diff --git a/advisories/github-reviewed/2017/10/GHSA-84fq-6626-w5fg/GHSA-84fq-6626-w5fg.json b/advisories/github-reviewed/2017/10/GHSA-84fq-6626-w5fg/GHSA-84fq-6626-w5fg.json
index ace747aa319..554c2bf4818 100644
--- a/advisories/github-reviewed/2017/10/GHSA-84fq-6626-w5fg/GHSA-84fq-6626-w5fg.json
+++ b/advisories/github-reviewed/2017/10/GHSA-84fq-6626-w5fg/GHSA-84fq-6626-w5fg.json
@@ -8,9 +8,7 @@
],
"summary": "CORS Token Disclosure in crumb",
"details": "When CORS is enabled on a hapi route handler, it is possible to set a crumb token for a different domain. An attacker would need to have an application consumer visit a site they control, request a route supporting CORS, and then retrieve the token. With this token, they could possibly make requests to non CORS routes as this user.\n\nA configuration and scenario where this would occur is unlikely, as most configurations will set CORS globally (where crumb is not used), or not at all.\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or greater.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2017/10/GHSA-cfjh-p3g4-3q2f/GHSA-cfjh-p3g4-3q2f.json b/advisories/github-reviewed/2017/10/GHSA-cfjh-p3g4-3q2f/GHSA-cfjh-p3g4-3q2f.json
index bfc98957cb4..2dbdcb95cfb 100644
--- a/advisories/github-reviewed/2017/10/GHSA-cfjh-p3g4-3q2f/GHSA-cfjh-p3g4-3q2f.json
+++ b/advisories/github-reviewed/2017/10/GHSA-cfjh-p3g4-3q2f/GHSA-cfjh-p3g4-3q2f.json
@@ -8,9 +8,7 @@
],
"summary": "VBScript Content Injection in marked",
"details": "Versions 0.3.2 and earlier of `marked` are affected by a cross-site scripting vulnerability even when `sanitize:true` is set. \n\n## Proof of Concept ( IE10 Compatibility Mode Only )\n\n`[xss link](vbscript:alert(1))`\n\nwill get a link\n\n`xss link`\n\n\n## Recommendation\n\nUpdate to version 0.3.3 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/01/GHSA-crmx-v835-hcp4/GHSA-crmx-v835-hcp4.json b/advisories/github-reviewed/2018/01/GHSA-crmx-v835-hcp4/GHSA-crmx-v835-hcp4.json
index 37c2af9f167..fa47e520fd4 100644
--- a/advisories/github-reviewed/2018/01/GHSA-crmx-v835-hcp4/GHSA-crmx-v835-hcp4.json
+++ b/advisories/github-reviewed/2018/01/GHSA-crmx-v835-hcp4/GHSA-crmx-v835-hcp4.json
@@ -9,9 +9,7 @@
],
"summary": "Moderate severity vulnerability that affects marked",
"details": "# Withdrawn\n\nThis advisory has been withdrawn, per NVD: [\"This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"](https://nvd.nist.gov/vuln/detail/CVE-2017-17461)\n\n# Original Description\n\nA Regular expression Denial of Service (ReDoS) vulnerability in the file marked.js of the marked npm package (tested on version 0.3.7) allows a remote attacker to overload and crash a server by passing a maliciously crafted string.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -44,9 +42,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:32:51Z",
diff --git a/advisories/github-reviewed/2018/07/GHSA-8hj4-w233-g35q/GHSA-8hj4-w233-g35q.json b/advisories/github-reviewed/2018/07/GHSA-8hj4-w233-g35q/GHSA-8hj4-w233-g35q.json
index e55e19243b3..7e903a6907c 100644
--- a/advisories/github-reviewed/2018/07/GHSA-8hj4-w233-g35q/GHSA-8hj4-w233-g35q.json
+++ b/advisories/github-reviewed/2018/07/GHSA-8hj4-w233-g35q/GHSA-8hj4-w233-g35q.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in react-native-baidu-voice-synthesizer",
"details": "Affected versions of `react-native-baidu-voice-synthesizer` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `react-native-baidu-voice-synthesizer`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/07/GHSA-ccq6-3qx5-vmqx/GHSA-ccq6-3qx5-vmqx.json b/advisories/github-reviewed/2018/07/GHSA-ccq6-3qx5-vmqx/GHSA-ccq6-3qx5-vmqx.json
index b7eaf378303..96ff42e2eb5 100644
--- a/advisories/github-reviewed/2018/07/GHSA-ccq6-3qx5-vmqx/GHSA-ccq6-3qx5-vmqx.json
+++ b/advisories/github-reviewed/2018/07/GHSA-ccq6-3qx5-vmqx/GHSA-ccq6-3qx5-vmqx.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:33:36Z",
"published": "2018-07-31T22:54:14Z",
"withdrawn": "2020-06-16T21:31:07Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects is-my-json-valid",
"details": "Withdrawn, accidental duplicate publish.\n\nThe is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:31:07Z",
diff --git a/advisories/github-reviewed/2018/07/GHSA-cgqv-x5cx-xvqh/GHSA-cgqv-x5cx-xvqh.json b/advisories/github-reviewed/2018/07/GHSA-cgqv-x5cx-xvqh/GHSA-cgqv-x5cx-xvqh.json
index 30ca0740821..41bba7a7102 100644
--- a/advisories/github-reviewed/2018/07/GHSA-cgqv-x5cx-xvqh/GHSA-cgqv-x5cx-xvqh.json
+++ b/advisories/github-reviewed/2018/07/GHSA-cgqv-x5cx-xvqh/GHSA-cgqv-x5cx-xvqh.json
@@ -8,9 +8,7 @@
],
"summary": "Arbitrary Code Injection in pouchdb",
"details": "Affected versions of `pouchdb` do not properly sandbox the code execution engine which executes the map/reduce functions for temporary views and design documents. Under certain circumstances, an attacker could uses this to run arbitrary code on the server.\n\n\n## Recommendation\n\nUpdate to version 6.0.5 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/07/GHSA-cr6c-85fh-cqpg/GHSA-cr6c-85fh-cqpg.json b/advisories/github-reviewed/2018/07/GHSA-cr6c-85fh-cqpg/GHSA-cr6c-85fh-cqpg.json
index 84511bd68c7..ce1845dd1c3 100644
--- a/advisories/github-reviewed/2018/07/GHSA-cr6c-85fh-cqpg/GHSA-cr6c-85fh-cqpg.json
+++ b/advisories/github-reviewed/2018/07/GHSA-cr6c-85fh-cqpg/GHSA-cr6c-85fh-cqpg.json
@@ -50,9 +50,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:32:38Z",
diff --git a/advisories/github-reviewed/2018/08/GHSA-995j-587r-259w/GHSA-995j-587r-259w.json b/advisories/github-reviewed/2018/08/GHSA-995j-587r-259w/GHSA-995j-587r-259w.json
index 024e14b125e..dbd9dd4a9c1 100644
--- a/advisories/github-reviewed/2018/08/GHSA-995j-587r-259w/GHSA-995j-587r-259w.json
+++ b/advisories/github-reviewed/2018/08/GHSA-995j-587r-259w/GHSA-995j-587r-259w.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:42:03Z",
"published": "2018-08-13T20:46:58Z",
"withdrawn": "2020-06-16T21:28:00Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects rack-mini-profiler",
"details": "Withdrawn, accidental duplicate publish.\n\nThe rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:28:00Z",
diff --git a/advisories/github-reviewed/2018/08/GHSA-9wv8-jgw4-4g28/GHSA-9wv8-jgw4-4g28.json b/advisories/github-reviewed/2018/08/GHSA-9wv8-jgw4-4g28/GHSA-9wv8-jgw4-4g28.json
index 4e6fa33f7bd..0fac6105d26 100644
--- a/advisories/github-reviewed/2018/08/GHSA-9wv8-jgw4-4g28/GHSA-9wv8-jgw4-4g28.json
+++ b/advisories/github-reviewed/2018/08/GHSA-9wv8-jgw4-4g28/GHSA-9wv8-jgw4-4g28.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:33:56Z",
"published": "2018-08-15T20:04:13Z",
"withdrawn": "2020-06-16T21:29:46Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "High severity vulnerability that affects festivaltts4r",
"details": "Withdrawn, accidental duplicate publish.\n\nThe festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2) to_mp3 method in lib/festivaltts4r/festival4r.rb.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -41,9 +37,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:29:46Z",
diff --git a/advisories/github-reviewed/2018/08/GHSA-cwp3-834g-x79g/GHSA-cwp3-834g-x79g.json b/advisories/github-reviewed/2018/08/GHSA-cwp3-834g-x79g/GHSA-cwp3-834g-x79g.json
index 10be411cb38..e403c559f34 100644
--- a/advisories/github-reviewed/2018/08/GHSA-cwp3-834g-x79g/GHSA-cwp3-834g-x79g.json
+++ b/advisories/github-reviewed/2018/08/GHSA-cwp3-834g-x79g/GHSA-cwp3-834g-x79g.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:39:02Z",
"published": "2018-08-21T17:07:36Z",
"withdrawn": "2020-06-16T21:33:06Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects archive-tar-minitar and minitar",
"details": "Withdrawn, accidental duplicate publish.\n\nDirectory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -63,9 +59,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:33:06Z",
diff --git a/advisories/github-reviewed/2018/09/GHSA-77pc-q5q7-qg9h/GHSA-77pc-q5q7-qg9h.json b/advisories/github-reviewed/2018/09/GHSA-77pc-q5q7-qg9h/GHSA-77pc-q5q7-qg9h.json
index d12ef402b76..6d6c4caa88b 100644
--- a/advisories/github-reviewed/2018/09/GHSA-77pc-q5q7-qg9h/GHSA-77pc-q5q7-qg9h.json
+++ b/advisories/github-reviewed/2018/09/GHSA-77pc-q5q7-qg9h/GHSA-77pc-q5q7-qg9h.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:37:28Z",
"published": "2018-09-17T21:58:30Z",
"withdrawn": "2020-06-16T21:21:56Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects rails-html-sanitizer",
"details": "Withdrawn, accidental duplicate publish.\n\nCross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:21:56Z",
diff --git a/advisories/github-reviewed/2018/09/GHSA-7phj-gmgx-2r66/GHSA-7phj-gmgx-2r66.json b/advisories/github-reviewed/2018/09/GHSA-7phj-gmgx-2r66/GHSA-7phj-gmgx-2r66.json
index fc738a4aee9..69fd23b75b5 100644
--- a/advisories/github-reviewed/2018/09/GHSA-7phj-gmgx-2r66/GHSA-7phj-gmgx-2r66.json
+++ b/advisories/github-reviewed/2018/09/GHSA-7phj-gmgx-2r66/GHSA-7phj-gmgx-2r66.json
@@ -4,14 +4,10 @@
"modified": "2021-12-03T14:24:43Z",
"published": "2018-09-17T21:58:09Z",
"withdrawn": "2020-06-16T21:23:09Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects activerecord",
"details": "Withdrawn, accidental duplicate publish.\n\nactiverecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -91,9 +87,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:23:09Z",
diff --git a/advisories/github-reviewed/2018/09/GHSA-9vc2-p34x-jhxh/GHSA-9vc2-p34x-jhxh.json b/advisories/github-reviewed/2018/09/GHSA-9vc2-p34x-jhxh/GHSA-9vc2-p34x-jhxh.json
index ae0d2fd83d6..ce919f6ccdf 100644
--- a/advisories/github-reviewed/2018/09/GHSA-9vc2-p34x-jhxh/GHSA-9vc2-p34x-jhxh.json
+++ b/advisories/github-reviewed/2018/09/GHSA-9vc2-p34x-jhxh/GHSA-9vc2-p34x-jhxh.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:54:47Z",
"published": "2018-09-17T21:56:30Z",
"withdrawn": "2020-06-16T21:29:41Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects rack",
"details": "Withdrawn, accidental duplicate publish.\n\nlib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -82,9 +78,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:29:41Z",
diff --git a/advisories/github-reviewed/2018/09/GHSA-c2vr-2c89-ph88/GHSA-c2vr-2c89-ph88.json b/advisories/github-reviewed/2018/09/GHSA-c2vr-2c89-ph88/GHSA-c2vr-2c89-ph88.json
index d5571477e0a..8d42adfe237 100644
--- a/advisories/github-reviewed/2018/09/GHSA-c2vr-2c89-ph88/GHSA-c2vr-2c89-ph88.json
+++ b/advisories/github-reviewed/2018/09/GHSA-c2vr-2c89-ph88/GHSA-c2vr-2c89-ph88.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in node-bsdiff-android",
"details": "Affected versions of `node-bsdiff-android` insecurely download resources over HTTP. \n\nIn scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package has not seen an update since 2014.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/10/GHSA-778x-2mqv-w6xw/GHSA-778x-2mqv-w6xw.json b/advisories/github-reviewed/2018/10/GHSA-778x-2mqv-w6xw/GHSA-778x-2mqv-w6xw.json
index 4261032657d..23fb6e9043b 100644
--- a/advisories/github-reviewed/2018/10/GHSA-778x-2mqv-w6xw/GHSA-778x-2mqv-w6xw.json
+++ b/advisories/github-reviewed/2018/10/GHSA-778x-2mqv-w6xw/GHSA-778x-2mqv-w6xw.json
@@ -8,9 +8,7 @@
],
"summary": "Moderate severity vulnerability that affects org.keycloak:keycloak-core",
"details": "Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/10/GHSA-7mc5-chhp-fmc3/GHSA-7mc5-chhp-fmc3.json b/advisories/github-reviewed/2018/10/GHSA-7mc5-chhp-fmc3/GHSA-7mc5-chhp-fmc3.json
index c9842e34c8f..7da3ac77037 100644
--- a/advisories/github-reviewed/2018/10/GHSA-7mc5-chhp-fmc3/GHSA-7mc5-chhp-fmc3.json
+++ b/advisories/github-reviewed/2018/10/GHSA-7mc5-chhp-fmc3/GHSA-7mc5-chhp-fmc3.json
@@ -8,9 +8,7 @@
],
"summary": "Regular Expression Denial of Service in negotiator",
"details": "Affected versions of `negotiator` are vulnerable to regular expression denial of service attacks, which trigger upon parsing a specially crafted `Accept-Language` header value.\n\n\n\n\n## Recommendation\n\nUpdate to version 0.6.1 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/10/GHSA-959q-32g8-vvp7/GHSA-959q-32g8-vvp7.json b/advisories/github-reviewed/2018/10/GHSA-959q-32g8-vvp7/GHSA-959q-32g8-vvp7.json
index 7103fe715d6..687ec7f2557 100644
--- a/advisories/github-reviewed/2018/10/GHSA-959q-32g8-vvp7/GHSA-959q-32g8-vvp7.json
+++ b/advisories/github-reviewed/2018/10/GHSA-959q-32g8-vvp7/GHSA-959q-32g8-vvp7.json
@@ -8,9 +8,7 @@
],
"summary": "Moderate severity vulnerability that affects org.keycloak:keycloak-core",
"details": "It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/10/GHSA-9gp4-qrff-c648/GHSA-9gp4-qrff-c648.json b/advisories/github-reviewed/2018/10/GHSA-9gp4-qrff-c648/GHSA-9gp4-qrff-c648.json
index 8e8bc49d6dd..d43feeac493 100644
--- a/advisories/github-reviewed/2018/10/GHSA-9gp4-qrff-c648/GHSA-9gp4-qrff-c648.json
+++ b/advisories/github-reviewed/2018/10/GHSA-9gp4-qrff-c648/GHSA-9gp4-qrff-c648.json
@@ -93,9 +93,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:28:32Z",
diff --git a/advisories/github-reviewed/2018/10/GHSA-c7hr-j4mj-j2w6/GHSA-c7hr-j4mj-j2w6.json b/advisories/github-reviewed/2018/10/GHSA-c7hr-j4mj-j2w6/GHSA-c7hr-j4mj-j2w6.json
index 01790ddaa02..7efb45ba09f 100644
--- a/advisories/github-reviewed/2018/10/GHSA-c7hr-j4mj-j2w6/GHSA-c7hr-j4mj-j2w6.json
+++ b/advisories/github-reviewed/2018/10/GHSA-c7hr-j4mj-j2w6/GHSA-c7hr-j4mj-j2w6.json
@@ -8,9 +8,7 @@
],
"summary": "Verification Bypass in jsonwebtoken",
"details": "Versions 4.2.1 and earlier of `jsonwebtoken` are affected by a verification bypass vulnerability. This is a result of weak validation of the JWT algorithm type, occuring when an attacker is allowed to arbitrarily specify the JWT algorithm.\n\n\n\n\n## Recommendation\n\nUpdate to version 4.2.2 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/10/GHSA-c8xf-m4ff-jcxj/GHSA-c8xf-m4ff-jcxj.json b/advisories/github-reviewed/2018/10/GHSA-c8xf-m4ff-jcxj/GHSA-c8xf-m4ff-jcxj.json
index 51a7ea4169e..206fc79a5bb 100644
--- a/advisories/github-reviewed/2018/10/GHSA-c8xf-m4ff-jcxj/GHSA-c8xf-m4ff-jcxj.json
+++ b/advisories/github-reviewed/2018/10/GHSA-c8xf-m4ff-jcxj/GHSA-c8xf-m4ff-jcxj.json
@@ -97,9 +97,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:30:37Z",
diff --git a/advisories/github-reviewed/2018/10/GHSA-cgpw-2gph-2r9g/GHSA-cgpw-2gph-2r9g.json b/advisories/github-reviewed/2018/10/GHSA-cgpw-2gph-2r9g/GHSA-cgpw-2gph-2r9g.json
index c5036b30604..465a906401d 100644
--- a/advisories/github-reviewed/2018/10/GHSA-cgpw-2gph-2r9g/GHSA-cgpw-2gph-2r9g.json
+++ b/advisories/github-reviewed/2018/10/GHSA-cgpw-2gph-2r9g/GHSA-cgpw-2gph-2r9g.json
@@ -3,14 +3,10 @@
"id": "GHSA-cgpw-2gph-2r9g",
"modified": "2021-12-03T14:28:10Z",
"published": "2018-10-16T19:59:59Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Moderate severity vulnerability that affects Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, and Microsoft.AspNetCore.Server.Kestrel.Core",
"details": "Microsoft is aware of a denial of service vulnerability in ASP.NET Core when a malformed request is terminated. An attacker who successfully exploited this vulnerability could cause a denial of service attack.\n\nThe update addresses the vulnerability by correcting how ASP.NET Core handles such requests.\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -119,9 +115,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:31:39Z",
diff --git a/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json b/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json
index 77f69e54842..82a4d41ee63 100644
--- a/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json
+++ b/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json
@@ -4,14 +4,10 @@
"modified": "2020-06-16T21:43:40Z",
"published": "2018-10-09T00:44:29Z",
"withdrawn": "2020-06-16T21:32:53Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "High severity vulnerability that affects qs",
"details": "Withdrawn, accidental duplicate publish.\n\nThe qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:32:53Z",
diff --git a/advisories/github-reviewed/2018/10/GHSA-f9cm-p3w6-xvr3/GHSA-f9cm-p3w6-xvr3.json b/advisories/github-reviewed/2018/10/GHSA-f9cm-p3w6-xvr3/GHSA-f9cm-p3w6-xvr3.json
index 9c71b05eaaf..bd974ac08e7 100644
--- a/advisories/github-reviewed/2018/10/GHSA-f9cm-p3w6-xvr3/GHSA-f9cm-p3w6-xvr3.json
+++ b/advisories/github-reviewed/2018/10/GHSA-f9cm-p3w6-xvr3/GHSA-f9cm-p3w6-xvr3.json
@@ -8,9 +8,7 @@
],
"summary": "Denial-of-Service Extended Event Loop Blocking in qs",
"details": "Versions prior to 1.0.0 of `qs` are affected by a denial of service vulnerability that results from excessive recursion in parsing a deeply nested JSON string.\n\n\n\n\n## Recommendation\n\nUpdate to version 1.0.0 or later",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/10/GHSA-fjqm-246c-mwqg/GHSA-fjqm-246c-mwqg.json b/advisories/github-reviewed/2018/10/GHSA-fjqm-246c-mwqg/GHSA-fjqm-246c-mwqg.json
index 12afa5bc8e5..ad4bcc59a07 100644
--- a/advisories/github-reviewed/2018/10/GHSA-fjqm-246c-mwqg/GHSA-fjqm-246c-mwqg.json
+++ b/advisories/github-reviewed/2018/10/GHSA-fjqm-246c-mwqg/GHSA-fjqm-246c-mwqg.json
@@ -97,9 +97,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:34:48Z",
diff --git a/advisories/github-reviewed/2018/11/GHSA-f7ph-p5rv-phw2/GHSA-f7ph-p5rv-phw2.json b/advisories/github-reviewed/2018/11/GHSA-f7ph-p5rv-phw2/GHSA-f7ph-p5rv-phw2.json
index 10fbfdc04c7..5153a8e883f 100644
--- a/advisories/github-reviewed/2018/11/GHSA-f7ph-p5rv-phw2/GHSA-f7ph-p5rv-phw2.json
+++ b/advisories/github-reviewed/2018/11/GHSA-f7ph-p5rv-phw2/GHSA-f7ph-p5rv-phw2.json
@@ -8,9 +8,7 @@
],
"summary": "Cross-Site Scripting in nunjucks",
"details": "Affected versions of `nunjucks` do not properly escape specially structured user input in template vars when in auto-escape mode, resulting in a cross-site scripting vulnerability.\n\n## Proof of Concept\n\nBy using an array for the keys in a template var, escaping is bypassed.\n```javascript\nname[]=\n```\n\nA full PoC is available in the references section.\n\n\n## Recommendation\n\nUpdate to version 2.4.3 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2018/11/GHSA-fwx5-5fqj-jv98/GHSA-fwx5-5fqj-jv98.json b/advisories/github-reviewed/2018/11/GHSA-fwx5-5fqj-jv98/GHSA-fwx5-5fqj-jv98.json
index 0792938ab26..be93fb474a1 100644
--- a/advisories/github-reviewed/2018/11/GHSA-fwx5-5fqj-jv98/GHSA-fwx5-5fqj-jv98.json
+++ b/advisories/github-reviewed/2018/11/GHSA-fwx5-5fqj-jv98/GHSA-fwx5-5fqj-jv98.json
@@ -8,9 +8,7 @@
],
"summary": "Cross-Site Scripting in morris.js",
"details": "Affected versions of `morris.js` are vulnerable to cross-site scripting attacks in labels that appear when hovering over a particular point on a generated graph. The text content of these labels is not escaped, so if control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.\n\n\n## Recommendation\n\nA patch for this vulnerability was created in 2014, but has still not been published to npm. In order to mitigate this issue effectively, install the library from github via:\n```\nnpm i morrisjs/morris.js -s\n```",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-769c-qphh-g3wm/GHSA-769c-qphh-g3wm.json b/advisories/github-reviewed/2019/02/GHSA-769c-qphh-g3wm/GHSA-769c-qphh-g3wm.json
index 8e469858e7a..bcc3c6a896b 100644
--- a/advisories/github-reviewed/2019/02/GHSA-769c-qphh-g3wm/GHSA-769c-qphh-g3wm.json
+++ b/advisories/github-reviewed/2019/02/GHSA-769c-qphh-g3wm/GHSA-769c-qphh-g3wm.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in macaca-chromedriver",
"details": "Affected versions of `macaca-chromedriver` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `macaca-chromedriver`.\n\n\n## Recommendation\n\nUpdate to version 1.0.29 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-7c9w-qmrq-ff8r/GHSA-7c9w-qmrq-ff8r.json b/advisories/github-reviewed/2019/02/GHSA-7c9w-qmrq-ff8r/GHSA-7c9w-qmrq-ff8r.json
index cecd5ae855d..5a9988e782a 100644
--- a/advisories/github-reviewed/2019/02/GHSA-7c9w-qmrq-ff8r/GHSA-7c9w-qmrq-ff8r.json
+++ b/advisories/github-reviewed/2019/02/GHSA-7c9w-qmrq-ff8r/GHSA-7c9w-qmrq-ff8r.json
@@ -8,9 +8,7 @@
],
"summary": "Path Traversal in http-live-simulator",
"details": "Versions of `http-live-simulator` prior to 1.0.7 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. For example: `curl --path-as-is http://localhost:8080//../../../../etc/passwd`.\n\n\n## Recommendation\n\nUpgrade to version 1.0.7",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-7r8m-45gc-m2c8/GHSA-7r8m-45gc-m2c8.json b/advisories/github-reviewed/2019/02/GHSA-7r8m-45gc-m2c8/GHSA-7r8m-45gc-m2c8.json
index 6138663862d..2c7fa8ac5e5 100644
--- a/advisories/github-reviewed/2019/02/GHSA-7r8m-45gc-m2c8/GHSA-7r8m-45gc-m2c8.json
+++ b/advisories/github-reviewed/2019/02/GHSA-7r8m-45gc-m2c8/GHSA-7r8m-45gc-m2c8.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in mongodb-instance",
"details": "Affected versions of `mongodb-instance` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `mongodb-instance`.\n\n\n## Recommendation\n\nUpdate to version 0.0.3 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-7vrq-vg6p-32fw/GHSA-7vrq-vg6p-32fw.json b/advisories/github-reviewed/2019/02/GHSA-7vrq-vg6p-32fw/GHSA-7vrq-vg6p-32fw.json
index 9f6be1c6468..d5767662a60 100644
--- a/advisories/github-reviewed/2019/02/GHSA-7vrq-vg6p-32fw/GHSA-7vrq-vg6p-32fw.json
+++ b/advisories/github-reviewed/2019/02/GHSA-7vrq-vg6p-32fw/GHSA-7vrq-vg6p-32fw.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in libxl",
"details": "Affected versions of `libxl` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `libxl`.\n\n\n## Recommendation\n\nThe module author recommends installing the bindings using a pinned and verified version of SDK instead of the automated download. More information is available in the modules [README](https://www.npmjs.com/package/libxl).",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-7xvg-m3vx-2hhv/GHSA-7xvg-m3vx-2hhv.json b/advisories/github-reviewed/2019/02/GHSA-7xvg-m3vx-2hhv/GHSA-7xvg-m3vx-2hhv.json
index 5cddb9d058a..09872c4da25 100644
--- a/advisories/github-reviewed/2019/02/GHSA-7xvg-m3vx-2hhv/GHSA-7xvg-m3vx-2hhv.json
+++ b/advisories/github-reviewed/2019/02/GHSA-7xvg-m3vx-2hhv/GHSA-7xvg-m3vx-2hhv.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in webrtc-native",
"details": "Affected versions of `webrtc-native` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `webrtc-native`.\n\n\n## Recommendation\n\nNo direct patch is currently available for this vulnerability. \n\nHowever, if the native components of `webrtc-native` are built from source, this avoids download the precompiled binary, therefore mitigating the insecure download. \n\nThe package author has provided instructions for building from source [here](https://github.com/vmolsa/webrtc-native/wiki/Getting-started#building-from-source).",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-84fv-prrc-5ggr/GHSA-84fv-prrc-5ggr.json b/advisories/github-reviewed/2019/02/GHSA-84fv-prrc-5ggr/GHSA-84fv-prrc-5ggr.json
index 7f779933193..fcda31cf4f6 100644
--- a/advisories/github-reviewed/2019/02/GHSA-84fv-prrc-5ggr/GHSA-84fv-prrc-5ggr.json
+++ b/advisories/github-reviewed/2019/02/GHSA-84fv-prrc-5ggr/GHSA-84fv-prrc-5ggr.json
@@ -8,9 +8,7 @@
],
"summary": "Route Validation Bypass in call",
"details": "Affected versions of `call` do not validate empty parameters, which may result in a bypass of route validation rules. \n\n## Proof of Concept\n\nRouting Scheme:\n```\n/api/{param}/{param2}/details\n```\nTriggering Request Path:\n```\n/api///\n```\n\n\n## Recommendation\n\nUpdate to version 3.0.2 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-856x-cp3q-47vg/GHSA-856x-cp3q-47vg.json b/advisories/github-reviewed/2019/02/GHSA-856x-cp3q-47vg/GHSA-856x-cp3q-47vg.json
index 4582a58cd08..5547bb18019 100644
--- a/advisories/github-reviewed/2019/02/GHSA-856x-cp3q-47vg/GHSA-856x-cp3q-47vg.json
+++ b/advisories/github-reviewed/2019/02/GHSA-856x-cp3q-47vg/GHSA-856x-cp3q-47vg.json
@@ -8,9 +8,7 @@
],
"summary": "Insecure Default Configuration in airbrake",
"details": "Affected versions of `airbrake` default to sending environment variables over an unencrypted HTTP connection. In scenarios where an attacker has a privileged network position, it is possible for them to capture and read these environment variables, which may result in leaking sensitive information.\n\n\n## Recommendation\n\nUpdate to version 0.4.0 or later, or upgrade from the now-deprecated `airbrake` module to its replacement, [`airbrake-js`](https://www.npmjs.com/package/airbrake-js).",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-87g3-x896-w798/GHSA-87g3-x896-w798.json b/advisories/github-reviewed/2019/02/GHSA-87g3-x896-w798/GHSA-87g3-x896-w798.json
index b7b0afa1950..f201561b447 100644
--- a/advisories/github-reviewed/2019/02/GHSA-87g3-x896-w798/GHSA-87g3-x896-w798.json
+++ b/advisories/github-reviewed/2019/02/GHSA-87g3-x896-w798/GHSA-87g3-x896-w798.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in atom-node-module-installer",
"details": "Affected versions of `atom-node-module-installer` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `atom-node-module-installer`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package has not been updated since 2014.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-8mrf-g42m-5qc8/GHSA-8mrf-g42m-5qc8.json b/advisories/github-reviewed/2019/02/GHSA-8mrf-g42m-5qc8/GHSA-8mrf-g42m-5qc8.json
index eebab512235..0b07bf21bb8 100644
--- a/advisories/github-reviewed/2019/02/GHSA-8mrf-g42m-5qc8/GHSA-8mrf-g42m-5qc8.json
+++ b/advisories/github-reviewed/2019/02/GHSA-8mrf-g42m-5qc8/GHSA-8mrf-g42m-5qc8.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in dalek-browser-chrome-canary",
"details": "Affected versions of `dalek-browser-chrome-canary` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `dalek-browser-chrome-canary`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-8p52-7cxv-6c95/GHSA-8p52-7cxv-6c95.json b/advisories/github-reviewed/2019/02/GHSA-8p52-7cxv-6c95/GHSA-8p52-7cxv-6c95.json
index f88c0659ed3..f977a09da23 100644
--- a/advisories/github-reviewed/2019/02/GHSA-8p52-7cxv-6c95/GHSA-8p52-7cxv-6c95.json
+++ b/advisories/github-reviewed/2019/02/GHSA-8p52-7cxv-6c95/GHSA-8p52-7cxv-6c95.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in curses",
"details": "Affected versions of `curses` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `curses`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package has not been updated since 2013.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-98pq-pmw9-4gpm/GHSA-98pq-pmw9-4gpm.json b/advisories/github-reviewed/2019/02/GHSA-98pq-pmw9-4gpm/GHSA-98pq-pmw9-4gpm.json
index c885b92c172..c7b53f2e7fe 100644
--- a/advisories/github-reviewed/2019/02/GHSA-98pq-pmw9-4gpm/GHSA-98pq-pmw9-4gpm.json
+++ b/advisories/github-reviewed/2019/02/GHSA-98pq-pmw9-4gpm/GHSA-98pq-pmw9-4gpm.json
@@ -8,9 +8,7 @@
],
"summary": "SQL Injection in sequelize",
"details": "Affected versions of `sequelize` are vulnerable to SQL Injection in locations where user input is passed into the `limit` or `order` parameters of `sequelize` query calls, such as `findOne` or `findAll`.\n\n\n\n## Recommendation\n\nUpdate to version 3.17.0 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-cgpp-wm2h-6hqx/GHSA-cgpp-wm2h-6hqx.json b/advisories/github-reviewed/2019/02/GHSA-cgpp-wm2h-6hqx/GHSA-cgpp-wm2h-6hqx.json
index 2ebe9765074..04317e9abfc 100644
--- a/advisories/github-reviewed/2019/02/GHSA-cgpp-wm2h-6hqx/GHSA-cgpp-wm2h-6hqx.json
+++ b/advisories/github-reviewed/2019/02/GHSA-cgpp-wm2h-6hqx/GHSA-cgpp-wm2h-6hqx.json
@@ -8,9 +8,7 @@
],
"summary": "SQL Injection in waterline-sequel",
"details": "Affected versions of `waterline-sequel` are vulnerable to SQL injection in cases where user input is passed into the `like`, `contains`, `startsWith`, or `endsWith` methods.\n\n\n\n## Recommendation\n\nUpgrade to at least version 0.5.1",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-cmj2-m9m2-6726/GHSA-cmj2-m9m2-6726.json b/advisories/github-reviewed/2019/02/GHSA-cmj2-m9m2-6726/GHSA-cmj2-m9m2-6726.json
index d4650745c66..f0ab8982bb1 100644
--- a/advisories/github-reviewed/2019/02/GHSA-cmj2-m9m2-6726/GHSA-cmj2-m9m2-6726.json
+++ b/advisories/github-reviewed/2019/02/GHSA-cmj2-m9m2-6726/GHSA-cmj2-m9m2-6726.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in grunt-ccompiler",
"details": "Affected versions of `grunt-ccompiler` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `grunt-ccompiler`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the repository has been deleted from the owner's github account.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-cr79-9pwf-r6f5/GHSA-cr79-9pwf-r6f5.json b/advisories/github-reviewed/2019/02/GHSA-cr79-9pwf-r6f5/GHSA-cr79-9pwf-r6f5.json
index 1fd5d1bb344..a406d8317c3 100644
--- a/advisories/github-reviewed/2019/02/GHSA-cr79-9pwf-r6f5/GHSA-cr79-9pwf-r6f5.json
+++ b/advisories/github-reviewed/2019/02/GHSA-cr79-9pwf-r6f5/GHSA-cr79-9pwf-r6f5.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in prince",
"details": "Affected versions of `prince` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `prince`.\n\n\n## Recommendation\n\nUpdate to version 1.4.6 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-cwp7-92h5-82wx/GHSA-cwp7-92h5-82wx.json b/advisories/github-reviewed/2019/02/GHSA-cwp7-92h5-82wx/GHSA-cwp7-92h5-82wx.json
index 5785c79b4b2..175ca2a0be0 100644
--- a/advisories/github-reviewed/2019/02/GHSA-cwp7-92h5-82wx/GHSA-cwp7-92h5-82wx.json
+++ b/advisories/github-reviewed/2019/02/GHSA-cwp7-92h5-82wx/GHSA-cwp7-92h5-82wx.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in haxe-dev",
"details": "Affected versions of `haxe-dev` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `haxe-dev`.\n\n\n## Recommendation\n\nThis package is actively maintained, yet after 2 years, the maintainer has not provided a patch for the vulnerability. This likely means that the maintainer has decided to accept the risk, and this vulnerability will never be patched.\n\nBecause of this, the best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-f5mh-hq6h-whxv/GHSA-f5mh-hq6h-whxv.json b/advisories/github-reviewed/2019/02/GHSA-f5mh-hq6h-whxv/GHSA-f5mh-hq6h-whxv.json
index 3618cca2aed..98f77632369 100644
--- a/advisories/github-reviewed/2019/02/GHSA-f5mh-hq6h-whxv/GHSA-f5mh-hq6h-whxv.json
+++ b/advisories/github-reviewed/2019/02/GHSA-f5mh-hq6h-whxv/GHSA-f5mh-hq6h-whxv.json
@@ -8,9 +8,7 @@
],
"summary": "Directory Traversal in bitty",
"details": "Affected versions of `bitty` are vulnerable to directory traversal via the URL path in GET requests.\n\n\n## Recommendation\n\nThe `bitty` package is not currently maintained, and has not seen an update since 2015. \n\nAt this time, the best available mitigation is to use an alternative module that is actively maintained and provides similar functionality, such as [serve](https://www.npmjs.com/package/serve).",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-ff29-f57w-2mm3/GHSA-ff29-f57w-2mm3.json b/advisories/github-reviewed/2019/02/GHSA-ff29-f57w-2mm3/GHSA-ff29-f57w-2mm3.json
index 8ef975ae4c1..36163020ce8 100644
--- a/advisories/github-reviewed/2019/02/GHSA-ff29-f57w-2mm3/GHSA-ff29-f57w-2mm3.json
+++ b/advisories/github-reviewed/2019/02/GHSA-ff29-f57w-2mm3/GHSA-ff29-f57w-2mm3.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in geoip-lite-country",
"details": "Affected versions of `geoip-lite-country` insecurely downloads resources over HTTP. \n\nIn scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution.\n\n\n## Recommendation\n\nUpdate to version 1.1.4 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-fwhp-2hqr-6g72/GHSA-fwhp-2hqr-6g72.json b/advisories/github-reviewed/2019/02/GHSA-fwhp-2hqr-6g72/GHSA-fwhp-2hqr-6g72.json
index 19d8ba0bdda..faa270cdb20 100644
--- a/advisories/github-reviewed/2019/02/GHSA-fwhp-2hqr-6g72/GHSA-fwhp-2hqr-6g72.json
+++ b/advisories/github-reviewed/2019/02/GHSA-fwhp-2hqr-6g72/GHSA-fwhp-2hqr-6g72.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in pk-app-wonderbox",
"details": "Affected versions of `pk-app-wonderbox` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `pk-app-wonderbox`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-g2pf-qjgf-6fw3/GHSA-g2pf-qjgf-6fw3.json b/advisories/github-reviewed/2019/02/GHSA-g2pf-qjgf-6fw3/GHSA-g2pf-qjgf-6fw3.json
index f144c038c12..0db59f40d7c 100644
--- a/advisories/github-reviewed/2019/02/GHSA-g2pf-qjgf-6fw3/GHSA-g2pf-qjgf-6fw3.json
+++ b/advisories/github-reviewed/2019/02/GHSA-g2pf-qjgf-6fw3/GHSA-g2pf-qjgf-6fw3.json
@@ -8,9 +8,7 @@
],
"summary": "Downloads Resources over HTTP in openframe-glslviewer",
"details": "Affected versions of `openframe-glslviewer` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `openframe-glslviewer`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package hasn't been updated since 2014.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/02/GHSA-g3r2-65gc-qpqc/GHSA-g3r2-65gc-qpqc.json b/advisories/github-reviewed/2019/02/GHSA-g3r2-65gc-qpqc/GHSA-g3r2-65gc-qpqc.json
index 3f2c765465d..e891ae4afac 100644
--- a/advisories/github-reviewed/2019/02/GHSA-g3r2-65gc-qpqc/GHSA-g3r2-65gc-qpqc.json
+++ b/advisories/github-reviewed/2019/02/GHSA-g3r2-65gc-qpqc/GHSA-g3r2-65gc-qpqc.json
@@ -8,9 +8,7 @@
],
"summary": "Denial of Service in mqtt-packet",
"details": "Versions of `mqtt-packet` prior to 3.4.6, or 4.x prior to 4.0.5 are affected by a denial of service vulnerability wherein specific sequences of MQTT packets can crash the application.\n\n\n\n\n## Recommendation\n\nVersion 3.x: Update to version 3.4.6 or later.\nVersion 4.x: Update to version 4.0.5 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/06/GHSA-886v-mm6p-4m66/GHSA-886v-mm6p-4m66.json b/advisories/github-reviewed/2019/06/GHSA-886v-mm6p-4m66/GHSA-886v-mm6p-4m66.json
index dde0da13c9f..47784662970 100644
--- a/advisories/github-reviewed/2019/06/GHSA-886v-mm6p-4m66/GHSA-886v-mm6p-4m66.json
+++ b/advisories/github-reviewed/2019/06/GHSA-886v-mm6p-4m66/GHSA-886v-mm6p-4m66.json
@@ -3,14 +3,10 @@
"id": "GHSA-886v-mm6p-4m66",
"modified": "2021-09-07T15:24:35Z",
"published": "2019-06-05T09:48:02Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "High severity vulnerability that affects gun",
"details": "## Urgent Upgrade\n\nThe static file server module included with GUN had a **serious vulnerability**:\n\n - Using `curl --path-as-is` allowed reads on any parent directory or files.\n\nThis did not work via the browser or via curl without as-is option.\n\n ### Fixed\n\nThis has been fixed since version `0.2019.416` and higher.\n\n ### Who Was Effected?\n\nMost NodeJS users who use the default setup, such as:\n\n - `npm start`\n - `node examples/http.js`\n - `Heroku` 1-click-deploy\n - `Docker`\n - `Now`\n\nIf you have a custom NodeJS code then you are probably safe *unless* you have something like `require('http').createServer(Gun.serve(__dirname))` in it.\n\nIf you have not upgraded, it is **mandatory** or else it is highly likely your environment variables and AWS (or other) keys could be leaked.\n\n ### Credit\n\nIt was reported and fixed by [JK0N](https://github.com/amark/gun/pull/527), but I did not understand the `--path-as-is` condition.\n\nJoonas Loppi from [function61](http://function61.com) rediscovered it and explained the urgency to me to fix it.\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2019/09/GHSA-9mrq-cjgh-32g2/GHSA-9mrq-cjgh-32g2.json b/advisories/github-reviewed/2019/09/GHSA-9mrq-cjgh-32g2/GHSA-9mrq-cjgh-32g2.json
index f61a5cdeb52..6c3e0533371 100644
--- a/advisories/github-reviewed/2019/09/GHSA-9mrq-cjgh-32g2/GHSA-9mrq-cjgh-32g2.json
+++ b/advisories/github-reviewed/2019/09/GHSA-9mrq-cjgh-32g2/GHSA-9mrq-cjgh-32g2.json
@@ -3,14 +3,10 @@
"id": "GHSA-9mrq-cjgh-32g2",
"modified": "2021-12-03T14:38:19Z",
"published": "2019-09-13T13:22:33Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Low severity vulnerability that affects smartbanner.js",
"details": "## rel noopener vulnerability\n\n### Impact\nClicking on smartbanner _View_ link and navigating to 3rd party page leaves `window.opener` exposed. It may allow hostile 3rd parties to abuse `window.opener`, e.g. by redirection or injection on the original page with smartbanner.\n\n### Patches\n`rel=\"noopener\"` is automatically populated to links as of `v1.14.1` which is a recommended upgrade to resolve the vulnerability.\n\n### Workarounds\nIf you can not upgrade to `v1.14.1`:\n1. Ensure _View_ link is only taking users to App Store or Google Play Store where security is guarded by respective app store security teams\n2. If _View_ link is going to a 3rd party page, limit smartbanner.js to be used on iOS that decreases the scope of the vulnerability since as of Safari 12.1, `rel=\"noopener\"` is imposed on all `target=\"_blank\"` links.\n\n Following combination of smartbanner meta tags can be used to achieve the above:\n\n ```html\n \n \n ```\n\n### References\n* [About rel=noopener](https://mathiasbynens.github.io/rel-noopener/)\n* [Safari 12.1 Release Notes](https://developer.apple.com/documentation/safari_release_notes/safari_12_1_release_notes#3130296)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [smartbanner.js](https://github.com/ain/smartbanner.js/issues/new)\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:29:02Z",
diff --git a/advisories/github-reviewed/2019/09/GHSA-cxw4-9qv9-vx5h/GHSA-cxw4-9qv9-vx5h.json b/advisories/github-reviewed/2019/09/GHSA-cxw4-9qv9-vx5h/GHSA-cxw4-9qv9-vx5h.json
index be6ca79b28d..794d3dfcf41 100644
--- a/advisories/github-reviewed/2019/09/GHSA-cxw4-9qv9-vx5h/GHSA-cxw4-9qv9-vx5h.json
+++ b/advisories/github-reviewed/2019/09/GHSA-cxw4-9qv9-vx5h/GHSA-cxw4-9qv9-vx5h.json
@@ -3,14 +3,10 @@
"id": "GHSA-cxw4-9qv9-vx5h",
"modified": "2022-01-18T23:06:09Z",
"published": "2019-09-30T19:42:28Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "High severity vulnerability that affects PeterO.Cbor",
"details": "### Impact\nThe CBOR library supports optional tags that enable CBOR objects to contain references to objects within them. Versions earlier than 4.0 resolved those references automatically. While this by itself doesn't cause much of a security problem, a denial of service can happen if those references are deeply nested and used multiple times (so that the same reference to the same object occurs multiple times), and if the decoded CBOR object is sent to a serialization method such as `EncodeToBytes`, `ToString`, or `ToJSONString`, since the objects referred to are expanded in the process and take up orders of magnitude more memory than if the references weren't resolved.\n\nThe impact of this problem on any particular system varies. In general, the risk is higher if the system allows users to send arbitrary CBOR objects without authentication, or exposes a remote endpoint in which arbitrary CBOR objects can be sent without authentication.\n\n### Patches\nThis problem is addressed in version 4.0 by disabling reference resolution by default. Users should use the latest version of this library.\n\n### Workarounds\nSince version 3.6, an encoding option (`resolvereferences=true` or `resolvereferences=false`) in CBOREncodeOptions sets whether the CBOR processor will resolve these kinds of references when decoding a CBOR object. Set `resolvereferences=false` to disable reference resolution.\n\nIn version 3.6, if the method used `CBORObject.Read()` or `CBORObject.DecodeFromBytes()` to decode a serialized CBOR object, call the overload that takes `CBOREncodeOptions` as follows:\n\n CBORObject.DecodeFromBytes(bytes, new CBOREncodeOptions(\"resolvereferences=false\"));\n\nIn versions 3.5 and earlier, this issue is present only if the CBOR object is an array or a map. If the application does not expect a decoded CBOR object to be an array or a map, it should check the CBOR object's type before encoding that object, as follows:\n\n if (cbor.Type != CBORType.Array && cbor.Type != CBORType.Map) {\n cbor.EncodeToBytes();\n }\n\nAlternatively, for such versions, the application can use `WriteTo` to decode the CBOR object to a so-called \"limited memory stream\", that is, a `Stream` that throws an exception if too many bytes would be written. How to write such a limited-memory stream is nontrivial and beyond the scope of this advisory.\n\n using(var stream = new LimitedMemoryStream(100000)) { // Limit to 100000 bytes\n cbor.WriteTo(stream);\n return stream.ToBytes();\n }\n\nTo check whether a byte array representing a CBOR object might exhibit this problem, check whether the array contains the byte 0xd8 followed immediately by either 0x19 or 0x1d. This check catches all affected CBOR objects but may catch some non-affected CBOR objects (notably integers and byte strings).\n\n### References\n\nSee the Wikipedia article [Billion laughs attack](https://en.wikipedia.org/wiki/Billion_laughs_attack) and the related issue in [Kubernetes](https://github.com/kubernetes/kubernetes/issues/83253).\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the CBOR repository](https://github.com/peteroupc/CBOR).\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:33:21Z",
diff --git a/advisories/github-reviewed/2019/10/GHSA-7cg8-pq9v-x98q/GHSA-7cg8-pq9v-x98q.json b/advisories/github-reviewed/2019/10/GHSA-7cg8-pq9v-x98q/GHSA-7cg8-pq9v-x98q.json
index 996882d82df..3e2d63af1bc 100644
--- a/advisories/github-reviewed/2019/10/GHSA-7cg8-pq9v-x98q/GHSA-7cg8-pq9v-x98q.json
+++ b/advisories/github-reviewed/2019/10/GHSA-7cg8-pq9v-x98q/GHSA-7cg8-pq9v-x98q.json
@@ -3,9 +3,7 @@
"id": "GHSA-7cg8-pq9v-x98q",
"modified": "2021-09-02T21:14:19Z",
"published": "2019-10-21T21:58:55Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Sandbox Breakout in realms-shim",
"details": "Versions of `realms-shim` prior to 1.2.1 are vulnerable to a Sandbox Breakout. The Realms evaluation function has an option to apply Babel-like transformations to the source code before it reaches the evaluator. One portion of this transform pipeline exposed a primal-Realm object to the rewriting function. Confined code which used the evaluator itself could provide a malicious rewriter function that captured this object, and use it to breach the sandbox.\n\n\n## Recommendation\n\nUpgrade to version 1.2.1 or later.",
"severity": [
@@ -58,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:22:25Z",
diff --git a/advisories/github-reviewed/2022/04/GHSA-v62p-cjv8-35xh/GHSA-v62p-cjv8-35xh.json b/advisories/github-reviewed/2022/04/GHSA-v62p-cjv8-35xh/GHSA-v62p-cjv8-35xh.json
index 6853e8bbe7e..401bfdc16cc 100644
--- a/advisories/github-reviewed/2022/04/GHSA-v62p-cjv8-35xh/GHSA-v62p-cjv8-35xh.json
+++ b/advisories/github-reviewed/2022/04/GHSA-v62p-cjv8-35xh/GHSA-v62p-cjv8-35xh.json
@@ -8,9 +8,7 @@
],
"summary": "Tahoe-LAFS fails to ensure integrity",
"details": "Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -61,9 +59,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-11-21T23:19:17Z",
diff --git a/advisories/github-reviewed/2022/05/GHSA-6rrm-xxvh-7r87/GHSA-6rrm-xxvh-7r87.json b/advisories/github-reviewed/2022/05/GHSA-6rrm-xxvh-7r87/GHSA-6rrm-xxvh-7r87.json
index 71418b6d31d..a82752e6657 100644
--- a/advisories/github-reviewed/2022/05/GHSA-6rrm-xxvh-7r87/GHSA-6rrm-xxvh-7r87.json
+++ b/advisories/github-reviewed/2022/05/GHSA-6rrm-xxvh-7r87/GHSA-6rrm-xxvh-7r87.json
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Glance arbitrary deletion of non-protected images",
"details": "The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -115,9 +113,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-12T20:29:57Z",
diff --git a/advisories/github-reviewed/2022/05/GHSA-8c7c-2c8j-3xfp/GHSA-8c7c-2c8j-3xfp.json b/advisories/github-reviewed/2022/05/GHSA-8c7c-2c8j-3xfp/GHSA-8c7c-2c8j-3xfp.json
index a66f732d198..9da12d9b337 100644
--- a/advisories/github-reviewed/2022/05/GHSA-8c7c-2c8j-3xfp/GHSA-8c7c-2c8j-3xfp.json
+++ b/advisories/github-reviewed/2022/05/GHSA-8c7c-2c8j-3xfp/GHSA-8c7c-2c8j-3xfp.json
@@ -8,9 +8,7 @@
],
"summary": "blosc2 heap-based buffer overflow",
"details": "blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2022/05/GHSA-hm8g-jxjj-gfm3/GHSA-hm8g-jxjj-gfm3.json b/advisories/github-reviewed/2022/05/GHSA-hm8g-jxjj-gfm3/GHSA-hm8g-jxjj-gfm3.json
index 22b233920b1..dd1b59f073b 100644
--- a/advisories/github-reviewed/2022/05/GHSA-hm8g-jxjj-gfm3/GHSA-hm8g-jxjj-gfm3.json
+++ b/advisories/github-reviewed/2022/05/GHSA-hm8g-jxjj-gfm3/GHSA-hm8g-jxjj-gfm3.json
@@ -8,9 +8,7 @@
],
"summary": "Zope allows remote attackers to read arbitrary files",
"details": "The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -78,9 +76,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-11-21T23:19:22Z",
diff --git a/advisories/github-reviewed/2022/05/GHSA-j772-hpmw-32rm/GHSA-j772-hpmw-32rm.json b/advisories/github-reviewed/2022/05/GHSA-j772-hpmw-32rm/GHSA-j772-hpmw-32rm.json
index cfea5bbeaef..c5d8378f6b3 100644
--- a/advisories/github-reviewed/2022/05/GHSA-j772-hpmw-32rm/GHSA-j772-hpmw-32rm.json
+++ b/advisories/github-reviewed/2022/05/GHSA-j772-hpmw-32rm/GHSA-j772-hpmw-32rm.json
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Horizon Cross-site scripting (XSS) vulnerability",
"details": "Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in `horizon/static/horizon/js/horizon.js` in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json b/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json
index 9b2f2fac3e6..b8a93e3b5b5 100644
--- a/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json
+++ b/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json
@@ -8,9 +8,7 @@
],
"summary": "Zope allows local users to read arbitrary files",
"details": "Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the \"raw\" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -105,9 +103,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-11-21T22:13:08Z",
diff --git a/advisories/github-reviewed/2022/05/GHSA-qvpr-qm6w-6rcc/GHSA-qvpr-qm6w-6rcc.json b/advisories/github-reviewed/2022/05/GHSA-qvpr-qm6w-6rcc/GHSA-qvpr-qm6w-6rcc.json
index 13ef96a1603..a4be940cf29 100644
--- a/advisories/github-reviewed/2022/05/GHSA-qvpr-qm6w-6rcc/GHSA-qvpr-qm6w-6rcc.json
+++ b/advisories/github-reviewed/2022/05/GHSA-qvpr-qm6w-6rcc/GHSA-qvpr-qm6w-6rcc.json
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Keystone intended authorization restrictions bypass",
"details": "OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -119,9 +117,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-01-12T20:22:36Z",
diff --git a/advisories/github-reviewed/2022/05/GHSA-vwr9-9f8v-vp5m/GHSA-vwr9-9f8v-vp5m.json b/advisories/github-reviewed/2022/05/GHSA-vwr9-9f8v-vp5m/GHSA-vwr9-9f8v-vp5m.json
index 9379b0c6708..2cda94b9561 100644
--- a/advisories/github-reviewed/2022/05/GHSA-vwr9-9f8v-vp5m/GHSA-vwr9-9f8v-vp5m.json
+++ b/advisories/github-reviewed/2022/05/GHSA-vwr9-9f8v-vp5m/GHSA-vwr9-9f8v-vp5m.json
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Glance arbitrary deletion of non-protected images",
"details": "The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -99,9 +97,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-12T20:28:42Z",
diff --git a/advisories/github-reviewed/2022/05/GHSA-w7h9-8wr4-hwqh/GHSA-w7h9-8wr4-hwqh.json b/advisories/github-reviewed/2022/05/GHSA-w7h9-8wr4-hwqh/GHSA-w7h9-8wr4-hwqh.json
index fef34f37c31..2530435f620 100644
--- a/advisories/github-reviewed/2022/05/GHSA-w7h9-8wr4-hwqh/GHSA-w7h9-8wr4-hwqh.json
+++ b/advisories/github-reviewed/2022/05/GHSA-w7h9-8wr4-hwqh/GHSA-w7h9-8wr4-hwqh.json
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Horizon Session Fixation",
"details": "Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2022/06/GHSA-6978-4w92-428p/GHSA-6978-4w92-428p.json b/advisories/github-reviewed/2022/06/GHSA-6978-4w92-428p/GHSA-6978-4w92-428p.json
index f433d705fe7..c302f3a0762 100644
--- a/advisories/github-reviewed/2022/06/GHSA-6978-4w92-428p/GHSA-6978-4w92-428p.json
+++ b/advisories/github-reviewed/2022/06/GHSA-6978-4w92-428p/GHSA-6978-4w92-428p.json
@@ -62,9 +62,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2022-06-17T21:51:19Z",
diff --git a/advisories/github-reviewed/2022/07/GHSA-pvjg-jwp3-mrj5/GHSA-pvjg-jwp3-mrj5.json b/advisories/github-reviewed/2022/07/GHSA-pvjg-jwp3-mrj5/GHSA-pvjg-jwp3-mrj5.json
index 7d603c6529b..59673d44528 100644
--- a/advisories/github-reviewed/2022/07/GHSA-pvjg-jwp3-mrj5/GHSA-pvjg-jwp3-mrj5.json
+++ b/advisories/github-reviewed/2022/07/GHSA-pvjg-jwp3-mrj5/GHSA-pvjg-jwp3-mrj5.json
@@ -58,9 +58,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-11-21T22:17:15Z",
diff --git a/advisories/github-reviewed/2024/04/GHSA-c5pj-mqfh-rvc3/GHSA-c5pj-mqfh-rvc3.json b/advisories/github-reviewed/2024/04/GHSA-c5pj-mqfh-rvc3/GHSA-c5pj-mqfh-rvc3.json
index 9969d9b6a24..a09104e26eb 100644
--- a/advisories/github-reviewed/2024/04/GHSA-c5pj-mqfh-rvc3/GHSA-c5pj-mqfh-rvc3.json
+++ b/advisories/github-reviewed/2024/04/GHSA-c5pj-mqfh-rvc3/GHSA-c5pj-mqfh-rvc3.json
@@ -4,9 +4,7 @@
"modified": "2024-06-05T18:30:34Z",
"published": "2024-04-26T06:30:34Z",
"withdrawn": "2024-04-30T09:37:23Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Withdrawn: Runc allows an arbitrary systemd property to be injected",
"details": "## Withdrawn Advisory\n\nThis advisory has been withdrawn because it was incorrectly attributed to runc. Please see the issue [here](https://github.com/opencontainers/runc/issues/4263) for more information.\n\n## Original Description\n\nA flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. This issue has its root in how runc handles Config Annotations lists.",
"severity": [
diff --git a/advisories/github-reviewed/2024/04/GHSA-v6rw-hhgg-wc4x/GHSA-v6rw-hhgg-wc4x.json b/advisories/github-reviewed/2024/04/GHSA-v6rw-hhgg-wc4x/GHSA-v6rw-hhgg-wc4x.json
index 7eae19eee66..b1e18259a48 100644
--- a/advisories/github-reviewed/2024/04/GHSA-v6rw-hhgg-wc4x/GHSA-v6rw-hhgg-wc4x.json
+++ b/advisories/github-reviewed/2024/04/GHSA-v6rw-hhgg-wc4x/GHSA-v6rw-hhgg-wc4x.json
@@ -3,9 +3,7 @@
"id": "GHSA-v6rw-hhgg-wc4x",
"modified": "2024-06-05T20:27:12Z",
"published": "2024-04-17T17:35:21Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Evmos vulnerable to DOS and transaction fee expropiation through Authz exploit",
"details": "## Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nAn attacker can use this bug to bypass the block gas limit and gas payment completely to perform a full Denial-of-Service against the chain.\n\n## Disclosure\n\nEvmos versions below `v11.0.1` do not check for `MsgEthereumTx` messages that are nested under other messages. This allows a malicious actor to perform EVM transactions that do not meet the checks performed under `newEthAnteHandler`. This opens the possibility for the DOS of validators and consequently halt the chain through an infinite EVM execution.\n\n### Additional details\n\nThe attack scenario is as follows:\n\n1. The attacker deploys a simple smart contract with an infinite loop to the chain. \n2. The attacker calls the smart contract using an embedded transaction with an extremely high gas value (`uint64` max or similar). \n3. Once the transaction is included in a block, nodes will try to execute the EVM transaction with almost infinite gas and get stuck. **This stops new block creation and effectively halts the chain, requiring a manual restart of all nodes.**\n\n## Users Impacted\nAll Evmos users are impacted by this vulnerability as it has the potential to halt the chain. Users' funds and chain state are safe but when under attack, the chain could be deemed unusable. \n\n## Patches\n\n_Has the problem been patched? What versions should users upgrade to?_\n\nThe vulnerability has been patched on Evmos versions ≥v12.0.0.\n\n### Details\n\nAs a temporary workaround, the fix blocks `MsgEthereumTxs` messages from being sent under the `authz` module's `MsgExec` message. It also covers the scenario in which `MsgEthereumTx` are deeply nested by:\n\n- Doing a recursive check over the nested messages of `MsgExec`\n- Limiting the amount of possible nested messages (inner messages) in `MsgExec`\n\nThis is done by adding an additional `AnteHandler` decorator (`AuthzLimiterDecorator`) for Cosmos and EIP-712 transactions.\n\nThis is a state machine-breaking change as it restricts previously allowed messages and thus requires a hard-fork upgrade.\n\n## References\n__Are there any links users can visit to find out more?__\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Reach out to the Core Team in [Discord](https://discord.gg/evmos)\n- Open a discussion in [evmos/evmos](https://github.com/evmos/evmos/discussions)\n- Email us at [security@evmos.org](mailto:security@evmos.org) for security questions\n- For Press, email us at [evmos@west-comms.com](mailto:evmos@west-comms.com).\n",
"severity": [
@@ -46,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-04-17T17:35:21Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-259v-xm34-p7fr/GHSA-259v-xm34-p7fr.json b/advisories/github-reviewed/2024/06/GHSA-259v-xm34-p7fr/GHSA-259v-xm34-p7fr.json
index de02afd7120..39bf3103d33 100644
--- a/advisories/github-reviewed/2024/06/GHSA-259v-xm34-p7fr/GHSA-259v-xm34-p7fr.json
+++ b/advisories/github-reviewed/2024/06/GHSA-259v-xm34-p7fr/GHSA-259v-xm34-p7fr.json
@@ -3,14 +3,10 @@
"id": "GHSA-259v-xm34-p7fr",
"modified": "2024-06-05T17:23:19Z",
"published": "2024-06-05T17:23:19Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Cross-Site Scripting in Language Pack Handling",
"details": "Failing to properly encode information from external sources, language pack handling in the install tool is vulnerable to cross-site scripting.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-4542-p56h-8xww/GHSA-4542-p56h-8xww.json b/advisories/github-reviewed/2024/06/GHSA-4542-p56h-8xww/GHSA-4542-p56h-8xww.json
index f2c1c8ee808..a7dd2b5cc98 100644
--- a/advisories/github-reviewed/2024/06/GHSA-4542-p56h-8xww/GHSA-4542-p56h-8xww.json
+++ b/advisories/github-reviewed/2024/06/GHSA-4542-p56h-8xww/GHSA-4542-p56h-8xww.json
@@ -3,14 +3,10 @@
"id": "GHSA-4542-p56h-8xww",
"modified": "2024-06-05T17:24:16Z",
"published": "2024-06-05T17:24:16Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting (XSS) vulnerabilities in Neos",
"details": "It has been discovered that Neos is vulnerable to several XSS attacks. Through these vulnerabilities, an attacker could tamper with page rendering, redirect victims to a fake login page, or capture user credentials (such as cookies). With the potential backdoor upload an attacker could gain access to the server itself, to an extent mainly limited by the server setup.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -66,9 +62,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:24:16Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-4m3g-6r7g-jv4f/GHSA-4m3g-6r7g-jv4f.json b/advisories/github-reviewed/2024/06/GHSA-4m3g-6r7g-jv4f/GHSA-4m3g-6r7g-jv4f.json
index 8039c575769..7efd38828e5 100644
--- a/advisories/github-reviewed/2024/06/GHSA-4m3g-6r7g-jv4f/GHSA-4m3g-6r7g-jv4f.json
+++ b/advisories/github-reviewed/2024/06/GHSA-4m3g-6r7g-jv4f/GHSA-4m3g-6r7g-jv4f.json
@@ -3,9 +3,7 @@
"id": "GHSA-4m3g-6r7g-jv4f",
"modified": "2024-06-05T14:15:50Z",
"published": "2024-06-05T14:15:50Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Arbitrary JavaScript execution due to using outdated libraries",
"details": "### Summary\ngradio-pdf projects with dependencies on the pdf.js library are vulnerable to CVE-2024-4367, which allows arbitrary JavaScript execution.\n\n### PoC\n1. Generate a pdf file with a malicious script in the fontmatrix. (This will run `alert(‘XSS’)`.)\n[poc.pdf](https://github.com/user-attachments/files/15516798/poc.pdf)\n\n2. Run the app. In this PoC, I've used the demo for a simple proof.\n\n\n3. Upload a PDF file containing the script.\n\n\n4. Check that the script is running.\n\n\n\n### Impact\nMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering.\n\n### Mitigation\nUpgrade the pdf.js to v4.2.67, which removes the vulnerability. (or set the option `isEvalSupported` to `false`.)\n\n### Reference\n1. https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/\n2. https://github.com/mozilla/pdf.js/pull/18015",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-4v5g-8pq2-32m2/GHSA-4v5g-8pq2-32m2.json b/advisories/github-reviewed/2024/06/GHSA-4v5g-8pq2-32m2/GHSA-4v5g-8pq2-32m2.json
index da0ee562438..eecc9a5200d 100644
--- a/advisories/github-reviewed/2024/06/GHSA-4v5g-8pq2-32m2/GHSA-4v5g-8pq2-32m2.json
+++ b/advisories/github-reviewed/2024/06/GHSA-4v5g-8pq2-32m2/GHSA-4v5g-8pq2-32m2.json
@@ -3,14 +3,10 @@
"id": "GHSA-4v5g-8pq2-32m2",
"modified": "2024-06-05T17:30:00Z",
"published": "2024-06-05T17:30:00Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "By-passing Protection of PharStreamWrapper Interceptor",
"details": "Insecure deserialization is a vulnerability which occurs when untrusted data is used to abuse the logic of an application. In July 2018, the vulnerability of insecure deserialization when executing Phar archives was addressed by removing the known attack vector in the TYPO3 core. For more details read the corresponding TYPO3 advisory.\n\nIn addition, a new interceptor was introduced to protect possible (but unknown) vulnerabilities in 3rd party components like TYPO3 extensions. Basically, the PharStreamWrapper intercepts direct invocations of Phar archives and allows or denies further processing based on individual rules.\n\nRecently, the PharStreamWrapper was extracted from the TYPO3 core and released as standalone package under the MIT license. It is now available for any PHP driven project.\n\nThe stream wrapper overwrites the existing Phar handling of PHP, applies its own assertions and then restores the native PHP Phar handling for the corresponding commands (e.g. file_exists, include, fopen) to continue processing. After that, the native PHP Phar handling gets disabled and is overwritten by the logic of the PharStreamWrapper again. This is the only way to control invocations of Phar archives as PHP only allows a single handler for each corresponding stream.\n\nWe were informed that exception and error handlers in custom applications (e.g. TYPO3 extensions) sometimes didn't return to the original operating sequence of the PharStreamWrapper. A possible consequence was that the unprotected native PHP Phar handling remained active and therefore became vulnerable for the basic issue of insecure deserialization again.\n\nExamples\nTake a look at the following examples showing how the handling is by-passed in custom application code.\n\nScenario A: Exception thrown from code organized in a Phar archive\n```\ntry {\n include('phar://path-to-archive/good-archive.phar');\n} catch (\\Throwable $throwable) {\n // not doing much here, continue execution\n}\n// the insecure value can be anything that is or was user-submitted\n// and cannot be trusted in terms of security, $_GET is just used as example\n$insecureValue = $_GET['path'];\n// the value might be 'phar://path-to-archive/malicious-archive.phar'\nfile_exists($insecureValue);\n```\nScenario B: Errors converted to exceptions and thrown when interacting with archive contents\n```\n// set error handler in order to convert errors to exceptions\nset_error_handler(function($errno, $errstr, $errfile, $errline, array $errcontext) {\n throw new ErrorException($errstr, 0, $errno, $errfile, $errline);\n});\n// interacting with Phar archive\ntry {\n $resource = opendir('phar://path-to-archive/good-archive.phar/non-existing-path/');\n closedir($resource);\n} catch (\\Throwable $throwable) {\n // not doing much here, continue execution\n}\n// the insecure value can be anything that is or was user-submitted\n// and cannot be trusted in terms of security, $_GET is just used as example\n$insecureValue = $_GET['path'];\n// the value might be 'phar://path-to-archive/malicious-archive.phar'\nfile_exists($insecureValue);\n```",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-5gr6-97fv-52cc/GHSA-5gr6-97fv-52cc.json b/advisories/github-reviewed/2024/06/GHSA-5gr6-97fv-52cc/GHSA-5gr6-97fv-52cc.json
index 8b3922fc13f..fb51c346568 100644
--- a/advisories/github-reviewed/2024/06/GHSA-5gr6-97fv-52cc/GHSA-5gr6-97fv-52cc.json
+++ b/advisories/github-reviewed/2024/06/GHSA-5gr6-97fv-52cc/GHSA-5gr6-97fv-52cc.json
@@ -3,9 +3,7 @@
"id": "GHSA-5gr6-97fv-52cc",
"modified": "2024-06-05T17:05:47Z",
"published": "2024-06-05T17:05:47Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in TYPO3 CMS",
"details": "Failing to properly encode user input, several places of the TYPO3 CMS are vulnerable to Cross-Site Scripting.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-5wx6-xwxf-q8qj/GHSA-5wx6-xwxf-q8qj.json b/advisories/github-reviewed/2024/06/GHSA-5wx6-xwxf-q8qj/GHSA-5wx6-xwxf-q8qj.json
index c2fc6228398..ea9973b2460 100644
--- a/advisories/github-reviewed/2024/06/GHSA-5wx6-xwxf-q8qj/GHSA-5wx6-xwxf-q8qj.json
+++ b/advisories/github-reviewed/2024/06/GHSA-5wx6-xwxf-q8qj/GHSA-5wx6-xwxf-q8qj.json
@@ -3,9 +3,7 @@
"id": "GHSA-5wx6-xwxf-q8qj",
"modified": "2024-06-05T14:17:47Z",
"published": "2024-06-05T14:17:47Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in TYPO3 Backend",
"details": "Failing to properly encode user input, some backend components are vulnerable to Cross-Site Scripting. A valid backend user account is needed to exploit this vulnerability.\n",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-67wg-6j7r-mqh8/GHSA-67wg-6j7r-mqh8.json b/advisories/github-reviewed/2024/06/GHSA-67wg-6j7r-mqh8/GHSA-67wg-6j7r-mqh8.json
index bb506c28e4b..c3bd6b68079 100644
--- a/advisories/github-reviewed/2024/06/GHSA-67wg-6j7r-mqh8/GHSA-67wg-6j7r-mqh8.json
+++ b/advisories/github-reviewed/2024/06/GHSA-67wg-6j7r-mqh8/GHSA-67wg-6j7r-mqh8.json
@@ -3,9 +3,7 @@
"id": "GHSA-67wg-6j7r-mqh8",
"modified": "2024-06-05T15:07:09Z",
"published": "2024-06-05T15:07:09Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Arbitrary Code Execution in TYPO3 CMS",
"details": "Due to a missing file extension in the fileDenyPattern, backend user are allowed to upload *.pht files which can be executed in certain web server setups. The new default fileDenyPattern is the following, which might have been overridden in the TYPO3 Install Tool.\n```\n\\.(php[3-7]?|phpsh|phtml|pht)(\\..*)?$|^\\.htaccess$\n```",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-6f9m-v7mp-7jjq/GHSA-6f9m-v7mp-7jjq.json b/advisories/github-reviewed/2024/06/GHSA-6f9m-v7mp-7jjq/GHSA-6f9m-v7mp-7jjq.json
index 38341bd275b..167b248a01f 100644
--- a/advisories/github-reviewed/2024/06/GHSA-6f9m-v7mp-7jjq/GHSA-6f9m-v7mp-7jjq.json
+++ b/advisories/github-reviewed/2024/06/GHSA-6f9m-v7mp-7jjq/GHSA-6f9m-v7mp-7jjq.json
@@ -3,14 +3,10 @@
"id": "GHSA-6f9m-v7mp-7jjq",
"modified": "2024-06-05T16:52:44Z",
"published": "2024-06-05T16:52:44Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Authentication Bypass in TYPO3 CMS",
"details": "It has been discovered that TYPO3’s Salted Password system extension (which is a mandatory system component) is vulnerable to Authentication Bypass when using hashing methods which are related by PHP class inheritance. In standard TYPO3 core distributions stored passwords using the blowfish hashing algorithm can be overridden when using MD5 as the default hashing algorithm by just knowing a valid username. Per default the Portable PHP hashing algorithm (PHPass) is used which is not vulnerable.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -85,9 +81,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T16:52:44Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-6xh8-8pfv-53vx/GHSA-6xh8-8pfv-53vx.json b/advisories/github-reviewed/2024/06/GHSA-6xh8-8pfv-53vx/GHSA-6xh8-8pfv-53vx.json
index 488a5ddcc2a..c767667a6a0 100644
--- a/advisories/github-reviewed/2024/06/GHSA-6xh8-8pfv-53vx/GHSA-6xh8-8pfv-53vx.json
+++ b/advisories/github-reviewed/2024/06/GHSA-6xh8-8pfv-53vx/GHSA-6xh8-8pfv-53vx.json
@@ -3,9 +3,7 @@
"id": "GHSA-6xh8-8pfv-53vx",
"modified": "2024-06-05T14:17:20Z",
"published": "2024-06-05T14:17:20Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Authentication Bypass in TYPO3 CMS",
"details": "The default authentication service misses to invalidate empty strings as password. Therefore it is possible to authenticate backend and frontend users without password set in the database.\nNote: TYPO3 does not allow to create user accounts without a password. Your TYPO3 installation might only be affected if there is a third party component creating user accounts without password by directly manipulating the database.\n\n",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-7qwg-fcpw-xg5g/GHSA-7qwg-fcpw-xg5g.json b/advisories/github-reviewed/2024/06/GHSA-7qwg-fcpw-xg5g/GHSA-7qwg-fcpw-xg5g.json
index 98976320464..c2088178ade 100644
--- a/advisories/github-reviewed/2024/06/GHSA-7qwg-fcpw-xg5g/GHSA-7qwg-fcpw-xg5g.json
+++ b/advisories/github-reviewed/2024/06/GHSA-7qwg-fcpw-xg5g/GHSA-7qwg-fcpw-xg5g.json
@@ -3,9 +3,7 @@
"id": "GHSA-7qwg-fcpw-xg5g",
"modified": "2024-06-05T15:10:19Z",
"published": "2024-06-05T15:10:19Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Privilege Escalation & SQL Injection in TYPO3 CMS",
"details": "Failing to properly dissociate system related configuration from user generated configuration, the Form Framework (system extension \"form\") is vulnerable to SQL injection and Privilege Escalation. Basically instructions can be persisted to a form definition file that were not configured to be modified - this applies to definitions managed using the form editor module as well as direct file upload using the regular file list module. A valid backend user account as well as having system extension form activated are needed in order to exploit this vulnerability.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-86r8-4g3w-7xjp/GHSA-86r8-4g3w-7xjp.json b/advisories/github-reviewed/2024/06/GHSA-86r8-4g3w-7xjp/GHSA-86r8-4g3w-7xjp.json
index 7fd9d8f5571..b3ac3e4d996 100644
--- a/advisories/github-reviewed/2024/06/GHSA-86r8-4g3w-7xjp/GHSA-86r8-4g3w-7xjp.json
+++ b/advisories/github-reviewed/2024/06/GHSA-86r8-4g3w-7xjp/GHSA-86r8-4g3w-7xjp.json
@@ -3,9 +3,7 @@
"id": "GHSA-86r8-4g3w-7xjp",
"modified": "2024-06-05T14:19:39Z",
"published": "2024-06-05T14:19:39Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in TYPO3 Backend",
"details": "Failing to properly encode user input, some backend components are vulnerable to Cross-Site Scripting. A valid backend user account is needed to exploit this vulnerability.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-8h28-f46f-m87h/GHSA-8h28-f46f-m87h.json b/advisories/github-reviewed/2024/06/GHSA-8h28-f46f-m87h/GHSA-8h28-f46f-m87h.json
index 9bc40059b22..512ca82680b 100644
--- a/advisories/github-reviewed/2024/06/GHSA-8h28-f46f-m87h/GHSA-8h28-f46f-m87h.json
+++ b/advisories/github-reviewed/2024/06/GHSA-8h28-f46f-m87h/GHSA-8h28-f46f-m87h.json
@@ -3,14 +3,10 @@
"id": "GHSA-8h28-f46f-m87h",
"modified": "2024-06-05T15:06:18Z",
"published": "2024-06-05T15:06:18Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Insecure Deserialization in TYPO3 CMS",
"details": "It has been discovered that the Form Framework (system extension \"form\") is vulnerable to Insecure Deserialization when being used with the additional PHP PECL package “yaml”, which is capable of unserializing YAML contents to PHP objects. A valid backend user account as well as having PHP setting \"yaml.decode_php\" enabled is needed to exploit this vulnerability (which is the default value according to PHP documentation).",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-c7p6-3c9c-f88q/GHSA-c7p6-3c9c-f88q.json b/advisories/github-reviewed/2024/06/GHSA-c7p6-3c9c-f88q/GHSA-c7p6-3c9c-f88q.json
index b5ee4c190e2..9c289711fab 100644
--- a/advisories/github-reviewed/2024/06/GHSA-c7p6-3c9c-f88q/GHSA-c7p6-3c9c-f88q.json
+++ b/advisories/github-reviewed/2024/06/GHSA-c7p6-3c9c-f88q/GHSA-c7p6-3c9c-f88q.json
@@ -3,9 +3,7 @@
"id": "GHSA-c7p6-3c9c-f88q",
"modified": "2024-06-05T15:11:36Z",
"published": "2024-06-05T15:11:36Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Information Disclosure in TYPO3 CMS",
"details": "HTTP requests being performed using the TYPO3 API expose the specific TYPO3 version to the called endpoint.",
"severity": [
@@ -69,9 +67,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T15:11:36Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-c7rj-92xr-wprg/GHSA-c7rj-92xr-wprg.json b/advisories/github-reviewed/2024/06/GHSA-c7rj-92xr-wprg/GHSA-c7rj-92xr-wprg.json
index fc87f0338b0..ff77a0456c2 100644
--- a/advisories/github-reviewed/2024/06/GHSA-c7rj-92xr-wprg/GHSA-c7rj-92xr-wprg.json
+++ b/advisories/github-reviewed/2024/06/GHSA-c7rj-92xr-wprg/GHSA-c7rj-92xr-wprg.json
@@ -3,9 +3,7 @@
"id": "GHSA-c7rj-92xr-wprg",
"modified": "2024-06-05T17:04:41Z",
"published": "2024-06-05T17:04:41Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Insecure Unserialize in TYPO3 Backend",
"details": "Failing to properly validate incoming data, the suggest wizard is susceptible to insecure unserialize. To exploit this vulnerability a valid backend user account is needed.",
"severity": [
@@ -80,9 +78,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:04:41Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-f5rr-9r84-wwqf/GHSA-f5rr-9r84-wwqf.json b/advisories/github-reviewed/2024/06/GHSA-f5rr-9r84-wwqf/GHSA-f5rr-9r84-wwqf.json
index 7cb6cf300ac..8619878261d 100644
--- a/advisories/github-reviewed/2024/06/GHSA-f5rr-9r84-wwqf/GHSA-f5rr-9r84-wwqf.json
+++ b/advisories/github-reviewed/2024/06/GHSA-f5rr-9r84-wwqf/GHSA-f5rr-9r84-wwqf.json
@@ -3,14 +3,10 @@
"id": "GHSA-f5rr-9r84-wwqf",
"modified": "2024-06-05T17:22:52Z",
"published": "2024-06-05T17:22:52Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Broken Access Control in Import Module",
"details": "It has been discovered that the Import/Export module is susceptible to broken access control. Regular backend users have access to import functionality which usually only is available to admin users or users having User TSconfig setting options.impexp.enableImportForNonAdminUser explicitly enabled.\n\nDatabase content to be imported however was correctly checked against users’ permissions and not affected. However it was possible to upload files by-passing restrictions of the file abstraction layer (FAL) - however this did not affect executable files which have been correctly secured by fileDenyPattern.\n\nCurrently the only known vulnerability is to directly inject *.form.yaml files which could be used to trigger the vulnerability of TYPO3-CORE-SA-2018-003 (privilege escalation & SQL injection) - which requires the Form Framework (ext:form) being available on an according website. CVSSv3 scoring is based on this scenario.\n\nA valid backend user account is needed in order to exploit this vulnerability.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:22:52Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-g46h-v2cc-6c94/GHSA-g46h-v2cc-6c94.json b/advisories/github-reviewed/2024/06/GHSA-g46h-v2cc-6c94/GHSA-g46h-v2cc-6c94.json
index cd871aeb44c..0405ab0b260 100644
--- a/advisories/github-reviewed/2024/06/GHSA-g46h-v2cc-6c94/GHSA-g46h-v2cc-6c94.json
+++ b/advisories/github-reviewed/2024/06/GHSA-g46h-v2cc-6c94/GHSA-g46h-v2cc-6c94.json
@@ -3,9 +3,7 @@
"id": "GHSA-g46h-v2cc-6c94",
"modified": "2024-06-05T16:43:50Z",
"published": "2024-06-05T16:43:50Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Information Disclosure in TYPO3 CMS",
"details": "Failing to properly check user permission on file storages, editors could gain knowledge of protected storages and its folders as well as using them in a file collection being rendered in the frontend. A valid backend user account is needed to exploit this vulnerability.",
"severity": [
@@ -69,9 +67,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T16:43:50Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-g4pf-3jvq-2gcw/GHSA-g4pf-3jvq-2gcw.json b/advisories/github-reviewed/2024/06/GHSA-g4pf-3jvq-2gcw/GHSA-g4pf-3jvq-2gcw.json
index fa19a7a743f..b38516fb08b 100644
--- a/advisories/github-reviewed/2024/06/GHSA-g4pf-3jvq-2gcw/GHSA-g4pf-3jvq-2gcw.json
+++ b/advisories/github-reviewed/2024/06/GHSA-g4pf-3jvq-2gcw/GHSA-g4pf-3jvq-2gcw.json
@@ -3,14 +3,10 @@
"id": "GHSA-g4pf-3jvq-2gcw",
"modified": "2024-06-05T15:08:03Z",
"published": "2024-06-05T15:08:03Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "TYPO3 Remote Code Execution in third party library swiftmailer",
"details": "TYPO3 uses the package swiftmailer/swiftmailer for mail actions. This package is known to be vulnerable to Remote Code Execution.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json b/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json
index c6b86257ffe..c2d4804af9f 100644
--- a/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json
+++ b/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json
@@ -3,14 +3,10 @@
"id": "GHSA-g9rv-6g56-65h8",
"modified": "2024-06-05T17:10:38Z",
"published": "2024-06-05T17:10:38Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Security Misconfiguration in User Session Handling",
"details": "When users change their password existing sessions for that particular user account are not revoked. A valid backend or frontend user account is required in order to make use of this vulnerability.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -66,9 +62,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:10:38Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-gwfx-p7mr-f92v/GHSA-gwfx-p7mr-f92v.json b/advisories/github-reviewed/2024/06/GHSA-gwfx-p7mr-f92v/GHSA-gwfx-p7mr-f92v.json
index 3241bd78547..5f2731966c7 100644
--- a/advisories/github-reviewed/2024/06/GHSA-gwfx-p7mr-f92v/GHSA-gwfx-p7mr-f92v.json
+++ b/advisories/github-reviewed/2024/06/GHSA-gwfx-p7mr-f92v/GHSA-gwfx-p7mr-f92v.json
@@ -3,9 +3,7 @@
"id": "GHSA-gwfx-p7mr-f92v",
"modified": "2024-06-05T14:22:26Z",
"published": "2024-06-05T14:22:26Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Missing Access Check in TYPO3 CMS",
"details": "Extbase request handling fails to implement a proper access check for requested controller/ action combinations, which makes it possible for an attacker to execute arbitrary Extbase actions by crafting a special request. To successfully exploit this vulnerability, an attacker must have access to at least one Extbase plugin or module action in a TYPO3 installation. The missing access check inevitably leads to information disclosure or remote code execution, depending on the action that an attacker is able to execute.",
"severity": [
@@ -84,9 +82,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T14:22:26Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-h934-f4m4-wc8x/GHSA-h934-f4m4-wc8x.json b/advisories/github-reviewed/2024/06/GHSA-h934-f4m4-wc8x/GHSA-h934-f4m4-wc8x.json
index a1424fd4c69..aedd0a51766 100644
--- a/advisories/github-reviewed/2024/06/GHSA-h934-f4m4-wc8x/GHSA-h934-f4m4-wc8x.json
+++ b/advisories/github-reviewed/2024/06/GHSA-h934-f4m4-wc8x/GHSA-h934-f4m4-wc8x.json
@@ -3,14 +3,10 @@
"id": "GHSA-h934-f4m4-wc8x",
"modified": "2024-06-05T17:21:19Z",
"published": "2024-06-05T17:21:19Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Information Disclosure in Page Tree",
"details": "It has been discovered backend users not having read access to specific pages still could see them in the page tree which actually should be disallowed. A valid backend user account is needed in order to exploit this vulnerability.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:21:19Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-hq37-rfjc-mr8h/GHSA-hq37-rfjc-mr8h.json b/advisories/github-reviewed/2024/06/GHSA-hq37-rfjc-mr8h/GHSA-hq37-rfjc-mr8h.json
index 4271ed018de..0eb121924d7 100644
--- a/advisories/github-reviewed/2024/06/GHSA-hq37-rfjc-mr8h/GHSA-hq37-rfjc-mr8h.json
+++ b/advisories/github-reviewed/2024/06/GHSA-hq37-rfjc-mr8h/GHSA-hq37-rfjc-mr8h.json
@@ -3,14 +3,10 @@
"id": "GHSA-hq37-rfjc-mr8h",
"modified": "2024-06-05T15:03:28Z",
"published": "2024-06-05T15:03:28Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting (XSS) in TYPO3 Backend",
"details": "Failing to properly encode user input, the page module is vulnerable to Cross-Site Scripting. A valid backend user account with permissions to edit plugins is needed to exploit this vulnerability.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-hvh4-5qr6-3v7r/GHSA-hvh4-5qr6-3v7r.json b/advisories/github-reviewed/2024/06/GHSA-hvh4-5qr6-3v7r/GHSA-hvh4-5qr6-3v7r.json
index 0aadf01a93e..167ff767f92 100644
--- a/advisories/github-reviewed/2024/06/GHSA-hvh4-5qr6-3v7r/GHSA-hvh4-5qr6-3v7r.json
+++ b/advisories/github-reviewed/2024/06/GHSA-hvh4-5qr6-3v7r/GHSA-hvh4-5qr6-3v7r.json
@@ -3,9 +3,7 @@
"id": "GHSA-hvh4-5qr6-3v7r",
"modified": "2024-06-05T18:36:15Z",
"published": "2024-06-05T16:56:35Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Observable Timing Discrepancy in pypqc",
"details": "### Impact\n`kyber512`, `kyber768`, and `kyber1024` on Mac OS \\(or when compiled with clang\\) only: An attacker able to submit many decapsulation requests against a single private key, and to gain timing information about the decapsulation, could recover the private key. Proof-of-concept exploit exists for a local attacker.\n\nCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:P/RL:U/RC:C \n\n### Patches\nNo patch is currently available / pending upstream [PQClean#556](https://github.com/PQClean/PQClean/issues/556).\n\n### Workarounds\nNo workarounds have been reported. The 0.0.7 -> 0.0.7.1 upgrade, when available, should be a drop-in replacement.\n\n### References\n\nhttps://pqshield.com/pqshield-plugs-timing-leaks-in-kyber-ml-kem-to-improve-pqc-implementation-maturity/\n\nhttps://github.com/antoonpurnal/clangover\n\nhttps://www.github.com/PQClean/PQClean/issues/556\n\nhttps://www.github.com/pq-crystals/kyber/commit/9b8d30698a3e7449aeb34e62339d4176f11e3c6c",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-hww5-6x85-mc24/GHSA-hww5-6x85-mc24.json b/advisories/github-reviewed/2024/06/GHSA-hww5-6x85-mc24/GHSA-hww5-6x85-mc24.json
index 92007bcfb71..44f37fad3d9 100644
--- a/advisories/github-reviewed/2024/06/GHSA-hww5-6x85-mc24/GHSA-hww5-6x85-mc24.json
+++ b/advisories/github-reviewed/2024/06/GHSA-hww5-6x85-mc24/GHSA-hww5-6x85-mc24.json
@@ -3,14 +3,10 @@
"id": "GHSA-hww5-6x85-mc24",
"modified": "2024-06-05T17:19:26Z",
"published": "2024-06-05T17:19:26Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Arbitrary Code Execution and Cross-Site Scripting in Backend API",
"details": "Backend API configuration using Page TSconfig is vulnerable to arbitrary code execution and cross-site scripting. TSconfig fields of page properties in backend forms can be used to inject malicious sequences. Field tsconfig_includes is vulnerable to directory traversal leading to same scenarios as having direct access to TSconfig settings.\n\nA valid backend user account having access to modify values for fields pages.TSconfig and pages.tsconfig_includes is needed in order to exploit this vulnerability.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -62,9 +58,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:19:26Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-j86x-pjmr-9m6w/GHSA-j86x-pjmr-9m6w.json b/advisories/github-reviewed/2024/06/GHSA-j86x-pjmr-9m6w/GHSA-j86x-pjmr-9m6w.json
index c22b322d75a..f21bc730938 100644
--- a/advisories/github-reviewed/2024/06/GHSA-j86x-pjmr-9m6w/GHSA-j86x-pjmr-9m6w.json
+++ b/advisories/github-reviewed/2024/06/GHSA-j86x-pjmr-9m6w/GHSA-j86x-pjmr-9m6w.json
@@ -3,9 +3,7 @@
"id": "GHSA-j86x-pjmr-9m6w",
"modified": "2024-06-05T14:23:20Z",
"published": "2024-06-05T14:23:20Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "SQL Injection in TYPO3 Frontend Login",
"details": "Failing to properly escape user input, the frontend login component is vulnerable to SQL Injection. A valid frontend user account is needed to exploit this vulnerability.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-jmh9-6rjq-gjh9/GHSA-jmh9-6rjq-gjh9.json b/advisories/github-reviewed/2024/06/GHSA-jmh9-6rjq-gjh9/GHSA-jmh9-6rjq-gjh9.json
index 0c4255343c3..dac2dd4453b 100644
--- a/advisories/github-reviewed/2024/06/GHSA-jmh9-6rjq-gjh9/GHSA-jmh9-6rjq-gjh9.json
+++ b/advisories/github-reviewed/2024/06/GHSA-jmh9-6rjq-gjh9/GHSA-jmh9-6rjq-gjh9.json
@@ -3,14 +3,10 @@
"id": "GHSA-jmh9-6rjq-gjh9",
"modified": "2024-06-05T13:28:36Z",
"published": "2024-06-05T13:28:36Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Vulnerable embedded jQuery Version",
"details": "### Summary\nPIMCore uses the JavaScript library jQuery in version 3.4.1. This version is vulnerable to cross-site-scripting (XSS).\n\n### Details\nIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.\n\nPublish Date: 2020-04-29\n\nURL:= https://security.snyk.io/package/npm/jquery/3.4.1\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -46,9 +42,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T13:28:36Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json b/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json
index aba6a70e5af..0efb8c831f3 100644
--- a/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json
+++ b/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json
@@ -3,14 +3,10 @@
"id": "GHSA-m96r-7vqm-j95g",
"modified": "2024-06-05T17:09:30Z",
"published": "2024-06-05T17:09:30Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Information Disclosure in User Authentication",
"details": "It has been discovered that login failures have been logged on the default stream with log level \"warning\" including plain-text user credentials.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:09:30Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-mh3r-6cp5-hc2j/GHSA-mh3r-6cp5-hc2j.json b/advisories/github-reviewed/2024/06/GHSA-mh3r-6cp5-hc2j/GHSA-mh3r-6cp5-hc2j.json
index bb06b253c41..741e33cf6ec 100644
--- a/advisories/github-reviewed/2024/06/GHSA-mh3r-6cp5-hc2j/GHSA-mh3r-6cp5-hc2j.json
+++ b/advisories/github-reviewed/2024/06/GHSA-mh3r-6cp5-hc2j/GHSA-mh3r-6cp5-hc2j.json
@@ -3,9 +3,7 @@
"id": "GHSA-mh3r-6cp5-hc2j",
"modified": "2024-06-05T16:55:00Z",
"published": "2024-06-05T16:55:00Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Authentication Bypass in TYPO3 Frontend",
"details": "Due to late TCA initialization the authentication service fails to restrict frontend user according to the validation rules. Therefore it is possible to authenticate restricted (e.g. disabled) frontend users.",
"severity": [
@@ -42,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T16:55:00Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-p5c5-gmj4-g48f/GHSA-p5c5-gmj4-g48f.json b/advisories/github-reviewed/2024/06/GHSA-p5c5-gmj4-g48f/GHSA-p5c5-gmj4-g48f.json
index 30700e574f2..44cd5f5bf96 100644
--- a/advisories/github-reviewed/2024/06/GHSA-p5c5-gmj4-g48f/GHSA-p5c5-gmj4-g48f.json
+++ b/advisories/github-reviewed/2024/06/GHSA-p5c5-gmj4-g48f/GHSA-p5c5-gmj4-g48f.json
@@ -3,14 +3,10 @@
"id": "GHSA-p5c5-gmj4-g48f",
"modified": "2024-06-05T15:04:23Z",
"published": "2024-06-05T15:04:23Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting (XSS) vulnerability in typolinks",
"details": "All link fields within the TYPO3 installation are vulnerable to Cross-Site Scripting as authorized editors can insert data commands by using the url scheme \"data:\".",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-ppgf-8745-8pgx/GHSA-ppgf-8745-8pgx.json b/advisories/github-reviewed/2024/06/GHSA-ppgf-8745-8pgx/GHSA-ppgf-8745-8pgx.json
index c9bdeb14e46..eb3a0ad0de4 100644
--- a/advisories/github-reviewed/2024/06/GHSA-ppgf-8745-8pgx/GHSA-ppgf-8745-8pgx.json
+++ b/advisories/github-reviewed/2024/06/GHSA-ppgf-8745-8pgx/GHSA-ppgf-8745-8pgx.json
@@ -3,14 +3,10 @@
"id": "GHSA-ppgf-8745-8pgx",
"modified": "2024-06-05T16:41:48Z",
"published": "2024-06-05T16:41:48Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Insecure Deserialization & Arbitrary Code Execution in TYPO3 CMS",
"details": "Phar files (formerly known as \"PHP archives\") can act als self extracting archives which leads to the fact that source code is executed when Phar files are invoked. The Phar file format is not limited to be stored with a dedicated file extension - \"bundle.phar\" would be valid as well as \"bundle.txt\" would be. This way, Phar files can be obfuscated as image or text file which would not be denied from being uploaded and persisted to a TYPO3 installation. Due to a missing sanitization of user input, those Phar files can be invoked by manipulated URLs in TYPO3 backend forms. A valid backend user account is needed to exploit this vulnerability. In theory the attack vector would be possible in the TYPO3 frontend as well, however no functional exploit has been identified so far.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-pw2q-qwvj-gh43/GHSA-pw2q-qwvj-gh43.json b/advisories/github-reviewed/2024/06/GHSA-pw2q-qwvj-gh43/GHSA-pw2q-qwvj-gh43.json
index 942330472b0..2335a1b094d 100644
--- a/advisories/github-reviewed/2024/06/GHSA-pw2q-qwvj-gh43/GHSA-pw2q-qwvj-gh43.json
+++ b/advisories/github-reviewed/2024/06/GHSA-pw2q-qwvj-gh43/GHSA-pw2q-qwvj-gh43.json
@@ -3,9 +3,7 @@
"id": "GHSA-pw2q-qwvj-gh43",
"modified": "2024-06-05T16:55:38Z",
"published": "2024-06-05T16:55:37Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cache Flooding in TYPO3 Frontend",
"details": " Links with a valid cHash argument lead to newly generated page cache entries. Because the cHash is not bound to a specific page, attackers could use valid cHash arguments for multiple pages, leading to additional useless page cache entries. Depending on the number of pages in the system and the number of available valid links with a cHash, attackers could add a considerable amount of additional cache entries, which in the end exceed storage limits and thus could lead to the system not responding any more. This means the Cache Flooding attack potentially could lead to a successful Denial of Service (DoS) attack.",
"severity": [
@@ -80,9 +78,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T16:55:37Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json b/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json
index 06233335a7f..c4cf4321ca6 100644
--- a/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json
+++ b/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json
@@ -3,14 +3,10 @@
"id": "GHSA-q9c4-9v5m-597p",
"modified": "2024-06-05T17:10:08Z",
"published": "2024-06-05T17:10:08Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Information Disclosure in Backend User Interface",
"details": "The element information component used to display properties of a certain record is susceptible to information disclosure. The list of references from or to the record is not properly checked for the backend user’s permissions. A valid backend user account is needed in order to exploit this vulnerability.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -66,9 +62,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:10:08Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-qmwf-j7g7-f5jw/GHSA-qmwf-j7g7-f5jw.json b/advisories/github-reviewed/2024/06/GHSA-qmwf-j7g7-f5jw/GHSA-qmwf-j7g7-f5jw.json
index f37885459d1..b65ca4c7416 100644
--- a/advisories/github-reviewed/2024/06/GHSA-qmwf-j7g7-f5jw/GHSA-qmwf-j7g7-f5jw.json
+++ b/advisories/github-reviewed/2024/06/GHSA-qmwf-j7g7-f5jw/GHSA-qmwf-j7g7-f5jw.json
@@ -3,14 +3,10 @@
"id": "GHSA-qmwf-j7g7-f5jw",
"modified": "2024-06-05T15:02:40Z",
"published": "2024-06-05T15:02:40Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in third party library mso/idna-convert",
"details": "Make sure to not expose the vendor directory to the publicly accessible document root. In composer managed installation, make sure to configure a dedicated web folder. In general it is recommended to not expose the complete typo3_src sources folder in the document root.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json b/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json
index ab563782768..8f507325313 100644
--- a/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json
+++ b/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json
@@ -3,14 +3,10 @@
"id": "GHSA-qr5f-6fcv-w69q",
"modified": "2024-06-05T17:12:58Z",
"published": "2024-06-05T17:12:58Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Typo3 Security Misconfiguration in Frontend Session Handling",
"details": "It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -66,9 +62,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:12:58Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-r6mm-wmhf-849m/GHSA-r6mm-wmhf-849m.json b/advisories/github-reviewed/2024/06/GHSA-r6mm-wmhf-849m/GHSA-r6mm-wmhf-849m.json
index c3250bf8830..ffcb9b64c6b 100644
--- a/advisories/github-reviewed/2024/06/GHSA-r6mm-wmhf-849m/GHSA-r6mm-wmhf-849m.json
+++ b/advisories/github-reviewed/2024/06/GHSA-r6mm-wmhf-849m/GHSA-r6mm-wmhf-849m.json
@@ -3,14 +3,10 @@
"id": "GHSA-r6mm-wmhf-849m",
"modified": "2024-06-05T17:28:47Z",
"published": "2024-06-05T17:28:47Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Time-Based Information Disclosure Vulnerability in Flow",
"details": "The PersistedUsernamePasswordProvider was prone to a information disclosure of account existance based on timing attacks as the hashing of passwords was only done in case an account was found. We changed the core so that the provider always does a password comparison in case credentials were submitted at all.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -123,9 +119,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:28:47Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-v4qr-8h2v-qpjx/GHSA-v4qr-8h2v-qpjx.json b/advisories/github-reviewed/2024/06/GHSA-v4qr-8h2v-qpjx/GHSA-v4qr-8h2v-qpjx.json
index 3f32ce7094a..5d2c9c56ce2 100644
--- a/advisories/github-reviewed/2024/06/GHSA-v4qr-8h2v-qpjx/GHSA-v4qr-8h2v-qpjx.json
+++ b/advisories/github-reviewed/2024/06/GHSA-v4qr-8h2v-qpjx/GHSA-v4qr-8h2v-qpjx.json
@@ -3,9 +3,7 @@
"id": "GHSA-v4qr-8h2v-qpjx",
"modified": "2024-06-05T17:07:16Z",
"published": "2024-06-05T17:07:15Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in TYPO3 CMS Backend",
"details": "Failing to properly encode user input, backend forms are vulnerable to Cross-Site Scripting. A valid backend user account is needed to exploit this vulnerability.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-v5jp-4h2p-j2p4/GHSA-v5jp-4h2p-j2p4.json b/advisories/github-reviewed/2024/06/GHSA-v5jp-4h2p-j2p4/GHSA-v5jp-4h2p-j2p4.json
index e2eeb2b4ed3..f01533fb5d6 100644
--- a/advisories/github-reviewed/2024/06/GHSA-v5jp-4h2p-j2p4/GHSA-v5jp-4h2p-j2p4.json
+++ b/advisories/github-reviewed/2024/06/GHSA-v5jp-4h2p-j2p4/GHSA-v5jp-4h2p-j2p4.json
@@ -3,9 +3,7 @@
"id": "GHSA-v5jp-4h2p-j2p4",
"modified": "2024-06-05T14:18:58Z",
"published": "2024-06-05T14:18:58Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Privilege Escalation in TYPO3 CMS",
"details": "The workspace/ version preview link created by a privileged (backend) user could be abused to obtain certain editing permission, if the admin panel is configured to be shown. A valid preview link is required to exploit this vulnerability.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-vh6j-wv25-8qxr/GHSA-vh6j-wv25-8qxr.json b/advisories/github-reviewed/2024/06/GHSA-vh6j-wv25-8qxr/GHSA-vh6j-wv25-8qxr.json
index 5680b4e9321..8bbdfc53d21 100644
--- a/advisories/github-reviewed/2024/06/GHSA-vh6j-wv25-8qxr/GHSA-vh6j-wv25-8qxr.json
+++ b/advisories/github-reviewed/2024/06/GHSA-vh6j-wv25-8qxr/GHSA-vh6j-wv25-8qxr.json
@@ -3,14 +3,10 @@
"id": "GHSA-vh6j-wv25-8qxr",
"modified": "2024-06-05T17:24:51Z",
"published": "2024-06-05T17:24:51Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Flow Bugfix Releases for Entity Security",
"details": "If you had used entity security and wanted to secure entities not just based on the user's role, but on some property of the user (like the company he belongs to), entity security did not work properly together with the doctrine query cache. This could lead to other users re-using SQL queries from the cache which were built for other users; and thus users could see entities which were not destined for them.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -123,9 +119,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:24:51Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-vpr3-rc99-2wpr/GHSA-vpr3-rc99-2wpr.json b/advisories/github-reviewed/2024/06/GHSA-vpr3-rc99-2wpr/GHSA-vpr3-rc99-2wpr.json
index 72ef7208bec..72918d3e497 100644
--- a/advisories/github-reviewed/2024/06/GHSA-vpr3-rc99-2wpr/GHSA-vpr3-rc99-2wpr.json
+++ b/advisories/github-reviewed/2024/06/GHSA-vpr3-rc99-2wpr/GHSA-vpr3-rc99-2wpr.json
@@ -3,9 +3,7 @@
"id": "GHSA-vpr3-rc99-2wpr",
"modified": "2024-06-05T15:01:46Z",
"published": "2024-06-05T15:01:46Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Information Disclosure in TYPO3 Backend",
"details": "The TYPO3 backend module stores the username of an authenticated backend user in its cache files. By guessing the file path to the cache files it is possible to receive valid backend usernames.",
"severity": [
diff --git a/advisories/github-reviewed/2024/06/GHSA-wr3c-6c22-m9v6/GHSA-wr3c-6c22-m9v6.json b/advisories/github-reviewed/2024/06/GHSA-wr3c-6c22-m9v6/GHSA-wr3c-6c22-m9v6.json
index 472a6bb3100..25c55dc8d39 100644
--- a/advisories/github-reviewed/2024/06/GHSA-wr3c-6c22-m9v6/GHSA-wr3c-6c22-m9v6.json
+++ b/advisories/github-reviewed/2024/06/GHSA-wr3c-6c22-m9v6/GHSA-wr3c-6c22-m9v6.json
@@ -3,9 +3,7 @@
"id": "GHSA-wr3c-6c22-m9v6",
"modified": "2024-06-05T17:28:04Z",
"published": "2024-06-05T17:28:04Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Privilege Escalation in TYPO3 Neos",
"details": "It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation. Logged in editors could access, create and modify content nodes that exist in the workspace of other editors.",
"severity": [
@@ -65,9 +63,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T17:28:04Z",
diff --git a/advisories/github-reviewed/2024/06/GHSA-xvcp-33rc-j8gq/GHSA-xvcp-33rc-j8gq.json b/advisories/github-reviewed/2024/06/GHSA-xvcp-33rc-j8gq/GHSA-xvcp-33rc-j8gq.json
index c7513be175d..1960537ccff 100644
--- a/advisories/github-reviewed/2024/06/GHSA-xvcp-33rc-j8gq/GHSA-xvcp-33rc-j8gq.json
+++ b/advisories/github-reviewed/2024/06/GHSA-xvcp-33rc-j8gq/GHSA-xvcp-33rc-j8gq.json
@@ -3,9 +3,7 @@
"id": "GHSA-xvcp-33rc-j8gq",
"modified": "2024-06-05T14:21:12Z",
"published": "2024-06-05T14:21:12Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Insecure Unserialize in TYPO3 Import/Export",
"details": "Failing to properly validate incoming import data, the Import/Export component is susceptible to insecure unserialize. To exploit this vulnerability a valid backend user account is needed.",
"severity": [
@@ -84,9 +82,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-05T14:21:12Z",
diff --git a/advisories/github-reviewed/2024/11/GHSA-49cc-xrjf-9qf7/GHSA-49cc-xrjf-9qf7.json b/advisories/github-reviewed/2024/11/GHSA-49cc-xrjf-9qf7/GHSA-49cc-xrjf-9qf7.json
index b56258af678..0bf81eadfa1 100644
--- a/advisories/github-reviewed/2024/11/GHSA-49cc-xrjf-9qf7/GHSA-49cc-xrjf-9qf7.json
+++ b/advisories/github-reviewed/2024/11/GHSA-49cc-xrjf-9qf7/GHSA-49cc-xrjf-9qf7.json
@@ -62,9 +62,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-11-21T23:19:07Z",
diff --git a/advisories/github-reviewed/2024/11/GHSA-5cph-wvm9-45gj/GHSA-5cph-wvm9-45gj.json b/advisories/github-reviewed/2024/11/GHSA-5cph-wvm9-45gj/GHSA-5cph-wvm9-45gj.json
index b5cec52cbc6..56ae091f36d 100644
--- a/advisories/github-reviewed/2024/11/GHSA-5cph-wvm9-45gj/GHSA-5cph-wvm9-45gj.json
+++ b/advisories/github-reviewed/2024/11/GHSA-5cph-wvm9-45gj/GHSA-5cph-wvm9-45gj.json
@@ -3,9 +3,7 @@
"id": "GHSA-5cph-wvm9-45gj",
"modified": "2024-11-21T22:21:03Z",
"published": "2024-11-21T22:21:03Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Flowise OverrideConfig security vulnerability",
"details": "### Impact\nFlowise allows developers to inject configuration into the Chainflow during execution through the `overrideConfig` option. This is supported in both the frontend web integration and the backend Prediction API. \n\nThis has a range of fundamental issues that are a **major** security vulnerability. \nWhile this feature is intentional, it should have strong protections added and be disabled by default. \n\nThese issues include: \n1. Remote code execution. While inside a sandbox this allows for\n 1. Sandbox escape \n 2. DoS by crashing the server\n 3. SSRF\n2. Prompt Injection, both System and User\n 1. Full control over LLM prompts\n 2. Server variable and data exfiltration\nAnd many many more such as altering the flow of a conversation, prompt exfiltration via LLM proxying etc.\n\nThese issues are self-targeted and do not persist to other users but do leave the server and business exposed. \nAll issues are shown with the API but also work with the web embed.\n\n### Workarounds\n- `overrideConfig` should be disabled by default\n- `overrideConfig` should have an explicit allow list of variables that are allowed to be modified. This way the user opts-in to where modifications can be made. \n- `vm2` and any forks of it should be removed as in the authors own words, \"fixing the vulnerability seems impossible\". The recommended replacement is https://www.npmjs.com/package/isolated-vm",
"severity": [
diff --git a/advisories/unreviewed/2022/05/GHSA-235f-6f76-gpqc/GHSA-235f-6f76-gpqc.json b/advisories/unreviewed/2022/05/GHSA-235f-6f76-gpqc/GHSA-235f-6f76-gpqc.json
index 81bd468c13e..bd82e0b31d3 100644
--- a/advisories/unreviewed/2022/05/GHSA-235f-6f76-gpqc/GHSA-235f-6f76-gpqc.json
+++ b/advisories/unreviewed/2022/05/GHSA-235f-6f76-gpqc/GHSA-235f-6f76-gpqc.json
@@ -7,12 +7,8 @@
"CVE-2007-3305"
],
"details": "Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execute arbitrary code via a message sent through the MSN protocol, or possibly other protocols, with a crafted UTF-8 string, which triggers improper memory allocation for word wrapping when a window width is used as a buffer size, a different vulnerability than CVE-2007-2478.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-238q-pvrw-f5h8/GHSA-238q-pvrw-f5h8.json b/advisories/unreviewed/2022/05/GHSA-238q-pvrw-f5h8/GHSA-238q-pvrw-f5h8.json
index b6d38ee675f..4e7e1143b62 100644
--- a/advisories/unreviewed/2022/05/GHSA-238q-pvrw-f5h8/GHSA-238q-pvrw-f5h8.json
+++ b/advisories/unreviewed/2022/05/GHSA-238q-pvrw-f5h8/GHSA-238q-pvrw-f5h8.json
@@ -7,12 +7,8 @@
"CVE-2007-3649"
],
"details": "Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-238v-fgv8-vxfq/GHSA-238v-fgv8-vxfq.json b/advisories/unreviewed/2022/05/GHSA-238v-fgv8-vxfq/GHSA-238v-fgv8-vxfq.json
index 9534693095f..1b52a3c63c0 100644
--- a/advisories/unreviewed/2022/05/GHSA-238v-fgv8-vxfq/GHSA-238v-fgv8-vxfq.json
+++ b/advisories/unreviewed/2022/05/GHSA-238v-fgv8-vxfq/GHSA-238v-fgv8-vxfq.json
@@ -7,12 +7,8 @@
"CVE-2007-3421"
],
"details": "The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP before 0.9.9.7 do not verify presence of users in memberlist.dat, which has unknown impact and remote attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-23ch-w9vh-2wxw/GHSA-23ch-w9vh-2wxw.json b/advisories/unreviewed/2022/05/GHSA-23ch-w9vh-2wxw/GHSA-23ch-w9vh-2wxw.json
index 7f1ee02fbf2..cc17229a692 100644
--- a/advisories/unreviewed/2022/05/GHSA-23ch-w9vh-2wxw/GHSA-23ch-w9vh-2wxw.json
+++ b/advisories/unreviewed/2022/05/GHSA-23ch-w9vh-2wxw/GHSA-23ch-w9vh-2wxw.json
@@ -7,12 +7,8 @@
"CVE-2007-3755"
],
"details": "Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a \"tel:\" link, which does not prompt the user before dialing the number.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-244f-56x7-fc34/GHSA-244f-56x7-fc34.json b/advisories/unreviewed/2022/05/GHSA-244f-56x7-fc34/GHSA-244f-56x7-fc34.json
index 88fdb26fe33..a5fccf1e27c 100644
--- a/advisories/unreviewed/2022/05/GHSA-244f-56x7-fc34/GHSA-244f-56x7-fc34.json
+++ b/advisories/unreviewed/2022/05/GHSA-244f-56x7-fc34/GHSA-244f-56x7-fc34.json
@@ -7,12 +7,8 @@
"CVE-2007-3302"
],
"details": "The CallCode ActiveX control in caller.dll 3.0 before 20070713, and 3.0 SP1 before 3.0.5.81, in CA (formerly Computer Associates) eTrust Intrusion Detection allows remote attackers to load arbitrary DLLs on a client system, and execute code from these DLLs, via unspecified \"scriptable functions.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-24wg-c2m3-qxmv/GHSA-24wg-c2m3-qxmv.json b/advisories/unreviewed/2022/05/GHSA-24wg-c2m3-qxmv/GHSA-24wg-c2m3-qxmv.json
index 15a14c4b5a3..272f0efa49b 100644
--- a/advisories/unreviewed/2022/05/GHSA-24wg-c2m3-qxmv/GHSA-24wg-c2m3-qxmv.json
+++ b/advisories/unreviewed/2022/05/GHSA-24wg-c2m3-qxmv/GHSA-24wg-c2m3-qxmv.json
@@ -7,12 +7,8 @@
"CVE-2007-3369"
],
"details": "Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial of service (device hang or reboot) via an INVITE message with a long Via header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-24wg-pppq-h253/GHSA-24wg-pppq-h253.json b/advisories/unreviewed/2022/05/GHSA-24wg-pppq-h253/GHSA-24wg-pppq-h253.json
index 2350d2f4023..529dd625a9d 100644
--- a/advisories/unreviewed/2022/05/GHSA-24wg-pppq-h253/GHSA-24wg-pppq-h253.json
+++ b/advisories/unreviewed/2022/05/GHSA-24wg-pppq-h253/GHSA-24wg-pppq-h253.json
@@ -7,12 +7,8 @@
"CVE-2007-3934"
],
"details": "PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL in the p_mode parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-25x2-3h45-fchh/GHSA-25x2-3h45-fchh.json b/advisories/unreviewed/2022/05/GHSA-25x2-3h45-fchh/GHSA-25x2-3h45-fchh.json
index 1ff9b190b26..ea193a3927f 100644
--- a/advisories/unreviewed/2022/05/GHSA-25x2-3h45-fchh/GHSA-25x2-3h45-fchh.json
+++ b/advisories/unreviewed/2022/05/GHSA-25x2-3h45-fchh/GHSA-25x2-3h45-fchh.json
@@ -7,12 +7,8 @@
"CVE-2007-3400"
],
"details": "The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-26cg-cvm3-73gm/GHSA-26cg-cvm3-73gm.json b/advisories/unreviewed/2022/05/GHSA-26cg-cvm3-73gm/GHSA-26cg-cvm3-73gm.json
index 917b8c8a21d..147cbc8c143 100644
--- a/advisories/unreviewed/2022/05/GHSA-26cg-cvm3-73gm/GHSA-26cg-cvm3-73gm.json
+++ b/advisories/unreviewed/2022/05/GHSA-26cg-cvm3-73gm/GHSA-26cg-cvm3-73gm.json
@@ -7,12 +7,8 @@
"CVE-2007-3940"
],
"details": "Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the svalue parameter in a search action. NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-26r7-75pc-fxh9/GHSA-26r7-75pc-fxh9.json b/advisories/unreviewed/2022/05/GHSA-26r7-75pc-fxh9/GHSA-26r7-75pc-fxh9.json
index 9259efb5b39..9212e7a261c 100644
--- a/advisories/unreviewed/2022/05/GHSA-26r7-75pc-fxh9/GHSA-26r7-75pc-fxh9.json
+++ b/advisories/unreviewed/2022/05/GHSA-26r7-75pc-fxh9/GHSA-26r7-75pc-fxh9.json
@@ -7,12 +7,8 @@
"CVE-2007-3258"
],
"details": "calendar.php in Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via large values to the (1) year and (2) month parameters, which causes negative values to be passed to the mktime library call, and reveals the installation path in the error message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-277x-wqvr-c5w3/GHSA-277x-wqvr-c5w3.json b/advisories/unreviewed/2022/05/GHSA-277x-wqvr-c5w3/GHSA-277x-wqvr-c5w3.json
index b3d9ae36408..aa66ef79227 100644
--- a/advisories/unreviewed/2022/05/GHSA-277x-wqvr-c5w3/GHSA-277x-wqvr-c5w3.json
+++ b/advisories/unreviewed/2022/05/GHSA-277x-wqvr-c5w3/GHSA-277x-wqvr-c5w3.json
@@ -7,12 +7,8 @@
"CVE-2007-3813"
],
"details": "PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-294w-jfj8-gx6r/GHSA-294w-jfj8-gx6r.json b/advisories/unreviewed/2022/05/GHSA-294w-jfj8-gx6r/GHSA-294w-jfj8-gx6r.json
index 1a598abaa0e..99959378a2d 100644
--- a/advisories/unreviewed/2022/05/GHSA-294w-jfj8-gx6r/GHSA-294w-jfj8-gx6r.json
+++ b/advisories/unreviewed/2022/05/GHSA-294w-jfj8-gx6r/GHSA-294w-jfj8-gx6r.json
@@ -7,12 +7,8 @@
"CVE-2007-3636"
],
"details": "Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. NOTE: this information is based upon a vague pre-advisory from a reliable researcher.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2952-9pxc-jw5m/GHSA-2952-9pxc-jw5m.json b/advisories/unreviewed/2022/05/GHSA-2952-9pxc-jw5m/GHSA-2952-9pxc-jw5m.json
index bc0bbbf81cb..388cb7284a5 100644
--- a/advisories/unreviewed/2022/05/GHSA-2952-9pxc-jw5m/GHSA-2952-9pxc-jw5m.json
+++ b/advisories/unreviewed/2022/05/GHSA-2952-9pxc-jw5m/GHSA-2952-9pxc-jw5m.json
@@ -7,12 +7,8 @@
"CVE-2007-3631"
],
"details": "SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2c69-wcv6-7xgx/GHSA-2c69-wcv6-7xgx.json b/advisories/unreviewed/2022/05/GHSA-2c69-wcv6-7xgx/GHSA-2c69-wcv6-7xgx.json
index a5672fd21f4..f6f20389ccd 100644
--- a/advisories/unreviewed/2022/05/GHSA-2c69-wcv6-7xgx/GHSA-2c69-wcv6-7xgx.json
+++ b/advisories/unreviewed/2022/05/GHSA-2c69-wcv6-7xgx/GHSA-2c69-wcv6-7xgx.json
@@ -7,12 +7,8 @@
"CVE-2007-3309"
],
"details": "Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2cff-8v78-vq77/GHSA-2cff-8v78-vq77.json b/advisories/unreviewed/2022/05/GHSA-2cff-8v78-vq77/GHSA-2cff-8v78-vq77.json
index fc49c1449a6..3d43f1601e5 100644
--- a/advisories/unreviewed/2022/05/GHSA-2cff-8v78-vq77/GHSA-2cff-8v78-vq77.json
+++ b/advisories/unreviewed/2022/05/GHSA-2cff-8v78-vq77/GHSA-2cff-8v78-vq77.json
@@ -7,12 +7,8 @@
"CVE-2007-3622"
],
"details": "Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2crp-9jmr-vp26/GHSA-2crp-9jmr-vp26.json b/advisories/unreviewed/2022/05/GHSA-2crp-9jmr-vp26/GHSA-2crp-9jmr-vp26.json
index 4dbff08baa9..19d623197ff 100644
--- a/advisories/unreviewed/2022/05/GHSA-2crp-9jmr-vp26/GHSA-2crp-9jmr-vp26.json
+++ b/advisories/unreviewed/2022/05/GHSA-2crp-9jmr-vp26/GHSA-2crp-9jmr-vp26.json
@@ -7,12 +7,8 @@
"CVE-2007-3491"
],
"details": "Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2f3q-68v6-f6wq/GHSA-2f3q-68v6-f6wq.json b/advisories/unreviewed/2022/05/GHSA-2f3q-68v6-f6wq/GHSA-2f3q-68v6-f6wq.json
index 8346f24e1ab..a621396c10b 100644
--- a/advisories/unreviewed/2022/05/GHSA-2f3q-68v6-f6wq/GHSA-2f3q-68v6-f6wq.json
+++ b/advisories/unreviewed/2022/05/GHSA-2f3q-68v6-f6wq/GHSA-2f3q-68v6-f6wq.json
@@ -7,12 +7,8 @@
"CVE-2007-3776"
],
"details": "Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2fhj-34vp-w6xg/GHSA-2fhj-34vp-w6xg.json b/advisories/unreviewed/2022/05/GHSA-2fhj-34vp-w6xg/GHSA-2fhj-34vp-w6xg.json
index bee43d51a5f..c6db1f0c01e 100644
--- a/advisories/unreviewed/2022/05/GHSA-2fhj-34vp-w6xg/GHSA-2fhj-34vp-w6xg.json
+++ b/advisories/unreviewed/2022/05/GHSA-2fhj-34vp-w6xg/GHSA-2fhj-34vp-w6xg.json
@@ -7,12 +7,8 @@
"CVE-2007-3718"
],
"details": "Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2frc-rr43-3rq2/GHSA-2frc-rr43-3rq2.json b/advisories/unreviewed/2022/05/GHSA-2frc-rr43-3rq2/GHSA-2frc-rr43-3rq2.json
index d5a6e1efa56..d29db9bbb76 100644
--- a/advisories/unreviewed/2022/05/GHSA-2frc-rr43-3rq2/GHSA-2frc-rr43-3rq2.json
+++ b/advisories/unreviewed/2022/05/GHSA-2frc-rr43-3rq2/GHSA-2frc-rr43-3rq2.json
@@ -7,12 +7,8 @@
"CVE-2007-3525"
],
"details": "Ripe Website Manager 0.8.9 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2g6c-q924-h63h/GHSA-2g6c-q924-h63h.json b/advisories/unreviewed/2022/05/GHSA-2g6c-q924-h63h/GHSA-2g6c-q924-h63h.json
index d5eb6216a61..5d043bed360 100644
--- a/advisories/unreviewed/2022/05/GHSA-2g6c-q924-h63h/GHSA-2g6c-q924-h63h.json
+++ b/advisories/unreviewed/2022/05/GHSA-2g6c-q924-h63h/GHSA-2g6c-q924-h63h.json
@@ -7,12 +7,8 @@
"CVE-2007-3339"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-2gx5-g66v-9rrc/GHSA-2gx5-g66v-9rrc.json b/advisories/unreviewed/2022/05/GHSA-2gx5-g66v-9rrc/GHSA-2gx5-g66v-9rrc.json
index 77f6295c969..6cd90e60d84 100644
--- a/advisories/unreviewed/2022/05/GHSA-2gx5-g66v-9rrc/GHSA-2gx5-g66v-9rrc.json
+++ b/advisories/unreviewed/2022/05/GHSA-2gx5-g66v-9rrc/GHSA-2gx5-g66v-9rrc.json
@@ -7,12 +7,8 @@
"CVE-2007-3912"
],
"details": "checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a running process.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2hhm-gh43-f53h/GHSA-2hhm-gh43-f53h.json b/advisories/unreviewed/2022/05/GHSA-2hhm-gh43-f53h/GHSA-2hhm-gh43-f53h.json
index 7c6385a1901..7d61291bbf6 100644
--- a/advisories/unreviewed/2022/05/GHSA-2hhm-gh43-f53h/GHSA-2hhm-gh43-f53h.json
+++ b/advisories/unreviewed/2022/05/GHSA-2hhm-gh43-f53h/GHSA-2hhm-gh43-f53h.json
@@ -7,12 +7,8 @@
"CVE-2007-3211"
],
"details": "Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2hhx-g28r-fqwv/GHSA-2hhx-g28r-fqwv.json b/advisories/unreviewed/2022/05/GHSA-2hhx-g28r-fqwv/GHSA-2hhx-g28r-fqwv.json
index f4f9133f319..a26a5f691a3 100644
--- a/advisories/unreviewed/2022/05/GHSA-2hhx-g28r-fqwv/GHSA-2hhx-g28r-fqwv.json
+++ b/advisories/unreviewed/2022/05/GHSA-2hhx-g28r-fqwv/GHSA-2hhx-g28r-fqwv.json
@@ -7,12 +7,8 @@
"CVE-2007-3544"
],
"details": "Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2hmc-pm44-rgw4/GHSA-2hmc-pm44-rgw4.json b/advisories/unreviewed/2022/05/GHSA-2hmc-pm44-rgw4/GHSA-2hmc-pm44-rgw4.json
index 9428ed3ff44..7a94aca7209 100644
--- a/advisories/unreviewed/2022/05/GHSA-2hmc-pm44-rgw4/GHSA-2hmc-pm44-rgw4.json
+++ b/advisories/unreviewed/2022/05/GHSA-2hmc-pm44-rgw4/GHSA-2hmc-pm44-rgw4.json
@@ -7,12 +7,8 @@
"CVE-2007-3238"
],
"details": "Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -68,9 +64,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2hx7-vxgc-r4p4/GHSA-2hx7-vxgc-r4p4.json b/advisories/unreviewed/2022/05/GHSA-2hx7-vxgc-r4p4/GHSA-2hx7-vxgc-r4p4.json
index a16bd1403d6..dab54db3263 100644
--- a/advisories/unreviewed/2022/05/GHSA-2hx7-vxgc-r4p4/GHSA-2hx7-vxgc-r4p4.json
+++ b/advisories/unreviewed/2022/05/GHSA-2hx7-vxgc-r4p4/GHSA-2hx7-vxgc-r4p4.json
@@ -7,12 +7,8 @@
"CVE-2007-3804"
],
"details": "The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2m5c-p827-r3fx/GHSA-2m5c-p827-r3fx.json b/advisories/unreviewed/2022/05/GHSA-2m5c-p827-r3fx/GHSA-2m5c-p827-r3fx.json
index 7ab2c411f52..7525fbfee7d 100644
--- a/advisories/unreviewed/2022/05/GHSA-2m5c-p827-r3fx/GHSA-2m5c-p827-r3fx.json
+++ b/advisories/unreviewed/2022/05/GHSA-2m5c-p827-r3fx/GHSA-2m5c-p827-r3fx.json
@@ -7,12 +7,8 @@
"CVE-2007-3709"
],
"details": "CRLF injection vulnerability in the redirect function in url_helper.php in CodeIgniter 1.5.3 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in an unspecified parameter, as demonstrated by a Set-Cookie header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2mmg-r5qc-hhcj/GHSA-2mmg-r5qc-hhcj.json b/advisories/unreviewed/2022/05/GHSA-2mmg-r5qc-hhcj/GHSA-2mmg-r5qc-hhcj.json
index 62f4b6e0f36..72f065d5295 100644
--- a/advisories/unreviewed/2022/05/GHSA-2mmg-r5qc-hhcj/GHSA-2mmg-r5qc-hhcj.json
+++ b/advisories/unreviewed/2022/05/GHSA-2mmg-r5qc-hhcj/GHSA-2mmg-r5qc-hhcj.json
@@ -7,12 +7,8 @@
"CVE-2007-3644"
],
"details": "archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -92,9 +88,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2p5w-vr7w-w9xh/GHSA-2p5w-vr7w-w9xh.json b/advisories/unreviewed/2022/05/GHSA-2p5w-vr7w-w9xh/GHSA-2p5w-vr7w-w9xh.json
index 8b0eee35fb2..0b7afaa7604 100644
--- a/advisories/unreviewed/2022/05/GHSA-2p5w-vr7w-w9xh/GHSA-2p5w-vr7w-w9xh.json
+++ b/advisories/unreviewed/2022/05/GHSA-2p5w-vr7w-w9xh/GHSA-2p5w-vr7w-w9xh.json
@@ -7,12 +7,8 @@
"CVE-2007-3431"
],
"details": "PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2p7h-c2c4-7p56/GHSA-2p7h-c2c4-7p56.json b/advisories/unreviewed/2022/05/GHSA-2p7h-c2c4-7p56/GHSA-2p7h-c2c4-7p56.json
index 21eaee7971e..8309b57616d 100644
--- a/advisories/unreviewed/2022/05/GHSA-2p7h-c2c4-7p56/GHSA-2p7h-c2c4-7p56.json
+++ b/advisories/unreviewed/2022/05/GHSA-2p7h-c2c4-7p56/GHSA-2p7h-c2c4-7p56.json
@@ -7,12 +7,8 @@
"CVE-2007-3220"
],
"details": "PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2p9j-f7cx-vh7m/GHSA-2p9j-f7cx-vh7m.json b/advisories/unreviewed/2022/05/GHSA-2p9j-f7cx-vh7m/GHSA-2p9j-f7cx-vh7m.json
index 28b0850ff1c..a425d1a07ab 100644
--- a/advisories/unreviewed/2022/05/GHSA-2p9j-f7cx-vh7m/GHSA-2p9j-f7cx-vh7m.json
+++ b/advisories/unreviewed/2022/05/GHSA-2p9j-f7cx-vh7m/GHSA-2p9j-f7cx-vh7m.json
@@ -7,12 +7,8 @@
"CVE-2007-3416"
],
"details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org WebAPP 0.8 through 0.9.9.6; and (b) web-app.net WebAPP 0.9.9.3.3, 0.9.9.3.4, and 2007; allow remote attackers to perform deletions as administrators.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-2ph9-m2f8-vv39/GHSA-2ph9-m2f8-vv39.json b/advisories/unreviewed/2022/05/GHSA-2ph9-m2f8-vv39/GHSA-2ph9-m2f8-vv39.json
index 1caca402a12..781acae57d5 100644
--- a/advisories/unreviewed/2022/05/GHSA-2ph9-m2f8-vv39/GHSA-2ph9-m2f8-vv39.json
+++ b/advisories/unreviewed/2022/05/GHSA-2ph9-m2f8-vv39/GHSA-2ph9-m2f8-vv39.json
@@ -7,12 +7,8 @@
"CVE-2007-3637"
],
"details": "SQL injection vulnerability in MKPortal 1.1.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZD-00000008. this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-2qgf-99w3-fmrx/GHSA-2qgf-99w3-fmrx.json b/advisories/unreviewed/2022/05/GHSA-2qgf-99w3-fmrx/GHSA-2qgf-99w3-fmrx.json
index 63fbad3f957..fbed139dd22 100644
--- a/advisories/unreviewed/2022/05/GHSA-2qgf-99w3-fmrx/GHSA-2qgf-99w3-fmrx.json
+++ b/advisories/unreviewed/2022/05/GHSA-2qgf-99w3-fmrx/GHSA-2qgf-99w3-fmrx.json
@@ -7,12 +7,8 @@
"CVE-2007-3754"
],
"details": "Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-2qgh-j9vp-6pwj/GHSA-2qgh-j9vp-6pwj.json b/advisories/unreviewed/2022/05/GHSA-2qgh-j9vp-6pwj/GHSA-2qgh-j9vp-6pwj.json
index 84c682650a2..ddf82701546 100644
--- a/advisories/unreviewed/2022/05/GHSA-2qgh-j9vp-6pwj/GHSA-2qgh-j9vp-6pwj.json
+++ b/advisories/unreviewed/2022/05/GHSA-2qgh-j9vp-6pwj/GHSA-2qgh-j9vp-6pwj.json
@@ -7,12 +7,8 @@
"CVE-2007-3298"
],
"details": "SQL injection vulnerability in Spey before 0.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to MessageProcessor.cc and possibly other components.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2vv4-xm6v-5wf5/GHSA-2vv4-xm6v-5wf5.json b/advisories/unreviewed/2022/05/GHSA-2vv4-xm6v-5wf5/GHSA-2vv4-xm6v-5wf5.json
index 99eb60c9cfd..547829eed6a 100644
--- a/advisories/unreviewed/2022/05/GHSA-2vv4-xm6v-5wf5/GHSA-2vv4-xm6v-5wf5.json
+++ b/advisories/unreviewed/2022/05/GHSA-2vv4-xm6v-5wf5/GHSA-2vv4-xm6v-5wf5.json
@@ -7,12 +7,8 @@
"CVE-2019-12962"
],
"details": "LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-2w7p-wvwf-625f/GHSA-2w7p-wvwf-625f.json b/advisories/unreviewed/2022/05/GHSA-2w7p-wvwf-625f/GHSA-2w7p-wvwf-625f.json
index 177df437fff..dca39b07f74 100644
--- a/advisories/unreviewed/2022/05/GHSA-2w7p-wvwf-625f/GHSA-2w7p-wvwf-625f.json
+++ b/advisories/unreviewed/2022/05/GHSA-2w7p-wvwf-625f/GHSA-2w7p-wvwf-625f.json
@@ -7,12 +7,8 @@
"CVE-2007-3726"
],
"details": "Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2x6q-8fjr-3hj2/GHSA-2x6q-8fjr-3hj2.json b/advisories/unreviewed/2022/05/GHSA-2x6q-8fjr-3hj2/GHSA-2x6q-8fjr-3hj2.json
index 6fdcd8d3031..7109cea77ae 100644
--- a/advisories/unreviewed/2022/05/GHSA-2x6q-8fjr-3hj2/GHSA-2x6q-8fjr-3hj2.json
+++ b/advisories/unreviewed/2022/05/GHSA-2x6q-8fjr-3hj2/GHSA-2x6q-8fjr-3hj2.json
@@ -7,12 +7,8 @@
"CVE-2007-3748"
],
"details": "Buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in iChat on Apple Mac OS X 10.3.9 and 10.4.10 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2x97-hfgj-7xpw/GHSA-2x97-hfgj-7xpw.json b/advisories/unreviewed/2022/05/GHSA-2x97-hfgj-7xpw/GHSA-2x97-hfgj-7xpw.json
index 72777265faa..fc0ec89c491 100644
--- a/advisories/unreviewed/2022/05/GHSA-2x97-hfgj-7xpw/GHSA-2x97-hfgj-7xpw.json
+++ b/advisories/unreviewed/2022/05/GHSA-2x97-hfgj-7xpw/GHSA-2x97-hfgj-7xpw.json
@@ -7,12 +7,8 @@
"CVE-2018-21009"
],
"details": "Poppler before 0.76.0 has an integer overflow in Parser::makeStream in Parser.cc.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-2xvj-x73g-2j9w/GHSA-2xvj-x73g-2j9w.json b/advisories/unreviewed/2022/05/GHSA-2xvj-x73g-2j9w/GHSA-2xvj-x73g-2j9w.json
index bd5f30af434..2d3eb40c598 100644
--- a/advisories/unreviewed/2022/05/GHSA-2xvj-x73g-2j9w/GHSA-2xvj-x73g-2j9w.json
+++ b/advisories/unreviewed/2022/05/GHSA-2xvj-x73g-2j9w/GHSA-2xvj-x73g-2j9w.json
@@ -7,12 +7,8 @@
"CVE-2007-3946"
],
"details": "mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -92,9 +88,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-32hv-c84f-hvp9/GHSA-32hv-c84f-hvp9.json b/advisories/unreviewed/2022/05/GHSA-32hv-c84f-hvp9/GHSA-32hv-c84f-hvp9.json
index fef1aec3cda..067e1839f13 100644
--- a/advisories/unreviewed/2022/05/GHSA-32hv-c84f-hvp9/GHSA-32hv-c84f-hvp9.json
+++ b/advisories/unreviewed/2022/05/GHSA-32hv-c84f-hvp9/GHSA-32hv-c84f-hvp9.json
@@ -7,12 +7,8 @@
"CVE-2007-3516"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in kayit.asp in Gorki Online Santrac Sitesi allow remote attackers to inject arbitrary web script or HTML via the (1) kullanici, (2) posta, or (3) takim_adi parameter to uyeler.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-346q-mxg8-55g2/GHSA-346q-mxg8-55g2.json b/advisories/unreviewed/2022/05/GHSA-346q-mxg8-55g2/GHSA-346q-mxg8-55g2.json
index fca8d9fc8e1..36d57fbee14 100644
--- a/advisories/unreviewed/2022/05/GHSA-346q-mxg8-55g2/GHSA-346q-mxg8-55g2.json
+++ b/advisories/unreviewed/2022/05/GHSA-346q-mxg8-55g2/GHSA-346q-mxg8-55g2.json
@@ -7,12 +7,8 @@
"CVE-2007-3925"
],
"details": "Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-349h-m66g-cww7/GHSA-349h-m66g-cww7.json b/advisories/unreviewed/2022/05/GHSA-349h-m66g-cww7/GHSA-349h-m66g-cww7.json
index cb9cd27cc66..ee63caff4e2 100644
--- a/advisories/unreviewed/2022/05/GHSA-349h-m66g-cww7/GHSA-349h-m66g-cww7.json
+++ b/advisories/unreviewed/2022/05/GHSA-349h-m66g-cww7/GHSA-349h-m66g-cww7.json
@@ -7,12 +7,8 @@
"CVE-2007-3549"
],
"details": "SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-34f8-9qw7-mxcp/GHSA-34f8-9qw7-mxcp.json b/advisories/unreviewed/2022/05/GHSA-34f8-9qw7-mxcp/GHSA-34f8-9qw7-mxcp.json
index a8d5a79153c..23a4173d5f8 100644
--- a/advisories/unreviewed/2022/05/GHSA-34f8-9qw7-mxcp/GHSA-34f8-9qw7-mxcp.json
+++ b/advisories/unreviewed/2022/05/GHSA-34f8-9qw7-mxcp/GHSA-34f8-9qw7-mxcp.json
@@ -7,12 +7,8 @@
"CVE-2007-3406"
],
"details": "Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribute of a body tag; or (5) the background:url attribute declared in the BODY parameter of a STYLE tag.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3532-6vcg-55x2/GHSA-3532-6vcg-55x2.json b/advisories/unreviewed/2022/05/GHSA-3532-6vcg-55x2/GHSA-3532-6vcg-55x2.json
index b14d6cfb564..62628e6ffd2 100644
--- a/advisories/unreviewed/2022/05/GHSA-3532-6vcg-55x2/GHSA-3532-6vcg-55x2.json
+++ b/advisories/unreviewed/2022/05/GHSA-3532-6vcg-55x2/GHSA-3532-6vcg-55x2.json
@@ -7,12 +7,8 @@
"CVE-2007-3577"
],
"details": "PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain \"window[eval\" and similar expressions; (5) certain Function expressions; (6) certain '=' expressions, as demonstrated by a 'whatever=\"something\"' sequence; and (7) certain \"with\" expressions, which allows remote attackers to inject arbitrary web script.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-35mv-64rp-pmf8/GHSA-35mv-64rp-pmf8.json b/advisories/unreviewed/2022/05/GHSA-35mv-64rp-pmf8/GHSA-35mv-64rp-pmf8.json
index 3b9305c301f..05589373481 100644
--- a/advisories/unreviewed/2022/05/GHSA-35mv-64rp-pmf8/GHSA-35mv-64rp-pmf8.json
+++ b/advisories/unreviewed/2022/05/GHSA-35mv-64rp-pmf8/GHSA-35mv-64rp-pmf8.json
@@ -7,12 +7,8 @@
"CVE-2007-3607"
],
"details": "Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-35rj-j8qg-5vgh/GHSA-35rj-j8qg-5vgh.json b/advisories/unreviewed/2022/05/GHSA-35rj-j8qg-5vgh/GHSA-35rj-j8qg-5vgh.json
index bf3050b64af..5c0fbdd9c49 100644
--- a/advisories/unreviewed/2022/05/GHSA-35rj-j8qg-5vgh/GHSA-35rj-j8qg-5vgh.json
+++ b/advisories/unreviewed/2022/05/GHSA-35rj-j8qg-5vgh/GHSA-35rj-j8qg-5vgh.json
@@ -7,12 +7,8 @@
"CVE-2007-3373"
],
"details": "daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-37qf-q5qg-m9f2/GHSA-37qf-q5qg-m9f2.json b/advisories/unreviewed/2022/05/GHSA-37qf-q5qg-m9f2/GHSA-37qf-q5qg-m9f2.json
index 989d87d8315..3994c002919 100644
--- a/advisories/unreviewed/2022/05/GHSA-37qf-q5qg-m9f2/GHSA-37qf-q5qg-m9f2.json
+++ b/advisories/unreviewed/2022/05/GHSA-37qf-q5qg-m9f2/GHSA-37qf-q5qg-m9f2.json
@@ -7,12 +7,8 @@
"CVE-2007-3214"
],
"details": "SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the template parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-38xp-mhx6-r7xx/GHSA-38xp-mhx6-r7xx.json b/advisories/unreviewed/2022/05/GHSA-38xp-mhx6-r7xx/GHSA-38xp-mhx6-r7xx.json
index 2cd00be5fa5..e85e976a1a9 100644
--- a/advisories/unreviewed/2022/05/GHSA-38xp-mhx6-r7xx/GHSA-38xp-mhx6-r7xx.json
+++ b/advisories/unreviewed/2022/05/GHSA-38xp-mhx6-r7xx/GHSA-38xp-mhx6-r7xx.json
@@ -7,12 +7,8 @@
"CVE-2007-3509"
],
"details": "Heap-based buffer overflow in the RPC subsystem in Symantec Backup Exec for Windows Servers 10.0, 10d, and 11d allows remote attackers to cause a denial of service (process exit) and possibly execute arbitrary code via crafted ncacn_ip_tcp requests.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-394v-q6vg-27qq/GHSA-394v-q6vg-27qq.json b/advisories/unreviewed/2022/05/GHSA-394v-q6vg-27qq/GHSA-394v-q6vg-27qq.json
index 54d73f6bdef..e9d1715e4fa 100644
--- a/advisories/unreviewed/2022/05/GHSA-394v-q6vg-27qq/GHSA-394v-q6vg-27qq.json
+++ b/advisories/unreviewed/2022/05/GHSA-394v-q6vg-27qq/GHSA-394v-q6vg-27qq.json
@@ -7,12 +7,8 @@
"CVE-2007-3691"
],
"details": "Multiple SQL injection vulnerabilities in changePW.php in AV Tutorial Script (avtutorial) 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) userid parameters, a different issue than CVE-2007-3630.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-39v5-536x-qjhm/GHSA-39v5-536x-qjhm.json b/advisories/unreviewed/2022/05/GHSA-39v5-536x-qjhm/GHSA-39v5-536x-qjhm.json
index 4a8487a4c3f..606a49add94 100644
--- a/advisories/unreviewed/2022/05/GHSA-39v5-536x-qjhm/GHSA-39v5-536x-qjhm.json
+++ b/advisories/unreviewed/2022/05/GHSA-39v5-536x-qjhm/GHSA-39v5-536x-qjhm.json
@@ -7,12 +7,8 @@
"CVE-2007-3727"
],
"details": "Multiple unspecified vulnerabilities in Webmatic before 2.7 have unknown impact and attack vectors, related to the \"administration area.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-39w4-7w4p-hfw4/GHSA-39w4-7w4p-hfw4.json b/advisories/unreviewed/2022/05/GHSA-39w4-7w4p-hfw4/GHSA-39w4-7w4p-hfw4.json
index 2112fca60d7..c1ff8401598 100644
--- a/advisories/unreviewed/2022/05/GHSA-39w4-7w4p-hfw4/GHSA-39w4-7w4p-hfw4.json
+++ b/advisories/unreviewed/2022/05/GHSA-39w4-7w4p-hfw4/GHSA-39w4-7w4p-hfw4.json
@@ -7,12 +7,8 @@
"CVE-2007-3589"
],
"details": "Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-39wh-r3pj-pmhm/GHSA-39wh-r3pj-pmhm.json b/advisories/unreviewed/2022/05/GHSA-39wh-r3pj-pmhm/GHSA-39wh-r3pj-pmhm.json
index 4a035ad304d..f152a786a3c 100644
--- a/advisories/unreviewed/2022/05/GHSA-39wh-r3pj-pmhm/GHSA-39wh-r3pj-pmhm.json
+++ b/advisories/unreviewed/2022/05/GHSA-39wh-r3pj-pmhm/GHSA-39wh-r3pj-pmhm.json
@@ -7,12 +7,8 @@
"CVE-2007-3275"
],
"details": "MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-39xg-qc4x-j5fj/GHSA-39xg-qc4x-j5fj.json b/advisories/unreviewed/2022/05/GHSA-39xg-qc4x-j5fj/GHSA-39xg-qc4x-j5fj.json
index 5adf86b136c..964eeaaf309 100644
--- a/advisories/unreviewed/2022/05/GHSA-39xg-qc4x-j5fj/GHSA-39xg-qc4x-j5fj.json
+++ b/advisories/unreviewed/2022/05/GHSA-39xg-qc4x-j5fj/GHSA-39xg-qc4x-j5fj.json
@@ -7,12 +7,8 @@
"CVE-2007-3451"
],
"details": "PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3c6c-24gr-prmj/GHSA-3c6c-24gr-prmj.json b/advisories/unreviewed/2022/05/GHSA-3c6c-24gr-prmj/GHSA-3c6c-24gr-prmj.json
index 7bc43bae82d..d4156bfa5d4 100644
--- a/advisories/unreviewed/2022/05/GHSA-3c6c-24gr-prmj/GHSA-3c6c-24gr-prmj.json
+++ b/advisories/unreviewed/2022/05/GHSA-3c6c-24gr-prmj/GHSA-3c6c-24gr-prmj.json
@@ -7,12 +7,8 @@
"CVE-2007-3932"
],
"details": "uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3fvp-w97c-35v6/GHSA-3fvp-w97c-35v6.json b/advisories/unreviewed/2022/05/GHSA-3fvp-w97c-35v6/GHSA-3fvp-w97c-35v6.json
index fd8ac4d58c8..8108718aa98 100644
--- a/advisories/unreviewed/2022/05/GHSA-3fvp-w97c-35v6/GHSA-3fvp-w97c-35v6.json
+++ b/advisories/unreviewed/2022/05/GHSA-3fvp-w97c-35v6/GHSA-3fvp-w97c-35v6.json
@@ -7,12 +7,8 @@
"CVE-2018-11569"
],
"details": "Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3fxq-f952-g28c/GHSA-3fxq-f952-g28c.json b/advisories/unreviewed/2022/05/GHSA-3fxq-f952-g28c/GHSA-3fxq-f952-g28c.json
index 17a5301ddff..434a3f298d1 100644
--- a/advisories/unreviewed/2022/05/GHSA-3fxq-f952-g28c/GHSA-3fxq-f952-g28c.json
+++ b/advisories/unreviewed/2022/05/GHSA-3fxq-f952-g28c/GHSA-3fxq-f952-g28c.json
@@ -7,12 +7,8 @@
"CVE-2007-3223"
],
"details": "Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3gmg-2p2p-x5wp/GHSA-3gmg-2p2p-x5wp.json b/advisories/unreviewed/2022/05/GHSA-3gmg-2p2p-x5wp/GHSA-3gmg-2p2p-x5wp.json
index f823e5f1af8..f718cc3c617 100644
--- a/advisories/unreviewed/2022/05/GHSA-3gmg-2p2p-x5wp/GHSA-3gmg-2p2p-x5wp.json
+++ b/advisories/unreviewed/2022/05/GHSA-3gmg-2p2p-x5wp/GHSA-3gmg-2p2p-x5wp.json
@@ -7,12 +7,8 @@
"CVE-2007-3661"
],
"details": "Eltima Software Virtual Serial Port (VSPAX) ActiveX control (VSPort.DLL) allows remote attackers to cause a denial of service via certain function calls, as demonstrated via the (1) Attach, (2) Write, and (3) WriteStr functions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3h5p-423v-vjw8/GHSA-3h5p-423v-vjw8.json b/advisories/unreviewed/2022/05/GHSA-3h5p-423v-vjw8/GHSA-3h5p-423v-vjw8.json
index 58b146e68a3..0354e0dc300 100644
--- a/advisories/unreviewed/2022/05/GHSA-3h5p-423v-vjw8/GHSA-3h5p-423v-vjw8.json
+++ b/advisories/unreviewed/2022/05/GHSA-3h5p-423v-vjw8/GHSA-3h5p-423v-vjw8.json
@@ -7,12 +7,8 @@
"CVE-2007-3692"
],
"details": "Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3hh3-wrj3-mf78/GHSA-3hh3-wrj3-mf78.json b/advisories/unreviewed/2022/05/GHSA-3hh3-wrj3-mf78/GHSA-3hh3-wrj3-mf78.json
index e82079f2467..e33d10d8cbb 100644
--- a/advisories/unreviewed/2022/05/GHSA-3hh3-wrj3-mf78/GHSA-3hh3-wrj3-mf78.json
+++ b/advisories/unreviewed/2022/05/GHSA-3hh3-wrj3-mf78/GHSA-3hh3-wrj3-mf78.json
@@ -7,12 +7,8 @@
"CVE-2007-3653"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-3m9j-7hqr-2v6h/GHSA-3m9j-7hqr-2v6h.json b/advisories/unreviewed/2022/05/GHSA-3m9j-7hqr-2v6h/GHSA-3m9j-7hqr-2v6h.json
index 124be256184..25444a2a0b3 100644
--- a/advisories/unreviewed/2022/05/GHSA-3m9j-7hqr-2v6h/GHSA-3m9j-7hqr-2v6h.json
+++ b/advisories/unreviewed/2022/05/GHSA-3m9j-7hqr-2v6h/GHSA-3m9j-7hqr-2v6h.json
@@ -7,12 +7,8 @@
"CVE-2007-3430"
],
"details": "SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3mxh-jhq3-34vp/GHSA-3mxh-jhq3-34vp.json b/advisories/unreviewed/2022/05/GHSA-3mxh-jhq3-34vp/GHSA-3mxh-jhq3-34vp.json
index c909efec9da..6fa0a44a075 100644
--- a/advisories/unreviewed/2022/05/GHSA-3mxh-jhq3-34vp/GHSA-3mxh-jhq3-34vp.json
+++ b/advisories/unreviewed/2022/05/GHSA-3mxh-jhq3-34vp/GHSA-3mxh-jhq3-34vp.json
@@ -7,12 +7,8 @@
"CVE-2019-2175"
],
"details": "In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3pq7-vjqr-6jh5/GHSA-3pq7-vjqr-6jh5.json b/advisories/unreviewed/2022/05/GHSA-3pq7-vjqr-6jh5/GHSA-3pq7-vjqr-6jh5.json
index 0bef9121a79..931cd7c57b7 100644
--- a/advisories/unreviewed/2022/05/GHSA-3pq7-vjqr-6jh5/GHSA-3pq7-vjqr-6jh5.json
+++ b/advisories/unreviewed/2022/05/GHSA-3pq7-vjqr-6jh5/GHSA-3pq7-vjqr-6jh5.json
@@ -7,12 +7,8 @@
"CVE-2007-3598"
],
"details": "index.php in vtiger CRM before 5.0.3 allows remote authenticated users to obtain all users' names and e-mail addresses, and possibly change user settings, via a modified record parameter in a DetailView action to the Users module. NOTE: the vendor disputes the changing of settings, reporting that the attack vector results in a \"You are not permitted to execute this Operation\" error message in a 5.0.3 demo.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3q5j-fh9m-jf9q/GHSA-3q5j-fh9m-jf9q.json b/advisories/unreviewed/2022/05/GHSA-3q5j-fh9m-jf9q/GHSA-3q5j-fh9m-jf9q.json
index 1ff1252745b..48e15ae3918 100644
--- a/advisories/unreviewed/2022/05/GHSA-3q5j-fh9m-jf9q/GHSA-3q5j-fh9m-jf9q.json
+++ b/advisories/unreviewed/2022/05/GHSA-3q5j-fh9m-jf9q/GHSA-3q5j-fh9m-jf9q.json
@@ -7,12 +7,8 @@
"CVE-2007-3760"
],
"details": "Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-3vcj-crmp-9f49/GHSA-3vcj-crmp-9f49.json b/advisories/unreviewed/2022/05/GHSA-3vcj-crmp-9f49/GHSA-3vcj-crmp-9f49.json
index db5f92d55b5..475b8a61310 100644
--- a/advisories/unreviewed/2022/05/GHSA-3vcj-crmp-9f49/GHSA-3vcj-crmp-9f49.json
+++ b/advisories/unreviewed/2022/05/GHSA-3vcj-crmp-9f49/GHSA-3vcj-crmp-9f49.json
@@ -7,12 +7,8 @@
"CVE-2007-3539"
],
"details": "Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-3vmp-mc23-cw7f/GHSA-3vmp-mc23-cw7f.json b/advisories/unreviewed/2022/05/GHSA-3vmp-mc23-cw7f/GHSA-3vmp-mc23-cw7f.json
index 744ba64c6d1..3594e845778 100644
--- a/advisories/unreviewed/2022/05/GHSA-3vmp-mc23-cw7f/GHSA-3vmp-mc23-cw7f.json
+++ b/advisories/unreviewed/2022/05/GHSA-3vmp-mc23-cw7f/GHSA-3vmp-mc23-cw7f.json
@@ -7,12 +7,8 @@
"CVE-2007-3296"
],
"details": "The ThunderServer.webThunder.1 ActiveX control in xunlei Web Thunderbolt 1.7.3.109 allows remote attackers to download arbitrary files and conduct other unauthorized actions by invoking dangerous methods.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-3xcc-p2pv-9q9p/GHSA-3xcc-p2pv-9q9p.json b/advisories/unreviewed/2022/05/GHSA-3xcc-p2pv-9q9p/GHSA-3xcc-p2pv-9q9p.json
index fa3973acaf4..3d1993a5760 100644
--- a/advisories/unreviewed/2022/05/GHSA-3xcc-p2pv-9q9p/GHSA-3xcc-p2pv-9q9p.json
+++ b/advisories/unreviewed/2022/05/GHSA-3xcc-p2pv-9q9p/GHSA-3xcc-p2pv-9q9p.json
@@ -7,12 +7,8 @@
"CVE-2007-3578"
],
"details": "PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remote attackers to inject arbitrary web script.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4227-j2p4-qfjx/GHSA-4227-j2p4-qfjx.json b/advisories/unreviewed/2022/05/GHSA-4227-j2p4-qfjx/GHSA-4227-j2p4-qfjx.json
index 301e372c918..7043f027a7f 100644
--- a/advisories/unreviewed/2022/05/GHSA-4227-j2p4-qfjx/GHSA-4227-j2p4-qfjx.json
+++ b/advisories/unreviewed/2022/05/GHSA-4227-j2p4-qfjx/GHSA-4227-j2p4-qfjx.json
@@ -7,12 +7,8 @@
"CVE-2007-3393"
],
"details": "Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via crafted DHCP-over-DOCSIS packets.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -112,9 +108,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-42q6-p5h5-993x/GHSA-42q6-p5h5-993x.json b/advisories/unreviewed/2022/05/GHSA-42q6-p5h5-993x/GHSA-42q6-p5h5-993x.json
index 72c720bc58d..200224b722d 100644
--- a/advisories/unreviewed/2022/05/GHSA-42q6-p5h5-993x/GHSA-42q6-p5h5-993x.json
+++ b/advisories/unreviewed/2022/05/GHSA-42q6-p5h5-993x/GHSA-42q6-p5h5-993x.json
@@ -7,12 +7,8 @@
"CVE-2007-3751"
],
"details": "Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-434f-9q9x-rchx/GHSA-434f-9q9x-rchx.json b/advisories/unreviewed/2022/05/GHSA-434f-9q9x-rchx/GHSA-434f-9q9x-rchx.json
index 3fd8e57925b..d9cce25d5c4 100644
--- a/advisories/unreviewed/2022/05/GHSA-434f-9q9x-rchx/GHSA-434f-9q9x-rchx.json
+++ b/advisories/unreviewed/2022/05/GHSA-434f-9q9x-rchx/GHSA-434f-9q9x-rchx.json
@@ -7,12 +7,8 @@
"CVE-2007-3959"
],
"details": "The IM Server (aka IMserve or IMserver) 2.0.5.30 and probably earlier in Ipswitch Instant Messaging before 2.07 in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (daemon crash) via certain data to TCP port 5179 that overwrites a destructor, as reachable by the (1) DoAttachVideoSender, (2) DoAttachVideoReceiver, (3) DoAttachAudioSender, and (4) DoAttachAudioReceiver functions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-438m-xgcg-7xx6/GHSA-438m-xgcg-7xx6.json b/advisories/unreviewed/2022/05/GHSA-438m-xgcg-7xx6/GHSA-438m-xgcg-7xx6.json
index 58f4e414243..5121e2a0ede 100644
--- a/advisories/unreviewed/2022/05/GHSA-438m-xgcg-7xx6/GHSA-438m-xgcg-7xx6.json
+++ b/advisories/unreviewed/2022/05/GHSA-438m-xgcg-7xx6/GHSA-438m-xgcg-7xx6.json
@@ -7,12 +7,8 @@
"CVE-2007-3452"
],
"details": "SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-43pp-4gq9-93xw/GHSA-43pp-4gq9-93xw.json b/advisories/unreviewed/2022/05/GHSA-43pp-4gq9-93xw/GHSA-43pp-4gq9-93xw.json
index 871c475c50c..1b732195b50 100644
--- a/advisories/unreviewed/2022/05/GHSA-43pp-4gq9-93xw/GHSA-43pp-4gq9-93xw.json
+++ b/advisories/unreviewed/2022/05/GHSA-43pp-4gq9-93xw/GHSA-43pp-4gq9-93xw.json
@@ -7,12 +7,8 @@
"CVE-2007-3572"
],
"details": "Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded \"`\" (backtick) characters (%60 sequences).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-444g-7h8r-45m8/GHSA-444g-7h8r-45m8.json b/advisories/unreviewed/2022/05/GHSA-444g-7h8r-45m8/GHSA-444g-7h8r-45m8.json
index 76ca66c5408..837f23984a1 100644
--- a/advisories/unreviewed/2022/05/GHSA-444g-7h8r-45m8/GHSA-444g-7h8r-45m8.json
+++ b/advisories/unreviewed/2022/05/GHSA-444g-7h8r-45m8/GHSA-444g-7h8r-45m8.json
@@ -7,12 +7,8 @@
"CVE-2007-3615"
],
"details": "Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attackers to cause a denial of service (process crash) via a URI of a certain length that contains a sap-isc-key parameter, related to configuration of a web cache.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-446h-6m77-5x8g/GHSA-446h-6m77-5x8g.json b/advisories/unreviewed/2022/05/GHSA-446h-6m77-5x8g/GHSA-446h-6m77-5x8g.json
index 05161409b2b..6e71468371d 100644
--- a/advisories/unreviewed/2022/05/GHSA-446h-6m77-5x8g/GHSA-446h-6m77-5x8g.json
+++ b/advisories/unreviewed/2022/05/GHSA-446h-6m77-5x8g/GHSA-446h-6m77-5x8g.json
@@ -7,12 +7,8 @@
"CVE-2007-3531"
],
"details": "The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-45g7-4cgq-4vp4/GHSA-45g7-4cgq-4vp4.json b/advisories/unreviewed/2022/05/GHSA-45g7-4cgq-4vp4/GHSA-45g7-4cgq-4vp4.json
index 32fe62e27d7..5d2462c7edf 100644
--- a/advisories/unreviewed/2022/05/GHSA-45g7-4cgq-4vp4/GHSA-45g7-4cgq-4vp4.json
+++ b/advisories/unreviewed/2022/05/GHSA-45g7-4cgq-4vp4/GHSA-45g7-4cgq-4vp4.json
@@ -7,12 +7,8 @@
"CVE-2019-1010173"
],
"details": "Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fixed version is: after commit 738ead193aff380a7e3d7ffb8e11e446f76867f3.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-45xr-m8r3-59qh/GHSA-45xr-m8r3-59qh.json b/advisories/unreviewed/2022/05/GHSA-45xr-m8r3-59qh/GHSA-45xr-m8r3-59qh.json
index 54544571243..50b9ac5f96d 100644
--- a/advisories/unreviewed/2022/05/GHSA-45xr-m8r3-59qh/GHSA-45xr-m8r3-59qh.json
+++ b/advisories/unreviewed/2022/05/GHSA-45xr-m8r3-59qh/GHSA-45xr-m8r3-59qh.json
@@ -7,12 +7,8 @@
"CVE-2007-3542"
],
"details": "Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-46qf-q25w-6m5v/GHSA-46qf-q25w-6m5v.json b/advisories/unreviewed/2022/05/GHSA-46qf-q25w-6m5v/GHSA-46qf-q25w-6m5v.json
index 65d20da8c7c..7aea8fbe4b5 100644
--- a/advisories/unreviewed/2022/05/GHSA-46qf-q25w-6m5v/GHSA-46qf-q25w-6m5v.json
+++ b/advisories/unreviewed/2022/05/GHSA-46qf-q25w-6m5v/GHSA-46qf-q25w-6m5v.json
@@ -7,12 +7,8 @@
"CVE-2007-3769"
],
"details": "Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-47x7-rp2q-7phv/GHSA-47x7-rp2q-7phv.json b/advisories/unreviewed/2022/05/GHSA-47x7-rp2q-7phv/GHSA-47x7-rp2q-7phv.json
index 9c4db416088..7d4c1e684ae 100644
--- a/advisories/unreviewed/2022/05/GHSA-47x7-rp2q-7phv/GHSA-47x7-rp2q-7phv.json
+++ b/advisories/unreviewed/2022/05/GHSA-47x7-rp2q-7phv/GHSA-47x7-rp2q-7phv.json
@@ -7,12 +7,8 @@
"CVE-2007-3907"
],
"details": "Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-482x-2mmr-88gg/GHSA-482x-2mmr-88gg.json b/advisories/unreviewed/2022/05/GHSA-482x-2mmr-88gg/GHSA-482x-2mmr-88gg.json
index 9f0c847d8cf..de9937d6d31 100644
--- a/advisories/unreviewed/2022/05/GHSA-482x-2mmr-88gg/GHSA-482x-2mmr-88gg.json
+++ b/advisories/unreviewed/2022/05/GHSA-482x-2mmr-88gg/GHSA-482x-2mmr-88gg.json
@@ -7,12 +7,8 @@
"CVE-2007-3729"
],
"details": "The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid POP usernames.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-485h-jr34-7f93/GHSA-485h-jr34-7f93.json b/advisories/unreviewed/2022/05/GHSA-485h-jr34-7f93/GHSA-485h-jr34-7f93.json
index a0c53b10d70..fa14368bf61 100644
--- a/advisories/unreviewed/2022/05/GHSA-485h-jr34-7f93/GHSA-485h-jr34-7f93.json
+++ b/advisories/unreviewed/2022/05/GHSA-485h-jr34-7f93/GHSA-485h-jr34-7f93.json
@@ -7,12 +7,8 @@
"CVE-2007-3449"
],
"details": "SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-494v-q3hh-x3w8/GHSA-494v-q3hh-x3w8.json b/advisories/unreviewed/2022/05/GHSA-494v-q3hh-x3w8/GHSA-494v-q3hh-x3w8.json
index f4c997e9123..7818e64e0ed 100644
--- a/advisories/unreviewed/2022/05/GHSA-494v-q3hh-x3w8/GHSA-494v-q3hh-x3w8.json
+++ b/advisories/unreviewed/2022/05/GHSA-494v-q3hh-x3w8/GHSA-494v-q3hh-x3w8.json
@@ -7,12 +7,8 @@
"CVE-2007-3781"
],
"details": "MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -120,9 +116,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-496j-c3w9-r7gw/GHSA-496j-c3w9-r7gw.json b/advisories/unreviewed/2022/05/GHSA-496j-c3w9-r7gw/GHSA-496j-c3w9-r7gw.json
index 8baab1bcaaa..38eac8153a3 100644
--- a/advisories/unreviewed/2022/05/GHSA-496j-c3w9-r7gw/GHSA-496j-c3w9-r7gw.json
+++ b/advisories/unreviewed/2022/05/GHSA-496j-c3w9-r7gw/GHSA-496j-c3w9-r7gw.json
@@ -7,12 +7,8 @@
"CVE-2007-3290"
],
"details": "categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-498h-6pm8-vxw6/GHSA-498h-6pm8-vxw6.json b/advisories/unreviewed/2022/05/GHSA-498h-6pm8-vxw6/GHSA-498h-6pm8-vxw6.json
index d45feb5f574..a3aba84d30a 100644
--- a/advisories/unreviewed/2022/05/GHSA-498h-6pm8-vxw6/GHSA-498h-6pm8-vxw6.json
+++ b/advisories/unreviewed/2022/05/GHSA-498h-6pm8-vxw6/GHSA-498h-6pm8-vxw6.json
@@ -7,12 +7,8 @@
"CVE-2007-3424"
],
"details": "The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an instant message, which has unknown impact and remote attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-49pp-grhv-9v9q/GHSA-49pp-grhv-9v9q.json b/advisories/unreviewed/2022/05/GHSA-49pp-grhv-9v9q/GHSA-49pp-grhv-9v9q.json
index 07d655406b2..5a9d60c8329 100644
--- a/advisories/unreviewed/2022/05/GHSA-49pp-grhv-9v9q/GHSA-49pp-grhv-9v9q.json
+++ b/advisories/unreviewed/2022/05/GHSA-49pp-grhv-9v9q/GHSA-49pp-grhv-9v9q.json
@@ -7,12 +7,8 @@
"CVE-2007-3648"
],
"details": "SQL injection vulnerability in Webmatic before 2.6.2, and possibly other versions before 2.7, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly related to admin/admin_album.php and admin/admin_downloads.php. NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4cpj-x587-9p29/GHSA-4cpj-x587-9p29.json b/advisories/unreviewed/2022/05/GHSA-4cpj-x587-9p29/GHSA-4cpj-x587-9p29.json
index 17035fa8b1e..1c5daccb7c9 100644
--- a/advisories/unreviewed/2022/05/GHSA-4cpj-x587-9p29/GHSA-4cpj-x587-9p29.json
+++ b/advisories/unreviewed/2022/05/GHSA-4cpj-x587-9p29/GHSA-4cpj-x587-9p29.json
@@ -7,12 +7,8 @@
"CVE-2007-3242"
],
"details": "The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the titles of items in a personal menu.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4cx6-x972-287m/GHSA-4cx6-x972-287m.json b/advisories/unreviewed/2022/05/GHSA-4cx6-x972-287m/GHSA-4cx6-x972-287m.json
index b069cc50d8e..05a8035fb63 100644
--- a/advisories/unreviewed/2022/05/GHSA-4cx6-x972-287m/GHSA-4cx6-x972-287m.json
+++ b/advisories/unreviewed/2022/05/GHSA-4cx6-x972-287m/GHSA-4cx6-x972-287m.json
@@ -7,12 +7,8 @@
"CVE-2007-3617"
],
"details": "The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4fmh-v866-49mp/GHSA-4fmh-v866-49mp.json b/advisories/unreviewed/2022/05/GHSA-4fmh-v866-49mp/GHSA-4fmh-v866-49mp.json
index d1cd9b8bacd..33034d12197 100644
--- a/advisories/unreviewed/2022/05/GHSA-4fmh-v866-49mp/GHSA-4fmh-v866-49mp.json
+++ b/advisories/unreviewed/2022/05/GHSA-4fmh-v866-49mp/GHSA-4fmh-v866-49mp.json
@@ -7,12 +7,8 @@
"CVE-2007-3588"
],
"details": "SQL injection vulnerability in reply.php in VBZooM 1.12 allows remote attackers to execute arbitrary SQL commands via the UserID parameter to sub-join.php. NOTE: this may be the same as CVE-2006-3691.4.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4h4h-8wm7-vc9v/GHSA-4h4h-8wm7-vc9v.json b/advisories/unreviewed/2022/05/GHSA-4h4h-8wm7-vc9v/GHSA-4h4h-8wm7-vc9v.json
index a1c52a158ee..04217fbeaa8 100644
--- a/advisories/unreviewed/2022/05/GHSA-4h4h-8wm7-vc9v/GHSA-4h4h-8wm7-vc9v.json
+++ b/advisories/unreviewed/2022/05/GHSA-4h4h-8wm7-vc9v/GHSA-4h4h-8wm7-vc9v.json
@@ -7,12 +7,8 @@
"CVE-2007-3467"
],
"details": "Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4hf8-w7gm-6656/GHSA-4hf8-w7gm-6656.json b/advisories/unreviewed/2022/05/GHSA-4hf8-w7gm-6656/GHSA-4hf8-w7gm-6656.json
index 3ff2a879b41..812b76cb6a7 100644
--- a/advisories/unreviewed/2022/05/GHSA-4hf8-w7gm-6656/GHSA-4hf8-w7gm-6656.json
+++ b/advisories/unreviewed/2022/05/GHSA-4hf8-w7gm-6656/GHSA-4hf8-w7gm-6656.json
@@ -7,12 +7,8 @@
"CVE-2007-3330"
],
"details": "Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is stored in news/ without sanitization.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4j9f-xx7v-6mmj/GHSA-4j9f-xx7v-6mmj.json b/advisories/unreviewed/2022/05/GHSA-4j9f-xx7v-6mmj/GHSA-4j9f-xx7v-6mmj.json
index 1462f9e2fb7..497275e5a7b 100644
--- a/advisories/unreviewed/2022/05/GHSA-4j9f-xx7v-6mmj/GHSA-4j9f-xx7v-6mmj.json
+++ b/advisories/unreviewed/2022/05/GHSA-4j9f-xx7v-6mmj/GHSA-4j9f-xx7v-6mmj.json
@@ -7,12 +7,8 @@
"CVE-2007-3621"
],
"details": "Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4mpq-wr5h-ghph/GHSA-4mpq-wr5h-ghph.json b/advisories/unreviewed/2022/05/GHSA-4mpq-wr5h-ghph/GHSA-4mpq-wr5h-ghph.json
index 840b56180d5..3c10fedae95 100644
--- a/advisories/unreviewed/2022/05/GHSA-4mpq-wr5h-ghph/GHSA-4mpq-wr5h-ghph.json
+++ b/advisories/unreviewed/2022/05/GHSA-4mpq-wr5h-ghph/GHSA-4mpq-wr5h-ghph.json
@@ -7,12 +7,8 @@
"CVE-2007-3673"
],
"details": "Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\\\symTDI\\, which results in memory overwrite.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4p94-gh8r-23m2/GHSA-4p94-gh8r-23m2.json b/advisories/unreviewed/2022/05/GHSA-4p94-gh8r-23m2/GHSA-4p94-gh8r-23m2.json
index 1c8ea25088a..993ca55e9ee 100644
--- a/advisories/unreviewed/2022/05/GHSA-4p94-gh8r-23m2/GHSA-4p94-gh8r-23m2.json
+++ b/advisories/unreviewed/2022/05/GHSA-4p94-gh8r-23m2/GHSA-4p94-gh8r-23m2.json
@@ -7,12 +7,8 @@
"CVE-2007-3633"
],
"details": "Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4w4r-xmmf-2qqm/GHSA-4w4r-xmmf-2qqm.json b/advisories/unreviewed/2022/05/GHSA-4w4r-xmmf-2qqm/GHSA-4w4r-xmmf-2qqm.json
index 51e0746696e..f32f4fc5542 100644
--- a/advisories/unreviewed/2022/05/GHSA-4w4r-xmmf-2qqm/GHSA-4w4r-xmmf-2qqm.json
+++ b/advisories/unreviewed/2022/05/GHSA-4w4r-xmmf-2qqm/GHSA-4w4r-xmmf-2qqm.json
@@ -7,12 +7,8 @@
"CVE-2007-3469"
],
"details": "Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4w53-w67f-ph68/GHSA-4w53-w67f-ph68.json b/advisories/unreviewed/2022/05/GHSA-4w53-w67f-ph68/GHSA-4w53-w67f-ph68.json
index 2e1f4a9a965..9d062162192 100644
--- a/advisories/unreviewed/2022/05/GHSA-4w53-w67f-ph68/GHSA-4w53-w67f-ph68.json
+++ b/advisories/unreviewed/2022/05/GHSA-4w53-w67f-ph68/GHSA-4w53-w67f-ph68.json
@@ -7,12 +7,8 @@
"CVE-2007-3374"
],
"details": "Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-4ww5-vxfr-977m/GHSA-4ww5-vxfr-977m.json b/advisories/unreviewed/2022/05/GHSA-4ww5-vxfr-977m/GHSA-4ww5-vxfr-977m.json
index 4fb12810469..f0f8f7a6910 100644
--- a/advisories/unreviewed/2022/05/GHSA-4ww5-vxfr-977m/GHSA-4ww5-vxfr-977m.json
+++ b/advisories/unreviewed/2022/05/GHSA-4ww5-vxfr-977m/GHSA-4ww5-vxfr-977m.json
@@ -7,12 +7,8 @@
"CVE-2007-3420"
],
"details": "The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has unknown impact and remote attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4x4q-cq8x-2hq4/GHSA-4x4q-cq8x-2hq4.json b/advisories/unreviewed/2022/05/GHSA-4x4q-cq8x-2hq4/GHSA-4x4q-cq8x-2hq4.json
index fd387f46034..19fd4b2239a 100644
--- a/advisories/unreviewed/2022/05/GHSA-4x4q-cq8x-2hq4/GHSA-4x4q-cq8x-2hq4.json
+++ b/advisories/unreviewed/2022/05/GHSA-4x4q-cq8x-2hq4/GHSA-4x4q-cq8x-2hq4.json
@@ -7,12 +7,8 @@
"CVE-2007-3705"
],
"details": "SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-4xh3-2gh4-x6h4/GHSA-4xh3-2gh4-x6h4.json b/advisories/unreviewed/2022/05/GHSA-4xh3-2gh4-x6h4/GHSA-4xh3-2gh4-x6h4.json
index d06eb1ad05d..87bc0216974 100644
--- a/advisories/unreviewed/2022/05/GHSA-4xh3-2gh4-x6h4/GHSA-4xh3-2gh4-x6h4.json
+++ b/advisories/unreviewed/2022/05/GHSA-4xh3-2gh4-x6h4/GHSA-4xh3-2gh4-x6h4.json
@@ -7,12 +7,8 @@
"CVE-2007-3703"
],
"details": "Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method. NOTE: this is probably a different issue than CVE-2007-2987.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-4xr7-vpx3-gqvp/GHSA-4xr7-vpx3-gqvp.json b/advisories/unreviewed/2022/05/GHSA-4xr7-vpx3-gqvp/GHSA-4xr7-vpx3-gqvp.json
index 78c30ec1eb4..66cce898a50 100644
--- a/advisories/unreviewed/2022/05/GHSA-4xr7-vpx3-gqvp/GHSA-4xr7-vpx3-gqvp.json
+++ b/advisories/unreviewed/2022/05/GHSA-4xr7-vpx3-gqvp/GHSA-4xr7-vpx3-gqvp.json
@@ -7,12 +7,8 @@
"CVE-2007-3243"
],
"details": "Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-534q-9f5r-pv5m/GHSA-534q-9f5r-pv5m.json b/advisories/unreviewed/2022/05/GHSA-534q-9f5r-pv5m/GHSA-534q-9f5r-pv5m.json
index de0c6af102f..a6898601a12 100644
--- a/advisories/unreviewed/2022/05/GHSA-534q-9f5r-pv5m/GHSA-534q-9f5r-pv5m.json
+++ b/advisories/unreviewed/2022/05/GHSA-534q-9f5r-pv5m/GHSA-534q-9f5r-pv5m.json
@@ -7,12 +7,8 @@
"CVE-2007-3352"
],
"details": "Cross-site scripting (XSS) vulnerability in the preview form in Stephen Ostermiller Contact Form before 2.00.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that contain an apostrophe.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5426-qc78-q4wm/GHSA-5426-qc78-q4wm.json b/advisories/unreviewed/2022/05/GHSA-5426-qc78-q4wm/GHSA-5426-qc78-q4wm.json
index dfaefb2df54..140e7f68bfb 100644
--- a/advisories/unreviewed/2022/05/GHSA-5426-qc78-q4wm/GHSA-5426-qc78-q4wm.json
+++ b/advisories/unreviewed/2022/05/GHSA-5426-qc78-q4wm/GHSA-5426-qc78-q4wm.json
@@ -7,12 +7,8 @@
"CVE-2007-3363"
],
"details": "Multiple unspecified vulnerabilities in ageet AGEphone before 1.6.3 allow remote attackers to have an unknown impact via malformed SIP packets.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-54j8-53fw-cj49/GHSA-54j8-53fw-cj49.json b/advisories/unreviewed/2022/05/GHSA-54j8-53fw-cj49/GHSA-54j8-53fw-cj49.json
index 75fa1824240..9720ee63861 100644
--- a/advisories/unreviewed/2022/05/GHSA-54j8-53fw-cj49/GHSA-54j8-53fw-cj49.json
+++ b/advisories/unreviewed/2022/05/GHSA-54j8-53fw-cj49/GHSA-54j8-53fw-cj49.json
@@ -7,12 +7,8 @@
"CVE-2007-3620"
],
"details": "Multiple directory traversal vulnerabilities in Maia Mailguard 1.0.2 and earlier might allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) prevlang and (2) super parameters to (a) php/login.php; the (3) charset parameter to (a) php/login.php, (b) php/internal-init.php, and (c) php/xlogin.php; the (4) lang parameter to (b) php/internal-init.php; and the (5) language parameter to (c) php/xlogin.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-55wp-xw38-9gmj/GHSA-55wp-xw38-9gmj.json b/advisories/unreviewed/2022/05/GHSA-55wp-xw38-9gmj/GHSA-55wp-xw38-9gmj.json
index d9ddbdce0b4..8876be20364 100644
--- a/advisories/unreviewed/2022/05/GHSA-55wp-xw38-9gmj/GHSA-55wp-xw38-9gmj.json
+++ b/advisories/unreviewed/2022/05/GHSA-55wp-xw38-9gmj/GHSA-55wp-xw38-9gmj.json
@@ -7,12 +7,8 @@
"CVE-2007-3391"
],
"details": "Wireshark 0.99.5 allows remote attackers to cause a denial of service (memory consumption) via a malformed DCP ETSI packet that triggers an infinite loop.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-55x7-8295-fg58/GHSA-55x7-8295-fg58.json b/advisories/unreviewed/2022/05/GHSA-55x7-8295-fg58/GHSA-55x7-8295-fg58.json
index 8afef8e2575..2a03b755eff 100644
--- a/advisories/unreviewed/2022/05/GHSA-55x7-8295-fg58/GHSA-55x7-8295-fg58.json
+++ b/advisories/unreviewed/2022/05/GHSA-55x7-8295-fg58/GHSA-55x7-8295-fg58.json
@@ -7,12 +7,8 @@
"CVE-2007-3329"
],
"details": "Multiple array index errors in the (1) get_intra_block, (2) get_inter_block_h263, and (3) get_inter_block_mpeg functions in src/bitstream/mbcoding.c in Xvid 1.1.2 allow remote attackers to execute arbitrary code via a crafted (a) Avi, (b) H.263, or (c) MPEG file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-567g-v7mv-p82f/GHSA-567g-v7mv-p82f.json b/advisories/unreviewed/2022/05/GHSA-567g-v7mv-p82f/GHSA-567g-v7mv-p82f.json
index ad252017f7b..95af1e38f05 100644
--- a/advisories/unreviewed/2022/05/GHSA-567g-v7mv-p82f/GHSA-567g-v7mv-p82f.json
+++ b/advisories/unreviewed/2022/05/GHSA-567g-v7mv-p82f/GHSA-567g-v7mv-p82f.json
@@ -7,12 +7,8 @@
"CVE-2007-3308"
],
"details": "Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5682-88q2-hhj3/GHSA-5682-88q2-hhj3.json b/advisories/unreviewed/2022/05/GHSA-5682-88q2-hhj3/GHSA-5682-88q2-hhj3.json
index 810e6029d12..6e5378538e6 100644
--- a/advisories/unreviewed/2022/05/GHSA-5682-88q2-hhj3/GHSA-5682-88q2-hhj3.json
+++ b/advisories/unreviewed/2022/05/GHSA-5682-88q2-hhj3/GHSA-5682-88q2-hhj3.json
@@ -7,12 +7,8 @@
"CVE-2007-3778"
],
"details": "The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the messageSignedText parameter to the gpg_check_sign_pgp_mime function in gpg_hook_functions.php. NOTE: a parameter value can be set in the contents of an e-mail message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-56rw-rc45-v8cg/GHSA-56rw-rc45-v8cg.json b/advisories/unreviewed/2022/05/GHSA-56rw-rc45-v8cg/GHSA-56rw-rc45-v8cg.json
index 49372cbe5bb..20b6708af0d 100644
--- a/advisories/unreviewed/2022/05/GHSA-56rw-rc45-v8cg/GHSA-56rw-rc45-v8cg.json
+++ b/advisories/unreviewed/2022/05/GHSA-56rw-rc45-v8cg/GHSA-56rw-rc45-v8cg.json
@@ -7,12 +7,8 @@
"CVE-2007-3606"
],
"details": "Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5722-2749-8q4j/GHSA-5722-2749-8q4j.json b/advisories/unreviewed/2022/05/GHSA-5722-2749-8q4j/GHSA-5722-2749-8q4j.json
index 959d938de9a..f138e44c4f4 100644
--- a/advisories/unreviewed/2022/05/GHSA-5722-2749-8q4j/GHSA-5722-2749-8q4j.json
+++ b/advisories/unreviewed/2022/05/GHSA-5722-2749-8q4j/GHSA-5722-2749-8q4j.json
@@ -7,12 +7,8 @@
"CVE-2007-3712"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in HiddenChest \"is ve Bayi Basvuru Formu\" (Yb ve Bayi Babvuru Formu) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-58h2-6vhw-p854/GHSA-58h2-6vhw-p854.json b/advisories/unreviewed/2022/05/GHSA-58h2-6vhw-p854/GHSA-58h2-6vhw-p854.json
index 75252e92195..b866176dbe1 100644
--- a/advisories/unreviewed/2022/05/GHSA-58h2-6vhw-p854/GHSA-58h2-6vhw-p854.json
+++ b/advisories/unreviewed/2022/05/GHSA-58h2-6vhw-p854/GHSA-58h2-6vhw-p854.json
@@ -7,12 +7,8 @@
"CVE-2007-3969"
],
"details": "Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from an \"Integer Cast Around.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-58wx-6q9p-f2rx/GHSA-58wx-6q9p-f2rx.json b/advisories/unreviewed/2022/05/GHSA-58wx-6q9p-f2rx/GHSA-58wx-6q9p-f2rx.json
index e4df698c10c..0f08e12cc2f 100644
--- a/advisories/unreviewed/2022/05/GHSA-58wx-6q9p-f2rx/GHSA-58wx-6q9p-f2rx.json
+++ b/advisories/unreviewed/2022/05/GHSA-58wx-6q9p-f2rx/GHSA-58wx-6q9p-f2rx.json
@@ -7,12 +7,8 @@
"CVE-2007-3546"
],
"details": "Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5982-ff7w-wx53/GHSA-5982-ff7w-wx53.json b/advisories/unreviewed/2022/05/GHSA-5982-ff7w-wx53/GHSA-5982-ff7w-wx53.json
index ad0a5bdb38d..ee4b2864a61 100644
--- a/advisories/unreviewed/2022/05/GHSA-5982-ff7w-wx53/GHSA-5982-ff7w-wx53.json
+++ b/advisories/unreviewed/2022/05/GHSA-5982-ff7w-wx53/GHSA-5982-ff7w-wx53.json
@@ -7,12 +7,8 @@
"CVE-2007-3320"
],
"details": "The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified impact.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5c2p-fpg9-rg5f/GHSA-5c2p-fpg9-rg5f.json b/advisories/unreviewed/2022/05/GHSA-5c2p-fpg9-rg5f/GHSA-5c2p-fpg9-rg5f.json
index 5a01fa7fc62..3640db48be3 100644
--- a/advisories/unreviewed/2022/05/GHSA-5c2p-fpg9-rg5f/GHSA-5c2p-fpg9-rg5f.json
+++ b/advisories/unreviewed/2022/05/GHSA-5c2p-fpg9-rg5f/GHSA-5c2p-fpg9-rg5f.json
@@ -7,12 +7,8 @@
"CVE-2007-3805"
],
"details": "The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5c74-49v7-vc6w/GHSA-5c74-49v7-vc6w.json b/advisories/unreviewed/2022/05/GHSA-5c74-49v7-vc6w/GHSA-5c74-49v7-vc6w.json
index 02136a5fad7..2df05af73f1 100644
--- a/advisories/unreviewed/2022/05/GHSA-5c74-49v7-vc6w/GHSA-5c74-49v7-vc6w.json
+++ b/advisories/unreviewed/2022/05/GHSA-5c74-49v7-vc6w/GHSA-5c74-49v7-vc6w.json
@@ -7,12 +7,8 @@
"CVE-2007-3362"
],
"details": "ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of service (call disruption and device hang) via a SIP message with a malformed header and (2) cause a denial of service (call disruption, false ring indication, and device outage) via a SIP message with a malformed SDP delimiter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5cmm-cmgf-4vfr/GHSA-5cmm-cmgf-4vfr.json b/advisories/unreviewed/2022/05/GHSA-5cmm-cmgf-4vfr/GHSA-5cmm-cmgf-4vfr.json
index e8bf5c85651..35b1d636ef5 100644
--- a/advisories/unreviewed/2022/05/GHSA-5cmm-cmgf-4vfr/GHSA-5cmm-cmgf-4vfr.json
+++ b/advisories/unreviewed/2022/05/GHSA-5cmm-cmgf-4vfr/GHSA-5cmm-cmgf-4vfr.json
@@ -7,12 +7,8 @@
"CVE-2007-3354"
],
"details": "Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5ff9-w726-3ph3/GHSA-5ff9-w726-3ph3.json b/advisories/unreviewed/2022/05/GHSA-5ff9-w726-3ph3/GHSA-5ff9-w726-3ph3.json
index 754d966151b..1ac6c353098 100644
--- a/advisories/unreviewed/2022/05/GHSA-5ff9-w726-3ph3/GHSA-5ff9-w726-3ph3.json
+++ b/advisories/unreviewed/2022/05/GHSA-5ff9-w726-3ph3/GHSA-5ff9-w726-3ph3.json
@@ -7,12 +7,8 @@
"CVE-2007-3625"
],
"details": "The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certain request that uses content redirection and a long pathname.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5fxq-f64v-57fq/GHSA-5fxq-f64v-57fq.json b/advisories/unreviewed/2022/05/GHSA-5fxq-f64v-57fq/GHSA-5fxq-f64v-57fq.json
index cbb70feb3c2..2923c3ff59b 100644
--- a/advisories/unreviewed/2022/05/GHSA-5fxq-f64v-57fq/GHSA-5fxq-f64v-57fq.json
+++ b/advisories/unreviewed/2022/05/GHSA-5fxq-f64v-57fq/GHSA-5fxq-f64v-57fq.json
@@ -7,12 +7,8 @@
"CVE-2007-3716"
],
"details": "The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-5g6q-w926-6v9p/GHSA-5g6q-w926-6v9p.json b/advisories/unreviewed/2022/05/GHSA-5g6q-w926-6v9p/GHSA-5g6q-w926-6v9p.json
index 466f8916066..6e18a87c9be 100644
--- a/advisories/unreviewed/2022/05/GHSA-5g6q-w926-6v9p/GHSA-5g6q-w926-6v9p.json
+++ b/advisories/unreviewed/2022/05/GHSA-5g6q-w926-6v9p/GHSA-5g6q-w926-6v9p.json
@@ -7,12 +7,8 @@
"CVE-2007-3534"
],
"details": "SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5gcg-pg3j-c96g/GHSA-5gcg-pg3j-c96g.json b/advisories/unreviewed/2022/05/GHSA-5gcg-pg3j-c96g/GHSA-5gcg-pg3j-c96g.json
index eb3b367391f..5781993698e 100644
--- a/advisories/unreviewed/2022/05/GHSA-5gcg-pg3j-c96g/GHSA-5gcg-pg3j-c96g.json
+++ b/advisories/unreviewed/2022/05/GHSA-5gcg-pg3j-c96g/GHSA-5gcg-pg3j-c96g.json
@@ -7,12 +7,8 @@
"CVE-2007-3224"
],
"details": "Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5ggr-m42r-xw35/GHSA-5ggr-m42r-xw35.json b/advisories/unreviewed/2022/05/GHSA-5ggr-m42r-xw35/GHSA-5ggr-m42r-xw35.json
index a4024cf00ab..7fe1d390b9e 100644
--- a/advisories/unreviewed/2022/05/GHSA-5ggr-m42r-xw35/GHSA-5ggr-m42r-xw35.json
+++ b/advisories/unreviewed/2022/05/GHSA-5ggr-m42r-xw35/GHSA-5ggr-m42r-xw35.json
@@ -7,12 +7,8 @@
"CVE-2007-3218"
],
"details": "Cross-site scripting (XSS) vulnerability in request.php in PHP Live! 3.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the pagex parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5h72-mqr4-8c7r/GHSA-5h72-mqr4-8c7r.json b/advisories/unreviewed/2022/05/GHSA-5h72-mqr4-8c7r/GHSA-5h72-mqr4-8c7r.json
index 27417586748..fe5ddb50b0f 100644
--- a/advisories/unreviewed/2022/05/GHSA-5h72-mqr4-8c7r/GHSA-5h72-mqr4-8c7r.json
+++ b/advisories/unreviewed/2022/05/GHSA-5h72-mqr4-8c7r/GHSA-5h72-mqr4-8c7r.json
@@ -7,12 +7,8 @@
"CVE-2007-3938"
],
"details": "SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-5hfq-gm8x-g6p7/GHSA-5hfq-gm8x-g6p7.json b/advisories/unreviewed/2022/05/GHSA-5hfq-gm8x-g6p7/GHSA-5hfq-gm8x-g6p7.json
index 6d4410d0e47..6f65830610c 100644
--- a/advisories/unreviewed/2022/05/GHSA-5hfq-gm8x-g6p7/GHSA-5hfq-gm8x-g6p7.json
+++ b/advisories/unreviewed/2022/05/GHSA-5hfq-gm8x-g6p7/GHSA-5hfq-gm8x-g6p7.json
@@ -7,12 +7,8 @@
"CVE-2007-3740"
],
"details": "The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -112,9 +108,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5j59-p777-2f8q/GHSA-5j59-p777-2f8q.json b/advisories/unreviewed/2022/05/GHSA-5j59-p777-2f8q/GHSA-5j59-p777-2f8q.json
index 4659fdee9bd..3c157e31340 100644
--- a/advisories/unreviewed/2022/05/GHSA-5j59-p777-2f8q/GHSA-5j59-p777-2f8q.json
+++ b/advisories/unreviewed/2022/05/GHSA-5j59-p777-2f8q/GHSA-5j59-p777-2f8q.json
@@ -7,12 +7,8 @@
"CVE-2007-3918"
],
"details": "Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-5p3v-g8h5-7gg9/GHSA-5p3v-g8h5-7gg9.json b/advisories/unreviewed/2022/05/GHSA-5p3v-g8h5-7gg9/GHSA-5p3v-g8h5-7gg9.json
index 4a8c046b8c7..64c8c516e31 100644
--- a/advisories/unreviewed/2022/05/GHSA-5p3v-g8h5-7gg9/GHSA-5p3v-g8h5-7gg9.json
+++ b/advisories/unreviewed/2022/05/GHSA-5p3v-g8h5-7gg9/GHSA-5p3v-g8h5-7gg9.json
@@ -7,12 +7,8 @@
"CVE-2007-3698"
],
"details": "The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -180,9 +176,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5q7r-x43f-873j/GHSA-5q7r-x43f-873j.json b/advisories/unreviewed/2022/05/GHSA-5q7r-x43f-873j/GHSA-5q7r-x43f-873j.json
index 1c91fa9734a..0872a666ad6 100644
--- a/advisories/unreviewed/2022/05/GHSA-5q7r-x43f-873j/GHSA-5q7r-x43f-873j.json
+++ b/advisories/unreviewed/2022/05/GHSA-5q7r-x43f-873j/GHSA-5q7r-x43f-873j.json
@@ -7,12 +7,8 @@
"CVE-2007-3261"
],
"details": "Cross-site scripting (XSS) vulnerability in widgets/widget_search.php in dKret before 2.6 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5r9m-522w-fg7m/GHSA-5r9m-522w-fg7m.json b/advisories/unreviewed/2022/05/GHSA-5r9m-522w-fg7m/GHSA-5r9m-522w-fg7m.json
index bdb7d314555..c4a3bb2512e 100644
--- a/advisories/unreviewed/2022/05/GHSA-5r9m-522w-fg7m/GHSA-5r9m-522w-fg7m.json
+++ b/advisories/unreviewed/2022/05/GHSA-5r9m-522w-fg7m/GHSA-5r9m-522w-fg7m.json
@@ -7,12 +7,8 @@
"CVE-2007-3690"
],
"details": "The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5vpx-2xvh-c9jm/GHSA-5vpx-2xvh-c9jm.json b/advisories/unreviewed/2022/05/GHSA-5vpx-2xvh-c9jm/GHSA-5vpx-2xvh-c9jm.json
index 780fc79a17d..cc79188d0a9 100644
--- a/advisories/unreviewed/2022/05/GHSA-5vpx-2xvh-c9jm/GHSA-5vpx-2xvh-c9jm.json
+++ b/advisories/unreviewed/2022/05/GHSA-5vpx-2xvh-c9jm/GHSA-5vpx-2xvh-c9jm.json
@@ -7,12 +7,8 @@
"CVE-2007-3439"
],
"details": "The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to read a list of missed calls, received calls, and dialed numbers via a direct request to the web server on port 1800.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5w2j-gqcp-rg3c/GHSA-5w2j-gqcp-rg3c.json b/advisories/unreviewed/2022/05/GHSA-5w2j-gqcp-rg3c/GHSA-5w2j-gqcp-rg3c.json
index 31876e466e4..bcf1d3a3cd5 100644
--- a/advisories/unreviewed/2022/05/GHSA-5w2j-gqcp-rg3c/GHSA-5w2j-gqcp-rg3c.json
+++ b/advisories/unreviewed/2022/05/GHSA-5w2j-gqcp-rg3c/GHSA-5w2j-gqcp-rg3c.json
@@ -7,12 +7,8 @@
"CVE-2007-3964"
],
"details": "Itaka before 0.2.1, when using Authentication mode, allows remote attackers to bypass authentication and obtain sensitive information by downloading screenshots via a direct request for /screenshot.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5wcf-fff9-wh9f/GHSA-5wcf-fff9-wh9f.json b/advisories/unreviewed/2022/05/GHSA-5wcf-fff9-wh9f/GHSA-5wcf-fff9-wh9f.json
index d7bb71ccbb0..7b26c635496 100644
--- a/advisories/unreviewed/2022/05/GHSA-5wcf-fff9-wh9f/GHSA-5wcf-fff9-wh9f.json
+++ b/advisories/unreviewed/2022/05/GHSA-5wcf-fff9-wh9f/GHSA-5wcf-fff9-wh9f.json
@@ -7,12 +7,8 @@
"CVE-2007-3317"
],
"details": "The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (device crash) via a malformed SIP message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-5x5x-c9q8-x83f/GHSA-5x5x-c9q8-x83f.json b/advisories/unreviewed/2022/05/GHSA-5x5x-c9q8-x83f/GHSA-5x5x-c9q8-x83f.json
index 86a56c1be04..e4c38e1d7cc 100644
--- a/advisories/unreviewed/2022/05/GHSA-5x5x-c9q8-x83f/GHSA-5x5x-c9q8-x83f.json
+++ b/advisories/unreviewed/2022/05/GHSA-5x5x-c9q8-x83f/GHSA-5x5x-c9q8-x83f.json
@@ -7,12 +7,8 @@
"CVE-2007-3917"
],
"details": "The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-639c-vgwm-wh2v/GHSA-639c-vgwm-wh2v.json b/advisories/unreviewed/2022/05/GHSA-639c-vgwm-wh2v/GHSA-639c-vgwm-wh2v.json
index 50c253511a4..eb3d26eac89 100644
--- a/advisories/unreviewed/2022/05/GHSA-639c-vgwm-wh2v/GHSA-639c-vgwm-wh2v.json
+++ b/advisories/unreviewed/2022/05/GHSA-639c-vgwm-wh2v/GHSA-639c-vgwm-wh2v.json
@@ -7,12 +7,8 @@
"CVE-2007-3596"
],
"details": "inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-65cm-xc9c-4rxq/GHSA-65cm-xc9c-4rxq.json b/advisories/unreviewed/2022/05/GHSA-65cm-xc9c-4rxq/GHSA-65cm-xc9c-4rxq.json
index 0487f2db737..2e6e058454c 100644
--- a/advisories/unreviewed/2022/05/GHSA-65cm-xc9c-4rxq/GHSA-65cm-xc9c-4rxq.json
+++ b/advisories/unreviewed/2022/05/GHSA-65cm-xc9c-4rxq/GHSA-65cm-xc9c-4rxq.json
@@ -7,12 +7,8 @@
"CVE-2007-3485"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Yandex.Server allow remote attackers to inject arbitrary web script or HTML via the (1) query or (2) within parameter to the default URI.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-672p-736c-w8qf/GHSA-672p-736c-w8qf.json b/advisories/unreviewed/2022/05/GHSA-672p-736c-w8qf/GHSA-672p-736c-w8qf.json
index 0642f470979..e18211142d5 100644
--- a/advisories/unreviewed/2022/05/GHSA-672p-736c-w8qf/GHSA-672p-736c-w8qf.json
+++ b/advisories/unreviewed/2022/05/GHSA-672p-736c-w8qf/GHSA-672p-736c-w8qf.json
@@ -7,12 +7,8 @@
"CVE-2007-3743"
],
"details": "Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-67wv-8wxx-3xhx/GHSA-67wv-8wxx-3xhx.json b/advisories/unreviewed/2022/05/GHSA-67wv-8wxx-3xhx/GHSA-67wv-8wxx-3xhx.json
index df3ac1a58a1..515d0a13cb2 100644
--- a/advisories/unreviewed/2022/05/GHSA-67wv-8wxx-3xhx/GHSA-67wv-8wxx-3xhx.json
+++ b/advisories/unreviewed/2022/05/GHSA-67wv-8wxx-3xhx/GHSA-67wv-8wxx-3xhx.json
@@ -7,12 +7,8 @@
"CVE-2007-3706"
],
"details": "The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6896-qcj9-3xh6/GHSA-6896-qcj9-3xh6.json b/advisories/unreviewed/2022/05/GHSA-6896-qcj9-3xh6/GHSA-6896-qcj9-3xh6.json
index 0fd27ac888a..0706af32054 100644
--- a/advisories/unreviewed/2022/05/GHSA-6896-qcj9-3xh6/GHSA-6896-qcj9-3xh6.json
+++ b/advisories/unreviewed/2022/05/GHSA-6896-qcj9-3xh6/GHSA-6896-qcj9-3xh6.json
@@ -7,12 +7,8 @@
"CVE-2007-3250"
],
"details": "SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie. NOTE: the product was patched without updating the version number; later downloads of 2006.4 are not affected.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-68fg-4qvx-c25f/GHSA-68fg-4qvx-c25f.json b/advisories/unreviewed/2022/05/GHSA-68fg-4qvx-c25f/GHSA-68fg-4qvx-c25f.json
index 2cff5b0ba80..e93d3163e77 100644
--- a/advisories/unreviewed/2022/05/GHSA-68fg-4qvx-c25f/GHSA-68fg-4qvx-c25f.json
+++ b/advisories/unreviewed/2022/05/GHSA-68fg-4qvx-c25f/GHSA-68fg-4qvx-c25f.json
@@ -7,12 +7,8 @@
"CVE-2007-3611"
],
"details": "admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-68pc-v254-2gfv/GHSA-68pc-v254-2gfv.json b/advisories/unreviewed/2022/05/GHSA-68pc-v254-2gfv/GHSA-68pc-v254-2gfv.json
index 88517bf45bd..4076200c284 100644
--- a/advisories/unreviewed/2022/05/GHSA-68pc-v254-2gfv/GHSA-68pc-v254-2gfv.json
+++ b/advisories/unreviewed/2022/05/GHSA-68pc-v254-2gfv/GHSA-68pc-v254-2gfv.json
@@ -7,12 +7,8 @@
"CVE-2007-3283"
],
"details": "GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6cr9-7cfm-4prq/GHSA-6cr9-7cfm-4prq.json b/advisories/unreviewed/2022/05/GHSA-6cr9-7cfm-4prq/GHSA-6cr9-7cfm-4prq.json
index edab130ac13..68dc55346e9 100644
--- a/advisories/unreviewed/2022/05/GHSA-6cr9-7cfm-4prq/GHSA-6cr9-7cfm-4prq.json
+++ b/advisories/unreviewed/2022/05/GHSA-6cr9-7cfm-4prq/GHSA-6cr9-7cfm-4prq.json
@@ -7,12 +7,8 @@
"CVE-2007-3401"
],
"details": "PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6f44-43mm-cpfr/GHSA-6f44-43mm-cpfr.json b/advisories/unreviewed/2022/05/GHSA-6f44-43mm-cpfr/GHSA-6f44-43mm-cpfr.json
index d4235e97e20..c3aba3bed71 100644
--- a/advisories/unreviewed/2022/05/GHSA-6f44-43mm-cpfr/GHSA-6f44-43mm-cpfr.json
+++ b/advisories/unreviewed/2022/05/GHSA-6f44-43mm-cpfr/GHSA-6f44-43mm-cpfr.json
@@ -7,12 +7,8 @@
"CVE-2007-3672"
],
"details": "Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6f5g-5vxv-fx2c/GHSA-6f5g-5vxv-fx2c.json b/advisories/unreviewed/2022/05/GHSA-6f5g-5vxv-fx2c/GHSA-6f5g-5vxv-fx2c.json
index 3812919790e..42c7f2a2a5d 100644
--- a/advisories/unreviewed/2022/05/GHSA-6f5g-5vxv-fx2c/GHSA-6f5g-5vxv-fx2c.json
+++ b/advisories/unreviewed/2022/05/GHSA-6f5g-5vxv-fx2c/GHSA-6f5g-5vxv-fx2c.json
@@ -7,12 +7,8 @@
"CVE-2007-3332"
],
"details": "Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the name parameter in a modload action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6fxv-cq4x-fxhj/GHSA-6fxv-cq4x-fxhj.json b/advisories/unreviewed/2022/05/GHSA-6fxv-cq4x-fxhj/GHSA-6fxv-cq4x-fxhj.json
index ded20dc12f5..036c7eb86fc 100644
--- a/advisories/unreviewed/2022/05/GHSA-6fxv-cq4x-fxhj/GHSA-6fxv-cq4x-fxhj.json
+++ b/advisories/unreviewed/2022/05/GHSA-6fxv-cq4x-fxhj/GHSA-6fxv-cq4x-fxhj.json
@@ -7,12 +7,8 @@
"CVE-2007-3939"
],
"details": "SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6g7w-fhqh-95gm/GHSA-6g7w-fhqh-95gm.json b/advisories/unreviewed/2022/05/GHSA-6g7w-fhqh-95gm/GHSA-6g7w-fhqh-95gm.json
index c98b2234be3..6f227117be6 100644
--- a/advisories/unreviewed/2022/05/GHSA-6g7w-fhqh-95gm/GHSA-6g7w-fhqh-95gm.json
+++ b/advisories/unreviewed/2022/05/GHSA-6g7w-fhqh-95gm/GHSA-6g7w-fhqh-95gm.json
@@ -7,12 +7,8 @@
"CVE-2007-3601"
],
"details": "vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6gv5-x4qm-mvwp/GHSA-6gv5-x4qm-mvwp.json b/advisories/unreviewed/2022/05/GHSA-6gv5-x4qm-mvwp/GHSA-6gv5-x4qm-mvwp.json
index 2f348b985a1..3699f84bb0a 100644
--- a/advisories/unreviewed/2022/05/GHSA-6gv5-x4qm-mvwp/GHSA-6gv5-x4qm-mvwp.json
+++ b/advisories/unreviewed/2022/05/GHSA-6gv5-x4qm-mvwp/GHSA-6gv5-x4qm-mvwp.json
@@ -7,12 +7,8 @@
"CVE-2007-3581"
],
"details": "The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel with the Palo plugin, opening a cube, and performing an Insert View.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6gvm-c4cj-xqv2/GHSA-6gvm-c4cj-xqv2.json b/advisories/unreviewed/2022/05/GHSA-6gvm-c4cj-xqv2/GHSA-6gvm-c4cj-xqv2.json
index 16adf5cecad..32c856d6032 100644
--- a/advisories/unreviewed/2022/05/GHSA-6gvm-c4cj-xqv2/GHSA-6gvm-c4cj-xqv2.json
+++ b/advisories/unreviewed/2022/05/GHSA-6gvm-c4cj-xqv2/GHSA-6gvm-c4cj-xqv2.json
@@ -7,12 +7,8 @@
"CVE-2019-15814"
],
"details": "Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6hf6-gxjx-g9j6/GHSA-6hf6-gxjx-g9j6.json b/advisories/unreviewed/2022/05/GHSA-6hf6-gxjx-g9j6/GHSA-6hf6-gxjx-g9j6.json
index 94df5db5896..60da3c1f512 100644
--- a/advisories/unreviewed/2022/05/GHSA-6hf6-gxjx-g9j6/GHSA-6hf6-gxjx-g9j6.json
+++ b/advisories/unreviewed/2022/05/GHSA-6hf6-gxjx-g9j6/GHSA-6hf6-gxjx-g9j6.json
@@ -7,12 +7,8 @@
"CVE-2007-3948"
],
"details": "connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -72,9 +68,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6j5h-7735-874p/GHSA-6j5h-7735-874p.json b/advisories/unreviewed/2022/05/GHSA-6j5h-7735-874p/GHSA-6j5h-7735-874p.json
index d8186405f0d..9175d04b0af 100644
--- a/advisories/unreviewed/2022/05/GHSA-6j5h-7735-874p/GHSA-6j5h-7735-874p.json
+++ b/advisories/unreviewed/2022/05/GHSA-6j5h-7735-874p/GHSA-6j5h-7735-874p.json
@@ -7,12 +7,8 @@
"CVE-2019-15937"
],
"details": "Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6jvm-prg5-594v/GHSA-6jvm-prg5-594v.json b/advisories/unreviewed/2022/05/GHSA-6jvm-prg5-594v/GHSA-6jvm-prg5-594v.json
index 4f26dcf30e7..ab46f98c4ba 100644
--- a/advisories/unreviewed/2022/05/GHSA-6jvm-prg5-594v/GHSA-6jvm-prg5-594v.json
+++ b/advisories/unreviewed/2022/05/GHSA-6jvm-prg5-594v/GHSA-6jvm-prg5-594v.json
@@ -7,12 +7,8 @@
"CVE-2007-3624"
],
"details": "Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6q2g-cq59-76q9/GHSA-6q2g-cq59-76q9.json b/advisories/unreviewed/2022/05/GHSA-6q2g-cq59-76q9/GHSA-6q2g-cq59-76q9.json
index a2bc345b734..aa2949280ac 100644
--- a/advisories/unreviewed/2022/05/GHSA-6q2g-cq59-76q9/GHSA-6q2g-cq59-76q9.json
+++ b/advisories/unreviewed/2022/05/GHSA-6q2g-cq59-76q9/GHSA-6q2g-cq59-76q9.json
@@ -7,12 +7,8 @@
"CVE-2007-3952"
],
"details": "The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to bypass the malware detection via a crafted DOC file, resulting from an \"integer cast around\".",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6r7m-cjqc-crvj/GHSA-6r7m-cjqc-crvj.json b/advisories/unreviewed/2022/05/GHSA-6r7m-cjqc-crvj/GHSA-6r7m-cjqc-crvj.json
index 7e2457b8d05..55f7fa972ba 100644
--- a/advisories/unreviewed/2022/05/GHSA-6r7m-cjqc-crvj/GHSA-6r7m-cjqc-crvj.json
+++ b/advisories/unreviewed/2022/05/GHSA-6r7m-cjqc-crvj/GHSA-6r7m-cjqc-crvj.json
@@ -7,12 +7,8 @@
"CVE-2007-3437"
],
"details": "AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application crash) via a malformed header value in a SIP INVITE message, a different vulnerability than CVE-2007-3350.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6rvx-p9fj-cv6x/GHSA-6rvx-p9fj-cv6x.json b/advisories/unreviewed/2022/05/GHSA-6rvx-p9fj-cv6x/GHSA-6rvx-p9fj-cv6x.json
index 9f48a9550de..2281f38ffc6 100644
--- a/advisories/unreviewed/2022/05/GHSA-6rvx-p9fj-cv6x/GHSA-6rvx-p9fj-cv6x.json
+++ b/advisories/unreviewed/2022/05/GHSA-6rvx-p9fj-cv6x/GHSA-6rvx-p9fj-cv6x.json
@@ -7,12 +7,8 @@
"CVE-2019-2277"
],
"details": "Out of bound read can happen due to lack of NULL termination on user controlled data in WLAN in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MSM8996AU, QCS405, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX24",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6w4j-qpvm-2vvx/GHSA-6w4j-qpvm-2vvx.json b/advisories/unreviewed/2022/05/GHSA-6w4j-qpvm-2vvx/GHSA-6w4j-qpvm-2vvx.json
index 5f6ab8668ac..5cc33a8318a 100644
--- a/advisories/unreviewed/2022/05/GHSA-6w4j-qpvm-2vvx/GHSA-6w4j-qpvm-2vvx.json
+++ b/advisories/unreviewed/2022/05/GHSA-6w4j-qpvm-2vvx/GHSA-6w4j-qpvm-2vvx.json
@@ -7,12 +7,8 @@
"CVE-2007-3448"
],
"details": "Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-6w9q-h3xg-92gf/GHSA-6w9q-h3xg-92gf.json b/advisories/unreviewed/2022/05/GHSA-6w9q-h3xg-92gf/GHSA-6w9q-h3xg-92gf.json
index dfbf2613b93..76bba895fb8 100644
--- a/advisories/unreviewed/2022/05/GHSA-6w9q-h3xg-92gf/GHSA-6w9q-h3xg-92gf.json
+++ b/advisories/unreviewed/2022/05/GHSA-6w9q-h3xg-92gf/GHSA-6w9q-h3xg-92gf.json
@@ -7,12 +7,8 @@
"CVE-2007-3722"
],
"details": "The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6wjq-23vp-x555/GHSA-6wjq-23vp-x555.json b/advisories/unreviewed/2022/05/GHSA-6wjq-23vp-x555/GHSA-6wjq-23vp-x555.json
index 1cc8b3bb700..30610face1a 100644
--- a/advisories/unreviewed/2022/05/GHSA-6wjq-23vp-x555/GHSA-6wjq-23vp-x555.json
+++ b/advisories/unreviewed/2022/05/GHSA-6wjq-23vp-x555/GHSA-6wjq-23vp-x555.json
@@ -7,12 +7,8 @@
"CVE-2007-3784"
],
"details": "Cross-site scripting (XSS) vulnerability in the Belkin G Plus Router F5D7231-4 with firmware 4.05.03 allows remote attackers to inject arbitrary web script or HTML via a hostname of a DHCP client.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-6xjq-ccqx-v4j7/GHSA-6xjq-ccqx-v4j7.json b/advisories/unreviewed/2022/05/GHSA-6xjq-ccqx-v4j7/GHSA-6xjq-ccqx-v4j7.json
index 5eb04bbfb4c..86bd2ab6540 100644
--- a/advisories/unreviewed/2022/05/GHSA-6xjq-ccqx-v4j7/GHSA-6xjq-ccqx-v4j7.json
+++ b/advisories/unreviewed/2022/05/GHSA-6xjq-ccqx-v4j7/GHSA-6xjq-ccqx-v4j7.json
@@ -7,12 +7,8 @@
"CVE-2007-3371"
],
"details": "PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-72gc-j98m-w58x/GHSA-72gc-j98m-w58x.json b/advisories/unreviewed/2022/05/GHSA-72gc-j98m-w58x/GHSA-72gc-j98m-w58x.json
index 490f5b23212..8fdd8da7275 100644
--- a/advisories/unreviewed/2022/05/GHSA-72gc-j98m-w58x/GHSA-72gc-j98m-w58x.json
+++ b/advisories/unreviewed/2022/05/GHSA-72gc-j98m-w58x/GHSA-72gc-j98m-w58x.json
@@ -7,12 +7,8 @@
"CVE-2007-3375"
],
"details": "Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-72gg-m2hj-9c97/GHSA-72gg-m2hj-9c97.json b/advisories/unreviewed/2022/05/GHSA-72gg-m2hj-9c97/GHSA-72gg-m2hj-9c97.json
index 0acec5fba81..b562712eaba 100644
--- a/advisories/unreviewed/2022/05/GHSA-72gg-m2hj-9c97/GHSA-72gg-m2hj-9c97.json
+++ b/advisories/unreviewed/2022/05/GHSA-72gg-m2hj-9c97/GHSA-72gg-m2hj-9c97.json
@@ -7,12 +7,8 @@
"CVE-2007-3641"
],
"details": "archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -84,9 +80,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-72xv-7h5g-gfmj/GHSA-72xv-7h5g-gfmj.json b/advisories/unreviewed/2022/05/GHSA-72xv-7h5g-gfmj/GHSA-72xv-7h5g-gfmj.json
index 3e4168fecca..fb277708a9e 100644
--- a/advisories/unreviewed/2022/05/GHSA-72xv-7h5g-gfmj/GHSA-72xv-7h5g-gfmj.json
+++ b/advisories/unreviewed/2022/05/GHSA-72xv-7h5g-gfmj/GHSA-72xv-7h5g-gfmj.json
@@ -7,12 +7,8 @@
"CVE-2007-3789"
],
"details": "SQL injection vulnerability in admin/index.php in Inmostore 4.0 allows remote attackers to execute arbitrary SQL commands via the Password field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7355-h593-rmfr/GHSA-7355-h593-rmfr.json b/advisories/unreviewed/2022/05/GHSA-7355-h593-rmfr/GHSA-7355-h593-rmfr.json
index 1abc9fe8799..f4e77f26ba1 100644
--- a/advisories/unreviewed/2022/05/GHSA-7355-h593-rmfr/GHSA-7355-h593-rmfr.json
+++ b/advisories/unreviewed/2022/05/GHSA-7355-h593-rmfr/GHSA-7355-h593-rmfr.json
@@ -7,12 +7,8 @@
"CVE-2007-3364"
],
"details": "Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-73f7-h4v5-cwjw/GHSA-73f7-h4v5-cwjw.json b/advisories/unreviewed/2022/05/GHSA-73f7-h4v5-cwjw/GHSA-73f7-h4v5-cwjw.json
index 91711ef7831..8b355a07ab0 100644
--- a/advisories/unreviewed/2022/05/GHSA-73f7-h4v5-cwjw/GHSA-73f7-h4v5-cwjw.json
+++ b/advisories/unreviewed/2022/05/GHSA-73f7-h4v5-cwjw/GHSA-73f7-h4v5-cwjw.json
@@ -7,12 +7,8 @@
"CVE-2007-3646"
],
"details": "SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-744m-rvgq-38hm/GHSA-744m-rvgq-38hm.json b/advisories/unreviewed/2022/05/GHSA-744m-rvgq-38hm/GHSA-744m-rvgq-38hm.json
index 57658d81f26..ea5220fc1b7 100644
--- a/advisories/unreviewed/2022/05/GHSA-744m-rvgq-38hm/GHSA-744m-rvgq-38hm.json
+++ b/advisories/unreviewed/2022/05/GHSA-744m-rvgq-38hm/GHSA-744m-rvgq-38hm.json
@@ -7,12 +7,8 @@
"CVE-2007-3505"
],
"details": "Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-773p-xv6c-mvj8/GHSA-773p-xv6c-mvj8.json b/advisories/unreviewed/2022/05/GHSA-773p-xv6c-mvj8/GHSA-773p-xv6c-mvj8.json
index d38903f6215..937296e31bc 100644
--- a/advisories/unreviewed/2022/05/GHSA-773p-xv6c-mvj8/GHSA-773p-xv6c-mvj8.json
+++ b/advisories/unreviewed/2022/05/GHSA-773p-xv6c-mvj8/GHSA-773p-xv6c-mvj8.json
@@ -7,12 +7,8 @@
"CVE-2007-3610"
],
"details": "SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-78xj-x9qf-5268/GHSA-78xj-x9qf-5268.json b/advisories/unreviewed/2022/05/GHSA-78xj-x9qf-5268/GHSA-78xj-x9qf-5268.json
index 832db9854bf..4dadeef4cbc 100644
--- a/advisories/unreviewed/2022/05/GHSA-78xj-x9qf-5268/GHSA-78xj-x9qf-5268.json
+++ b/advisories/unreviewed/2022/05/GHSA-78xj-x9qf-5268/GHSA-78xj-x9qf-5268.json
@@ -7,12 +7,8 @@
"CVE-2007-3533"
],
"details": "The 3Com IntelliJack Switch NJ220 before 2.0.23 allows remote attackers to cause a denial of service (reboot and reporting outage) via a loopback packet with zero in the length field.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7939-9gq4-g76m/GHSA-7939-9gq4-g76m.json b/advisories/unreviewed/2022/05/GHSA-7939-9gq4-g76m/GHSA-7939-9gq4-g76m.json
index 9f8630173c3..e2b517b929d 100644
--- a/advisories/unreviewed/2022/05/GHSA-7939-9gq4-g76m/GHSA-7939-9gq4-g76m.json
+++ b/advisories/unreviewed/2022/05/GHSA-7939-9gq4-g76m/GHSA-7939-9gq4-g76m.json
@@ -7,12 +7,8 @@
"CVE-2007-3783"
],
"details": "SQL injection vulnerability in default.asp in enVivo!CMS allows remote attackers to execute arbitrary SQL commands via the ID parameter in an article action. NOTE: this is probably different from CVE-2005-1413.4.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7c6m-q9jm-ch6c/GHSA-7c6m-q9jm-ch6c.json b/advisories/unreviewed/2022/05/GHSA-7c6m-q9jm-ch6c/GHSA-7c6m-q9jm-ch6c.json
index 4d44c131118..c0f5b114789 100644
--- a/advisories/unreviewed/2022/05/GHSA-7c6m-q9jm-ch6c/GHSA-7c6m-q9jm-ch6c.json
+++ b/advisories/unreviewed/2022/05/GHSA-7c6m-q9jm-ch6c/GHSA-7c6m-q9jm-ch6c.json
@@ -7,12 +7,8 @@
"CVE-2007-3553"
],
"details": "Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the \"Secondary Login Page\", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7c9x-vh62-vc8g/GHSA-7c9x-vh62-vc8g.json b/advisories/unreviewed/2022/05/GHSA-7c9x-vh62-vc8g/GHSA-7c9x-vh62-vc8g.json
index 31240ea6aff..cfa0a141c2c 100644
--- a/advisories/unreviewed/2022/05/GHSA-7c9x-vh62-vc8g/GHSA-7c9x-vh62-vc8g.json
+++ b/advisories/unreviewed/2022/05/GHSA-7c9x-vh62-vc8g/GHSA-7c9x-vh62-vc8g.json
@@ -7,12 +7,8 @@
"CVE-2007-3415"
],
"details": "Multiple SQL injection vulnerabilities in index.php in phpRaider 1.0.0 rc8 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) type parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7cfv-jg3m-5vqg/GHSA-7cfv-jg3m-5vqg.json b/advisories/unreviewed/2022/05/GHSA-7cfv-jg3m-5vqg/GHSA-7cfv-jg3m-5vqg.json
index 8c2fbae259a..484c69a4ce9 100644
--- a/advisories/unreviewed/2022/05/GHSA-7cfv-jg3m-5vqg/GHSA-7cfv-jg3m-5vqg.json
+++ b/advisories/unreviewed/2022/05/GHSA-7cfv-jg3m-5vqg/GHSA-7cfv-jg3m-5vqg.json
@@ -7,12 +7,8 @@
"CVE-2007-3960"
],
"details": "Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a \"Potential security exposure\" in the Samples component (PK40213).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7g4f-rgpr-35g2/GHSA-7g4f-rgpr-35g2.json b/advisories/unreviewed/2022/05/GHSA-7g4f-rgpr-35g2/GHSA-7g4f-rgpr-35g2.json
index 1adbb19e42b..e76f8dcdba7 100644
--- a/advisories/unreviewed/2022/05/GHSA-7g4f-rgpr-35g2/GHSA-7g4f-rgpr-35g2.json
+++ b/advisories/unreviewed/2022/05/GHSA-7g4f-rgpr-35g2/GHSA-7g4f-rgpr-35g2.json
@@ -7,12 +7,8 @@
"CVE-2007-3937"
],
"details": "Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-7g5m-8x27-79gh/GHSA-7g5m-8x27-79gh.json b/advisories/unreviewed/2022/05/GHSA-7g5m-8x27-79gh/GHSA-7g5m-8x27-79gh.json
index d376d37e9d7..5a0556c4a9b 100644
--- a/advisories/unreviewed/2022/05/GHSA-7g5m-8x27-79gh/GHSA-7g5m-8x27-79gh.json
+++ b/advisories/unreviewed/2022/05/GHSA-7g5m-8x27-79gh/GHSA-7g5m-8x27-79gh.json
@@ -7,12 +7,8 @@
"CVE-2007-3328"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Interact 2.4 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) module_key parameter to (a) kb/kb.php, (b) quiz/runquiz.php, (c) quiz/quiz.php, (d) forum/forum.php, (e) forum/byname.php, and (f) journal/journalview.php in modules/, and unspecified other scripts; the (2) tag_key parameter to modules/journal/journalview.php; the (3) user_group_key parameter to (g) users/secureaccounts.php; and (4) the request_uri parameter to (h) login.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -68,9 +64,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7gxf-4q7v-m96f/GHSA-7gxf-4q7v-m96f.json b/advisories/unreviewed/2022/05/GHSA-7gxf-4q7v-m96f/GHSA-7gxf-4q7v-m96f.json
index 7048d16f8a5..e280ecdb274 100644
--- a/advisories/unreviewed/2022/05/GHSA-7gxf-4q7v-m96f/GHSA-7gxf-4q7v-m96f.json
+++ b/advisories/unreviewed/2022/05/GHSA-7gxf-4q7v-m96f/GHSA-7gxf-4q7v-m96f.json
@@ -7,12 +7,8 @@
"CVE-2019-7848"
],
"details": "Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7hxv-5pvm-4mww/GHSA-7hxv-5pvm-4mww.json b/advisories/unreviewed/2022/05/GHSA-7hxv-5pvm-4mww/GHSA-7hxv-5pvm-4mww.json
index 19284794b75..5465f447583 100644
--- a/advisories/unreviewed/2022/05/GHSA-7hxv-5pvm-4mww/GHSA-7hxv-5pvm-4mww.json
+++ b/advisories/unreviewed/2022/05/GHSA-7hxv-5pvm-4mww/GHSA-7hxv-5pvm-4mww.json
@@ -7,12 +7,8 @@
"CVE-2007-3410"
],
"details": "Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-7m4h-vmxp-2j43/GHSA-7m4h-vmxp-2j43.json b/advisories/unreviewed/2022/05/GHSA-7m4h-vmxp-2j43/GHSA-7m4h-vmxp-2j43.json
index 41c7bdf63d8..f32da49c19d 100644
--- a/advisories/unreviewed/2022/05/GHSA-7m4h-vmxp-2j43/GHSA-7m4h-vmxp-2j43.json
+++ b/advisories/unreviewed/2022/05/GHSA-7m4h-vmxp-2j43/GHSA-7m4h-vmxp-2j43.json
@@ -7,12 +7,8 @@
"CVE-2007-3503"
],
"details": "The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-7m9j-p4pc-q4hm/GHSA-7m9j-p4pc-q4hm.json b/advisories/unreviewed/2022/05/GHSA-7m9j-p4pc-q4hm/GHSA-7m9j-p4pc-q4hm.json
index 02450872052..2f3c5a85c16 100644
--- a/advisories/unreviewed/2022/05/GHSA-7m9j-p4pc-q4hm/GHSA-7m9j-p4pc-q4hm.json
+++ b/advisories/unreviewed/2022/05/GHSA-7m9j-p4pc-q4hm/GHSA-7m9j-p4pc-q4hm.json
@@ -7,12 +7,8 @@
"CVE-2007-3486"
],
"details": "Cross-site scripting (XSS) vulnerability in AltaVista search engine allows remote attackers to inject arbitrary web script or HTML via the text parameter to the default URI.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7mxv-fq9j-x6mx/GHSA-7mxv-fq9j-x6mx.json b/advisories/unreviewed/2022/05/GHSA-7mxv-fq9j-x6mx/GHSA-7mxv-fq9j-x6mx.json
index dd49d8b0e92..e04fabcd0fd 100644
--- a/advisories/unreviewed/2022/05/GHSA-7mxv-fq9j-x6mx/GHSA-7mxv-fq9j-x6mx.json
+++ b/advisories/unreviewed/2022/05/GHSA-7mxv-fq9j-x6mx/GHSA-7mxv-fq9j-x6mx.json
@@ -7,12 +7,8 @@
"CVE-2007-3820"
],
"details": "konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -124,9 +120,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7p87-3v89-xjw3/GHSA-7p87-3v89-xjw3.json b/advisories/unreviewed/2022/05/GHSA-7p87-3v89-xjw3/GHSA-7p87-3v89-xjw3.json
index fab7017a373..38f061290a6 100644
--- a/advisories/unreviewed/2022/05/GHSA-7p87-3v89-xjw3/GHSA-7p87-3v89-xjw3.json
+++ b/advisories/unreviewed/2022/05/GHSA-7p87-3v89-xjw3/GHSA-7p87-3v89-xjw3.json
@@ -7,12 +7,8 @@
"CVE-2007-3394"
],
"details": "Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7q5j-8jvh-4jj2/GHSA-7q5j-8jvh-4jj2.json b/advisories/unreviewed/2022/05/GHSA-7q5j-8jvh-4jj2/GHSA-7q5j-8jvh-4jj2.json
index eb156ef3235..18420e1656c 100644
--- a/advisories/unreviewed/2022/05/GHSA-7q5j-8jvh-4jj2/GHSA-7q5j-8jvh-4jj2.json
+++ b/advisories/unreviewed/2022/05/GHSA-7q5j-8jvh-4jj2/GHSA-7q5j-8jvh-4jj2.json
@@ -7,12 +7,8 @@
"CVE-2007-3719"
],
"details": "The process scheduler in the Linux kernel 2.6.16 gives preference to \"interactive\" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7qgw-j3rw-j7v9/GHSA-7qgw-j3rw-j7v9.json b/advisories/unreviewed/2022/05/GHSA-7qgw-j3rw-j7v9/GHSA-7qgw-j3rw-j7v9.json
index 978a2931c3d..949381655a1 100644
--- a/advisories/unreviewed/2022/05/GHSA-7qgw-j3rw-j7v9/GHSA-7qgw-j3rw-j7v9.json
+++ b/advisories/unreviewed/2022/05/GHSA-7qgw-j3rw-j7v9/GHSA-7qgw-j3rw-j7v9.json
@@ -7,12 +7,8 @@
"CVE-2007-3586"
],
"details": "Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included by games.php. NOTE: programs that use games.php might include (a) snakep.php, (b) tetrisp.php, and possibly other site-specific files.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-7qj6-vx86-3xm5/GHSA-7qj6-vx86-3xm5.json b/advisories/unreviewed/2022/05/GHSA-7qj6-vx86-3xm5/GHSA-7qj6-vx86-3xm5.json
index 8531f61565b..5ac01ec0787 100644
--- a/advisories/unreviewed/2022/05/GHSA-7qj6-vx86-3xm5/GHSA-7qj6-vx86-3xm5.json
+++ b/advisories/unreviewed/2022/05/GHSA-7qj6-vx86-3xm5/GHSA-7qj6-vx86-3xm5.json
@@ -7,12 +7,8 @@
"CVE-2007-3597"
],
"details": "Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-7r3g-gjqx-w4jm/GHSA-7r3g-gjqx-w4jm.json b/advisories/unreviewed/2022/05/GHSA-7r3g-gjqx-w4jm/GHSA-7r3g-gjqx-w4jm.json
index 78862d1f344..66ffe2f66b9 100644
--- a/advisories/unreviewed/2022/05/GHSA-7r3g-gjqx-w4jm/GHSA-7r3g-gjqx-w4jm.json
+++ b/advisories/unreviewed/2022/05/GHSA-7r3g-gjqx-w4jm/GHSA-7r3g-gjqx-w4jm.json
@@ -7,12 +7,8 @@
"CVE-2006-1078"
],
"details": "Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -76,9 +72,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-7r88-6fh6-rqh5/GHSA-7r88-6fh6-rqh5.json b/advisories/unreviewed/2022/05/GHSA-7r88-6fh6-rqh5/GHSA-7r88-6fh6-rqh5.json
index 5d7582f0f83..17a1e08fb6a 100644
--- a/advisories/unreviewed/2022/05/GHSA-7r88-6fh6-rqh5/GHSA-7r88-6fh6-rqh5.json
+++ b/advisories/unreviewed/2022/05/GHSA-7r88-6fh6-rqh5/GHSA-7r88-6fh6-rqh5.json
@@ -7,12 +7,8 @@
"CVE-2007-3638"
],
"details": "Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-7vxc-jxh7-6rfv/GHSA-7vxc-jxh7-6rfv.json b/advisories/unreviewed/2022/05/GHSA-7vxc-jxh7-6rfv/GHSA-7vxc-jxh7-6rfv.json
index 4db255e7480..39eef063cfe 100644
--- a/advisories/unreviewed/2022/05/GHSA-7vxc-jxh7-6rfv/GHSA-7vxc-jxh7-6rfv.json
+++ b/advisories/unreviewed/2022/05/GHSA-7vxc-jxh7-6rfv/GHSA-7vxc-jxh7-6rfv.json
@@ -7,12 +7,8 @@
"CVE-2007-3344"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in netjukebox 4.01b allow remote attackers to inject arbitrary web script or HTML via the (1) album_id, (2) order, (3) sort, (4) filter, and (5) genre_id parameters to (a) index.php; and the (6) url parameter to (b) ridirect.php. NOTE: the attack also reveals the installation path.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-822c-3x4j-h56q/GHSA-822c-3x4j-h56q.json b/advisories/unreviewed/2022/05/GHSA-822c-3x4j-h56q/GHSA-822c-3x4j-h56q.json
index e261f938d08..821423552e0 100644
--- a/advisories/unreviewed/2022/05/GHSA-822c-3x4j-h56q/GHSA-822c-3x4j-h56q.json
+++ b/advisories/unreviewed/2022/05/GHSA-822c-3x4j-h56q/GHSA-822c-3x4j-h56q.json
@@ -7,12 +7,8 @@
"CVE-2007-3763"
],
"details": "The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-82hr-rgm4-3x6p/GHSA-82hr-rgm4-3x6p.json b/advisories/unreviewed/2022/05/GHSA-82hr-rgm4-3x6p/GHSA-82hr-rgm4-3x6p.json
index 7e090d3c91a..f81daa0b097 100644
--- a/advisories/unreviewed/2022/05/GHSA-82hr-rgm4-3x6p/GHSA-82hr-rgm4-3x6p.json
+++ b/advisories/unreviewed/2022/05/GHSA-82hr-rgm4-3x6p/GHSA-82hr-rgm4-3x6p.json
@@ -7,12 +7,8 @@
"CVE-2007-3455"
],
"details": "cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to \"stored decrypted user logon information.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-82rp-r6c3-rrxr/GHSA-82rp-r6c3-rrxr.json b/advisories/unreviewed/2022/05/GHSA-82rp-r6c3-rrxr/GHSA-82rp-r6c3-rrxr.json
index 5cac98dd47a..5adaca9c679 100644
--- a/advisories/unreviewed/2022/05/GHSA-82rp-r6c3-rrxr/GHSA-82rp-r6c3-rrxr.json
+++ b/advisories/unreviewed/2022/05/GHSA-82rp-r6c3-rrxr/GHSA-82rp-r6c3-rrxr.json
@@ -7,12 +7,8 @@
"CVE-2007-3792"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-835p-qcg2-q9mr/GHSA-835p-qcg2-q9mr.json b/advisories/unreviewed/2022/05/GHSA-835p-qcg2-q9mr/GHSA-835p-qcg2-q9mr.json
index f7e0c652ecf..337940e91b1 100644
--- a/advisories/unreviewed/2022/05/GHSA-835p-qcg2-q9mr/GHSA-835p-qcg2-q9mr.json
+++ b/advisories/unreviewed/2022/05/GHSA-835p-qcg2-q9mr/GHSA-835p-qcg2-q9mr.json
@@ -7,12 +7,8 @@
"CVE-2007-3573"
],
"details": "Multiple SQL injection vulnerabilities in akocomment allow remote attackers to execute arbitrary SQL commands via the (1) acparentid or (2) acitemid parameter to an unspecified component, different vectors than CVE-2006-1421.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8375-gg7c-7cc8/GHSA-8375-gg7c-7cc8.json b/advisories/unreviewed/2022/05/GHSA-8375-gg7c-7cc8/GHSA-8375-gg7c-7cc8.json
index c3c58dc04fa..e4857aa5e4f 100644
--- a/advisories/unreviewed/2022/05/GHSA-8375-gg7c-7cc8/GHSA-8375-gg7c-7cc8.json
+++ b/advisories/unreviewed/2022/05/GHSA-8375-gg7c-7cc8/GHSA-8375-gg7c-7cc8.json
@@ -7,12 +7,8 @@
"CVE-2007-3527"
],
"details": "Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain database operations with multi-byte character sets that trigger an attempt to use the value 65536 for a 16-bit integer, which is treated as 0 and causes an infinite loop on zero-length data.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-83vp-5vg4-r3g7/GHSA-83vp-5vg4-r3g7.json b/advisories/unreviewed/2022/05/GHSA-83vp-5vg4-r3g7/GHSA-83vp-5vg4-r3g7.json
index 980c8f222ee..12303836e02 100644
--- a/advisories/unreviewed/2022/05/GHSA-83vp-5vg4-r3g7/GHSA-83vp-5vg4-r3g7.json
+++ b/advisories/unreviewed/2022/05/GHSA-83vp-5vg4-r3g7/GHSA-83vp-5vg4-r3g7.json
@@ -7,12 +7,8 @@
"CVE-2007-3564"
],
"details": "libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allows remote attackers to bypass certain access restrictions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-84qc-cgrr-m4wp/GHSA-84qc-cgrr-m4wp.json b/advisories/unreviewed/2022/05/GHSA-84qc-cgrr-m4wp/GHSA-84qc-cgrr-m4wp.json
index 4f954117d6b..8d9a9a3f61b 100644
--- a/advisories/unreviewed/2022/05/GHSA-84qc-cgrr-m4wp/GHSA-84qc-cgrr-m4wp.json
+++ b/advisories/unreviewed/2022/05/GHSA-84qc-cgrr-m4wp/GHSA-84qc-cgrr-m4wp.json
@@ -7,12 +7,8 @@
"CVE-2007-3929"
],
"details": "Use-after-free vulnerability in the BitTorrent support in Opera before 9.22 allows user-assisted remote attackers to execute arbitrary code via a crafted header in a torrent file, which leaves a dangling pointer to an invalid object.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-85pw-5r65-3fwm/GHSA-85pw-5r65-3fwm.json b/advisories/unreviewed/2022/05/GHSA-85pw-5r65-3fwm/GHSA-85pw-5r65-3fwm.json
index 7cf7386bf51..8c7278bcb54 100644
--- a/advisories/unreviewed/2022/05/GHSA-85pw-5r65-3fwm/GHSA-85pw-5r65-3fwm.json
+++ b/advisories/unreviewed/2022/05/GHSA-85pw-5r65-3fwm/GHSA-85pw-5r65-3fwm.json
@@ -7,12 +7,8 @@
"CVE-2007-3228"
],
"details": "PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-86w2-42v3-g3w8/GHSA-86w2-42v3-g3w8.json b/advisories/unreviewed/2022/05/GHSA-86w2-42v3-g3w8/GHSA-86w2-42v3-g3w8.json
index 754382f6e78..078d7b7172e 100644
--- a/advisories/unreviewed/2022/05/GHSA-86w2-42v3-g3w8/GHSA-86w2-42v3-g3w8.json
+++ b/advisories/unreviewed/2022/05/GHSA-86w2-42v3-g3w8/GHSA-86w2-42v3-g3w8.json
@@ -7,12 +7,8 @@
"CVE-2007-3222"
],
"details": "PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-86w8-6xgq-q96x/GHSA-86w8-6xgq-q96x.json b/advisories/unreviewed/2022/05/GHSA-86w8-6xgq-q96x/GHSA-86w8-6xgq-q96x.json
index 0fd1f2ba433..2af3d5662d1 100644
--- a/advisories/unreviewed/2022/05/GHSA-86w8-6xgq-q96x/GHSA-86w8-6xgq-q96x.json
+++ b/advisories/unreviewed/2022/05/GHSA-86w8-6xgq-q96x/GHSA-86w8-6xgq-q96x.json
@@ -7,12 +7,8 @@
"CVE-2007-3630"
],
"details": "changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-878r-8pw6-2fjw/GHSA-878r-8pw6-2fjw.json b/advisories/unreviewed/2022/05/GHSA-878r-8pw6-2fjw/GHSA-878r-8pw6-2fjw.json
index a5464bd20cd..551d768701b 100644
--- a/advisories/unreviewed/2022/05/GHSA-878r-8pw6-2fjw/GHSA-878r-8pw6-2fjw.json
+++ b/advisories/unreviewed/2022/05/GHSA-878r-8pw6-2fjw/GHSA-878r-8pw6-2fjw.json
@@ -7,12 +7,8 @@
"CVE-2019-15111"
],
"details": "The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-87v6-98r2-2c3g/GHSA-87v6-98r2-2c3g.json b/advisories/unreviewed/2022/05/GHSA-87v6-98r2-2c3g/GHSA-87v6-98r2-2c3g.json
index ae58ffbd1fc..2d999f2968c 100644
--- a/advisories/unreviewed/2022/05/GHSA-87v6-98r2-2c3g/GHSA-87v6-98r2-2c3g.json
+++ b/advisories/unreviewed/2022/05/GHSA-87v6-98r2-2c3g/GHSA-87v6-98r2-2c3g.json
@@ -7,12 +7,8 @@
"CVE-2007-3561"
],
"details": "Cross-site scripting (XSS) vulnerability in ara.asp in Efendy Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-884p-rv7w-x8h6/GHSA-884p-rv7w-x8h6.json b/advisories/unreviewed/2022/05/GHSA-884p-rv7w-x8h6/GHSA-884p-rv7w-x8h6.json
index 060ca13230c..341ac101878 100644
--- a/advisories/unreviewed/2022/05/GHSA-884p-rv7w-x8h6/GHSA-884p-rv7w-x8h6.json
+++ b/advisories/unreviewed/2022/05/GHSA-884p-rv7w-x8h6/GHSA-884p-rv7w-x8h6.json
@@ -7,12 +7,8 @@
"CVE-2007-3634"
],
"details": "Unspecified vulnerability in the G/PGP (GPG) Plugin 2.0 for Squirrelmail 1.4.10a allows remote authenticated users to execute arbitrary commands via unspecified vectors, possibly related to the passphrase variable in the gpg_sign_attachment function, aka ZD-00000004. this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-88c5-h2gm-6wp3/GHSA-88c5-h2gm-6wp3.json b/advisories/unreviewed/2022/05/GHSA-88c5-h2gm-6wp3/GHSA-88c5-h2gm-6wp3.json
index 3be22b6b659..8fc53a0f9a7 100644
--- a/advisories/unreviewed/2022/05/GHSA-88c5-h2gm-6wp3/GHSA-88c5-h2gm-6wp3.json
+++ b/advisories/unreviewed/2022/05/GHSA-88c5-h2gm-6wp3/GHSA-88c5-h2gm-6wp3.json
@@ -7,12 +7,8 @@
"CVE-2007-3811"
],
"details": "Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8c33-5pqg-7qpm/GHSA-8c33-5pqg-7qpm.json b/advisories/unreviewed/2022/05/GHSA-8c33-5pqg-7qpm/GHSA-8c33-5pqg-7qpm.json
index 7a9146ea9ee..7488bbe98fe 100644
--- a/advisories/unreviewed/2022/05/GHSA-8c33-5pqg-7qpm/GHSA-8c33-5pqg-7qpm.json
+++ b/advisories/unreviewed/2022/05/GHSA-8c33-5pqg-7qpm/GHSA-8c33-5pqg-7qpm.json
@@ -7,12 +7,8 @@
"CVE-2007-3545"
],
"details": "Buffer overflow in Warzone 2100 Resurrection before 2.0.7 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename when setting background music.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8cgw-vjfc-fgm4/GHSA-8cgw-vjfc-fgm4.json b/advisories/unreviewed/2022/05/GHSA-8cgw-vjfc-fgm4/GHSA-8cgw-vjfc-fgm4.json
index 63b4917b136..5e0aca2995a 100644
--- a/advisories/unreviewed/2022/05/GHSA-8cgw-vjfc-fgm4/GHSA-8cgw-vjfc-fgm4.json
+++ b/advisories/unreviewed/2022/05/GHSA-8cgw-vjfc-fgm4/GHSA-8cgw-vjfc-fgm4.json
@@ -7,12 +7,8 @@
"CVE-2007-3538"
],
"details": "SQL injection vulnerability in qtg_msg_view.php in QuickTalk guestbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8fvf-2jw2-pr87/GHSA-8fvf-2jw2-pr87.json b/advisories/unreviewed/2022/05/GHSA-8fvf-2jw2-pr87/GHSA-8fvf-2jw2-pr87.json
index ae50b66120c..688850e35d1 100644
--- a/advisories/unreviewed/2022/05/GHSA-8fvf-2jw2-pr87/GHSA-8fvf-2jw2-pr87.json
+++ b/advisories/unreviewed/2022/05/GHSA-8fvf-2jw2-pr87/GHSA-8fvf-2jw2-pr87.json
@@ -7,12 +7,8 @@
"CVE-2007-3933"
],
"details": "SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the CFTOKEN parameter, a different vector than CVE-2006-2053.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-8j8r-fm4v-fvr8/GHSA-8j8r-fm4v-fvr8.json b/advisories/unreviewed/2022/05/GHSA-8j8r-fm4v-fvr8/GHSA-8j8r-fm4v-fvr8.json
index 64bea2b74ea..8b669e852a3 100644
--- a/advisories/unreviewed/2022/05/GHSA-8j8r-fm4v-fvr8/GHSA-8j8r-fm4v-fvr8.json
+++ b/advisories/unreviewed/2022/05/GHSA-8j8r-fm4v-fvr8/GHSA-8j8r-fm4v-fvr8.json
@@ -7,12 +7,8 @@
"CVE-2007-3584"
],
"details": "SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8m8h-3hp6-j28x/GHSA-8m8h-3hp6-j28x.json b/advisories/unreviewed/2022/05/GHSA-8m8h-3hp6-j28x/GHSA-8m8h-3hp6-j28x.json
index 0972c129cf5..1070bf40176 100644
--- a/advisories/unreviewed/2022/05/GHSA-8m8h-3hp6-j28x/GHSA-8m8h-3hp6-j28x.json
+++ b/advisories/unreviewed/2022/05/GHSA-8m8h-3hp6-j28x/GHSA-8m8h-3hp6-j28x.json
@@ -7,12 +7,8 @@
"CVE-2007-3662"
],
"details": "Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FLV file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8mc6-rcpw-3j8c/GHSA-8mc6-rcpw-3j8c.json b/advisories/unreviewed/2022/05/GHSA-8mc6-rcpw-3j8c/GHSA-8mc6-rcpw-3j8c.json
index 0d0e983d44a..bae9bf27b41 100644
--- a/advisories/unreviewed/2022/05/GHSA-8mc6-rcpw-3j8c/GHSA-8mc6-rcpw-3j8c.json
+++ b/advisories/unreviewed/2022/05/GHSA-8mc6-rcpw-3j8c/GHSA-8mc6-rcpw-3j8c.json
@@ -7,12 +7,8 @@
"CVE-2007-3230"
],
"details": "PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8p3g-fvg6-vqh6/GHSA-8p3g-fvg6-vqh6.json b/advisories/unreviewed/2022/05/GHSA-8p3g-fvg6-vqh6/GHSA-8p3g-fvg6-vqh6.json
index 6d44bb8d8bb..893548948e4 100644
--- a/advisories/unreviewed/2022/05/GHSA-8p3g-fvg6-vqh6/GHSA-8p3g-fvg6-vqh6.json
+++ b/advisories/unreviewed/2022/05/GHSA-8p3g-fvg6-vqh6/GHSA-8p3g-fvg6-vqh6.json
@@ -7,12 +7,8 @@
"CVE-2007-3326"
],
"details": "Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and other attacks, a different vulnerability than CVE-2005-3025.2.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8pcm-74vv-2c6m/GHSA-8pcm-74vv-2c6m.json b/advisories/unreviewed/2022/05/GHSA-8pcm-74vv-2c6m/GHSA-8pcm-74vv-2c6m.json
index 78046df582a..0117fe4a316 100644
--- a/advisories/unreviewed/2022/05/GHSA-8pcm-74vv-2c6m/GHSA-8pcm-74vv-2c6m.json
+++ b/advisories/unreviewed/2022/05/GHSA-8pcm-74vv-2c6m/GHSA-8pcm-74vv-2c6m.json
@@ -7,12 +7,8 @@
"CVE-2007-3574"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-8q64-j7wc-42px/GHSA-8q64-j7wc-42px.json b/advisories/unreviewed/2022/05/GHSA-8q64-j7wc-42px/GHSA-8q64-j7wc-42px.json
index 8b1cfba2ed3..eb9706a5f4d 100644
--- a/advisories/unreviewed/2022/05/GHSA-8q64-j7wc-42px/GHSA-8q64-j7wc-42px.json
+++ b/advisories/unreviewed/2022/05/GHSA-8q64-j7wc-42px/GHSA-8q64-j7wc-42px.json
@@ -7,12 +7,8 @@
"CVE-2007-3499"
],
"details": "SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a valid signature, which allows remote Slackware mirror sites or man-in-the-middle attackers to cause a denial of service (data inconsistency) or possibly install Trojan horse packages via malformed gpg signatures.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8v42-99xf-jmf6/GHSA-8v42-99xf-jmf6.json b/advisories/unreviewed/2022/05/GHSA-8v42-99xf-jmf6/GHSA-8v42-99xf-jmf6.json
index 2b85086dfea..02dbe75dacf 100644
--- a/advisories/unreviewed/2022/05/GHSA-8v42-99xf-jmf6/GHSA-8v42-99xf-jmf6.json
+++ b/advisories/unreviewed/2022/05/GHSA-8v42-99xf-jmf6/GHSA-8v42-99xf-jmf6.json
@@ -7,12 +7,8 @@
"CVE-2007-3632"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -68,9 +64,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8v86-544p-jvp9/GHSA-8v86-544p-jvp9.json b/advisories/unreviewed/2022/05/GHSA-8v86-544p-jvp9/GHSA-8v86-544p-jvp9.json
index ea8c5fc7580..c0235433558 100644
--- a/advisories/unreviewed/2022/05/GHSA-8v86-544p-jvp9/GHSA-8v86-544p-jvp9.json
+++ b/advisories/unreviewed/2022/05/GHSA-8v86-544p-jvp9/GHSA-8v86-544p-jvp9.json
@@ -7,12 +7,8 @@
"CVE-2007-3208"
],
"details": "CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8vqf-2742-m7gx/GHSA-8vqf-2742-m7gx.json b/advisories/unreviewed/2022/05/GHSA-8vqf-2742-m7gx/GHSA-8vqf-2742-m7gx.json
index 4e6d2ccafae..40ab7135676 100644
--- a/advisories/unreviewed/2022/05/GHSA-8vqf-2742-m7gx/GHSA-8vqf-2742-m7gx.json
+++ b/advisories/unreviewed/2022/05/GHSA-8vqf-2742-m7gx/GHSA-8vqf-2742-m7gx.json
@@ -7,12 +7,8 @@
"CVE-2007-3742"
],
"details": "WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing \"look-alike characters\" (homographs) and possibly perform phishing attacks.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8w88-phhf-cpcq/GHSA-8w88-phhf-cpcq.json b/advisories/unreviewed/2022/05/GHSA-8w88-phhf-cpcq/GHSA-8w88-phhf-cpcq.json
index d567e0b1292..676b1d2795a 100644
--- a/advisories/unreviewed/2022/05/GHSA-8w88-phhf-cpcq/GHSA-8w88-phhf-cpcq.json
+++ b/advisories/unreviewed/2022/05/GHSA-8w88-phhf-cpcq/GHSA-8w88-phhf-cpcq.json
@@ -7,12 +7,8 @@
"CVE-2007-3711"
],
"details": "Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows remote attackers to avoid detection by sending certain fragmented packets.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-8wff-6353-mjv4/GHSA-8wff-6353-mjv4.json b/advisories/unreviewed/2022/05/GHSA-8wff-6353-mjv4/GHSA-8wff-6353-mjv4.json
index cad951b34ac..0eb766491b6 100644
--- a/advisories/unreviewed/2022/05/GHSA-8wff-6353-mjv4/GHSA-8wff-6353-mjv4.json
+++ b/advisories/unreviewed/2022/05/GHSA-8wff-6353-mjv4/GHSA-8wff-6353-mjv4.json
@@ -7,12 +7,8 @@
"CVE-2007-3349"
],
"details": "The Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to (1) cause a denial of service (device freeze) via a malformed SIP message of a certain length or (2) cause a denial of service (continuous ring) via a malformed SIP message of a certain other length.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8wqm-f965-58f5/GHSA-8wqm-f965-58f5.json b/advisories/unreviewed/2022/05/GHSA-8wqm-f965-58f5/GHSA-8wqm-f965-58f5.json
index 9af535ef8f8..e41029ff25b 100644
--- a/advisories/unreviewed/2022/05/GHSA-8wqm-f965-58f5/GHSA-8wqm-f965-58f5.json
+++ b/advisories/unreviewed/2022/05/GHSA-8wqm-f965-58f5/GHSA-8wqm-f965-58f5.json
@@ -7,12 +7,8 @@
"CVE-2007-3519"
],
"details": "SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8xmw-vwcq-7673/GHSA-8xmw-vwcq-7673.json b/advisories/unreviewed/2022/05/GHSA-8xmw-vwcq-7673/GHSA-8xmw-vwcq-7673.json
index 2016d51ee3d..7782dc3a10e 100644
--- a/advisories/unreviewed/2022/05/GHSA-8xmw-vwcq-7673/GHSA-8xmw-vwcq-7673.json
+++ b/advisories/unreviewed/2022/05/GHSA-8xmw-vwcq-7673/GHSA-8xmw-vwcq-7673.json
@@ -7,12 +7,8 @@
"CVE-2007-3412"
],
"details": "Cross-site scripting (XSS) vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8xqh-x8mx-wj7m/GHSA-8xqh-x8mx-wj7m.json b/advisories/unreviewed/2022/05/GHSA-8xqh-x8mx-wj7m/GHSA-8xqh-x8mx-wj7m.json
index ad5ff5363e8..a6dcf33e79f 100644
--- a/advisories/unreviewed/2022/05/GHSA-8xqh-x8mx-wj7m/GHSA-8xqh-x8mx-wj7m.json
+++ b/advisories/unreviewed/2022/05/GHSA-8xqh-x8mx-wj7m/GHSA-8xqh-x8mx-wj7m.json
@@ -7,12 +7,8 @@
"CVE-2007-3209"
],
"details": "Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-8xwc-94h7-p674/GHSA-8xwc-94h7-p674.json b/advisories/unreviewed/2022/05/GHSA-8xwc-94h7-p674/GHSA-8xwc-94h7-p674.json
index 7f4cfa64afc..4ff31d21630 100644
--- a/advisories/unreviewed/2022/05/GHSA-8xwc-94h7-p674/GHSA-8xwc-94h7-p674.json
+++ b/advisories/unreviewed/2022/05/GHSA-8xwc-94h7-p674/GHSA-8xwc-94h7-p674.json
@@ -7,12 +7,8 @@
"CVE-2007-3482"
],
"details": "Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the \"same origin policy\" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-92pf-97hv-xf5j/GHSA-92pf-97hv-xf5j.json b/advisories/unreviewed/2022/05/GHSA-92pf-97hv-xf5j/GHSA-92pf-97hv-xf5j.json
index 2287f482363..b0fec6e7aec 100644
--- a/advisories/unreviewed/2022/05/GHSA-92pf-97hv-xf5j/GHSA-92pf-97hv-xf5j.json
+++ b/advisories/unreviewed/2022/05/GHSA-92pf-97hv-xf5j/GHSA-92pf-97hv-xf5j.json
@@ -7,12 +7,8 @@
"CVE-2007-3604"
],
"details": "vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-93f5-22qw-63mg/GHSA-93f5-22qw-63mg.json b/advisories/unreviewed/2022/05/GHSA-93f5-22qw-63mg/GHSA-93f5-22qw-63mg.json
index 143a426930e..9fc24eb1958 100644
--- a/advisories/unreviewed/2022/05/GHSA-93f5-22qw-63mg/GHSA-93f5-22qw-63mg.json
+++ b/advisories/unreviewed/2022/05/GHSA-93f5-22qw-63mg/GHSA-93f5-22qw-63mg.json
@@ -7,12 +7,8 @@
"CVE-2007-3447"
],
"details": "SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the \"basic search box.\" NOTE: 4.0.2 and other versions might also be affected.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-93x6-25w5-vc7r/GHSA-93x6-25w5-vc7r.json b/advisories/unreviewed/2022/05/GHSA-93x6-25w5-vc7r/GHSA-93x6-25w5-vc7r.json
index c7f582346a3..8a48ea93cde 100644
--- a/advisories/unreviewed/2022/05/GHSA-93x6-25w5-vc7r/GHSA-93x6-25w5-vc7r.json
+++ b/advisories/unreviewed/2022/05/GHSA-93x6-25w5-vc7r/GHSA-93x6-25w5-vc7r.json
@@ -7,12 +7,8 @@
"CVE-2007-3643"
],
"details": "admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-94cg-3wxp-w993/GHSA-94cg-3wxp-w993.json b/advisories/unreviewed/2022/05/GHSA-94cg-3wxp-w993/GHSA-94cg-3wxp-w993.json
index 718d1dc6735..13cf893e560 100644
--- a/advisories/unreviewed/2022/05/GHSA-94cg-3wxp-w993/GHSA-94cg-3wxp-w993.json
+++ b/advisories/unreviewed/2022/05/GHSA-94cg-3wxp-w993/GHSA-94cg-3wxp-w993.json
@@ -7,12 +7,8 @@
"CVE-2007-3547"
],
"details": "Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-94cx-8qx3-6fv7/GHSA-94cx-8qx3-6fv7.json b/advisories/unreviewed/2022/05/GHSA-94cx-8qx3-6fv7/GHSA-94cx-8qx3-6fv7.json
index 690bc6b7522..07f49208b44 100644
--- a/advisories/unreviewed/2022/05/GHSA-94cx-8qx3-6fv7/GHSA-94cx-8qx3-6fv7.json
+++ b/advisories/unreviewed/2022/05/GHSA-94cx-8qx3-6fv7/GHSA-94cx-8qx3-6fv7.json
@@ -7,12 +7,8 @@
"CVE-2019-12960"
],
"details": "LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-95fv-8qj3-cq4r/GHSA-95fv-8qj3-cq4r.json b/advisories/unreviewed/2022/05/GHSA-95fv-8qj3-cq4r/GHSA-95fv-8qj3-cq4r.json
index 8d206e72469..3b59c879ebb 100644
--- a/advisories/unreviewed/2022/05/GHSA-95fv-8qj3-cq4r/GHSA-95fv-8qj3-cq4r.json
+++ b/advisories/unreviewed/2022/05/GHSA-95fv-8qj3-cq4r/GHSA-95fv-8qj3-cq4r.json
@@ -7,12 +7,8 @@
"CVE-2007-3540"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-96j2-crfj-6gpp/GHSA-96j2-crfj-6gpp.json b/advisories/unreviewed/2022/05/GHSA-96j2-crfj-6gpp/GHSA-96j2-crfj-6gpp.json
index 322cf468032..840ca46bbc7 100644
--- a/advisories/unreviewed/2022/05/GHSA-96j2-crfj-6gpp/GHSA-96j2-crfj-6gpp.json
+++ b/advisories/unreviewed/2022/05/GHSA-96j2-crfj-6gpp/GHSA-96j2-crfj-6gpp.json
@@ -7,12 +7,8 @@
"CVE-2007-3446"
],
"details": "BugMall Shopping Cart 2.5 and earlier has a default username \"demo\" and password \"demo,\" which allows remote attackers to obtain login access.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-973h-3554-jfxv/GHSA-973h-3554-jfxv.json b/advisories/unreviewed/2022/05/GHSA-973h-3554-jfxv/GHSA-973h-3554-jfxv.json
index df6512b5ef3..db1db86505d 100644
--- a/advisories/unreviewed/2022/05/GHSA-973h-3554-jfxv/GHSA-973h-3554-jfxv.json
+++ b/advisories/unreviewed/2022/05/GHSA-973h-3554-jfxv/GHSA-973h-3554-jfxv.json
@@ -7,12 +7,8 @@
"CVE-2007-3219"
],
"details": "Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers to modify another user's profile data, such as an AIM screen name or Yahoo! identity.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-97cw-rp4w-hv59/GHSA-97cw-rp4w-hv59.json b/advisories/unreviewed/2022/05/GHSA-97cw-rp4w-hv59/GHSA-97cw-rp4w-hv59.json
index b9547ed11d4..29275ed5635 100644
--- a/advisories/unreviewed/2022/05/GHSA-97cw-rp4w-hv59/GHSA-97cw-rp4w-hv59.json
+++ b/advisories/unreviewed/2022/05/GHSA-97cw-rp4w-hv59/GHSA-97cw-rp4w-hv59.json
@@ -7,12 +7,8 @@
"CVE-2007-3524"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-97h3-3mmg-phv4/GHSA-97h3-3mmg-phv4.json b/advisories/unreviewed/2022/05/GHSA-97h3-3mmg-phv4/GHSA-97h3-3mmg-phv4.json
index 688dd63684c..a67873e8bc0 100644
--- a/advisories/unreviewed/2022/05/GHSA-97h3-3mmg-phv4/GHSA-97h3-3mmg-phv4.json
+++ b/advisories/unreviewed/2022/05/GHSA-97h3-3mmg-phv4/GHSA-97h3-3mmg-phv4.json
@@ -7,12 +7,8 @@
"CVE-2007-3761"
],
"details": "Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1 allows remote attackers to inject arbitrary web script or HTML by causing Javascript events to be applied to a frame in another domain.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-98m4-vh7x-3mwr/GHSA-98m4-vh7x-3mwr.json b/advisories/unreviewed/2022/05/GHSA-98m4-vh7x-3mwr/GHSA-98m4-vh7x-3mwr.json
index 7b6a145d107..a30c1692f48 100644
--- a/advisories/unreviewed/2022/05/GHSA-98m4-vh7x-3mwr/GHSA-98m4-vh7x-3mwr.json
+++ b/advisories/unreviewed/2022/05/GHSA-98m4-vh7x-3mwr/GHSA-98m4-vh7x-3mwr.json
@@ -7,12 +7,8 @@
"CVE-2007-3685"
],
"details": "Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9cfh-j5rr-38cm/GHSA-9cfh-j5rr-38cm.json b/advisories/unreviewed/2022/05/GHSA-9cfh-j5rr-38cm/GHSA-9cfh-j5rr-38cm.json
index 47ac6e2e353..86de8b1a7c0 100644
--- a/advisories/unreviewed/2022/05/GHSA-9cfh-j5rr-38cm/GHSA-9cfh-j5rr-38cm.json
+++ b/advisories/unreviewed/2022/05/GHSA-9cfh-j5rr-38cm/GHSA-9cfh-j5rr-38cm.json
@@ -7,12 +7,8 @@
"CVE-2007-3954"
],
"details": "Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking SeaMonkey.exe, a related issue to CVE-2007-3670.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-9g82-44g6-4xr3/GHSA-9g82-44g6-4xr3.json b/advisories/unreviewed/2022/05/GHSA-9g82-44g6-4xr3/GHSA-9g82-44g6-4xr3.json
index 0e78f988310..6252bd1e246 100644
--- a/advisories/unreviewed/2022/05/GHSA-9g82-44g6-4xr3/GHSA-9g82-44g6-4xr3.json
+++ b/advisories/unreviewed/2022/05/GHSA-9g82-44g6-4xr3/GHSA-9g82-44g6-4xr3.json
@@ -7,12 +7,8 @@
"CVE-2007-3687"
],
"details": "SQL injection vulnerability in inferno.php in the Inferno Technologies RPG Inferno 2.4 and earlier, a vBulletin module, allows remote authenticated attackers to execute arbitrary SQL commands via the id parameter in a ScanMember do action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-9g9c-g893-6m3w/GHSA-9g9c-g893-6m3w.json b/advisories/unreviewed/2022/05/GHSA-9g9c-g893-6m3w/GHSA-9g9c-g893-6m3w.json
index a71bb58f773..25f8758386f 100644
--- a/advisories/unreviewed/2022/05/GHSA-9g9c-g893-6m3w/GHSA-9g9c-g893-6m3w.json
+++ b/advisories/unreviewed/2022/05/GHSA-9g9c-g893-6m3w/GHSA-9g9c-g893-6m3w.json
@@ -7,12 +7,8 @@
"CVE-2007-3456"
],
"details": "Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an \"input validation error,\" including a signed comparison of values that are assumed to be non-negative.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -140,9 +136,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9jvm-5xgq-52vp/GHSA-9jvm-5xgq-52vp.json b/advisories/unreviewed/2022/05/GHSA-9jvm-5xgq-52vp/GHSA-9jvm-5xgq-52vp.json
index 5257a82b2c1..02cecdd0828 100644
--- a/advisories/unreviewed/2022/05/GHSA-9jvm-5xgq-52vp/GHSA-9jvm-5xgq-52vp.json
+++ b/advisories/unreviewed/2022/05/GHSA-9jvm-5xgq-52vp/GHSA-9jvm-5xgq-52vp.json
@@ -7,12 +7,8 @@
"CVE-2007-3614"
],
"details": "Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to \"numerous other fields.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9m43-xjfp-4f8q/GHSA-9m43-xjfp-4f8q.json b/advisories/unreviewed/2022/05/GHSA-9m43-xjfp-4f8q/GHSA-9m43-xjfp-4f8q.json
index 9615e0f64cf..e76cfe4eebd 100644
--- a/advisories/unreviewed/2022/05/GHSA-9m43-xjfp-4f8q/GHSA-9m43-xjfp-4f8q.json
+++ b/advisories/unreviewed/2022/05/GHSA-9m43-xjfp-4f8q/GHSA-9m43-xjfp-4f8q.json
@@ -7,12 +7,8 @@
"CVE-2007-3323"
],
"details": "SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9m4x-mqxm-3qc3/GHSA-9m4x-mqxm-3qc3.json b/advisories/unreviewed/2022/05/GHSA-9m4x-mqxm-3qc3/GHSA-9m4x-mqxm-3qc3.json
index 9949ef7d952..c3fe3afc16c 100644
--- a/advisories/unreviewed/2022/05/GHSA-9m4x-mqxm-3qc3/GHSA-9m4x-mqxm-3qc3.json
+++ b/advisories/unreviewed/2022/05/GHSA-9m4x-mqxm-3qc3/GHSA-9m4x-mqxm-3qc3.json
@@ -7,12 +7,8 @@
"CVE-2007-3807"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9p72-5wr5-29cq/GHSA-9p72-5wr5-29cq.json b/advisories/unreviewed/2022/05/GHSA-9p72-5wr5-29cq/GHSA-9p72-5wr5-29cq.json
index 91e75bff21e..52e0d1cc5f7 100644
--- a/advisories/unreviewed/2022/05/GHSA-9p72-5wr5-29cq/GHSA-9p72-5wr5-29cq.json
+++ b/advisories/unreviewed/2022/05/GHSA-9p72-5wr5-29cq/GHSA-9p72-5wr5-29cq.json
@@ -7,12 +7,8 @@
"CVE-2007-3523"
],
"details": "Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9qc5-qrj6-x6rf/GHSA-9qc5-qrj6-x6rf.json b/advisories/unreviewed/2022/05/GHSA-9qc5-qrj6-x6rf/GHSA-9qc5-qrj6-x6rf.json
index 6131f0a1b70..6f765d7a730 100644
--- a/advisories/unreviewed/2022/05/GHSA-9qc5-qrj6-x6rf/GHSA-9qc5-qrj6-x6rf.json
+++ b/advisories/unreviewed/2022/05/GHSA-9qc5-qrj6-x6rf/GHSA-9qc5-qrj6-x6rf.json
@@ -7,12 +7,8 @@
"CVE-2007-3356"
],
"details": "NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Common.php and (2) imageresizer.php, and (3) the use of __FILE__ in error reporting by imageresizer.php; and (4) via certain requests that reveal the table name and complete query, related to the Halt_On_Error setting in Mysql_db.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9qqw-jqgg-j6rq/GHSA-9qqw-jqgg-j6rq.json b/advisories/unreviewed/2022/05/GHSA-9qqw-jqgg-j6rq/GHSA-9qqw-jqgg-j6rq.json
index f0fc723a189..110e1639f72 100644
--- a/advisories/unreviewed/2022/05/GHSA-9qqw-jqgg-j6rq/GHSA-9qqw-jqgg-j6rq.json
+++ b/advisories/unreviewed/2022/05/GHSA-9qqw-jqgg-j6rq/GHSA-9qqw-jqgg-j6rq.json
@@ -7,12 +7,8 @@
"CVE-2007-3423"
],
"details": "cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9qxh-q6xq-r46v/GHSA-9qxh-q6xq-r46v.json b/advisories/unreviewed/2022/05/GHSA-9qxh-q6xq-r46v/GHSA-9qxh-q6xq-r46v.json
index ca1ea8459fd..fcf7a9935f6 100644
--- a/advisories/unreviewed/2022/05/GHSA-9qxh-q6xq-r46v/GHSA-9qxh-q6xq-r46v.json
+++ b/advisories/unreviewed/2022/05/GHSA-9qxh-q6xq-r46v/GHSA-9qxh-q6xq-r46v.json
@@ -7,12 +7,8 @@
"CVE-2007-3522"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9r2m-wv8g-mp4x/GHSA-9r2m-wv8g-mp4x.json b/advisories/unreviewed/2022/05/GHSA-9r2m-wv8g-mp4x/GHSA-9r2m-wv8g-mp4x.json
index 45df9e00dc6..99207f38d51 100644
--- a/advisories/unreviewed/2022/05/GHSA-9r2m-wv8g-mp4x/GHSA-9r2m-wv8g-mp4x.json
+++ b/advisories/unreviewed/2022/05/GHSA-9r2m-wv8g-mp4x/GHSA-9r2m-wv8g-mp4x.json
@@ -7,12 +7,8 @@
"CVE-2007-3800"
],
"details": "Unspecified vulnerability in the Real-time scanner (RTVScan) component in Symantec AntiVirus Corporate Edition 9.0 through 10.1 and Client Security 2.0 through 3.1, when the Notification Message window is enabled, allows local users to gain privileges via crafted code.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9r86-m2fw-8wr3/GHSA-9r86-m2fw-8wr3.json b/advisories/unreviewed/2022/05/GHSA-9r86-m2fw-8wr3/GHSA-9r86-m2fw-8wr3.json
index 746494ab50d..7d8e313966f 100644
--- a/advisories/unreviewed/2022/05/GHSA-9r86-m2fw-8wr3/GHSA-9r86-m2fw-8wr3.json
+++ b/advisories/unreviewed/2022/05/GHSA-9r86-m2fw-8wr3/GHSA-9r86-m2fw-8wr3.json
@@ -7,12 +7,8 @@
"CVE-2007-3428"
],
"details": "Multiple unspecified vulnerabilities in phpTrafficA before 1.4.2 allow remote attackers to have an unknown impact via the file parameter to (1) plotStatBar.php or (2) plotStatPie.php, different vectors than CVE-2007-1076.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9vf5-8r62-q8wp/GHSA-9vf5-8r62-q8wp.json b/advisories/unreviewed/2022/05/GHSA-9vf5-8r62-q8wp/GHSA-9vf5-8r62-q8wp.json
index e6b19774553..220ffd90a34 100644
--- a/advisories/unreviewed/2022/05/GHSA-9vf5-8r62-q8wp/GHSA-9vf5-8r62-q8wp.json
+++ b/advisories/unreviewed/2022/05/GHSA-9vf5-8r62-q8wp/GHSA-9vf5-8r62-q8wp.json
@@ -7,12 +7,8 @@
"CVE-2007-3812"
],
"details": "SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9w27-9x4w-w3w3/GHSA-9w27-9x4w-w3w3.json b/advisories/unreviewed/2022/05/GHSA-9w27-9x4w-w3w3/GHSA-9w27-9x4w-w3w3.json
index c07dc8d18fd..d957d9fd868 100644
--- a/advisories/unreviewed/2022/05/GHSA-9w27-9x4w-w3w3/GHSA-9w27-9x4w-w3w3.json
+++ b/advisories/unreviewed/2022/05/GHSA-9w27-9x4w-w3w3/GHSA-9w27-9x4w-w3w3.json
@@ -7,12 +7,8 @@
"CVE-2007-3772"
],
"details": "Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9wp9-mvvj-c449/GHSA-9wp9-mvvj-c449.json b/advisories/unreviewed/2022/05/GHSA-9wp9-mvvj-c449/GHSA-9wp9-mvvj-c449.json
index 83d702070e2..9214d64d17f 100644
--- a/advisories/unreviewed/2022/05/GHSA-9wp9-mvvj-c449/GHSA-9wp9-mvvj-c449.json
+++ b/advisories/unreviewed/2022/05/GHSA-9wp9-mvvj-c449/GHSA-9wp9-mvvj-c449.json
@@ -7,12 +7,8 @@
"CVE-2007-3704"
],
"details": "Entertainment CMS allows remote attackers to bypass authentication and perform certain administrative actions by setting the adminLogged cookie to \"Administrator.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9x93-wjhv-53jj/GHSA-9x93-wjhv-53jj.json b/advisories/unreviewed/2022/05/GHSA-9x93-wjhv-53jj/GHSA-9x93-wjhv-53jj.json
index 884c530078f..3fb98e9c14c 100644
--- a/advisories/unreviewed/2022/05/GHSA-9x93-wjhv-53jj/GHSA-9x93-wjhv-53jj.json
+++ b/advisories/unreviewed/2022/05/GHSA-9x93-wjhv-53jj/GHSA-9x93-wjhv-53jj.json
@@ -7,12 +7,8 @@
"CVE-2007-3492"
],
"details": "Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string containing \"//A:\" in the argument to the LIST command.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9xh5-8jph-vqv9/GHSA-9xh5-8jph-vqv9.json b/advisories/unreviewed/2022/05/GHSA-9xh5-8jph-vqv9/GHSA-9xh5-8jph-vqv9.json
index 7c3532a0f56..072eea48d15 100644
--- a/advisories/unreviewed/2022/05/GHSA-9xh5-8jph-vqv9/GHSA-9xh5-8jph-vqv9.json
+++ b/advisories/unreviewed/2022/05/GHSA-9xh5-8jph-vqv9/GHSA-9xh5-8jph-vqv9.json
@@ -7,12 +7,8 @@
"CVE-2007-3794"
],
"details": "Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9xpc-6hg7-3hcw/GHSA-9xpc-6hg7-3hcw.json b/advisories/unreviewed/2022/05/GHSA-9xpc-6hg7-3hcw/GHSA-9xpc-6hg7-3hcw.json
index 6dd883c9635..07432e6196b 100644
--- a/advisories/unreviewed/2022/05/GHSA-9xpc-6hg7-3hcw/GHSA-9xpc-6hg7-3hcw.json
+++ b/advisories/unreviewed/2022/05/GHSA-9xpc-6hg7-3hcw/GHSA-9xpc-6hg7-3hcw.json
@@ -7,12 +7,8 @@
"CVE-2007-3695"
],
"details": "Buffer overflow in LICRCMD.EXE in CA ERwin Process Modeler (formerly AllFusion Process Modeler) 7.1 allows attackers to execute arbitrary code via a long filename. NOTE: the researcher does not suggest any circumstances in which the filename would come from an untrusted source, and therefore perhaps the issue does not cross privilege boundaries and should not be included in CVE.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-9xr3-c3rj-hw9r/GHSA-9xr3-c3rj-hw9r.json b/advisories/unreviewed/2022/05/GHSA-9xr3-c3rj-hw9r/GHSA-9xr3-c3rj-hw9r.json
index eb9870a3b31..29be4306e35 100644
--- a/advisories/unreviewed/2022/05/GHSA-9xr3-c3rj-hw9r/GHSA-9xr3-c3rj-hw9r.json
+++ b/advisories/unreviewed/2022/05/GHSA-9xr3-c3rj-hw9r/GHSA-9xr3-c3rj-hw9r.json
@@ -7,12 +7,8 @@
"CVE-2007-3392"
],
"details": "Wireshark before 0.99.6 allows remote attackers to cause a denial of service via malformed (1) SSL or (2) MMS packets that trigger an infinite loop.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -112,9 +108,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c2c7-2qj9-j2mc/GHSA-c2c7-2qj9-j2mc.json b/advisories/unreviewed/2022/05/GHSA-c2c7-2qj9-j2mc/GHSA-c2c7-2qj9-j2mc.json
index a5e88b8b436..564f11a963e 100644
--- a/advisories/unreviewed/2022/05/GHSA-c2c7-2qj9-j2mc/GHSA-c2c7-2qj9-j2mc.json
+++ b/advisories/unreviewed/2022/05/GHSA-c2c7-2qj9-j2mc/GHSA-c2c7-2qj9-j2mc.json
@@ -7,12 +7,8 @@
"CVE-2007-3281"
],
"details": "Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c2cf-m6mx-7rqm/GHSA-c2cf-m6mx-7rqm.json b/advisories/unreviewed/2022/05/GHSA-c2cf-m6mx-7rqm/GHSA-c2cf-m6mx-7rqm.json
index b0299b66ee8..33edc54b8f8 100644
--- a/advisories/unreviewed/2022/05/GHSA-c2cf-m6mx-7rqm/GHSA-c2cf-m6mx-7rqm.json
+++ b/advisories/unreviewed/2022/05/GHSA-c2cf-m6mx-7rqm/GHSA-c2cf-m6mx-7rqm.json
@@ -7,12 +7,8 @@
"CVE-2007-3699"
],
"details": "The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c2xh-7j87-6j25/GHSA-c2xh-7j87-6j25.json b/advisories/unreviewed/2022/05/GHSA-c2xh-7j87-6j25/GHSA-c2xh-7j87-6j25.json
index 49f6e3ee2f1..77b3b75af1a 100644
--- a/advisories/unreviewed/2022/05/GHSA-c2xh-7j87-6j25/GHSA-c2xh-7j87-6j25.json
+++ b/advisories/unreviewed/2022/05/GHSA-c2xh-7j87-6j25/GHSA-c2xh-7j87-6j25.json
@@ -7,12 +7,8 @@
"CVE-2007-3922"
],
"details": "Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -136,9 +132,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c32f-73w9-32xc/GHSA-c32f-73w9-32xc.json b/advisories/unreviewed/2022/05/GHSA-c32f-73w9-32xc/GHSA-c32f-73w9-32xc.json
index e613866815a..39dbd0aef73 100644
--- a/advisories/unreviewed/2022/05/GHSA-c32f-73w9-32xc/GHSA-c32f-73w9-32xc.json
+++ b/advisories/unreviewed/2022/05/GHSA-c32f-73w9-32xc/GHSA-c32f-73w9-32xc.json
@@ -7,12 +7,8 @@
"CVE-2007-3619"
],
"details": "Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c393-9g57-887f/GHSA-c393-9g57-887f.json b/advisories/unreviewed/2022/05/GHSA-c393-9g57-887f/GHSA-c393-9g57-887f.json
index 572da593d5f..a2d9e0b60f1 100644
--- a/advisories/unreviewed/2022/05/GHSA-c393-9g57-887f/GHSA-c393-9g57-887f.json
+++ b/advisories/unreviewed/2022/05/GHSA-c393-9g57-887f/GHSA-c393-9g57-887f.json
@@ -7,12 +7,8 @@
"CVE-2007-3930"
],
"details": "Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c3jq-8mx5-pwh7/GHSA-c3jq-8mx5-pwh7.json b/advisories/unreviewed/2022/05/GHSA-c3jq-8mx5-pwh7/GHSA-c3jq-8mx5-pwh7.json
index 651da95cc2d..444f08d7722 100644
--- a/advisories/unreviewed/2022/05/GHSA-c3jq-8mx5-pwh7/GHSA-c3jq-8mx5-pwh7.json
+++ b/advisories/unreviewed/2022/05/GHSA-c3jq-8mx5-pwh7/GHSA-c3jq-8mx5-pwh7.json
@@ -7,12 +7,8 @@
"CVE-2007-3590"
],
"details": "Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c499-49rq-mpwf/GHSA-c499-49rq-mpwf.json b/advisories/unreviewed/2022/05/GHSA-c499-49rq-mpwf/GHSA-c499-49rq-mpwf.json
index c9edd749105..d0a0b473b6d 100644
--- a/advisories/unreviewed/2022/05/GHSA-c499-49rq-mpwf/GHSA-c499-49rq-mpwf.json
+++ b/advisories/unreviewed/2022/05/GHSA-c499-49rq-mpwf/GHSA-c499-49rq-mpwf.json
@@ -7,12 +7,8 @@
"CVE-2007-3671"
],
"details": "Unspecified vulnerability in the kernel in Microsoft Windows Vista has unspecified remote attack vectors and impact, as shown in the \"0day IPO\" presentation at SyScan'07.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c4f5-524q-wgpg/GHSA-c4f5-524q-wgpg.json b/advisories/unreviewed/2022/05/GHSA-c4f5-524q-wgpg/GHSA-c4f5-524q-wgpg.json
index 5c532e4e844..8f47eaedaa4 100644
--- a/advisories/unreviewed/2022/05/GHSA-c4f5-524q-wgpg/GHSA-c4f5-524q-wgpg.json
+++ b/advisories/unreviewed/2022/05/GHSA-c4f5-524q-wgpg/GHSA-c4f5-524q-wgpg.json
@@ -7,12 +7,8 @@
"CVE-2007-3744"
],
"details": "Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-c4ww-pxpv-jwhw/GHSA-c4ww-pxpv-jwhw.json b/advisories/unreviewed/2022/05/GHSA-c4ww-pxpv-jwhw/GHSA-c4ww-pxpv-jwhw.json
index 1b8781803f8..4497d5c68e1 100644
--- a/advisories/unreviewed/2022/05/GHSA-c4ww-pxpv-jwhw/GHSA-c4ww-pxpv-jwhw.json
+++ b/advisories/unreviewed/2022/05/GHSA-c4ww-pxpv-jwhw/GHSA-c4ww-pxpv-jwhw.json
@@ -7,12 +7,8 @@
"CVE-2007-3562"
],
"details": "SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c5jq-cv22-5987/GHSA-c5jq-cv22-5987.json b/advisories/unreviewed/2022/05/GHSA-c5jq-cv22-5987/GHSA-c5jq-cv22-5987.json
index 7e407f1e9ba..81cbd594e78 100644
--- a/advisories/unreviewed/2022/05/GHSA-c5jq-cv22-5987/GHSA-c5jq-cv22-5987.json
+++ b/advisories/unreviewed/2022/05/GHSA-c5jq-cv22-5987/GHSA-c5jq-cv22-5987.json
@@ -7,12 +7,8 @@
"CVE-2007-3953"
],
"details": "The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to cause a denial of service via a crafted DOC file that triggers a divide-by-zero error.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c5xf-xf94-3jc3/GHSA-c5xf-xf94-3jc3.json b/advisories/unreviewed/2022/05/GHSA-c5xf-xf94-3jc3/GHSA-c5xf-xf94-3jc3.json
index 0c6dc35f16e..7265ec66b5a 100644
--- a/advisories/unreviewed/2022/05/GHSA-c5xf-xf94-3jc3/GHSA-c5xf-xf94-3jc3.json
+++ b/advisories/unreviewed/2022/05/GHSA-c5xf-xf94-3jc3/GHSA-c5xf-xf94-3jc3.json
@@ -7,12 +7,8 @@
"CVE-2007-3681"
],
"details": "The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -68,9 +64,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c66c-c4c3-hgxf/GHSA-c66c-c4c3-hgxf.json b/advisories/unreviewed/2022/05/GHSA-c66c-c4c3-hgxf/GHSA-c66c-c4c3-hgxf.json
index 4526ca82b96..39571bc91c6 100644
--- a/advisories/unreviewed/2022/05/GHSA-c66c-c4c3-hgxf/GHSA-c66c-c4c3-hgxf.json
+++ b/advisories/unreviewed/2022/05/GHSA-c66c-c4c3-hgxf/GHSA-c66c-c4c3-hgxf.json
@@ -7,12 +7,8 @@
"CVE-2007-3246"
],
"details": "The do_set_password function in modules/chanserv/set.c in IRC Services before 5.0.60 preserves channel founder privileges across a channel password change (ChanServ SET PASSWORD), which allows remote authenticated users to obtain the new password through automated e-mail, or perform privileged actions without knowing the new password.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c7c4-9rr5-ggxw/GHSA-c7c4-9rr5-ggxw.json b/advisories/unreviewed/2022/05/GHSA-c7c4-9rr5-ggxw/GHSA-c7c4-9rr5-ggxw.json
index fd156f2c2b3..5777312413a 100644
--- a/advisories/unreviewed/2022/05/GHSA-c7c4-9rr5-ggxw/GHSA-c7c4-9rr5-ggxw.json
+++ b/advisories/unreviewed/2022/05/GHSA-c7c4-9rr5-ggxw/GHSA-c7c4-9rr5-ggxw.json
@@ -7,12 +7,8 @@
"CVE-2007-3530"
],
"details": "PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c8c6-m3x8-7cq5/GHSA-c8c6-m3x8-7cq5.json b/advisories/unreviewed/2022/05/GHSA-c8c6-m3x8-7cq5/GHSA-c8c6-m3x8-7cq5.json
index cd25c090205..ec8b23142fe 100644
--- a/advisories/unreviewed/2022/05/GHSA-c8c6-m3x8-7cq5/GHSA-c8c6-m3x8-7cq5.json
+++ b/advisories/unreviewed/2022/05/GHSA-c8c6-m3x8-7cq5/GHSA-c8c6-m3x8-7cq5.json
@@ -7,12 +7,8 @@
"CVE-2007-3764"
],
"details": "The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a certain data length value in a crafted packet, which results in an \"overly large memcpy.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-c8cm-fm44-j669/GHSA-c8cm-fm44-j669.json b/advisories/unreviewed/2022/05/GHSA-c8cm-fm44-j669/GHSA-c8cm-fm44-j669.json
index e7d19f1083b..8894de80d6e 100644
--- a/advisories/unreviewed/2022/05/GHSA-c8cm-fm44-j669/GHSA-c8cm-fm44-j669.json
+++ b/advisories/unreviewed/2022/05/GHSA-c8cm-fm44-j669/GHSA-c8cm-fm44-j669.json
@@ -7,12 +7,8 @@
"CVE-2007-3941"
],
"details": "Cross-site scripting (XSS) vulnerability in profile.php in Jasmine CMS 1.0_1 allows remote authenticated users to inject arbitrary web script or HTML via the profile_email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cc3x-9q4q-r2fh/GHSA-cc3x-9q4q-r2fh.json b/advisories/unreviewed/2022/05/GHSA-cc3x-9q4q-r2fh/GHSA-cc3x-9q4q-r2fh.json
index d57a2158fb0..6ea5f469bca 100644
--- a/advisories/unreviewed/2022/05/GHSA-cc3x-9q4q-r2fh/GHSA-cc3x-9q4q-r2fh.json
+++ b/advisories/unreviewed/2022/05/GHSA-cc3x-9q4q-r2fh/GHSA-cc3x-9q4q-r2fh.json
@@ -7,12 +7,8 @@
"CVE-2007-3366"
],
"details": "Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-ccc3-wm6w-jpr7/GHSA-ccc3-wm6w-jpr7.json b/advisories/unreviewed/2022/05/GHSA-ccc3-wm6w-jpr7/GHSA-ccc3-wm6w-jpr7.json
index 9f339294ef1..52951b759c2 100644
--- a/advisories/unreviewed/2022/05/GHSA-ccc3-wm6w-jpr7/GHSA-ccc3-wm6w-jpr7.json
+++ b/advisories/unreviewed/2022/05/GHSA-ccc3-wm6w-jpr7/GHSA-ccc3-wm6w-jpr7.json
@@ -7,12 +7,8 @@
"CVE-2007-3723"
],
"details": "The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and performs scheduling based upon CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cf5w-7gqx-4gh9/GHSA-cf5w-7gqx-4gh9.json b/advisories/unreviewed/2022/05/GHSA-cf5w-7gqx-4gh9/GHSA-cf5w-7gqx-4gh9.json
index c6c9987e095..f1c8e47975e 100644
--- a/advisories/unreviewed/2022/05/GHSA-cf5w-7gqx-4gh9/GHSA-cf5w-7gqx-4gh9.json
+++ b/advisories/unreviewed/2022/05/GHSA-cf5w-7gqx-4gh9/GHSA-cf5w-7gqx-4gh9.json
@@ -7,12 +7,8 @@
"CVE-2007-3919"
],
"details": "(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-cf95-2h9h-gh2x/GHSA-cf95-2h9h-gh2x.json b/advisories/unreviewed/2022/05/GHSA-cf95-2h9h-gh2x/GHSA-cf95-2h9h-gh2x.json
index 29ef6c0bbde..bec2ee644fb 100644
--- a/advisories/unreviewed/2022/05/GHSA-cf95-2h9h-gh2x/GHSA-cf95-2h9h-gh2x.json
+++ b/advisories/unreviewed/2022/05/GHSA-cf95-2h9h-gh2x/GHSA-cf95-2h9h-gh2x.json
@@ -7,12 +7,8 @@
"CVE-2007-3278"
],
"details": "PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -136,9 +132,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cg97-vqm3-w6m4/GHSA-cg97-vqm3-w6m4.json b/advisories/unreviewed/2022/05/GHSA-cg97-vqm3-w6m4/GHSA-cg97-vqm3-w6m4.json
index c11ad7f2efb..9549f7bd7f9 100644
--- a/advisories/unreviewed/2022/05/GHSA-cg97-vqm3-w6m4/GHSA-cg97-vqm3-w6m4.json
+++ b/advisories/unreviewed/2022/05/GHSA-cg97-vqm3-w6m4/GHSA-cg97-vqm3-w6m4.json
@@ -7,12 +7,8 @@
"CVE-2007-3689"
],
"details": "The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cgfv-fhwj-h4gc/GHSA-cgfv-fhwj-h4gc.json b/advisories/unreviewed/2022/05/GHSA-cgfv-fhwj-h4gc/GHSA-cgfv-fhwj-h4gc.json
index 36706369574..83ab768b4b8 100644
--- a/advisories/unreviewed/2022/05/GHSA-cgfv-fhwj-h4gc/GHSA-cgfv-fhwj-h4gc.json
+++ b/advisories/unreviewed/2022/05/GHSA-cgfv-fhwj-h4gc/GHSA-cgfv-fhwj-h4gc.json
@@ -7,12 +7,8 @@
"CVE-2007-3404"
],
"details": "Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cjv3-x5fw-xf73/GHSA-cjv3-x5fw-xf73.json b/advisories/unreviewed/2022/05/GHSA-cjv3-x5fw-xf73/GHSA-cjv3-x5fw-xf73.json
index 12b5af63cfb..85e143503d5 100644
--- a/advisories/unreviewed/2022/05/GHSA-cjv3-x5fw-xf73/GHSA-cjv3-x5fw-xf73.json
+++ b/advisories/unreviewed/2022/05/GHSA-cjv3-x5fw-xf73/GHSA-cjv3-x5fw-xf73.json
@@ -7,12 +7,8 @@
"CVE-2007-3341"
],
"details": "Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to \"see a valid memory address\" via unspecified vectors, a different issue than CVE-2007-0217.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cm9g-pjwp-f2r8/GHSA-cm9g-pjwp-f2r8.json b/advisories/unreviewed/2022/05/GHSA-cm9g-pjwp-f2r8/GHSA-cm9g-pjwp-f2r8.json
index d2d4431a891..67e76176bd7 100644
--- a/advisories/unreviewed/2022/05/GHSA-cm9g-pjwp-f2r8/GHSA-cm9g-pjwp-f2r8.json
+++ b/advisories/unreviewed/2022/05/GHSA-cm9g-pjwp-f2r8/GHSA-cm9g-pjwp-f2r8.json
@@ -7,12 +7,8 @@
"CVE-2007-3965"
],
"details": "Unspecified vulnerability in uFMOD before 1.2.5 has unknown impact and attack vectors, possibly related to malformed files, and possibly an integer signedness error for relative note instruments.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cmvx-834c-h7mg/GHSA-cmvx-834c-h7mg.json b/advisories/unreviewed/2022/05/GHSA-cmvx-834c-h7mg/GHSA-cmvx-834c-h7mg.json
index 8ae6a3f582d..d55a60a9152 100644
--- a/advisories/unreviewed/2022/05/GHSA-cmvx-834c-h7mg/GHSA-cmvx-834c-h7mg.json
+++ b/advisories/unreviewed/2022/05/GHSA-cmvx-834c-h7mg/GHSA-cmvx-834c-h7mg.json
@@ -7,12 +7,8 @@
"CVE-2007-3517"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cpw5-29fw-w53x/GHSA-cpw5-29fw-w53x.json b/advisories/unreviewed/2022/05/GHSA-cpw5-29fw-w53x/GHSA-cpw5-29fw-w53x.json
index fe67e34e164..bc77523e125 100644
--- a/advisories/unreviewed/2022/05/GHSA-cpw5-29fw-w53x/GHSA-cpw5-29fw-w53x.json
+++ b/advisories/unreviewed/2022/05/GHSA-cpw5-29fw-w53x/GHSA-cpw5-29fw-w53x.json
@@ -7,12 +7,8 @@
"CVE-2007-3479"
],
"details": "Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary code via a long string in the \"used DLL\" field in a WDP project file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cv94-h2x3-63c2/GHSA-cv94-h2x3-63c2.json b/advisories/unreviewed/2022/05/GHSA-cv94-h2x3-63c2/GHSA-cv94-h2x3-63c2.json
index f3dfcee97ee..e59c53c02d1 100644
--- a/advisories/unreviewed/2022/05/GHSA-cv94-h2x3-63c2/GHSA-cv94-h2x3-63c2.json
+++ b/advisories/unreviewed/2022/05/GHSA-cv94-h2x3-63c2/GHSA-cv94-h2x3-63c2.json
@@ -7,12 +7,8 @@
"CVE-2007-3814"
],
"details": "Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cw2p-h75f-wq2f/GHSA-cw2p-h75f-wq2f.json b/advisories/unreviewed/2022/05/GHSA-cw2p-h75f-wq2f/GHSA-cw2p-h75f-wq2f.json
index fe2631741b8..13a44486a6d 100644
--- a/advisories/unreviewed/2022/05/GHSA-cw2p-h75f-wq2f/GHSA-cw2p-h75f-wq2f.json
+++ b/advisories/unreviewed/2022/05/GHSA-cw2p-h75f-wq2f/GHSA-cw2p-h75f-wq2f.json
@@ -7,12 +7,8 @@
"CVE-2007-3322"
],
"details": "The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of service (audio quality loss) via a flood of packets to the RTP port.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cwmp-cc64-x5pj/GHSA-cwmp-cc64-x5pj.json b/advisories/unreviewed/2022/05/GHSA-cwmp-cc64-x5pj/GHSA-cwmp-cc64-x5pj.json
index 7fdf7171043..f3150efb423 100644
--- a/advisories/unreviewed/2022/05/GHSA-cwmp-cc64-x5pj/GHSA-cwmp-cc64-x5pj.json
+++ b/advisories/unreviewed/2022/05/GHSA-cwmp-cc64-x5pj/GHSA-cwmp-cc64-x5pj.json
@@ -7,12 +7,8 @@
"CVE-2007-3762"
],
"details": "Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cwv4-w8p5-2mhm/GHSA-cwv4-w8p5-2mhm.json b/advisories/unreviewed/2022/05/GHSA-cwv4-w8p5-2mhm/GHSA-cwv4-w8p5-2mhm.json
index d8417c45926..80748598df0 100644
--- a/advisories/unreviewed/2022/05/GHSA-cwv4-w8p5-2mhm/GHSA-cwv4-w8p5-2mhm.json
+++ b/advisories/unreviewed/2022/05/GHSA-cwv4-w8p5-2mhm/GHSA-cwv4-w8p5-2mhm.json
@@ -7,12 +7,8 @@
"CVE-2007-3583"
],
"details": "SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the idnew parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-cxgf-gp38-x352/GHSA-cxgf-gp38-x352.json b/advisories/unreviewed/2022/05/GHSA-cxgf-gp38-x352/GHSA-cxgf-gp38-x352.json
index 09f238cdf35..3909d8ec873 100644
--- a/advisories/unreviewed/2022/05/GHSA-cxgf-gp38-x352/GHSA-cxgf-gp38-x352.json
+++ b/advisories/unreviewed/2022/05/GHSA-cxgf-gp38-x352/GHSA-cxgf-gp38-x352.json
@@ -7,12 +7,8 @@
"CVE-2007-3678"
],
"details": "Stack-based buffer overflow in the MSWord text-import extension (Word 6-2000 Filter.xnt) in QuarkXPress 7.2 for Windows, when using the Rectangle Text Box tool for importing text, allows user-assisted remote attackers to execute arbitrary code via a long font name.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-f23g-mp7v-582j/GHSA-f23g-mp7v-582j.json b/advisories/unreviewed/2022/05/GHSA-f23g-mp7v-582j/GHSA-f23g-mp7v-582j.json
index 28e481f8945..77bae26b1f8 100644
--- a/advisories/unreviewed/2022/05/GHSA-f23g-mp7v-582j/GHSA-f23g-mp7v-582j.json
+++ b/advisories/unreviewed/2022/05/GHSA-f23g-mp7v-582j/GHSA-f23g-mp7v-582j.json
@@ -7,12 +7,8 @@
"CVE-2007-3514"
],
"details": "Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f2c3-gw2m-p4r2/GHSA-f2c3-gw2m-p4r2.json b/advisories/unreviewed/2022/05/GHSA-f2c3-gw2m-p4r2/GHSA-f2c3-gw2m-p4r2.json
index 58e9b608681..29556a903a4 100644
--- a/advisories/unreviewed/2022/05/GHSA-f2c3-gw2m-p4r2/GHSA-f2c3-gw2m-p4r2.json
+++ b/advisories/unreviewed/2022/05/GHSA-f2c3-gw2m-p4r2/GHSA-f2c3-gw2m-p4r2.json
@@ -7,12 +7,8 @@
"CVE-2007-3457"
],
"details": "Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-f3p9-jv6g-wchp/GHSA-f3p9-jv6g-wchp.json b/advisories/unreviewed/2022/05/GHSA-f3p9-jv6g-wchp/GHSA-f3p9-jv6g-wchp.json
index 2a184376562..e150e665f44 100644
--- a/advisories/unreviewed/2022/05/GHSA-f3p9-jv6g-wchp/GHSA-f3p9-jv6g-wchp.json
+++ b/advisories/unreviewed/2022/05/GHSA-f3p9-jv6g-wchp/GHSA-f3p9-jv6g-wchp.json
@@ -7,12 +7,8 @@
"CVE-2007-3908"
],
"details": "Unspecified vulnerability in HP ServiceGuard for Linux for Red Hat Enterprise Linux (RHEL) 2.1 SG A.11.14.04 through A.11.14.06; RHEL 3.0 SG A.11.16.04 through A.11.16.10; and ServiceGuard Cluster Object Manager B.03.01.02 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2007-0980.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f3vf-85qq-vx9q/GHSA-f3vf-85qq-vx9q.json b/advisories/unreviewed/2022/05/GHSA-f3vf-85qq-vx9q/GHSA-f3vf-85qq-vx9q.json
index 0a476a5de03..25de8afc9ee 100644
--- a/advisories/unreviewed/2022/05/GHSA-f3vf-85qq-vx9q/GHSA-f3vf-85qq-vx9q.json
+++ b/advisories/unreviewed/2022/05/GHSA-f3vf-85qq-vx9q/GHSA-f3vf-85qq-vx9q.json
@@ -7,12 +7,8 @@
"CVE-2007-3639"
],
"details": "WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f48p-73hx-764h/GHSA-f48p-73hx-764h.json b/advisories/unreviewed/2022/05/GHSA-f48p-73hx-764h/GHSA-f48p-73hx-764h.json
index 5278c982ccf..aa7e11152ca 100644
--- a/advisories/unreviewed/2022/05/GHSA-f48p-73hx-764h/GHSA-f48p-73hx-764h.json
+++ b/advisories/unreviewed/2022/05/GHSA-f48p-73hx-764h/GHSA-f48p-73hx-764h.json
@@ -7,12 +7,8 @@
"CVE-2007-3380"
],
"details": "The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the service.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f4vh-cc5j-94gx/GHSA-f4vh-cc5j-94gx.json b/advisories/unreviewed/2022/05/GHSA-f4vh-cc5j-94gx/GHSA-f4vh-cc5j-94gx.json
index 341d7288aec..f14dae2f940 100644
--- a/advisories/unreviewed/2022/05/GHSA-f4vh-cc5j-94gx/GHSA-f4vh-cc5j-94gx.json
+++ b/advisories/unreviewed/2022/05/GHSA-f4vh-cc5j-94gx/GHSA-f4vh-cc5j-94gx.json
@@ -7,12 +7,8 @@
"CVE-2007-3593"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c) netflow/jspui/index.jsp, and the (4) rtype parameter in (d) netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp. NOTE: it was later reported that vector 3 also affects 7.5 build 7500.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-f574-9vfr-vwxg/GHSA-f574-9vfr-vwxg.json b/advisories/unreviewed/2022/05/GHSA-f574-9vfr-vwxg/GHSA-f574-9vfr-vwxg.json
index b83fc4293ee..59961c7bff5 100644
--- a/advisories/unreviewed/2022/05/GHSA-f574-9vfr-vwxg/GHSA-f574-9vfr-vwxg.json
+++ b/advisories/unreviewed/2022/05/GHSA-f574-9vfr-vwxg/GHSA-f574-9vfr-vwxg.json
@@ -7,12 +7,8 @@
"CVE-2007-3407"
],
"details": "Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f7gx-3pf8-q7f6/GHSA-f7gx-3pf8-q7f6.json b/advisories/unreviewed/2022/05/GHSA-f7gx-3pf8-q7f6/GHSA-f7gx-3pf8-q7f6.json
index d3cd4e58858..8d417a85f76 100644
--- a/advisories/unreviewed/2022/05/GHSA-f7gx-3pf8-q7f6/GHSA-f7gx-3pf8-q7f6.json
+++ b/advisories/unreviewed/2022/05/GHSA-f7gx-3pf8-q7f6/GHSA-f7gx-3pf8-q7f6.json
@@ -7,12 +7,8 @@
"CVE-2007-3478"
],
"details": "Race condition in gdImageStringFTEx (gdft_draw_bitmap) in gdft.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving truetype font (TTF) support.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-f844-8gxq-37w7/GHSA-f844-8gxq-37w7.json b/advisories/unreviewed/2022/05/GHSA-f844-8gxq-37w7/GHSA-f844-8gxq-37w7.json
index cb1b20348f7..e351d40f175 100644
--- a/advisories/unreviewed/2022/05/GHSA-f844-8gxq-37w7/GHSA-f844-8gxq-37w7.json
+++ b/advisories/unreviewed/2022/05/GHSA-f844-8gxq-37w7/GHSA-f844-8gxq-37w7.json
@@ -7,12 +7,8 @@
"CVE-2007-3771"
],
"details": "Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. NOTE: the original vendor advisory referenced CVE-2006-3456, but this was an error.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f8q5-9g23-3hwp/GHSA-f8q5-9g23-3hwp.json b/advisories/unreviewed/2022/05/GHSA-f8q5-9g23-3hwp/GHSA-f8q5-9g23-3hwp.json
index 3a7fbfd8001..b84f158ca05 100644
--- a/advisories/unreviewed/2022/05/GHSA-f8q5-9g23-3hwp/GHSA-f8q5-9g23-3hwp.json
+++ b/advisories/unreviewed/2022/05/GHSA-f8q5-9g23-3hwp/GHSA-f8q5-9g23-3hwp.json
@@ -7,12 +7,8 @@
"CVE-2007-3355"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in NetClassifieds Premium Edition allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f8v6-4mr6-mw8q/GHSA-f8v6-4mr6-mw8q.json b/advisories/unreviewed/2022/05/GHSA-f8v6-4mr6-mw8q/GHSA-f8v6-4mr6-mw8q.json
index 887bac75082..a6f3d1ff867 100644
--- a/advisories/unreviewed/2022/05/GHSA-f8v6-4mr6-mw8q/GHSA-f8v6-4mr6-mw8q.json
+++ b/advisories/unreviewed/2022/05/GHSA-f8v6-4mr6-mw8q/GHSA-f8v6-4mr6-mw8q.json
@@ -7,12 +7,8 @@
"CVE-2007-3666"
],
"details": "Buffer overflow in RemoteCommand.DLL in Symantec Norton Ghost 12.0 allows remote attackers to execute arbitrary code via the Connect function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-f9w4-q8jc-qc4v/GHSA-f9w4-q8jc-qc4v.json b/advisories/unreviewed/2022/05/GHSA-f9w4-q8jc-qc4v/GHSA-f9w4-q8jc-qc4v.json
index 4e855737154..656f6676f85 100644
--- a/advisories/unreviewed/2022/05/GHSA-f9w4-q8jc-qc4v/GHSA-f9w4-q8jc-qc4v.json
+++ b/advisories/unreviewed/2022/05/GHSA-f9w4-q8jc-qc4v/GHSA-f9w4-q8jc-qc4v.json
@@ -7,12 +7,8 @@
"CVE-2007-3765"
],
"details": "The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fc24-87cc-589r/GHSA-fc24-87cc-589r.json b/advisories/unreviewed/2022/05/GHSA-fc24-87cc-589r/GHSA-fc24-87cc-589r.json
index e837954d109..1323705bd2b 100644
--- a/advisories/unreviewed/2022/05/GHSA-fc24-87cc-589r/GHSA-fc24-87cc-589r.json
+++ b/advisories/unreviewed/2022/05/GHSA-fc24-87cc-589r/GHSA-fc24-87cc-589r.json
@@ -7,12 +7,8 @@
"CVE-2007-3961"
],
"details": "Off-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before 0.9 allows remote attackers to cause a denial of service via a directory entry whose length is exactly MAXNAMELEN, which prevents a terminating null byte from being added.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fcg2-3xr7-ff6g/GHSA-fcg2-3xr7-ff6g.json b/advisories/unreviewed/2022/05/GHSA-fcg2-3xr7-ff6g/GHSA-fcg2-3xr7-ff6g.json
index bb3c2531bef..f741418a7a6 100644
--- a/advisories/unreviewed/2022/05/GHSA-fcg2-3xr7-ff6g/GHSA-fcg2-3xr7-ff6g.json
+++ b/advisories/unreviewed/2022/05/GHSA-fcg2-3xr7-ff6g/GHSA-fcg2-3xr7-ff6g.json
@@ -7,12 +7,8 @@
"CVE-2007-3324"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different vectors than CVE-2004-0681.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fcmw-q542-jmpj/GHSA-fcmw-q542-jmpj.json b/advisories/unreviewed/2022/05/GHSA-fcmw-q542-jmpj/GHSA-fcmw-q542-jmpj.json
index 30c4c2ff324..a384c098e59 100644
--- a/advisories/unreviewed/2022/05/GHSA-fcmw-q542-jmpj/GHSA-fcmw-q542-jmpj.json
+++ b/advisories/unreviewed/2022/05/GHSA-fcmw-q542-jmpj/GHSA-fcmw-q542-jmpj.json
@@ -7,12 +7,8 @@
"CVE-2007-3824"
],
"details": "SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands via the katID parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-ffw7-89pg-vjx2/GHSA-ffw7-89pg-vjx2.json b/advisories/unreviewed/2022/05/GHSA-ffw7-89pg-vjx2/GHSA-ffw7-89pg-vjx2.json
index 2f6751915de..bfd2e22d046 100644
--- a/advisories/unreviewed/2022/05/GHSA-ffw7-89pg-vjx2/GHSA-ffw7-89pg-vjx2.json
+++ b/advisories/unreviewed/2022/05/GHSA-ffw7-89pg-vjx2/GHSA-ffw7-89pg-vjx2.json
@@ -7,12 +7,8 @@
"CVE-2007-3675"
],
"details": "Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in \"various string formatting functions,\" which trigger heap-based buffer overflows.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-fgg3-cq2r-mqwx/GHSA-fgg3-cq2r-mqwx.json b/advisories/unreviewed/2022/05/GHSA-fgg3-cq2r-mqwx/GHSA-fgg3-cq2r-mqwx.json
index ed8b2ecd65f..511a3373c25 100644
--- a/advisories/unreviewed/2022/05/GHSA-fgg3-cq2r-mqwx/GHSA-fgg3-cq2r-mqwx.json
+++ b/advisories/unreviewed/2022/05/GHSA-fgg3-cq2r-mqwx/GHSA-fgg3-cq2r-mqwx.json
@@ -7,12 +7,8 @@
"CVE-2007-3548"
],
"details": "Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fh3c-6974-c7cg/GHSA-fh3c-6974-c7cg.json b/advisories/unreviewed/2022/05/GHSA-fh3c-6974-c7cg/GHSA-fh3c-6974-c7cg.json
index 87d8eccbe5a..0a3a76e9ed8 100644
--- a/advisories/unreviewed/2022/05/GHSA-fh3c-6974-c7cg/GHSA-fh3c-6974-c7cg.json
+++ b/advisories/unreviewed/2022/05/GHSA-fh3c-6974-c7cg/GHSA-fh3c-6974-c7cg.json
@@ -7,12 +7,8 @@
"CVE-2007-3773"
],
"details": "Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-fm38-9r6v-gv9m/GHSA-fm38-9r6v-gv9m.json b/advisories/unreviewed/2022/05/GHSA-fm38-9r6v-gv9m/GHSA-fm38-9r6v-gv9m.json
index 5b2973aaa3c..31d93a1b73f 100644
--- a/advisories/unreviewed/2022/05/GHSA-fm38-9r6v-gv9m/GHSA-fm38-9r6v-gv9m.json
+++ b/advisories/unreviewed/2022/05/GHSA-fm38-9r6v-gv9m/GHSA-fm38-9r6v-gv9m.json
@@ -7,12 +7,8 @@
"CVE-2007-3600"
],
"details": "WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fmgx-grvc-558f/GHSA-fmgx-grvc-558f.json b/advisories/unreviewed/2022/05/GHSA-fmgx-grvc-558f/GHSA-fmgx-grvc-558f.json
index e8802548dd7..f5469294a45 100644
--- a/advisories/unreviewed/2022/05/GHSA-fmgx-grvc-558f/GHSA-fmgx-grvc-558f.json
+++ b/advisories/unreviewed/2022/05/GHSA-fmgx-grvc-558f/GHSA-fmgx-grvc-558f.json
@@ -7,12 +7,8 @@
"CVE-2007-3389"
],
"details": "Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-fp2f-qgf9-93cx/GHSA-fp2f-qgf9-93cx.json b/advisories/unreviewed/2022/05/GHSA-fp2f-qgf9-93cx/GHSA-fp2f-qgf9-93cx.json
index 580cc205085..0efbc16a1fd 100644
--- a/advisories/unreviewed/2022/05/GHSA-fp2f-qgf9-93cx/GHSA-fp2f-qgf9-93cx.json
+++ b/advisories/unreviewed/2022/05/GHSA-fp2f-qgf9-93cx/GHSA-fp2f-qgf9-93cx.json
@@ -7,12 +7,8 @@
"CVE-2007-3647"
],
"details": "The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the username cookie to \"traffic.\" NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fpm8-7326-6p2g/GHSA-fpm8-7326-6p2g.json b/advisories/unreviewed/2022/05/GHSA-fpm8-7326-6p2g/GHSA-fpm8-7326-6p2g.json
index ce30be9534c..d8394a2e84e 100644
--- a/advisories/unreviewed/2022/05/GHSA-fpm8-7326-6p2g/GHSA-fpm8-7326-6p2g.json
+++ b/advisories/unreviewed/2022/05/GHSA-fpm8-7326-6p2g/GHSA-fpm8-7326-6p2g.json
@@ -7,12 +7,8 @@
"CVE-2007-3331"
],
"details": "Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that is posted automatically by JavaScript or (2) a news post.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fqqp-86gc-c7qf/GHSA-fqqp-86gc-c7qf.json b/advisories/unreviewed/2022/05/GHSA-fqqp-86gc-c7qf/GHSA-fqqp-86gc-c7qf.json
index 2cdce0b4399..90929f65dff 100644
--- a/advisories/unreviewed/2022/05/GHSA-fqqp-86gc-c7qf/GHSA-fqqp-86gc-c7qf.json
+++ b/advisories/unreviewed/2022/05/GHSA-fqqp-86gc-c7qf/GHSA-fqqp-86gc-c7qf.json
@@ -7,12 +7,8 @@
"CVE-2007-3660"
],
"details": "The Nonnoi ASP/Barcode ActiveX control (nonnoi_ASPBarcode.dll) allows remote attackers to overwrite arbitrary files via an argument to the SaveBarcode function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-frm9-8j39-j893/GHSA-frm9-8j39-j893.json b/advisories/unreviewed/2022/05/GHSA-frm9-8j39-j893/GHSA-frm9-8j39-j893.json
index 3ffccdb56a4..f8483fb30a7 100644
--- a/advisories/unreviewed/2022/05/GHSA-frm9-8j39-j893/GHSA-frm9-8j39-j893.json
+++ b/advisories/unreviewed/2022/05/GHSA-frm9-8j39-j893/GHSA-frm9-8j39-j893.json
@@ -7,12 +7,8 @@
"CVE-2007-3321"
],
"details": "The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) via a flood of packets to the BOOTP port (68/udp).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fv75-9f4p-j7c2/GHSA-fv75-9f4p-j7c2.json b/advisories/unreviewed/2022/05/GHSA-fv75-9f4p-j7c2/GHSA-fv75-9f4p-j7c2.json
index 59a9c0434ae..30815c65881 100644
--- a/advisories/unreviewed/2022/05/GHSA-fv75-9f4p-j7c2/GHSA-fv75-9f4p-j7c2.json
+++ b/advisories/unreviewed/2022/05/GHSA-fv75-9f4p-j7c2/GHSA-fv75-9f4p-j7c2.json
@@ -7,12 +7,8 @@
"CVE-2007-3923"
],
"details": "The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-fw5v-h2w7-75mc/GHSA-fw5v-h2w7-75mc.json b/advisories/unreviewed/2022/05/GHSA-fw5v-h2w7-75mc/GHSA-fw5v-h2w7-75mc.json
index 4d8bcb68991..6a2c1daed63 100644
--- a/advisories/unreviewed/2022/05/GHSA-fw5v-h2w7-75mc/GHSA-fw5v-h2w7-75mc.json
+++ b/advisories/unreviewed/2022/05/GHSA-fw5v-h2w7-75mc/GHSA-fw5v-h2w7-75mc.json
@@ -7,12 +7,8 @@
"CVE-2007-3528"
],
"details": "The blowfish mode in DAR before 2.3.4 uses weak Blowfish-CBC cryptography by (1) discarding random bits by the blowfish::make_ivec function in libdar/crypto.cpp that results in predictable and repeating IV values, and (2) direct use of a password for keying, which makes it easier for context-dependent attackers to decrypt files.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g4wr-mw5v-6wqw/GHSA-g4wr-mw5v-6wqw.json b/advisories/unreviewed/2022/05/GHSA-g4wr-mw5v-6wqw/GHSA-g4wr-mw5v-6wqw.json
index 6e65a78a46f..445a60e6f92 100644
--- a/advisories/unreviewed/2022/05/GHSA-g4wr-mw5v-6wqw/GHSA-g4wr-mw5v-6wqw.json
+++ b/advisories/unreviewed/2022/05/GHSA-g4wr-mw5v-6wqw/GHSA-g4wr-mw5v-6wqw.json
@@ -7,12 +7,8 @@
"CVE-2007-3613"
],
"details": "Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g6xg-m395-v4m6/GHSA-g6xg-m395-v4m6.json b/advisories/unreviewed/2022/05/GHSA-g6xg-m395-v4m6/GHSA-g6xg-m395-v4m6.json
index 5c6573e25b1..a24165619e8 100644
--- a/advisories/unreviewed/2022/05/GHSA-g6xg-m395-v4m6/GHSA-g6xg-m395-v4m6.json
+++ b/advisories/unreviewed/2022/05/GHSA-g6xg-m395-v4m6/GHSA-g6xg-m395-v4m6.json
@@ -7,12 +7,8 @@
"CVE-2007-3315"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter to bodyTemplate.php in (1) templates/Classic/, (2) templates/Classic Guestbook/, (3) templates/DarkNights/, and (4) templates/Simplistic/, different vectors than CVE-2007-3271. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g74r-9q47-hwcj/GHSA-g74r-9q47-hwcj.json b/advisories/unreviewed/2022/05/GHSA-g74r-9q47-hwcj/GHSA-g74r-9q47-hwcj.json
index 5993d168275..e92b4d0d9b3 100644
--- a/advisories/unreviewed/2022/05/GHSA-g74r-9q47-hwcj/GHSA-g74r-9q47-hwcj.json
+++ b/advisories/unreviewed/2022/05/GHSA-g74r-9q47-hwcj/GHSA-g74r-9q47-hwcj.json
@@ -7,12 +7,8 @@
"CVE-2007-3453"
],
"details": "SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid parameter to certain components.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g79c-8pc3-xg93/GHSA-g79c-8pc3-xg93.json b/advisories/unreviewed/2022/05/GHSA-g79c-8pc3-xg93/GHSA-g79c-8pc3-xg93.json
index 317ee0047e6..2d83b7a3b97 100644
--- a/advisories/unreviewed/2022/05/GHSA-g79c-8pc3-xg93/GHSA-g79c-8pc3-xg93.json
+++ b/advisories/unreviewed/2022/05/GHSA-g79c-8pc3-xg93/GHSA-g79c-8pc3-xg93.json
@@ -7,12 +7,8 @@
"CVE-2007-3454"
],
"details": "Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-g79q-phhr-2g7p/GHSA-g79q-phhr-2g7p.json b/advisories/unreviewed/2022/05/GHSA-g79q-phhr-2g7p/GHSA-g79q-phhr-2g7p.json
index db882aae3fe..6693fce3905 100644
--- a/advisories/unreviewed/2022/05/GHSA-g79q-phhr-2g7p/GHSA-g79q-phhr-2g7p.json
+++ b/advisories/unreviewed/2022/05/GHSA-g79q-phhr-2g7p/GHSA-g79q-phhr-2g7p.json
@@ -7,12 +7,8 @@
"CVE-2007-3627"
],
"details": "Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g7f2-6mph-mrj7/GHSA-g7f2-6mph-mrj7.json b/advisories/unreviewed/2022/05/GHSA-g7f2-6mph-mrj7/GHSA-g7f2-6mph-mrj7.json
index 9f943135a75..e36b72b2315 100644
--- a/advisories/unreviewed/2022/05/GHSA-g7f2-6mph-mrj7/GHSA-g7f2-6mph-mrj7.json
+++ b/advisories/unreviewed/2022/05/GHSA-g7f2-6mph-mrj7/GHSA-g7f2-6mph-mrj7.json
@@ -7,12 +7,8 @@
"CVE-2007-3770"
],
"details": "The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the \"Open Link\" functionality.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g7j5-7cg8-g6q6/GHSA-g7j5-7cg8-g6q6.json b/advisories/unreviewed/2022/05/GHSA-g7j5-7cg8-g6q6/GHSA-g7j5-7cg8-g6q6.json
index 6dd5011bda3..87d67f3744c 100644
--- a/advisories/unreviewed/2022/05/GHSA-g7j5-7cg8-g6q6/GHSA-g7j5-7cg8-g6q6.json
+++ b/advisories/unreviewed/2022/05/GHSA-g7j5-7cg8-g6q6/GHSA-g7j5-7cg8-g6q6.json
@@ -7,12 +7,8 @@
"CVE-2007-3480"
],
"details": "PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to cause a denial of service (infinite loop and resource consumption) via a malformed WDP project file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g86j-3x5c-hv2j/GHSA-g86j-3x5c-hv2j.json b/advisories/unreviewed/2022/05/GHSA-g86j-3x5c-hv2j/GHSA-g86j-3x5c-hv2j.json
index 9a2752a8861..fc2a07c6a0f 100644
--- a/advisories/unreviewed/2022/05/GHSA-g86j-3x5c-hv2j/GHSA-g86j-3x5c-hv2j.json
+++ b/advisories/unreviewed/2022/05/GHSA-g86j-3x5c-hv2j/GHSA-g86j-3x5c-hv2j.json
@@ -7,12 +7,8 @@
"CVE-2007-3440"
],
"details": "The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to place calls to arbitrary phone numbers via certain requests to the web server on port 1800.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g8m8-5prf-39x3/GHSA-g8m8-5prf-39x3.json b/advisories/unreviewed/2022/05/GHSA-g8m8-5prf-39x3/GHSA-g8m8-5prf-39x3.json
index d38cde5d70f..de0439c54f7 100644
--- a/advisories/unreviewed/2022/05/GHSA-g8m8-5prf-39x3/GHSA-g8m8-5prf-39x3.json
+++ b/advisories/unreviewed/2022/05/GHSA-g8m8-5prf-39x3/GHSA-g8m8-5prf-39x3.json
@@ -7,12 +7,8 @@
"CVE-2007-3817"
],
"details": "Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a \"Log out\" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the username by removing certain characters, so this might not be a vulnerability on default installations.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g93v-phhv-j82g/GHSA-g93v-phhv-j82g.json b/advisories/unreviewed/2022/05/GHSA-g93v-phhv-j82g/GHSA-g93v-phhv-j82g.json
index 00e674acdfc..733721585fa 100644
--- a/advisories/unreviewed/2022/05/GHSA-g93v-phhv-j82g/GHSA-g93v-phhv-j82g.json
+++ b/advisories/unreviewed/2022/05/GHSA-g93v-phhv-j82g/GHSA-g93v-phhv-j82g.json
@@ -7,12 +7,8 @@
"CVE-2007-3426"
],
"details": "Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g962-r766-7j3p/GHSA-g962-r766-7j3p.json b/advisories/unreviewed/2022/05/GHSA-g962-r766-7j3p/GHSA-g962-r766-7j3p.json
index 9b6eb9af8d2..4ecb93192d8 100644
--- a/advisories/unreviewed/2022/05/GHSA-g962-r766-7j3p/GHSA-g962-r766-7j3p.json
+++ b/advisories/unreviewed/2022/05/GHSA-g962-r766-7j3p/GHSA-g962-r766-7j3p.json
@@ -7,12 +7,8 @@
"CVE-2007-3931"
],
"details": "The wrap_setuid_third_party_application function in the installation script for the Samsung SCX-4200 Driver 2.00.95 adds setuid permissions to third party applications such as xsane and xscanimage, which allows local users to gain privileges.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-g9r8-mr7q-g5r2/GHSA-g9r8-mr7q-g5r2.json b/advisories/unreviewed/2022/05/GHSA-g9r8-mr7q-g5r2/GHSA-g9r8-mr7q-g5r2.json
index 1a5af3cad32..4c0d043593d 100644
--- a/advisories/unreviewed/2022/05/GHSA-g9r8-mr7q-g5r2/GHSA-g9r8-mr7q-g5r2.json
+++ b/advisories/unreviewed/2022/05/GHSA-g9r8-mr7q-g5r2/GHSA-g9r8-mr7q-g5r2.json
@@ -7,12 +7,8 @@
"CVE-2007-3739"
],
"details": "mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserved kernel page memory, which allows local users to cause a denial of service (OOPS) via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-gfgf-h5fj-26vx/GHSA-gfgf-h5fj-26vx.json b/advisories/unreviewed/2022/05/GHSA-gfgf-h5fj-26vx/GHSA-gfgf-h5fj-26vx.json
index c24ce40079f..ce2c1ca11ae 100644
--- a/advisories/unreviewed/2022/05/GHSA-gfgf-h5fj-26vx/GHSA-gfgf-h5fj-26vx.json
+++ b/advisories/unreviewed/2022/05/GHSA-gfgf-h5fj-26vx/GHSA-gfgf-h5fj-26vx.json
@@ -7,12 +7,8 @@
"CVE-2007-3381"
],
"details": "The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-gfqp-jcmw-676w/GHSA-gfqp-jcmw-676w.json b/advisories/unreviewed/2022/05/GHSA-gfqp-jcmw-676w/GHSA-gfqp-jcmw-676w.json
index 829fd95596d..e159ea02f58 100644
--- a/advisories/unreviewed/2022/05/GHSA-gfqp-jcmw-676w/GHSA-gfqp-jcmw-676w.json
+++ b/advisories/unreviewed/2022/05/GHSA-gfqp-jcmw-676w/GHSA-gfqp-jcmw-676w.json
@@ -7,12 +7,8 @@
"CVE-2007-3435"
],
"details": "Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-ggmq-gfc4-hg63/GHSA-ggmq-gfc4-hg63.json b/advisories/unreviewed/2022/05/GHSA-ggmq-gfc4-hg63/GHSA-ggmq-gfc4-hg63.json
index 4db55247fd1..22bcee3a558 100644
--- a/advisories/unreviewed/2022/05/GHSA-ggmq-gfc4-hg63/GHSA-ggmq-gfc4-hg63.json
+++ b/advisories/unreviewed/2022/05/GHSA-ggmq-gfc4-hg63/GHSA-ggmq-gfc4-hg63.json
@@ -7,12 +7,8 @@
"CVE-2007-3707"
],
"details": "Directory traversal vulnerability in index.php in CodeIgniter 1.5.3 before 20070628, when enable_query_strings is true, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gh9m-q2pq-4h89/GHSA-gh9m-q2pq-4h89.json b/advisories/unreviewed/2022/05/GHSA-gh9m-q2pq-4h89/GHSA-gh9m-q2pq-4h89.json
index b64eca5d00a..288d9a178be 100644
--- a/advisories/unreviewed/2022/05/GHSA-gh9m-q2pq-4h89/GHSA-gh9m-q2pq-4h89.json
+++ b/advisories/unreviewed/2022/05/GHSA-gh9m-q2pq-4h89/GHSA-gh9m-q2pq-4h89.json
@@ -7,12 +7,8 @@
"CVE-2007-3299"
],
"details": "Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gj87-6rqc-vpmp/GHSA-gj87-6rqc-vpmp.json b/advisories/unreviewed/2022/05/GHSA-gj87-6rqc-vpmp/GHSA-gj87-6rqc-vpmp.json
index 4a0a00afd01..9ae36140fc8 100644
--- a/advisories/unreviewed/2022/05/GHSA-gj87-6rqc-vpmp/GHSA-gj87-6rqc-vpmp.json
+++ b/advisories/unreviewed/2022/05/GHSA-gj87-6rqc-vpmp/GHSA-gj87-6rqc-vpmp.json
@@ -7,12 +7,8 @@
"CVE-2007-3433"
],
"details": "SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gj88-x3rv-r4r4/GHSA-gj88-x3rv-r4r4.json b/advisories/unreviewed/2022/05/GHSA-gj88-x3rv-r4r4/GHSA-gj88-x3rv-r4r4.json
index ef4bfaa6e47..fb11693cca7 100644
--- a/advisories/unreviewed/2022/05/GHSA-gj88-x3rv-r4r4/GHSA-gj88-x3rv-r4r4.json
+++ b/advisories/unreviewed/2022/05/GHSA-gj88-x3rv-r4r4/GHSA-gj88-x3rv-r4r4.json
@@ -7,12 +7,8 @@
"CVE-2007-3683"
],
"details": "SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary SQL commands via the topic_id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gjxf-qqj7-vg8x/GHSA-gjxf-qqj7-vg8x.json b/advisories/unreviewed/2022/05/GHSA-gjxf-qqj7-vg8x/GHSA-gjxf-qqj7-vg8x.json
index 295967750a0..b073bf22d5d 100644
--- a/advisories/unreviewed/2022/05/GHSA-gjxf-qqj7-vg8x/GHSA-gjxf-qqj7-vg8x.json
+++ b/advisories/unreviewed/2022/05/GHSA-gjxf-qqj7-vg8x/GHSA-gjxf-qqj7-vg8x.json
@@ -7,12 +7,8 @@
"CVE-2007-3370"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gpmm-pwfh-wr28/GHSA-gpmm-pwfh-wr28.json b/advisories/unreviewed/2022/05/GHSA-gpmm-pwfh-wr28/GHSA-gpmm-pwfh-wr28.json
index 6997fa2660b..5d5b7f199ad 100644
--- a/advisories/unreviewed/2022/05/GHSA-gpmm-pwfh-wr28/GHSA-gpmm-pwfh-wr28.json
+++ b/advisories/unreviewed/2022/05/GHSA-gpmm-pwfh-wr28/GHSA-gpmm-pwfh-wr28.json
@@ -7,12 +7,8 @@
"CVE-2007-3471"
],
"details": "Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gpqw-m5q2-44j5/GHSA-gpqw-m5q2-44j5.json b/advisories/unreviewed/2022/05/GHSA-gpqw-m5q2-44j5/GHSA-gpqw-m5q2-44j5.json
index 51689ebbb92..1eb5ed2a029 100644
--- a/advisories/unreviewed/2022/05/GHSA-gpqw-m5q2-44j5/GHSA-gpqw-m5q2-44j5.json
+++ b/advisories/unreviewed/2022/05/GHSA-gpqw-m5q2-44j5/GHSA-gpqw-m5q2-44j5.json
@@ -7,12 +7,8 @@
"CVE-2007-3460"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gpvh-w327-7rr5/GHSA-gpvh-w327-7rr5.json b/advisories/unreviewed/2022/05/GHSA-gpvh-w327-7rr5/GHSA-gpvh-w327-7rr5.json
index aa0546b5b7e..f9a99481183 100644
--- a/advisories/unreviewed/2022/05/GHSA-gpvh-w327-7rr5/GHSA-gpvh-w327-7rr5.json
+++ b/advisories/unreviewed/2022/05/GHSA-gpvh-w327-7rr5/GHSA-gpvh-w327-7rr5.json
@@ -7,12 +7,8 @@
"CVE-2007-3585"
],
"details": "PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gqcr-mpmp-f8m6/GHSA-gqcr-mpmp-f8m6.json b/advisories/unreviewed/2022/05/GHSA-gqcr-mpmp-f8m6/GHSA-gqcr-mpmp-f8m6.json
index baa98c71ea4..be7814ec264 100644
--- a/advisories/unreviewed/2022/05/GHSA-gqcr-mpmp-f8m6/GHSA-gqcr-mpmp-f8m6.json
+++ b/advisories/unreviewed/2022/05/GHSA-gqcr-mpmp-f8m6/GHSA-gqcr-mpmp-f8m6.json
@@ -7,12 +7,8 @@
"CVE-2007-3535"
],
"details": "Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gr33-v93c-5c2q/GHSA-gr33-v93c-5c2q.json b/advisories/unreviewed/2022/05/GHSA-gr33-v93c-5c2q/GHSA-gr33-v93c-5c2q.json
index 6ec0d456d18..bcbbe029e10 100644
--- a/advisories/unreviewed/2022/05/GHSA-gr33-v93c-5c2q/GHSA-gr33-v93c-5c2q.json
+++ b/advisories/unreviewed/2022/05/GHSA-gr33-v93c-5c2q/GHSA-gr33-v93c-5c2q.json
@@ -7,12 +7,8 @@
"CVE-2007-3294"
],
"details": "Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an unspecified vector to the tidy_repair_string function. NOTE: this might only be an issue in environments where vsnprintf is implemented as a wrapper for vsprintf.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-gr88-hv4f-43wj/GHSA-gr88-hv4f-43wj.json b/advisories/unreviewed/2022/05/GHSA-gr88-hv4f-43wj/GHSA-gr88-hv4f-43wj.json
index 6258da7c2a5..1b9e4ee6f16 100644
--- a/advisories/unreviewed/2022/05/GHSA-gr88-hv4f-43wj/GHSA-gr88-hv4f-43wj.json
+++ b/advisories/unreviewed/2022/05/GHSA-gr88-hv4f-43wj/GHSA-gr88-hv4f-43wj.json
@@ -7,12 +7,8 @@
"CVE-2007-3911"
],
"details": "Multiple heap-based buffer overflows in (1) clsscheduler.exe (aka scheduler client) and (2) srvscheduler.exe (aka scheduler server) in BakBone NetVault Reporter 3.5 before Update4 allow remote attackers to execute arbitrary code via long filename arguments in HTTP requests.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-gv62-262h-h9q4/GHSA-gv62-262h-h9q4.json b/advisories/unreviewed/2022/05/GHSA-gv62-262h-h9q4/GHSA-gv62-262h-h9q4.json
index 258553085bb..357c7289893 100644
--- a/advisories/unreviewed/2022/05/GHSA-gv62-262h-h9q4/GHSA-gv62-262h-h9q4.json
+++ b/advisories/unreviewed/2022/05/GHSA-gv62-262h-h9q4/GHSA-gv62-262h-h9q4.json
@@ -7,12 +7,8 @@
"CVE-2007-3262"
],
"details": "Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a \"TCP issue,\" or to MPAlarmThread and a resultant memory leak.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gv8q-4r76-rh77/GHSA-gv8q-4r76-rh77.json b/advisories/unreviewed/2022/05/GHSA-gv8q-4r76-rh77/GHSA-gv8q-4r76-rh77.json
index 4c2078e82fe..72859503c6c 100644
--- a/advisories/unreviewed/2022/05/GHSA-gv8q-4r76-rh77/GHSA-gv8q-4r76-rh77.json
+++ b/advisories/unreviewed/2022/05/GHSA-gv8q-4r76-rh77/GHSA-gv8q-4r76-rh77.json
@@ -7,12 +7,8 @@
"CVE-2007-3490"
],
"details": "Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gvjx-cgxf-v27v/GHSA-gvjx-cgxf-v27v.json b/advisories/unreviewed/2022/05/GHSA-gvjx-cgxf-v27v/GHSA-gvjx-cgxf-v27v.json
index ce505096faa..407d2d54bb1 100644
--- a/advisories/unreviewed/2022/05/GHSA-gvjx-cgxf-v27v/GHSA-gvjx-cgxf-v27v.json
+++ b/advisories/unreviewed/2022/05/GHSA-gvjx-cgxf-v27v/GHSA-gvjx-cgxf-v27v.json
@@ -7,12 +7,8 @@
"CVE-2019-11658"
],
"details": "Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-gw23-fpc3-c9mr/GHSA-gw23-fpc3-c9mr.json b/advisories/unreviewed/2022/05/GHSA-gw23-fpc3-c9mr/GHSA-gw23-fpc3-c9mr.json
index ba892865a7c..865c47cbc17 100644
--- a/advisories/unreviewed/2022/05/GHSA-gw23-fpc3-c9mr/GHSA-gw23-fpc3-c9mr.json
+++ b/advisories/unreviewed/2022/05/GHSA-gw23-fpc3-c9mr/GHSA-gw23-fpc3-c9mr.json
@@ -7,12 +7,8 @@
"CVE-2007-3264"
],
"details": "Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h246-qhjp-2w7j/GHSA-h246-qhjp-2w7j.json b/advisories/unreviewed/2022/05/GHSA-h246-qhjp-2w7j/GHSA-h246-qhjp-2w7j.json
index 53c3aa4afb5..394bdf06990 100644
--- a/advisories/unreviewed/2022/05/GHSA-h246-qhjp-2w7j/GHSA-h246-qhjp-2w7j.json
+++ b/advisories/unreviewed/2022/05/GHSA-h246-qhjp-2w7j/GHSA-h246-qhjp-2w7j.json
@@ -7,12 +7,8 @@
"CVE-2007-3313"
],
"details": "Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h37p-grfj-94pv/GHSA-h37p-grfj-94pv.json b/advisories/unreviewed/2022/05/GHSA-h37p-grfj-94pv/GHSA-h37p-grfj-94pv.json
index c9dfea28371..0de355a1106 100644
--- a/advisories/unreviewed/2022/05/GHSA-h37p-grfj-94pv/GHSA-h37p-grfj-94pv.json
+++ b/advisories/unreviewed/2022/05/GHSA-h37p-grfj-94pv/GHSA-h37p-grfj-94pv.json
@@ -7,12 +7,8 @@
"CVE-2007-3245"
],
"details": "IRC Services before 5.0.62, and 5.1 before 5.1pre3, allows remote attackers to disconnect users with guest nicknames by linking a guest nickname to a nickname that is already registered.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h4xc-2rv5-8gwh/GHSA-h4xc-2rv5-8gwh.json b/advisories/unreviewed/2022/05/GHSA-h4xc-2rv5-8gwh/GHSA-h4xc-2rv5-8gwh.json
index a5ed259ed78..7d2b800aa73 100644
--- a/advisories/unreviewed/2022/05/GHSA-h4xc-2rv5-8gwh/GHSA-h4xc-2rv5-8gwh.json
+++ b/advisories/unreviewed/2022/05/GHSA-h4xc-2rv5-8gwh/GHSA-h4xc-2rv5-8gwh.json
@@ -7,12 +7,8 @@
"CVE-2007-3791"
],
"details": "Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h66w-99qh-343x/GHSA-h66w-99qh-343x.json b/advisories/unreviewed/2022/05/GHSA-h66w-99qh-343x/GHSA-h66w-99qh-343x.json
index 8a9cf67e5a6..89030184d60 100644
--- a/advisories/unreviewed/2022/05/GHSA-h66w-99qh-343x/GHSA-h66w-99qh-343x.json
+++ b/advisories/unreviewed/2022/05/GHSA-h66w-99qh-343x/GHSA-h66w-99qh-343x.json
@@ -7,12 +7,8 @@
"CVE-2007-3417"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search string, which is not sanitized when an HREF attribute is printed by the (1) process_search or (2) show_recent_searches function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h6j5-2wwr-4fm9/GHSA-h6j5-2wwr-4fm9.json b/advisories/unreviewed/2022/05/GHSA-h6j5-2wwr-4fm9/GHSA-h6j5-2wwr-4fm9.json
index f29e653ce22..a3785d3ae6c 100644
--- a/advisories/unreviewed/2022/05/GHSA-h6j5-2wwr-4fm9/GHSA-h6j5-2wwr-4fm9.json
+++ b/advisories/unreviewed/2022/05/GHSA-h6j5-2wwr-4fm9/GHSA-h6j5-2wwr-4fm9.json
@@ -7,12 +7,8 @@
"CVE-2007-3963"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h6mp-cjj6-rgm3/GHSA-h6mp-cjj6-rgm3.json b/advisories/unreviewed/2022/05/GHSA-h6mp-cjj6-rgm3/GHSA-h6mp-cjj6-rgm3.json
index 8b5150b7042..2a0862687b1 100644
--- a/advisories/unreviewed/2022/05/GHSA-h6mp-cjj6-rgm3/GHSA-h6mp-cjj6-rgm3.json
+++ b/advisories/unreviewed/2022/05/GHSA-h6mp-cjj6-rgm3/GHSA-h6mp-cjj6-rgm3.json
@@ -7,12 +7,8 @@
"CVE-2007-3312"
],
"details": "Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arbitrary local files a .. (dot dot) in the u parameter. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h6ph-xppj-hh4g/GHSA-h6ph-xppj-hh4g.json b/advisories/unreviewed/2022/05/GHSA-h6ph-xppj-hh4g/GHSA-h6ph-xppj-hh4g.json
index 4027eda9bad..b716a06a2f8 100644
--- a/advisories/unreviewed/2022/05/GHSA-h6ph-xppj-hh4g/GHSA-h6ph-xppj-hh4g.json
+++ b/advisories/unreviewed/2022/05/GHSA-h6ph-xppj-hh4g/GHSA-h6ph-xppj-hh4g.json
@@ -7,12 +7,8 @@
"CVE-2007-3444"
],
"details": "The Research in Motion BlackBerry 7270 with 4.0 SP1 Bundle 83 allows remote attackers to cause a denial of service (blocked call reception) via a malformed SIP invite message, possibly related to multiple format string specifiers in the From field, a spoofed source IP address, and limitations of the function stack frame.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h7vx-cf93-p4j3/GHSA-h7vx-cf93-p4j3.json b/advisories/unreviewed/2022/05/GHSA-h7vx-cf93-p4j3/GHSA-h7vx-cf93-p4j3.json
index 52bdee1fd90..d9f8066fde7 100644
--- a/advisories/unreviewed/2022/05/GHSA-h7vx-cf93-p4j3/GHSA-h7vx-cf93-p4j3.json
+++ b/advisories/unreviewed/2022/05/GHSA-h7vx-cf93-p4j3/GHSA-h7vx-cf93-p4j3.json
@@ -7,12 +7,8 @@
"CVE-2007-3280"
],
"details": "The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-h8xf-8xfr-w35v/GHSA-h8xf-8xfr-w35v.json b/advisories/unreviewed/2022/05/GHSA-h8xf-8xfr-w35v/GHSA-h8xf-8xfr-w35v.json
index 38556af6d72..779702c3821 100644
--- a/advisories/unreviewed/2022/05/GHSA-h8xf-8xfr-w35v/GHSA-h8xf-8xfr-w35v.json
+++ b/advisories/unreviewed/2022/05/GHSA-h8xf-8xfr-w35v/GHSA-h8xf-8xfr-w35v.json
@@ -7,12 +7,8 @@
"CVE-2007-3757"
],
"details": "Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted \"tel:\" link that causes iPhone to display a different number than the number that will be dialed.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-hf6h-p3m2-p9hr/GHSA-hf6h-p3m2-p9hr.json b/advisories/unreviewed/2022/05/GHSA-hf6h-p3m2-p9hr/GHSA-hf6h-p3m2-p9hr.json
index f85a94e63cf..266a9399873 100644
--- a/advisories/unreviewed/2022/05/GHSA-hf6h-p3m2-p9hr/GHSA-hf6h-p3m2-p9hr.json
+++ b/advisories/unreviewed/2022/05/GHSA-hf6h-p3m2-p9hr/GHSA-hf6h-p3m2-p9hr.json
@@ -7,12 +7,8 @@
"CVE-2019-2269"
],
"details": "Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150, MDM9650, MSM8996AU, QCS405, QCS605, SD 625, SD 636, SD 665, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24, SXR1130",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hf87-rfwq-8qqr/GHSA-hf87-rfwq-8qqr.json b/advisories/unreviewed/2022/05/GHSA-hf87-rfwq-8qqr/GHSA-hf87-rfwq-8qqr.json
index bdeea109a0f..279e1b41cef 100644
--- a/advisories/unreviewed/2022/05/GHSA-hf87-rfwq-8qqr/GHSA-hf87-rfwq-8qqr.json
+++ b/advisories/unreviewed/2022/05/GHSA-hf87-rfwq-8qqr/GHSA-hf87-rfwq-8qqr.json
@@ -7,12 +7,8 @@
"CVE-2007-3390"
],
"details": "Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allows remote attackers to cause a denial of service (crash) via crafted iSeries capture files that trigger a SIGTRAP.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -108,9 +104,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hg2r-f4fp-pm95/GHSA-hg2r-f4fp-pm95.json b/advisories/unreviewed/2022/05/GHSA-hg2r-f4fp-pm95/GHSA-hg2r-f4fp-pm95.json
index eeb77564654..70ca5832def 100644
--- a/advisories/unreviewed/2022/05/GHSA-hg2r-f4fp-pm95/GHSA-hg2r-f4fp-pm95.json
+++ b/advisories/unreviewed/2022/05/GHSA-hg2r-f4fp-pm95/GHSA-hg2r-f4fp-pm95.json
@@ -7,12 +7,8 @@
"CVE-2007-3338"
],
"details": "Multiple stack-based buffer overflows in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allow remote attackers to execute arbitrary code via the (1) uuid_from_char or (2) duve_get_args functions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-hg46-3v5v-rp73/GHSA-hg46-3v5v-rp73.json b/advisories/unreviewed/2022/05/GHSA-hg46-3v5v-rp73/GHSA-hg46-3v5v-rp73.json
index 2a598ed9dc1..ca647290645 100644
--- a/advisories/unreviewed/2022/05/GHSA-hg46-3v5v-rp73/GHSA-hg46-3v5v-rp73.json
+++ b/advisories/unreviewed/2022/05/GHSA-hg46-3v5v-rp73/GHSA-hg46-3v5v-rp73.json
@@ -7,12 +7,8 @@
"CVE-2007-3658"
],
"details": "Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hggv-r2p4-ww92/GHSA-hggv-r2p4-ww92.json b/advisories/unreviewed/2022/05/GHSA-hggv-r2p4-ww92/GHSA-hggv-r2p4-ww92.json
index 40fa3d7d532..d50ef1a4c9e 100644
--- a/advisories/unreviewed/2022/05/GHSA-hggv-r2p4-ww92/GHSA-hggv-r2p4-ww92.json
+++ b/advisories/unreviewed/2022/05/GHSA-hggv-r2p4-ww92/GHSA-hggv-r2p4-ww92.json
@@ -7,12 +7,8 @@
"CVE-2007-3379"
],
"details": "Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hgwx-v3w7-cwj6/GHSA-hgwx-v3w7-cwj6.json b/advisories/unreviewed/2022/05/GHSA-hgwx-v3w7-cwj6/GHSA-hgwx-v3w7-cwj6.json
index 06d4639246a..5675ecdf8bc 100644
--- a/advisories/unreviewed/2022/05/GHSA-hgwx-v3w7-cwj6/GHSA-hgwx-v3w7-cwj6.json
+++ b/advisories/unreviewed/2022/05/GHSA-hgwx-v3w7-cwj6/GHSA-hgwx-v3w7-cwj6.json
@@ -7,12 +7,8 @@
"CVE-2007-3334"
],
"details": "Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -76,9 +72,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hjcr-7hpx-g2cw/GHSA-hjcr-7hpx-g2cw.json b/advisories/unreviewed/2022/05/GHSA-hjcr-7hpx-g2cw/GHSA-hjcr-7hpx-g2cw.json
index 1f993447b4a..ae050fce477 100644
--- a/advisories/unreviewed/2022/05/GHSA-hjcr-7hpx-g2cw/GHSA-hjcr-7hpx-g2cw.json
+++ b/advisories/unreviewed/2022/05/GHSA-hjcr-7hpx-g2cw/GHSA-hjcr-7hpx-g2cw.json
@@ -7,12 +7,8 @@
"CVE-2007-3559"
],
"details": "Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hjxc-gvpm-wh37/GHSA-hjxc-gvpm-wh37.json b/advisories/unreviewed/2022/05/GHSA-hjxc-gvpm-wh37/GHSA-hjxc-gvpm-wh37.json
index a9828365036..c606225b018 100644
--- a/advisories/unreviewed/2022/05/GHSA-hjxc-gvpm-wh37/GHSA-hjxc-gvpm-wh37.json
+++ b/advisories/unreviewed/2022/05/GHSA-hjxc-gvpm-wh37/GHSA-hjxc-gvpm-wh37.json
@@ -7,12 +7,8 @@
"CVE-2007-3725"
],
"details": "The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -116,9 +112,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hm6h-6v88-fgh7/GHSA-hm6h-6v88-fgh7.json b/advisories/unreviewed/2022/05/GHSA-hm6h-6v88-fgh7/GHSA-hm6h-6v88-fgh7.json
index 0ae8bf9538f..908d97081b5 100644
--- a/advisories/unreviewed/2022/05/GHSA-hm6h-6v88-fgh7/GHSA-hm6h-6v88-fgh7.json
+++ b/advisories/unreviewed/2022/05/GHSA-hm6h-6v88-fgh7/GHSA-hm6h-6v88-fgh7.json
@@ -7,12 +7,8 @@
"CVE-2007-3301"
],
"details": "SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-hm7g-9r5x-m849/GHSA-hm7g-9r5x-m849.json b/advisories/unreviewed/2022/05/GHSA-hm7g-9r5x-m849/GHSA-hm7g-9r5x-m849.json
index 1976743d3dc..dac2ea47e4f 100644
--- a/advisories/unreviewed/2022/05/GHSA-hm7g-9r5x-m849/GHSA-hm7g-9r5x-m849.json
+++ b/advisories/unreviewed/2022/05/GHSA-hm7g-9r5x-m849/GHSA-hm7g-9r5x-m849.json
@@ -7,12 +7,8 @@
"CVE-2007-3913"
],
"details": "SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-hp5x-r3h5-p375/GHSA-hp5x-r3h5-p375.json b/advisories/unreviewed/2022/05/GHSA-hp5x-r3h5-p375/GHSA-hp5x-r3h5-p375.json
index 3b544e67752..8e6c743562d 100644
--- a/advisories/unreviewed/2022/05/GHSA-hp5x-r3h5-p375/GHSA-hp5x-r3h5-p375.json
+++ b/advisories/unreviewed/2022/05/GHSA-hp5x-r3h5-p375/GHSA-hp5x-r3h5-p375.json
@@ -7,12 +7,8 @@
"CVE-2007-3628"
],
"details": "Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to \"manipulate the generated sorting queries.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hp6w-h6gw-qjwm/GHSA-hp6w-h6gw-qjwm.json b/advisories/unreviewed/2022/05/GHSA-hp6w-h6gw-qjwm/GHSA-hp6w-h6gw-qjwm.json
index 157fd73398e..80ecc8f018a 100644
--- a/advisories/unreviewed/2022/05/GHSA-hp6w-h6gw-qjwm/GHSA-hp6w-h6gw-qjwm.json
+++ b/advisories/unreviewed/2022/05/GHSA-hp6w-h6gw-qjwm/GHSA-hp6w-h6gw-qjwm.json
@@ -7,12 +7,8 @@
"CVE-2007-3688"
],
"details": "Multiple cross-site request forgery (CSRF) vulnerabilities in DotClear 1.2.6 allow remote attackers to perform actions as arbitrary users via the (1) tool_url parameter to ecrire/tools.php and multiple fields on the (2) blogconf, (3) blogroll, (4) ecrire/redacteur.php, and (5) ecrire/user_prefs.php pages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hppx-p2c7-j397/GHSA-hppx-p2c7-j397.json b/advisories/unreviewed/2022/05/GHSA-hppx-p2c7-j397/GHSA-hppx-p2c7-j397.json
index 3f0acc96a60..85a3c586961 100644
--- a/advisories/unreviewed/2022/05/GHSA-hppx-p2c7-j397/GHSA-hppx-p2c7-j397.json
+++ b/advisories/unreviewed/2022/05/GHSA-hppx-p2c7-j397/GHSA-hppx-p2c7-j397.json
@@ -7,12 +7,8 @@
"CVE-2007-3502"
],
"details": "Unspecified vulnerability in the web-based product configuration system in Kaspersky Anti-Spam before 3.0 MP1 allows remote attackers to obtain access to certain directories.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hqj6-4xqm-57x8/GHSA-hqj6-4xqm-57x8.json b/advisories/unreviewed/2022/05/GHSA-hqj6-4xqm-57x8/GHSA-hqj6-4xqm-57x8.json
index aba10364ee2..f3e0db187d2 100644
--- a/advisories/unreviewed/2022/05/GHSA-hqj6-4xqm-57x8/GHSA-hqj6-4xqm-57x8.json
+++ b/advisories/unreviewed/2022/05/GHSA-hqj6-4xqm-57x8/GHSA-hqj6-4xqm-57x8.json
@@ -7,12 +7,8 @@
"CVE-2007-3429"
],
"details": "Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hqmf-7qgf-8qgx/GHSA-hqmf-7qgf-8qgx.json b/advisories/unreviewed/2022/05/GHSA-hqmf-7qgf-8qgx/GHSA-hqmf-7qgf-8qgx.json
index d47d64b4e02..a766ef6ec0a 100644
--- a/advisories/unreviewed/2022/05/GHSA-hqmf-7qgf-8qgx/GHSA-hqmf-7qgf-8qgx.json
+++ b/advisories/unreviewed/2022/05/GHSA-hqmf-7qgf-8qgx/GHSA-hqmf-7qgf-8qgx.json
@@ -7,12 +7,8 @@
"CVE-2007-3790"
],
"details": "The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hqqh-w4r2-5w25/GHSA-hqqh-w4r2-5w25.json b/advisories/unreviewed/2022/05/GHSA-hqqh-w4r2-5w25/GHSA-hqqh-w4r2-5w25.json
index 16c10b581ab..d075001f942 100644
--- a/advisories/unreviewed/2022/05/GHSA-hqqh-w4r2-5w25/GHSA-hqqh-w4r2-5w25.json
+++ b/advisories/unreviewed/2022/05/GHSA-hqqh-w4r2-5w25/GHSA-hqqh-w4r2-5w25.json
@@ -7,12 +7,8 @@
"CVE-2007-3314"
],
"details": "Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hr4f-v74c-rx23/GHSA-hr4f-v74c-rx23.json b/advisories/unreviewed/2022/05/GHSA-hr4f-v74c-rx23/GHSA-hr4f-v74c-rx23.json
index 16d21395cfe..ed71fe5b0d3 100644
--- a/advisories/unreviewed/2022/05/GHSA-hr4f-v74c-rx23/GHSA-hr4f-v74c-rx23.json
+++ b/advisories/unreviewed/2022/05/GHSA-hr4f-v74c-rx23/GHSA-hr4f-v74c-rx23.json
@@ -7,12 +7,8 @@
"CVE-2007-3244"
],
"details": "SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the \"quircky slashes bug.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hr83-fmp4-9jx3/GHSA-hr83-fmp4-9jx3.json b/advisories/unreviewed/2022/05/GHSA-hr83-fmp4-9jx3/GHSA-hr83-fmp4-9jx3.json
index 746146135a9..7959c0b429f 100644
--- a/advisories/unreviewed/2022/05/GHSA-hr83-fmp4-9jx3/GHSA-hr83-fmp4-9jx3.json
+++ b/advisories/unreviewed/2022/05/GHSA-hr83-fmp4-9jx3/GHSA-hr83-fmp4-9jx3.json
@@ -7,12 +7,8 @@
"CVE-2007-3286"
],
"details": "Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-hrcv-2p36-pwrv/GHSA-hrcv-2p36-pwrv.json b/advisories/unreviewed/2022/05/GHSA-hrcv-2p36-pwrv/GHSA-hrcv-2p36-pwrv.json
index 702e95709e7..360fd34730e 100644
--- a/advisories/unreviewed/2022/05/GHSA-hrcv-2p36-pwrv/GHSA-hrcv-2p36-pwrv.json
+++ b/advisories/unreviewed/2022/05/GHSA-hrcv-2p36-pwrv/GHSA-hrcv-2p36-pwrv.json
@@ -7,12 +7,8 @@
"CVE-2007-3575"
],
"details": "SQL injection vulnerability in includes/functions in FreeDomain.co.nr Clone allows remote attackers to execute arbitrary SQL commands via the logindomain parameter to members.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hrvh-vj4j-f9xp/GHSA-hrvh-vj4j-f9xp.json b/advisories/unreviewed/2022/05/GHSA-hrvh-vj4j-f9xp/GHSA-hrvh-vj4j-f9xp.json
index 8c048dde772..ddd694afedb 100644
--- a/advisories/unreviewed/2022/05/GHSA-hrvh-vj4j-f9xp/GHSA-hrvh-vj4j-f9xp.json
+++ b/advisories/unreviewed/2022/05/GHSA-hrvh-vj4j-f9xp/GHSA-hrvh-vj4j-f9xp.json
@@ -7,12 +7,8 @@
"CVE-2007-3276"
],
"details": "Cross-site scripting (XSS) vulnerability in index.php in Site@School (S@S) 2.4.10 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hv4w-g3mp-j6rw/GHSA-hv4w-g3mp-j6rw.json b/advisories/unreviewed/2022/05/GHSA-hv4w-g3mp-j6rw/GHSA-hv4w-g3mp-j6rw.json
index 8e7260d163b..0d544dc9502 100644
--- a/advisories/unreviewed/2022/05/GHSA-hv4w-g3mp-j6rw/GHSA-hv4w-g3mp-j6rw.json
+++ b/advisories/unreviewed/2022/05/GHSA-hv4w-g3mp-j6rw/GHSA-hv4w-g3mp-j6rw.json
@@ -7,12 +7,8 @@
"CVE-2007-3818"
],
"details": "Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with \"administer blocks\" permission to inject arbitrary JavaScript and gain privileges via \"the message displayed above the default user login block.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hvv3-w36m-h8q5/GHSA-hvv3-w36m-h8q5.json b/advisories/unreviewed/2022/05/GHSA-hvv3-w36m-h8q5/GHSA-hvv3-w36m-h8q5.json
index bd9f72cdfee..88f76e8f992 100644
--- a/advisories/unreviewed/2022/05/GHSA-hvv3-w36m-h8q5/GHSA-hvv3-w36m-h8q5.json
+++ b/advisories/unreviewed/2022/05/GHSA-hvv3-w36m-h8q5/GHSA-hvv3-w36m-h8q5.json
@@ -7,12 +7,8 @@
"CVE-2007-3570"
],
"details": "The Linux Access Gateway in Novell Access Manager before 3.0 SP1 Release Candidate 1 (RC1) allows remote attackers to bypass unspecified security controls via Fullwidth/Halfwidth Unicode encoded data in a HTTP POST request.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hw45-72c5-h6pw/GHSA-hw45-72c5-h6pw.json b/advisories/unreviewed/2022/05/GHSA-hw45-72c5-h6pw/GHSA-hw45-72c5-h6pw.json
index 6838415379d..b131458a892 100644
--- a/advisories/unreviewed/2022/05/GHSA-hw45-72c5-h6pw/GHSA-hw45-72c5-h6pw.json
+++ b/advisories/unreviewed/2022/05/GHSA-hw45-72c5-h6pw/GHSA-hw45-72c5-h6pw.json
@@ -7,12 +7,8 @@
"CVE-2007-3494"
],
"details": "Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote authenticated users to (1) read the entire database by accessing the database backup plugin via a devtools/templates/newdump_backend.html argument in the template parameter to interna/plugin.php, (2) create plugins, (3) remove plugins, (4) enable debug mode, and have other unspecified impact.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hwpm-vwv2-5556/GHSA-hwpm-vwv2-5556.json b/advisories/unreviewed/2022/05/GHSA-hwpm-vwv2-5556/GHSA-hwpm-vwv2-5556.json
index 6cdfe778259..1bd1c82b8f1 100644
--- a/advisories/unreviewed/2022/05/GHSA-hwpm-vwv2-5556/GHSA-hwpm-vwv2-5556.json
+++ b/advisories/unreviewed/2022/05/GHSA-hwpm-vwv2-5556/GHSA-hwpm-vwv2-5556.json
@@ -7,12 +7,8 @@
"CVE-2007-3293"
],
"details": "SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hx2q-8pcc-xc36/GHSA-hx2q-8pcc-xc36.json b/advisories/unreviewed/2022/05/GHSA-hx2q-8pcc-xc36/GHSA-hx2q-8pcc-xc36.json
index 3a01c57a9c9..3b2a2860dd4 100644
--- a/advisories/unreviewed/2022/05/GHSA-hx2q-8pcc-xc36/GHSA-hx2q-8pcc-xc36.json
+++ b/advisories/unreviewed/2022/05/GHSA-hx2q-8pcc-xc36/GHSA-hx2q-8pcc-xc36.json
@@ -7,12 +7,8 @@
"CVE-2007-3950"
],
"details": "lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -72,9 +68,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hx3p-mvcq-8g8m/GHSA-hx3p-mvcq-8g8m.json b/advisories/unreviewed/2022/05/GHSA-hx3p-mvcq-8g8m/GHSA-hx3p-mvcq-8g8m.json
index fe4d0933f68..3672b401ef9 100644
--- a/advisories/unreviewed/2022/05/GHSA-hx3p-mvcq-8g8m/GHSA-hx3p-mvcq-8g8m.json
+++ b/advisories/unreviewed/2022/05/GHSA-hx3p-mvcq-8g8m/GHSA-hx3p-mvcq-8g8m.json
@@ -7,12 +7,8 @@
"CVE-2007-3436"
],
"details": "Microsoft MSN Messenger 4.7 on Windows XP allows remote attackers to cause a denial of service (resource consumption) via a flood of SIP INVITE requests to the port specified for voice conversation.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hxj5-ccfq-hvjx/GHSA-hxj5-ccfq-hvjx.json b/advisories/unreviewed/2022/05/GHSA-hxj5-ccfq-hvjx/GHSA-hxj5-ccfq-hvjx.json
index 63f26ed1d56..abc01348be4 100644
--- a/advisories/unreviewed/2022/05/GHSA-hxj5-ccfq-hvjx/GHSA-hxj5-ccfq-hvjx.json
+++ b/advisories/unreviewed/2022/05/GHSA-hxj5-ccfq-hvjx/GHSA-hxj5-ccfq-hvjx.json
@@ -7,12 +7,8 @@
"CVE-2007-3303"
],
"details": "Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-hxjp-f6cv-xgr2/GHSA-hxjp-f6cv-xgr2.json b/advisories/unreviewed/2022/05/GHSA-hxjp-f6cv-xgr2/GHSA-hxjp-f6cv-xgr2.json
index f73c883fdad..711bf70be8b 100644
--- a/advisories/unreviewed/2022/05/GHSA-hxjp-f6cv-xgr2/GHSA-hxjp-f6cv-xgr2.json
+++ b/advisories/unreviewed/2022/05/GHSA-hxjp-f6cv-xgr2/GHSA-hxjp-f6cv-xgr2.json
@@ -7,12 +7,8 @@
"CVE-2007-3418"
],
"details": "The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authenticated users to impersonate other users.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hxmf-j46h-w93f/GHSA-hxmf-j46h-w93f.json b/advisories/unreviewed/2022/05/GHSA-hxmf-j46h-w93f/GHSA-hxmf-j46h-w93f.json
index de7a918c3e9..79358087757 100644
--- a/advisories/unreviewed/2022/05/GHSA-hxmf-j46h-w93f/GHSA-hxmf-j46h-w93f.json
+++ b/advisories/unreviewed/2022/05/GHSA-hxmf-j46h-w93f/GHSA-hxmf-j46h-w93f.json
@@ -7,12 +7,8 @@
"CVE-2007-3591"
],
"details": "Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to \"a remote form,\" probably related to direct requests and missing authorization checks.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-hxxw-hhch-pc3w/GHSA-hxxw-hhch-pc3w.json b/advisories/unreviewed/2022/05/GHSA-hxxw-hhch-pc3w/GHSA-hxxw-hhch-pc3w.json
index a862985f585..0944be78d6f 100644
--- a/advisories/unreviewed/2022/05/GHSA-hxxw-hhch-pc3w/GHSA-hxxw-hhch-pc3w.json
+++ b/advisories/unreviewed/2022/05/GHSA-hxxw-hhch-pc3w/GHSA-hxxw-hhch-pc3w.json
@@ -7,12 +7,8 @@
"CVE-2007-3462"
],
"details": "Cross-site request forgery (CSRF) vulnerability in Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, allows remote attackers to execute commands as arbitrary users, and disable firewalling of the protected network.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j33j-4j8g-vjrw/GHSA-j33j-4j8g-vjrw.json b/advisories/unreviewed/2022/05/GHSA-j33j-4j8g-vjrw/GHSA-j33j-4j8g-vjrw.json
index 1e6e75a347b..d165903b5fa 100644
--- a/advisories/unreviewed/2022/05/GHSA-j33j-4j8g-vjrw/GHSA-j33j-4j8g-vjrw.json
+++ b/advisories/unreviewed/2022/05/GHSA-j33j-4j8g-vjrw/GHSA-j33j-4j8g-vjrw.json
@@ -7,12 +7,8 @@
"CVE-2007-3554"
],
"details": "Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j37r-3w4j-jc68/GHSA-j37r-3w4j-jc68.json b/advisories/unreviewed/2022/05/GHSA-j37r-3w4j-jc68/GHSA-j37r-3w4j-jc68.json
index fd0cf400b9d..07151571104 100644
--- a/advisories/unreviewed/2022/05/GHSA-j37r-3w4j-jc68/GHSA-j37r-3w4j-jc68.json
+++ b/advisories/unreviewed/2022/05/GHSA-j37r-3w4j-jc68/GHSA-j37r-3w4j-jc68.json
@@ -7,12 +7,8 @@
"CVE-2007-3529"
],
"details": "videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j3fc-rcm4-h5g9/GHSA-j3fc-rcm4-h5g9.json b/advisories/unreviewed/2022/05/GHSA-j3fc-rcm4-h5g9/GHSA-j3fc-rcm4-h5g9.json
index 175cfca528a..bd19105fc68 100644
--- a/advisories/unreviewed/2022/05/GHSA-j3fc-rcm4-h5g9/GHSA-j3fc-rcm4-h5g9.json
+++ b/advisories/unreviewed/2022/05/GHSA-j3fc-rcm4-h5g9/GHSA-j3fc-rcm4-h5g9.json
@@ -7,12 +7,8 @@
"CVE-2007-3292"
],
"details": "Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for \"a small image\" associated with an article.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j53f-68p8-c4ww/GHSA-j53f-68p8-c4ww.json b/advisories/unreviewed/2022/05/GHSA-j53f-68p8-c4ww/GHSA-j53f-68p8-c4ww.json
index 24c71d09088..b1e07c67136 100644
--- a/advisories/unreviewed/2022/05/GHSA-j53f-68p8-c4ww/GHSA-j53f-68p8-c4ww.json
+++ b/advisories/unreviewed/2022/05/GHSA-j53f-68p8-c4ww/GHSA-j53f-68p8-c4ww.json
@@ -7,12 +7,8 @@
"CVE-2007-3506"
],
"details": "The ft_bitmap_assure_buffer function in src/base/ftbimap.c in FreeType 2.3.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors involving bitmap fonts, related to a \"memory buffer overwrite bug.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j68c-fr78-mc97/GHSA-j68c-fr78-mc97.json b/advisories/unreviewed/2022/05/GHSA-j68c-fr78-mc97/GHSA-j68c-fr78-mc97.json
index 523e1310f5a..124f6bb9e6c 100644
--- a/advisories/unreviewed/2022/05/GHSA-j68c-fr78-mc97/GHSA-j68c-fr78-mc97.json
+++ b/advisories/unreviewed/2022/05/GHSA-j68c-fr78-mc97/GHSA-j68c-fr78-mc97.json
@@ -7,12 +7,8 @@
"CVE-2007-3782"
],
"details": "MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -108,9 +104,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j9p8-vp8h-7qgg/GHSA-j9p8-vp8h-7qgg.json b/advisories/unreviewed/2022/05/GHSA-j9p8-vp8h-7qgg/GHSA-j9p8-vp8h-7qgg.json
index 3ec2d3b471a..02cae9e5bfe 100644
--- a/advisories/unreviewed/2022/05/GHSA-j9p8-vp8h-7qgg/GHSA-j9p8-vp8h-7qgg.json
+++ b/advisories/unreviewed/2022/05/GHSA-j9p8-vp8h-7qgg/GHSA-j9p8-vp8h-7qgg.json
@@ -7,12 +7,8 @@
"CVE-2007-3603"
],
"details": "SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute arbitrary SQL commands via the assigned_user_id parameter in a Potentials ListView action to index.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-j9v5-cxq9-4x9q/GHSA-j9v5-cxq9-4x9q.json b/advisories/unreviewed/2022/05/GHSA-j9v5-cxq9-4x9q/GHSA-j9v5-cxq9-4x9q.json
index 99e5fe1552d..16090b9a13b 100644
--- a/advisories/unreviewed/2022/05/GHSA-j9v5-cxq9-4x9q/GHSA-j9v5-cxq9-4x9q.json
+++ b/advisories/unreviewed/2022/05/GHSA-j9v5-cxq9-4x9q/GHSA-j9v5-cxq9-4x9q.json
@@ -7,12 +7,8 @@
"CVE-2007-3231"
],
"details": "Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jc23-3hm3-wvxg/GHSA-jc23-3hm3-wvxg.json b/advisories/unreviewed/2022/05/GHSA-jc23-3hm3-wvxg/GHSA-jc23-3hm3-wvxg.json
index 5e6f51c9589..17f2add9179 100644
--- a/advisories/unreviewed/2022/05/GHSA-jc23-3hm3-wvxg/GHSA-jc23-3hm3-wvxg.json
+++ b/advisories/unreviewed/2022/05/GHSA-jc23-3hm3-wvxg/GHSA-jc23-3hm3-wvxg.json
@@ -7,12 +7,8 @@
"CVE-2007-3713"
],
"details": "Multiple buffer overflows in Konst CenterICQ 4.9.11 through 4.21 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might overlap CVE-2007-0160.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jccf-mcj7-gjxw/GHSA-jccf-mcj7-gjxw.json b/advisories/unreviewed/2022/05/GHSA-jccf-mcj7-gjxw/GHSA-jccf-mcj7-gjxw.json
index 9c2db45e62e..c4f93c2e1ee 100644
--- a/advisories/unreviewed/2022/05/GHSA-jccf-mcj7-gjxw/GHSA-jccf-mcj7-gjxw.json
+++ b/advisories/unreviewed/2022/05/GHSA-jccf-mcj7-gjxw/GHSA-jccf-mcj7-gjxw.json
@@ -7,12 +7,8 @@
"CVE-2007-3697"
],
"details": "PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jcqm-cffq-3cmw/GHSA-jcqm-cffq-3cmw.json b/advisories/unreviewed/2022/05/GHSA-jcqm-cffq-3cmw/GHSA-jcqm-cffq-3cmw.json
index 05451df9c33..c95f180a15f 100644
--- a/advisories/unreviewed/2022/05/GHSA-jcqm-cffq-3cmw/GHSA-jcqm-cffq-3cmw.json
+++ b/advisories/unreviewed/2022/05/GHSA-jcqm-cffq-3cmw/GHSA-jcqm-cffq-3cmw.json
@@ -7,12 +7,8 @@
"CVE-2007-3951"
],
"details": "Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an \"integer cast around.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -76,9 +72,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jcw9-xh9j-x87m/GHSA-jcw9-xh9j-x87m.json b/advisories/unreviewed/2022/05/GHSA-jcw9-xh9j-x87m/GHSA-jcw9-xh9j-x87m.json
index 52b24e233be..26d9b39f831 100644
--- a/advisories/unreviewed/2022/05/GHSA-jcw9-xh9j-x87m/GHSA-jcw9-xh9j-x87m.json
+++ b/advisories/unreviewed/2022/05/GHSA-jcw9-xh9j-x87m/GHSA-jcw9-xh9j-x87m.json
@@ -7,12 +7,8 @@
"CVE-2007-3921"
],
"details": "gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-jgjj-vrw9-h43x/GHSA-jgjj-vrw9-h43x.json b/advisories/unreviewed/2022/05/GHSA-jgjj-vrw9-h43x/GHSA-jgjj-vrw9-h43x.json
index c4009d6ceba..36cabc2f786 100644
--- a/advisories/unreviewed/2022/05/GHSA-jgjj-vrw9-h43x/GHSA-jgjj-vrw9-h43x.json
+++ b/advisories/unreviewed/2022/05/GHSA-jgjj-vrw9-h43x/GHSA-jgjj-vrw9-h43x.json
@@ -7,12 +7,8 @@
"CVE-2007-3288"
],
"details": "Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer field.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jgqh-rpqx-64g9/GHSA-jgqh-rpqx-64g9.json b/advisories/unreviewed/2022/05/GHSA-jgqh-rpqx-64g9/GHSA-jgqh-rpqx-64g9.json
index f7b12e68a13..27c25c4c3c3 100644
--- a/advisories/unreviewed/2022/05/GHSA-jgqh-rpqx-64g9/GHSA-jgqh-rpqx-64g9.json
+++ b/advisories/unreviewed/2022/05/GHSA-jgqh-rpqx-64g9/GHSA-jgqh-rpqx-64g9.json
@@ -7,12 +7,8 @@
"CVE-2007-3234"
],
"details": "SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jj42-27cj-4ph7/GHSA-jj42-27cj-4ph7.json b/advisories/unreviewed/2022/05/GHSA-jj42-27cj-4ph7/GHSA-jj42-27cj-4ph7.json
index 89f75a85cee..fa27fea9be6 100644
--- a/advisories/unreviewed/2022/05/GHSA-jj42-27cj-4ph7/GHSA-jj42-27cj-4ph7.json
+++ b/advisories/unreviewed/2022/05/GHSA-jj42-27cj-4ph7/GHSA-jj42-27cj-4ph7.json
@@ -7,12 +7,8 @@
"CVE-2007-3669"
],
"details": "Multiple unspecified vulnerabilities in the Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control have unspecified attack vectors and impact, including a denial of service via \"improper use\" of the SaveToFile function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jj7v-w3xx-rq39/GHSA-jj7v-w3xx-rq39.json b/advisories/unreviewed/2022/05/GHSA-jj7v-w3xx-rq39/GHSA-jj7v-w3xx-rq39.json
index 77824b74037..a3ec26d30f7 100644
--- a/advisories/unreviewed/2022/05/GHSA-jj7v-w3xx-rq39/GHSA-jj7v-w3xx-rq39.json
+++ b/advisories/unreviewed/2022/05/GHSA-jj7v-w3xx-rq39/GHSA-jj7v-w3xx-rq39.json
@@ -7,12 +7,8 @@
"CVE-2007-3235"
],
"details": "Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jjgw-mx44-pv3c/GHSA-jjgw-mx44-pv3c.json b/advisories/unreviewed/2022/05/GHSA-jjgw-mx44-pv3c/GHSA-jjgw-mx44-pv3c.json
index fe7539eebdd..8a8a1685881 100644
--- a/advisories/unreviewed/2022/05/GHSA-jjgw-mx44-pv3c/GHSA-jjgw-mx44-pv3c.json
+++ b/advisories/unreviewed/2022/05/GHSA-jjgw-mx44-pv3c/GHSA-jjgw-mx44-pv3c.json
@@ -7,12 +7,8 @@
"CVE-2007-3378"
],
"details": "The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlier, when invoked from a .htaccess file, allow remote attackers to bypass safe_mode and open_basedir restrictions and possibly execute arbitrary commands, as demonstrated using (a) php_value, (b) php_flag, and (c) directives in .htaccess.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -192,9 +188,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jm8f-6296-mrgf/GHSA-jm8f-6296-mrgf.json b/advisories/unreviewed/2022/05/GHSA-jm8f-6296-mrgf/GHSA-jm8f-6296-mrgf.json
index a406cdbac95..e350f2e79aa 100644
--- a/advisories/unreviewed/2022/05/GHSA-jm8f-6296-mrgf/GHSA-jm8f-6296-mrgf.json
+++ b/advisories/unreviewed/2022/05/GHSA-jm8f-6296-mrgf/GHSA-jm8f-6296-mrgf.json
@@ -7,12 +7,8 @@
"CVE-2007-3599"
],
"details": "vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permission.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jmqg-r3wj-jjfh/GHSA-jmqg-r3wj-jjfh.json b/advisories/unreviewed/2022/05/GHSA-jmqg-r3wj-jjfh/GHSA-jmqg-r3wj-jjfh.json
index 00a662ffb9b..249fc71ce1b 100644
--- a/advisories/unreviewed/2022/05/GHSA-jmqg-r3wj-jjfh/GHSA-jmqg-r3wj-jjfh.json
+++ b/advisories/unreviewed/2022/05/GHSA-jmqg-r3wj-jjfh/GHSA-jmqg-r3wj-jjfh.json
@@ -7,12 +7,8 @@
"CVE-2007-3520"
],
"details": "SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jpg3-w2h5-g48c/GHSA-jpg3-w2h5-g48c.json b/advisories/unreviewed/2022/05/GHSA-jpg3-w2h5-g48c/GHSA-jpg3-w2h5-g48c.json
index b9c82de15d0..9f39ee45719 100644
--- a/advisories/unreviewed/2022/05/GHSA-jpg3-w2h5-g48c/GHSA-jpg3-w2h5-g48c.json
+++ b/advisories/unreviewed/2022/05/GHSA-jpg3-w2h5-g48c/GHSA-jpg3-w2h5-g48c.json
@@ -7,12 +7,8 @@
"CVE-2007-3652"
],
"details": "SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-jpg5-4x2v-qmh4/GHSA-jpg5-4x2v-qmh4.json b/advisories/unreviewed/2022/05/GHSA-jpg5-4x2v-qmh4/GHSA-jpg5-4x2v-qmh4.json
index 675522b0c05..204047313a8 100644
--- a/advisories/unreviewed/2022/05/GHSA-jpg5-4x2v-qmh4/GHSA-jpg5-4x2v-qmh4.json
+++ b/advisories/unreviewed/2022/05/GHSA-jpg5-4x2v-qmh4/GHSA-jpg5-4x2v-qmh4.json
@@ -7,12 +7,8 @@
"CVE-2007-3468"
],
"details": "input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jr23-4p9p-9p44/GHSA-jr23-4p9p-9p44.json b/advisories/unreviewed/2022/05/GHSA-jr23-4p9p-9p44/GHSA-jr23-4p9p-9p44.json
index 20fa6940043..845fdc27ec3 100644
--- a/advisories/unreviewed/2022/05/GHSA-jr23-4p9p-9p44/GHSA-jr23-4p9p-9p44.json
+++ b/advisories/unreviewed/2022/05/GHSA-jr23-4p9p-9p44/GHSA-jr23-4p9p-9p44.json
@@ -7,12 +7,8 @@
"CVE-2007-3679"
],
"details": "The Citrix EPA ActiveX control (aka the \"endpoint checking control\" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jwf4-x6v5-mvc5/GHSA-jwf4-x6v5-mvc5.json b/advisories/unreviewed/2022/05/GHSA-jwf4-x6v5-mvc5/GHSA-jwf4-x6v5-mvc5.json
index 53f43ccc49a..d998eedc6fa 100644
--- a/advisories/unreviewed/2022/05/GHSA-jwf4-x6v5-mvc5/GHSA-jwf4-x6v5-mvc5.json
+++ b/advisories/unreviewed/2022/05/GHSA-jwf4-x6v5-mvc5/GHSA-jwf4-x6v5-mvc5.json
@@ -7,12 +7,8 @@
"CVE-2007-3445"
],
"details": "Buffer overflow in SJ Labs SJphone 1.60.303c, running under Windows Mobile 2003 on the Samsung SCH-i730 phone, allows remote attackers to cause a denial of service (device hang and call termination) via a malformed SIP INVITE message, a different vulnerability than CVE-2007-3351.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jwhj-49m2-63w7/GHSA-jwhj-49m2-63w7.json b/advisories/unreviewed/2022/05/GHSA-jwhj-49m2-63w7/GHSA-jwhj-49m2-63w7.json
index 9ecfad448a9..3905ae56d8e 100644
--- a/advisories/unreviewed/2022/05/GHSA-jwhj-49m2-63w7/GHSA-jwhj-49m2-63w7.json
+++ b/advisories/unreviewed/2022/05/GHSA-jwhj-49m2-63w7/GHSA-jwhj-49m2-63w7.json
@@ -7,12 +7,8 @@
"CVE-2007-3450"
],
"details": "SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jwrg-mcm2-hppm/GHSA-jwrg-mcm2-hppm.json b/advisories/unreviewed/2022/05/GHSA-jwrg-mcm2-hppm/GHSA-jwrg-mcm2-hppm.json
index 124c3ec3a58..1034c3cfb20 100644
--- a/advisories/unreviewed/2022/05/GHSA-jwrg-mcm2-hppm/GHSA-jwrg-mcm2-hppm.json
+++ b/advisories/unreviewed/2022/05/GHSA-jwrg-mcm2-hppm/GHSA-jwrg-mcm2-hppm.json
@@ -7,12 +7,8 @@
"CVE-2007-3306"
],
"details": "PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-jxh4-j45j-4gp9/GHSA-jxh4-j45j-4gp9.json b/advisories/unreviewed/2022/05/GHSA-jxh4-j45j-4gp9/GHSA-jxh4-j45j-4gp9.json
index 41cc3873755..38caf2978ba 100644
--- a/advisories/unreviewed/2022/05/GHSA-jxh4-j45j-4gp9/GHSA-jxh4-j45j-4gp9.json
+++ b/advisories/unreviewed/2022/05/GHSA-jxh4-j45j-4gp9/GHSA-jxh4-j45j-4gp9.json
@@ -7,12 +7,8 @@
"CVE-2007-3642"
],
"details": "The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -72,9 +68,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m278-7c4j-w5jw/GHSA-m278-7c4j-w5jw.json b/advisories/unreviewed/2022/05/GHSA-m278-7c4j-w5jw/GHSA-m278-7c4j-w5jw.json
index f9c59dac374..94d611fea65 100644
--- a/advisories/unreviewed/2022/05/GHSA-m278-7c4j-w5jw/GHSA-m278-7c4j-w5jw.json
+++ b/advisories/unreviewed/2022/05/GHSA-m278-7c4j-w5jw/GHSA-m278-7c4j-w5jw.json
@@ -7,12 +7,8 @@
"CVE-2007-3730"
],
"details": "The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 does not log the source IP address or attempted username for login attempts, which might help remote attackers to avoid identification.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m2qp-fqw9-www2/GHSA-m2qp-fqw9-www2.json b/advisories/unreviewed/2022/05/GHSA-m2qp-fqw9-www2/GHSA-m2qp-fqw9-www2.json
index 7dbbab389b1..4cc623eacca 100644
--- a/advisories/unreviewed/2022/05/GHSA-m2qp-fqw9-www2/GHSA-m2qp-fqw9-www2.json
+++ b/advisories/unreviewed/2022/05/GHSA-m2qp-fqw9-www2/GHSA-m2qp-fqw9-www2.json
@@ -7,12 +7,8 @@
"CVE-2007-3677"
],
"details": "Multiple SQL injection vulnerabilities in Maxsi eVisit Analyst allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) idsp1.pl, (2) ip.pl, and (3) einsite_director.pl. NOTE: this issue can be leveraged for path disclosure from resulting error messages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-m39v-jwfm-r5x9/GHSA-m39v-jwfm-r5x9.json b/advisories/unreviewed/2022/05/GHSA-m39v-jwfm-r5x9/GHSA-m39v-jwfm-r5x9.json
index 0116f897afb..58f78f38774 100644
--- a/advisories/unreviewed/2022/05/GHSA-m39v-jwfm-r5x9/GHSA-m39v-jwfm-r5x9.json
+++ b/advisories/unreviewed/2022/05/GHSA-m39v-jwfm-r5x9/GHSA-m39v-jwfm-r5x9.json
@@ -7,12 +7,8 @@
"CVE-2007-3297"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[ini_array][EXTLIB_PATH] parameter to (1) msDb.php, (2) modules/MusooTemplateLite.php, or (3) modules/SoundImporter.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m3p7-qgpp-q63r/GHSA-m3p7-qgpp-q63r.json b/advisories/unreviewed/2022/05/GHSA-m3p7-qgpp-q63r/GHSA-m3p7-qgpp-q63r.json
index 5aee9652043..43e7b35f82b 100644
--- a/advisories/unreviewed/2022/05/GHSA-m3p7-qgpp-q63r/GHSA-m3p7-qgpp-q63r.json
+++ b/advisories/unreviewed/2022/05/GHSA-m3p7-qgpp-q63r/GHSA-m3p7-qgpp-q63r.json
@@ -7,12 +7,8 @@
"CVE-2007-3629"
],
"details": "SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m4rq-7ghf-vqgw/GHSA-m4rq-7ghf-vqgw.json b/advisories/unreviewed/2022/05/GHSA-m4rq-7ghf-vqgw/GHSA-m4rq-7ghf-vqgw.json
index df69202a528..0b1b3fc9ddb 100644
--- a/advisories/unreviewed/2022/05/GHSA-m4rq-7ghf-vqgw/GHSA-m4rq-7ghf-vqgw.json
+++ b/advisories/unreviewed/2022/05/GHSA-m4rq-7ghf-vqgw/GHSA-m4rq-7ghf-vqgw.json
@@ -7,12 +7,8 @@
"CVE-2007-3350"
],
"details": "AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP INVITE requests.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m6hp-84jq-2xx8/GHSA-m6hp-84jq-2xx8.json b/advisories/unreviewed/2022/05/GHSA-m6hp-84jq-2xx8/GHSA-m6hp-84jq-2xx8.json
index 0c73ada6d7d..e05aabf216c 100644
--- a/advisories/unreviewed/2022/05/GHSA-m6hp-84jq-2xx8/GHSA-m6hp-84jq-2xx8.json
+++ b/advisories/unreviewed/2022/05/GHSA-m6hp-84jq-2xx8/GHSA-m6hp-84jq-2xx8.json
@@ -7,12 +7,8 @@
"CVE-2007-3212"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m7vm-xh92-2mwf/GHSA-m7vm-xh92-2mwf.json b/advisories/unreviewed/2022/05/GHSA-m7vm-xh92-2mwf/GHSA-m7vm-xh92-2mwf.json
index b6c6a74141b..2220387c882 100644
--- a/advisories/unreviewed/2022/05/GHSA-m7vm-xh92-2mwf/GHSA-m7vm-xh92-2mwf.json
+++ b/advisories/unreviewed/2022/05/GHSA-m7vm-xh92-2mwf/GHSA-m7vm-xh92-2mwf.json
@@ -7,12 +7,8 @@
"CVE-2007-3715"
],
"details": "Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-m89h-98qr-7v73/GHSA-m89h-98qr-7v73.json b/advisories/unreviewed/2022/05/GHSA-m89h-98qr-7v73/GHSA-m89h-98qr-7v73.json
index 51eb1903884..0254c92b292 100644
--- a/advisories/unreviewed/2022/05/GHSA-m89h-98qr-7v73/GHSA-m89h-98qr-7v73.json
+++ b/advisories/unreviewed/2022/05/GHSA-m89h-98qr-7v73/GHSA-m89h-98qr-7v73.json
@@ -7,12 +7,8 @@
"CVE-2007-3569"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform parameters to the (b) \"Basic Search page\"; and (8) username parameter when (c) logging on.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-m8c6-398r-jfvx/GHSA-m8c6-398r-jfvx.json b/advisories/unreviewed/2022/05/GHSA-m8c6-398r-jfvx/GHSA-m8c6-398r-jfvx.json
index 843a3fd995d..35985878487 100644
--- a/advisories/unreviewed/2022/05/GHSA-m8c6-398r-jfvx/GHSA-m8c6-398r-jfvx.json
+++ b/advisories/unreviewed/2022/05/GHSA-m8c6-398r-jfvx/GHSA-m8c6-398r-jfvx.json
@@ -7,12 +7,8 @@
"CVE-2007-3376"
],
"details": "Buffer overflow in Apple Safari 3.0.2 on Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long value in the title HTML tag, which triggers the overflow when the user adds the page as a bookmark.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mcxg-xvqr-5m3p/GHSA-mcxg-xvqr-5m3p.json b/advisories/unreviewed/2022/05/GHSA-mcxg-xvqr-5m3p/GHSA-mcxg-xvqr-5m3p.json
index c706564eb39..4976a22e102 100644
--- a/advisories/unreviewed/2022/05/GHSA-mcxg-xvqr-5m3p/GHSA-mcxg-xvqr-5m3p.json
+++ b/advisories/unreviewed/2022/05/GHSA-mcxg-xvqr-5m3p/GHSA-mcxg-xvqr-5m3p.json
@@ -7,12 +7,8 @@
"CVE-2007-3507"
],
"details": "Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mf26-396f-m5wh/GHSA-mf26-396f-m5wh.json b/advisories/unreviewed/2022/05/GHSA-mf26-396f-m5wh/GHSA-mf26-396f-m5wh.json
index 6ffb982efd5..c65573898fd 100644
--- a/advisories/unreviewed/2022/05/GHSA-mf26-396f-m5wh/GHSA-mf26-396f-m5wh.json
+++ b/advisories/unreviewed/2022/05/GHSA-mf26-396f-m5wh/GHSA-mf26-396f-m5wh.json
@@ -7,12 +7,8 @@
"CVE-2007-3541"
],
"details": "Cross-site scripting (XSS) vulnerability in Kurinton sHTTPd 20070408 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mfjv-7924-r28v/GHSA-mfjv-7924-r28v.json b/advisories/unreviewed/2022/05/GHSA-mfjv-7924-r28v/GHSA-mfjv-7924-r28v.json
index 50afe712036..30a3d216d60 100644
--- a/advisories/unreviewed/2022/05/GHSA-mfjv-7924-r28v/GHSA-mfjv-7924-r28v.json
+++ b/advisories/unreviewed/2022/05/GHSA-mfjv-7924-r28v/GHSA-mfjv-7924-r28v.json
@@ -7,12 +7,8 @@
"CVE-2007-3419"
],
"details": "The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat.dat, (6) states.dat, and (7) ages.dat files before saving profile settings of members, which has unknown impact and remote attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mfpf-q6m7-mqrm/GHSA-mfpf-q6m7-mqrm.json b/advisories/unreviewed/2022/05/GHSA-mfpf-q6m7-mqrm/GHSA-mfpf-q6m7-mqrm.json
index ad409831075..4d3736b6656 100644
--- a/advisories/unreviewed/2022/05/GHSA-mfpf-q6m7-mqrm/GHSA-mfpf-q6m7-mqrm.json
+++ b/advisories/unreviewed/2022/05/GHSA-mfpf-q6m7-mqrm/GHSA-mfpf-q6m7-mqrm.json
@@ -7,12 +7,8 @@
"CVE-2007-3359"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in SerWeb 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter to (1) html/load_apu.php or (2) html/mail_prepend.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mhjq-6fqv-c96q/GHSA-mhjq-6fqv-c96q.json b/advisories/unreviewed/2022/05/GHSA-mhjq-6fqv-c96q/GHSA-mhjq-6fqv-c96q.json
index 9941d01bc34..09b3254a6c9 100644
--- a/advisories/unreviewed/2022/05/GHSA-mhjq-6fqv-c96q/GHSA-mhjq-6fqv-c96q.json
+++ b/advisories/unreviewed/2022/05/GHSA-mhjq-6fqv-c96q/GHSA-mhjq-6fqv-c96q.json
@@ -7,12 +7,8 @@
"CVE-2007-3616"
],
"details": "index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mhwx-cv4j-f56v/GHSA-mhwx-cv4j-f56v.json b/advisories/unreviewed/2022/05/GHSA-mhwx-cv4j-f56v/GHSA-mhwx-cv4j-f56v.json
index 9d3c7c4149e..20702172f31 100644
--- a/advisories/unreviewed/2022/05/GHSA-mhwx-cv4j-f56v/GHSA-mhwx-cv4j-f56v.json
+++ b/advisories/unreviewed/2022/05/GHSA-mhwx-cv4j-f56v/GHSA-mhwx-cv4j-f56v.json
@@ -7,12 +7,8 @@
"CVE-2007-3655"
],
"details": "Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-mm2x-5hh8-297w/GHSA-mm2x-5hh8-297w.json b/advisories/unreviewed/2022/05/GHSA-mm2x-5hh8-297w/GHSA-mm2x-5hh8-297w.json
index de584266665..b7b2366a1c1 100644
--- a/advisories/unreviewed/2022/05/GHSA-mm2x-5hh8-297w/GHSA-mm2x-5hh8-297w.json
+++ b/advisories/unreviewed/2022/05/GHSA-mm2x-5hh8-297w/GHSA-mm2x-5hh8-297w.json
@@ -7,12 +7,8 @@
"CVE-2007-3700"
],
"details": "Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mqvh-pw7w-82rr/GHSA-mqvh-pw7w-82rr.json b/advisories/unreviewed/2022/05/GHSA-mqvh-pw7w-82rr/GHSA-mqvh-pw7w-82rr.json
index d9cf9720178..4637c2cbcec 100644
--- a/advisories/unreviewed/2022/05/GHSA-mqvh-pw7w-82rr/GHSA-mqvh-pw7w-82rr.json
+++ b/advisories/unreviewed/2022/05/GHSA-mqvh-pw7w-82rr/GHSA-mqvh-pw7w-82rr.json
@@ -7,12 +7,8 @@
"CVE-2007-3556"
],
"details": "Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mqxh-9jq5-mw9p/GHSA-mqxh-9jq5-mw9p.json b/advisories/unreviewed/2022/05/GHSA-mqxh-9jq5-mw9p/GHSA-mqxh-9jq5-mw9p.json
index ef1dfcc4001..6be42519363 100644
--- a/advisories/unreviewed/2022/05/GHSA-mqxh-9jq5-mw9p/GHSA-mqxh-9jq5-mw9p.json
+++ b/advisories/unreviewed/2022/05/GHSA-mqxh-9jq5-mw9p/GHSA-mqxh-9jq5-mw9p.json
@@ -7,12 +7,8 @@
"CVE-2007-3667"
],
"details": "Unspecified vulnerability in EXCLEXPT.DLL in ActiveReportsExcelReport allows remote attackers to cause a denial of service via the DDRow Height variable.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mrjh-wq58-w8wr/GHSA-mrjh-wq58-w8wr.json b/advisories/unreviewed/2022/05/GHSA-mrjh-wq58-w8wr/GHSA-mrjh-wq58-w8wr.json
index 914f21df69a..fef8c702e37 100644
--- a/advisories/unreviewed/2022/05/GHSA-mrjh-wq58-w8wr/GHSA-mrjh-wq58-w8wr.json
+++ b/advisories/unreviewed/2022/05/GHSA-mrjh-wq58-w8wr/GHSA-mrjh-wq58-w8wr.json
@@ -7,12 +7,8 @@
"CVE-2007-3239"
],
"details": "Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mv47-qh9x-3pwh/GHSA-mv47-qh9x-3pwh.json b/advisories/unreviewed/2022/05/GHSA-mv47-qh9x-3pwh/GHSA-mv47-qh9x-3pwh.json
index 2da5623d48b..6c4626a2861 100644
--- a/advisories/unreviewed/2022/05/GHSA-mv47-qh9x-3pwh/GHSA-mv47-qh9x-3pwh.json
+++ b/advisories/unreviewed/2022/05/GHSA-mv47-qh9x-3pwh/GHSA-mv47-qh9x-3pwh.json
@@ -7,12 +7,8 @@
"CVE-2007-3543"
],
"details": "Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mw7g-gxjp-7rwj/GHSA-mw7g-gxjp-7rwj.json b/advisories/unreviewed/2022/05/GHSA-mw7g-gxjp-7rwj/GHSA-mw7g-gxjp-7rwj.json
index f96dd79e3dd..5eb8d52d618 100644
--- a/advisories/unreviewed/2022/05/GHSA-mw7g-gxjp-7rwj/GHSA-mw7g-gxjp-7rwj.json
+++ b/advisories/unreviewed/2022/05/GHSA-mw7g-gxjp-7rwj/GHSA-mw7g-gxjp-7rwj.json
@@ -7,12 +7,8 @@
"CVE-2007-3796"
],
"details": "The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mwxx-w696-8r5q/GHSA-mwxx-w696-8r5q.json b/advisories/unreviewed/2022/05/GHSA-mwxx-w696-8r5q/GHSA-mwxx-w696-8r5q.json
index 9a0b4b46333..09b2f5b3897 100644
--- a/advisories/unreviewed/2022/05/GHSA-mwxx-w696-8r5q/GHSA-mwxx-w696-8r5q.json
+++ b/advisories/unreviewed/2022/05/GHSA-mwxx-w696-8r5q/GHSA-mwxx-w696-8r5q.json
@@ -7,12 +7,8 @@
"CVE-2007-3345"
],
"details": "Multiple SQL injection vulnerabilities in index.php in PHPAccounts 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) Outgoing_Type_ID, (2) Outgoing_ID, (3) Project_ID, (4) Client_ID, (5) Invoice_ID, or (6) Vendor_ID parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mx2j-qfcf-xcrp/GHSA-mx2j-qfcf-xcrp.json b/advisories/unreviewed/2022/05/GHSA-mx2j-qfcf-xcrp/GHSA-mx2j-qfcf-xcrp.json
index f09b625340c..399a37316de 100644
--- a/advisories/unreviewed/2022/05/GHSA-mx2j-qfcf-xcrp/GHSA-mx2j-qfcf-xcrp.json
+++ b/advisories/unreviewed/2022/05/GHSA-mx2j-qfcf-xcrp/GHSA-mx2j-qfcf-xcrp.json
@@ -7,12 +7,8 @@
"CVE-2007-3924"
],
"details": "Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape; this issue could arise with other protocol handlers in IE.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mx46-hr66-3h8h/GHSA-mx46-hr66-3h8h.json b/advisories/unreviewed/2022/05/GHSA-mx46-hr66-3h8h/GHSA-mx46-hr66-3h8h.json
index b93cf4c8e9a..873e3f6b9d6 100644
--- a/advisories/unreviewed/2022/05/GHSA-mx46-hr66-3h8h/GHSA-mx46-hr66-3h8h.json
+++ b/advisories/unreviewed/2022/05/GHSA-mx46-hr66-3h8h/GHSA-mx46-hr66-3h8h.json
@@ -7,12 +7,8 @@
"CVE-2007-3408"
],
"details": "Multiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involving the use of vulnerable FreeType libraries that contain CVE-2007-2754 and/or CVE-2007-1351.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mx67-p696-pxj5/GHSA-mx67-p696-pxj5.json b/advisories/unreviewed/2022/05/GHSA-mx67-p696-pxj5/GHSA-mx67-p696-pxj5.json
index 7bb5922d426..0f0096876b7 100644
--- a/advisories/unreviewed/2022/05/GHSA-mx67-p696-pxj5/GHSA-mx67-p696-pxj5.json
+++ b/advisories/unreviewed/2022/05/GHSA-mx67-p696-pxj5/GHSA-mx67-p696-pxj5.json
@@ -7,12 +7,8 @@
"CVE-2007-3425"
],
"details": "Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-mx9g-cc8m-w7qh/GHSA-mx9g-cc8m-w7qh.json b/advisories/unreviewed/2022/05/GHSA-mx9g-cc8m-w7qh/GHSA-mx9g-cc8m-w7qh.json
index 51f57464e8d..bece6b56d12 100644
--- a/advisories/unreviewed/2022/05/GHSA-mx9g-cc8m-w7qh/GHSA-mx9g-cc8m-w7qh.json
+++ b/advisories/unreviewed/2022/05/GHSA-mx9g-cc8m-w7qh/GHSA-mx9g-cc8m-w7qh.json
@@ -7,12 +7,8 @@
"CVE-2007-3928"
],
"details": "Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-p24c-446w-cgxm/GHSA-p24c-446w-cgxm.json b/advisories/unreviewed/2022/05/GHSA-p24c-446w-cgxm/GHSA-p24c-446w-cgxm.json
index 5419a99a76a..fc8891763c8 100644
--- a/advisories/unreviewed/2022/05/GHSA-p24c-446w-cgxm/GHSA-p24c-446w-cgxm.json
+++ b/advisories/unreviewed/2022/05/GHSA-p24c-446w-cgxm/GHSA-p24c-446w-cgxm.json
@@ -7,12 +7,8 @@
"CVE-2007-3233"
],
"details": "The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p2rp-pqrc-rw7g/GHSA-p2rp-pqrc-rw7g.json b/advisories/unreviewed/2022/05/GHSA-p2rp-pqrc-rw7g/GHSA-p2rp-pqrc-rw7g.json
index 8a567b2c6dc..442bd7a21c4 100644
--- a/advisories/unreviewed/2022/05/GHSA-p2rp-pqrc-rw7g/GHSA-p2rp-pqrc-rw7g.json
+++ b/advisories/unreviewed/2022/05/GHSA-p2rp-pqrc-rw7g/GHSA-p2rp-pqrc-rw7g.json
@@ -7,12 +7,8 @@
"CVE-2007-3254"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -68,9 +64,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p2rr-82hv-fhx7/GHSA-p2rr-82hv-fhx7.json b/advisories/unreviewed/2022/05/GHSA-p2rr-82hv-fhx7/GHSA-p2rr-82hv-fhx7.json
index fb309d95936..79702f9615b 100644
--- a/advisories/unreviewed/2022/05/GHSA-p2rr-82hv-fhx7/GHSA-p2rr-82hv-fhx7.json
+++ b/advisories/unreviewed/2022/05/GHSA-p2rr-82hv-fhx7/GHSA-p2rr-82hv-fhx7.json
@@ -7,12 +7,8 @@
"CVE-2007-3664"
],
"details": "Multiple unspecified vulnerabilities in Eltima Software RunService ActiveX control (RunService.dll) allow remote attackers to cause a denial of service via certain functions when \"improperly used\", as demonstrated by the AcceptControls subroutine.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p2wf-r9mv-p43x/GHSA-p2wf-r9mv-p43x.json b/advisories/unreviewed/2022/05/GHSA-p2wf-r9mv-p43x/GHSA-p2wf-r9mv-p43x.json
index 9435016325a..264b7c78194 100644
--- a/advisories/unreviewed/2022/05/GHSA-p2wf-r9mv-p43x/GHSA-p2wf-r9mv-p43x.json
+++ b/advisories/unreviewed/2022/05/GHSA-p2wf-r9mv-p43x/GHSA-p2wf-r9mv-p43x.json
@@ -7,12 +7,8 @@
"CVE-2007-3558"
],
"details": "SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p36c-8r99-rg84/GHSA-p36c-8r99-rg84.json b/advisories/unreviewed/2022/05/GHSA-p36c-8r99-rg84/GHSA-p36c-8r99-rg84.json
index 3abfa27f9f4..a465342c237 100644
--- a/advisories/unreviewed/2022/05/GHSA-p36c-8r99-rg84/GHSA-p36c-8r99-rg84.json
+++ b/advisories/unreviewed/2022/05/GHSA-p36c-8r99-rg84/GHSA-p36c-8r99-rg84.json
@@ -7,12 +7,8 @@
"CVE-2007-3745"
],
"details": "The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 contains an unsafe interface that is exposed by JDirect, which allows remote attackers to free arbitrary memory and thereby execute arbitrary code.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p36c-r52p-qmw9/GHSA-p36c-r52p-qmw9.json b/advisories/unreviewed/2022/05/GHSA-p36c-r52p-qmw9/GHSA-p36c-r52p-qmw9.json
index 81dda2c9dfe..fadf245c971 100644
--- a/advisories/unreviewed/2022/05/GHSA-p36c-r52p-qmw9/GHSA-p36c-r52p-qmw9.json
+++ b/advisories/unreviewed/2022/05/GHSA-p36c-r52p-qmw9/GHSA-p36c-r52p-qmw9.json
@@ -7,12 +7,8 @@
"CVE-2007-3916"
],
"details": "The main function in skkdic-expr.c in SKK Tools 1.2 allows local users to overwrite or delete arbitrary files via a symlink attack on a skkdic$PID temporary file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-p3hw-3f33-wxcf/GHSA-p3hw-3f33-wxcf.json b/advisories/unreviewed/2022/05/GHSA-p3hw-3f33-wxcf/GHSA-p3hw-3f33-wxcf.json
index 8fc4f4ba8cc..6dc118dea1c 100644
--- a/advisories/unreviewed/2022/05/GHSA-p3hw-3f33-wxcf/GHSA-p3hw-3f33-wxcf.json
+++ b/advisories/unreviewed/2022/05/GHSA-p3hw-3f33-wxcf/GHSA-p3hw-3f33-wxcf.json
@@ -7,12 +7,8 @@
"CVE-2007-3357"
],
"details": "NetClassifieds Premium Edition does not use encryption for (1) stored passwords or (2) sensitive data, which might allow attackers to obtain information via certain vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p4gx-p8r8-g93m/GHSA-p4gx-p8r8-g93m.json b/advisories/unreviewed/2022/05/GHSA-p4gx-p8r8-g93m/GHSA-p4gx-p8r8-g93m.json
index cf7f2913aed..5e1e52836d1 100644
--- a/advisories/unreviewed/2022/05/GHSA-p4gx-p8r8-g93m/GHSA-p4gx-p8r8-g93m.json
+++ b/advisories/unreviewed/2022/05/GHSA-p4gx-p8r8-g93m/GHSA-p4gx-p8r8-g93m.json
@@ -7,12 +7,8 @@
"CVE-2007-3605"
],
"details": "Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\\SapGui\\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p4jf-wg5g-j577/GHSA-p4jf-wg5g-j577.json b/advisories/unreviewed/2022/05/GHSA-p4jf-wg5g-j577/GHSA-p4jf-wg5g-j577.json
index e4d3b28dcd4..c999792b81f 100644
--- a/advisories/unreviewed/2022/05/GHSA-p4jf-wg5g-j577/GHSA-p4jf-wg5g-j577.json
+++ b/advisories/unreviewed/2022/05/GHSA-p4jf-wg5g-j577/GHSA-p4jf-wg5g-j577.json
@@ -7,12 +7,8 @@
"CVE-2007-3348"
],
"details": "The D-Link DPH-540/DPH-541 phone allows remote attackers to cause a denial of service (device outage) via a malformed SDP header in a SIP INVITE message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p692-fh52-62mr/GHSA-p692-fh52-62mr.json b/advisories/unreviewed/2022/05/GHSA-p692-fh52-62mr/GHSA-p692-fh52-62mr.json
index 2aa38493a38..f53f49911b4 100644
--- a/advisories/unreviewed/2022/05/GHSA-p692-fh52-62mr/GHSA-p692-fh52-62mr.json
+++ b/advisories/unreviewed/2022/05/GHSA-p692-fh52-62mr/GHSA-p692-fh52-62mr.json
@@ -7,12 +7,8 @@
"CVE-2007-3351"
],
"details": "The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a direct crafted INVITE transaction, which causes the phone to transmit many RTP packets.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p6c4-9hc7-j357/GHSA-p6c4-9hc7-j357.json b/advisories/unreviewed/2022/05/GHSA-p6c4-9hc7-j357/GHSA-p6c4-9hc7-j357.json
index 0f4b77d2588..a756a4428a9 100644
--- a/advisories/unreviewed/2022/05/GHSA-p6c4-9hc7-j357/GHSA-p6c4-9hc7-j357.json
+++ b/advisories/unreviewed/2022/05/GHSA-p6c4-9hc7-j357/GHSA-p6c4-9hc7-j357.json
@@ -7,12 +7,8 @@
"CVE-2007-3458"
],
"details": "The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Name Service Caching Daemon (nscd) crash) via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p6fg-g56w-m243/GHSA-p6fg-g56w-m243.json b/advisories/unreviewed/2022/05/GHSA-p6fg-g56w-m243/GHSA-p6fg-g56w-m243.json
index e0a26ed8cc5..c72a708b561 100644
--- a/advisories/unreviewed/2022/05/GHSA-p6fg-g56w-m243/GHSA-p6fg-g56w-m243.json
+++ b/advisories/unreviewed/2022/05/GHSA-p6fg-g56w-m243/GHSA-p6fg-g56w-m243.json
@@ -7,12 +7,8 @@
"CVE-2007-3443"
],
"details": "The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p7w8-837g-24j4/GHSA-p7w8-837g-24j4.json b/advisories/unreviewed/2022/05/GHSA-p7w8-837g-24j4/GHSA-p7w8-837g-24j4.json
index abcde214b5f..35aa7002fea 100644
--- a/advisories/unreviewed/2022/05/GHSA-p7w8-837g-24j4/GHSA-p7w8-837g-24j4.json
+++ b/advisories/unreviewed/2022/05/GHSA-p7w8-837g-24j4/GHSA-p7w8-837g-24j4.json
@@ -7,12 +7,8 @@
"CVE-2007-3512"
],
"details": "Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA \"Extended Header Size\" value in an LZH archive, a different issue than CVE-2007-3375.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p7x8-595f-3whp/GHSA-p7x8-595f-3whp.json b/advisories/unreviewed/2022/05/GHSA-p7x8-595f-3whp/GHSA-p7x8-595f-3whp.json
index 30cef87b9bd..c757177774d 100644
--- a/advisories/unreviewed/2022/05/GHSA-p7x8-595f-3whp/GHSA-p7x8-595f-3whp.json
+++ b/advisories/unreviewed/2022/05/GHSA-p7x8-595f-3whp/GHSA-p7x8-595f-3whp.json
@@ -7,12 +7,8 @@
"CVE-2007-3787"
],
"details": "The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, making a password change from an unattended workstation, or other attacks.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-p95q-73mc-vq93/GHSA-p95q-73mc-vq93.json b/advisories/unreviewed/2022/05/GHSA-p95q-73mc-vq93/GHSA-p95q-73mc-vq93.json
index aae152eb39a..defd30b68b4 100644
--- a/advisories/unreviewed/2022/05/GHSA-p95q-73mc-vq93/GHSA-p95q-73mc-vq93.json
+++ b/advisories/unreviewed/2022/05/GHSA-p95q-73mc-vq93/GHSA-p95q-73mc-vq93.json
@@ -7,12 +7,8 @@
"CVE-2007-3724"
],
"details": "The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to \"interactive\" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pf5r-qf55-xphg/GHSA-pf5r-qf55-xphg.json b/advisories/unreviewed/2022/05/GHSA-pf5r-qf55-xphg/GHSA-pf5r-qf55-xphg.json
index 8b276874ca3..fe5ecb78410 100644
--- a/advisories/unreviewed/2022/05/GHSA-pf5r-qf55-xphg/GHSA-pf5r-qf55-xphg.json
+++ b/advisories/unreviewed/2022/05/GHSA-pf5r-qf55-xphg/GHSA-pf5r-qf55-xphg.json
@@ -7,12 +7,8 @@
"CVE-2007-3422"
],
"details": "The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pgc7-gff7-v95h/GHSA-pgc7-gff7-v95h.json b/advisories/unreviewed/2022/05/GHSA-pgc7-gff7-v95h/GHSA-pgc7-gff7-v95h.json
index 386e3baa290..98d8924294a 100644
--- a/advisories/unreviewed/2022/05/GHSA-pgc7-gff7-v95h/GHSA-pgc7-gff7-v95h.json
+++ b/advisories/unreviewed/2022/05/GHSA-pgc7-gff7-v95h/GHSA-pgc7-gff7-v95h.json
@@ -7,12 +7,8 @@
"CVE-2007-3759"
],
"details": "Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to attacks that the user does not expect.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pggh-jcwv-xxqx/GHSA-pggh-jcwv-xxqx.json b/advisories/unreviewed/2022/05/GHSA-pggh-jcwv-xxqx/GHSA-pggh-jcwv-xxqx.json
index 3b7b284a213..26a259b50f6 100644
--- a/advisories/unreviewed/2022/05/GHSA-pggh-jcwv-xxqx/GHSA-pggh-jcwv-xxqx.json
+++ b/advisories/unreviewed/2022/05/GHSA-pggh-jcwv-xxqx/GHSA-pggh-jcwv-xxqx.json
@@ -7,12 +7,8 @@
"CVE-2007-3659"
],
"details": "Buffer overflow in the doBrowserAction function in FreeWRL 1.19.3 allows local users to execute arbitrary code via a crafted BROWSER environment variable. NOTE: it is not clear whether this issue crosses privilege boundaries.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pj87-rm3h-3wm4/GHSA-pj87-rm3h-3wm4.json b/advisories/unreviewed/2022/05/GHSA-pj87-rm3h-3wm4/GHSA-pj87-rm3h-3wm4.json
index 58406a6571c..c24425cf206 100644
--- a/advisories/unreviewed/2022/05/GHSA-pj87-rm3h-3wm4/GHSA-pj87-rm3h-3wm4.json
+++ b/advisories/unreviewed/2022/05/GHSA-pj87-rm3h-3wm4/GHSA-pj87-rm3h-3wm4.json
@@ -7,12 +7,8 @@
"CVE-2007-3651"
],
"details": "class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-pphx-j7gg-53fm/GHSA-pphx-j7gg-53fm.json b/advisories/unreviewed/2022/05/GHSA-pphx-j7gg-53fm/GHSA-pphx-j7gg-53fm.json
index 15e96bf919b..5b5addf6f5d 100644
--- a/advisories/unreviewed/2022/05/GHSA-pphx-j7gg-53fm/GHSA-pphx-j7gg-53fm.json
+++ b/advisories/unreviewed/2022/05/GHSA-pphx-j7gg-53fm/GHSA-pphx-j7gg-53fm.json
@@ -7,12 +7,8 @@
"CVE-2007-3249"
],
"details": "Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-ppvj-8723-v728/GHSA-ppvj-8723-v728.json b/advisories/unreviewed/2022/05/GHSA-ppvj-8723-v728/GHSA-ppvj-8723-v728.json
index 1cf9ed34391..4e4e20da64f 100644
--- a/advisories/unreviewed/2022/05/GHSA-ppvj-8723-v728/GHSA-ppvj-8723-v728.json
+++ b/advisories/unreviewed/2022/05/GHSA-ppvj-8723-v728/GHSA-ppvj-8723-v728.json
@@ -7,12 +7,8 @@
"CVE-2007-3555"
],
"details": "Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -68,9 +64,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pq79-5jg4-62p2/GHSA-pq79-5jg4-62p2.json b/advisories/unreviewed/2022/05/GHSA-pq79-5jg4-62p2/GHSA-pq79-5jg4-62p2.json
index de830358a28..e0e2c2fd47b 100644
--- a/advisories/unreviewed/2022/05/GHSA-pq79-5jg4-62p2/GHSA-pq79-5jg4-62p2.json
+++ b/advisories/unreviewed/2022/05/GHSA-pq79-5jg4-62p2/GHSA-pq79-5jg4-62p2.json
@@ -7,12 +7,8 @@
"CVE-2007-3920"
],
"details": "GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -80,9 +76,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pqhj-g522-2pc9/GHSA-pqhj-g522-2pc9.json b/advisories/unreviewed/2022/05/GHSA-pqhj-g522-2pc9/GHSA-pqhj-g522-2pc9.json
index b4c030fb09c..5b1fad91572 100644
--- a/advisories/unreviewed/2022/05/GHSA-pqhj-g522-2pc9/GHSA-pqhj-g522-2pc9.json
+++ b/advisories/unreviewed/2022/05/GHSA-pqhj-g522-2pc9/GHSA-pqhj-g522-2pc9.json
@@ -7,12 +7,8 @@
"CVE-2007-3551"
],
"details": "Buffer overflow in bbs100 before 3.2 allows remote attackers to cause a denial of service (crash) by attempting to login as the Guest user when another Guest user is already logged in, possibly related to the state_login_prompt function in state_login.c.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-pqx5-mp9c-hm3r/GHSA-pqx5-mp9c-hm3r.json b/advisories/unreviewed/2022/05/GHSA-pqx5-mp9c-hm3r/GHSA-pqx5-mp9c-hm3r.json
index 140d12bcdcf..0063384914f 100644
--- a/advisories/unreviewed/2022/05/GHSA-pqx5-mp9c-hm3r/GHSA-pqx5-mp9c-hm3r.json
+++ b/advisories/unreviewed/2022/05/GHSA-pqx5-mp9c-hm3r/GHSA-pqx5-mp9c-hm3r.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-pqxp-mpqr-m4gq/GHSA-pqxp-mpqr-m4gq.json b/advisories/unreviewed/2022/05/GHSA-pqxp-mpqr-m4gq/GHSA-pqxp-mpqr-m4gq.json
index e0b064c5ad7..6670fdc174c 100644
--- a/advisories/unreviewed/2022/05/GHSA-pqxp-mpqr-m4gq/GHSA-pqxp-mpqr-m4gq.json
+++ b/advisories/unreviewed/2022/05/GHSA-pqxp-mpqr-m4gq/GHSA-pqxp-mpqr-m4gq.json
@@ -7,12 +7,8 @@
"CVE-2007-3247"
],
"details": "SQL injection vulnerability in VirtueMart before 1.0.11 allows remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-prv3-w8fc-w6j2/GHSA-prv3-w8fc-w6j2.json b/advisories/unreviewed/2022/05/GHSA-prv3-w8fc-w6j2/GHSA-prv3-w8fc-w6j2.json
index 26e6008e065..a2173ca4fb2 100644
--- a/advisories/unreviewed/2022/05/GHSA-prv3-w8fc-w6j2/GHSA-prv3-w8fc-w6j2.json
+++ b/advisories/unreviewed/2022/05/GHSA-prv3-w8fc-w6j2/GHSA-prv3-w8fc-w6j2.json
@@ -7,12 +7,8 @@
"CVE-2007-3368"
],
"details": "Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pwm5-359r-f8qp/GHSA-pwm5-359r-f8qp.json b/advisories/unreviewed/2022/05/GHSA-pwm5-359r-f8qp/GHSA-pwm5-359r-f8qp.json
index 4367ad564cf..7ad861b30b3 100644
--- a/advisories/unreviewed/2022/05/GHSA-pwm5-359r-f8qp/GHSA-pwm5-359r-f8qp.json
+++ b/advisories/unreviewed/2022/05/GHSA-pwm5-359r-f8qp/GHSA-pwm5-359r-f8qp.json
@@ -7,12 +7,8 @@
"CVE-2007-3464"
],
"details": "Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, does not require entry of the old password when changing the admin password, which might allow attackers to gain privileges by conducting a CSRF attack, making a password change on an unattended workstation, or other vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-pwp5-jmpj-2v4w/GHSA-pwp5-jmpj-2v4w.json b/advisories/unreviewed/2022/05/GHSA-pwp5-jmpj-2v4w/GHSA-pwp5-jmpj-2v4w.json
index 42f2d4e595a..7bcae8b9d1b 100644
--- a/advisories/unreviewed/2022/05/GHSA-pwp5-jmpj-2v4w/GHSA-pwp5-jmpj-2v4w.json
+++ b/advisories/unreviewed/2022/05/GHSA-pwp5-jmpj-2v4w/GHSA-pwp5-jmpj-2v4w.json
@@ -7,12 +7,8 @@
"CVE-2007-3240"
],
"details": "Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q394-4rmx-q232/GHSA-q394-4rmx-q232.json b/advisories/unreviewed/2022/05/GHSA-q394-4rmx-q232/GHSA-q394-4rmx-q232.json
index 0d8102bf65c..e541de4b043 100644
--- a/advisories/unreviewed/2022/05/GHSA-q394-4rmx-q232/GHSA-q394-4rmx-q232.json
+++ b/advisories/unreviewed/2022/05/GHSA-q394-4rmx-q232/GHSA-q394-4rmx-q232.json
@@ -7,12 +7,8 @@
"CVE-2017-18553"
],
"details": "The ad-buttons plugin before 2.3.2 for WordPress has XSS.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q3v2-w8fm-m2fr/GHSA-q3v2-w8fm-m2fr.json b/advisories/unreviewed/2022/05/GHSA-q3v2-w8fm-m2fr/GHSA-q3v2-w8fm-m2fr.json
index a051c5a9538..10a4e90058f 100644
--- a/advisories/unreviewed/2022/05/GHSA-q3v2-w8fm-m2fr/GHSA-q3v2-w8fm-m2fr.json
+++ b/advisories/unreviewed/2022/05/GHSA-q3v2-w8fm-m2fr/GHSA-q3v2-w8fm-m2fr.json
@@ -7,12 +7,8 @@
"CVE-2007-3623"
],
"details": "Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q534-gvjc-fpgw/GHSA-q534-gvjc-fpgw.json b/advisories/unreviewed/2022/05/GHSA-q534-gvjc-fpgw/GHSA-q534-gvjc-fpgw.json
index 554706a5a89..b7ad878ff7e 100644
--- a/advisories/unreviewed/2022/05/GHSA-q534-gvjc-fpgw/GHSA-q534-gvjc-fpgw.json
+++ b/advisories/unreviewed/2022/05/GHSA-q534-gvjc-fpgw/GHSA-q534-gvjc-fpgw.json
@@ -7,12 +7,8 @@
"CVE-2007-3694"
],
"details": "Cross-site scripting (XSS) vulnerability in login.php in Miro Project Broadcast Machine 0.9.9.9 allows remote attackers to inject arbitrary web script or HTML via the username parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-q5vg-xwm5-j6v4/GHSA-q5vg-xwm5-j6v4.json b/advisories/unreviewed/2022/05/GHSA-q5vg-xwm5-j6v4/GHSA-q5vg-xwm5-j6v4.json
index 94c36d36273..4938a44f3dd 100644
--- a/advisories/unreviewed/2022/05/GHSA-q5vg-xwm5-j6v4/GHSA-q5vg-xwm5-j6v4.json
+++ b/advisories/unreviewed/2022/05/GHSA-q5vg-xwm5-j6v4/GHSA-q5vg-xwm5-j6v4.json
@@ -7,12 +7,8 @@
"CVE-2007-3427"
],
"details": "SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q77q-qh4p-mr23/GHSA-q77q-qh4p-mr23.json b/advisories/unreviewed/2022/05/GHSA-q77q-qh4p-mr23/GHSA-q77q-qh4p-mr23.json
index 443ee8747f5..36516c74dd5 100644
--- a/advisories/unreviewed/2022/05/GHSA-q77q-qh4p-mr23/GHSA-q77q-qh4p-mr23.json
+++ b/advisories/unreviewed/2022/05/GHSA-q77q-qh4p-mr23/GHSA-q77q-qh4p-mr23.json
@@ -7,12 +7,8 @@
"CVE-2007-3608"
],
"details": "Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q782-hgfx-w6cc/GHSA-q782-hgfx-w6cc.json b/advisories/unreviewed/2022/05/GHSA-q782-hgfx-w6cc/GHSA-q782-hgfx-w6cc.json
index 287185f48fc..acb0a1d777c 100644
--- a/advisories/unreviewed/2022/05/GHSA-q782-hgfx-w6cc/GHSA-q782-hgfx-w6cc.json
+++ b/advisories/unreviewed/2022/05/GHSA-q782-hgfx-w6cc/GHSA-q782-hgfx-w6cc.json
@@ -7,12 +7,8 @@
"CVE-2007-3336"
],
"details": "Multiple \"pointer overwrite\" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -76,9 +72,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q79v-qx3j-83xp/GHSA-q79v-qx3j-83xp.json b/advisories/unreviewed/2022/05/GHSA-q79v-qx3j-83xp/GHSA-q79v-qx3j-83xp.json
index 4d867c8b0d7..8e122998669 100644
--- a/advisories/unreviewed/2022/05/GHSA-q79v-qx3j-83xp/GHSA-q79v-qx3j-83xp.json
+++ b/advisories/unreviewed/2022/05/GHSA-q79v-qx3j-83xp/GHSA-q79v-qx3j-83xp.json
@@ -7,12 +7,8 @@
"CVE-2007-3461"
],
"details": "SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q7wr-mqfr-3mcx/GHSA-q7wr-mqfr-3mcx.json b/advisories/unreviewed/2022/05/GHSA-q7wr-mqfr-3mcx/GHSA-q7wr-mqfr-3mcx.json
index 3d1f81e688d..b1985c16821 100644
--- a/advisories/unreviewed/2022/05/GHSA-q7wr-mqfr-3mcx/GHSA-q7wr-mqfr-3mcx.json
+++ b/advisories/unreviewed/2022/05/GHSA-q7wr-mqfr-3mcx/GHSA-q7wr-mqfr-3mcx.json
@@ -7,12 +7,8 @@
"CVE-2007-3612"
],
"details": "Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q837-frm9-4v72/GHSA-q837-frm9-4v72.json b/advisories/unreviewed/2022/05/GHSA-q837-frm9-4v72/GHSA-q837-frm9-4v72.json
index 18e05ef3917..1012aaac14f 100644
--- a/advisories/unreviewed/2022/05/GHSA-q837-frm9-4v72/GHSA-q837-frm9-4v72.json
+++ b/advisories/unreviewed/2022/05/GHSA-q837-frm9-4v72/GHSA-q837-frm9-4v72.json
@@ -7,12 +7,8 @@
"CVE-2007-3327"
],
"details": "httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q89m-fvww-2r72/GHSA-q89m-fvww-2r72.json b/advisories/unreviewed/2022/05/GHSA-q89m-fvww-2r72/GHSA-q89m-fvww-2r72.json
index ed3c2386d89..c6c6b9edf63 100644
--- a/advisories/unreviewed/2022/05/GHSA-q89m-fvww-2r72/GHSA-q89m-fvww-2r72.json
+++ b/advisories/unreviewed/2022/05/GHSA-q89m-fvww-2r72/GHSA-q89m-fvww-2r72.json
@@ -7,12 +7,8 @@
"CVE-2007-3587"
],
"details": "MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q969-45px-2vhh/GHSA-q969-45px-2vhh.json b/advisories/unreviewed/2022/05/GHSA-q969-45px-2vhh/GHSA-q969-45px-2vhh.json
index 7c647d15005..676962e55f7 100644
--- a/advisories/unreviewed/2022/05/GHSA-q969-45px-2vhh/GHSA-q969-45px-2vhh.json
+++ b/advisories/unreviewed/2022/05/GHSA-q969-45px-2vhh/GHSA-q969-45px-2vhh.json
@@ -7,12 +7,8 @@
"CVE-2007-3560"
],
"details": "Multiple unspecified vulnerabilities in Esqlanelapse before 2.6 have unknown impact and attack vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q98q-gxvr-67p2/GHSA-q98q-gxvr-67p2.json b/advisories/unreviewed/2022/05/GHSA-q98q-gxvr-67p2/GHSA-q98q-gxvr-67p2.json
index 51d732b2106..795de7be65f 100644
--- a/advisories/unreviewed/2022/05/GHSA-q98q-gxvr-67p2/GHSA-q98q-gxvr-67p2.json
+++ b/advisories/unreviewed/2022/05/GHSA-q98q-gxvr-67p2/GHSA-q98q-gxvr-67p2.json
@@ -7,12 +7,8 @@
"CVE-2007-3236"
],
"details": "PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-q9wq-fgjg-qwhp/GHSA-q9wq-fgjg-qwhp.json b/advisories/unreviewed/2022/05/GHSA-q9wq-fgjg-qwhp/GHSA-q9wq-fgjg-qwhp.json
index 79fcbc39546..1ff6ea5c928 100644
--- a/advisories/unreviewed/2022/05/GHSA-q9wq-fgjg-qwhp/GHSA-q9wq-fgjg-qwhp.json
+++ b/advisories/unreviewed/2022/05/GHSA-q9wq-fgjg-qwhp/GHSA-q9wq-fgjg-qwhp.json
@@ -7,12 +7,8 @@
"CVE-2007-3532"
],
"details": "NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvidia* device files with insecure permissions, which allows local users to modify video card settings, cause a denial of service (crash or physical video card damage), and obtain sensitive information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qf8q-r97f-f4p9/GHSA-qf8q-r97f-f4p9.json b/advisories/unreviewed/2022/05/GHSA-qf8q-r97f-f4p9/GHSA-qf8q-r97f-f4p9.json
index d550df99fba..a35c297bb00 100644
--- a/advisories/unreviewed/2022/05/GHSA-qf8q-r97f-f4p9/GHSA-qf8q-r97f-f4p9.json
+++ b/advisories/unreviewed/2022/05/GHSA-qf8q-r97f-f4p9/GHSA-qf8q-r97f-f4p9.json
@@ -7,12 +7,8 @@
"CVE-2007-3316"
],
"details": "Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -84,9 +80,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qj4x-qcmg-qwfr/GHSA-qj4x-qcmg-qwfr.json b/advisories/unreviewed/2022/05/GHSA-qj4x-qcmg-qwfr/GHSA-qj4x-qcmg-qwfr.json
index 575ab99a5a0..42d46714a8f 100644
--- a/advisories/unreviewed/2022/05/GHSA-qj4x-qcmg-qwfr/GHSA-qj4x-qcmg-qwfr.json
+++ b/advisories/unreviewed/2022/05/GHSA-qj4x-qcmg-qwfr/GHSA-qj4x-qcmg-qwfr.json
@@ -7,12 +7,8 @@
"CVE-2007-3513"
],
"details": "The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption).",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -112,9 +108,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qjf7-69w3-45mh/GHSA-qjf7-69w3-45mh.json b/advisories/unreviewed/2022/05/GHSA-qjf7-69w3-45mh/GHSA-qjf7-69w3-45mh.json
index eadd409fc62..4c6a1059427 100644
--- a/advisories/unreviewed/2022/05/GHSA-qjf7-69w3-45mh/GHSA-qjf7-69w3-45mh.json
+++ b/advisories/unreviewed/2022/05/GHSA-qjf7-69w3-45mh/GHSA-qjf7-69w3-45mh.json
@@ -7,12 +7,8 @@
"CVE-2007-3216"
],
"details": "Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2) rxsSetUserInfo, (3) rxsRenameUser, (4) rxsSetMessageLogSettings, (5) rxsExportData, (6) rxsSetServerOptions, (7) rxsRenameFile, (8) rxsACIManageSend, (9) rxsExportUser, (10) rxsImportUser, (11) rxsMoveUserData, (12) rxsUseLicenseIni, (13) rxsLicGetSiteId, (14) rxsGetLogFileNames, (15) rxsGetBackupLog, (16) rxsBackupComplete, (17) rxsSetDataProtectionSecurityData, (18) rxsSetDefaultConfigName, (19) rxsGetMessageLogSettings, (20) rxsHWDiskGetTotal, (21) rxsHWDiskGetFree, (22) rxsGetSubDirs, (23) rxsGetServerDBPathName, (24) rxsSetServerOptions, (25) rxsDeleteFile, (26) rxsACIManageSend, (27) rxcReadBackupSetList, (28) rxcWriteConfigInfo, (29) rxcSetAssetManagement, (30) rxcWriteFileListForRestore, (31) rxcReadSaveSetProfile, (32) rxcInitSaveSetProfile, (33) rxcAddSaveSetNextAppList, (34) rxcAddSaveSetNextFilesPathList, (35) rxcAddNextBackupSetIncWildCard, (36) rxcGetRevisions, (37) rxrAddMovedUser, (38) rxrSetClientVersion, or (39) rxsSetDataGrowthScheduleAndFilter commands.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-qmhw-3h9q-qm39/GHSA-qmhw-3h9q-qm39.json b/advisories/unreviewed/2022/05/GHSA-qmhw-3h9q-qm39/GHSA-qmhw-3h9q-qm39.json
index 106984907dc..7e89d098a47 100644
--- a/advisories/unreviewed/2022/05/GHSA-qmhw-3h9q-qm39/GHSA-qmhw-3h9q-qm39.json
+++ b/advisories/unreviewed/2022/05/GHSA-qmhw-3h9q-qm39/GHSA-qmhw-3h9q-qm39.json
@@ -7,12 +7,8 @@
"CVE-2007-3248"
],
"details": "Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (system crash) via certain network traffic.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qmjp-82xf-5f6p/GHSA-qmjp-82xf-5f6p.json b/advisories/unreviewed/2022/05/GHSA-qmjp-82xf-5f6p/GHSA-qmjp-82xf-5f6p.json
index 77695cdad20..4ec989ded93 100644
--- a/advisories/unreviewed/2022/05/GHSA-qmjp-82xf-5f6p/GHSA-qmjp-82xf-5f6p.json
+++ b/advisories/unreviewed/2022/05/GHSA-qmjp-82xf-5f6p/GHSA-qmjp-82xf-5f6p.json
@@ -7,12 +7,8 @@
"CVE-2007-3413"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in bosDataGrid 2.50 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GridSearch, (2) gsearch, or (3) ParentID parameter to an unspecified component.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qqgj-8qjg-m293/GHSA-qqgj-8qjg-m293.json b/advisories/unreviewed/2022/05/GHSA-qqgj-8qjg-m293/GHSA-qqgj-8qjg-m293.json
index 5122ba1faa8..55fe8044d95 100644
--- a/advisories/unreviewed/2022/05/GHSA-qqgj-8qjg-m293/GHSA-qqgj-8qjg-m293.json
+++ b/advisories/unreviewed/2022/05/GHSA-qqgj-8qjg-m293/GHSA-qqgj-8qjg-m293.json
@@ -7,12 +7,8 @@
"CVE-2007-3518"
],
"details": "SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qqrx-qxhr-rv75/GHSA-qqrx-qxhr-rv75.json b/advisories/unreviewed/2022/05/GHSA-qqrx-qxhr-rv75/GHSA-qqrx-qxhr-rv75.json
index f544d0117d3..6cdd95f4e35 100644
--- a/advisories/unreviewed/2022/05/GHSA-qqrx-qxhr-rv75/GHSA-qqrx-qxhr-rv75.json
+++ b/advisories/unreviewed/2022/05/GHSA-qqrx-qxhr-rv75/GHSA-qqrx-qxhr-rv75.json
@@ -7,12 +7,8 @@
"CVE-2007-3750"
],
"details": "Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via crafted Sample Table Sample Descriptor (STSD) atoms in a movie file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-qr8g-f6qc-9j77/GHSA-qr8g-f6qc-9j77.json b/advisories/unreviewed/2022/05/GHSA-qr8g-f6qc-9j77/GHSA-qr8g-f6qc-9j77.json
index 94fda5c0bc9..e580ca9fd38 100644
--- a/advisories/unreviewed/2022/05/GHSA-qr8g-f6qc-9j77/GHSA-qr8g-f6qc-9j77.json
+++ b/advisories/unreviewed/2022/05/GHSA-qr8g-f6qc-9j77/GHSA-qr8g-f6qc-9j77.json
@@ -7,12 +7,8 @@
"CVE-2007-3819"
],
"details": "Opera 9.21 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -72,9 +68,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qrr5-mx6f-rh9m/GHSA-qrr5-mx6f-rh9m.json b/advisories/unreviewed/2022/05/GHSA-qrr5-mx6f-rh9m/GHSA-qrr5-mx6f-rh9m.json
index cb0b6c7ec17..e2930cf020f 100644
--- a/advisories/unreviewed/2022/05/GHSA-qrr5-mx6f-rh9m/GHSA-qrr5-mx6f-rh9m.json
+++ b/advisories/unreviewed/2022/05/GHSA-qrr5-mx6f-rh9m/GHSA-qrr5-mx6f-rh9m.json
@@ -7,12 +7,8 @@
"CVE-2007-3640"
],
"details": "Adobe Integrated Runtime (AIR, aka Apollo) allows context-dependent attackers to modify arbitrary files within an executing .air file (compiled AIR application) and perform cross-site scripting (XSS) attacks, as demonstrated by an application that modifies an HTML file inside itself via JavaScript that uses an APPEND open operation and the writeUTFBytes function. NOTE: this may be an intended consequence of the AIR permission model; if so, then perhaps this issue should not be included in CVE.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qv35-fg75-f39j/GHSA-qv35-fg75-f39j.json b/advisories/unreviewed/2022/05/GHSA-qv35-fg75-f39j/GHSA-qv35-fg75-f39j.json
index 2ef416ab9f3..1fe6cb7c8a7 100644
--- a/advisories/unreviewed/2022/05/GHSA-qv35-fg75-f39j/GHSA-qv35-fg75-f39j.json
+++ b/advisories/unreviewed/2022/05/GHSA-qv35-fg75-f39j/GHSA-qv35-fg75-f39j.json
@@ -7,12 +7,8 @@
"CVE-2007-3537"
],
"details": "IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qvf8-hcv3-phxr/GHSA-qvf8-hcv3-phxr.json b/advisories/unreviewed/2022/05/GHSA-qvf8-hcv3-phxr/GHSA-qvf8-hcv3-phxr.json
index caa601b9fe4..f41713921d3 100644
--- a/advisories/unreviewed/2022/05/GHSA-qvf8-hcv3-phxr/GHSA-qvf8-hcv3-phxr.json
+++ b/advisories/unreviewed/2022/05/GHSA-qvf8-hcv3-phxr/GHSA-qvf8-hcv3-phxr.json
@@ -7,12 +7,8 @@
"CVE-2007-3342"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Movable Type (MT) before 3.34 allow remote attackers to inject arbitrary web script or HTML via comments that have (1) a malformed SGML numeric character reference with a '\\0' (0x00) character in a javascript: URI or (2) an attribute in an element that lacks the '>' character at the end of the start tag, a different vulnerability than CVE-2007-0231.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qvvm-3vx3-4pcg/GHSA-qvvm-3vx3-4pcg.json b/advisories/unreviewed/2022/05/GHSA-qvvm-3vx3-4pcg/GHSA-qvvm-3vx3-4pcg.json
index e1f7a179db3..749aa2c09f8 100644
--- a/advisories/unreviewed/2022/05/GHSA-qvvm-3vx3-4pcg/GHSA-qvvm-3vx3-4pcg.json
+++ b/advisories/unreviewed/2022/05/GHSA-qvvm-3vx3-4pcg/GHSA-qvvm-3vx3-4pcg.json
@@ -7,12 +7,8 @@
"CVE-2007-3788"
],
"details": "The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qwgm-xvrp-g7gq/GHSA-qwgm-xvrp-g7gq.json b/advisories/unreviewed/2022/05/GHSA-qwgm-xvrp-g7gq/GHSA-qwgm-xvrp-g7gq.json
index 432abe4a4ec..8b06edbe993 100644
--- a/advisories/unreviewed/2022/05/GHSA-qwgm-xvrp-g7gq/GHSA-qwgm-xvrp-g7gq.json
+++ b/advisories/unreviewed/2022/05/GHSA-qwgm-xvrp-g7gq/GHSA-qwgm-xvrp-g7gq.json
@@ -7,12 +7,8 @@
"CVE-2007-3810"
],
"details": "SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qwrg-9vx9-7fhm/GHSA-qwrg-9vx9-7fhm.json b/advisories/unreviewed/2022/05/GHSA-qwrg-9vx9-7fhm/GHSA-qwrg-9vx9-7fhm.json
index c6ce101c55a..888eca3e7e7 100644
--- a/advisories/unreviewed/2022/05/GHSA-qwrg-9vx9-7fhm/GHSA-qwrg-9vx9-7fhm.json
+++ b/advisories/unreviewed/2022/05/GHSA-qwrg-9vx9-7fhm/GHSA-qwrg-9vx9-7fhm.json
@@ -7,12 +7,8 @@
"CVE-2007-3259"
],
"details": "Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qx67-wv8v-cqm3/GHSA-qx67-wv8v-cqm3.json b/advisories/unreviewed/2022/05/GHSA-qx67-wv8v-cqm3/GHSA-qx67-wv8v-cqm3.json
index eae67482d45..b8e54862eb2 100644
--- a/advisories/unreviewed/2022/05/GHSA-qx67-wv8v-cqm3/GHSA-qx67-wv8v-cqm3.json
+++ b/advisories/unreviewed/2022/05/GHSA-qx67-wv8v-cqm3/GHSA-qx67-wv8v-cqm3.json
@@ -7,12 +7,8 @@
"CVE-2007-3571"
],
"details": "The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-qxqw-pch2-xr57/GHSA-qxqw-pch2-xr57.json b/advisories/unreviewed/2022/05/GHSA-qxqw-pch2-xr57/GHSA-qxqw-pch2-xr57.json
index 311e5b345e2..cfc710b8e6d 100644
--- a/advisories/unreviewed/2022/05/GHSA-qxqw-pch2-xr57/GHSA-qxqw-pch2-xr57.json
+++ b/advisories/unreviewed/2022/05/GHSA-qxqw-pch2-xr57/GHSA-qxqw-pch2-xr57.json
@@ -7,12 +7,8 @@
"CVE-2007-3635"
],
"details": "Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2.1 for Squirrelmail might allow \"local authenticated users\" to inject certain commands via unspecified vectors. NOTE: this might overlap CVE-2005-1924, CVE-2006-4169, or CVE-2007-3634.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r225-x7hq-44cf/GHSA-r225-x7hq-44cf.json b/advisories/unreviewed/2022/05/GHSA-r225-x7hq-44cf/GHSA-r225-x7hq-44cf.json
index fa74abf739f..3d0b758bd00 100644
--- a/advisories/unreviewed/2022/05/GHSA-r225-x7hq-44cf/GHSA-r225-x7hq-44cf.json
+++ b/advisories/unreviewed/2022/05/GHSA-r225-x7hq-44cf/GHSA-r225-x7hq-44cf.json
@@ -7,12 +7,8 @@
"CVE-2007-3958"
],
"details": "Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r329-wqv5-772f/GHSA-r329-wqv5-772f.json b/advisories/unreviewed/2022/05/GHSA-r329-wqv5-772f/GHSA-r329-wqv5-772f.json
index 5580bfa0a9c..14970eb10d4 100644
--- a/advisories/unreviewed/2022/05/GHSA-r329-wqv5-772f/GHSA-r329-wqv5-772f.json
+++ b/advisories/unreviewed/2022/05/GHSA-r329-wqv5-772f/GHSA-r329-wqv5-772f.json
@@ -7,12 +7,8 @@
"CVE-2007-3311"
],
"details": "SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r3rh-93q9-6h72/GHSA-r3rh-93q9-6h72.json b/advisories/unreviewed/2022/05/GHSA-r3rh-93q9-6h72/GHSA-r3rh-93q9-6h72.json
index 0bc1b20fe9d..f3af8c72d65 100644
--- a/advisories/unreviewed/2022/05/GHSA-r3rh-93q9-6h72/GHSA-r3rh-93q9-6h72.json
+++ b/advisories/unreviewed/2022/05/GHSA-r3rh-93q9-6h72/GHSA-r3rh-93q9-6h72.json
@@ -7,12 +7,8 @@
"CVE-2007-3780"
],
"details": "MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-r554-5qhr-m45g/GHSA-r554-5qhr-m45g.json b/advisories/unreviewed/2022/05/GHSA-r554-5qhr-m45g/GHSA-r554-5qhr-m45g.json
index 3a9abbe1471..98932e24f19 100644
--- a/advisories/unreviewed/2022/05/GHSA-r554-5qhr-m45g/GHSA-r554-5qhr-m45g.json
+++ b/advisories/unreviewed/2022/05/GHSA-r554-5qhr-m45g/GHSA-r554-5qhr-m45g.json
@@ -7,12 +7,8 @@
"CVE-2007-3434"
],
"details": "index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r664-w4qh-gcvh/GHSA-r664-w4qh-gcvh.json b/advisories/unreviewed/2022/05/GHSA-r664-w4qh-gcvh/GHSA-r664-w4qh-gcvh.json
index 76b275bf04f..5a0ddfeea6d 100644
--- a/advisories/unreviewed/2022/05/GHSA-r664-w4qh-gcvh/GHSA-r664-w4qh-gcvh.json
+++ b/advisories/unreviewed/2022/05/GHSA-r664-w4qh-gcvh/GHSA-r664-w4qh-gcvh.json
@@ -7,12 +7,8 @@
"CVE-2007-3809"
],
"details": "Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory.php, and other unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r6q3-8283-3fw2/GHSA-r6q3-8283-3fw2.json b/advisories/unreviewed/2022/05/GHSA-r6q3-8283-3fw2/GHSA-r6q3-8283-3fw2.json
index d3303b5ad32..211cd679178 100644
--- a/advisories/unreviewed/2022/05/GHSA-r6q3-8283-3fw2/GHSA-r6q3-8283-3fw2.json
+++ b/advisories/unreviewed/2022/05/GHSA-r6q3-8283-3fw2/GHSA-r6q3-8283-3fw2.json
@@ -7,12 +7,8 @@
"CVE-2007-3747"
],
"details": "The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r7r5-3464-pm26/GHSA-r7r5-3464-pm26.json b/advisories/unreviewed/2022/05/GHSA-r7r5-3464-pm26/GHSA-r7r5-3464-pm26.json
index 4cd495399c3..66cffb7fcdf 100644
--- a/advisories/unreviewed/2022/05/GHSA-r7r5-3464-pm26/GHSA-r7r5-3464-pm26.json
+++ b/advisories/unreviewed/2022/05/GHSA-r7r5-3464-pm26/GHSA-r7r5-3464-pm26.json
@@ -7,12 +7,8 @@
"CVE-2007-3501"
],
"details": "Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r96g-59m6-x7mf/GHSA-r96g-59m6-x7mf.json b/advisories/unreviewed/2022/05/GHSA-r96g-59m6-x7mf/GHSA-r96g-59m6-x7mf.json
index 119ffc8eb35..baa318fd47c 100644
--- a/advisories/unreviewed/2022/05/GHSA-r96g-59m6-x7mf/GHSA-r96g-59m6-x7mf.json
+++ b/advisories/unreviewed/2022/05/GHSA-r96g-59m6-x7mf/GHSA-r96g-59m6-x7mf.json
@@ -7,12 +7,8 @@
"CVE-2007-3465"
],
"details": "Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, has a certain default password.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-r9q5-397x-m26x/GHSA-r9q5-397x-m26x.json b/advisories/unreviewed/2022/05/GHSA-r9q5-397x-m26x/GHSA-r9q5-397x-m26x.json
index 79fcd61a753..9c6cd70d3b1 100644
--- a/advisories/unreviewed/2022/05/GHSA-r9q5-397x-m26x/GHSA-r9q5-397x-m26x.json
+++ b/advisories/unreviewed/2022/05/GHSA-r9q5-397x-m26x/GHSA-r9q5-397x-m26x.json
@@ -7,12 +7,8 @@
"CVE-2007-3226"
],
"details": "Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rcgr-v82x-83h7/GHSA-rcgr-v82x-83h7.json b/advisories/unreviewed/2022/05/GHSA-rcgr-v82x-83h7/GHSA-rcgr-v82x-83h7.json
index 455f593dceb..3bbb2d51251 100644
--- a/advisories/unreviewed/2022/05/GHSA-rcgr-v82x-83h7/GHSA-rcgr-v82x-83h7.json
+++ b/advisories/unreviewed/2022/05/GHSA-rcgr-v82x-83h7/GHSA-rcgr-v82x-83h7.json
@@ -7,12 +7,8 @@
"CVE-2007-3495"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in the SAP Internet Communication Framework (BC-MID-ICF) in the SAP Basis component 700 before SP12, and 640 before SP20, allow remote attackers to inject arbitrary web script or HTML via certain parameters associated with the default login error page.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rf2g-fg3p-24pj/GHSA-rf2g-fg3p-24pj.json b/advisories/unreviewed/2022/05/GHSA-rf2g-fg3p-24pj/GHSA-rf2g-fg3p-24pj.json
index 6908d3a11e9..b44ef613a55 100644
--- a/advisories/unreviewed/2022/05/GHSA-rf2g-fg3p-24pj/GHSA-rf2g-fg3p-24pj.json
+++ b/advisories/unreviewed/2022/05/GHSA-rf2g-fg3p-24pj/GHSA-rf2g-fg3p-24pj.json
@@ -7,12 +7,8 @@
"CVE-2007-3582"
],
"details": "SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rfrf-3h83-9qr2/GHSA-rfrf-3h83-9qr2.json b/advisories/unreviewed/2022/05/GHSA-rfrf-3h83-9qr2/GHSA-rfrf-3h83-9qr2.json
index 80bb989e657..ce41e1332e9 100644
--- a/advisories/unreviewed/2022/05/GHSA-rfrf-3h83-9qr2/GHSA-rfrf-3h83-9qr2.json
+++ b/advisories/unreviewed/2022/05/GHSA-rfrf-3h83-9qr2/GHSA-rfrf-3h83-9qr2.json
@@ -7,12 +7,8 @@
"CVE-2007-3803"
],
"details": "The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rgcp-q563-45f3/GHSA-rgcp-q563-45f3.json b/advisories/unreviewed/2022/05/GHSA-rgcp-q563-45f3/GHSA-rgcp-q563-45f3.json
index 1091e0bf170..bfb68bfd73f 100644
--- a/advisories/unreviewed/2022/05/GHSA-rgcp-q563-45f3/GHSA-rgcp-q563-45f3.json
+++ b/advisories/unreviewed/2022/05/GHSA-rgcp-q563-45f3/GHSA-rgcp-q563-45f3.json
@@ -7,12 +7,8 @@
"CVE-2007-3483"
],
"details": "Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of arbitrary third-party applications on BlackBerry devices, which might facilitate loading of malware.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rgw4-fq4j-g37q/GHSA-rgw4-fq4j-g37q.json b/advisories/unreviewed/2022/05/GHSA-rgw4-fq4j-g37q/GHSA-rgw4-fq4j-g37q.json
index 07047f40bf2..a471ec647d6 100644
--- a/advisories/unreviewed/2022/05/GHSA-rgw4-fq4j-g37q/GHSA-rgw4-fq4j-g37q.json
+++ b/advisories/unreviewed/2022/05/GHSA-rgw4-fq4j-g37q/GHSA-rgw4-fq4j-g37q.json
@@ -7,12 +7,8 @@
"CVE-2007-3927"
],
"details": "Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to \"subscribe.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rgx6-gghj-w753/GHSA-rgx6-gghj-w753.json b/advisories/unreviewed/2022/05/GHSA-rgx6-gghj-w753/GHSA-rgx6-gghj-w753.json
index 13f4486e0a9..d6b590c55a9 100644
--- a/advisories/unreviewed/2022/05/GHSA-rgx6-gghj-w753/GHSA-rgx6-gghj-w753.json
+++ b/advisories/unreviewed/2022/05/GHSA-rgx6-gghj-w753/GHSA-rgx6-gghj-w753.json
@@ -7,12 +7,8 @@
"CVE-2007-3775"
],
"details": "Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allows remote attackers to cause a denial of service (loss of cluster services) via unspecified vectors, aka (1) CSCsj09859 and (2) CSCsj19985.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rh7x-cgv7-x5w5/GHSA-rh7x-cgv7-x5w5.json b/advisories/unreviewed/2022/05/GHSA-rh7x-cgv7-x5w5/GHSA-rh7x-cgv7-x5w5.json
index d88519decb3..0d4de4e61a4 100644
--- a/advisories/unreviewed/2022/05/GHSA-rh7x-cgv7-x5w5/GHSA-rh7x-cgv7-x5w5.json
+++ b/advisories/unreviewed/2022/05/GHSA-rh7x-cgv7-x5w5/GHSA-rh7x-cgv7-x5w5.json
@@ -7,12 +7,8 @@
"CVE-2007-3906"
],
"details": "Unspecified vulnerability in Kaspersky Anti-Virus for Check Point FireWall-1 before Critical Fix 1 (5.5.161.0) might allow attackers to cause a denial of service (kernel hang) via unspecified vectors. NOTE: it is not clear whether there is an attacker role.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rm3j-39m3-3c8p/GHSA-rm3j-39m3-3c8p.json b/advisories/unreviewed/2022/05/GHSA-rm3j-39m3-3c8p/GHSA-rm3j-39m3-3c8p.json
index 6c151be8741..0bda390dc40 100644
--- a/advisories/unreviewed/2022/05/GHSA-rm3j-39m3-3c8p/GHSA-rm3j-39m3-3c8p.json
+++ b/advisories/unreviewed/2022/05/GHSA-rm3j-39m3-3c8p/GHSA-rm3j-39m3-3c8p.json
@@ -7,12 +7,8 @@
"CVE-2007-3609"
],
"details": "Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) b.php and (2) account/gallery.php, and other unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rm4p-5c85-7wp5/GHSA-rm4p-5c85-7wp5.json b/advisories/unreviewed/2022/05/GHSA-rm4p-5c85-7wp5/GHSA-rm4p-5c85-7wp5.json
index 559dcdf9be6..28a3f87ea1c 100644
--- a/advisories/unreviewed/2022/05/GHSA-rm4p-5c85-7wp5/GHSA-rm4p-5c85-7wp5.json
+++ b/advisories/unreviewed/2022/05/GHSA-rm4p-5c85-7wp5/GHSA-rm4p-5c85-7wp5.json
@@ -7,12 +7,8 @@
"CVE-2007-3955"
],
"details": "Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rm7m-7988-c75v/GHSA-rm7m-7988-c75v.json b/advisories/unreviewed/2022/05/GHSA-rm7m-7988-c75v/GHSA-rm7m-7988-c75v.json
index 34ea7a09d39..9ac80561780 100644
--- a/advisories/unreviewed/2022/05/GHSA-rm7m-7988-c75v/GHSA-rm7m-7988-c75v.json
+++ b/advisories/unreviewed/2022/05/GHSA-rm7m-7988-c75v/GHSA-rm7m-7988-c75v.json
@@ -7,12 +7,8 @@
"CVE-2007-3361"
],
"details": "The Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to cause a denial of service (device crash) via a SIP message with a malformed header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rmvr-wmxx-583v/GHSA-rmvr-wmxx-583v.json b/advisories/unreviewed/2022/05/GHSA-rmvr-wmxx-583v/GHSA-rmvr-wmxx-583v.json
index 991cf5b62cb..15f6da04a29 100644
--- a/advisories/unreviewed/2022/05/GHSA-rmvr-wmxx-583v/GHSA-rmvr-wmxx-583v.json
+++ b/advisories/unreviewed/2022/05/GHSA-rmvr-wmxx-583v/GHSA-rmvr-wmxx-583v.json
@@ -7,12 +7,8 @@
"CVE-2007-3701"
],
"details": "TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-rmwv-2j93-7282/GHSA-rmwv-2j93-7282.json b/advisories/unreviewed/2022/05/GHSA-rmwv-2j93-7282/GHSA-rmwv-2j93-7282.json
index 264aac47b79..fd1faefc0c5 100644
--- a/advisories/unreviewed/2022/05/GHSA-rmwv-2j93-7282/GHSA-rmwv-2j93-7282.json
+++ b/advisories/unreviewed/2022/05/GHSA-rmwv-2j93-7282/GHSA-rmwv-2j93-7282.json
@@ -7,12 +7,8 @@
"CVE-2007-3500"
],
"details": "Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rp99-928p-mmhv/GHSA-rp99-928p-mmhv.json b/advisories/unreviewed/2022/05/GHSA-rp99-928p-mmhv/GHSA-rp99-928p-mmhv.json
index 157cdd61e74..ee49777bf31 100644
--- a/advisories/unreviewed/2022/05/GHSA-rp99-928p-mmhv/GHSA-rp99-928p-mmhv.json
+++ b/advisories/unreviewed/2022/05/GHSA-rp99-928p-mmhv/GHSA-rp99-928p-mmhv.json
@@ -7,12 +7,8 @@
"CVE-2007-3592"
],
"details": "PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rq87-q5qh-gw9j/GHSA-rq87-q5qh-gw9j.json b/advisories/unreviewed/2022/05/GHSA-rq87-q5qh-gw9j/GHSA-rq87-q5qh-gw9j.json
index a295770775a..27506de2e8e 100644
--- a/advisories/unreviewed/2022/05/GHSA-rq87-q5qh-gw9j/GHSA-rq87-q5qh-gw9j.json
+++ b/advisories/unreviewed/2022/05/GHSA-rq87-q5qh-gw9j/GHSA-rq87-q5qh-gw9j.json
@@ -7,12 +7,8 @@
"CVE-2007-3594"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c) reports/ReportViewAction.do; the (5) operation parameter to (d) admin/ServiceConfiguration.do; and the (6) selectedNode and (7) selectedTab parameters to (e) admin/DeviceAssociation.do. NOTE: the searchTerm parameter in Search.do is already covered by CVE-2006-2343.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -72,9 +68,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rqw8-265m-q6rg/GHSA-rqw8-265m-q6rg.json b/advisories/unreviewed/2022/05/GHSA-rqw8-265m-q6rg/GHSA-rqw8-265m-q6rg.json
index 3386846dbb9..2966c444cb2 100644
--- a/advisories/unreviewed/2022/05/GHSA-rqw8-265m-q6rg/GHSA-rqw8-265m-q6rg.json
+++ b/advisories/unreviewed/2022/05/GHSA-rqw8-265m-q6rg/GHSA-rqw8-265m-q6rg.json
@@ -7,12 +7,8 @@
"CVE-2007-3962"
],
"details": "Multiple stack-based buffer overflows in fsplib.c in fsplib before 0.9 might allow remote attackers to execute arbitrary code via (1) a long filename that is not properly handled by the fsp_readdir_native function when MAXNAMLEN is greater than 255, or (2) a long d_name directory (dirent) field in the fsp_readdir function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-rr4r-mpmc-37vp/GHSA-rr4r-mpmc-37vp.json b/advisories/unreviewed/2022/05/GHSA-rr4r-mpmc-37vp/GHSA-rr4r-mpmc-37vp.json
index 127290d6573..6c90cd0279d 100644
--- a/advisories/unreviewed/2022/05/GHSA-rr4r-mpmc-37vp/GHSA-rr4r-mpmc-37vp.json
+++ b/advisories/unreviewed/2022/05/GHSA-rr4r-mpmc-37vp/GHSA-rr4r-mpmc-37vp.json
@@ -7,12 +7,8 @@
"CVE-2007-3668"
],
"details": "Multiple unspecified vulnerabilities in NMSDVDXU.DLL in NuMedia NMSDVDX allow remote attackers to cause a denial of service via \"improperly initialized\" (1) LoadSegmentWord, (2) PartitionType, (3) SectorCount, and (4) BootFilePath variables.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rr93-grpr-q2g2/GHSA-rr93-grpr-q2g2.json b/advisories/unreviewed/2022/05/GHSA-rr93-grpr-q2g2/GHSA-rr93-grpr-q2g2.json
index 90669317da9..85626b765c0 100644
--- a/advisories/unreviewed/2022/05/GHSA-rr93-grpr-q2g2/GHSA-rr93-grpr-q2g2.json
+++ b/advisories/unreviewed/2022/05/GHSA-rr93-grpr-q2g2/GHSA-rr93-grpr-q2g2.json
@@ -7,12 +7,8 @@
"CVE-2007-3768"
],
"details": "The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rrhm-pxgh-hw46/GHSA-rrhm-pxgh-hw46.json b/advisories/unreviewed/2022/05/GHSA-rrhm-pxgh-hw46/GHSA-rrhm-pxgh-hw46.json
index 32681b980a6..30bd51584c3 100644
--- a/advisories/unreviewed/2022/05/GHSA-rrhm-pxgh-hw46/GHSA-rrhm-pxgh-hw46.json
+++ b/advisories/unreviewed/2022/05/GHSA-rrhm-pxgh-hw46/GHSA-rrhm-pxgh-hw46.json
@@ -7,12 +7,8 @@
"CVE-2007-3926"
],
"details": "Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an \"overwritten destructor.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rvqc-v6vj-m9pw/GHSA-rvqc-v6vj-m9pw.json b/advisories/unreviewed/2022/05/GHSA-rvqc-v6vj-m9pw/GHSA-rvqc-v6vj-m9pw.json
index 55e597621a1..7594a003e2e 100644
--- a/advisories/unreviewed/2022/05/GHSA-rvqc-v6vj-m9pw/GHSA-rvqc-v6vj-m9pw.json
+++ b/advisories/unreviewed/2022/05/GHSA-rvqc-v6vj-m9pw/GHSA-rvqc-v6vj-m9pw.json
@@ -7,12 +7,8 @@
"CVE-2007-3397"
],
"details": "The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rw56-66x6-gv3f/GHSA-rw56-66x6-gv3f.json b/advisories/unreviewed/2022/05/GHSA-rw56-66x6-gv3f/GHSA-rw56-66x6-gv3f.json
index fa9fc448af7..b24ec423d1f 100644
--- a/advisories/unreviewed/2022/05/GHSA-rw56-66x6-gv3f/GHSA-rw56-66x6-gv3f.json
+++ b/advisories/unreviewed/2022/05/GHSA-rw56-66x6-gv3f/GHSA-rw56-66x6-gv3f.json
@@ -7,12 +7,8 @@
"CVE-2007-3229"
],
"details": "index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rwvw-2wr7-j8cw/GHSA-rwvw-2wr7-j8cw.json b/advisories/unreviewed/2022/05/GHSA-rwvw-2wr7-j8cw/GHSA-rwvw-2wr7-j8cw.json
index f64cb3dfbaf..e5f2bb829ae 100644
--- a/advisories/unreviewed/2022/05/GHSA-rwvw-2wr7-j8cw/GHSA-rwvw-2wr7-j8cw.json
+++ b/advisories/unreviewed/2022/05/GHSA-rwvw-2wr7-j8cw/GHSA-rwvw-2wr7-j8cw.json
@@ -7,12 +7,8 @@
"CVE-2007-3217"
],
"details": "Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the path_inc parameter to (1) index.php in gestion/; (2) identification.php, (3) disconnect.php, (4) loginliste.php, (5) loginmodif.php, (6) index.php, and (7) ident.inc.php in ident/; (8) menuadministration.php and (9) menuprincipal.php in menu/; (10) param.inc.php in param/; (11) index.php in plugins/phpgacl/; and (12) index.php and (13) common.inc.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -88,9 +84,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rx48-rqwf-j9g3/GHSA-rx48-rqwf-j9g3.json b/advisories/unreviewed/2022/05/GHSA-rx48-rqwf-j9g3/GHSA-rx48-rqwf-j9g3.json
index c4f939da04f..f41e5429294 100644
--- a/advisories/unreviewed/2022/05/GHSA-rx48-rqwf-j9g3/GHSA-rx48-rqwf-j9g3.json
+++ b/advisories/unreviewed/2022/05/GHSA-rx48-rqwf-j9g3/GHSA-rx48-rqwf-j9g3.json
@@ -7,12 +7,8 @@
"CVE-2007-3720"
],
"details": "The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rxgv-x78r-p9p9/GHSA-rxgv-x78r-p9p9.json b/advisories/unreviewed/2022/05/GHSA-rxgv-x78r-p9p9/GHSA-rxgv-x78r-p9p9.json
index 91ea3c47c0b..b2f4ca9c3ee 100644
--- a/advisories/unreviewed/2022/05/GHSA-rxgv-x78r-p9p9/GHSA-rxgv-x78r-p9p9.json
+++ b/advisories/unreviewed/2022/05/GHSA-rxgv-x78r-p9p9/GHSA-rxgv-x78r-p9p9.json
@@ -7,12 +7,8 @@
"CVE-2007-3949"
],
"details": "mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -76,9 +72,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-rxrm-7wj4-5wvw/GHSA-rxrm-7wj4-5wvw.json b/advisories/unreviewed/2022/05/GHSA-rxrm-7wj4-5wvw/GHSA-rxrm-7wj4-5wvw.json
index 339e94e328d..aac5baf5092 100644
--- a/advisories/unreviewed/2022/05/GHSA-rxrm-7wj4-5wvw/GHSA-rxrm-7wj4-5wvw.json
+++ b/advisories/unreviewed/2022/05/GHSA-rxrm-7wj4-5wvw/GHSA-rxrm-7wj4-5wvw.json
@@ -7,12 +7,8 @@
"CVE-2007-3459"
],
"details": "A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v33q-cjfm-hjqj/GHSA-v33q-cjfm-hjqj.json b/advisories/unreviewed/2022/05/GHSA-v33q-cjfm-hjqj/GHSA-v33q-cjfm-hjqj.json
index 69a00d15146..1b745471fdb 100644
--- a/advisories/unreviewed/2022/05/GHSA-v33q-cjfm-hjqj/GHSA-v33q-cjfm-hjqj.json
+++ b/advisories/unreviewed/2022/05/GHSA-v33q-cjfm-hjqj/GHSA-v33q-cjfm-hjqj.json
@@ -7,12 +7,8 @@
"CVE-2007-3774"
],
"details": "Dvbbs 7.1.0 SP1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Data/Dvbbs7.mdb.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v3mc-p9q9-fjwf/GHSA-v3mc-p9q9-fjwf.json b/advisories/unreviewed/2022/05/GHSA-v3mc-p9q9-fjwf/GHSA-v3mc-p9q9-fjwf.json
index 4aa73be06d9..027b33283d1 100644
--- a/advisories/unreviewed/2022/05/GHSA-v3mc-p9q9-fjwf/GHSA-v3mc-p9q9-fjwf.json
+++ b/advisories/unreviewed/2022/05/GHSA-v3mc-p9q9-fjwf/GHSA-v3mc-p9q9-fjwf.json
@@ -7,12 +7,8 @@
"CVE-2019-1010170"
],
"details": "Jsish 2.4.77 2.0477 is affected by: Use After Free. The impact is: denial of service. The component is: function Jsi_ObjFree (jsiObj.c:230). The attack vector is: executing crafted javascript code. The fixed version is: 2.4.78.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v4w9-96h9-5rvv/GHSA-v4w9-96h9-5rvv.json b/advisories/unreviewed/2022/05/GHSA-v4w9-96h9-5rvv/GHSA-v4w9-96h9-5rvv.json
index 1153a8cf69d..f6a9de0cdc9 100644
--- a/advisories/unreviewed/2022/05/GHSA-v4w9-96h9-5rvv/GHSA-v4w9-96h9-5rvv.json
+++ b/advisories/unreviewed/2022/05/GHSA-v4w9-96h9-5rvv/GHSA-v4w9-96h9-5rvv.json
@@ -7,12 +7,8 @@
"CVE-2007-3665"
],
"details": "Multiple unspecified vulnerabilities in FileBackup.DLL in Symantec Norton Ghost 12.0 allow remote attackers to cause a denial of service via unspecified vectors involving the UpdateCatalog and other functions.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v4wh-3r94-wm5p/GHSA-v4wh-3r94-wm5p.json b/advisories/unreviewed/2022/05/GHSA-v4wh-3r94-wm5p/GHSA-v4wh-3r94-wm5p.json
index 7cf98adddae..831d4464c9c 100644
--- a/advisories/unreviewed/2022/05/GHSA-v4wh-3r94-wm5p/GHSA-v4wh-3r94-wm5p.json
+++ b/advisories/unreviewed/2022/05/GHSA-v4wh-3r94-wm5p/GHSA-v4wh-3r94-wm5p.json
@@ -7,12 +7,8 @@
"CVE-2007-3580"
],
"details": "PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v56r-gf53-p6qp/GHSA-v56r-gf53-p6qp.json b/advisories/unreviewed/2022/05/GHSA-v56r-gf53-p6qp/GHSA-v56r-gf53-p6qp.json
index 3580c52a420..31cba086900 100644
--- a/advisories/unreviewed/2022/05/GHSA-v56r-gf53-p6qp/GHSA-v56r-gf53-p6qp.json
+++ b/advisories/unreviewed/2022/05/GHSA-v56r-gf53-p6qp/GHSA-v56r-gf53-p6qp.json
@@ -7,12 +7,8 @@
"CVE-2007-3684"
],
"details": "Multiple SQL injection vulnerabilities in Unobtrusive Ajax Star Rating Bar before 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) q and (2) t parameters in (a) db.php and (b) rpc.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v66v-63h2-8q5q/GHSA-v66v-63h2-8q5q.json b/advisories/unreviewed/2022/05/GHSA-v66v-63h2-8q5q/GHSA-v66v-63h2-8q5q.json
index da16add56c0..3ad0d17adeb 100644
--- a/advisories/unreviewed/2022/05/GHSA-v66v-63h2-8q5q/GHSA-v66v-63h2-8q5q.json
+++ b/advisories/unreviewed/2022/05/GHSA-v66v-63h2-8q5q/GHSA-v66v-63h2-8q5q.json
@@ -7,12 +7,8 @@
"CVE-2007-3386"
],
"details": "Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-v6vv-w825-m5c7/GHSA-v6vv-w825-m5c7.json b/advisories/unreviewed/2022/05/GHSA-v6vv-w825-m5c7/GHSA-v6vv-w825-m5c7.json
index 5339a62ebe9..c0cd9f7f5f2 100644
--- a/advisories/unreviewed/2022/05/GHSA-v6vv-w825-m5c7/GHSA-v6vv-w825-m5c7.json
+++ b/advisories/unreviewed/2022/05/GHSA-v6vv-w825-m5c7/GHSA-v6vv-w825-m5c7.json
@@ -7,12 +7,8 @@
"CVE-2007-3360"
],
"details": "hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v7rv-756m-xj53/GHSA-v7rv-756m-xj53.json b/advisories/unreviewed/2022/05/GHSA-v7rv-756m-xj53/GHSA-v7rv-756m-xj53.json
index b6f804adffb..9f9977426db 100644
--- a/advisories/unreviewed/2022/05/GHSA-v7rv-756m-xj53/GHSA-v7rv-756m-xj53.json
+++ b/advisories/unreviewed/2022/05/GHSA-v7rv-756m-xj53/GHSA-v7rv-756m-xj53.json
@@ -7,12 +7,8 @@
"CVE-2007-3414"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in access2asp 4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) od and (2) search parameters to (a) suppliersList.asp and (b) contactsList.asp.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v9f4-g9jg-27gq/GHSA-v9f4-g9jg-27gq.json b/advisories/unreviewed/2022/05/GHSA-v9f4-g9jg-27gq/GHSA-v9f4-g9jg-27gq.json
index 69e31bb6510..cde1bf0f6a5 100644
--- a/advisories/unreviewed/2022/05/GHSA-v9f4-g9jg-27gq/GHSA-v9f4-g9jg-27gq.json
+++ b/advisories/unreviewed/2022/05/GHSA-v9f4-g9jg-27gq/GHSA-v9f4-g9jg-27gq.json
@@ -7,12 +7,8 @@
"CVE-2007-3935"
],
"details": "PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-v9xf-gqqg-xhgx/GHSA-v9xf-gqqg-xhgx.json b/advisories/unreviewed/2022/05/GHSA-v9xf-gqqg-xhgx/GHSA-v9xf-gqqg-xhgx.json
index 61df0b2884f..74178fa32e8 100644
--- a/advisories/unreviewed/2022/05/GHSA-v9xf-gqqg-xhgx/GHSA-v9xf-gqqg-xhgx.json
+++ b/advisories/unreviewed/2022/05/GHSA-v9xf-gqqg-xhgx/GHSA-v9xf-gqqg-xhgx.json
@@ -7,12 +7,8 @@
"CVE-2007-3241"
],
"details": "Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vc4c-pfw2-x65r/GHSA-vc4c-pfw2-x65r.json b/advisories/unreviewed/2022/05/GHSA-vc4c-pfw2-x65r/GHSA-vc4c-pfw2-x65r.json
index 3a0c049209e..a044a01d3bc 100644
--- a/advisories/unreviewed/2022/05/GHSA-vc4c-pfw2-x65r/GHSA-vc4c-pfw2-x65r.json
+++ b/advisories/unreviewed/2022/05/GHSA-vc4c-pfw2-x65r/GHSA-vc4c-pfw2-x65r.json
@@ -7,12 +7,8 @@
"CVE-2007-3335"
],
"details": "Multiple SQL injection vulnerabilities in the admin panel in PHPEcho CMS before 1.6 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vf44-r5vg-xjp5/GHSA-vf44-r5vg-xjp5.json b/advisories/unreviewed/2022/05/GHSA-vf44-r5vg-xjp5/GHSA-vf44-r5vg-xjp5.json
index 9f0529f96e7..032f4be7885 100644
--- a/advisories/unreviewed/2022/05/GHSA-vf44-r5vg-xjp5/GHSA-vf44-r5vg-xjp5.json
+++ b/advisories/unreviewed/2022/05/GHSA-vf44-r5vg-xjp5/GHSA-vf44-r5vg-xjp5.json
@@ -7,12 +7,8 @@
"CVE-2007-3777"
],
"details": "avg7core.sys 7.5.0.444 in Grisoft AVG Anti-Virus 7.5.448 and Free Edition 7.5.446, provides an internal function that copies data to an arbitrary address, which allows local users to gain privileges via arbitrary address arguments to a function provided by the 0x5348E004 IOCTL for the generic DeviceIoControl handler.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vgjg-9655-rqmc/GHSA-vgjg-9655-rqmc.json b/advisories/unreviewed/2022/05/GHSA-vgjg-9655-rqmc/GHSA-vgjg-9655-rqmc.json
index 6892deeec8c..1d152e316cc 100644
--- a/advisories/unreviewed/2022/05/GHSA-vgjg-9655-rqmc/GHSA-vgjg-9655-rqmc.json
+++ b/advisories/unreviewed/2022/05/GHSA-vgjg-9655-rqmc/GHSA-vgjg-9655-rqmc.json
@@ -7,12 +7,8 @@
"CVE-2007-3567"
],
"details": "MySQLDumper 1.21b through 1.23 REV227 uses a \"Limit GET\" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vh6m-wfc3-jrhc/GHSA-vh6m-wfc3-jrhc.json b/advisories/unreviewed/2022/05/GHSA-vh6m-wfc3-jrhc/GHSA-vh6m-wfc3-jrhc.json
index 8b6db437d86..030b349f658 100644
--- a/advisories/unreviewed/2022/05/GHSA-vh6m-wfc3-jrhc/GHSA-vh6m-wfc3-jrhc.json
+++ b/advisories/unreviewed/2022/05/GHSA-vh6m-wfc3-jrhc/GHSA-vh6m-wfc3-jrhc.json
@@ -7,12 +7,8 @@
"CVE-2007-3319"
],
"details": "The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept communications.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vjpf-ph39-5hrp/GHSA-vjpf-ph39-5hrp.json b/advisories/unreviewed/2022/05/GHSA-vjpf-ph39-5hrp/GHSA-vjpf-ph39-5hrp.json
index b82eac2f3ac..7577fc780b4 100644
--- a/advisories/unreviewed/2022/05/GHSA-vjpf-ph39-5hrp/GHSA-vjpf-ph39-5hrp.json
+++ b/advisories/unreviewed/2022/05/GHSA-vjpf-ph39-5hrp/GHSA-vjpf-ph39-5hrp.json
@@ -7,12 +7,8 @@
"CVE-2007-3441"
],
"details": "Format string vulnerability in the Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to cause a denial of service (blocked call reception and slow calling) via format string specifiers in an SDP header value, a different vulnerability than CVE-2007-3349.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vm69-cg97-j9wr/GHSA-vm69-cg97-j9wr.json b/advisories/unreviewed/2022/05/GHSA-vm69-cg97-j9wr/GHSA-vm69-cg97-j9wr.json
index 7e3121201d1..7a29ad205e3 100644
--- a/advisories/unreviewed/2022/05/GHSA-vm69-cg97-j9wr/GHSA-vm69-cg97-j9wr.json
+++ b/advisories/unreviewed/2022/05/GHSA-vm69-cg97-j9wr/GHSA-vm69-cg97-j9wr.json
@@ -7,12 +7,8 @@
"CVE-2007-3438"
],
"details": "Buffer overflow in the SIP header parsing module in the Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to execute arbitrary code via a malformed message, a different vulnerability than CVE-2007-3361.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vmmw-r7wc-96jr/GHSA-vmmw-r7wc-96jr.json b/advisories/unreviewed/2022/05/GHSA-vmmw-r7wc-96jr/GHSA-vmmw-r7wc-96jr.json
index adf7e00fb92..efda111892e 100644
--- a/advisories/unreviewed/2022/05/GHSA-vmmw-r7wc-96jr/GHSA-vmmw-r7wc-96jr.json
+++ b/advisories/unreviewed/2022/05/GHSA-vmmw-r7wc-96jr/GHSA-vmmw-r7wc-96jr.json
@@ -7,12 +7,8 @@
"CVE-2007-3526"
],
"details": "Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vp9h-w4rm-xp28/GHSA-vp9h-w4rm-xp28.json b/advisories/unreviewed/2022/05/GHSA-vp9h-w4rm-xp28/GHSA-vp9h-w4rm-xp28.json
index 3ed59f7ad3e..77bf2b8afe9 100644
--- a/advisories/unreviewed/2022/05/GHSA-vp9h-w4rm-xp28/GHSA-vp9h-w4rm-xp28.json
+++ b/advisories/unreviewed/2022/05/GHSA-vp9h-w4rm-xp28/GHSA-vp9h-w4rm-xp28.json
@@ -7,12 +7,8 @@
"CVE-2007-3504"
],
"details": "Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-vqj2-jf89-h87v/GHSA-vqj2-jf89-h87v.json b/advisories/unreviewed/2022/05/GHSA-vqj2-jf89-h87v/GHSA-vqj2-jf89-h87v.json
index 08bde4f31f1..c9f9fc208ea 100644
--- a/advisories/unreviewed/2022/05/GHSA-vqj2-jf89-h87v/GHSA-vqj2-jf89-h87v.json
+++ b/advisories/unreviewed/2022/05/GHSA-vqj2-jf89-h87v/GHSA-vqj2-jf89-h87v.json
@@ -7,12 +7,8 @@
"CVE-2007-3511"
],
"details": "The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the \"for\" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -212,9 +208,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vr29-hp79-9fjh/GHSA-vr29-hp79-9fjh.json b/advisories/unreviewed/2022/05/GHSA-vr29-hp79-9fjh/GHSA-vr29-hp79-9fjh.json
index b4b11124020..611b6ca5092 100644
--- a/advisories/unreviewed/2022/05/GHSA-vr29-hp79-9fjh/GHSA-vr29-hp79-9fjh.json
+++ b/advisories/unreviewed/2022/05/GHSA-vr29-hp79-9fjh/GHSA-vr29-hp79-9fjh.json
@@ -7,12 +7,8 @@
"CVE-2007-3808"
],
"details": "SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vr9w-hgcg-99p2/GHSA-vr9w-hgcg-99p2.json b/advisories/unreviewed/2022/05/GHSA-vr9w-hgcg-99p2/GHSA-vr9w-hgcg-99p2.json
index 097d96b3245..1a324838a48 100644
--- a/advisories/unreviewed/2022/05/GHSA-vr9w-hgcg-99p2/GHSA-vr9w-hgcg-99p2.json
+++ b/advisories/unreviewed/2022/05/GHSA-vr9w-hgcg-99p2/GHSA-vr9w-hgcg-99p2.json
@@ -7,12 +7,8 @@
"CVE-2007-3399"
],
"details": "SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-vrfq-42cm-pfc7/GHSA-vrfq-42cm-pfc7.json b/advisories/unreviewed/2022/05/GHSA-vrfq-42cm-pfc7/GHSA-vrfq-42cm-pfc7.json
index 8d644c727d5..a4f5cbe5b7a 100644
--- a/advisories/unreviewed/2022/05/GHSA-vrfq-42cm-pfc7/GHSA-vrfq-42cm-pfc7.json
+++ b/advisories/unreviewed/2022/05/GHSA-vrfq-42cm-pfc7/GHSA-vrfq-42cm-pfc7.json
@@ -7,12 +7,8 @@
"CVE-2007-3728"
],
"details": "Buffer overflow in lib/silcclient/client_notify.c of SILC Client and SILC Toolkit before 1.1.2 allows remote attackers to cause a denial of service via \"NICK_CHANGE\" notifications.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vv83-68vg-922h/GHSA-vv83-68vg-922h.json b/advisories/unreviewed/2022/05/GHSA-vv83-68vg-922h/GHSA-vv83-68vg-922h.json
index 84ce3ac4fb4..df02a529774 100644
--- a/advisories/unreviewed/2022/05/GHSA-vv83-68vg-922h/GHSA-vv83-68vg-922h.json
+++ b/advisories/unreviewed/2022/05/GHSA-vv83-68vg-922h/GHSA-vv83-68vg-922h.json
@@ -7,12 +7,8 @@
"CVE-2007-3566"
],
"details": "Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a create request to port 3050/tcp.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vvcr-q3cj-chhj/GHSA-vvcr-q3cj-chhj.json b/advisories/unreviewed/2022/05/GHSA-vvcr-q3cj-chhj/GHSA-vvcr-q3cj-chhj.json
index bf10733a3ba..1c8e17bd2ed 100644
--- a/advisories/unreviewed/2022/05/GHSA-vvcr-q3cj-chhj/GHSA-vvcr-q3cj-chhj.json
+++ b/advisories/unreviewed/2022/05/GHSA-vvcr-q3cj-chhj/GHSA-vvcr-q3cj-chhj.json
@@ -7,12 +7,8 @@
"CVE-2007-3602"
],
"details": "The SOAP webservice in vtiger CRM before 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with inactive accounts to access and modify data, as demonstrated by the Thunderbird plugin.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vvcx-j7jq-9x76/GHSA-vvcx-j7jq-9x76.json b/advisories/unreviewed/2022/05/GHSA-vvcx-j7jq-9x76/GHSA-vvcx-j7jq-9x76.json
index 54743ed7227..0ab3078b883 100644
--- a/advisories/unreviewed/2022/05/GHSA-vvcx-j7jq-9x76/GHSA-vvcx-j7jq-9x76.json
+++ b/advisories/unreviewed/2022/05/GHSA-vvcx-j7jq-9x76/GHSA-vvcx-j7jq-9x76.json
@@ -7,12 +7,8 @@
"CVE-2007-3403"
],
"details": "Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vvqg-75f9-88hx/GHSA-vvqg-75f9-88hx.json b/advisories/unreviewed/2022/05/GHSA-vvqg-75f9-88hx/GHSA-vvqg-75f9-88hx.json
index c11950cf360..c1977fc5875 100644
--- a/advisories/unreviewed/2022/05/GHSA-vvqg-75f9-88hx/GHSA-vvqg-75f9-88hx.json
+++ b/advisories/unreviewed/2022/05/GHSA-vvqg-75f9-88hx/GHSA-vvqg-75f9-88hx.json
@@ -7,12 +7,8 @@
"CVE-2007-3289"
],
"details": "PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vwgw-8h47-46gp/GHSA-vwgw-8h47-46gp.json b/advisories/unreviewed/2022/05/GHSA-vwgw-8h47-46gp/GHSA-vwgw-8h47-46gp.json
index c83d0ab2a80..bf4602f5f3b 100644
--- a/advisories/unreviewed/2022/05/GHSA-vwgw-8h47-46gp/GHSA-vwgw-8h47-46gp.json
+++ b/advisories/unreviewed/2022/05/GHSA-vwgw-8h47-46gp/GHSA-vwgw-8h47-46gp.json
@@ -7,12 +7,8 @@
"CVE-2007-3291"
],
"details": "Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-vwmx-6456-487h/GHSA-vwmx-6456-487h.json b/advisories/unreviewed/2022/05/GHSA-vwmx-6456-487h/GHSA-vwmx-6456-487h.json
index 30378d44224..7557397963c 100644
--- a/advisories/unreviewed/2022/05/GHSA-vwmx-6456-487h/GHSA-vwmx-6456-487h.json
+++ b/advisories/unreviewed/2022/05/GHSA-vwmx-6456-487h/GHSA-vwmx-6456-487h.json
@@ -7,12 +7,8 @@
"CVE-2007-3237"
],
"details": "PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-vxqm-jmmw-cfg4/GHSA-vxqm-jmmw-cfg4.json b/advisories/unreviewed/2022/05/GHSA-vxqm-jmmw-cfg4/GHSA-vxqm-jmmw-cfg4.json
index 66c0f0aca12..6cb26e0bf5c 100644
--- a/advisories/unreviewed/2022/05/GHSA-vxqm-jmmw-cfg4/GHSA-vxqm-jmmw-cfg4.json
+++ b/advisories/unreviewed/2022/05/GHSA-vxqm-jmmw-cfg4/GHSA-vxqm-jmmw-cfg4.json
@@ -7,12 +7,8 @@
"CVE-2007-3337"
],
"details": "wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -64,9 +60,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w25q-2c3c-rj7f/GHSA-w25q-2c3c-rj7f.json b/advisories/unreviewed/2022/05/GHSA-w25q-2c3c-rj7f/GHSA-w25q-2c3c-rj7f.json
index 94ae9c852d8..03f8f399f10 100644
--- a/advisories/unreviewed/2022/05/GHSA-w25q-2c3c-rj7f/GHSA-w25q-2c3c-rj7f.json
+++ b/advisories/unreviewed/2022/05/GHSA-w25q-2c3c-rj7f/GHSA-w25q-2c3c-rj7f.json
@@ -7,12 +7,8 @@
"CVE-2007-3696"
],
"details": "CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w2j5-jh8w-fwc4/GHSA-w2j5-jh8w-fwc4.json b/advisories/unreviewed/2022/05/GHSA-w2j5-jh8w-fwc4/GHSA-w2j5-jh8w-fwc4.json
index 8156cbc1010..d79b2258c9b 100644
--- a/advisories/unreviewed/2022/05/GHSA-w2j5-jh8w-fwc4/GHSA-w2j5-jh8w-fwc4.json
+++ b/advisories/unreviewed/2022/05/GHSA-w2j5-jh8w-fwc4/GHSA-w2j5-jh8w-fwc4.json
@@ -7,12 +7,8 @@
"CVE-2019-15110"
],
"details": "The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w2m4-mx84-gv3g/GHSA-w2m4-mx84-gv3g.json b/advisories/unreviewed/2022/05/GHSA-w2m4-mx84-gv3g/GHSA-w2m4-mx84-gv3g.json
index d4ebaf0560a..f411e0cdc68 100644
--- a/advisories/unreviewed/2022/05/GHSA-w2m4-mx84-gv3g/GHSA-w2m4-mx84-gv3g.json
+++ b/advisories/unreviewed/2022/05/GHSA-w2m4-mx84-gv3g/GHSA-w2m4-mx84-gv3g.json
@@ -7,12 +7,8 @@
"CVE-2007-3300"
],
"details": "Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -60,9 +56,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w2v3-p9w4-6w6c/GHSA-w2v3-p9w4-6w6c.json b/advisories/unreviewed/2022/05/GHSA-w2v3-p9w4-6w6c/GHSA-w2v3-p9w4-6w6c.json
index b367e97864e..d86d9b7323c 100644
--- a/advisories/unreviewed/2022/05/GHSA-w2v3-p9w4-6w6c/GHSA-w2v3-p9w4-6w6c.json
+++ b/advisories/unreviewed/2022/05/GHSA-w2v3-p9w4-6w6c/GHSA-w2v3-p9w4-6w6c.json
@@ -7,12 +7,8 @@
"CVE-2007-3552"
],
"details": "Multiple unspecified vulnerabilities in bbs100 before 3.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving certain v*printf and shift_StringIO functions. NOTE: some details were obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w2v9-62px-pr3m/GHSA-w2v9-62px-pr3m.json b/advisories/unreviewed/2022/05/GHSA-w2v9-62px-pr3m/GHSA-w2v9-62px-pr3m.json
index d001c60a3c9..899310ab007 100644
--- a/advisories/unreviewed/2022/05/GHSA-w2v9-62px-pr3m/GHSA-w2v9-62px-pr3m.json
+++ b/advisories/unreviewed/2022/05/GHSA-w2v9-62px-pr3m/GHSA-w2v9-62px-pr3m.json
@@ -7,12 +7,8 @@
"CVE-2007-3557"
],
"details": "SQL injection vulnerability in admin/login.php in Wheatblog (wB) 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w4rq-85mw-mch5/GHSA-w4rq-85mw-mch5.json b/advisories/unreviewed/2022/05/GHSA-w4rq-85mw-mch5/GHSA-w4rq-85mw-mch5.json
index 48cd0cfea41..ed0fd606c6d 100644
--- a/advisories/unreviewed/2022/05/GHSA-w4rq-85mw-mch5/GHSA-w4rq-85mw-mch5.json
+++ b/advisories/unreviewed/2022/05/GHSA-w4rq-85mw-mch5/GHSA-w4rq-85mw-mch5.json
@@ -7,12 +7,8 @@
"CVE-2007-3367"
],
"details": "Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive information via a direct request, which reveals the path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w53f-m8p6-x7g6/GHSA-w53f-m8p6-x7g6.json b/advisories/unreviewed/2022/05/GHSA-w53f-m8p6-x7g6/GHSA-w53f-m8p6-x7g6.json
index ecbf72d5747..24efe732a22 100644
--- a/advisories/unreviewed/2022/05/GHSA-w53f-m8p6-x7g6/GHSA-w53f-m8p6-x7g6.json
+++ b/advisories/unreviewed/2022/05/GHSA-w53f-m8p6-x7g6/GHSA-w53f-m8p6-x7g6.json
@@ -7,12 +7,8 @@
"CVE-2007-3372"
],
"details": "The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -88,9 +84,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w578-7c88-2rq6/GHSA-w578-7c88-2rq6.json b/advisories/unreviewed/2022/05/GHSA-w578-7c88-2rq6/GHSA-w578-7c88-2rq6.json
index af6651cc535..f02674814a6 100644
--- a/advisories/unreviewed/2022/05/GHSA-w578-7c88-2rq6/GHSA-w578-7c88-2rq6.json
+++ b/advisories/unreviewed/2022/05/GHSA-w578-7c88-2rq6/GHSA-w578-7c88-2rq6.json
@@ -7,12 +7,8 @@
"CVE-2007-3943"
],
"details": "SQL injection vulnerability in Infinite Responder before 1.48 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w5jh-v6cw-v522/GHSA-w5jh-v6cw-v522.json b/advisories/unreviewed/2022/05/GHSA-w5jh-v6cw-v522/GHSA-w5jh-v6cw-v522.json
index 5cd3be378ad..945c2b05692 100644
--- a/advisories/unreviewed/2022/05/GHSA-w5jh-v6cw-v522/GHSA-w5jh-v6cw-v522.json
+++ b/advisories/unreviewed/2022/05/GHSA-w5jh-v6cw-v522/GHSA-w5jh-v6cw-v522.json
@@ -7,12 +7,8 @@
"CVE-2007-3497"
],
"details": "Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length JavaScript variable.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w65r-5grf-v66x/GHSA-w65r-5grf-v66x.json b/advisories/unreviewed/2022/05/GHSA-w65r-5grf-v66x/GHSA-w65r-5grf-v66x.json
index a1bbc5dd9ac..b98c1d484fd 100644
--- a/advisories/unreviewed/2022/05/GHSA-w65r-5grf-v66x/GHSA-w65r-5grf-v66x.json
+++ b/advisories/unreviewed/2022/05/GHSA-w65r-5grf-v66x/GHSA-w65r-5grf-v66x.json
@@ -7,12 +7,8 @@
"CVE-2007-3702"
],
"details": "Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w6f4-vq25-88j8/GHSA-w6f4-vq25-88j8.json b/advisories/unreviewed/2022/05/GHSA-w6f4-vq25-88j8/GHSA-w6f4-vq25-88j8.json
index 977aa1ef1b9..ea2a146e948 100644
--- a/advisories/unreviewed/2022/05/GHSA-w6f4-vq25-88j8/GHSA-w6f4-vq25-88j8.json
+++ b/advisories/unreviewed/2022/05/GHSA-w6f4-vq25-88j8/GHSA-w6f4-vq25-88j8.json
@@ -7,12 +7,8 @@
"CVE-2007-3225"
],
"details": "Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w6pf-wcmg-gfh2/GHSA-w6pf-wcmg-gfh2.json b/advisories/unreviewed/2022/05/GHSA-w6pf-wcmg-gfh2/GHSA-w6pf-wcmg-gfh2.json
index f30b182e5b4..879c938627a 100644
--- a/advisories/unreviewed/2022/05/GHSA-w6pf-wcmg-gfh2/GHSA-w6pf-wcmg-gfh2.json
+++ b/advisories/unreviewed/2022/05/GHSA-w6pf-wcmg-gfh2/GHSA-w6pf-wcmg-gfh2.json
@@ -7,12 +7,8 @@
"CVE-2007-3396"
],
"details": "Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w84g-5gj4-2xj9/GHSA-w84g-5gj4-2xj9.json b/advisories/unreviewed/2022/05/GHSA-w84g-5gj4-2xj9/GHSA-w84g-5gj4-2xj9.json
index f2723e27295..0cf91f723ef 100644
--- a/advisories/unreviewed/2022/05/GHSA-w84g-5gj4-2xj9/GHSA-w84g-5gj4-2xj9.json
+++ b/advisories/unreviewed/2022/05/GHSA-w84g-5gj4-2xj9/GHSA-w84g-5gj4-2xj9.json
@@ -7,12 +7,8 @@
"CVE-2007-3568"
],
"details": "The _LoadBMP function in imlib 1.9.15 and earlier allows context-dependent attackers to cause a denial of service (infinite loop) via a BMP image with a Bits Per Page (BPP) value of 0.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w8vh-crmm-4pp5/GHSA-w8vh-crmm-4pp5.json b/advisories/unreviewed/2022/05/GHSA-w8vh-crmm-4pp5/GHSA-w8vh-crmm-4pp5.json
index 62f38b99cc5..4a465794ea5 100644
--- a/advisories/unreviewed/2022/05/GHSA-w8vh-crmm-4pp5/GHSA-w8vh-crmm-4pp5.json
+++ b/advisories/unreviewed/2022/05/GHSA-w8vh-crmm-4pp5/GHSA-w8vh-crmm-4pp5.json
@@ -7,12 +7,8 @@
"CVE-2007-3347"
],
"details": "The D-Link DPH-540/DPH-541 phone accepts SIP INVITE messages that are not from the Call Server's IP address, which allows remote attackers to engage in arbitrary SIP communication with the phone, as demonstrated by communication with forged caller ID.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-w8xf-4vr7-9jv8/GHSA-w8xf-4vr7-9jv8.json b/advisories/unreviewed/2022/05/GHSA-w8xf-4vr7-9jv8/GHSA-w8xf-4vr7-9jv8.json
index 3cb611f4e32..1dc925073d8 100644
--- a/advisories/unreviewed/2022/05/GHSA-w8xf-4vr7-9jv8/GHSA-w8xf-4vr7-9jv8.json
+++ b/advisories/unreviewed/2022/05/GHSA-w8xf-4vr7-9jv8/GHSA-w8xf-4vr7-9jv8.json
@@ -7,12 +7,8 @@
"CVE-2007-3310"
],
"details": "Cross-site scripting (XSS) vulnerability in arama.asp in TDizin allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wc53-cvcx-2wqx/GHSA-wc53-cvcx-2wqx.json b/advisories/unreviewed/2022/05/GHSA-wc53-cvcx-2wqx/GHSA-wc53-cvcx-2wqx.json
index e327dbf75ba..34ca1da3d6b 100644
--- a/advisories/unreviewed/2022/05/GHSA-wc53-cvcx-2wqx/GHSA-wc53-cvcx-2wqx.json
+++ b/advisories/unreviewed/2022/05/GHSA-wc53-cvcx-2wqx/GHSA-wc53-cvcx-2wqx.json
@@ -7,12 +7,8 @@
"CVE-2007-3645"
],
"details": "archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -88,9 +84,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wfpq-2475-x4qm/GHSA-wfpq-2475-x4qm.json b/advisories/unreviewed/2022/05/GHSA-wfpq-2475-x4qm/GHSA-wfpq-2475-x4qm.json
index f05be8e3c82..2ae0f6cad25 100644
--- a/advisories/unreviewed/2022/05/GHSA-wfpq-2475-x4qm/GHSA-wfpq-2475-x4qm.json
+++ b/advisories/unreviewed/2022/05/GHSA-wfpq-2475-x4qm/GHSA-wfpq-2475-x4qm.json
@@ -7,12 +7,8 @@
"CVE-2007-3402"
],
"details": "SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wg33-hg7j-vq7x/GHSA-wg33-hg7j-vq7x.json b/advisories/unreviewed/2022/05/GHSA-wg33-hg7j-vq7x/GHSA-wg33-hg7j-vq7x.json
index 46319db9a00..e9591ae2bdd 100644
--- a/advisories/unreviewed/2022/05/GHSA-wg33-hg7j-vq7x/GHSA-wg33-hg7j-vq7x.json
+++ b/advisories/unreviewed/2022/05/GHSA-wg33-hg7j-vq7x/GHSA-wg33-hg7j-vq7x.json
@@ -7,12 +7,8 @@
"CVE-2007-3626"
],
"details": "Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wgf3-8pqx-jmqx/GHSA-wgf3-8pqx-jmqx.json b/advisories/unreviewed/2022/05/GHSA-wgf3-8pqx-jmqx/GHSA-wgf3-8pqx-jmqx.json
index 1419e8774f4..eebf2d8ceab 100644
--- a/advisories/unreviewed/2022/05/GHSA-wgf3-8pqx-jmqx/GHSA-wgf3-8pqx-jmqx.json
+++ b/advisories/unreviewed/2022/05/GHSA-wgf3-8pqx-jmqx/GHSA-wgf3-8pqx-jmqx.json
@@ -7,12 +7,8 @@
"CVE-2007-3496"
],
"details": "Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wh9j-69f5-7f9c/GHSA-wh9j-69f5-7f9c.json b/advisories/unreviewed/2022/05/GHSA-wh9j-69f5-7f9c/GHSA-wh9j-69f5-7f9c.json
index 5208a8f072b..cf023d1db97 100644
--- a/advisories/unreviewed/2022/05/GHSA-wh9j-69f5-7f9c/GHSA-wh9j-69f5-7f9c.json
+++ b/advisories/unreviewed/2022/05/GHSA-wh9j-69f5-7f9c/GHSA-wh9j-69f5-7f9c.json
@@ -7,12 +7,8 @@
"CVE-2007-3746"
],
"details": "The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wjh6-q6cx-7rch/GHSA-wjh6-q6cx-7rch.json b/advisories/unreviewed/2022/05/GHSA-wjh6-q6cx-7rch/GHSA-wjh6-q6cx-7rch.json
index 558fc50afa7..d53af30bfdb 100644
--- a/advisories/unreviewed/2022/05/GHSA-wjh6-q6cx-7rch/GHSA-wjh6-q6cx-7rch.json
+++ b/advisories/unreviewed/2022/05/GHSA-wjh6-q6cx-7rch/GHSA-wjh6-q6cx-7rch.json
@@ -7,12 +7,8 @@
"CVE-2007-3686"
],
"details": "CRLF injection vulnerability in db.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary HTTP headers and data via CRLF sequences in the HTTP_REFERER parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wjqv-5qh4-crjj/GHSA-wjqv-5qh4-crjj.json b/advisories/unreviewed/2022/05/GHSA-wjqv-5qh4-crjj/GHSA-wjqv-5qh4-crjj.json
index 26c4f9681b6..783a2173151 100644
--- a/advisories/unreviewed/2022/05/GHSA-wjqv-5qh4-crjj/GHSA-wjqv-5qh4-crjj.json
+++ b/advisories/unreviewed/2022/05/GHSA-wjqv-5qh4-crjj/GHSA-wjqv-5qh4-crjj.json
@@ -7,12 +7,8 @@
"CVE-2007-3411"
],
"details": "SQL injection vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the image_id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wjrx-825m-6vc9/GHSA-wjrx-825m-6vc9.json b/advisories/unreviewed/2022/05/GHSA-wjrx-825m-6vc9/GHSA-wjrx-825m-6vc9.json
index 8e8065a232e..fd76961367a 100644
--- a/advisories/unreviewed/2022/05/GHSA-wjrx-825m-6vc9/GHSA-wjrx-825m-6vc9.json
+++ b/advisories/unreviewed/2022/05/GHSA-wjrx-825m-6vc9/GHSA-wjrx-825m-6vc9.json
@@ -7,12 +7,8 @@
"CVE-2007-3708"
],
"details": "Cross-site scripting (XSS) vulnerability in CodeIgniter 1.5.3 before 20070626 allows remote attackers to inject arbitrary web script or HTML via (1) String.fromCharCode and (2) malformed nested tag manipulations in an unspecified component, related to insufficient sanitization by the xss_clean function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wm2m-wxgh-453h/GHSA-wm2m-wxgh-453h.json b/advisories/unreviewed/2022/05/GHSA-wm2m-wxgh-453h/GHSA-wm2m-wxgh-453h.json
index 4ae8ca2f863..297178383c8 100644
--- a/advisories/unreviewed/2022/05/GHSA-wm2m-wxgh-453h/GHSA-wm2m-wxgh-453h.json
+++ b/advisories/unreviewed/2022/05/GHSA-wm2m-wxgh-453h/GHSA-wm2m-wxgh-453h.json
@@ -7,12 +7,8 @@
"CVE-2007-3717"
],
"details": "rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wm42-hhvj-57r4/GHSA-wm42-hhvj-57r4.json b/advisories/unreviewed/2022/05/GHSA-wm42-hhvj-57r4/GHSA-wm42-hhvj-57r4.json
index 59d21da1f76..ce5ad6da7bb 100644
--- a/advisories/unreviewed/2022/05/GHSA-wm42-hhvj-57r4/GHSA-wm42-hhvj-57r4.json
+++ b/advisories/unreviewed/2022/05/GHSA-wm42-hhvj-57r4/GHSA-wm42-hhvj-57r4.json
@@ -7,12 +7,8 @@
"CVE-2007-3682"
],
"details": "SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wmh5-cx85-6vrg/GHSA-wmh5-cx85-6vrg.json b/advisories/unreviewed/2022/05/GHSA-wmh5-cx85-6vrg/GHSA-wmh5-cx85-6vrg.json
index 233cdf42650..04e2a039504 100644
--- a/advisories/unreviewed/2022/05/GHSA-wmh5-cx85-6vrg/GHSA-wmh5-cx85-6vrg.json
+++ b/advisories/unreviewed/2022/05/GHSA-wmh5-cx85-6vrg/GHSA-wmh5-cx85-6vrg.json
@@ -7,12 +7,8 @@
"CVE-2007-3721"
],
"details": "The ULE process scheduler in the FreeBSD kernel gives preference to \"interactive\" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wmj3-mcr6-p6ph/GHSA-wmj3-mcr6-p6ph.json b/advisories/unreviewed/2022/05/GHSA-wmj3-mcr6-p6ph/GHSA-wmj3-mcr6-p6ph.json
index f114cbe28a5..b9a80a130ae 100644
--- a/advisories/unreviewed/2022/05/GHSA-wmj3-mcr6-p6ph/GHSA-wmj3-mcr6-p6ph.json
+++ b/advisories/unreviewed/2022/05/GHSA-wmj3-mcr6-p6ph/GHSA-wmj3-mcr6-p6ph.json
@@ -7,12 +7,8 @@
"CVE-2007-3521"
],
"details": "SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wpfm-275v-5frm/GHSA-wpfm-275v-5frm.json b/advisories/unreviewed/2022/05/GHSA-wpfm-275v-5frm/GHSA-wpfm-275v-5frm.json
index b1b2bc61197..699a7b8fbae 100644
--- a/advisories/unreviewed/2022/05/GHSA-wpfm-275v-5frm/GHSA-wpfm-275v-5frm.json
+++ b/advisories/unreviewed/2022/05/GHSA-wpfm-275v-5frm/GHSA-wpfm-275v-5frm.json
@@ -7,12 +7,8 @@
"CVE-2007-3405"
],
"details": "Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ad and (2) konu parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-wpmf-xc6q-mrfq/GHSA-wpmf-xc6q-mrfq.json b/advisories/unreviewed/2022/05/GHSA-wpmf-xc6q-mrfq/GHSA-wpmf-xc6q-mrfq.json
index eb7cf10336b..6e8989fd2f1 100644
--- a/advisories/unreviewed/2022/05/GHSA-wpmf-xc6q-mrfq/GHSA-wpmf-xc6q-mrfq.json
+++ b/advisories/unreviewed/2022/05/GHSA-wpmf-xc6q-mrfq/GHSA-wpmf-xc6q-mrfq.json
@@ -7,12 +7,8 @@
"CVE-2007-3340"
],
"details": "BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for nonexistent pages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-wqfm-r7wm-f27r/GHSA-wqfm-r7wm-f27r.json b/advisories/unreviewed/2022/05/GHSA-wqfm-r7wm-f27r/GHSA-wqfm-r7wm-f27r.json
index cae3226ae52..4ee768bef20 100644
--- a/advisories/unreviewed/2022/05/GHSA-wqfm-r7wm-f27r/GHSA-wqfm-r7wm-f27r.json
+++ b/advisories/unreviewed/2022/05/GHSA-wqfm-r7wm-f27r/GHSA-wqfm-r7wm-f27r.json
@@ -7,12 +7,8 @@
"CVE-2007-3442"
],
"details": "Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wqwf-8hjj-2c34/GHSA-wqwf-8hjj-2c34.json b/advisories/unreviewed/2022/05/GHSA-wqwf-8hjj-2c34/GHSA-wqwf-8hjj-2c34.json
index 7d554d33756..b68b4c8e13e 100644
--- a/advisories/unreviewed/2022/05/GHSA-wqwf-8hjj-2c34/GHSA-wqwf-8hjj-2c34.json
+++ b/advisories/unreviewed/2022/05/GHSA-wqwf-8hjj-2c34/GHSA-wqwf-8hjj-2c34.json
@@ -7,12 +7,8 @@
"CVE-2007-3693"
],
"details": "Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search function.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wqxw-p9c6-v664/GHSA-wqxw-p9c6-v664.json b/advisories/unreviewed/2022/05/GHSA-wqxw-p9c6-v664/GHSA-wqxw-p9c6-v664.json
index 3c55c8ad777..c47f1c4be67 100644
--- a/advisories/unreviewed/2022/05/GHSA-wqxw-p9c6-v664/GHSA-wqxw-p9c6-v664.json
+++ b/advisories/unreviewed/2022/05/GHSA-wqxw-p9c6-v664/GHSA-wqxw-p9c6-v664.json
@@ -7,12 +7,8 @@
"CVE-2007-3284"
],
"details": "corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wrqr-xfx4-g626/GHSA-wrqr-xfx4-g626.json b/advisories/unreviewed/2022/05/GHSA-wrqr-xfx4-g626/GHSA-wrqr-xfx4-g626.json
index e87c4e23716..7cda7d3ca74 100644
--- a/advisories/unreviewed/2022/05/GHSA-wrqr-xfx4-g626/GHSA-wrqr-xfx4-g626.json
+++ b/advisories/unreviewed/2022/05/GHSA-wrqr-xfx4-g626/GHSA-wrqr-xfx4-g626.json
@@ -7,12 +7,8 @@
"CVE-2007-3663"
],
"details": "Divide-by-zero error in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted MPA file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wvhf-3vfg-f285/GHSA-wvhf-3vfg-f285.json b/advisories/unreviewed/2022/05/GHSA-wvhf-3vfg-f285/GHSA-wvhf-3vfg-f285.json
index 542e981344f..3a0f05309b4 100644
--- a/advisories/unreviewed/2022/05/GHSA-wvhf-3vfg-f285/GHSA-wvhf-3vfg-f285.json
+++ b/advisories/unreviewed/2022/05/GHSA-wvhf-3vfg-f285/GHSA-wvhf-3vfg-f285.json
@@ -7,12 +7,8 @@
"CVE-2007-3470"
],
"details": "Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to \"memory buffers\" of Secure Socket Layer (SSL) records.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-ww42-ch2p-4w5x/GHSA-ww42-ch2p-4w5x.json b/advisories/unreviewed/2022/05/GHSA-ww42-ch2p-4w5x/GHSA-ww42-ch2p-4w5x.json
index cb8cda8a42a..7d94fed0eed 100644
--- a/advisories/unreviewed/2022/05/GHSA-ww42-ch2p-4w5x/GHSA-ww42-ch2p-4w5x.json
+++ b/advisories/unreviewed/2022/05/GHSA-ww42-ch2p-4w5x/GHSA-ww42-ch2p-4w5x.json
@@ -7,12 +7,8 @@
"CVE-2007-3753"
],
"details": "Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Service Discovery Protocol (SDP) packets, related to insufficient input validation.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-wwm7-8cp9-2h4f/GHSA-wwm7-8cp9-2h4f.json b/advisories/unreviewed/2022/05/GHSA-wwm7-8cp9-2h4f/GHSA-wwm7-8cp9-2h4f.json
index 2f63a34e67e..293b1e045f3 100644
--- a/advisories/unreviewed/2022/05/GHSA-wwm7-8cp9-2h4f/GHSA-wwm7-8cp9-2h4f.json
+++ b/advisories/unreviewed/2022/05/GHSA-wwm7-8cp9-2h4f/GHSA-wwm7-8cp9-2h4f.json
@@ -7,12 +7,8 @@
"CVE-2007-3799"
],
"details": "The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-wwr9-w8xj-rh7w/GHSA-wwr9-w8xj-rh7w.json b/advisories/unreviewed/2022/05/GHSA-wwr9-w8xj-rh7w/GHSA-wwr9-w8xj-rh7w.json
index 3beb612f583..42e2b74ac10 100644
--- a/advisories/unreviewed/2022/05/GHSA-wwr9-w8xj-rh7w/GHSA-wwr9-w8xj-rh7w.json
+++ b/advisories/unreviewed/2022/05/GHSA-wwr9-w8xj-rh7w/GHSA-wwr9-w8xj-rh7w.json
@@ -7,12 +7,8 @@
"CVE-2007-3779"
],
"details": "PHP local file inclusion vulnerability in gpg_pop_init.php in the G/PGP (GPG) Plugin before 20070707 for Squirrelmail allows remote attackers to include and execute arbitrary local files, related to the MOD parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-wwvp-jhg6-qpxv/GHSA-wwvp-jhg6-qpxv.json b/advisories/unreviewed/2022/05/GHSA-wwvp-jhg6-qpxv/GHSA-wwvp-jhg6-qpxv.json
index 4a621119039..df74cac67f8 100644
--- a/advisories/unreviewed/2022/05/GHSA-wwvp-jhg6-qpxv/GHSA-wwvp-jhg6-qpxv.json
+++ b/advisories/unreviewed/2022/05/GHSA-wwvp-jhg6-qpxv/GHSA-wwvp-jhg6-qpxv.json
@@ -7,12 +7,8 @@
"CVE-2007-3650"
],
"details": "myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-wwx9-h5pq-vhh5/GHSA-wwx9-h5pq-vhh5.json b/advisories/unreviewed/2022/05/GHSA-wwx9-h5pq-vhh5/GHSA-wwx9-h5pq-vhh5.json
index 3080261ad21..b159d180c6d 100644
--- a/advisories/unreviewed/2022/05/GHSA-wwx9-h5pq-vhh5/GHSA-wwx9-h5pq-vhh5.json
+++ b/advisories/unreviewed/2022/05/GHSA-wwx9-h5pq-vhh5/GHSA-wwx9-h5pq-vhh5.json
@@ -7,12 +7,8 @@
"CVE-2007-3515"
],
"details": "SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x289-7h64-434h/GHSA-x289-7h64-434h.json b/advisories/unreviewed/2022/05/GHSA-x289-7h64-434h/GHSA-x289-7h64-434h.json
index 5857010dba0..07eb97111db 100644
--- a/advisories/unreviewed/2022/05/GHSA-x289-7h64-434h/GHSA-x289-7h64-434h.json
+++ b/advisories/unreviewed/2022/05/GHSA-x289-7h64-434h/GHSA-x289-7h64-434h.json
@@ -7,12 +7,8 @@
"CVE-2007-3957"
],
"details": "Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x2pw-f7w4-wmj2/GHSA-x2pw-f7w4-wmj2.json b/advisories/unreviewed/2022/05/GHSA-x2pw-f7w4-wmj2/GHSA-x2pw-f7w4-wmj2.json
index d72ab3ca446..056599868e0 100644
--- a/advisories/unreviewed/2022/05/GHSA-x2pw-f7w4-wmj2/GHSA-x2pw-f7w4-wmj2.json
+++ b/advisories/unreviewed/2022/05/GHSA-x2pw-f7w4-wmj2/GHSA-x2pw-f7w4-wmj2.json
@@ -7,12 +7,8 @@
"CVE-2007-3346"
],
"details": "Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x36m-283q-4ccw/GHSA-x36m-283q-4ccw.json b/advisories/unreviewed/2022/05/GHSA-x36m-283q-4ccw/GHSA-x36m-283q-4ccw.json
index 9bfe281f425..93a115438e8 100644
--- a/advisories/unreviewed/2022/05/GHSA-x36m-283q-4ccw/GHSA-x36m-283q-4ccw.json
+++ b/advisories/unreviewed/2022/05/GHSA-x36m-283q-4ccw/GHSA-x36m-283q-4ccw.json
@@ -7,12 +7,8 @@
"CVE-2007-3398"
],
"details": "LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x3hm-wxfj-93jm/GHSA-x3hm-wxfj-93jm.json b/advisories/unreviewed/2022/05/GHSA-x3hm-wxfj-93jm/GHSA-x3hm-wxfj-93jm.json
index e0472273b9b..b5372d6f2ea 100644
--- a/advisories/unreviewed/2022/05/GHSA-x3hm-wxfj-93jm/GHSA-x3hm-wxfj-93jm.json
+++ b/advisories/unreviewed/2022/05/GHSA-x3hm-wxfj-93jm/GHSA-x3hm-wxfj-93jm.json
@@ -7,12 +7,8 @@
"CVE-2007-3579"
],
"details": "PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x4mf-mcmh-f5fv/GHSA-x4mf-mcmh-f5fv.json b/advisories/unreviewed/2022/05/GHSA-x4mf-mcmh-f5fv/GHSA-x4mf-mcmh-f5fv.json
index a6ac26c9c18..addef1eb278 100644
--- a/advisories/unreviewed/2022/05/GHSA-x4mf-mcmh-f5fv/GHSA-x4mf-mcmh-f5fv.json
+++ b/advisories/unreviewed/2022/05/GHSA-x4mf-mcmh-f5fv/GHSA-x4mf-mcmh-f5fv.json
@@ -7,12 +7,8 @@
"CVE-2007-3432"
],
"details": "Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x538-f2g7-g99g/GHSA-x538-f2g7-g99g.json b/advisories/unreviewed/2022/05/GHSA-x538-f2g7-g99g/GHSA-x538-f2g7-g99g.json
index 70e4a69b965..dbdaec9de12 100644
--- a/advisories/unreviewed/2022/05/GHSA-x538-f2g7-g99g/GHSA-x538-f2g7-g99g.json
+++ b/advisories/unreviewed/2022/05/GHSA-x538-f2g7-g99g/GHSA-x538-f2g7-g99g.json
@@ -7,12 +7,8 @@
"CVE-2007-3536"
],
"details": "Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x5cx-jmq5-8g38/GHSA-x5cx-jmq5-8g38.json b/advisories/unreviewed/2022/05/GHSA-x5cx-jmq5-8g38/GHSA-x5cx-jmq5-8g38.json
index 7a6b7453fb1..b37809efcb3 100644
--- a/advisories/unreviewed/2022/05/GHSA-x5cx-jmq5-8g38/GHSA-x5cx-jmq5-8g38.json
+++ b/advisories/unreviewed/2022/05/GHSA-x5cx-jmq5-8g38/GHSA-x5cx-jmq5-8g38.json
@@ -7,12 +7,8 @@
"CVE-2007-3487"
],
"details": "Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-x5ff-24v2-wj9j/GHSA-x5ff-24v2-wj9j.json b/advisories/unreviewed/2022/05/GHSA-x5ff-24v2-wj9j/GHSA-x5ff-24v2-wj9j.json
index f045465694a..240f5816988 100644
--- a/advisories/unreviewed/2022/05/GHSA-x5ff-24v2-wj9j/GHSA-x5ff-24v2-wj9j.json
+++ b/advisories/unreviewed/2022/05/GHSA-x5ff-24v2-wj9j/GHSA-x5ff-24v2-wj9j.json
@@ -7,12 +7,8 @@
"CVE-2007-3806"
],
"details": "The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-x7c7-97cr-xfrf/GHSA-x7c7-97cr-xfrf.json b/advisories/unreviewed/2022/05/GHSA-x7c7-97cr-xfrf/GHSA-x7c7-97cr-xfrf.json
index 6a35404967a..f895ba1b949 100644
--- a/advisories/unreviewed/2022/05/GHSA-x7c7-97cr-xfrf/GHSA-x7c7-97cr-xfrf.json
+++ b/advisories/unreviewed/2022/05/GHSA-x7c7-97cr-xfrf/GHSA-x7c7-97cr-xfrf.json
@@ -7,12 +7,8 @@
"CVE-2007-3318"
],
"details": "Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (call reception outage) via a malformed SIP message.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x7cg-jfmw-c453/GHSA-x7cg-jfmw-c453.json b/advisories/unreviewed/2022/05/GHSA-x7cg-jfmw-c453/GHSA-x7cg-jfmw-c453.json
index 97c8be33d12..2e44e94bd78 100644
--- a/advisories/unreviewed/2022/05/GHSA-x7cg-jfmw-c453/GHSA-x7cg-jfmw-c453.json
+++ b/advisories/unreviewed/2022/05/GHSA-x7cg-jfmw-c453/GHSA-x7cg-jfmw-c453.json
@@ -7,12 +7,8 @@
"CVE-2007-3343"
],
"details": "Cross-site scripting (XSS) vulnerability in RaidenHTTPD before 2.0.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x7qf-6495-r9hp/GHSA-x7qf-6495-r9hp.json b/advisories/unreviewed/2022/05/GHSA-x7qf-6495-r9hp/GHSA-x7qf-6495-r9hp.json
index 7014cb8142b..5fda9770a45 100644
--- a/advisories/unreviewed/2022/05/GHSA-x7qf-6495-r9hp/GHSA-x7qf-6495-r9hp.json
+++ b/advisories/unreviewed/2022/05/GHSA-x7qf-6495-r9hp/GHSA-x7qf-6495-r9hp.json
@@ -7,12 +7,8 @@
"CVE-2007-3815"
],
"details": "Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x8gp-4pg8-hx24/GHSA-x8gp-4pg8-hx24.json b/advisories/unreviewed/2022/05/GHSA-x8gp-4pg8-hx24/GHSA-x8gp-4pg8-hx24.json
index 4223bce6093..e5b80e4b9b9 100644
--- a/advisories/unreviewed/2022/05/GHSA-x8gp-4pg8-hx24/GHSA-x8gp-4pg8-hx24.json
+++ b/advisories/unreviewed/2022/05/GHSA-x8gp-4pg8-hx24/GHSA-x8gp-4pg8-hx24.json
@@ -7,12 +7,8 @@
"CVE-2007-3295"
],
"details": "Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the member hash, and is propagated to the language variable in (1) HelpCentre.pl and (2) ICQPager.pl, (3) the use_lang variable in Subs.pl, and the actlang variable in (4) Post.pl and (5) InstantMessage.pl; as demonstrated by pointing userlanguage to the English folder, modifying English/HelpCentre.lng file to contain Perl statements, and then invoking the help action in YaBB.pl.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x8mw-87h3-52hg/GHSA-x8mw-87h3-52hg.json b/advisories/unreviewed/2022/05/GHSA-x8mw-87h3-52hg/GHSA-x8mw-87h3-52hg.json
index f744a2e38b8..72bef024013 100644
--- a/advisories/unreviewed/2022/05/GHSA-x8mw-87h3-52hg/GHSA-x8mw-87h3-52hg.json
+++ b/advisories/unreviewed/2022/05/GHSA-x8mw-87h3-52hg/GHSA-x8mw-87h3-52hg.json
@@ -7,12 +7,8 @@
"CVE-2007-3714"
],
"details": "Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this is probably a different issue than CVE-2004-2464. NOTE: it was later reported that 0.6.21 and earlier is also affected.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-x96g-cvf2-237v/GHSA-x96g-cvf2-237v.json b/advisories/unreviewed/2022/05/GHSA-x96g-cvf2-237v/GHSA-x96g-cvf2-237v.json
index 775059af238..eeebb966ee5 100644
--- a/advisories/unreviewed/2022/05/GHSA-x96g-cvf2-237v/GHSA-x96g-cvf2-237v.json
+++ b/advisories/unreviewed/2022/05/GHSA-x96g-cvf2-237v/GHSA-x96g-cvf2-237v.json
@@ -7,12 +7,8 @@
"CVE-2007-3232"
],
"details": "The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xc38-vmxr-3cx5/GHSA-xc38-vmxr-3cx5.json b/advisories/unreviewed/2022/05/GHSA-xc38-vmxr-3cx5/GHSA-xc38-vmxr-3cx5.json
index 915f90fb0fa..108efb41c4a 100644
--- a/advisories/unreviewed/2022/05/GHSA-xc38-vmxr-3cx5/GHSA-xc38-vmxr-3cx5.json
+++ b/advisories/unreviewed/2022/05/GHSA-xc38-vmxr-3cx5/GHSA-xc38-vmxr-3cx5.json
@@ -7,12 +7,8 @@
"CVE-2007-3307"
],
"details": "SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xc6c-w4cc-h95v/GHSA-xc6c-w4cc-h95v.json b/advisories/unreviewed/2022/05/GHSA-xc6c-w4cc-h95v/GHSA-xc6c-w4cc-h95v.json
index 3854f83d4db..3ac8d7ad91e 100644
--- a/advisories/unreviewed/2022/05/GHSA-xc6c-w4cc-h95v/GHSA-xc6c-w4cc-h95v.json
+++ b/advisories/unreviewed/2022/05/GHSA-xc6c-w4cc-h95v/GHSA-xc6c-w4cc-h95v.json
@@ -7,12 +7,8 @@
"CVE-2007-3618"
],
"details": "Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a \"long invalid subcmd.\"",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -56,9 +52,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xg2j-5v2f-c764/GHSA-xg2j-5v2f-c764.json b/advisories/unreviewed/2022/05/GHSA-xg2j-5v2f-c764/GHSA-xg2j-5v2f-c764.json
index 2fe890aa8ba..1dfd58cfb6e 100644
--- a/advisories/unreviewed/2022/05/GHSA-xg2j-5v2f-c764/GHSA-xg2j-5v2f-c764.json
+++ b/advisories/unreviewed/2022/05/GHSA-xg2j-5v2f-c764/GHSA-xg2j-5v2f-c764.json
@@ -7,12 +7,8 @@
"CVE-2007-3510"
],
"details": "Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-xgp8-x9mp-9656/GHSA-xgp8-x9mp-9656.json b/advisories/unreviewed/2022/05/GHSA-xgp8-x9mp-9656/GHSA-xgp8-x9mp-9656.json
index db8c888f299..278f8dd9c11 100644
--- a/advisories/unreviewed/2022/05/GHSA-xgp8-x9mp-9656/GHSA-xgp8-x9mp-9656.json
+++ b/advisories/unreviewed/2022/05/GHSA-xgp8-x9mp-9656/GHSA-xgp8-x9mp-9656.json
@@ -7,12 +7,8 @@
"CVE-2007-3710"
],
"details": "PHP remote file inclusion vulnerability in example/gamedemo/inc.functions.php in PHP Comet-Server allows remote attackers to execute arbitrary PHP code via a URL in the projectPath parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xh77-g4qv-rh25/GHSA-xh77-g4qv-rh25.json b/advisories/unreviewed/2022/05/GHSA-xh77-g4qv-rh25/GHSA-xh77-g4qv-rh25.json
index 6886cde226a..ac5ff840fe5 100644
--- a/advisories/unreviewed/2022/05/GHSA-xh77-g4qv-rh25/GHSA-xh77-g4qv-rh25.json
+++ b/advisories/unreviewed/2022/05/GHSA-xh77-g4qv-rh25/GHSA-xh77-g4qv-rh25.json
@@ -7,12 +7,8 @@
"CVE-2007-3488"
],
"details": "Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W, SNC-RX570N/B, SNC-RX550N/W, SNC-RX550N/B, SNC-RX530N/W, and SNC-RX530N/B 3.00 and 2.x before 2.31; allows remote attackers to execute arbitrary code via a long first argument to the PrmSetNetworkParam method.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xp3w-m47v-rv5p/GHSA-xp3w-m47v-rv5p.json b/advisories/unreviewed/2022/05/GHSA-xp3w-m47v-rv5p/GHSA-xp3w-m47v-rv5p.json
index b2a5db17b68..66ded93b147 100644
--- a/advisories/unreviewed/2022/05/GHSA-xp3w-m47v-rv5p/GHSA-xp3w-m47v-rv5p.json
+++ b/advisories/unreviewed/2022/05/GHSA-xp3w-m47v-rv5p/GHSA-xp3w-m47v-rv5p.json
@@ -7,12 +7,8 @@
"CVE-2007-3493"
],
"details": "A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xp89-62wf-p429/GHSA-xp89-62wf-p429.json b/advisories/unreviewed/2022/05/GHSA-xp89-62wf-p429/GHSA-xp89-62wf-p429.json
index 587ff47dd04..9177990a2f2 100644
--- a/advisories/unreviewed/2022/05/GHSA-xp89-62wf-p429/GHSA-xp89-62wf-p429.json
+++ b/advisories/unreviewed/2022/05/GHSA-xp89-62wf-p429/GHSA-xp89-62wf-p429.json
@@ -7,12 +7,8 @@
"CVE-2007-3758"
],
"details": "Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cross-site scripting (XSS) attacks.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-xp8f-x545-6j5r/GHSA-xp8f-x545-6j5r.json b/advisories/unreviewed/2022/05/GHSA-xp8f-x545-6j5r/GHSA-xp8f-x545-6j5r.json
index a50d7f2dd84..4a88c7db105 100644
--- a/advisories/unreviewed/2022/05/GHSA-xp8f-x545-6j5r/GHSA-xp8f-x545-6j5r.json
+++ b/advisories/unreviewed/2022/05/GHSA-xp8f-x545-6j5r/GHSA-xp8f-x545-6j5r.json
@@ -7,12 +7,8 @@
"CVE-2007-3563"
],
"details": "SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2022/05/GHSA-xq2x-m5mh-fh59/GHSA-xq2x-m5mh-fh59.json b/advisories/unreviewed/2022/05/GHSA-xq2x-m5mh-fh59/GHSA-xq2x-m5mh-fh59.json
index 8015066d43d..f7621a4dfd3 100644
--- a/advisories/unreviewed/2022/05/GHSA-xq2x-m5mh-fh59/GHSA-xq2x-m5mh-fh59.json
+++ b/advisories/unreviewed/2022/05/GHSA-xq2x-m5mh-fh59/GHSA-xq2x-m5mh-fh59.json
@@ -7,12 +7,8 @@
"CVE-2007-3325"
],
"details": "PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xrj9-vwwj-2w2c/GHSA-xrj9-vwwj-2w2c.json b/advisories/unreviewed/2022/05/GHSA-xrj9-vwwj-2w2c/GHSA-xrj9-vwwj-2w2c.json
index 44d6da7d860..d6e67c31ea5 100644
--- a/advisories/unreviewed/2022/05/GHSA-xrj9-vwwj-2w2c/GHSA-xrj9-vwwj-2w2c.json
+++ b/advisories/unreviewed/2022/05/GHSA-xrj9-vwwj-2w2c/GHSA-xrj9-vwwj-2w2c.json
@@ -7,12 +7,8 @@
"CVE-2007-3221"
],
"details": "PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xrxm-c9j3-54pp/GHSA-xrxm-c9j3-54pp.json b/advisories/unreviewed/2022/05/GHSA-xrxm-c9j3-54pp/GHSA-xrxm-c9j3-54pp.json
index cc6c2df1c22..4306bd10735 100644
--- a/advisories/unreviewed/2022/05/GHSA-xrxm-c9j3-54pp/GHSA-xrxm-c9j3-54pp.json
+++ b/advisories/unreviewed/2022/05/GHSA-xrxm-c9j3-54pp/GHSA-xrxm-c9j3-54pp.json
@@ -7,12 +7,8 @@
"CVE-2007-3676"
],
"details": "IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xv4p-rc8w-pq62/GHSA-xv4p-rc8w-pq62.json b/advisories/unreviewed/2022/05/GHSA-xv4p-rc8w-pq62/GHSA-xv4p-rc8w-pq62.json
index 747cdf8e8dc..e546e3d8675 100644
--- a/advisories/unreviewed/2022/05/GHSA-xv4p-rc8w-pq62/GHSA-xv4p-rc8w-pq62.json
+++ b/advisories/unreviewed/2022/05/GHSA-xv4p-rc8w-pq62/GHSA-xv4p-rc8w-pq62.json
@@ -7,12 +7,8 @@
"CVE-2007-3358"
],
"details": "PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/05/GHSA-xxxv-6j6h-6fqv/GHSA-xxxv-6j6h-6fqv.json b/advisories/unreviewed/2022/05/GHSA-xxxv-6j6h-6fqv/GHSA-xxxv-6j6h-6fqv.json
index 84b845b7cf2..990cd8116fd 100644
--- a/advisories/unreviewed/2022/05/GHSA-xxxv-6j6h-6fqv/GHSA-xxxv-6j6h-6fqv.json
+++ b/advisories/unreviewed/2022/05/GHSA-xxxv-6j6h-6fqv/GHSA-xxxv-6j6h-6fqv.json
@@ -7,12 +7,8 @@
"CVE-2007-3489"
],
"details": "Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-q833-5r3h-2vq9/GHSA-q833-5r3h-2vq9.json b/advisories/unreviewed/2024/02/GHSA-q833-5r3h-2vq9/GHSA-q833-5r3h-2vq9.json
index cee10f41e50..525fbba354c 100644
--- a/advisories/unreviewed/2024/02/GHSA-q833-5r3h-2vq9/GHSA-q833-5r3h-2vq9.json
+++ b/advisories/unreviewed/2024/02/GHSA-q833-5r3h-2vq9/GHSA-q833-5r3h-2vq9.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json b/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json
index 7c6b5123348..1deb9b85450 100644
--- a/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json
+++ b/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json b/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json
index 6091b2e8dff..834c8819ed1 100644
--- a/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json
+++ b/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json b/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json
index e61c2dafa04..7a01f9dcf24 100644
--- a/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json
+++ b/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json b/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json
index d8629ca17c4..01edc5deb4c 100644
--- a/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json
+++ b/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json b/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json
index 6dee2b607b8..14c38a9d9ba 100644
--- a/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json
+++ b/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json b/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json
index 51e0908c5d7..1460ca1c06e 100644
--- a/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json
+++ b/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json b/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json
index 5b225291cfa..aeabc4ce89a 100644
--- a/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json
+++ b/advisories/unreviewed/2024/04/GHSA-85q5-wrpf-m53q/GHSA-85q5-wrpf-m53q.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -35,9 +33,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-9cx2-p53m-9qp4/GHSA-9cx2-p53m-9qp4.json b/advisories/unreviewed/2024/04/GHSA-9cx2-p53m-9qp4/GHSA-9cx2-p53m-9qp4.json
index 668b30fce74..105072bb81e 100644
--- a/advisories/unreviewed/2024/04/GHSA-9cx2-p53m-9qp4/GHSA-9cx2-p53m-9qp4.json
+++ b/advisories/unreviewed/2024/04/GHSA-9cx2-p53m-9qp4/GHSA-9cx2-p53m-9qp4.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json b/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json
index e7b2fed28c0..430928fdde1 100644
--- a/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json
+++ b/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json b/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json
index eb75d38f99e..100990bbcd3 100644
--- a/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json
+++ b/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json b/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json
index aa7f063d2cd..511ea091d61 100644
--- a/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json
+++ b/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json
@@ -7,12 +7,8 @@
"CVE-2024-28065"
],
"details": "In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json b/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json
index 339de6dd98b..58bf0766a9b 100644
--- a/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json
+++ b/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json b/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json
index 1c15511f888..11acee8c52b 100644
--- a/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json
+++ b/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json b/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json
index 59b9712d5ab..820f937d6c6 100644
--- a/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json
+++ b/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json b/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json
index 3609e0842a5..54804c53f04 100644
--- a/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json
+++ b/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json b/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json
index 51cfd34965b..3c2aad47ab4 100644
--- a/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json
+++ b/advisories/unreviewed/2024/04/GHSA-fgh4-9fc9-vxgv/GHSA-fgh4-9fc9-vxgv.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json b/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json
index 38216e9ad04..b02cd2b8963 100644
--- a/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json
+++ b/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json b/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json
index 46164071bef..d7f9a623ce1 100644
--- a/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json
+++ b/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-h282-h49g-gvfm/GHSA-h282-h49g-gvfm.json b/advisories/unreviewed/2024/04/GHSA-h282-h49g-gvfm/GHSA-h282-h49g-gvfm.json
index b2a0382d1ca..d4cbde148fc 100644
--- a/advisories/unreviewed/2024/04/GHSA-h282-h49g-gvfm/GHSA-h282-h49g-gvfm.json
+++ b/advisories/unreviewed/2024/04/GHSA-h282-h49g-gvfm/GHSA-h282-h49g-gvfm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json b/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json
index 7b0783d20d3..076aad9576a 100644
--- a/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json
+++ b/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json b/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json
index 6fdcc9908ce..78945866dec 100644
--- a/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json
+++ b/advisories/unreviewed/2024/04/GHSA-j2g4-vr97-pwvm/GHSA-j2g4-vr97-pwvm.json
@@ -7,12 +7,8 @@
"CVE-2024-26750"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Drop oob_skb ref before purging queue in GC.\n\nsyzbot reported another task hung in __unix_gc(). [0]\n\nThe current while loop assumes that all of the left candidates\nhave oob_skb and calling kfree_skb(oob_skb) releases the remaining\ncandidates.\n\nHowever, I missed a case that oob_skb has self-referencing fd and\nanother fd and the latter sk is placed before the former in the\ncandidate list. Then, the while loop never proceeds, resulting\nthe task hung.\n\n__unix_gc() has the same loop just before purging the collected skb,\nso we can call kfree_skb(oob_skb) there and let __skb_queue_purge()\nrelease all inflight sockets.\n\n[0]:\nSending NMI from CPU 0 to CPUs 1:\nNMI backtrace for cpu 1\nCPU: 1 PID: 2784 Comm: kworker/u4:8 Not tainted 6.8.0-rc4-syzkaller-01028-g71b605d32017 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nWorkqueue: events_unbound __unix_gc\nRIP: 0010:__sanitizer_cov_trace_pc+0x0/0x70 kernel/kcov.c:200\nCode: 89 fb e8 23 00 00 00 48 8b 3d 84 f5 1a 0c 48 89 de 5b e9 43 26 57 00 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1e fa 48 8b 04 24 65 48 8b 0d 90 52 70 7e 65 8b 15 91 52 70\nRSP: 0018:ffffc9000a17fa78 EFLAGS: 00000287\nRAX: ffffffff8a0a6108 RBX: ffff88802b6c2640 RCX: ffff88802c0b3b80\nRDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000000\nRBP: ffffc9000a17fbf0 R08: ffffffff89383f1d R09: 1ffff1100ee5ff84\nR10: dffffc0000000000 R11: ffffed100ee5ff85 R12: 1ffff110056d84ee\nR13: ffffc9000a17fae0 R14: 0000000000000000 R15: ffffffff8f47b840\nFS: 0000000000000000(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffef5687ff8 CR3: 0000000029b34000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n \n \n __unix_gc+0xe69/0xf40 net/unix/garbage.c:343\n process_one_work kernel/workqueue.c:2633 [inline]\n process_scheduled_works+0x913/0x1420 kernel/workqueue.c:2706\n worker_thread+0xa5f/0x1000 kernel/workqueue.c:2787\n kthread+0x2ef/0x390 kernel/kthread.c:388\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:242\n ",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json b/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json
index bbfdba95770..1246554df52 100644
--- a/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json
+++ b/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json b/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json
index e9b9a87fe35..082ad66f485 100644
--- a/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json
+++ b/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json
@@ -7,12 +7,8 @@
"CVE-2024-29753"
],
"details": "In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json b/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json
index 075b9fb779c..912487c2b59 100644
--- a/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json
+++ b/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json b/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json
index 6ee019394d4..34bf625786f 100644
--- a/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json
+++ b/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json b/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json
index 77dbd5b20fb..910f19e1c73 100644
--- a/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json
+++ b/advisories/unreviewed/2024/04/GHSA-q4hp-86wf-hj44/GHSA-q4hp-86wf-hj44.json
@@ -7,12 +7,8 @@
"CVE-2024-26800"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix use-after-free on failed backlog decryption\n\nWhen the decrypt request goes to the backlog and crypto_aead_decrypt\nreturns -EBUSY, tls_do_decryption will wait until all async\ndecryptions have completed. If one of them fails, tls_do_decryption\nwill return -EBADMSG and tls_decrypt_sg jumps to the error path,\nreleasing all the pages. But the pages have been passed to the async\ncallback, and have already been released by tls_decrypt_done.\n\nThe only true async case is when crypto_aead_decrypt returns\n -EINPROGRESS. With -EBUSY, we already waited so we can tell\ntls_sw_recvmsg that the data is available for immediate copy, but we\nneed to notify tls_decrypt_sg (via the new ->async_done flag) that the\nmemory has already been released.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json b/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json
index 38bf6f10dcd..30550175f73 100644
--- a/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json
+++ b/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json b/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json
index 6aea3b161a3..d98fea6c4ac 100644
--- a/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json
+++ b/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json b/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json
index 5687775e16c..4ece47fd826 100644
--- a/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json
+++ b/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json b/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json
index fc8d56d800a..d56244e2c72 100644
--- a/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json
+++ b/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json b/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json
index c620520d991..a55ab47ee5d 100644
--- a/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json
+++ b/advisories/unreviewed/2024/04/GHSA-r7p6-cff4-g6q4/GHSA-r7p6-cff4-g6q4.json
@@ -7,12 +7,8 @@
"CVE-2024-26802"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstmmac: Clear variable when destroying workqueue\n\nCurrently when suspending driver and stopping workqueue it is checked whether\nworkqueue is not NULL and if so, it is destroyed.\nFunction destroy_workqueue() does drain queue and does clear variable, but\nit does not set workqueue variable to NULL. This can cause kernel/module\npanic if code attempts to clear workqueue that was not initialized.\n\nThis scenario is possible when resuming suspended driver in stmmac_resume(),\nbecause there is no handling for failed stmmac_hw_setup(),\nwhich can fail and return if DMA engine has failed to initialize,\nand workqueue is initialized after DMA engine.\nShould DMA engine fail to initialize, resume will proceed normally,\nbut interface won't work and TX queue will eventually timeout,\ncausing 'Reset adapter' error.\nThis then does destroy workqueue during reset process.\nAnd since workqueue is initialized after DMA engine and can be skipped,\nit will cause kernel/module panic.\n\nTo secure against this possible crash, set workqueue variable to NULL when\ndestroying workqueue.\n\nLog/backtrace from crash goes as follows:\n[88.031977]------------[ cut here ]------------\n[88.031985]NETDEV WATCHDOG: eth0 (sxgmac): transmit queue 1 timed out\n[88.032017]WARNING: CPU: 0 PID: 0 at net/sched/sch_generic.c:477 dev_watchdog+0x390/0x398\n \n[88.032251]---[ end trace e70de432e4d5c2c0 ]---\n[88.032282]sxgmac 16d88000.ethernet eth0: Reset adapter.\n[88.036359]------------[ cut here ]------------\n[88.036519]Call trace:\n[88.036523] flush_workqueue+0x3e4/0x430\n[88.036528] drain_workqueue+0xc4/0x160\n[88.036533] destroy_workqueue+0x40/0x270\n[88.036537] stmmac_fpe_stop_wq+0x4c/0x70\n[88.036541] stmmac_release+0x278/0x280\n[88.036546] __dev_close_many+0xcc/0x158\n[88.036551] dev_close_many+0xbc/0x190\n[88.036555] dev_close.part.0+0x70/0xc0\n[88.036560] dev_close+0x24/0x30\n[88.036564] stmmac_service_task+0x110/0x140\n[88.036569] process_one_work+0x1d8/0x4a0\n[88.036573] worker_thread+0x54/0x408\n[88.036578] kthread+0x164/0x170\n[88.036583] ret_from_fork+0x10/0x20\n[88.036588]---[ end trace e70de432e4d5c2c1 ]---\n[88.036597]Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json b/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json
index cd840766dd5..af613502e4f 100644
--- a/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json
+++ b/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json b/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json
index 8eb764d917c..d5c382ef1f1 100644
--- a/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json
+++ b/advisories/unreviewed/2024/04/GHSA-rmrx-q6x5-whjx/GHSA-rmrx-q6x5-whjx.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json b/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json
index 89062bae11e..93939231f2e 100644
--- a/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json
+++ b/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json b/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json
index b79422e150d..63a70f78297 100644
--- a/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json
+++ b/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json b/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json
index 1947e5cd131..40763b45182 100644
--- a/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json
+++ b/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json b/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json
index 50219fa317a..a8fc19f506d 100644
--- a/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json
+++ b/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json
@@ -7,12 +7,8 @@
"CVE-2024-29006"
],
"details": "By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json b/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json
index 9d7e5d2953e..6e823242395 100644
--- a/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json
+++ b/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json
@@ -7,12 +7,8 @@
"CVE-2024-26806"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks\n\nThe ->runtime_suspend() and ->runtime_resume() callbacks are not\nexpected to call spi_controller_suspend() and spi_controller_resume().\nRemove calls to those in the cadence-qspi driver.\n\nThose helpers have two roles currently:\n - They stop/start the queue, including dealing with the kworker.\n - They toggle the SPI controller SPI_CONTROLLER_SUSPENDED flag. It\n requires acquiring ctlr->bus_lock_mutex.\n\nStep one is irrelevant because cadence-qspi is not queued. Step two\nhowever has two implications:\n - A deadlock occurs, because ->runtime_resume() is called in a context\n where the lock is already taken (in the ->exec_op() callback, where\n the usage count is incremented).\n - It would disallow all operations once the device is auto-suspended.\n\nHere is a brief call tree highlighting the mutex deadlock:\n\nspi_mem_exec_op()\n ...\n spi_mem_access_start()\n mutex_lock(&ctlr->bus_lock_mutex)\n\n cqspi_exec_mem_op()\n pm_runtime_resume_and_get()\n cqspi_resume()\n spi_controller_resume()\n mutex_lock(&ctlr->bus_lock_mutex)\n ...\n\n spi_mem_access_end()\n mutex_unlock(&ctlr->bus_lock_mutex)\n ...",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json b/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json
index 10e09381539..be3ef59c9ac 100644
--- a/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json
+++ b/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json b/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json
index f7feda94f46..4729824f0b7 100644
--- a/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json
+++ b/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json b/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json
index ddca9cde2a8..6d08879063e 100644
--- a/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json
+++ b/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json b/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json
index 93ae35ac19f..c0bab29aaf6 100644
--- a/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json
+++ b/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/05/GHSA-5cqc-m9rw-57r9/GHSA-5cqc-m9rw-57r9.json b/advisories/unreviewed/2024/05/GHSA-5cqc-m9rw-57r9/GHSA-5cqc-m9rw-57r9.json
index 27de0a5626a..188f8452aab 100644
--- a/advisories/unreviewed/2024/05/GHSA-5cqc-m9rw-57r9/GHSA-5cqc-m9rw-57r9.json
+++ b/advisories/unreviewed/2024/05/GHSA-5cqc-m9rw-57r9/GHSA-5cqc-m9rw-57r9.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/05/GHSA-9wjv-frj6-hjv9/GHSA-9wjv-frj6-hjv9.json b/advisories/unreviewed/2024/05/GHSA-9wjv-frj6-hjv9/GHSA-9wjv-frj6-hjv9.json
index c487bdc133e..f698d664018 100644
--- a/advisories/unreviewed/2024/05/GHSA-9wjv-frj6-hjv9/GHSA-9wjv-frj6-hjv9.json
+++ b/advisories/unreviewed/2024/05/GHSA-9wjv-frj6-hjv9/GHSA-9wjv-frj6-hjv9.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/05/GHSA-wmcv-82jv-v932/GHSA-wmcv-82jv-v932.json b/advisories/unreviewed/2024/05/GHSA-wmcv-82jv-v932/GHSA-wmcv-82jv-v932.json
index f1a79d203f8..aeed6c142c4 100644
--- a/advisories/unreviewed/2024/05/GHSA-wmcv-82jv-v932/GHSA-wmcv-82jv-v932.json
+++ b/advisories/unreviewed/2024/05/GHSA-wmcv-82jv-v932/GHSA-wmcv-82jv-v932.json
@@ -7,12 +7,8 @@
"CVE-2024-1275"
],
"details": "Use of Default Cryptographic Key vulnerability in Baxter Welch Ally Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Ally Connex Spot Monitor in all versions prior to 1.52.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json b/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json
index 5318b805654..cd45e8e04bf 100644
--- a/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json
+++ b/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json b/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json
index 02b3f9d5cae..0c42bf9eddd 100644
--- a/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json
+++ b/advisories/unreviewed/2024/06/GHSA-3j8q-j2j7-x49c/GHSA-3j8q-j2j7-x49c.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json b/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json
index d2017c8e48e..1bedaa956da 100644
--- a/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json
+++ b/advisories/unreviewed/2024/06/GHSA-55rp-jrc5-px98/GHSA-55rp-jrc5-px98.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-5jjj-4rqq-qph2/GHSA-5jjj-4rqq-qph2.json b/advisories/unreviewed/2024/06/GHSA-5jjj-4rqq-qph2/GHSA-5jjj-4rqq-qph2.json
index d7d488657bc..c87709e3571 100644
--- a/advisories/unreviewed/2024/06/GHSA-5jjj-4rqq-qph2/GHSA-5jjj-4rqq-qph2.json
+++ b/advisories/unreviewed/2024/06/GHSA-5jjj-4rqq-qph2/GHSA-5jjj-4rqq-qph2.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-64mq-qqh2-x5vh/GHSA-64mq-qqh2-x5vh.json b/advisories/unreviewed/2024/06/GHSA-64mq-qqh2-x5vh/GHSA-64mq-qqh2-x5vh.json
index 2f1ecb9ae4d..e64e0c16180 100644
--- a/advisories/unreviewed/2024/06/GHSA-64mq-qqh2-x5vh/GHSA-64mq-qqh2-x5vh.json
+++ b/advisories/unreviewed/2024/06/GHSA-64mq-qqh2-x5vh/GHSA-64mq-qqh2-x5vh.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-9gjv-rxm7-w3wq/GHSA-9gjv-rxm7-w3wq.json b/advisories/unreviewed/2024/06/GHSA-9gjv-rxm7-w3wq/GHSA-9gjv-rxm7-w3wq.json
index bd9626d39d7..277feb3d4c1 100644
--- a/advisories/unreviewed/2024/06/GHSA-9gjv-rxm7-w3wq/GHSA-9gjv-rxm7-w3wq.json
+++ b/advisories/unreviewed/2024/06/GHSA-9gjv-rxm7-w3wq/GHSA-9gjv-rxm7-w3wq.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-f874-gmmp-7878/GHSA-f874-gmmp-7878.json b/advisories/unreviewed/2024/06/GHSA-f874-gmmp-7878/GHSA-f874-gmmp-7878.json
index 5c15db2b2d2..330e5e0cbd3 100644
--- a/advisories/unreviewed/2024/06/GHSA-f874-gmmp-7878/GHSA-f874-gmmp-7878.json
+++ b/advisories/unreviewed/2024/06/GHSA-f874-gmmp-7878/GHSA-f874-gmmp-7878.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-g3x6-hjcc-gxpf/GHSA-g3x6-hjcc-gxpf.json b/advisories/unreviewed/2024/06/GHSA-g3x6-hjcc-gxpf/GHSA-g3x6-hjcc-gxpf.json
index 8b80b33c4ae..eb8db007ca5 100644
--- a/advisories/unreviewed/2024/06/GHSA-g3x6-hjcc-gxpf/GHSA-g3x6-hjcc-gxpf.json
+++ b/advisories/unreviewed/2024/06/GHSA-g3x6-hjcc-gxpf/GHSA-g3x6-hjcc-gxpf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-hcv5-vch2-p84m/GHSA-hcv5-vch2-p84m.json b/advisories/unreviewed/2024/06/GHSA-hcv5-vch2-p84m/GHSA-hcv5-vch2-p84m.json
index dbd603036c4..3bc9aeee7c7 100644
--- a/advisories/unreviewed/2024/06/GHSA-hcv5-vch2-p84m/GHSA-hcv5-vch2-p84m.json
+++ b/advisories/unreviewed/2024/06/GHSA-hcv5-vch2-p84m/GHSA-hcv5-vch2-p84m.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json b/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json
index f2d51e58101..6e08ca05d56 100644
--- a/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json
+++ b/advisories/unreviewed/2024/06/GHSA-jjqv-cfcp-2xj7/GHSA-jjqv-cfcp-2xj7.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-pr8c-f372-64ch/GHSA-pr8c-f372-64ch.json b/advisories/unreviewed/2024/06/GHSA-pr8c-f372-64ch/GHSA-pr8c-f372-64ch.json
index 5cda3dbecfc..6daedbbaf6b 100644
--- a/advisories/unreviewed/2024/06/GHSA-pr8c-f372-64ch/GHSA-pr8c-f372-64ch.json
+++ b/advisories/unreviewed/2024/06/GHSA-pr8c-f372-64ch/GHSA-pr8c-f372-64ch.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-q59j-865p-4rmj/GHSA-q59j-865p-4rmj.json b/advisories/unreviewed/2024/06/GHSA-q59j-865p-4rmj/GHSA-q59j-865p-4rmj.json
index c991b0302ac..e3442736d48 100644
--- a/advisories/unreviewed/2024/06/GHSA-q59j-865p-4rmj/GHSA-q59j-865p-4rmj.json
+++ b/advisories/unreviewed/2024/06/GHSA-q59j-865p-4rmj/GHSA-q59j-865p-4rmj.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-r64p-8jc5-c29v/GHSA-r64p-8jc5-c29v.json b/advisories/unreviewed/2024/06/GHSA-r64p-8jc5-c29v/GHSA-r64p-8jc5-c29v.json
index cb1e49374a7..9910f345174 100644
--- a/advisories/unreviewed/2024/06/GHSA-r64p-8jc5-c29v/GHSA-r64p-8jc5-c29v.json
+++ b/advisories/unreviewed/2024/06/GHSA-r64p-8jc5-c29v/GHSA-r64p-8jc5-c29v.json
@@ -7,12 +7,8 @@
"CVE-2024-31622"
],
"details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.",
- "severity": [
-
- ],
- "affected": [
-
- ],
+ "severity": [],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -20,9 +16,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json b/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json
index 2476dbe7e82..f1338ca4d38 100644
--- a/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json
+++ b/advisories/unreviewed/2024/06/GHSA-v5xq-m8f8-3cc2/GHSA-v5xq-m8f8-3cc2.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json b/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json
index 6abd348ca1d..898faf5f85c 100644
--- a/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json
+++ b/advisories/unreviewed/2024/06/GHSA-vg42-hcc7-h8cf/GHSA-vg42-hcc7-h8cf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-2w8v-rcqr-7wxj/GHSA-2w8v-rcqr-7wxj.json b/advisories/unreviewed/2024/07/GHSA-2w8v-rcqr-7wxj/GHSA-2w8v-rcqr-7wxj.json
index 1bff09756a9..4a1e46bc701 100644
--- a/advisories/unreviewed/2024/07/GHSA-2w8v-rcqr-7wxj/GHSA-2w8v-rcqr-7wxj.json
+++ b/advisories/unreviewed/2024/07/GHSA-2w8v-rcqr-7wxj/GHSA-2w8v-rcqr-7wxj.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json b/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json
index 99c0eb2d8f3..011ca1ce87a 100644
--- a/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json
+++ b/advisories/unreviewed/2024/07/GHSA-2wg4-c3jx-83f5/GHSA-2wg4-c3jx-83f5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json b/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json
index fae92161981..aaaa422904b 100644
--- a/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json
+++ b/advisories/unreviewed/2024/07/GHSA-4ww9-x3qp-vcwc/GHSA-4ww9-x3qp-vcwc.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json b/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json
index d6fa8309c3b..1022ca675f5 100644
--- a/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json
+++ b/advisories/unreviewed/2024/07/GHSA-7r67-crqq-3693/GHSA-7r67-crqq-3693.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json b/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json
index 034292c11be..1f25e6e57da 100644
--- a/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json
+++ b/advisories/unreviewed/2024/07/GHSA-86xc-mwv4-f994/GHSA-86xc-mwv4-f994.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-8mrq-m68x-jfcm/GHSA-8mrq-m68x-jfcm.json b/advisories/unreviewed/2024/07/GHSA-8mrq-m68x-jfcm/GHSA-8mrq-m68x-jfcm.json
index bdcc4153b9c..41f205c113a 100644
--- a/advisories/unreviewed/2024/07/GHSA-8mrq-m68x-jfcm/GHSA-8mrq-m68x-jfcm.json
+++ b/advisories/unreviewed/2024/07/GHSA-8mrq-m68x-jfcm/GHSA-8mrq-m68x-jfcm.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json b/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json
index fb7401190ac..6f3c3d115ed 100644
--- a/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json
+++ b/advisories/unreviewed/2024/07/GHSA-8pgq-57fj-h74q/GHSA-8pgq-57fj-h74q.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json b/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json
index 122fe770b00..7336b492695 100644
--- a/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json
+++ b/advisories/unreviewed/2024/07/GHSA-99mg-hh47-f9qh/GHSA-99mg-hh47-f9qh.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-c2wj-q48m-x7c3/GHSA-c2wj-q48m-x7c3.json b/advisories/unreviewed/2024/07/GHSA-c2wj-q48m-x7c3/GHSA-c2wj-q48m-x7c3.json
index 6b3d1ec5f11..1342abdf7ee 100644
--- a/advisories/unreviewed/2024/07/GHSA-c2wj-q48m-x7c3/GHSA-c2wj-q48m-x7c3.json
+++ b/advisories/unreviewed/2024/07/GHSA-c2wj-q48m-x7c3/GHSA-c2wj-q48m-x7c3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json b/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json
index d4a11815fd9..a96e232bb28 100644
--- a/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json
+++ b/advisories/unreviewed/2024/07/GHSA-g638-3qxw-g3gp/GHSA-g638-3qxw-g3gp.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json b/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json
index 908e69cbb42..9fae8109b11 100644
--- a/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json
+++ b/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json b/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json
index 7b77c84858a..987721420f5 100644
--- a/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json
+++ b/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json b/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json
index 851a5d9e217..670d7bef66d 100644
--- a/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json
+++ b/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json b/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json
index 6ad4584bd25..0a9c8d1dd91 100644
--- a/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json
+++ b/advisories/unreviewed/2024/07/GHSA-x8qr-mh28-f32f/GHSA-x8qr-mh28-f32f.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json b/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json
index 0722145dab9..970b4bc087a 100644
--- a/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json
+++ b/advisories/unreviewed/2024/08/GHSA-23fw-5352-7h9v/GHSA-23fw-5352-7h9v.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-2848-mrx7-c934/GHSA-2848-mrx7-c934.json b/advisories/unreviewed/2024/08/GHSA-2848-mrx7-c934/GHSA-2848-mrx7-c934.json
index 0c67e27fad5..ef8467c3ee7 100644
--- a/advisories/unreviewed/2024/08/GHSA-2848-mrx7-c934/GHSA-2848-mrx7-c934.json
+++ b/advisories/unreviewed/2024/08/GHSA-2848-mrx7-c934/GHSA-2848-mrx7-c934.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json b/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json
index 6d872e5b38d..227f5aa12ca 100644
--- a/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json
+++ b/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json b/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json
index 3320a4194da..587d37d1c76 100644
--- a/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json
+++ b/advisories/unreviewed/2024/08/GHSA-2wwv-3g3g-h8w3/GHSA-2wwv-3g3g-h8w3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json b/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json
index 6a45d551b6c..eb4b3d43b28 100644
--- a/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json
+++ b/advisories/unreviewed/2024/08/GHSA-8v23-cgh2-vf2c/GHSA-8v23-cgh2-vf2c.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json b/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json
index de3a0f636a3..ceecac95de7 100644
--- a/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json
+++ b/advisories/unreviewed/2024/08/GHSA-92g2-6qfc-5xw4/GHSA-92g2-6qfc-5xw4.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json b/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json
index 6f7402ceb93..ab161eaf983 100644
--- a/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json
+++ b/advisories/unreviewed/2024/08/GHSA-c5f9-wr82-c7qx/GHSA-c5f9-wr82-c7qx.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-c69h-4c8j-wh43/GHSA-c69h-4c8j-wh43.json b/advisories/unreviewed/2024/08/GHSA-c69h-4c8j-wh43/GHSA-c69h-4c8j-wh43.json
index 2c8c39b77c5..888302e4ea3 100644
--- a/advisories/unreviewed/2024/08/GHSA-c69h-4c8j-wh43/GHSA-c69h-4c8j-wh43.json
+++ b/advisories/unreviewed/2024/08/GHSA-c69h-4c8j-wh43/GHSA-c69h-4c8j-wh43.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json b/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json
index a52c736bb06..1f7abc831ba 100644
--- a/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json
+++ b/advisories/unreviewed/2024/08/GHSA-f58v-43c6-f6hf/GHSA-f58v-43c6-f6hf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json b/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json
index 382f277a909..ceeff80db56 100644
--- a/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json
+++ b/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -31,9 +29,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json b/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json
index ac4d337a806..11a11d769dd 100644
--- a/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json
+++ b/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json b/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json
index 1b7ad041b6a..db530de7833 100644
--- a/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json
+++ b/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json
index 57eaef7862a..ec239085ad1 100644
--- a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json
+++ b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json b/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json
index 5eca452705e..6f692b56975 100644
--- a/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json
+++ b/advisories/unreviewed/2024/08/GHSA-qw3c-xh2p-rwmf/GHSA-qw3c-xh2p-rwmf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-rvh8-75gg-f2cc/GHSA-rvh8-75gg-f2cc.json b/advisories/unreviewed/2024/08/GHSA-rvh8-75gg-f2cc/GHSA-rvh8-75gg-f2cc.json
index 267d09c0422..518a16bc58c 100644
--- a/advisories/unreviewed/2024/08/GHSA-rvh8-75gg-f2cc/GHSA-rvh8-75gg-f2cc.json
+++ b/advisories/unreviewed/2024/08/GHSA-rvh8-75gg-f2cc/GHSA-rvh8-75gg-f2cc.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json b/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json
index ecc7f6c772e..24f74c92939 100644
--- a/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json
+++ b/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json b/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json
index 491b4f28ad2..f48db336de2 100644
--- a/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json
+++ b/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json b/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json
index b09e15db00a..fbef2df739b 100644
--- a/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json
+++ b/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-2px3-mvqp-56jf/GHSA-2px3-mvqp-56jf.json b/advisories/unreviewed/2024/09/GHSA-2px3-mvqp-56jf/GHSA-2px3-mvqp-56jf.json
index 2a21663076a..93670707ae0 100644
--- a/advisories/unreviewed/2024/09/GHSA-2px3-mvqp-56jf/GHSA-2px3-mvqp-56jf.json
+++ b/advisories/unreviewed/2024/09/GHSA-2px3-mvqp-56jf/GHSA-2px3-mvqp-56jf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-36j4-jjhr-3m5r/GHSA-36j4-jjhr-3m5r.json b/advisories/unreviewed/2024/09/GHSA-36j4-jjhr-3m5r/GHSA-36j4-jjhr-3m5r.json
index e1355ed476d..bf0382cfe14 100644
--- a/advisories/unreviewed/2024/09/GHSA-36j4-jjhr-3m5r/GHSA-36j4-jjhr-3m5r.json
+++ b/advisories/unreviewed/2024/09/GHSA-36j4-jjhr-3m5r/GHSA-36j4-jjhr-3m5r.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json b/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json
index 77af4f4da1a..011d8e56580 100644
--- a/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json
+++ b/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json b/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json
index 019079bacfc..623ba01c939 100644
--- a/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json
+++ b/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json b/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json
index dd86f155e09..a97704bc8fa 100644
--- a/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json
+++ b/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-3mxm-3f2x-wfrr/GHSA-3mxm-3f2x-wfrr.json b/advisories/unreviewed/2024/09/GHSA-3mxm-3f2x-wfrr/GHSA-3mxm-3f2x-wfrr.json
index 2d62e8f2081..18a3f7b6af2 100644
--- a/advisories/unreviewed/2024/09/GHSA-3mxm-3f2x-wfrr/GHSA-3mxm-3f2x-wfrr.json
+++ b/advisories/unreviewed/2024/09/GHSA-3mxm-3f2x-wfrr/GHSA-3mxm-3f2x-wfrr.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json b/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json
index afff552a742..9b1170bb1b5 100644
--- a/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json
+++ b/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-43rj-h44p-4j25/GHSA-43rj-h44p-4j25.json b/advisories/unreviewed/2024/09/GHSA-43rj-h44p-4j25/GHSA-43rj-h44p-4j25.json
index 1084b2f4557..8948b269967 100644
--- a/advisories/unreviewed/2024/09/GHSA-43rj-h44p-4j25/GHSA-43rj-h44p-4j25.json
+++ b/advisories/unreviewed/2024/09/GHSA-43rj-h44p-4j25/GHSA-43rj-h44p-4j25.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json b/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json
index a798c19e18c..8296698168e 100644
--- a/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json
+++ b/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-47xq-6f8h-pg46/GHSA-47xq-6f8h-pg46.json b/advisories/unreviewed/2024/09/GHSA-47xq-6f8h-pg46/GHSA-47xq-6f8h-pg46.json
index da88de13ab2..eb962f12265 100644
--- a/advisories/unreviewed/2024/09/GHSA-47xq-6f8h-pg46/GHSA-47xq-6f8h-pg46.json
+++ b/advisories/unreviewed/2024/09/GHSA-47xq-6f8h-pg46/GHSA-47xq-6f8h-pg46.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json b/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json
index c33a30947bb..51f640bd6df 100644
--- a/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json
+++ b/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json b/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json
index bdb6bad3828..6ef34e2ab70 100644
--- a/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json
+++ b/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-4jr8-m4vf-8c9w/GHSA-4jr8-m4vf-8c9w.json b/advisories/unreviewed/2024/09/GHSA-4jr8-m4vf-8c9w/GHSA-4jr8-m4vf-8c9w.json
index 991e7b75fdf..82ce96ac3bb 100644
--- a/advisories/unreviewed/2024/09/GHSA-4jr8-m4vf-8c9w/GHSA-4jr8-m4vf-8c9w.json
+++ b/advisories/unreviewed/2024/09/GHSA-4jr8-m4vf-8c9w/GHSA-4jr8-m4vf-8c9w.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json b/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json
index ba20cf5af8b..ce6909f751f 100644
--- a/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json
+++ b/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json b/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json
index 7f3bf99cb1c..c92b12793aa 100644
--- a/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json
+++ b/advisories/unreviewed/2024/09/GHSA-4r99-7p57-xjr3/GHSA-4r99-7p57-xjr3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-4vq2-qg29-vjf5/GHSA-4vq2-qg29-vjf5.json b/advisories/unreviewed/2024/09/GHSA-4vq2-qg29-vjf5/GHSA-4vq2-qg29-vjf5.json
index 250372f4ba5..bb642e14181 100644
--- a/advisories/unreviewed/2024/09/GHSA-4vq2-qg29-vjf5/GHSA-4vq2-qg29-vjf5.json
+++ b/advisories/unreviewed/2024/09/GHSA-4vq2-qg29-vjf5/GHSA-4vq2-qg29-vjf5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json b/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json
index d7ad223767b..811c43f0c20 100644
--- a/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json
+++ b/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json b/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json
index b355e0912b9..5a2767cfe77 100644
--- a/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json
+++ b/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json b/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json
index 8c2d2749561..a908c9be9f2 100644
--- a/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json
+++ b/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-63rm-q44g-v6m3/GHSA-63rm-q44g-v6m3.json b/advisories/unreviewed/2024/09/GHSA-63rm-q44g-v6m3/GHSA-63rm-q44g-v6m3.json
index 3cbecf92159..182071e3a7c 100644
--- a/advisories/unreviewed/2024/09/GHSA-63rm-q44g-v6m3/GHSA-63rm-q44g-v6m3.json
+++ b/advisories/unreviewed/2024/09/GHSA-63rm-q44g-v6m3/GHSA-63rm-q44g-v6m3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json b/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json
index 95b2d4d56f3..4a51740a6a4 100644
--- a/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json
+++ b/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-6gc2-29f6-wg72/GHSA-6gc2-29f6-wg72.json b/advisories/unreviewed/2024/09/GHSA-6gc2-29f6-wg72/GHSA-6gc2-29f6-wg72.json
index 5af52ab6905..c264d017964 100644
--- a/advisories/unreviewed/2024/09/GHSA-6gc2-29f6-wg72/GHSA-6gc2-29f6-wg72.json
+++ b/advisories/unreviewed/2024/09/GHSA-6gc2-29f6-wg72/GHSA-6gc2-29f6-wg72.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json b/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json
index ddd0a38a114..4be8d24b452 100644
--- a/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json
+++ b/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-7242-jxqh-9vj3/GHSA-7242-jxqh-9vj3.json b/advisories/unreviewed/2024/09/GHSA-7242-jxqh-9vj3/GHSA-7242-jxqh-9vj3.json
index 4e1375d6115..865c1cdcf94 100644
--- a/advisories/unreviewed/2024/09/GHSA-7242-jxqh-9vj3/GHSA-7242-jxqh-9vj3.json
+++ b/advisories/unreviewed/2024/09/GHSA-7242-jxqh-9vj3/GHSA-7242-jxqh-9vj3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-7h4w-p362-v54g/GHSA-7h4w-p362-v54g.json b/advisories/unreviewed/2024/09/GHSA-7h4w-p362-v54g/GHSA-7h4w-p362-v54g.json
index 9ed1a2d1a6d..2b89c26c805 100644
--- a/advisories/unreviewed/2024/09/GHSA-7h4w-p362-v54g/GHSA-7h4w-p362-v54g.json
+++ b/advisories/unreviewed/2024/09/GHSA-7h4w-p362-v54g/GHSA-7h4w-p362-v54g.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json b/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json
index 65b26634c88..24d37b2c9cc 100644
--- a/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json
+++ b/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-7xgq-69ff-jfjc/GHSA-7xgq-69ff-jfjc.json b/advisories/unreviewed/2024/09/GHSA-7xgq-69ff-jfjc/GHSA-7xgq-69ff-jfjc.json
index e5d900301cf..b265d247b0e 100644
--- a/advisories/unreviewed/2024/09/GHSA-7xgq-69ff-jfjc/GHSA-7xgq-69ff-jfjc.json
+++ b/advisories/unreviewed/2024/09/GHSA-7xgq-69ff-jfjc/GHSA-7xgq-69ff-jfjc.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json b/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json
index 6e72afa9eef..ca82c5247c6 100644
--- a/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json
+++ b/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json b/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json
index 6ab08e35b92..6f2b4d9c5eb 100644
--- a/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json
+++ b/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json b/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json
index c9200651b1b..a150315a018 100644
--- a/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json
+++ b/advisories/unreviewed/2024/09/GHSA-8j7x-j8g8-g329/GHSA-8j7x-j8g8-g329.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json b/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json
index 725e0c8fdfd..e014887b806 100644
--- a/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json
+++ b/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-9354-h3w8-49p7/GHSA-9354-h3w8-49p7.json b/advisories/unreviewed/2024/09/GHSA-9354-h3w8-49p7/GHSA-9354-h3w8-49p7.json
index f16341d75d1..17b34df07ca 100644
--- a/advisories/unreviewed/2024/09/GHSA-9354-h3w8-49p7/GHSA-9354-h3w8-49p7.json
+++ b/advisories/unreviewed/2024/09/GHSA-9354-h3w8-49p7/GHSA-9354-h3w8-49p7.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-93jv-pgxc-4w5p/GHSA-93jv-pgxc-4w5p.json b/advisories/unreviewed/2024/09/GHSA-93jv-pgxc-4w5p/GHSA-93jv-pgxc-4w5p.json
index bbccb0c9206..d1510a2d050 100644
--- a/advisories/unreviewed/2024/09/GHSA-93jv-pgxc-4w5p/GHSA-93jv-pgxc-4w5p.json
+++ b/advisories/unreviewed/2024/09/GHSA-93jv-pgxc-4w5p/GHSA-93jv-pgxc-4w5p.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json b/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json
index ee432a735d1..118620974ed 100644
--- a/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json
+++ b/advisories/unreviewed/2024/09/GHSA-c4p9-95wg-q39w/GHSA-c4p9-95wg-q39w.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json
index dd6cc6afab5..b98856ec716 100644
--- a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json
+++ b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json b/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json
index e7626f8813e..51fa88c4410 100644
--- a/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json
+++ b/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json b/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json
index 768d3ebc90a..e0e38deb5f6 100644
--- a/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json
+++ b/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json b/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json
index 4540f52a899..807ba925e48 100644
--- a/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json
+++ b/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json b/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json
index 19a2d55c4a9..89d7c387915 100644
--- a/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json
+++ b/advisories/unreviewed/2024/09/GHSA-f3mw-pmh2-74wc/GHSA-f3mw-pmh2-74wc.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/09/GHSA-fc6c-mjwq-f62w/GHSA-fc6c-mjwq-f62w.json b/advisories/unreviewed/2024/09/GHSA-fc6c-mjwq-f62w/GHSA-fc6c-mjwq-f62w.json
index 8ba07fee567..9b6e55c8188 100644
--- a/advisories/unreviewed/2024/09/GHSA-fc6c-mjwq-f62w/GHSA-fc6c-mjwq-f62w.json
+++ b/advisories/unreviewed/2024/09/GHSA-fc6c-mjwq-f62w/GHSA-fc6c-mjwq-f62w.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json b/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json
index 28001dc2974..896c4529869 100644
--- a/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json
+++ b/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json b/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json
index 50c87a8a0e1..c70d934e6b3 100644
--- a/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json
+++ b/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json b/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json
index cd116154dfc..749bc5ec822 100644
--- a/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json
+++ b/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json b/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json
index cfb20cf03eb..e63a25220d7 100644
--- a/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json
+++ b/advisories/unreviewed/2024/09/GHSA-g9m4-c8qf-67qw/GHSA-g9m4-c8qf-67qw.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json b/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json
index 5c90f0c9b09..0a690c0230e 100644
--- a/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json
+++ b/advisories/unreviewed/2024/09/GHSA-gf29-3f4w-753g/GHSA-gf29-3f4w-753g.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-gfc5-9fgm-gcmj/GHSA-gfc5-9fgm-gcmj.json b/advisories/unreviewed/2024/09/GHSA-gfc5-9fgm-gcmj/GHSA-gfc5-9fgm-gcmj.json
index 8720eeb3824..af337fb0796 100644
--- a/advisories/unreviewed/2024/09/GHSA-gfc5-9fgm-gcmj/GHSA-gfc5-9fgm-gcmj.json
+++ b/advisories/unreviewed/2024/09/GHSA-gfc5-9fgm-gcmj/GHSA-gfc5-9fgm-gcmj.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json b/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json
index a275671af5b..63e0558bd2c 100644
--- a/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json
+++ b/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-h5rx-p76j-6cqj/GHSA-h5rx-p76j-6cqj.json b/advisories/unreviewed/2024/09/GHSA-h5rx-p76j-6cqj/GHSA-h5rx-p76j-6cqj.json
index ecba0cd14a2..260e3acb023 100644
--- a/advisories/unreviewed/2024/09/GHSA-h5rx-p76j-6cqj/GHSA-h5rx-p76j-6cqj.json
+++ b/advisories/unreviewed/2024/09/GHSA-h5rx-p76j-6cqj/GHSA-h5rx-p76j-6cqj.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json b/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json
index a51aa912e03..e919dae6cd6 100644
--- a/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json
+++ b/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-hv2g-w7p8-jf6j/GHSA-hv2g-w7p8-jf6j.json b/advisories/unreviewed/2024/09/GHSA-hv2g-w7p8-jf6j/GHSA-hv2g-w7p8-jf6j.json
index 8c1752cf4f6..0aefce754ff 100644
--- a/advisories/unreviewed/2024/09/GHSA-hv2g-w7p8-jf6j/GHSA-hv2g-w7p8-jf6j.json
+++ b/advisories/unreviewed/2024/09/GHSA-hv2g-w7p8-jf6j/GHSA-hv2g-w7p8-jf6j.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-hxpq-9j27-gq6f/GHSA-hxpq-9j27-gq6f.json b/advisories/unreviewed/2024/09/GHSA-hxpq-9j27-gq6f/GHSA-hxpq-9j27-gq6f.json
index 97552d14df3..1afe723fd73 100644
--- a/advisories/unreviewed/2024/09/GHSA-hxpq-9j27-gq6f/GHSA-hxpq-9j27-gq6f.json
+++ b/advisories/unreviewed/2024/09/GHSA-hxpq-9j27-gq6f/GHSA-hxpq-9j27-gq6f.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json b/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json
index 9965f023723..32e516e3355 100644
--- a/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json
+++ b/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json b/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json
index 24f10a5c25a..ed643690737 100644
--- a/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json
+++ b/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-j583-4h4q-5jwm/GHSA-j583-4h4q-5jwm.json b/advisories/unreviewed/2024/09/GHSA-j583-4h4q-5jwm/GHSA-j583-4h4q-5jwm.json
index ce124428867..62ad73e84ec 100644
--- a/advisories/unreviewed/2024/09/GHSA-j583-4h4q-5jwm/GHSA-j583-4h4q-5jwm.json
+++ b/advisories/unreviewed/2024/09/GHSA-j583-4h4q-5jwm/GHSA-j583-4h4q-5jwm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-j73c-62cp-6vqj/GHSA-j73c-62cp-6vqj.json b/advisories/unreviewed/2024/09/GHSA-j73c-62cp-6vqj/GHSA-j73c-62cp-6vqj.json
index 76db7675e43..0d62858770e 100644
--- a/advisories/unreviewed/2024/09/GHSA-j73c-62cp-6vqj/GHSA-j73c-62cp-6vqj.json
+++ b/advisories/unreviewed/2024/09/GHSA-j73c-62cp-6vqj/GHSA-j73c-62cp-6vqj.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json b/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json
index bf9c9f692c2..0bd0553961d 100644
--- a/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json
+++ b/advisories/unreviewed/2024/09/GHSA-jr6g-3qr2-xfh3/GHSA-jr6g-3qr2-xfh3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json b/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json
index 9d4c8f1c7d3..8ca5547a408 100644
--- a/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json
+++ b/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-jxpp-qw6j-h3gv/GHSA-jxpp-qw6j-h3gv.json b/advisories/unreviewed/2024/09/GHSA-jxpp-qw6j-h3gv/GHSA-jxpp-qw6j-h3gv.json
index a8df3684f1a..93f8782aae0 100644
--- a/advisories/unreviewed/2024/09/GHSA-jxpp-qw6j-h3gv/GHSA-jxpp-qw6j-h3gv.json
+++ b/advisories/unreviewed/2024/09/GHSA-jxpp-qw6j-h3gv/GHSA-jxpp-qw6j-h3gv.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-m8vf-vpr3-f452/GHSA-m8vf-vpr3-f452.json b/advisories/unreviewed/2024/09/GHSA-m8vf-vpr3-f452/GHSA-m8vf-vpr3-f452.json
index fd9d1765a0f..a287840edff 100644
--- a/advisories/unreviewed/2024/09/GHSA-m8vf-vpr3-f452/GHSA-m8vf-vpr3-f452.json
+++ b/advisories/unreviewed/2024/09/GHSA-m8vf-vpr3-f452/GHSA-m8vf-vpr3-f452.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json b/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json
index 0ca901097ea..da9ab7fbfbe 100644
--- a/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json
+++ b/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json b/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json
index a262156dc92..0a468d7e263 100644
--- a/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json
+++ b/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json b/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json
index 29a8c71d316..fe739b98f10 100644
--- a/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json
+++ b/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json b/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json
index 67bb3f47e7f..40429392dbf 100644
--- a/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json
+++ b/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json b/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json
index abf90e3351a..76d649740fe 100644
--- a/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json
+++ b/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json b/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json
index db3ac4ccfcc..d4a79e6989e 100644
--- a/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json
+++ b/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json b/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json
index ad047f05950..c107bddd7f1 100644
--- a/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json
+++ b/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json b/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json
index 785304cbd6a..6464adc2573 100644
--- a/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json
+++ b/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-pw2j-fq2f-334f/GHSA-pw2j-fq2f-334f.json b/advisories/unreviewed/2024/09/GHSA-pw2j-fq2f-334f/GHSA-pw2j-fq2f-334f.json
index 0d6efa5ae3b..5b1db85fd87 100644
--- a/advisories/unreviewed/2024/09/GHSA-pw2j-fq2f-334f/GHSA-pw2j-fq2f-334f.json
+++ b/advisories/unreviewed/2024/09/GHSA-pw2j-fq2f-334f/GHSA-pw2j-fq2f-334f.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json b/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json
index 19a7bf41e02..d6ded47fe09 100644
--- a/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json
+++ b/advisories/unreviewed/2024/09/GHSA-pw8j-vg82-pm6c/GHSA-pw8j-vg82-pm6c.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-q44j-mpqx-mx83/GHSA-q44j-mpqx-mx83.json b/advisories/unreviewed/2024/09/GHSA-q44j-mpqx-mx83/GHSA-q44j-mpqx-mx83.json
index ea5794abd96..ab734b0551b 100644
--- a/advisories/unreviewed/2024/09/GHSA-q44j-mpqx-mx83/GHSA-q44j-mpqx-mx83.json
+++ b/advisories/unreviewed/2024/09/GHSA-q44j-mpqx-mx83/GHSA-q44j-mpqx-mx83.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json b/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json
index 7625749f8ad..6765059daec 100644
--- a/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json
+++ b/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json b/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json
index 72d28bf87cc..9910bdaefb6 100644
--- a/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json
+++ b/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json b/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json
index 56a1c5ac2f1..bdb857c7258 100644
--- a/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json
+++ b/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json b/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json
index 3c55c97a14e..ab1f6ef1e8f 100644
--- a/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json
+++ b/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json b/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json
index cc6a7a51842..97ba5d20b8a 100644
--- a/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json
+++ b/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json b/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json
index 38dceb5775d..957cbe86f15 100644
--- a/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json
+++ b/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json b/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json
index 4a15758bad8..703b06c5beb 100644
--- a/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json
+++ b/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-v39h-7cp3-rgxc/GHSA-v39h-7cp3-rgxc.json b/advisories/unreviewed/2024/09/GHSA-v39h-7cp3-rgxc/GHSA-v39h-7cp3-rgxc.json
index f124819b860..95fd2ac4f26 100644
--- a/advisories/unreviewed/2024/09/GHSA-v39h-7cp3-rgxc/GHSA-v39h-7cp3-rgxc.json
+++ b/advisories/unreviewed/2024/09/GHSA-v39h-7cp3-rgxc/GHSA-v39h-7cp3-rgxc.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-v589-hwp6-crrx/GHSA-v589-hwp6-crrx.json b/advisories/unreviewed/2024/09/GHSA-v589-hwp6-crrx/GHSA-v589-hwp6-crrx.json
index e5d35e10fed..92d0c1ee2d1 100644
--- a/advisories/unreviewed/2024/09/GHSA-v589-hwp6-crrx/GHSA-v589-hwp6-crrx.json
+++ b/advisories/unreviewed/2024/09/GHSA-v589-hwp6-crrx/GHSA-v589-hwp6-crrx.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-v87f-v7fv-frg2/GHSA-v87f-v7fv-frg2.json b/advisories/unreviewed/2024/09/GHSA-v87f-v7fv-frg2/GHSA-v87f-v7fv-frg2.json
index c66ce53cadd..fd9211e9f88 100644
--- a/advisories/unreviewed/2024/09/GHSA-v87f-v7fv-frg2/GHSA-v87f-v7fv-frg2.json
+++ b/advisories/unreviewed/2024/09/GHSA-v87f-v7fv-frg2/GHSA-v87f-v7fv-frg2.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json b/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json
index ecc30807e53..993e3407375 100644
--- a/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json
+++ b/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json b/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json
index 41b6bd621fe..80ceec9355b 100644
--- a/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json
+++ b/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json b/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json
index 54ac4f19ed3..c9356173c17 100644
--- a/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json
+++ b/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -31,9 +29,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/09/GHSA-vx3h-qc6g-v68q/GHSA-vx3h-qc6g-v68q.json b/advisories/unreviewed/2024/09/GHSA-vx3h-qc6g-v68q/GHSA-vx3h-qc6g-v68q.json
index 624e2ff71d3..05405e4c2a4 100644
--- a/advisories/unreviewed/2024/09/GHSA-vx3h-qc6g-v68q/GHSA-vx3h-qc6g-v68q.json
+++ b/advisories/unreviewed/2024/09/GHSA-vx3h-qc6g-v68q/GHSA-vx3h-qc6g-v68q.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json b/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json
index efb739a9081..761623b0f9a 100644
--- a/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json
+++ b/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json b/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json
index 053c64ba2d5..615b3335b59 100644
--- a/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json
+++ b/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json b/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json
index 68b1dd012c4..70b612b9b84 100644
--- a/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json
+++ b/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json b/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json
index c16e86e63f4..3a68bf82e2c 100644
--- a/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json
+++ b/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json b/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json
index 9379b166810..a793dcece5c 100644
--- a/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json
+++ b/advisories/unreviewed/2024/11/GHSA-26fv-px38-wm73/GHSA-26fv-px38-wm73.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/11/GHSA-2jp2-4gcw-39mv/GHSA-2jp2-4gcw-39mv.json b/advisories/unreviewed/2024/11/GHSA-2jp2-4gcw-39mv/GHSA-2jp2-4gcw-39mv.json
index cb06c1ddfee..0003fb08964 100644
--- a/advisories/unreviewed/2024/11/GHSA-2jp2-4gcw-39mv/GHSA-2jp2-4gcw-39mv.json
+++ b/advisories/unreviewed/2024/11/GHSA-2jp2-4gcw-39mv/GHSA-2jp2-4gcw-39mv.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-37v9-jh5m-f5pg/GHSA-37v9-jh5m-f5pg.json b/advisories/unreviewed/2024/11/GHSA-37v9-jh5m-f5pg/GHSA-37v9-jh5m-f5pg.json
index 653cb343197..bdeaa218556 100644
--- a/advisories/unreviewed/2024/11/GHSA-37v9-jh5m-f5pg/GHSA-37v9-jh5m-f5pg.json
+++ b/advisories/unreviewed/2024/11/GHSA-37v9-jh5m-f5pg/GHSA-37v9-jh5m-f5pg.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-3wr4-4m2q-j8pw/GHSA-3wr4-4m2q-j8pw.json b/advisories/unreviewed/2024/11/GHSA-3wr4-4m2q-j8pw/GHSA-3wr4-4m2q-j8pw.json
index ef3d9da4831..6b09c103f45 100644
--- a/advisories/unreviewed/2024/11/GHSA-3wr4-4m2q-j8pw/GHSA-3wr4-4m2q-j8pw.json
+++ b/advisories/unreviewed/2024/11/GHSA-3wr4-4m2q-j8pw/GHSA-3wr4-4m2q-j8pw.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json b/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json
index 51b3df35483..268006b07a0 100644
--- a/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json
+++ b/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json
@@ -17,9 +17,7 @@
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json b/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json
index 1e570eb8c2d..f8922f1981f 100644
--- a/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json
+++ b/advisories/unreviewed/2024/11/GHSA-4gvm-v69v-r798/GHSA-4gvm-v69v-r798.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json b/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json
index a242bc309e9..d30b1b056aa 100644
--- a/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json
+++ b/advisories/unreviewed/2024/11/GHSA-4jvj-8r9f-f6pm/GHSA-4jvj-8r9f-f6pm.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/11/GHSA-4qgx-w4q7-p46p/GHSA-4qgx-w4q7-p46p.json b/advisories/unreviewed/2024/11/GHSA-4qgx-w4q7-p46p/GHSA-4qgx-w4q7-p46p.json
index 602fcc298f5..01e3f396c51 100644
--- a/advisories/unreviewed/2024/11/GHSA-4qgx-w4q7-p46p/GHSA-4qgx-w4q7-p46p.json
+++ b/advisories/unreviewed/2024/11/GHSA-4qgx-w4q7-p46p/GHSA-4qgx-w4q7-p46p.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-6245-p6w7-hf5m/GHSA-6245-p6w7-hf5m.json b/advisories/unreviewed/2024/11/GHSA-6245-p6w7-hf5m/GHSA-6245-p6w7-hf5m.json
index 170e2e3fcc7..31ab5f0caed 100644
--- a/advisories/unreviewed/2024/11/GHSA-6245-p6w7-hf5m/GHSA-6245-p6w7-hf5m.json
+++ b/advisories/unreviewed/2024/11/GHSA-6245-p6w7-hf5m/GHSA-6245-p6w7-hf5m.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-78cp-pmx4-6cr5/GHSA-78cp-pmx4-6cr5.json b/advisories/unreviewed/2024/11/GHSA-78cp-pmx4-6cr5/GHSA-78cp-pmx4-6cr5.json
index caf73876880..9f77d2e5317 100644
--- a/advisories/unreviewed/2024/11/GHSA-78cp-pmx4-6cr5/GHSA-78cp-pmx4-6cr5.json
+++ b/advisories/unreviewed/2024/11/GHSA-78cp-pmx4-6cr5/GHSA-78cp-pmx4-6cr5.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/11/GHSA-84j6-9f5r-c6v4/GHSA-84j6-9f5r-c6v4.json b/advisories/unreviewed/2024/11/GHSA-84j6-9f5r-c6v4/GHSA-84j6-9f5r-c6v4.json
index 0893912096f..fe819a93c58 100644
--- a/advisories/unreviewed/2024/11/GHSA-84j6-9f5r-c6v4/GHSA-84j6-9f5r-c6v4.json
+++ b/advisories/unreviewed/2024/11/GHSA-84j6-9f5r-c6v4/GHSA-84j6-9f5r-c6v4.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-865x-83mq-3qpq/GHSA-865x-83mq-3qpq.json b/advisories/unreviewed/2024/11/GHSA-865x-83mq-3qpq/GHSA-865x-83mq-3qpq.json
index 33d4875b5b7..f1090fb8865 100644
--- a/advisories/unreviewed/2024/11/GHSA-865x-83mq-3qpq/GHSA-865x-83mq-3qpq.json
+++ b/advisories/unreviewed/2024/11/GHSA-865x-83mq-3qpq/GHSA-865x-83mq-3qpq.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-8rrm-crhv-qpmv/GHSA-8rrm-crhv-qpmv.json b/advisories/unreviewed/2024/11/GHSA-8rrm-crhv-qpmv/GHSA-8rrm-crhv-qpmv.json
index a90423e565d..6adc6ffb3bd 100644
--- a/advisories/unreviewed/2024/11/GHSA-8rrm-crhv-qpmv/GHSA-8rrm-crhv-qpmv.json
+++ b/advisories/unreviewed/2024/11/GHSA-8rrm-crhv-qpmv/GHSA-8rrm-crhv-qpmv.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-f2q5-6frm-qr93/GHSA-f2q5-6frm-qr93.json b/advisories/unreviewed/2024/11/GHSA-f2q5-6frm-qr93/GHSA-f2q5-6frm-qr93.json
index 5e2c3bf3456..64f33a7d689 100644
--- a/advisories/unreviewed/2024/11/GHSA-f2q5-6frm-qr93/GHSA-f2q5-6frm-qr93.json
+++ b/advisories/unreviewed/2024/11/GHSA-f2q5-6frm-qr93/GHSA-f2q5-6frm-qr93.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-h32x-x27w-622g/GHSA-h32x-x27w-622g.json b/advisories/unreviewed/2024/11/GHSA-h32x-x27w-622g/GHSA-h32x-x27w-622g.json
index 102cb7c6ad8..5958f23098f 100644
--- a/advisories/unreviewed/2024/11/GHSA-h32x-x27w-622g/GHSA-h32x-x27w-622g.json
+++ b/advisories/unreviewed/2024/11/GHSA-h32x-x27w-622g/GHSA-h32x-x27w-622g.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json b/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json
index 496d45c0bc5..a9963995070 100644
--- a/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json
+++ b/advisories/unreviewed/2024/11/GHSA-qgrx-3ff6-vw5g/GHSA-qgrx-3ff6-vw5g.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json b/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json
index 4f003c4be67..1dc63c88968 100644
--- a/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json
+++ b/advisories/unreviewed/2024/11/GHSA-qj8p-7c2x-55jf/GHSA-qj8p-7c2x-55jf.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-rjm6-gxhw-jxmp/GHSA-rjm6-gxhw-jxmp.json b/advisories/unreviewed/2024/11/GHSA-rjm6-gxhw-jxmp/GHSA-rjm6-gxhw-jxmp.json
index fc978990408..32dba7e35da 100644
--- a/advisories/unreviewed/2024/11/GHSA-rjm6-gxhw-jxmp/GHSA-rjm6-gxhw-jxmp.json
+++ b/advisories/unreviewed/2024/11/GHSA-rjm6-gxhw-jxmp/GHSA-rjm6-gxhw-jxmp.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-rwfw-fp96-gm62/GHSA-rwfw-fp96-gm62.json b/advisories/unreviewed/2024/11/GHSA-rwfw-fp96-gm62/GHSA-rwfw-fp96-gm62.json
index 271054637da..a610f76489a 100644
--- a/advisories/unreviewed/2024/11/GHSA-rwfw-fp96-gm62/GHSA-rwfw-fp96-gm62.json
+++ b/advisories/unreviewed/2024/11/GHSA-rwfw-fp96-gm62/GHSA-rwfw-fp96-gm62.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-v3h8-6499-8h5p/GHSA-v3h8-6499-8h5p.json b/advisories/unreviewed/2024/11/GHSA-v3h8-6499-8h5p/GHSA-v3h8-6499-8h5p.json
index dec34d417ea..40660e681d9 100644
--- a/advisories/unreviewed/2024/11/GHSA-v3h8-6499-8h5p/GHSA-v3h8-6499-8h5p.json
+++ b/advisories/unreviewed/2024/11/GHSA-v3h8-6499-8h5p/GHSA-v3h8-6499-8h5p.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-ww64-984p-7pch/GHSA-ww64-984p-7pch.json b/advisories/unreviewed/2024/11/GHSA-ww64-984p-7pch/GHSA-ww64-984p-7pch.json
index 2ab724cb7bb..de9191ab5ef 100644
--- a/advisories/unreviewed/2024/11/GHSA-ww64-984p-7pch/GHSA-ww64-984p-7pch.json
+++ b/advisories/unreviewed/2024/11/GHSA-ww64-984p-7pch/GHSA-ww64-984p-7pch.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-wwc5-p8v7-jw92/GHSA-wwc5-p8v7-jw92.json b/advisories/unreviewed/2024/11/GHSA-wwc5-p8v7-jw92/GHSA-wwc5-p8v7-jw92.json
index 168372f6acc..2aad2b99a37 100644
--- a/advisories/unreviewed/2024/11/GHSA-wwc5-p8v7-jw92/GHSA-wwc5-p8v7-jw92.json
+++ b/advisories/unreviewed/2024/11/GHSA-wwc5-p8v7-jw92/GHSA-wwc5-p8v7-jw92.json
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",
diff --git a/advisories/unreviewed/2024/11/GHSA-xjf4-fvc9-r77j/GHSA-xjf4-fvc9-r77j.json b/advisories/unreviewed/2024/11/GHSA-xjf4-fvc9-r77j/GHSA-xjf4-fvc9-r77j.json
index a7716ba2085..c6f2923f1b8 100644
--- a/advisories/unreviewed/2024/11/GHSA-xjf4-fvc9-r77j/GHSA-xjf4-fvc9-r77j.json
+++ b/advisories/unreviewed/2024/11/GHSA-xjf4-fvc9-r77j/GHSA-xjf4-fvc9-r77j.json
@@ -13,9 +13,7 @@
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
- "affected": [
-
- ],
+ "affected": [],
"references": [
{
"type": "ADVISORY",