009-0290" ], "details": "Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpqh-rc5f-935m/GHSA-gpqh-rc5f-935m.json b/advisories/unreviewed/2022/05/GHSA-gpqh-rc5f-935m/GHSA-gpqh-rc5f-935m.json index e5809d9945b..28abd1abfc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpqh-rc5f-935m/GHSA-gpqh-rc5f-935m.json +++ b/advisories/unreviewed/2022/05/GHSA-gpqh-rc5f-935m/GHSA-gpqh-rc5f-935m.json @@ -7,12 +7,8 @@ "CVE-2009-0677" ], "details": "avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gprc-5h5v-mh5j/GHSA-gprc-5h5v-mh5j.json b/advisories/unreviewed/2022/05/GHSA-gprc-5h5v-mh5j/GHSA-gprc-5h5v-mh5j.json index 8a33f86bfd5..fac4a5805ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-gprc-5h5v-mh5j/GHSA-gprc-5h5v-mh5j.json +++ b/advisories/unreviewed/2022/05/GHSA-gprc-5h5v-mh5j/GHSA-gprc-5h5v-mh5j.json @@ -7,12 +7,8 @@ "CVE-2009-0746" ], "details": "The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq6x-qcc2-xccg/GHSA-gq6x-qcc2-xccg.json b/advisories/unreviewed/2022/05/GHSA-gq6x-qcc2-xccg/GHSA-gq6x-qcc2-xccg.json index c2aa9eb11fa..cae83c61a70 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq6x-qcc2-xccg/GHSA-gq6x-qcc2-xccg.json +++ b/advisories/unreviewed/2022/05/GHSA-gq6x-qcc2-xccg/GHSA-gq6x-qcc2-xccg.json @@ -7,12 +7,8 @@ "CVE-2009-0873" ], "details": "The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that \"override each other.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq89-cf9v-xh3g/GHSA-gq89-cf9v-xh3g.json b/advisories/unreviewed/2022/05/GHSA-gq89-cf9v-xh3g/GHSA-gq89-cf9v-xh3g.json index 89c4cda4bd2..be845a90ef7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq89-cf9v-xh3g/GHSA-gq89-cf9v-xh3g.json +++ b/advisories/unreviewed/2022/05/GHSA-gq89-cf9v-xh3g/GHSA-gq89-cf9v-xh3g.json @@ -7,12 +7,8 @@ "CVE-2009-0547" ], "details": "Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvxh-7jqr-8hgq/GHSA-gvxh-7jqr-8hgq.json b/advisories/unreviewed/2022/05/GHSA-gvxh-7jqr-8hgq/GHSA-gvxh-7jqr-8hgq.json index 3b1e17d7505..7347ab7451a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvxh-7jqr-8hgq/GHSA-gvxh-7jqr-8hgq.json +++ b/advisories/unreviewed/2022/05/GHSA-gvxh-7jqr-8hgq/GHSA-gvxh-7jqr-8hgq.json @@ -7,12 +7,8 @@ "CVE-2009-0600" ], "details": "Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwch-hrm7-6996/GHSA-gwch-hrm7-6996.json b/advisories/unreviewed/2022/05/GHSA-gwch-hrm7-6996/GHSA-gwch-hrm7-6996.json index 8cb5ab3ddc8..5bb8393d9ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwch-hrm7-6996/GHSA-gwch-hrm7-6996.json +++ b/advisories/unreviewed/2022/05/GHSA-gwch-hrm7-6996/GHSA-gwch-hrm7-6996.json @@ -7,12 +7,8 @@ "CVE-2009-0370" ], "details": "Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating \"secure log files.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwh8-27m5-c3g7/GHSA-gwh8-27m5-c3g7.json b/advisories/unreviewed/2022/05/GHSA-gwh8-27m5-c3g7/GHSA-gwh8-27m5-c3g7.json index 86078aaa42d..d4f15a838e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwh8-27m5-c3g7/GHSA-gwh8-27m5-c3g7.json +++ b/advisories/unreviewed/2022/05/GHSA-gwh8-27m5-c3g7/GHSA-gwh8-27m5-c3g7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxgp-v476-3c85/GHSA-gxgp-v476-3c85.json b/advisories/unreviewed/2022/05/GHSA-gxgp-v476-3c85/GHSA-gxgp-v476-3c85.json index 0baa1513979..0ad49f78054 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxgp-v476-3c85/GHSA-gxgp-v476-3c85.json +++ b/advisories/unreviewed/2022/05/GHSA-gxgp-v476-3c85/GHSA-gxgp-v476-3c85.json @@ -7,12 +7,8 @@ "CVE-2009-0366" ], "details": "The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h27q-m239-g8g2/GHSA-h27q-m239-g8g2.json b/advisories/unreviewed/2022/05/GHSA-h27q-m239-g8g2/GHSA-h27q-m239-g8g2.json index d79a7439d14..875e0a6ff41 100644 --- a/advisories/unreviewed/2022/05/GHSA-h27q-m239-g8g2/GHSA-h27q-m239-g8g2.json +++ b/advisories/unreviewed/2022/05/GHSA-h27q-m239-g8g2/GHSA-h27q-m239-g8g2.json @@ -7,12 +7,8 @@ "CVE-2009-0379" ], "details": "SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2q7-pj3w-pr6f/GHSA-h2q7-pj3w-pr6f.json b/advisories/unreviewed/2022/05/GHSA-h2q7-pj3w-pr6f/GHSA-h2q7-pj3w-pr6f.json index 7e893f4914d..512164ffc59 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2q7-pj3w-pr6f/GHSA-h2q7-pj3w-pr6f.json +++ b/advisories/unreviewed/2022/05/GHSA-h2q7-pj3w-pr6f/GHSA-h2q7-pj3w-pr6f.json @@ -7,12 +7,8 @@ "CVE-2009-0355" ], "details": "components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type=\"file\" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h35j-98vm-989g/GHSA-h35j-98vm-989g.json b/advisories/unreviewed/2022/05/GHSA-h35j-98vm-989g/GHSA-h35j-98vm-989g.json index 0d33d1aa305..04f40e1e9b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h35j-98vm-989g/GHSA-h35j-98vm-989g.json +++ b/advisories/unreviewed/2022/05/GHSA-h35j-98vm-989g/GHSA-h35j-98vm-989g.json @@ -7,12 +7,8 @@ "CVE-2009-0521" ], "details": "Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3mv-4rf4-23c6/GHSA-h3mv-4rf4-23c6.json b/advisories/unreviewed/2022/05/GHSA-h3mv-4rf4-23c6/GHSA-h3mv-4rf4-23c6.json index 35094efcd69..1f7273312bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3mv-4rf4-23c6/GHSA-h3mv-4rf4-23c6.json +++ b/advisories/unreviewed/2022/05/GHSA-h3mv-4rf4-23c6/GHSA-h3mv-4rf4-23c6.json @@ -7,12 +7,8 @@ "CVE-2009-0204" ], "details": "Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3vw-f6h8-86mg/GHSA-h3vw-f6h8-86mg.json b/advisories/unreviewed/2022/05/GHSA-h3vw-f6h8-86mg/GHSA-h3vw-f6h8-86mg.json index 241e6c03ee6..fdea642ffc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3vw-f6h8-86mg/GHSA-h3vw-f6h8-86mg.json +++ b/advisories/unreviewed/2022/05/GHSA-h3vw-f6h8-86mg/GHSA-h3vw-f6h8-86mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3wc-jxm7-mr49/GHSA-h3wc-jxm7-mr49.json b/advisories/unreviewed/2022/05/GHSA-h3wc-jxm7-mr49/GHSA-h3wc-jxm7-mr49.json index 37ea0ccf4b6..691b61b4811 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3wc-jxm7-mr49/GHSA-h3wc-jxm7-mr49.json +++ b/advisories/unreviewed/2022/05/GHSA-h3wc-jxm7-mr49/GHSA-h3wc-jxm7-mr49.json @@ -7,12 +7,8 @@ "CVE-2009-0385" ], "details": "Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h498-wcj2-54x4/GHSA-h498-wcj2-54x4.json b/advisories/unreviewed/2022/05/GHSA-h498-wcj2-54x4/GHSA-h498-wcj2-54x4.json index 904bf2826b2..ff5df1d247c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h498-wcj2-54x4/GHSA-h498-wcj2-54x4.json +++ b/advisories/unreviewed/2022/05/GHSA-h498-wcj2-54x4/GHSA-h498-wcj2-54x4.json @@ -7,12 +7,8 @@ "CVE-2009-0740" ], "details": "SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5q4-fw75-h7px/GHSA-h5q4-fw75-h7px.json b/advisories/unreviewed/2022/05/GHSA-h5q4-fw75-h7px/GHSA-h5q4-fw75-h7px.json index 36ce5b538bb..39507ca85fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5q4-fw75-h7px/GHSA-h5q4-fw75-h7px.json +++ b/advisories/unreviewed/2022/05/GHSA-h5q4-fw75-h7px/GHSA-h5q4-fw75-h7px.json @@ -7,12 +7,8 @@ "CVE-2009-0207" ], "details": "Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h69g-fw62-jj7r/GHSA-h69g-fw62-jj7r.json b/advisories/unreviewed/2022/05/GHSA-h69g-fw62-jj7r/GHSA-h69g-fw62-jj7r.json index aa5bc972893..ebf87d895c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h69g-fw62-jj7r/GHSA-h69g-fw62-jj7r.json +++ b/advisories/unreviewed/2022/05/GHSA-h69g-fw62-jj7r/GHSA-h69g-fw62-jj7r.json @@ -7,12 +7,8 @@ "CVE-2009-0347" ], "details": "Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7j8-fpcf-934w/GHSA-h7j8-fpcf-934w.json b/advisories/unreviewed/2022/05/GHSA-h7j8-fpcf-934w/GHSA-h7j8-fpcf-934w.json index e5f98ad454e..423b740a45c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7j8-fpcf-934w/GHSA-h7j8-fpcf-934w.json +++ b/advisories/unreviewed/2022/05/GHSA-h7j8-fpcf-934w/GHSA-h7j8-fpcf-934w.json @@ -7,12 +7,8 @@ "CVE-2009-0675" ], "details": "The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an \"inverted logic\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8qx-x78q-837g/GHSA-h8qx-x78q-837g.json b/advisories/unreviewed/2022/05/GHSA-h8qx-x78q-837g/GHSA-h8qx-x78q-837g.json index 0a403cb6ff2..49b17fd7711 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8qx-x78q-837g/GHSA-h8qx-x78q-837g.json +++ b/advisories/unreviewed/2022/05/GHSA-h8qx-x78q-837g/GHSA-h8qx-x78q-837g.json @@ -7,12 +7,8 @@ "CVE-2009-0652" ], "details": "The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h99j-7r79-64w9/GHSA-h99j-7r79-64w9.json b/advisories/unreviewed/2022/05/GHSA-h99j-7r79-64w9/GHSA-h99j-7r79-64w9.json index fca431ce269..89b263a2f21 100644 --- a/advisories/unreviewed/2022/05/GHSA-h99j-7r79-64w9/GHSA-h99j-7r79-64w9.json +++ b/advisories/unreviewed/2022/05/GHSA-h99j-7r79-64w9/GHSA-h99j-7r79-64w9.json @@ -7,12 +7,8 @@ "CVE-2009-0928" ], "details": "Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcfv-65gf-h2wv/GHSA-hcfv-65gf-h2wv.json b/advisories/unreviewed/2022/05/GHSA-hcfv-65gf-h2wv/GHSA-hcfv-65gf-h2wv.json index 8b890ddcc6e..177f988ca6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcfv-65gf-h2wv/GHSA-hcfv-65gf-h2wv.json +++ b/advisories/unreviewed/2022/05/GHSA-hcfv-65gf-h2wv/GHSA-hcfv-65gf-h2wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcjh-4chw-69ff/GHSA-hcjh-4chw-69ff.json b/advisories/unreviewed/2022/05/GHSA-hcjh-4chw-69ff/GHSA-hcjh-4chw-69ff.json index bad0e7a118f..a5153a576e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcjh-4chw-69ff/GHSA-hcjh-4chw-69ff.json +++ b/advisories/unreviewed/2022/05/GHSA-hcjh-4chw-69ff/GHSA-hcjh-4chw-69ff.json @@ -7,12 +7,8 @@ "CVE-2009-0722" ], "details": "Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the user cookie parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfvr-c7p7-275p/GHSA-hfvr-c7p7-275p.json b/advisories/unreviewed/2022/05/GHSA-hfvr-c7p7-275p/GHSA-hfvr-c7p7-275p.json index 03bcf01de05..8c0cc467303 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfvr-c7p7-275p/GHSA-hfvr-c7p7-275p.json +++ b/advisories/unreviewed/2022/05/GHSA-hfvr-c7p7-275p/GHSA-hfvr-c7p7-275p.json @@ -7,12 +7,8 @@ "CVE-2009-0732" ], "details": "Downloadcenter 2.1 stores common.h under the web root with insufficient access control, which allows remote attackers to obtain user credentials and other sensitive information via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgj9-pq3m-8vp3/GHSA-hgj9-pq3m-8vp3.json b/advisories/unreviewed/2022/05/GHSA-hgj9-pq3m-8vp3/GHSA-hgj9-pq3m-8vp3.json index 0b7c72b45a6..e28e9f8cd01 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgj9-pq3m-8vp3/GHSA-hgj9-pq3m-8vp3.json +++ b/advisories/unreviewed/2022/05/GHSA-hgj9-pq3m-8vp3/GHSA-hgj9-pq3m-8vp3.json @@ -7,12 +7,8 @@ "CVE-2009-0819" ], "details": "sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via \"an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML(),\" which triggers an assertion failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh96-73jp-6mhv/GHSA-hh96-73jp-6mhv.json b/advisories/unreviewed/2022/05/GHSA-hh96-73jp-6mhv/GHSA-hh96-73jp-6mhv.json index 55205e2ccf7..4c8b98842c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh96-73jp-6mhv/GHSA-hh96-73jp-6mhv.json +++ b/advisories/unreviewed/2022/05/GHSA-hh96-73jp-6mhv/GHSA-hh96-73jp-6mhv.json @@ -7,12 +7,8 @@ "CVE-2009-0704" ], "details": "SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands via the search parameter in an advanced action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhjm-w4mx-fgwh/GHSA-hhjm-w4mx-fgwh.json b/advisories/unreviewed/2022/05/GHSA-hhjm-w4mx-fgwh/GHSA-hhjm-w4mx-fgwh.json index b252c968d4a..a0f6de38b60 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhjm-w4mx-fgwh/GHSA-hhjm-w4mx-fgwh.json +++ b/advisories/unreviewed/2022/05/GHSA-hhjm-w4mx-fgwh/GHSA-hhjm-w4mx-fgwh.json @@ -7,12 +7,8 @@ "CVE-2009-0876" ], "details": "Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj2w-cqp4-v4p9/GHSA-hj2w-cqp4-v4p9.json b/advisories/unreviewed/2022/05/GHSA-hj2w-cqp4-v4p9/GHSA-hj2w-cqp4-v4p9.json index 2c46faad833..53456cff36e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj2w-cqp4-v4p9/GHSA-hj2w-cqp4-v4p9.json +++ b/advisories/unreviewed/2022/05/GHSA-hj2w-cqp4-v4p9/GHSA-hj2w-cqp4-v4p9.json @@ -7,12 +7,8 @@ "CVE-2009-0359" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj4v-gwj2-gcf6/GHSA-hj4v-gwj2-gcf6.json b/advisories/unreviewed/2022/05/GHSA-hj4v-gwj2-gcf6/GHSA-hj4v-gwj2-gcf6.json index ec1a3ccec05..9baca3ccc63 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj4v-gwj2-gcf6/GHSA-hj4v-gwj2-gcf6.json +++ b/advisories/unreviewed/2022/05/GHSA-hj4v-gwj2-gcf6/GHSA-hj4v-gwj2-gcf6.json @@ -7,12 +7,8 @@ "CVE-2009-0344" ], "details": "Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6633175, a different vulnerability than CVE-2007-5717.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hj7x-q95g-w7pw/GHSA-hj7x-q95g-w7pw.json b/advisories/unreviewed/2022/05/GHSA-hj7x-q95g-w7pw/GHSA-hj7x-q95g-w7pw.json index b660922088e..6d1c690140f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj7x-q95g-w7pw/GHSA-hj7x-q95g-w7pw.json +++ b/advisories/unreviewed/2022/05/GHSA-hj7x-q95g-w7pw/GHSA-hj7x-q95g-w7pw.json @@ -7,12 +7,8 @@ "CVE-2009-0739" ], "details": "SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjvf-5wjr-24jf/GHSA-hjvf-5wjr-24jf.json b/advisories/unreviewed/2022/05/GHSA-hjvf-5wjr-24jf/GHSA-hjvf-5wjr-24jf.json index 7eac4234910..e9c0e870ff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjvf-5wjr-24jf/GHSA-hjvf-5wjr-24jf.json +++ b/advisories/unreviewed/2022/05/GHSA-hjvf-5wjr-24jf/GHSA-hjvf-5wjr-24jf.json @@ -7,12 +7,8 @@ "CVE-2009-0896" ], "details": "Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hm9c-qrxw-gvc3/GHSA-hm9c-qrxw-gvc3.json b/advisories/unreviewed/2022/05/GHSA-hm9c-qrxw-gvc3/GHSA-hm9c-qrxw-gvc3.json index fb2a239bfc1..3b7bbf11e37 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm9c-qrxw-gvc3/GHSA-hm9c-qrxw-gvc3.json +++ b/advisories/unreviewed/2022/05/GHSA-hm9c-qrxw-gvc3/GHSA-hm9c-qrxw-gvc3.json @@ -7,12 +7,8 @@ "CVE-2009-0579" ], "details": "Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmqh-4jf7-28gf/GHSA-hmqh-4jf7-28gf.json b/advisories/unreviewed/2022/05/GHSA-hmqh-4jf7-28gf/GHSA-hmqh-4jf7-28gf.json index 2190f0b5718..51aa577cb82 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmqh-4jf7-28gf/GHSA-hmqh-4jf7-28gf.json +++ b/advisories/unreviewed/2022/05/GHSA-hmqh-4jf7-28gf/GHSA-hmqh-4jf7-28gf.json @@ -7,12 +7,8 @@ "CVE-2009-0328" ], "details": "ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmrf-8h3c-5r96/GHSA-hmrf-8h3c-5r96.json b/advisories/unreviewed/2022/05/GHSA-hmrf-8h3c-5r96/GHSA-hmrf-8h3c-5r96.json index 1bfd4004b85..67cdbabef70 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmrf-8h3c-5r96/GHSA-hmrf-8h3c-5r96.json +++ b/advisories/unreviewed/2022/05/GHSA-hmrf-8h3c-5r96/GHSA-hmrf-8h3c-5r96.json @@ -7,12 +7,8 @@ "CVE-2009-0611" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hmxr-rwh4-hh58/GHSA-hmxr-rwh4-hh58.json b/advisories/unreviewed/2022/05/GHSA-hmxr-rwh4-hh58/GHSA-hmxr-rwh4-hh58.json index f7c05696cc8..a30787d95d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmxr-rwh4-hh58/GHSA-hmxr-rwh4-hh58.json +++ b/advisories/unreviewed/2022/05/GHSA-hmxr-rwh4-hh58/GHSA-hmxr-rwh4-hh58.json @@ -7,12 +7,8 @@ "CVE-2009-0367" ], "details": "The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp47-gp47-6w8j/GHSA-hp47-gp47-6w8j.json b/advisories/unreviewed/2022/05/GHSA-hp47-gp47-6w8j/GHSA-hp47-gp47-6w8j.json index d2e869a1ec5..79333d1a84f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp47-gp47-6w8j/GHSA-hp47-gp47-6w8j.json +++ b/advisories/unreviewed/2022/05/GHSA-hp47-gp47-6w8j/GHSA-hp47-gp47-6w8j.json @@ -7,12 +7,8 @@ "CVE-2009-0291" ], "details": "Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpm9-3r29-xprg/GHSA-hpm9-3r29-xprg.json b/advisories/unreviewed/2022/05/GHSA-hpm9-3r29-xprg/GHSA-hpm9-3r29-xprg.json index 600f0c7ddb7..861a44edb48 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpm9-3r29-xprg/GHSA-hpm9-3r29-xprg.json +++ b/advisories/unreviewed/2022/05/GHSA-hpm9-3r29-xprg/GHSA-hpm9-3r29-xprg.json @@ -7,12 +7,8 @@ "CVE-2009-0812" ], "details": "Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hprr-xq95-m5m9/GHSA-hprr-xq95-m5m9.json b/advisories/unreviewed/2022/05/GHSA-hprr-xq95-m5m9/GHSA-hprr-xq95-m5m9.json index 36f93a42c1c..2fbb58f4aa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hprr-xq95-m5m9/GHSA-hprr-xq95-m5m9.json +++ b/advisories/unreviewed/2022/05/GHSA-hprr-xq95-m5m9/GHSA-hprr-xq95-m5m9.json @@ -7,12 +7,8 @@ "CVE-2009-0365" ], "details": "nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqm7-387p-82rc/GHSA-hqm7-387p-82rc.json b/advisories/unreviewed/2022/05/GHSA-hqm7-387p-82rc/GHSA-hqm7-387p-82rc.json index b20a285b7f7..ea9e58531c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqm7-387p-82rc/GHSA-hqm7-387p-82rc.json +++ b/advisories/unreviewed/2022/05/GHSA-hqm7-387p-82rc/GHSA-hqm7-387p-82rc.json @@ -7,12 +7,8 @@ "CVE-2009-0401" ], "details": "SQL injection vulnerability in browsecats.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr5p-fhw2-cxvq/GHSA-hr5p-fhw2-cxvq.json b/advisories/unreviewed/2022/05/GHSA-hr5p-fhw2-cxvq/GHSA-hr5p-fhw2-cxvq.json index f1d09d9b209..51231d17c6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr5p-fhw2-cxvq/GHSA-hr5p-fhw2-cxvq.json +++ b/advisories/unreviewed/2022/05/GHSA-hr5p-fhw2-cxvq/GHSA-hr5p-fhw2-cxvq.json @@ -7,12 +7,8 @@ "CVE-2009-0894" ], "details": "Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hv22-96xg-53m5/GHSA-hv22-96xg-53m5.json b/advisories/unreviewed/2022/05/GHSA-hv22-96xg-53m5/GHSA-hv22-96xg-53m5.json index 31d8d0a2c33..e459f18e619 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv22-96xg-53m5/GHSA-hv22-96xg-53m5.json +++ b/advisories/unreviewed/2022/05/GHSA-hv22-96xg-53m5/GHSA-hv22-96xg-53m5.json @@ -7,12 +7,8 @@ "CVE-2009-0736" ], "details": "Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvcj-pfq5-3r38/GHSA-hvcj-pfq5-3r38.json b/advisories/unreviewed/2022/05/GHSA-hvcj-pfq5-3r38/GHSA-hvcj-pfq5-3r38.json index 1b5d6214144..343e7d34b68 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvcj-pfq5-3r38/GHSA-hvcj-pfq5-3r38.json +++ b/advisories/unreviewed/2022/05/GHSA-hvcj-pfq5-3r38/GHSA-hvcj-pfq5-3r38.json @@ -7,12 +7,8 @@ "CVE-2009-0701" ], "details": "Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvr2-xgj6-r6c3/GHSA-hvr2-xgj6-r6c3.json b/advisories/unreviewed/2022/05/GHSA-hvr2-xgj6-r6c3/GHSA-hvr2-xgj6-r6c3.json index 1bd3f848faf..3fb5f081fc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvr2-xgj6-r6c3/GHSA-hvr2-xgj6-r6c3.json +++ b/advisories/unreviewed/2022/05/GHSA-hvr2-xgj6-r6c3/GHSA-hvr2-xgj6-r6c3.json @@ -7,12 +7,8 @@ "CVE-2009-0636" ], "details": "Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw68-6jxh-m64r/GHSA-hw68-6jxh-m64r.json b/advisories/unreviewed/2022/05/GHSA-hw68-6jxh-m64r/GHSA-hw68-6jxh-m64r.json index cce5b3afc02..87b99fb4578 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw68-6jxh-m64r/GHSA-hw68-6jxh-m64r.json +++ b/advisories/unreviewed/2022/05/GHSA-hw68-6jxh-m64r/GHSA-hw68-6jxh-m64r.json @@ -7,12 +7,8 @@ "CVE-2009-0494" ], "details": "SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw93-jhp7-rqq6/GHSA-hw93-jhp7-rqq6.json b/advisories/unreviewed/2022/05/GHSA-hw93-jhp7-rqq6/GHSA-hw93-jhp7-rqq6.json index 390af8163fa..c46e9616a14 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw93-jhp7-rqq6/GHSA-hw93-jhp7-rqq6.json +++ b/advisories/unreviewed/2022/05/GHSA-hw93-jhp7-rqq6/GHSA-hw93-jhp7-rqq6.json @@ -7,12 +7,8 @@ "CVE-2009-0323" ], "details": "Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an \"HTML GI\" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j23w-r722-rm78/GHSA-j23w-r722-rm78.json b/advisories/unreviewed/2022/05/GHSA-j23w-r722-rm78/GHSA-j23w-r722-rm78.json index aa5ed0ffae9..50b5d56560a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j23w-r722-rm78/GHSA-j23w-r722-rm78.json +++ b/advisories/unreviewed/2022/05/GHSA-j23w-r722-rm78/GHSA-j23w-r722-rm78.json @@ -7,12 +7,8 @@ "CVE-2009-0388" ], "details": "Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2jf-9wq5-5895/GHSA-j2jf-9wq5-5895.json b/advisories/unreviewed/2022/05/GHSA-j2jf-9wq5-5895/GHSA-j2jf-9wq5-5895.json index 15528686f15..d113d808e54 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2jf-9wq5-5895/GHSA-j2jf-9wq5-5895.json +++ b/advisories/unreviewed/2022/05/GHSA-j2jf-9wq5-5895/GHSA-j2jf-9wq5-5895.json @@ -7,12 +7,8 @@ "CVE-2009-0108" ], "details": "PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2m4-6xqf-46h6/GHSA-j2m4-6xqf-46h6.json b/advisories/unreviewed/2022/05/GHSA-j2m4-6xqf-46h6/GHSA-j2m4-6xqf-46h6.json index 718a7425cd6..615f07329a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2m4-6xqf-46h6/GHSA-j2m4-6xqf-46h6.json +++ b/advisories/unreviewed/2022/05/GHSA-j2m4-6xqf-46h6/GHSA-j2m4-6xqf-46h6.json @@ -7,12 +7,8 @@ "CVE-2009-0495" ], "details": "PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2w9-gvpp-fx4v/GHSA-j2w9-gvpp-fx4v.json b/advisories/unreviewed/2022/05/GHSA-j2w9-gvpp-fx4v/GHSA-j2w9-gvpp-fx4v.json index cca1a1bcee6..c0b513bbdc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2w9-gvpp-fx4v/GHSA-j2w9-gvpp-fx4v.json +++ b/advisories/unreviewed/2022/05/GHSA-j2w9-gvpp-fx4v/GHSA-j2w9-gvpp-fx4v.json @@ -7,12 +7,8 @@ "CVE-2009-0325" ], "details": "Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4gr-j44w-w9m4/GHSA-j4gr-j44w-w9m4.json b/advisories/unreviewed/2022/05/GHSA-j4gr-j44w-w9m4/GHSA-j4gr-j44w-w9m4.json index ea3c275f75b..039805d92d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4gr-j44w-w9m4/GHSA-j4gr-j44w-w9m4.json +++ b/advisories/unreviewed/2022/05/GHSA-j4gr-j44w-w9m4/GHSA-j4gr-j44w-w9m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j57p-6rwh-fjcv/GHSA-j57p-6rwh-fjcv.json b/advisories/unreviewed/2022/05/GHSA-j57p-6rwh-fjcv/GHSA-j57p-6rwh-fjcv.json index 1be0f527d7d..05f3971e6fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j57p-6rwh-fjcv/GHSA-j57p-6rwh-fjcv.json +++ b/advisories/unreviewed/2022/05/GHSA-j57p-6rwh-fjcv/GHSA-j57p-6rwh-fjcv.json @@ -7,12 +7,8 @@ "CVE-2009-0827" ], "details": "PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5w4-f7qm-4ww8/GHSA-j5w4-f7qm-4ww8.json b/advisories/unreviewed/2022/05/GHSA-j5w4-f7qm-4ww8/GHSA-j5w4-f7qm-4ww8.json index 4088b075222..78c53553e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5w4-f7qm-4ww8/GHSA-j5w4-f7qm-4ww8.json +++ b/advisories/unreviewed/2022/05/GHSA-j5w4-f7qm-4ww8/GHSA-j5w4-f7qm-4ww8.json @@ -7,12 +7,8 @@ "CVE-2009-0932" ], "details": "Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j69x-v3vw-7m6g/GHSA-j69x-v3vw-7m6g.json b/advisories/unreviewed/2022/05/GHSA-j69x-v3vw-7m6g/GHSA-j69x-v3vw-7m6g.json index 5246c1a70e7..dd1ae1cc8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j69x-v3vw-7m6g/GHSA-j69x-v3vw-7m6g.json +++ b/advisories/unreviewed/2022/05/GHSA-j69x-v3vw-7m6g/GHSA-j69x-v3vw-7m6g.json @@ -7,12 +7,8 @@ "CVE-2009-0620" ], "details": "Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6h2-22f6-hhf6/GHSA-j6h2-22f6-hhf6.json b/advisories/unreviewed/2022/05/GHSA-j6h2-22f6-hhf6/GHSA-j6h2-22f6-hhf6.json index abb50b1b6b2..53a48def855 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6h2-22f6-hhf6/GHSA-j6h2-22f6-hhf6.json +++ b/advisories/unreviewed/2022/05/GHSA-j6h2-22f6-hhf6/GHSA-j6h2-22f6-hhf6.json @@ -7,12 +7,8 @@ "CVE-2009-0524" ], "details": "Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7qj-hw73-j3f2/GHSA-j7qj-hw73-j3f2.json b/advisories/unreviewed/2022/05/GHSA-j7qj-hw73-j3f2/GHSA-j7qj-hw73-j3f2.json index 1d6bbb996a9..601b3138aba 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7qj-hw73-j3f2/GHSA-j7qj-hw73-j3f2.json +++ b/advisories/unreviewed/2022/05/GHSA-j7qj-hw73-j3f2/GHSA-j7qj-hw73-j3f2.json @@ -7,12 +7,8 @@ "CVE-2009-0337" ], "details": "SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8j4-5jvm-4jxq/GHSA-j8j4-5jvm-4jxq.json b/advisories/unreviewed/2022/05/GHSA-j8j4-5jvm-4jxq/GHSA-j8j4-5jvm-4jxq.json index b470fddd913..e781b3a614b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8j4-5jvm-4jxq/GHSA-j8j4-5jvm-4jxq.json +++ b/advisories/unreviewed/2022/05/GHSA-j8j4-5jvm-4jxq/GHSA-j8j4-5jvm-4jxq.json @@ -7,12 +7,8 @@ "CVE-2009-0335" ], "details": "Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc4c-fgp6-8m4x/GHSA-jc4c-fgp6-8m4x.json b/advisories/unreviewed/2022/05/GHSA-jc4c-fgp6-8m4x/GHSA-jc4c-fgp6-8m4x.json index 9ad739217e7..69cb0d604ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc4c-fgp6-8m4x/GHSA-jc4c-fgp6-8m4x.json +++ b/advisories/unreviewed/2022/05/GHSA-jc4c-fgp6-8m4x/GHSA-jc4c-fgp6-8m4x.json @@ -7,12 +7,8 @@ "CVE-2009-0630" ], "details": "The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible Exchange Protocol (BEEP); (5) Network Admission Control HTTP Authentication Proxy; (6) Per-user URL Redirect for EAPoUDP, Dot1x, and MAC Authentication Bypass; (7) Distributed Director with HTTP Redirects; and (8) TCP DNS features in Cisco IOS 12.0 through 12.4 do not properly handle IP sockets, which allows remote attackers to cause a denial of service (outage or resource consumption) via a series of crafted TCP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf8r-xm3h-hcg6/GHSA-jf8r-xm3h-hcg6.json b/advisories/unreviewed/2022/05/GHSA-jf8r-xm3h-hcg6/GHSA-jf8r-xm3h-hcg6.json index 0a550bd3db8..45f208b9ffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf8r-xm3h-hcg6/GHSA-jf8r-xm3h-hcg6.json +++ b/advisories/unreviewed/2022/05/GHSA-jf8r-xm3h-hcg6/GHSA-jf8r-xm3h-hcg6.json @@ -7,12 +7,8 @@ "CVE-2009-0377" ], "details": "SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhxf-rmj6-ghq6/GHSA-jhxf-rmj6-ghq6.json b/advisories/unreviewed/2022/05/GHSA-jhxf-rmj6-ghq6/GHSA-jhxf-rmj6-ghq6.json index d45d6c974c4..d82ae5fb524 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhxf-rmj6-ghq6/GHSA-jhxf-rmj6-ghq6.json +++ b/advisories/unreviewed/2022/05/GHSA-jhxf-rmj6-ghq6/GHSA-jhxf-rmj6-ghq6.json @@ -7,12 +7,8 @@ "CVE-2009-0698" ], "details": "Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjhm-3xjm-qf49/GHSA-jjhm-3xjm-qf49.json b/advisories/unreviewed/2022/05/GHSA-jjhm-3xjm-qf49/GHSA-jjhm-3xjm-qf49.json index 1c65c609bc3..d38b94b9bd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjhm-3xjm-qf49/GHSA-jjhm-3xjm-qf49.json +++ b/advisories/unreviewed/2022/05/GHSA-jjhm-3xjm-qf49/GHSA-jjhm-3xjm-qf49.json @@ -7,12 +7,8 @@ "CVE-2009-0576" ], "details": "Unspecified vulnerability in Sun Java System Directory Server 5.2 p6 and earlier, and Enterprise Edition 5, allows remote attackers to cause a denial of service (daemon crash) via crafted LDAP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmc7-m54g-vwh9/GHSA-jmc7-m54g-vwh9.json b/advisories/unreviewed/2022/05/GHSA-jmc7-m54g-vwh9/GHSA-jmc7-m54g-vwh9.json index 7d3d02dd45d..643751c2474 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmc7-m54g-vwh9/GHSA-jmc7-m54g-vwh9.json +++ b/advisories/unreviewed/2022/05/GHSA-jmc7-m54g-vwh9/GHSA-jmc7-m54g-vwh9.json @@ -7,12 +7,8 @@ "CVE-2009-0755" ], "details": "The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmpc-v965-868j/GHSA-jmpc-v965-868j.json b/advisories/unreviewed/2022/05/GHSA-jmpc-v965-868j/GHSA-jmpc-v965-868j.json index 56ad2125baf..003c113598b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmpc-v965-868j/GHSA-jmpc-v965-868j.json +++ b/advisories/unreviewed/2022/05/GHSA-jmpc-v965-868j/GHSA-jmpc-v965-868j.json @@ -7,12 +7,8 @@ "CVE-2009-0638" ], "details": "The Cisco Firewall Services Module (FWSM) 2.x, 3.1 before 3.1(16), 3.2 before 3.2(13), and 4.0 before 4.0(6) for Cisco Catalyst 6500 switches and Cisco 7600 routers allows remote attackers to cause a denial of service (traffic-handling outage) via a series of malformed ICMP messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp6g-28v3-6rrm/GHSA-jp6g-28v3-6rrm.json b/advisories/unreviewed/2022/05/GHSA-jp6g-28v3-6rrm/GHSA-jp6g-28v3-6rrm.json index 62b7c4d43d3..16eec5b3f6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp6g-28v3-6rrm/GHSA-jp6g-28v3-6rrm.json +++ b/advisories/unreviewed/2022/05/GHSA-jp6g-28v3-6rrm/GHSA-jp6g-28v3-6rrm.json @@ -7,12 +7,8 @@ "CVE-2009-0298" ], "details": "Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqhc-vmcp-q22q/GHSA-jqhc-vmcp-q22q.json b/advisories/unreviewed/2022/05/GHSA-jqhc-vmcp-q22q/GHSA-jqhc-vmcp-q22q.json index 851d8737bb8..b4528a2905d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqhc-vmcp-q22q/GHSA-jqhc-vmcp-q22q.json +++ b/advisories/unreviewed/2022/05/GHSA-jqhc-vmcp-q22q/GHSA-jqhc-vmcp-q22q.json @@ -7,12 +7,8 @@ "CVE-2009-0199" ], "details": "Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jr29-2xh9-xxrh/GHSA-jr29-2xh9-xxrh.json b/advisories/unreviewed/2022/05/GHSA-jr29-2xh9-xxrh/GHSA-jr29-2xh9-xxrh.json index a87e1761da4..25213707c77 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr29-2xh9-xxrh/GHSA-jr29-2xh9-xxrh.json +++ b/advisories/unreviewed/2022/05/GHSA-jr29-2xh9-xxrh/GHSA-jr29-2xh9-xxrh.json @@ -7,12 +7,8 @@ "CVE-2009-0392" ], "details": "Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrh8-99hv-m6mp/GHSA-jrh8-99hv-m6mp.json b/advisories/unreviewed/2022/05/GHSA-jrh8-99hv-m6mp/GHSA-jrh8-99hv-m6mp.json index c89b6366c39..b044eeb1d48 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrh8-99hv-m6mp/GHSA-jrh8-99hv-m6mp.json +++ b/advisories/unreviewed/2022/05/GHSA-jrh8-99hv-m6mp/GHSA-jrh8-99hv-m6mp.json @@ -7,12 +7,8 @@ "CVE-2009-0841" ], "details": "Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrmj-xfwf-hjph/GHSA-jrmj-xfwf-hjph.json b/advisories/unreviewed/2022/05/GHSA-jrmj-xfwf-hjph/GHSA-jrmj-xfwf-hjph.json index 569c52a3e3e..e6453f7a145 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrmj-xfwf-hjph/GHSA-jrmj-xfwf-hjph.json +++ b/advisories/unreviewed/2022/05/GHSA-jrmj-xfwf-hjph/GHSA-jrmj-xfwf-hjph.json @@ -7,12 +7,8 @@ "CVE-2009-0860" ], "details": "Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrx2-84gx-ffrx/GHSA-jrx2-84gx-ffrx.json b/advisories/unreviewed/2022/05/GHSA-jrx2-84gx-ffrx/GHSA-jrx2-84gx-ffrx.json index fadb681c5d5..fdcedd80986 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrx2-84gx-ffrx/GHSA-jrx2-84gx-ffrx.json +++ b/advisories/unreviewed/2022/05/GHSA-jrx2-84gx-ffrx/GHSA-jrx2-84gx-ffrx.json @@ -7,12 +7,8 @@ "CVE-2009-0761" ], "details": "Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrx8-5mjp-vjpm/GHSA-jrx8-5mjp-vjpm.json b/advisories/unreviewed/2022/05/GHSA-jrx8-5mjp-vjpm/GHSA-jrx8-5mjp-vjpm.json index bfda19ced02..dd590bcc107 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrx8-5mjp-vjpm/GHSA-jrx8-5mjp-vjpm.json +++ b/advisories/unreviewed/2022/05/GHSA-jrx8-5mjp-vjpm/GHSA-jrx8-5mjp-vjpm.json @@ -7,12 +7,8 @@ "CVE-2009-0635" ], "details": "Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv86-ffgr-4446/GHSA-jv86-ffgr-4446.json b/advisories/unreviewed/2022/05/GHSA-jv86-ffgr-4446/GHSA-jv86-ffgr-4446.json index 71a593df9be..160a477e2e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv86-ffgr-4446/GHSA-jv86-ffgr-4446.json +++ b/advisories/unreviewed/2022/05/GHSA-jv86-ffgr-4446/GHSA-jv86-ffgr-4446.json @@ -7,12 +7,8 @@ "CVE-2009-0920" ], "details": "Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvv6-vvpc-5jxh/GHSA-jvv6-vvpc-5jxh.json b/advisories/unreviewed/2022/05/GHSA-jvv6-vvpc-5jxh/GHSA-jvv6-vvpc-5jxh.json index ab1d2ec1549..88fe4ce6f6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvv6-vvpc-5jxh/GHSA-jvv6-vvpc-5jxh.json +++ b/advisories/unreviewed/2022/05/GHSA-jvv6-vvpc-5jxh/GHSA-jvv6-vvpc-5jxh.json @@ -7,12 +7,8 @@ "CVE-2009-0373" ], "details": "SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwhg-ppr8-j6wh/GHSA-jwhg-ppr8-j6wh.json b/advisories/unreviewed/2022/05/GHSA-jwhg-ppr8-j6wh/GHSA-jwhg-ppr8-j6wh.json index c89fca7cb11..c6a00a6d698 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwhg-ppr8-j6wh/GHSA-jwhg-ppr8-j6wh.json +++ b/advisories/unreviewed/2022/05/GHSA-jwhg-ppr8-j6wh/GHSA-jwhg-ppr8-j6wh.json @@ -7,12 +7,8 @@ "CVE-2009-0613" ], "details": "Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwpp-857g-6hpg/GHSA-jwpp-857g-6hpg.json b/advisories/unreviewed/2022/05/GHSA-jwpp-857g-6hpg/GHSA-jwpp-857g-6hpg.json index ba4472eee8f..660db9bdc5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwpp-857g-6hpg/GHSA-jwpp-857g-6hpg.json +++ b/advisories/unreviewed/2022/05/GHSA-jwpp-857g-6hpg/GHSA-jwpp-857g-6hpg.json @@ -7,12 +7,8 @@ "CVE-2009-0627" ], "details": "Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified \"sequence of TCP packets\" related to \"TCP State manipulation,\" possibly related to separate attacks against CVE-2008-4609.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jx6f-8xjr-qf2g/GHSA-jx6f-8xjr-qf2g.json b/advisories/unreviewed/2022/05/GHSA-jx6f-8xjr-qf2g/GHSA-jx6f-8xjr-qf2g.json index 17634384907..52a2db1ba70 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx6f-8xjr-qf2g/GHSA-jx6f-8xjr-qf2g.json +++ b/advisories/unreviewed/2022/05/GHSA-jx6f-8xjr-qf2g/GHSA-jx6f-8xjr-qf2g.json @@ -7,12 +7,8 @@ "CVE-2009-0856" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m22q-2q8g-c2mg/GHSA-m22q-2q8g-c2mg.json b/advisories/unreviewed/2022/05/GHSA-m22q-2q8g-c2mg/GHSA-m22q-2q8g-c2mg.json index bc72068f6f2..7b059fae754 100644 --- a/advisories/unreviewed/2022/05/GHSA-m22q-2q8g-c2mg/GHSA-m22q-2q8g-c2mg.json +++ b/advisories/unreviewed/2022/05/GHSA-m22q-2q8g-c2mg/GHSA-m22q-2q8g-c2mg.json @@ -7,12 +7,8 @@ "CVE-2009-0386" ], "details": "Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m26p-hq85-35gf/GHSA-m26p-hq85-35gf.json b/advisories/unreviewed/2022/05/GHSA-m26p-hq85-35gf/GHSA-m26p-hq85-35gf.json index c8f122d999f..ff42551c331 100644 --- a/advisories/unreviewed/2022/05/GHSA-m26p-hq85-35gf/GHSA-m26p-hq85-35gf.json +++ b/advisories/unreviewed/2022/05/GHSA-m26p-hq85-35gf/GHSA-m26p-hq85-35gf.json @@ -7,12 +7,8 @@ "CVE-2009-0779" ], "details": "Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long \"input string.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3cg-wrvh-hrx5/GHSA-m3cg-wrvh-hrx5.json b/advisories/unreviewed/2022/05/GHSA-m3cg-wrvh-hrx5/GHSA-m3cg-wrvh-hrx5.json index d1685c7e9ea..da68b3f40e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3cg-wrvh-hrx5/GHSA-m3cg-wrvh-hrx5.json +++ b/advisories/unreviewed/2022/05/GHSA-m3cg-wrvh-hrx5/GHSA-m3cg-wrvh-hrx5.json @@ -7,12 +7,8 @@ "CVE-2009-0695" ], "details": "hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3w7-436v-mfw5/GHSA-m3w7-436v-mfw5.json b/advisories/unreviewed/2022/05/GHSA-m3w7-436v-mfw5/GHSA-m3w7-436v-mfw5.json index 7de2a456ef6..08d0615b506 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3w7-436v-mfw5/GHSA-m3w7-436v-mfw5.json +++ b/advisories/unreviewed/2022/05/GHSA-m3w7-436v-mfw5/GHSA-m3w7-436v-mfw5.json @@ -7,12 +7,8 @@ "CVE-2009-0752" ], "details": "Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related to the password recovery mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4rf-c9xj-c2gp/GHSA-m4rf-c9xj-c2gp.json b/advisories/unreviewed/2022/05/GHSA-m4rf-c9xj-c2gp/GHSA-m4rf-c9xj-c2gp.json index f8368b65c91..fd4f1e98e96 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4rf-c9xj-c2gp/GHSA-m4rf-c9xj-c2gp.json +++ b/advisories/unreviewed/2022/05/GHSA-m4rf-c9xj-c2gp/GHSA-m4rf-c9xj-c2gp.json @@ -7,12 +7,8 @@ "CVE-2009-0542" ], "details": "SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a \"%\" (percent) character in the username, which introduces a \"'\" (single quote) character during variable substitution by mod_sql.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m59h-8962-2rc8/GHSA-m59h-8962-2rc8.json b/advisories/unreviewed/2022/05/GHSA-m59h-8962-2rc8/GHSA-m59h-8962-2rc8.json index b55ea33e328..a4693896e51 100644 --- a/advisories/unreviewed/2022/05/GHSA-m59h-8962-2rc8/GHSA-m59h-8962-2rc8.json +++ b/advisories/unreviewed/2022/05/GHSA-m59h-8962-2rc8/GHSA-m59h-8962-2rc8.json @@ -7,12 +7,8 @@ "CVE-2009-0879" ], "details": "The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9cq-7rp5-q2v4/GHSA-m9cq-7rp5-q2v4.json b/advisories/unreviewed/2022/05/GHSA-m9cq-7rp5-q2v4/GHSA-m9cq-7rp5-q2v4.json index 704ccd7a971..d1bd8cc6a65 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9cq-7rp5-q2v4/GHSA-m9cq-7rp5-q2v4.json +++ b/advisories/unreviewed/2022/05/GHSA-m9cq-7rp5-q2v4/GHSA-m9cq-7rp5-q2v4.json @@ -7,12 +7,8 @@ "CVE-2009-0301" ], "details": "Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9mf-786v-p6mh/GHSA-m9mf-786v-p6mh.json b/advisories/unreviewed/2022/05/GHSA-m9mf-786v-p6mh/GHSA-m9mf-786v-p6mh.json index cff7cfe999c..d18c14f32a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9mf-786v-p6mh/GHSA-m9mf-786v-p6mh.json +++ b/advisories/unreviewed/2022/05/GHSA-m9mf-786v-p6mh/GHSA-m9mf-786v-p6mh.json @@ -7,12 +7,8 @@ "CVE-2009-0511" ], "details": "Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcpg-wmrf-chpc/GHSA-mcpg-wmrf-chpc.json b/advisories/unreviewed/2022/05/GHSA-mcpg-wmrf-chpc/GHSA-mcpg-wmrf-chpc.json index cbb1c6021db..de39ad2da73 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcpg-wmrf-chpc/GHSA-mcpg-wmrf-chpc.json +++ b/advisories/unreviewed/2022/05/GHSA-mcpg-wmrf-chpc/GHSA-mcpg-wmrf-chpc.json @@ -7,12 +7,8 @@ "CVE-2009-0341" ], "details": "The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcwc-rj3c-cccj/GHSA-mcwc-rj3c-cccj.json b/advisories/unreviewed/2022/05/GHSA-mcwc-rj3c-cccj/GHSA-mcwc-rj3c-cccj.json index 467e588d2ed..238e207c032 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcwc-rj3c-cccj/GHSA-mcwc-rj3c-cccj.json +++ b/advisories/unreviewed/2022/05/GHSA-mcwc-rj3c-cccj/GHSA-mcwc-rj3c-cccj.json @@ -7,12 +7,8 @@ "CVE-2009-0734" ], "details": "Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh9q-4hwx-prrv/GHSA-mh9q-4hwx-prrv.json b/advisories/unreviewed/2022/05/GHSA-mh9q-4hwx-prrv/GHSA-mh9q-4hwx-prrv.json index af400893656..13c9c856ecc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh9q-4hwx-prrv/GHSA-mh9q-4hwx-prrv.json +++ b/advisories/unreviewed/2022/05/GHSA-mh9q-4hwx-prrv/GHSA-mh9q-4hwx-prrv.json @@ -7,12 +7,8 @@ "CVE-2009-0626" ], "details": "The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhhq-94xq-hxv3/GHSA-mhhq-94xq-hxv3.json b/advisories/unreviewed/2022/05/GHSA-mhhq-94xq-hxv3/GHSA-mhhq-94xq-hxv3.json index 6bf027d162e..a71a6d173b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhhq-94xq-hxv3/GHSA-mhhq-94xq-hxv3.json +++ b/advisories/unreviewed/2022/05/GHSA-mhhq-94xq-hxv3/GHSA-mhhq-94xq-hxv3.json @@ -7,12 +7,8 @@ "CVE-2009-0327" ], "details": "SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjfx-cfq9-cvwm/GHSA-mjfx-cfq9-cvwm.json b/advisories/unreviewed/2022/05/GHSA-mjfx-cfq9-cvwm/GHSA-mjfx-cfq9-cvwm.json index 7c63dcd65f2..fca0b454fd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjfx-cfq9-cvwm/GHSA-mjfx-cfq9-cvwm.json +++ b/advisories/unreviewed/2022/05/GHSA-mjfx-cfq9-cvwm/GHSA-mjfx-cfq9-cvwm.json @@ -7,12 +7,8 @@ "CVE-2009-0573" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjr5-2p56-h9cx/GHSA-mjr5-2p56-h9cx.json b/advisories/unreviewed/2022/05/GHSA-mjr5-2p56-h9cx/GHSA-mjr5-2p56-h9cx.json index deb1a9fca9a..385095f51e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjr5-2p56-h9cx/GHSA-mjr5-2p56-h9cx.json +++ b/advisories/unreviewed/2022/05/GHSA-mjr5-2p56-h9cx/GHSA-mjr5-2p56-h9cx.json @@ -7,12 +7,8 @@ "CVE-2009-0209" ], "details": "PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm82-c2wc-w6j7/GHSA-mm82-c2wc-w6j7.json b/advisories/unreviewed/2022/05/GHSA-mm82-c2wc-w6j7/GHSA-mm82-c2wc-w6j7.json index 359af45d253..621874afc26 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm82-c2wc-w6j7/GHSA-mm82-c2wc-w6j7.json +++ b/advisories/unreviewed/2022/05/GHSA-mm82-c2wc-w6j7/GHSA-mm82-c2wc-w6j7.json @@ -7,12 +7,8 @@ "CVE-2009-0733" ], "details": "Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm94-82mx-j73h/GHSA-mm94-82mx-j73h.json b/advisories/unreviewed/2022/05/GHSA-mm94-82mx-j73h/GHSA-mm94-82mx-j73h.json index 17d05abe9d3..83ca682574d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm94-82mx-j73h/GHSA-mm94-82mx-j73h.json +++ b/advisories/unreviewed/2022/05/GHSA-mm94-82mx-j73h/GHSA-mm94-82mx-j73h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmxm-qr72-x76h/GHSA-mmxm-qr72-x76h.json b/advisories/unreviewed/2022/05/GHSA-mmxm-qr72-x76h/GHSA-mmxm-qr72-x76h.json index 0f96544053d..4a033f312b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmxm-qr72-x76h/GHSA-mmxm-qr72-x76h.json +++ b/advisories/unreviewed/2022/05/GHSA-mmxm-qr72-x76h/GHSA-mmxm-qr72-x76h.json @@ -7,12 +7,8 @@ "CVE-2009-0219" ], "details": "The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mp2x-g22c-42cx/GHSA-mp2x-g22c-42cx.json b/advisories/unreviewed/2022/05/GHSA-mp2x-g22c-42cx/GHSA-mp2x-g22c-42cx.json index 325fe8826d7..903d7c1f4a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp2x-g22c-42cx/GHSA-mp2x-g22c-42cx.json +++ b/advisories/unreviewed/2022/05/GHSA-mp2x-g22c-42cx/GHSA-mp2x-g22c-42cx.json @@ -7,12 +7,8 @@ "CVE-2009-0657" ], "details": "Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpcx-vp9j-q8cq/GHSA-mpcx-vp9j-q8cq.json b/advisories/unreviewed/2022/05/GHSA-mpcx-vp9j-q8cq/GHSA-mpcx-vp9j-q8cq.json index 3a766295efc..6c30987f3a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpcx-vp9j-q8cq/GHSA-mpcx-vp9j-q8cq.json +++ b/advisories/unreviewed/2022/05/GHSA-mpcx-vp9j-q8cq/GHSA-mpcx-vp9j-q8cq.json @@ -7,12 +7,8 @@ "CVE-2009-0497" ], "details": "Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in the log parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpf2-mfxq-qcgx/GHSA-mpf2-mfxq-qcgx.json b/advisories/unreviewed/2022/05/GHSA-mpf2-mfxq-qcgx/GHSA-mpf2-mfxq-qcgx.json index a3f91ee8fff..d850ccfcbd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpf2-mfxq-qcgx/GHSA-mpf2-mfxq-qcgx.json +++ b/advisories/unreviewed/2022/05/GHSA-mpf2-mfxq-qcgx/GHSA-mpf2-mfxq-qcgx.json @@ -7,12 +7,8 @@ "CVE-2009-0597" ], "details": "SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq8h-2x9x-3xfp/GHSA-mq8h-2x9x-3xfp.json b/advisories/unreviewed/2022/05/GHSA-mq8h-2x9x-3xfp/GHSA-mq8h-2x9x-3xfp.json index 652f0a22672..eda033c8125 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq8h-2x9x-3xfp/GHSA-mq8h-2x9x-3xfp.json +++ b/advisories/unreviewed/2022/05/GHSA-mq8h-2x9x-3xfp/GHSA-mq8h-2x9x-3xfp.json @@ -7,12 +7,8 @@ "CVE-2009-0741" ], "details": "SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq9f-wr48-f2j5/GHSA-mq9f-wr48-f2j5.json b/advisories/unreviewed/2022/05/GHSA-mq9f-wr48-f2j5/GHSA-mq9f-wr48-f2j5.json index 8752e8899ea..d6f02b8fa5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq9f-wr48-f2j5/GHSA-mq9f-wr48-f2j5.json +++ b/advisories/unreviewed/2022/05/GHSA-mq9f-wr48-f2j5/GHSA-mq9f-wr48-f2j5.json @@ -7,12 +7,8 @@ "CVE-2009-0381" ], "details": "SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqgh-xh6m-9qmc/GHSA-mqgh-xh6m-9qmc.json b/advisories/unreviewed/2022/05/GHSA-mqgh-xh6m-9qmc/GHSA-mqgh-xh6m-9qmc.json index b85d51e0fd6..b9977fecf74 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqgh-xh6m-9qmc/GHSA-mqgh-xh6m-9qmc.json +++ b/advisories/unreviewed/2022/05/GHSA-mqgh-xh6m-9qmc/GHSA-mqgh-xh6m-9qmc.json @@ -7,12 +7,8 @@ "CVE-2009-0811" ], "details": "Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqxw-x2wr-vcc9/GHSA-mqxw-x2wr-vcc9.json b/advisories/unreviewed/2022/05/GHSA-mqxw-x2wr-vcc9/GHSA-mqxw-x2wr-vcc9.json index a9e9f018ec5..20e5ae48515 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqxw-x2wr-vcc9/GHSA-mqxw-x2wr-vcc9.json +++ b/advisories/unreviewed/2022/05/GHSA-mqxw-x2wr-vcc9/GHSA-mqxw-x2wr-vcc9.json @@ -7,12 +7,8 @@ "CVE-2009-0339" ], "details": "SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to execute arbitrary SQL commands via the itemID parameter in a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrg2-3353-vhcw/GHSA-mrg2-3353-vhcw.json b/advisories/unreviewed/2022/05/GHSA-mrg2-3353-vhcw/GHSA-mrg2-3353-vhcw.json index 75ab75359d0..30546a7c33c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrg2-3353-vhcw/GHSA-mrg2-3353-vhcw.json +++ b/advisories/unreviewed/2022/05/GHSA-mrg2-3353-vhcw/GHSA-mrg2-3353-vhcw.json @@ -7,12 +7,8 @@ "CVE-2009-0297" ], "details": "SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvmj-r599-v76g/GHSA-mvmj-r599-v76g.json b/advisories/unreviewed/2022/05/GHSA-mvmj-r599-v76g/GHSA-mvmj-r599-v76g.json index e6e6224fc11..a98176a49c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvmj-r599-v76g/GHSA-mvmj-r599-v76g.json +++ b/advisories/unreviewed/2022/05/GHSA-mvmj-r599-v76g/GHSA-mvmj-r599-v76g.json @@ -7,12 +7,8 @@ "CVE-2009-0469" ], "details": "Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mw3c-3c68-9v4f/GHSA-mw3c-3c68-9v4f.json b/advisories/unreviewed/2022/05/GHSA-mw3c-3c68-9v4f/GHSA-mw3c-3c68-9v4f.json index 9ccf9de0427..1b01a67e316 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw3c-3c68-9v4f/GHSA-mw3c-3c68-9v4f.json +++ b/advisories/unreviewed/2022/05/GHSA-mw3c-3c68-9v4f/GHSA-mw3c-3c68-9v4f.json @@ -7,12 +7,8 @@ "CVE-2009-0526" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3) the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw5g-cjmr-pr3j/GHSA-mw5g-cjmr-pr3j.json b/advisories/unreviewed/2022/05/GHSA-mw5g-cjmr-pr3j/GHSA-mw5g-cjmr-pr3j.json index 25dc6416434..fe3990e8c59 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw5g-cjmr-pr3j/GHSA-mw5g-cjmr-pr3j.json +++ b/advisories/unreviewed/2022/05/GHSA-mw5g-cjmr-pr3j/GHSA-mw5g-cjmr-pr3j.json @@ -7,12 +7,8 @@ "CVE-2009-0743" ], "details": "Cross-site scripting (XSS) vulnerability in the edit account page in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote authenticated users to inject arbitrary web script or HTML via the E-mail Address field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3jh-55p5-h23p/GHSA-p3jh-55p5-h23p.json b/advisories/unreviewed/2022/05/GHSA-p3jh-55p5-h23p/GHSA-p3jh-55p5-h23p.json index b3a8138301e..06b603278d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3jh-55p5-h23p/GHSA-p3jh-55p5-h23p.json +++ b/advisories/unreviewed/2022/05/GHSA-p3jh-55p5-h23p/GHSA-p3jh-55p5-h23p.json @@ -7,12 +7,8 @@ "CVE-2009-0712" ], "details": "Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows local users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3v2-8f3r-2cvg/GHSA-p3v2-8f3r-2cvg.json b/advisories/unreviewed/2022/05/GHSA-p3v2-8f3r-2cvg/GHSA-p3v2-8f3r-2cvg.json index 3412f9105fb..9aa9edc2016 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3v2-8f3r-2cvg/GHSA-p3v2-8f3r-2cvg.json +++ b/advisories/unreviewed/2022/05/GHSA-p3v2-8f3r-2cvg/GHSA-p3v2-8f3r-2cvg.json @@ -7,12 +7,8 @@ "CVE-2009-0889" ], "details": "Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0512, and CVE-2009-0888.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p45g-44mp-mq74/GHSA-p45g-44mp-mq74.json b/advisories/unreviewed/2022/05/GHSA-p45g-44mp-mq74/GHSA-p45g-44mp-mq74.json index 356909649c0..04a8b2b6863 100644 --- a/advisories/unreviewed/2022/05/GHSA-p45g-44mp-mq74/GHSA-p45g-44mp-mq74.json +++ b/advisories/unreviewed/2022/05/GHSA-p45g-44mp-mq74/GHSA-p45g-44mp-mq74.json @@ -7,12 +7,8 @@ "CVE-2009-0887" ], "details": "Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5p6-vf7x-q4f7/GHSA-p5p6-vf7x-q4f7.json b/advisories/unreviewed/2022/05/GHSA-p5p6-vf7x-q4f7/GHSA-p5p6-vf7x-q4f7.json index 44c290f434d..083397d7771 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5p6-vf7x-q4f7/GHSA-p5p6-vf7x-q4f7.json +++ b/advisories/unreviewed/2022/05/GHSA-p5p6-vf7x-q4f7/GHSA-p5p6-vf7x-q4f7.json @@ -7,12 +7,8 @@ "CVE-2009-0891" ], "details": "The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5q7-3j52-5rg9/GHSA-p5q7-3j52-5rg9.json b/advisories/unreviewed/2022/05/GHSA-p5q7-3j52-5rg9/GHSA-p5q7-3j52-5rg9.json index eafc5108c71..e672a9f9907 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5q7-3j52-5rg9/GHSA-p5q7-3j52-5rg9.json +++ b/advisories/unreviewed/2022/05/GHSA-p5q7-3j52-5rg9/GHSA-p5q7-3j52-5rg9.json @@ -7,12 +7,8 @@ "CVE-2009-0415" ], "details": "Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD_PRELOAD path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6m8-wcqr-r4v8/GHSA-p6m8-wcqr-r4v8.json b/advisories/unreviewed/2022/05/GHSA-p6m8-wcqr-r4v8/GHSA-p6m8-wcqr-r4v8.json index c3170fb2a8e..1640d1e0cb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6m8-wcqr-r4v8/GHSA-p6m8-wcqr-r4v8.json +++ b/advisories/unreviewed/2022/05/GHSA-p6m8-wcqr-r4v8/GHSA-p6m8-wcqr-r4v8.json @@ -7,12 +7,8 @@ "CVE-2009-0994" ], "details": "Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-1017.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6q5-7686-4mrq/GHSA-p6q5-7686-4mrq.json b/advisories/unreviewed/2022/05/GHSA-p6q5-7686-4mrq/GHSA-p6q5-7686-4mrq.json index fba03e194f4..a7c893cbcb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6q5-7686-4mrq/GHSA-p6q5-7686-4mrq.json +++ b/advisories/unreviewed/2022/05/GHSA-p6q5-7686-4mrq/GHSA-p6q5-7686-4mrq.json @@ -7,12 +7,8 @@ "CVE-2009-0628" ], "details": "Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading to a Transmission Control Block (TCB) leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p738-xrj8-6293/GHSA-p738-xrj8-6293.json b/advisories/unreviewed/2022/05/GHSA-p738-xrj8-6293/GHSA-p738-xrj8-6293.json index 254c49cde34..54a1f066b3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p738-xrj8-6293/GHSA-p738-xrj8-6293.json +++ b/advisories/unreviewed/2022/05/GHSA-p738-xrj8-6293/GHSA-p738-xrj8-6293.json @@ -7,12 +7,8 @@ "CVE-2009-0865" ], "details": "Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p74c-8xj5-rjw6/GHSA-p74c-8xj5-rjw6.json b/advisories/unreviewed/2022/05/GHSA-p74c-8xj5-rjw6/GHSA-p74c-8xj5-rjw6.json index 2a3697c1f1a..e1af1da2fb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p74c-8xj5-rjw6/GHSA-p74c-8xj5-rjw6.json +++ b/advisories/unreviewed/2022/05/GHSA-p74c-8xj5-rjw6/GHSA-p74c-8xj5-rjw6.json @@ -7,12 +7,8 @@ "CVE-2009-0371" ], "details": "Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8cg-339m-cpjf/GHSA-p8cg-339m-cpjf.json b/advisories/unreviewed/2022/05/GHSA-p8cg-339m-cpjf/GHSA-p8cg-339m-cpjf.json index 03b5172ee16..4893f0733cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8cg-339m-cpjf/GHSA-p8cg-339m-cpjf.json +++ b/advisories/unreviewed/2022/05/GHSA-p8cg-339m-cpjf/GHSA-p8cg-339m-cpjf.json @@ -7,12 +7,8 @@ "CVE-2009-0532" ], "details": "Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc9p-qh58-2xv7/GHSA-pc9p-qh58-2xv7.json b/advisories/unreviewed/2022/05/GHSA-pc9p-qh58-2xv7/GHSA-pc9p-qh58-2xv7.json index beec1d0f7cb..2157b1099d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc9p-qh58-2xv7/GHSA-pc9p-qh58-2xv7.json +++ b/advisories/unreviewed/2022/05/GHSA-pc9p-qh58-2xv7/GHSA-pc9p-qh58-2xv7.json @@ -7,12 +7,8 @@ "CVE-2009-0333" ], "details": "SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf7x-vr8p-v434/GHSA-pf7x-vr8p-v434.json b/advisories/unreviewed/2022/05/GHSA-pf7x-vr8p-v434/GHSA-pf7x-vr8p-v434.json index 9c5a459e35d..f913f5d5659 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf7x-vr8p-v434/GHSA-pf7x-vr8p-v434.json +++ b/advisories/unreviewed/2022/05/GHSA-pf7x-vr8p-v434/GHSA-pf7x-vr8p-v434.json @@ -7,12 +7,8 @@ "CVE-2009-0708" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) hijack the authentication of administrators via unknown vectors or (2) hijack the authentication of arbitrary users via vectors involving the profile page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfc6-wvw7-vx69/GHSA-pfc6-wvw7-vx69.json b/advisories/unreviewed/2022/05/GHSA-pfc6-wvw7-vx69/GHSA-pfc6-wvw7-vx69.json index 3160a4d5d84..d00f95f066b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfc6-wvw7-vx69/GHSA-pfc6-wvw7-vx69.json +++ b/advisories/unreviewed/2022/05/GHSA-pfc6-wvw7-vx69/GHSA-pfc6-wvw7-vx69.json @@ -7,12 +7,8 @@ "CVE-2009-0874" ], "details": "Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the door_call function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgcm-99fr-54fx/GHSA-pgcm-99fr-54fx.json b/advisories/unreviewed/2022/05/GHSA-pgcm-99fr-54fx/GHSA-pgcm-99fr-54fx.json index baf89e5b416..20bde98870a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgcm-99fr-54fx/GHSA-pgcm-99fr-54fx.json +++ b/advisories/unreviewed/2022/05/GHSA-pgcm-99fr-54fx/GHSA-pgcm-99fr-54fx.json @@ -7,12 +7,8 @@ "CVE-2009-0326" ], "details": "SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph4p-rhxr-85rq/GHSA-ph4p-rhxr-85rq.json b/advisories/unreviewed/2022/05/GHSA-ph4p-rhxr-85rq/GHSA-ph4p-rhxr-85rq.json index 40091081793..a249566a252 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph4p-rhxr-85rq/GHSA-ph4p-rhxr-85rq.json +++ b/advisories/unreviewed/2022/05/GHSA-ph4p-rhxr-85rq/GHSA-ph4p-rhxr-85rq.json @@ -7,12 +7,8 @@ "CVE-2009-0847" ], "details": "The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj5p-pmfv-gr5m/GHSA-pj5p-pmfv-gr5m.json b/advisories/unreviewed/2022/05/GHSA-pj5p-pmfv-gr5m/GHSA-pj5p-pmfv-gr5m.json index 6fed2857c67..c15c02a2fdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj5p-pmfv-gr5m/GHSA-pj5p-pmfv-gr5m.json +++ b/advisories/unreviewed/2022/05/GHSA-pj5p-pmfv-gr5m/GHSA-pj5p-pmfv-gr5m.json @@ -7,12 +7,8 @@ "CVE-2009-0868" ], "details": "CRLF injection vulnerability in the WebLink template in Fujitsu Jasmine2000 Enterprise Edition allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm5j-jrq9-vmhx/GHSA-pm5j-jrq9-vmhx.json b/advisories/unreviewed/2022/05/GHSA-pm5j-jrq9-vmhx/GHSA-pm5j-jrq9-vmhx.json index f3d864bdf70..3cede98961c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm5j-jrq9-vmhx/GHSA-pm5j-jrq9-vmhx.json +++ b/advisories/unreviewed/2022/05/GHSA-pm5j-jrq9-vmhx/GHSA-pm5j-jrq9-vmhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmh2-h42j-q27q/GHSA-pmh2-h42j-q27q.json b/advisories/unreviewed/2022/05/GHSA-pmh2-h42j-q27q/GHSA-pmh2-h42j-q27q.json index 00031ce9237..005fb107482 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmh2-h42j-q27q/GHSA-pmh2-h42j-q27q.json +++ b/advisories/unreviewed/2022/05/GHSA-pmh2-h42j-q27q/GHSA-pmh2-h42j-q27q.json @@ -7,12 +7,8 @@ "CVE-2009-0745" ], "details": "The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause a denial of service (OOPS) by arranging for crafted values to be present in available memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr5c-5h27-fxw4/GHSA-pr5c-5h27-fxw4.json b/advisories/unreviewed/2022/05/GHSA-pr5c-5h27-fxw4/GHSA-pr5c-5h27-fxw4.json index 19bc5128298..3e775a1fd3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr5c-5h27-fxw4/GHSA-pr5c-5h27-fxw4.json +++ b/advisories/unreviewed/2022/05/GHSA-pr5c-5h27-fxw4/GHSA-pr5c-5h27-fxw4.json @@ -7,12 +7,8 @@ "CVE-2009-0803" ], "details": "SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prp2-54v2-c9p2/GHSA-prp2-54v2-c9p2.json b/advisories/unreviewed/2022/05/GHSA-prp2-54v2-c9p2/GHSA-prp2-54v2-c9p2.json index cfa2baf8799..e2aab6b9e20 100644 --- a/advisories/unreviewed/2022/05/GHSA-prp2-54v2-c9p2/GHSA-prp2-54v2-c9p2.json +++ b/advisories/unreviewed/2022/05/GHSA-prp2-54v2-c9p2/GHSA-prp2-54v2-c9p2.json @@ -7,12 +7,8 @@ "CVE-2009-0883" ], "details": "SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pv6c-7f5h-fjj3/GHSA-pv6c-7f5h-fjj3.json b/advisories/unreviewed/2022/05/GHSA-pv6c-7f5h-fjj3/GHSA-pv6c-7f5h-fjj3.json index 6389a23acbe..13997222c51 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv6c-7f5h-fjj3/GHSA-pv6c-7f5h-fjj3.json +++ b/advisories/unreviewed/2022/05/GHSA-pv6c-7f5h-fjj3/GHSA-pv6c-7f5h-fjj3.json @@ -7,12 +7,8 @@ "CVE-2009-0530" ], "details": "Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2) g_pcltar_lib_dir parameter to includes/tar_lib/pcltar.lib.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwwh-5hg7-cxj9/GHSA-pwwh-5hg7-cxj9.json b/advisories/unreviewed/2022/05/GHSA-pwwh-5hg7-cxj9/GHSA-pwwh-5hg7-cxj9.json index 70f45845dcd..31794647908 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwwh-5hg7-cxj9/GHSA-pwwh-5hg7-cxj9.json +++ b/advisories/unreviewed/2022/05/GHSA-pwwh-5hg7-cxj9/GHSA-pwwh-5hg7-cxj9.json @@ -7,12 +7,8 @@ "CVE-2009-0909" ], "details": "Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxcp-c9j5-gwr2/GHSA-pxcp-c9j5-gwr2.json b/advisories/unreviewed/2022/05/GHSA-pxcp-c9j5-gwr2/GHSA-pxcp-c9j5-gwr2.json index 2eb5e571808..6092bfbe7d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxcp-c9j5-gwr2/GHSA-pxcp-c9j5-gwr2.json +++ b/advisories/unreviewed/2022/05/GHSA-pxcp-c9j5-gwr2/GHSA-pxcp-c9j5-gwr2.json @@ -7,12 +7,8 @@ "CVE-2009-0594" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q27c-728j-g55g/GHSA-q27c-728j-g55g.json b/advisories/unreviewed/2022/05/GHSA-q27c-728j-g55g/GHSA-q27c-728j-g55g.json index 8fed911a041..a21c4540656 100644 --- a/advisories/unreviewed/2022/05/GHSA-q27c-728j-g55g/GHSA-q27c-728j-g55g.json +++ b/advisories/unreviewed/2022/05/GHSA-q27c-728j-g55g/GHSA-q27c-728j-g55g.json @@ -7,12 +7,8 @@ "CVE-2009-0403" ], "details": "SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2pp-hq8h-7mm3/GHSA-q2pp-hq8h-7mm3.json b/advisories/unreviewed/2022/05/GHSA-q2pp-hq8h-7mm3/GHSA-q2pp-hq8h-7mm3.json index 4eb77dd65d1..929bbbd9dfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2pp-hq8h-7mm3/GHSA-q2pp-hq8h-7mm3.json +++ b/advisories/unreviewed/2022/05/GHSA-q2pp-hq8h-7mm3/GHSA-q2pp-hq8h-7mm3.json @@ -7,12 +7,8 @@ "CVE-2009-0368" ], "details": "OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q369-qc62-gmgr/GHSA-q369-qc62-gmgr.json b/advisories/unreviewed/2022/05/GHSA-q369-qc62-gmgr/GHSA-q369-qc62-gmgr.json index 64f2de3c7be..cf276f8b671 100644 --- a/advisories/unreviewed/2022/05/GHSA-q369-qc62-gmgr/GHSA-q369-qc62-gmgr.json +++ b/advisories/unreviewed/2022/05/GHSA-q369-qc62-gmgr/GHSA-q369-qc62-gmgr.json @@ -7,12 +7,8 @@ "CVE-2009-0376" ], "details": "Heap-based buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a modified field that controls an unspecified structure length and triggers heap corruption, related to use of RealPlayer through a Windows Explorer plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3p5-hhw7-66hg/GHSA-q3p5-hhw7-66hg.json b/advisories/unreviewed/2022/05/GHSA-q3p5-hhw7-66hg/GHSA-q3p5-hhw7-66hg.json index 501223cc7ac..3f2a996b4d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3p5-hhw7-66hg/GHSA-q3p5-hhw7-66hg.json +++ b/advisories/unreviewed/2022/05/GHSA-q3p5-hhw7-66hg/GHSA-q3p5-hhw7-66hg.json @@ -7,12 +7,8 @@ "CVE-2009-0568" ], "details": "The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to \"IDL interfaces containing a non-conformant varying array\" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka \"RPC Marshalling Engine Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3wc-p9hf-q4xg/GHSA-q3wc-p9hf-q4xg.json b/advisories/unreviewed/2022/05/GHSA-q3wc-p9hf-q4xg/GHSA-q3wc-p9hf-q4xg.json index 7d640f1ef74..849087695b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3wc-p9hf-q4xg/GHSA-q3wc-p9hf-q4xg.json +++ b/advisories/unreviewed/2022/05/GHSA-q3wc-p9hf-q4xg/GHSA-q3wc-p9hf-q4xg.json @@ -7,12 +7,8 @@ "CVE-2009-0869" ], "details": "Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 on Windows allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q57m-cgxh-vv5j/GHSA-q57m-cgxh-vv5j.json b/advisories/unreviewed/2022/05/GHSA-q57m-cgxh-vv5j/GHSA-q57m-cgxh-vv5j.json index 5673bc6c75f..3d42c24d79e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q57m-cgxh-vv5j/GHSA-q57m-cgxh-vv5j.json +++ b/advisories/unreviewed/2022/05/GHSA-q57m-cgxh-vv5j/GHSA-q57m-cgxh-vv5j.json @@ -7,12 +7,8 @@ "CVE-2009-0663" ], "details": "Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5m9-pgx8-2fj7/GHSA-q5m9-pgx8-2fj7.json b/advisories/unreviewed/2022/05/GHSA-q5m9-pgx8-2fj7/GHSA-q5m9-pgx8-2fj7.json index 4cfcc0b8f3c..c541a268fc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5m9-pgx8-2fj7/GHSA-q5m9-pgx8-2fj7.json +++ b/advisories/unreviewed/2022/05/GHSA-q5m9-pgx8-2fj7/GHSA-q5m9-pgx8-2fj7.json @@ -7,12 +7,8 @@ "CVE-2009-0420" ], "details": "SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6gf-j4x6-jmf6/GHSA-q6gf-j4x6-jmf6.json b/advisories/unreviewed/2022/05/GHSA-q6gf-j4x6-jmf6/GHSA-q6gf-j4x6-jmf6.json index c028993126d..1c216a0e47f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6gf-j4x6-jmf6/GHSA-q6gf-j4x6-jmf6.json +++ b/advisories/unreviewed/2022/05/GHSA-q6gf-j4x6-jmf6/GHSA-q6gf-j4x6-jmf6.json @@ -7,12 +7,8 @@ "CVE-2009-0916" ], "details": "Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a \"moderately severe issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6p7-x98h-wq2r/GHSA-q6p7-x98h-wq2r.json b/advisories/unreviewed/2022/05/GHSA-q6p7-x98h-wq2r/GHSA-q6p7-x98h-wq2r.json index 4152c149dd8..84cbaca58a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6p7-x98h-wq2r/GHSA-q6p7-x98h-wq2r.json +++ b/advisories/unreviewed/2022/05/GHSA-q6p7-x98h-wq2r/GHSA-q6p7-x98h-wq2r.json @@ -7,12 +7,8 @@ "CVE-2009-0477" ], "details": "Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via vectors related to the contract filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6r6-8rm7-3r93/GHSA-q6r6-8rm7-3r93.json b/advisories/unreviewed/2022/05/GHSA-q6r6-8rm7-3r93/GHSA-q6r6-8rm7-3r93.json index 2fd84490f8b..5a48d879418 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6r6-8rm7-3r93/GHSA-q6r6-8rm7-3r93.json +++ b/advisories/unreviewed/2022/05/GHSA-q6r6-8rm7-3r93/GHSA-q6r6-8rm7-3r93.json @@ -7,12 +7,8 @@ "CVE-2009-0348" ], "details": "The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7v7-wgvv-h4x9/GHSA-q7v7-wgvv-h4x9.json b/advisories/unreviewed/2022/05/GHSA-q7v7-wgvv-h4x9/GHSA-q7v7-wgvv-h4x9.json index ba7fa239da1..664a5be1777 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7v7-wgvv-h4x9/GHSA-q7v7-wgvv-h4x9.json +++ b/advisories/unreviewed/2022/05/GHSA-q7v7-wgvv-h4x9/GHSA-q7v7-wgvv-h4x9.json @@ -7,12 +7,8 @@ "CVE-2009-0482" ], "details": "Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q85f-4wpm-qqjc/GHSA-q85f-4wpm-qqjc.json b/advisories/unreviewed/2022/05/GHSA-q85f-4wpm-qqjc/GHSA-q85f-4wpm-qqjc.json index 2aa3f3f2c70..ce26159b6da 100644 --- a/advisories/unreviewed/2022/05/GHSA-q85f-4wpm-qqjc/GHSA-q85f-4wpm-qqjc.json +++ b/advisories/unreviewed/2022/05/GHSA-q85f-4wpm-qqjc/GHSA-q85f-4wpm-qqjc.json @@ -7,12 +7,8 @@ "CVE-2009-0843" ], "details": "The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q946-j8q9-vv2q/GHSA-q946-j8q9-vv2q.json b/advisories/unreviewed/2022/05/GHSA-q946-j8q9-vv2q/GHSA-q946-j8q9-vv2q.json index 4164cca83c8..aabb8d419f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q946-j8q9-vv2q/GHSA-q946-j8q9-vv2q.json +++ b/advisories/unreviewed/2022/05/GHSA-q946-j8q9-vv2q/GHSA-q946-j8q9-vv2q.json @@ -7,12 +7,8 @@ "CVE-2009-0765" ], "details": "Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the configfile parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9ff-c5gg-qmrr/GHSA-q9ff-c5gg-qmrr.json b/advisories/unreviewed/2022/05/GHSA-q9ff-c5gg-qmrr/GHSA-q9ff-c5gg-qmrr.json index e240d8bc010..253c01af9b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9ff-c5gg-qmrr/GHSA-q9ff-c5gg-qmrr.json +++ b/advisories/unreviewed/2022/05/GHSA-q9ff-c5gg-qmrr/GHSA-q9ff-c5gg-qmrr.json @@ -7,12 +7,8 @@ "CVE-2009-0105" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9fv-vxwp-xphg/GHSA-q9fv-vxwp-xphg.json b/advisories/unreviewed/2022/05/GHSA-q9fv-vxwp-xphg/GHSA-q9fv-vxwp-xphg.json index 923a558159f..d7c77313074 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9fv-vxwp-xphg/GHSA-q9fv-vxwp-xphg.json +++ b/advisories/unreviewed/2022/05/GHSA-q9fv-vxwp-xphg/GHSA-q9fv-vxwp-xphg.json @@ -7,12 +7,8 @@ "CVE-2009-0605" ], "details": "Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9jq-m54g-4gc4/GHSA-q9jq-m54g-4gc4.json b/advisories/unreviewed/2022/05/GHSA-q9jq-m54g-4gc4/GHSA-q9jq-m54g-4gc4.json index ec290022338..a181728265e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9jq-m54g-4gc4/GHSA-q9jq-m54g-4gc4.json +++ b/advisories/unreviewed/2022/05/GHSA-q9jq-m54g-4gc4/GHSA-q9jq-m54g-4gc4.json @@ -7,12 +7,8 @@ "CVE-2009-0340" ], "details": "Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc2r-pgq6-m25v/GHSA-qc2r-pgq6-m25v.json b/advisories/unreviewed/2022/05/GHSA-qc2r-pgq6-m25v/GHSA-qc2r-pgq6-m25v.json index 6efa61d825d..bb83541b5e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc2r-pgq6-m25v/GHSA-qc2r-pgq6-m25v.json +++ b/advisories/unreviewed/2022/05/GHSA-qc2r-pgq6-m25v/GHSA-qc2r-pgq6-m25v.json @@ -7,12 +7,8 @@ "CVE-2009-0489" ], "details": "The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfpv-wrwf-3vwj/GHSA-qfpv-wrwf-3vwj.json b/advisories/unreviewed/2022/05/GHSA-qfpv-wrwf-3vwj/GHSA-qfpv-wrwf-3vwj.json index c6cd2e54e76..539fc437c13 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfpv-wrwf-3vwj/GHSA-qfpv-wrwf-3vwj.json +++ b/advisories/unreviewed/2022/05/GHSA-qfpv-wrwf-3vwj/GHSA-qfpv-wrwf-3vwj.json @@ -7,12 +7,8 @@ "CVE-2009-0358" ], "details": "Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg3q-75wp-xqwp/GHSA-qg3q-75wp-xqwp.json b/advisories/unreviewed/2022/05/GHSA-qg3q-75wp-xqwp/GHSA-qg3q-75wp-xqwp.json index f489d00cfbe..09ed33b721e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg3q-75wp-xqwp/GHSA-qg3q-75wp-xqwp.json +++ b/advisories/unreviewed/2022/05/GHSA-qg3q-75wp-xqwp/GHSA-qg3q-75wp-xqwp.json @@ -7,12 +7,8 @@ "CVE-2009-0610" ], "details": "Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to display.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj38-4888-qchf/GHSA-qj38-4888-qchf.json b/advisories/unreviewed/2022/05/GHSA-qj38-4888-qchf/GHSA-qj38-4888-qchf.json index c8f7e9338b6..8b8f7c1a2cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj38-4888-qchf/GHSA-qj38-4888-qchf.json +++ b/advisories/unreviewed/2022/05/GHSA-qj38-4888-qchf/GHSA-qj38-4888-qchf.json @@ -7,12 +7,8 @@ "CVE-2009-0917" ], "details": "Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by PTK. NOTE: the vendor states that the product is intended for use in a laboratory with \"no contact from / to internet.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmp2-97fj-8p95/GHSA-qmp2-97fj-8p95.json b/advisories/unreviewed/2022/05/GHSA-qmp2-97fj-8p95/GHSA-qmp2-97fj-8p95.json index 0ea65776e51..4061f29c222 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmp2-97fj-8p95/GHSA-qmp2-97fj-8p95.json +++ b/advisories/unreviewed/2022/05/GHSA-qmp2-97fj-8p95/GHSA-qmp2-97fj-8p95.json @@ -7,12 +7,8 @@ "CVE-2009-0859" ], "details": "The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp8x-4f6p-mmhh/GHSA-qp8x-4f6p-mmhh.json b/advisories/unreviewed/2022/05/GHSA-qp8x-4f6p-mmhh/GHSA-qp8x-4f6p-mmhh.json index f7acb8ee084..e1d8d615d51 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp8x-4f6p-mmhh/GHSA-qp8x-4f6p-mmhh.json +++ b/advisories/unreviewed/2022/05/GHSA-qp8x-4f6p-mmhh/GHSA-qp8x-4f6p-mmhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qphg-f927-gw8f/GHSA-qphg-f927-gw8f.json b/advisories/unreviewed/2022/05/GHSA-qphg-f927-gw8f/GHSA-qphg-f927-gw8f.json index 6564cabc0b4..1b2f5bbad9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qphg-f927-gw8f/GHSA-qphg-f927-gw8f.json +++ b/advisories/unreviewed/2022/05/GHSA-qphg-f927-gw8f/GHSA-qphg-f927-gw8f.json @@ -7,12 +7,8 @@ "CVE-2009-0578" ], "details": "GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr6w-h8jw-cw4j/GHSA-qr6w-h8jw-cw4j.json b/advisories/unreviewed/2022/05/GHSA-qr6w-h8jw-cw4j/GHSA-qr6w-h8jw-cw4j.json index a441fb90dd0..46e437b6229 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr6w-h8jw-cw4j/GHSA-qr6w-h8jw-cw4j.json +++ b/advisories/unreviewed/2022/05/GHSA-qr6w-h8jw-cw4j/GHSA-qr6w-h8jw-cw4j.json @@ -7,12 +7,8 @@ "CVE-2009-0522" ], "details": "Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the \"mouse pointer display,\" related to a \"Clickjacking attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrjg-9vj5-93pc/GHSA-qrjg-9vj5-93pc.json b/advisories/unreviewed/2022/05/GHSA-qrjg-9vj5-93pc/GHSA-qrjg-9vj5-93pc.json index 9ea4f1dca03..34e614ba367 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrjg-9vj5-93pc/GHSA-qrjg-9vj5-93pc.json +++ b/advisories/unreviewed/2022/05/GHSA-qrjg-9vj5-93pc/GHSA-qrjg-9vj5-93pc.json @@ -7,12 +7,8 @@ "CVE-2009-0305" ], "details": "Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv5f-7w93-3mpg/GHSA-qv5f-7w93-3mpg.json b/advisories/unreviewed/2022/05/GHSA-qv5f-7w93-3mpg/GHSA-qv5f-7w93-3mpg.json index c51ac2bb361..4a493df1285 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv5f-7w93-3mpg/GHSA-qv5f-7w93-3mpg.json +++ b/advisories/unreviewed/2022/05/GHSA-qv5f-7w93-3mpg/GHSA-qv5f-7w93-3mpg.json @@ -7,12 +7,8 @@ "CVE-2009-0104" ], "details": "SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxxc-64qv-jfrg/GHSA-qxxc-64qv-jfrg.json b/advisories/unreviewed/2022/05/GHSA-qxxc-64qv-jfrg/GHSA-qxxc-64qv-jfrg.json index f84b4c3c412..0be3ecb3bf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxxc-64qv-jfrg/GHSA-qxxc-64qv-jfrg.json +++ b/advisories/unreviewed/2022/05/GHSA-qxxc-64qv-jfrg/GHSA-qxxc-64qv-jfrg.json @@ -7,12 +7,8 @@ "CVE-2009-0737" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r26m-hp24-85qr/GHSA-r26m-hp24-85qr.json b/advisories/unreviewed/2022/05/GHSA-r26m-hp24-85qr/GHSA-r26m-hp24-85qr.json index 090abb1d214..eca42e16faf 100644 --- a/advisories/unreviewed/2022/05/GHSA-r26m-hp24-85qr/GHSA-r26m-hp24-85qr.json +++ b/advisories/unreviewed/2022/05/GHSA-r26m-hp24-85qr/GHSA-r26m-hp24-85qr.json @@ -7,12 +7,8 @@ "CVE-2009-0317" ], "details": "Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2g9-mqfm-6gvv/GHSA-r2g9-mqfm-6gvv.json b/advisories/unreviewed/2022/05/GHSA-r2g9-mqfm-6gvv/GHSA-r2g9-mqfm-6gvv.json index a32e66d27df..15b19a423bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2g9-mqfm-6gvv/GHSA-r2g9-mqfm-6gvv.json +++ b/advisories/unreviewed/2022/05/GHSA-r2g9-mqfm-6gvv/GHSA-r2g9-mqfm-6gvv.json @@ -7,12 +7,8 @@ "CVE-2009-0881" ], "details": "SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2rh-4fmj-hpq7/GHSA-r2rh-4fmj-hpq7.json b/advisories/unreviewed/2022/05/GHSA-r2rh-4fmj-hpq7/GHSA-r2rh-4fmj-hpq7.json index b698370226e..5184edbb090 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2rh-4fmj-hpq7/GHSA-r2rh-4fmj-hpq7.json +++ b/advisories/unreviewed/2022/05/GHSA-r2rh-4fmj-hpq7/GHSA-r2rh-4fmj-hpq7.json @@ -7,12 +7,8 @@ "CVE-2009-0422" ], "details": "Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4gm-vpf3-q479/GHSA-r4gm-vpf3-q479.json b/advisories/unreviewed/2022/05/GHSA-r4gm-vpf3-q479/GHSA-r4gm-vpf3-q479.json index bbde16a0579..104a6b74af7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4gm-vpf3-q479/GHSA-r4gm-vpf3-q479.json +++ b/advisories/unreviewed/2022/05/GHSA-r4gm-vpf3-q479/GHSA-r4gm-vpf3-q479.json @@ -7,12 +7,8 @@ "CVE-2009-0486" ], "details": "Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r65m-3g44-24hw/GHSA-r65m-3g44-24hw.json b/advisories/unreviewed/2022/05/GHSA-r65m-3g44-24hw/GHSA-r65m-3g44-24hw.json index e2f29232b2b..d39a59e4f7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r65m-3g44-24hw/GHSA-r65m-3g44-24hw.json +++ b/advisories/unreviewed/2022/05/GHSA-r65m-3g44-24hw/GHSA-r65m-3g44-24hw.json @@ -7,12 +7,8 @@ "CVE-2009-0096" ], "details": "Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka \"Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6w5-38x8-rrr4/GHSA-r6w5-38x8-rrr4.json b/advisories/unreviewed/2022/05/GHSA-r6w5-38x8-rrr4/GHSA-r6w5-38x8-rrr4.json index 75f04fa8de1..05fcf0ec217 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6w5-38x8-rrr4/GHSA-r6w5-38x8-rrr4.json +++ b/advisories/unreviewed/2022/05/GHSA-r6w5-38x8-rrr4/GHSA-r6w5-38x8-rrr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7jh-88fq-f64h/GHSA-r7jh-88fq-f64h.json b/advisories/unreviewed/2022/05/GHSA-r7jh-88fq-f64h/GHSA-r7jh-88fq-f64h.json index 73f2231ff92..e64cede33bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7jh-88fq-f64h/GHSA-r7jh-88fq-f64h.json +++ b/advisories/unreviewed/2022/05/GHSA-r7jh-88fq-f64h/GHSA-r7jh-88fq-f64h.json @@ -7,12 +7,8 @@ "CVE-2009-0502" ], "details": "Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the \"Login as\" feature is used to visit a MyMoodle or Blog page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r82w-5vrw-9x74/GHSA-r82w-5vrw-9x74.json b/advisories/unreviewed/2022/05/GHSA-r82w-5vrw-9x74/GHSA-r82w-5vrw-9x74.json index 0e3a257b036..63c0eb9bc23 100644 --- a/advisories/unreviewed/2022/05/GHSA-r82w-5vrw-9x74/GHSA-r82w-5vrw-9x74.json +++ b/advisories/unreviewed/2022/05/GHSA-r82w-5vrw-9x74/GHSA-r82w-5vrw-9x74.json @@ -7,12 +7,8 @@ "CVE-2009-0321" ], "details": "Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r88f-pqmx-v4jx/GHSA-r88f-pqmx-v4jx.json b/advisories/unreviewed/2022/05/GHSA-r88f-pqmx-v4jx/GHSA-r88f-pqmx-v4jx.json index 9f077f8913b..3e81a36bd7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r88f-pqmx-v4jx/GHSA-r88f-pqmx-v4jx.json +++ b/advisories/unreviewed/2022/05/GHSA-r88f-pqmx-v4jx/GHSA-r88f-pqmx-v4jx.json @@ -7,12 +7,8 @@ "CVE-2009-0808" ], "details": "Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8p2-rgr4-pvv5/GHSA-r8p2-rgr4-pvv5.json b/advisories/unreviewed/2022/05/GHSA-r8p2-rgr4-pvv5/GHSA-r8p2-rgr4-pvv5.json index a267fd685e0..fa3ffcb839e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8p2-rgr4-pvv5/GHSA-r8p2-rgr4-pvv5.json +++ b/advisories/unreviewed/2022/05/GHSA-r8p2-rgr4-pvv5/GHSA-r8p2-rgr4-pvv5.json @@ -7,12 +7,8 @@ "CVE-2009-0331" ], "details": "Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. NOTE: the vulnerability may be in my little homepage Comment script. If so, then this should not be treated as a vulnerability in ESPG.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json b/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json index 4ff058eaae1..3c20a50585c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json +++ b/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json @@ -7,12 +7,8 @@ "CVE-2009-0554" ], "details": "Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc77-w9xr-6vvf/GHSA-rc77-w9xr-6vvf.json b/advisories/unreviewed/2022/05/GHSA-rc77-w9xr-6vvf/GHSA-rc77-w9xr-6vvf.json index 18d5a9fada2..772abff3117 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc77-w9xr-6vvf/GHSA-rc77-w9xr-6vvf.json +++ b/advisories/unreviewed/2022/05/GHSA-rc77-w9xr-6vvf/GHSA-rc77-w9xr-6vvf.json @@ -7,12 +7,8 @@ "CVE-2009-0362" ], "details": "filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcc4-xh8r-mf9w/GHSA-rcc4-xh8r-mf9w.json b/advisories/unreviewed/2022/05/GHSA-rcc4-xh8r-mf9w/GHSA-rcc4-xh8r-mf9w.json index d3f0991370b..50efd354d58 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcc4-xh8r-mf9w/GHSA-rcc4-xh8r-mf9w.json +++ b/advisories/unreviewed/2022/05/GHSA-rcc4-xh8r-mf9w/GHSA-rcc4-xh8r-mf9w.json @@ -7,12 +7,8 @@ "CVE-2009-0784" ], "details": "Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcf3-vv2f-fwg2/GHSA-rcf3-vv2f-fwg2.json b/advisories/unreviewed/2022/05/GHSA-rcf3-vv2f-fwg2/GHSA-rcf3-vv2f-fwg2.json index 9a7b9f1751e..a76439a4974 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcf3-vv2f-fwg2/GHSA-rcf3-vv2f-fwg2.json +++ b/advisories/unreviewed/2022/05/GHSA-rcf3-vv2f-fwg2/GHSA-rcf3-vv2f-fwg2.json @@ -7,12 +7,8 @@ "CVE-2009-0361" ], "details": "Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcq7-x45j-38jc/GHSA-rcq7-x45j-38jc.json b/advisories/unreviewed/2022/05/GHSA-rcq7-x45j-38jc/GHSA-rcq7-x45j-38jc.json index 4c24c3a7da0..068f2ad3469 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcq7-x45j-38jc/GHSA-rcq7-x45j-38jc.json +++ b/advisories/unreviewed/2022/05/GHSA-rcq7-x45j-38jc/GHSA-rcq7-x45j-38jc.json @@ -7,12 +7,8 @@ "CVE-2009-0383" ], "details": "delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rffq-q3v2-pw4q/GHSA-rffq-q3v2-pw4q.json b/advisories/unreviewed/2022/05/GHSA-rffq-q3v2-pw4q/GHSA-rffq-q3v2-pw4q.json index b239d3893b5..ff8b50b086b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rffq-q3v2-pw4q/GHSA-rffq-q3v2-pw4q.json +++ b/advisories/unreviewed/2022/05/GHSA-rffq-q3v2-pw4q/GHSA-rffq-q3v2-pw4q.json @@ -7,12 +7,8 @@ "CVE-2009-0364" ], "details": "Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfwr-vfr5-h8m9/GHSA-rfwr-vfr5-h8m9.json b/advisories/unreviewed/2022/05/GHSA-rfwr-vfr5-h8m9/GHSA-rfwr-vfr5-h8m9.json index 3da1c0993dd..9b524e967e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfwr-vfr5-h8m9/GHSA-rfwr-vfr5-h8m9.json +++ b/advisories/unreviewed/2022/05/GHSA-rfwr-vfr5-h8m9/GHSA-rfwr-vfr5-h8m9.json @@ -7,12 +7,8 @@ "CVE-2009-0672" ], "details": "SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary SQL commands via the user_prefix parameter to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg4c-g979-gc45/GHSA-rg4c-g979-gc45.json b/advisories/unreviewed/2022/05/GHSA-rg4c-g979-gc45/GHSA-rg4c-g979-gc45.json index e4799eacab8..3d2deeefb6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg4c-g979-gc45/GHSA-rg4c-g979-gc45.json +++ b/advisories/unreviewed/2022/05/GHSA-rg4c-g979-gc45/GHSA-rg4c-g979-gc45.json @@ -7,12 +7,8 @@ "CVE-2009-0886" ], "details": "Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg6c-jj5w-9pgp/GHSA-rg6c-jj5w-9pgp.json b/advisories/unreviewed/2022/05/GHSA-rg6c-jj5w-9pgp/GHSA-rg6c-jj5w-9pgp.json index 726182df2bf..f6e13089168 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg6c-jj5w-9pgp/GHSA-rg6c-jj5w-9pgp.json +++ b/advisories/unreviewed/2022/05/GHSA-rg6c-jj5w-9pgp/GHSA-rg6c-jj5w-9pgp.json @@ -7,12 +7,8 @@ "CVE-2009-0402" ], "details": "SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute arbitrary SQL commands via the (1) familyname, (2) christname, (3) company_name, (4) is_company, (5) email, (6) phone, (7) fax, (8) addr1, (9) addr2, (10) addr3, (11) zipcode, (12) city, (13) state, (14) country, and (15) vat_num parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgh3-gqjf-4mqv/GHSA-rgh3-gqjf-4mqv.json b/advisories/unreviewed/2022/05/GHSA-rgh3-gqjf-4mqv/GHSA-rgh3-gqjf-4mqv.json index 6693a2f7a88..8640e1bdc5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgh3-gqjf-4mqv/GHSA-rgh3-gqjf-4mqv.json +++ b/advisories/unreviewed/2022/05/GHSA-rgh3-gqjf-4mqv/GHSA-rgh3-gqjf-4mqv.json @@ -7,12 +7,8 @@ "CVE-2009-0775" ], "details": "Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via \"cloned XUL DOM elements which were linked as a parent and child,\" which are not properly handled during garbage collection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rgh6-3fpr-9grp/GHSA-rgh6-3fpr-9grp.json b/advisories/unreviewed/2022/05/GHSA-rgh6-3fpr-9grp/GHSA-rgh6-3fpr-9grp.json index 0fb31250dc2..c6777d39811 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgh6-3fpr-9grp/GHSA-rgh6-3fpr-9grp.json +++ b/advisories/unreviewed/2022/05/GHSA-rgh6-3fpr-9grp/GHSA-rgh6-3fpr-9grp.json @@ -7,12 +7,8 @@ "CVE-2009-0411" ], "details": "Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rgrg-gqmp-ch3r/GHSA-rgrg-gqmp-ch3r.json b/advisories/unreviewed/2022/05/GHSA-rgrg-gqmp-ch3r/GHSA-rgrg-gqmp-ch3r.json index b56b040f8c6..99e238c449f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgrg-gqmp-ch3r/GHSA-rgrg-gqmp-ch3r.json +++ b/advisories/unreviewed/2022/05/GHSA-rgrg-gqmp-ch3r/GHSA-rgrg-gqmp-ch3r.json @@ -7,12 +7,8 @@ "CVE-2009-0709" ], "details": "SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhm5-jg35-jp78/GHSA-rhm5-jg35-jp78.json b/advisories/unreviewed/2022/05/GHSA-rhm5-jg35-jp78/GHSA-rhm5-jg35-jp78.json index cb0ee7da9da..40b58323c18 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhm5-jg35-jp78/GHSA-rhm5-jg35-jp78.json +++ b/advisories/unreviewed/2022/05/GHSA-rhm5-jg35-jp78/GHSA-rhm5-jg35-jp78.json @@ -7,12 +7,8 @@ "CVE-2009-0288" ], "details": "Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhw7-2gj6-g7rw/GHSA-rhw7-2gj6-g7rw.json b/advisories/unreviewed/2022/05/GHSA-rhw7-2gj6-g7rw/GHSA-rhw7-2gj6-g7rw.json index 19ed78e74f3..a03ebd2f296 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhw7-2gj6-g7rw/GHSA-rhw7-2gj6-g7rw.json +++ b/advisories/unreviewed/2022/05/GHSA-rhw7-2gj6-g7rw/GHSA-rhw7-2gj6-g7rw.json @@ -7,12 +7,8 @@ "CVE-2009-0546" ], "details": "Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj7r-4vm6-xprx/GHSA-rj7r-4vm6-xprx.json b/advisories/unreviewed/2022/05/GHSA-rj7r-4vm6-xprx/GHSA-rj7r-4vm6-xprx.json index c18b680e675..494308719ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj7r-4vm6-xprx/GHSA-rj7r-4vm6-xprx.json +++ b/advisories/unreviewed/2022/05/GHSA-rj7r-4vm6-xprx/GHSA-rj7r-4vm6-xprx.json @@ -7,12 +7,8 @@ "CVE-2009-0996" ], "details": "Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjc8-j2rv-vwfj/GHSA-rjc8-j2rv-vwfj.json b/advisories/unreviewed/2022/05/GHSA-rjc8-j2rv-vwfj/GHSA-rjc8-j2rv-vwfj.json index dd4c48e3b28..587ec54b964 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjc8-j2rv-vwfj/GHSA-rjc8-j2rv-vwfj.json +++ b/advisories/unreviewed/2022/05/GHSA-rjc8-j2rv-vwfj/GHSA-rjc8-j2rv-vwfj.json @@ -7,12 +7,8 @@ "CVE-2009-0699" ], "details": "Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjcc-fp5m-hj73/GHSA-rjcc-fp5m-hj73.json b/advisories/unreviewed/2022/05/GHSA-rjcc-fp5m-hj73/GHSA-rjcc-fp5m-hj73.json index f1facc8e985..ea442762119 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjcc-fp5m-hj73/GHSA-rjcc-fp5m-hj73.json +++ b/advisories/unreviewed/2022/05/GHSA-rjcc-fp5m-hj73/GHSA-rjcc-fp5m-hj73.json @@ -7,12 +7,8 @@ "CVE-2009-0090" ], "details": "Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka \"Microsoft .NET Framework Pointer Verification Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjqp-cxwg-rwxv/GHSA-rjqp-cxwg-rwxv.json b/advisories/unreviewed/2022/05/GHSA-rjqp-cxwg-rwxv/GHSA-rjqp-cxwg-rwxv.json index 0d15e161313..23519e8ade8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjqp-cxwg-rwxv/GHSA-rjqp-cxwg-rwxv.json +++ b/advisories/unreviewed/2022/05/GHSA-rjqp-cxwg-rwxv/GHSA-rjqp-cxwg-rwxv.json @@ -7,12 +7,8 @@ "CVE-2009-0899" ], "details": "IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq9h-6m6h-p32x/GHSA-rq9h-6m6h-p32x.json b/advisories/unreviewed/2022/05/GHSA-rq9h-6m6h-p32x/GHSA-rq9h-6m6h-p32x.json index b1850582c01..395996d0cb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq9h-6m6h-p32x/GHSA-rq9h-6m6h-p32x.json +++ b/advisories/unreviewed/2022/05/GHSA-rq9h-6m6h-p32x/GHSA-rq9h-6m6h-p32x.json @@ -7,12 +7,8 @@ "CVE-2009-0776" ], "details": "nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv2x-rg9m-9qj8/GHSA-rv2x-rg9m-9qj8.json b/advisories/unreviewed/2022/05/GHSA-rv2x-rg9m-9qj8/GHSA-rv2x-rg9m-9qj8.json index 8b38c789214..141e42838de 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv2x-rg9m-9qj8/GHSA-rv2x-rg9m-9qj8.json +++ b/advisories/unreviewed/2022/05/GHSA-rv2x-rg9m-9qj8/GHSA-rv2x-rg9m-9qj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv5q-992m-3p7h/GHSA-rv5q-992m-3p7h.json b/advisories/unreviewed/2022/05/GHSA-rv5q-992m-3p7h/GHSA-rv5q-992m-3p7h.json index 488808a0bb7..a8aa6a087aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv5q-992m-3p7h/GHSA-rv5q-992m-3p7h.json +++ b/advisories/unreviewed/2022/05/GHSA-rv5q-992m-3p7h/GHSA-rv5q-992m-3p7h.json @@ -7,12 +7,8 @@ "CVE-2009-0706" ], "details": "SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvg6-xg72-xc4w/GHSA-rvg6-xg72-xc4w.json b/advisories/unreviewed/2022/05/GHSA-rvg6-xg72-xc4w/GHSA-rvg6-xg72-xc4w.json index 5cca2d7aef1..6c18e320d90 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvg6-xg72-xc4w/GHSA-rvg6-xg72-xc4w.json +++ b/advisories/unreviewed/2022/05/GHSA-rvg6-xg72-xc4w/GHSA-rvg6-xg72-xc4w.json @@ -7,12 +7,8 @@ "CVE-2009-0343" ], "details": "Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rw9c-7x74-gmc7/GHSA-rw9c-7x74-gmc7.json b/advisories/unreviewed/2022/05/GHSA-rw9c-7x74-gmc7/GHSA-rw9c-7x74-gmc7.json index fa7d27fcc83..ab58fc0fc9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw9c-7x74-gmc7/GHSA-rw9c-7x74-gmc7.json +++ b/advisories/unreviewed/2022/05/GHSA-rw9c-7x74-gmc7/GHSA-rw9c-7x74-gmc7.json @@ -7,12 +7,8 @@ "CVE-2009-0814" ], "details": "Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwmg-r3c4-c2mr/GHSA-rwmg-r3c4-c2mr.json b/advisories/unreviewed/2022/05/GHSA-rwmg-r3c4-c2mr/GHSA-rwmg-r3c4-c2mr.json index c35f9e90cb5..d22d77b0c1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwmg-r3c4-c2mr/GHSA-rwmg-r3c4-c2mr.json +++ b/advisories/unreviewed/2022/05/GHSA-rwmg-r3c4-c2mr/GHSA-rwmg-r3c4-c2mr.json @@ -7,12 +7,8 @@ "CVE-2009-0534" ], "details": "SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v25f-45fp-wvrq/GHSA-v25f-45fp-wvrq.json b/advisories/unreviewed/2022/05/GHSA-v25f-45fp-wvrq/GHSA-v25f-45fp-wvrq.json index 2d4f6be37a4..f4d4c9c11b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v25f-45fp-wvrq/GHSA-v25f-45fp-wvrq.json +++ b/advisories/unreviewed/2022/05/GHSA-v25f-45fp-wvrq/GHSA-v25f-45fp-wvrq.json @@ -7,12 +7,8 @@ "CVE-2009-0387" ], "details": "Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to \"mark keyframes.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2jf-wqm3-34g8/GHSA-v2jf-wqm3-34g8.json b/advisories/unreviewed/2022/05/GHSA-v2jf-wqm3-34g8/GHSA-v2jf-wqm3-34g8.json index 898493aeed1..3fc93b8b908 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2jf-wqm3-34g8/GHSA-v2jf-wqm3-34g8.json +++ b/advisories/unreviewed/2022/05/GHSA-v2jf-wqm3-34g8/GHSA-v2jf-wqm3-34g8.json @@ -7,12 +7,8 @@ "CVE-2009-0345" ], "details": "Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6648082, a different vulnerability than CVE-2007-5717.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v44g-p4wf-wh36/GHSA-v44g-p4wf-wh36.json b/advisories/unreviewed/2022/05/GHSA-v44g-p4wf-wh36/GHSA-v44g-p4wf-wh36.json index 2790bc4b737..98669aeacf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v44g-p4wf-wh36/GHSA-v44g-p4wf-wh36.json +++ b/advisories/unreviewed/2022/05/GHSA-v44g-p4wf-wh36/GHSA-v44g-p4wf-wh36.json @@ -7,12 +7,8 @@ "CVE-2009-0871" ], "details": "The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v494-p56g-qm3c/GHSA-v494-p56g-qm3c.json b/advisories/unreviewed/2022/05/GHSA-v494-p56g-qm3c/GHSA-v494-p56g-qm3c.json index b7e7583a208..e62f2d0ae36 100644 --- a/advisories/unreviewed/2022/05/GHSA-v494-p56g-qm3c/GHSA-v494-p56g-qm3c.json +++ b/advisories/unreviewed/2022/05/GHSA-v494-p56g-qm3c/GHSA-v494-p56g-qm3c.json @@ -7,12 +7,8 @@ "CVE-2009-0679" ], "details": "Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v52c-rjhj-v6hm/GHSA-v52c-rjhj-v6hm.json b/advisories/unreviewed/2022/05/GHSA-v52c-rjhj-v6hm/GHSA-v52c-rjhj-v6hm.json index 62178c4af3a..414b1c27706 100644 --- a/advisories/unreviewed/2022/05/GHSA-v52c-rjhj-v6hm/GHSA-v52c-rjhj-v6hm.json +++ b/advisories/unreviewed/2022/05/GHSA-v52c-rjhj-v6hm/GHSA-v52c-rjhj-v6hm.json @@ -7,12 +7,8 @@ "CVE-2009-0500" ], "details": "Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6m9-gggv-wxxh/GHSA-v6m9-gggv-wxxh.json b/advisories/unreviewed/2022/05/GHSA-v6m9-gggv-wxxh/GHSA-v6m9-gggv-wxxh.json index f1d9e0f56ae..fa62f8c3870 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6m9-gggv-wxxh/GHSA-v6m9-gggv-wxxh.json +++ b/advisories/unreviewed/2022/05/GHSA-v6m9-gggv-wxxh/GHSA-v6m9-gggv-wxxh.json @@ -7,12 +7,8 @@ "CVE-2009-0809" ], "details": "The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v76x-pjw5-9f7q/GHSA-v76x-pjw5-9f7q.json b/advisories/unreviewed/2022/05/GHSA-v76x-pjw5-9f7q/GHSA-v76x-pjw5-9f7q.json index 131cf26127b..df287b5dd3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v76x-pjw5-9f7q/GHSA-v76x-pjw5-9f7q.json +++ b/advisories/unreviewed/2022/05/GHSA-v76x-pjw5-9f7q/GHSA-v76x-pjw5-9f7q.json @@ -7,12 +7,8 @@ "CVE-2009-0351" ], "details": "Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v973-q8fj-656q/GHSA-v973-q8fj-656q.json b/advisories/unreviewed/2022/05/GHSA-v973-q8fj-656q/GHSA-v973-q8fj-656q.json index 7e8f2164a76..32beaca58b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v973-q8fj-656q/GHSA-v973-q8fj-656q.json +++ b/advisories/unreviewed/2022/05/GHSA-v973-q8fj-656q/GHSA-v973-q8fj-656q.json @@ -7,12 +7,8 @@ "CVE-2009-0821" ], "details": "Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9pf-x8fm-7j69/GHSA-v9pf-x8fm-7j69.json b/advisories/unreviewed/2022/05/GHSA-v9pf-x8fm-7j69/GHSA-v9pf-x8fm-7j69.json index ce63166911a..2a1e7bbf045 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9pf-x8fm-7j69/GHSA-v9pf-x8fm-7j69.json +++ b/advisories/unreviewed/2022/05/GHSA-v9pf-x8fm-7j69/GHSA-v9pf-x8fm-7j69.json @@ -7,12 +7,8 @@ "CVE-2009-0934" ], "details": "Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg6j-84m6-m9vp/GHSA-vg6j-84m6-m9vp.json b/advisories/unreviewed/2022/05/GHSA-vg6j-84m6-m9vp/GHSA-vg6j-84m6-m9vp.json index 11a05456cbf..33380cd7c12 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg6j-84m6-m9vp/GHSA-vg6j-84m6-m9vp.json +++ b/advisories/unreviewed/2022/05/GHSA-vg6j-84m6-m9vp/GHSA-vg6j-84m6-m9vp.json @@ -7,12 +7,8 @@ "CVE-2009-0527" ], "details": "PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vgwx-7mjc-5w5g/GHSA-vgwx-7mjc-5w5g.json b/advisories/unreviewed/2022/05/GHSA-vgwx-7mjc-5w5g/GHSA-vgwx-7mjc-5w5g.json index 85de879f50d..8f8df86aed8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgwx-7mjc-5w5g/GHSA-vgwx-7mjc-5w5g.json +++ b/advisories/unreviewed/2022/05/GHSA-vgwx-7mjc-5w5g/GHSA-vgwx-7mjc-5w5g.json @@ -7,12 +7,8 @@ "CVE-2009-0647" ], "details": "msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh3c-x5gp-gq3w/GHSA-vh3c-x5gp-gq3w.json b/advisories/unreviewed/2022/05/GHSA-vh3c-x5gp-gq3w/GHSA-vh3c-x5gp-gq3w.json index ca93c5c857c..78a67cc7bdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh3c-x5gp-gq3w/GHSA-vh3c-x5gp-gq3w.json +++ b/advisories/unreviewed/2022/05/GHSA-vh3c-x5gp-gq3w/GHSA-vh3c-x5gp-gq3w.json @@ -7,12 +7,8 @@ "CVE-2009-0338" ], "details": "Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh8q-wmg6-w8v4/GHSA-vh8q-wmg6-w8v4.json b/advisories/unreviewed/2022/05/GHSA-vh8q-wmg6-w8v4/GHSA-vh8q-wmg6-w8v4.json index 7bcf4e144bf..27a46013ef4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh8q-wmg6-w8v4/GHSA-vh8q-wmg6-w8v4.json +++ b/advisories/unreviewed/2022/05/GHSA-vh8q-wmg6-w8v4/GHSA-vh8q-wmg6-w8v4.json @@ -7,12 +7,8 @@ "CVE-2009-0802" ], "details": "Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vhv4-mr2w-hc59/GHSA-vhv4-mr2w-hc59.json b/advisories/unreviewed/2022/05/GHSA-vhv4-mr2w-hc59/GHSA-vhv4-mr2w-hc59.json index cd9eceef522..f9c65308c9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhv4-mr2w-hc59/GHSA-vhv4-mr2w-hc59.json +++ b/advisories/unreviewed/2022/05/GHSA-vhv4-mr2w-hc59/GHSA-vhv4-mr2w-hc59.json @@ -7,12 +7,8 @@ "CVE-2009-0735" ], "details": "Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the pfadhier parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjj6-55w4-4x57/GHSA-vjj6-55w4-4x57.json b/advisories/unreviewed/2022/05/GHSA-vjj6-55w4-4x57/GHSA-vjj6-55w4-4x57.json index 094a40491c2..59ada3fca13 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjj6-55w4-4x57/GHSA-vjj6-55w4-4x57.json +++ b/advisories/unreviewed/2022/05/GHSA-vjj6-55w4-4x57/GHSA-vjj6-55w4-4x57.json @@ -7,12 +7,8 @@ "CVE-2009-1005" ], "details": "Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Product Suite 10.3.0, 3.2, 3.0.1, and 3.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpxw-jphr-pjhp/GHSA-vpxw-jphr-pjhp.json b/advisories/unreviewed/2022/05/GHSA-vpxw-jphr-pjhp/GHSA-vpxw-jphr-pjhp.json index 70ab3627ad8..dd8462e87b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpxw-jphr-pjhp/GHSA-vpxw-jphr-pjhp.json +++ b/advisories/unreviewed/2022/05/GHSA-vpxw-jphr-pjhp/GHSA-vpxw-jphr-pjhp.json @@ -7,12 +7,8 @@ "CVE-2009-1041" ], "details": "The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq8r-2vvq-cr5h/GHSA-vq8r-2vvq-cr5h.json b/advisories/unreviewed/2022/05/GHSA-vq8r-2vvq-cr5h/GHSA-vq8r-2vvq-cr5h.json index da3f617aa0c..a427eab636f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq8r-2vvq-cr5h/GHSA-vq8r-2vvq-cr5h.json +++ b/advisories/unreviewed/2022/05/GHSA-vq8r-2vvq-cr5h/GHSA-vq8r-2vvq-cr5h.json @@ -7,12 +7,8 @@ "CVE-2009-0908" ], "details": "Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vqv6-r48r-39m7/GHSA-vqv6-r48r-39m7.json b/advisories/unreviewed/2022/05/GHSA-vqv6-r48r-39m7/GHSA-vqv6-r48r-39m7.json index b5c7e3849ce..014321f5db4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqv6-r48r-39m7/GHSA-vqv6-r48r-39m7.json +++ b/advisories/unreviewed/2022/05/GHSA-vqv6-r48r-39m7/GHSA-vqv6-r48r-39m7.json @@ -7,12 +7,8 @@ "CVE-2009-0993" ], "details": "Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that allows remote attackers to execute arbitrary code via format string specifiers in an HTTP POST URI, which are not properly handled when logging to opmn/logs/opmn.log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vr9h-mqv2-4p47/GHSA-vr9h-mqv2-4p47.json b/advisories/unreviewed/2022/05/GHSA-vr9h-mqv2-4p47/GHSA-vr9h-mqv2-4p47.json index 32ba82b9311..0e6d4ec7908 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr9h-mqv2-4p47/GHSA-vr9h-mqv2-4p47.json +++ b/advisories/unreviewed/2022/05/GHSA-vr9h-mqv2-4p47/GHSA-vr9h-mqv2-4p47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrc7-xp75-mp3c/GHSA-vrc7-xp75-mp3c.json b/advisories/unreviewed/2022/05/GHSA-vrc7-xp75-mp3c/GHSA-vrc7-xp75-mp3c.json index 0e1d7ff46ae..14cb260dc8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrc7-xp75-mp3c/GHSA-vrc7-xp75-mp3c.json +++ b/advisories/unreviewed/2022/05/GHSA-vrc7-xp75-mp3c/GHSA-vrc7-xp75-mp3c.json @@ -7,12 +7,8 @@ "CVE-2009-0565" ], "details": "Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a malformed record that triggers memory corruption, aka \"Word Buffer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrfj-4vq5-9448/GHSA-vrfj-4vq5-9448.json b/advisories/unreviewed/2022/05/GHSA-vrfj-4vq5-9448/GHSA-vrfj-4vq5-9448.json index 71d13ab0754..68a346ff6cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrfj-4vq5-9448/GHSA-vrfj-4vq5-9448.json +++ b/advisories/unreviewed/2022/05/GHSA-vrfj-4vq5-9448/GHSA-vrfj-4vq5-9448.json @@ -7,12 +7,8 @@ "CVE-2009-0506" ], "details": "Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwm5-4pv2-47qx/GHSA-vwm5-4pv2-47qx.json b/advisories/unreviewed/2022/05/GHSA-vwm5-4pv2-47qx/GHSA-vwm5-4pv2-47qx.json index 6b91e5f54a2..5b2d7f5940f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwm5-4pv2-47qx/GHSA-vwm5-4pv2-47qx.json +++ b/advisories/unreviewed/2022/05/GHSA-vwm5-4pv2-47qx/GHSA-vwm5-4pv2-47qx.json @@ -7,12 +7,8 @@ "CVE-2009-0559" ], "details": "Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"String Copy Stack-Based Overrun Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx9q-r464-6v8x/GHSA-vx9q-r464-6v8x.json b/advisories/unreviewed/2022/05/GHSA-vx9q-r464-6v8x/GHSA-vx9q-r464-6v8x.json index f3ef6d9a647..09f121a1fb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx9q-r464-6v8x/GHSA-vx9q-r464-6v8x.json +++ b/advisories/unreviewed/2022/05/GHSA-vx9q-r464-6v8x/GHSA-vx9q-r464-6v8x.json @@ -7,12 +7,8 @@ "CVE-2009-0767" ], "details": "Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w25f-3mhv-pm3v/GHSA-w25f-3mhv-pm3v.json b/advisories/unreviewed/2022/05/GHSA-w25f-3mhv-pm3v/GHSA-w25f-3mhv-pm3v.json index 910f80d8c3b..10266cd7182 100644 --- a/advisories/unreviewed/2022/05/GHSA-w25f-3mhv-pm3v/GHSA-w25f-3mhv-pm3v.json +++ b/advisories/unreviewed/2022/05/GHSA-w25f-3mhv-pm3v/GHSA-w25f-3mhv-pm3v.json @@ -7,12 +7,8 @@ "CVE-2009-0621" ], "details": "Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device management, which makes it easier for remote attackers to perform configuration changes to the Device Manager and other components, or obtain operating-system access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w25v-2mf8-86hr/GHSA-w25v-2mf8-86hr.json b/advisories/unreviewed/2022/05/GHSA-w25v-2mf8-86hr/GHSA-w25v-2mf8-86hr.json index 55d883c0c61..30639e57227 100644 --- a/advisories/unreviewed/2022/05/GHSA-w25v-2mf8-86hr/GHSA-w25v-2mf8-86hr.json +++ b/advisories/unreviewed/2022/05/GHSA-w25v-2mf8-86hr/GHSA-w25v-2mf8-86hr.json @@ -7,12 +7,8 @@ "CVE-2009-0556" ], "details": "Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka \"Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3ph-grj2-mw52/GHSA-w3ph-grj2-mw52.json b/advisories/unreviewed/2022/05/GHSA-w3ph-grj2-mw52/GHSA-w3ph-grj2-mw52.json index 922e4af9bcf..5720995c4ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3ph-grj2-mw52/GHSA-w3ph-grj2-mw52.json +++ b/advisories/unreviewed/2022/05/GHSA-w3ph-grj2-mw52/GHSA-w3ph-grj2-mw52.json @@ -7,12 +7,8 @@ "CVE-2009-0667" ], "details": "Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4g7-v9f4-grmg/GHSA-w4g7-v9f4-grmg.json b/advisories/unreviewed/2022/05/GHSA-w4g7-v9f4-grmg/GHSA-w4g7-v9f4-grmg.json index cd2cd8d3656..d694568c54c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4g7-v9f4-grmg/GHSA-w4g7-v9f4-grmg.json +++ b/advisories/unreviewed/2022/05/GHSA-w4g7-v9f4-grmg/GHSA-w4g7-v9f4-grmg.json @@ -7,12 +7,8 @@ "CVE-2009-0213" ], "details": "Unspecified vulnerability in the NETIO application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32021.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w69g-qpc5-9834/GHSA-w69g-qpc5-9834.json b/advisories/unreviewed/2022/05/GHSA-w69g-qpc5-9834/GHSA-w69g-qpc5-9834.json index cca7e85b9eb..f4967dbaa78 100644 --- a/advisories/unreviewed/2022/05/GHSA-w69g-qpc5-9834/GHSA-w69g-qpc5-9834.json +++ b/advisories/unreviewed/2022/05/GHSA-w69g-qpc5-9834/GHSA-w69g-qpc5-9834.json @@ -7,12 +7,8 @@ "CVE-2009-0095" ], "details": "Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka \"Memory Validation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w87g-c2c7-4fx5/GHSA-w87g-c2c7-4fx5.json b/advisories/unreviewed/2022/05/GHSA-w87g-c2c7-4fx5/GHSA-w87g-c2c7-4fx5.json index 1716a0cfb75..614552f3743 100644 --- a/advisories/unreviewed/2022/05/GHSA-w87g-c2c7-4fx5/GHSA-w87g-c2c7-4fx5.json +++ b/advisories/unreviewed/2022/05/GHSA-w87g-c2c7-4fx5/GHSA-w87g-c2c7-4fx5.json @@ -7,12 +7,8 @@ "CVE-2009-0801" ], "details": "Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8h6-6x8h-3fj6/GHSA-w8h6-6x8h-3fj6.json b/advisories/unreviewed/2022/05/GHSA-w8h6-6x8h-3fj6/GHSA-w8h6-6x8h-3fj6.json index 3181ff91c88..c2b08b44058 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8h6-6x8h-3fj6/GHSA-w8h6-6x8h-3fj6.json +++ b/advisories/unreviewed/2022/05/GHSA-w8h6-6x8h-3fj6/GHSA-w8h6-6x8h-3fj6.json @@ -7,12 +7,8 @@ "CVE-2009-0099" ], "details": "The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka \"Literal Processing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9fp-w8cr-vgpg/GHSA-w9fp-w8cr-vgpg.json b/advisories/unreviewed/2022/05/GHSA-w9fp-w8cr-vgpg/GHSA-w9fp-w8cr-vgpg.json index 2f81fadd517..14a89789453 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9fp-w8cr-vgpg/GHSA-w9fp-w8cr-vgpg.json +++ b/advisories/unreviewed/2022/05/GHSA-w9fp-w8cr-vgpg/GHSA-w9fp-w8cr-vgpg.json @@ -7,12 +7,8 @@ "CVE-2009-0544" ], "details": "Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9qv-f37g-g59w/GHSA-w9qv-f37g-g59w.json b/advisories/unreviewed/2022/05/GHSA-w9qv-f37g-g59w/GHSA-w9qv-f37g-g59w.json index d61fdef539f..beeabd61d15 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9qv-f37g-g59w/GHSA-w9qv-f37g-g59w.json +++ b/advisories/unreviewed/2022/05/GHSA-w9qv-f37g-g59w/GHSA-w9qv-f37g-g59w.json @@ -7,12 +7,8 @@ "CVE-2009-0593" ], "details": "SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9wh-8xxf-539c/GHSA-w9wh-8xxf-539c.json b/advisories/unreviewed/2022/05/GHSA-w9wh-8xxf-539c/GHSA-w9wh-8xxf-539c.json index 650ecf0058d..f1667562481 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9wh-8xxf-539c/GHSA-w9wh-8xxf-539c.json +++ b/advisories/unreviewed/2022/05/GHSA-w9wh-8xxf-539c/GHSA-w9wh-8xxf-539c.json @@ -7,12 +7,8 @@ "CVE-2009-0548" ], "details": "Cross-site scripting (XSS) vulnerability in the Additional Report Settings interface in ESET Remote Administrator before 3.0.105 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfhh-24j3-j9j7/GHSA-wfhh-24j3-j9j7.json b/advisories/unreviewed/2022/05/GHSA-wfhh-24j3-j9j7/GHSA-wfhh-24j3-j9j7.json index 598d11f49fc..7d04d8f123a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfhh-24j3-j9j7/GHSA-wfhh-24j3-j9j7.json +++ b/advisories/unreviewed/2022/05/GHSA-wfhh-24j3-j9j7/GHSA-wfhh-24j3-j9j7.json @@ -7,12 +7,8 @@ "CVE-2009-0644" ], "details": "The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it easier for remote attackers to obtain privileged access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfpj-872h-h97h/GHSA-wfpj-872h-h97h.json b/advisories/unreviewed/2022/05/GHSA-wfpj-872h-h97h/GHSA-wfpj-872h-h97h.json index d25e4f1cb0b..573609ef746 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfpj-872h-h97h/GHSA-wfpj-872h-h97h.json +++ b/advisories/unreviewed/2022/05/GHSA-wfpj-872h-h97h/GHSA-wfpj-872h-h97h.json @@ -7,12 +7,8 @@ "CVE-2009-0310" ], "details": "Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to \"incoming data and authentication-strings.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg4w-r6g5-ch43/GHSA-wg4w-r6g5-ch43.json b/advisories/unreviewed/2022/05/GHSA-wg4w-r6g5-ch43/GHSA-wg4w-r6g5-ch43.json index 8f5c98cf161..59ca00ce6af 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg4w-r6g5-ch43/GHSA-wg4w-r6g5-ch43.json +++ b/advisories/unreviewed/2022/05/GHSA-wg4w-r6g5-ch43/GHSA-wg4w-r6g5-ch43.json @@ -7,12 +7,8 @@ "CVE-2009-0805" ], "details": "Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a module for XOOPS, allows remote attackers to inject arbitrary web script or HTML via the event_id parameter in index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgrv-9pmx-9m2f/GHSA-wgrv-9pmx-9m2f.json b/advisories/unreviewed/2022/05/GHSA-wgrv-9pmx-9m2f/GHSA-wgrv-9pmx-9m2f.json index 08994054554..0c53adae918 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgrv-9pmx-9m2f/GHSA-wgrv-9pmx-9m2f.json +++ b/advisories/unreviewed/2022/05/GHSA-wgrv-9pmx-9m2f/GHSA-wgrv-9pmx-9m2f.json @@ -7,12 +7,8 @@ "CVE-2009-0208" ], "details": "Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgx8-9q2v-2mgc/GHSA-wgx8-9q2v-2mgc.json b/advisories/unreviewed/2022/05/GHSA-wgx8-9q2v-2mgc/GHSA-wgx8-9q2v-2mgc.json index 95acb5da6a0..92f3534e229 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgx8-9q2v-2mgc/GHSA-wgx8-9q2v-2mgc.json +++ b/advisories/unreviewed/2022/05/GHSA-wgx8-9q2v-2mgc/GHSA-wgx8-9q2v-2mgc.json @@ -7,12 +7,8 @@ "CVE-2009-0634" ], "details": "Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via an ICMP packet, aka Bug ID CSCso05337.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whhp-65p4-rw8g/GHSA-whhp-65p4-rw8g.json b/advisories/unreviewed/2022/05/GHSA-whhp-65p4-rw8g/GHSA-whhp-65p4-rw8g.json index 9a2387181e3..0b921d4f030 100644 --- a/advisories/unreviewed/2022/05/GHSA-whhp-65p4-rw8g/GHSA-whhp-65p4-rw8g.json +++ b/advisories/unreviewed/2022/05/GHSA-whhp-65p4-rw8g/GHSA-whhp-65p4-rw8g.json @@ -7,12 +7,8 @@ "CVE-2009-0799" ], "details": "The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whp8-h58w-r9jr/GHSA-whp8-h58w-r9jr.json b/advisories/unreviewed/2022/05/GHSA-whp8-h58w-r9jr/GHSA-whp8-h58w-r9jr.json index bf66b3fe3c9..2a1d0781dc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-whp8-h58w-r9jr/GHSA-whp8-h58w-r9jr.json +++ b/advisories/unreviewed/2022/05/GHSA-whp8-h58w-r9jr/GHSA-whp8-h58w-r9jr.json @@ -7,12 +7,8 @@ "CVE-2009-0523" ], "details": "Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpr5-pr7m-mmcw/GHSA-wpr5-pr7m-mmcw.json b/advisories/unreviewed/2022/05/GHSA-wpr5-pr7m-mmcw/GHSA-wpr5-pr7m-mmcw.json index 664cf8cdb01..92eecc44fdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpr5-pr7m-mmcw/GHSA-wpr5-pr7m-mmcw.json +++ b/advisories/unreviewed/2022/05/GHSA-wpr5-pr7m-mmcw/GHSA-wpr5-pr7m-mmcw.json @@ -7,12 +7,8 @@ "CVE-2009-0831" ], "details": "SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqvp-33cw-jgjc/GHSA-wqvp-33cw-jgjc.json b/advisories/unreviewed/2022/05/GHSA-wqvp-33cw-jgjc/GHSA-wqvp-33cw-jgjc.json index 2c75ca6eadc..3cfb44e8145 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqvp-33cw-jgjc/GHSA-wqvp-33cw-jgjc.json +++ b/advisories/unreviewed/2022/05/GHSA-wqvp-33cw-jgjc/GHSA-wqvp-33cw-jgjc.json @@ -7,12 +7,8 @@ "CVE-2009-0350" ], "details": "Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqx4-27xw-wwjw/GHSA-wqx4-27xw-wwjw.json b/advisories/unreviewed/2022/05/GHSA-wqx4-27xw-wwjw/GHSA-wqx4-27xw-wwjw.json index f98b4f663b8..305b8516f92 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqx4-27xw-wwjw/GHSA-wqx4-27xw-wwjw.json +++ b/advisories/unreviewed/2022/05/GHSA-wqx4-27xw-wwjw/GHSA-wqx4-27xw-wwjw.json @@ -7,12 +7,8 @@ "CVE-2009-0877" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express allow remote attackers to inject arbitrary web script or HTML via the (1) Full Name or (2) Subject field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr6h-vrp6-vq67/GHSA-wr6h-vrp6-vq67.json b/advisories/unreviewed/2022/05/GHSA-wr6h-vrp6-vq67/GHSA-wr6h-vrp6-vq67.json index 3ca97e8304a..b644c1590a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr6h-vrp6-vq67/GHSA-wr6h-vrp6-vq67.json +++ b/advisories/unreviewed/2022/05/GHSA-wr6h-vrp6-vq67/GHSA-wr6h-vrp6-vq67.json @@ -7,12 +7,8 @@ "CVE-2009-0602" ], "details": "Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr9v-3qgm-q33g/GHSA-wr9v-3qgm-q33g.json b/advisories/unreviewed/2022/05/GHSA-wr9v-3qgm-q33g/GHSA-wr9v-3qgm-q33g.json index ca1f48a0673..ce1deaf97e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr9v-3qgm-q33g/GHSA-wr9v-3qgm-q33g.json +++ b/advisories/unreviewed/2022/05/GHSA-wr9v-3qgm-q33g/GHSA-wr9v-3qgm-q33g.json @@ -7,12 +7,8 @@ "CVE-2009-0927" ], "details": "Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrr7-c372-7gc7/GHSA-wrr7-c372-7gc7.json b/advisories/unreviewed/2022/05/GHSA-wrr7-c372-7gc7/GHSA-wrr7-c372-7gc7.json index 1caa50687cd..3edbbc6b0ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrr7-c372-7gc7/GHSA-wrr7-c372-7gc7.json +++ b/advisories/unreviewed/2022/05/GHSA-wrr7-c372-7gc7/GHSA-wrr7-c372-7gc7.json @@ -7,12 +7,8 @@ "CVE-2009-0606" ], "details": "The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to CVE-2002-0820.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvh6-xg9p-6jf7/GHSA-wvh6-xg9p-6jf7.json b/advisories/unreviewed/2022/05/GHSA-wvh6-xg9p-6jf7/GHSA-wvh6-xg9p-6jf7.json index 0874648e819..66155f38bd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvh6-xg9p-6jf7/GHSA-wvh6-xg9p-6jf7.json +++ b/advisories/unreviewed/2022/05/GHSA-wvh6-xg9p-6jf7/GHSA-wvh6-xg9p-6jf7.json @@ -7,12 +7,8 @@ "CVE-2009-0863" ], "details": "SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvqf-rrqc-53gr/GHSA-wvqf-rrqc-53gr.json b/advisories/unreviewed/2022/05/GHSA-wvqf-rrqc-53gr/GHSA-wvqf-rrqc-53gr.json index de9d9f977ec..cd195103e23 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvqf-rrqc-53gr/GHSA-wvqf-rrqc-53gr.json +++ b/advisories/unreviewed/2022/05/GHSA-wvqf-rrqc-53gr/GHSA-wvqf-rrqc-53gr.json @@ -7,12 +7,8 @@ "CVE-2009-0562" ], "details": "The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger \"system state\" corruption, aka \"Office Web Components Memory Allocation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvxj-557q-2v4v/GHSA-wvxj-557q-2v4v.json b/advisories/unreviewed/2022/05/GHSA-wvxj-557q-2v4v/GHSA-wvxj-557q-2v4v.json index c85902ae93c..bf75e7a14c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvxj-557q-2v4v/GHSA-wvxj-557q-2v4v.json +++ b/advisories/unreviewed/2022/05/GHSA-wvxj-557q-2v4v/GHSA-wvxj-557q-2v4v.json @@ -7,12 +7,8 @@ "CVE-2009-0514" ], "details": "Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxvr-h7g5-rfc7/GHSA-wxvr-h7g5-rfc7.json b/advisories/unreviewed/2022/05/GHSA-wxvr-h7g5-rfc7/GHSA-wxvr-h7g5-rfc7.json index df7b55bbf9f..be729143038 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxvr-h7g5-rfc7/GHSA-wxvr-h7g5-rfc7.json +++ b/advisories/unreviewed/2022/05/GHSA-wxvr-h7g5-rfc7/GHSA-wxvr-h7g5-rfc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x35x-2vjr-cm9p/GHSA-x35x-2vjr-cm9p.json b/advisories/unreviewed/2022/05/GHSA-x35x-2vjr-cm9p/GHSA-x35x-2vjr-cm9p.json index c2a4317b13a..a680d19bee1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x35x-2vjr-cm9p/GHSA-x35x-2vjr-cm9p.json +++ b/advisories/unreviewed/2022/05/GHSA-x35x-2vjr-cm9p/GHSA-x35x-2vjr-cm9p.json @@ -7,12 +7,8 @@ "CVE-2009-0332" ], "details": "Multiple SQL injection vulnerabilities in AV Book Library before 1.1 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/edit.php, (2) admin/add.php, (3) lib/book_search.php, and possibly other components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3v4-9m46-pvqg/GHSA-x3v4-9m46-pvqg.json b/advisories/unreviewed/2022/05/GHSA-x3v4-9m46-pvqg/GHSA-x3v4-9m46-pvqg.json index b0930c31341..b3a25ffc770 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3v4-9m46-pvqg/GHSA-x3v4-9m46-pvqg.json +++ b/advisories/unreviewed/2022/05/GHSA-x3v4-9m46-pvqg/GHSA-x3v4-9m46-pvqg.json @@ -7,12 +7,8 @@ "CVE-2009-0519" ], "details": "Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x433-429v-9473/GHSA-x433-429v-9473.json b/advisories/unreviewed/2022/05/GHSA-x433-429v-9473/GHSA-x433-429v-9473.json index 7f3ec5badbf..c22bd9314fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-x433-429v-9473/GHSA-x433-429v-9473.json +++ b/advisories/unreviewed/2022/05/GHSA-x433-429v-9473/GHSA-x433-429v-9473.json @@ -7,12 +7,8 @@ "CVE-2009-0316" ], "details": "Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x474-4899-v7hv/GHSA-x474-4899-v7hv.json b/advisories/unreviewed/2022/05/GHSA-x474-4899-v7hv/GHSA-x474-4899-v7hv.json index 2db532e3bee..ab7e1bea348 100644 --- a/advisories/unreviewed/2022/05/GHSA-x474-4899-v7hv/GHSA-x474-4899-v7hv.json +++ b/advisories/unreviewed/2022/05/GHSA-x474-4899-v7hv/GHSA-x474-4899-v7hv.json @@ -7,12 +7,8 @@ "CVE-2009-0375" ], "details": "Buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a filename length field containing a large integer, which triggers overwrite of an arbitrary memory location with a 0x00 byte value, related to use of RealPlayer through a Windows Explorer plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4h4-7v2v-mpwh/GHSA-x4h4-7v2v-mpwh.json b/advisories/unreviewed/2022/05/GHSA-x4h4-7v2v-mpwh/GHSA-x4h4-7v2v-mpwh.json index df3151c07d4..6a022464daa 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4h4-7v2v-mpwh/GHSA-x4h4-7v2v-mpwh.json +++ b/advisories/unreviewed/2022/05/GHSA-x4h4-7v2v-mpwh/GHSA-x4h4-7v2v-mpwh.json @@ -7,12 +7,8 @@ "CVE-2009-0826" ], "details": "BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4pm-92c9-5597/GHSA-x4pm-92c9-5597.json b/advisories/unreviewed/2022/05/GHSA-x4pm-92c9-5597/GHSA-x4pm-92c9-5597.json index 7a48a99deee..57d04959ecb 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4pm-92c9-5597/GHSA-x4pm-92c9-5597.json +++ b/advisories/unreviewed/2022/05/GHSA-x4pm-92c9-5597/GHSA-x4pm-92c9-5597.json @@ -7,12 +7,8 @@ "CVE-2009-0870" ], "details": "The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x574-mhvf-59h5/GHSA-x574-mhvf-59h5.json b/advisories/unreviewed/2022/05/GHSA-x574-mhvf-59h5/GHSA-x574-mhvf-59h5.json index a94cf3e6a50..7086333cb7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x574-mhvf-59h5/GHSA-x574-mhvf-59h5.json +++ b/advisories/unreviewed/2022/05/GHSA-x574-mhvf-59h5/GHSA-x574-mhvf-59h5.json @@ -7,12 +7,8 @@ "CVE-2009-0661" ], "details": "Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x59c-mx27-2m9h/GHSA-x59c-mx27-2m9h.json b/advisories/unreviewed/2022/05/GHSA-x59c-mx27-2m9h/GHSA-x59c-mx27-2m9h.json index a901cd8f5c1..8699c3616b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x59c-mx27-2m9h/GHSA-x59c-mx27-2m9h.json +++ b/advisories/unreviewed/2022/05/GHSA-x59c-mx27-2m9h/GHSA-x59c-mx27-2m9h.json @@ -7,12 +7,8 @@ "CVE-2009-0501" ], "details": "Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct \"brute force attacks on user accounts\" via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5gw-2qjg-7h6j/GHSA-x5gw-2qjg-7h6j.json b/advisories/unreviewed/2022/05/GHSA-x5gw-2qjg-7h6j/GHSA-x5gw-2qjg-7h6j.json index e81f8138d62..10e9666082d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5gw-2qjg-7h6j/GHSA-x5gw-2qjg-7h6j.json +++ b/advisories/unreviewed/2022/05/GHSA-x5gw-2qjg-7h6j/GHSA-x5gw-2qjg-7h6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6xf-5q35-j8vr/GHSA-x6xf-5q35-j8vr.json b/advisories/unreviewed/2022/05/GHSA-x6xf-5q35-j8vr/GHSA-x6xf-5q35-j8vr.json index e14059773b5..f1a2188546b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6xf-5q35-j8vr/GHSA-x6xf-5q35-j8vr.json +++ b/advisories/unreviewed/2022/05/GHSA-x6xf-5q35-j8vr/GHSA-x6xf-5q35-j8vr.json @@ -7,12 +7,8 @@ "CVE-2009-0629" ], "details": "The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over TCP (XOT), and (10) X.25 Routing features in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (device reload) via a series of crafted TCP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6xj-cmvp-3m3j/GHSA-x6xj-cmvp-3m3j.json b/advisories/unreviewed/2022/05/GHSA-x6xj-cmvp-3m3j/GHSA-x6xj-cmvp-3m3j.json index d8bdd89903e..fa4d044e6ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6xj-cmvp-3m3j/GHSA-x6xj-cmvp-3m3j.json +++ b/advisories/unreviewed/2022/05/GHSA-x6xj-cmvp-3m3j/GHSA-x6xj-cmvp-3m3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x75x-89gj-wfcm/GHSA-x75x-89gj-wfcm.json b/advisories/unreviewed/2022/05/GHSA-x75x-89gj-wfcm/GHSA-x75x-89gj-wfcm.json index e763b809b17..c7be618588f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x75x-89gj-wfcm/GHSA-x75x-89gj-wfcm.json +++ b/advisories/unreviewed/2022/05/GHSA-x75x-89gj-wfcm/GHSA-x75x-89gj-wfcm.json @@ -7,12 +7,8 @@ "CVE-2009-0835" ], "details": "The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -116,9 +112,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8q6-p6fc-wh5c/GHSA-x8q6-p6fc-wh5c.json b/advisories/unreviewed/2022/05/GHSA-x8q6-p6fc-wh5c/GHSA-x8q6-p6fc-wh5c.json index ebd26e8ccaa..3ec7192f403 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8q6-p6fc-wh5c/GHSA-x8q6-p6fc-wh5c.json +++ b/advisories/unreviewed/2022/05/GHSA-x8q6-p6fc-wh5c/GHSA-x8q6-p6fc-wh5c.json @@ -7,12 +7,8 @@ "CVE-2009-0728" ], "details": "SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc25-6376-965v/GHSA-xc25-6376-965v.json b/advisories/unreviewed/2022/05/GHSA-xc25-6376-965v/GHSA-xc25-6376-965v.json index 56772514c8f..146fff31f1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc25-6376-965v/GHSA-xc25-6376-965v.json +++ b/advisories/unreviewed/2022/05/GHSA-xc25-6376-965v/GHSA-xc25-6376-965v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcfx-wvq8-gmhg/GHSA-xcfx-wvq8-gmhg.json b/advisories/unreviewed/2022/05/GHSA-xcfx-wvq8-gmhg/GHSA-xcfx-wvq8-gmhg.json index 904ce8ce904..90c9a667614 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcfx-wvq8-gmhg/GHSA-xcfx-wvq8-gmhg.json +++ b/advisories/unreviewed/2022/05/GHSA-xcfx-wvq8-gmhg/GHSA-xcfx-wvq8-gmhg.json @@ -7,12 +7,8 @@ "CVE-2009-0645" ], "details": "Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcjm-r85p-mrq7/GHSA-xcjm-r85p-mrq7.json b/advisories/unreviewed/2022/05/GHSA-xcjm-r85p-mrq7/GHSA-xcjm-r85p-mrq7.json index ccac7e57ceb..f20c8f0f531 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcjm-r85p-mrq7/GHSA-xcjm-r85p-mrq7.json +++ b/advisories/unreviewed/2022/05/GHSA-xcjm-r85p-mrq7/GHSA-xcjm-r85p-mrq7.json @@ -7,12 +7,8 @@ "CVE-2009-0893" ], "details": "Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a \"missing resync marker range check\" and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf8f-c2h7-7qmc/GHSA-xf8f-c2h7-7qmc.json b/advisories/unreviewed/2022/05/GHSA-xf8f-c2h7-7qmc/GHSA-xf8f-c2h7-7qmc.json index 0b03fdcd1b2..682b30a7021 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf8f-c2h7-7qmc/GHSA-xf8f-c2h7-7qmc.json +++ b/advisories/unreviewed/2022/05/GHSA-xf8f-c2h7-7qmc/GHSA-xf8f-c2h7-7qmc.json @@ -7,12 +7,8 @@ "CVE-2009-0790" ], "details": "The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgfh-24vj-5m9m/GHSA-xgfh-24vj-5m9m.json b/advisories/unreviewed/2022/05/GHSA-xgfh-24vj-5m9m/GHSA-xgfh-24vj-5m9m.json index bab06b48cb5..fafd6c8f969 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgfh-24vj-5m9m/GHSA-xgfh-24vj-5m9m.json +++ b/advisories/unreviewed/2022/05/GHSA-xgfh-24vj-5m9m/GHSA-xgfh-24vj-5m9m.json @@ -7,12 +7,8 @@ "CVE-2009-0529" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgpw-5ww4-gfq7/GHSA-xgpw-5ww4-gfq7.json b/advisories/unreviewed/2022/05/GHSA-xgpw-5ww4-gfq7/GHSA-xgpw-5ww4-gfq7.json index 44919c9d233..456213ba4cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgpw-5ww4-gfq7/GHSA-xgpw-5ww4-gfq7.json +++ b/advisories/unreviewed/2022/05/GHSA-xgpw-5ww4-gfq7/GHSA-xgpw-5ww4-gfq7.json @@ -7,12 +7,8 @@ "CVE-2009-0838" ], "details": "The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xgq6-cgqf-jpp9/GHSA-xgq6-cgqf-jpp9.json b/advisories/unreviewed/2022/05/GHSA-xgq6-cgqf-jpp9/GHSA-xgq6-cgqf-jpp9.json index 178f96dafbe..027b60167fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgq6-cgqf-jpp9/GHSA-xgq6-cgqf-jpp9.json +++ b/advisories/unreviewed/2022/05/GHSA-xgq6-cgqf-jpp9/GHSA-xgq6-cgqf-jpp9.json @@ -7,12 +7,8 @@ "CVE-2009-0550" ], "details": "Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remote web servers to capture and replay NTLM credentials, and execute arbitrary code, via vectors related to absence of a \"credential-reflection protections\" opt-in step, aka \"Windows HTTP Services Credential Reflection Vulnerability\" and \"WinINet Credential Reflection Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xhf5-wgpx-m22c/GHSA-xhf5-wgpx-m22c.json b/advisories/unreviewed/2022/05/GHSA-xhf5-wgpx-m22c/GHSA-xhf5-wgpx-m22c.json index fbfaf9e6637..0b9af6fe857 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhf5-wgpx-m22c/GHSA-xhf5-wgpx-m22c.json +++ b/advisories/unreviewed/2022/05/GHSA-xhf5-wgpx-m22c/GHSA-xhf5-wgpx-m22c.json @@ -7,12 +7,8 @@ "CVE-2009-0372" ], "details": "Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj4f-h5gm-5gh9/GHSA-xj4f-h5gm-5gh9.json b/advisories/unreviewed/2022/05/GHSA-xj4f-h5gm-5gh9/GHSA-xj4f-h5gm-5gh9.json index 3e78c460579..3196e2e8fa3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj4f-h5gm-5gh9/GHSA-xj4f-h5gm-5gh9.json +++ b/advisories/unreviewed/2022/05/GHSA-xj4f-h5gm-5gh9/GHSA-xj4f-h5gm-5gh9.json @@ -7,12 +7,8 @@ "CVE-2009-0624" ], "details": "Unspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv1 packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjpq-q5j9-jvwc/GHSA-xjpq-q5j9-jvwc.json b/advisories/unreviewed/2022/05/GHSA-xjpq-q5j9-jvwc/GHSA-xjpq-q5j9-jvwc.json index b8f7768f73f..bf191b7bf28 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjpq-q5j9-jvwc/GHSA-xjpq-q5j9-jvwc.json +++ b/advisories/unreviewed/2022/05/GHSA-xjpq-q5j9-jvwc/GHSA-xjpq-q5j9-jvwc.json @@ -7,12 +7,8 @@ "CVE-2009-0536" ], "details": "at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjqg-mw9v-vpv9/GHSA-xjqg-mw9v-vpv9.json b/advisories/unreviewed/2022/05/GHSA-xjqg-mw9v-vpv9/GHSA-xjqg-mw9v-vpv9.json index 463385e6a58..c0381bb49f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjqg-mw9v-vpv9/GHSA-xjqg-mw9v-vpv9.json +++ b/advisories/unreviewed/2022/05/GHSA-xjqg-mw9v-vpv9/GHSA-xjqg-mw9v-vpv9.json @@ -7,12 +7,8 @@ "CVE-2009-0396" ], "details": "The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2) UDP port 2948.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmr3-m6h9-383p/GHSA-xmr3-m6h9-383p.json b/advisories/unreviewed/2022/05/GHSA-xmr3-m6h9-383p/GHSA-xmr3-m6h9-383p.json index 653087c48af..51c5855e1bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmr3-m6h9-383p/GHSA-xmr3-m6h9-383p.json +++ b/advisories/unreviewed/2022/05/GHSA-xmr3-m6h9-383p/GHSA-xmr3-m6h9-383p.json @@ -7,12 +7,8 @@ "CVE-2009-0353" ], "details": "Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xp5q-j3fq-3qw3/GHSA-xp5q-j3fq-3qw3.json b/advisories/unreviewed/2022/05/GHSA-xp5q-j3fq-3qw3/GHSA-xp5q-j3fq-3qw3.json index b8218a195ed..ab8ca1da7bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp5q-j3fq-3qw3/GHSA-xp5q-j3fq-3qw3.json +++ b/advisories/unreviewed/2022/05/GHSA-xp5q-j3fq-3qw3/GHSA-xp5q-j3fq-3qw3.json @@ -7,12 +7,8 @@ "CVE-2009-0836" ], "details": "Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the \"Open/Execute a file\" action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp6v-2px2-m727/GHSA-xp6v-2px2-m727.json b/advisories/unreviewed/2022/05/GHSA-xp6v-2px2-m727/GHSA-xp6v-2px2-m727.json index c9133bbdfbc..3acd6a055d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp6v-2px2-m727/GHSA-xp6v-2px2-m727.json +++ b/advisories/unreviewed/2022/05/GHSA-xp6v-2px2-m727/GHSA-xp6v-2px2-m727.json @@ -7,12 +7,8 @@ "CVE-2009-0552" ], "details": "Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xprq-37ch-7r6g/GHSA-xprq-37ch-7r6g.json b/advisories/unreviewed/2022/05/GHSA-xprq-37ch-7r6g/GHSA-xprq-37ch-7r6g.json index f1fe7d28671..6e7a5518d65 100644 --- a/advisories/unreviewed/2022/05/GHSA-xprq-37ch-7r6g/GHSA-xprq-37ch-7r6g.json +++ b/advisories/unreviewed/2022/05/GHSA-xprq-37ch-7r6g/GHSA-xprq-37ch-7r6g.json @@ -7,12 +7,8 @@ "CVE-2009-0727" ], "details": "SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xprr-83m2-vv8v/GHSA-xprr-83m2-vv8v.json b/advisories/unreviewed/2022/05/GHSA-xprr-83m2-vv8v/GHSA-xprr-83m2-vv8v.json index 9941ad77f1c..fc088d4baeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xprr-83m2-vv8v/GHSA-xprr-83m2-vv8v.json +++ b/advisories/unreviewed/2022/05/GHSA-xprr-83m2-vv8v/GHSA-xprr-83m2-vv8v.json @@ -7,12 +7,8 @@ "CVE-2009-0357" ], "details": "Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xv7x-qjw2-9399/GHSA-xv7x-qjw2-9399.json b/advisories/unreviewed/2022/05/GHSA-xv7x-qjw2-9399/GHSA-xv7x-qjw2-9399.json index bdaefd59ebf..3f2813daf32 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv7x-qjw2-9399/GHSA-xv7x-qjw2-9399.json +++ b/advisories/unreviewed/2022/05/GHSA-xv7x-qjw2-9399/GHSA-xv7x-qjw2-9399.json @@ -7,12 +7,8 @@ "CVE-2009-0768" ], "details": "SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv87-mrpm-wc53/GHSA-xv87-mrpm-wc53.json b/advisories/unreviewed/2022/05/GHSA-xv87-mrpm-wc53/GHSA-xv87-mrpm-wc53.json index 9faf7bfff4b..724547c46cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv87-mrpm-wc53/GHSA-xv87-mrpm-wc53.json +++ b/advisories/unreviewed/2022/05/GHSA-xv87-mrpm-wc53/GHSA-xv87-mrpm-wc53.json @@ -7,12 +7,8 @@ "CVE-2012-5306" ], "details": "Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvg2-wrv6-8v46/GHSA-xvg2-wrv6-8v46.json b/advisories/unreviewed/2022/05/GHSA-xvg2-wrv6-8v46/GHSA-xvg2-wrv6-8v46.json index a0c42830f2f..d97a3c9f4d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvg2-wrv6-8v46/GHSA-xvg2-wrv6-8v46.json +++ b/advisories/unreviewed/2022/05/GHSA-xvg2-wrv6-8v46/GHSA-xvg2-wrv6-8v46.json @@ -7,12 +7,8 @@ "CVE-2009-0574" ], "details": "SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xx89-xmcq-2q77/GHSA-xx89-xmcq-2q77.json b/advisories/unreviewed/2022/05/GHSA-xx89-xmcq-2q77/GHSA-xx89-xmcq-2q77.json index 2967b163c9f..4ba63a8ae7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx89-xmcq-2q77/GHSA-xx89-xmcq-2q77.json +++ b/advisories/unreviewed/2022/05/GHSA-xx89-xmcq-2q77/GHSA-xx89-xmcq-2q77.json @@ -7,12 +7,8 @@ "CVE-2009-0897" ], "details": "IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the \"schema DB2 instance id\" and the bcgarchive (aka the archiver script).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxw3-m93w-7c72/GHSA-xxw3-m93w-7c72.json b/advisories/unreviewed/2022/05/GHSA-xxw3-m93w-7c72/GHSA-xxw3-m93w-7c72.json index b4f7bc0415e..4fb388b5065 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxw3-m93w-7c72/GHSA-xxw3-m93w-7c72.json +++ b/advisories/unreviewed/2022/05/GHSA-xxw3-m93w-7c72/GHSA-xxw3-m93w-7c72.json @@ -7,12 +7,8 @@ "CVE-2009-0866" ], "details": "pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for extra/genbackup.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-pg89-46xq-98vv/GHSA-pg89-46xq-98vv.json b/advisories/unreviewed/2022/08/GHSA-pg89-46xq-98vv/GHSA-pg89-46xq-98vv.json index 48d812a61af..26d8c80caa3 100644 --- a/advisories/unreviewed/2022/08/GHSA-pg89-46xq-98vv/GHSA-pg89-46xq-98vv.json +++ b/advisories/unreviewed/2022/08/GHSA-pg89-46xq-98vv/GHSA-pg89-46xq-98vv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-48c6-w667-vv6w/GHSA-48c6-w667-vv6w.json b/advisories/unreviewed/2022/09/GHSA-48c6-w667-vv6w/GHSA-48c6-w667-vv6w.json index 2cb85c8ad7d..1283f4c55ae 100644 --- a/advisories/unreviewed/2022/09/GHSA-48c6-w667-vv6w/GHSA-48c6-w667-vv6w.json +++ b/advisories/unreviewed/2022/09/GHSA-48c6-w667-vv6w/GHSA-48c6-w667-vv6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-5gmm-5672-7w8f/GHSA-5gmm-5672-7w8f.json b/advisories/unreviewed/2022/09/GHSA-5gmm-5672-7w8f/GHSA-5gmm-5672-7w8f.json index b0963a5d3ff..ebcdab1e9cb 100644 --- a/advisories/unreviewed/2022/09/GHSA-5gmm-5672-7w8f/GHSA-5gmm-5672-7w8f.json +++ b/advisories/unreviewed/2022/09/GHSA-5gmm-5672-7w8f/GHSA-5gmm-5672-7w8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-5gmq-7hwh-fxj9/GHSA-5gmq-7hwh-fxj9.json b/advisories/unreviewed/2022/09/GHSA-5gmq-7hwh-fxj9/GHSA-5gmq-7hwh-fxj9.json index a347a4a1da0..74512837a1b 100644 --- a/advisories/unreviewed/2022/09/GHSA-5gmq-7hwh-fxj9/GHSA-5gmq-7hwh-fxj9.json +++ b/advisories/unreviewed/2022/09/GHSA-5gmq-7hwh-fxj9/GHSA-5gmq-7hwh-fxj9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-8mff-48jp-39q5/GHSA-8mff-48jp-39q5.json b/advisories/unreviewed/2022/09/GHSA-8mff-48jp-39q5/GHSA-8mff-48jp-39q5.json index b46a29dee05..2a10105451b 100644 --- a/advisories/unreviewed/2022/09/GHSA-8mff-48jp-39q5/GHSA-8mff-48jp-39q5.json +++ b/advisories/unreviewed/2022/09/GHSA-8mff-48jp-39q5/GHSA-8mff-48jp-39q5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-px4g-wqmp-7rhq/GHSA-px4g-wqmp-7rhq.json b/advisories/unreviewed/2022/09/GHSA-px4g-wqmp-7rhq/GHSA-px4g-wqmp-7rhq.json index 60ed2f1f7ce..81ba1f8bcd0 100644 --- a/advisories/unreviewed/2022/09/GHSA-px4g-wqmp-7rhq/GHSA-px4g-wqmp-7rhq.json +++ b/advisories/unreviewed/2022/09/GHSA-px4g-wqmp-7rhq/GHSA-px4g-wqmp-7rhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-2crw-c3p5-4j2g/GHSA-2crw-c3p5-4j2g.json b/advisories/unreviewed/2022/10/GHSA-2crw-c3p5-4j2g/GHSA-2crw-c3p5-4j2g.json index 204803cb654..bdadc7d1cf3 100644 --- a/advisories/unreviewed/2022/10/GHSA-2crw-c3p5-4j2g/GHSA-2crw-c3p5-4j2g.json +++ b/advisories/unreviewed/2022/10/GHSA-2crw-c3p5-4j2g/GHSA-2crw-c3p5-4j2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json b/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json index 32d4f381e6a..d3fb45e9d45 100644 --- a/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json +++ b/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json b/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json index efb260244db..7cdc9d970ad 100644 --- a/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json +++ b/advisories/unreviewed/2022/10/GHSA-2v7r-pp26-r79c/GHSA-2v7r-pp26-r79c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json b/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json index a00092b8043..039ad608832 100644 --- a/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json +++ b/advisories/unreviewed/2022/10/GHSA-32f7-x79r-fq9w/GHSA-32f7-x79r-fq9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-34pj-rwf2-r7x2/GHSA-34pj-rwf2-r7x2.json b/advisories/unreviewed/2022/10/GHSA-34pj-rwf2-r7x2/GHSA-34pj-rwf2-r7x2.json index 3c7c4be1a98..fbe54c147e6 100644 --- a/advisories/unreviewed/2022/10/GHSA-34pj-rwf2-r7x2/GHSA-34pj-rwf2-r7x2.json +++ b/advisories/unreviewed/2022/10/GHSA-34pj-rwf2-r7x2/GHSA-34pj-rwf2-r7x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json b/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json index e80b5b045b5..c65d04fa3e3 100644 --- a/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json +++ b/advisories/unreviewed/2022/10/GHSA-4f2h-772x-5h66/GHSA-4f2h-772x-5h66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-5c25-wqmw-998w/GHSA-5c25-wqmw-998w.json b/advisories/unreviewed/2022/10/GHSA-5c25-wqmw-998w/GHSA-5c25-wqmw-998w.json index 95a8eae4bdf..e29aa6bbaab 100644 --- a/advisories/unreviewed/2022/10/GHSA-5c25-wqmw-998w/GHSA-5c25-wqmw-998w.json +++ b/advisories/unreviewed/2022/10/GHSA-5c25-wqmw-998w/GHSA-5c25-wqmw-998w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-5mj6-f6jx-93g9/GHSA-5mj6-f6jx-93g9.json b/advisories/unreviewed/2022/10/GHSA-5mj6-f6jx-93g9/GHSA-5mj6-f6jx-93g9.json index bbc1a42d1c3..8c1d06b2246 100644 --- a/advisories/unreviewed/2022/10/GHSA-5mj6-f6jx-93g9/GHSA-5mj6-f6jx-93g9.json +++ b/advisories/unreviewed/2022/10/GHSA-5mj6-f6jx-93g9/GHSA-5mj6-f6jx-93g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-65jr-gjjg-957c/GHSA-65jr-gjjg-957c.json b/advisories/unreviewed/2022/10/GHSA-65jr-gjjg-957c/GHSA-65jr-gjjg-957c.json index ff9b51e5d5d..524ec819a92 100644 --- a/advisories/unreviewed/2022/10/GHSA-65jr-gjjg-957c/GHSA-65jr-gjjg-957c.json +++ b/advisories/unreviewed/2022/10/GHSA-65jr-gjjg-957c/GHSA-65jr-gjjg-957c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json b/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json index 0cd7261e8e7..389e9994404 100644 --- a/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json +++ b/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json b/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json index c07094f8c5f..84865d5b8f8 100644 --- a/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json +++ b/advisories/unreviewed/2022/10/GHSA-662p-8mx9-xvc4/GHSA-662p-8mx9-xvc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-66g9-p6q6-rqc4/GHSA-66g9-p6q6-rqc4.json b/advisories/unreviewed/2022/10/GHSA-66g9-p6q6-rqc4/GHSA-66g9-p6q6-rqc4.json index bd42e2b7c2a..0febb3c088d 100644 --- a/advisories/unreviewed/2022/10/GHSA-66g9-p6q6-rqc4/GHSA-66g9-p6q6-rqc4.json +++ b/advisories/unreviewed/2022/10/GHSA-66g9-p6q6-rqc4/GHSA-66g9-p6q6-rqc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json b/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json index 2d8ecdb5d4f..3bafa21e1a5 100644 --- a/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json +++ b/advisories/unreviewed/2022/10/GHSA-6q82-84qc-99r9/GHSA-6q82-84qc-99r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json b/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json index 9f49a40e547..be61a470642 100644 --- a/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json +++ b/advisories/unreviewed/2022/10/GHSA-6xc3-9629-w8h2/GHSA-6xc3-9629-w8h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-72mc-vm7f-x4q8/GHSA-72mc-vm7f-x4q8.json b/advisories/unreviewed/2022/10/GHSA-72mc-vm7f-x4q8/GHSA-72mc-vm7f-x4q8.json index 2967b57be82..8840c1d5ffa 100644 --- a/advisories/unreviewed/2022/10/GHSA-72mc-vm7f-x4q8/GHSA-72mc-vm7f-x4q8.json +++ b/advisories/unreviewed/2022/10/GHSA-72mc-vm7f-x4q8/GHSA-72mc-vm7f-x4q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json b/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json index de9834b1d5e..b547e0936c4 100644 --- a/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json +++ b/advisories/unreviewed/2022/10/GHSA-7443-rx53-4v58/GHSA-7443-rx53-4v58.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-7995-p757-mmj4/GHSA-7995-p757-mmj4.json b/advisories/unreviewed/2022/10/GHSA-7995-p757-mmj4/GHSA-7995-p757-mmj4.json index 04cb0dabee3..f05085a0cde 100644 --- a/advisories/unreviewed/2022/10/GHSA-7995-p757-mmj4/GHSA-7995-p757-mmj4.json +++ b/advisories/unreviewed/2022/10/GHSA-7995-p757-mmj4/GHSA-7995-p757-mmj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json b/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json index d10509cbc4e..93949e0deb9 100644 --- a/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json +++ b/advisories/unreviewed/2022/10/GHSA-8hxv-4x2j-cj7g/GHSA-8hxv-4x2j-cj7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-c26j-p8cc-7337/GHSA-c26j-p8cc-7337.json b/advisories/unreviewed/2022/10/GHSA-c26j-p8cc-7337/GHSA-c26j-p8cc-7337.json index ab624849416..1356ea9d81a 100644 --- a/advisories/unreviewed/2022/10/GHSA-c26j-p8cc-7337/GHSA-c26j-p8cc-7337.json +++ b/advisories/unreviewed/2022/10/GHSA-c26j-p8cc-7337/GHSA-c26j-p8cc-7337.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-c4m9-5h6p-hwwg/GHSA-c4m9-5h6p-hwwg.json b/advisories/unreviewed/2022/10/GHSA-c4m9-5h6p-hwwg/GHSA-c4m9-5h6p-hwwg.json index 7d920ec0f69..9c3838dbafd 100644 --- a/advisories/unreviewed/2022/10/GHSA-c4m9-5h6p-hwwg/GHSA-c4m9-5h6p-hwwg.json +++ b/advisories/unreviewed/2022/10/GHSA-c4m9-5h6p-hwwg/GHSA-c4m9-5h6p-hwwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-cfr4-7372-927c/GHSA-cfr4-7372-927c.json b/advisories/unreviewed/2022/10/GHSA-cfr4-7372-927c/GHSA-cfr4-7372-927c.json index d8d060470a1..30d0a7f7c32 100644 --- a/advisories/unreviewed/2022/10/GHSA-cfr4-7372-927c/GHSA-cfr4-7372-927c.json +++ b/advisories/unreviewed/2022/10/GHSA-cfr4-7372-927c/GHSA-cfr4-7372-927c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-cp6r-jg55-7qfj/GHSA-cp6r-jg55-7qfj.json b/advisories/unreviewed/2022/10/GHSA-cp6r-jg55-7qfj/GHSA-cp6r-jg55-7qfj.json index edcd0ab4ad8..6b844b0db47 100644 --- a/advisories/unreviewed/2022/10/GHSA-cp6r-jg55-7qfj/GHSA-cp6r-jg55-7qfj.json +++ b/advisories/unreviewed/2022/10/GHSA-cp6r-jg55-7qfj/GHSA-cp6r-jg55-7qfj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json b/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json index f967285b90f..83146721b16 100644 --- a/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json +++ b/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-f656-9j3j-ff9j/GHSA-f656-9j3j-ff9j.json b/advisories/unreviewed/2022/10/GHSA-f656-9j3j-ff9j/GHSA-f656-9j3j-ff9j.json index d6df395e90b..912fe5d87bc 100644 --- a/advisories/unreviewed/2022/10/GHSA-f656-9j3j-ff9j/GHSA-f656-9j3j-ff9j.json +++ b/advisories/unreviewed/2022/10/GHSA-f656-9j3j-ff9j/GHSA-f656-9j3j-ff9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json b/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json index 1461539c07f..e2190d91abe 100644 --- a/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json +++ b/advisories/unreviewed/2022/10/GHSA-fh77-7rc7-3797/GHSA-fh77-7rc7-3797.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json b/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json index f3ceabf7d81..1a607850b0b 100644 --- a/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json +++ b/advisories/unreviewed/2022/10/GHSA-fwrg-4qc6-4q9c/GHSA-fwrg-4qc6-4q9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json b/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json index 64a9cb9e567..d1c0d67b9ae 100644 --- a/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json +++ b/advisories/unreviewed/2022/10/GHSA-g2xr-62jm-9q24/GHSA-g2xr-62jm-9q24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-h6fv-6hh7-gvc6/GHSA-h6fv-6hh7-gvc6.json b/advisories/unreviewed/2022/10/GHSA-h6fv-6hh7-gvc6/GHSA-h6fv-6hh7-gvc6.json index fdf284cc072..3e756bda4b7 100644 --- a/advisories/unreviewed/2022/10/GHSA-h6fv-6hh7-gvc6/GHSA-h6fv-6hh7-gvc6.json +++ b/advisories/unreviewed/2022/10/GHSA-h6fv-6hh7-gvc6/GHSA-h6fv-6hh7-gvc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json b/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json index 7e18c482df6..c69b01137ea 100644 --- a/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json +++ b/advisories/unreviewed/2022/10/GHSA-hc6j-mmwg-vmww/GHSA-hc6j-mmwg-vmww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-hj7m-4fjj-fp55/GHSA-hj7m-4fjj-fp55.json b/advisories/unreviewed/2022/10/GHSA-hj7m-4fjj-fp55/GHSA-hj7m-4fjj-fp55.json index a012258065e..e4dafda4fd5 100644 --- a/advisories/unreviewed/2022/10/GHSA-hj7m-4fjj-fp55/GHSA-hj7m-4fjj-fp55.json +++ b/advisories/unreviewed/2022/10/GHSA-hj7m-4fjj-fp55/GHSA-hj7m-4fjj-fp55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-hw79-279g-555h/GHSA-hw79-279g-555h.json b/advisories/unreviewed/2022/10/GHSA-hw79-279g-555h/GHSA-hw79-279g-555h.json index abf7d35389a..912bb127623 100644 --- a/advisories/unreviewed/2022/10/GHSA-hw79-279g-555h/GHSA-hw79-279g-555h.json +++ b/advisories/unreviewed/2022/10/GHSA-hw79-279g-555h/GHSA-hw79-279g-555h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-j43q-9x66-wv6c/GHSA-j43q-9x66-wv6c.json b/advisories/unreviewed/2022/10/GHSA-j43q-9x66-wv6c/GHSA-j43q-9x66-wv6c.json index 401fdcfacae..7e67b872fab 100644 --- a/advisories/unreviewed/2022/10/GHSA-j43q-9x66-wv6c/GHSA-j43q-9x66-wv6c.json +++ b/advisories/unreviewed/2022/10/GHSA-j43q-9x66-wv6c/GHSA-j43q-9x66-wv6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-j5xh-7x7x-vvpj/GHSA-j5xh-7x7x-vvpj.json b/advisories/unreviewed/2022/10/GHSA-j5xh-7x7x-vvpj/GHSA-j5xh-7x7x-vvpj.json index 4a541ab39e4..e9fc53f389b 100644 --- a/advisories/unreviewed/2022/10/GHSA-j5xh-7x7x-vvpj/GHSA-j5xh-7x7x-vvpj.json +++ b/advisories/unreviewed/2022/10/GHSA-j5xh-7x7x-vvpj/GHSA-j5xh-7x7x-vvpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-j97j-vxwq-j8q5/GHSA-j97j-vxwq-j8q5.json b/advisories/unreviewed/2022/10/GHSA-j97j-vxwq-j8q5/GHSA-j97j-vxwq-j8q5.json index b4100c8ad43..4c31fdb9262 100644 --- a/advisories/unreviewed/2022/10/GHSA-j97j-vxwq-j8q5/GHSA-j97j-vxwq-j8q5.json +++ b/advisories/unreviewed/2022/10/GHSA-j97j-vxwq-j8q5/GHSA-j97j-vxwq-j8q5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jc6m-p2qm-xj5h/GHSA-jc6m-p2qm-xj5h.json b/advisories/unreviewed/2022/10/GHSA-jc6m-p2qm-xj5h/GHSA-jc6m-p2qm-xj5h.json index fb91079e7ef..0ab4dfa3bed 100644 --- a/advisories/unreviewed/2022/10/GHSA-jc6m-p2qm-xj5h/GHSA-jc6m-p2qm-xj5h.json +++ b/advisories/unreviewed/2022/10/GHSA-jc6m-p2qm-xj5h/GHSA-jc6m-p2qm-xj5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json b/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json index b4123028658..b02d3086bbc 100644 --- a/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json +++ b/advisories/unreviewed/2022/10/GHSA-jcg7-m437-6g35/GHSA-jcg7-m437-6g35.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json b/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json index f8942220f86..59e1b5ed1c0 100644 --- a/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json +++ b/advisories/unreviewed/2022/10/GHSA-jpcv-6q9f-58c6/GHSA-jpcv-6q9f-58c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json b/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json index 265d28cbfec..d6716ebebc6 100644 --- a/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json +++ b/advisories/unreviewed/2022/10/GHSA-m824-p6mx-3cw8/GHSA-m824-p6mx-3cw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json b/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json index 8470206bfe9..99437364675 100644 --- a/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json +++ b/advisories/unreviewed/2022/10/GHSA-m8qv-r68j-xjrq/GHSA-m8qv-r68j-xjrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-mp6v-6f6f-cw72/GHSA-mp6v-6f6f-cw72.json b/advisories/unreviewed/2022/10/GHSA-mp6v-6f6f-cw72/GHSA-mp6v-6f6f-cw72.json index 94d79f94723..c954e76d7ae 100644 --- a/advisories/unreviewed/2022/10/GHSA-mp6v-6f6f-cw72/GHSA-mp6v-6f6f-cw72.json +++ b/advisories/unreviewed/2022/10/GHSA-mp6v-6f6f-cw72/GHSA-mp6v-6f6f-cw72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json b/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json index 2aa96cd4758..f651055345c 100644 --- a/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json +++ b/advisories/unreviewed/2022/10/GHSA-phx5-p62q-ppqc/GHSA-phx5-p62q-ppqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-pqgf-fq7r-x6mq/GHSA-pqgf-fq7r-x6mq.json b/advisories/unreviewed/2022/10/GHSA-pqgf-fq7r-x6mq/GHSA-pqgf-fq7r-x6mq.json index 24dec614aaf..c578eabca66 100644 --- a/advisories/unreviewed/2022/10/GHSA-pqgf-fq7r-x6mq/GHSA-pqgf-fq7r-x6mq.json +++ b/advisories/unreviewed/2022/10/GHSA-pqgf-fq7r-x6mq/GHSA-pqgf-fq7r-x6mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json b/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json index 1edc4e5d595..3c4ef678e92 100644 --- a/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json +++ b/advisories/unreviewed/2022/10/GHSA-px7v-2mmh-wrwf/GHSA-px7v-2mmh-wrwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-q279-7v5j-3mv3/GHSA-q279-7v5j-3mv3.json b/advisories/unreviewed/2022/10/GHSA-q279-7v5j-3mv3/GHSA-q279-7v5j-3mv3.json index 1ef439416fd..45e8f24c411 100644 --- a/advisories/unreviewed/2022/10/GHSA-q279-7v5j-3mv3/GHSA-q279-7v5j-3mv3.json +++ b/advisories/unreviewed/2022/10/GHSA-q279-7v5j-3mv3/GHSA-q279-7v5j-3mv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json b/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json index d93972664bb..d55a9e2cb67 100644 --- a/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json +++ b/advisories/unreviewed/2022/10/GHSA-q36q-v436-3mgq/GHSA-q36q-v436-3mgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json b/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json index 8eb3e9c6721..cbf261ee542 100644 --- a/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json +++ b/advisories/unreviewed/2022/10/GHSA-q83g-rwc4-phpc/GHSA-q83g-rwc4-phpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json b/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json index 8098d4f244c..e91fd2f1d2f 100644 --- a/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json +++ b/advisories/unreviewed/2022/10/GHSA-qm62-5pc4-c833/GHSA-qm62-5pc4-c833.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-rh44-7w5q-mcqg/GHSA-rh44-7w5q-mcqg.json b/advisories/unreviewed/2022/10/GHSA-rh44-7w5q-mcqg/GHSA-rh44-7w5q-mcqg.json index 700aa74a1d3..acf00d9594d 100644 --- a/advisories/unreviewed/2022/10/GHSA-rh44-7w5q-mcqg/GHSA-rh44-7w5q-mcqg.json +++ b/advisories/unreviewed/2022/10/GHSA-rh44-7w5q-mcqg/GHSA-rh44-7w5q-mcqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-rjp6-whc2-47rm/GHSA-rjp6-whc2-47rm.json b/advisories/unreviewed/2022/10/GHSA-rjp6-whc2-47rm/GHSA-rjp6-whc2-47rm.json index fdd820e1b0c..b6413515764 100644 --- a/advisories/unreviewed/2022/10/GHSA-rjp6-whc2-47rm/GHSA-rjp6-whc2-47rm.json +++ b/advisories/unreviewed/2022/10/GHSA-rjp6-whc2-47rm/GHSA-rjp6-whc2-47rm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-vg29-gv35-r399/GHSA-vg29-gv35-r399.json b/advisories/unreviewed/2022/10/GHSA-vg29-gv35-r399/GHSA-vg29-gv35-r399.json index 23227386893..230867125be 100644 --- a/advisories/unreviewed/2022/10/GHSA-vg29-gv35-r399/GHSA-vg29-gv35-r399.json +++ b/advisories/unreviewed/2022/10/GHSA-vg29-gv35-r399/GHSA-vg29-gv35-r399.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json b/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json index 4a4fa4c4bde..2bd93dce253 100644 --- a/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json +++ b/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json b/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json index 02f586dfb2c..f7a8a050f87 100644 --- a/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json +++ b/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-w6wp-gc59-837q/GHSA-w6wp-gc59-837q.json b/advisories/unreviewed/2022/10/GHSA-w6wp-gc59-837q/GHSA-w6wp-gc59-837q.json index 2cbaca58431..a8fd8f0675c 100644 --- a/advisories/unreviewed/2022/10/GHSA-w6wp-gc59-837q/GHSA-w6wp-gc59-837q.json +++ b/advisories/unreviewed/2022/10/GHSA-w6wp-gc59-837q/GHSA-w6wp-gc59-837q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json b/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json index 37d2dc7cc32..8cfe5cdec31 100644 --- a/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json +++ b/advisories/unreviewed/2022/10/GHSA-w789-m2hg-5x2h/GHSA-w789-m2hg-5x2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json b/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json index 45d613146d6..49e3045f321 100644 --- a/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json +++ b/advisories/unreviewed/2022/10/GHSA-w7mc-j82q-7jh2/GHSA-w7mc-j82q-7jh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-x9jw-v3xm-j473/GHSA-x9jw-v3xm-j473.json b/advisories/unreviewed/2022/10/GHSA-x9jw-v3xm-j473/GHSA-x9jw-v3xm-j473.json index 416b0eda621..1ad213c9c95 100644 --- a/advisories/unreviewed/2022/10/GHSA-x9jw-v3xm-j473/GHSA-x9jw-v3xm-j473.json +++ b/advisories/unreviewed/2022/10/GHSA-x9jw-v3xm-j473/GHSA-x9jw-v3xm-j473.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-2764-9vrm-2xfc/GHSA-2764-9vrm-2xfc.json b/advisories/unreviewed/2022/11/GHSA-2764-9vrm-2xfc/GHSA-2764-9vrm-2xfc.json index a50620da09e..4ee5b3f653a 100644 --- a/advisories/unreviewed/2022/11/GHSA-2764-9vrm-2xfc/GHSA-2764-9vrm-2xfc.json +++ b/advisories/unreviewed/2022/11/GHSA-2764-9vrm-2xfc/GHSA-2764-9vrm-2xfc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-28fm-qh2h-3mch/GHSA-28fm-qh2h-3mch.json b/advisories/unreviewed/2022/11/GHSA-28fm-qh2h-3mch/GHSA-28fm-qh2h-3mch.json index 50f136318f4..bc0fb257e39 100644 --- a/advisories/unreviewed/2022/11/GHSA-28fm-qh2h-3mch/GHSA-28fm-qh2h-3mch.json +++ b/advisories/unreviewed/2022/11/GHSA-28fm-qh2h-3mch/GHSA-28fm-qh2h-3mch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-2c3g-5x92-qfrv/GHSA-2c3g-5x92-qfrv.json b/advisories/unreviewed/2022/11/GHSA-2c3g-5x92-qfrv/GHSA-2c3g-5x92-qfrv.json index 55828625f76..20688f9845f 100644 --- a/advisories/unreviewed/2022/11/GHSA-2c3g-5x92-qfrv/GHSA-2c3g-5x92-qfrv.json +++ b/advisories/unreviewed/2022/11/GHSA-2c3g-5x92-qfrv/GHSA-2c3g-5x92-qfrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-2cfx-8j9j-pg36/GHSA-2cfx-8j9j-pg36.json b/advisories/unreviewed/2022/11/GHSA-2cfx-8j9j-pg36/GHSA-2cfx-8j9j-pg36.json index bb53ab6c63f..8caba916780 100644 --- a/advisories/unreviewed/2022/11/GHSA-2cfx-8j9j-pg36/GHSA-2cfx-8j9j-pg36.json +++ b/advisories/unreviewed/2022/11/GHSA-2cfx-8j9j-pg36/GHSA-2cfx-8j9j-pg36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-36vh-mp6p-rrp2/GHSA-36vh-mp6p-rrp2.json b/advisories/unreviewed/2022/11/GHSA-36vh-mp6p-rrp2/GHSA-36vh-mp6p-rrp2.json index 6c31887e6ef..fc5acbbba31 100644 --- a/advisories/unreviewed/2022/11/GHSA-36vh-mp6p-rrp2/GHSA-36vh-mp6p-rrp2.json +++ b/advisories/unreviewed/2022/11/GHSA-36vh-mp6p-rrp2/GHSA-36vh-mp6p-rrp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-39pq-3mh9-m5qg/GHSA-39pq-3mh9-m5qg.json b/advisories/unreviewed/2022/11/GHSA-39pq-3mh9-m5qg/GHSA-39pq-3mh9-m5qg.json index 48e852a97be..41c0f4480fc 100644 --- a/advisories/unreviewed/2022/11/GHSA-39pq-3mh9-m5qg/GHSA-39pq-3mh9-m5qg.json +++ b/advisories/unreviewed/2022/11/GHSA-39pq-3mh9-m5qg/GHSA-39pq-3mh9-m5qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-3f72-rqqj-2fm8/GHSA-3f72-rqqj-2fm8.json b/advisories/unreviewed/2022/11/GHSA-3f72-rqqj-2fm8/GHSA-3f72-rqqj-2fm8.json index 3d47b43cbed..76d0ffb33f3 100644 --- a/advisories/unreviewed/2022/11/GHSA-3f72-rqqj-2fm8/GHSA-3f72-rqqj-2fm8.json +++ b/advisories/unreviewed/2022/11/GHSA-3f72-rqqj-2fm8/GHSA-3f72-rqqj-2fm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-3p7c-m357-q3xv/GHSA-3p7c-m357-q3xv.json b/advisories/unreviewed/2022/11/GHSA-3p7c-m357-q3xv/GHSA-3p7c-m357-q3xv.json index 4c9c661cce1..840194a685b 100644 --- a/advisories/unreviewed/2022/11/GHSA-3p7c-m357-q3xv/GHSA-3p7c-m357-q3xv.json +++ b/advisories/unreviewed/2022/11/GHSA-3p7c-m357-q3xv/GHSA-3p7c-m357-q3xv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-442m-jwp5-fc29/GHSA-442m-jwp5-fc29.json b/advisories/unreviewed/2022/11/GHSA-442m-jwp5-fc29/GHSA-442m-jwp5-fc29.json index b89d35085e1..2aefacc4f3b 100644 --- a/advisories/unreviewed/2022/11/GHSA-442m-jwp5-fc29/GHSA-442m-jwp5-fc29.json +++ b/advisories/unreviewed/2022/11/GHSA-442m-jwp5-fc29/GHSA-442m-jwp5-fc29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-46mv-p9ph-q95r/GHSA-46mv-p9ph-q95r.json b/advisories/unreviewed/2022/11/GHSA-46mv-p9ph-q95r/GHSA-46mv-p9ph-q95r.json index a37d6b90029..fafe2312897 100644 --- a/advisories/unreviewed/2022/11/GHSA-46mv-p9ph-q95r/GHSA-46mv-p9ph-q95r.json +++ b/advisories/unreviewed/2022/11/GHSA-46mv-p9ph-q95r/GHSA-46mv-p9ph-q95r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-4763-gm32-3j45/GHSA-4763-gm32-3j45.json b/advisories/unreviewed/2022/11/GHSA-4763-gm32-3j45/GHSA-4763-gm32-3j45.json index 24fd704621a..30492aed7dc 100644 --- a/advisories/unreviewed/2022/11/GHSA-4763-gm32-3j45/GHSA-4763-gm32-3j45.json +++ b/advisories/unreviewed/2022/11/GHSA-4763-gm32-3j45/GHSA-4763-gm32-3j45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-49q7-gc3f-7wp4/GHSA-49q7-gc3f-7wp4.json b/advisories/unreviewed/2022/11/GHSA-49q7-gc3f-7wp4/GHSA-49q7-gc3f-7wp4.json index 8d2e1856329..3326b3bc2e0 100644 --- a/advisories/unreviewed/2022/11/GHSA-49q7-gc3f-7wp4/GHSA-49q7-gc3f-7wp4.json +++ b/advisories/unreviewed/2022/11/GHSA-49q7-gc3f-7wp4/GHSA-49q7-gc3f-7wp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-4mgp-8x4h-v3vm/GHSA-4mgp-8x4h-v3vm.json b/advisories/unreviewed/2022/11/GHSA-4mgp-8x4h-v3vm/GHSA-4mgp-8x4h-v3vm.json index 30d0f96db08..5e81da41d7c 100644 --- a/advisories/unreviewed/2022/11/GHSA-4mgp-8x4h-v3vm/GHSA-4mgp-8x4h-v3vm.json +++ b/advisories/unreviewed/2022/11/GHSA-4mgp-8x4h-v3vm/GHSA-4mgp-8x4h-v3vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-4rhq-r59j-x4fc/GHSA-4rhq-r59j-x4fc.json b/advisories/unreviewed/2022/11/GHSA-4rhq-r59j-x4fc/GHSA-4rhq-r59j-x4fc.json index 563fc337086..61ad671b943 100644 --- a/advisories/unreviewed/2022/11/GHSA-4rhq-r59j-x4fc/GHSA-4rhq-r59j-x4fc.json +++ b/advisories/unreviewed/2022/11/GHSA-4rhq-r59j-x4fc/GHSA-4rhq-r59j-x4fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-4vg6-qj9w-48p3/GHSA-4vg6-qj9w-48p3.json b/advisories/unreviewed/2022/11/GHSA-4vg6-qj9w-48p3/GHSA-4vg6-qj9w-48p3.json index a8c9c93f4d9..c878b25f9d2 100644 --- a/advisories/unreviewed/2022/11/GHSA-4vg6-qj9w-48p3/GHSA-4vg6-qj9w-48p3.json +++ b/advisories/unreviewed/2022/11/GHSA-4vg6-qj9w-48p3/GHSA-4vg6-qj9w-48p3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-4xrx-h5ww-f9ph/GHSA-4xrx-h5ww-f9ph.json b/advisories/unreviewed/2022/11/GHSA-4xrx-h5ww-f9ph/GHSA-4xrx-h5ww-f9ph.json index 634efaffbce..e8612e7a2db 100644 --- a/advisories/unreviewed/2022/11/GHSA-4xrx-h5ww-f9ph/GHSA-4xrx-h5ww-f9ph.json +++ b/advisories/unreviewed/2022/11/GHSA-4xrx-h5ww-f9ph/GHSA-4xrx-h5ww-f9ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-53rj-vpf5-jg7q/GHSA-53rj-vpf5-jg7q.json b/advisories/unreviewed/2022/11/GHSA-53rj-vpf5-jg7q/GHSA-53rj-vpf5-jg7q.json index 9ae45e65fac..79acca2d98f 100644 --- a/advisories/unreviewed/2022/11/GHSA-53rj-vpf5-jg7q/GHSA-53rj-vpf5-jg7q.json +++ b/advisories/unreviewed/2022/11/GHSA-53rj-vpf5-jg7q/GHSA-53rj-vpf5-jg7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-5p8h-xw8m-3w4j/GHSA-5p8h-xw8m-3w4j.json b/advisories/unreviewed/2022/11/GHSA-5p8h-xw8m-3w4j/GHSA-5p8h-xw8m-3w4j.json index 83d0fe421de..94b5a29de4c 100644 --- a/advisories/unreviewed/2022/11/GHSA-5p8h-xw8m-3w4j/GHSA-5p8h-xw8m-3w4j.json +++ b/advisories/unreviewed/2022/11/GHSA-5p8h-xw8m-3w4j/GHSA-5p8h-xw8m-3w4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-5x48-4r9f-3jvf/GHSA-5x48-4r9f-3jvf.json b/advisories/unreviewed/2022/11/GHSA-5x48-4r9f-3jvf/GHSA-5x48-4r9f-3jvf.json index 5b98a2c04e9..ea1db3c7c2d 100644 --- a/advisories/unreviewed/2022/11/GHSA-5x48-4r9f-3jvf/GHSA-5x48-4r9f-3jvf.json +++ b/advisories/unreviewed/2022/11/GHSA-5x48-4r9f-3jvf/GHSA-5x48-4r9f-3jvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-65q9-jqm2-9grv/GHSA-65q9-jqm2-9grv.json b/advisories/unreviewed/2022/11/GHSA-65q9-jqm2-9grv/GHSA-65q9-jqm2-9grv.json index bdeb8d73744..75fbb34825e 100644 --- a/advisories/unreviewed/2022/11/GHSA-65q9-jqm2-9grv/GHSA-65q9-jqm2-9grv.json +++ b/advisories/unreviewed/2022/11/GHSA-65q9-jqm2-9grv/GHSA-65q9-jqm2-9grv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-68r7-3388-cmpg/GHSA-68r7-3388-cmpg.json b/advisories/unreviewed/2022/11/GHSA-68r7-3388-cmpg/GHSA-68r7-3388-cmpg.json index 17401ca3f5e..3a2a6b243ce 100644 --- a/advisories/unreviewed/2022/11/GHSA-68r7-3388-cmpg/GHSA-68r7-3388-cmpg.json +++ b/advisories/unreviewed/2022/11/GHSA-68r7-3388-cmpg/GHSA-68r7-3388-cmpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-692h-3jrr-4265/GHSA-692h-3jrr-4265.json b/advisories/unreviewed/2022/11/GHSA-692h-3jrr-4265/GHSA-692h-3jrr-4265.json index 8d372766502..b92f0ff1512 100644 --- a/advisories/unreviewed/2022/11/GHSA-692h-3jrr-4265/GHSA-692h-3jrr-4265.json +++ b/advisories/unreviewed/2022/11/GHSA-692h-3jrr-4265/GHSA-692h-3jrr-4265.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json b/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json index aaaf940226e..acbe1af7076 100644 --- a/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json +++ b/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-6x6f-v4f4-m9jh/GHSA-6x6f-v4f4-m9jh.json b/advisories/unreviewed/2022/11/GHSA-6x6f-v4f4-m9jh/GHSA-6x6f-v4f4-m9jh.json index 7105466c850..77e5689f984 100644 --- a/advisories/unreviewed/2022/11/GHSA-6x6f-v4f4-m9jh/GHSA-6x6f-v4f4-m9jh.json +++ b/advisories/unreviewed/2022/11/GHSA-6x6f-v4f4-m9jh/GHSA-6x6f-v4f4-m9jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-72gj-xg53-728v/GHSA-72gj-xg53-728v.json b/advisories/unreviewed/2022/11/GHSA-72gj-xg53-728v/GHSA-72gj-xg53-728v.json index 6117caee752..ed5c7c8535d 100644 --- a/advisories/unreviewed/2022/11/GHSA-72gj-xg53-728v/GHSA-72gj-xg53-728v.json +++ b/advisories/unreviewed/2022/11/GHSA-72gj-xg53-728v/GHSA-72gj-xg53-728v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json b/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json index eefe3f91592..47c21d1ba6a 100644 --- a/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json +++ b/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-77rv-4wjp-cfhf/GHSA-77rv-4wjp-cfhf.json b/advisories/unreviewed/2022/11/GHSA-77rv-4wjp-cfhf/GHSA-77rv-4wjp-cfhf.json index e9782d513b9..2c2ddeb2c38 100644 --- a/advisories/unreviewed/2022/11/GHSA-77rv-4wjp-cfhf/GHSA-77rv-4wjp-cfhf.json +++ b/advisories/unreviewed/2022/11/GHSA-77rv-4wjp-cfhf/GHSA-77rv-4wjp-cfhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-839x-g2vq-gcpw/GHSA-839x-g2vq-gcpw.json b/advisories/unreviewed/2022/11/GHSA-839x-g2vq-gcpw/GHSA-839x-g2vq-gcpw.json index dbcacc8650a..c3b35a92db6 100644 --- a/advisories/unreviewed/2022/11/GHSA-839x-g2vq-gcpw/GHSA-839x-g2vq-gcpw.json +++ b/advisories/unreviewed/2022/11/GHSA-839x-g2vq-gcpw/GHSA-839x-g2vq-gcpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-83q8-jp32-qmf2/GHSA-83q8-jp32-qmf2.json b/advisories/unreviewed/2022/11/GHSA-83q8-jp32-qmf2/GHSA-83q8-jp32-qmf2.json index c64c56017a7..5607b69af67 100644 --- a/advisories/unreviewed/2022/11/GHSA-83q8-jp32-qmf2/GHSA-83q8-jp32-qmf2.json +++ b/advisories/unreviewed/2022/11/GHSA-83q8-jp32-qmf2/GHSA-83q8-jp32-qmf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-8hwg-9379-6q79/GHSA-8hwg-9379-6q79.json b/advisories/unreviewed/2022/11/GHSA-8hwg-9379-6q79/GHSA-8hwg-9379-6q79.json index bfd173702a4..c5c52020d48 100644 --- a/advisories/unreviewed/2022/11/GHSA-8hwg-9379-6q79/GHSA-8hwg-9379-6q79.json +++ b/advisories/unreviewed/2022/11/GHSA-8hwg-9379-6q79/GHSA-8hwg-9379-6q79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-8mhw-phfm-55jr/GHSA-8mhw-phfm-55jr.json b/advisories/unreviewed/2022/11/GHSA-8mhw-phfm-55jr/GHSA-8mhw-phfm-55jr.json index 68b165c1e8c..a1827c069e6 100644 --- a/advisories/unreviewed/2022/11/GHSA-8mhw-phfm-55jr/GHSA-8mhw-phfm-55jr.json +++ b/advisories/unreviewed/2022/11/GHSA-8mhw-phfm-55jr/GHSA-8mhw-phfm-55jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-8pqr-x5vx-fgpj/GHSA-8pqr-x5vx-fgpj.json b/advisories/unreviewed/2022/11/GHSA-8pqr-x5vx-fgpj/GHSA-8pqr-x5vx-fgpj.json index 7834101eef0..057c107799f 100644 --- a/advisories/unreviewed/2022/11/GHSA-8pqr-x5vx-fgpj/GHSA-8pqr-x5vx-fgpj.json +++ b/advisories/unreviewed/2022/11/GHSA-8pqr-x5vx-fgpj/GHSA-8pqr-x5vx-fgpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json b/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json index 728316802db..2ba798e5981 100644 --- a/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json +++ b/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-8wqm-p249-4r57/GHSA-8wqm-p249-4r57.json b/advisories/unreviewed/2022/11/GHSA-8wqm-p249-4r57/GHSA-8wqm-p249-4r57.json index 5b7eadd2181..c89b1181cf5 100644 --- a/advisories/unreviewed/2022/11/GHSA-8wqm-p249-4r57/GHSA-8wqm-p249-4r57.json +++ b/advisories/unreviewed/2022/11/GHSA-8wqm-p249-4r57/GHSA-8wqm-p249-4r57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-93cj-p8xr-qghp/GHSA-93cj-p8xr-qghp.json b/advisories/unreviewed/2022/11/GHSA-93cj-p8xr-qghp/GHSA-93cj-p8xr-qghp.json index c503a6738c6..3e691c32012 100644 --- a/advisories/unreviewed/2022/11/GHSA-93cj-p8xr-qghp/GHSA-93cj-p8xr-qghp.json +++ b/advisories/unreviewed/2022/11/GHSA-93cj-p8xr-qghp/GHSA-93cj-p8xr-qghp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-982x-v642-cgcx/GHSA-982x-v642-cgcx.json b/advisories/unreviewed/2022/11/GHSA-982x-v642-cgcx/GHSA-982x-v642-cgcx.json index 048d12e1927..11440c7dcf6 100644 --- a/advisories/unreviewed/2022/11/GHSA-982x-v642-cgcx/GHSA-982x-v642-cgcx.json +++ b/advisories/unreviewed/2022/11/GHSA-982x-v642-cgcx/GHSA-982x-v642-cgcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-983j-cwr5-gp93/GHSA-983j-cwr5-gp93.json b/advisories/unreviewed/2022/11/GHSA-983j-cwr5-gp93/GHSA-983j-cwr5-gp93.json index 9a9a28a1514..1a85fd21241 100644 --- a/advisories/unreviewed/2022/11/GHSA-983j-cwr5-gp93/GHSA-983j-cwr5-gp93.json +++ b/advisories/unreviewed/2022/11/GHSA-983j-cwr5-gp93/GHSA-983j-cwr5-gp93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-9f29-7vg9-w67x/GHSA-9f29-7vg9-w67x.json b/advisories/unreviewed/2022/11/GHSA-9f29-7vg9-w67x/GHSA-9f29-7vg9-w67x.json index 37dc2482a19..6056a7d058b 100644 --- a/advisories/unreviewed/2022/11/GHSA-9f29-7vg9-w67x/GHSA-9f29-7vg9-w67x.json +++ b/advisories/unreviewed/2022/11/GHSA-9f29-7vg9-w67x/GHSA-9f29-7vg9-w67x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-9g5x-8ppm-2gh6/GHSA-9g5x-8ppm-2gh6.json b/advisories/unreviewed/2022/11/GHSA-9g5x-8ppm-2gh6/GHSA-9g5x-8ppm-2gh6.json index 3e1ef1028b4..353cdd2d642 100644 --- a/advisories/unreviewed/2022/11/GHSA-9g5x-8ppm-2gh6/GHSA-9g5x-8ppm-2gh6.json +++ b/advisories/unreviewed/2022/11/GHSA-9g5x-8ppm-2gh6/GHSA-9g5x-8ppm-2gh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-9x3h-hpx6-h3hp/GHSA-9x3h-hpx6-h3hp.json b/advisories/unreviewed/2022/11/GHSA-9x3h-hpx6-h3hp/GHSA-9x3h-hpx6-h3hp.json index 4ce7946a8f0..2ffe5784378 100644 --- a/advisories/unreviewed/2022/11/GHSA-9x3h-hpx6-h3hp/GHSA-9x3h-hpx6-h3hp.json +++ b/advisories/unreviewed/2022/11/GHSA-9x3h-hpx6-h3hp/GHSA-9x3h-hpx6-h3hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-cc32-h3p6-f962/GHSA-cc32-h3p6-f962.json b/advisories/unreviewed/2022/11/GHSA-cc32-h3p6-f962/GHSA-cc32-h3p6-f962.json index 8a9bf218ef5..7f721493143 100644 --- a/advisories/unreviewed/2022/11/GHSA-cc32-h3p6-f962/GHSA-cc32-h3p6-f962.json +++ b/advisories/unreviewed/2022/11/GHSA-cc32-h3p6-f962/GHSA-cc32-h3p6-f962.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-ccfq-vqq6-835v/GHSA-ccfq-vqq6-835v.json b/advisories/unreviewed/2022/11/GHSA-ccfq-vqq6-835v/GHSA-ccfq-vqq6-835v.json index 98998656a28..3a9fdea75aa 100644 --- a/advisories/unreviewed/2022/11/GHSA-ccfq-vqq6-835v/GHSA-ccfq-vqq6-835v.json +++ b/advisories/unreviewed/2022/11/GHSA-ccfq-vqq6-835v/GHSA-ccfq-vqq6-835v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-chj3-ww9m-fv7v/GHSA-chj3-ww9m-fv7v.json b/advisories/unreviewed/2022/11/GHSA-chj3-ww9m-fv7v/GHSA-chj3-ww9m-fv7v.json index b4b722bbfba..e4f8420d5c0 100644 --- a/advisories/unreviewed/2022/11/GHSA-chj3-ww9m-fv7v/GHSA-chj3-ww9m-fv7v.json +++ b/advisories/unreviewed/2022/11/GHSA-chj3-ww9m-fv7v/GHSA-chj3-ww9m-fv7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-cmjm-9vqg-fhfw/GHSA-cmjm-9vqg-fhfw.json b/advisories/unreviewed/2022/11/GHSA-cmjm-9vqg-fhfw/GHSA-cmjm-9vqg-fhfw.json index a27fffe7cd4..bfd2560902d 100644 --- a/advisories/unreviewed/2022/11/GHSA-cmjm-9vqg-fhfw/GHSA-cmjm-9vqg-fhfw.json +++ b/advisories/unreviewed/2022/11/GHSA-cmjm-9vqg-fhfw/GHSA-cmjm-9vqg-fhfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-cr69-9hhr-pqp9/GHSA-cr69-9hhr-pqp9.json b/advisories/unreviewed/2022/11/GHSA-cr69-9hhr-pqp9/GHSA-cr69-9hhr-pqp9.json index f36e58439e5..81694d55ada 100644 --- a/advisories/unreviewed/2022/11/GHSA-cr69-9hhr-pqp9/GHSA-cr69-9hhr-pqp9.json +++ b/advisories/unreviewed/2022/11/GHSA-cr69-9hhr-pqp9/GHSA-cr69-9hhr-pqp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-cxx2-36cf-cwrx/GHSA-cxx2-36cf-cwrx.json b/advisories/unreviewed/2022/11/GHSA-cxx2-36cf-cwrx/GHSA-cxx2-36cf-cwrx.json index 7425332fe4d..f0cca1f0a6b 100644 --- a/advisories/unreviewed/2022/11/GHSA-cxx2-36cf-cwrx/GHSA-cxx2-36cf-cwrx.json +++ b/advisories/unreviewed/2022/11/GHSA-cxx2-36cf-cwrx/GHSA-cxx2-36cf-cwrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-f2fh-x4pc-jpm8/GHSA-f2fh-x4pc-jpm8.json b/advisories/unreviewed/2022/11/GHSA-f2fh-x4pc-jpm8/GHSA-f2fh-x4pc-jpm8.json index 076b45dff2a..18d72958baf 100644 --- a/advisories/unreviewed/2022/11/GHSA-f2fh-x4pc-jpm8/GHSA-f2fh-x4pc-jpm8.json +++ b/advisories/unreviewed/2022/11/GHSA-f2fh-x4pc-jpm8/GHSA-f2fh-x4pc-jpm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-f52g-59g4-9xhq/GHSA-f52g-59g4-9xhq.json b/advisories/unreviewed/2022/11/GHSA-f52g-59g4-9xhq/GHSA-f52g-59g4-9xhq.json index e18096d50fd..73cdb1f6800 100644 --- a/advisories/unreviewed/2022/11/GHSA-f52g-59g4-9xhq/GHSA-f52g-59g4-9xhq.json +++ b/advisories/unreviewed/2022/11/GHSA-f52g-59g4-9xhq/GHSA-f52g-59g4-9xhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-fch5-fx89-m666/GHSA-fch5-fx89-m666.json b/advisories/unreviewed/2022/11/GHSA-fch5-fx89-m666/GHSA-fch5-fx89-m666.json index 88ac01baed1..695cca306d6 100644 --- a/advisories/unreviewed/2022/11/GHSA-fch5-fx89-m666/GHSA-fch5-fx89-m666.json +++ b/advisories/unreviewed/2022/11/GHSA-fch5-fx89-m666/GHSA-fch5-fx89-m666.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-ffrp-57c3-vhxc/GHSA-ffrp-57c3-vhxc.json b/advisories/unreviewed/2022/11/GHSA-ffrp-57c3-vhxc/GHSA-ffrp-57c3-vhxc.json index 631019f86c5..ef8231f679f 100644 --- a/advisories/unreviewed/2022/11/GHSA-ffrp-57c3-vhxc/GHSA-ffrp-57c3-vhxc.json +++ b/advisories/unreviewed/2022/11/GHSA-ffrp-57c3-vhxc/GHSA-ffrp-57c3-vhxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-fmvq-5xpx-r256/GHSA-fmvq-5xpx-r256.json b/advisories/unreviewed/2022/11/GHSA-fmvq-5xpx-r256/GHSA-fmvq-5xpx-r256.json index 80374b30474..86556ce4e54 100644 --- a/advisories/unreviewed/2022/11/GHSA-fmvq-5xpx-r256/GHSA-fmvq-5xpx-r256.json +++ b/advisories/unreviewed/2022/11/GHSA-fmvq-5xpx-r256/GHSA-fmvq-5xpx-r256.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-fw5q-wvfg-966g/GHSA-fw5q-wvfg-966g.json b/advisories/unreviewed/2022/11/GHSA-fw5q-wvfg-966g/GHSA-fw5q-wvfg-966g.json index 0b60b81ed48..1707da5be46 100644 --- a/advisories/unreviewed/2022/11/GHSA-fw5q-wvfg-966g/GHSA-fw5q-wvfg-966g.json +++ b/advisories/unreviewed/2022/11/GHSA-fw5q-wvfg-966g/GHSA-fw5q-wvfg-966g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-fwj8-64xx-fwh9/GHSA-fwj8-64xx-fwh9.json b/advisories/unreviewed/2022/11/GHSA-fwj8-64xx-fwh9/GHSA-fwj8-64xx-fwh9.json index ead47275997..6e986bade32 100644 --- a/advisories/unreviewed/2022/11/GHSA-fwj8-64xx-fwh9/GHSA-fwj8-64xx-fwh9.json +++ b/advisories/unreviewed/2022/11/GHSA-fwj8-64xx-fwh9/GHSA-fwj8-64xx-fwh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-fxhg-25q8-4697/GHSA-fxhg-25q8-4697.json b/advisories/unreviewed/2022/11/GHSA-fxhg-25q8-4697/GHSA-fxhg-25q8-4697.json index 11b4b2521be..5130d6f525b 100644 --- a/advisories/unreviewed/2022/11/GHSA-fxhg-25q8-4697/GHSA-fxhg-25q8-4697.json +++ b/advisories/unreviewed/2022/11/GHSA-fxhg-25q8-4697/GHSA-fxhg-25q8-4697.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-g2r7-hx5q-vxx6/GHSA-g2r7-hx5q-vxx6.json b/advisories/unreviewed/2022/11/GHSA-g2r7-hx5q-vxx6/GHSA-g2r7-hx5q-vxx6.json index 5084dd9366f..3bac3b27b48 100644 --- a/advisories/unreviewed/2022/11/GHSA-g2r7-hx5q-vxx6/GHSA-g2r7-hx5q-vxx6.json +++ b/advisories/unreviewed/2022/11/GHSA-g2r7-hx5q-vxx6/GHSA-g2r7-hx5q-vxx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-g333-g9g8-m3x9/GHSA-g333-g9g8-m3x9.json b/advisories/unreviewed/2022/11/GHSA-g333-g9g8-m3x9/GHSA-g333-g9g8-m3x9.json index bd5a264e889..aafd8e70502 100644 --- a/advisories/unreviewed/2022/11/GHSA-g333-g9g8-m3x9/GHSA-g333-g9g8-m3x9.json +++ b/advisories/unreviewed/2022/11/GHSA-g333-g9g8-m3x9/GHSA-g333-g9g8-m3x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-g7p3-8636-5h4v/GHSA-g7p3-8636-5h4v.json b/advisories/unreviewed/2022/11/GHSA-g7p3-8636-5h4v/GHSA-g7p3-8636-5h4v.json index 2bab47f407d..8b0bfc25080 100644 --- a/advisories/unreviewed/2022/11/GHSA-g7p3-8636-5h4v/GHSA-g7p3-8636-5h4v.json +++ b/advisories/unreviewed/2022/11/GHSA-g7p3-8636-5h4v/GHSA-g7p3-8636-5h4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-gfqf-vmrm-g6r6/GHSA-gfqf-vmrm-g6r6.json b/advisories/unreviewed/2022/11/GHSA-gfqf-vmrm-g6r6/GHSA-gfqf-vmrm-g6r6.json index 52475affb65..5205c0b02d8 100644 --- a/advisories/unreviewed/2022/11/GHSA-gfqf-vmrm-g6r6/GHSA-gfqf-vmrm-g6r6.json +++ b/advisories/unreviewed/2022/11/GHSA-gfqf-vmrm-g6r6/GHSA-gfqf-vmrm-g6r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-gpm8-7vr3-jj6m/GHSA-gpm8-7vr3-jj6m.json b/advisories/unreviewed/2022/11/GHSA-gpm8-7vr3-jj6m/GHSA-gpm8-7vr3-jj6m.json index 019ae482420..0d6399a46b7 100644 --- a/advisories/unreviewed/2022/11/GHSA-gpm8-7vr3-jj6m/GHSA-gpm8-7vr3-jj6m.json +++ b/advisories/unreviewed/2022/11/GHSA-gpm8-7vr3-jj6m/GHSA-gpm8-7vr3-jj6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-h2v5-wfxf-w2jf/GHSA-h2v5-wfxf-w2jf.json b/advisories/unreviewed/2022/11/GHSA-h2v5-wfxf-w2jf/GHSA-h2v5-wfxf-w2jf.json index 01db06c0d5e..741047aed80 100644 --- a/advisories/unreviewed/2022/11/GHSA-h2v5-wfxf-w2jf/GHSA-h2v5-wfxf-w2jf.json +++ b/advisories/unreviewed/2022/11/GHSA-h2v5-wfxf-w2jf/GHSA-h2v5-wfxf-w2jf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-hjc7-grqv-7x6q/GHSA-hjc7-grqv-7x6q.json b/advisories/unreviewed/2022/11/GHSA-hjc7-grqv-7x6q/GHSA-hjc7-grqv-7x6q.json index e00e3bed3df..b8dc702e4c4 100644 --- a/advisories/unreviewed/2022/11/GHSA-hjc7-grqv-7x6q/GHSA-hjc7-grqv-7x6q.json +++ b/advisories/unreviewed/2022/11/GHSA-hjc7-grqv-7x6q/GHSA-hjc7-grqv-7x6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-hv7h-jqcv-92v9/GHSA-hv7h-jqcv-92v9.json b/advisories/unreviewed/2022/11/GHSA-hv7h-jqcv-92v9/GHSA-hv7h-jqcv-92v9.json index eeefe75e49f..7c3f7bc2379 100644 --- a/advisories/unreviewed/2022/11/GHSA-hv7h-jqcv-92v9/GHSA-hv7h-jqcv-92v9.json +++ b/advisories/unreviewed/2022/11/GHSA-hv7h-jqcv-92v9/GHSA-hv7h-jqcv-92v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-jqv9-xxr8-r2p9/GHSA-jqv9-xxr8-r2p9.json b/advisories/unreviewed/2022/11/GHSA-jqv9-xxr8-r2p9/GHSA-jqv9-xxr8-r2p9.json index b9a4206f131..e1e22491430 100644 --- a/advisories/unreviewed/2022/11/GHSA-jqv9-xxr8-r2p9/GHSA-jqv9-xxr8-r2p9.json +++ b/advisories/unreviewed/2022/11/GHSA-jqv9-xxr8-r2p9/GHSA-jqv9-xxr8-r2p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-jw3w-3gxw-82qw/GHSA-jw3w-3gxw-82qw.json b/advisories/unreviewed/2022/11/GHSA-jw3w-3gxw-82qw/GHSA-jw3w-3gxw-82qw.json index 9ed65d0ad9f..317e891f8ea 100644 --- a/advisories/unreviewed/2022/11/GHSA-jw3w-3gxw-82qw/GHSA-jw3w-3gxw-82qw.json +++ b/advisories/unreviewed/2022/11/GHSA-jw3w-3gxw-82qw/GHSA-jw3w-3gxw-82qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json b/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json index e04314b7d27..807c26aad3a 100644 --- a/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json +++ b/advisories/unreviewed/2022/11/GHSA-jw98-jrc9-mrx5/GHSA-jw98-jrc9-mrx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-m4wm-6gf3-2xqw/GHSA-m4wm-6gf3-2xqw.json b/advisories/unreviewed/2022/11/GHSA-m4wm-6gf3-2xqw/GHSA-m4wm-6gf3-2xqw.json index e387bb14878..8004024573e 100644 --- a/advisories/unreviewed/2022/11/GHSA-m4wm-6gf3-2xqw/GHSA-m4wm-6gf3-2xqw.json +++ b/advisories/unreviewed/2022/11/GHSA-m4wm-6gf3-2xqw/GHSA-m4wm-6gf3-2xqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-m5hg-m5vh-mqwx/GHSA-m5hg-m5vh-mqwx.json b/advisories/unreviewed/2022/11/GHSA-m5hg-m5vh-mqwx/GHSA-m5hg-m5vh-mqwx.json index 62f7a92ed54..8f2c66e58a8 100644 --- a/advisories/unreviewed/2022/11/GHSA-m5hg-m5vh-mqwx/GHSA-m5hg-m5vh-mqwx.json +++ b/advisories/unreviewed/2022/11/GHSA-m5hg-m5vh-mqwx/GHSA-m5hg-m5vh-mqwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-m74r-fc5w-h4v6/GHSA-m74r-fc5w-h4v6.json b/advisories/unreviewed/2022/11/GHSA-m74r-fc5w-h4v6/GHSA-m74r-fc5w-h4v6.json index 8f0665cffca..5dd467ae2ab 100644 --- a/advisories/unreviewed/2022/11/GHSA-m74r-fc5w-h4v6/GHSA-m74r-fc5w-h4v6.json +++ b/advisories/unreviewed/2022/11/GHSA-m74r-fc5w-h4v6/GHSA-m74r-fc5w-h4v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-m8p3-2xcr-6pq8/GHSA-m8p3-2xcr-6pq8.json b/advisories/unreviewed/2022/11/GHSA-m8p3-2xcr-6pq8/GHSA-m8p3-2xcr-6pq8.json index e8915dccf78..4e379d3c937 100644 --- a/advisories/unreviewed/2022/11/GHSA-m8p3-2xcr-6pq8/GHSA-m8p3-2xcr-6pq8.json +++ b/advisories/unreviewed/2022/11/GHSA-m8p3-2xcr-6pq8/GHSA-m8p3-2xcr-6pq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mjvr-2vf5-fx5p/GHSA-mjvr-2vf5-fx5p.json b/advisories/unreviewed/2022/11/GHSA-mjvr-2vf5-fx5p/GHSA-mjvr-2vf5-fx5p.json index 445bcd1873d..fde0d3bb99a 100644 --- a/advisories/unreviewed/2022/11/GHSA-mjvr-2vf5-fx5p/GHSA-mjvr-2vf5-fx5p.json +++ b/advisories/unreviewed/2022/11/GHSA-mjvr-2vf5-fx5p/GHSA-mjvr-2vf5-fx5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mvr7-h5h4-f8g6/GHSA-mvr7-h5h4-f8g6.json b/advisories/unreviewed/2022/11/GHSA-mvr7-h5h4-f8g6/GHSA-mvr7-h5h4-f8g6.json index dd7192664fc..8e747f6ef4d 100644 --- a/advisories/unreviewed/2022/11/GHSA-mvr7-h5h4-f8g6/GHSA-mvr7-h5h4-f8g6.json +++ b/advisories/unreviewed/2022/11/GHSA-mvr7-h5h4-f8g6/GHSA-mvr7-h5h4-f8g6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-mxp8-22g2-rqq6/GHSA-mxp8-22g2-rqq6.json b/advisories/unreviewed/2022/11/GHSA-mxp8-22g2-rqq6/GHSA-mxp8-22g2-rqq6.json index acc40e6ec18..0d31213730e 100644 --- a/advisories/unreviewed/2022/11/GHSA-mxp8-22g2-rqq6/GHSA-mxp8-22g2-rqq6.json +++ b/advisories/unreviewed/2022/11/GHSA-mxp8-22g2-rqq6/GHSA-mxp8-22g2-rqq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-p449-69hx-vfj9/GHSA-p449-69hx-vfj9.json b/advisories/unreviewed/2022/11/GHSA-p449-69hx-vfj9/GHSA-p449-69hx-vfj9.json index 61a4e2b8e96..06622417a7a 100644 --- a/advisories/unreviewed/2022/11/GHSA-p449-69hx-vfj9/GHSA-p449-69hx-vfj9.json +++ b/advisories/unreviewed/2022/11/GHSA-p449-69hx-vfj9/GHSA-p449-69hx-vfj9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-pf8m-6mx3-9xpj/GHSA-pf8m-6mx3-9xpj.json b/advisories/unreviewed/2022/11/GHSA-pf8m-6mx3-9xpj/GHSA-pf8m-6mx3-9xpj.json index 0caabc4242b..2376bab9bc5 100644 --- a/advisories/unreviewed/2022/11/GHSA-pf8m-6mx3-9xpj/GHSA-pf8m-6mx3-9xpj.json +++ b/advisories/unreviewed/2022/11/GHSA-pf8m-6mx3-9xpj/GHSA-pf8m-6mx3-9xpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-pggw-w357-q8q8/GHSA-pggw-w357-q8q8.json b/advisories/unreviewed/2022/11/GHSA-pggw-w357-q8q8/GHSA-pggw-w357-q8q8.json index 4336ab7f96a..0c5e7ca6546 100644 --- a/advisories/unreviewed/2022/11/GHSA-pggw-w357-q8q8/GHSA-pggw-w357-q8q8.json +++ b/advisories/unreviewed/2022/11/GHSA-pggw-w357-q8q8/GHSA-pggw-w357-q8q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json b/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json index 03689177d15..50b128436e7 100644 --- a/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json +++ b/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-pr89-cv9w-3vj3/GHSA-pr89-cv9w-3vj3.json b/advisories/unreviewed/2022/11/GHSA-pr89-cv9w-3vj3/GHSA-pr89-cv9w-3vj3.json index a51ea03c321..58b034640a4 100644 --- a/advisories/unreviewed/2022/11/GHSA-pr89-cv9w-3vj3/GHSA-pr89-cv9w-3vj3.json +++ b/advisories/unreviewed/2022/11/GHSA-pr89-cv9w-3vj3/GHSA-pr89-cv9w-3vj3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-pvw8-76h2-7q32/GHSA-pvw8-76h2-7q32.json b/advisories/unreviewed/2022/11/GHSA-pvw8-76h2-7q32/GHSA-pvw8-76h2-7q32.json index 620bffb4f6a..dd0f241bf23 100644 --- a/advisories/unreviewed/2022/11/GHSA-pvw8-76h2-7q32/GHSA-pvw8-76h2-7q32.json +++ b/advisories/unreviewed/2022/11/GHSA-pvw8-76h2-7q32/GHSA-pvw8-76h2-7q32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-q5jj-rrmh-qqh6/GHSA-q5jj-rrmh-qqh6.json b/advisories/unreviewed/2022/11/GHSA-q5jj-rrmh-qqh6/GHSA-q5jj-rrmh-qqh6.json index aad8040b0e6..3ad5183213d 100644 --- a/advisories/unreviewed/2022/11/GHSA-q5jj-rrmh-qqh6/GHSA-q5jj-rrmh-qqh6.json +++ b/advisories/unreviewed/2022/11/GHSA-q5jj-rrmh-qqh6/GHSA-q5jj-rrmh-qqh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qff8-jrqx-8xjm/GHSA-qff8-jrqx-8xjm.json b/advisories/unreviewed/2022/11/GHSA-qff8-jrqx-8xjm/GHSA-qff8-jrqx-8xjm.json index 4fbc5f30757..b82d13c00d8 100644 --- a/advisories/unreviewed/2022/11/GHSA-qff8-jrqx-8xjm/GHSA-qff8-jrqx-8xjm.json +++ b/advisories/unreviewed/2022/11/GHSA-qff8-jrqx-8xjm/GHSA-qff8-jrqx-8xjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qj2j-75v9-3gq2/GHSA-qj2j-75v9-3gq2.json b/advisories/unreviewed/2022/11/GHSA-qj2j-75v9-3gq2/GHSA-qj2j-75v9-3gq2.json index b2f3a5ce92e..e75d79c552e 100644 --- a/advisories/unreviewed/2022/11/GHSA-qj2j-75v9-3gq2/GHSA-qj2j-75v9-3gq2.json +++ b/advisories/unreviewed/2022/11/GHSA-qj2j-75v9-3gq2/GHSA-qj2j-75v9-3gq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qm27-xfxw-qqmp/GHSA-qm27-xfxw-qqmp.json b/advisories/unreviewed/2022/11/GHSA-qm27-xfxw-qqmp/GHSA-qm27-xfxw-qqmp.json index b9bce6cbd09..4d054342b41 100644 --- a/advisories/unreviewed/2022/11/GHSA-qm27-xfxw-qqmp/GHSA-qm27-xfxw-qqmp.json +++ b/advisories/unreviewed/2022/11/GHSA-qm27-xfxw-qqmp/GHSA-qm27-xfxw-qqmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-qq8m-wq89-2wqp/GHSA-qq8m-wq89-2wqp.json b/advisories/unreviewed/2022/11/GHSA-qq8m-wq89-2wqp/GHSA-qq8m-wq89-2wqp.json index 60bd3963100..b846ec28bb0 100644 --- a/advisories/unreviewed/2022/11/GHSA-qq8m-wq89-2wqp/GHSA-qq8m-wq89-2wqp.json +++ b/advisories/unreviewed/2022/11/GHSA-qq8m-wq89-2wqp/GHSA-qq8m-wq89-2wqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qvpw-wr9p-gh42/GHSA-qvpw-wr9p-gh42.json b/advisories/unreviewed/2022/11/GHSA-qvpw-wr9p-gh42/GHSA-qvpw-wr9p-gh42.json index 879908794d5..439bf414139 100644 --- a/advisories/unreviewed/2022/11/GHSA-qvpw-wr9p-gh42/GHSA-qvpw-wr9p-gh42.json +++ b/advisories/unreviewed/2022/11/GHSA-qvpw-wr9p-gh42/GHSA-qvpw-wr9p-gh42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qw9m-cx2j-p94f/GHSA-qw9m-cx2j-p94f.json b/advisories/unreviewed/2022/11/GHSA-qw9m-cx2j-p94f/GHSA-qw9m-cx2j-p94f.json index c112a5c2ea6..a047af438e6 100644 --- a/advisories/unreviewed/2022/11/GHSA-qw9m-cx2j-p94f/GHSA-qw9m-cx2j-p94f.json +++ b/advisories/unreviewed/2022/11/GHSA-qw9m-cx2j-p94f/GHSA-qw9m-cx2j-p94f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qx83-927w-w8jp/GHSA-qx83-927w-w8jp.json b/advisories/unreviewed/2022/11/GHSA-qx83-927w-w8jp/GHSA-qx83-927w-w8jp.json index bfaf67658f8..d4ca6a541a7 100644 --- a/advisories/unreviewed/2022/11/GHSA-qx83-927w-w8jp/GHSA-qx83-927w-w8jp.json +++ b/advisories/unreviewed/2022/11/GHSA-qx83-927w-w8jp/GHSA-qx83-927w-w8jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-r67w-vvh8-6wg2/GHSA-r67w-vvh8-6wg2.json b/advisories/unreviewed/2022/11/GHSA-r67w-vvh8-6wg2/GHSA-r67w-vvh8-6wg2.json index 94b258ab5f3..e67e7bbf6de 100644 --- a/advisories/unreviewed/2022/11/GHSA-r67w-vvh8-6wg2/GHSA-r67w-vvh8-6wg2.json +++ b/advisories/unreviewed/2022/11/GHSA-r67w-vvh8-6wg2/GHSA-r67w-vvh8-6wg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json b/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json index ca86b1f15e0..b0c76016a4f 100644 --- a/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json +++ b/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-r94j-7j3g-wg4f/GHSA-r94j-7j3g-wg4f.json b/advisories/unreviewed/2022/11/GHSA-r94j-7j3g-wg4f/GHSA-r94j-7j3g-wg4f.json index c35aa46909e..e5a7fcc1c8f 100644 --- a/advisories/unreviewed/2022/11/GHSA-r94j-7j3g-wg4f/GHSA-r94j-7j3g-wg4f.json +++ b/advisories/unreviewed/2022/11/GHSA-r94j-7j3g-wg4f/GHSA-r94j-7j3g-wg4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json b/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json index 62bcb140bb3..9a331eb581c 100644 --- a/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json +++ b/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-rpqg-gc44-45f5/GHSA-rpqg-gc44-45f5.json b/advisories/unreviewed/2022/11/GHSA-rpqg-gc44-45f5/GHSA-rpqg-gc44-45f5.json index 25837a85767..33120099fb8 100644 --- a/advisories/unreviewed/2022/11/GHSA-rpqg-gc44-45f5/GHSA-rpqg-gc44-45f5.json +++ b/advisories/unreviewed/2022/11/GHSA-rpqg-gc44-45f5/GHSA-rpqg-gc44-45f5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json b/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json index 28a1be5bfd1..80f0390910d 100644 --- a/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json +++ b/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-rq3j-7w29-7pqx/GHSA-rq3j-7w29-7pqx.json b/advisories/unreviewed/2022/11/GHSA-rq3j-7w29-7pqx/GHSA-rq3j-7w29-7pqx.json index 7bc803e036a..efc05a3a76e 100644 --- a/advisories/unreviewed/2022/11/GHSA-rq3j-7w29-7pqx/GHSA-rq3j-7w29-7pqx.json +++ b/advisories/unreviewed/2022/11/GHSA-rq3j-7w29-7pqx/GHSA-rq3j-7w29-7pqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-v76v-6f4h-xrc7/GHSA-v76v-6f4h-xrc7.json b/advisories/unreviewed/2022/11/GHSA-v76v-6f4h-xrc7/GHSA-v76v-6f4h-xrc7.json index afb452f41f0..270252de849 100644 --- a/advisories/unreviewed/2022/11/GHSA-v76v-6f4h-xrc7/GHSA-v76v-6f4h-xrc7.json +++ b/advisories/unreviewed/2022/11/GHSA-v76v-6f4h-xrc7/GHSA-v76v-6f4h-xrc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-wcm6-qr3c-r573/GHSA-wcm6-qr3c-r573.json b/advisories/unreviewed/2022/11/GHSA-wcm6-qr3c-r573/GHSA-wcm6-qr3c-r573.json index ed9ee417b8d..95b45399cc8 100644 --- a/advisories/unreviewed/2022/11/GHSA-wcm6-qr3c-r573/GHSA-wcm6-qr3c-r573.json +++ b/advisories/unreviewed/2022/11/GHSA-wcm6-qr3c-r573/GHSA-wcm6-qr3c-r573.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-wwxq-357h-jjr5/GHSA-wwxq-357h-jjr5.json b/advisories/unreviewed/2022/11/GHSA-wwxq-357h-jjr5/GHSA-wwxq-357h-jjr5.json index 50d6d73f5f0..fed2f48fc88 100644 --- a/advisories/unreviewed/2022/11/GHSA-wwxq-357h-jjr5/GHSA-wwxq-357h-jjr5.json +++ b/advisories/unreviewed/2022/11/GHSA-wwxq-357h-jjr5/GHSA-wwxq-357h-jjr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-wxff-8g4p-xj2g/GHSA-wxff-8g4p-xj2g.json b/advisories/unreviewed/2022/11/GHSA-wxff-8g4p-xj2g/GHSA-wxff-8g4p-xj2g.json index 37affe9f936..d490ce882cb 100644 --- a/advisories/unreviewed/2022/11/GHSA-wxff-8g4p-xj2g/GHSA-wxff-8g4p-xj2g.json +++ b/advisories/unreviewed/2022/11/GHSA-wxff-8g4p-xj2g/GHSA-wxff-8g4p-xj2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-x4p3-9wcx-48ww/GHSA-x4p3-9wcx-48ww.json b/advisories/unreviewed/2022/11/GHSA-x4p3-9wcx-48ww/GHSA-x4p3-9wcx-48ww.json index 933663feae6..8698fcd7eec 100644 --- a/advisories/unreviewed/2022/11/GHSA-x4p3-9wcx-48ww/GHSA-x4p3-9wcx-48ww.json +++ b/advisories/unreviewed/2022/11/GHSA-x4p3-9wcx-48ww/GHSA-x4p3-9wcx-48ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-xcxp-vf6x-3fjg/GHSA-xcxp-vf6x-3fjg.json b/advisories/unreviewed/2022/11/GHSA-xcxp-vf6x-3fjg/GHSA-xcxp-vf6x-3fjg.json index c8b938e03d5..3b7806af25b 100644 --- a/advisories/unreviewed/2022/11/GHSA-xcxp-vf6x-3fjg/GHSA-xcxp-vf6x-3fjg.json +++ b/advisories/unreviewed/2022/11/GHSA-xcxp-vf6x-3fjg/GHSA-xcxp-vf6x-3fjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-xh59-2wmf-7vqp/GHSA-xh59-2wmf-7vqp.json b/advisories/unreviewed/2022/11/GHSA-xh59-2wmf-7vqp/GHSA-xh59-2wmf-7vqp.json index b2575ad2732..cb059138332 100644 --- a/advisories/unreviewed/2022/11/GHSA-xh59-2wmf-7vqp/GHSA-xh59-2wmf-7vqp.json +++ b/advisories/unreviewed/2022/11/GHSA-xh59-2wmf-7vqp/GHSA-xh59-2wmf-7vqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-323q-3h7w-jpg8/GHSA-323q-3h7w-jpg8.json b/advisories/unreviewed/2022/12/GHSA-323q-3h7w-jpg8/GHSA-323q-3h7w-jpg8.json index 6080e20c8b8..8b01ff00ab2 100644 --- a/advisories/unreviewed/2022/12/GHSA-323q-3h7w-jpg8/GHSA-323q-3h7w-jpg8.json +++ b/advisories/unreviewed/2022/12/GHSA-323q-3h7w-jpg8/GHSA-323q-3h7w-jpg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json b/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json index b1e401d90d5..d065bba767f 100644 --- a/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json +++ b/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-3pv7-h25w-9xp8/GHSA-3pv7-h25w-9xp8.json b/advisories/unreviewed/2022/12/GHSA-3pv7-h25w-9xp8/GHSA-3pv7-h25w-9xp8.json index 1ef84307be7..9698f559767 100644 --- a/advisories/unreviewed/2022/12/GHSA-3pv7-h25w-9xp8/GHSA-3pv7-h25w-9xp8.json +++ b/advisories/unreviewed/2022/12/GHSA-3pv7-h25w-9xp8/GHSA-3pv7-h25w-9xp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-69wm-75j8-rv9g/GHSA-69wm-75j8-rv9g.json b/advisories/unreviewed/2022/12/GHSA-69wm-75j8-rv9g/GHSA-69wm-75j8-rv9g.json index a226961a695..4848fd9a4c1 100644 --- a/advisories/unreviewed/2022/12/GHSA-69wm-75j8-rv9g/GHSA-69wm-75j8-rv9g.json +++ b/advisories/unreviewed/2022/12/GHSA-69wm-75j8-rv9g/GHSA-69wm-75j8-rv9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-725m-hf23-77j7/GHSA-725m-hf23-77j7.json b/advisories/unreviewed/2022/12/GHSA-725m-hf23-77j7/GHSA-725m-hf23-77j7.json index 3a183198604..0e8d39b85f8 100644 --- a/advisories/unreviewed/2022/12/GHSA-725m-hf23-77j7/GHSA-725m-hf23-77j7.json +++ b/advisories/unreviewed/2022/12/GHSA-725m-hf23-77j7/GHSA-725m-hf23-77j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-9v76-fx89-wh58/GHSA-9v76-fx89-wh58.json b/advisories/unreviewed/2022/12/GHSA-9v76-fx89-wh58/GHSA-9v76-fx89-wh58.json index 46dab7beebe..66753fdda7f 100644 --- a/advisories/unreviewed/2022/12/GHSA-9v76-fx89-wh58/GHSA-9v76-fx89-wh58.json +++ b/advisories/unreviewed/2022/12/GHSA-9v76-fx89-wh58/GHSA-9v76-fx89-wh58.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-chpf-j4rw-9gw7/GHSA-chpf-j4rw-9gw7.json b/advisories/unreviewed/2022/12/GHSA-chpf-j4rw-9gw7/GHSA-chpf-j4rw-9gw7.json index 94c091e6dde..244e8cabe1c 100644 --- a/advisories/unreviewed/2022/12/GHSA-chpf-j4rw-9gw7/GHSA-chpf-j4rw-9gw7.json +++ b/advisories/unreviewed/2022/12/GHSA-chpf-j4rw-9gw7/GHSA-chpf-j4rw-9gw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json b/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json index 12c3ef3f2d2..f4fd1e859fb 100644 --- a/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json +++ b/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-pxm2-47wv-gcmv/GHSA-pxm2-47wv-gcmv.json b/advisories/unreviewed/2022/12/GHSA-pxm2-47wv-gcmv/GHSA-pxm2-47wv-gcmv.json index f1e1da797b2..9dc92705770 100644 --- a/advisories/unreviewed/2022/12/GHSA-pxm2-47wv-gcmv/GHSA-pxm2-47wv-gcmv.json +++ b/advisories/unreviewed/2022/12/GHSA-pxm2-47wv-gcmv/GHSA-pxm2-47wv-gcmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json b/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json index f2d37b3711b..697f7f6803c 100644 --- a/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json +++ b/advisories/unreviewed/2022/12/GHSA-qv3c-3mgw-hqqj/GHSA-qv3c-3mgw-hqqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json b/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json index cbdb89f2623..2b4c2137b9e 100644 --- a/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json +++ b/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-w43j-xjf7-hmp3/GHSA-w43j-xjf7-hmp3.json b/advisories/unreviewed/2022/12/GHSA-w43j-xjf7-hmp3/GHSA-w43j-xjf7-hmp3.json index 93a0efbe605..7db7065c793 100644 --- a/advisories/unreviewed/2022/12/GHSA-w43j-xjf7-hmp3/GHSA-w43j-xjf7-hmp3.json +++ b/advisories/unreviewed/2022/12/GHSA-w43j-xjf7-hmp3/GHSA-w43j-xjf7-hmp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json b/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json index f5aea203a4e..0adaf50526e 100644 --- a/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json +++ b/advisories/unreviewed/2022/12/GHSA-xg52-54c7-pvc7/GHSA-xg52-54c7-pvc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-8f9j-pr37-5xr3/GHSA-8f9j-pr37-5xr3.json b/advisories/unreviewed/2023/02/GHSA-8f9j-pr37-5xr3/GHSA-8f9j-pr37-5xr3.json index 349cd253d68..154c5638538 100644 --- a/advisories/unreviewed/2023/02/GHSA-8f9j-pr37-5xr3/GHSA-8f9j-pr37-5xr3.json +++ b/advisories/unreviewed/2023/02/GHSA-8f9j-pr37-5xr3/GHSA-8f9j-pr37-5xr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-fvfp-w3v3-v2cp/GHSA-fvfp-w3v3-v2cp.json b/advisories/unreviewed/2023/02/GHSA-fvfp-w3v3-v2cp/GHSA-fvfp-w3v3-v2cp.json index ba4d8f2db31..b5f0d3017db 100644 --- a/advisories/unreviewed/2023/02/GHSA-fvfp-w3v3-v2cp/GHSA-fvfp-w3v3-v2cp.json +++ b/advisories/unreviewed/2023/02/GHSA-fvfp-w3v3-v2cp/GHSA-fvfp-w3v3-v2cp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-3g98-4f8c-vh63/GHSA-3g98-4f8c-vh63.json b/advisories/unreviewed/2023/11/GHSA-3g98-4f8c-vh63/GHSA-3g98-4f8c-vh63.json index 1ec52492ae4..d151f78780e 100644 --- a/advisories/unreviewed/2023/11/GHSA-3g98-4f8c-vh63/GHSA-3g98-4f8c-vh63.json +++ b/advisories/unreviewed/2023/11/GHSA-3g98-4f8c-vh63/GHSA-3g98-4f8c-vh63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-755r-2xqh-f6rj/GHSA-755r-2xqh-f6rj.json b/advisories/unreviewed/2023/11/GHSA-755r-2xqh-f6rj/GHSA-755r-2xqh-f6rj.json index 6556eb41ea4..358ef30d768 100644 --- a/advisories/unreviewed/2023/11/GHSA-755r-2xqh-f6rj/GHSA-755r-2xqh-f6rj.json +++ b/advisories/unreviewed/2023/11/GHSA-755r-2xqh-f6rj/GHSA-755r-2xqh-f6rj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json b/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json index 96671be56d5..5f76595ebf8 100644 --- a/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json +++ b/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9wqw-4jfm-38vq/GHSA-9wqw-4jfm-38vq.json b/advisories/unreviewed/2023/11/GHSA-9wqw-4jfm-38vq/GHSA-9wqw-4jfm-38vq.json index 1eee2db17c8..9680a2b6275 100644 --- a/advisories/unreviewed/2023/11/GHSA-9wqw-4jfm-38vq/GHSA-9wqw-4jfm-38vq.json +++ b/advisories/unreviewed/2023/11/GHSA-9wqw-4jfm-38vq/GHSA-9wqw-4jfm-38vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-f9g8-99mc-gf4v/GHSA-f9g8-99mc-gf4v.json b/advisories/unreviewed/2023/11/GHSA-f9g8-99mc-gf4v/GHSA-f9g8-99mc-gf4v.json index 20573fb1cf9..8f054ed7840 100644 --- a/advisories/unreviewed/2023/11/GHSA-f9g8-99mc-gf4v/GHSA-f9g8-99mc-gf4v.json +++ b/advisories/unreviewed/2023/11/GHSA-f9g8-99mc-gf4v/GHSA-f9g8-99mc-gf4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-gr4q-fjfj-g89j/GHSA-gr4q-fjfj-g89j.json b/advisories/unreviewed/2023/11/GHSA-gr4q-fjfj-g89j/GHSA-gr4q-fjfj-g89j.json index 2e831d03b40..e4b356b7099 100644 --- a/advisories/unreviewed/2023/11/GHSA-gr4q-fjfj-g89j/GHSA-gr4q-fjfj-g89j.json +++ b/advisories/unreviewed/2023/11/GHSA-gr4q-fjfj-g89j/GHSA-gr4q-fjfj-g89j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json b/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json index 542db2b4cbe..68e46c19567 100644 --- a/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json +++ b/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-j9gj-v4jx-fj5v/GHSA-j9gj-v4jx-fj5v.json b/advisories/unreviewed/2023/11/GHSA-j9gj-v4jx-fj5v/GHSA-j9gj-v4jx-fj5v.json index cd5387e53c8..b01a648e22c 100644 --- a/advisories/unreviewed/2023/11/GHSA-j9gj-v4jx-fj5v/GHSA-j9gj-v4jx-fj5v.json +++ b/advisories/unreviewed/2023/11/GHSA-j9gj-v4jx-fj5v/GHSA-j9gj-v4jx-fj5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-jmgq-6phq-mqvq/GHSA-jmgq-6phq-mqvq.json b/advisories/unreviewed/2023/11/GHSA-jmgq-6phq-mqvq/GHSA-jmgq-6phq-mqvq.json index d3fd1e36fb9..4a1d140c2aa 100644 --- a/advisories/unreviewed/2023/11/GHSA-jmgq-6phq-mqvq/GHSA-jmgq-6phq-mqvq.json +++ b/advisories/unreviewed/2023/11/GHSA-jmgq-6phq-mqvq/GHSA-jmgq-6phq-mqvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-m2v8-gq8g-4wpj/GHSA-m2v8-gq8g-4wpj.json b/advisories/unreviewed/2023/11/GHSA-m2v8-gq8g-4wpj/GHSA-m2v8-gq8g-4wpj.json index 7c43afcb734..dab86d95dbd 100644 --- a/advisories/unreviewed/2023/11/GHSA-m2v8-gq8g-4wpj/GHSA-m2v8-gq8g-4wpj.json +++ b/advisories/unreviewed/2023/11/GHSA-m2v8-gq8g-4wpj/GHSA-m2v8-gq8g-4wpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-qh68-5xq4-9pr9/GHSA-qh68-5xq4-9pr9.json b/advisories/unreviewed/2023/11/GHSA-qh68-5xq4-9pr9/GHSA-qh68-5xq4-9pr9.json index facd6d924f1..fe6e20673c3 100644 --- a/advisories/unreviewed/2023/11/GHSA-qh68-5xq4-9pr9/GHSA-qh68-5xq4-9pr9.json +++ b/advisories/unreviewed/2023/11/GHSA-qh68-5xq4-9pr9/GHSA-qh68-5xq4-9pr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-rqfx-9c5w-q3jj/GHSA-rqfx-9c5w-q3jj.json b/advisories/unreviewed/2023/11/GHSA-rqfx-9c5w-q3jj/GHSA-rqfx-9c5w-q3jj.json index e2db94d8a89..345b33e594e 100644 --- a/advisories/unreviewed/2023/11/GHSA-rqfx-9c5w-q3jj/GHSA-rqfx-9c5w-q3jj.json +++ b/advisories/unreviewed/2023/11/GHSA-rqfx-9c5w-q3jj/GHSA-rqfx-9c5w-q3jj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-v5gj-gr4g-9rmq/GHSA-v5gj-gr4g-9rmq.json b/advisories/unreviewed/2023/11/GHSA-v5gj-gr4g-9rmq/GHSA-v5gj-gr4g-9rmq.json index 8de24390a17..32a05e4e99f 100644 --- a/advisories/unreviewed/2023/11/GHSA-v5gj-gr4g-9rmq/GHSA-v5gj-gr4g-9rmq.json +++ b/advisories/unreviewed/2023/11/GHSA-v5gj-gr4g-9rmq/GHSA-v5gj-gr4g-9rmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-vm68-58gf-qg82/GHSA-vm68-58gf-qg82.json b/advisories/unreviewed/2023/11/GHSA-vm68-58gf-qg82/GHSA-vm68-58gf-qg82.json index 38c6659a9d4..429e66dbf28 100644 --- a/advisories/unreviewed/2023/11/GHSA-vm68-58gf-qg82/GHSA-vm68-58gf-qg82.json +++ b/advisories/unreviewed/2023/11/GHSA-vm68-58gf-qg82/GHSA-vm68-58gf-qg82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-whr2-w3q9-5g6m/GHSA-whr2-w3q9-5g6m.json b/advisories/unreviewed/2023/11/GHSA-whr2-w3q9-5g6m/GHSA-whr2-w3q9-5g6m.json index 434c7e1b439..4a0951fc4b5 100644 --- a/advisories/unreviewed/2023/11/GHSA-whr2-w3q9-5g6m/GHSA-whr2-w3q9-5g6m.json +++ b/advisories/unreviewed/2023/11/GHSA-whr2-w3q9-5g6m/GHSA-whr2-w3q9-5g6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json b/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json index f50ece5e8a5..8b3fd91a597 100644 --- a/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json +++ b/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-344g-jvx4-773r/GHSA-344g-jvx4-773r.json b/advisories/unreviewed/2024/08/GHSA-344g-jvx4-773r/GHSA-344g-jvx4-773r.json index c3f53c769cc..72716fb1a32 100644 --- a/advisories/unreviewed/2024/08/GHSA-344g-jvx4-773r/GHSA-344g-jvx4-773r.json +++ b/advisories/unreviewed/2024/08/GHSA-344g-jvx4-773r/GHSA-344g-jvx4-773r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json b/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json index ade68ae7021..02411c55e74 100644 --- a/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json +++ b/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json b/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json index f72e965f88c..3e0aa6ec710 100644 --- a/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json +++ b/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json b/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json index 541a0a53bfe..50c842256bf 100644 --- a/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json +++ b/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json b/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json index 923e868fd0a..8a88d95c1ab 100644 --- a/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json +++ b/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json b/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json index e35b08d695f..ee7789e32e3 100644 --- a/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json +++ b/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json b/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json index d2d289f183e..9232ab5a680 100644 --- a/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json +++ b/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json b/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json index cb22ec9893e..75d533120c3 100644 --- a/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json +++ b/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json b/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json index 0bd14fcd784..61c594de168 100644 --- a/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json +++ b/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5qp7-c857-4gm9/GHSA-5qp7-c857-4gm9.json b/advisories/unreviewed/2024/08/GHSA-5qp7-c857-4gm9/GHSA-5qp7-c857-4gm9.json index 1c7d8a4c85a..a2281a1009c 100644 --- a/advisories/unreviewed/2024/08/GHSA-5qp7-c857-4gm9/GHSA-5qp7-c857-4gm9.json +++ b/advisories/unreviewed/2024/08/GHSA-5qp7-c857-4gm9/GHSA-5qp7-c857-4gm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json b/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json index 5a88cecbe26..4152506f7bb 100644 --- a/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json +++ b/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json b/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json index 5f13ce2b3e5..6a5b166f01a 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json +++ b/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json b/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json index 93a3a3a858a..3944cd2d20b 100644 --- a/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json +++ b/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json b/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json index 4a91de800a7..4a18048cff3 100644 --- a/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json +++ b/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json b/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json index c9e00b017c7..afbf88d0ede 100644 --- a/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json +++ b/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-c6cg-7q2c-x256/GHSA-c6cg-7q2c-x256.json b/advisories/unreviewed/2024/08/GHSA-c6cg-7q2c-x256/GHSA-c6cg-7q2c-x256.json index 56fba3740d8..bd7f118bdde 100644 --- a/advisories/unreviewed/2024/08/GHSA-c6cg-7q2c-x256/GHSA-c6cg-7q2c-x256.json +++ b/advisories/unreviewed/2024/08/GHSA-c6cg-7q2c-x256/GHSA-c6cg-7q2c-x256.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json b/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json index 0132de6d9c1..3b9638c19e0 100644 --- a/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json +++ b/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json b/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json index 84733d8fdcb..689b1d70219 100644 --- a/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json +++ b/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json b/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json index 033d7daec56..efb193ae4ca 100644 --- a/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json +++ b/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json b/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json index 76b0231ce84..879a5b865ad 100644 --- a/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json +++ b/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json b/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json index 15d7c0fd45b..c5b83e87427 100644 --- a/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json +++ b/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json b/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json index cfd6cf9aa4b..5a0d73dd30c 100644 --- a/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json +++ b/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json b/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json index ae81ab0c2c2..8543a1a6f09 100644 --- a/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json +++ b/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json b/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json index 4ef7dbd54e8..a0a42faa347 100644 --- a/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json +++ b/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-v3vh-37fv-r9r7/GHSA-v3vh-37fv-r9r7.json b/advisories/unreviewed/2024/08/GHSA-v3vh-37fv-r9r7/GHSA-v3vh-37fv-r9r7.json index 26c75d554cb..6c5c647f0e5 100644 --- a/advisories/unreviewed/2024/08/GHSA-v3vh-37fv-r9r7/GHSA-v3vh-37fv-r9r7.json +++ b/advisories/unreviewed/2024/08/GHSA-v3vh-37fv-r9r7/GHSA-v3vh-37fv-r9r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json b/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json index 109d53ccd3f..e30192682e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json +++ b/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-vgwc-ppmj-vcrg/GHSA-vgwc-ppmj-vcrg.json b/advisories/unreviewed/2024/08/GHSA-vgwc-ppmj-vcrg/GHSA-vgwc-ppmj-vcrg.json index 42a1aa99d78..8f1e203988b 100644 --- a/advisories/unreviewed/2024/08/GHSA-vgwc-ppmj-vcrg/GHSA-vgwc-ppmj-vcrg.json +++ b/advisories/unreviewed/2024/08/GHSA-vgwc-ppmj-vcrg/GHSA-vgwc-ppmj-vcrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json b/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json index 1715eca89d0..3266620c96c 100644 --- a/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json +++ b/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json b/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json index f95ebb9440e..12a6ee3e83c 100644 --- a/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json +++ b/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",