From 55822d77c7c636d3892bcab8fb0e60af016ed003 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 05:14:17 +0000 Subject: [PATCH] Advisory Database Sync --- .../10/GHSA-9h6g-gp95-x3q5/GHSA-9h6g-gp95-x3q5.json | 4 +--- .../10/GHSA-ffpv-c4hm-3x6v/GHSA-ffpv-c4hm-3x6v.json | 4 +--- .../10/GHSA-mpxf-gcw2-pw5q/GHSA-mpxf-gcw2-pw5q.json | 4 +--- .../10/GHSA-p692-7mm3-3fxg/GHSA-p692-7mm3-3fxg.json | 4 +--- .../12/GHSA-7fpw-cfc4-3p2c/GHSA-7fpw-cfc4-3p2c.json | 4 +--- .../09/GHSA-8whr-v3gm-w8h9/GHSA-8whr-v3gm-w8h9.json | 4 +--- .../05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json | 4 +--- .../04/GHSA-225c-mv8x-h9xj/GHSA-225c-mv8x-h9xj.json | 12 +++--------- .../04/GHSA-229w-c447-wm6p/GHSA-229w-c447-wm6p.json | 12 +++--------- .../04/GHSA-27xw-5882-cqhf/GHSA-27xw-5882-cqhf.json | 8 ++------ .../04/GHSA-28xm-3c4m-c8r4/GHSA-28xm-3c4m-c8r4.json | 12 +++--------- .../04/GHSA-2hf6-2xwx-h8c4/GHSA-2hf6-2xwx-h8c4.json | 8 ++------ .../04/GHSA-2jrj-qmg4-g429/GHSA-2jrj-qmg4-g429.json | 8 ++------ .../04/GHSA-2pm5-c2hr-7xg4/GHSA-2pm5-c2hr-7xg4.json | 8 ++------ .../04/GHSA-2q5q-95j3-2gf8/GHSA-2q5q-95j3-2gf8.json | 8 ++------ .../04/GHSA-2r24-q9c8-57g2/GHSA-2r24-q9c8-57g2.json | 12 +++--------- .../04/GHSA-2xv7-55qq-fqg6/GHSA-2xv7-55qq-fqg6.json | 8 ++------ .../04/GHSA-34v2-gcjc-32ph/GHSA-34v2-gcjc-32ph.json | 8 ++------ .../04/GHSA-352q-p9ch-9v33/GHSA-352q-p9ch-9v33.json | 8 ++------ .../04/GHSA-3cf2-6pj6-x5w3/GHSA-3cf2-6pj6-x5w3.json | 12 +++--------- .../04/GHSA-3f5f-x3vv-f92r/GHSA-3f5f-x3vv-f92r.json | 12 +++--------- .../04/GHSA-3fm9-pr9w-23q9/GHSA-3fm9-pr9w-23q9.json | 12 +++--------- .../04/GHSA-3gg5-c54v-vxvr/GHSA-3gg5-c54v-vxvr.json | 12 +++--------- .../04/GHSA-3jc7-m4hm-g848/GHSA-3jc7-m4hm-g848.json | 12 +++--------- .../04/GHSA-3mgr-cw56-9xx7/GHSA-3mgr-cw56-9xx7.json | 4 +--- .../04/GHSA-459f-26mc-vgm2/GHSA-459f-26mc-vgm2.json | 12 +++--------- .../04/GHSA-463q-c9pm-65qg/GHSA-463q-c9pm-65qg.json | 4 +--- .../04/GHSA-46vj-5wgx-vh7x/GHSA-46vj-5wgx-vh7x.json | 12 +++--------- .../04/GHSA-492f-5jc2-5m33/GHSA-492f-5jc2-5m33.json | 4 +--- .../04/GHSA-4g2v-vgjp-2c73/GHSA-4g2v-vgjp-2c73.json | 12 +++--------- .../04/GHSA-4hw3-x9c6-9f43/GHSA-4hw3-x9c6-9f43.json | 4 +--- .../04/GHSA-4p45-2736-fq3x/GHSA-4p45-2736-fq3x.json | 4 +--- .../04/GHSA-4pvp-pp8j-mcf5/GHSA-4pvp-pp8j-mcf5.json | 12 +++--------- .../04/GHSA-4w9w-xw54-8fxp/GHSA-4w9w-xw54-8fxp.json | 8 ++------ .../04/GHSA-4wf3-9pvj-q52c/GHSA-4wf3-9pvj-q52c.json | 12 +++--------- .../04/GHSA-4xxw-jx52-qf53/GHSA-4xxw-jx52-qf53.json | 4 +--- .../04/GHSA-527c-22g3-c82g/GHSA-527c-22g3-c82g.json | 12 +++--------- .../04/GHSA-52vv-c34v-c37f/GHSA-52vv-c34v-c37f.json | 12 +++--------- .../04/GHSA-543m-2r39-9vrj/GHSA-543m-2r39-9vrj.json | 12 +++--------- .../04/GHSA-55hr-hv86-7xr4/GHSA-55hr-hv86-7xr4.json | 4 +--- .../04/GHSA-5969-x38p-xrjj/GHSA-5969-x38p-xrjj.json | 4 +--- .../04/GHSA-59qr-cc8f-v837/GHSA-59qr-cc8f-v837.json | 8 ++------ .../04/GHSA-5f92-rmj7-665j/GHSA-5f92-rmj7-665j.json | 8 ++------ .../04/GHSA-5j27-r362-gvrr/GHSA-5j27-r362-gvrr.json | 12 +++--------- .../04/GHSA-63gp-3rq7-g7h2/GHSA-63gp-3rq7-g7h2.json | 8 ++------ .../04/GHSA-6c94-2q82-97hw/GHSA-6c94-2q82-97hw.json | 4 +--- .../04/GHSA-6cq5-57cw-hg4c/GHSA-6cq5-57cw-hg4c.json | 12 +++--------- .../04/GHSA-6g5v-qx4m-5w7m/GHSA-6g5v-qx4m-5w7m.json | 8 ++------ .../04/GHSA-6jcv-h8m6-j6vm/GHSA-6jcv-h8m6-j6vm.json | 4 +--- .../04/GHSA-72m4-92vp-gxfj/GHSA-72m4-92vp-gxfj.json | 12 +++--------- .../04/GHSA-739f-46gp-44jc/GHSA-739f-46gp-44jc.json | 12 +++--------- .../04/GHSA-7428-xfvg-x3qj/GHSA-7428-xfvg-x3qj.json | 4 +--- .../04/GHSA-7552-rx4g-hpqv/GHSA-7552-rx4g-hpqv.json | 4 +--- .../04/GHSA-75vj-765v-x3fg/GHSA-75vj-765v-x3fg.json | 4 +--- .../04/GHSA-78fw-2gr4-583c/GHSA-78fw-2gr4-583c.json | 4 +--- .../04/GHSA-78gg-3pq4-5rh6/GHSA-78gg-3pq4-5rh6.json | 12 +++--------- .../04/GHSA-79qc-35xf-whr6/GHSA-79qc-35xf-whr6.json | 8 ++------ .../04/GHSA-7c4p-f5qf-vx4w/GHSA-7c4p-f5qf-vx4w.json | 8 ++------ .../04/GHSA-7cv3-2v97-6cpf/GHSA-7cv3-2v97-6cpf.json | 12 +++--------- .../04/GHSA-7j3m-5478-cr36/GHSA-7j3m-5478-cr36.json | 12 +++--------- .../04/GHSA-7jgq-4jfh-mw69/GHSA-7jgq-4jfh-mw69.json | 8 ++------ .../04/GHSA-7qg4-rqjp-rwv5/GHSA-7qg4-rqjp-rwv5.json | 12 +++--------- .../04/GHSA-7qr9-r4q9-9m8f/GHSA-7qr9-r4q9-9m8f.json | 12 +++--------- .../04/GHSA-7rf5-wxhm-vx5h/GHSA-7rf5-wxhm-vx5h.json | 8 ++------ .../04/GHSA-7wmj-7phv-64wc/GHSA-7wmj-7phv-64wc.json | 8 ++------ .../04/GHSA-7ww5-vvcr-3rw4/GHSA-7ww5-vvcr-3rw4.json | 12 +++--------- .../04/GHSA-8768-7prf-6f7g/GHSA-8768-7prf-6f7g.json | 12 +++--------- .../04/GHSA-87p2-j2pw-qwfc/GHSA-87p2-j2pw-qwfc.json | 12 +++--------- .../04/GHSA-88vq-mwgw-6mcf/GHSA-88vq-mwgw-6mcf.json | 12 +++--------- .../04/GHSA-893w-6f8w-fqc2/GHSA-893w-6f8w-fqc2.json | 12 +++--------- .../04/GHSA-89hf-mmpp-p6fm/GHSA-89hf-mmpp-p6fm.json | 8 ++------ .../04/GHSA-8cqc-8pp8-h3j3/GHSA-8cqc-8pp8-h3j3.json | 12 +++--------- .../04/GHSA-8h7q-8fjc-rcf2/GHSA-8h7q-8fjc-rcf2.json | 12 +++--------- .../04/GHSA-8j88-pc4h-vcrg/GHSA-8j88-pc4h-vcrg.json | 8 ++------ .../04/GHSA-8jfx-95h8-fj8m/GHSA-8jfx-95h8-fj8m.json | 4 +--- .../04/GHSA-8jpc-3pph-f5r4/GHSA-8jpc-3pph-f5r4.json | 12 +++--------- .../04/GHSA-8jr2-hcch-7696/GHSA-8jr2-hcch-7696.json | 4 +--- .../04/GHSA-8m55-fv54-pfp6/GHSA-8m55-fv54-pfp6.json | 8 ++------ .../04/GHSA-8m5q-4p59-97f5/GHSA-8m5q-4p59-97f5.json | 12 +++--------- .../04/GHSA-8vx4-2p49-2m5m/GHSA-8vx4-2p49-2m5m.json | 12 +++--------- .../04/GHSA-8w62-g849-p4ww/GHSA-8w62-g849-p4ww.json | 12 +++--------- .../04/GHSA-8wcg-8pwm-v3gc/GHSA-8wcg-8pwm-v3gc.json | 12 +++--------- .../04/GHSA-929f-q38q-qmr6/GHSA-929f-q38q-qmr6.json | 8 ++------ .../04/GHSA-93vc-c3w9-g6c9/GHSA-93vc-c3w9-g6c9.json | 12 +++--------- .../04/GHSA-94fw-9r5j-jcw8/GHSA-94fw-9r5j-jcw8.json | 8 ++------ .../04/GHSA-96qj-c9wr-w9gx/GHSA-96qj-c9wr-w9gx.json | 8 ++------ .../04/GHSA-9f24-x6jp-22h6/GHSA-9f24-x6jp-22h6.json | 8 ++------ .../04/GHSA-9j8w-xrww-p6wr/GHSA-9j8w-xrww-p6wr.json | 12 +++--------- .../04/GHSA-9j8x-rg33-7fqr/GHSA-9j8x-rg33-7fqr.json | 12 +++--------- .../04/GHSA-9jjv-62gr-rmvp/GHSA-9jjv-62gr-rmvp.json | 12 +++--------- .../04/GHSA-9vw5-3fpc-j23p/GHSA-9vw5-3fpc-j23p.json | 8 ++------ .../04/GHSA-9wmx-j898-fr8m/GHSA-9wmx-j898-fr8m.json | 12 +++--------- .../04/GHSA-9wr3-8fv2-9fcj/GHSA-9wr3-8fv2-9fcj.json | 12 +++--------- .../04/GHSA-c47f-j86j-3p94/GHSA-c47f-j86j-3p94.json | 12 +++--------- .../04/GHSA-c6f2-x332-pmpr/GHSA-c6f2-x332-pmpr.json | 8 ++------ .../04/GHSA-c6v3-42rv-hx7j/GHSA-c6v3-42rv-hx7j.json | 8 ++------ .../04/GHSA-cfgx-7qv4-jhxr/GHSA-cfgx-7qv4-jhxr.json | 12 +++--------- .../04/GHSA-cgw3-wxh9-7v9c/GHSA-cgw3-wxh9-7v9c.json | 4 +--- .../04/GHSA-cxwh-v9vc-654w/GHSA-cxwh-v9vc-654w.json | 12 +++--------- .../04/GHSA-f3h8-8rx5-4v78/GHSA-f3h8-8rx5-4v78.json | 12 +++--------- .../04/GHSA-ffhj-hj7m-wj9r/GHSA-ffhj-hj7m-wj9r.json | 4 +--- .../04/GHSA-fm7f-2pvq-7cvg/GHSA-fm7f-2pvq-7cvg.json | 12 +++--------- .../04/GHSA-fq8g-x6c4-fpm3/GHSA-fq8g-x6c4-fpm3.json | 12 +++--------- .../04/GHSA-fwmf-9cw3-w3x3/GHSA-fwmf-9cw3-w3x3.json | 12 +++--------- .../04/GHSA-g2cj-p4q5-49m4/GHSA-g2cj-p4q5-49m4.json | 12 +++--------- .../04/GHSA-g572-wc44-wvcc/GHSA-g572-wc44-wvcc.json | 12 +++--------- .../04/GHSA-gh4c-fhq7-w2p8/GHSA-gh4c-fhq7-w2p8.json | 4 +--- .../04/GHSA-gh68-vx3r-mw6g/GHSA-gh68-vx3r-mw6g.json | 8 ++------ .../04/GHSA-gm87-84c8-m332/GHSA-gm87-84c8-m332.json | 12 +++--------- .../04/GHSA-gpfp-vw26-wc3m/GHSA-gpfp-vw26-wc3m.json | 8 ++------ .../04/GHSA-gqh4-5m73-25f6/GHSA-gqh4-5m73-25f6.json | 12 +++--------- .../04/GHSA-gv87-4wrx-xhh7/GHSA-gv87-4wrx-xhh7.json | 12 +++--------- .../04/GHSA-h2p2-h9vg-jvx9/GHSA-h2p2-h9vg-jvx9.json | 8 ++------ .../04/GHSA-h349-mgv6-6cmc/GHSA-h349-mgv6-6cmc.json | 4 +--- .../04/GHSA-h3jq-4749-5xmp/GHSA-h3jq-4749-5xmp.json | 4 +--- .../04/GHSA-h535-v6v7-r4q9/GHSA-h535-v6v7-r4q9.json | 12 +++--------- .../04/GHSA-h59g-2v7c-2x9c/GHSA-h59g-2v7c-2x9c.json | 8 ++------ .../04/GHSA-h8h8-j6q6-6c44/GHSA-h8h8-j6q6-6c44.json | 4 +--- .../04/GHSA-h97q-x4cw-q828/GHSA-h97q-x4cw-q828.json | 12 +++--------- .../04/GHSA-h9pf-v244-3x9w/GHSA-h9pf-v244-3x9w.json | 12 +++--------- .../04/GHSA-hg7h-2pr6-wvjf/GHSA-hg7h-2pr6-wvjf.json | 4 +--- .../04/GHSA-hhgh-vxgw-ph3w/GHSA-hhgh-vxgw-ph3w.json | 12 +++--------- .../04/GHSA-hm4p-5rh2-8894/GHSA-hm4p-5rh2-8894.json | 8 ++------ .../04/GHSA-hpp2-7wxh-2grj/GHSA-hpp2-7wxh-2grj.json | 12 +++--------- .../04/GHSA-hrwj-3h8v-xmqx/GHSA-hrwj-3h8v-xmqx.json | 12 +++--------- .../04/GHSA-hx8c-hfvj-265v/GHSA-hx8c-hfvj-265v.json | 12 +++--------- .../04/GHSA-j364-gj4x-7f3p/GHSA-j364-gj4x-7f3p.json | 12 +++--------- .../04/GHSA-j48w-866x-v5fr/GHSA-j48w-866x-v5fr.json | 12 +++--------- .../04/GHSA-j4f7-q8hr-jwf3/GHSA-j4f7-q8hr-jwf3.json | 4 +--- .../04/GHSA-j597-jrh6-3m7m/GHSA-j597-jrh6-3m7m.json | 12 +++--------- .../04/GHSA-j878-9p76-8q9h/GHSA-j878-9p76-8q9h.json | 8 ++------ .../04/GHSA-jghw-mw88-pq53/GHSA-jghw-mw88-pq53.json | 12 +++--------- .../04/GHSA-jm4q-r2cm-cjq2/GHSA-jm4q-r2cm-cjq2.json | 8 ++------ .../04/GHSA-jmf2-9gpj-6cw4/GHSA-jmf2-9gpj-6cw4.json | 8 ++------ .../04/GHSA-jmhc-44vq-xxm4/GHSA-jmhc-44vq-xxm4.json | 12 +++--------- .../04/GHSA-jw3x-m75w-3629/GHSA-jw3x-m75w-3629.json | 12 +++--------- .../04/GHSA-jxxq-gmfj-7r8f/GHSA-jxxq-gmfj-7r8f.json | 12 +++--------- .../04/GHSA-m2xp-5rxh-x3wc/GHSA-m2xp-5rxh-x3wc.json | 12 +++--------- .../04/GHSA-mcmc-pq28-m22x/GHSA-mcmc-pq28-m22x.json | 12 +++--------- .../04/GHSA-mgvj-rwrg-mch6/GHSA-mgvj-rwrg-mch6.json | 4 +--- .../04/GHSA-mj28-hjxw-jmfp/GHSA-mj28-hjxw-jmfp.json | 8 ++------ .../04/GHSA-mjjf-5gp4-m9fg/GHSA-mjjf-5gp4-m9fg.json | 12 +++--------- .../04/GHSA-mrqh-xmc6-c5gm/GHSA-mrqh-xmc6-c5gm.json | 4 +--- .../04/GHSA-mxx4-32g7-frv8/GHSA-mxx4-32g7-frv8.json | 12 +++--------- .../04/GHSA-p2jx-rwxh-4rq2/GHSA-p2jx-rwxh-4rq2.json | 12 +++--------- .../04/GHSA-p39c-3779-23qg/GHSA-p39c-3779-23qg.json | 12 +++--------- .../04/GHSA-p4vv-m3jf-xfp4/GHSA-p4vv-m3jf-xfp4.json | 12 +++--------- .../04/GHSA-p7c9-q84g-w8qj/GHSA-p7c9-q84g-w8qj.json | 12 +++--------- .../04/GHSA-ph7q-8jfj-8h3x/GHSA-ph7q-8jfj-8h3x.json | 12 +++--------- .../04/GHSA-pqf9-f88f-jphj/GHSA-pqf9-f88f-jphj.json | 12 +++--------- .../04/GHSA-q2wc-9mx8-xr8j/GHSA-q2wc-9mx8-xr8j.json | 8 ++------ .../04/GHSA-q452-qm69-w9xq/GHSA-q452-qm69-w9xq.json | 8 ++------ .../04/GHSA-q4ww-p595-37cj/GHSA-q4ww-p595-37cj.json | 4 +--- .../04/GHSA-q7m3-c8fc-p3xq/GHSA-q7m3-c8fc-p3xq.json | 8 ++------ .../04/GHSA-q7x5-x7rr-2859/GHSA-q7x5-x7rr-2859.json | 8 ++------ .../04/GHSA-q8wc-pw9v-8w8r/GHSA-q8wc-pw9v-8w8r.json | 4 +--- .../04/GHSA-qm9r-wvg3-383h/GHSA-qm9r-wvg3-383h.json | 12 +++--------- .../04/GHSA-qq57-jfgr-8wj6/GHSA-qq57-jfgr-8wj6.json | 12 +++--------- .../04/GHSA-qqg3-vq27-3xvx/GHSA-qqg3-vq27-3xvx.json | 8 ++------ .../04/GHSA-qqr5-q566-72w2/GHSA-qqr5-q566-72w2.json | 12 +++--------- .../04/GHSA-qw86-p44c-xfpr/GHSA-qw86-p44c-xfpr.json | 8 ++------ .../04/GHSA-qxh4-gwjr-r2m4/GHSA-qxh4-gwjr-r2m4.json | 12 +++--------- .../04/GHSA-r458-gcmr-cw5r/GHSA-r458-gcmr-cw5r.json | 12 +++--------- .../04/GHSA-r523-qv88-gm52/GHSA-r523-qv88-gm52.json | 12 +++--------- .../04/GHSA-r666-gxw4-v6gf/GHSA-r666-gxw4-v6gf.json | 4 +--- .../04/GHSA-rfrp-w4hm-99fx/GHSA-rfrp-w4hm-99fx.json | 12 +++--------- .../04/GHSA-rgwr-fg6p-5whf/GHSA-rgwr-fg6p-5whf.json | 12 +++--------- .../04/GHSA-rqm2-qh4g-xjjg/GHSA-rqm2-qh4g-xjjg.json | 12 +++--------- .../04/GHSA-rrcq-rghp-hjgx/GHSA-rrcq-rghp-hjgx.json | 12 +++--------- .../04/GHSA-rrx6-pgjg-pmv7/GHSA-rrx6-pgjg-pmv7.json | 8 ++------ .../04/GHSA-v5m5-87cx-vqf2/GHSA-v5m5-87cx-vqf2.json | 8 ++------ .../04/GHSA-v7r2-f6jx-59j6/GHSA-v7r2-f6jx-59j6.json | 12 +++--------- .../04/GHSA-vfmq-w45j-w9m6/GHSA-vfmq-w45j-w9m6.json | 12 +++--------- .../04/GHSA-vjr9-xh2p-7wpp/GHSA-vjr9-xh2p-7wpp.json | 8 ++------ .../04/GHSA-vr3h-889p-pwx2/GHSA-vr3h-889p-pwx2.json | 12 +++--------- .../04/GHSA-vr7c-vmw2-482c/GHSA-vr7c-vmw2-482c.json | 12 +++--------- .../04/GHSA-vwr7-jw8x-3pcx/GHSA-vwr7-jw8x-3pcx.json | 12 +++--------- .../04/GHSA-vxcx-7p8x-jr3r/GHSA-vxcx-7p8x-jr3r.json | 12 +++--------- .../04/GHSA-w892-7g74-x2wg/GHSA-w892-7g74-x2wg.json | 4 +--- .../04/GHSA-wjpc-9hpw-c7p9/GHSA-wjpc-9hpw-c7p9.json | 12 +++--------- .../04/GHSA-wpg3-r2mr-mv9m/GHSA-wpg3-r2mr-mv9m.json | 8 ++------ .../04/GHSA-wph5-jqqm-rqpf/GHSA-wph5-jqqm-rqpf.json | 12 +++--------- .../04/GHSA-wq6x-r2mj-jc4m/GHSA-wq6x-r2mj-jc4m.json | 8 ++------ .../04/GHSA-wrcj-gm3v-fgv6/GHSA-wrcj-gm3v-fgv6.json | 12 +++--------- .../04/GHSA-wvg7-5q5w-jh2m/GHSA-wvg7-5q5w-jh2m.json | 12 +++--------- .../04/GHSA-ww6p-x9mv-7hjc/GHSA-ww6p-x9mv-7hjc.json | 12 +++--------- .../04/GHSA-x4qg-m523-2cjh/GHSA-x4qg-m523-2cjh.json | 12 +++--------- .../04/GHSA-x7q8-c93w-mjgm/GHSA-x7q8-c93w-mjgm.json | 12 +++--------- .../04/GHSA-xcm3-73w3-h54h/GHSA-xcm3-73w3-h54h.json | 12 +++--------- .../04/GHSA-xfvx-h8x3-2vxx/GHSA-xfvx-h8x3-2vxx.json | 12 +++--------- .../04/GHSA-xqwv-q7pr-7f9f/GHSA-xqwv-q7pr-7f9f.json | 12 +++--------- .../04/GHSA-xvg2-gfxv-qc4c/GHSA-xvg2-gfxv-qc4c.json | 12 +++--------- .../04/GHSA-xvx7-78wp-jmp4/GHSA-xvx7-78wp-jmp4.json | 12 +++--------- .../04/GHSA-xxmv-v72m-r6w4/GHSA-xxmv-v72m-r6w4.json | 12 +++--------- .../05/GHSA-23w9-jw3m-h5hj/GHSA-23w9-jw3m-h5hj.json | 8 ++------ .../05/GHSA-23x8-m9wv-h49m/GHSA-23x8-m9wv-h49m.json | 8 ++------ .../05/GHSA-258m-qv8h-28wx/GHSA-258m-qv8h-28wx.json | 8 ++------ .../05/GHSA-25cw-47xx-658v/GHSA-25cw-47xx-658v.json | 8 ++------ .../05/GHSA-25x7-rqcx-mfwh/GHSA-25x7-rqcx-mfwh.json | 4 +--- .../05/GHSA-26q2-38pj-p8fv/GHSA-26q2-38pj-p8fv.json | 8 ++------ .../05/GHSA-27g2-h3jp-46x8/GHSA-27g2-h3jp-46x8.json | 12 +++--------- .../05/GHSA-2866-fxpg-497j/GHSA-2866-fxpg-497j.json | 8 ++------ .../05/GHSA-287f-5vcq-p94w/GHSA-287f-5vcq-p94w.json | 8 ++------ .../05/GHSA-28cr-3625-x6c5/GHSA-28cr-3625-x6c5.json | 8 ++------ .../05/GHSA-28r8-9g34-2x25/GHSA-28r8-9g34-2x25.json | 8 ++------ .../05/GHSA-2984-fgj8-4x8h/GHSA-2984-fgj8-4x8h.json | 8 ++------ .../05/GHSA-2cc9-295v-25m8/GHSA-2cc9-295v-25m8.json | 8 ++------ .../05/GHSA-2f29-629x-3r89/GHSA-2f29-629x-3r89.json | 8 ++------ .../05/GHSA-2f5g-rwwg-jqh6/GHSA-2f5g-rwwg-jqh6.json | 8 ++------ .../05/GHSA-2fpm-8hx3-wxj9/GHSA-2fpm-8hx3-wxj9.json | 8 ++------ .../05/GHSA-2hqm-x8qp-68ph/GHSA-2hqm-x8qp-68ph.json | 8 ++------ .../05/GHSA-2jmj-6ff4-3p3w/GHSA-2jmj-6ff4-3p3w.json | 8 ++------ .../05/GHSA-2jq2-rfq2-wr2p/GHSA-2jq2-rfq2-wr2p.json | 12 +++--------- .../05/GHSA-2m9j-f7hm-696q/GHSA-2m9j-f7hm-696q.json | 8 ++------ .../05/GHSA-2mrx-4g5g-2vw5/GHSA-2mrx-4g5g-2vw5.json | 8 ++------ .../05/GHSA-2pfh-m36r-gfqc/GHSA-2pfh-m36r-gfqc.json | 4 +--- .../05/GHSA-2rjp-9cc6-3v2j/GHSA-2rjp-9cc6-3v2j.json | 4 +--- .../05/GHSA-2v2r-vm5q-9pwc/GHSA-2v2r-vm5q-9pwc.json | 8 ++------ .../05/GHSA-2vwg-wm97-9xx9/GHSA-2vwg-wm97-9xx9.json | 8 ++------ .../05/GHSA-2whc-3w32-64h4/GHSA-2whc-3w32-64h4.json | 8 ++------ .../05/GHSA-2wq8-q24x-h8rw/GHSA-2wq8-q24x-h8rw.json | 8 ++------ .../05/GHSA-2xc3-3457-6965/GHSA-2xc3-3457-6965.json | 8 ++------ .../05/GHSA-2xjp-8pmx-7mmj/GHSA-2xjp-8pmx-7mmj.json | 8 ++------ .../05/GHSA-2xwg-c668-f9x5/GHSA-2xwg-c668-f9x5.json | 12 +++--------- .../05/GHSA-3228-63jx-j274/GHSA-3228-63jx-j274.json | 8 ++------ .../05/GHSA-32x3-2qh2-v3w9/GHSA-32x3-2qh2-v3w9.json | 8 ++------ .../05/GHSA-33g5-vw3f-w92q/GHSA-33g5-vw3f-w92q.json | 8 ++------ .../05/GHSA-33r4-rw8x-j8x9/GHSA-33r4-rw8x-j8x9.json | 12 +++--------- .../05/GHSA-3435-jrhh-rq8g/GHSA-3435-jrhh-rq8g.json | 8 ++------ .../05/GHSA-3456-r253-4f5r/GHSA-3456-r253-4f5r.json | 8 ++------ .../05/GHSA-34h5-5rm5-5r55/GHSA-34h5-5rm5-5r55.json | 8 ++------ .../05/GHSA-355x-g6q7-4c7g/GHSA-355x-g6q7-4c7g.json | 8 ++------ .../05/GHSA-35j5-3cvj-g2x4/GHSA-35j5-3cvj-g2x4.json | 12 +++--------- .../05/GHSA-35pj-cxpm-pvh5/GHSA-35pj-cxpm-pvh5.json | 12 +++--------- .../05/GHSA-363j-9xx8-29r4/GHSA-363j-9xx8-29r4.json | 8 ++------ .../05/GHSA-36pj-8gmw-49gg/GHSA-36pj-8gmw-49gg.json | 8 ++------ .../05/GHSA-36wp-g3gj-7v3h/GHSA-36wp-g3gj-7v3h.json | 8 ++------ .../05/GHSA-37cv-ggq7-j55v/GHSA-37cv-ggq7-j55v.json | 8 ++------ .../05/GHSA-37gp-666w-35h8/GHSA-37gp-666w-35h8.json | 8 ++------ .../05/GHSA-37m6-73f6-jm7w/GHSA-37m6-73f6-jm7w.json | 8 ++------ .../05/GHSA-37w4-w4g6-8f3q/GHSA-37w4-w4g6-8f3q.json | 12 +++--------- .../05/GHSA-386q-xj43-6wfr/GHSA-386q-xj43-6wfr.json | 4 +--- .../05/GHSA-392p-h7qw-6vx7/GHSA-392p-h7qw-6vx7.json | 8 ++------ .../05/GHSA-3956-xf6j-hjw9/GHSA-3956-xf6j-hjw9.json | 8 ++------ .../05/GHSA-399x-p377-379h/GHSA-399x-p377-379h.json | 8 ++------ .../05/GHSA-3c2f-8cpm-89m3/GHSA-3c2f-8cpm-89m3.json | 8 ++------ .../05/GHSA-3c9h-j75v-3mr5/GHSA-3c9h-j75v-3mr5.json | 8 ++------ .../05/GHSA-3f3f-hqx2-w523/GHSA-3f3f-hqx2-w523.json | 8 ++------ .../05/GHSA-3f76-vp73-hc25/GHSA-3f76-vp73-hc25.json | 8 ++------ .../05/GHSA-3fgp-cw9p-5ff5/GHSA-3fgp-cw9p-5ff5.json | 8 ++------ .../05/GHSA-3fjh-3qmq-p25v/GHSA-3fjh-3qmq-p25v.json | 8 ++------ .../05/GHSA-3grp-6v62-v4vr/GHSA-3grp-6v62-v4vr.json | 8 ++------ .../05/GHSA-3hp7-gf4j-8f4c/GHSA-3hp7-gf4j-8f4c.json | 8 ++------ .../05/GHSA-3jcw-ph85-3mv4/GHSA-3jcw-ph85-3mv4.json | 8 ++------ .../05/GHSA-3jj3-875w-p3wj/GHSA-3jj3-875w-p3wj.json | 4 +--- .../05/GHSA-3jm5-qqg2-4jf9/GHSA-3jm5-qqg2-4jf9.json | 4 +--- .../05/GHSA-3mmm-4792-65w2/GHSA-3mmm-4792-65w2.json | 8 ++------ .../05/GHSA-3qg5-3wgr-h9mq/GHSA-3qg5-3wgr-h9mq.json | 12 +++--------- .../05/GHSA-3rff-xjq9-pg37/GHSA-3rff-xjq9-pg37.json | 8 ++------ .../05/GHSA-3vf9-hrcp-mj3p/GHSA-3vf9-hrcp-mj3p.json | 8 ++------ .../05/GHSA-3w33-h749-fgfr/GHSA-3w33-h749-fgfr.json | 12 +++--------- .../05/GHSA-3w55-xwjg-qq8w/GHSA-3w55-xwjg-qq8w.json | 12 +++--------- .../05/GHSA-3w6j-54mg-5cr4/GHSA-3w6j-54mg-5cr4.json | 12 +++--------- .../05/GHSA-3xx7-g9gf-wrw5/GHSA-3xx7-g9gf-wrw5.json | 8 ++------ .../05/GHSA-423p-ch83-27qw/GHSA-423p-ch83-27qw.json | 8 ++------ .../05/GHSA-42r3-423m-j869/GHSA-42r3-423m-j869.json | 8 ++------ .../05/GHSA-4325-8w9c-7p9p/GHSA-4325-8w9c-7p9p.json | 8 ++------ .../05/GHSA-43m5-x878-2c62/GHSA-43m5-x878-2c62.json | 8 ++------ .../05/GHSA-4456-4h4r-g935/GHSA-4456-4h4r-g935.json | 8 ++------ .../05/GHSA-44fv-7q57-6rj5/GHSA-44fv-7q57-6rj5.json | 8 ++------ .../05/GHSA-44rv-rqpv-5h55/GHSA-44rv-rqpv-5h55.json | 8 ++------ .../05/GHSA-4563-pqrg-7hcj/GHSA-4563-pqrg-7hcj.json | 8 ++------ .../05/GHSA-456m-cqc5-g822/GHSA-456m-cqc5-g822.json | 8 ++------ .../05/GHSA-45j6-22mm-5x5p/GHSA-45j6-22mm-5x5p.json | 8 ++------ .../05/GHSA-46qp-3938-63jv/GHSA-46qp-3938-63jv.json | 8 ++------ .../05/GHSA-46vq-m3cv-fvrh/GHSA-46vq-m3cv-fvrh.json | 8 ++------ .../05/GHSA-473q-jggx-5qr3/GHSA-473q-jggx-5qr3.json | 8 ++------ .../05/GHSA-485r-9478-c3ww/GHSA-485r-9478-c3ww.json | 8 ++------ .../05/GHSA-48wj-mfx4-4qc2/GHSA-48wj-mfx4-4qc2.json | 4 +--- .../05/GHSA-48xm-jq3f-3xjx/GHSA-48xm-jq3f-3xjx.json | 8 ++------ .../05/GHSA-49ch-rg68-hqhr/GHSA-49ch-rg68-hqhr.json | 8 ++------ .../05/GHSA-4chx-4wv3-ph6v/GHSA-4chx-4wv3-ph6v.json | 8 ++------ .../05/GHSA-4crf-hf39-p7m7/GHSA-4crf-hf39-p7m7.json | 8 ++------ .../05/GHSA-4f7j-5j3r-xxc5/GHSA-4f7j-5j3r-xxc5.json | 8 ++------ .../05/GHSA-4fhq-wm67-3x2v/GHSA-4fhq-wm67-3x2v.json | 8 ++------ .../05/GHSA-4gh5-fw3f-vm8m/GHSA-4gh5-fw3f-vm8m.json | 8 ++------ .../05/GHSA-4h83-62ff-59wh/GHSA-4h83-62ff-59wh.json | 8 ++------ .../05/GHSA-4hw8-23gq-m2qg/GHSA-4hw8-23gq-m2qg.json | 8 ++------ .../05/GHSA-4jc3-3v3g-h745/GHSA-4jc3-3v3g-h745.json | 8 ++------ .../05/GHSA-4jvq-wc69-2rqj/GHSA-4jvq-wc69-2rqj.json | 8 ++------ .../05/GHSA-4mfr-jgjm-cvx8/GHSA-4mfr-jgjm-cvx8.json | 8 ++------ .../05/GHSA-4p43-cv9p-j29m/GHSA-4p43-cv9p-j29m.json | 8 ++------ .../05/GHSA-4pjq-cx2j-g6rm/GHSA-4pjq-cx2j-g6rm.json | 8 ++------ .../05/GHSA-4qc6-wq65-6w7q/GHSA-4qc6-wq65-6w7q.json | 12 +++--------- .../05/GHSA-4qr3-ph4h-wwpf/GHSA-4qr3-ph4h-wwpf.json | 8 ++------ .../05/GHSA-4qr9-9cg9-9gvw/GHSA-4qr9-9cg9-9gvw.json | 8 ++------ .../05/GHSA-4r7v-vq9j-hv62/GHSA-4r7v-vq9j-hv62.json | 8 ++------ .../05/GHSA-4vx6-93q8-5vcf/GHSA-4vx6-93q8-5vcf.json | 8 ++------ .../05/GHSA-4x5r-86c2-22gq/GHSA-4x5r-86c2-22gq.json | 8 ++------ .../05/GHSA-525v-m682-5h53/GHSA-525v-m682-5h53.json | 8 ++------ .../05/GHSA-526j-q77m-37w5/GHSA-526j-q77m-37w5.json | 8 ++------ .../05/GHSA-52f9-w6mx-8654/GHSA-52f9-w6mx-8654.json | 8 ++------ .../05/GHSA-53fv-h732-7vpp/GHSA-53fv-h732-7vpp.json | 8 ++------ .../05/GHSA-53jq-rch4-w6wr/GHSA-53jq-rch4-w6wr.json | 8 ++------ .../05/GHSA-53r8-v6vr-f62f/GHSA-53r8-v6vr-f62f.json | 8 ++------ .../05/GHSA-543r-2767-7774/GHSA-543r-2767-7774.json | 8 ++------ .../05/GHSA-5534-3qgp-mmmx/GHSA-5534-3qgp-mmmx.json | 8 ++------ .../05/GHSA-55fr-5wq7-grv8/GHSA-55fr-5wq7-grv8.json | 8 ++------ .../05/GHSA-55v7-pmqj-6x6g/GHSA-55v7-pmqj-6x6g.json | 8 ++------ .../05/GHSA-56cp-9m37-vqw4/GHSA-56cp-9m37-vqw4.json | 8 ++------ .../05/GHSA-56v6-8r67-xw4x/GHSA-56v6-8r67-xw4x.json | 8 ++------ .../05/GHSA-5745-c668-f862/GHSA-5745-c668-f862.json | 8 ++------ .../05/GHSA-588x-rqx3-m99w/GHSA-588x-rqx3-m99w.json | 8 ++------ .../05/GHSA-5fxv-93pc-g3cm/GHSA-5fxv-93pc-g3cm.json | 8 ++------ .../05/GHSA-5g5r-7m54-r43v/GHSA-5g5r-7m54-r43v.json | 12 +++--------- .../05/GHSA-5gfx-64wm-m22c/GHSA-5gfx-64wm-m22c.json | 8 ++------ .../05/GHSA-5gvh-fv85-vvrf/GHSA-5gvh-fv85-vvrf.json | 8 ++------ .../05/GHSA-5jpj-9pv4-xgm6/GHSA-5jpj-9pv4-xgm6.json | 8 ++------ .../05/GHSA-5jq3-c46h-gv5g/GHSA-5jq3-c46h-gv5g.json | 8 ++------ .../05/GHSA-5jqg-5g42-mwgq/GHSA-5jqg-5g42-mwgq.json | 8 ++------ .../05/GHSA-5m2p-g5x2-c2rf/GHSA-5m2p-g5x2-c2rf.json | 4 +--- .../05/GHSA-5m6p-6vp8-4hgg/GHSA-5m6p-6vp8-4hgg.json | 8 ++------ .../05/GHSA-5m72-x79r-fchm/GHSA-5m72-x79r-fchm.json | 8 ++------ .../05/GHSA-5p8f-8fm7-qwfr/GHSA-5p8f-8fm7-qwfr.json | 8 ++------ .../05/GHSA-5qjq-mx2m-jmx9/GHSA-5qjq-mx2m-jmx9.json | 8 ++------ .../05/GHSA-5r54-pmvg-4gqx/GHSA-5r54-pmvg-4gqx.json | 4 +--- .../05/GHSA-5rvp-q2j7-h9rj/GHSA-5rvp-q2j7-h9rj.json | 4 +--- .../05/GHSA-5v8v-xvv6-4rhg/GHSA-5v8v-xvv6-4rhg.json | 8 ++------ .../05/GHSA-5w24-r25p-r962/GHSA-5w24-r25p-r962.json | 8 ++------ .../05/GHSA-5w46-q7q8-42rm/GHSA-5w46-q7q8-42rm.json | 12 +++--------- .../05/GHSA-5wpm-phm2-2mfm/GHSA-5wpm-phm2-2mfm.json | 12 +++--------- .../05/GHSA-5x44-6vjc-wrhm/GHSA-5x44-6vjc-wrhm.json | 8 ++------ .../05/GHSA-64ch-64p7-9mrx/GHSA-64ch-64p7-9mrx.json | 12 +++--------- .../05/GHSA-6553-8h6r-vxxh/GHSA-6553-8h6r-vxxh.json | 8 ++------ .../05/GHSA-656q-3mvc-v648/GHSA-656q-3mvc-v648.json | 8 ++------ .../05/GHSA-6586-wxp2-vw2f/GHSA-6586-wxp2-vw2f.json | 8 ++------ .../05/GHSA-65pf-jw4p-p3f8/GHSA-65pf-jw4p-p3f8.json | 8 ++------ .../05/GHSA-65vg-v22r-h32v/GHSA-65vg-v22r-h32v.json | 8 ++------ .../05/GHSA-66g2-4363-r37f/GHSA-66g2-4363-r37f.json | 8 ++------ .../05/GHSA-66j4-v3cw-v3vv/GHSA-66j4-v3cw-v3vv.json | 8 ++------ .../05/GHSA-66v8-hp22-2q37/GHSA-66v8-hp22-2q37.json | 8 ++------ .../05/GHSA-674c-q4r5-6548/GHSA-674c-q4r5-6548.json | 8 ++------ .../05/GHSA-6753-4jpx-jv2w/GHSA-6753-4jpx-jv2w.json | 8 ++------ .../05/GHSA-67c2-jfqm-8gqc/GHSA-67c2-jfqm-8gqc.json | 8 ++------ .../05/GHSA-67pr-qr62-6vcm/GHSA-67pr-qr62-6vcm.json | 8 ++------ .../05/GHSA-67v8-27c2-cwg5/GHSA-67v8-27c2-cwg5.json | 8 ++------ .../05/GHSA-686m-27qq-c25w/GHSA-686m-27qq-c25w.json | 8 ++------ .../05/GHSA-68cc-2jmx-28r6/GHSA-68cc-2jmx-28r6.json | 8 ++------ .../05/GHSA-68gc-rmhh-c4gg/GHSA-68gc-rmhh-c4gg.json | 8 ++------ .../05/GHSA-68r3-j757-34j6/GHSA-68r3-j757-34j6.json | 8 ++------ .../05/GHSA-69g2-x726-84wf/GHSA-69g2-x726-84wf.json | 8 ++------ .../05/GHSA-69hv-2gp6-4mgw/GHSA-69hv-2gp6-4mgw.json | 8 ++------ .../05/GHSA-69r8-874p-8rwh/GHSA-69r8-874p-8rwh.json | 8 ++------ .../05/GHSA-6c9w-r483-q74w/GHSA-6c9w-r483-q74w.json | 8 ++------ .../05/GHSA-6crx-v72m-r4wf/GHSA-6crx-v72m-r4wf.json | 4 +--- .../05/GHSA-6f4r-f2fv-g8f4/GHSA-6f4r-f2fv-g8f4.json | 4 +--- .../05/GHSA-6hj9-w8vp-p698/GHSA-6hj9-w8vp-p698.json | 8 ++------ .../05/GHSA-6hwc-9rpr-8qpg/GHSA-6hwc-9rpr-8qpg.json | 8 ++------ .../05/GHSA-6hx2-43pp-mgr8/GHSA-6hx2-43pp-mgr8.json | 8 ++------ .../05/GHSA-6j4h-fwwv-9pxx/GHSA-6j4h-fwwv-9pxx.json | 12 +++--------- .../05/GHSA-6jjh-r6w9-f8mv/GHSA-6jjh-r6w9-f8mv.json | 8 ++------ .../05/GHSA-6pfh-vwh5-gvrc/GHSA-6pfh-vwh5-gvrc.json | 8 ++------ .../05/GHSA-6phh-6j34-7q6c/GHSA-6phh-6j34-7q6c.json | 8 ++------ .../05/GHSA-6pph-j4qx-pw58/GHSA-6pph-j4qx-pw58.json | 8 ++------ .../05/GHSA-6qj4-6737-c6h8/GHSA-6qj4-6737-c6h8.json | 8 ++------ .../05/GHSA-6qqx-5fph-qx4j/GHSA-6qqx-5fph-qx4j.json | 8 ++------ .../05/GHSA-6r44-qm3p-h99q/GHSA-6r44-qm3p-h99q.json | 8 ++------ .../05/GHSA-6r63-p37j-88jj/GHSA-6r63-p37j-88jj.json | 8 ++------ .../05/GHSA-6rqr-xfwj-w2q9/GHSA-6rqr-xfwj-w2q9.json | 8 ++------ .../05/GHSA-6v42-384q-wwf5/GHSA-6v42-384q-wwf5.json | 8 ++------ .../05/GHSA-6vq6-ghrc-jpjw/GHSA-6vq6-ghrc-jpjw.json | 4 +--- .../05/GHSA-6vx9-m878-j4x6/GHSA-6vx9-m878-j4x6.json | 8 ++------ .../05/GHSA-6w86-cqhf-wpxg/GHSA-6w86-cqhf-wpxg.json | 8 ++------ .../05/GHSA-6xfc-46hj-r3cf/GHSA-6xfc-46hj-r3cf.json | 8 ++------ .../05/GHSA-6xfc-qhvw-m8cg/GHSA-6xfc-qhvw-m8cg.json | 8 ++------ .../05/GHSA-6xpf-79gp-9fc2/GHSA-6xpf-79gp-9fc2.json | 8 ++------ .../05/GHSA-72h8-c2vg-vxqr/GHSA-72h8-c2vg-vxqr.json | 8 ++------ .../05/GHSA-734r-xc2j-r7m7/GHSA-734r-xc2j-r7m7.json | 8 ++------ .../05/GHSA-735q-mc2p-r2jc/GHSA-735q-mc2p-r2jc.json | 8 ++------ .../05/GHSA-739f-9qhv-6594/GHSA-739f-9qhv-6594.json | 8 ++------ .../05/GHSA-75xc-p7x5-2rwx/GHSA-75xc-p7x5-2rwx.json | 8 ++------ .../05/GHSA-7726-7mp9-p4f2/GHSA-7726-7mp9-p4f2.json | 8 ++------ .../05/GHSA-77p6-jjq7-fgjg/GHSA-77p6-jjq7-fgjg.json | 8 ++------ .../05/GHSA-77q8-crvw-8w9q/GHSA-77q8-crvw-8w9q.json | 12 +++--------- .../05/GHSA-79pm-w7jm-jv2r/GHSA-79pm-w7jm-jv2r.json | 8 ++------ .../05/GHSA-7c77-3v5r-6jr7/GHSA-7c77-3v5r-6jr7.json | 8 ++------ .../05/GHSA-7c9w-2w99-hrrm/GHSA-7c9w-2w99-hrrm.json | 8 ++------ .../05/GHSA-7cg5-4j3g-r99c/GHSA-7cg5-4j3g-r99c.json | 8 ++------ .../05/GHSA-7cpf-9rpm-3gq2/GHSA-7cpf-9rpm-3gq2.json | 8 ++------ .../05/GHSA-7crf-438p-2fw4/GHSA-7crf-438p-2fw4.json | 8 ++------ .../05/GHSA-7f55-fqw6-8jjp/GHSA-7f55-fqw6-8jjp.json | 8 ++------ .../05/GHSA-7g87-66j4-g7g4/GHSA-7g87-66j4-g7g4.json | 8 ++------ .../05/GHSA-7hh7-8vvm-32g4/GHSA-7hh7-8vvm-32g4.json | 8 ++------ .../05/GHSA-7hmr-qxwq-qpx6/GHSA-7hmr-qxwq-qpx6.json | 8 ++------ .../05/GHSA-7hx2-xxcg-v7c4/GHSA-7hx2-xxcg-v7c4.json | 8 ++------ .../05/GHSA-7j8m-fm49-xgmg/GHSA-7j8m-fm49-xgmg.json | 8 ++------ .../05/GHSA-7mj3-xm28-cffc/GHSA-7mj3-xm28-cffc.json | 8 ++------ .../05/GHSA-7mmx-34xp-frcg/GHSA-7mmx-34xp-frcg.json | 8 ++------ .../05/GHSA-7p7r-8rqq-6xf9/GHSA-7p7r-8rqq-6xf9.json | 12 +++--------- .../05/GHSA-7qgv-8gh6-qmr8/GHSA-7qgv-8gh6-qmr8.json | 8 ++------ .../05/GHSA-7rwq-q3mj-f9qw/GHSA-7rwq-q3mj-f9qw.json | 8 ++------ .../05/GHSA-7rx2-32cc-p83x/GHSA-7rx2-32cc-p83x.json | 8 ++------ .../05/GHSA-7wcx-h8gf-8fh3/GHSA-7wcx-h8gf-8fh3.json | 8 ++------ .../05/GHSA-7wjq-q3c8-8q2h/GHSA-7wjq-q3c8-8q2h.json | 8 ++------ .../05/GHSA-7xgg-9m2p-jqr2/GHSA-7xgg-9m2p-jqr2.json | 8 ++------ .../05/GHSA-8293-g32j-pp9g/GHSA-8293-g32j-pp9g.json | 8 ++------ .../05/GHSA-82fx-x8mw-q5qv/GHSA-82fx-x8mw-q5qv.json | 8 ++------ .../05/GHSA-83h2-hcgw-9hc5/GHSA-83h2-hcgw-9hc5.json | 12 +++--------- .../05/GHSA-8424-8x2w-j5fr/GHSA-8424-8x2w-j5fr.json | 4 +--- .../05/GHSA-847v-wqmh-26g6/GHSA-847v-wqmh-26g6.json | 8 ++------ .../05/GHSA-84w2-4gr5-7c3f/GHSA-84w2-4gr5-7c3f.json | 8 ++------ .../05/GHSA-863x-vcg8-vghr/GHSA-863x-vcg8-vghr.json | 8 ++------ .../05/GHSA-879w-9vpf-9pw9/GHSA-879w-9vpf-9pw9.json | 4 +--- .../05/GHSA-87x6-qp9x-whwg/GHSA-87x6-qp9x-whwg.json | 8 ++------ .../05/GHSA-8963-5hmx-g354/GHSA-8963-5hmx-g354.json | 12 +++--------- .../05/GHSA-8c5r-6wpq-9ghx/GHSA-8c5r-6wpq-9ghx.json | 8 ++------ .../05/GHSA-8cg6-978m-p6jw/GHSA-8cg6-978m-p6jw.json | 8 ++------ .../05/GHSA-8chv-3mvf-2569/GHSA-8chv-3mvf-2569.json | 8 ++------ .../05/GHSA-8cw3-r54r-hfvp/GHSA-8cw3-r54r-hfvp.json | 8 ++------ .../05/GHSA-8f4f-mpwv-cr26/GHSA-8f4f-mpwv-cr26.json | 4 +--- .../05/GHSA-8g5p-w4wh-f5fj/GHSA-8g5p-w4wh-f5fj.json | 8 ++------ .../05/GHSA-8g9c-9q8r-972g/GHSA-8g9c-9q8r-972g.json | 8 ++------ .../05/GHSA-8hmh-2f4f-8hr6/GHSA-8hmh-2f4f-8hr6.json | 8 ++------ .../05/GHSA-8hrr-3cmh-hr2j/GHSA-8hrr-3cmh-hr2j.json | 8 ++------ .../05/GHSA-8j82-3vp9-g4x4/GHSA-8j82-3vp9-g4x4.json | 8 ++------ .../05/GHSA-8m9c-9p98-p88q/GHSA-8m9c-9p98-p88q.json | 8 ++------ .../05/GHSA-8mp4-rxj5-mmqw/GHSA-8mp4-rxj5-mmqw.json | 8 ++------ .../05/GHSA-8p6g-m4gv-rh9c/GHSA-8p6g-m4gv-rh9c.json | 8 ++------ .../05/GHSA-8p9f-c7cc-v345/GHSA-8p9f-c7cc-v345.json | 8 ++------ .../05/GHSA-8pf6-658f-7qh2/GHSA-8pf6-658f-7qh2.json | 8 ++------ .../05/GHSA-8pvx-gf46-6h4p/GHSA-8pvx-gf46-6h4p.json | 8 ++------ .../05/GHSA-8pw5-pwp5-8mcx/GHSA-8pw5-pwp5-8mcx.json | 8 ++------ .../05/GHSA-8q35-pvh9-gxxg/GHSA-8q35-pvh9-gxxg.json | 8 ++------ .../05/GHSA-8q5h-q6w3-hpf3/GHSA-8q5h-q6w3-hpf3.json | 8 ++------ .../05/GHSA-8qqr-fmwm-8jr3/GHSA-8qqr-fmwm-8jr3.json | 8 ++------ .../05/GHSA-8r69-p3hj-6c77/GHSA-8r69-p3hj-6c77.json | 12 +++--------- .../05/GHSA-8rjj-rr5j-hqwh/GHSA-8rjj-rr5j-hqwh.json | 8 ++------ .../05/GHSA-8vqf-8cjg-mqp5/GHSA-8vqf-8cjg-mqp5.json | 8 ++------ .../05/GHSA-8w42-f9rr-g7xm/GHSA-8w42-f9rr-g7xm.json | 8 ++------ .../05/GHSA-8w66-g4m4-h3qv/GHSA-8w66-g4m4-h3qv.json | 8 ++------ .../05/GHSA-8wv9-vqfr-6hg4/GHSA-8wv9-vqfr-6hg4.json | 12 +++--------- .../05/GHSA-8xfg-5ch9-qcf9/GHSA-8xfg-5ch9-qcf9.json | 12 +++--------- .../05/GHSA-8xmx-4f3h-rv3w/GHSA-8xmx-4f3h-rv3w.json | 8 ++------ .../05/GHSA-8xxp-2wxg-r73w/GHSA-8xxp-2wxg-r73w.json | 8 ++------ .../05/GHSA-9259-8h7w-9x58/GHSA-9259-8h7w-9x58.json | 8 ++------ .../05/GHSA-92rw-4752-77x9/GHSA-92rw-4752-77x9.json | 4 +--- .../05/GHSA-944w-6c47-g6xp/GHSA-944w-6c47-g6xp.json | 8 ++------ .../05/GHSA-94pr-mrj6-75rc/GHSA-94pr-mrj6-75rc.json | 8 ++------ .../05/GHSA-962q-q67c-qr76/GHSA-962q-q67c-qr76.json | 8 ++------ .../05/GHSA-96m4-c9r6-grgc/GHSA-96m4-c9r6-grgc.json | 8 ++------ .../05/GHSA-96m9-r7rv-3jq4/GHSA-96m9-r7rv-3jq4.json | 8 ++------ .../05/GHSA-96qc-3p4r-7pjx/GHSA-96qc-3p4r-7pjx.json | 8 ++------ .../05/GHSA-97gc-j846-38jc/GHSA-97gc-j846-38jc.json | 8 ++------ .../05/GHSA-97x2-phf9-hw3v/GHSA-97x2-phf9-hw3v.json | 8 ++------ .../05/GHSA-97x9-ww3p-2gr4/GHSA-97x9-ww3p-2gr4.json | 8 ++------ .../05/GHSA-9838-gx4v-3hpg/GHSA-9838-gx4v-3hpg.json | 8 ++------ .../05/GHSA-98x2-8rq4-gpx2/GHSA-98x2-8rq4-gpx2.json | 8 ++------ .../05/GHSA-99cq-hqh8-c6pp/GHSA-99cq-hqh8-c6pp.json | 12 +++--------- .../05/GHSA-99jg-h7vq-66c7/GHSA-99jg-h7vq-66c7.json | 8 ++------ .../05/GHSA-99mm-5pqr-cw6w/GHSA-99mm-5pqr-cw6w.json | 8 ++------ .../05/GHSA-99wx-928f-hqw6/GHSA-99wx-928f-hqw6.json | 12 +++--------- .../05/GHSA-9c42-4w7m-j868/GHSA-9c42-4w7m-j868.json | 8 ++------ .../05/GHSA-9cf6-x23r-2w69/GHSA-9cf6-x23r-2w69.json | 8 ++------ .../05/GHSA-9g7p-qc7f-rppp/GHSA-9g7p-qc7f-rppp.json | 8 ++------ .../05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json | 8 ++------ .../05/GHSA-9gxq-wfg7-72x4/GHSA-9gxq-wfg7-72x4.json | 4 +--- .../05/GHSA-9hcw-xp2g-53qq/GHSA-9hcw-xp2g-53qq.json | 8 ++------ .../05/GHSA-9hg6-fhc4-v9hp/GHSA-9hg6-fhc4-v9hp.json | 8 ++------ .../05/GHSA-9jxc-x8cc-f2vm/GHSA-9jxc-x8cc-f2vm.json | 8 ++------ .../05/GHSA-9m87-mg83-692p/GHSA-9m87-mg83-692p.json | 8 ++------ .../05/GHSA-9m94-79m8-fpjq/GHSA-9m94-79m8-fpjq.json | 8 ++------ .../05/GHSA-9mpj-44vg-wf94/GHSA-9mpj-44vg-wf94.json | 8 ++------ .../05/GHSA-9p5g-qpwr-674r/GHSA-9p5g-qpwr-674r.json | 8 ++------ .../05/GHSA-9pq2-v987-f9hr/GHSA-9pq2-v987-f9hr.json | 8 ++------ .../05/GHSA-9pq7-v5jj-f484/GHSA-9pq7-v5jj-f484.json | 8 ++------ .../05/GHSA-9r48-fh9f-54xj/GHSA-9r48-fh9f-54xj.json | 8 ++------ .../05/GHSA-9rmr-65mh-rj57/GHSA-9rmr-65mh-rj57.json | 8 ++------ .../05/GHSA-9rpv-24xv-p334/GHSA-9rpv-24xv-p334.json | 8 ++------ .../05/GHSA-9rx5-vw74-rpgf/GHSA-9rx5-vw74-rpgf.json | 4 +--- .../05/GHSA-9v5g-g6rw-x6vc/GHSA-9v5g-g6rw-x6vc.json | 8 ++------ .../05/GHSA-9v5r-mvwm-mx35/GHSA-9v5r-mvwm-mx35.json | 8 ++------ .../05/GHSA-9vr7-48xw-7c8q/GHSA-9vr7-48xw-7c8q.json | 8 ++------ .../05/GHSA-9xp3-9x27-9cfq/GHSA-9xp3-9x27-9cfq.json | 8 ++------ .../05/GHSA-c27c-3q9w-fj4p/GHSA-c27c-3q9w-fj4p.json | 8 ++------ .../05/GHSA-c2c3-chmq-vwx2/GHSA-c2c3-chmq-vwx2.json | 8 ++------ .../05/GHSA-c2jc-w78x-gvc4/GHSA-c2jc-w78x-gvc4.json | 12 +++--------- .../05/GHSA-c2mj-qmxh-xhgx/GHSA-c2mj-qmxh-xhgx.json | 12 +++--------- .../05/GHSA-c4mq-vprg-6v7w/GHSA-c4mq-vprg-6v7w.json | 8 ++------ .../05/GHSA-c94x-m5f4-ghh7/GHSA-c94x-m5f4-ghh7.json | 8 ++------ .../05/GHSA-c9f9-9mhq-cpjq/GHSA-c9f9-9mhq-cpjq.json | 8 ++------ .../05/GHSA-cchm-6hjg-chgx/GHSA-cchm-6hjg-chgx.json | 8 ++------ .../05/GHSA-ccm7-x3qr-c5mr/GHSA-ccm7-x3qr-c5mr.json | 8 ++------ .../05/GHSA-cff3-jr7v-m727/GHSA-cff3-jr7v-m727.json | 12 +++--------- .../05/GHSA-cfxj-95gx-6rxg/GHSA-cfxj-95gx-6rxg.json | 8 ++------ .../05/GHSA-cg9v-g83h-3phq/GHSA-cg9v-g83h-3phq.json | 8 ++------ .../05/GHSA-cgc9-vr83-r9vv/GHSA-cgc9-vr83-r9vv.json | 8 ++------ .../05/GHSA-cgmg-vh78-2874/GHSA-cgmg-vh78-2874.json | 8 ++------ .../05/GHSA-ch46-6845-9c7h/GHSA-ch46-6845-9c7h.json | 8 ++------ .../05/GHSA-cmfr-9hrr-hpg4/GHSA-cmfr-9hrr-hpg4.json | 12 +++--------- .../05/GHSA-cp3h-pwpw-5h82/GHSA-cp3h-pwpw-5h82.json | 8 ++------ .../05/GHSA-cpq4-98gj-fhjv/GHSA-cpq4-98gj-fhjv.json | 8 ++------ .../05/GHSA-cr57-r5gm-397j/GHSA-cr57-r5gm-397j.json | 8 ++------ .../05/GHSA-crwc-cm48-x5x4/GHSA-crwc-cm48-x5x4.json | 8 ++------ .../05/GHSA-cv3c-8grj-qrcf/GHSA-cv3c-8grj-qrcf.json | 4 +--- .../05/GHSA-cvg9-c9g7-9f5r/GHSA-cvg9-c9g7-9f5r.json | 8 ++------ .../05/GHSA-cvrh-6g95-2jv6/GHSA-cvrh-6g95-2jv6.json | 8 ++------ .../05/GHSA-cwwf-85g3-pxwf/GHSA-cwwf-85g3-pxwf.json | 8 ++------ .../05/GHSA-cx39-5qm9-xxr4/GHSA-cx39-5qm9-xxr4.json | 8 ++------ .../05/GHSA-cx4x-7qcr-phfj/GHSA-cx4x-7qcr-phfj.json | 8 ++------ .../05/GHSA-cx82-xv8x-vcx3/GHSA-cx82-xv8x-vcx3.json | 8 ++------ .../05/GHSA-cx8c-h5wc-m358/GHSA-cx8c-h5wc-m358.json | 8 ++------ .../05/GHSA-f28r-ffpj-3747/GHSA-f28r-ffpj-3747.json | 8 ++------ .../05/GHSA-f33f-4j39-x4gc/GHSA-f33f-4j39-x4gc.json | 8 ++------ .../05/GHSA-f3xm-4hq3-2w74/GHSA-f3xm-4hq3-2w74.json | 8 ++------ .../05/GHSA-f46j-qjjj-q5vh/GHSA-f46j-qjjj-q5vh.json | 4 +--- .../05/GHSA-f4w8-g7fj-mpg4/GHSA-f4w8-g7fj-mpg4.json | 12 +++--------- .../05/GHSA-f55g-c9wq-p6hv/GHSA-f55g-c9wq-p6hv.json | 8 ++------ .../05/GHSA-f6rj-2xqc-57mm/GHSA-f6rj-2xqc-57mm.json | 4 +--- .../05/GHSA-f73m-j2hx-pp49/GHSA-f73m-j2hx-pp49.json | 8 ++------ .../05/GHSA-f7vm-7p43-fw6x/GHSA-f7vm-7p43-fw6x.json | 8 ++------ .../05/GHSA-f82q-vw5f-q4cw/GHSA-f82q-vw5f-q4cw.json | 8 ++------ .../05/GHSA-f8xv-g4pr-rpx5/GHSA-f8xv-g4pr-rpx5.json | 12 +++--------- .../05/GHSA-f9pq-xgqx-2754/GHSA-f9pq-xgqx-2754.json | 8 ++------ .../05/GHSA-f9x8-qhfh-2jh9/GHSA-f9x8-qhfh-2jh9.json | 8 ++------ .../05/GHSA-fcpj-4vr6-97f6/GHSA-fcpj-4vr6-97f6.json | 12 +++--------- .../05/GHSA-ffhw-7rj7-7c3x/GHSA-ffhw-7rj7-7c3x.json | 8 ++------ .../05/GHSA-fg3h-xxgq-pq9h/GHSA-fg3h-xxgq-pq9h.json | 8 ++------ .../05/GHSA-fgc3-w3gg-xj3f/GHSA-fgc3-w3gg-xj3f.json | 8 ++------ .../05/GHSA-fgjc-j4q7-m9gg/GHSA-fgjc-j4q7-m9gg.json | 8 ++------ .../05/GHSA-fgp2-c6v9-rwf9/GHSA-fgp2-c6v9-rwf9.json | 8 ++------ .../05/GHSA-fhgx-q2mg-m75m/GHSA-fhgx-q2mg-m75m.json | 8 ++------ .../05/GHSA-fj54-mvm9-92fv/GHSA-fj54-mvm9-92fv.json | 8 ++------ .../05/GHSA-fp36-mxpm-8r2j/GHSA-fp36-mxpm-8r2j.json | 8 ++------ .../05/GHSA-fp59-hqpm-fm38/GHSA-fp59-hqpm-fm38.json | 8 ++------ .../05/GHSA-fqf9-mxr9-9v4v/GHSA-fqf9-mxr9-9v4v.json | 8 ++------ .../05/GHSA-frj5-x46r-24w8/GHSA-frj5-x46r-24w8.json | 8 ++------ .../05/GHSA-fv5w-mvmp-j2mj/GHSA-fv5w-mvmp-j2mj.json | 8 ++------ .../05/GHSA-fvxj-xw9f-pwm9/GHSA-fvxj-xw9f-pwm9.json | 8 ++------ .../05/GHSA-fw36-5gff-4jqw/GHSA-fw36-5gff-4jqw.json | 8 ++------ .../05/GHSA-fwfq-c389-w955/GHSA-fwfq-c389-w955.json | 8 ++------ .../05/GHSA-fwj9-5x88-wxr5/GHSA-fwj9-5x88-wxr5.json | 8 ++------ .../05/GHSA-fx3w-3327-g65c/GHSA-fx3w-3327-g65c.json | 8 ++------ .../05/GHSA-g3vc-mp64-64gm/GHSA-g3vc-mp64-64gm.json | 12 +++--------- .../05/GHSA-g442-vq7g-fmrc/GHSA-g442-vq7g-fmrc.json | 12 +++--------- .../05/GHSA-g5f5-c2xf-hc55/GHSA-g5f5-c2xf-hc55.json | 8 ++------ .../05/GHSA-g5q9-9wx3-w9fh/GHSA-g5q9-9wx3-w9fh.json | 8 ++------ .../05/GHSA-g626-cx5c-cqr6/GHSA-g626-cx5c-cqr6.json | 4 +--- .../05/GHSA-g6h9-mmp2-jjh2/GHSA-g6h9-mmp2-jjh2.json | 8 ++------ .../05/GHSA-g7fc-v5jh-qw54/GHSA-g7fc-v5jh-qw54.json | 8 ++------ .../05/GHSA-g84f-574q-5p85/GHSA-g84f-574q-5p85.json | 12 +++--------- .../05/GHSA-g89v-h54q-6rcc/GHSA-g89v-h54q-6rcc.json | 8 ++------ .../05/GHSA-g8gv-6qwm-g2m8/GHSA-g8gv-6qwm-g2m8.json | 8 ++------ .../05/GHSA-g8hw-8grv-27jh/GHSA-g8hw-8grv-27jh.json | 8 ++------ .../05/GHSA-g8q3-q7hj-qv33/GHSA-g8q3-q7hj-qv33.json | 8 ++------ .../05/GHSA-g96f-p224-qwcp/GHSA-g96f-p224-qwcp.json | 8 ++------ .../05/GHSA-g9hj-jwc2-h8m7/GHSA-g9hj-jwc2-h8m7.json | 8 ++------ .../05/GHSA-g9j8-5mrc-ff94/GHSA-g9j8-5mrc-ff94.json | 8 ++------ .../05/GHSA-g9mq-5vvv-88hf/GHSA-g9mq-5vvv-88hf.json | 8 ++------ .../05/GHSA-gcp2-mf64-vph6/GHSA-gcp2-mf64-vph6.json | 4 +--- .../05/GHSA-gf7w-9wxw-3pvh/GHSA-gf7w-9wxw-3pvh.json | 8 ++------ .../05/GHSA-gg32-gf45-4mcx/GHSA-gg32-gf45-4mcx.json | 8 ++------ .../05/GHSA-ghmp-r6gv-m86f/GHSA-ghmp-r6gv-m86f.json | 8 ++------ .../05/GHSA-ghvr-pf77-p73g/GHSA-ghvr-pf77-p73g.json | 8 ++------ .../05/GHSA-ghwf-37v5-w69f/GHSA-ghwf-37v5-w69f.json | 8 ++------ .../05/GHSA-gp5w-f9p7-f7f5/GHSA-gp5w-f9p7-f7f5.json | 8 ++------ .../05/GHSA-gp8q-5m2c-vprm/GHSA-gp8q-5m2c-vprm.json | 8 ++------ .../05/GHSA-gpfp-4wh2-7vm2/GHSA-gpfp-4wh2-7vm2.json | 8 ++------ .../05/GHSA-gpmw-c588-4p7h/GHSA-gpmw-c588-4p7h.json | 8 ++------ .../05/GHSA-gq4f-x93r-43mj/GHSA-gq4f-x93r-43mj.json | 4 +--- .../05/GHSA-gq7j-hx55-h62p/GHSA-gq7j-hx55-h62p.json | 8 ++------ .../05/GHSA-gr2x-jjff-73f3/GHSA-gr2x-jjff-73f3.json | 8 ++------ .../05/GHSA-gr45-j35r-73rq/GHSA-gr45-j35r-73rq.json | 8 ++------ .../05/GHSA-gr4h-9jxj-93vm/GHSA-gr4h-9jxj-93vm.json | 8 ++------ .../05/GHSA-grgr-vq9q-2h9m/GHSA-grgr-vq9q-2h9m.json | 8 ++------ .../05/GHSA-gvpr-jjwj-3pgg/GHSA-gvpr-jjwj-3pgg.json | 8 ++------ .../05/GHSA-gvxw-rm6f-gffg/GHSA-gvxw-rm6f-gffg.json | 8 ++------ .../05/GHSA-gx2v-252m-68c8/GHSA-gx2v-252m-68c8.json | 8 ++------ .../05/GHSA-gx5r-j32f-r3vc/GHSA-gx5r-j32f-r3vc.json | 8 ++------ .../05/GHSA-gxj7-5cpw-xw2j/GHSA-gxj7-5cpw-xw2j.json | 12 +++--------- .../05/GHSA-gxqw-x97w-h62r/GHSA-gxqw-x97w-h62r.json | 8 ++------ .../05/GHSA-h32x-w4cv-wrq9/GHSA-h32x-w4cv-wrq9.json | 8 ++------ .../05/GHSA-h5cq-wx25-g7hx/GHSA-h5cq-wx25-g7hx.json | 8 ++------ .../05/GHSA-h5gp-hgjc-h2ch/GHSA-h5gp-hgjc-h2ch.json | 8 ++------ .../05/GHSA-h5w7-wjh6-r5wj/GHSA-h5w7-wjh6-r5wj.json | 8 ++------ .../05/GHSA-h7jm-76x4-67c7/GHSA-h7jm-76x4-67c7.json | 12 +++--------- .../05/GHSA-h7qr-pc33-78hj/GHSA-h7qr-pc33-78hj.json | 8 ++------ .../05/GHSA-h8p7-486m-m9h4/GHSA-h8p7-486m-m9h4.json | 8 ++------ .../05/GHSA-h9qf-rfgj-f3p7/GHSA-h9qf-rfgj-f3p7.json | 8 ++------ .../05/GHSA-hc64-fgqq-8m59/GHSA-hc64-fgqq-8m59.json | 8 ++------ .../05/GHSA-hc8f-9595-gg78/GHSA-hc8f-9595-gg78.json | 8 ++------ .../05/GHSA-hg4w-g985-vv3m/GHSA-hg4w-g985-vv3m.json | 8 ++------ .../05/GHSA-hh59-28c3-fqc2/GHSA-hh59-28c3-fqc2.json | 8 ++------ .../05/GHSA-hj7w-jjq4-xh7q/GHSA-hj7w-jjq4-xh7q.json | 8 ++------ .../05/GHSA-hj87-7frf-pcgq/GHSA-hj87-7frf-pcgq.json | 4 +--- .../05/GHSA-hjq3-5xjw-j37q/GHSA-hjq3-5xjw-j37q.json | 8 ++------ .../05/GHSA-hjxr-5xv6-cvq9/GHSA-hjxr-5xv6-cvq9.json | 12 +++--------- .../05/GHSA-hm3v-rmvw-rq7w/GHSA-hm3v-rmvw-rq7w.json | 8 ++------ .../05/GHSA-hmxf-3r58-8g5v/GHSA-hmxf-3r58-8g5v.json | 4 +--- .../05/GHSA-hp27-7h6w-3254/GHSA-hp27-7h6w-3254.json | 8 ++------ .../05/GHSA-hq96-75hc-q3ww/GHSA-hq96-75hc-q3ww.json | 8 ++------ .../05/GHSA-hqm7-vfw5-95rq/GHSA-hqm7-vfw5-95rq.json | 8 ++------ .../05/GHSA-hqq7-9p4f-x9pj/GHSA-hqq7-9p4f-x9pj.json | 8 ++------ .../05/GHSA-hqvv-6648-f492/GHSA-hqvv-6648-f492.json | 8 ++------ .../05/GHSA-hrpm-72v9-33v3/GHSA-hrpm-72v9-33v3.json | 8 ++------ .../05/GHSA-hv8p-8h35-vgf5/GHSA-hv8p-8h35-vgf5.json | 8 ++------ .../05/GHSA-hw3p-w63h-mj9c/GHSA-hw3p-w63h-mj9c.json | 8 ++------ .../05/GHSA-hwh7-pqc2-733j/GHSA-hwh7-pqc2-733j.json | 8 ++------ .../05/GHSA-hwx9-j325-fw69/GHSA-hwx9-j325-fw69.json | 12 +++--------- .../05/GHSA-hxc8-899q-wp57/GHSA-hxc8-899q-wp57.json | 8 ++------ .../05/GHSA-j25r-q825-8mxr/GHSA-j25r-q825-8mxr.json | 8 ++------ .../05/GHSA-j2c4-gm52-5cf5/GHSA-j2c4-gm52-5cf5.json | 8 ++------ .../05/GHSA-j364-gjm2-cwx8/GHSA-j364-gjm2-cwx8.json | 8 ++------ .../05/GHSA-j385-7m59-57jx/GHSA-j385-7m59-57jx.json | 8 ++------ .../05/GHSA-j4vm-fm5v-hp47/GHSA-j4vm-fm5v-hp47.json | 8 ++------ .../05/GHSA-j52m-vhf5-m2h5/GHSA-j52m-vhf5-m2h5.json | 8 ++------ .../05/GHSA-j5fv-c2rq-qx5w/GHSA-j5fv-c2rq-qx5w.json | 8 ++------ .../05/GHSA-j5vx-99c2-mcfv/GHSA-j5vx-99c2-mcfv.json | 8 ++------ .../05/GHSA-j684-c6q4-x85p/GHSA-j684-c6q4-x85p.json | 8 ++------ .../05/GHSA-j6j9-67jq-2hgx/GHSA-j6j9-67jq-2hgx.json | 8 ++------ .../05/GHSA-j6q6-gjjx-g2w9/GHSA-j6q6-gjjx-g2w9.json | 8 ++------ .../05/GHSA-j7g6-6g73-449h/GHSA-j7g6-6g73-449h.json | 8 ++------ .../05/GHSA-j89q-qm4p-pm48/GHSA-j89q-qm4p-pm48.json | 12 +++--------- .../05/GHSA-j94m-42w6-vqp7/GHSA-j94m-42w6-vqp7.json | 8 ++------ .../05/GHSA-j9g2-35f7-x39p/GHSA-j9g2-35f7-x39p.json | 8 ++------ .../05/GHSA-j9qv-h9xj-hx5p/GHSA-j9qv-h9xj-hx5p.json | 8 ++------ .../05/GHSA-j9xp-4524-r98c/GHSA-j9xp-4524-r98c.json | 8 ++------ .../05/GHSA-j9xr-q95m-m875/GHSA-j9xr-q95m-m875.json | 8 ++------ .../05/GHSA-jcjj-wj46-9ph3/GHSA-jcjj-wj46-9ph3.json | 12 +++--------- .../05/GHSA-jcqg-j4q8-3vwg/GHSA-jcqg-j4q8-3vwg.json | 8 ++------ .../05/GHSA-jf5c-qc6c-fgm8/GHSA-jf5c-qc6c-fgm8.json | 8 ++------ .../05/GHSA-jf7p-v9hx-5vrc/GHSA-jf7p-v9hx-5vrc.json | 8 ++------ .../05/GHSA-jfwm-3rx7-mcj8/GHSA-jfwm-3rx7-mcj8.json | 8 ++------ .../05/GHSA-jg58-pvw7-8g35/GHSA-jg58-pvw7-8g35.json | 8 ++------ .../05/GHSA-jggj-8r25-c9r7/GHSA-jggj-8r25-c9r7.json | 8 ++------ .../05/GHSA-jh7g-mcqh-6w6x/GHSA-jh7g-mcqh-6w6x.json | 8 ++------ .../05/GHSA-jj9h-68w9-rr33/GHSA-jj9h-68w9-rr33.json | 8 ++------ .../05/GHSA-jmf4-pvqr-x2gx/GHSA-jmf4-pvqr-x2gx.json | 12 +++--------- .../05/GHSA-jprc-322p-6cp4/GHSA-jprc-322p-6cp4.json | 8 ++------ .../05/GHSA-jrh8-929c-jgcv/GHSA-jrh8-929c-jgcv.json | 8 ++------ .../05/GHSA-jrm2-4w7g-fjw7/GHSA-jrm2-4w7g-fjw7.json | 8 ++------ .../05/GHSA-jrrf-28xq-3v3x/GHSA-jrrf-28xq-3v3x.json | 8 ++------ .../05/GHSA-jv66-wgjv-q2mw/GHSA-jv66-wgjv-q2mw.json | 8 ++------ .../05/GHSA-jw59-g868-rpww/GHSA-jw59-g868-rpww.json | 8 ++------ .../05/GHSA-jwx3-h29g-4mcg/GHSA-jwx3-h29g-4mcg.json | 8 ++------ .../05/GHSA-jx3f-3w4x-79wc/GHSA-jx3f-3w4x-79wc.json | 4 +--- .../05/GHSA-jxpr-3vxp-fp3x/GHSA-jxpr-3vxp-fp3x.json | 12 +++--------- .../05/GHSA-m36c-qvvp-5mjx/GHSA-m36c-qvvp-5mjx.json | 12 +++--------- .../05/GHSA-m3qf-5r58-3mvg/GHSA-m3qf-5r58-3mvg.json | 12 +++--------- .../05/GHSA-m44f-wcwx-2834/GHSA-m44f-wcwx-2834.json | 8 ++------ .../05/GHSA-m4cc-m73q-8mw7/GHSA-m4cc-m73q-8mw7.json | 8 ++------ .../05/GHSA-m596-2w5j-7vgh/GHSA-m596-2w5j-7vgh.json | 8 ++------ .../05/GHSA-m5c5-xwjq-ppf4/GHSA-m5c5-xwjq-ppf4.json | 8 ++------ .../05/GHSA-m5pp-xqx7-796m/GHSA-m5pp-xqx7-796m.json | 8 ++------ .../05/GHSA-m6x6-gxj6-rqq5/GHSA-m6x6-gxj6-rqq5.json | 8 ++------ .../05/GHSA-m6xm-3899-jhmj/GHSA-m6xm-3899-jhmj.json | 8 ++------ .../05/GHSA-m7w5-q5c5-xqrr/GHSA-m7w5-q5c5-xqrr.json | 12 +++--------- .../05/GHSA-m7xm-6mh9-6wwv/GHSA-m7xm-6mh9-6wwv.json | 8 ++------ .../05/GHSA-m82m-22qc-g394/GHSA-m82m-22qc-g394.json | 8 ++------ .../05/GHSA-m879-r67c-4hhh/GHSA-m879-r67c-4hhh.json | 8 ++------ .../05/GHSA-m8w3-4mqx-j486/GHSA-m8w3-4mqx-j486.json | 8 ++------ .../05/GHSA-m93g-hpch-vvw7/GHSA-m93g-hpch-vvw7.json | 8 ++------ .../05/GHSA-m9rf-7fmw-cww6/GHSA-m9rf-7fmw-cww6.json | 8 ++------ .../05/GHSA-mcmp-w9g9-2h7m/GHSA-mcmp-w9g9-2h7m.json | 8 ++------ .../05/GHSA-mfgg-fx8q-m7qh/GHSA-mfgg-fx8q-m7qh.json | 8 ++------ .../05/GHSA-mg6r-7gcg-995g/GHSA-mg6r-7gcg-995g.json | 8 ++------ .../05/GHSA-mhmp-xjgc-756r/GHSA-mhmp-xjgc-756r.json | 8 ++------ .../05/GHSA-mhr3-6pv8-895v/GHSA-mhr3-6pv8-895v.json | 8 ++------ .../05/GHSA-mhvc-g5wh-hrxg/GHSA-mhvc-g5wh-hrxg.json | 8 ++------ .../05/GHSA-mj97-rpm8-w7h9/GHSA-mj97-rpm8-w7h9.json | 8 ++------ .../05/GHSA-mjgx-fh7r-8mmh/GHSA-mjgx-fh7r-8mmh.json | 8 ++------ .../05/GHSA-mjxr-7f24-c564/GHSA-mjxr-7f24-c564.json | 8 ++------ .../05/GHSA-mm25-gp82-85xp/GHSA-mm25-gp82-85xp.json | 8 ++------ .../05/GHSA-mm8c-qj5f-qmf3/GHSA-mm8c-qj5f-qmf3.json | 8 ++------ .../05/GHSA-mmm7-m95r-6pxf/GHSA-mmm7-m95r-6pxf.json | 8 ++------ .../05/GHSA-mpc2-x6fj-x52w/GHSA-mpc2-x6fj-x52w.json | 8 ++------ .../05/GHSA-mq69-2ph6-cgwf/GHSA-mq69-2ph6-cgwf.json | 8 ++------ .../05/GHSA-mqp6-5v25-72qq/GHSA-mqp6-5v25-72qq.json | 8 ++------ .../05/GHSA-mr5h-jvqg-8jg8/GHSA-mr5h-jvqg-8jg8.json | 8 ++------ .../05/GHSA-mr62-x8vh-x4g5/GHSA-mr62-x8vh-x4g5.json | 8 ++------ .../05/GHSA-mv62-rwhc-m5xf/GHSA-mv62-rwhc-m5xf.json | 8 ++------ .../05/GHSA-mv68-j39w-7qfq/GHSA-mv68-j39w-7qfq.json | 8 ++------ .../05/GHSA-mv6x-4xh6-87hm/GHSA-mv6x-4xh6-87hm.json | 8 ++------ .../05/GHSA-mv75-4vxr-65wq/GHSA-mv75-4vxr-65wq.json | 12 +++--------- .../05/GHSA-mvmq-2g5g-4ccc/GHSA-mvmq-2g5g-4ccc.json | 8 ++------ .../05/GHSA-mvwc-vwx4-4x8g/GHSA-mvwc-vwx4-4x8g.json | 8 ++------ .../05/GHSA-mw8p-fqvp-7r34/GHSA-mw8p-fqvp-7r34.json | 8 ++------ .../05/GHSA-mx5q-vqqv-9q7f/GHSA-mx5q-vqqv-9q7f.json | 8 ++------ .../05/GHSA-p2jc-8hc7-j466/GHSA-p2jc-8hc7-j466.json | 8 ++------ .../05/GHSA-p35j-j49h-qh9f/GHSA-p35j-j49h-qh9f.json | 8 ++------ .../05/GHSA-p523-j8f3-523j/GHSA-p523-j8f3-523j.json | 8 ++------ .../05/GHSA-p53p-8qcj-mq4g/GHSA-p53p-8qcj-mq4g.json | 8 ++------ .../05/GHSA-p652-vj2w-8mcw/GHSA-p652-vj2w-8mcw.json | 4 +--- .../05/GHSA-p734-gx4c-4737/GHSA-p734-gx4c-4737.json | 8 ++------ .../05/GHSA-p76r-h495-4wc2/GHSA-p76r-h495-4wc2.json | 12 +++--------- .../05/GHSA-p7xx-frqx-57x6/GHSA-p7xx-frqx-57x6.json | 8 ++------ .../05/GHSA-p83v-6fw4-64rm/GHSA-p83v-6fw4-64rm.json | 8 ++------ .../05/GHSA-p869-hg26-w7c6/GHSA-p869-hg26-w7c6.json | 8 ++------ .../05/GHSA-p87m-wmf9-45h3/GHSA-p87m-wmf9-45h3.json | 8 ++------ .../05/GHSA-p8f2-32q9-cvxw/GHSA-p8f2-32q9-cvxw.json | 8 ++------ .../05/GHSA-p8f4-vrqv-6cp2/GHSA-p8f4-vrqv-6cp2.json | 4 +--- .../05/GHSA-pcrm-wg3j-58j3/GHSA-pcrm-wg3j-58j3.json | 8 ++------ .../05/GHSA-pffp-ch4h-4669/GHSA-pffp-ch4h-4669.json | 4 +--- .../05/GHSA-pg9w-cr87-mrj9/GHSA-pg9w-cr87-mrj9.json | 8 ++------ .../05/GHSA-pgm3-3759-c76g/GHSA-pgm3-3759-c76g.json | 12 +++--------- .../05/GHSA-pgq5-9c6x-f99f/GHSA-pgq5-9c6x-f99f.json | 8 ++------ .../05/GHSA-ph9r-85qg-rxh4/GHSA-ph9r-85qg-rxh4.json | 8 ++------ .../05/GHSA-pjq4-grjv-rg5j/GHSA-pjq4-grjv-rg5j.json | 12 +++--------- .../05/GHSA-ppjx-q6h7-v8hx/GHSA-ppjx-q6h7-v8hx.json | 8 ++------ .../05/GHSA-ppx6-vv9m-fpgm/GHSA-ppx6-vv9m-fpgm.json | 8 ++------ .../05/GHSA-pr3j-rqpg-432w/GHSA-pr3j-rqpg-432w.json | 8 ++------ .../05/GHSA-pvpg-9553-f979/GHSA-pvpg-9553-f979.json | 8 ++------ .../05/GHSA-pw3w-whq9-h2ww/GHSA-pw3w-whq9-h2ww.json | 8 ++------ .../05/GHSA-pw76-p7mv-vxq5/GHSA-pw76-p7mv-vxq5.json | 8 ++------ .../05/GHSA-pwh6-hxc9-8cf2/GHSA-pwh6-hxc9-8cf2.json | 8 ++------ .../05/GHSA-pwhm-g5xc-f3xm/GHSA-pwhm-g5xc-f3xm.json | 8 ++------ .../05/GHSA-pwmw-jmr6-f7c4/GHSA-pwmw-jmr6-f7c4.json | 8 ++------ .../05/GHSA-pwpp-fc52-54w9/GHSA-pwpp-fc52-54w9.json | 8 ++------ .../05/GHSA-q23c-mjcp-8vj6/GHSA-q23c-mjcp-8vj6.json | 8 ++------ .../05/GHSA-q2g9-chwh-vpqj/GHSA-q2g9-chwh-vpqj.json | 8 ++------ .../05/GHSA-q58p-hm39-45gx/GHSA-q58p-hm39-45gx.json | 8 ++------ .../05/GHSA-q58x-r4q4-h596/GHSA-q58x-r4q4-h596.json | 8 ++------ .../05/GHSA-q5m9-8685-c94f/GHSA-q5m9-8685-c94f.json | 8 ++------ .../05/GHSA-q62r-wv6v-9494/GHSA-q62r-wv6v-9494.json | 8 ++------ .../05/GHSA-q688-c68r-qc96/GHSA-q688-c68r-qc96.json | 8 ++------ .../05/GHSA-q729-rgv8-6phg/GHSA-q729-rgv8-6phg.json | 8 ++------ .../05/GHSA-q738-7qq7-r8ff/GHSA-q738-7qq7-r8ff.json | 8 ++------ .../05/GHSA-q7cq-6x2w-xg5f/GHSA-q7cq-6x2w-xg5f.json | 8 ++------ .../05/GHSA-q7h5-v9jq-wx6v/GHSA-q7h5-v9jq-wx6v.json | 8 ++------ .../05/GHSA-q7hf-7qcc-gmg8/GHSA-q7hf-7qcc-gmg8.json | 8 ++------ .../05/GHSA-q83w-52wv-55jx/GHSA-q83w-52wv-55jx.json | 8 ++------ .../05/GHSA-q868-35f4-p658/GHSA-q868-35f4-p658.json | 8 ++------ .../05/GHSA-q8qf-8pcx-vfw7/GHSA-q8qf-8pcx-vfw7.json | 8 ++------ .../05/GHSA-q949-6jcq-74v3/GHSA-q949-6jcq-74v3.json | 12 +++--------- .../05/GHSA-q966-hp9v-pw89/GHSA-q966-hp9v-pw89.json | 8 ++------ .../05/GHSA-q9fg-c965-3f7m/GHSA-q9fg-c965-3f7m.json | 8 ++------ .../05/GHSA-q9fj-r59w-qgwr/GHSA-q9fj-r59w-qgwr.json | 8 ++------ .../05/GHSA-q9gg-5799-8666/GHSA-q9gg-5799-8666.json | 8 ++------ .../05/GHSA-q9m8-r9fr-8x4q/GHSA-q9m8-r9fr-8x4q.json | 8 ++------ .../05/GHSA-qc69-r7wf-6p6c/GHSA-qc69-r7wf-6p6c.json | 8 ++------ .../05/GHSA-qgc6-rvwm-9cf7/GHSA-qgc6-rvwm-9cf7.json | 12 +++--------- .../05/GHSA-qgg7-qhjr-6jh4/GHSA-qgg7-qhjr-6jh4.json | 8 ++------ .../05/GHSA-qhwr-mfcx-qrr9/GHSA-qhwr-mfcx-qrr9.json | 8 ++------ .../05/GHSA-qj37-hv9r-mmr8/GHSA-qj37-hv9r-mmr8.json | 8 ++------ .../05/GHSA-qm5r-g6v2-jcgq/GHSA-qm5r-g6v2-jcgq.json | 8 ++------ .../05/GHSA-qm8q-5g67-7xh5/GHSA-qm8q-5g67-7xh5.json | 8 ++------ .../05/GHSA-qmv6-2p8v-6766/GHSA-qmv6-2p8v-6766.json | 12 +++--------- .../05/GHSA-qp95-2hv6-rp65/GHSA-qp95-2hv6-rp65.json | 8 ++------ .../05/GHSA-qpc5-j9g4-58fr/GHSA-qpc5-j9g4-58fr.json | 8 ++------ .../05/GHSA-qpx8-mq5g-ppwg/GHSA-qpx8-mq5g-ppwg.json | 8 ++------ .../05/GHSA-qq53-8g57-9gr8/GHSA-qq53-8g57-9gr8.json | 8 ++------ .../05/GHSA-qq7v-5jvx-g2r7/GHSA-qq7v-5jvx-g2r7.json | 8 ++------ .../05/GHSA-qqc4-654m-g55g/GHSA-qqc4-654m-g55g.json | 8 ++------ .../05/GHSA-qqg6-4j54-68gr/GHSA-qqg6-4j54-68gr.json | 8 ++------ .../05/GHSA-qr7j-48q9-7wvf/GHSA-qr7j-48q9-7wvf.json | 12 +++--------- .../05/GHSA-qrhf-q88m-c43r/GHSA-qrhf-q88m-c43r.json | 4 +--- .../05/GHSA-qrv4-5384-prhq/GHSA-qrv4-5384-prhq.json | 8 ++------ .../05/GHSA-qv67-8hwr-88xh/GHSA-qv67-8hwr-88xh.json | 8 ++------ .../05/GHSA-qwq9-fh29-mw39/GHSA-qwq9-fh29-mw39.json | 8 ++------ .../05/GHSA-qx8w-qf9q-g5vp/GHSA-qx8w-qf9q-g5vp.json | 12 +++--------- .../05/GHSA-qxh3-5p6c-whgc/GHSA-qxh3-5p6c-whgc.json | 12 +++--------- .../05/GHSA-r275-5g72-r3ph/GHSA-r275-5g72-r3ph.json | 8 ++------ .../05/GHSA-r2cj-jqqc-j833/GHSA-r2cj-jqqc-j833.json | 4 +--- .../05/GHSA-r367-9w5p-9666/GHSA-r367-9w5p-9666.json | 8 ++------ .../05/GHSA-r524-g3q7-mjq5/GHSA-r524-g3q7-mjq5.json | 8 ++------ .../05/GHSA-r5pw-3hxj-jmpq/GHSA-r5pw-3hxj-jmpq.json | 8 ++------ .../05/GHSA-r5vx-622x-4rx2/GHSA-r5vx-622x-4rx2.json | 12 +++--------- .../05/GHSA-r6qr-r386-hmx7/GHSA-r6qr-r386-hmx7.json | 8 ++------ .../05/GHSA-r6rm-754v-479j/GHSA-r6rm-754v-479j.json | 8 ++------ .../05/GHSA-r6xm-wq7q-jr6c/GHSA-r6xm-wq7q-jr6c.json | 8 ++------ .../05/GHSA-r776-v6gr-rxfh/GHSA-r776-v6gr-rxfh.json | 8 ++------ .../05/GHSA-r89j-f3jf-r787/GHSA-r89j-f3jf-r787.json | 8 ++------ .../05/GHSA-r9wc-j38m-fr2f/GHSA-r9wc-j38m-fr2f.json | 8 ++------ .../05/GHSA-rc5q-3pm2-x989/GHSA-rc5q-3pm2-x989.json | 8 ++------ .../05/GHSA-rcj8-5g6r-c9cg/GHSA-rcj8-5g6r-c9cg.json | 12 +++--------- .../05/GHSA-rcq3-m33j-rj5c/GHSA-rcq3-m33j-rj5c.json | 8 ++------ .../05/GHSA-rfv6-w65g-9xh7/GHSA-rfv6-w65g-9xh7.json | 8 ++------ .../05/GHSA-rfw8-3q2w-42qv/GHSA-rfw8-3q2w-42qv.json | 8 ++------ .../05/GHSA-rhrj-qwv6-j538/GHSA-rhrj-qwv6-j538.json | 12 +++--------- .../05/GHSA-rhxm-f2f4-p3p6/GHSA-rhxm-f2f4-p3p6.json | 8 ++------ .../05/GHSA-rjww-mm6p-2h5r/GHSA-rjww-mm6p-2h5r.json | 8 ++------ .../05/GHSA-rp5q-m4xm-3f3r/GHSA-rp5q-m4xm-3f3r.json | 8 ++------ .../05/GHSA-rp6f-x899-cqm4/GHSA-rp6f-x899-cqm4.json | 8 ++------ .../05/GHSA-rpgw-phj8-8867/GHSA-rpgw-phj8-8867.json | 8 ++------ .../05/GHSA-rq2j-wqqr-j8p7/GHSA-rq2j-wqqr-j8p7.json | 8 ++------ .../05/GHSA-rr5f-wx27-pp65/GHSA-rr5f-wx27-pp65.json | 8 ++------ .../05/GHSA-rr5p-rpfr-2rwr/GHSA-rr5p-rpfr-2rwr.json | 8 ++------ .../05/GHSA-rr8m-qw97-823v/GHSA-rr8m-qw97-823v.json | 8 ++------ .../05/GHSA-rv8p-hqqg-w3w8/GHSA-rv8p-hqqg-w3w8.json | 8 ++------ .../05/GHSA-rx44-mqhf-g68j/GHSA-rx44-mqhf-g68j.json | 8 ++------ .../05/GHSA-rx59-9p4r-r7rq/GHSA-rx59-9p4r-r7rq.json | 8 ++------ .../05/GHSA-rxj8-q442-6jcq/GHSA-rxj8-q442-6jcq.json | 8 ++------ .../05/GHSA-v23p-5qjj-x793/GHSA-v23p-5qjj-x793.json | 8 ++------ .../05/GHSA-v285-3pr6-cp87/GHSA-v285-3pr6-cp87.json | 12 +++--------- .../05/GHSA-v28v-ph75-h265/GHSA-v28v-ph75-h265.json | 8 ++------ .../05/GHSA-v298-98c4-32g7/GHSA-v298-98c4-32g7.json | 12 +++--------- .../05/GHSA-v29q-fh48-g7j6/GHSA-v29q-fh48-g7j6.json | 4 +--- .../05/GHSA-v2jq-h62v-wr47/GHSA-v2jq-h62v-wr47.json | 8 ++------ .../05/GHSA-v2p5-mvpw-w7pp/GHSA-v2p5-mvpw-w7pp.json | 8 ++------ .../05/GHSA-v342-j8qr-3849/GHSA-v342-j8qr-3849.json | 8 ++------ .../05/GHSA-v3ph-4853-w2q8/GHSA-v3ph-4853-w2q8.json | 8 ++------ .../05/GHSA-v438-w5c9-9hgq/GHSA-v438-w5c9-9hgq.json | 8 ++------ .../05/GHSA-v452-696f-f255/GHSA-v452-696f-f255.json | 8 ++------ .../05/GHSA-v545-xg3x-8p59/GHSA-v545-xg3x-8p59.json | 8 ++------ .../05/GHSA-v55m-v2xf-m8qw/GHSA-v55m-v2xf-m8qw.json | 8 ++------ .../05/GHSA-v5ff-x4w5-hjhp/GHSA-v5ff-x4w5-hjhp.json | 8 ++------ .../05/GHSA-v5v7-mmfp-xmvv/GHSA-v5v7-mmfp-xmvv.json | 8 ++------ .../05/GHSA-v6vv-p627-g9h9/GHSA-v6vv-p627-g9h9.json | 8 ++------ .../05/GHSA-v6vx-mcc3-f8vr/GHSA-v6vx-mcc3-f8vr.json | 8 ++------ .../05/GHSA-v6x4-5gp4-2g6g/GHSA-v6x4-5gp4-2g6g.json | 12 +++--------- .../05/GHSA-v73h-hhxg-x865/GHSA-v73h-hhxg-x865.json | 12 +++--------- .../05/GHSA-v7m7-f4jx-vjc4/GHSA-v7m7-f4jx-vjc4.json | 8 ++------ .../05/GHSA-v7v6-9p3w-f3m9/GHSA-v7v6-9p3w-f3m9.json | 8 ++------ .../05/GHSA-v8hr-pgg6-cf38/GHSA-v8hr-pgg6-cf38.json | 8 ++------ .../05/GHSA-v943-hr28-2mp8/GHSA-v943-hr28-2mp8.json | 8 ++------ .../05/GHSA-v97c-wm3x-xr3x/GHSA-v97c-wm3x-xr3x.json | 4 +--- .../05/GHSA-v9w5-rf3g-c746/GHSA-v9w5-rf3g-c746.json | 12 +++--------- .../05/GHSA-vc53-c78q-93qw/GHSA-vc53-c78q-93qw.json | 8 ++------ .../05/GHSA-vfw8-4p7f-cjjh/GHSA-vfw8-4p7f-cjjh.json | 4 +--- .../05/GHSA-vg73-6x83-mx7q/GHSA-vg73-6x83-mx7q.json | 4 +--- .../05/GHSA-vhv6-87pm-667v/GHSA-vhv6-87pm-667v.json | 8 ++------ .../05/GHSA-vj85-qf86-f23q/GHSA-vj85-qf86-f23q.json | 8 ++------ .../05/GHSA-vm7q-8rhw-2wwq/GHSA-vm7q-8rhw-2wwq.json | 8 ++------ .../05/GHSA-vpjc-79v8-48cm/GHSA-vpjc-79v8-48cm.json | 8 ++------ .../05/GHSA-vpvq-fg2r-frcr/GHSA-vpvq-fg2r-frcr.json | 8 ++------ .../05/GHSA-vpxx-wvjv-769j/GHSA-vpxx-wvjv-769j.json | 8 ++------ .../05/GHSA-vr92-pw33-4fxj/GHSA-vr92-pw33-4fxj.json | 8 ++------ .../05/GHSA-vrjw-8hw2-rwm5/GHSA-vrjw-8hw2-rwm5.json | 8 ++------ .../05/GHSA-vrq7-q46g-p2fq/GHSA-vrq7-q46g-p2fq.json | 8 ++------ .../05/GHSA-vv8p-qf65-j73w/GHSA-vv8p-qf65-j73w.json | 4 +--- .../05/GHSA-vvf2-r5qm-w4f7/GHSA-vvf2-r5qm-w4f7.json | 8 ++------ .../05/GHSA-vvq3-v6fg-g5vw/GHSA-vvq3-v6fg-g5vw.json | 8 ++------ .../05/GHSA-vw53-rmxx-2xmr/GHSA-vw53-rmxx-2xmr.json | 8 ++------ .../05/GHSA-vwcx-ffx9-jw3x/GHSA-vwcx-ffx9-jw3x.json | 8 ++------ .../05/GHSA-vwqf-h7h6-r8gg/GHSA-vwqf-h7h6-r8gg.json | 8 ++------ .../05/GHSA-w2j5-7v7j-3j8r/GHSA-w2j5-7v7j-3j8r.json | 8 ++------ .../05/GHSA-w44v-8fr4-v7gw/GHSA-w44v-8fr4-v7gw.json | 12 +++--------- .../05/GHSA-w46m-mpvw-cv2h/GHSA-w46m-mpvw-cv2h.json | 4 +--- .../05/GHSA-w479-762h-chxx/GHSA-w479-762h-chxx.json | 8 ++------ .../05/GHSA-w4g5-mcc7-3767/GHSA-w4g5-mcc7-3767.json | 8 ++------ .../05/GHSA-w4j5-x3m4-x3jx/GHSA-w4j5-x3m4-x3jx.json | 8 ++------ .../05/GHSA-w5fp-2j8v-x63m/GHSA-w5fp-2j8v-x63m.json | 8 ++------ .../05/GHSA-w7f7-f46g-r954/GHSA-w7f7-f46g-r954.json | 4 +--- .../05/GHSA-w7xj-fmh9-68cc/GHSA-w7xj-fmh9-68cc.json | 8 ++------ .../05/GHSA-w82f-48jf-c4v4/GHSA-w82f-48jf-c4v4.json | 8 ++------ .../05/GHSA-w84r-65r3-58rj/GHSA-w84r-65r3-58rj.json | 8 ++------ .../05/GHSA-w8j2-273f-92wh/GHSA-w8j2-273f-92wh.json | 8 ++------ .../05/GHSA-w8w2-r9w7-hqwr/GHSA-w8w2-r9w7-hqwr.json | 8 ++------ .../05/GHSA-w998-mp46-3582/GHSA-w998-mp46-3582.json | 8 ++------ .../05/GHSA-w9rf-wf6f-8c9r/GHSA-w9rf-wf6f-8c9r.json | 8 ++------ .../05/GHSA-wc4x-mm5r-q4j3/GHSA-wc4x-mm5r-q4j3.json | 12 +++--------- .../05/GHSA-wc6g-g9wj-mchg/GHSA-wc6g-g9wj-mchg.json | 8 ++------ .../05/GHSA-wc7g-h7q8-29g2/GHSA-wc7g-h7q8-29g2.json | 12 +++--------- .../05/GHSA-wcf9-3wr2-8wmf/GHSA-wcf9-3wr2-8wmf.json | 8 ++------ .../05/GHSA-wcrm-5qg4-797w/GHSA-wcrm-5qg4-797w.json | 8 ++------ .../05/GHSA-wf63-v8gp-v4wv/GHSA-wf63-v8gp-v4wv.json | 12 +++--------- .../05/GHSA-wfrc-r682-56qv/GHSA-wfrc-r682-56qv.json | 4 +--- .../05/GHSA-wg6f-7wh7-87pc/GHSA-wg6f-7wh7-87pc.json | 8 ++------ .../05/GHSA-wgc8-c98w-8fvh/GHSA-wgc8-c98w-8fvh.json | 8 ++------ .../05/GHSA-whgc-86v6-h65r/GHSA-whgc-86v6-h65r.json | 8 ++------ .../05/GHSA-wmxr-9qh6-cpq8/GHSA-wmxr-9qh6-cpq8.json | 8 ++------ .../05/GHSA-wq9m-52vr-cc44/GHSA-wq9m-52vr-cc44.json | 8 ++------ .../05/GHSA-wqm8-5876-3578/GHSA-wqm8-5876-3578.json | 8 ++------ .../05/GHSA-wqmq-2c4h-8v64/GHSA-wqmq-2c4h-8v64.json | 4 +--- .../05/GHSA-wr4v-mm53-3vc3/GHSA-wr4v-mm53-3vc3.json | 8 ++------ .../05/GHSA-wrjw-5qvp-gqcg/GHSA-wrjw-5qvp-gqcg.json | 8 ++------ .../05/GHSA-wv77-666p-gm5q/GHSA-wv77-666p-gm5q.json | 12 +++--------- .../05/GHSA-ww34-37gv-7gf7/GHSA-ww34-37gv-7gf7.json | 12 +++--------- .../05/GHSA-ww76-wxv4-qwxc/GHSA-ww76-wxv4-qwxc.json | 8 ++------ .../05/GHSA-wwmg-f4mg-ffmp/GHSA-wwmg-f4mg-ffmp.json | 8 ++------ .../05/GHSA-x26x-3jfm-g5qc/GHSA-x26x-3jfm-g5qc.json | 8 ++------ .../05/GHSA-x2q6-5p25-frj9/GHSA-x2q6-5p25-frj9.json | 8 ++------ .../05/GHSA-x32h-9jvh-q4wv/GHSA-x32h-9jvh-q4wv.json | 8 ++------ .../05/GHSA-x33g-fm74-m47v/GHSA-x33g-fm74-m47v.json | 8 ++------ .../05/GHSA-x4j2-vmqc-w7pq/GHSA-x4j2-vmqc-w7pq.json | 8 ++------ .../05/GHSA-x58f-3mqq-mj3r/GHSA-x58f-3mqq-mj3r.json | 8 ++------ .../05/GHSA-x5vr-crjr-r249/GHSA-x5vr-crjr-r249.json | 8 ++------ .../05/GHSA-x6rc-q735-q8qg/GHSA-x6rc-q735-q8qg.json | 8 ++------ .../05/GHSA-x7jf-9rq8-cf6r/GHSA-x7jf-9rq8-cf6r.json | 8 ++------ .../05/GHSA-x85r-5p3p-3jxw/GHSA-x85r-5p3p-3jxw.json | 8 ++------ .../05/GHSA-x8h5-wv39-rvrw/GHSA-x8h5-wv39-rvrw.json | 12 +++--------- .../05/GHSA-xc2v-fcxv-wj59/GHSA-xc2v-fcxv-wj59.json | 8 ++------ .../05/GHSA-xchf-g75x-m4xx/GHSA-xchf-g75x-m4xx.json | 8 ++------ .../05/GHSA-xcj4-r8wq-5rcc/GHSA-xcj4-r8wq-5rcc.json | 8 ++------ .../05/GHSA-xcp4-49mj-2j86/GHSA-xcp4-49mj-2j86.json | 4 +--- .../05/GHSA-xf35-pm29-wrq6/GHSA-xf35-pm29-wrq6.json | 8 ++------ .../05/GHSA-xf3h-cpcr-5vv3/GHSA-xf3h-cpcr-5vv3.json | 8 ++------ .../05/GHSA-xg86-vxqv-4j86/GHSA-xg86-vxqv-4j86.json | 8 ++------ .../05/GHSA-xgm3-c263-cjqp/GHSA-xgm3-c263-cjqp.json | 8 ++------ .../05/GHSA-xgvj-75pc-8x47/GHSA-xgvj-75pc-8x47.json | 8 ++------ .../05/GHSA-xhw5-6m93-pmpj/GHSA-xhw5-6m93-pmpj.json | 8 ++------ .../05/GHSA-xj55-jcm5-7pgm/GHSA-xj55-jcm5-7pgm.json | 8 ++------ .../05/GHSA-xjw8-23hc-2wq2/GHSA-xjw8-23hc-2wq2.json | 8 ++------ .../05/GHSA-xjxp-x9rc-crcf/GHSA-xjxp-x9rc-crcf.json | 8 ++------ .../05/GHSA-xmm8-v82g-957c/GHSA-xmm8-v82g-957c.json | 8 ++------ .../05/GHSA-xp87-7m9f-4cr9/GHSA-xp87-7m9f-4cr9.json | 8 ++------ .../05/GHSA-xp9j-q8vg-2xqp/GHSA-xp9j-q8vg-2xqp.json | 8 ++------ .../05/GHSA-xpw5-q9mj-2rfm/GHSA-xpw5-q9mj-2rfm.json | 8 ++------ .../05/GHSA-xq8c-cw49-4mwf/GHSA-xq8c-cw49-4mwf.json | 8 ++------ .../05/GHSA-xq8j-8h49-q9q4/GHSA-xq8j-8h49-q9q4.json | 8 ++------ .../05/GHSA-xv56-v69h-6cw4/GHSA-xv56-v69h-6cw4.json | 8 ++------ .../05/GHSA-xw74-fx28-hrj8/GHSA-xw74-fx28-hrj8.json | 8 ++------ .../05/GHSA-xwfp-hh8f-q7xp/GHSA-xwfp-hh8f-q7xp.json | 8 ++------ .../05/GHSA-xwhw-2q44-qw48/GHSA-xwhw-2q44-qw48.json | 8 ++------ .../05/GHSA-xwmw-hpfw-6rrp/GHSA-xwmw-hpfw-6rrp.json | 8 ++------ .../08/GHSA-73jx-2vf6-7ffj/GHSA-73jx-2vf6-7ffj.json | 4 +--- .../08/GHSA-7jc3-54w2-9q65/GHSA-7jc3-54w2-9q65.json | 4 +--- .../08/GHSA-963w-7frp-mf37/GHSA-963w-7frp-mf37.json | 4 +--- .../08/GHSA-gq7w-5v6q-h6vc/GHSA-gq7w-5v6q-h6vc.json | 4 +--- .../08/GHSA-jgmm-xwf9-46q6/GHSA-jgmm-xwf9-46q6.json | 4 +--- .../08/GHSA-p7ww-6g8j-7w56/GHSA-p7ww-6g8j-7w56.json | 4 +--- .../08/GHSA-pjg2-878f-mvhc/GHSA-pjg2-878f-mvhc.json | 4 +--- .../08/GHSA-pvc4-x6fm-w5wg/GHSA-pvc4-x6fm-w5wg.json | 4 +--- .../08/GHSA-rv2q-xwg7-w99w/GHSA-rv2q-xwg7-w99w.json | 4 +--- .../08/GHSA-rw64-76vh-4phc/GHSA-rw64-76vh-4phc.json | 4 +--- .../10/GHSA-qqx5-8972-3h6c/GHSA-qqx5-8972-3h6c.json | 4 +--- .../01/GHSA-hcqv-28c5-78g8/GHSA-hcqv-28c5-78g8.json | 4 +--- .../02/GHSA-89mw-w342-mqrr/GHSA-89mw-w342-mqrr.json | 4 +--- .../02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json | 4 +--- .../08/GHSA-xc82-5m89-g4jv/GHSA-xc82-5m89-g4jv.json | 4 +--- .../04/GHSA-22fc-mghg-jrwm/GHSA-22fc-mghg-jrwm.json | 4 +--- .../04/GHSA-52h9-53cv-vm4j/GHSA-52h9-53cv-vm4j.json | 12 +++--------- .../04/GHSA-5m8f-c344-mvcv/GHSA-5m8f-c344-mvcv.json | 4 +--- .../04/GHSA-693f-8j8c-5qr2/GHSA-693f-8j8c-5qr2.json | 4 +--- .../04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json | 8 ++------ .../04/GHSA-739r-wh9x-q588/GHSA-739r-wh9x-q588.json | 4 +--- .../04/GHSA-7mfg-57xp-v6gq/GHSA-7mfg-57xp-v6gq.json | 4 +--- .../04/GHSA-7rww-65p2-qxxm/GHSA-7rww-65p2-qxxm.json | 4 +--- .../04/GHSA-7wmw-pgq8-x3w7/GHSA-7wmw-pgq8-x3w7.json | 4 +--- .../04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json | 4 +--- .../04/GHSA-9wwg-9qf5-q4v9/GHSA-9wwg-9qf5-q4v9.json | 4 +--- .../04/GHSA-c4rr-rjwx-4xwh/GHSA-c4rr-rjwx-4xwh.json | 4 +--- .../04/GHSA-ccj7-29gf-j48r/GHSA-ccj7-29gf-j48r.json | 4 +--- .../04/GHSA-cf8f-v932-h337/GHSA-cf8f-v932-h337.json | 4 +--- .../04/GHSA-cv8f-mv6h-rf73/GHSA-cv8f-mv6h-rf73.json | 4 +--- .../04/GHSA-cwvf-gq9g-7g6c/GHSA-cwvf-gq9g-7g6c.json | 4 +--- .../04/GHSA-f56q-4m6g-3xjv/GHSA-f56q-4m6g-3xjv.json | 4 +--- .../04/GHSA-ffr6-cv7v-5fr9/GHSA-ffr6-cv7v-5fr9.json | 4 +--- .../04/GHSA-h9fj-vwxm-9wf4/GHSA-h9fj-vwxm-9wf4.json | 4 +--- .../04/GHSA-hf38-mh8v-7vgj/GHSA-hf38-mh8v-7vgj.json | 4 +--- .../04/GHSA-hvqv-h887-g62m/GHSA-hvqv-h887-g62m.json | 4 +--- .../04/GHSA-hw63-cg2c-rh7g/GHSA-hw63-cg2c-rh7g.json | 4 +--- .../04/GHSA-j2pj-rx5h-324m/GHSA-j2pj-rx5h-324m.json | 4 +--- .../04/GHSA-j64h-79xv-rx9g/GHSA-j64h-79xv-rx9g.json | 4 +--- .../04/GHSA-jg9h-x22w-cq68/GHSA-jg9h-x22w-cq68.json | 4 +--- .../04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json | 12 +++--------- .../04/GHSA-mcqc-h58c-24vj/GHSA-mcqc-h58c-24vj.json | 4 +--- .../04/GHSA-mx9v-h7x6-c37p/GHSA-mx9v-h7x6-c37p.json | 4 +--- .../04/GHSA-p7j9-7qwr-c4hr/GHSA-p7j9-7qwr-c4hr.json | 4 +--- .../04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json | 4 +--- .../04/GHSA-pgj3-fh25-fqr8/GHSA-pgj3-fh25-fqr8.json | 4 +--- .../04/GHSA-pp78-fggv-r899/GHSA-pp78-fggv-r899.json | 4 +--- .../04/GHSA-pvgx-c7xr-3j3w/GHSA-pvgx-c7xr-3j3w.json | 4 +--- .../04/GHSA-pvq7-259f-j6f4/GHSA-pvq7-259f-j6f4.json | 4 +--- .../04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json | 8 ++------ .../04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json | 4 +--- .../04/GHSA-qr2x-466f-55hc/GHSA-qr2x-466f-55hc.json | 4 +--- .../04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json | 8 ++------ .../04/GHSA-rpw4-j7hf-75q9/GHSA-rpw4-j7hf-75q9.json | 4 +--- .../04/GHSA-rqwm-368v-fp53/GHSA-rqwm-368v-fp53.json | 4 +--- .../04/GHSA-v6f7-cqmv-v5gc/GHSA-v6f7-cqmv-v5gc.json | 4 +--- .../04/GHSA-v9pm-5x6v-2p6p/GHSA-v9pm-5x6v-2p6p.json | 4 +--- .../04/GHSA-vp2r-x5x7-7629/GHSA-vp2r-x5x7-7629.json | 4 +--- .../04/GHSA-vqwp-3mpx-9rh4/GHSA-vqwp-3mpx-9rh4.json | 4 +--- .../04/GHSA-x8vp-jrrr-mxv3/GHSA-x8vp-jrrr-mxv3.json | 4 +--- .../04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json | 4 +--- .../04/GHSA-xmh3-q6gr-4qrp/GHSA-xmh3-q6gr-4qrp.json | 4 +--- 966 files changed, 1978 insertions(+), 5934 deletions(-) diff --git a/advisories/github-reviewed/2017/10/GHSA-9h6g-gp95-x3q5/GHSA-9h6g-gp95-x3q5.json b/advisories/github-reviewed/2017/10/GHSA-9h6g-gp95-x3q5/GHSA-9h6g-gp95-x3q5.json index 6cddd72115e..5c33af7a844 100644 --- a/advisories/github-reviewed/2017/10/GHSA-9h6g-gp95-x3q5/GHSA-9h6g-gp95-x3q5.json +++ b/advisories/github-reviewed/2017/10/GHSA-9h6g-gp95-x3q5/GHSA-9h6g-gp95-x3q5.json @@ -93,9 +93,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:28:45Z", diff --git a/advisories/github-reviewed/2017/10/GHSA-ffpv-c4hm-3x6v/GHSA-ffpv-c4hm-3x6v.json b/advisories/github-reviewed/2017/10/GHSA-ffpv-c4hm-3x6v/GHSA-ffpv-c4hm-3x6v.json index 174ca3a22bd..d636c3419b0 100644 --- a/advisories/github-reviewed/2017/10/GHSA-ffpv-c4hm-3x6v/GHSA-ffpv-c4hm-3x6v.json +++ b/advisories/github-reviewed/2017/10/GHSA-ffpv-c4hm-3x6v/GHSA-ffpv-c4hm-3x6v.json @@ -157,9 +157,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:34:31Z", diff --git a/advisories/github-reviewed/2017/10/GHSA-mpxf-gcw2-pw5q/GHSA-mpxf-gcw2-pw5q.json b/advisories/github-reviewed/2017/10/GHSA-mpxf-gcw2-pw5q/GHSA-mpxf-gcw2-pw5q.json index f83a07cb9a9..030376dcef1 100644 --- a/advisories/github-reviewed/2017/10/GHSA-mpxf-gcw2-pw5q/GHSA-mpxf-gcw2-pw5q.json +++ b/advisories/github-reviewed/2017/10/GHSA-mpxf-gcw2-pw5q/GHSA-mpxf-gcw2-pw5q.json @@ -8,9 +8,7 @@ ], "summary": "actionpack Improper Input Validation vulnerability", "details": "`actionpack/lib/action_view/lookup_context.rb` in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-p692-7mm3-3fxg/GHSA-p692-7mm3-3fxg.json b/advisories/github-reviewed/2017/10/GHSA-p692-7mm3-3fxg/GHSA-p692-7mm3-3fxg.json index a89c5e724ff..d8d7cf04517 100644 --- a/advisories/github-reviewed/2017/10/GHSA-p692-7mm3-3fxg/GHSA-p692-7mm3-3fxg.json +++ b/advisories/github-reviewed/2017/10/GHSA-p692-7mm3-3fxg/GHSA-p692-7mm3-3fxg.json @@ -135,9 +135,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:48:14Z", diff --git a/advisories/github-reviewed/2017/12/GHSA-7fpw-cfc4-3p2c/GHSA-7fpw-cfc4-3p2c.json b/advisories/github-reviewed/2017/12/GHSA-7fpw-cfc4-3p2c/GHSA-7fpw-cfc4-3p2c.json index 6385703b780..ec63d731813 100644 --- a/advisories/github-reviewed/2017/12/GHSA-7fpw-cfc4-3p2c/GHSA-7fpw-cfc4-3p2c.json +++ b/advisories/github-reviewed/2017/12/GHSA-7fpw-cfc4-3p2c/GHSA-7fpw-cfc4-3p2c.json @@ -4,9 +4,7 @@ "modified": "2023-06-21T22:00:08Z", "published": "2017-12-28T22:51:45Z", "withdrawn": "2023-06-21T22:00:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate advisory: High severity vulnerability that affects passport-wsfed-saml2", "details": "## Duplicate advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-77fw-rf4v-vfp9. This link is maintained to preserve external references.\n\n## Original Description\nA vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-8whr-v3gm-w8h9/GHSA-8whr-v3gm-w8h9.json b/advisories/github-reviewed/2020/09/GHSA-8whr-v3gm-w8h9/GHSA-8whr-v3gm-w8h9.json index b7a269aeefb..e007ec263e1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8whr-v3gm-w8h9/GHSA-8whr-v3gm-w8h9.json +++ b/advisories/github-reviewed/2020/09/GHSA-8whr-v3gm-w8h9/GHSA-8whr-v3gm-w8h9.json @@ -3,9 +3,7 @@ "id": "GHSA-8whr-v3gm-w8h9", "modified": "2021-10-04T21:08:30Z", "published": "2020-09-03T15:51:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in node-rules", "details": "Versions of `node-rules` prior to 5.0.0 are vulnerable to Command Injection. The package fails to sanitize input rules and passes it directly to an `eval` call when using the `fromJSON` function. This may allow attackers to execute arbitrary code in the system if the rules are user-controlled.\n\n\n## Recommendation\n\nUpgrade to version 5.0.0 or later.", "severity": [ diff --git a/advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json b/advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json index a9fe8fb63ae..f80a0d719bb 100644 --- a/advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json +++ b/advisories/github-reviewed/2022/05/GHSA-m7xj-ccqc-p4g2/GHSA-m7xj-ccqc-p4g2.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat Directory Traversal vulnerability", "details": "Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2022/04/GHSA-225c-mv8x-h9xj/GHSA-225c-mv8x-h9xj.json b/advisories/unreviewed/2022/04/GHSA-225c-mv8x-h9xj/GHSA-225c-mv8x-h9xj.json index 0c42bdab5b7..2737d081e7d 100644 --- a/advisories/unreviewed/2022/04/GHSA-225c-mv8x-h9xj/GHSA-225c-mv8x-h9xj.json +++ b/advisories/unreviewed/2022/04/GHSA-225c-mv8x-h9xj/GHSA-225c-mv8x-h9xj.json @@ -7,12 +7,8 @@ "CVE-2000-0702" ], "details": "The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-229w-c447-wm6p/GHSA-229w-c447-wm6p.json b/advisories/unreviewed/2022/04/GHSA-229w-c447-wm6p/GHSA-229w-c447-wm6p.json index 5c00d4208d4..102f1267b2d 100644 --- a/advisories/unreviewed/2022/04/GHSA-229w-c447-wm6p/GHSA-229w-c447-wm6p.json +++ b/advisories/unreviewed/2022/04/GHSA-229w-c447-wm6p/GHSA-229w-c447-wm6p.json @@ -7,12 +7,8 @@ "CVE-2000-0691" ], "details": "The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-27xw-5882-cqhf/GHSA-27xw-5882-cqhf.json b/advisories/unreviewed/2022/04/GHSA-27xw-5882-cqhf/GHSA-27xw-5882-cqhf.json index 64d9f802041..39786ae33b8 100644 --- a/advisories/unreviewed/2022/04/GHSA-27xw-5882-cqhf/GHSA-27xw-5882-cqhf.json +++ b/advisories/unreviewed/2022/04/GHSA-27xw-5882-cqhf/GHSA-27xw-5882-cqhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-28xm-3c4m-c8r4/GHSA-28xm-3c4m-c8r4.json b/advisories/unreviewed/2022/04/GHSA-28xm-3c4m-c8r4/GHSA-28xm-3c4m-c8r4.json index c7f99e928ed..34a1b184914 100644 --- a/advisories/unreviewed/2022/04/GHSA-28xm-3c4m-c8r4/GHSA-28xm-3c4m-c8r4.json +++ b/advisories/unreviewed/2022/04/GHSA-28xm-3c4m-c8r4/GHSA-28xm-3c4m-c8r4.json @@ -7,12 +7,8 @@ "CVE-2000-0778" ], "details": "IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a \"Translate: f\" header, aka the \"Specialized Header\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2hf6-2xwx-h8c4/GHSA-2hf6-2xwx-h8c4.json b/advisories/unreviewed/2022/04/GHSA-2hf6-2xwx-h8c4/GHSA-2hf6-2xwx-h8c4.json index 61109284752..22438b5e190 100644 --- a/advisories/unreviewed/2022/04/GHSA-2hf6-2xwx-h8c4/GHSA-2hf6-2xwx-h8c4.json +++ b/advisories/unreviewed/2022/04/GHSA-2hf6-2xwx-h8c4/GHSA-2hf6-2xwx-h8c4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jrj-qmg4-g429/GHSA-2jrj-qmg4-g429.json b/advisories/unreviewed/2022/04/GHSA-2jrj-qmg4-g429/GHSA-2jrj-qmg4-g429.json index bbfc32f9853..9619ce56f82 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jrj-qmg4-g429/GHSA-2jrj-qmg4-g429.json +++ b/advisories/unreviewed/2022/04/GHSA-2jrj-qmg4-g429/GHSA-2jrj-qmg4-g429.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2pm5-c2hr-7xg4/GHSA-2pm5-c2hr-7xg4.json b/advisories/unreviewed/2022/04/GHSA-2pm5-c2hr-7xg4/GHSA-2pm5-c2hr-7xg4.json index e31f195fa90..03779adf1f1 100644 --- a/advisories/unreviewed/2022/04/GHSA-2pm5-c2hr-7xg4/GHSA-2pm5-c2hr-7xg4.json +++ b/advisories/unreviewed/2022/04/GHSA-2pm5-c2hr-7xg4/GHSA-2pm5-c2hr-7xg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2q5q-95j3-2gf8/GHSA-2q5q-95j3-2gf8.json b/advisories/unreviewed/2022/04/GHSA-2q5q-95j3-2gf8/GHSA-2q5q-95j3-2gf8.json index a344cf4bc81..bc07acbf2f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-2q5q-95j3-2gf8/GHSA-2q5q-95j3-2gf8.json +++ b/advisories/unreviewed/2022/04/GHSA-2q5q-95j3-2gf8/GHSA-2q5q-95j3-2gf8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2r24-q9c8-57g2/GHSA-2r24-q9c8-57g2.json b/advisories/unreviewed/2022/04/GHSA-2r24-q9c8-57g2/GHSA-2r24-q9c8-57g2.json index 5ed9b4beb44..05d6c42a460 100644 --- a/advisories/unreviewed/2022/04/GHSA-2r24-q9c8-57g2/GHSA-2r24-q9c8-57g2.json +++ b/advisories/unreviewed/2022/04/GHSA-2r24-q9c8-57g2/GHSA-2r24-q9c8-57g2.json @@ -7,12 +7,8 @@ "CVE-2000-0690" ], "details": "Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2xv7-55qq-fqg6/GHSA-2xv7-55qq-fqg6.json b/advisories/unreviewed/2022/04/GHSA-2xv7-55qq-fqg6/GHSA-2xv7-55qq-fqg6.json index 140987a8162..862473754fb 100644 --- a/advisories/unreviewed/2022/04/GHSA-2xv7-55qq-fqg6/GHSA-2xv7-55qq-fqg6.json +++ b/advisories/unreviewed/2022/04/GHSA-2xv7-55qq-fqg6/GHSA-2xv7-55qq-fqg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-34v2-gcjc-32ph/GHSA-34v2-gcjc-32ph.json b/advisories/unreviewed/2022/04/GHSA-34v2-gcjc-32ph/GHSA-34v2-gcjc-32ph.json index 886317aeec2..a5b683f0906 100644 --- a/advisories/unreviewed/2022/04/GHSA-34v2-gcjc-32ph/GHSA-34v2-gcjc-32ph.json +++ b/advisories/unreviewed/2022/04/GHSA-34v2-gcjc-32ph/GHSA-34v2-gcjc-32ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-352q-p9ch-9v33/GHSA-352q-p9ch-9v33.json b/advisories/unreviewed/2022/04/GHSA-352q-p9ch-9v33/GHSA-352q-p9ch-9v33.json index 96e65c54154..256b98f3d99 100644 --- a/advisories/unreviewed/2022/04/GHSA-352q-p9ch-9v33/GHSA-352q-p9ch-9v33.json +++ b/advisories/unreviewed/2022/04/GHSA-352q-p9ch-9v33/GHSA-352q-p9ch-9v33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3cf2-6pj6-x5w3/GHSA-3cf2-6pj6-x5w3.json b/advisories/unreviewed/2022/04/GHSA-3cf2-6pj6-x5w3/GHSA-3cf2-6pj6-x5w3.json index ddd257f07f3..5e55b246da2 100644 --- a/advisories/unreviewed/2022/04/GHSA-3cf2-6pj6-x5w3/GHSA-3cf2-6pj6-x5w3.json +++ b/advisories/unreviewed/2022/04/GHSA-3cf2-6pj6-x5w3/GHSA-3cf2-6pj6-x5w3.json @@ -7,12 +7,8 @@ "CVE-2000-0783" ], "details": "Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3f5f-x3vv-f92r/GHSA-3f5f-x3vv-f92r.json b/advisories/unreviewed/2022/04/GHSA-3f5f-x3vv-f92r/GHSA-3f5f-x3vv-f92r.json index 6d7b675c732..6c034582d99 100644 --- a/advisories/unreviewed/2022/04/GHSA-3f5f-x3vv-f92r/GHSA-3f5f-x3vv-f92r.json +++ b/advisories/unreviewed/2022/04/GHSA-3f5f-x3vv-f92r/GHSA-3f5f-x3vv-f92r.json @@ -7,12 +7,8 @@ "CVE-2000-0777" ], "details": "The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the \"Money Password\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3fm9-pr9w-23q9/GHSA-3fm9-pr9w-23q9.json b/advisories/unreviewed/2022/04/GHSA-3fm9-pr9w-23q9/GHSA-3fm9-pr9w-23q9.json index a8a7a5eb368..1082e5b0f38 100644 --- a/advisories/unreviewed/2022/04/GHSA-3fm9-pr9w-23q9/GHSA-3fm9-pr9w-23q9.json +++ b/advisories/unreviewed/2022/04/GHSA-3fm9-pr9w-23q9/GHSA-3fm9-pr9w-23q9.json @@ -7,12 +7,8 @@ "CVE-2000-0756" ], "details": "Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3gg5-c54v-vxvr/GHSA-3gg5-c54v-vxvr.json b/advisories/unreviewed/2022/04/GHSA-3gg5-c54v-vxvr/GHSA-3gg5-c54v-vxvr.json index c63d4c04d86..686a1668e07 100644 --- a/advisories/unreviewed/2022/04/GHSA-3gg5-c54v-vxvr/GHSA-3gg5-c54v-vxvr.json +++ b/advisories/unreviewed/2022/04/GHSA-3gg5-c54v-vxvr/GHSA-3gg5-c54v-vxvr.json @@ -7,12 +7,8 @@ "CVE-2000-0728" ], "details": "xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3jc7-m4hm-g848/GHSA-3jc7-m4hm-g848.json b/advisories/unreviewed/2022/04/GHSA-3jc7-m4hm-g848/GHSA-3jc7-m4hm-g848.json index 057181771ef..467b3bc97a4 100644 --- a/advisories/unreviewed/2022/04/GHSA-3jc7-m4hm-g848/GHSA-3jc7-m4hm-g848.json +++ b/advisories/unreviewed/2022/04/GHSA-3jc7-m4hm-g848/GHSA-3jc7-m4hm-g848.json @@ -7,12 +7,8 @@ "CVE-2000-0751" ], "details": "mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mgr-cw56-9xx7/GHSA-3mgr-cw56-9xx7.json b/advisories/unreviewed/2022/04/GHSA-3mgr-cw56-9xx7/GHSA-3mgr-cw56-9xx7.json index 4c356c578ce..f3307da4587 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mgr-cw56-9xx7/GHSA-3mgr-cw56-9xx7.json +++ b/advisories/unreviewed/2022/04/GHSA-3mgr-cw56-9xx7/GHSA-3mgr-cw56-9xx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-459f-26mc-vgm2/GHSA-459f-26mc-vgm2.json b/advisories/unreviewed/2022/04/GHSA-459f-26mc-vgm2/GHSA-459f-26mc-vgm2.json index c252661d6d9..41382e9891a 100644 --- a/advisories/unreviewed/2022/04/GHSA-459f-26mc-vgm2/GHSA-459f-26mc-vgm2.json +++ b/advisories/unreviewed/2022/04/GHSA-459f-26mc-vgm2/GHSA-459f-26mc-vgm2.json @@ -7,12 +7,8 @@ "CVE-2000-0673" ], "details": "The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the \"NetBIOS Name Server Protocol Spoofing\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-463q-c9pm-65qg/GHSA-463q-c9pm-65qg.json b/advisories/unreviewed/2022/04/GHSA-463q-c9pm-65qg/GHSA-463q-c9pm-65qg.json index 8f1be4f3c3f..bb8a3eea7d6 100644 --- a/advisories/unreviewed/2022/04/GHSA-463q-c9pm-65qg/GHSA-463q-c9pm-65qg.json +++ b/advisories/unreviewed/2022/04/GHSA-463q-c9pm-65qg/GHSA-463q-c9pm-65qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-46vj-5wgx-vh7x/GHSA-46vj-5wgx-vh7x.json b/advisories/unreviewed/2022/04/GHSA-46vj-5wgx-vh7x/GHSA-46vj-5wgx-vh7x.json index 6fd9c63033d..d386f7cc2a5 100644 --- a/advisories/unreviewed/2022/04/GHSA-46vj-5wgx-vh7x/GHSA-46vj-5wgx-vh7x.json +++ b/advisories/unreviewed/2022/04/GHSA-46vj-5wgx-vh7x/GHSA-46vj-5wgx-vh7x.json @@ -7,12 +7,8 @@ "CVE-2000-0764" ], "details": "Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-492f-5jc2-5m33/GHSA-492f-5jc2-5m33.json b/advisories/unreviewed/2022/04/GHSA-492f-5jc2-5m33/GHSA-492f-5jc2-5m33.json index 1c7dc73cf3a..dd17a1ca021 100644 --- a/advisories/unreviewed/2022/04/GHSA-492f-5jc2-5m33/GHSA-492f-5jc2-5m33.json +++ b/advisories/unreviewed/2022/04/GHSA-492f-5jc2-5m33/GHSA-492f-5jc2-5m33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4g2v-vgjp-2c73/GHSA-4g2v-vgjp-2c73.json b/advisories/unreviewed/2022/04/GHSA-4g2v-vgjp-2c73/GHSA-4g2v-vgjp-2c73.json index 127ad792fa2..15ea1adda7f 100644 --- a/advisories/unreviewed/2022/04/GHSA-4g2v-vgjp-2c73/GHSA-4g2v-vgjp-2c73.json +++ b/advisories/unreviewed/2022/04/GHSA-4g2v-vgjp-2c73/GHSA-4g2v-vgjp-2c73.json @@ -7,12 +7,8 @@ "CVE-2000-0735" ], "details": "Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hw3-x9c6-9f43/GHSA-4hw3-x9c6-9f43.json b/advisories/unreviewed/2022/04/GHSA-4hw3-x9c6-9f43/GHSA-4hw3-x9c6-9f43.json index 48993a920c1..7be1600c450 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hw3-x9c6-9f43/GHSA-4hw3-x9c6-9f43.json +++ b/advisories/unreviewed/2022/04/GHSA-4hw3-x9c6-9f43/GHSA-4hw3-x9c6-9f43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4p45-2736-fq3x/GHSA-4p45-2736-fq3x.json b/advisories/unreviewed/2022/04/GHSA-4p45-2736-fq3x/GHSA-4p45-2736-fq3x.json index 7a47d04d3e0..6eccdd87506 100644 --- a/advisories/unreviewed/2022/04/GHSA-4p45-2736-fq3x/GHSA-4p45-2736-fq3x.json +++ b/advisories/unreviewed/2022/04/GHSA-4p45-2736-fq3x/GHSA-4p45-2736-fq3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4pvp-pp8j-mcf5/GHSA-4pvp-pp8j-mcf5.json b/advisories/unreviewed/2022/04/GHSA-4pvp-pp8j-mcf5/GHSA-4pvp-pp8j-mcf5.json index a0a7656f67c..4b6461cfa03 100644 --- a/advisories/unreviewed/2022/04/GHSA-4pvp-pp8j-mcf5/GHSA-4pvp-pp8j-mcf5.json +++ b/advisories/unreviewed/2022/04/GHSA-4pvp-pp8j-mcf5/GHSA-4pvp-pp8j-mcf5.json @@ -7,12 +7,8 @@ "CVE-2000-0726" ], "details": "CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4w9w-xw54-8fxp/GHSA-4w9w-xw54-8fxp.json b/advisories/unreviewed/2022/04/GHSA-4w9w-xw54-8fxp/GHSA-4w9w-xw54-8fxp.json index d8d2d9f76cd..945f7fa8518 100644 --- a/advisories/unreviewed/2022/04/GHSA-4w9w-xw54-8fxp/GHSA-4w9w-xw54-8fxp.json +++ b/advisories/unreviewed/2022/04/GHSA-4w9w-xw54-8fxp/GHSA-4w9w-xw54-8fxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4wf3-9pvj-q52c/GHSA-4wf3-9pvj-q52c.json b/advisories/unreviewed/2022/04/GHSA-4wf3-9pvj-q52c/GHSA-4wf3-9pvj-q52c.json index 91d6ab98a10..e16a4cff229 100644 --- a/advisories/unreviewed/2022/04/GHSA-4wf3-9pvj-q52c/GHSA-4wf3-9pvj-q52c.json +++ b/advisories/unreviewed/2022/04/GHSA-4wf3-9pvj-q52c/GHSA-4wf3-9pvj-q52c.json @@ -7,12 +7,8 @@ "CVE-2000-0698" ], "details": "Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4xxw-jx52-qf53/GHSA-4xxw-jx52-qf53.json b/advisories/unreviewed/2022/04/GHSA-4xxw-jx52-qf53/GHSA-4xxw-jx52-qf53.json index 51b930366c3..364ef0707fe 100644 --- a/advisories/unreviewed/2022/04/GHSA-4xxw-jx52-qf53/GHSA-4xxw-jx52-qf53.json +++ b/advisories/unreviewed/2022/04/GHSA-4xxw-jx52-qf53/GHSA-4xxw-jx52-qf53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-527c-22g3-c82g/GHSA-527c-22g3-c82g.json b/advisories/unreviewed/2022/04/GHSA-527c-22g3-c82g/GHSA-527c-22g3-c82g.json index 2008043a180..160a361d417 100644 --- a/advisories/unreviewed/2022/04/GHSA-527c-22g3-c82g/GHSA-527c-22g3-c82g.json +++ b/advisories/unreviewed/2022/04/GHSA-527c-22g3-c82g/GHSA-527c-22g3-c82g.json @@ -7,12 +7,8 @@ "CVE-2000-0663" ], "details": "The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the \"Relative Shell Path\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-52vv-c34v-c37f/GHSA-52vv-c34v-c37f.json b/advisories/unreviewed/2022/04/GHSA-52vv-c34v-c37f/GHSA-52vv-c34v-c37f.json index f1821d4cedd..84b9a8669a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-52vv-c34v-c37f/GHSA-52vv-c34v-c37f.json +++ b/advisories/unreviewed/2022/04/GHSA-52vv-c34v-c37f/GHSA-52vv-c34v-c37f.json @@ -7,12 +7,8 @@ "CVE-2000-0717" ], "details": "GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-543m-2r39-9vrj/GHSA-543m-2r39-9vrj.json b/advisories/unreviewed/2022/04/GHSA-543m-2r39-9vrj/GHSA-543m-2r39-9vrj.json index e2f58bd66b1..16db5b5b053 100644 --- a/advisories/unreviewed/2022/04/GHSA-543m-2r39-9vrj/GHSA-543m-2r39-9vrj.json +++ b/advisories/unreviewed/2022/04/GHSA-543m-2r39-9vrj/GHSA-543m-2r39-9vrj.json @@ -7,12 +7,8 @@ "CVE-2000-0740" ], "details": "Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-55hr-hv86-7xr4/GHSA-55hr-hv86-7xr4.json b/advisories/unreviewed/2022/04/GHSA-55hr-hv86-7xr4/GHSA-55hr-hv86-7xr4.json index f6f43c6cf59..3dc0e0641c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-55hr-hv86-7xr4/GHSA-55hr-hv86-7xr4.json +++ b/advisories/unreviewed/2022/04/GHSA-55hr-hv86-7xr4/GHSA-55hr-hv86-7xr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5969-x38p-xrjj/GHSA-5969-x38p-xrjj.json b/advisories/unreviewed/2022/04/GHSA-5969-x38p-xrjj/GHSA-5969-x38p-xrjj.json index 8caa28065ad..3b650f779de 100644 --- a/advisories/unreviewed/2022/04/GHSA-5969-x38p-xrjj/GHSA-5969-x38p-xrjj.json +++ b/advisories/unreviewed/2022/04/GHSA-5969-x38p-xrjj/GHSA-5969-x38p-xrjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-59qr-cc8f-v837/GHSA-59qr-cc8f-v837.json b/advisories/unreviewed/2022/04/GHSA-59qr-cc8f-v837/GHSA-59qr-cc8f-v837.json index af3274507ef..fbe7718ceb8 100644 --- a/advisories/unreviewed/2022/04/GHSA-59qr-cc8f-v837/GHSA-59qr-cc8f-v837.json +++ b/advisories/unreviewed/2022/04/GHSA-59qr-cc8f-v837/GHSA-59qr-cc8f-v837.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5f92-rmj7-665j/GHSA-5f92-rmj7-665j.json b/advisories/unreviewed/2022/04/GHSA-5f92-rmj7-665j/GHSA-5f92-rmj7-665j.json index 23142d20510..7ebf1b6e1fb 100644 --- a/advisories/unreviewed/2022/04/GHSA-5f92-rmj7-665j/GHSA-5f92-rmj7-665j.json +++ b/advisories/unreviewed/2022/04/GHSA-5f92-rmj7-665j/GHSA-5f92-rmj7-665j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5j27-r362-gvrr/GHSA-5j27-r362-gvrr.json b/advisories/unreviewed/2022/04/GHSA-5j27-r362-gvrr/GHSA-5j27-r362-gvrr.json index bb3277fc5a3..99a91dfd3e1 100644 --- a/advisories/unreviewed/2022/04/GHSA-5j27-r362-gvrr/GHSA-5j27-r362-gvrr.json +++ b/advisories/unreviewed/2022/04/GHSA-5j27-r362-gvrr/GHSA-5j27-r362-gvrr.json @@ -7,12 +7,8 @@ "CVE-2000-0721" ], "details": "The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-63gp-3rq7-g7h2/GHSA-63gp-3rq7-g7h2.json b/advisories/unreviewed/2022/04/GHSA-63gp-3rq7-g7h2/GHSA-63gp-3rq7-g7h2.json index e1c7ce892ef..eed099eb03e 100644 --- a/advisories/unreviewed/2022/04/GHSA-63gp-3rq7-g7h2/GHSA-63gp-3rq7-g7h2.json +++ b/advisories/unreviewed/2022/04/GHSA-63gp-3rq7-g7h2/GHSA-63gp-3rq7-g7h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6c94-2q82-97hw/GHSA-6c94-2q82-97hw.json b/advisories/unreviewed/2022/04/GHSA-6c94-2q82-97hw/GHSA-6c94-2q82-97hw.json index ae61a3a26b1..b34e8160e1a 100644 --- a/advisories/unreviewed/2022/04/GHSA-6c94-2q82-97hw/GHSA-6c94-2q82-97hw.json +++ b/advisories/unreviewed/2022/04/GHSA-6c94-2q82-97hw/GHSA-6c94-2q82-97hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6cq5-57cw-hg4c/GHSA-6cq5-57cw-hg4c.json b/advisories/unreviewed/2022/04/GHSA-6cq5-57cw-hg4c/GHSA-6cq5-57cw-hg4c.json index 5f2c7efb00d..a466fdc4fb0 100644 --- a/advisories/unreviewed/2022/04/GHSA-6cq5-57cw-hg4c/GHSA-6cq5-57cw-hg4c.json +++ b/advisories/unreviewed/2022/04/GHSA-6cq5-57cw-hg4c/GHSA-6cq5-57cw-hg4c.json @@ -7,12 +7,8 @@ "CVE-2000-0736" ], "details": "Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6g5v-qx4m-5w7m/GHSA-6g5v-qx4m-5w7m.json b/advisories/unreviewed/2022/04/GHSA-6g5v-qx4m-5w7m/GHSA-6g5v-qx4m-5w7m.json index bf94f72792f..da96cb988c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-6g5v-qx4m-5w7m/GHSA-6g5v-qx4m-5w7m.json +++ b/advisories/unreviewed/2022/04/GHSA-6g5v-qx4m-5w7m/GHSA-6g5v-qx4m-5w7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6jcv-h8m6-j6vm/GHSA-6jcv-h8m6-j6vm.json b/advisories/unreviewed/2022/04/GHSA-6jcv-h8m6-j6vm/GHSA-6jcv-h8m6-j6vm.json index e456bcc3dbe..6ae806c1827 100644 --- a/advisories/unreviewed/2022/04/GHSA-6jcv-h8m6-j6vm/GHSA-6jcv-h8m6-j6vm.json +++ b/advisories/unreviewed/2022/04/GHSA-6jcv-h8m6-j6vm/GHSA-6jcv-h8m6-j6vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-72m4-92vp-gxfj/GHSA-72m4-92vp-gxfj.json b/advisories/unreviewed/2022/04/GHSA-72m4-92vp-gxfj/GHSA-72m4-92vp-gxfj.json index 93d7c1daa3d..64f732d2048 100644 --- a/advisories/unreviewed/2022/04/GHSA-72m4-92vp-gxfj/GHSA-72m4-92vp-gxfj.json +++ b/advisories/unreviewed/2022/04/GHSA-72m4-92vp-gxfj/GHSA-72m4-92vp-gxfj.json @@ -7,12 +7,8 @@ "CVE-2000-0672" ], "details": "The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-739f-46gp-44jc/GHSA-739f-46gp-44jc.json b/advisories/unreviewed/2022/04/GHSA-739f-46gp-44jc/GHSA-739f-46gp-44jc.json index 502c3541d9d..a8a1758b15f 100644 --- a/advisories/unreviewed/2022/04/GHSA-739f-46gp-44jc/GHSA-739f-46gp-44jc.json +++ b/advisories/unreviewed/2022/04/GHSA-739f-46gp-44jc/GHSA-739f-46gp-44jc.json @@ -7,12 +7,8 @@ "CVE-2000-0789" ], "details": "WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7428-xfvg-x3qj/GHSA-7428-xfvg-x3qj.json b/advisories/unreviewed/2022/04/GHSA-7428-xfvg-x3qj/GHSA-7428-xfvg-x3qj.json index f117cce8ae5..0ba699ee453 100644 --- a/advisories/unreviewed/2022/04/GHSA-7428-xfvg-x3qj/GHSA-7428-xfvg-x3qj.json +++ b/advisories/unreviewed/2022/04/GHSA-7428-xfvg-x3qj/GHSA-7428-xfvg-x3qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7552-rx4g-hpqv/GHSA-7552-rx4g-hpqv.json b/advisories/unreviewed/2022/04/GHSA-7552-rx4g-hpqv/GHSA-7552-rx4g-hpqv.json index 9036726afd0..c169a5fe717 100644 --- a/advisories/unreviewed/2022/04/GHSA-7552-rx4g-hpqv/GHSA-7552-rx4g-hpqv.json +++ b/advisories/unreviewed/2022/04/GHSA-7552-rx4g-hpqv/GHSA-7552-rx4g-hpqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-75vj-765v-x3fg/GHSA-75vj-765v-x3fg.json b/advisories/unreviewed/2022/04/GHSA-75vj-765v-x3fg/GHSA-75vj-765v-x3fg.json index 5320cd2b212..754c83741c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-75vj-765v-x3fg/GHSA-75vj-765v-x3fg.json +++ b/advisories/unreviewed/2022/04/GHSA-75vj-765v-x3fg/GHSA-75vj-765v-x3fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-78fw-2gr4-583c/GHSA-78fw-2gr4-583c.json b/advisories/unreviewed/2022/04/GHSA-78fw-2gr4-583c/GHSA-78fw-2gr4-583c.json index b0bce049f6e..26459cf0bfa 100644 --- a/advisories/unreviewed/2022/04/GHSA-78fw-2gr4-583c/GHSA-78fw-2gr4-583c.json +++ b/advisories/unreviewed/2022/04/GHSA-78fw-2gr4-583c/GHSA-78fw-2gr4-583c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-78gg-3pq4-5rh6/GHSA-78gg-3pq4-5rh6.json b/advisories/unreviewed/2022/04/GHSA-78gg-3pq4-5rh6/GHSA-78gg-3pq4-5rh6.json index 984bad78923..77605e6bec2 100644 --- a/advisories/unreviewed/2022/04/GHSA-78gg-3pq4-5rh6/GHSA-78gg-3pq4-5rh6.json +++ b/advisories/unreviewed/2022/04/GHSA-78gg-3pq4-5rh6/GHSA-78gg-3pq4-5rh6.json @@ -7,12 +7,8 @@ "CVE-2000-0771" ], "details": "Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the \"Local Security Policy Corruption\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-79qc-35xf-whr6/GHSA-79qc-35xf-whr6.json b/advisories/unreviewed/2022/04/GHSA-79qc-35xf-whr6/GHSA-79qc-35xf-whr6.json index 124988cd9f5..92e8efa39eb 100644 --- a/advisories/unreviewed/2022/04/GHSA-79qc-35xf-whr6/GHSA-79qc-35xf-whr6.json +++ b/advisories/unreviewed/2022/04/GHSA-79qc-35xf-whr6/GHSA-79qc-35xf-whr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c4p-f5qf-vx4w/GHSA-7c4p-f5qf-vx4w.json b/advisories/unreviewed/2022/04/GHSA-7c4p-f5qf-vx4w/GHSA-7c4p-f5qf-vx4w.json index ac7b7e80bf4..c47aee1e96b 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c4p-f5qf-vx4w/GHSA-7c4p-f5qf-vx4w.json +++ b/advisories/unreviewed/2022/04/GHSA-7c4p-f5qf-vx4w/GHSA-7c4p-f5qf-vx4w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7cv3-2v97-6cpf/GHSA-7cv3-2v97-6cpf.json b/advisories/unreviewed/2022/04/GHSA-7cv3-2v97-6cpf/GHSA-7cv3-2v97-6cpf.json index 2a33109fc44..c65f1d293f5 100644 --- a/advisories/unreviewed/2022/04/GHSA-7cv3-2v97-6cpf/GHSA-7cv3-2v97-6cpf.json +++ b/advisories/unreviewed/2022/04/GHSA-7cv3-2v97-6cpf/GHSA-7cv3-2v97-6cpf.json @@ -7,12 +7,8 @@ "CVE-2000-0710" ], "details": "The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7j3m-5478-cr36/GHSA-7j3m-5478-cr36.json b/advisories/unreviewed/2022/04/GHSA-7j3m-5478-cr36/GHSA-7j3m-5478-cr36.json index 3030fff7663..57384361954 100644 --- a/advisories/unreviewed/2022/04/GHSA-7j3m-5478-cr36/GHSA-7j3m-5478-cr36.json +++ b/advisories/unreviewed/2022/04/GHSA-7j3m-5478-cr36/GHSA-7j3m-5478-cr36.json @@ -7,12 +7,8 @@ "CVE-2000-0767" ], "details": "The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the \"Scriptlet Rendering\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7jgq-4jfh-mw69/GHSA-7jgq-4jfh-mw69.json b/advisories/unreviewed/2022/04/GHSA-7jgq-4jfh-mw69/GHSA-7jgq-4jfh-mw69.json index 5e9aae10261..e3eb6d78e9e 100644 --- a/advisories/unreviewed/2022/04/GHSA-7jgq-4jfh-mw69/GHSA-7jgq-4jfh-mw69.json +++ b/advisories/unreviewed/2022/04/GHSA-7jgq-4jfh-mw69/GHSA-7jgq-4jfh-mw69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7qg4-rqjp-rwv5/GHSA-7qg4-rqjp-rwv5.json b/advisories/unreviewed/2022/04/GHSA-7qg4-rqjp-rwv5/GHSA-7qg4-rqjp-rwv5.json index 01c483a6d3d..008dd9db837 100644 --- a/advisories/unreviewed/2022/04/GHSA-7qg4-rqjp-rwv5/GHSA-7qg4-rqjp-rwv5.json +++ b/advisories/unreviewed/2022/04/GHSA-7qg4-rqjp-rwv5/GHSA-7qg4-rqjp-rwv5.json @@ -7,12 +7,8 @@ "CVE-2000-0785" ], "details": "WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7qr9-r4q9-9m8f/GHSA-7qr9-r4q9-9m8f.json b/advisories/unreviewed/2022/04/GHSA-7qr9-r4q9-9m8f/GHSA-7qr9-r4q9-9m8f.json index 09ab1b2e886..baf7190fe2f 100644 --- a/advisories/unreviewed/2022/04/GHSA-7qr9-r4q9-9m8f/GHSA-7qr9-r4q9-9m8f.json +++ b/advisories/unreviewed/2022/04/GHSA-7qr9-r4q9-9m8f/GHSA-7qr9-r4q9-9m8f.json @@ -7,12 +7,8 @@ "CVE-2000-0738" ], "details": "WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7rf5-wxhm-vx5h/GHSA-7rf5-wxhm-vx5h.json b/advisories/unreviewed/2022/04/GHSA-7rf5-wxhm-vx5h/GHSA-7rf5-wxhm-vx5h.json index aac9b21f194..b81e5f8c214 100644 --- a/advisories/unreviewed/2022/04/GHSA-7rf5-wxhm-vx5h/GHSA-7rf5-wxhm-vx5h.json +++ b/advisories/unreviewed/2022/04/GHSA-7rf5-wxhm-vx5h/GHSA-7rf5-wxhm-vx5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7wmj-7phv-64wc/GHSA-7wmj-7phv-64wc.json b/advisories/unreviewed/2022/04/GHSA-7wmj-7phv-64wc/GHSA-7wmj-7phv-64wc.json index afb15a71488..71b2f7003da 100644 --- a/advisories/unreviewed/2022/04/GHSA-7wmj-7phv-64wc/GHSA-7wmj-7phv-64wc.json +++ b/advisories/unreviewed/2022/04/GHSA-7wmj-7phv-64wc/GHSA-7wmj-7phv-64wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7ww5-vvcr-3rw4/GHSA-7ww5-vvcr-3rw4.json b/advisories/unreviewed/2022/04/GHSA-7ww5-vvcr-3rw4/GHSA-7ww5-vvcr-3rw4.json index 0258b1e1a1b..140503e0477 100644 --- a/advisories/unreviewed/2022/04/GHSA-7ww5-vvcr-3rw4/GHSA-7ww5-vvcr-3rw4.json +++ b/advisories/unreviewed/2022/04/GHSA-7ww5-vvcr-3rw4/GHSA-7ww5-vvcr-3rw4.json @@ -7,12 +7,8 @@ "CVE-2000-0753" ], "details": "The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8768-7prf-6f7g/GHSA-8768-7prf-6f7g.json b/advisories/unreviewed/2022/04/GHSA-8768-7prf-6f7g/GHSA-8768-7prf-6f7g.json index d4097bed81d..50e3ca8f9dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-8768-7prf-6f7g/GHSA-8768-7prf-6f7g.json +++ b/advisories/unreviewed/2022/04/GHSA-8768-7prf-6f7g/GHSA-8768-7prf-6f7g.json @@ -7,12 +7,8 @@ "CVE-2000-0708" ], "details": "Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-87p2-j2pw-qwfc/GHSA-87p2-j2pw-qwfc.json b/advisories/unreviewed/2022/04/GHSA-87p2-j2pw-qwfc/GHSA-87p2-j2pw-qwfc.json index 1b123c3d79c..c67eb160b60 100644 --- a/advisories/unreviewed/2022/04/GHSA-87p2-j2pw-qwfc/GHSA-87p2-j2pw-qwfc.json +++ b/advisories/unreviewed/2022/04/GHSA-87p2-j2pw-qwfc/GHSA-87p2-j2pw-qwfc.json @@ -7,12 +7,8 @@ "CVE-2000-0713" ], "details": "Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88vq-mwgw-6mcf/GHSA-88vq-mwgw-6mcf.json b/advisories/unreviewed/2022/04/GHSA-88vq-mwgw-6mcf/GHSA-88vq-mwgw-6mcf.json index a5cb55d050d..e102a8e44cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-88vq-mwgw-6mcf/GHSA-88vq-mwgw-6mcf.json +++ b/advisories/unreviewed/2022/04/GHSA-88vq-mwgw-6mcf/GHSA-88vq-mwgw-6mcf.json @@ -7,12 +7,8 @@ "CVE-2000-0729" ], "details": "FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-893w-6f8w-fqc2/GHSA-893w-6f8w-fqc2.json b/advisories/unreviewed/2022/04/GHSA-893w-6f8w-fqc2/GHSA-893w-6f8w-fqc2.json index 9fca6690afb..ca6a66d0364 100644 --- a/advisories/unreviewed/2022/04/GHSA-893w-6f8w-fqc2/GHSA-893w-6f8w-fqc2.json +++ b/advisories/unreviewed/2022/04/GHSA-893w-6f8w-fqc2/GHSA-893w-6f8w-fqc2.json @@ -7,12 +7,8 @@ "CVE-2000-0674" ], "details": "ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-89hf-mmpp-p6fm/GHSA-89hf-mmpp-p6fm.json b/advisories/unreviewed/2022/04/GHSA-89hf-mmpp-p6fm/GHSA-89hf-mmpp-p6fm.json index 859593e8f15..2d5e4f87fcd 100644 --- a/advisories/unreviewed/2022/04/GHSA-89hf-mmpp-p6fm/GHSA-89hf-mmpp-p6fm.json +++ b/advisories/unreviewed/2022/04/GHSA-89hf-mmpp-p6fm/GHSA-89hf-mmpp-p6fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cqc-8pp8-h3j3/GHSA-8cqc-8pp8-h3j3.json b/advisories/unreviewed/2022/04/GHSA-8cqc-8pp8-h3j3/GHSA-8cqc-8pp8-h3j3.json index d3492552590..5959916a3d3 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cqc-8pp8-h3j3/GHSA-8cqc-8pp8-h3j3.json +++ b/advisories/unreviewed/2022/04/GHSA-8cqc-8pp8-h3j3/GHSA-8cqc-8pp8-h3j3.json @@ -7,12 +7,8 @@ "CVE-2000-0701" ], "details": "The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8h7q-8fjc-rcf2/GHSA-8h7q-8fjc-rcf2.json b/advisories/unreviewed/2022/04/GHSA-8h7q-8fjc-rcf2/GHSA-8h7q-8fjc-rcf2.json index d1a3a112b78..f8bfa33b938 100644 --- a/advisories/unreviewed/2022/04/GHSA-8h7q-8fjc-rcf2/GHSA-8h7q-8fjc-rcf2.json +++ b/advisories/unreviewed/2022/04/GHSA-8h7q-8fjc-rcf2/GHSA-8h7q-8fjc-rcf2.json @@ -7,12 +7,8 @@ "CVE-2000-0749" ], "details": "Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8j88-pc4h-vcrg/GHSA-8j88-pc4h-vcrg.json b/advisories/unreviewed/2022/04/GHSA-8j88-pc4h-vcrg/GHSA-8j88-pc4h-vcrg.json index 216cc76a185..8c67a40a360 100644 --- a/advisories/unreviewed/2022/04/GHSA-8j88-pc4h-vcrg/GHSA-8j88-pc4h-vcrg.json +++ b/advisories/unreviewed/2022/04/GHSA-8j88-pc4h-vcrg/GHSA-8j88-pc4h-vcrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8jfx-95h8-fj8m/GHSA-8jfx-95h8-fj8m.json b/advisories/unreviewed/2022/04/GHSA-8jfx-95h8-fj8m/GHSA-8jfx-95h8-fj8m.json index df66ba2347f..59940b64e94 100644 --- a/advisories/unreviewed/2022/04/GHSA-8jfx-95h8-fj8m/GHSA-8jfx-95h8-fj8m.json +++ b/advisories/unreviewed/2022/04/GHSA-8jfx-95h8-fj8m/GHSA-8jfx-95h8-fj8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8jpc-3pph-f5r4/GHSA-8jpc-3pph-f5r4.json b/advisories/unreviewed/2022/04/GHSA-8jpc-3pph-f5r4/GHSA-8jpc-3pph-f5r4.json index dbdc75af8ba..0d99d8c65a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-8jpc-3pph-f5r4/GHSA-8jpc-3pph-f5r4.json +++ b/advisories/unreviewed/2022/04/GHSA-8jpc-3pph-f5r4/GHSA-8jpc-3pph-f5r4.json @@ -7,12 +7,8 @@ "CVE-2000-0786" ], "details": "GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8jr2-hcch-7696/GHSA-8jr2-hcch-7696.json b/advisories/unreviewed/2022/04/GHSA-8jr2-hcch-7696/GHSA-8jr2-hcch-7696.json index 541bafe8f12..2d7181454cf 100644 --- a/advisories/unreviewed/2022/04/GHSA-8jr2-hcch-7696/GHSA-8jr2-hcch-7696.json +++ b/advisories/unreviewed/2022/04/GHSA-8jr2-hcch-7696/GHSA-8jr2-hcch-7696.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8m55-fv54-pfp6/GHSA-8m55-fv54-pfp6.json b/advisories/unreviewed/2022/04/GHSA-8m55-fv54-pfp6/GHSA-8m55-fv54-pfp6.json index 52f494d5bd4..c2805f2db97 100644 --- a/advisories/unreviewed/2022/04/GHSA-8m55-fv54-pfp6/GHSA-8m55-fv54-pfp6.json +++ b/advisories/unreviewed/2022/04/GHSA-8m55-fv54-pfp6/GHSA-8m55-fv54-pfp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8m5q-4p59-97f5/GHSA-8m5q-4p59-97f5.json b/advisories/unreviewed/2022/04/GHSA-8m5q-4p59-97f5/GHSA-8m5q-4p59-97f5.json index 88b42dc0882..8820c00e861 100644 --- a/advisories/unreviewed/2022/04/GHSA-8m5q-4p59-97f5/GHSA-8m5q-4p59-97f5.json +++ b/advisories/unreviewed/2022/04/GHSA-8m5q-4p59-97f5/GHSA-8m5q-4p59-97f5.json @@ -7,12 +7,8 @@ "CVE-2000-0790" ], "details": "The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8vx4-2p49-2m5m/GHSA-8vx4-2p49-2m5m.json b/advisories/unreviewed/2022/04/GHSA-8vx4-2p49-2m5m/GHSA-8vx4-2p49-2m5m.json index 192afc57603..041adaebc45 100644 --- a/advisories/unreviewed/2022/04/GHSA-8vx4-2p49-2m5m/GHSA-8vx4-2p49-2m5m.json +++ b/advisories/unreviewed/2022/04/GHSA-8vx4-2p49-2m5m/GHSA-8vx4-2p49-2m5m.json @@ -7,12 +7,8 @@ "CVE-2000-0737" ], "details": "The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the \"Service Control Manager Named Pipe Impersonation\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8w62-g849-p4ww/GHSA-8w62-g849-p4ww.json b/advisories/unreviewed/2022/04/GHSA-8w62-g849-p4ww/GHSA-8w62-g849-p4ww.json index abbe07e5359..624bea931b2 100644 --- a/advisories/unreviewed/2022/04/GHSA-8w62-g849-p4ww/GHSA-8w62-g849-p4ww.json +++ b/advisories/unreviewed/2022/04/GHSA-8w62-g849-p4ww/GHSA-8w62-g849-p4ww.json @@ -7,12 +7,8 @@ "CVE-2000-0763" ], "details": "xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8wcg-8pwm-v3gc/GHSA-8wcg-8pwm-v3gc.json b/advisories/unreviewed/2022/04/GHSA-8wcg-8pwm-v3gc/GHSA-8wcg-8pwm-v3gc.json index 0e1e2a03e79..ee8559df3ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-8wcg-8pwm-v3gc/GHSA-8wcg-8pwm-v3gc.json +++ b/advisories/unreviewed/2022/04/GHSA-8wcg-8pwm-v3gc/GHSA-8wcg-8pwm-v3gc.json @@ -7,12 +7,8 @@ "CVE-2000-0770" ], "details": "IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the \"File Permission Canonicalization\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-929f-q38q-qmr6/GHSA-929f-q38q-qmr6.json b/advisories/unreviewed/2022/04/GHSA-929f-q38q-qmr6/GHSA-929f-q38q-qmr6.json index cc8984679b5..c1fabc2703a 100644 --- a/advisories/unreviewed/2022/04/GHSA-929f-q38q-qmr6/GHSA-929f-q38q-qmr6.json +++ b/advisories/unreviewed/2022/04/GHSA-929f-q38q-qmr6/GHSA-929f-q38q-qmr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-93vc-c3w9-g6c9/GHSA-93vc-c3w9-g6c9.json b/advisories/unreviewed/2022/04/GHSA-93vc-c3w9-g6c9/GHSA-93vc-c3w9-g6c9.json index ecc0d85ab35..70b142d9d53 100644 --- a/advisories/unreviewed/2022/04/GHSA-93vc-c3w9-g6c9/GHSA-93vc-c3w9-g6c9.json +++ b/advisories/unreviewed/2022/04/GHSA-93vc-c3w9-g6c9/GHSA-93vc-c3w9-g6c9.json @@ -7,12 +7,8 @@ "CVE-2000-0746" ], "details": "Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the \"IIS Cross-Site Scripting\" vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-94fw-9r5j-jcw8/GHSA-94fw-9r5j-jcw8.json b/advisories/unreviewed/2022/04/GHSA-94fw-9r5j-jcw8/GHSA-94fw-9r5j-jcw8.json index 08e06ab1998..014c4ea24e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-94fw-9r5j-jcw8/GHSA-94fw-9r5j-jcw8.json +++ b/advisories/unreviewed/2022/04/GHSA-94fw-9r5j-jcw8/GHSA-94fw-9r5j-jcw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-96qj-c9wr-w9gx/GHSA-96qj-c9wr-w9gx.json b/advisories/unreviewed/2022/04/GHSA-96qj-c9wr-w9gx/GHSA-96qj-c9wr-w9gx.json index a1b9a43c229..bec6af1ed06 100644 --- a/advisories/unreviewed/2022/04/GHSA-96qj-c9wr-w9gx/GHSA-96qj-c9wr-w9gx.json +++ b/advisories/unreviewed/2022/04/GHSA-96qj-c9wr-w9gx/GHSA-96qj-c9wr-w9gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9f24-x6jp-22h6/GHSA-9f24-x6jp-22h6.json b/advisories/unreviewed/2022/04/GHSA-9f24-x6jp-22h6/GHSA-9f24-x6jp-22h6.json index 25b568354b1..9f7e1c71069 100644 --- a/advisories/unreviewed/2022/04/GHSA-9f24-x6jp-22h6/GHSA-9f24-x6jp-22h6.json +++ b/advisories/unreviewed/2022/04/GHSA-9f24-x6jp-22h6/GHSA-9f24-x6jp-22h6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9j8w-xrww-p6wr/GHSA-9j8w-xrww-p6wr.json b/advisories/unreviewed/2022/04/GHSA-9j8w-xrww-p6wr/GHSA-9j8w-xrww-p6wr.json index 8e45e9d585d..d6d5e87d56f 100644 --- a/advisories/unreviewed/2022/04/GHSA-9j8w-xrww-p6wr/GHSA-9j8w-xrww-p6wr.json +++ b/advisories/unreviewed/2022/04/GHSA-9j8w-xrww-p6wr/GHSA-9j8w-xrww-p6wr.json @@ -7,12 +7,8 @@ "CVE-2000-0683" ], "details": "BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9j8x-rg33-7fqr/GHSA-9j8x-rg33-7fqr.json b/advisories/unreviewed/2022/04/GHSA-9j8x-rg33-7fqr/GHSA-9j8x-rg33-7fqr.json index bbf64d17c50..184acd9557a 100644 --- a/advisories/unreviewed/2022/04/GHSA-9j8x-rg33-7fqr/GHSA-9j8x-rg33-7fqr.json +++ b/advisories/unreviewed/2022/04/GHSA-9j8x-rg33-7fqr/GHSA-9j8x-rg33-7fqr.json @@ -7,12 +7,8 @@ "CVE-2000-0762" ], "details": "The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9jjv-62gr-rmvp/GHSA-9jjv-62gr-rmvp.json b/advisories/unreviewed/2022/04/GHSA-9jjv-62gr-rmvp/GHSA-9jjv-62gr-rmvp.json index 0f39a108ecc..09812623617 100644 --- a/advisories/unreviewed/2022/04/GHSA-9jjv-62gr-rmvp/GHSA-9jjv-62gr-rmvp.json +++ b/advisories/unreviewed/2022/04/GHSA-9jjv-62gr-rmvp/GHSA-9jjv-62gr-rmvp.json @@ -7,12 +7,8 @@ "CVE-2000-0727" ], "details": "xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vw5-3fpc-j23p/GHSA-9vw5-3fpc-j23p.json b/advisories/unreviewed/2022/04/GHSA-9vw5-3fpc-j23p/GHSA-9vw5-3fpc-j23p.json index c91ab0035e5..54cb2fec2e9 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vw5-3fpc-j23p/GHSA-9vw5-3fpc-j23p.json +++ b/advisories/unreviewed/2022/04/GHSA-9vw5-3fpc-j23p/GHSA-9vw5-3fpc-j23p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9wmx-j898-fr8m/GHSA-9wmx-j898-fr8m.json b/advisories/unreviewed/2022/04/GHSA-9wmx-j898-fr8m/GHSA-9wmx-j898-fr8m.json index d4477124faa..3ac01438247 100644 --- a/advisories/unreviewed/2022/04/GHSA-9wmx-j898-fr8m/GHSA-9wmx-j898-fr8m.json +++ b/advisories/unreviewed/2022/04/GHSA-9wmx-j898-fr8m/GHSA-9wmx-j898-fr8m.json @@ -7,12 +7,8 @@ "CVE-2000-0694" ], "details": "pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9wr3-8fv2-9fcj/GHSA-9wr3-8fv2-9fcj.json b/advisories/unreviewed/2022/04/GHSA-9wr3-8fv2-9fcj/GHSA-9wr3-8fv2-9fcj.json index 9c333e9eb2a..a6667c7556b 100644 --- a/advisories/unreviewed/2022/04/GHSA-9wr3-8fv2-9fcj/GHSA-9wr3-8fv2-9fcj.json +++ b/advisories/unreviewed/2022/04/GHSA-9wr3-8fv2-9fcj/GHSA-9wr3-8fv2-9fcj.json @@ -7,12 +7,8 @@ "CVE-2000-0787" ], "details": "IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c47f-j86j-3p94/GHSA-c47f-j86j-3p94.json b/advisories/unreviewed/2022/04/GHSA-c47f-j86j-3p94/GHSA-c47f-j86j-3p94.json index dcdc3df9b47..14efbe8b53c 100644 --- a/advisories/unreviewed/2022/04/GHSA-c47f-j86j-3p94/GHSA-c47f-j86j-3p94.json +++ b/advisories/unreviewed/2022/04/GHSA-c47f-j86j-3p94/GHSA-c47f-j86j-3p94.json @@ -7,12 +7,8 @@ "CVE-2000-0682" ], "details": "BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c6f2-x332-pmpr/GHSA-c6f2-x332-pmpr.json b/advisories/unreviewed/2022/04/GHSA-c6f2-x332-pmpr/GHSA-c6f2-x332-pmpr.json index 8c518be965d..3b4d9cf49b9 100644 --- a/advisories/unreviewed/2022/04/GHSA-c6f2-x332-pmpr/GHSA-c6f2-x332-pmpr.json +++ b/advisories/unreviewed/2022/04/GHSA-c6f2-x332-pmpr/GHSA-c6f2-x332-pmpr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c6v3-42rv-hx7j/GHSA-c6v3-42rv-hx7j.json b/advisories/unreviewed/2022/04/GHSA-c6v3-42rv-hx7j/GHSA-c6v3-42rv-hx7j.json index a04bc3b2aa7..15a1a3e50a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-c6v3-42rv-hx7j/GHSA-c6v3-42rv-hx7j.json +++ b/advisories/unreviewed/2022/04/GHSA-c6v3-42rv-hx7j/GHSA-c6v3-42rv-hx7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cfgx-7qv4-jhxr/GHSA-cfgx-7qv4-jhxr.json b/advisories/unreviewed/2022/04/GHSA-cfgx-7qv4-jhxr/GHSA-cfgx-7qv4-jhxr.json index b9090ed2ca2..48045b9d869 100644 --- a/advisories/unreviewed/2022/04/GHSA-cfgx-7qv4-jhxr/GHSA-cfgx-7qv4-jhxr.json +++ b/advisories/unreviewed/2022/04/GHSA-cfgx-7qv4-jhxr/GHSA-cfgx-7qv4-jhxr.json @@ -7,12 +7,8 @@ "CVE-2000-0750" ], "details": "Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cgw3-wxh9-7v9c/GHSA-cgw3-wxh9-7v9c.json b/advisories/unreviewed/2022/04/GHSA-cgw3-wxh9-7v9c/GHSA-cgw3-wxh9-7v9c.json index 655a0f89728..ba330a79a4d 100644 --- a/advisories/unreviewed/2022/04/GHSA-cgw3-wxh9-7v9c/GHSA-cgw3-wxh9-7v9c.json +++ b/advisories/unreviewed/2022/04/GHSA-cgw3-wxh9-7v9c/GHSA-cgw3-wxh9-7v9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cxwh-v9vc-654w/GHSA-cxwh-v9vc-654w.json b/advisories/unreviewed/2022/04/GHSA-cxwh-v9vc-654w/GHSA-cxwh-v9vc-654w.json index fd1599a72b9..04d1a498a1e 100644 --- a/advisories/unreviewed/2022/04/GHSA-cxwh-v9vc-654w/GHSA-cxwh-v9vc-654w.json +++ b/advisories/unreviewed/2022/04/GHSA-cxwh-v9vc-654w/GHSA-cxwh-v9vc-654w.json @@ -7,12 +7,8 @@ "CVE-2000-0685" ], "details": "BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f3h8-8rx5-4v78/GHSA-f3h8-8rx5-4v78.json b/advisories/unreviewed/2022/04/GHSA-f3h8-8rx5-4v78/GHSA-f3h8-8rx5-4v78.json index aadea95f8f6..f6f5ea993a6 100644 --- a/advisories/unreviewed/2022/04/GHSA-f3h8-8rx5-4v78/GHSA-f3h8-8rx5-4v78.json +++ b/advisories/unreviewed/2022/04/GHSA-f3h8-8rx5-4v78/GHSA-f3h8-8rx5-4v78.json @@ -7,12 +7,8 @@ "CVE-2000-0693" ], "details": "pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the \"cp\" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate \"cp\" program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ffhj-hj7m-wj9r/GHSA-ffhj-hj7m-wj9r.json b/advisories/unreviewed/2022/04/GHSA-ffhj-hj7m-wj9r/GHSA-ffhj-hj7m-wj9r.json index 39bd00306d4..986215488d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-ffhj-hj7m-wj9r/GHSA-ffhj-hj7m-wj9r.json +++ b/advisories/unreviewed/2022/04/GHSA-ffhj-hj7m-wj9r/GHSA-ffhj-hj7m-wj9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-fm7f-2pvq-7cvg/GHSA-fm7f-2pvq-7cvg.json b/advisories/unreviewed/2022/04/GHSA-fm7f-2pvq-7cvg/GHSA-fm7f-2pvq-7cvg.json index 425cd9aa591..45a21c1660b 100644 --- a/advisories/unreviewed/2022/04/GHSA-fm7f-2pvq-7cvg/GHSA-fm7f-2pvq-7cvg.json +++ b/advisories/unreviewed/2022/04/GHSA-fm7f-2pvq-7cvg/GHSA-fm7f-2pvq-7cvg.json @@ -7,12 +7,8 @@ "CVE-2000-0776" ], "details": "Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fq8g-x6c4-fpm3/GHSA-fq8g-x6c4-fpm3.json b/advisories/unreviewed/2022/04/GHSA-fq8g-x6c4-fpm3/GHSA-fq8g-x6c4-fpm3.json index 763a3eab3a7..914657b7d69 100644 --- a/advisories/unreviewed/2022/04/GHSA-fq8g-x6c4-fpm3/GHSA-fq8g-x6c4-fpm3.json +++ b/advisories/unreviewed/2022/04/GHSA-fq8g-x6c4-fpm3/GHSA-fq8g-x6c4-fpm3.json @@ -7,12 +7,8 @@ "CVE-2000-0781" ], "details": "uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fwmf-9cw3-w3x3/GHSA-fwmf-9cw3-w3x3.json b/advisories/unreviewed/2022/04/GHSA-fwmf-9cw3-w3x3/GHSA-fwmf-9cw3-w3x3.json index f5209b3c26a..ae912de87ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwmf-9cw3-w3x3/GHSA-fwmf-9cw3-w3x3.json +++ b/advisories/unreviewed/2022/04/GHSA-fwmf-9cw3-w3x3/GHSA-fwmf-9cw3-w3x3.json @@ -7,12 +7,8 @@ "CVE-2000-0703" ], "details": "suidperl (aka sperl) does not properly cleanse the escape sequence \"~!\" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the \"interactive\" environmental variable and calling suidperl with a filename that contains the escape sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g2cj-p4q5-49m4/GHSA-g2cj-p4q5-49m4.json b/advisories/unreviewed/2022/04/GHSA-g2cj-p4q5-49m4/GHSA-g2cj-p4q5-49m4.json index d003e5a9dd6..9b1fbfd35d0 100644 --- a/advisories/unreviewed/2022/04/GHSA-g2cj-p4q5-49m4/GHSA-g2cj-p4q5-49m4.json +++ b/advisories/unreviewed/2022/04/GHSA-g2cj-p4q5-49m4/GHSA-g2cj-p4q5-49m4.json @@ -7,12 +7,8 @@ "CVE-2000-0794" ], "details": "Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g572-wc44-wvcc/GHSA-g572-wc44-wvcc.json b/advisories/unreviewed/2022/04/GHSA-g572-wc44-wvcc/GHSA-g572-wc44-wvcc.json index 53b28a48fd5..8347e0ebdff 100644 --- a/advisories/unreviewed/2022/04/GHSA-g572-wc44-wvcc/GHSA-g572-wc44-wvcc.json +++ b/advisories/unreviewed/2022/04/GHSA-g572-wc44-wvcc/GHSA-g572-wc44-wvcc.json @@ -7,12 +7,8 @@ "CVE-2000-0692" ], "details": "ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gh4c-fhq7-w2p8/GHSA-gh4c-fhq7-w2p8.json b/advisories/unreviewed/2022/04/GHSA-gh4c-fhq7-w2p8/GHSA-gh4c-fhq7-w2p8.json index 04685a78a44..fb9f410861c 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh4c-fhq7-w2p8/GHSA-gh4c-fhq7-w2p8.json +++ b/advisories/unreviewed/2022/04/GHSA-gh4c-fhq7-w2p8/GHSA-gh4c-fhq7-w2p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gh68-vx3r-mw6g/GHSA-gh68-vx3r-mw6g.json b/advisories/unreviewed/2022/04/GHSA-gh68-vx3r-mw6g/GHSA-gh68-vx3r-mw6g.json index d0473203995..1ad17cde0ad 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh68-vx3r-mw6g/GHSA-gh68-vx3r-mw6g.json +++ b/advisories/unreviewed/2022/04/GHSA-gh68-vx3r-mw6g/GHSA-gh68-vx3r-mw6g.json @@ -7,12 +7,8 @@ "CVE-2000-0715" ], "details": "DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gm87-84c8-m332/GHSA-gm87-84c8-m332.json b/advisories/unreviewed/2022/04/GHSA-gm87-84c8-m332/GHSA-gm87-84c8-m332.json index b7c774dbaf2..aa45181e465 100644 --- a/advisories/unreviewed/2022/04/GHSA-gm87-84c8-m332/GHSA-gm87-84c8-m332.json +++ b/advisories/unreviewed/2022/04/GHSA-gm87-84c8-m332/GHSA-gm87-84c8-m332.json @@ -7,12 +7,8 @@ "CVE-2000-0695" ], "details": "Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gpfp-vw26-wc3m/GHSA-gpfp-vw26-wc3m.json b/advisories/unreviewed/2022/04/GHSA-gpfp-vw26-wc3m/GHSA-gpfp-vw26-wc3m.json index 1b6b398e526..4a728ff748e 100644 --- a/advisories/unreviewed/2022/04/GHSA-gpfp-vw26-wc3m/GHSA-gpfp-vw26-wc3m.json +++ b/advisories/unreviewed/2022/04/GHSA-gpfp-vw26-wc3m/GHSA-gpfp-vw26-wc3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gqh4-5m73-25f6/GHSA-gqh4-5m73-25f6.json b/advisories/unreviewed/2022/04/GHSA-gqh4-5m73-25f6/GHSA-gqh4-5m73-25f6.json index aceb10df896..4ed0ecb2e12 100644 --- a/advisories/unreviewed/2022/04/GHSA-gqh4-5m73-25f6/GHSA-gqh4-5m73-25f6.json +++ b/advisories/unreviewed/2022/04/GHSA-gqh4-5m73-25f6/GHSA-gqh4-5m73-25f6.json @@ -7,12 +7,8 @@ "CVE-2000-0766" ], "details": "Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gv87-4wrx-xhh7/GHSA-gv87-4wrx-xhh7.json b/advisories/unreviewed/2022/04/GHSA-gv87-4wrx-xhh7/GHSA-gv87-4wrx-xhh7.json index 752b4b6be99..7085bc510dc 100644 --- a/advisories/unreviewed/2022/04/GHSA-gv87-4wrx-xhh7/GHSA-gv87-4wrx-xhh7.json +++ b/advisories/unreviewed/2022/04/GHSA-gv87-4wrx-xhh7/GHSA-gv87-4wrx-xhh7.json @@ -7,12 +7,8 @@ "CVE-2000-0722" ], "details": "Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h2p2-h9vg-jvx9/GHSA-h2p2-h9vg-jvx9.json b/advisories/unreviewed/2022/04/GHSA-h2p2-h9vg-jvx9/GHSA-h2p2-h9vg-jvx9.json index f46c488cb89..657a5f20708 100644 --- a/advisories/unreviewed/2022/04/GHSA-h2p2-h9vg-jvx9/GHSA-h2p2-h9vg-jvx9.json +++ b/advisories/unreviewed/2022/04/GHSA-h2p2-h9vg-jvx9/GHSA-h2p2-h9vg-jvx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h349-mgv6-6cmc/GHSA-h349-mgv6-6cmc.json b/advisories/unreviewed/2022/04/GHSA-h349-mgv6-6cmc/GHSA-h349-mgv6-6cmc.json index f8b08a6b74d..f06056a3031 100644 --- a/advisories/unreviewed/2022/04/GHSA-h349-mgv6-6cmc/GHSA-h349-mgv6-6cmc.json +++ b/advisories/unreviewed/2022/04/GHSA-h349-mgv6-6cmc/GHSA-h349-mgv6-6cmc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-h3jq-4749-5xmp/GHSA-h3jq-4749-5xmp.json b/advisories/unreviewed/2022/04/GHSA-h3jq-4749-5xmp/GHSA-h3jq-4749-5xmp.json index 588bf08a123..f5c4907460f 100644 --- a/advisories/unreviewed/2022/04/GHSA-h3jq-4749-5xmp/GHSA-h3jq-4749-5xmp.json +++ b/advisories/unreviewed/2022/04/GHSA-h3jq-4749-5xmp/GHSA-h3jq-4749-5xmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-h535-v6v7-r4q9/GHSA-h535-v6v7-r4q9.json b/advisories/unreviewed/2022/04/GHSA-h535-v6v7-r4q9/GHSA-h535-v6v7-r4q9.json index 568b2faa0b8..585fee6a335 100644 --- a/advisories/unreviewed/2022/04/GHSA-h535-v6v7-r4q9/GHSA-h535-v6v7-r4q9.json +++ b/advisories/unreviewed/2022/04/GHSA-h535-v6v7-r4q9/GHSA-h535-v6v7-r4q9.json @@ -7,12 +7,8 @@ "CVE-2000-0724" ], "details": "The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h59g-2v7c-2x9c/GHSA-h59g-2v7c-2x9c.json b/advisories/unreviewed/2022/04/GHSA-h59g-2v7c-2x9c/GHSA-h59g-2v7c-2x9c.json index b51975ddb3b..6da3d06ef15 100644 --- a/advisories/unreviewed/2022/04/GHSA-h59g-2v7c-2x9c/GHSA-h59g-2v7c-2x9c.json +++ b/advisories/unreviewed/2022/04/GHSA-h59g-2v7c-2x9c/GHSA-h59g-2v7c-2x9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h8h8-j6q6-6c44/GHSA-h8h8-j6q6-6c44.json b/advisories/unreviewed/2022/04/GHSA-h8h8-j6q6-6c44/GHSA-h8h8-j6q6-6c44.json index 30f37dca1da..a20d7f38903 100644 --- a/advisories/unreviewed/2022/04/GHSA-h8h8-j6q6-6c44/GHSA-h8h8-j6q6-6c44.json +++ b/advisories/unreviewed/2022/04/GHSA-h8h8-j6q6-6c44/GHSA-h8h8-j6q6-6c44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-h97q-x4cw-q828/GHSA-h97q-x4cw-q828.json b/advisories/unreviewed/2022/04/GHSA-h97q-x4cw-q828/GHSA-h97q-x4cw-q828.json index b7aff9f393e..a79315a433d 100644 --- a/advisories/unreviewed/2022/04/GHSA-h97q-x4cw-q828/GHSA-h97q-x4cw-q828.json +++ b/advisories/unreviewed/2022/04/GHSA-h97q-x4cw-q828/GHSA-h97q-x4cw-q828.json @@ -7,12 +7,8 @@ "CVE-2000-0719" ], "details": "VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h9pf-v244-3x9w/GHSA-h9pf-v244-3x9w.json b/advisories/unreviewed/2022/04/GHSA-h9pf-v244-3x9w/GHSA-h9pf-v244-3x9w.json index e23c7b179d8..6d467e2baf0 100644 --- a/advisories/unreviewed/2022/04/GHSA-h9pf-v244-3x9w/GHSA-h9pf-v244-3x9w.json +++ b/advisories/unreviewed/2022/04/GHSA-h9pf-v244-3x9w/GHSA-h9pf-v244-3x9w.json @@ -7,12 +7,8 @@ "CVE-2000-0697" ], "details": "The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hg7h-2pr6-wvjf/GHSA-hg7h-2pr6-wvjf.json b/advisories/unreviewed/2022/04/GHSA-hg7h-2pr6-wvjf/GHSA-hg7h-2pr6-wvjf.json index 86a42eb9a85..245d71fdc48 100644 --- a/advisories/unreviewed/2022/04/GHSA-hg7h-2pr6-wvjf/GHSA-hg7h-2pr6-wvjf.json +++ b/advisories/unreviewed/2022/04/GHSA-hg7h-2pr6-wvjf/GHSA-hg7h-2pr6-wvjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hhgh-vxgw-ph3w/GHSA-hhgh-vxgw-ph3w.json b/advisories/unreviewed/2022/04/GHSA-hhgh-vxgw-ph3w/GHSA-hhgh-vxgw-ph3w.json index 55ed0bd9801..81708accbe2 100644 --- a/advisories/unreviewed/2022/04/GHSA-hhgh-vxgw-ph3w/GHSA-hhgh-vxgw-ph3w.json +++ b/advisories/unreviewed/2022/04/GHSA-hhgh-vxgw-ph3w/GHSA-hhgh-vxgw-ph3w.json @@ -7,12 +7,8 @@ "CVE-2000-0689" ], "details": "Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hm4p-5rh2-8894/GHSA-hm4p-5rh2-8894.json b/advisories/unreviewed/2022/04/GHSA-hm4p-5rh2-8894/GHSA-hm4p-5rh2-8894.json index d482d62ac86..7216e2f4b7f 100644 --- a/advisories/unreviewed/2022/04/GHSA-hm4p-5rh2-8894/GHSA-hm4p-5rh2-8894.json +++ b/advisories/unreviewed/2022/04/GHSA-hm4p-5rh2-8894/GHSA-hm4p-5rh2-8894.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hpp2-7wxh-2grj/GHSA-hpp2-7wxh-2grj.json b/advisories/unreviewed/2022/04/GHSA-hpp2-7wxh-2grj/GHSA-hpp2-7wxh-2grj.json index 9c7aa006041..58e50c546b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-hpp2-7wxh-2grj/GHSA-hpp2-7wxh-2grj.json +++ b/advisories/unreviewed/2022/04/GHSA-hpp2-7wxh-2grj/GHSA-hpp2-7wxh-2grj.json @@ -7,12 +7,8 @@ "CVE-2000-0775" ], "details": "Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hrwj-3h8v-xmqx/GHSA-hrwj-3h8v-xmqx.json b/advisories/unreviewed/2022/04/GHSA-hrwj-3h8v-xmqx/GHSA-hrwj-3h8v-xmqx.json index 3358e6a8649..6189f82ff80 100644 --- a/advisories/unreviewed/2022/04/GHSA-hrwj-3h8v-xmqx/GHSA-hrwj-3h8v-xmqx.json +++ b/advisories/unreviewed/2022/04/GHSA-hrwj-3h8v-xmqx/GHSA-hrwj-3h8v-xmqx.json @@ -7,12 +7,8 @@ "CVE-2000-0716" ], "details": "WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hx8c-hfvj-265v/GHSA-hx8c-hfvj-265v.json b/advisories/unreviewed/2022/04/GHSA-hx8c-hfvj-265v/GHSA-hx8c-hfvj-265v.json index cf512437ba9..a68e5df6ddd 100644 --- a/advisories/unreviewed/2022/04/GHSA-hx8c-hfvj-265v/GHSA-hx8c-hfvj-265v.json +++ b/advisories/unreviewed/2022/04/GHSA-hx8c-hfvj-265v/GHSA-hx8c-hfvj-265v.json @@ -7,12 +7,8 @@ "CVE-2000-0779" ], "details": "Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j364-gj4x-7f3p/GHSA-j364-gj4x-7f3p.json b/advisories/unreviewed/2022/04/GHSA-j364-gj4x-7f3p/GHSA-j364-gj4x-7f3p.json index 362e50b8717..d7933005868 100644 --- a/advisories/unreviewed/2022/04/GHSA-j364-gj4x-7f3p/GHSA-j364-gj4x-7f3p.json +++ b/advisories/unreviewed/2022/04/GHSA-j364-gj4x-7f3p/GHSA-j364-gj4x-7f3p.json @@ -7,12 +7,8 @@ "CVE-2000-0732" ], "details": "Worm HTTP server allows remote attackers to cause a denial of service via a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j48w-866x-v5fr/GHSA-j48w-866x-v5fr.json b/advisories/unreviewed/2022/04/GHSA-j48w-866x-v5fr/GHSA-j48w-866x-v5fr.json index 9ca510ff362..3bcec6bd28b 100644 --- a/advisories/unreviewed/2022/04/GHSA-j48w-866x-v5fr/GHSA-j48w-866x-v5fr.json +++ b/advisories/unreviewed/2022/04/GHSA-j48w-866x-v5fr/GHSA-j48w-866x-v5fr.json @@ -7,12 +7,8 @@ "CVE-2000-0730" ], "details": "Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j4f7-q8hr-jwf3/GHSA-j4f7-q8hr-jwf3.json b/advisories/unreviewed/2022/04/GHSA-j4f7-q8hr-jwf3/GHSA-j4f7-q8hr-jwf3.json index 19ce80783f0..36f97025e29 100644 --- a/advisories/unreviewed/2022/04/GHSA-j4f7-q8hr-jwf3/GHSA-j4f7-q8hr-jwf3.json +++ b/advisories/unreviewed/2022/04/GHSA-j4f7-q8hr-jwf3/GHSA-j4f7-q8hr-jwf3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j597-jrh6-3m7m/GHSA-j597-jrh6-3m7m.json b/advisories/unreviewed/2022/04/GHSA-j597-jrh6-3m7m/GHSA-j597-jrh6-3m7m.json index ab91fc6e7bf..e9130c177f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-j597-jrh6-3m7m/GHSA-j597-jrh6-3m7m.json +++ b/advisories/unreviewed/2022/04/GHSA-j597-jrh6-3m7m/GHSA-j597-jrh6-3m7m.json @@ -7,12 +7,8 @@ "CVE-2000-0741" ], "details": "Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j878-9p76-8q9h/GHSA-j878-9p76-8q9h.json b/advisories/unreviewed/2022/04/GHSA-j878-9p76-8q9h/GHSA-j878-9p76-8q9h.json index ce84b1e840f..1a50b6eaf62 100644 --- a/advisories/unreviewed/2022/04/GHSA-j878-9p76-8q9h/GHSA-j878-9p76-8q9h.json +++ b/advisories/unreviewed/2022/04/GHSA-j878-9p76-8q9h/GHSA-j878-9p76-8q9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jghw-mw88-pq53/GHSA-jghw-mw88-pq53.json b/advisories/unreviewed/2022/04/GHSA-jghw-mw88-pq53/GHSA-jghw-mw88-pq53.json index 76c093f5fcb..5f80062bd36 100644 --- a/advisories/unreviewed/2022/04/GHSA-jghw-mw88-pq53/GHSA-jghw-mw88-pq53.json +++ b/advisories/unreviewed/2022/04/GHSA-jghw-mw88-pq53/GHSA-jghw-mw88-pq53.json @@ -7,12 +7,8 @@ "CVE-2000-0686" ], "details": "Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jm4q-r2cm-cjq2/GHSA-jm4q-r2cm-cjq2.json b/advisories/unreviewed/2022/04/GHSA-jm4q-r2cm-cjq2/GHSA-jm4q-r2cm-cjq2.json index e0af7f37e51..4fd2b7b2ef3 100644 --- a/advisories/unreviewed/2022/04/GHSA-jm4q-r2cm-cjq2/GHSA-jm4q-r2cm-cjq2.json +++ b/advisories/unreviewed/2022/04/GHSA-jm4q-r2cm-cjq2/GHSA-jm4q-r2cm-cjq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jmf2-9gpj-6cw4/GHSA-jmf2-9gpj-6cw4.json b/advisories/unreviewed/2022/04/GHSA-jmf2-9gpj-6cw4/GHSA-jmf2-9gpj-6cw4.json index 27513f1613e..05e895a8471 100644 --- a/advisories/unreviewed/2022/04/GHSA-jmf2-9gpj-6cw4/GHSA-jmf2-9gpj-6cw4.json +++ b/advisories/unreviewed/2022/04/GHSA-jmf2-9gpj-6cw4/GHSA-jmf2-9gpj-6cw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jmhc-44vq-xxm4/GHSA-jmhc-44vq-xxm4.json b/advisories/unreviewed/2022/04/GHSA-jmhc-44vq-xxm4/GHSA-jmhc-44vq-xxm4.json index bfd772e02db..4c93be79053 100644 --- a/advisories/unreviewed/2022/04/GHSA-jmhc-44vq-xxm4/GHSA-jmhc-44vq-xxm4.json +++ b/advisories/unreviewed/2022/04/GHSA-jmhc-44vq-xxm4/GHSA-jmhc-44vq-xxm4.json @@ -7,12 +7,8 @@ "CVE-2000-0744" ], "details": "DEPRECATED. This entry has been deprecated. It is a duplicate of CVE-2000-0743.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jw3x-m75w-3629/GHSA-jw3x-m75w-3629.json b/advisories/unreviewed/2022/04/GHSA-jw3x-m75w-3629/GHSA-jw3x-m75w-3629.json index 46a01d04e1c..4a55af2fbbc 100644 --- a/advisories/unreviewed/2022/04/GHSA-jw3x-m75w-3629/GHSA-jw3x-m75w-3629.json +++ b/advisories/unreviewed/2022/04/GHSA-jw3x-m75w-3629/GHSA-jw3x-m75w-3629.json @@ -7,12 +7,8 @@ "CVE-2000-0696" ], "details": "The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jxxq-gmfj-7r8f/GHSA-jxxq-gmfj-7r8f.json b/advisories/unreviewed/2022/04/GHSA-jxxq-gmfj-7r8f/GHSA-jxxq-gmfj-7r8f.json index caf6180469b..07906fdebed 100644 --- a/advisories/unreviewed/2022/04/GHSA-jxxq-gmfj-7r8f/GHSA-jxxq-gmfj-7r8f.json +++ b/advisories/unreviewed/2022/04/GHSA-jxxq-gmfj-7r8f/GHSA-jxxq-gmfj-7r8f.json @@ -7,12 +7,8 @@ "CVE-2000-0734" ], "details": "eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m2xp-5rxh-x3wc/GHSA-m2xp-5rxh-x3wc.json b/advisories/unreviewed/2022/04/GHSA-m2xp-5rxh-x3wc/GHSA-m2xp-5rxh-x3wc.json index bbdf0da3381..88109a269c5 100644 --- a/advisories/unreviewed/2022/04/GHSA-m2xp-5rxh-x3wc/GHSA-m2xp-5rxh-x3wc.json +++ b/advisories/unreviewed/2022/04/GHSA-m2xp-5rxh-x3wc/GHSA-m2xp-5rxh-x3wc.json @@ -7,12 +7,8 @@ "CVE-2000-0707" ], "details": "PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mcmc-pq28-m22x/GHSA-mcmc-pq28-m22x.json b/advisories/unreviewed/2022/04/GHSA-mcmc-pq28-m22x/GHSA-mcmc-pq28-m22x.json index de7ccb67c32..e9ea1dcaf45 100644 --- a/advisories/unreviewed/2022/04/GHSA-mcmc-pq28-m22x/GHSA-mcmc-pq28-m22x.json +++ b/advisories/unreviewed/2022/04/GHSA-mcmc-pq28-m22x/GHSA-mcmc-pq28-m22x.json @@ -7,12 +7,8 @@ "CVE-2000-0768" ], "details": "A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the \"Frame Domain Verification\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mgvj-rwrg-mch6/GHSA-mgvj-rwrg-mch6.json b/advisories/unreviewed/2022/04/GHSA-mgvj-rwrg-mch6/GHSA-mgvj-rwrg-mch6.json index 89e8634f2ad..600f6c99677 100644 --- a/advisories/unreviewed/2022/04/GHSA-mgvj-rwrg-mch6/GHSA-mgvj-rwrg-mch6.json +++ b/advisories/unreviewed/2022/04/GHSA-mgvj-rwrg-mch6/GHSA-mgvj-rwrg-mch6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mj28-hjxw-jmfp/GHSA-mj28-hjxw-jmfp.json b/advisories/unreviewed/2022/04/GHSA-mj28-hjxw-jmfp/GHSA-mj28-hjxw-jmfp.json index fa5b7369af9..7194635c789 100644 --- a/advisories/unreviewed/2022/04/GHSA-mj28-hjxw-jmfp/GHSA-mj28-hjxw-jmfp.json +++ b/advisories/unreviewed/2022/04/GHSA-mj28-hjxw-jmfp/GHSA-mj28-hjxw-jmfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mjjf-5gp4-m9fg/GHSA-mjjf-5gp4-m9fg.json b/advisories/unreviewed/2022/04/GHSA-mjjf-5gp4-m9fg/GHSA-mjjf-5gp4-m9fg.json index 55fe2c62cc2..7b3e02a1cd4 100644 --- a/advisories/unreviewed/2022/04/GHSA-mjjf-5gp4-m9fg/GHSA-mjjf-5gp4-m9fg.json +++ b/advisories/unreviewed/2022/04/GHSA-mjjf-5gp4-m9fg/GHSA-mjjf-5gp4-m9fg.json @@ -7,12 +7,8 @@ "CVE-2000-0745" ], "details": "admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mrqh-xmc6-c5gm/GHSA-mrqh-xmc6-c5gm.json b/advisories/unreviewed/2022/04/GHSA-mrqh-xmc6-c5gm/GHSA-mrqh-xmc6-c5gm.json index 8b66e4170db..8f09a128c41 100644 --- a/advisories/unreviewed/2022/04/GHSA-mrqh-xmc6-c5gm/GHSA-mrqh-xmc6-c5gm.json +++ b/advisories/unreviewed/2022/04/GHSA-mrqh-xmc6-c5gm/GHSA-mrqh-xmc6-c5gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mxx4-32g7-frv8/GHSA-mxx4-32g7-frv8.json b/advisories/unreviewed/2022/04/GHSA-mxx4-32g7-frv8/GHSA-mxx4-32g7-frv8.json index d1a7169c39a..c4b14b0053e 100644 --- a/advisories/unreviewed/2022/04/GHSA-mxx4-32g7-frv8/GHSA-mxx4-32g7-frv8.json +++ b/advisories/unreviewed/2022/04/GHSA-mxx4-32g7-frv8/GHSA-mxx4-32g7-frv8.json @@ -7,12 +7,8 @@ "CVE-2000-0780" ], "details": "The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p2jx-rwxh-4rq2/GHSA-p2jx-rwxh-4rq2.json b/advisories/unreviewed/2022/04/GHSA-p2jx-rwxh-4rq2/GHSA-p2jx-rwxh-4rq2.json index 53ab318b0d5..eab888ce0c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-p2jx-rwxh-4rq2/GHSA-p2jx-rwxh-4rq2.json +++ b/advisories/unreviewed/2022/04/GHSA-p2jx-rwxh-4rq2/GHSA-p2jx-rwxh-4rq2.json @@ -7,12 +7,8 @@ "CVE-2000-0769" ], "details": "O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p39c-3779-23qg/GHSA-p39c-3779-23qg.json b/advisories/unreviewed/2022/04/GHSA-p39c-3779-23qg/GHSA-p39c-3779-23qg.json index 996f01fe006..fd77d474199 100644 --- a/advisories/unreviewed/2022/04/GHSA-p39c-3779-23qg/GHSA-p39c-3779-23qg.json +++ b/advisories/unreviewed/2022/04/GHSA-p39c-3779-23qg/GHSA-p39c-3779-23qg.json @@ -7,12 +7,8 @@ "CVE-2000-0773" ], "details": "Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a \"....\", a variant of the dot dot directory traversal attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p4vv-m3jf-xfp4/GHSA-p4vv-m3jf-xfp4.json b/advisories/unreviewed/2022/04/GHSA-p4vv-m3jf-xfp4/GHSA-p4vv-m3jf-xfp4.json index 5c20640a9d0..e1d2007c532 100644 --- a/advisories/unreviewed/2022/04/GHSA-p4vv-m3jf-xfp4/GHSA-p4vv-m3jf-xfp4.json +++ b/advisories/unreviewed/2022/04/GHSA-p4vv-m3jf-xfp4/GHSA-p4vv-m3jf-xfp4.json @@ -7,12 +7,8 @@ "CVE-2000-0718" ], "details": "A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p7c9-q84g-w8qj/GHSA-p7c9-q84g-w8qj.json b/advisories/unreviewed/2022/04/GHSA-p7c9-q84g-w8qj/GHSA-p7c9-q84g-w8qj.json index 05430d490b7..64fab20a489 100644 --- a/advisories/unreviewed/2022/04/GHSA-p7c9-q84g-w8qj/GHSA-p7c9-q84g-w8qj.json +++ b/advisories/unreviewed/2022/04/GHSA-p7c9-q84g-w8qj/GHSA-p7c9-q84g-w8qj.json @@ -7,12 +7,8 @@ "CVE-2000-0705" ], "details": "ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ph7q-8jfj-8h3x/GHSA-ph7q-8jfj-8h3x.json b/advisories/unreviewed/2022/04/GHSA-ph7q-8jfj-8h3x/GHSA-ph7q-8jfj-8h3x.json index e8825a1ab68..dff3e6a3873 100644 --- a/advisories/unreviewed/2022/04/GHSA-ph7q-8jfj-8h3x/GHSA-ph7q-8jfj-8h3x.json +++ b/advisories/unreviewed/2022/04/GHSA-ph7q-8jfj-8h3x/GHSA-ph7q-8jfj-8h3x.json @@ -7,12 +7,8 @@ "CVE-2000-0772" ], "details": "The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account \"sa\" with no password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pqf9-f88f-jphj/GHSA-pqf9-f88f-jphj.json b/advisories/unreviewed/2022/04/GHSA-pqf9-f88f-jphj/GHSA-pqf9-f88f-jphj.json index de463a42ddf..796ff79ada4 100644 --- a/advisories/unreviewed/2022/04/GHSA-pqf9-f88f-jphj/GHSA-pqf9-f88f-jphj.json +++ b/advisories/unreviewed/2022/04/GHSA-pqf9-f88f-jphj/GHSA-pqf9-f88f-jphj.json @@ -7,12 +7,8 @@ "CVE-2000-0687" ], "details": "Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q2wc-9mx8-xr8j/GHSA-q2wc-9mx8-xr8j.json b/advisories/unreviewed/2022/04/GHSA-q2wc-9mx8-xr8j/GHSA-q2wc-9mx8-xr8j.json index a9f0269d9fd..00e70ab60d8 100644 --- a/advisories/unreviewed/2022/04/GHSA-q2wc-9mx8-xr8j/GHSA-q2wc-9mx8-xr8j.json +++ b/advisories/unreviewed/2022/04/GHSA-q2wc-9mx8-xr8j/GHSA-q2wc-9mx8-xr8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q452-qm69-w9xq/GHSA-q452-qm69-w9xq.json b/advisories/unreviewed/2022/04/GHSA-q452-qm69-w9xq/GHSA-q452-qm69-w9xq.json index 2160ddb3889..dac2f082442 100644 --- a/advisories/unreviewed/2022/04/GHSA-q452-qm69-w9xq/GHSA-q452-qm69-w9xq.json +++ b/advisories/unreviewed/2022/04/GHSA-q452-qm69-w9xq/GHSA-q452-qm69-w9xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q4ww-p595-37cj/GHSA-q4ww-p595-37cj.json b/advisories/unreviewed/2022/04/GHSA-q4ww-p595-37cj/GHSA-q4ww-p595-37cj.json index 3070830829d..8529f9cb4f8 100644 --- a/advisories/unreviewed/2022/04/GHSA-q4ww-p595-37cj/GHSA-q4ww-p595-37cj.json +++ b/advisories/unreviewed/2022/04/GHSA-q4ww-p595-37cj/GHSA-q4ww-p595-37cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q7m3-c8fc-p3xq/GHSA-q7m3-c8fc-p3xq.json b/advisories/unreviewed/2022/04/GHSA-q7m3-c8fc-p3xq/GHSA-q7m3-c8fc-p3xq.json index 2660c1c8b0a..8ab66cad22a 100644 --- a/advisories/unreviewed/2022/04/GHSA-q7m3-c8fc-p3xq/GHSA-q7m3-c8fc-p3xq.json +++ b/advisories/unreviewed/2022/04/GHSA-q7m3-c8fc-p3xq/GHSA-q7m3-c8fc-p3xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q7x5-x7rr-2859/GHSA-q7x5-x7rr-2859.json b/advisories/unreviewed/2022/04/GHSA-q7x5-x7rr-2859/GHSA-q7x5-x7rr-2859.json index d29cef37c63..9b745576457 100644 --- a/advisories/unreviewed/2022/04/GHSA-q7x5-x7rr-2859/GHSA-q7x5-x7rr-2859.json +++ b/advisories/unreviewed/2022/04/GHSA-q7x5-x7rr-2859/GHSA-q7x5-x7rr-2859.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q8wc-pw9v-8w8r/GHSA-q8wc-pw9v-8w8r.json b/advisories/unreviewed/2022/04/GHSA-q8wc-pw9v-8w8r/GHSA-q8wc-pw9v-8w8r.json index 90f82210a79..63668dda7e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-q8wc-pw9v-8w8r/GHSA-q8wc-pw9v-8w8r.json +++ b/advisories/unreviewed/2022/04/GHSA-q8wc-pw9v-8w8r/GHSA-q8wc-pw9v-8w8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qm9r-wvg3-383h/GHSA-qm9r-wvg3-383h.json b/advisories/unreviewed/2022/04/GHSA-qm9r-wvg3-383h/GHSA-qm9r-wvg3-383h.json index b03eb991032..27c88dc24b2 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm9r-wvg3-383h/GHSA-qm9r-wvg3-383h.json +++ b/advisories/unreviewed/2022/04/GHSA-qm9r-wvg3-383h/GHSA-qm9r-wvg3-383h.json @@ -7,12 +7,8 @@ "CVE-2000-0684" ], "details": "BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qq57-jfgr-8wj6/GHSA-qq57-jfgr-8wj6.json b/advisories/unreviewed/2022/04/GHSA-qq57-jfgr-8wj6/GHSA-qq57-jfgr-8wj6.json index fef83906093..6d130c6756e 100644 --- a/advisories/unreviewed/2022/04/GHSA-qq57-jfgr-8wj6/GHSA-qq57-jfgr-8wj6.json +++ b/advisories/unreviewed/2022/04/GHSA-qq57-jfgr-8wj6/GHSA-qq57-jfgr-8wj6.json @@ -7,12 +7,8 @@ "CVE-2000-0743" ], "details": "Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qqg3-vq27-3xvx/GHSA-qqg3-vq27-3xvx.json b/advisories/unreviewed/2022/04/GHSA-qqg3-vq27-3xvx/GHSA-qqg3-vq27-3xvx.json index 1255ebfc93e..171429b34f5 100644 --- a/advisories/unreviewed/2022/04/GHSA-qqg3-vq27-3xvx/GHSA-qqg3-vq27-3xvx.json +++ b/advisories/unreviewed/2022/04/GHSA-qqg3-vq27-3xvx/GHSA-qqg3-vq27-3xvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qqr5-q566-72w2/GHSA-qqr5-q566-72w2.json b/advisories/unreviewed/2022/04/GHSA-qqr5-q566-72w2/GHSA-qqr5-q566-72w2.json index 3083e55ad77..efdd421a6f1 100644 --- a/advisories/unreviewed/2022/04/GHSA-qqr5-q566-72w2/GHSA-qqr5-q566-72w2.json +++ b/advisories/unreviewed/2022/04/GHSA-qqr5-q566-72w2/GHSA-qqr5-q566-72w2.json @@ -7,12 +7,8 @@ "CVE-2000-0760" ], "details": "The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qw86-p44c-xfpr/GHSA-qw86-p44c-xfpr.json b/advisories/unreviewed/2022/04/GHSA-qw86-p44c-xfpr/GHSA-qw86-p44c-xfpr.json index 9da2862569b..dded68d0cbd 100644 --- a/advisories/unreviewed/2022/04/GHSA-qw86-p44c-xfpr/GHSA-qw86-p44c-xfpr.json +++ b/advisories/unreviewed/2022/04/GHSA-qw86-p44c-xfpr/GHSA-qw86-p44c-xfpr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qxh4-gwjr-r2m4/GHSA-qxh4-gwjr-r2m4.json b/advisories/unreviewed/2022/04/GHSA-qxh4-gwjr-r2m4/GHSA-qxh4-gwjr-r2m4.json index 83694c35922..6d78e1d6e17 100644 --- a/advisories/unreviewed/2022/04/GHSA-qxh4-gwjr-r2m4/GHSA-qxh4-gwjr-r2m4.json +++ b/advisories/unreviewed/2022/04/GHSA-qxh4-gwjr-r2m4/GHSA-qxh4-gwjr-r2m4.json @@ -7,12 +7,8 @@ "CVE-2000-0709" ], "details": "The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r458-gcmr-cw5r/GHSA-r458-gcmr-cw5r.json b/advisories/unreviewed/2022/04/GHSA-r458-gcmr-cw5r/GHSA-r458-gcmr-cw5r.json index 00519583888..d1662dbebb2 100644 --- a/advisories/unreviewed/2022/04/GHSA-r458-gcmr-cw5r/GHSA-r458-gcmr-cw5r.json +++ b/advisories/unreviewed/2022/04/GHSA-r458-gcmr-cw5r/GHSA-r458-gcmr-cw5r.json @@ -7,12 +7,8 @@ "CVE-2000-0748" ], "details": "OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r523-qv88-gm52/GHSA-r523-qv88-gm52.json b/advisories/unreviewed/2022/04/GHSA-r523-qv88-gm52/GHSA-r523-qv88-gm52.json index 40737178a70..263c5deade7 100644 --- a/advisories/unreviewed/2022/04/GHSA-r523-qv88-gm52/GHSA-r523-qv88-gm52.json +++ b/advisories/unreviewed/2022/04/GHSA-r523-qv88-gm52/GHSA-r523-qv88-gm52.json @@ -7,12 +7,8 @@ "CVE-2000-0739" ], "details": "Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r666-gxw4-v6gf/GHSA-r666-gxw4-v6gf.json b/advisories/unreviewed/2022/04/GHSA-r666-gxw4-v6gf/GHSA-r666-gxw4-v6gf.json index f63ed45c267..7c247e41461 100644 --- a/advisories/unreviewed/2022/04/GHSA-r666-gxw4-v6gf/GHSA-r666-gxw4-v6gf.json +++ b/advisories/unreviewed/2022/04/GHSA-r666-gxw4-v6gf/GHSA-r666-gxw4-v6gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rfrp-w4hm-99fx/GHSA-rfrp-w4hm-99fx.json b/advisories/unreviewed/2022/04/GHSA-rfrp-w4hm-99fx/GHSA-rfrp-w4hm-99fx.json index 9116de75703..c14f0fc33bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-rfrp-w4hm-99fx/GHSA-rfrp-w4hm-99fx.json +++ b/advisories/unreviewed/2022/04/GHSA-rfrp-w4hm-99fx/GHSA-rfrp-w4hm-99fx.json @@ -7,12 +7,8 @@ "CVE-2000-0774" ], "details": "The sample Java servlet \"test\" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rgwr-fg6p-5whf/GHSA-rgwr-fg6p-5whf.json b/advisories/unreviewed/2022/04/GHSA-rgwr-fg6p-5whf/GHSA-rgwr-fg6p-5whf.json index 04859b2f49e..c72de6fe810 100644 --- a/advisories/unreviewed/2022/04/GHSA-rgwr-fg6p-5whf/GHSA-rgwr-fg6p-5whf.json +++ b/advisories/unreviewed/2022/04/GHSA-rgwr-fg6p-5whf/GHSA-rgwr-fg6p-5whf.json @@ -7,12 +7,8 @@ "CVE-2000-0699" ], "details": "Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rqm2-qh4g-xjjg/GHSA-rqm2-qh4g-xjjg.json b/advisories/unreviewed/2022/04/GHSA-rqm2-qh4g-xjjg/GHSA-rqm2-qh4g-xjjg.json index 258359005d9..2910a97c88d 100644 --- a/advisories/unreviewed/2022/04/GHSA-rqm2-qh4g-xjjg/GHSA-rqm2-qh4g-xjjg.json +++ b/advisories/unreviewed/2022/04/GHSA-rqm2-qh4g-xjjg/GHSA-rqm2-qh4g-xjjg.json @@ -7,12 +7,8 @@ "CVE-2000-0765" ], "details": "Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the \"Microsoft Office HTML Object Tag\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rrcq-rghp-hjgx/GHSA-rrcq-rghp-hjgx.json b/advisories/unreviewed/2022/04/GHSA-rrcq-rghp-hjgx/GHSA-rrcq-rghp-hjgx.json index aeea85577b2..29415dd3edb 100644 --- a/advisories/unreviewed/2022/04/GHSA-rrcq-rghp-hjgx/GHSA-rrcq-rghp-hjgx.json +++ b/advisories/unreviewed/2022/04/GHSA-rrcq-rghp-hjgx/GHSA-rrcq-rghp-hjgx.json @@ -7,12 +7,8 @@ "CVE-2000-0752" ], "details": "Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rrx6-pgjg-pmv7/GHSA-rrx6-pgjg-pmv7.json b/advisories/unreviewed/2022/04/GHSA-rrx6-pgjg-pmv7/GHSA-rrx6-pgjg-pmv7.json index 00899267832..1c19bd13791 100644 --- a/advisories/unreviewed/2022/04/GHSA-rrx6-pgjg-pmv7/GHSA-rrx6-pgjg-pmv7.json +++ b/advisories/unreviewed/2022/04/GHSA-rrx6-pgjg-pmv7/GHSA-rrx6-pgjg-pmv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v5m5-87cx-vqf2/GHSA-v5m5-87cx-vqf2.json b/advisories/unreviewed/2022/04/GHSA-v5m5-87cx-vqf2/GHSA-v5m5-87cx-vqf2.json index 95c8a17846b..31cc7902eb0 100644 --- a/advisories/unreviewed/2022/04/GHSA-v5m5-87cx-vqf2/GHSA-v5m5-87cx-vqf2.json +++ b/advisories/unreviewed/2022/04/GHSA-v5m5-87cx-vqf2/GHSA-v5m5-87cx-vqf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v7r2-f6jx-59j6/GHSA-v7r2-f6jx-59j6.json b/advisories/unreviewed/2022/04/GHSA-v7r2-f6jx-59j6/GHSA-v7r2-f6jx-59j6.json index c762f9f22e0..136da419f16 100644 --- a/advisories/unreviewed/2022/04/GHSA-v7r2-f6jx-59j6/GHSA-v7r2-f6jx-59j6.json +++ b/advisories/unreviewed/2022/04/GHSA-v7r2-f6jx-59j6/GHSA-v7r2-f6jx-59j6.json @@ -7,12 +7,8 @@ "CVE-2000-0700" ], "details": "Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vfmq-w45j-w9m6/GHSA-vfmq-w45j-w9m6.json b/advisories/unreviewed/2022/04/GHSA-vfmq-w45j-w9m6/GHSA-vfmq-w45j-w9m6.json index 3c333c3b8fb..a1f030bbf7e 100644 --- a/advisories/unreviewed/2022/04/GHSA-vfmq-w45j-w9m6/GHSA-vfmq-w45j-w9m6.json +++ b/advisories/unreviewed/2022/04/GHSA-vfmq-w45j-w9m6/GHSA-vfmq-w45j-w9m6.json @@ -7,12 +7,8 @@ "CVE-2000-0758" ], "details": "The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vjr9-xh2p-7wpp/GHSA-vjr9-xh2p-7wpp.json b/advisories/unreviewed/2022/04/GHSA-vjr9-xh2p-7wpp/GHSA-vjr9-xh2p-7wpp.json index 72ea47bd3ff..36d730fcaf3 100644 --- a/advisories/unreviewed/2022/04/GHSA-vjr9-xh2p-7wpp/GHSA-vjr9-xh2p-7wpp.json +++ b/advisories/unreviewed/2022/04/GHSA-vjr9-xh2p-7wpp/GHSA-vjr9-xh2p-7wpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vr3h-889p-pwx2/GHSA-vr3h-889p-pwx2.json b/advisories/unreviewed/2022/04/GHSA-vr3h-889p-pwx2/GHSA-vr3h-889p-pwx2.json index b5a110ea9cc..4f80261f78c 100644 --- a/advisories/unreviewed/2022/04/GHSA-vr3h-889p-pwx2/GHSA-vr3h-889p-pwx2.json +++ b/advisories/unreviewed/2022/04/GHSA-vr3h-889p-pwx2/GHSA-vr3h-889p-pwx2.json @@ -7,12 +7,8 @@ "CVE-2000-0714" ], "details": "umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vr7c-vmw2-482c/GHSA-vr7c-vmw2-482c.json b/advisories/unreviewed/2022/04/GHSA-vr7c-vmw2-482c/GHSA-vr7c-vmw2-482c.json index 39e69cdd50d..c29499fbc3e 100644 --- a/advisories/unreviewed/2022/04/GHSA-vr7c-vmw2-482c/GHSA-vr7c-vmw2-482c.json +++ b/advisories/unreviewed/2022/04/GHSA-vr7c-vmw2-482c/GHSA-vr7c-vmw2-482c.json @@ -7,12 +7,8 @@ "CVE-2000-0720" ], "details": "news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vwr7-jw8x-3pcx/GHSA-vwr7-jw8x-3pcx.json b/advisories/unreviewed/2022/04/GHSA-vwr7-jw8x-3pcx/GHSA-vwr7-jw8x-3pcx.json index a035a35b916..0d3f68c8591 100644 --- a/advisories/unreviewed/2022/04/GHSA-vwr7-jw8x-3pcx/GHSA-vwr7-jw8x-3pcx.json +++ b/advisories/unreviewed/2022/04/GHSA-vwr7-jw8x-3pcx/GHSA-vwr7-jw8x-3pcx.json @@ -7,12 +7,8 @@ "CVE-2000-0782" ], "details": "netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vxcx-7p8x-jr3r/GHSA-vxcx-7p8x-jr3r.json b/advisories/unreviewed/2022/04/GHSA-vxcx-7p8x-jr3r/GHSA-vxcx-7p8x-jr3r.json index 62e9168880d..33545b240e8 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxcx-7p8x-jr3r/GHSA-vxcx-7p8x-jr3r.json +++ b/advisories/unreviewed/2022/04/GHSA-vxcx-7p8x-jr3r/GHSA-vxcx-7p8x-jr3r.json @@ -7,12 +7,8 @@ "CVE-2000-0712" ], "details": "Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w892-7g74-x2wg/GHSA-w892-7g74-x2wg.json b/advisories/unreviewed/2022/04/GHSA-w892-7g74-x2wg/GHSA-w892-7g74-x2wg.json index c3ac8211118..055d02f3a87 100644 --- a/advisories/unreviewed/2022/04/GHSA-w892-7g74-x2wg/GHSA-w892-7g74-x2wg.json +++ b/advisories/unreviewed/2022/04/GHSA-w892-7g74-x2wg/GHSA-w892-7g74-x2wg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wjpc-9hpw-c7p9/GHSA-wjpc-9hpw-c7p9.json b/advisories/unreviewed/2022/04/GHSA-wjpc-9hpw-c7p9/GHSA-wjpc-9hpw-c7p9.json index 2b1c1be3579..cbe2541bdb6 100644 --- a/advisories/unreviewed/2022/04/GHSA-wjpc-9hpw-c7p9/GHSA-wjpc-9hpw-c7p9.json +++ b/advisories/unreviewed/2022/04/GHSA-wjpc-9hpw-c7p9/GHSA-wjpc-9hpw-c7p9.json @@ -7,12 +7,8 @@ "CVE-2000-0742" ], "details": "The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the \"Malformed IPX Ping Packet\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wpg3-r2mr-mv9m/GHSA-wpg3-r2mr-mv9m.json b/advisories/unreviewed/2022/04/GHSA-wpg3-r2mr-mv9m/GHSA-wpg3-r2mr-mv9m.json index 056ad2921e7..fb78b987134 100644 --- a/advisories/unreviewed/2022/04/GHSA-wpg3-r2mr-mv9m/GHSA-wpg3-r2mr-mv9m.json +++ b/advisories/unreviewed/2022/04/GHSA-wpg3-r2mr-mv9m/GHSA-wpg3-r2mr-mv9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wph5-jqqm-rqpf/GHSA-wph5-jqqm-rqpf.json b/advisories/unreviewed/2022/04/GHSA-wph5-jqqm-rqpf/GHSA-wph5-jqqm-rqpf.json index 973566884b2..d0d00ded7cc 100644 --- a/advisories/unreviewed/2022/04/GHSA-wph5-jqqm-rqpf/GHSA-wph5-jqqm-rqpf.json +++ b/advisories/unreviewed/2022/04/GHSA-wph5-jqqm-rqpf/GHSA-wph5-jqqm-rqpf.json @@ -7,12 +7,8 @@ "CVE-2000-0803" ], "details": "GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wq6x-r2mj-jc4m/GHSA-wq6x-r2mj-jc4m.json b/advisories/unreviewed/2022/04/GHSA-wq6x-r2mj-jc4m/GHSA-wq6x-r2mj-jc4m.json index d21d4c65606..c5f860c7f62 100644 --- a/advisories/unreviewed/2022/04/GHSA-wq6x-r2mj-jc4m/GHSA-wq6x-r2mj-jc4m.json +++ b/advisories/unreviewed/2022/04/GHSA-wq6x-r2mj-jc4m/GHSA-wq6x-r2mj-jc4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wrcj-gm3v-fgv6/GHSA-wrcj-gm3v-fgv6.json b/advisories/unreviewed/2022/04/GHSA-wrcj-gm3v-fgv6/GHSA-wrcj-gm3v-fgv6.json index 898cc8a0082..2142347a40a 100644 --- a/advisories/unreviewed/2022/04/GHSA-wrcj-gm3v-fgv6/GHSA-wrcj-gm3v-fgv6.json +++ b/advisories/unreviewed/2022/04/GHSA-wrcj-gm3v-fgv6/GHSA-wrcj-gm3v-fgv6.json @@ -7,12 +7,8 @@ "CVE-2000-0755" ], "details": "Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wvg7-5q5w-jh2m/GHSA-wvg7-5q5w-jh2m.json b/advisories/unreviewed/2022/04/GHSA-wvg7-5q5w-jh2m/GHSA-wvg7-5q5w-jh2m.json index aba7551cbf0..9b10b6e75b7 100644 --- a/advisories/unreviewed/2022/04/GHSA-wvg7-5q5w-jh2m/GHSA-wvg7-5q5w-jh2m.json +++ b/advisories/unreviewed/2022/04/GHSA-wvg7-5q5w-jh2m/GHSA-wvg7-5q5w-jh2m.json @@ -7,12 +7,8 @@ "CVE-2000-0747" ], "details": "The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ww6p-x9mv-7hjc/GHSA-ww6p-x9mv-7hjc.json b/advisories/unreviewed/2022/04/GHSA-ww6p-x9mv-7hjc/GHSA-ww6p-x9mv-7hjc.json index 13f5e455e56..76c202d5de4 100644 --- a/advisories/unreviewed/2022/04/GHSA-ww6p-x9mv-7hjc/GHSA-ww6p-x9mv-7hjc.json +++ b/advisories/unreviewed/2022/04/GHSA-ww6p-x9mv-7hjc/GHSA-ww6p-x9mv-7hjc.json @@ -7,12 +7,8 @@ "CVE-2000-0711" ], "details": "Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4qg-m523-2cjh/GHSA-x4qg-m523-2cjh.json b/advisories/unreviewed/2022/04/GHSA-x4qg-m523-2cjh/GHSA-x4qg-m523-2cjh.json index 7a56712872d..f6d297964bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4qg-m523-2cjh/GHSA-x4qg-m523-2cjh.json +++ b/advisories/unreviewed/2022/04/GHSA-x4qg-m523-2cjh/GHSA-x4qg-m523-2cjh.json @@ -7,12 +7,8 @@ "CVE-2000-0784" ], "details": "sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded \"rsadmin\" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x7q8-c93w-mjgm/GHSA-x7q8-c93w-mjgm.json b/advisories/unreviewed/2022/04/GHSA-x7q8-c93w-mjgm/GHSA-x7q8-c93w-mjgm.json index 2581a97f2f7..7e9f2ce6a6c 100644 --- a/advisories/unreviewed/2022/04/GHSA-x7q8-c93w-mjgm/GHSA-x7q8-c93w-mjgm.json +++ b/advisories/unreviewed/2022/04/GHSA-x7q8-c93w-mjgm/GHSA-x7q8-c93w-mjgm.json @@ -7,12 +7,8 @@ "CVE-2000-0688" ], "details": "Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xcm3-73w3-h54h/GHSA-xcm3-73w3-h54h.json b/advisories/unreviewed/2022/04/GHSA-xcm3-73w3-h54h/GHSA-xcm3-73w3-h54h.json index 2253c8beb4d..ef816a8ffbd 100644 --- a/advisories/unreviewed/2022/04/GHSA-xcm3-73w3-h54h/GHSA-xcm3-73w3-h54h.json +++ b/advisories/unreviewed/2022/04/GHSA-xcm3-73w3-h54h/GHSA-xcm3-73w3-h54h.json @@ -7,12 +7,8 @@ "CVE-2000-0731" ], "details": "Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xfvx-h8x3-2vxx/GHSA-xfvx-h8x3-2vxx.json b/advisories/unreviewed/2022/04/GHSA-xfvx-h8x3-2vxx/GHSA-xfvx-h8x3-2vxx.json index a89c6fb1aee..1d8e571bd06 100644 --- a/advisories/unreviewed/2022/04/GHSA-xfvx-h8x3-2vxx/GHSA-xfvx-h8x3-2vxx.json +++ b/advisories/unreviewed/2022/04/GHSA-xfvx-h8x3-2vxx/GHSA-xfvx-h8x3-2vxx.json @@ -7,12 +7,8 @@ "CVE-2000-0723" ], "details": "Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xqwv-q7pr-7f9f/GHSA-xqwv-q7pr-7f9f.json b/advisories/unreviewed/2022/04/GHSA-xqwv-q7pr-7f9f/GHSA-xqwv-q7pr-7f9f.json index 5c3b4f0e320..fb29cde6f5a 100644 --- a/advisories/unreviewed/2022/04/GHSA-xqwv-q7pr-7f9f/GHSA-xqwv-q7pr-7f9f.json +++ b/advisories/unreviewed/2022/04/GHSA-xqwv-q7pr-7f9f/GHSA-xqwv-q7pr-7f9f.json @@ -7,12 +7,8 @@ "CVE-2000-0754" ], "details": "Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xvg2-gfxv-qc4c/GHSA-xvg2-gfxv-qc4c.json b/advisories/unreviewed/2022/04/GHSA-xvg2-gfxv-qc4c/GHSA-xvg2-gfxv-qc4c.json index 6ede0e3c9e7..fab4725cc35 100644 --- a/advisories/unreviewed/2022/04/GHSA-xvg2-gfxv-qc4c/GHSA-xvg2-gfxv-qc4c.json +++ b/advisories/unreviewed/2022/04/GHSA-xvg2-gfxv-qc4c/GHSA-xvg2-gfxv-qc4c.json @@ -7,12 +7,8 @@ "CVE-2000-0679" ], "details": "The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xvx7-78wp-jmp4/GHSA-xvx7-78wp-jmp4.json b/advisories/unreviewed/2022/04/GHSA-xvx7-78wp-jmp4/GHSA-xvx7-78wp-jmp4.json index f301670045e..952ff2ae152 100644 --- a/advisories/unreviewed/2022/04/GHSA-xvx7-78wp-jmp4/GHSA-xvx7-78wp-jmp4.json +++ b/advisories/unreviewed/2022/04/GHSA-xvx7-78wp-jmp4/GHSA-xvx7-78wp-jmp4.json @@ -7,12 +7,8 @@ "CVE-2000-0802" ], "details": "The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xxmv-v72m-r6w4/GHSA-xxmv-v72m-r6w4.json b/advisories/unreviewed/2022/04/GHSA-xxmv-v72m-r6w4/GHSA-xxmv-v72m-r6w4.json index 7b5bc0390ad..b33a85d1097 100644 --- a/advisories/unreviewed/2022/04/GHSA-xxmv-v72m-r6w4/GHSA-xxmv-v72m-r6w4.json +++ b/advisories/unreviewed/2022/04/GHSA-xxmv-v72m-r6w4/GHSA-xxmv-v72m-r6w4.json @@ -7,12 +7,8 @@ "CVE-2000-0757" ], "details": "The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23w9-jw3m-h5hj/GHSA-23w9-jw3m-h5hj.json b/advisories/unreviewed/2022/05/GHSA-23w9-jw3m-h5hj/GHSA-23w9-jw3m-h5hj.json index b072822bc90..7fa35221322 100644 --- a/advisories/unreviewed/2022/05/GHSA-23w9-jw3m-h5hj/GHSA-23w9-jw3m-h5hj.json +++ b/advisories/unreviewed/2022/05/GHSA-23w9-jw3m-h5hj/GHSA-23w9-jw3m-h5hj.json @@ -7,12 +7,8 @@ "CVE-2020-36171" ], "details": "The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23x8-m9wv-h49m/GHSA-23x8-m9wv-h49m.json b/advisories/unreviewed/2022/05/GHSA-23x8-m9wv-h49m/GHSA-23x8-m9wv-h49m.json index 7a7aac96239..a3b70c930ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-23x8-m9wv-h49m/GHSA-23x8-m9wv-h49m.json +++ b/advisories/unreviewed/2022/05/GHSA-23x8-m9wv-h49m/GHSA-23x8-m9wv-h49m.json @@ -7,12 +7,8 @@ "CVE-2020-35804" ], "details": "Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7800 before 1.0.1.58, R7800 before 1.0.2.74, R8900 before 1.0.5.18, R9000 before 1.0.5.18, and XR700 before 1.0.1.34.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-258m-qv8h-28wx/GHSA-258m-qv8h-28wx.json b/advisories/unreviewed/2022/05/GHSA-258m-qv8h-28wx/GHSA-258m-qv8h-28wx.json index 2d5b63a2d4e..bfc02ab85eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-258m-qv8h-28wx/GHSA-258m-qv8h-28wx.json +++ b/advisories/unreviewed/2022/05/GHSA-258m-qv8h-28wx/GHSA-258m-qv8h-28wx.json @@ -7,12 +7,8 @@ "CVE-2020-4895" ], "details": "IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25cw-47xx-658v/GHSA-25cw-47xx-658v.json b/advisories/unreviewed/2022/05/GHSA-25cw-47xx-658v/GHSA-25cw-47xx-658v.json index 044544aef28..223b278fcad 100644 --- a/advisories/unreviewed/2022/05/GHSA-25cw-47xx-658v/GHSA-25cw-47xx-658v.json +++ b/advisories/unreviewed/2022/05/GHSA-25cw-47xx-658v/GHSA-25cw-47xx-658v.json @@ -7,12 +7,8 @@ "CVE-2020-26994" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of PCX files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25x7-rqcx-mfwh/GHSA-25x7-rqcx-mfwh.json b/advisories/unreviewed/2022/05/GHSA-25x7-rqcx-mfwh/GHSA-25x7-rqcx-mfwh.json index c3d97a2339f..f2a00a00d30 100644 --- a/advisories/unreviewed/2022/05/GHSA-25x7-rqcx-mfwh/GHSA-25x7-rqcx-mfwh.json +++ b/advisories/unreviewed/2022/05/GHSA-25x7-rqcx-mfwh/GHSA-25x7-rqcx-mfwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26q2-38pj-p8fv/GHSA-26q2-38pj-p8fv.json b/advisories/unreviewed/2022/05/GHSA-26q2-38pj-p8fv/GHSA-26q2-38pj-p8fv.json index 47d8304f5b2..37ec1576dce 100644 --- a/advisories/unreviewed/2022/05/GHSA-26q2-38pj-p8fv/GHSA-26q2-38pj-p8fv.json +++ b/advisories/unreviewed/2022/05/GHSA-26q2-38pj-p8fv/GHSA-26q2-38pj-p8fv.json @@ -7,12 +7,8 @@ "CVE-2020-28382" ], "details": "A vulnerability has been identified in Solid Edge (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in a out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27g2-h3jp-46x8/GHSA-27g2-h3jp-46x8.json b/advisories/unreviewed/2022/05/GHSA-27g2-h3jp-46x8/GHSA-27g2-h3jp-46x8.json index a936a53e525..c54bb9fd5c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-27g2-h3jp-46x8/GHSA-27g2-h3jp-46x8.json +++ b/advisories/unreviewed/2022/05/GHSA-27g2-h3jp-46x8/GHSA-27g2-h3jp-46x8.json @@ -7,12 +7,8 @@ "CVE-2020-35801" ], "details": "Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2866-fxpg-497j/GHSA-2866-fxpg-497j.json b/advisories/unreviewed/2022/05/GHSA-2866-fxpg-497j/GHSA-2866-fxpg-497j.json index 0a4c26c8b66..61ea0587b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-2866-fxpg-497j/GHSA-2866-fxpg-497j.json +++ b/advisories/unreviewed/2022/05/GHSA-2866-fxpg-497j/GHSA-2866-fxpg-497j.json @@ -7,12 +7,8 @@ "CVE-2019-20484" ], "details": "An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-287f-5vcq-p94w/GHSA-287f-5vcq-p94w.json b/advisories/unreviewed/2022/05/GHSA-287f-5vcq-p94w/GHSA-287f-5vcq-p94w.json index de23708b789..580bf4db17a 100644 --- a/advisories/unreviewed/2022/05/GHSA-287f-5vcq-p94w/GHSA-287f-5vcq-p94w.json +++ b/advisories/unreviewed/2022/05/GHSA-287f-5vcq-p94w/GHSA-287f-5vcq-p94w.json @@ -7,12 +7,8 @@ "CVE-2020-36052" ], "details": "Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28cr-3625-x6c5/GHSA-28cr-3625-x6c5.json b/advisories/unreviewed/2022/05/GHSA-28cr-3625-x6c5/GHSA-28cr-3625-x6c5.json index db961cdcf9b..25899793f03 100644 --- a/advisories/unreviewed/2022/05/GHSA-28cr-3625-x6c5/GHSA-28cr-3625-x6c5.json +++ b/advisories/unreviewed/2022/05/GHSA-28cr-3625-x6c5/GHSA-28cr-3625-x6c5.json @@ -7,12 +7,8 @@ "CVE-2016-9026" ], "details": "Exponent CMS before 2.6.0 has improper input validation in fileController.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28r8-9g34-2x25/GHSA-28r8-9g34-2x25.json b/advisories/unreviewed/2022/05/GHSA-28r8-9g34-2x25/GHSA-28r8-9g34-2x25.json index 8719548aa92..f09113b8864 100644 --- a/advisories/unreviewed/2022/05/GHSA-28r8-9g34-2x25/GHSA-28r8-9g34-2x25.json +++ b/advisories/unreviewed/2022/05/GHSA-28r8-9g34-2x25/GHSA-28r8-9g34-2x25.json @@ -7,12 +7,8 @@ "CVE-2021-1350" ], "details": "\n A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service.\n The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI.\n Cisco has addressed this vulnerability. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2984-fgj8-4x8h/GHSA-2984-fgj8-4x8h.json b/advisories/unreviewed/2022/05/GHSA-2984-fgj8-4x8h/GHSA-2984-fgj8-4x8h.json index dbd697b1382..1d08fb6fedf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2984-fgj8-4x8h/GHSA-2984-fgj8-4x8h.json +++ b/advisories/unreviewed/2022/05/GHSA-2984-fgj8-4x8h/GHSA-2984-fgj8-4x8h.json @@ -7,12 +7,8 @@ "CVE-2021-1200" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cc9-295v-25m8/GHSA-2cc9-295v-25m8.json b/advisories/unreviewed/2022/05/GHSA-2cc9-295v-25m8/GHSA-2cc9-295v-25m8.json index 202ded5816e..8ec80720a1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cc9-295v-25m8/GHSA-2cc9-295v-25m8.json +++ b/advisories/unreviewed/2022/05/GHSA-2cc9-295v-25m8/GHSA-2cc9-295v-25m8.json @@ -7,12 +7,8 @@ "CVE-2019-25012" ], "details": "The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f29-629x-3r89/GHSA-2f29-629x-3r89.json b/advisories/unreviewed/2022/05/GHSA-2f29-629x-3r89/GHSA-2f29-629x-3r89.json index 3b6187c01fc..e6d90a05df6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f29-629x-3r89/GHSA-2f29-629x-3r89.json +++ b/advisories/unreviewed/2022/05/GHSA-2f29-629x-3r89/GHSA-2f29-629x-3r89.json @@ -7,12 +7,8 @@ "CVE-2020-29160" ], "details": "An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f5g-rwwg-jqh6/GHSA-2f5g-rwwg-jqh6.json b/advisories/unreviewed/2022/05/GHSA-2f5g-rwwg-jqh6/GHSA-2f5g-rwwg-jqh6.json index e902d4fed54..a0f9510f95d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f5g-rwwg-jqh6/GHSA-2f5g-rwwg-jqh6.json +++ b/advisories/unreviewed/2022/05/GHSA-2f5g-rwwg-jqh6/GHSA-2f5g-rwwg-jqh6.json @@ -7,12 +7,8 @@ "CVE-2020-26993" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer in the font index handling function. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fpm-8hx3-wxj9/GHSA-2fpm-8hx3-wxj9.json b/advisories/unreviewed/2022/05/GHSA-2fpm-8hx3-wxj9/GHSA-2fpm-8hx3-wxj9.json index 16f7273d3c9..6a176a90312 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fpm-8hx3-wxj9/GHSA-2fpm-8hx3-wxj9.json +++ b/advisories/unreviewed/2022/05/GHSA-2fpm-8hx3-wxj9/GHSA-2fpm-8hx3-wxj9.json @@ -7,12 +7,8 @@ "CVE-2020-14341" ], "details": "The \"Test Connection\" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hqm-x8qp-68ph/GHSA-2hqm-x8qp-68ph.json b/advisories/unreviewed/2022/05/GHSA-2hqm-x8qp-68ph/GHSA-2hqm-x8qp-68ph.json index 4d3d90e1e6d..ed0dfc76287 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hqm-x8qp-68ph/GHSA-2hqm-x8qp-68ph.json +++ b/advisories/unreviewed/2022/05/GHSA-2hqm-x8qp-68ph/GHSA-2hqm-x8qp-68ph.json @@ -7,12 +7,8 @@ "CVE-2020-26992" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jmj-6ff4-3p3w/GHSA-2jmj-6ff4-3p3w.json b/advisories/unreviewed/2022/05/GHSA-2jmj-6ff4-3p3w/GHSA-2jmj-6ff4-3p3w.json index fea3df6d509..e75a9b9d1ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jmj-6ff4-3p3w/GHSA-2jmj-6ff4-3p3w.json +++ b/advisories/unreviewed/2022/05/GHSA-2jmj-6ff4-3p3w/GHSA-2jmj-6ff4-3p3w.json @@ -7,12 +7,8 @@ "CVE-2020-27220" ], "details": "The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission for the gateway device to act on its behalf. This means an authenticated device of a certain tenant, notably also a non-gateway device acting like a gateway, may receive command & control messages targeted at a different device of the same tenant without corresponding permissions getting checked.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jq2-rfq2-wr2p/GHSA-2jq2-rfq2-wr2p.json b/advisories/unreviewed/2022/05/GHSA-2jq2-rfq2-wr2p/GHSA-2jq2-rfq2-wr2p.json index 9717c427d95..9b826d8a96b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jq2-rfq2-wr2p/GHSA-2jq2-rfq2-wr2p.json +++ b/advisories/unreviewed/2022/05/GHSA-2jq2-rfq2-wr2p/GHSA-2jq2-rfq2-wr2p.json @@ -7,12 +7,8 @@ "CVE-2021-3022" ], "details": "An issue was discovered on LG mobile devices with Android OS 10 software. There was no write protection for the MTK protect2 partition. The LG ID is LVE-SMP-200028 (January 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m9j-f7hm-696q/GHSA-2m9j-f7hm-696q.json b/advisories/unreviewed/2022/05/GHSA-2m9j-f7hm-696q/GHSA-2m9j-f7hm-696q.json index 53a557890f9..ce5598178f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m9j-f7hm-696q/GHSA-2m9j-f7hm-696q.json +++ b/advisories/unreviewed/2022/05/GHSA-2m9j-f7hm-696q/GHSA-2m9j-f7hm-696q.json @@ -7,12 +7,8 @@ "CVE-2020-14102" ], "details": "There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mrx-4g5g-2vw5/GHSA-2mrx-4g5g-2vw5.json b/advisories/unreviewed/2022/05/GHSA-2mrx-4g5g-2vw5/GHSA-2mrx-4g5g-2vw5.json index 23d93d468c3..3d63b4093e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mrx-4g5g-2vw5/GHSA-2mrx-4g5g-2vw5.json +++ b/advisories/unreviewed/2022/05/GHSA-2mrx-4g5g-2vw5/GHSA-2mrx-4g5g-2vw5.json @@ -7,12 +7,8 @@ "CVE-2021-23242" ], "details": "MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pfh-m36r-gfqc/GHSA-2pfh-m36r-gfqc.json b/advisories/unreviewed/2022/05/GHSA-2pfh-m36r-gfqc/GHSA-2pfh-m36r-gfqc.json index 0cfed483deb..7e2f3d2a448 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pfh-m36r-gfqc/GHSA-2pfh-m36r-gfqc.json +++ b/advisories/unreviewed/2022/05/GHSA-2pfh-m36r-gfqc/GHSA-2pfh-m36r-gfqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rjp-9cc6-3v2j/GHSA-2rjp-9cc6-3v2j.json b/advisories/unreviewed/2022/05/GHSA-2rjp-9cc6-3v2j/GHSA-2rjp-9cc6-3v2j.json index 3329ad8b659..6e66a727c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rjp-9cc6-3v2j/GHSA-2rjp-9cc6-3v2j.json +++ b/advisories/unreviewed/2022/05/GHSA-2rjp-9cc6-3v2j/GHSA-2rjp-9cc6-3v2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v2r-vm5q-9pwc/GHSA-2v2r-vm5q-9pwc.json b/advisories/unreviewed/2022/05/GHSA-2v2r-vm5q-9pwc/GHSA-2v2r-vm5q-9pwc.json index 7fcd1f12cce..f8a112f3acd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v2r-vm5q-9pwc/GHSA-2v2r-vm5q-9pwc.json +++ b/advisories/unreviewed/2022/05/GHSA-2v2r-vm5q-9pwc/GHSA-2v2r-vm5q-9pwc.json @@ -7,12 +7,8 @@ "CVE-2021-1204" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vwg-wm97-9xx9/GHSA-2vwg-wm97-9xx9.json b/advisories/unreviewed/2022/05/GHSA-2vwg-wm97-9xx9/GHSA-2vwg-wm97-9xx9.json index dfa9ccaeef9..d6e83d5c5a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vwg-wm97-9xx9/GHSA-2vwg-wm97-9xx9.json +++ b/advisories/unreviewed/2022/05/GHSA-2vwg-wm97-9xx9/GHSA-2vwg-wm97-9xx9.json @@ -7,12 +7,8 @@ "CVE-2018-11008" ], "details": "An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2whc-3w32-64h4/GHSA-2whc-3w32-64h4.json b/advisories/unreviewed/2022/05/GHSA-2whc-3w32-64h4/GHSA-2whc-3w32-64h4.json index f2aa8cf9d05..5ec660dc813 100644 --- a/advisories/unreviewed/2022/05/GHSA-2whc-3w32-64h4/GHSA-2whc-3w32-64h4.json +++ b/advisories/unreviewed/2022/05/GHSA-2whc-3w32-64h4/GHSA-2whc-3w32-64h4.json @@ -7,12 +7,8 @@ "CVE-2020-16023" ], "details": "Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wq8-q24x-h8rw/GHSA-2wq8-q24x-h8rw.json b/advisories/unreviewed/2022/05/GHSA-2wq8-q24x-h8rw/GHSA-2wq8-q24x-h8rw.json index 378153fa754..0af6dd9e79d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wq8-q24x-h8rw/GHSA-2wq8-q24x-h8rw.json +++ b/advisories/unreviewed/2022/05/GHSA-2wq8-q24x-h8rw/GHSA-2wq8-q24x-h8rw.json @@ -7,12 +7,8 @@ "CVE-2020-16146" ], "details": "Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xc3-3457-6965/GHSA-2xc3-3457-6965.json b/advisories/unreviewed/2022/05/GHSA-2xc3-3457-6965/GHSA-2xc3-3457-6965.json index 36c12534373..57235079ad5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xc3-3457-6965/GHSA-2xc3-3457-6965.json +++ b/advisories/unreviewed/2022/05/GHSA-2xc3-3457-6965/GHSA-2xc3-3457-6965.json @@ -7,12 +7,8 @@ "CVE-2020-29231" ], "details": "EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xjp-8pmx-7mmj/GHSA-2xjp-8pmx-7mmj.json b/advisories/unreviewed/2022/05/GHSA-2xjp-8pmx-7mmj/GHSA-2xjp-8pmx-7mmj.json index 4ec20403804..bc55e0d0de2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xjp-8pmx-7mmj/GHSA-2xjp-8pmx-7mmj.json +++ b/advisories/unreviewed/2022/05/GHSA-2xjp-8pmx-7mmj/GHSA-2xjp-8pmx-7mmj.json @@ -7,12 +7,8 @@ "CVE-2020-35831" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xwg-c668-f9x5/GHSA-2xwg-c668-f9x5.json b/advisories/unreviewed/2022/05/GHSA-2xwg-c668-f9x5/GHSA-2xwg-c668-f9x5.json index f9d2ad5d2e4..e668ea22e24 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xwg-c668-f9x5/GHSA-2xwg-c668-f9x5.json +++ b/advisories/unreviewed/2022/05/GHSA-2xwg-c668-f9x5/GHSA-2xwg-c668-f9x5.json @@ -7,12 +7,8 @@ "CVE-2021-1269" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3228-63jx-j274/GHSA-3228-63jx-j274.json b/advisories/unreviewed/2022/05/GHSA-3228-63jx-j274/GHSA-3228-63jx-j274.json index 06c93c5d8c9..8f9f6632072 100644 --- a/advisories/unreviewed/2022/05/GHSA-3228-63jx-j274/GHSA-3228-63jx-j274.json +++ b/advisories/unreviewed/2022/05/GHSA-3228-63jx-j274/GHSA-3228-63jx-j274.json @@ -7,12 +7,8 @@ "CVE-2020-35262" ], "details": "Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and \"Keyword\" in URL Filter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32x3-2qh2-v3w9/GHSA-32x3-2qh2-v3w9.json b/advisories/unreviewed/2022/05/GHSA-32x3-2qh2-v3w9/GHSA-32x3-2qh2-v3w9.json index 5a3b249f3f9..3d7cc2f5256 100644 --- a/advisories/unreviewed/2022/05/GHSA-32x3-2qh2-v3w9/GHSA-32x3-2qh2-v3w9.json +++ b/advisories/unreviewed/2022/05/GHSA-32x3-2qh2-v3w9/GHSA-32x3-2qh2-v3w9.json @@ -7,12 +7,8 @@ "CVE-2021-1265" ], "details": " A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being stored in clear text, which can be retrieved by various API calls. An attacker could exploit this vulnerability by authenticating to the device and executing a series of API calls. A successful exploit could allow the attacker to retrieve the full unmasked running configurations of managed devices. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33g5-vw3f-w92q/GHSA-33g5-vw3f-w92q.json b/advisories/unreviewed/2022/05/GHSA-33g5-vw3f-w92q/GHSA-33g5-vw3f-w92q.json index cda2a056fec..cab445f9471 100644 --- a/advisories/unreviewed/2022/05/GHSA-33g5-vw3f-w92q/GHSA-33g5-vw3f-w92q.json +++ b/advisories/unreviewed/2022/05/GHSA-33g5-vw3f-w92q/GHSA-33g5-vw3f-w92q.json @@ -7,12 +7,8 @@ "CVE-2021-21462" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33r4-rw8x-j8x9/GHSA-33r4-rw8x-j8x9.json b/advisories/unreviewed/2022/05/GHSA-33r4-rw8x-j8x9/GHSA-33r4-rw8x-j8x9.json index b86e1c2b51f..b99dfc46a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-33r4-rw8x-j8x9/GHSA-33r4-rw8x-j8x9.json +++ b/advisories/unreviewed/2022/05/GHSA-33r4-rw8x-j8x9/GHSA-33r4-rw8x-j8x9.json @@ -7,12 +7,8 @@ "CVE-2020-28093" ], "details": "On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3435-jrhh-rq8g/GHSA-3435-jrhh-rq8g.json b/advisories/unreviewed/2022/05/GHSA-3435-jrhh-rq8g/GHSA-3435-jrhh-rq8g.json index e08c7203250..24a463b7e25 100644 --- a/advisories/unreviewed/2022/05/GHSA-3435-jrhh-rq8g/GHSA-3435-jrhh-rq8g.json +++ b/advisories/unreviewed/2022/05/GHSA-3435-jrhh-rq8g/GHSA-3435-jrhh-rq8g.json @@ -7,12 +7,8 @@ "CVE-2020-17363" ], "details": "USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap CVE-2020-25069.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3456-r253-4f5r/GHSA-3456-r253-4f5r.json b/advisories/unreviewed/2022/05/GHSA-3456-r253-4f5r/GHSA-3456-r253-4f5r.json index edac2b517e3..9a7356c4c99 100644 --- a/advisories/unreviewed/2022/05/GHSA-3456-r253-4f5r/GHSA-3456-r253-4f5r.json +++ b/advisories/unreviewed/2022/05/GHSA-3456-r253-4f5r/GHSA-3456-r253-4f5r.json @@ -7,12 +7,8 @@ "CVE-2020-35946" ], "details": "An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34h5-5rm5-5r55/GHSA-34h5-5rm5-5r55.json b/advisories/unreviewed/2022/05/GHSA-34h5-5rm5-5r55/GHSA-34h5-5rm5-5r55.json index 232062510f0..574b8e4caf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-34h5-5rm5-5r55/GHSA-34h5-5rm5-5r55.json +++ b/advisories/unreviewed/2022/05/GHSA-34h5-5rm5-5r55/GHSA-34h5-5rm5-5r55.json @@ -7,12 +7,8 @@ "CVE-2021-1169" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-355x-g6q7-4c7g/GHSA-355x-g6q7-4c7g.json b/advisories/unreviewed/2022/05/GHSA-355x-g6q7-4c7g/GHSA-355x-g6q7-4c7g.json index 8e484f3bbe0..d8ffd4ecda0 100644 --- a/advisories/unreviewed/2022/05/GHSA-355x-g6q7-4c7g/GHSA-355x-g6q7-4c7g.json +++ b/advisories/unreviewed/2022/05/GHSA-355x-g6q7-4c7g/GHSA-355x-g6q7-4c7g.json @@ -7,12 +7,8 @@ "CVE-2020-27265" ], "details": "KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and remotely execute code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35j5-3cvj-g2x4/GHSA-35j5-3cvj-g2x4.json b/advisories/unreviewed/2022/05/GHSA-35j5-3cvj-g2x4/GHSA-35j5-3cvj-g2x4.json index 523347151c3..8328f8f0ceb 100644 --- a/advisories/unreviewed/2022/05/GHSA-35j5-3cvj-g2x4/GHSA-35j5-3cvj-g2x4.json +++ b/advisories/unreviewed/2022/05/GHSA-35j5-3cvj-g2x4/GHSA-35j5-3cvj-g2x4.json @@ -7,12 +7,8 @@ "CVE-2020-36169" ], "details": "An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create directories under the top level of any drive. If a low privileged user creates an affected path with a library that the Veritas product attempts to load, they can execute arbitrary code as SYSTEM or Administrator. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This vulnerability affects master servers, media servers, clients, and OpsCenter servers on the Windows platform. The system is vulnerable during an install or upgrade and post-install during normal operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35pj-cxpm-pvh5/GHSA-35pj-cxpm-pvh5.json b/advisories/unreviewed/2022/05/GHSA-35pj-cxpm-pvh5/GHSA-35pj-cxpm-pvh5.json index 0fa5ae091f6..08b5e485dd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-35pj-cxpm-pvh5/GHSA-35pj-cxpm-pvh5.json +++ b/advisories/unreviewed/2022/05/GHSA-35pj-cxpm-pvh5/GHSA-35pj-cxpm-pvh5.json @@ -7,12 +7,8 @@ "CVE-2020-28275" ], "details": "Prototype pollution vulnerability in 'cache-base' versions 0.7.0 through 4.0.0 allows attacker to cause a denial of service and may lead to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-363j-9xx8-29r4/GHSA-363j-9xx8-29r4.json b/advisories/unreviewed/2022/05/GHSA-363j-9xx8-29r4/GHSA-363j-9xx8-29r4.json index 3de63ef39f3..e84b11f7d1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-363j-9xx8-29r4/GHSA-363j-9xx8-29r4.json +++ b/advisories/unreviewed/2022/05/GHSA-363j-9xx8-29r4/GHSA-363j-9xx8-29r4.json @@ -7,12 +7,8 @@ "CVE-2021-21114" ], "details": "Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36pj-8gmw-49gg/GHSA-36pj-8gmw-49gg.json b/advisories/unreviewed/2022/05/GHSA-36pj-8gmw-49gg/GHSA-36pj-8gmw-49gg.json index f63898be49e..af231082be8 100644 --- a/advisories/unreviewed/2022/05/GHSA-36pj-8gmw-49gg/GHSA-36pj-8gmw-49gg.json +++ b/advisories/unreviewed/2022/05/GHSA-36pj-8gmw-49gg/GHSA-36pj-8gmw-49gg.json @@ -7,12 +7,8 @@ "CVE-2020-35840" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.76, WNR1000v4 before 1.1.0.62, WNR2020 before 1.1.0.62, and WNR2050 before 1.1.0.62.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36wp-g3gj-7v3h/GHSA-36wp-g3gj-7v3h.json b/advisories/unreviewed/2022/05/GHSA-36wp-g3gj-7v3h/GHSA-36wp-g3gj-7v3h.json index b00d3832b7c..0672c77e433 100644 --- a/advisories/unreviewed/2022/05/GHSA-36wp-g3gj-7v3h/GHSA-36wp-g3gj-7v3h.json +++ b/advisories/unreviewed/2022/05/GHSA-36wp-g3gj-7v3h/GHSA-36wp-g3gj-7v3h.json @@ -7,12 +7,8 @@ "CVE-2020-4667" ], "details": "IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive information due to improper input validation. IBM X-Force ID: 186282.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37cv-ggq7-j55v/GHSA-37cv-ggq7-j55v.json b/advisories/unreviewed/2022/05/GHSA-37cv-ggq7-j55v/GHSA-37cv-ggq7-j55v.json index 74a06155d54..bba5e3a206a 100644 --- a/advisories/unreviewed/2022/05/GHSA-37cv-ggq7-j55v/GHSA-37cv-ggq7-j55v.json +++ b/advisories/unreviewed/2022/05/GHSA-37cv-ggq7-j55v/GHSA-37cv-ggq7-j55v.json @@ -7,12 +7,8 @@ "CVE-2021-1188" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37gp-666w-35h8/GHSA-37gp-666w-35h8.json b/advisories/unreviewed/2022/05/GHSA-37gp-666w-35h8/GHSA-37gp-666w-35h8.json index 4e6dfbcbcf6..6f5504691db 100644 --- a/advisories/unreviewed/2022/05/GHSA-37gp-666w-35h8/GHSA-37gp-666w-35h8.json +++ b/advisories/unreviewed/2022/05/GHSA-37gp-666w-35h8/GHSA-37gp-666w-35h8.json @@ -7,12 +7,8 @@ "CVE-2021-1286" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37m6-73f6-jm7w/GHSA-37m6-73f6-jm7w.json b/advisories/unreviewed/2022/05/GHSA-37m6-73f6-jm7w/GHSA-37m6-73f6-jm7w.json index 1a936cf2c8a..f0f5f7e5b24 100644 --- a/advisories/unreviewed/2022/05/GHSA-37m6-73f6-jm7w/GHSA-37m6-73f6-jm7w.json +++ b/advisories/unreviewed/2022/05/GHSA-37m6-73f6-jm7w/GHSA-37m6-73f6-jm7w.json @@ -7,12 +7,8 @@ "CVE-2020-26712" ], "details": "REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37w4-w4g6-8f3q/GHSA-37w4-w4g6-8f3q.json b/advisories/unreviewed/2022/05/GHSA-37w4-w4g6-8f3q/GHSA-37w4-w4g6-8f3q.json index 35ec9c03a7a..bc6bc13468d 100644 --- a/advisories/unreviewed/2022/05/GHSA-37w4-w4g6-8f3q/GHSA-37w4-w4g6-8f3q.json +++ b/advisories/unreviewed/2022/05/GHSA-37w4-w4g6-8f3q/GHSA-37w4-w4g6-8f3q.json @@ -7,12 +7,8 @@ "CVE-2020-36166" ], "details": "An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \\usr\\local\\ssl. This library attempts to load the \\usr\\local\\ssl\\openssl.cnf configuration file, which may not exist. On Windows systems, this path could translate to :\\usr\\local\\ssl\\openssl.cnf, where could be the default Windows installation drive such as C:\\ or the drive where a Veritas product is installed. By default, on Windows systems, users can create directories under any top-level directory. A low privileged user can create a :\\usr\\local\\ssl\\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-386q-xj43-6wfr/GHSA-386q-xj43-6wfr.json b/advisories/unreviewed/2022/05/GHSA-386q-xj43-6wfr/GHSA-386q-xj43-6wfr.json index 28bf1f13268..30450c8ff9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-386q-xj43-6wfr/GHSA-386q-xj43-6wfr.json +++ b/advisories/unreviewed/2022/05/GHSA-386q-xj43-6wfr/GHSA-386q-xj43-6wfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-392p-h7qw-6vx7/GHSA-392p-h7qw-6vx7.json b/advisories/unreviewed/2022/05/GHSA-392p-h7qw-6vx7/GHSA-392p-h7qw-6vx7.json index 2c702f782d9..771e4e1a90f 100644 --- a/advisories/unreviewed/2022/05/GHSA-392p-h7qw-6vx7/GHSA-392p-h7qw-6vx7.json +++ b/advisories/unreviewed/2022/05/GHSA-392p-h7qw-6vx7/GHSA-392p-h7qw-6vx7.json @@ -7,12 +7,8 @@ "CVE-2020-10655" ], "details": "The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3956-xf6j-hjw9/GHSA-3956-xf6j-hjw9.json b/advisories/unreviewed/2022/05/GHSA-3956-xf6j-hjw9/GHSA-3956-xf6j-hjw9.json index c9664fc3d7f..83e2763a69f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3956-xf6j-hjw9/GHSA-3956-xf6j-hjw9.json +++ b/advisories/unreviewed/2022/05/GHSA-3956-xf6j-hjw9/GHSA-3956-xf6j-hjw9.json @@ -7,12 +7,8 @@ "CVE-2020-10206" ], "details": "Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows local attackers to view and interact with the video output of the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-399x-p377-379h/GHSA-399x-p377-379h.json b/advisories/unreviewed/2022/05/GHSA-399x-p377-379h/GHSA-399x-p377-379h.json index 02199f31683..8ba921662d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-399x-p377-379h/GHSA-399x-p377-379h.json +++ b/advisories/unreviewed/2022/05/GHSA-399x-p377-379h/GHSA-399x-p377-379h.json @@ -7,12 +7,8 @@ "CVE-2018-25002" ], "details": "uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c2f-8cpm-89m3/GHSA-3c2f-8cpm-89m3.json b/advisories/unreviewed/2022/05/GHSA-3c2f-8cpm-89m3/GHSA-3c2f-8cpm-89m3.json index cf3ea33fed5..3b3fd4d62e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c2f-8cpm-89m3/GHSA-3c2f-8cpm-89m3.json +++ b/advisories/unreviewed/2022/05/GHSA-3c2f-8cpm-89m3/GHSA-3c2f-8cpm-89m3.json @@ -7,12 +7,8 @@ "CVE-2021-0211" ], "details": "An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions in network traffic causing a Denial of Service (DoS) condition. Continued receipt of these update messages will cause a sustained Denial of Service condition. This issue affects Juniper Networks: Junos OS: All versions prior to 17.3R3-S10 with the exceptions of 15.1X49-D240 on SRX Series and 15.1R7-S8 on EX Series; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior to 19.3R2-S5, 19.3R3-S1; 19.4 versions prior to 19.4R1-S3, 19.4R2-S3, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S3 20.2R2; 20.3 versions prior to 20.3R1-S1, 20.3R2. Junos OS Evolved: All versions prior to 20.3R1-S1-EVO, 20.3R2-EVO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c9h-j75v-3mr5/GHSA-3c9h-j75v-3mr5.json b/advisories/unreviewed/2022/05/GHSA-3c9h-j75v-3mr5/GHSA-3c9h-j75v-3mr5.json index 65091c7ffa8..0efcb0a52d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c9h-j75v-3mr5/GHSA-3c9h-j75v-3mr5.json +++ b/advisories/unreviewed/2022/05/GHSA-3c9h-j75v-3mr5/GHSA-3c9h-j75v-3mr5.json @@ -7,12 +7,8 @@ "CVE-2020-26979" ], "details": "When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This vulnerability affects Firefox < 84.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f3f-hqx2-w523/GHSA-3f3f-hqx2-w523.json b/advisories/unreviewed/2022/05/GHSA-3f3f-hqx2-w523/GHSA-3f3f-hqx2-w523.json index f91295dbafa..6686638e83d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f3f-hqx2-w523/GHSA-3f3f-hqx2-w523.json +++ b/advisories/unreviewed/2022/05/GHSA-3f3f-hqx2-w523/GHSA-3f3f-hqx2-w523.json @@ -7,12 +7,8 @@ "CVE-2018-20316" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f76-vp73-hc25/GHSA-3f76-vp73-hc25.json b/advisories/unreviewed/2022/05/GHSA-3f76-vp73-hc25/GHSA-3f76-vp73-hc25.json index d8262c95ab9..b3e0930a658 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f76-vp73-hc25/GHSA-3f76-vp73-hc25.json +++ b/advisories/unreviewed/2022/05/GHSA-3f76-vp73-hc25/GHSA-3f76-vp73-hc25.json @@ -7,12 +7,8 @@ "CVE-2021-1194" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fgp-cw9p-5ff5/GHSA-3fgp-cw9p-5ff5.json b/advisories/unreviewed/2022/05/GHSA-3fgp-cw9p-5ff5/GHSA-3fgp-cw9p-5ff5.json index 97f95dad75f..34d6845548d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fgp-cw9p-5ff5/GHSA-3fgp-cw9p-5ff5.json +++ b/advisories/unreviewed/2022/05/GHSA-3fgp-cw9p-5ff5/GHSA-3fgp-cw9p-5ff5.json @@ -7,12 +7,8 @@ "CVE-2020-27291" ], "details": "Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fjh-3qmq-p25v/GHSA-3fjh-3qmq-p25v.json b/advisories/unreviewed/2022/05/GHSA-3fjh-3qmq-p25v/GHSA-3fjh-3qmq-p25v.json index 54daca06ec2..605346a0344 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fjh-3qmq-p25v/GHSA-3fjh-3qmq-p25v.json +++ b/advisories/unreviewed/2022/05/GHSA-3fjh-3qmq-p25v/GHSA-3fjh-3qmq-p25v.json @@ -7,12 +7,8 @@ "CVE-2021-1312" ], "details": "\n A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device.\n The vulnerability is due to inadequate provisioning of kernel parameters for the maximum number of TCP connections and SYN backlog. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to block TCP listening ports that are used by the health monitor API. This vulnerability only affects customers who use the health monitor API.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3grp-6v62-v4vr/GHSA-3grp-6v62-v4vr.json b/advisories/unreviewed/2022/05/GHSA-3grp-6v62-v4vr/GHSA-3grp-6v62-v4vr.json index ef71a965cd3..e7d08bcda54 100644 --- a/advisories/unreviewed/2022/05/GHSA-3grp-6v62-v4vr/GHSA-3grp-6v62-v4vr.json +++ b/advisories/unreviewed/2022/05/GHSA-3grp-6v62-v4vr/GHSA-3grp-6v62-v4vr.json @@ -7,12 +7,8 @@ "CVE-2016-9025" ], "details": "Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hp7-gf4j-8f4c/GHSA-3hp7-gf4j-8f4c.json b/advisories/unreviewed/2022/05/GHSA-3hp7-gf4j-8f4c/GHSA-3hp7-gf4j-8f4c.json index 57a13c9db02..5f0612d6c75 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hp7-gf4j-8f4c/GHSA-3hp7-gf4j-8f4c.json +++ b/advisories/unreviewed/2022/05/GHSA-3hp7-gf4j-8f4c/GHSA-3hp7-gf4j-8f4c.json @@ -7,12 +7,8 @@ "CVE-2020-35687" ], "details": "PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jcw-ph85-3mv4/GHSA-3jcw-ph85-3mv4.json b/advisories/unreviewed/2022/05/GHSA-3jcw-ph85-3mv4/GHSA-3jcw-ph85-3mv4.json index 10f96478e4e..26916d2a40a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jcw-ph85-3mv4/GHSA-3jcw-ph85-3mv4.json +++ b/advisories/unreviewed/2022/05/GHSA-3jcw-ph85-3mv4/GHSA-3jcw-ph85-3mv4.json @@ -7,12 +7,8 @@ "CVE-2020-24700" ], "details": "OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jj3-875w-p3wj/GHSA-3jj3-875w-p3wj.json b/advisories/unreviewed/2022/05/GHSA-3jj3-875w-p3wj/GHSA-3jj3-875w-p3wj.json index a30b01e74f4..83819a17899 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jj3-875w-p3wj/GHSA-3jj3-875w-p3wj.json +++ b/advisories/unreviewed/2022/05/GHSA-3jj3-875w-p3wj/GHSA-3jj3-875w-p3wj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jm5-qqg2-4jf9/GHSA-3jm5-qqg2-4jf9.json b/advisories/unreviewed/2022/05/GHSA-3jm5-qqg2-4jf9/GHSA-3jm5-qqg2-4jf9.json index 6ea85bde294..799b7d97437 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jm5-qqg2-4jf9/GHSA-3jm5-qqg2-4jf9.json +++ b/advisories/unreviewed/2022/05/GHSA-3jm5-qqg2-4jf9/GHSA-3jm5-qqg2-4jf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mmm-4792-65w2/GHSA-3mmm-4792-65w2.json b/advisories/unreviewed/2022/05/GHSA-3mmm-4792-65w2/GHSA-3mmm-4792-65w2.json index eca47a89c98..0e7802565f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mmm-4792-65w2/GHSA-3mmm-4792-65w2.json +++ b/advisories/unreviewed/2022/05/GHSA-3mmm-4792-65w2/GHSA-3mmm-4792-65w2.json @@ -7,12 +7,8 @@ "CVE-2020-26045" ], "details": "FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qg5-3wgr-h9mq/GHSA-3qg5-3wgr-h9mq.json b/advisories/unreviewed/2022/05/GHSA-3qg5-3wgr-h9mq/GHSA-3qg5-3wgr-h9mq.json index b7f8adc9d9d..30b26fe3c0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qg5-3wgr-h9mq/GHSA-3qg5-3wgr-h9mq.json +++ b/advisories/unreviewed/2022/05/GHSA-3qg5-3wgr-h9mq/GHSA-3qg5-3wgr-h9mq.json @@ -7,12 +7,8 @@ "CVE-2007-0842" ], "details": "The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rff-xjq9-pg37/GHSA-3rff-xjq9-pg37.json b/advisories/unreviewed/2022/05/GHSA-3rff-xjq9-pg37/GHSA-3rff-xjq9-pg37.json index 0191ac18a0a..087f090acbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rff-xjq9-pg37/GHSA-3rff-xjq9-pg37.json +++ b/advisories/unreviewed/2022/05/GHSA-3rff-xjq9-pg37/GHSA-3rff-xjq9-pg37.json @@ -7,12 +7,8 @@ "CVE-2020-9124" ], "details": "There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause memory leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vf9-hrcp-mj3p/GHSA-3vf9-hrcp-mj3p.json b/advisories/unreviewed/2022/05/GHSA-3vf9-hrcp-mj3p/GHSA-3vf9-hrcp-mj3p.json index 0e984dc1a42..69484ae206b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vf9-hrcp-mj3p/GHSA-3vf9-hrcp-mj3p.json +++ b/advisories/unreviewed/2022/05/GHSA-3vf9-hrcp-mj3p/GHSA-3vf9-hrcp-mj3p.json @@ -7,12 +7,8 @@ "CVE-2020-6656" ], "details": "Eaton's easySoft software v7.20 and prior are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w33-h749-fgfr/GHSA-3w33-h749-fgfr.json b/advisories/unreviewed/2022/05/GHSA-3w33-h749-fgfr/GHSA-3w33-h749-fgfr.json index dcbe73320a0..98b49ce8391 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w33-h749-fgfr/GHSA-3w33-h749-fgfr.json +++ b/advisories/unreviewed/2022/05/GHSA-3w33-h749-fgfr/GHSA-3w33-h749-fgfr.json @@ -7,12 +7,8 @@ "CVE-2020-16020" ], "details": "Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w55-xwjg-qq8w/GHSA-3w55-xwjg-qq8w.json b/advisories/unreviewed/2022/05/GHSA-3w55-xwjg-qq8w/GHSA-3w55-xwjg-qq8w.json index ea36dfd589e..8582713595e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w55-xwjg-qq8w/GHSA-3w55-xwjg-qq8w.json +++ b/advisories/unreviewed/2022/05/GHSA-3w55-xwjg-qq8w/GHSA-3w55-xwjg-qq8w.json @@ -7,12 +7,8 @@ "CVE-2021-1994" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w6j-54mg-5cr4/GHSA-3w6j-54mg-5cr4.json b/advisories/unreviewed/2022/05/GHSA-3w6j-54mg-5cr4/GHSA-3w6j-54mg-5cr4.json index 68fc50b1daa..6f3266aeba1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w6j-54mg-5cr4/GHSA-3w6j-54mg-5cr4.json +++ b/advisories/unreviewed/2022/05/GHSA-3w6j-54mg-5cr4/GHSA-3w6j-54mg-5cr4.json @@ -7,12 +7,8 @@ "CVE-2020-35800" ], "details": "Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D6000 before 1.0.0.80, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D7800 before 1.0.3.48, D8500 before 1.0.3.50, DC112A before 1.0.0.48, DGN2200v4 before 1.0.0.114, DM200 before 1.0.0.66, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX2700 before 1.0.1.58, EX3110 before 1.0.1.68, EX3700 before 1.0.0.84, EX3800 before 1.0.0.84, EX3920 before 1.0.0.84, EX6000 before 1.0.0.44, EX6100v2 before 1.0.1.94, EX6110 before 1.0.1.68, EX6120 before 1.0.0.54, EX6130 before 1.0.0.36, EX6150v1 before 1.0.0.46, EX6150v2 before 1.0.1.94, EX6200v1 before 1.0.3.94, EX6250 before 1.0.0.128, EX6400 before 1.0.2.152, EX6400v2 before 1.0.0.128, EX6410 before 1.0.0.128, EX6920 before 1.0.0.54, EX7000 before 1.0.1.90, EX7300 before 1.0.2.152, EX7300v2 before 1.0.0.128, EX7320 before 1.0.0.128, EX7500 before 1.0.0.68, EX7700 before 1.0.0.210, EX8000 before 1.0.1.224, MK62 before 1.0.5.102, MR60 before 1.0.5.102, MS60 before 1.0.5.102, R6120 before 1.0.0.70, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6250 before 1.0.4.42, R6260 before 1.1.0.76, R6300v2 before 1.0.4.42, R6330 before 1.1.0.76, R6350 before 1.1.0.76, R6400v1 before 1.0.1.62, R6400v2 before 1.0.4.98, R6700v1 before 1.0.2.16, R6700v2 before 1.2.0.72, R6700v3 before 1.0.4.98, R6800 before 1.2.0.72, R6800 before 1.2.0.72, R6850 before 1.1.0.76, R6900 before 1.0.2.16, R6900P before 1.3.2.124, R6900v2 before 1.2.0.72, R7000 before 1.0.11.106, R7000P before 1.3.2.124, R7100LG before 1.0.0.56, R7200 before 1.2.0.72, R7350 before 1.2.0.72, R7400 before 1.2.0.72, R7450 before 1.2.0.72, R7500v2 before 1.0.3.48, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900 before 1.0.4.26, R7900P before 1.4.1.62, R7960P before 1.4.1.62, R8000 before 1.0.4.58, R8000P before 1.4.1.62, R8300 before 1.0.2.134, R8500 before 1.0.2.134, R8900 before 1.0.5.24, R9000 before 1.0.5.24, RAX120 before 1.0.1.136, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX200 before 1.0.5.24, RAX35 before 1.0.3.80, RAX40 before 1.0.3.80, RAX45 before 1.0.2.64, RAX50 before 1.0.2.64, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK12 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, RBK20 before 2.6.1.38, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.38, RBR40 before 2.6.1.38, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBS40V before 2.5.1.6, RBS40V-200 before 1.0.0.46, RBS50Y before 2.6.1.40, RBW30 before 2.5.0.4, RS400 before 1.5.0.48, WN2500RPv2 before 1.0.1.56, WN3000RPv3 before 1.0.2.86, WN3500RPv1 before 1.0.0.28, WNDR3400v3 before 1.0.1.32, WNR1000v3 before 1.0.2.78, WNR2000v2 before 1.2.0.12, XR300 before 1.0.3.50, XR450 before 2.3.2.66, XR500 before 2.3.2.66, and XR700 before 1.0.1.34.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xx7-g9gf-wrw5/GHSA-3xx7-g9gf-wrw5.json b/advisories/unreviewed/2022/05/GHSA-3xx7-g9gf-wrw5/GHSA-3xx7-g9gf-wrw5.json index 312bd93691e..bb1e745c9a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xx7-g9gf-wrw5/GHSA-3xx7-g9gf-wrw5.json +++ b/advisories/unreviewed/2022/05/GHSA-3xx7-g9gf-wrw5/GHSA-3xx7-g9gf-wrw5.json @@ -7,12 +7,8 @@ "CVE-2021-21461" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-423p-ch83-27qw/GHSA-423p-ch83-27qw.json b/advisories/unreviewed/2022/05/GHSA-423p-ch83-27qw/GHSA-423p-ch83-27qw.json index 0f9736f8d61..0a06a865c77 100644 --- a/advisories/unreviewed/2022/05/GHSA-423p-ch83-27qw/GHSA-423p-ch83-27qw.json +++ b/advisories/unreviewed/2022/05/GHSA-423p-ch83-27qw/GHSA-423p-ch83-27qw.json @@ -7,12 +7,8 @@ "CVE-2020-26199" ], "details": "Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the exposed password to gain access with the privileges of the compromised user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42r3-423m-j869/GHSA-42r3-423m-j869.json b/advisories/unreviewed/2022/05/GHSA-42r3-423m-j869/GHSA-42r3-423m-j869.json index d290ab87b22..2c445f5b6dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-42r3-423m-j869/GHSA-42r3-423m-j869.json +++ b/advisories/unreviewed/2022/05/GHSA-42r3-423m-j869/GHSA-42r3-423m-j869.json @@ -7,12 +7,8 @@ "CVE-2020-5804" ], "details": "Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path prior to using it in file deletion operations. An authenticated, remote attacker can leverage this vulnerability to delete arbitrary remote files as SYSTEM or root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4325-8w9c-7p9p/GHSA-4325-8w9c-7p9p.json b/advisories/unreviewed/2022/05/GHSA-4325-8w9c-7p9p/GHSA-4325-8w9c-7p9p.json index 01fade55434..d848b3ebf94 100644 --- a/advisories/unreviewed/2022/05/GHSA-4325-8w9c-7p9p/GHSA-4325-8w9c-7p9p.json +++ b/advisories/unreviewed/2022/05/GHSA-4325-8w9c-7p9p/GHSA-4325-8w9c-7p9p.json @@ -7,12 +7,8 @@ "CVE-2021-1051" ], "details": "NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an operation is performed which may lead to denial of service or escalation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43m5-x878-2c62/GHSA-43m5-x878-2c62.json b/advisories/unreviewed/2022/05/GHSA-43m5-x878-2c62/GHSA-43m5-x878-2c62.json index 109d5d59a77..dac0ec7c941 100644 --- a/advisories/unreviewed/2022/05/GHSA-43m5-x878-2c62/GHSA-43m5-x878-2c62.json +++ b/advisories/unreviewed/2022/05/GHSA-43m5-x878-2c62/GHSA-43m5-x878-2c62.json @@ -7,12 +7,8 @@ "CVE-2020-26046" ], "details": "FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4456-4h4r-g935/GHSA-4456-4h4r-g935.json b/advisories/unreviewed/2022/05/GHSA-4456-4h4r-g935/GHSA-4456-4h4r-g935.json index 4b9960566ec..42f38ccf92d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4456-4h4r-g935/GHSA-4456-4h4r-g935.json +++ b/advisories/unreviewed/2022/05/GHSA-4456-4h4r-g935/GHSA-4456-4h4r-g935.json @@ -7,12 +7,8 @@ "CVE-2021-21107" ], "details": "Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44fv-7q57-6rj5/GHSA-44fv-7q57-6rj5.json b/advisories/unreviewed/2022/05/GHSA-44fv-7q57-6rj5/GHSA-44fv-7q57-6rj5.json index 981c806844a..5863bf5722f 100644 --- a/advisories/unreviewed/2022/05/GHSA-44fv-7q57-6rj5/GHSA-44fv-7q57-6rj5.json +++ b/advisories/unreviewed/2022/05/GHSA-44fv-7q57-6rj5/GHSA-44fv-7q57-6rj5.json @@ -7,12 +7,8 @@ "CVE-2021-23932" ], "details": "OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44rv-rqpv-5h55/GHSA-44rv-rqpv-5h55.json b/advisories/unreviewed/2022/05/GHSA-44rv-rqpv-5h55/GHSA-44rv-rqpv-5h55.json index d36b0ae1862..58cb1629a21 100644 --- a/advisories/unreviewed/2022/05/GHSA-44rv-rqpv-5h55/GHSA-44rv-rqpv-5h55.json +++ b/advisories/unreviewed/2022/05/GHSA-44rv-rqpv-5h55/GHSA-44rv-rqpv-5h55.json @@ -7,12 +7,8 @@ "CVE-2020-10207" ], "details": "Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve and modify the device settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4563-pqrg-7hcj/GHSA-4563-pqrg-7hcj.json b/advisories/unreviewed/2022/05/GHSA-4563-pqrg-7hcj/GHSA-4563-pqrg-7hcj.json index c5faed0f0fc..21e77d78b2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4563-pqrg-7hcj/GHSA-4563-pqrg-7hcj.json +++ b/advisories/unreviewed/2022/05/GHSA-4563-pqrg-7hcj/GHSA-4563-pqrg-7hcj.json @@ -7,12 +7,8 @@ "CVE-2021-21459" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-456m-cqc5-g822/GHSA-456m-cqc5-g822.json b/advisories/unreviewed/2022/05/GHSA-456m-cqc5-g822/GHSA-456m-cqc5-g822.json index 4cacca2db3f..b0c334e7af4 100644 --- a/advisories/unreviewed/2022/05/GHSA-456m-cqc5-g822/GHSA-456m-cqc5-g822.json +++ b/advisories/unreviewed/2022/05/GHSA-456m-cqc5-g822/GHSA-456m-cqc5-g822.json @@ -7,12 +7,8 @@ "CVE-2021-0208" ], "details": "An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of Service (DoS) condition. Continued receipt of the packet will sustain the Denial of Service. This issue affects: Juniper Networks Junos OS: All versions prior to 17.3R3-S10 except 15.1X49-D240 for SRX series; 17.4 versions prior to 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.3 versions prior to 18.3R3-S2; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S2; 19.1 versions prior to 19.1R1-S5, 19.1R3-S3; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R2-S5, 19.3R3; 19.4 versions prior to 19.4R2-S2, 19.4R3-S1; 20.1 versions prior to 20.1R1-S4, 20.1R2; 15.1X49 versions prior to 15.1X49-D240 on SRX Series. Juniper Networks Junos OS Evolved: 19.3 versions prior to 19.3R2-S5-EVO; 19.4 versions prior to 19.4R2-S2-EVO; 20.1 versions prior to 20.1R1-S4-EVO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45j6-22mm-5x5p/GHSA-45j6-22mm-5x5p.json b/advisories/unreviewed/2022/05/GHSA-45j6-22mm-5x5p/GHSA-45j6-22mm-5x5p.json index ef0df6e348d..2468a174df9 100644 --- a/advisories/unreviewed/2022/05/GHSA-45j6-22mm-5x5p/GHSA-45j6-22mm-5x5p.json +++ b/advisories/unreviewed/2022/05/GHSA-45j6-22mm-5x5p/GHSA-45j6-22mm-5x5p.json @@ -7,12 +7,8 @@ "CVE-2021-1185" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46qp-3938-63jv/GHSA-46qp-3938-63jv.json b/advisories/unreviewed/2022/05/GHSA-46qp-3938-63jv/GHSA-46qp-3938-63jv.json index 359a4de8c88..1334f894195 100644 --- a/advisories/unreviewed/2022/05/GHSA-46qp-3938-63jv/GHSA-46qp-3938-63jv.json +++ b/advisories/unreviewed/2022/05/GHSA-46qp-3938-63jv/GHSA-46qp-3938-63jv.json @@ -7,12 +7,8 @@ "CVE-2020-0471" ], "details": "In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-169327567.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46vq-m3cv-fvrh/GHSA-46vq-m3cv-fvrh.json b/advisories/unreviewed/2022/05/GHSA-46vq-m3cv-fvrh/GHSA-46vq-m3cv-fvrh.json index 2a32581b295..0973f435679 100644 --- a/advisories/unreviewed/2022/05/GHSA-46vq-m3cv-fvrh/GHSA-46vq-m3cv-fvrh.json +++ b/advisories/unreviewed/2022/05/GHSA-46vq-m3cv-fvrh/GHSA-46vq-m3cv-fvrh.json @@ -7,12 +7,8 @@ "CVE-2020-26972" ], "details": "The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-473q-jggx-5qr3/GHSA-473q-jggx-5qr3.json b/advisories/unreviewed/2022/05/GHSA-473q-jggx-5qr3/GHSA-473q-jggx-5qr3.json index b8cb50ff9d4..536a9abc40f 100644 --- a/advisories/unreviewed/2022/05/GHSA-473q-jggx-5qr3/GHSA-473q-jggx-5qr3.json +++ b/advisories/unreviewed/2022/05/GHSA-473q-jggx-5qr3/GHSA-473q-jggx-5qr3.json @@ -7,12 +7,8 @@ "CVE-2021-0301" ], "details": "In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android SoC; Android ID: A-172514667.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-485r-9478-c3ww/GHSA-485r-9478-c3ww.json b/advisories/unreviewed/2022/05/GHSA-485r-9478-c3ww/GHSA-485r-9478-c3ww.json index 9f41b70e985..bac7a767b0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-485r-9478-c3ww/GHSA-485r-9478-c3ww.json +++ b/advisories/unreviewed/2022/05/GHSA-485r-9478-c3ww/GHSA-485r-9478-c3ww.json @@ -7,12 +7,8 @@ "CVE-2020-16045" ], "details": "Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48wj-mfx4-4qc2/GHSA-48wj-mfx4-4qc2.json b/advisories/unreviewed/2022/05/GHSA-48wj-mfx4-4qc2/GHSA-48wj-mfx4-4qc2.json index 42cec63adf0..d4eaeef2a08 100644 --- a/advisories/unreviewed/2022/05/GHSA-48wj-mfx4-4qc2/GHSA-48wj-mfx4-4qc2.json +++ b/advisories/unreviewed/2022/05/GHSA-48wj-mfx4-4qc2/GHSA-48wj-mfx4-4qc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48xm-jq3f-3xjx/GHSA-48xm-jq3f-3xjx.json b/advisories/unreviewed/2022/05/GHSA-48xm-jq3f-3xjx/GHSA-48xm-jq3f-3xjx.json index c41eb8e8dcc..6055971e31b 100644 --- a/advisories/unreviewed/2022/05/GHSA-48xm-jq3f-3xjx/GHSA-48xm-jq3f-3xjx.json +++ b/advisories/unreviewed/2022/05/GHSA-48xm-jq3f-3xjx/GHSA-48xm-jq3f-3xjx.json @@ -7,12 +7,8 @@ "CVE-2020-35950" ], "details": "An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49ch-rg68-hqhr/GHSA-49ch-rg68-hqhr.json b/advisories/unreviewed/2022/05/GHSA-49ch-rg68-hqhr/GHSA-49ch-rg68-hqhr.json index bb39cdc3642..7f0b79a102e 100644 --- a/advisories/unreviewed/2022/05/GHSA-49ch-rg68-hqhr/GHSA-49ch-rg68-hqhr.json +++ b/advisories/unreviewed/2022/05/GHSA-49ch-rg68-hqhr/GHSA-49ch-rg68-hqhr.json @@ -7,12 +7,8 @@ "CVE-2021-1197" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4chx-4wv3-ph6v/GHSA-4chx-4wv3-ph6v.json b/advisories/unreviewed/2022/05/GHSA-4chx-4wv3-ph6v/GHSA-4chx-4wv3-ph6v.json index be6d7aaa860..94f1dd0f199 100644 --- a/advisories/unreviewed/2022/05/GHSA-4chx-4wv3-ph6v/GHSA-4chx-4wv3-ph6v.json +++ b/advisories/unreviewed/2022/05/GHSA-4chx-4wv3-ph6v/GHSA-4chx-4wv3-ph6v.json @@ -7,12 +7,8 @@ "CVE-2020-29016" ], "details": "A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4crf-hf39-p7m7/GHSA-4crf-hf39-p7m7.json b/advisories/unreviewed/2022/05/GHSA-4crf-hf39-p7m7/GHSA-4crf-hf39-p7m7.json index 7b0daa5626c..635f7f0bf7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4crf-hf39-p7m7/GHSA-4crf-hf39-p7m7.json +++ b/advisories/unreviewed/2022/05/GHSA-4crf-hf39-p7m7/GHSA-4crf-hf39-p7m7.json @@ -7,12 +7,8 @@ "CVE-2021-1151" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f7j-5j3r-xxc5/GHSA-4f7j-5j3r-xxc5.json b/advisories/unreviewed/2022/05/GHSA-4f7j-5j3r-xxc5/GHSA-4f7j-5j3r-xxc5.json index cbf233a2ad8..e2de8a5ed0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f7j-5j3r-xxc5/GHSA-4f7j-5j3r-xxc5.json +++ b/advisories/unreviewed/2022/05/GHSA-4f7j-5j3r-xxc5/GHSA-4f7j-5j3r-xxc5.json @@ -7,12 +7,8 @@ "CVE-2020-35808" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.63, DM200 before 1.0.0.61, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.68, and WNR2000v5 before 1.0.0.66.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fhq-wm67-3x2v/GHSA-4fhq-wm67-3x2v.json b/advisories/unreviewed/2022/05/GHSA-4fhq-wm67-3x2v/GHSA-4fhq-wm67-3x2v.json index 49454256008..5b3cb07ddfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fhq-wm67-3x2v/GHSA-4fhq-wm67-3x2v.json +++ b/advisories/unreviewed/2022/05/GHSA-4fhq-wm67-3x2v/GHSA-4fhq-wm67-3x2v.json @@ -7,12 +7,8 @@ "CVE-2020-16028" ], "details": "Heap buffer overflow in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gh5-fw3f-vm8m/GHSA-4gh5-fw3f-vm8m.json b/advisories/unreviewed/2022/05/GHSA-4gh5-fw3f-vm8m/GHSA-4gh5-fw3f-vm8m.json index 559103b5d74..c87b66de0b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gh5-fw3f-vm8m/GHSA-4gh5-fw3f-vm8m.json +++ b/advisories/unreviewed/2022/05/GHSA-4gh5-fw3f-vm8m/GHSA-4gh5-fw3f-vm8m.json @@ -7,12 +7,8 @@ "CVE-2021-0210" ], "details": "An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevate their privileges over the target system through opportunistic use of an authenticated users session. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S17; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S6; 18.3 versions prior to 18.3R2-S4, 18.3R3-S4; 18.4 versions prior to 18.4R2-S5, 18.4R3-S5; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R1-S5, 19.2R3, 19.2R3-S1; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2-S2, 19.4R3; 20.1 versions prior to 20.1R1-S4, 20.1R2; 20.2 versions prior to 20.2R1-S1, 20.2R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h83-62ff-59wh/GHSA-4h83-62ff-59wh.json b/advisories/unreviewed/2022/05/GHSA-4h83-62ff-59wh/GHSA-4h83-62ff-59wh.json index 5d0f506d7c2..0995fbd7896 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h83-62ff-59wh/GHSA-4h83-62ff-59wh.json +++ b/advisories/unreviewed/2022/05/GHSA-4h83-62ff-59wh/GHSA-4h83-62ff-59wh.json @@ -7,12 +7,8 @@ "CVE-2018-20313" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hw8-23gq-m2qg/GHSA-4hw8-23gq-m2qg.json b/advisories/unreviewed/2022/05/GHSA-4hw8-23gq-m2qg/GHSA-4hw8-23gq-m2qg.json index 041b0b212ce..9f20ee421e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hw8-23gq-m2qg/GHSA-4hw8-23gq-m2qg.json +++ b/advisories/unreviewed/2022/05/GHSA-4hw8-23gq-m2qg/GHSA-4hw8-23gq-m2qg.json @@ -7,12 +7,8 @@ "CVE-2021-1145" ], "details": "A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the affected device. The vulnerability is due to insecure handling of symbolic links. An attacker could exploit this vulnerability by sending a crafted SFTP command to an affected device. A successful exploit could allow the attacker to read arbitrary files on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jc3-3v3g-h745/GHSA-4jc3-3v3g-h745.json b/advisories/unreviewed/2022/05/GHSA-4jc3-3v3g-h745/GHSA-4jc3-3v3g-h745.json index c6f0a1f54cc..b946f8c6d55 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jc3-3v3g-h745/GHSA-4jc3-3v3g-h745.json +++ b/advisories/unreviewed/2022/05/GHSA-4jc3-3v3g-h745/GHSA-4jc3-3v3g-h745.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jvq-wc69-2rqj/GHSA-4jvq-wc69-2rqj.json b/advisories/unreviewed/2022/05/GHSA-4jvq-wc69-2rqj/GHSA-4jvq-wc69-2rqj.json index 4d63b36504a..5d7d433a2e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jvq-wc69-2rqj/GHSA-4jvq-wc69-2rqj.json +++ b/advisories/unreviewed/2022/05/GHSA-4jvq-wc69-2rqj/GHSA-4jvq-wc69-2rqj.json @@ -7,12 +7,8 @@ "CVE-2020-5801" ], "details": "An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mfr-jgjm-cvx8/GHSA-4mfr-jgjm-cvx8.json b/advisories/unreviewed/2022/05/GHSA-4mfr-jgjm-cvx8/GHSA-4mfr-jgjm-cvx8.json index 9f959126a09..b47b6fc0dce 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mfr-jgjm-cvx8/GHSA-4mfr-jgjm-cvx8.json +++ b/advisories/unreviewed/2022/05/GHSA-4mfr-jgjm-cvx8/GHSA-4mfr-jgjm-cvx8.json @@ -7,12 +7,8 @@ "CVE-2020-13116" ], "details": "OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p43-cv9p-j29m/GHSA-4p43-cv9p-j29m.json b/advisories/unreviewed/2022/05/GHSA-4p43-cv9p-j29m/GHSA-4p43-cv9p-j29m.json index caf64d6735d..896f21f1df8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p43-cv9p-j29m/GHSA-4p43-cv9p-j29m.json +++ b/advisories/unreviewed/2022/05/GHSA-4p43-cv9p-j29m/GHSA-4p43-cv9p-j29m.json @@ -7,12 +7,8 @@ "CVE-2019-16962" ], "details": "Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pjq-cx2j-g6rm/GHSA-4pjq-cx2j-g6rm.json b/advisories/unreviewed/2022/05/GHSA-4pjq-cx2j-g6rm/GHSA-4pjq-cx2j-g6rm.json index 38150bbdd41..71912600a77 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pjq-cx2j-g6rm/GHSA-4pjq-cx2j-g6rm.json +++ b/advisories/unreviewed/2022/05/GHSA-4pjq-cx2j-g6rm/GHSA-4pjq-cx2j-g6rm.json @@ -7,12 +7,8 @@ "CVE-2020-35833" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qc6-wq65-6w7q/GHSA-4qc6-wq65-6w7q.json b/advisories/unreviewed/2022/05/GHSA-4qc6-wq65-6w7q/GHSA-4qc6-wq65-6w7q.json index ff0e5aea9ca..691bd9d0833 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qc6-wq65-6w7q/GHSA-4qc6-wq65-6w7q.json +++ b/advisories/unreviewed/2022/05/GHSA-4qc6-wq65-6w7q/GHSA-4qc6-wq65-6w7q.json @@ -7,12 +7,8 @@ "CVE-2021-3005" ], "details": "MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qr3-ph4h-wwpf/GHSA-4qr3-ph4h-wwpf.json b/advisories/unreviewed/2022/05/GHSA-4qr3-ph4h-wwpf/GHSA-4qr3-ph4h-wwpf.json index 84c4dce783f..fd5522c4b89 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qr3-ph4h-wwpf/GHSA-4qr3-ph4h-wwpf.json +++ b/advisories/unreviewed/2022/05/GHSA-4qr3-ph4h-wwpf/GHSA-4qr3-ph4h-wwpf.json @@ -7,12 +7,8 @@ "CVE-2020-26984" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of JT files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qr9-9cg9-9gvw/GHSA-4qr9-9cg9-9gvw.json b/advisories/unreviewed/2022/05/GHSA-4qr9-9cg9-9gvw/GHSA-4qr9-9cg9-9gvw.json index 7ca290b031b..f52f8110d84 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qr9-9cg9-9gvw/GHSA-4qr9-9cg9-9gvw.json +++ b/advisories/unreviewed/2022/05/GHSA-4qr9-9cg9-9gvw/GHSA-4qr9-9cg9-9gvw.json @@ -7,12 +7,8 @@ "CVE-2020-36157" ], "details": "An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (or any custom Ultimate Member role) and effectively be granted those privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r7v-vq9j-hv62/GHSA-4r7v-vq9j-hv62.json b/advisories/unreviewed/2022/05/GHSA-4r7v-vq9j-hv62/GHSA-4r7v-vq9j-hv62.json index fb5523e9d40..1d5859565f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r7v-vq9j-hv62/GHSA-4r7v-vq9j-hv62.json +++ b/advisories/unreviewed/2022/05/GHSA-4r7v-vq9j-hv62/GHSA-4r7v-vq9j-hv62.json @@ -7,12 +7,8 @@ "CVE-2021-1127" ], "details": "A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker could exploit this vulnerability by modifying a log file with malicious code and getting a user to view the modified log file. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vx6-93q8-5vcf/GHSA-4vx6-93q8-5vcf.json b/advisories/unreviewed/2022/05/GHSA-4vx6-93q8-5vcf/GHSA-4vx6-93q8-5vcf.json index 0389aaedba1..f045b4630fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vx6-93q8-5vcf/GHSA-4vx6-93q8-5vcf.json +++ b/advisories/unreviewed/2022/05/GHSA-4vx6-93q8-5vcf/GHSA-4vx6-93q8-5vcf.json @@ -7,12 +7,8 @@ "CVE-2021-1209" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x5r-86c2-22gq/GHSA-4x5r-86c2-22gq.json b/advisories/unreviewed/2022/05/GHSA-4x5r-86c2-22gq/GHSA-4x5r-86c2-22gq.json index ff07da6c663..d2fa8fa122d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x5r-86c2-22gq/GHSA-4x5r-86c2-22gq.json +++ b/advisories/unreviewed/2022/05/GHSA-4x5r-86c2-22gq/GHSA-4x5r-86c2-22gq.json @@ -7,12 +7,8 @@ "CVE-2021-1199" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-525v-m682-5h53/GHSA-525v-m682-5h53.json b/advisories/unreviewed/2022/05/GHSA-525v-m682-5h53/GHSA-525v-m682-5h53.json index a2814870b7b..f7909ee7c51 100644 --- a/advisories/unreviewed/2022/05/GHSA-525v-m682-5h53/GHSA-525v-m682-5h53.json +++ b/advisories/unreviewed/2022/05/GHSA-525v-m682-5h53/GHSA-525v-m682-5h53.json @@ -7,12 +7,8 @@ "CVE-2020-35930" ], "details": "Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-526j-q77m-37w5/GHSA-526j-q77m-37w5.json b/advisories/unreviewed/2022/05/GHSA-526j-q77m-37w5/GHSA-526j-q77m-37w5.json index 561661a2e7a..17279f3d425 100644 --- a/advisories/unreviewed/2022/05/GHSA-526j-q77m-37w5/GHSA-526j-q77m-37w5.json +++ b/advisories/unreviewed/2022/05/GHSA-526j-q77m-37w5/GHSA-526j-q77m-37w5.json @@ -7,12 +7,8 @@ "CVE-2021-0318" ], "details": "In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-8.1, Android-10, Android-11; Android ID: A-168211968.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52f9-w6mx-8654/GHSA-52f9-w6mx-8654.json b/advisories/unreviewed/2022/05/GHSA-52f9-w6mx-8654/GHSA-52f9-w6mx-8654.json index a3f554cf479..56949f10ae2 100644 --- a/advisories/unreviewed/2022/05/GHSA-52f9-w6mx-8654/GHSA-52f9-w6mx-8654.json +++ b/advisories/unreviewed/2022/05/GHSA-52f9-w6mx-8654/GHSA-52f9-w6mx-8654.json @@ -7,12 +7,8 @@ "CVE-2021-1065" ], "details": "NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53fv-h732-7vpp/GHSA-53fv-h732-7vpp.json b/advisories/unreviewed/2022/05/GHSA-53fv-h732-7vpp/GHSA-53fv-h732-7vpp.json index fd4a38d0c9d..be11690a7a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-53fv-h732-7vpp/GHSA-53fv-h732-7vpp.json +++ b/advisories/unreviewed/2022/05/GHSA-53fv-h732-7vpp/GHSA-53fv-h732-7vpp.json @@ -7,12 +7,8 @@ "CVE-2021-23931" ], "details": "OX App Suite through 7.10.4 allows XSS via an inline binary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53jq-rch4-w6wr/GHSA-53jq-rch4-w6wr.json b/advisories/unreviewed/2022/05/GHSA-53jq-rch4-w6wr/GHSA-53jq-rch4-w6wr.json index 1600070a516..d7076583cce 100644 --- a/advisories/unreviewed/2022/05/GHSA-53jq-rch4-w6wr/GHSA-53jq-rch4-w6wr.json +++ b/advisories/unreviewed/2022/05/GHSA-53jq-rch4-w6wr/GHSA-53jq-rch4-w6wr.json @@ -7,12 +7,8 @@ "CVE-2020-29018" ], "details": "A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53r8-v6vr-f62f/GHSA-53r8-v6vr-f62f.json b/advisories/unreviewed/2022/05/GHSA-53r8-v6vr-f62f/GHSA-53r8-v6vr-f62f.json index e29db681e9e..63a63e00f0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-53r8-v6vr-f62f/GHSA-53r8-v6vr-f62f.json +++ b/advisories/unreviewed/2022/05/GHSA-53r8-v6vr-f62f/GHSA-53r8-v6vr-f62f.json @@ -7,12 +7,8 @@ "CVE-2021-1201" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-543r-2767-7774/GHSA-543r-2767-7774.json b/advisories/unreviewed/2022/05/GHSA-543r-2767-7774/GHSA-543r-2767-7774.json index 97107d73086..fd820809695 100644 --- a/advisories/unreviewed/2022/05/GHSA-543r-2767-7774/GHSA-543r-2767-7774.json +++ b/advisories/unreviewed/2022/05/GHSA-543r-2767-7774/GHSA-543r-2767-7774.json @@ -7,12 +7,8 @@ "CVE-2021-21111" ], "details": "Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5534-3qgp-mmmx/GHSA-5534-3qgp-mmmx.json b/advisories/unreviewed/2022/05/GHSA-5534-3qgp-mmmx/GHSA-5534-3qgp-mmmx.json index 3acc04a1e05..5fc4a8d9e4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5534-3qgp-mmmx/GHSA-5534-3qgp-mmmx.json +++ b/advisories/unreviewed/2022/05/GHSA-5534-3qgp-mmmx/GHSA-5534-3qgp-mmmx.json @@ -7,12 +7,8 @@ "CVE-2020-4604" ], "details": "IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 184861.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55fr-5wq7-grv8/GHSA-55fr-5wq7-grv8.json b/advisories/unreviewed/2022/05/GHSA-55fr-5wq7-grv8/GHSA-55fr-5wq7-grv8.json index fae3ad7044c..32e6f3e92e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-55fr-5wq7-grv8/GHSA-55fr-5wq7-grv8.json +++ b/advisories/unreviewed/2022/05/GHSA-55fr-5wq7-grv8/GHSA-55fr-5wq7-grv8.json @@ -7,12 +7,8 @@ "CVE-2021-1175" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55v7-pmqj-6x6g/GHSA-55v7-pmqj-6x6g.json b/advisories/unreviewed/2022/05/GHSA-55v7-pmqj-6x6g/GHSA-55v7-pmqj-6x6g.json index 69229621df0..a44d6dfe9df 100644 --- a/advisories/unreviewed/2022/05/GHSA-55v7-pmqj-6x6g/GHSA-55v7-pmqj-6x6g.json +++ b/advisories/unreviewed/2022/05/GHSA-55v7-pmqj-6x6g/GHSA-55v7-pmqj-6x6g.json @@ -7,12 +7,8 @@ "CVE-2020-35829" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56cp-9m37-vqw4/GHSA-56cp-9m37-vqw4.json b/advisories/unreviewed/2022/05/GHSA-56cp-9m37-vqw4/GHSA-56cp-9m37-vqw4.json index 250b1d137bd..2179fb20499 100644 --- a/advisories/unreviewed/2022/05/GHSA-56cp-9m37-vqw4/GHSA-56cp-9m37-vqw4.json +++ b/advisories/unreviewed/2022/05/GHSA-56cp-9m37-vqw4/GHSA-56cp-9m37-vqw4.json @@ -7,12 +7,8 @@ "CVE-2020-11833" ], "details": "In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write does not check the parameter len which causes a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56v6-8r67-xw4x/GHSA-56v6-8r67-xw4x.json b/advisories/unreviewed/2022/05/GHSA-56v6-8r67-xw4x/GHSA-56v6-8r67-xw4x.json index 975a7688eff..796a196f480 100644 --- a/advisories/unreviewed/2022/05/GHSA-56v6-8r67-xw4x/GHSA-56v6-8r67-xw4x.json +++ b/advisories/unreviewed/2022/05/GHSA-56v6-8r67-xw4x/GHSA-56v6-8r67-xw4x.json @@ -7,12 +7,8 @@ "CVE-2020-4663" ], "details": "IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186234.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5745-c668-f862/GHSA-5745-c668-f862.json b/advisories/unreviewed/2022/05/GHSA-5745-c668-f862/GHSA-5745-c668-f862.json index 51438da48fb..83005421f9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5745-c668-f862/GHSA-5745-c668-f862.json +++ b/advisories/unreviewed/2022/05/GHSA-5745-c668-f862/GHSA-5745-c668-f862.json @@ -7,12 +7,8 @@ "CVE-2020-29502" ], "details": "Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-588x-rqx3-m99w/GHSA-588x-rqx3-m99w.json b/advisories/unreviewed/2022/05/GHSA-588x-rqx3-m99w/GHSA-588x-rqx3-m99w.json index 4c0f031dfaa..14d7e9f4e76 100644 --- a/advisories/unreviewed/2022/05/GHSA-588x-rqx3-m99w/GHSA-588x-rqx3-m99w.json +++ b/advisories/unreviewed/2022/05/GHSA-588x-rqx3-m99w/GHSA-588x-rqx3-m99w.json @@ -7,12 +7,8 @@ "CVE-2020-26987" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fxv-93pc-g3cm/GHSA-5fxv-93pc-g3cm.json b/advisories/unreviewed/2022/05/GHSA-5fxv-93pc-g3cm/GHSA-5fxv-93pc-g3cm.json index 511c164aa7d..a9c2b83ee9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fxv-93pc-g3cm/GHSA-5fxv-93pc-g3cm.json +++ b/advisories/unreviewed/2022/05/GHSA-5fxv-93pc-g3cm/GHSA-5fxv-93pc-g3cm.json @@ -7,12 +7,8 @@ "CVE-2020-29501" ], "details": "Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g5r-7m54-r43v/GHSA-5g5r-7m54-r43v.json b/advisories/unreviewed/2022/05/GHSA-5g5r-7m54-r43v/GHSA-5g5r-7m54-r43v.json index 6d0cabb35e5..58b233aff74 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g5r-7m54-r43v/GHSA-5g5r-7m54-r43v.json +++ b/advisories/unreviewed/2022/05/GHSA-5g5r-7m54-r43v/GHSA-5g5r-7m54-r43v.json @@ -7,12 +7,8 @@ "CVE-2020-36160" ], "details": "An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \\usr\\local\\ssl. This library attempts to load the from \\usr\\local\\ssl\\openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\\. A low privileged user can create a C:\\usr\\local\\ssl\\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data and installed applications, etc. If the system is also an Active Directory domain controller, then this can affect the entire domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5gfx-64wm-m22c/GHSA-5gfx-64wm-m22c.json b/advisories/unreviewed/2022/05/GHSA-5gfx-64wm-m22c/GHSA-5gfx-64wm-m22c.json index 8a7b900d79b..f5a66aebec9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gfx-64wm-m22c/GHSA-5gfx-64wm-m22c.json +++ b/advisories/unreviewed/2022/05/GHSA-5gfx-64wm-m22c/GHSA-5gfx-64wm-m22c.json @@ -7,12 +7,8 @@ "CVE-2020-26035" ], "details": "An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gvh-fv85-vvrf/GHSA-5gvh-fv85-vvrf.json b/advisories/unreviewed/2022/05/GHSA-5gvh-fv85-vvrf/GHSA-5gvh-fv85-vvrf.json index 1ba326230b2..04302ee7615 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gvh-fv85-vvrf/GHSA-5gvh-fv85-vvrf.json +++ b/advisories/unreviewed/2022/05/GHSA-5gvh-fv85-vvrf/GHSA-5gvh-fv85-vvrf.json @@ -7,12 +7,8 @@ "CVE-2021-1216" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jpj-9pv4-xgm6/GHSA-5jpj-9pv4-xgm6.json b/advisories/unreviewed/2022/05/GHSA-5jpj-9pv4-xgm6/GHSA-5jpj-9pv4-xgm6.json index 556c9724a5b..0af2c7f0b9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jpj-9pv4-xgm6/GHSA-5jpj-9pv4-xgm6.json +++ b/advisories/unreviewed/2022/05/GHSA-5jpj-9pv4-xgm6/GHSA-5jpj-9pv4-xgm6.json @@ -7,12 +7,8 @@ "CVE-2021-1131" ], "details": "A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco Discovery Protocol messages are processed. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected IP camera. A successful exploit could allow the attacker to cause the affected IP camera to reload unexpectedly, resulting in a denial of service (DoS) condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jq3-c46h-gv5g/GHSA-5jq3-c46h-gv5g.json b/advisories/unreviewed/2022/05/GHSA-5jq3-c46h-gv5g/GHSA-5jq3-c46h-gv5g.json index f3316c788a0..d64e2c48fb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jq3-c46h-gv5g/GHSA-5jq3-c46h-gv5g.json +++ b/advisories/unreviewed/2022/05/GHSA-5jq3-c46h-gv5g/GHSA-5jq3-c46h-gv5g.json @@ -7,12 +7,8 @@ "CVE-2020-26986" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of JT files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jqg-5g42-mwgq/GHSA-5jqg-5g42-mwgq.json b/advisories/unreviewed/2022/05/GHSA-5jqg-5g42-mwgq/GHSA-5jqg-5g42-mwgq.json index ef9743d491b..fd66643be3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jqg-5g42-mwgq/GHSA-5jqg-5g42-mwgq.json +++ b/advisories/unreviewed/2022/05/GHSA-5jqg-5g42-mwgq/GHSA-5jqg-5g42-mwgq.json @@ -7,12 +7,8 @@ "CVE-2018-11246" ], "details": "K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory Leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m2p-g5x2-c2rf/GHSA-5m2p-g5x2-c2rf.json b/advisories/unreviewed/2022/05/GHSA-5m2p-g5x2-c2rf/GHSA-5m2p-g5x2-c2rf.json index f3f5a170561..bfd69a99ecb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m2p-g5x2-c2rf/GHSA-5m2p-g5x2-c2rf.json +++ b/advisories/unreviewed/2022/05/GHSA-5m2p-g5x2-c2rf/GHSA-5m2p-g5x2-c2rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m6p-6vp8-4hgg/GHSA-5m6p-6vp8-4hgg.json b/advisories/unreviewed/2022/05/GHSA-5m6p-6vp8-4hgg/GHSA-5m6p-6vp8-4hgg.json index 7cbb48587f5..3590ad854ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m6p-6vp8-4hgg/GHSA-5m6p-6vp8-4hgg.json +++ b/advisories/unreviewed/2022/05/GHSA-5m6p-6vp8-4hgg/GHSA-5m6p-6vp8-4hgg.json @@ -7,12 +7,8 @@ "CVE-2020-35837" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m72-x79r-fchm/GHSA-5m72-x79r-fchm.json b/advisories/unreviewed/2022/05/GHSA-5m72-x79r-fchm/GHSA-5m72-x79r-fchm.json index 59b0b157f6b..0c1c61efc88 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m72-x79r-fchm/GHSA-5m72-x79r-fchm.json +++ b/advisories/unreviewed/2022/05/GHSA-5m72-x79r-fchm/GHSA-5m72-x79r-fchm.json @@ -7,12 +7,8 @@ "CVE-2020-4918" ], "details": "IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p8f-8fm7-qwfr/GHSA-5p8f-8fm7-qwfr.json b/advisories/unreviewed/2022/05/GHSA-5p8f-8fm7-qwfr/GHSA-5p8f-8fm7-qwfr.json index 70ad432aa89..91d8b7a85d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p8f-8fm7-qwfr/GHSA-5p8f-8fm7-qwfr.json +++ b/advisories/unreviewed/2022/05/GHSA-5p8f-8fm7-qwfr/GHSA-5p8f-8fm7-qwfr.json @@ -7,12 +7,8 @@ "CVE-2020-26996" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of CG4 files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qjq-mx2m-jmx9/GHSA-5qjq-mx2m-jmx9.json b/advisories/unreviewed/2022/05/GHSA-5qjq-mx2m-jmx9/GHSA-5qjq-mx2m-jmx9.json index 8e71c607e29..fb7657a98d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qjq-mx2m-jmx9/GHSA-5qjq-mx2m-jmx9.json +++ b/advisories/unreviewed/2022/05/GHSA-5qjq-mx2m-jmx9/GHSA-5qjq-mx2m-jmx9.json @@ -7,12 +7,8 @@ "CVE-2020-35131" ], "details": "Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r54-pmvg-4gqx/GHSA-5r54-pmvg-4gqx.json b/advisories/unreviewed/2022/05/GHSA-5r54-pmvg-4gqx/GHSA-5r54-pmvg-4gqx.json index 6f501f8cccb..3291ab50b77 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r54-pmvg-4gqx/GHSA-5r54-pmvg-4gqx.json +++ b/advisories/unreviewed/2022/05/GHSA-5r54-pmvg-4gqx/GHSA-5r54-pmvg-4gqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5rvp-q2j7-h9rj/GHSA-5rvp-q2j7-h9rj.json b/advisories/unreviewed/2022/05/GHSA-5rvp-q2j7-h9rj/GHSA-5rvp-q2j7-h9rj.json index 63a9249aacb..5b40c020465 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rvp-q2j7-h9rj/GHSA-5rvp-q2j7-h9rj.json +++ b/advisories/unreviewed/2022/05/GHSA-5rvp-q2j7-h9rj/GHSA-5rvp-q2j7-h9rj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v8v-xvv6-4rhg/GHSA-5v8v-xvv6-4rhg.json b/advisories/unreviewed/2022/05/GHSA-5v8v-xvv6-4rhg/GHSA-5v8v-xvv6-4rhg.json index adcfc4885b4..c003df64c11 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v8v-xvv6-4rhg/GHSA-5v8v-xvv6-4rhg.json +++ b/advisories/unreviewed/2022/05/GHSA-5v8v-xvv6-4rhg/GHSA-5v8v-xvv6-4rhg.json @@ -7,12 +7,8 @@ "CVE-2021-1213" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w24-r25p-r962/GHSA-5w24-r25p-r962.json b/advisories/unreviewed/2022/05/GHSA-5w24-r25p-r962/GHSA-5w24-r25p-r962.json index 6b8b51c30c1..46ef0b34a12 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w24-r25p-r962/GHSA-5w24-r25p-r962.json +++ b/advisories/unreviewed/2022/05/GHSA-5w24-r25p-r962/GHSA-5w24-r25p-r962.json @@ -7,12 +7,8 @@ "CVE-2021-1206" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w46-q7q8-42rm/GHSA-5w46-q7q8-42rm.json b/advisories/unreviewed/2022/05/GHSA-5w46-q7q8-42rm/GHSA-5w46-q7q8-42rm.json index 66938be841d..323d2967a9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w46-q7q8-42rm/GHSA-5w46-q7q8-42rm.json +++ b/advisories/unreviewed/2022/05/GHSA-5w46-q7q8-42rm/GHSA-5w46-q7q8-42rm.json @@ -7,12 +7,8 @@ "CVE-2021-2043" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wpm-phm2-2mfm/GHSA-5wpm-phm2-2mfm.json b/advisories/unreviewed/2022/05/GHSA-5wpm-phm2-2mfm/GHSA-5wpm-phm2-2mfm.json index 801747a1746..60dff43418e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wpm-phm2-2mfm/GHSA-5wpm-phm2-2mfm.json +++ b/advisories/unreviewed/2022/05/GHSA-5wpm-phm2-2mfm/GHSA-5wpm-phm2-2mfm.json @@ -7,12 +7,8 @@ "CVE-2020-24638" ], "details": "Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x44-6vjc-wrhm/GHSA-5x44-6vjc-wrhm.json b/advisories/unreviewed/2022/05/GHSA-5x44-6vjc-wrhm/GHSA-5x44-6vjc-wrhm.json index e2dc7144f31..e393e1c62dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x44-6vjc-wrhm/GHSA-5x44-6vjc-wrhm.json +++ b/advisories/unreviewed/2022/05/GHSA-5x44-6vjc-wrhm/GHSA-5x44-6vjc-wrhm.json @@ -7,12 +7,8 @@ "CVE-2020-24641" ], "details": "In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately gain administrative access on the web administrative interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64ch-64p7-9mrx/GHSA-64ch-64p7-9mrx.json b/advisories/unreviewed/2022/05/GHSA-64ch-64p7-9mrx/GHSA-64ch-64p7-9mrx.json index be970fd8f04..8a55e99668f 100644 --- a/advisories/unreviewed/2022/05/GHSA-64ch-64p7-9mrx/GHSA-64ch-64p7-9mrx.json +++ b/advisories/unreviewed/2022/05/GHSA-64ch-64p7-9mrx/GHSA-64ch-64p7-9mrx.json @@ -7,12 +7,8 @@ "CVE-2021-0203" ], "details": "On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. Storm Control enables the device to monitor traffic levels and to drop broadcast, multicast, and unknown unicast packets when a specified traffic level is exceeded, thus preventing packets from proliferating and degrading the LAN. Note: this issue does not affect EX2200, EX3300, EX4200, and EX9200 Series. This issue affects Juniper Networks Junos OS on EX Series and QFX5K Series: 15.1 versions prior to 15.1R7-S7; 16.1 versions prior to 16.1R7-S8; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R2-S5, 18.4R3-S3; 19.1 versions prior to 19.1R2-S2, 19.1R3-S2; 19.2 versions prior to 19.2R1-S5, 19.2R2-S1, 19.2R3; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2-S1, 19.4R3; 20.1 versions prior to 20.1R1-S2, 20.1R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6553-8h6r-vxxh/GHSA-6553-8h6r-vxxh.json b/advisories/unreviewed/2022/05/GHSA-6553-8h6r-vxxh/GHSA-6553-8h6r-vxxh.json index 7516326e475..10400af692c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6553-8h6r-vxxh/GHSA-6553-8h6r-vxxh.json +++ b/advisories/unreviewed/2022/05/GHSA-6553-8h6r-vxxh/GHSA-6553-8h6r-vxxh.json @@ -7,12 +7,8 @@ "CVE-2020-25846" ], "details": "The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-656q-3mvc-v648/GHSA-656q-3mvc-v648.json b/advisories/unreviewed/2022/05/GHSA-656q-3mvc-v648/GHSA-656q-3mvc-v648.json index 25ec65ca950..f7644bd33e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-656q-3mvc-v648/GHSA-656q-3mvc-v648.json +++ b/advisories/unreviewed/2022/05/GHSA-656q-3mvc-v648/GHSA-656q-3mvc-v648.json @@ -7,12 +7,8 @@ "CVE-2021-1237" ], "details": "A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by inserting a configuration file in a specific path in the system which, in turn, causes a malicious DLL file to be loaded when the application starts. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6586-wxp2-vw2f/GHSA-6586-wxp2-vw2f.json b/advisories/unreviewed/2022/05/GHSA-6586-wxp2-vw2f/GHSA-6586-wxp2-vw2f.json index e93eb625592..b25af16ef90 100644 --- a/advisories/unreviewed/2022/05/GHSA-6586-wxp2-vw2f/GHSA-6586-wxp2-vw2f.json +++ b/advisories/unreviewed/2022/05/GHSA-6586-wxp2-vw2f/GHSA-6586-wxp2-vw2f.json @@ -7,12 +7,8 @@ "CVE-2020-35825" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65pf-jw4p-p3f8/GHSA-65pf-jw4p-p3f8.json b/advisories/unreviewed/2022/05/GHSA-65pf-jw4p-p3f8/GHSA-65pf-jw4p-p3f8.json index 39e6fca1c86..70d0343e534 100644 --- a/advisories/unreviewed/2022/05/GHSA-65pf-jw4p-p3f8/GHSA-65pf-jw4p-p3f8.json +++ b/advisories/unreviewed/2022/05/GHSA-65pf-jw4p-p3f8/GHSA-65pf-jw4p-p3f8.json @@ -7,12 +7,8 @@ "CVE-2020-24902" ], "details": "Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65vg-v22r-h32v/GHSA-65vg-v22r-h32v.json b/advisories/unreviewed/2022/05/GHSA-65vg-v22r-h32v/GHSA-65vg-v22r-h32v.json index 662f89b8fd2..0978ae40a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-65vg-v22r-h32v/GHSA-65vg-v22r-h32v.json +++ b/advisories/unreviewed/2022/05/GHSA-65vg-v22r-h32v/GHSA-65vg-v22r-h32v.json @@ -7,12 +7,8 @@ "CVE-2020-35113" ], "details": "Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66g2-4363-r37f/GHSA-66g2-4363-r37f.json b/advisories/unreviewed/2022/05/GHSA-66g2-4363-r37f/GHSA-66g2-4363-r37f.json index a4752140b3b..9bf4d3584d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-66g2-4363-r37f/GHSA-66g2-4363-r37f.json +++ b/advisories/unreviewed/2022/05/GHSA-66g2-4363-r37f/GHSA-66g2-4363-r37f.json @@ -7,12 +7,8 @@ "CVE-2019-16960" ], "details": "SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66j4-v3cw-v3vv/GHSA-66j4-v3cw-v3vv.json b/advisories/unreviewed/2022/05/GHSA-66j4-v3cw-v3vv/GHSA-66j4-v3cw-v3vv.json index b622371ddf6..bb2e4744134 100644 --- a/advisories/unreviewed/2022/05/GHSA-66j4-v3cw-v3vv/GHSA-66j4-v3cw-v3vv.json +++ b/advisories/unreviewed/2022/05/GHSA-66j4-v3cw-v3vv/GHSA-66j4-v3cw-v3vv.json @@ -7,12 +7,8 @@ "CVE-2020-35824" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66v8-hp22-2q37/GHSA-66v8-hp22-2q37.json b/advisories/unreviewed/2022/05/GHSA-66v8-hp22-2q37/GHSA-66v8-hp22-2q37.json index acd8f275084..d3ef5450e01 100644 --- a/advisories/unreviewed/2022/05/GHSA-66v8-hp22-2q37/GHSA-66v8-hp22-2q37.json +++ b/advisories/unreviewed/2022/05/GHSA-66v8-hp22-2q37/GHSA-66v8-hp22-2q37.json @@ -7,12 +7,8 @@ "CVE-2020-27263" ], "details": "KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-674c-q4r5-6548/GHSA-674c-q4r5-6548.json b/advisories/unreviewed/2022/05/GHSA-674c-q4r5-6548/GHSA-674c-q4r5-6548.json index c0e2a0a2069..2817f772d83 100644 --- a/advisories/unreviewed/2022/05/GHSA-674c-q4r5-6548/GHSA-674c-q4r5-6548.json +++ b/advisories/unreviewed/2022/05/GHSA-674c-q4r5-6548/GHSA-674c-q4r5-6548.json @@ -7,12 +7,8 @@ "CVE-2021-1280" ], "details": "\n A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need valid credentials on the Windows system.\n This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with SYSTEM privileges.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6753-4jpx-jv2w/GHSA-6753-4jpx-jv2w.json b/advisories/unreviewed/2022/05/GHSA-6753-4jpx-jv2w/GHSA-6753-4jpx-jv2w.json index 004ecac9ee2..a5c12db0a42 100644 --- a/advisories/unreviewed/2022/05/GHSA-6753-4jpx-jv2w/GHSA-6753-4jpx-jv2w.json +++ b/advisories/unreviewed/2022/05/GHSA-6753-4jpx-jv2w/GHSA-6753-4jpx-jv2w.json @@ -7,12 +7,8 @@ "CVE-2020-35944" ], "details": "An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67c2-jfqm-8gqc/GHSA-67c2-jfqm-8gqc.json b/advisories/unreviewed/2022/05/GHSA-67c2-jfqm-8gqc/GHSA-67c2-jfqm-8gqc.json index f642419a1bf..424afc6ba2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-67c2-jfqm-8gqc/GHSA-67c2-jfqm-8gqc.json +++ b/advisories/unreviewed/2022/05/GHSA-67c2-jfqm-8gqc/GHSA-67c2-jfqm-8gqc.json @@ -7,12 +7,8 @@ "CVE-2020-26988" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67pr-qr62-6vcm/GHSA-67pr-qr62-6vcm.json b/advisories/unreviewed/2022/05/GHSA-67pr-qr62-6vcm/GHSA-67pr-qr62-6vcm.json index 17ea85b5537..72f3c2850e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-67pr-qr62-6vcm/GHSA-67pr-qr62-6vcm.json +++ b/advisories/unreviewed/2022/05/GHSA-67pr-qr62-6vcm/GHSA-67pr-qr62-6vcm.json @@ -7,12 +7,8 @@ "CVE-2021-1207" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67v8-27c2-cwg5/GHSA-67v8-27c2-cwg5.json b/advisories/unreviewed/2022/05/GHSA-67v8-27c2-cwg5/GHSA-67v8-27c2-cwg5.json index 0ac5403756a..475241a52ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-67v8-27c2-cwg5/GHSA-67v8-27c2-cwg5.json +++ b/advisories/unreviewed/2022/05/GHSA-67v8-27c2-cwg5/GHSA-67v8-27c2-cwg5.json @@ -7,12 +7,8 @@ "CVE-2021-21458" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-686m-27qq-c25w/GHSA-686m-27qq-c25w.json b/advisories/unreviewed/2022/05/GHSA-686m-27qq-c25w/GHSA-686m-27qq-c25w.json index 22e4cbb21b1..9c62819b934 100644 --- a/advisories/unreviewed/2022/05/GHSA-686m-27qq-c25w/GHSA-686m-27qq-c25w.json +++ b/advisories/unreviewed/2022/05/GHSA-686m-27qq-c25w/GHSA-686m-27qq-c25w.json @@ -7,12 +7,8 @@ "CVE-2020-16255" ], "details": "ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68cc-2jmx-28r6/GHSA-68cc-2jmx-28r6.json b/advisories/unreviewed/2022/05/GHSA-68cc-2jmx-28r6/GHSA-68cc-2jmx-28r6.json index 985540ad045..ad82293cde6 100644 --- a/advisories/unreviewed/2022/05/GHSA-68cc-2jmx-28r6/GHSA-68cc-2jmx-28r6.json +++ b/advisories/unreviewed/2022/05/GHSA-68cc-2jmx-28r6/GHSA-68cc-2jmx-28r6.json @@ -7,12 +7,8 @@ "CVE-2020-9145" ], "details": "There is an Out-of-bounds Write vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability may cause out-of-bounds access to the physical memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68gc-rmhh-c4gg/GHSA-68gc-rmhh-c4gg.json b/advisories/unreviewed/2022/05/GHSA-68gc-rmhh-c4gg/GHSA-68gc-rmhh-c4gg.json index 55ca3062be2..c84d051f09d 100644 --- a/advisories/unreviewed/2022/05/GHSA-68gc-rmhh-c4gg/GHSA-68gc-rmhh-c4gg.json +++ b/advisories/unreviewed/2022/05/GHSA-68gc-rmhh-c4gg/GHSA-68gc-rmhh-c4gg.json @@ -7,12 +7,8 @@ "CVE-2020-36177" ], "details": "RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68r3-j757-34j6/GHSA-68r3-j757-34j6.json b/advisories/unreviewed/2022/05/GHSA-68r3-j757-34j6/GHSA-68r3-j757-34j6.json index 1d3e2af8126..f4685b3dcf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-68r3-j757-34j6/GHSA-68r3-j757-34j6.json +++ b/advisories/unreviewed/2022/05/GHSA-68r3-j757-34j6/GHSA-68r3-j757-34j6.json @@ -7,12 +7,8 @@ "CVE-2020-29587" ], "details": "SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap modals. The Bootbox.js library intentionally does not perform any sanitization of user input, which results in a DOM XSS, because it uses the jQuery .html() function to directly append the payload to a dialog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69g2-x726-84wf/GHSA-69g2-x726-84wf.json b/advisories/unreviewed/2022/05/GHSA-69g2-x726-84wf/GHSA-69g2-x726-84wf.json index a8ba21cd0f0..6ee88862c51 100644 --- a/advisories/unreviewed/2022/05/GHSA-69g2-x726-84wf/GHSA-69g2-x726-84wf.json +++ b/advisories/unreviewed/2022/05/GHSA-69g2-x726-84wf/GHSA-69g2-x726-84wf.json @@ -7,12 +7,8 @@ "CVE-2020-25950" ], "details": "Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69hv-2gp6-4mgw/GHSA-69hv-2gp6-4mgw.json b/advisories/unreviewed/2022/05/GHSA-69hv-2gp6-4mgw/GHSA-69hv-2gp6-4mgw.json index b2447fe3bd6..64d074590fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-69hv-2gp6-4mgw/GHSA-69hv-2gp6-4mgw.json +++ b/advisories/unreviewed/2022/05/GHSA-69hv-2gp6-4mgw/GHSA-69hv-2gp6-4mgw.json @@ -7,12 +7,8 @@ "CVE-2020-24639" ], "details": "There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69r8-874p-8rwh/GHSA-69r8-874p-8rwh.json b/advisories/unreviewed/2022/05/GHSA-69r8-874p-8rwh/GHSA-69r8-874p-8rwh.json index ac1e1b52eba..87b69ee38e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-69r8-874p-8rwh/GHSA-69r8-874p-8rwh.json +++ b/advisories/unreviewed/2022/05/GHSA-69r8-874p-8rwh/GHSA-69r8-874p-8rwh.json @@ -7,12 +7,8 @@ "CVE-2020-23643" ], "details": "XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c9w-r483-q74w/GHSA-6c9w-r483-q74w.json b/advisories/unreviewed/2022/05/GHSA-6c9w-r483-q74w/GHSA-6c9w-r483-q74w.json index f5018959e3a..eaee00aa6d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c9w-r483-q74w/GHSA-6c9w-r483-q74w.json +++ b/advisories/unreviewed/2022/05/GHSA-6c9w-r483-q74w/GHSA-6c9w-r483-q74w.json @@ -7,12 +7,8 @@ "CVE-2021-1184" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6crx-v72m-r4wf/GHSA-6crx-v72m-r4wf.json b/advisories/unreviewed/2022/05/GHSA-6crx-v72m-r4wf/GHSA-6crx-v72m-r4wf.json index 7225dd885aa..fee5b678155 100644 --- a/advisories/unreviewed/2022/05/GHSA-6crx-v72m-r4wf/GHSA-6crx-v72m-r4wf.json +++ b/advisories/unreviewed/2022/05/GHSA-6crx-v72m-r4wf/GHSA-6crx-v72m-r4wf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f4r-f2fv-g8f4/GHSA-6f4r-f2fv-g8f4.json b/advisories/unreviewed/2022/05/GHSA-6f4r-f2fv-g8f4/GHSA-6f4r-f2fv-g8f4.json index 5e320898327..c904b94cee1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f4r-f2fv-g8f4/GHSA-6f4r-f2fv-g8f4.json +++ b/advisories/unreviewed/2022/05/GHSA-6f4r-f2fv-g8f4/GHSA-6f4r-f2fv-g8f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hj9-w8vp-p698/GHSA-6hj9-w8vp-p698.json b/advisories/unreviewed/2022/05/GHSA-6hj9-w8vp-p698/GHSA-6hj9-w8vp-p698.json index ae1b2d0af66..a1a1f0e5989 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hj9-w8vp-p698/GHSA-6hj9-w8vp-p698.json +++ b/advisories/unreviewed/2022/05/GHSA-6hj9-w8vp-p698/GHSA-6hj9-w8vp-p698.json @@ -7,12 +7,8 @@ "CVE-2019-12953" ], "details": "Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hwc-9rpr-8qpg/GHSA-6hwc-9rpr-8qpg.json b/advisories/unreviewed/2022/05/GHSA-6hwc-9rpr-8qpg/GHSA-6hwc-9rpr-8qpg.json index 55253aa9bdf..2958b9520f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hwc-9rpr-8qpg/GHSA-6hwc-9rpr-8qpg.json +++ b/advisories/unreviewed/2022/05/GHSA-6hwc-9rpr-8qpg/GHSA-6hwc-9rpr-8qpg.json @@ -7,12 +7,8 @@ "CVE-2020-10208" ], "details": "Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hx2-43pp-mgr8/GHSA-6hx2-43pp-mgr8.json b/advisories/unreviewed/2022/05/GHSA-6hx2-43pp-mgr8/GHSA-6hx2-43pp-mgr8.json index 59b90b08e76..74d16e852ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hx2-43pp-mgr8/GHSA-6hx2-43pp-mgr8.json +++ b/advisories/unreviewed/2022/05/GHSA-6hx2-43pp-mgr8/GHSA-6hx2-43pp-mgr8.json @@ -7,12 +7,8 @@ "CVE-2020-8584" ], "details": "Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j4h-fwwv-9pxx/GHSA-6j4h-fwwv-9pxx.json b/advisories/unreviewed/2022/05/GHSA-6j4h-fwwv-9pxx/GHSA-6j4h-fwwv-9pxx.json index e4c4b2dd889..2cac60fc134 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j4h-fwwv-9pxx/GHSA-6j4h-fwwv-9pxx.json +++ b/advisories/unreviewed/2022/05/GHSA-6j4h-fwwv-9pxx/GHSA-6j4h-fwwv-9pxx.json @@ -7,12 +7,8 @@ "CVE-2020-29478" ], "details": "CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6jjh-r6w9-f8mv/GHSA-6jjh-r6w9-f8mv.json b/advisories/unreviewed/2022/05/GHSA-6jjh-r6w9-f8mv/GHSA-6jjh-r6w9-f8mv.json index c3f8850791f..7df5db92d3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jjh-r6w9-f8mv/GHSA-6jjh-r6w9-f8mv.json +++ b/advisories/unreviewed/2022/05/GHSA-6jjh-r6w9-f8mv/GHSA-6jjh-r6w9-f8mv.json @@ -7,12 +7,8 @@ "CVE-2021-21457" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pfh-vwh5-gvrc/GHSA-6pfh-vwh5-gvrc.json b/advisories/unreviewed/2022/05/GHSA-6pfh-vwh5-gvrc/GHSA-6pfh-vwh5-gvrc.json index 8f1ae0c9efa..9c2133498f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pfh-vwh5-gvrc/GHSA-6pfh-vwh5-gvrc.json +++ b/advisories/unreviewed/2022/05/GHSA-6pfh-vwh5-gvrc/GHSA-6pfh-vwh5-gvrc.json @@ -7,12 +7,8 @@ "CVE-2021-0320" ], "details": "In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Android ID: A-169933423.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6phh-6j34-7q6c/GHSA-6phh-6j34-7q6c.json b/advisories/unreviewed/2022/05/GHSA-6phh-6j34-7q6c/GHSA-6phh-6j34-7q6c.json index a41f399e3f0..296689ecb3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6phh-6j34-7q6c/GHSA-6phh-6j34-7q6c.json +++ b/advisories/unreviewed/2022/05/GHSA-6phh-6j34-7q6c/GHSA-6phh-6j34-7q6c.json @@ -7,12 +7,8 @@ "CVE-2021-1171" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pph-j4qx-pw58/GHSA-6pph-j4qx-pw58.json b/advisories/unreviewed/2022/05/GHSA-6pph-j4qx-pw58/GHSA-6pph-j4qx-pw58.json index a12bf5e6b6c..fa32667b461 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pph-j4qx-pw58/GHSA-6pph-j4qx-pw58.json +++ b/advisories/unreviewed/2022/05/GHSA-6pph-j4qx-pw58/GHSA-6pph-j4qx-pw58.json @@ -7,12 +7,8 @@ "CVE-2020-35826" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qj4-6737-c6h8/GHSA-6qj4-6737-c6h8.json b/advisories/unreviewed/2022/05/GHSA-6qj4-6737-c6h8/GHSA-6qj4-6737-c6h8.json index d06938ebc4d..a5283fb1b6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qj4-6737-c6h8/GHSA-6qj4-6737-c6h8.json +++ b/advisories/unreviewed/2022/05/GHSA-6qj4-6737-c6h8/GHSA-6qj4-6737-c6h8.json @@ -7,12 +7,8 @@ "CVE-2021-1156" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qqx-5fph-qx4j/GHSA-6qqx-5fph-qx4j.json b/advisories/unreviewed/2022/05/GHSA-6qqx-5fph-qx4j/GHSA-6qqx-5fph-qx4j.json index 68463ba9845..f92d0085c8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qqx-5fph-qx4j/GHSA-6qqx-5fph-qx4j.json +++ b/advisories/unreviewed/2022/05/GHSA-6qqx-5fph-qx4j/GHSA-6qqx-5fph-qx4j.json @@ -7,12 +7,8 @@ "CVE-2020-26181" ], "details": "Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r44-qm3p-h99q/GHSA-6r44-qm3p-h99q.json b/advisories/unreviewed/2022/05/GHSA-6r44-qm3p-h99q/GHSA-6r44-qm3p-h99q.json index 4c733d12d3d..e29d79b8176 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r44-qm3p-h99q/GHSA-6r44-qm3p-h99q.json +++ b/advisories/unreviewed/2022/05/GHSA-6r44-qm3p-h99q/GHSA-6r44-qm3p-h99q.json @@ -7,12 +7,8 @@ "CVE-2020-29250" ], "details": "CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r63-p37j-88jj/GHSA-6r63-p37j-88jj.json b/advisories/unreviewed/2022/05/GHSA-6r63-p37j-88jj/GHSA-6r63-p37j-88jj.json index 40eefb8375f..7631c1b7aa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r63-p37j-88jj/GHSA-6r63-p37j-88jj.json +++ b/advisories/unreviewed/2022/05/GHSA-6r63-p37j-88jj/GHSA-6r63-p37j-88jj.json @@ -7,12 +7,8 @@ "CVE-2020-4697" ], "details": "IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rqr-xfwj-w2q9/GHSA-6rqr-xfwj-w2q9.json b/advisories/unreviewed/2022/05/GHSA-6rqr-xfwj-w2q9/GHSA-6rqr-xfwj-w2q9.json index efaf69c7d39..58b8cd6ad21 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rqr-xfwj-w2q9/GHSA-6rqr-xfwj-w2q9.json +++ b/advisories/unreviewed/2022/05/GHSA-6rqr-xfwj-w2q9/GHSA-6rqr-xfwj-w2q9.json @@ -7,12 +7,8 @@ "CVE-2020-5021" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v42-384q-wwf5/GHSA-6v42-384q-wwf5.json b/advisories/unreviewed/2022/05/GHSA-6v42-384q-wwf5/GHSA-6v42-384q-wwf5.json index 973a684e753..93f9e9449f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v42-384q-wwf5/GHSA-6v42-384q-wwf5.json +++ b/advisories/unreviewed/2022/05/GHSA-6v42-384q-wwf5/GHSA-6v42-384q-wwf5.json @@ -7,12 +7,8 @@ "CVE-2020-16040" ], "details": "Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vq6-ghrc-jpjw/GHSA-6vq6-ghrc-jpjw.json b/advisories/unreviewed/2022/05/GHSA-6vq6-ghrc-jpjw/GHSA-6vq6-ghrc-jpjw.json index 4665eb384ca..7dc3e6d5dec 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vq6-ghrc-jpjw/GHSA-6vq6-ghrc-jpjw.json +++ b/advisories/unreviewed/2022/05/GHSA-6vq6-ghrc-jpjw/GHSA-6vq6-ghrc-jpjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vx9-m878-j4x6/GHSA-6vx9-m878-j4x6.json b/advisories/unreviewed/2022/05/GHSA-6vx9-m878-j4x6/GHSA-6vx9-m878-j4x6.json index f80bdd74e55..2c2214bec84 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vx9-m878-j4x6/GHSA-6vx9-m878-j4x6.json +++ b/advisories/unreviewed/2022/05/GHSA-6vx9-m878-j4x6/GHSA-6vx9-m878-j4x6.json @@ -7,12 +7,8 @@ "CVE-2020-11103" ], "details": "JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w86-cqhf-wpxg/GHSA-6w86-cqhf-wpxg.json b/advisories/unreviewed/2022/05/GHSA-6w86-cqhf-wpxg/GHSA-6w86-cqhf-wpxg.json index a168e64f3d0..06605e1b56f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w86-cqhf-wpxg/GHSA-6w86-cqhf-wpxg.json +++ b/advisories/unreviewed/2022/05/GHSA-6w86-cqhf-wpxg/GHSA-6w86-cqhf-wpxg.json @@ -7,12 +7,8 @@ "CVE-2020-5146" ], "details": "A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xfc-46hj-r3cf/GHSA-6xfc-46hj-r3cf.json b/advisories/unreviewed/2022/05/GHSA-6xfc-46hj-r3cf/GHSA-6xfc-46hj-r3cf.json index 1f93470bf0d..f106940bb21 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xfc-46hj-r3cf/GHSA-6xfc-46hj-r3cf.json +++ b/advisories/unreviewed/2022/05/GHSA-6xfc-46hj-r3cf/GHSA-6xfc-46hj-r3cf.json @@ -7,12 +7,8 @@ "CVE-2021-1130" ], "details": "A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need to have administrative credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xfc-qhvw-m8cg/GHSA-6xfc-qhvw-m8cg.json b/advisories/unreviewed/2022/05/GHSA-6xfc-qhvw-m8cg/GHSA-6xfc-qhvw-m8cg.json index 3632db7faa6..62c31e2786f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xfc-qhvw-m8cg/GHSA-6xfc-qhvw-m8cg.json +++ b/advisories/unreviewed/2022/05/GHSA-6xfc-qhvw-m8cg/GHSA-6xfc-qhvw-m8cg.json @@ -7,12 +7,8 @@ "CVE-2020-26980" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing JT files. A crafted JT file can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xpf-79gp-9fc2/GHSA-6xpf-79gp-9fc2.json b/advisories/unreviewed/2022/05/GHSA-6xpf-79gp-9fc2/GHSA-6xpf-79gp-9fc2.json index 5c7988e9613..fb1be3c8504 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xpf-79gp-9fc2/GHSA-6xpf-79gp-9fc2.json +++ b/advisories/unreviewed/2022/05/GHSA-6xpf-79gp-9fc2/GHSA-6xpf-79gp-9fc2.json @@ -7,12 +7,8 @@ "CVE-2020-5805" ], "details": "In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72h8-c2vg-vxqr/GHSA-72h8-c2vg-vxqr.json b/advisories/unreviewed/2022/05/GHSA-72h8-c2vg-vxqr/GHSA-72h8-c2vg-vxqr.json index 7855144af71..8b94c7293bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-72h8-c2vg-vxqr/GHSA-72h8-c2vg-vxqr.json +++ b/advisories/unreviewed/2022/05/GHSA-72h8-c2vg-vxqr/GHSA-72h8-c2vg-vxqr.json @@ -7,12 +7,8 @@ "CVE-2018-11007" ], "details": "A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-734r-xc2j-r7m7/GHSA-734r-xc2j-r7m7.json b/advisories/unreviewed/2022/05/GHSA-734r-xc2j-r7m7/GHSA-734r-xc2j-r7m7.json index fe7a7d23a18..41bca1b9b10 100644 --- a/advisories/unreviewed/2022/05/GHSA-734r-xc2j-r7m7/GHSA-734r-xc2j-r7m7.json +++ b/advisories/unreviewed/2022/05/GHSA-734r-xc2j-r7m7/GHSA-734r-xc2j-r7m7.json @@ -7,12 +7,8 @@ "CVE-2020-27275" ], "details": "Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-735q-mc2p-r2jc/GHSA-735q-mc2p-r2jc.json b/advisories/unreviewed/2022/05/GHSA-735q-mc2p-r2jc/GHSA-735q-mc2p-r2jc.json index b0ed656191a..aee533a1bf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-735q-mc2p-r2jc/GHSA-735q-mc2p-r2jc.json +++ b/advisories/unreviewed/2022/05/GHSA-735q-mc2p-r2jc/GHSA-735q-mc2p-r2jc.json @@ -7,12 +7,8 @@ "CVE-2020-35836" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, XR500 before 2.3.2.56, XR700 before 1.0.1.10, and RAX120 before 1.0.0.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-739f-9qhv-6594/GHSA-739f-9qhv-6594.json b/advisories/unreviewed/2022/05/GHSA-739f-9qhv-6594/GHSA-739f-9qhv-6594.json index 82569684817..d8314d3bd26 100644 --- a/advisories/unreviewed/2022/05/GHSA-739f-9qhv-6594/GHSA-739f-9qhv-6594.json +++ b/advisories/unreviewed/2022/05/GHSA-739f-9qhv-6594/GHSA-739f-9qhv-6594.json @@ -7,12 +7,8 @@ "CVE-2020-28851" ], "details": "In x/text in Go 1.15.4, an \"index out of range\" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75xc-p7x5-2rwx/GHSA-75xc-p7x5-2rwx.json b/advisories/unreviewed/2022/05/GHSA-75xc-p7x5-2rwx/GHSA-75xc-p7x5-2rwx.json index b338f68185f..de15c099086 100644 --- a/advisories/unreviewed/2022/05/GHSA-75xc-p7x5-2rwx/GHSA-75xc-p7x5-2rwx.json +++ b/advisories/unreviewed/2022/05/GHSA-75xc-p7x5-2rwx/GHSA-75xc-p7x5-2rwx.json @@ -7,12 +7,8 @@ "CVE-2020-23249" ], "details": "GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7726-7mp9-p4f2/GHSA-7726-7mp9-p4f2.json b/advisories/unreviewed/2022/05/GHSA-7726-7mp9-p4f2/GHSA-7726-7mp9-p4f2.json index dab6fd83aca..6e65dcbbf8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7726-7mp9-p4f2/GHSA-7726-7mp9-p4f2.json +++ b/advisories/unreviewed/2022/05/GHSA-7726-7mp9-p4f2/GHSA-7726-7mp9-p4f2.json @@ -7,12 +7,8 @@ "CVE-2020-8160" ], "details": "MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77p6-jjq7-fgjg/GHSA-77p6-jjq7-fgjg.json b/advisories/unreviewed/2022/05/GHSA-77p6-jjq7-fgjg/GHSA-77p6-jjq7-fgjg.json index 8c26e7c0fbe..8dc050643af 100644 --- a/advisories/unreviewed/2022/05/GHSA-77p6-jjq7-fgjg/GHSA-77p6-jjq7-fgjg.json +++ b/advisories/unreviewed/2022/05/GHSA-77p6-jjq7-fgjg/GHSA-77p6-jjq7-fgjg.json @@ -7,12 +7,8 @@ "CVE-2021-1214" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77q8-crvw-8w9q/GHSA-77q8-crvw-8w9q.json b/advisories/unreviewed/2022/05/GHSA-77q8-crvw-8w9q/GHSA-77q8-crvw-8w9q.json index b928c940cd8..97ec5e07b6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-77q8-crvw-8w9q/GHSA-77q8-crvw-8w9q.json +++ b/advisories/unreviewed/2022/05/GHSA-77q8-crvw-8w9q/GHSA-77q8-crvw-8w9q.json @@ -7,12 +7,8 @@ "CVE-2020-26976" ], "details": "When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79pm-w7jm-jv2r/GHSA-79pm-w7jm-jv2r.json b/advisories/unreviewed/2022/05/GHSA-79pm-w7jm-jv2r/GHSA-79pm-w7jm-jv2r.json index 0ed0f8203d3..edf8a53b410 100644 --- a/advisories/unreviewed/2022/05/GHSA-79pm-w7jm-jv2r/GHSA-79pm-w7jm-jv2r.json +++ b/advisories/unreviewed/2022/05/GHSA-79pm-w7jm-jv2r/GHSA-79pm-w7jm-jv2r.json @@ -7,12 +7,8 @@ "CVE-2019-4728" ], "details": "IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c77-3v5r-6jr7/GHSA-7c77-3v5r-6jr7.json b/advisories/unreviewed/2022/05/GHSA-7c77-3v5r-6jr7/GHSA-7c77-3v5r-6jr7.json index e2a290541ec..77b6914da69 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c77-3v5r-6jr7/GHSA-7c77-3v5r-6jr7.json +++ b/advisories/unreviewed/2022/05/GHSA-7c77-3v5r-6jr7/GHSA-7c77-3v5r-6jr7.json @@ -7,12 +7,8 @@ "CVE-2020-4913" ], "details": "IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c9w-2w99-hrrm/GHSA-7c9w-2w99-hrrm.json b/advisories/unreviewed/2022/05/GHSA-7c9w-2w99-hrrm/GHSA-7c9w-2w99-hrrm.json index b5e1f48f782..b3094b802d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c9w-2w99-hrrm/GHSA-7c9w-2w99-hrrm.json +++ b/advisories/unreviewed/2022/05/GHSA-7c9w-2w99-hrrm/GHSA-7c9w-2w99-hrrm.json @@ -7,12 +7,8 @@ "CVE-2020-13449" ], "details": "A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cg5-4j3g-r99c/GHSA-7cg5-4j3g-r99c.json b/advisories/unreviewed/2022/05/GHSA-7cg5-4j3g-r99c/GHSA-7cg5-4j3g-r99c.json index bb5ab48947f..3a2314b95dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cg5-4j3g-r99c/GHSA-7cg5-4j3g-r99c.json +++ b/advisories/unreviewed/2022/05/GHSA-7cg5-4j3g-r99c/GHSA-7cg5-4j3g-r99c.json @@ -7,12 +7,8 @@ "CVE-2021-1196" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cpf-9rpm-3gq2/GHSA-7cpf-9rpm-3gq2.json b/advisories/unreviewed/2022/05/GHSA-7cpf-9rpm-3gq2/GHSA-7cpf-9rpm-3gq2.json index 8f6e7b1706a..93782514405 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cpf-9rpm-3gq2/GHSA-7cpf-9rpm-3gq2.json +++ b/advisories/unreviewed/2022/05/GHSA-7cpf-9rpm-3gq2/GHSA-7cpf-9rpm-3gq2.json @@ -7,12 +7,8 @@ "CVE-2021-1157" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7crf-438p-2fw4/GHSA-7crf-438p-2fw4.json b/advisories/unreviewed/2022/05/GHSA-7crf-438p-2fw4/GHSA-7crf-438p-2fw4.json index d084520cee2..691176e74d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7crf-438p-2fw4/GHSA-7crf-438p-2fw4.json +++ b/advisories/unreviewed/2022/05/GHSA-7crf-438p-2fw4/GHSA-7crf-438p-2fw4.json @@ -7,12 +7,8 @@ "CVE-2021-23241" ], "details": "MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f55-fqw6-8jjp/GHSA-7f55-fqw6-8jjp.json b/advisories/unreviewed/2022/05/GHSA-7f55-fqw6-8jjp/GHSA-7f55-fqw6-8jjp.json index 816c97304f5..b4300375361 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f55-fqw6-8jjp/GHSA-7f55-fqw6-8jjp.json +++ b/advisories/unreviewed/2022/05/GHSA-7f55-fqw6-8jjp/GHSA-7f55-fqw6-8jjp.json @@ -7,12 +7,8 @@ "CVE-2020-8289" ], "details": "Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g87-66j4-g7g4/GHSA-7g87-66j4-g7g4.json b/advisories/unreviewed/2022/05/GHSA-7g87-66j4-g7g4/GHSA-7g87-66j4-g7g4.json index 24d5d248388..acd02b73020 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g87-66j4-g7g4/GHSA-7g87-66j4-g7g4.json +++ b/advisories/unreviewed/2022/05/GHSA-7g87-66j4-g7g4/GHSA-7g87-66j4-g7g4.json @@ -7,12 +7,8 @@ "CVE-2020-9138" ], "details": "There is a heap-based buffer overflow vulnerability in some Huawei Smartphone, Successful exploit of this vulnerability can cause process exceptions during updating.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hh7-8vvm-32g4/GHSA-7hh7-8vvm-32g4.json b/advisories/unreviewed/2022/05/GHSA-7hh7-8vvm-32g4/GHSA-7hh7-8vvm-32g4.json index cecb9cfef5e..7e5096aa882 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hh7-8vvm-32g4/GHSA-7hh7-8vvm-32g4.json +++ b/advisories/unreviewed/2022/05/GHSA-7hh7-8vvm-32g4/GHSA-7hh7-8vvm-32g4.json @@ -7,12 +7,8 @@ "CVE-2020-10657" ], "details": "The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin or config-admin privileges in the console) to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hmr-qxwq-qpx6/GHSA-7hmr-qxwq-qpx6.json b/advisories/unreviewed/2022/05/GHSA-7hmr-qxwq-qpx6/GHSA-7hmr-qxwq-qpx6.json index a2321b463ed..99db4718e15 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hmr-qxwq-qpx6/GHSA-7hmr-qxwq-qpx6.json +++ b/advisories/unreviewed/2022/05/GHSA-7hmr-qxwq-qpx6/GHSA-7hmr-qxwq-qpx6.json @@ -7,12 +7,8 @@ "CVE-2020-24901" ], "details": "The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hx2-xxcg-v7c4/GHSA-7hx2-xxcg-v7c4.json b/advisories/unreviewed/2022/05/GHSA-7hx2-xxcg-v7c4/GHSA-7hx2-xxcg-v7c4.json index 0f14b989d57..a55fd579bcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hx2-xxcg-v7c4/GHSA-7hx2-xxcg-v7c4.json +++ b/advisories/unreviewed/2022/05/GHSA-7hx2-xxcg-v7c4/GHSA-7hx2-xxcg-v7c4.json @@ -7,12 +7,8 @@ "CVE-2020-29249" ], "details": "CXUUCMS V3 allows class=\"layui-input\" XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j8m-fm49-xgmg/GHSA-7j8m-fm49-xgmg.json b/advisories/unreviewed/2022/05/GHSA-7j8m-fm49-xgmg/GHSA-7j8m-fm49-xgmg.json index 4c3b1bba878..8b374a3c6b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j8m-fm49-xgmg/GHSA-7j8m-fm49-xgmg.json +++ b/advisories/unreviewed/2022/05/GHSA-7j8m-fm49-xgmg/GHSA-7j8m-fm49-xgmg.json @@ -7,12 +7,8 @@ "CVE-2020-35849" ], "details": "An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potentially confidential information via the bugnote_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mj3-xm28-cffc/GHSA-7mj3-xm28-cffc.json b/advisories/unreviewed/2022/05/GHSA-7mj3-xm28-cffc/GHSA-7mj3-xm28-cffc.json index be8f879711c..9d0e6eb25a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mj3-xm28-cffc/GHSA-7mj3-xm28-cffc.json +++ b/advisories/unreviewed/2022/05/GHSA-7mj3-xm28-cffc/GHSA-7mj3-xm28-cffc.json @@ -7,12 +7,8 @@ "CVE-2020-35219" ], "details": "The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mmx-34xp-frcg/GHSA-7mmx-34xp-frcg.json b/advisories/unreviewed/2022/05/GHSA-7mmx-34xp-frcg/GHSA-7mmx-34xp-frcg.json index 80bb4cdf659..e30ac224f81 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mmx-34xp-frcg/GHSA-7mmx-34xp-frcg.json +++ b/advisories/unreviewed/2022/05/GHSA-7mmx-34xp-frcg/GHSA-7mmx-34xp-frcg.json @@ -7,12 +7,8 @@ "CVE-2020-4909" ], "details": "IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191273.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p7r-8rqq-6xf9/GHSA-7p7r-8rqq-6xf9.json b/advisories/unreviewed/2022/05/GHSA-7p7r-8rqq-6xf9/GHSA-7p7r-8rqq-6xf9.json index 794b7c742f2..1fad9409da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p7r-8rqq-6xf9/GHSA-7p7r-8rqq-6xf9.json +++ b/advisories/unreviewed/2022/05/GHSA-7p7r-8rqq-6xf9/GHSA-7p7r-8rqq-6xf9.json @@ -7,12 +7,8 @@ "CVE-2020-26973" ], "details": "Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qgv-8gh6-qmr8/GHSA-7qgv-8gh6-qmr8.json b/advisories/unreviewed/2022/05/GHSA-7qgv-8gh6-qmr8/GHSA-7qgv-8gh6-qmr8.json index dbef678eb9c..eec30b923ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qgv-8gh6-qmr8/GHSA-7qgv-8gh6-qmr8.json +++ b/advisories/unreviewed/2022/05/GHSA-7qgv-8gh6-qmr8/GHSA-7qgv-8gh6-qmr8.json @@ -7,12 +7,8 @@ "CVE-2016-20005" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rwq-q3mj-f9qw/GHSA-7rwq-q3mj-f9qw.json b/advisories/unreviewed/2022/05/GHSA-7rwq-q3mj-f9qw/GHSA-7rwq-q3mj-f9qw.json index b952b97d456..f6b3b5faf8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rwq-q3mj-f9qw/GHSA-7rwq-q3mj-f9qw.json +++ b/advisories/unreviewed/2022/05/GHSA-7rwq-q3mj-f9qw/GHSA-7rwq-q3mj-f9qw.json @@ -7,12 +7,8 @@ "CVE-2016-20007" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rx2-32cc-p83x/GHSA-7rx2-32cc-p83x.json b/advisories/unreviewed/2022/05/GHSA-7rx2-32cc-p83x/GHSA-7rx2-32cc-p83x.json index cd014fa825d..53aa5264439 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rx2-32cc-p83x/GHSA-7rx2-32cc-p83x.json +++ b/advisories/unreviewed/2022/05/GHSA-7rx2-32cc-p83x/GHSA-7rx2-32cc-p83x.json @@ -7,12 +7,8 @@ "CVE-2018-20312" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wcx-h8gf-8fh3/GHSA-7wcx-h8gf-8fh3.json b/advisories/unreviewed/2022/05/GHSA-7wcx-h8gf-8fh3/GHSA-7wcx-h8gf-8fh3.json index 278672a4256..2fdfb34cb97 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wcx-h8gf-8fh3/GHSA-7wcx-h8gf-8fh3.json +++ b/advisories/unreviewed/2022/05/GHSA-7wcx-h8gf-8fh3/GHSA-7wcx-h8gf-8fh3.json @@ -7,12 +7,8 @@ "CVE-2020-17502" ], "details": "Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wjq-q3c8-8q2h/GHSA-7wjq-q3c8-8q2h.json b/advisories/unreviewed/2022/05/GHSA-7wjq-q3c8-8q2h/GHSA-7wjq-q3c8-8q2h.json index 45cae4f2476..4591811fb1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wjq-q3c8-8q2h/GHSA-7wjq-q3c8-8q2h.json +++ b/advisories/unreviewed/2022/05/GHSA-7wjq-q3c8-8q2h/GHSA-7wjq-q3c8-8q2h.json @@ -7,12 +7,8 @@ "CVE-2020-27643" ], "details": "The %PROGRAMDATA%\\1E\\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system directory. This leads to partial privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xgg-9m2p-jqr2/GHSA-7xgg-9m2p-jqr2.json b/advisories/unreviewed/2022/05/GHSA-7xgg-9m2p-jqr2/GHSA-7xgg-9m2p-jqr2.json index ec7abd166a5..81a7b4aa115 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xgg-9m2p-jqr2/GHSA-7xgg-9m2p-jqr2.json +++ b/advisories/unreviewed/2022/05/GHSA-7xgg-9m2p-jqr2/GHSA-7xgg-9m2p-jqr2.json @@ -7,12 +7,8 @@ "CVE-2020-17503" ], "details": "The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameter \"locking\" is not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8293-g32j-pp9g/GHSA-8293-g32j-pp9g.json b/advisories/unreviewed/2022/05/GHSA-8293-g32j-pp9g/GHSA-8293-g32j-pp9g.json index 57bebec2fd4..b335ea7e2b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8293-g32j-pp9g/GHSA-8293-g32j-pp9g.json +++ b/advisories/unreviewed/2022/05/GHSA-8293-g32j-pp9g/GHSA-8293-g32j-pp9g.json @@ -7,12 +7,8 @@ "CVE-2020-5020" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 193656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82fx-x8mw-q5qv/GHSA-82fx-x8mw-q5qv.json b/advisories/unreviewed/2022/05/GHSA-82fx-x8mw-q5qv/GHSA-82fx-x8mw-q5qv.json index 112c616d60d..75aa1f2278d 100644 --- a/advisories/unreviewed/2022/05/GHSA-82fx-x8mw-q5qv/GHSA-82fx-x8mw-q5qv.json +++ b/advisories/unreviewed/2022/05/GHSA-82fx-x8mw-q5qv/GHSA-82fx-x8mw-q5qv.json @@ -7,12 +7,8 @@ "CVE-2020-23250" ], "details": "GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83h2-hcgw-9hc5/GHSA-83h2-hcgw-9hc5.json b/advisories/unreviewed/2022/05/GHSA-83h2-hcgw-9hc5/GHSA-83h2-hcgw-9hc5.json index d16c82082a9..be737bcadb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-83h2-hcgw-9hc5/GHSA-83h2-hcgw-9hc5.json +++ b/advisories/unreviewed/2022/05/GHSA-83h2-hcgw-9hc5/GHSA-83h2-hcgw-9hc5.json @@ -7,12 +7,8 @@ "CVE-2020-16034" ], "details": "Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8424-8x2w-j5fr/GHSA-8424-8x2w-j5fr.json b/advisories/unreviewed/2022/05/GHSA-8424-8x2w-j5fr/GHSA-8424-8x2w-j5fr.json index 880d6ac81d7..f0a8f7ae8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8424-8x2w-j5fr/GHSA-8424-8x2w-j5fr.json +++ b/advisories/unreviewed/2022/05/GHSA-8424-8x2w-j5fr/GHSA-8424-8x2w-j5fr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-847v-wqmh-26g6/GHSA-847v-wqmh-26g6.json b/advisories/unreviewed/2022/05/GHSA-847v-wqmh-26g6/GHSA-847v-wqmh-26g6.json index 6f0871ee1fb..395a84f4e77 100644 --- a/advisories/unreviewed/2022/05/GHSA-847v-wqmh-26g6/GHSA-847v-wqmh-26g6.json +++ b/advisories/unreviewed/2022/05/GHSA-847v-wqmh-26g6/GHSA-847v-wqmh-26g6.json @@ -7,12 +7,8 @@ "CVE-2020-35814" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84w2-4gr5-7c3f/GHSA-84w2-4gr5-7c3f.json b/advisories/unreviewed/2022/05/GHSA-84w2-4gr5-7c3f/GHSA-84w2-4gr5-7c3f.json index c08fb9397a1..3ee7e0e6542 100644 --- a/advisories/unreviewed/2022/05/GHSA-84w2-4gr5-7c3f/GHSA-84w2-4gr5-7c3f.json +++ b/advisories/unreviewed/2022/05/GHSA-84w2-4gr5-7c3f/GHSA-84w2-4gr5-7c3f.json @@ -7,12 +7,8 @@ "CVE-2021-1208" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-863x-vcg8-vghr/GHSA-863x-vcg8-vghr.json b/advisories/unreviewed/2022/05/GHSA-863x-vcg8-vghr/GHSA-863x-vcg8-vghr.json index 4236d8bdb73..c0a650ba716 100644 --- a/advisories/unreviewed/2022/05/GHSA-863x-vcg8-vghr/GHSA-863x-vcg8-vghr.json +++ b/advisories/unreviewed/2022/05/GHSA-863x-vcg8-vghr/GHSA-863x-vcg8-vghr.json @@ -7,12 +7,8 @@ "CVE-2020-5361" ], "details": "Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can generate BIOS recovery passwords. The tools, which are not authorized by Dell, can be used by a physically present attacker to reset BIOS passwords and BIOS-managed Hard Disk Drive (HDD) passwords. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to bypass security restrictions for BIOS Setup configuration, HDD access and BIOS pre-boot authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-879w-9vpf-9pw9/GHSA-879w-9vpf-9pw9.json b/advisories/unreviewed/2022/05/GHSA-879w-9vpf-9pw9/GHSA-879w-9vpf-9pw9.json index 9356f733bfd..668f532fabc 100644 --- a/advisories/unreviewed/2022/05/GHSA-879w-9vpf-9pw9/GHSA-879w-9vpf-9pw9.json +++ b/advisories/unreviewed/2022/05/GHSA-879w-9vpf-9pw9/GHSA-879w-9vpf-9pw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87x6-qp9x-whwg/GHSA-87x6-qp9x-whwg.json b/advisories/unreviewed/2022/05/GHSA-87x6-qp9x-whwg/GHSA-87x6-qp9x-whwg.json index 5a7a6e9de9e..f8e440e0ee3 100644 --- a/advisories/unreviewed/2022/05/GHSA-87x6-qp9x-whwg/GHSA-87x6-qp9x-whwg.json +++ b/advisories/unreviewed/2022/05/GHSA-87x6-qp9x-whwg/GHSA-87x6-qp9x-whwg.json @@ -7,12 +7,8 @@ "CVE-2020-27283" ], "details": "An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8963-5hmx-g354/GHSA-8963-5hmx-g354.json b/advisories/unreviewed/2022/05/GHSA-8963-5hmx-g354/GHSA-8963-5hmx-g354.json index 0f022e094b1..982d9f08831 100644 --- a/advisories/unreviewed/2022/05/GHSA-8963-5hmx-g354/GHSA-8963-5hmx-g354.json +++ b/advisories/unreviewed/2022/05/GHSA-8963-5hmx-g354/GHSA-8963-5hmx-g354.json @@ -7,12 +7,8 @@ "CVE-2020-35952" ], "details": "login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single \"Incorrect username or password\" message in both cases), which might allow enumeration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c5r-6wpq-9ghx/GHSA-8c5r-6wpq-9ghx.json b/advisories/unreviewed/2022/05/GHSA-8c5r-6wpq-9ghx/GHSA-8c5r-6wpq-9ghx.json index b6d2aae6719..9a35f4c2792 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c5r-6wpq-9ghx/GHSA-8c5r-6wpq-9ghx.json +++ b/advisories/unreviewed/2022/05/GHSA-8c5r-6wpq-9ghx/GHSA-8c5r-6wpq-9ghx.json @@ -7,12 +7,8 @@ "CVE-2020-17508" ], "details": "The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cg6-978m-p6jw/GHSA-8cg6-978m-p6jw.json b/advisories/unreviewed/2022/05/GHSA-8cg6-978m-p6jw/GHSA-8cg6-978m-p6jw.json index 2421adab003..68bdd2ac965 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cg6-978m-p6jw/GHSA-8cg6-978m-p6jw.json +++ b/advisories/unreviewed/2022/05/GHSA-8cg6-978m-p6jw/GHSA-8cg6-978m-p6jw.json @@ -7,12 +7,8 @@ "CVE-2020-36174" ], "details": "The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8chv-3mvf-2569/GHSA-8chv-3mvf-2569.json b/advisories/unreviewed/2022/05/GHSA-8chv-3mvf-2569/GHSA-8chv-3mvf-2569.json index b124095a1e6..4965c247577 100644 --- a/advisories/unreviewed/2022/05/GHSA-8chv-3mvf-2569/GHSA-8chv-3mvf-2569.json +++ b/advisories/unreviewed/2022/05/GHSA-8chv-3mvf-2569/GHSA-8chv-3mvf-2569.json @@ -7,12 +7,8 @@ "CVE-2020-35820" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cw3-r54r-hfvp/GHSA-8cw3-r54r-hfvp.json b/advisories/unreviewed/2022/05/GHSA-8cw3-r54r-hfvp/GHSA-8cw3-r54r-hfvp.json index d55bed3b60f..09a883f4de7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cw3-r54r-hfvp/GHSA-8cw3-r54r-hfvp.json +++ b/advisories/unreviewed/2022/05/GHSA-8cw3-r54r-hfvp/GHSA-8cw3-r54r-hfvp.json @@ -7,12 +7,8 @@ "CVE-2021-0311" ], "details": "In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170240631.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f4f-mpwv-cr26/GHSA-8f4f-mpwv-cr26.json b/advisories/unreviewed/2022/05/GHSA-8f4f-mpwv-cr26/GHSA-8f4f-mpwv-cr26.json index 55556e30fb4..09910bc63cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f4f-mpwv-cr26/GHSA-8f4f-mpwv-cr26.json +++ b/advisories/unreviewed/2022/05/GHSA-8f4f-mpwv-cr26/GHSA-8f4f-mpwv-cr26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g5p-w4wh-f5fj/GHSA-8g5p-w4wh-f5fj.json b/advisories/unreviewed/2022/05/GHSA-8g5p-w4wh-f5fj/GHSA-8g5p-w4wh-f5fj.json index 8d6a881afba..e6910cd2b6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g5p-w4wh-f5fj/GHSA-8g5p-w4wh-f5fj.json +++ b/advisories/unreviewed/2022/05/GHSA-8g5p-w4wh-f5fj/GHSA-8g5p-w4wh-f5fj.json @@ -7,12 +7,8 @@ "CVE-2021-3002" ], "details": "Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g9c-9q8r-972g/GHSA-8g9c-9q8r-972g.json b/advisories/unreviewed/2022/05/GHSA-8g9c-9q8r-972g/GHSA-8g9c-9q8r-972g.json index 77767c3a152..4df47089dbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g9c-9q8r-972g/GHSA-8g9c-9q8r-972g.json +++ b/advisories/unreviewed/2022/05/GHSA-8g9c-9q8r-972g/GHSA-8g9c-9q8r-972g.json @@ -7,12 +7,8 @@ "CVE-2020-35817" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hmh-2f4f-8hr6/GHSA-8hmh-2f4f-8hr6.json b/advisories/unreviewed/2022/05/GHSA-8hmh-2f4f-8hr6/GHSA-8hmh-2f4f-8hr6.json index 895ee083623..08eabc3e321 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hmh-2f4f-8hr6/GHSA-8hmh-2f4f-8hr6.json +++ b/advisories/unreviewed/2022/05/GHSA-8hmh-2f4f-8hr6/GHSA-8hmh-2f4f-8hr6.json @@ -7,12 +7,8 @@ "CVE-2019-18643" ], "details": "Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain remote code execution on the application. The application typically runs as LocalSystem as mandated in the installation guide. Patched in versions 8.10 and 9.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hrr-3cmh-hr2j/GHSA-8hrr-3cmh-hr2j.json b/advisories/unreviewed/2022/05/GHSA-8hrr-3cmh-hr2j/GHSA-8hrr-3cmh-hr2j.json index b5759273485..8507d983562 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hrr-3cmh-hr2j/GHSA-8hrr-3cmh-hr2j.json +++ b/advisories/unreviewed/2022/05/GHSA-8hrr-3cmh-hr2j/GHSA-8hrr-3cmh-hr2j.json @@ -7,12 +7,8 @@ "CVE-2020-29477" ], "details": "Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j82-3vp9-g4x4/GHSA-8j82-3vp9-g4x4.json b/advisories/unreviewed/2022/05/GHSA-8j82-3vp9-g4x4/GHSA-8j82-3vp9-g4x4.json index d861638b12c..3a0d00d4f83 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j82-3vp9-g4x4/GHSA-8j82-3vp9-g4x4.json +++ b/advisories/unreviewed/2022/05/GHSA-8j82-3vp9-g4x4/GHSA-8j82-3vp9-g4x4.json @@ -7,12 +7,8 @@ "CVE-2020-4691" ], "details": "IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m9c-9p98-p88q/GHSA-8m9c-9p98-p88q.json b/advisories/unreviewed/2022/05/GHSA-8m9c-9p98-p88q/GHSA-8m9c-9p98-p88q.json index c0d5a328439..71611697b0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m9c-9p98-p88q/GHSA-8m9c-9p98-p88q.json +++ b/advisories/unreviewed/2022/05/GHSA-8m9c-9p98-p88q/GHSA-8m9c-9p98-p88q.json @@ -7,12 +7,8 @@ "CVE-2021-1202" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mp4-rxj5-mmqw/GHSA-8mp4-rxj5-mmqw.json b/advisories/unreviewed/2022/05/GHSA-8mp4-rxj5-mmqw/GHSA-8mp4-rxj5-mmqw.json index bc45a289b81..6fc9d8f3487 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mp4-rxj5-mmqw/GHSA-8mp4-rxj5-mmqw.json +++ b/advisories/unreviewed/2022/05/GHSA-8mp4-rxj5-mmqw/GHSA-8mp4-rxj5-mmqw.json @@ -7,12 +7,8 @@ "CVE-2020-29498" ], "details": "Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p6g-m4gv-rh9c/GHSA-8p6g-m4gv-rh9c.json b/advisories/unreviewed/2022/05/GHSA-8p6g-m4gv-rh9c/GHSA-8p6g-m4gv-rh9c.json index 35348771c55..c7875a89b10 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p6g-m4gv-rh9c/GHSA-8p6g-m4gv-rh9c.json +++ b/advisories/unreviewed/2022/05/GHSA-8p6g-m4gv-rh9c/GHSA-8p6g-m4gv-rh9c.json @@ -7,12 +7,8 @@ "CVE-2021-1168" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p9f-c7cc-v345/GHSA-8p9f-c7cc-v345.json b/advisories/unreviewed/2022/05/GHSA-8p9f-c7cc-v345/GHSA-8p9f-c7cc-v345.json index 456a96d101c..c2d0bbced28 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p9f-c7cc-v345/GHSA-8p9f-c7cc-v345.json +++ b/advisories/unreviewed/2022/05/GHSA-8p9f-c7cc-v345/GHSA-8p9f-c7cc-v345.json @@ -7,12 +7,8 @@ "CVE-2018-11009" ], "details": "A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pf6-658f-7qh2/GHSA-8pf6-658f-7qh2.json b/advisories/unreviewed/2022/05/GHSA-8pf6-658f-7qh2/GHSA-8pf6-658f-7qh2.json index 0a80b46cd22..e1bf43f0f58 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pf6-658f-7qh2/GHSA-8pf6-658f-7qh2.json +++ b/advisories/unreviewed/2022/05/GHSA-8pf6-658f-7qh2/GHSA-8pf6-658f-7qh2.json @@ -7,12 +7,8 @@ "CVE-2020-27835" ], "details": "A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user calls Ioctl after open dev file and fork. A local user could use this flaw to crash the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pvx-gf46-6h4p/GHSA-8pvx-gf46-6h4p.json b/advisories/unreviewed/2022/05/GHSA-8pvx-gf46-6h4p/GHSA-8pvx-gf46-6h4p.json index 0f4e5b313e1..b3362bc690d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pvx-gf46-6h4p/GHSA-8pvx-gf46-6h4p.json +++ b/advisories/unreviewed/2022/05/GHSA-8pvx-gf46-6h4p/GHSA-8pvx-gf46-6h4p.json @@ -7,12 +7,8 @@ "CVE-2020-27289" ], "details": "Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pw5-pwp5-8mcx/GHSA-8pw5-pwp5-8mcx.json b/advisories/unreviewed/2022/05/GHSA-8pw5-pwp5-8mcx/GHSA-8pw5-pwp5-8mcx.json index 1b9a74fc3e9..38a7244ac2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pw5-pwp5-8mcx/GHSA-8pw5-pwp5-8mcx.json +++ b/advisories/unreviewed/2022/05/GHSA-8pw5-pwp5-8mcx/GHSA-8pw5-pwp5-8mcx.json @@ -7,12 +7,8 @@ "CVE-2020-26800" ], "details": "A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json file may result in a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q35-pvh9-gxxg/GHSA-8q35-pvh9-gxxg.json b/advisories/unreviewed/2022/05/GHSA-8q35-pvh9-gxxg/GHSA-8q35-pvh9-gxxg.json index 6987c1b6354..d0aca8db4a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q35-pvh9-gxxg/GHSA-8q35-pvh9-gxxg.json +++ b/advisories/unreviewed/2022/05/GHSA-8q35-pvh9-gxxg/GHSA-8q35-pvh9-gxxg.json @@ -7,12 +7,8 @@ "CVE-2020-35841" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.76, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, WNR1000v4 before 1.1.0.62, WNR2020 before 1.1.0.62, and WNR2050 before 1.1.0.62.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q5h-q6w3-hpf3/GHSA-8q5h-q6w3-hpf3.json b/advisories/unreviewed/2022/05/GHSA-8q5h-q6w3-hpf3/GHSA-8q5h-q6w3-hpf3.json index 53a062e680d..0dfb438ef77 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q5h-q6w3-hpf3/GHSA-8q5h-q6w3-hpf3.json +++ b/advisories/unreviewed/2022/05/GHSA-8q5h-q6w3-hpf3/GHSA-8q5h-q6w3-hpf3.json @@ -7,12 +7,8 @@ "CVE-2020-25799" ], "details": "LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qqr-fmwm-8jr3/GHSA-8qqr-fmwm-8jr3.json b/advisories/unreviewed/2022/05/GHSA-8qqr-fmwm-8jr3/GHSA-8qqr-fmwm-8jr3.json index 5d263920d08..c08de8ee76c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qqr-fmwm-8jr3/GHSA-8qqr-fmwm-8jr3.json +++ b/advisories/unreviewed/2022/05/GHSA-8qqr-fmwm-8jr3/GHSA-8qqr-fmwm-8jr3.json @@ -7,12 +7,8 @@ "CVE-2020-16026" ], "details": "Use after free in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r69-p3hj-6c77/GHSA-8r69-p3hj-6c77.json b/advisories/unreviewed/2022/05/GHSA-8r69-p3hj-6c77/GHSA-8r69-p3hj-6c77.json index 93689bca0ee..70ae15210c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r69-p3hj-6c77/GHSA-8r69-p3hj-6c77.json +++ b/advisories/unreviewed/2022/05/GHSA-8r69-p3hj-6c77/GHSA-8r69-p3hj-6c77.json @@ -7,12 +7,8 @@ "CVE-2019-18642" ], "details": "Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another account, even the administrator account. Upon changing another account's email address, performing a password reset to the new email address could allow an attacker to take over any account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rjj-rr5j-hqwh/GHSA-8rjj-rr5j-hqwh.json b/advisories/unreviewed/2022/05/GHSA-8rjj-rr5j-hqwh/GHSA-8rjj-rr5j-hqwh.json index 6356c72196b..e7c2497f452 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rjj-rr5j-hqwh/GHSA-8rjj-rr5j-hqwh.json +++ b/advisories/unreviewed/2022/05/GHSA-8rjj-rr5j-hqwh/GHSA-8rjj-rr5j-hqwh.json @@ -7,12 +7,8 @@ "CVE-2020-5017" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vqf-8cjg-mqp5/GHSA-8vqf-8cjg-mqp5.json b/advisories/unreviewed/2022/05/GHSA-8vqf-8cjg-mqp5/GHSA-8vqf-8cjg-mqp5.json index feac8c13f80..c60026a0b07 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vqf-8cjg-mqp5/GHSA-8vqf-8cjg-mqp5.json +++ b/advisories/unreviewed/2022/05/GHSA-8vqf-8cjg-mqp5/GHSA-8vqf-8cjg-mqp5.json @@ -7,12 +7,8 @@ "CVE-2020-35749" ], "details": "Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w42-f9rr-g7xm/GHSA-8w42-f9rr-g7xm.json b/advisories/unreviewed/2022/05/GHSA-8w42-f9rr-g7xm/GHSA-8w42-f9rr-g7xm.json index 61c8febde43..a53fa05b05a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w42-f9rr-g7xm/GHSA-8w42-f9rr-g7xm.json +++ b/advisories/unreviewed/2022/05/GHSA-8w42-f9rr-g7xm/GHSA-8w42-f9rr-g7xm.json @@ -7,12 +7,8 @@ "CVE-2018-20310" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w66-g4m4-h3qv/GHSA-8w66-g4m4-h3qv.json b/advisories/unreviewed/2022/05/GHSA-8w66-g4m4-h3qv/GHSA-8w66-g4m4-h3qv.json index 7763d061b69..bf1e7aa7b58 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w66-g4m4-h3qv/GHSA-8w66-g4m4-h3qv.json +++ b/advisories/unreviewed/2022/05/GHSA-8w66-g4m4-h3qv/GHSA-8w66-g4m4-h3qv.json @@ -7,12 +7,8 @@ "CVE-2021-21447" ], "details": "SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wv9-vqfr-6hg4/GHSA-8wv9-vqfr-6hg4.json b/advisories/unreviewed/2022/05/GHSA-8wv9-vqfr-6hg4/GHSA-8wv9-vqfr-6hg4.json index 4c4e677fcfc..3ef98b5cd14 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wv9-vqfr-6hg4/GHSA-8wv9-vqfr-6hg4.json +++ b/advisories/unreviewed/2022/05/GHSA-8wv9-vqfr-6hg4/GHSA-8wv9-vqfr-6hg4.json @@ -7,12 +7,8 @@ "CVE-2020-36162" ], "details": "An issue was discovered in Veritas CloudPoint before 8.3.0.1+hotfix. The CloudPoint Windows Agent leverages OpenSSL. This OpenSSL library attempts to load the \\usr\\local\\ssl\\openssl.cnf configuration file, which does not exist. By default, on Windows systems users can create directories under :\\. A low privileged user can create a :\\usr\\local\\ssl\\openssl.cnf configuration file to load a malicious OpenSSL engine, which may result in arbitrary code execution. This would give the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xfg-5ch9-qcf9/GHSA-8xfg-5ch9-qcf9.json b/advisories/unreviewed/2022/05/GHSA-8xfg-5ch9-qcf9/GHSA-8xfg-5ch9-qcf9.json index a522f45b051..0094f7c7070 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xfg-5ch9-qcf9/GHSA-8xfg-5ch9-qcf9.json +++ b/advisories/unreviewed/2022/05/GHSA-8xfg-5ch9-qcf9/GHSA-8xfg-5ch9-qcf9.json @@ -7,12 +7,8 @@ "CVE-2021-0307" ], "details": "In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a dangerous permission with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Android ID: A-155648771.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xmx-4f3h-rv3w/GHSA-8xmx-4f3h-rv3w.json b/advisories/unreviewed/2022/05/GHSA-8xmx-4f3h-rv3w/GHSA-8xmx-4f3h-rv3w.json index 97aa45ff674..b4f17cb2282 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xmx-4f3h-rv3w/GHSA-8xmx-4f3h-rv3w.json +++ b/advisories/unreviewed/2022/05/GHSA-8xmx-4f3h-rv3w/GHSA-8xmx-4f3h-rv3w.json @@ -7,12 +7,8 @@ "CVE-2020-29489" ], "details": "Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the exposed password to gain access with the privileges of the compromised user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xxp-2wxg-r73w/GHSA-8xxp-2wxg-r73w.json b/advisories/unreviewed/2022/05/GHSA-8xxp-2wxg-r73w/GHSA-8xxp-2wxg-r73w.json index ef8f2d699b1..7f96250b8df 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xxp-2wxg-r73w/GHSA-8xxp-2wxg-r73w.json +++ b/advisories/unreviewed/2022/05/GHSA-8xxp-2wxg-r73w/GHSA-8xxp-2wxg-r73w.json @@ -7,12 +7,8 @@ "CVE-2021-21470" ], "details": "SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-based attacks in applications that accept attacker-controlled XML configuration files. This occurs as logging service does not disable XML external entities when parsing configuration files and a successful exploit would result in limited impact on integrity and availability of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9259-8h7w-9x58/GHSA-9259-8h7w-9x58.json b/advisories/unreviewed/2022/05/GHSA-9259-8h7w-9x58/GHSA-9259-8h7w-9x58.json index 19c6d8a19ce..9901355b203 100644 --- a/advisories/unreviewed/2022/05/GHSA-9259-8h7w-9x58/GHSA-9259-8h7w-9x58.json +++ b/advisories/unreviewed/2022/05/GHSA-9259-8h7w-9x58/GHSA-9259-8h7w-9x58.json @@ -7,12 +7,8 @@ "CVE-2021-1179" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92rw-4752-77x9/GHSA-92rw-4752-77x9.json b/advisories/unreviewed/2022/05/GHSA-92rw-4752-77x9/GHSA-92rw-4752-77x9.json index 1d702cd4c1b..38c2d16af47 100644 --- a/advisories/unreviewed/2022/05/GHSA-92rw-4752-77x9/GHSA-92rw-4752-77x9.json +++ b/advisories/unreviewed/2022/05/GHSA-92rw-4752-77x9/GHSA-92rw-4752-77x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-944w-6c47-g6xp/GHSA-944w-6c47-g6xp.json b/advisories/unreviewed/2022/05/GHSA-944w-6c47-g6xp/GHSA-944w-6c47-g6xp.json index 9e6fac19704..0fed17a1d73 100644 --- a/advisories/unreviewed/2022/05/GHSA-944w-6c47-g6xp/GHSA-944w-6c47-g6xp.json +++ b/advisories/unreviewed/2022/05/GHSA-944w-6c47-g6xp/GHSA-944w-6c47-g6xp.json @@ -7,12 +7,8 @@ "CVE-2020-36175" ], "details": "The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94pr-mrj6-75rc/GHSA-94pr-mrj6-75rc.json b/advisories/unreviewed/2022/05/GHSA-94pr-mrj6-75rc/GHSA-94pr-mrj6-75rc.json index 7eecedede9c..945debf1457 100644 --- a/advisories/unreviewed/2022/05/GHSA-94pr-mrj6-75rc/GHSA-94pr-mrj6-75rc.json +++ b/advisories/unreviewed/2022/05/GHSA-94pr-mrj6-75rc/GHSA-94pr-mrj6-75rc.json @@ -7,12 +7,8 @@ "CVE-2020-5019" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 193655.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-962q-q67c-qr76/GHSA-962q-q67c-qr76.json b/advisories/unreviewed/2022/05/GHSA-962q-q67c-qr76/GHSA-962q-q67c-qr76.json index 00cac5e8b35..5adcdf93e15 100644 --- a/advisories/unreviewed/2022/05/GHSA-962q-q67c-qr76/GHSA-962q-q67c-qr76.json +++ b/advisories/unreviewed/2022/05/GHSA-962q-q67c-qr76/GHSA-962q-q67c-qr76.json @@ -7,12 +7,8 @@ "CVE-2020-23630" ], "details": "A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96m4-c9r6-grgc/GHSA-96m4-c9r6-grgc.json b/advisories/unreviewed/2022/05/GHSA-96m4-c9r6-grgc/GHSA-96m4-c9r6-grgc.json index f645b6859ea..f1eae56ebf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-96m4-c9r6-grgc/GHSA-96m4-c9r6-grgc.json +++ b/advisories/unreviewed/2022/05/GHSA-96m4-c9r6-grgc/GHSA-96m4-c9r6-grgc.json @@ -7,12 +7,8 @@ "CVE-2021-1158" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96m9-r7rv-3jq4/GHSA-96m9-r7rv-3jq4.json b/advisories/unreviewed/2022/05/GHSA-96m9-r7rv-3jq4/GHSA-96m9-r7rv-3jq4.json index c26a3c3cac8..d9d65eb8864 100644 --- a/advisories/unreviewed/2022/05/GHSA-96m9-r7rv-3jq4/GHSA-96m9-r7rv-3jq4.json +++ b/advisories/unreviewed/2022/05/GHSA-96m9-r7rv-3jq4/GHSA-96m9-r7rv-3jq4.json @@ -7,12 +7,8 @@ "CVE-2021-1170" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96qc-3p4r-7pjx/GHSA-96qc-3p4r-7pjx.json b/advisories/unreviewed/2022/05/GHSA-96qc-3p4r-7pjx/GHSA-96qc-3p4r-7pjx.json index eb68e4e0ec1..2d059959ed2 100644 --- a/advisories/unreviewed/2022/05/GHSA-96qc-3p4r-7pjx/GHSA-96qc-3p4r-7pjx.json +++ b/advisories/unreviewed/2022/05/GHSA-96qc-3p4r-7pjx/GHSA-96qc-3p4r-7pjx.json @@ -7,12 +7,8 @@ "CVE-2018-11010" ], "details": "A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97gc-j846-38jc/GHSA-97gc-j846-38jc.json b/advisories/unreviewed/2022/05/GHSA-97gc-j846-38jc/GHSA-97gc-j846-38jc.json index 240b9944096..822eedd6ca8 100644 --- a/advisories/unreviewed/2022/05/GHSA-97gc-j846-38jc/GHSA-97gc-j846-38jc.json +++ b/advisories/unreviewed/2022/05/GHSA-97gc-j846-38jc/GHSA-97gc-j846-38jc.json @@ -7,12 +7,8 @@ "CVE-2019-16956" ], "details": "SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97x2-phf9-hw3v/GHSA-97x2-phf9-hw3v.json b/advisories/unreviewed/2022/05/GHSA-97x2-phf9-hw3v/GHSA-97x2-phf9-hw3v.json index d509f2ac87c..a16bd0119c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-97x2-phf9-hw3v/GHSA-97x2-phf9-hw3v.json +++ b/advisories/unreviewed/2022/05/GHSA-97x2-phf9-hw3v/GHSA-97x2-phf9-hw3v.json @@ -7,12 +7,8 @@ "CVE-2020-28381" ], "details": "A vulnerability has been identified in Solid Edge (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write into uninitialized memory. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97x9-ww3p-2gr4/GHSA-97x9-ww3p-2gr4.json b/advisories/unreviewed/2022/05/GHSA-97x9-ww3p-2gr4/GHSA-97x9-ww3p-2gr4.json index 8550322eaee..82d94dea572 100644 --- a/advisories/unreviewed/2022/05/GHSA-97x9-ww3p-2gr4/GHSA-97x9-ww3p-2gr4.json +++ b/advisories/unreviewed/2022/05/GHSA-97x9-ww3p-2gr4/GHSA-97x9-ww3p-2gr4.json @@ -7,12 +7,8 @@ "CVE-2020-6776" ], "details": "A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or submitting a malicious form. A successful exploit allows the attacker to perform arbitrary actions with the privileges of the victim, e.g. creating and modifying user accounts, changing system configuration settings and cause DoS conditions. Note: For Bosch PRAESIDEO 4.31 and newer and Bosch PRAESENSA in all versions, the confidentiality impact is considered low because user credentials are not shown in the web interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9838-gx4v-3hpg/GHSA-9838-gx4v-3hpg.json b/advisories/unreviewed/2022/05/GHSA-9838-gx4v-3hpg/GHSA-9838-gx4v-3hpg.json index db89533370e..86d7296a1da 100644 --- a/advisories/unreviewed/2022/05/GHSA-9838-gx4v-3hpg/GHSA-9838-gx4v-3hpg.json +++ b/advisories/unreviewed/2022/05/GHSA-9838-gx4v-3hpg/GHSA-9838-gx4v-3hpg.json @@ -7,12 +7,8 @@ "CVE-2021-1174" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98x2-8rq4-gpx2/GHSA-98x2-8rq4-gpx2.json b/advisories/unreviewed/2022/05/GHSA-98x2-8rq4-gpx2/GHSA-98x2-8rq4-gpx2.json index 44bdbb0f65f..08eaa8f98d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-98x2-8rq4-gpx2/GHSA-98x2-8rq4-gpx2.json +++ b/advisories/unreviewed/2022/05/GHSA-98x2-8rq4-gpx2/GHSA-98x2-8rq4-gpx2.json @@ -7,12 +7,8 @@ "CVE-2020-6655" ], "details": "The Eaton's easySoft software v7.20 and prior are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The vulnerability arises due to improper validation and parsing of the E70 file content by the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99cq-hqh8-c6pp/GHSA-99cq-hqh8-c6pp.json b/advisories/unreviewed/2022/05/GHSA-99cq-hqh8-c6pp/GHSA-99cq-hqh8-c6pp.json index 75de82f636f..55e70b2f2af 100644 --- a/advisories/unreviewed/2022/05/GHSA-99cq-hqh8-c6pp/GHSA-99cq-hqh8-c6pp.json +++ b/advisories/unreviewed/2022/05/GHSA-99cq-hqh8-c6pp/GHSA-99cq-hqh8-c6pp.json @@ -7,12 +7,8 @@ "CVE-2020-24003" ], "details": "Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99jg-h7vq-66c7/GHSA-99jg-h7vq-66c7.json b/advisories/unreviewed/2022/05/GHSA-99jg-h7vq-66c7/GHSA-99jg-h7vq-66c7.json index 83d05f08b02..7b8147d8e3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-99jg-h7vq-66c7/GHSA-99jg-h7vq-66c7.json +++ b/advisories/unreviewed/2022/05/GHSA-99jg-h7vq-66c7/GHSA-99jg-h7vq-66c7.json @@ -7,12 +7,8 @@ "CVE-2021-1186" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99mm-5pqr-cw6w/GHSA-99mm-5pqr-cw6w.json b/advisories/unreviewed/2022/05/GHSA-99mm-5pqr-cw6w/GHSA-99mm-5pqr-cw6w.json index c1608a1f2d3..3de5138f8c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-99mm-5pqr-cw6w/GHSA-99mm-5pqr-cw6w.json +++ b/advisories/unreviewed/2022/05/GHSA-99mm-5pqr-cw6w/GHSA-99mm-5pqr-cw6w.json @@ -7,12 +7,8 @@ "CVE-2019-4702" ], "details": "IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99wx-928f-hqw6/GHSA-99wx-928f-hqw6.json b/advisories/unreviewed/2022/05/GHSA-99wx-928f-hqw6/GHSA-99wx-928f-hqw6.json index 6676e20890e..891f01051e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-99wx-928f-hqw6/GHSA-99wx-928f-hqw6.json +++ b/advisories/unreviewed/2022/05/GHSA-99wx-928f-hqw6/GHSA-99wx-928f-hqw6.json @@ -7,12 +7,8 @@ "CVE-2019-15079" ], "details": "A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This vulnerability could be used by an attacker to acquire EAI tokens for free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9c42-4w7m-j868/GHSA-9c42-4w7m-j868.json b/advisories/unreviewed/2022/05/GHSA-9c42-4w7m-j868/GHSA-9c42-4w7m-j868.json index d2d728b9525..3efb090a883 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c42-4w7m-j868/GHSA-9c42-4w7m-j868.json +++ b/advisories/unreviewed/2022/05/GHSA-9c42-4w7m-j868/GHSA-9c42-4w7m-j868.json @@ -7,12 +7,8 @@ "CVE-2020-35834" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cf6-x23r-2w69/GHSA-9cf6-x23r-2w69.json b/advisories/unreviewed/2022/05/GHSA-9cf6-x23r-2w69/GHSA-9cf6-x23r-2w69.json index 16626eb9cc4..3ffde89cf4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cf6-x23r-2w69/GHSA-9cf6-x23r-2w69.json +++ b/advisories/unreviewed/2022/05/GHSA-9cf6-x23r-2w69/GHSA-9cf6-x23r-2w69.json @@ -7,12 +7,8 @@ "CVE-2018-8724" ], "details": "K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g7p-qc7f-rppp/GHSA-9g7p-qc7f-rppp.json b/advisories/unreviewed/2022/05/GHSA-9g7p-qc7f-rppp/GHSA-9g7p-qc7f-rppp.json index 96ea7f2a4ac..669687e7603 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g7p-qc7f-rppp/GHSA-9g7p-qc7f-rppp.json +++ b/advisories/unreviewed/2022/05/GHSA-9g7p-qc7f-rppp/GHSA-9g7p-qc7f-rppp.json @@ -7,12 +7,8 @@ "CVE-2016-9022" ], "details": "Exponent CMS before 2.6.0 has improper input validation in usersController.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json b/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json index d81a19ea9d0..c926b17defe 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json +++ b/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json @@ -7,12 +7,8 @@ "CVE-2020-35241" ], "details": "FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in Blog content via the admin panel. Each time any user will go to that blog page, the XSS triggers and the attacker can steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gxq-wfg7-72x4/GHSA-9gxq-wfg7-72x4.json b/advisories/unreviewed/2022/05/GHSA-9gxq-wfg7-72x4/GHSA-9gxq-wfg7-72x4.json index 759fb6d1e51..5976d415eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gxq-wfg7-72x4/GHSA-9gxq-wfg7-72x4.json +++ b/advisories/unreviewed/2022/05/GHSA-9gxq-wfg7-72x4/GHSA-9gxq-wfg7-72x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hcw-xp2g-53qq/GHSA-9hcw-xp2g-53qq.json b/advisories/unreviewed/2022/05/GHSA-9hcw-xp2g-53qq/GHSA-9hcw-xp2g-53qq.json index 8a011c5696d..9d686916752 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hcw-xp2g-53qq/GHSA-9hcw-xp2g-53qq.json +++ b/advisories/unreviewed/2022/05/GHSA-9hcw-xp2g-53qq/GHSA-9hcw-xp2g-53qq.json @@ -7,12 +7,8 @@ "CVE-2021-0306" ], "details": "In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-154505240.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hg6-fhc4-v9hp/GHSA-9hg6-fhc4-v9hp.json b/advisories/unreviewed/2022/05/GHSA-9hg6-fhc4-v9hp/GHSA-9hg6-fhc4-v9hp.json index 6e9cf7a11b5..07510f90504 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hg6-fhc4-v9hp/GHSA-9hg6-fhc4-v9hp.json +++ b/advisories/unreviewed/2022/05/GHSA-9hg6-fhc4-v9hp/GHSA-9hg6-fhc4-v9hp.json @@ -7,12 +7,8 @@ "CVE-2021-1159" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jxc-x8cc-f2vm/GHSA-9jxc-x8cc-f2vm.json b/advisories/unreviewed/2022/05/GHSA-9jxc-x8cc-f2vm/GHSA-9jxc-x8cc-f2vm.json index 64471dcf0e5..1df0999a9ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jxc-x8cc-f2vm/GHSA-9jxc-x8cc-f2vm.json +++ b/advisories/unreviewed/2022/05/GHSA-9jxc-x8cc-f2vm/GHSA-9jxc-x8cc-f2vm.json @@ -7,12 +7,8 @@ "CVE-2021-0206" ], "details": "A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, resulting in a Denial of Service (DoS). By continuously sending these specific packets, an attacker can repeatedly disable the PFE causing a sustained Denial of Service (DoS). This issue only affects Juniper Networks NFX Series, SRX Series platforms when SSL Proxy is configured. This issue affects Juniper Networks Junos OS on NFX Series and SRX Series: 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R3-S1; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS versions on NFX Series and SRX Series prior to 18.3R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m87-mg83-692p/GHSA-9m87-mg83-692p.json b/advisories/unreviewed/2022/05/GHSA-9m87-mg83-692p/GHSA-9m87-mg83-692p.json index 07688a4407c..b5bd9038996 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m87-mg83-692p/GHSA-9m87-mg83-692p.json +++ b/advisories/unreviewed/2022/05/GHSA-9m87-mg83-692p/GHSA-9m87-mg83-692p.json @@ -7,12 +7,8 @@ "CVE-2020-29019" ], "details": "A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to crash the httpd daemon thread by sending a request with a crafted cookie header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m94-79m8-fpjq/GHSA-9m94-79m8-fpjq.json b/advisories/unreviewed/2022/05/GHSA-9m94-79m8-fpjq/GHSA-9m94-79m8-fpjq.json index 218caf8671d..825a4dd3d8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m94-79m8-fpjq/GHSA-9m94-79m8-fpjq.json +++ b/advisories/unreviewed/2022/05/GHSA-9m94-79m8-fpjq/GHSA-9m94-79m8-fpjq.json @@ -7,12 +7,8 @@ "CVE-2020-35821" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mpj-44vg-wf94/GHSA-9mpj-44vg-wf94.json b/advisories/unreviewed/2022/05/GHSA-9mpj-44vg-wf94/GHSA-9mpj-44vg-wf94.json index f42554d56f6..ff07803f0eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mpj-44vg-wf94/GHSA-9mpj-44vg-wf94.json +++ b/advisories/unreviewed/2022/05/GHSA-9mpj-44vg-wf94/GHSA-9mpj-44vg-wf94.json @@ -7,12 +7,8 @@ "CVE-2020-28208" ], "details": "An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.7.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p5g-qpwr-674r/GHSA-9p5g-qpwr-674r.json b/advisories/unreviewed/2022/05/GHSA-9p5g-qpwr-674r/GHSA-9p5g-qpwr-674r.json index ebf108afb89..002e4ece990 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p5g-qpwr-674r/GHSA-9p5g-qpwr-674r.json +++ b/advisories/unreviewed/2022/05/GHSA-9p5g-qpwr-674r/GHSA-9p5g-qpwr-674r.json @@ -7,12 +7,8 @@ "CVE-2020-16041" ], "details": "Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pq2-v987-f9hr/GHSA-9pq2-v987-f9hr.json b/advisories/unreviewed/2022/05/GHSA-9pq2-v987-f9hr/GHSA-9pq2-v987-f9hr.json index c12963fffe1..6af89d8068e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pq2-v987-f9hr/GHSA-9pq2-v987-f9hr.json +++ b/advisories/unreviewed/2022/05/GHSA-9pq2-v987-f9hr/GHSA-9pq2-v987-f9hr.json @@ -7,12 +7,8 @@ "CVE-2021-1215" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pq7-v5jj-f484/GHSA-9pq7-v5jj-f484.json b/advisories/unreviewed/2022/05/GHSA-9pq7-v5jj-f484/GHSA-9pq7-v5jj-f484.json index 6ed51a0c8c5..9db9342e053 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pq7-v5jj-f484/GHSA-9pq7-v5jj-f484.json +++ b/advisories/unreviewed/2022/05/GHSA-9pq7-v5jj-f484/GHSA-9pq7-v5jj-f484.json @@ -7,12 +7,8 @@ "CVE-2020-36155" ], "details": "An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r48-fh9f-54xj/GHSA-9r48-fh9f-54xj.json b/advisories/unreviewed/2022/05/GHSA-9r48-fh9f-54xj/GHSA-9r48-fh9f-54xj.json index 00b16020739..e7badf138da 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r48-fh9f-54xj/GHSA-9r48-fh9f-54xj.json +++ b/advisories/unreviewed/2022/05/GHSA-9r48-fh9f-54xj/GHSA-9r48-fh9f-54xj.json @@ -7,12 +7,8 @@ "CVE-2021-22493" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The quram library allows attackers to execute arbitrary code or cause a denial of service (memory corruption) during dng decoding. The Samsung ID is SVE-2020-18811 (January 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rmr-65mh-rj57/GHSA-9rmr-65mh-rj57.json b/advisories/unreviewed/2022/05/GHSA-9rmr-65mh-rj57/GHSA-9rmr-65mh-rj57.json index 428fdc32ab5..5c397c7ab2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rmr-65mh-rj57/GHSA-9rmr-65mh-rj57.json +++ b/advisories/unreviewed/2022/05/GHSA-9rmr-65mh-rj57/GHSA-9rmr-65mh-rj57.json @@ -7,12 +7,8 @@ "CVE-2020-26186" ], "details": "Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rpv-24xv-p334/GHSA-9rpv-24xv-p334.json b/advisories/unreviewed/2022/05/GHSA-9rpv-24xv-p334/GHSA-9rpv-24xv-p334.json index 3be3ef2458a..7ad9e5794c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rpv-24xv-p334/GHSA-9rpv-24xv-p334.json +++ b/advisories/unreviewed/2022/05/GHSA-9rpv-24xv-p334/GHSA-9rpv-24xv-p334.json @@ -7,12 +7,8 @@ "CVE-2021-1183" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rx5-vw74-rpgf/GHSA-9rx5-vw74-rpgf.json b/advisories/unreviewed/2022/05/GHSA-9rx5-vw74-rpgf/GHSA-9rx5-vw74-rpgf.json index ddd060f563d..e1cf2331792 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rx5-vw74-rpgf/GHSA-9rx5-vw74-rpgf.json +++ b/advisories/unreviewed/2022/05/GHSA-9rx5-vw74-rpgf/GHSA-9rx5-vw74-rpgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v5g-g6rw-x6vc/GHSA-9v5g-g6rw-x6vc.json b/advisories/unreviewed/2022/05/GHSA-9v5g-g6rw-x6vc/GHSA-9v5g-g6rw-x6vc.json index 028a71b49d2..8fe6c635aff 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5g-g6rw-x6vc/GHSA-9v5g-g6rw-x6vc.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5g-g6rw-x6vc/GHSA-9v5g-g6rw-x6vc.json @@ -7,12 +7,8 @@ "CVE-2020-27279" ], "details": "A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v5r-mvwm-mx35/GHSA-9v5r-mvwm-mx35.json b/advisories/unreviewed/2022/05/GHSA-9v5r-mvwm-mx35/GHSA-9v5r-mvwm-mx35.json index 689f5e4c756..2f71f193783 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5r-mvwm-mx35/GHSA-9v5r-mvwm-mx35.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5r-mvwm-mx35/GHSA-9v5r-mvwm-mx35.json @@ -7,12 +7,8 @@ "CVE-2020-35832" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vr7-48xw-7c8q/GHSA-9vr7-48xw-7c8q.json b/advisories/unreviewed/2022/05/GHSA-9vr7-48xw-7c8q/GHSA-9vr7-48xw-7c8q.json index 60aaed74f9e..025946cbc98 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vr7-48xw-7c8q/GHSA-9vr7-48xw-7c8q.json +++ b/advisories/unreviewed/2022/05/GHSA-9vr7-48xw-7c8q/GHSA-9vr7-48xw-7c8q.json @@ -7,12 +7,8 @@ "CVE-2020-11834" ], "details": "In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not check the parameter len, resulting in a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xp3-9x27-9cfq/GHSA-9xp3-9x27-9cfq.json b/advisories/unreviewed/2022/05/GHSA-9xp3-9x27-9cfq/GHSA-9xp3-9x27-9cfq.json index 4fa4aad742f..71b255cbcaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xp3-9x27-9cfq/GHSA-9xp3-9x27-9cfq.json +++ b/advisories/unreviewed/2022/05/GHSA-9xp3-9x27-9cfq/GHSA-9xp3-9x27-9cfq.json @@ -7,12 +7,8 @@ "CVE-2021-1176" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c27c-3q9w-fj4p/GHSA-c27c-3q9w-fj4p.json b/advisories/unreviewed/2022/05/GHSA-c27c-3q9w-fj4p/GHSA-c27c-3q9w-fj4p.json index 30592a7e798..27ffe1f5aeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-c27c-3q9w-fj4p/GHSA-c27c-3q9w-fj4p.json +++ b/advisories/unreviewed/2022/05/GHSA-c27c-3q9w-fj4p/GHSA-c27c-3q9w-fj4p.json @@ -7,12 +7,8 @@ "CVE-2021-1303" ], "details": "\n A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device.\n The vulnerability is due to improper enforcement of actions for assigned user roles. An attacker could exploit this vulnerability by authenticating as a user with an Observer role and executing commands on the affected device. A successful exploit could allow a user with the Observer role to execute commands to view diagnostic information of the devices that Cisco DNA Center manages.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2c3-chmq-vwx2/GHSA-c2c3-chmq-vwx2.json b/advisories/unreviewed/2022/05/GHSA-c2c3-chmq-vwx2/GHSA-c2c3-chmq-vwx2.json index 6df77ced741..4c67a42607b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2c3-chmq-vwx2/GHSA-c2c3-chmq-vwx2.json +++ b/advisories/unreviewed/2022/05/GHSA-c2c3-chmq-vwx2/GHSA-c2c3-chmq-vwx2.json @@ -7,12 +7,8 @@ "CVE-2020-14274" ], "details": "Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2jc-w78x-gvc4/GHSA-c2jc-w78x-gvc4.json b/advisories/unreviewed/2022/05/GHSA-c2jc-w78x-gvc4/GHSA-c2jc-w78x-gvc4.json index b75d3636d91..5503d266fe7 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2jc-w78x-gvc4/GHSA-c2jc-w78x-gvc4.json +++ b/advisories/unreviewed/2022/05/GHSA-c2jc-w78x-gvc4/GHSA-c2jc-w78x-gvc4.json @@ -7,12 +7,8 @@ "CVE-2021-1996" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2mj-qmxh-xhgx/GHSA-c2mj-qmxh-xhgx.json b/advisories/unreviewed/2022/05/GHSA-c2mj-qmxh-xhgx/GHSA-c2mj-qmxh-xhgx.json index 83556d0a98d..51a3cc6fa05 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2mj-qmxh-xhgx/GHSA-c2mj-qmxh-xhgx.json +++ b/advisories/unreviewed/2022/05/GHSA-c2mj-qmxh-xhgx/GHSA-c2mj-qmxh-xhgx.json @@ -7,12 +7,8 @@ "CVE-2020-35112" ], "details": "If a user downloaded a file lacking an extension on Windows, and then \"Open\"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4mq-vprg-6v7w/GHSA-c4mq-vprg-6v7w.json b/advisories/unreviewed/2022/05/GHSA-c4mq-vprg-6v7w/GHSA-c4mq-vprg-6v7w.json index 7db6dbdf9da..2a799a85dd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4mq-vprg-6v7w/GHSA-c4mq-vprg-6v7w.json +++ b/advisories/unreviewed/2022/05/GHSA-c4mq-vprg-6v7w/GHSA-c4mq-vprg-6v7w.json @@ -7,12 +7,8 @@ "CVE-2020-7845" ], "details": "Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute arbitrary code via crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c94x-m5f4-ghh7/GHSA-c94x-m5f4-ghh7.json b/advisories/unreviewed/2022/05/GHSA-c94x-m5f4-ghh7/GHSA-c94x-m5f4-ghh7.json index dcb2c5647a0..d27bdf0f087 100644 --- a/advisories/unreviewed/2022/05/GHSA-c94x-m5f4-ghh7/GHSA-c94x-m5f4-ghh7.json +++ b/advisories/unreviewed/2022/05/GHSA-c94x-m5f4-ghh7/GHSA-c94x-m5f4-ghh7.json @@ -7,12 +7,8 @@ "CVE-2021-21454" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9f9-9mhq-cpjq/GHSA-c9f9-9mhq-cpjq.json b/advisories/unreviewed/2022/05/GHSA-c9f9-9mhq-cpjq/GHSA-c9f9-9mhq-cpjq.json index 892e07763cb..32eb46f40b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9f9-9mhq-cpjq/GHSA-c9f9-9mhq-cpjq.json +++ b/advisories/unreviewed/2022/05/GHSA-c9f9-9mhq-cpjq/GHSA-c9f9-9mhq-cpjq.json @@ -7,12 +7,8 @@ "CVE-2021-1211" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cchm-6hjg-chgx/GHSA-cchm-6hjg-chgx.json b/advisories/unreviewed/2022/05/GHSA-cchm-6hjg-chgx/GHSA-cchm-6hjg-chgx.json index 7cd93b4666c..99b25104f76 100644 --- a/advisories/unreviewed/2022/05/GHSA-cchm-6hjg-chgx/GHSA-cchm-6hjg-chgx.json +++ b/advisories/unreviewed/2022/05/GHSA-cchm-6hjg-chgx/GHSA-cchm-6hjg-chgx.json @@ -7,12 +7,8 @@ "CVE-2020-5685" ], "details": "UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccm7-x3qr-c5mr/GHSA-ccm7-x3qr-c5mr.json b/advisories/unreviewed/2022/05/GHSA-ccm7-x3qr-c5mr/GHSA-ccm7-x3qr-c5mr.json index 68ada5056a6..f460bd9fe7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccm7-x3qr-c5mr/GHSA-ccm7-x3qr-c5mr.json +++ b/advisories/unreviewed/2022/05/GHSA-ccm7-x3qr-c5mr/GHSA-ccm7-x3qr-c5mr.json @@ -7,12 +7,8 @@ "CVE-2020-16032" ], "details": "Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cff3-jr7v-m727/GHSA-cff3-jr7v-m727.json b/advisories/unreviewed/2022/05/GHSA-cff3-jr7v-m727/GHSA-cff3-jr7v-m727.json index 9b23d526b61..c9336871afd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cff3-jr7v-m727/GHSA-cff3-jr7v-m727.json +++ b/advisories/unreviewed/2022/05/GHSA-cff3-jr7v-m727/GHSA-cff3-jr7v-m727.json @@ -7,12 +7,8 @@ "CVE-2021-22494" ], "details": "An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) software. When a screen protector is used, the required image compensation is not present. Consequently, inversion can occur during fingerprint enrollment, and a high False Recognition Rate (FRR) can occur. The Samsung ID is SVE-2020-19216 (January 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfxj-95gx-6rxg/GHSA-cfxj-95gx-6rxg.json b/advisories/unreviewed/2022/05/GHSA-cfxj-95gx-6rxg/GHSA-cfxj-95gx-6rxg.json index cb25cef5b31..e7f9d347260 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfxj-95gx-6rxg/GHSA-cfxj-95gx-6rxg.json +++ b/advisories/unreviewed/2022/05/GHSA-cfxj-95gx-6rxg/GHSA-cfxj-95gx-6rxg.json @@ -7,12 +7,8 @@ "CVE-2020-26981" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external dtd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg9v-g83h-3phq/GHSA-cg9v-g83h-3phq.json b/advisories/unreviewed/2022/05/GHSA-cg9v-g83h-3phq/GHSA-cg9v-g83h-3phq.json index 7969739da5b..328d6136ea6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg9v-g83h-3phq/GHSA-cg9v-g83h-3phq.json +++ b/advisories/unreviewed/2022/05/GHSA-cg9v-g83h-3phq/GHSA-cg9v-g83h-3phq.json @@ -7,12 +7,8 @@ "CVE-2020-4666" ], "details": "IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186281.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgc9-vr83-r9vv/GHSA-cgc9-vr83-r9vv.json b/advisories/unreviewed/2022/05/GHSA-cgc9-vr83-r9vv/GHSA-cgc9-vr83-r9vv.json index ef6141c9b00..7b7c71139f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgc9-vr83-r9vv/GHSA-cgc9-vr83-r9vv.json +++ b/advisories/unreviewed/2022/05/GHSA-cgc9-vr83-r9vv/GHSA-cgc9-vr83-r9vv.json @@ -7,12 +7,8 @@ "CVE-2021-21110" ], "details": "Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgmg-vh78-2874/GHSA-cgmg-vh78-2874.json b/advisories/unreviewed/2022/05/GHSA-cgmg-vh78-2874/GHSA-cgmg-vh78-2874.json index b77c4a0b643..7b091054b83 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgmg-vh78-2874/GHSA-cgmg-vh78-2874.json +++ b/advisories/unreviewed/2022/05/GHSA-cgmg-vh78-2874/GHSA-cgmg-vh78-2874.json @@ -7,12 +7,8 @@ "CVE-2020-25498" ], "details": "Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and \"Keyword\" in URL Filter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch46-6845-9c7h/GHSA-ch46-6845-9c7h.json b/advisories/unreviewed/2022/05/GHSA-ch46-6845-9c7h/GHSA-ch46-6845-9c7h.json index 8672006331f..8d4019f0838 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch46-6845-9c7h/GHSA-ch46-6845-9c7h.json +++ b/advisories/unreviewed/2022/05/GHSA-ch46-6845-9c7h/GHSA-ch46-6845-9c7h.json @@ -7,12 +7,8 @@ "CVE-2021-23933" ], "details": "OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmfr-9hrr-hpg4/GHSA-cmfr-9hrr-hpg4.json b/advisories/unreviewed/2022/05/GHSA-cmfr-9hrr-hpg4/GHSA-cmfr-9hrr-hpg4.json index 895f6f62bc6..1259d33500a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmfr-9hrr-hpg4/GHSA-cmfr-9hrr-hpg4.json +++ b/advisories/unreviewed/2022/05/GHSA-cmfr-9hrr-hpg4/GHSA-cmfr-9hrr-hpg4.json @@ -7,12 +7,8 @@ "CVE-2020-26975" ], "details": "When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cp3h-pwpw-5h82/GHSA-cp3h-pwpw-5h82.json b/advisories/unreviewed/2022/05/GHSA-cp3h-pwpw-5h82/GHSA-cp3h-pwpw-5h82.json index 19bf26baa6e..6379c590317 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp3h-pwpw-5h82/GHSA-cp3h-pwpw-5h82.json +++ b/advisories/unreviewed/2022/05/GHSA-cp3h-pwpw-5h82/GHSA-cp3h-pwpw-5h82.json @@ -7,12 +7,8 @@ "CVE-2019-20483" ], "details": "An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpq4-98gj-fhjv/GHSA-cpq4-98gj-fhjv.json b/advisories/unreviewed/2022/05/GHSA-cpq4-98gj-fhjv/GHSA-cpq4-98gj-fhjv.json index a3d7e34ab11..de442a2d2a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpq4-98gj-fhjv/GHSA-cpq4-98gj-fhjv.json +++ b/advisories/unreviewed/2022/05/GHSA-cpq4-98gj-fhjv/GHSA-cpq4-98gj-fhjv.json @@ -7,12 +7,8 @@ "CVE-2020-35965" ], "details": "decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr57-r5gm-397j/GHSA-cr57-r5gm-397j.json b/advisories/unreviewed/2022/05/GHSA-cr57-r5gm-397j/GHSA-cr57-r5gm-397j.json index 46f6e97c44e..37d3b4eacbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr57-r5gm-397j/GHSA-cr57-r5gm-397j.json +++ b/advisories/unreviewed/2022/05/GHSA-cr57-r5gm-397j/GHSA-cr57-r5gm-397j.json @@ -7,12 +7,8 @@ "CVE-2020-16033" ], "details": "Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crwc-cm48-x5x4/GHSA-crwc-cm48-x5x4.json b/advisories/unreviewed/2022/05/GHSA-crwc-cm48-x5x4/GHSA-crwc-cm48-x5x4.json index c0beba301f6..79062757d32 100644 --- a/advisories/unreviewed/2022/05/GHSA-crwc-cm48-x5x4/GHSA-crwc-cm48-x5x4.json +++ b/advisories/unreviewed/2022/05/GHSA-crwc-cm48-x5x4/GHSA-crwc-cm48-x5x4.json @@ -7,12 +7,8 @@ "CVE-2021-1153" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv3c-8grj-qrcf/GHSA-cv3c-8grj-qrcf.json b/advisories/unreviewed/2022/05/GHSA-cv3c-8grj-qrcf/GHSA-cv3c-8grj-qrcf.json index 437376aae8b..c16565d93fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv3c-8grj-qrcf/GHSA-cv3c-8grj-qrcf.json +++ b/advisories/unreviewed/2022/05/GHSA-cv3c-8grj-qrcf/GHSA-cv3c-8grj-qrcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvg9-c9g7-9f5r/GHSA-cvg9-c9g7-9f5r.json b/advisories/unreviewed/2022/05/GHSA-cvg9-c9g7-9f5r/GHSA-cvg9-c9g7-9f5r.json index d4fde2f3e3c..b349ca85ab0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvg9-c9g7-9f5r/GHSA-cvg9-c9g7-9f5r.json +++ b/advisories/unreviewed/2022/05/GHSA-cvg9-c9g7-9f5r/GHSA-cvg9-c9g7-9f5r.json @@ -7,12 +7,8 @@ "CVE-2018-9332" ], "details": "K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvrh-6g95-2jv6/GHSA-cvrh-6g95-2jv6.json b/advisories/unreviewed/2022/05/GHSA-cvrh-6g95-2jv6/GHSA-cvrh-6g95-2jv6.json index 269c5b5e966..8c05564d82e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvrh-6g95-2jv6/GHSA-cvrh-6g95-2jv6.json +++ b/advisories/unreviewed/2022/05/GHSA-cvrh-6g95-2jv6/GHSA-cvrh-6g95-2jv6.json @@ -7,12 +7,8 @@ "CVE-2021-1063" ], "details": "NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwwf-85g3-pxwf/GHSA-cwwf-85g3-pxwf.json b/advisories/unreviewed/2022/05/GHSA-cwwf-85g3-pxwf/GHSA-cwwf-85g3-pxwf.json index 46c46904686..33a3e40d0a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwwf-85g3-pxwf/GHSA-cwwf-85g3-pxwf.json +++ b/advisories/unreviewed/2022/05/GHSA-cwwf-85g3-pxwf/GHSA-cwwf-85g3-pxwf.json @@ -7,12 +7,8 @@ "CVE-2020-36172" ], "details": "The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx39-5qm9-xxr4/GHSA-cx39-5qm9-xxr4.json b/advisories/unreviewed/2022/05/GHSA-cx39-5qm9-xxr4/GHSA-cx39-5qm9-xxr4.json index 771fe9d7f23..cb7113c827a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx39-5qm9-xxr4/GHSA-cx39-5qm9-xxr4.json +++ b/advisories/unreviewed/2022/05/GHSA-cx39-5qm9-xxr4/GHSA-cx39-5qm9-xxr4.json @@ -7,12 +7,8 @@ "CVE-2020-4602" ], "details": "IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx4x-7qcr-phfj/GHSA-cx4x-7qcr-phfj.json b/advisories/unreviewed/2022/05/GHSA-cx4x-7qcr-phfj/GHSA-cx4x-7qcr-phfj.json index 044cf7cfdde..47d00fbe4e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx4x-7qcr-phfj/GHSA-cx4x-7qcr-phfj.json +++ b/advisories/unreviewed/2022/05/GHSA-cx4x-7qcr-phfj/GHSA-cx4x-7qcr-phfj.json @@ -7,12 +7,8 @@ "CVE-2020-23631" ], "details": "Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx82-xv8x-vcx3/GHSA-cx82-xv8x-vcx3.json b/advisories/unreviewed/2022/05/GHSA-cx82-xv8x-vcx3/GHSA-cx82-xv8x-vcx3.json index a38bbba5c60..40dc10865ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx82-xv8x-vcx3/GHSA-cx82-xv8x-vcx3.json +++ b/advisories/unreviewed/2022/05/GHSA-cx82-xv8x-vcx3/GHSA-cx82-xv8x-vcx3.json @@ -7,12 +7,8 @@ "CVE-2020-36051" ], "details": "Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx8c-h5wc-m358/GHSA-cx8c-h5wc-m358.json b/advisories/unreviewed/2022/05/GHSA-cx8c-h5wc-m358/GHSA-cx8c-h5wc-m358.json index b68c0adadc8..3d405cb26dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx8c-h5wc-m358/GHSA-cx8c-h5wc-m358.json +++ b/advisories/unreviewed/2022/05/GHSA-cx8c-h5wc-m358/GHSA-cx8c-h5wc-m358.json @@ -7,12 +7,8 @@ "CVE-2020-26982" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CG4 and CGM files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f28r-ffpj-3747/GHSA-f28r-ffpj-3747.json b/advisories/unreviewed/2022/05/GHSA-f28r-ffpj-3747/GHSA-f28r-ffpj-3747.json index 2dbe3272795..6e75ccee2d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f28r-ffpj-3747/GHSA-f28r-ffpj-3747.json +++ b/advisories/unreviewed/2022/05/GHSA-f28r-ffpj-3747/GHSA-f28r-ffpj-3747.json @@ -7,12 +7,8 @@ "CVE-2021-21456" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f33f-4j39-x4gc/GHSA-f33f-4j39-x4gc.json b/advisories/unreviewed/2022/05/GHSA-f33f-4j39-x4gc/GHSA-f33f-4j39-x4gc.json index 3015caf20a8..0ca5b9678f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-f33f-4j39-x4gc/GHSA-f33f-4j39-x4gc.json +++ b/advisories/unreviewed/2022/05/GHSA-f33f-4j39-x4gc/GHSA-f33f-4j39-x4gc.json @@ -7,12 +7,8 @@ "CVE-2020-4606" ], "details": "IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3xm-4hq3-2w74/GHSA-f3xm-4hq3-2w74.json b/advisories/unreviewed/2022/05/GHSA-f3xm-4hq3-2w74/GHSA-f3xm-4hq3-2w74.json index a8bd12217ed..13a80d5ec9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3xm-4hq3-2w74/GHSA-f3xm-4hq3-2w74.json +++ b/advisories/unreviewed/2022/05/GHSA-f3xm-4hq3-2w74/GHSA-f3xm-4hq3-2w74.json @@ -7,12 +7,8 @@ "CVE-2021-1270" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f46j-qjjj-q5vh/GHSA-f46j-qjjj-q5vh.json b/advisories/unreviewed/2022/05/GHSA-f46j-qjjj-q5vh/GHSA-f46j-qjjj-q5vh.json index ec45f95c1c4..b7db4e18b97 100644 --- a/advisories/unreviewed/2022/05/GHSA-f46j-qjjj-q5vh/GHSA-f46j-qjjj-q5vh.json +++ b/advisories/unreviewed/2022/05/GHSA-f46j-qjjj-q5vh/GHSA-f46j-qjjj-q5vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4w8-g7fj-mpg4/GHSA-f4w8-g7fj-mpg4.json b/advisories/unreviewed/2022/05/GHSA-f4w8-g7fj-mpg4/GHSA-f4w8-g7fj-mpg4.json index e5b0818c116..095fd3574a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4w8-g7fj-mpg4/GHSA-f4w8-g7fj-mpg4.json +++ b/advisories/unreviewed/2022/05/GHSA-f4w8-g7fj-mpg4/GHSA-f4w8-g7fj-mpg4.json @@ -7,12 +7,8 @@ "CVE-2020-36159" ], "details": "Veritas Desktop and Laptop Option (DLO) before 9.5 disclosed operational information on the backup processing status through a URL that did not require authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f55g-c9wq-p6hv/GHSA-f55g-c9wq-p6hv.json b/advisories/unreviewed/2022/05/GHSA-f55g-c9wq-p6hv/GHSA-f55g-c9wq-p6hv.json index 8a4fa31766e..759ae59b6f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-f55g-c9wq-p6hv/GHSA-f55g-c9wq-p6hv.json +++ b/advisories/unreviewed/2022/05/GHSA-f55g-c9wq-p6hv/GHSA-f55g-c9wq-p6hv.json @@ -7,12 +7,8 @@ "CVE-2019-16954" ], "details": "SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6rj-2xqc-57mm/GHSA-f6rj-2xqc-57mm.json b/advisories/unreviewed/2022/05/GHSA-f6rj-2xqc-57mm/GHSA-f6rj-2xqc-57mm.json index f02b2abe4bb..5be456dfd45 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6rj-2xqc-57mm/GHSA-f6rj-2xqc-57mm.json +++ b/advisories/unreviewed/2022/05/GHSA-f6rj-2xqc-57mm/GHSA-f6rj-2xqc-57mm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f73m-j2hx-pp49/GHSA-f73m-j2hx-pp49.json b/advisories/unreviewed/2022/05/GHSA-f73m-j2hx-pp49/GHSA-f73m-j2hx-pp49.json index 6f212759483..74bbbc18ce3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f73m-j2hx-pp49/GHSA-f73m-j2hx-pp49.json +++ b/advisories/unreviewed/2022/05/GHSA-f73m-j2hx-pp49/GHSA-f73m-j2hx-pp49.json @@ -7,12 +7,8 @@ "CVE-2020-35936" ], "details": "Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7vm-7p43-fw6x/GHSA-f7vm-7p43-fw6x.json b/advisories/unreviewed/2022/05/GHSA-f7vm-7p43-fw6x/GHSA-f7vm-7p43-fw6x.json index 53b689c853a..8ec05fc3d7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7vm-7p43-fw6x/GHSA-f7vm-7p43-fw6x.json +++ b/advisories/unreviewed/2022/05/GHSA-f7vm-7p43-fw6x/GHSA-f7vm-7p43-fw6x.json @@ -7,12 +7,8 @@ "CVE-2018-20314" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f82q-vw5f-q4cw/GHSA-f82q-vw5f-q4cw.json b/advisories/unreviewed/2022/05/GHSA-f82q-vw5f-q4cw/GHSA-f82q-vw5f-q4cw.json index 780e2ec211e..985ce1f6126 100644 --- a/advisories/unreviewed/2022/05/GHSA-f82q-vw5f-q4cw/GHSA-f82q-vw5f-q4cw.json +++ b/advisories/unreviewed/2022/05/GHSA-f82q-vw5f-q4cw/GHSA-f82q-vw5f-q4cw.json @@ -7,12 +7,8 @@ "CVE-2020-27848" ], "details": "dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8xv-g4pr-rpx5/GHSA-f8xv-g4pr-rpx5.json b/advisories/unreviewed/2022/05/GHSA-f8xv-g4pr-rpx5/GHSA-f8xv-g4pr-rpx5.json index 3d76c4a8fdf..7b4e451fc5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8xv-g4pr-rpx5/GHSA-f8xv-g4pr-rpx5.json +++ b/advisories/unreviewed/2022/05/GHSA-f8xv-g4pr-rpx5/GHSA-f8xv-g4pr-rpx5.json @@ -7,12 +7,8 @@ "CVE-2020-16035" ], "details": "Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9pq-xgqx-2754/GHSA-f9pq-xgqx-2754.json b/advisories/unreviewed/2022/05/GHSA-f9pq-xgqx-2754/GHSA-f9pq-xgqx-2754.json index b87310ab8de..0c4b3e5b4a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9pq-xgqx-2754/GHSA-f9pq-xgqx-2754.json +++ b/advisories/unreviewed/2022/05/GHSA-f9pq-xgqx-2754/GHSA-f9pq-xgqx-2754.json @@ -7,12 +7,8 @@ "CVE-2020-4597" ], "details": "IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 184822.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9x8-qhfh-2jh9/GHSA-f9x8-qhfh-2jh9.json b/advisories/unreviewed/2022/05/GHSA-f9x8-qhfh-2jh9/GHSA-f9x8-qhfh-2jh9.json index c3631e3772d..6efb3d115f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9x8-qhfh-2jh9/GHSA-f9x8-qhfh-2jh9.json +++ b/advisories/unreviewed/2022/05/GHSA-f9x8-qhfh-2jh9/GHSA-f9x8-qhfh-2jh9.json @@ -7,12 +7,8 @@ "CVE-2016-20001" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcpj-4vr6-97f6/GHSA-fcpj-4vr6-97f6.json b/advisories/unreviewed/2022/05/GHSA-fcpj-4vr6-97f6/GHSA-fcpj-4vr6-97f6.json index 460069c402d..498f32bd704 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcpj-4vr6-97f6/GHSA-fcpj-4vr6-97f6.json +++ b/advisories/unreviewed/2022/05/GHSA-fcpj-4vr6-97f6/GHSA-fcpj-4vr6-97f6.json @@ -7,12 +7,8 @@ "CVE-2020-16043" ], "details": "Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ffhw-7rj7-7c3x/GHSA-ffhw-7rj7-7c3x.json b/advisories/unreviewed/2022/05/GHSA-ffhw-7rj7-7c3x/GHSA-ffhw-7rj7-7c3x.json index b0d482e00f9..47aefee84fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffhw-7rj7-7c3x/GHSA-ffhw-7rj7-7c3x.json +++ b/advisories/unreviewed/2022/05/GHSA-ffhw-7rj7-7c3x/GHSA-ffhw-7rj7-7c3x.json @@ -7,12 +7,8 @@ "CVE-2020-28384" ], "details": "A vulnerability has been identified in Solid Edge (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could lead to a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg3h-xxgq-pq9h/GHSA-fg3h-xxgq-pq9h.json b/advisories/unreviewed/2022/05/GHSA-fg3h-xxgq-pq9h/GHSA-fg3h-xxgq-pq9h.json index 4ea2eee2f3a..f2c5f5be1e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg3h-xxgq-pq9h/GHSA-fg3h-xxgq-pq9h.json +++ b/advisories/unreviewed/2022/05/GHSA-fg3h-xxgq-pq9h/GHSA-fg3h-xxgq-pq9h.json @@ -7,12 +7,8 @@ "CVE-2021-1060" ], "details": "NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgc3-w3gg-xj3f/GHSA-fgc3-w3gg-xj3f.json b/advisories/unreviewed/2022/05/GHSA-fgc3-w3gg-xj3f/GHSA-fgc3-w3gg-xj3f.json index 96d5fa7cc66..b6b1f231aee 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgc3-w3gg-xj3f/GHSA-fgc3-w3gg-xj3f.json +++ b/advisories/unreviewed/2022/05/GHSA-fgc3-w3gg-xj3f/GHSA-fgc3-w3gg-xj3f.json @@ -7,12 +7,8 @@ "CVE-2021-3025" ], "details": "Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgjc-j4q7-m9gg/GHSA-fgjc-j4q7-m9gg.json b/advisories/unreviewed/2022/05/GHSA-fgjc-j4q7-m9gg/GHSA-fgjc-j4q7-m9gg.json index b4b0b8ba226..206636baf54 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgjc-j4q7-m9gg/GHSA-fgjc-j4q7-m9gg.json +++ b/advisories/unreviewed/2022/05/GHSA-fgjc-j4q7-m9gg/GHSA-fgjc-j4q7-m9gg.json @@ -7,12 +7,8 @@ "CVE-2020-16119" ], "details": "Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgp2-c6v9-rwf9/GHSA-fgp2-c6v9-rwf9.json b/advisories/unreviewed/2022/05/GHSA-fgp2-c6v9-rwf9/GHSA-fgp2-c6v9-rwf9.json index 4fe2df65c72..8aee9af12ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgp2-c6v9-rwf9/GHSA-fgp2-c6v9-rwf9.json +++ b/advisories/unreviewed/2022/05/GHSA-fgp2-c6v9-rwf9/GHSA-fgp2-c6v9-rwf9.json @@ -7,12 +7,8 @@ "CVE-2021-1180" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhgx-q2mg-m75m/GHSA-fhgx-q2mg-m75m.json b/advisories/unreviewed/2022/05/GHSA-fhgx-q2mg-m75m/GHSA-fhgx-q2mg-m75m.json index ecff4f24366..1944c8f9f33 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhgx-q2mg-m75m/GHSA-fhgx-q2mg-m75m.json +++ b/advisories/unreviewed/2022/05/GHSA-fhgx-q2mg-m75m/GHSA-fhgx-q2mg-m75m.json @@ -7,12 +7,8 @@ "CVE-2021-21449" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj54-mvm9-92fv/GHSA-fj54-mvm9-92fv.json b/advisories/unreviewed/2022/05/GHSA-fj54-mvm9-92fv/GHSA-fj54-mvm9-92fv.json index e66b5a286f7..b6dce8117ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj54-mvm9-92fv/GHSA-fj54-mvm9-92fv.json +++ b/advisories/unreviewed/2022/05/GHSA-fj54-mvm9-92fv/GHSA-fj54-mvm9-92fv.json @@ -7,12 +7,8 @@ "CVE-2020-29490" ], "details": "Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp36-mxpm-8r2j/GHSA-fp36-mxpm-8r2j.json b/advisories/unreviewed/2022/05/GHSA-fp36-mxpm-8r2j/GHSA-fp36-mxpm-8r2j.json index 3f7472f23e9..acfb858e05e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp36-mxpm-8r2j/GHSA-fp36-mxpm-8r2j.json +++ b/advisories/unreviewed/2022/05/GHSA-fp36-mxpm-8r2j/GHSA-fp36-mxpm-8r2j.json @@ -7,12 +7,8 @@ "CVE-2021-1225" ], "details": "\n Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system.\n These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulnerabilities by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp59-hqpm-fm38/GHSA-fp59-hqpm-fm38.json b/advisories/unreviewed/2022/05/GHSA-fp59-hqpm-fm38/GHSA-fp59-hqpm-fm38.json index 806d805a068..a5bdf482662 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp59-hqpm-fm38/GHSA-fp59-hqpm-fm38.json +++ b/advisories/unreviewed/2022/05/GHSA-fp59-hqpm-fm38/GHSA-fp59-hqpm-fm38.json @@ -7,12 +7,8 @@ "CVE-2018-19418" ], "details": "Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqf9-mxr9-9v4v/GHSA-fqf9-mxr9-9v4v.json b/advisories/unreviewed/2022/05/GHSA-fqf9-mxr9-9v4v/GHSA-fqf9-mxr9-9v4v.json index dfaef7e6762..e79231c6a9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqf9-mxr9-9v4v/GHSA-fqf9-mxr9-9v4v.json +++ b/advisories/unreviewed/2022/05/GHSA-fqf9-mxr9-9v4v/GHSA-fqf9-mxr9-9v4v.json @@ -7,12 +7,8 @@ "CVE-2020-4912" ], "details": "IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frj5-x46r-24w8/GHSA-frj5-x46r-24w8.json b/advisories/unreviewed/2022/05/GHSA-frj5-x46r-24w8/GHSA-frj5-x46r-24w8.json index d49a4b3a467..7efdca51a93 100644 --- a/advisories/unreviewed/2022/05/GHSA-frj5-x46r-24w8/GHSA-frj5-x46r-24w8.json +++ b/advisories/unreviewed/2022/05/GHSA-frj5-x46r-24w8/GHSA-frj5-x46r-24w8.json @@ -7,12 +7,8 @@ "CVE-2020-35114" ], "details": "Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv5w-mvmp-j2mj/GHSA-fv5w-mvmp-j2mj.json b/advisories/unreviewed/2022/05/GHSA-fv5w-mvmp-j2mj/GHSA-fv5w-mvmp-j2mj.json index 510fffe88f4..16c6267a1ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv5w-mvmp-j2mj/GHSA-fv5w-mvmp-j2mj.json +++ b/advisories/unreviewed/2022/05/GHSA-fv5w-mvmp-j2mj/GHSA-fv5w-mvmp-j2mj.json @@ -7,12 +7,8 @@ "CVE-2021-1181" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvxj-xw9f-pwm9/GHSA-fvxj-xw9f-pwm9.json b/advisories/unreviewed/2022/05/GHSA-fvxj-xw9f-pwm9/GHSA-fvxj-xw9f-pwm9.json index f4c5be8aa1b..98970ab06d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvxj-xw9f-pwm9/GHSA-fvxj-xw9f-pwm9.json +++ b/advisories/unreviewed/2022/05/GHSA-fvxj-xw9f-pwm9/GHSA-fvxj-xw9f-pwm9.json @@ -7,12 +7,8 @@ "CVE-2021-23929" ], "details": "OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw36-5gff-4jqw/GHSA-fw36-5gff-4jqw.json b/advisories/unreviewed/2022/05/GHSA-fw36-5gff-4jqw/GHSA-fw36-5gff-4jqw.json index 99e6d40184f..2ba2d07cda7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw36-5gff-4jqw/GHSA-fw36-5gff-4jqw.json +++ b/advisories/unreviewed/2022/05/GHSA-fw36-5gff-4jqw/GHSA-fw36-5gff-4jqw.json @@ -7,12 +7,8 @@ "CVE-2021-1177" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwfq-c389-w955/GHSA-fwfq-c389-w955.json b/advisories/unreviewed/2022/05/GHSA-fwfq-c389-w955/GHSA-fwfq-c389-w955.json index d3776932b7a..32a68e570e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwfq-c389-w955/GHSA-fwfq-c389-w955.json +++ b/advisories/unreviewed/2022/05/GHSA-fwfq-c389-w955/GHSA-fwfq-c389-w955.json @@ -7,12 +7,8 @@ "CVE-2020-35939" ], "details": "PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwj9-5x88-wxr5/GHSA-fwj9-5x88-wxr5.json b/advisories/unreviewed/2022/05/GHSA-fwj9-5x88-wxr5/GHSA-fwj9-5x88-wxr5.json index 55e1f628150..b45437b68a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwj9-5x88-wxr5/GHSA-fwj9-5x88-wxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-fwj9-5x88-wxr5/GHSA-fwj9-5x88-wxr5.json @@ -7,12 +7,8 @@ "CVE-2020-9094" ], "details": "There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with specific message properly. Attackers can exploit this vulnerability by sending malicious packet. This can lead to denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx3w-3327-g65c/GHSA-fx3w-3327-g65c.json b/advisories/unreviewed/2022/05/GHSA-fx3w-3327-g65c/GHSA-fx3w-3327-g65c.json index 6e3514e1144..4ac7b321965 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx3w-3327-g65c/GHSA-fx3w-3327-g65c.json +++ b/advisories/unreviewed/2022/05/GHSA-fx3w-3327-g65c/GHSA-fx3w-3327-g65c.json @@ -7,12 +7,8 @@ "CVE-2019-12768" ], "details": "An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3vc-mp64-64gm/GHSA-g3vc-mp64-64gm.json b/advisories/unreviewed/2022/05/GHSA-g3vc-mp64-64gm/GHSA-g3vc-mp64-64gm.json index fb749a44c87..797b5f7c460 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3vc-mp64-64gm/GHSA-g3vc-mp64-64gm.json +++ b/advisories/unreviewed/2022/05/GHSA-g3vc-mp64-64gm/GHSA-g3vc-mp64-64gm.json @@ -7,12 +7,8 @@ "CVE-2020-36170" ], "details": "The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name=\"timestamp\" fields in forms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g442-vq7g-fmrc/GHSA-g442-vq7g-fmrc.json b/advisories/unreviewed/2022/05/GHSA-g442-vq7g-fmrc/GHSA-g442-vq7g-fmrc.json index fcf451fd6cd..6496555bd01 100644 --- a/advisories/unreviewed/2022/05/GHSA-g442-vq7g-fmrc/GHSA-g442-vq7g-fmrc.json +++ b/advisories/unreviewed/2022/05/GHSA-g442-vq7g-fmrc/GHSA-g442-vq7g-fmrc.json @@ -7,12 +7,8 @@ "CVE-2020-16019" ], "details": "Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5f5-c2xf-hc55/GHSA-g5f5-c2xf-hc55.json b/advisories/unreviewed/2022/05/GHSA-g5f5-c2xf-hc55/GHSA-g5f5-c2xf-hc55.json index c2c26f38a4b..777b1834cc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5f5-c2xf-hc55/GHSA-g5f5-c2xf-hc55.json +++ b/advisories/unreviewed/2022/05/GHSA-g5f5-c2xf-hc55/GHSA-g5f5-c2xf-hc55.json @@ -7,12 +7,8 @@ "CVE-2020-26050" ], "details": "SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5q9-9wx3-w9fh/GHSA-g5q9-9wx3-w9fh.json b/advisories/unreviewed/2022/05/GHSA-g5q9-9wx3-w9fh/GHSA-g5q9-9wx3-w9fh.json index 1a3d1b738f5..c868e440d4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5q9-9wx3-w9fh/GHSA-g5q9-9wx3-w9fh.json +++ b/advisories/unreviewed/2022/05/GHSA-g5q9-9wx3-w9fh/GHSA-g5q9-9wx3-w9fh.json @@ -7,12 +7,8 @@ "CVE-2020-29475" ], "details": "nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g626-cx5c-cqr6/GHSA-g626-cx5c-cqr6.json b/advisories/unreviewed/2022/05/GHSA-g626-cx5c-cqr6/GHSA-g626-cx5c-cqr6.json index 5ea66d90f28..2815d0ffd28 100644 --- a/advisories/unreviewed/2022/05/GHSA-g626-cx5c-cqr6/GHSA-g626-cx5c-cqr6.json +++ b/advisories/unreviewed/2022/05/GHSA-g626-cx5c-cqr6/GHSA-g626-cx5c-cqr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6h9-mmp2-jjh2/GHSA-g6h9-mmp2-jjh2.json b/advisories/unreviewed/2022/05/GHSA-g6h9-mmp2-jjh2/GHSA-g6h9-mmp2-jjh2.json index 4529c97161a..565dedf8dee 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6h9-mmp2-jjh2/GHSA-g6h9-mmp2-jjh2.json +++ b/advisories/unreviewed/2022/05/GHSA-g6h9-mmp2-jjh2/GHSA-g6h9-mmp2-jjh2.json @@ -7,12 +7,8 @@ "CVE-2020-26713" ], "details": "REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the response and not escaped leading to the reflected XSS vulnerability. Attackers can exploit vulnerabilities to steal login session information or borrow user rights to perform unauthorized acts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7fc-v5jh-qw54/GHSA-g7fc-v5jh-qw54.json b/advisories/unreviewed/2022/05/GHSA-g7fc-v5jh-qw54/GHSA-g7fc-v5jh-qw54.json index 8359b7970b4..4b6b88331fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7fc-v5jh-qw54/GHSA-g7fc-v5jh-qw54.json +++ b/advisories/unreviewed/2022/05/GHSA-g7fc-v5jh-qw54/GHSA-g7fc-v5jh-qw54.json @@ -7,12 +7,8 @@ "CVE-2019-16747" ], "details": "In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g84f-574q-5p85/GHSA-g84f-574q-5p85.json b/advisories/unreviewed/2022/05/GHSA-g84f-574q-5p85/GHSA-g84f-574q-5p85.json index f1346de1fe2..a7e4f61baa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-g84f-574q-5p85/GHSA-g84f-574q-5p85.json +++ b/advisories/unreviewed/2022/05/GHSA-g84f-574q-5p85/GHSA-g84f-574q-5p85.json @@ -7,12 +7,8 @@ "CVE-2020-16012" ], "details": "Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g89v-h54q-6rcc/GHSA-g89v-h54q-6rcc.json b/advisories/unreviewed/2022/05/GHSA-g89v-h54q-6rcc/GHSA-g89v-h54q-6rcc.json index 4724f6abd44..f9b0a03c082 100644 --- a/advisories/unreviewed/2022/05/GHSA-g89v-h54q-6rcc/GHSA-g89v-h54q-6rcc.json +++ b/advisories/unreviewed/2022/05/GHSA-g89v-h54q-6rcc/GHSA-g89v-h54q-6rcc.json @@ -7,12 +7,8 @@ "CVE-2020-5633" ], "details": "Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8gv-6qwm-g2m8/GHSA-g8gv-6qwm-g2m8.json b/advisories/unreviewed/2022/05/GHSA-g8gv-6qwm-g2m8/GHSA-g8gv-6qwm-g2m8.json index f50ae5b0020..c63057cf4cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8gv-6qwm-g2m8/GHSA-g8gv-6qwm-g2m8.json +++ b/advisories/unreviewed/2022/05/GHSA-g8gv-6qwm-g2m8/GHSA-g8gv-6qwm-g2m8.json @@ -7,12 +7,8 @@ "CVE-2021-1061" ], "details": "NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8hw-8grv-27jh/GHSA-g8hw-8grv-27jh.json b/advisories/unreviewed/2022/05/GHSA-g8hw-8grv-27jh/GHSA-g8hw-8grv-27jh.json index e4fb176e4e5..d3ee5f20f79 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8hw-8grv-27jh/GHSA-g8hw-8grv-27jh.json +++ b/advisories/unreviewed/2022/05/GHSA-g8hw-8grv-27jh/GHSA-g8hw-8grv-27jh.json @@ -7,12 +7,8 @@ "CVE-2020-29299" ], "details": "Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8q3-q7hj-qv33/GHSA-g8q3-q7hj-qv33.json b/advisories/unreviewed/2022/05/GHSA-g8q3-q7hj-qv33/GHSA-g8q3-q7hj-qv33.json index 8f2610054a2..759c7e9121c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8q3-q7hj-qv33/GHSA-g8q3-q7hj-qv33.json +++ b/advisories/unreviewed/2022/05/GHSA-g8q3-q7hj-qv33/GHSA-g8q3-q7hj-qv33.json @@ -7,12 +7,8 @@ "CVE-2020-9207" ], "details": "There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g96f-p224-qwcp/GHSA-g96f-p224-qwcp.json b/advisories/unreviewed/2022/05/GHSA-g96f-p224-qwcp/GHSA-g96f-p224-qwcp.json index 5cce5188873..994d4fd85c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g96f-p224-qwcp/GHSA-g96f-p224-qwcp.json +++ b/advisories/unreviewed/2022/05/GHSA-g96f-p224-qwcp/GHSA-g96f-p224-qwcp.json @@ -7,12 +7,8 @@ "CVE-2020-5018" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9hj-jwc2-h8m7/GHSA-g9hj-jwc2-h8m7.json b/advisories/unreviewed/2022/05/GHSA-g9hj-jwc2-h8m7/GHSA-g9hj-jwc2-h8m7.json index d447b09baeb..9436100a7fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9hj-jwc2-h8m7/GHSA-g9hj-jwc2-h8m7.json +++ b/advisories/unreviewed/2022/05/GHSA-g9hj-jwc2-h8m7/GHSA-g9hj-jwc2-h8m7.json @@ -7,12 +7,8 @@ "CVE-2020-35827" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, XR500 before 2.3.2.56, XR700 before 1.0.1.10, and RAX120 before 1.0.0.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9j8-5mrc-ff94/GHSA-g9j8-5mrc-ff94.json b/advisories/unreviewed/2022/05/GHSA-g9j8-5mrc-ff94/GHSA-g9j8-5mrc-ff94.json index aa35062d081..a6b3e2c78bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9j8-5mrc-ff94/GHSA-g9j8-5mrc-ff94.json +++ b/advisories/unreviewed/2022/05/GHSA-g9j8-5mrc-ff94/GHSA-g9j8-5mrc-ff94.json @@ -7,12 +7,8 @@ "CVE-2021-22492" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetooth chipsets) software. The Bluetooth UART driver has a buffer overflow. The Samsung ID is SVE-2020-18731 (January 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9mq-5vvv-88hf/GHSA-g9mq-5vvv-88hf.json b/advisories/unreviewed/2022/05/GHSA-g9mq-5vvv-88hf/GHSA-g9mq-5vvv-88hf.json index 83510276a14..db1d332d217 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9mq-5vvv-88hf/GHSA-g9mq-5vvv-88hf.json +++ b/advisories/unreviewed/2022/05/GHSA-g9mq-5vvv-88hf/GHSA-g9mq-5vvv-88hf.json @@ -7,12 +7,8 @@ "CVE-2020-27277" ], "details": "Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcp2-mf64-vph6/GHSA-gcp2-mf64-vph6.json b/advisories/unreviewed/2022/05/GHSA-gcp2-mf64-vph6/GHSA-gcp2-mf64-vph6.json index 86f0ad7eff7..65d9a185bfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcp2-mf64-vph6/GHSA-gcp2-mf64-vph6.json +++ b/advisories/unreviewed/2022/05/GHSA-gcp2-mf64-vph6/GHSA-gcp2-mf64-vph6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf7w-9wxw-3pvh/GHSA-gf7w-9wxw-3pvh.json b/advisories/unreviewed/2022/05/GHSA-gf7w-9wxw-3pvh/GHSA-gf7w-9wxw-3pvh.json index 506b586d156..05d5548bb2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf7w-9wxw-3pvh/GHSA-gf7w-9wxw-3pvh.json +++ b/advisories/unreviewed/2022/05/GHSA-gf7w-9wxw-3pvh/GHSA-gf7w-9wxw-3pvh.json @@ -7,12 +7,8 @@ "CVE-2021-1203" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg32-gf45-4mcx/GHSA-gg32-gf45-4mcx.json b/advisories/unreviewed/2022/05/GHSA-gg32-gf45-4mcx/GHSA-gg32-gf45-4mcx.json index cecb3bd03a0..02980f0ec02 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg32-gf45-4mcx/GHSA-gg32-gf45-4mcx.json +++ b/advisories/unreviewed/2022/05/GHSA-gg32-gf45-4mcx/GHSA-gg32-gf45-4mcx.json @@ -7,12 +7,8 @@ "CVE-2021-1064" ], "details": "NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghmp-r6gv-m86f/GHSA-ghmp-r6gv-m86f.json b/advisories/unreviewed/2022/05/GHSA-ghmp-r6gv-m86f/GHSA-ghmp-r6gv-m86f.json index 331a754435e..7f35df66cc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghmp-r6gv-m86f/GHSA-ghmp-r6gv-m86f.json +++ b/advisories/unreviewed/2022/05/GHSA-ghmp-r6gv-m86f/GHSA-ghmp-r6gv-m86f.json @@ -7,12 +7,8 @@ "CVE-2020-26983" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing PDF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghvr-pf77-p73g/GHSA-ghvr-pf77-p73g.json b/advisories/unreviewed/2022/05/GHSA-ghvr-pf77-p73g/GHSA-ghvr-pf77-p73g.json index 4785599e56d..2cfd81a4cd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghvr-pf77-p73g/GHSA-ghvr-pf77-p73g.json +++ b/advisories/unreviewed/2022/05/GHSA-ghvr-pf77-p73g/GHSA-ghvr-pf77-p73g.json @@ -7,12 +7,8 @@ "CVE-2020-2508" ], "details": "A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghwf-37v5-w69f/GHSA-ghwf-37v5-w69f.json b/advisories/unreviewed/2022/05/GHSA-ghwf-37v5-w69f/GHSA-ghwf-37v5-w69f.json index d8f9c80343b..27f20f960a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghwf-37v5-w69f/GHSA-ghwf-37v5-w69f.json +++ b/advisories/unreviewed/2022/05/GHSA-ghwf-37v5-w69f/GHSA-ghwf-37v5-w69f.json @@ -7,12 +7,8 @@ "CVE-2020-16015" ], "details": "Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp5w-f9p7-f7f5/GHSA-gp5w-f9p7-f7f5.json b/advisories/unreviewed/2022/05/GHSA-gp5w-f9p7-f7f5/GHSA-gp5w-f9p7-f7f5.json index fd907ee79c4..8b83cf90761 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp5w-f9p7-f7f5/GHSA-gp5w-f9p7-f7f5.json +++ b/advisories/unreviewed/2022/05/GHSA-gp5w-f9p7-f7f5/GHSA-gp5w-f9p7-f7f5.json @@ -7,12 +7,8 @@ "CVE-2020-35578" ], "details": "An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp8q-5m2c-vprm/GHSA-gp8q-5m2c-vprm.json b/advisories/unreviewed/2022/05/GHSA-gp8q-5m2c-vprm/GHSA-gp8q-5m2c-vprm.json index 75bbd4c4fc2..f0e64de9ab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp8q-5m2c-vprm/GHSA-gp8q-5m2c-vprm.json +++ b/advisories/unreviewed/2022/05/GHSA-gp8q-5m2c-vprm/GHSA-gp8q-5m2c-vprm.json @@ -7,12 +7,8 @@ "CVE-2021-0209" ], "details": "In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause Junos OS Evolved to access an uninitialized pointer causing RPD to core leading to a Denial of Service (DoS). Continued receipt of these types of valid BGP update packets will cause an extended Denial of Service condition. RPD will require a restart to recover. An indicator of compromise is to see if the file rpd.re exists by issuing the command: show system core-dumps This issue affects: Juniper Networks Junos OS Evolved 19.4 versions prior to 19.4R2-S2-EVO; 20.1 versions prior to 20.1R1-S2-EVO, 20.1R2-S1-EVO. This issue does not affect Junos OS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpfp-4wh2-7vm2/GHSA-gpfp-4wh2-7vm2.json b/advisories/unreviewed/2022/05/GHSA-gpfp-4wh2-7vm2/GHSA-gpfp-4wh2-7vm2.json index 44873966a86..028367d701b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpfp-4wh2-7vm2/GHSA-gpfp-4wh2-7vm2.json +++ b/advisories/unreviewed/2022/05/GHSA-gpfp-4wh2-7vm2/GHSA-gpfp-4wh2-7vm2.json @@ -7,12 +7,8 @@ "CVE-2020-35686" ], "details": "The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windows 10 computers, may allow escalation of privilege via a fake DLL. (As a resolution, Windows Update is being submitted for all affected products to update to 2.0.9.18 or later.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpmw-c588-4p7h/GHSA-gpmw-c588-4p7h.json b/advisories/unreviewed/2022/05/GHSA-gpmw-c588-4p7h/GHSA-gpmw-c588-4p7h.json index 2f4c370ec59..9d7d6c0a499 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpmw-c588-4p7h/GHSA-gpmw-c588-4p7h.json +++ b/advisories/unreviewed/2022/05/GHSA-gpmw-c588-4p7h/GHSA-gpmw-c588-4p7h.json @@ -7,12 +7,8 @@ "CVE-2020-35938" ], "details": "PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq4f-x93r-43mj/GHSA-gq4f-x93r-43mj.json b/advisories/unreviewed/2022/05/GHSA-gq4f-x93r-43mj/GHSA-gq4f-x93r-43mj.json index cf5513b3b02..67653ed98af 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq4f-x93r-43mj/GHSA-gq4f-x93r-43mj.json +++ b/advisories/unreviewed/2022/05/GHSA-gq4f-x93r-43mj/GHSA-gq4f-x93r-43mj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq7j-hx55-h62p/GHSA-gq7j-hx55-h62p.json b/advisories/unreviewed/2022/05/GHSA-gq7j-hx55-h62p/GHSA-gq7j-hx55-h62p.json index 792811c453b..5b506e34448 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq7j-hx55-h62p/GHSA-gq7j-hx55-h62p.json +++ b/advisories/unreviewed/2022/05/GHSA-gq7j-hx55-h62p/GHSA-gq7j-hx55-h62p.json @@ -7,12 +7,8 @@ "CVE-2020-5686" ], "details": "Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr2x-jjff-73f3/GHSA-gr2x-jjff-73f3.json b/advisories/unreviewed/2022/05/GHSA-gr2x-jjff-73f3/GHSA-gr2x-jjff-73f3.json index f298ce0d809..2ee159b149f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr2x-jjff-73f3/GHSA-gr2x-jjff-73f3.json +++ b/advisories/unreviewed/2022/05/GHSA-gr2x-jjff-73f3/GHSA-gr2x-jjff-73f3.json @@ -7,12 +7,8 @@ "CVE-2020-16037" ], "details": "Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr45-j35r-73rq/GHSA-gr45-j35r-73rq.json b/advisories/unreviewed/2022/05/GHSA-gr45-j35r-73rq/GHSA-gr45-j35r-73rq.json index 2b77df855c0..f76c5710b99 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr45-j35r-73rq/GHSA-gr45-j35r-73rq.json +++ b/advisories/unreviewed/2022/05/GHSA-gr45-j35r-73rq/GHSA-gr45-j35r-73rq.json @@ -7,12 +7,8 @@ "CVE-2020-29500" ], "details": "Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr4h-9jxj-93vm/GHSA-gr4h-9jxj-93vm.json b/advisories/unreviewed/2022/05/GHSA-gr4h-9jxj-93vm/GHSA-gr4h-9jxj-93vm.json index 083b0528a6c..ab243ca36bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr4h-9jxj-93vm/GHSA-gr4h-9jxj-93vm.json +++ b/advisories/unreviewed/2022/05/GHSA-gr4h-9jxj-93vm/GHSA-gr4h-9jxj-93vm.json @@ -7,12 +7,8 @@ "CVE-2020-26974" ], "details": "When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grgr-vq9q-2h9m/GHSA-grgr-vq9q-2h9m.json b/advisories/unreviewed/2022/05/GHSA-grgr-vq9q-2h9m/GHSA-grgr-vq9q-2h9m.json index 55cd9eab7cd..ac27c893093 100644 --- a/advisories/unreviewed/2022/05/GHSA-grgr-vq9q-2h9m/GHSA-grgr-vq9q-2h9m.json +++ b/advisories/unreviewed/2022/05/GHSA-grgr-vq9q-2h9m/GHSA-grgr-vq9q-2h9m.json @@ -7,12 +7,8 @@ "CVE-2020-35581" ], "details": "A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php request with the meta[title] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvpr-jjwj-3pgg/GHSA-gvpr-jjwj-3pgg.json b/advisories/unreviewed/2022/05/GHSA-gvpr-jjwj-3pgg/GHSA-gvpr-jjwj-3pgg.json index 6d80b60f5ca..62ba214011e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvpr-jjwj-3pgg/GHSA-gvpr-jjwj-3pgg.json +++ b/advisories/unreviewed/2022/05/GHSA-gvpr-jjwj-3pgg/GHSA-gvpr-jjwj-3pgg.json @@ -7,12 +7,8 @@ "CVE-2020-35819" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvxw-rm6f-gffg/GHSA-gvxw-rm6f-gffg.json b/advisories/unreviewed/2022/05/GHSA-gvxw-rm6f-gffg/GHSA-gvxw-rm6f-gffg.json index 458a547069f..2433fbde5fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvxw-rm6f-gffg/GHSA-gvxw-rm6f-gffg.json +++ b/advisories/unreviewed/2022/05/GHSA-gvxw-rm6f-gffg/GHSA-gvxw-rm6f-gffg.json @@ -7,12 +7,8 @@ "CVE-2021-1162" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx2v-252m-68c8/GHSA-gx2v-252m-68c8.json b/advisories/unreviewed/2022/05/GHSA-gx2v-252m-68c8/GHSA-gx2v-252m-68c8.json index b2afb3494b3..9b6877ee6a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx2v-252m-68c8/GHSA-gx2v-252m-68c8.json +++ b/advisories/unreviewed/2022/05/GHSA-gx2v-252m-68c8/GHSA-gx2v-252m-68c8.json @@ -7,12 +7,8 @@ "CVE-2021-21112" ], "details": "Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx5r-j32f-r3vc/GHSA-gx5r-j32f-r3vc.json b/advisories/unreviewed/2022/05/GHSA-gx5r-j32f-r3vc/GHSA-gx5r-j32f-r3vc.json index 8a0fa2fd8bf..923079cff74 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx5r-j32f-r3vc/GHSA-gx5r-j32f-r3vc.json +++ b/advisories/unreviewed/2022/05/GHSA-gx5r-j32f-r3vc/GHSA-gx5r-j32f-r3vc.json @@ -7,12 +7,8 @@ "CVE-2020-27488" ], "details": "Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the \"signature of the update package.\" Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated cloud service for an indeterminate time period (possibly forever). Once an individual device's firmware is updated, and authentication occurs once, the cloud service recategorizes the device so that authentication is subsequently always required, and spoofing cannot occur.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxj7-5cpw-xw2j/GHSA-gxj7-5cpw-xw2j.json b/advisories/unreviewed/2022/05/GHSA-gxj7-5cpw-xw2j/GHSA-gxj7-5cpw-xw2j.json index a096c661b26..eeedd8fb700 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxj7-5cpw-xw2j/GHSA-gxj7-5cpw-xw2j.json +++ b/advisories/unreviewed/2022/05/GHSA-gxj7-5cpw-xw2j/GHSA-gxj7-5cpw-xw2j.json @@ -7,12 +7,8 @@ "CVE-2021-2039" ], "details": "Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Search). Supported versions that are affected are 20.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Core - Server Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - Server Framework accessible data as well as unauthorized update, insert or delete access to some of Siebel Core - Server Framework accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxqw-x97w-h62r/GHSA-gxqw-x97w-h62r.json b/advisories/unreviewed/2022/05/GHSA-gxqw-x97w-h62r/GHSA-gxqw-x97w-h62r.json index d748fa7d0ab..13a67afdc17 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxqw-x97w-h62r/GHSA-gxqw-x97w-h62r.json +++ b/advisories/unreviewed/2022/05/GHSA-gxqw-x97w-h62r/GHSA-gxqw-x97w-h62r.json @@ -7,12 +7,8 @@ "CVE-2021-0308" ], "details": "In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158063095.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h32x-w4cv-wrq9/GHSA-h32x-w4cv-wrq9.json b/advisories/unreviewed/2022/05/GHSA-h32x-w4cv-wrq9/GHSA-h32x-w4cv-wrq9.json index 658fe8a694a..04e5fcc50be 100644 --- a/advisories/unreviewed/2022/05/GHSA-h32x-w4cv-wrq9/GHSA-h32x-w4cv-wrq9.json +++ b/advisories/unreviewed/2022/05/GHSA-h32x-w4cv-wrq9/GHSA-h32x-w4cv-wrq9.json @@ -7,12 +7,8 @@ "CVE-2020-25680" ], "details": "A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5cq-wx25-g7hx/GHSA-h5cq-wx25-g7hx.json b/advisories/unreviewed/2022/05/GHSA-h5cq-wx25-g7hx/GHSA-h5cq-wx25-g7hx.json index b5a5d569755..562dd0bfb89 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5cq-wx25-g7hx/GHSA-h5cq-wx25-g7hx.json +++ b/advisories/unreviewed/2022/05/GHSA-h5cq-wx25-g7hx/GHSA-h5cq-wx25-g7hx.json @@ -7,12 +7,8 @@ "CVE-2021-1166" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5gp-hgjc-h2ch/GHSA-h5gp-hgjc-h2ch.json b/advisories/unreviewed/2022/05/GHSA-h5gp-hgjc-h2ch/GHSA-h5gp-hgjc-h2ch.json index 6cbef51bc5e..fd687f8d9b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5gp-hgjc-h2ch/GHSA-h5gp-hgjc-h2ch.json +++ b/advisories/unreviewed/2022/05/GHSA-h5gp-hgjc-h2ch/GHSA-h5gp-hgjc-h2ch.json @@ -7,12 +7,8 @@ "CVE-2020-4336" ], "details": "IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 177932.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5w7-wjh6-r5wj/GHSA-h5w7-wjh6-r5wj.json b/advisories/unreviewed/2022/05/GHSA-h5w7-wjh6-r5wj/GHSA-h5w7-wjh6-r5wj.json index 90edd643107..60feefe4c9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5w7-wjh6-r5wj/GHSA-h5w7-wjh6-r5wj.json +++ b/advisories/unreviewed/2022/05/GHSA-h5w7-wjh6-r5wj/GHSA-h5w7-wjh6-r5wj.json @@ -7,12 +7,8 @@ "CVE-2021-0322" ], "details": "In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android; Versions: Android-10, Android-11, Android-9; Android ID: A-159145361.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7jm-76x4-67c7/GHSA-h7jm-76x4-67c7.json b/advisories/unreviewed/2022/05/GHSA-h7jm-76x4-67c7/GHSA-h7jm-76x4-67c7.json index f8cd128e1fd..5fcbe3d8c0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7jm-76x4-67c7/GHSA-h7jm-76x4-67c7.json +++ b/advisories/unreviewed/2022/05/GHSA-h7jm-76x4-67c7/GHSA-h7jm-76x4-67c7.json @@ -7,12 +7,8 @@ "CVE-2016-20008" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h7qr-pc33-78hj/GHSA-h7qr-pc33-78hj.json b/advisories/unreviewed/2022/05/GHSA-h7qr-pc33-78hj/GHSA-h7qr-pc33-78hj.json index 160b0f35921..b182e6355a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qr-pc33-78hj/GHSA-h7qr-pc33-78hj.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qr-pc33-78hj/GHSA-h7qr-pc33-78hj.json @@ -7,12 +7,8 @@ "CVE-2020-25842" ], "details": "The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8p7-486m-m9h4/GHSA-h8p7-486m-m9h4.json b/advisories/unreviewed/2022/05/GHSA-h8p7-486m-m9h4/GHSA-h8p7-486m-m9h4.json index 2709cd14731..41a5b47173b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8p7-486m-m9h4/GHSA-h8p7-486m-m9h4.json +++ b/advisories/unreviewed/2022/05/GHSA-h8p7-486m-m9h4/GHSA-h8p7-486m-m9h4.json @@ -7,12 +7,8 @@ "CVE-2020-4600" ], "details": "IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184832.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9qf-rfgj-f3p7/GHSA-h9qf-rfgj-f3p7.json b/advisories/unreviewed/2022/05/GHSA-h9qf-rfgj-f3p7/GHSA-h9qf-rfgj-f3p7.json index d463f0e8718..6e240e33ff7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9qf-rfgj-f3p7/GHSA-h9qf-rfgj-f3p7.json +++ b/advisories/unreviewed/2022/05/GHSA-h9qf-rfgj-f3p7/GHSA-h9qf-rfgj-f3p7.json @@ -7,12 +7,8 @@ "CVE-2020-4761" ], "details": "IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 188895.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc64-fgqq-8m59/GHSA-hc64-fgqq-8m59.json b/advisories/unreviewed/2022/05/GHSA-hc64-fgqq-8m59/GHSA-hc64-fgqq-8m59.json index 9807c5e5827..a6ee8dbab66 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc64-fgqq-8m59/GHSA-hc64-fgqq-8m59.json +++ b/advisories/unreviewed/2022/05/GHSA-hc64-fgqq-8m59/GHSA-hc64-fgqq-8m59.json @@ -7,12 +7,8 @@ "CVE-2021-1190" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc8f-9595-gg78/GHSA-hc8f-9595-gg78.json b/advisories/unreviewed/2022/05/GHSA-hc8f-9595-gg78/GHSA-hc8f-9595-gg78.json index 1438785908f..cd694e9cda3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc8f-9595-gg78/GHSA-hc8f-9595-gg78.json +++ b/advisories/unreviewed/2022/05/GHSA-hc8f-9595-gg78/GHSA-hc8f-9595-gg78.json @@ -7,12 +7,8 @@ "CVE-2020-29496" ], "details": "Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with high privileges could exploit this vulnerability to store malicious HTML or JavaScript code while creating the Enduser. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg4w-g985-vv3m/GHSA-hg4w-g985-vv3m.json b/advisories/unreviewed/2022/05/GHSA-hg4w-g985-vv3m/GHSA-hg4w-g985-vv3m.json index cf2d20a708c..3bfdb4af400 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg4w-g985-vv3m/GHSA-hg4w-g985-vv3m.json +++ b/advisories/unreviewed/2022/05/GHSA-hg4w-g985-vv3m/GHSA-hg4w-g985-vv3m.json @@ -7,12 +7,8 @@ "CVE-2020-29437" ], "details": "SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh59-28c3-fqc2/GHSA-hh59-28c3-fqc2.json b/advisories/unreviewed/2022/05/GHSA-hh59-28c3-fqc2/GHSA-hh59-28c3-fqc2.json index fac845912e5..38b03cfd021 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh59-28c3-fqc2/GHSA-hh59-28c3-fqc2.json +++ b/advisories/unreviewed/2022/05/GHSA-hh59-28c3-fqc2/GHSA-hh59-28c3-fqc2.json @@ -7,12 +7,8 @@ "CVE-2020-35736" ], "details": "GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj7w-jjq4-xh7q/GHSA-hj7w-jjq4-xh7q.json b/advisories/unreviewed/2022/05/GHSA-hj7w-jjq4-xh7q/GHSA-hj7w-jjq4-xh7q.json index d18cf2f090e..e31f832fa1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj7w-jjq4-xh7q/GHSA-hj7w-jjq4-xh7q.json +++ b/advisories/unreviewed/2022/05/GHSA-hj7w-jjq4-xh7q/GHSA-hj7w-jjq4-xh7q.json @@ -7,12 +7,8 @@ "CVE-2021-21115" ], "details": "User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj87-7frf-pcgq/GHSA-hj87-7frf-pcgq.json b/advisories/unreviewed/2022/05/GHSA-hj87-7frf-pcgq/GHSA-hj87-7frf-pcgq.json index 2292a8aeb31..0c320414aaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj87-7frf-pcgq/GHSA-hj87-7frf-pcgq.json +++ b/advisories/unreviewed/2022/05/GHSA-hj87-7frf-pcgq/GHSA-hj87-7frf-pcgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjq3-5xjw-j37q/GHSA-hjq3-5xjw-j37q.json b/advisories/unreviewed/2022/05/GHSA-hjq3-5xjw-j37q/GHSA-hjq3-5xjw-j37q.json index baa18e691f1..0dfd165f76f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjq3-5xjw-j37q/GHSA-hjq3-5xjw-j37q.json +++ b/advisories/unreviewed/2022/05/GHSA-hjq3-5xjw-j37q/GHSA-hjq3-5xjw-j37q.json @@ -7,12 +7,8 @@ "CVE-2020-4544" ], "details": "IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjxr-5xv6-cvq9/GHSA-hjxr-5xv6-cvq9.json b/advisories/unreviewed/2022/05/GHSA-hjxr-5xv6-cvq9/GHSA-hjxr-5xv6-cvq9.json index 3034f1dbca6..156fe040590 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjxr-5xv6-cvq9/GHSA-hjxr-5xv6-cvq9.json +++ b/advisories/unreviewed/2022/05/GHSA-hjxr-5xv6-cvq9/GHSA-hjxr-5xv6-cvq9.json @@ -7,12 +7,8 @@ "CVE-2020-14275" ], "details": "Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm3v-rmvw-rq7w/GHSA-hm3v-rmvw-rq7w.json b/advisories/unreviewed/2022/05/GHSA-hm3v-rmvw-rq7w/GHSA-hm3v-rmvw-rq7w.json index d86309f9a58..32dd12acedc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm3v-rmvw-rq7w/GHSA-hm3v-rmvw-rq7w.json +++ b/advisories/unreviewed/2022/05/GHSA-hm3v-rmvw-rq7w/GHSA-hm3v-rmvw-rq7w.json @@ -7,12 +7,8 @@ "CVE-2021-3021" ], "details": "ISPConfig before 3.2.2 allows SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hmxf-3r58-8g5v/GHSA-hmxf-3r58-8g5v.json b/advisories/unreviewed/2022/05/GHSA-hmxf-3r58-8g5v/GHSA-hmxf-3r58-8g5v.json index a62a0d516f9..8b92a249bd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmxf-3r58-8g5v/GHSA-hmxf-3r58-8g5v.json +++ b/advisories/unreviewed/2022/05/GHSA-hmxf-3r58-8g5v/GHSA-hmxf-3r58-8g5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp27-7h6w-3254/GHSA-hp27-7h6w-3254.json b/advisories/unreviewed/2022/05/GHSA-hp27-7h6w-3254/GHSA-hp27-7h6w-3254.json index feacbfa5a2c..dc5cbde7f3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp27-7h6w-3254/GHSA-hp27-7h6w-3254.json +++ b/advisories/unreviewed/2022/05/GHSA-hp27-7h6w-3254/GHSA-hp27-7h6w-3254.json @@ -7,12 +7,8 @@ "CVE-2021-21451" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SGI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq96-75hc-q3ww/GHSA-hq96-75hc-q3ww.json b/advisories/unreviewed/2022/05/GHSA-hq96-75hc-q3ww/GHSA-hq96-75hc-q3ww.json index 0500171a1a8..414b4689031 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq96-75hc-q3ww/GHSA-hq96-75hc-q3ww.json +++ b/advisories/unreviewed/2022/05/GHSA-hq96-75hc-q3ww/GHSA-hq96-75hc-q3ww.json @@ -7,12 +7,8 @@ "CVE-2020-24027" ], "details": "In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP \"PLAY\" command, when the command specifies seeking by absolute time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqm7-vfw5-95rq/GHSA-hqm7-vfw5-95rq.json b/advisories/unreviewed/2022/05/GHSA-hqm7-vfw5-95rq/GHSA-hqm7-vfw5-95rq.json index b6a327b23e8..b0f348c1381 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqm7-vfw5-95rq/GHSA-hqm7-vfw5-95rq.json +++ b/advisories/unreviewed/2022/05/GHSA-hqm7-vfw5-95rq/GHSA-hqm7-vfw5-95rq.json @@ -7,12 +7,8 @@ "CVE-2020-5147" ], "details": "SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqq7-9p4f-x9pj/GHSA-hqq7-9p4f-x9pj.json b/advisories/unreviewed/2022/05/GHSA-hqq7-9p4f-x9pj/GHSA-hqq7-9p4f-x9pj.json index c2635d83c20..fac51ef22e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqq7-9p4f-x9pj/GHSA-hqq7-9p4f-x9pj.json +++ b/advisories/unreviewed/2022/05/GHSA-hqq7-9p4f-x9pj/GHSA-hqq7-9p4f-x9pj.json @@ -7,12 +7,8 @@ "CVE-2020-8274" ], "details": "Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqvv-6648-f492/GHSA-hqvv-6648-f492.json b/advisories/unreviewed/2022/05/GHSA-hqvv-6648-f492/GHSA-hqvv-6648-f492.json index ec0e86f2cf4..d4b2f3baca1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqvv-6648-f492/GHSA-hqvv-6648-f492.json +++ b/advisories/unreviewed/2022/05/GHSA-hqvv-6648-f492/GHSA-hqvv-6648-f492.json @@ -7,12 +7,8 @@ "CVE-2020-9141" ], "details": "There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information disclosure and malfunctions due to insufficient verification of data authenticity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrpm-72v9-33v3/GHSA-hrpm-72v9-33v3.json b/advisories/unreviewed/2022/05/GHSA-hrpm-72v9-33v3/GHSA-hrpm-72v9-33v3.json index f5c37ba0665..fa582e15c6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrpm-72v9-33v3/GHSA-hrpm-72v9-33v3.json +++ b/advisories/unreviewed/2022/05/GHSA-hrpm-72v9-33v3/GHSA-hrpm-72v9-33v3.json @@ -7,12 +7,8 @@ "CVE-2020-8884" ], "details": "rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hv8p-8h35-vgf5/GHSA-hv8p-8h35-vgf5.json b/advisories/unreviewed/2022/05/GHSA-hv8p-8h35-vgf5/GHSA-hv8p-8h35-vgf5.json index 7be20d81928..a7d02b948e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv8p-8h35-vgf5/GHSA-hv8p-8h35-vgf5.json +++ b/advisories/unreviewed/2022/05/GHSA-hv8p-8h35-vgf5/GHSA-hv8p-8h35-vgf5.json @@ -7,12 +7,8 @@ "CVE-2020-4899" ], "details": "IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across the network. IBM X-Force ID: 190990.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw3p-w63h-mj9c/GHSA-hw3p-w63h-mj9c.json b/advisories/unreviewed/2022/05/GHSA-hw3p-w63h-mj9c/GHSA-hw3p-w63h-mj9c.json index 7b6f01e60c4..529b608092b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw3p-w63h-mj9c/GHSA-hw3p-w63h-mj9c.json +++ b/advisories/unreviewed/2022/05/GHSA-hw3p-w63h-mj9c/GHSA-hw3p-w63h-mj9c.json @@ -7,12 +7,8 @@ "CVE-2019-15523" ], "details": "An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwh7-pqc2-733j/GHSA-hwh7-pqc2-733j.json b/advisories/unreviewed/2022/05/GHSA-hwh7-pqc2-733j/GHSA-hwh7-pqc2-733j.json index 4f27bc97bac..0154f6e9321 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwh7-pqc2-733j/GHSA-hwh7-pqc2-733j.json +++ b/advisories/unreviewed/2022/05/GHSA-hwh7-pqc2-733j/GHSA-hwh7-pqc2-733j.json @@ -7,12 +7,8 @@ "CVE-2021-3111" ], "details": "The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwx9-j325-fw69/GHSA-hwx9-j325-fw69.json b/advisories/unreviewed/2022/05/GHSA-hwx9-j325-fw69/GHSA-hwx9-j325-fw69.json index 42bde71f580..0170fabacae 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwx9-j325-fw69/GHSA-hwx9-j325-fw69.json +++ b/advisories/unreviewed/2022/05/GHSA-hwx9-j325-fw69/GHSA-hwx9-j325-fw69.json @@ -7,12 +7,8 @@ "CVE-2020-26414" ], "details": "An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxc8-899q-wp57/GHSA-hxc8-899q-wp57.json b/advisories/unreviewed/2022/05/GHSA-hxc8-899q-wp57/GHSA-hxc8-899q-wp57.json index 7f381feb249..06a6b36fff5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxc8-899q-wp57/GHSA-hxc8-899q-wp57.json +++ b/advisories/unreviewed/2022/05/GHSA-hxc8-899q-wp57/GHSA-hxc8-899q-wp57.json @@ -7,12 +7,8 @@ "CVE-2020-24701" ], "details": "OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j25r-q825-8mxr/GHSA-j25r-q825-8mxr.json b/advisories/unreviewed/2022/05/GHSA-j25r-q825-8mxr/GHSA-j25r-q825-8mxr.json index a9380c0aec7..ae4318d7b2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j25r-q825-8mxr/GHSA-j25r-q825-8mxr.json +++ b/advisories/unreviewed/2022/05/GHSA-j25r-q825-8mxr/GHSA-j25r-q825-8mxr.json @@ -7,12 +7,8 @@ "CVE-2021-21450" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2c4-gm52-5cf5/GHSA-j2c4-gm52-5cf5.json b/advisories/unreviewed/2022/05/GHSA-j2c4-gm52-5cf5/GHSA-j2c4-gm52-5cf5.json index c90368d2564..61f2d5edf0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2c4-gm52-5cf5/GHSA-j2c4-gm52-5cf5.json +++ b/advisories/unreviewed/2022/05/GHSA-j2c4-gm52-5cf5/GHSA-j2c4-gm52-5cf5.json @@ -7,12 +7,8 @@ "CVE-2020-36112" ], "details": "CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j364-gjm2-cwx8/GHSA-j364-gjm2-cwx8.json b/advisories/unreviewed/2022/05/GHSA-j364-gjm2-cwx8/GHSA-j364-gjm2-cwx8.json index 0e519434fdf..37bb06bddb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j364-gjm2-cwx8/GHSA-j364-gjm2-cwx8.json +++ b/advisories/unreviewed/2022/05/GHSA-j364-gjm2-cwx8/GHSA-j364-gjm2-cwx8.json @@ -7,12 +7,8 @@ "CVE-2021-3139" ], "details": "In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j385-7m59-57jx/GHSA-j385-7m59-57jx.json b/advisories/unreviewed/2022/05/GHSA-j385-7m59-57jx/GHSA-j385-7m59-57jx.json index 344da3a1357..4ba0194dd4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j385-7m59-57jx/GHSA-j385-7m59-57jx.json +++ b/advisories/unreviewed/2022/05/GHSA-j385-7m59-57jx/GHSA-j385-7m59-57jx.json @@ -7,12 +7,8 @@ "CVE-2021-1152" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4vm-fm5v-hp47/GHSA-j4vm-fm5v-hp47.json b/advisories/unreviewed/2022/05/GHSA-j4vm-fm5v-hp47/GHSA-j4vm-fm5v-hp47.json index 0460e26218c..3d3d3ad08bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4vm-fm5v-hp47/GHSA-j4vm-fm5v-hp47.json +++ b/advisories/unreviewed/2022/05/GHSA-j4vm-fm5v-hp47/GHSA-j4vm-fm5v-hp47.json @@ -7,12 +7,8 @@ "CVE-2020-9139" ], "details": "There is a improper input validation vulnerability in some Huawei Smartphone.Successful exploit of this vulnerability can cause memory access errors and denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j52m-vhf5-m2h5/GHSA-j52m-vhf5-m2h5.json b/advisories/unreviewed/2022/05/GHSA-j52m-vhf5-m2h5/GHSA-j52m-vhf5-m2h5.json index b00194dcb6a..6538e144a6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j52m-vhf5-m2h5/GHSA-j52m-vhf5-m2h5.json +++ b/advisories/unreviewed/2022/05/GHSA-j52m-vhf5-m2h5/GHSA-j52m-vhf5-m2h5.json @@ -7,12 +7,8 @@ "CVE-2018-14067" ], "details": "Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all network interfaces (including the external Internet) by default. NOTE: this may overlap CVE-2017-9980.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5fv-c2rq-qx5w/GHSA-j5fv-c2rq-qx5w.json b/advisories/unreviewed/2022/05/GHSA-j5fv-c2rq-qx5w/GHSA-j5fv-c2rq-qx5w.json index f500cf4f016..bf5c80c7108 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5fv-c2rq-qx5w/GHSA-j5fv-c2rq-qx5w.json +++ b/advisories/unreviewed/2022/05/GHSA-j5fv-c2rq-qx5w/GHSA-j5fv-c2rq-qx5w.json @@ -7,12 +7,8 @@ "CVE-2020-16039" ], "details": "Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5vx-99c2-mcfv/GHSA-j5vx-99c2-mcfv.json b/advisories/unreviewed/2022/05/GHSA-j5vx-99c2-mcfv/GHSA-j5vx-99c2-mcfv.json index e85eaad594a..ebd9091871e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5vx-99c2-mcfv/GHSA-j5vx-99c2-mcfv.json +++ b/advisories/unreviewed/2022/05/GHSA-j5vx-99c2-mcfv/GHSA-j5vx-99c2-mcfv.json @@ -7,12 +7,8 @@ "CVE-2018-8044" ], "details": "K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j684-c6q4-x85p/GHSA-j684-c6q4-x85p.json b/advisories/unreviewed/2022/05/GHSA-j684-c6q4-x85p/GHSA-j684-c6q4-x85p.json index fae755b798c..9668360ce88 100644 --- a/advisories/unreviewed/2022/05/GHSA-j684-c6q4-x85p/GHSA-j684-c6q4-x85p.json +++ b/advisories/unreviewed/2022/05/GHSA-j684-c6q4-x85p/GHSA-j684-c6q4-x85p.json @@ -7,12 +7,8 @@ "CVE-2020-4928" ], "details": "IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6j9-67jq-2hgx/GHSA-j6j9-67jq-2hgx.json b/advisories/unreviewed/2022/05/GHSA-j6j9-67jq-2hgx/GHSA-j6j9-67jq-2hgx.json index 6ee927b1a04..1bcf215594c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6j9-67jq-2hgx/GHSA-j6j9-67jq-2hgx.json +++ b/advisories/unreviewed/2022/05/GHSA-j6j9-67jq-2hgx/GHSA-j6j9-67jq-2hgx.json @@ -7,12 +7,8 @@ "CVE-2020-16038" ], "details": "Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6q6-gjjx-g2w9/GHSA-j6q6-gjjx-g2w9.json b/advisories/unreviewed/2022/05/GHSA-j6q6-gjjx-g2w9/GHSA-j6q6-gjjx-g2w9.json index ff7633aded5..88122efa7cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6q6-gjjx-g2w9/GHSA-j6q6-gjjx-g2w9.json +++ b/advisories/unreviewed/2022/05/GHSA-j6q6-gjjx-g2w9/GHSA-j6q6-gjjx-g2w9.json @@ -7,12 +7,8 @@ "CVE-2021-0310" ], "details": "In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Android ID: A-170212632.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7g6-6g73-449h/GHSA-j7g6-6g73-449h.json b/advisories/unreviewed/2022/05/GHSA-j7g6-6g73-449h/GHSA-j7g6-6g73-449h.json index 734b8b31d07..7614c84dbd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7g6-6g73-449h/GHSA-j7g6-6g73-449h.json +++ b/advisories/unreviewed/2022/05/GHSA-j7g6-6g73-449h/GHSA-j7g6-6g73-449h.json @@ -7,12 +7,8 @@ "CVE-2020-35949" ], "details": "An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j89q-qm4p-pm48/GHSA-j89q-qm4p-pm48.json b/advisories/unreviewed/2022/05/GHSA-j89q-qm4p-pm48/GHSA-j89q-qm4p-pm48.json index 71643822daa..b7f88441c14 100644 --- a/advisories/unreviewed/2022/05/GHSA-j89q-qm4p-pm48/GHSA-j89q-qm4p-pm48.json +++ b/advisories/unreviewed/2022/05/GHSA-j89q-qm4p-pm48/GHSA-j89q-qm4p-pm48.json @@ -7,12 +7,8 @@ "CVE-2020-36168" ], "details": "An issue was discovered in Veritas Resiliency Platform 3.4 and 3.5. It leverages OpenSSL on Windows systems when using the Managed Host addon. On start-up, it loads the OpenSSL library. This library may attempt to load the openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\\. A low privileged user can create a C:\\usr\\local\\ssl\\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j94m-42w6-vqp7/GHSA-j94m-42w6-vqp7.json b/advisories/unreviewed/2022/05/GHSA-j94m-42w6-vqp7/GHSA-j94m-42w6-vqp7.json index 7a761b214f0..d29c66ae423 100644 --- a/advisories/unreviewed/2022/05/GHSA-j94m-42w6-vqp7/GHSA-j94m-42w6-vqp7.json +++ b/advisories/unreviewed/2022/05/GHSA-j94m-42w6-vqp7/GHSA-j94m-42w6-vqp7.json @@ -7,12 +7,8 @@ "CVE-2021-1255" ], "details": "Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9g2-35f7-x39p/GHSA-j9g2-35f7-x39p.json b/advisories/unreviewed/2022/05/GHSA-j9g2-35f7-x39p/GHSA-j9g2-35f7-x39p.json index 965c3495364..e55b8058da1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9g2-35f7-x39p/GHSA-j9g2-35f7-x39p.json +++ b/advisories/unreviewed/2022/05/GHSA-j9g2-35f7-x39p/GHSA-j9g2-35f7-x39p.json @@ -7,12 +7,8 @@ "CVE-2021-1283" ], "details": "\n A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to view sensitive information in a system log file that should be restricted.\n The vulnerability exists because sensitive information is not properly masked before it is written to system log files. An attacker could exploit this vulnerability by authenticating to an affected device and inspecting a specific system log file. A successful exploit could allow the attacker to view sensitive information in the system log file. To exploit this vulnerability, the attacker would need to have valid user credentials.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9qv-h9xj-hx5p/GHSA-j9qv-h9xj-hx5p.json b/advisories/unreviewed/2022/05/GHSA-j9qv-h9xj-hx5p/GHSA-j9qv-h9xj-hx5p.json index 59acbb3149d..bb14469f352 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9qv-h9xj-hx5p/GHSA-j9qv-h9xj-hx5p.json +++ b/advisories/unreviewed/2022/05/GHSA-j9qv-h9xj-hx5p/GHSA-j9qv-h9xj-hx5p.json @@ -7,12 +7,8 @@ "CVE-2020-4838" ], "details": "IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9xp-4524-r98c/GHSA-j9xp-4524-r98c.json b/advisories/unreviewed/2022/05/GHSA-j9xp-4524-r98c/GHSA-j9xp-4524-r98c.json index c3c8f2260d2..c9ea29ce7ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9xp-4524-r98c/GHSA-j9xp-4524-r98c.json +++ b/advisories/unreviewed/2022/05/GHSA-j9xp-4524-r98c/GHSA-j9xp-4524-r98c.json @@ -7,12 +7,8 @@ "CVE-2020-28386" ], "details": "A vulnerability has been identified in Solid Edge (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing DFT files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9xr-q95m-m875/GHSA-j9xr-q95m-m875.json b/advisories/unreviewed/2022/05/GHSA-j9xr-q95m-m875/GHSA-j9xr-q95m-m875.json index 9fc2da7c64d..a7103f86b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9xr-q95m-m875/GHSA-j9xr-q95m-m875.json +++ b/advisories/unreviewed/2022/05/GHSA-j9xr-q95m-m875/GHSA-j9xr-q95m-m875.json @@ -7,12 +7,8 @@ "CVE-2021-1250" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcjj-wj46-9ph3/GHSA-jcjj-wj46-9ph3.json b/advisories/unreviewed/2022/05/GHSA-jcjj-wj46-9ph3/GHSA-jcjj-wj46-9ph3.json index c989e071ec3..8ddbdf804b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcjj-wj46-9ph3/GHSA-jcjj-wj46-9ph3.json +++ b/advisories/unreviewed/2022/05/GHSA-jcjj-wj46-9ph3/GHSA-jcjj-wj46-9ph3.json @@ -7,12 +7,8 @@ "CVE-2020-14101" ], "details": "The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcqg-j4q8-3vwg/GHSA-jcqg-j4q8-3vwg.json b/advisories/unreviewed/2022/05/GHSA-jcqg-j4q8-3vwg/GHSA-jcqg-j4q8-3vwg.json index 0240235bdcd..a6a7e97097d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcqg-j4q8-3vwg/GHSA-jcqg-j4q8-3vwg.json +++ b/advisories/unreviewed/2022/05/GHSA-jcqg-j4q8-3vwg/GHSA-jcqg-j4q8-3vwg.json @@ -7,12 +7,8 @@ "CVE-2020-16042" ], "details": "Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf5c-qc6c-fgm8/GHSA-jf5c-qc6c-fgm8.json b/advisories/unreviewed/2022/05/GHSA-jf5c-qc6c-fgm8/GHSA-jf5c-qc6c-fgm8.json index 6c6f75ec32d..12b3f6a1bf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf5c-qc6c-fgm8/GHSA-jf5c-qc6c-fgm8.json +++ b/advisories/unreviewed/2022/05/GHSA-jf5c-qc6c-fgm8/GHSA-jf5c-qc6c-fgm8.json @@ -7,12 +7,8 @@ "CVE-2020-5022" ], "details": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf7p-v9hx-5vrc/GHSA-jf7p-v9hx-5vrc.json b/advisories/unreviewed/2022/05/GHSA-jf7p-v9hx-5vrc/GHSA-jf7p-v9hx-5vrc.json index 0c6ebde0012..170bba18076 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf7p-v9hx-5vrc/GHSA-jf7p-v9hx-5vrc.json +++ b/advisories/unreviewed/2022/05/GHSA-jf7p-v9hx-5vrc/GHSA-jf7p-v9hx-5vrc.json @@ -7,12 +7,8 @@ "CVE-2020-4893" ], "details": "IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man in the middle methods. IBM X-Force ID: 190984.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfwm-3rx7-mcj8/GHSA-jfwm-3rx7-mcj8.json b/advisories/unreviewed/2022/05/GHSA-jfwm-3rx7-mcj8/GHSA-jfwm-3rx7-mcj8.json index 448a03b85e2..b16889bc963 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfwm-3rx7-mcj8/GHSA-jfwm-3rx7-mcj8.json +++ b/advisories/unreviewed/2022/05/GHSA-jfwm-3rx7-mcj8/GHSA-jfwm-3rx7-mcj8.json @@ -7,12 +7,8 @@ "CVE-2020-25797" ], "details": "LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg58-pvw7-8g35/GHSA-jg58-pvw7-8g35.json b/advisories/unreviewed/2022/05/GHSA-jg58-pvw7-8g35/GHSA-jg58-pvw7-8g35.json index 9bb7a51a787..ef3e7a39d40 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg58-pvw7-8g35/GHSA-jg58-pvw7-8g35.json +++ b/advisories/unreviewed/2022/05/GHSA-jg58-pvw7-8g35/GHSA-jg58-pvw7-8g35.json @@ -7,12 +7,8 @@ "CVE-2021-1182" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jggj-8r25-c9r7/GHSA-jggj-8r25-c9r7.json b/advisories/unreviewed/2022/05/GHSA-jggj-8r25-c9r7/GHSA-jggj-8r25-c9r7.json index 0a4253755b9..5e71406aff6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jggj-8r25-c9r7/GHSA-jggj-8r25-c9r7.json +++ b/advisories/unreviewed/2022/05/GHSA-jggj-8r25-c9r7/GHSA-jggj-8r25-c9r7.json @@ -7,12 +7,8 @@ "CVE-2020-4595" ], "details": "IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184819.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh7g-mcqh-6w6x/GHSA-jh7g-mcqh-6w6x.json b/advisories/unreviewed/2022/05/GHSA-jh7g-mcqh-6w6x/GHSA-jh7g-mcqh-6w6x.json index f2ffab9ca25..eb742a3a4d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh7g-mcqh-6w6x/GHSA-jh7g-mcqh-6w6x.json +++ b/advisories/unreviewed/2022/05/GHSA-jh7g-mcqh-6w6x/GHSA-jh7g-mcqh-6w6x.json @@ -7,12 +7,8 @@ "CVE-2020-35612" ], "details": "An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jj9h-68w9-rr33/GHSA-jj9h-68w9-rr33.json b/advisories/unreviewed/2022/05/GHSA-jj9h-68w9-rr33/GHSA-jj9h-68w9-rr33.json index 25466285bc3..9df4230242b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj9h-68w9-rr33/GHSA-jj9h-68w9-rr33.json +++ b/advisories/unreviewed/2022/05/GHSA-jj9h-68w9-rr33/GHSA-jj9h-68w9-rr33.json @@ -7,12 +7,8 @@ "CVE-2018-20309" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmf4-pvqr-x2gx/GHSA-jmf4-pvqr-x2gx.json b/advisories/unreviewed/2022/05/GHSA-jmf4-pvqr-x2gx/GHSA-jmf4-pvqr-x2gx.json index 95ca4b7f9ee..c0ae8691367 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmf4-pvqr-x2gx/GHSA-jmf4-pvqr-x2gx.json +++ b/advisories/unreviewed/2022/05/GHSA-jmf4-pvqr-x2gx/GHSA-jmf4-pvqr-x2gx.json @@ -7,12 +7,8 @@ "CVE-2019-15080" ], "details": "An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo in the constructor of the Owned contract (which is inherited by MORPH Token) allows attackers to acquire contract ownership. A new owner can subsequently obtain MORPH Tokens for free and can perform a DoS attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jprc-322p-6cp4/GHSA-jprc-322p-6cp4.json b/advisories/unreviewed/2022/05/GHSA-jprc-322p-6cp4/GHSA-jprc-322p-6cp4.json index 5bd22ebb011..ceacaed6da4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jprc-322p-6cp4/GHSA-jprc-322p-6cp4.json +++ b/advisories/unreviewed/2022/05/GHSA-jprc-322p-6cp4/GHSA-jprc-322p-6cp4.json @@ -7,12 +7,8 @@ "CVE-2020-35701" ], "details": "An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrh8-929c-jgcv/GHSA-jrh8-929c-jgcv.json b/advisories/unreviewed/2022/05/GHSA-jrh8-929c-jgcv/GHSA-jrh8-929c-jgcv.json index 7777b8043ff..8896a0370a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrh8-929c-jgcv/GHSA-jrh8-929c-jgcv.json +++ b/advisories/unreviewed/2022/05/GHSA-jrh8-929c-jgcv/GHSA-jrh8-929c-jgcv.json @@ -7,12 +7,8 @@ "CVE-2018-19944" ], "details": "A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrm2-4w7g-fjw7/GHSA-jrm2-4w7g-fjw7.json b/advisories/unreviewed/2022/05/GHSA-jrm2-4w7g-fjw7/GHSA-jrm2-4w7g-fjw7.json index c47877bf708..e72f62d2cae 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrm2-4w7g-fjw7/GHSA-jrm2-4w7g-fjw7.json +++ b/advisories/unreviewed/2022/05/GHSA-jrm2-4w7g-fjw7/GHSA-jrm2-4w7g-fjw7.json @@ -7,12 +7,8 @@ "CVE-2021-1178" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrrf-28xq-3v3x/GHSA-jrrf-28xq-3v3x.json b/advisories/unreviewed/2022/05/GHSA-jrrf-28xq-3v3x/GHSA-jrrf-28xq-3v3x.json index d3846285258..e4ec354bbbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrrf-28xq-3v3x/GHSA-jrrf-28xq-3v3x.json +++ b/advisories/unreviewed/2022/05/GHSA-jrrf-28xq-3v3x/GHSA-jrrf-28xq-3v3x.json @@ -7,12 +7,8 @@ "CVE-2021-0313" ], "details": "In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv66-wgjv-q2mw/GHSA-jv66-wgjv-q2mw.json b/advisories/unreviewed/2022/05/GHSA-jv66-wgjv-q2mw/GHSA-jv66-wgjv-q2mw.json index 5e7065f1be6..e5bf1c023ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv66-wgjv-q2mw/GHSA-jv66-wgjv-q2mw.json +++ b/advisories/unreviewed/2022/05/GHSA-jv66-wgjv-q2mw/GHSA-jv66-wgjv-q2mw.json @@ -7,12 +7,8 @@ "CVE-2018-11006" ], "details": "An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw59-g868-rpww/GHSA-jw59-g868-rpww.json b/advisories/unreviewed/2022/05/GHSA-jw59-g868-rpww/GHSA-jw59-g868-rpww.json index b68d861de1e..6611d4f4d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw59-g868-rpww/GHSA-jw59-g868-rpww.json +++ b/advisories/unreviewed/2022/05/GHSA-jw59-g868-rpww/GHSA-jw59-g868-rpww.json @@ -7,12 +7,8 @@ "CVE-2021-21452" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwx3-h29g-4mcg/GHSA-jwx3-h29g-4mcg.json b/advisories/unreviewed/2022/05/GHSA-jwx3-h29g-4mcg/GHSA-jwx3-h29g-4mcg.json index f10645e26d1..7a9581090f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwx3-h29g-4mcg/GHSA-jwx3-h29g-4mcg.json +++ b/advisories/unreviewed/2022/05/GHSA-jwx3-h29g-4mcg/GHSA-jwx3-h29g-4mcg.json @@ -7,12 +7,8 @@ "CVE-2021-0315" ], "details": "In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-169763814.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx3f-3w4x-79wc/GHSA-jx3f-3w4x-79wc.json b/advisories/unreviewed/2022/05/GHSA-jx3f-3w4x-79wc/GHSA-jx3f-3w4x-79wc.json index f3a87b4942d..dc4f1652eb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx3f-3w4x-79wc/GHSA-jx3f-3w4x-79wc.json +++ b/advisories/unreviewed/2022/05/GHSA-jx3f-3w4x-79wc/GHSA-jx3f-3w4x-79wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxpr-3vxp-fp3x/GHSA-jxpr-3vxp-fp3x.json b/advisories/unreviewed/2022/05/GHSA-jxpr-3vxp-fp3x/GHSA-jxpr-3vxp-fp3x.json index a5250be9d00..5c0fdb45af8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxpr-3vxp-fp3x/GHSA-jxpr-3vxp-fp3x.json +++ b/advisories/unreviewed/2022/05/GHSA-jxpr-3vxp-fp3x/GHSA-jxpr-3vxp-fp3x.json @@ -7,12 +7,8 @@ "CVE-2016-20006" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m36c-qvvp-5mjx/GHSA-m36c-qvvp-5mjx.json b/advisories/unreviewed/2022/05/GHSA-m36c-qvvp-5mjx/GHSA-m36c-qvvp-5mjx.json index 13f350310e9..8670d3fb5c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m36c-qvvp-5mjx/GHSA-m36c-qvvp-5mjx.json +++ b/advisories/unreviewed/2022/05/GHSA-m36c-qvvp-5mjx/GHSA-m36c-qvvp-5mjx.json @@ -7,12 +7,8 @@ "CVE-2020-9223" ], "details": "There is a denial of service vulnerability in some Huawei smartphones. Due to the improper processing of received abnormal messages, remote attackers may exploit this vulnerability to cause a denial of service (DoS) on the specific module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3qf-5r58-3mvg/GHSA-m3qf-5r58-3mvg.json b/advisories/unreviewed/2022/05/GHSA-m3qf-5r58-3mvg/GHSA-m3qf-5r58-3mvg.json index 0055403d9d9..dc6c938b483 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3qf-5r58-3mvg/GHSA-m3qf-5r58-3mvg.json +++ b/advisories/unreviewed/2022/05/GHSA-m3qf-5r58-3mvg/GHSA-m3qf-5r58-3mvg.json @@ -7,12 +7,8 @@ "CVE-2020-14097" ], "details": "Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m44f-wcwx-2834/GHSA-m44f-wcwx-2834.json b/advisories/unreviewed/2022/05/GHSA-m44f-wcwx-2834/GHSA-m44f-wcwx-2834.json index c4263bbcc71..f8f9745cda0 100644 --- a/advisories/unreviewed/2022/05/GHSA-m44f-wcwx-2834/GHSA-m44f-wcwx-2834.json +++ b/advisories/unreviewed/2022/05/GHSA-m44f-wcwx-2834/GHSA-m44f-wcwx-2834.json @@ -7,12 +7,8 @@ "CVE-2020-36173" ], "details": "The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4cc-m73q-8mw7/GHSA-m4cc-m73q-8mw7.json b/advisories/unreviewed/2022/05/GHSA-m4cc-m73q-8mw7/GHSA-m4cc-m73q-8mw7.json index dc9cbe52b75..d03b90b203c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4cc-m73q-8mw7/GHSA-m4cc-m73q-8mw7.json +++ b/advisories/unreviewed/2022/05/GHSA-m4cc-m73q-8mw7/GHSA-m4cc-m73q-8mw7.json @@ -7,12 +7,8 @@ "CVE-2020-29017" ], "details": "An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection vulnerability on the Customization page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m596-2w5j-7vgh/GHSA-m596-2w5j-7vgh.json b/advisories/unreviewed/2022/05/GHSA-m596-2w5j-7vgh/GHSA-m596-2w5j-7vgh.json index 9e3adeede9d..b79507bc4f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m596-2w5j-7vgh/GHSA-m596-2w5j-7vgh.json +++ b/advisories/unreviewed/2022/05/GHSA-m596-2w5j-7vgh/GHSA-m596-2w5j-7vgh.json @@ -7,12 +7,8 @@ "CVE-2020-17504" ], "details": "The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in ngpsystemcmd.php in which the http parameters \"x_modules\" and \"y_modules\" are not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5c5-xwjq-ppf4/GHSA-m5c5-xwjq-ppf4.json b/advisories/unreviewed/2022/05/GHSA-m5c5-xwjq-ppf4/GHSA-m5c5-xwjq-ppf4.json index 5bbdeb88213..deb1dd30b7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5c5-xwjq-ppf4/GHSA-m5c5-xwjq-ppf4.json +++ b/advisories/unreviewed/2022/05/GHSA-m5c5-xwjq-ppf4/GHSA-m5c5-xwjq-ppf4.json @@ -7,12 +7,8 @@ "CVE-2021-1164" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5pp-xqx7-796m/GHSA-m5pp-xqx7-796m.json b/advisories/unreviewed/2022/05/GHSA-m5pp-xqx7-796m/GHSA-m5pp-xqx7-796m.json index 35b803d3d87..d7a966ddc09 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5pp-xqx7-796m/GHSA-m5pp-xqx7-796m.json +++ b/advisories/unreviewed/2022/05/GHSA-m5pp-xqx7-796m/GHSA-m5pp-xqx7-796m.json @@ -7,12 +7,8 @@ "CVE-2019-16961" ], "details": "SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6x6-gxj6-rqq5/GHSA-m6x6-gxj6-rqq5.json b/advisories/unreviewed/2022/05/GHSA-m6x6-gxj6-rqq5/GHSA-m6x6-gxj6-rqq5.json index 60e8aa425a3..c0e17df674d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6x6-gxj6-rqq5/GHSA-m6x6-gxj6-rqq5.json +++ b/advisories/unreviewed/2022/05/GHSA-m6x6-gxj6-rqq5/GHSA-m6x6-gxj6-rqq5.json @@ -7,12 +7,8 @@ "CVE-2020-16022" ], "details": "Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6xm-3899-jhmj/GHSA-m6xm-3899-jhmj.json b/advisories/unreviewed/2022/05/GHSA-m6xm-3899-jhmj/GHSA-m6xm-3899-jhmj.json index e8544bca067..6f77bd64ab1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6xm-3899-jhmj/GHSA-m6xm-3899-jhmj.json +++ b/advisories/unreviewed/2022/05/GHSA-m6xm-3899-jhmj/GHSA-m6xm-3899-jhmj.json @@ -7,12 +7,8 @@ "CVE-2021-21455" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7w5-q5c5-xqrr/GHSA-m7w5-q5c5-xqrr.json b/advisories/unreviewed/2022/05/GHSA-m7w5-q5c5-xqrr/GHSA-m7w5-q5c5-xqrr.json index a1e25c655d3..9bacf5e608a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7w5-q5c5-xqrr/GHSA-m7w5-q5c5-xqrr.json +++ b/advisories/unreviewed/2022/05/GHSA-m7w5-q5c5-xqrr/GHSA-m7w5-q5c5-xqrr.json @@ -7,12 +7,8 @@ "CVE-2019-15078" ], "details": "An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The name of the constructor has a typo (wrong case: XBornID versus XBORNID) that allows an attacker to change the owner of the contract and obtain cryptocurrency for free.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7xm-6mh9-6wwv/GHSA-m7xm-6mh9-6wwv.json b/advisories/unreviewed/2022/05/GHSA-m7xm-6mh9-6wwv/GHSA-m7xm-6mh9-6wwv.json index f9034d5e5de..b1074cc2a87 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7xm-6mh9-6wwv/GHSA-m7xm-6mh9-6wwv.json +++ b/advisories/unreviewed/2022/05/GHSA-m7xm-6mh9-6wwv/GHSA-m7xm-6mh9-6wwv.json @@ -7,12 +7,8 @@ "CVE-2021-0319" ], "details": "In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC addresses, with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-167244818.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m82m-22qc-g394/GHSA-m82m-22qc-g394.json b/advisories/unreviewed/2022/05/GHSA-m82m-22qc-g394/GHSA-m82m-22qc-g394.json index 70b2b1a859f..da41e13321d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m82m-22qc-g394/GHSA-m82m-22qc-g394.json +++ b/advisories/unreviewed/2022/05/GHSA-m82m-22qc-g394/GHSA-m82m-22qc-g394.json @@ -7,12 +7,8 @@ "CVE-2020-16027" ], "details": "Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from the user's disk via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m879-r67c-4hhh/GHSA-m879-r67c-4hhh.json b/advisories/unreviewed/2022/05/GHSA-m879-r67c-4hhh/GHSA-m879-r67c-4hhh.json index 3e2098c19e1..a5630259943 100644 --- a/advisories/unreviewed/2022/05/GHSA-m879-r67c-4hhh/GHSA-m879-r67c-4hhh.json +++ b/advisories/unreviewed/2022/05/GHSA-m879-r67c-4hhh/GHSA-m879-r67c-4hhh.json @@ -7,12 +7,8 @@ "CVE-2020-35835" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8w3-4mqx-j486/GHSA-m8w3-4mqx-j486.json b/advisories/unreviewed/2022/05/GHSA-m8w3-4mqx-j486/GHSA-m8w3-4mqx-j486.json index f656ca6f2d2..efddb72b40a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8w3-4mqx-j486/GHSA-m8w3-4mqx-j486.json +++ b/advisories/unreviewed/2022/05/GHSA-m8w3-4mqx-j486/GHSA-m8w3-4mqx-j486.json @@ -7,12 +7,8 @@ "CVE-2020-11947" ], "details": "iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m93g-hpch-vvw7/GHSA-m93g-hpch-vvw7.json b/advisories/unreviewed/2022/05/GHSA-m93g-hpch-vvw7/GHSA-m93g-hpch-vvw7.json index 531a8c5f011..c2c58967ed5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m93g-hpch-vvw7/GHSA-m93g-hpch-vvw7.json +++ b/advisories/unreviewed/2022/05/GHSA-m93g-hpch-vvw7/GHSA-m93g-hpch-vvw7.json @@ -7,12 +7,8 @@ "CVE-2020-8281" ], "details": "A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9rf-7fmw-cww6/GHSA-m9rf-7fmw-cww6.json b/advisories/unreviewed/2022/05/GHSA-m9rf-7fmw-cww6/GHSA-m9rf-7fmw-cww6.json index aa6cabcff34..52f0dea4c08 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9rf-7fmw-cww6/GHSA-m9rf-7fmw-cww6.json +++ b/advisories/unreviewed/2022/05/GHSA-m9rf-7fmw-cww6/GHSA-m9rf-7fmw-cww6.json @@ -7,12 +7,8 @@ "CVE-2020-4594" ], "details": "IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcmp-w9g9-2h7m/GHSA-mcmp-w9g9-2h7m.json b/advisories/unreviewed/2022/05/GHSA-mcmp-w9g9-2h7m/GHSA-mcmp-w9g9-2h7m.json index 12a0f57b70d..758aafaf951 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcmp-w9g9-2h7m/GHSA-mcmp-w9g9-2h7m.json +++ b/advisories/unreviewed/2022/05/GHSA-mcmp-w9g9-2h7m/GHSA-mcmp-w9g9-2h7m.json @@ -7,12 +7,8 @@ "CVE-2020-4599" ], "details": "IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184824.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfgg-fx8q-m7qh/GHSA-mfgg-fx8q-m7qh.json b/advisories/unreviewed/2022/05/GHSA-mfgg-fx8q-m7qh/GHSA-mfgg-fx8q-m7qh.json index 88d945566d1..f6745f2f21a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfgg-fx8q-m7qh/GHSA-mfgg-fx8q-m7qh.json +++ b/advisories/unreviewed/2022/05/GHSA-mfgg-fx8q-m7qh/GHSA-mfgg-fx8q-m7qh.json @@ -7,12 +7,8 @@ "CVE-2016-20004" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg6r-7gcg-995g/GHSA-mg6r-7gcg-995g.json b/advisories/unreviewed/2022/05/GHSA-mg6r-7gcg-995g/GHSA-mg6r-7gcg-995g.json index cbed9b9c60f..7fdabde0e25 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg6r-7gcg-995g/GHSA-mg6r-7gcg-995g.json +++ b/advisories/unreviewed/2022/05/GHSA-mg6r-7gcg-995g/GHSA-mg6r-7gcg-995g.json @@ -7,12 +7,8 @@ "CVE-2021-1226" ], "details": "A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhmp-xjgc-756r/GHSA-mhmp-xjgc-756r.json b/advisories/unreviewed/2022/05/GHSA-mhmp-xjgc-756r/GHSA-mhmp-xjgc-756r.json index 55272167bf6..c3686e9f83d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhmp-xjgc-756r/GHSA-mhmp-xjgc-756r.json +++ b/advisories/unreviewed/2022/05/GHSA-mhmp-xjgc-756r/GHSA-mhmp-xjgc-756r.json @@ -7,12 +7,8 @@ "CVE-2020-9140" ], "details": "There is a vulnerability with buffer access with incorrect length value in some Huawei Smartphone.Unauthorized users may trigger code execution when a buffer overflow occurs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhr3-6pv8-895v/GHSA-mhr3-6pv8-895v.json b/advisories/unreviewed/2022/05/GHSA-mhr3-6pv8-895v/GHSA-mhr3-6pv8-895v.json index 6274dbe37a2..15ae64a8bf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhr3-6pv8-895v/GHSA-mhr3-6pv8-895v.json +++ b/advisories/unreviewed/2022/05/GHSA-mhr3-6pv8-895v/GHSA-mhr3-6pv8-895v.json @@ -7,12 +7,8 @@ "CVE-2020-27281" ], "details": "A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhvc-g5wh-hrxg/GHSA-mhvc-g5wh-hrxg.json b/advisories/unreviewed/2022/05/GHSA-mhvc-g5wh-hrxg/GHSA-mhvc-g5wh-hrxg.json index 734c36b8e36..59bac42cf23 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhvc-g5wh-hrxg/GHSA-mhvc-g5wh-hrxg.json +++ b/advisories/unreviewed/2022/05/GHSA-mhvc-g5wh-hrxg/GHSA-mhvc-g5wh-hrxg.json @@ -7,12 +7,8 @@ "CVE-2021-23124" ], "details": "An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mj97-rpm8-w7h9/GHSA-mj97-rpm8-w7h9.json b/advisories/unreviewed/2022/05/GHSA-mj97-rpm8-w7h9/GHSA-mj97-rpm8-w7h9.json index 5babaa4b362..eac0e80aaab 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj97-rpm8-w7h9/GHSA-mj97-rpm8-w7h9.json +++ b/advisories/unreviewed/2022/05/GHSA-mj97-rpm8-w7h9/GHSA-mj97-rpm8-w7h9.json @@ -7,12 +7,8 @@ "CVE-2020-35838" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjgx-fh7r-8mmh/GHSA-mjgx-fh7r-8mmh.json b/advisories/unreviewed/2022/05/GHSA-mjgx-fh7r-8mmh/GHSA-mjgx-fh7r-8mmh.json index a121ca6ea2d..27a6df9152e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjgx-fh7r-8mmh/GHSA-mjgx-fh7r-8mmh.json +++ b/advisories/unreviewed/2022/05/GHSA-mjgx-fh7r-8mmh/GHSA-mjgx-fh7r-8mmh.json @@ -7,12 +7,8 @@ "CVE-2020-26085" ], "details": "Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjxr-7f24-c564/GHSA-mjxr-7f24-c564.json b/advisories/unreviewed/2022/05/GHSA-mjxr-7f24-c564/GHSA-mjxr-7f24-c564.json index 872f438f61e..689b1abfa51 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjxr-7f24-c564/GHSA-mjxr-7f24-c564.json +++ b/advisories/unreviewed/2022/05/GHSA-mjxr-7f24-c564/GHSA-mjxr-7f24-c564.json @@ -7,12 +7,8 @@ "CVE-2020-35458" ], "details": "An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm25-gp82-85xp/GHSA-mm25-gp82-85xp.json b/advisories/unreviewed/2022/05/GHSA-mm25-gp82-85xp/GHSA-mm25-gp82-85xp.json index 67c8ec62655..556fcc2aa15 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm25-gp82-85xp/GHSA-mm25-gp82-85xp.json +++ b/advisories/unreviewed/2022/05/GHSA-mm25-gp82-85xp/GHSA-mm25-gp82-85xp.json @@ -7,12 +7,8 @@ "CVE-2021-3019" ], "details": "ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm8c-qj5f-qmf3/GHSA-mm8c-qj5f-qmf3.json b/advisories/unreviewed/2022/05/GHSA-mm8c-qj5f-qmf3/GHSA-mm8c-qj5f-qmf3.json index c16e89c2555..0a81be6ea2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm8c-qj5f-qmf3/GHSA-mm8c-qj5f-qmf3.json +++ b/advisories/unreviewed/2022/05/GHSA-mm8c-qj5f-qmf3/GHSA-mm8c-qj5f-qmf3.json @@ -7,12 +7,8 @@ "CVE-2020-16029" ], "details": "Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmm7-m95r-6pxf/GHSA-mmm7-m95r-6pxf.json b/advisories/unreviewed/2022/05/GHSA-mmm7-m95r-6pxf/GHSA-mmm7-m95r-6pxf.json index 8aeda193bf7..40411b4b6fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmm7-m95r-6pxf/GHSA-mmm7-m95r-6pxf.json +++ b/advisories/unreviewed/2022/05/GHSA-mmm7-m95r-6pxf/GHSA-mmm7-m95r-6pxf.json @@ -7,12 +7,8 @@ "CVE-2021-1192" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpc2-x6fj-x52w/GHSA-mpc2-x6fj-x52w.json b/advisories/unreviewed/2022/05/GHSA-mpc2-x6fj-x52w/GHSA-mpc2-x6fj-x52w.json index fcb8d5c75f0..35626fbb7ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpc2-x6fj-x52w/GHSA-mpc2-x6fj-x52w.json +++ b/advisories/unreviewed/2022/05/GHSA-mpc2-x6fj-x52w/GHSA-mpc2-x6fj-x52w.json @@ -7,12 +7,8 @@ "CVE-2021-21453" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq69-2ph6-cgwf/GHSA-mq69-2ph6-cgwf.json b/advisories/unreviewed/2022/05/GHSA-mq69-2ph6-cgwf/GHSA-mq69-2ph6-cgwf.json index f2de1712435..ca902c96f39 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq69-2ph6-cgwf/GHSA-mq69-2ph6-cgwf.json +++ b/advisories/unreviewed/2022/05/GHSA-mq69-2ph6-cgwf/GHSA-mq69-2ph6-cgwf.json @@ -7,12 +7,8 @@ "CVE-2021-23928" ], "details": "OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqp6-5v25-72qq/GHSA-mqp6-5v25-72qq.json b/advisories/unreviewed/2022/05/GHSA-mqp6-5v25-72qq/GHSA-mqp6-5v25-72qq.json index 3ed36f4d3a4..9fcf494e5d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqp6-5v25-72qq/GHSA-mqp6-5v25-72qq.json +++ b/advisories/unreviewed/2022/05/GHSA-mqp6-5v25-72qq/GHSA-mqp6-5v25-72qq.json @@ -7,12 +7,8 @@ "CVE-2020-29193" ], "details": "Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr5h-jvqg-8jg8/GHSA-mr5h-jvqg-8jg8.json b/advisories/unreviewed/2022/05/GHSA-mr5h-jvqg-8jg8/GHSA-mr5h-jvqg-8jg8.json index 8494e16b9d6..b6bb03c0a9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr5h-jvqg-8jg8/GHSA-mr5h-jvqg-8jg8.json +++ b/advisories/unreviewed/2022/05/GHSA-mr5h-jvqg-8jg8/GHSA-mr5h-jvqg-8jg8.json @@ -7,12 +7,8 @@ "CVE-2020-27267" ], "details": "KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr62-x8vh-x4g5/GHSA-mr62-x8vh-x4g5.json b/advisories/unreviewed/2022/05/GHSA-mr62-x8vh-x4g5/GHSA-mr62-x8vh-x4g5.json index 9f9d046d36f..72b99f8f64e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr62-x8vh-x4g5/GHSA-mr62-x8vh-x4g5.json +++ b/advisories/unreviewed/2022/05/GHSA-mr62-x8vh-x4g5/GHSA-mr62-x8vh-x4g5.json @@ -7,12 +7,8 @@ "CVE-2021-1057" ], "details": "NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, denial of service, or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv62-rwhc-m5xf/GHSA-mv62-rwhc-m5xf.json b/advisories/unreviewed/2022/05/GHSA-mv62-rwhc-m5xf/GHSA-mv62-rwhc-m5xf.json index 8efd8f01d89..22a7785dbb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv62-rwhc-m5xf/GHSA-mv62-rwhc-m5xf.json +++ b/advisories/unreviewed/2022/05/GHSA-mv62-rwhc-m5xf/GHSA-mv62-rwhc-m5xf.json @@ -7,12 +7,8 @@ "CVE-2020-9144" ], "details": "There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap overflows due to improper restriction of operations within the bounds of a memory buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv68-j39w-7qfq/GHSA-mv68-j39w-7qfq.json b/advisories/unreviewed/2022/05/GHSA-mv68-j39w-7qfq/GHSA-mv68-j39w-7qfq.json index 19b4673034f..b44903e1d94 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv68-j39w-7qfq/GHSA-mv68-j39w-7qfq.json +++ b/advisories/unreviewed/2022/05/GHSA-mv68-j39w-7qfq/GHSA-mv68-j39w-7qfq.json @@ -7,12 +7,8 @@ "CVE-2020-27368" ], "details": "Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv6x-4xh6-87hm/GHSA-mv6x-4xh6-87hm.json b/advisories/unreviewed/2022/05/GHSA-mv6x-4xh6-87hm/GHSA-mv6x-4xh6-87hm.json index 904e1a9f741..6a3ea004255 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv6x-4xh6-87hm/GHSA-mv6x-4xh6-87hm.json +++ b/advisories/unreviewed/2022/05/GHSA-mv6x-4xh6-87hm/GHSA-mv6x-4xh6-87hm.json @@ -7,12 +7,8 @@ "CVE-2020-4917" ], "details": "IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv75-4vxr-65wq/GHSA-mv75-4vxr-65wq.json b/advisories/unreviewed/2022/05/GHSA-mv75-4vxr-65wq/GHSA-mv75-4vxr-65wq.json index 166b8a28fef..6edcea9bccd 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv75-4vxr-65wq/GHSA-mv75-4vxr-65wq.json +++ b/advisories/unreviewed/2022/05/GHSA-mv75-4vxr-65wq/GHSA-mv75-4vxr-65wq.json @@ -7,12 +7,8 @@ "CVE-2020-16036" ], "details": "Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mvmq-2g5g-4ccc/GHSA-mvmq-2g5g-4ccc.json b/advisories/unreviewed/2022/05/GHSA-mvmq-2g5g-4ccc/GHSA-mvmq-2g5g-4ccc.json index 9d1ec006ff0..64976c3aa12 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvmq-2g5g-4ccc/GHSA-mvmq-2g5g-4ccc.json +++ b/advisories/unreviewed/2022/05/GHSA-mvmq-2g5g-4ccc/GHSA-mvmq-2g5g-4ccc.json @@ -7,12 +7,8 @@ "CVE-2020-19664" ], "details": "DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvwc-vwx4-4x8g/GHSA-mvwc-vwx4-4x8g.json b/advisories/unreviewed/2022/05/GHSA-mvwc-vwx4-4x8g/GHSA-mvwc-vwx4-4x8g.json index 7009712ca73..034e95e8225 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvwc-vwx4-4x8g/GHSA-mvwc-vwx4-4x8g.json +++ b/advisories/unreviewed/2022/05/GHSA-mvwc-vwx4-4x8g/GHSA-mvwc-vwx4-4x8g.json @@ -7,12 +7,8 @@ "CVE-2021-1173" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw8p-fqvp-7r34/GHSA-mw8p-fqvp-7r34.json b/advisories/unreviewed/2022/05/GHSA-mw8p-fqvp-7r34/GHSA-mw8p-fqvp-7r34.json index d3ae224e95c..1ab0d60affa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw8p-fqvp-7r34/GHSA-mw8p-fqvp-7r34.json +++ b/advisories/unreviewed/2022/05/GHSA-mw8p-fqvp-7r34/GHSA-mw8p-fqvp-7r34.json @@ -7,12 +7,8 @@ "CVE-2020-16046" ], "details": "Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx5q-vqqv-9q7f/GHSA-mx5q-vqqv-9q7f.json b/advisories/unreviewed/2022/05/GHSA-mx5q-vqqv-9q7f/GHSA-mx5q-vqqv-9q7f.json index 67d3346c677..4db6388cf61 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx5q-vqqv-9q7f/GHSA-mx5q-vqqv-9q7f.json +++ b/advisories/unreviewed/2022/05/GHSA-mx5q-vqqv-9q7f/GHSA-mx5q-vqqv-9q7f.json @@ -7,12 +7,8 @@ "CVE-2020-28390" ], "details": "A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacker who has access to the Web Client Session Storage could disclose the passwords of currently logged-in users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2jc-8hc7-j466/GHSA-p2jc-8hc7-j466.json b/advisories/unreviewed/2022/05/GHSA-p2jc-8hc7-j466/GHSA-p2jc-8hc7-j466.json index 295514e8ed1..688e1065c49 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2jc-8hc7-j466/GHSA-p2jc-8hc7-j466.json +++ b/advisories/unreviewed/2022/05/GHSA-p2jc-8hc7-j466/GHSA-p2jc-8hc7-j466.json @@ -7,12 +7,8 @@ "CVE-2020-35948" ], "details": "An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p35j-j49h-qh9f/GHSA-p35j-j49h-qh9f.json b/advisories/unreviewed/2022/05/GHSA-p35j-j49h-qh9f/GHSA-p35j-j49h-qh9f.json index 50ce2ed5a90..8afdfae64d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p35j-j49h-qh9f/GHSA-p35j-j49h-qh9f.json +++ b/advisories/unreviewed/2022/05/GHSA-p35j-j49h-qh9f/GHSA-p35j-j49h-qh9f.json @@ -7,12 +7,8 @@ "CVE-2020-7202" ], "details": "A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p523-j8f3-523j/GHSA-p523-j8f3-523j.json b/advisories/unreviewed/2022/05/GHSA-p523-j8f3-523j/GHSA-p523-j8f3-523j.json index 9520b9d3b0e..65eb7eb8b7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p523-j8f3-523j/GHSA-p523-j8f3-523j.json +++ b/advisories/unreviewed/2022/05/GHSA-p523-j8f3-523j/GHSA-p523-j8f3-523j.json @@ -7,12 +7,8 @@ "CVE-2020-25533" ], "details": "An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of posix_spawn.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p53p-8qcj-mq4g/GHSA-p53p-8qcj-mq4g.json b/advisories/unreviewed/2022/05/GHSA-p53p-8qcj-mq4g/GHSA-p53p-8qcj-mq4g.json index 463ee54d37d..6b74829b3f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p53p-8qcj-mq4g/GHSA-p53p-8qcj-mq4g.json +++ b/advisories/unreviewed/2022/05/GHSA-p53p-8qcj-mq4g/GHSA-p53p-8qcj-mq4g.json @@ -7,12 +7,8 @@ "CVE-2020-9203" ], "details": "There is a resource management errors vulnerability in Huawei P30. Local attackers construct broadcast message for some application, causing this application to send this broadcast message and impact the customer's use experience.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p652-vj2w-8mcw/GHSA-p652-vj2w-8mcw.json b/advisories/unreviewed/2022/05/GHSA-p652-vj2w-8mcw/GHSA-p652-vj2w-8mcw.json index 3ba20546650..3ebc3c19db6 100644 --- a/advisories/unreviewed/2022/05/GHSA-p652-vj2w-8mcw/GHSA-p652-vj2w-8mcw.json +++ b/advisories/unreviewed/2022/05/GHSA-p652-vj2w-8mcw/GHSA-p652-vj2w-8mcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p734-gx4c-4737/GHSA-p734-gx4c-4737.json b/advisories/unreviewed/2022/05/GHSA-p734-gx4c-4737/GHSA-p734-gx4c-4737.json index 1c40a5bc479..fa39b9b6396 100644 --- a/advisories/unreviewed/2022/05/GHSA-p734-gx4c-4737/GHSA-p734-gx4c-4737.json +++ b/advisories/unreviewed/2022/05/GHSA-p734-gx4c-4737/GHSA-p734-gx4c-4737.json @@ -7,12 +7,8 @@ "CVE-2021-1165" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p76r-h495-4wc2/GHSA-p76r-h495-4wc2.json b/advisories/unreviewed/2022/05/GHSA-p76r-h495-4wc2/GHSA-p76r-h495-4wc2.json index 5b9dda4bce3..35a412668a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p76r-h495-4wc2/GHSA-p76r-h495-4wc2.json +++ b/advisories/unreviewed/2022/05/GHSA-p76r-h495-4wc2/GHSA-p76r-h495-4wc2.json @@ -7,12 +7,8 @@ "CVE-2021-2038" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7xx-frqx-57x6/GHSA-p7xx-frqx-57x6.json b/advisories/unreviewed/2022/05/GHSA-p7xx-frqx-57x6/GHSA-p7xx-frqx-57x6.json index e295e90b723..91a279e334b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7xx-frqx-57x6/GHSA-p7xx-frqx-57x6.json +++ b/advisories/unreviewed/2022/05/GHSA-p7xx-frqx-57x6/GHSA-p7xx-frqx-57x6.json @@ -7,12 +7,8 @@ "CVE-2020-35937" ], "details": "Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p83v-6fw4-64rm/GHSA-p83v-6fw4-64rm.json b/advisories/unreviewed/2022/05/GHSA-p83v-6fw4-64rm/GHSA-p83v-6fw4-64rm.json index 2f20645864b..0ea0c891725 100644 --- a/advisories/unreviewed/2022/05/GHSA-p83v-6fw4-64rm/GHSA-p83v-6fw4-64rm.json +++ b/advisories/unreviewed/2022/05/GHSA-p83v-6fw4-64rm/GHSA-p83v-6fw4-64rm.json @@ -7,12 +7,8 @@ "CVE-2021-21116" ], "details": "Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p869-hg26-w7c6/GHSA-p869-hg26-w7c6.json b/advisories/unreviewed/2022/05/GHSA-p869-hg26-w7c6/GHSA-p869-hg26-w7c6.json index c9d3db79cff..5d707d11cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p869-hg26-w7c6/GHSA-p869-hg26-w7c6.json +++ b/advisories/unreviewed/2022/05/GHSA-p869-hg26-w7c6/GHSA-p869-hg26-w7c6.json @@ -7,12 +7,8 @@ "CVE-2020-13452" ], "details": "In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p87m-wmf9-45h3/GHSA-p87m-wmf9-45h3.json b/advisories/unreviewed/2022/05/GHSA-p87m-wmf9-45h3/GHSA-p87m-wmf9-45h3.json index 9043194eb72..94a6ca04af8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p87m-wmf9-45h3/GHSA-p87m-wmf9-45h3.json +++ b/advisories/unreviewed/2022/05/GHSA-p87m-wmf9-45h3/GHSA-p87m-wmf9-45h3.json @@ -7,12 +7,8 @@ "CVE-2016-20002" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8f2-32q9-cvxw/GHSA-p8f2-32q9-cvxw.json b/advisories/unreviewed/2022/05/GHSA-p8f2-32q9-cvxw/GHSA-p8f2-32q9-cvxw.json index a387c2fb933..c354ce66ea7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8f2-32q9-cvxw/GHSA-p8f2-32q9-cvxw.json +++ b/advisories/unreviewed/2022/05/GHSA-p8f2-32q9-cvxw/GHSA-p8f2-32q9-cvxw.json @@ -7,12 +7,8 @@ "CVE-2021-1193" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8f4-vrqv-6cp2/GHSA-p8f4-vrqv-6cp2.json b/advisories/unreviewed/2022/05/GHSA-p8f4-vrqv-6cp2/GHSA-p8f4-vrqv-6cp2.json index ea48ca2c045..e060d6d612d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8f4-vrqv-6cp2/GHSA-p8f4-vrqv-6cp2.json +++ b/advisories/unreviewed/2022/05/GHSA-p8f4-vrqv-6cp2/GHSA-p8f4-vrqv-6cp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcrm-wg3j-58j3/GHSA-pcrm-wg3j-58j3.json b/advisories/unreviewed/2022/05/GHSA-pcrm-wg3j-58j3/GHSA-pcrm-wg3j-58j3.json index 411268c853c..436d22397f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcrm-wg3j-58j3/GHSA-pcrm-wg3j-58j3.json +++ b/advisories/unreviewed/2022/05/GHSA-pcrm-wg3j-58j3/GHSA-pcrm-wg3j-58j3.json @@ -7,12 +7,8 @@ "CVE-2021-21109" ], "details": "Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pffp-ch4h-4669/GHSA-pffp-ch4h-4669.json b/advisories/unreviewed/2022/05/GHSA-pffp-ch4h-4669/GHSA-pffp-ch4h-4669.json index 8043441e7f6..e4655a34b77 100644 --- a/advisories/unreviewed/2022/05/GHSA-pffp-ch4h-4669/GHSA-pffp-ch4h-4669.json +++ b/advisories/unreviewed/2022/05/GHSA-pffp-ch4h-4669/GHSA-pffp-ch4h-4669.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg9w-cr87-mrj9/GHSA-pg9w-cr87-mrj9.json b/advisories/unreviewed/2022/05/GHSA-pg9w-cr87-mrj9/GHSA-pg9w-cr87-mrj9.json index 71201b5c9bb..e1d43e647bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg9w-cr87-mrj9/GHSA-pg9w-cr87-mrj9.json +++ b/advisories/unreviewed/2022/05/GHSA-pg9w-cr87-mrj9/GHSA-pg9w-cr87-mrj9.json @@ -7,12 +7,8 @@ "CVE-2021-0342" ], "details": "In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Versions: Android kernel; Android ID: A-146554327.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgm3-3759-c76g/GHSA-pgm3-3759-c76g.json b/advisories/unreviewed/2022/05/GHSA-pgm3-3759-c76g/GHSA-pgm3-3759-c76g.json index 499fa8e58ed..71ff08b8392 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgm3-3759-c76g/GHSA-pgm3-3759-c76g.json +++ b/advisories/unreviewed/2022/05/GHSA-pgm3-3759-c76g/GHSA-pgm3-3759-c76g.json @@ -7,12 +7,8 @@ "CVE-2020-28672" ], "details": "MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be saved to category/[foldername]/index.php causing RCE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgq5-9c6x-f99f/GHSA-pgq5-9c6x-f99f.json b/advisories/unreviewed/2022/05/GHSA-pgq5-9c6x-f99f/GHSA-pgq5-9c6x-f99f.json index 4d9e876ad80..551d9ccbfd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgq5-9c6x-f99f/GHSA-pgq5-9c6x-f99f.json +++ b/advisories/unreviewed/2022/05/GHSA-pgq5-9c6x-f99f/GHSA-pgq5-9c6x-f99f.json @@ -7,12 +7,8 @@ "CVE-2020-16018" ], "details": "Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph9r-85qg-rxh4/GHSA-ph9r-85qg-rxh4.json b/advisories/unreviewed/2022/05/GHSA-ph9r-85qg-rxh4/GHSA-ph9r-85qg-rxh4.json index e1e59ff61f9..54bb30aab99 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph9r-85qg-rxh4/GHSA-ph9r-85qg-rxh4.json +++ b/advisories/unreviewed/2022/05/GHSA-ph9r-85qg-rxh4/GHSA-ph9r-85qg-rxh4.json @@ -7,12 +7,8 @@ "CVE-2021-1210" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjq4-grjv-rg5j/GHSA-pjq4-grjv-rg5j.json b/advisories/unreviewed/2022/05/GHSA-pjq4-grjv-rg5j/GHSA-pjq4-grjv-rg5j.json index 62e323f2f0c..d93091cc7cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjq4-grjv-rg5j/GHSA-pjq4-grjv-rg5j.json +++ b/advisories/unreviewed/2022/05/GHSA-pjq4-grjv-rg5j/GHSA-pjq4-grjv-rg5j.json @@ -7,12 +7,8 @@ "CVE-2021-0205" ], "details": "When the \"Intrusion Detection Service\" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to block unexpected traffic. This issue affects only IPv6 prefixes when used as source and destination. This issue affects MX Series devices using MS-MPC, MS-MIC or MS-SPC3 service cards with IDS service configured. This issue affects: Juniper Networks Junos OS 17.3 versions prior to 17.3R3-S10 on MX Series; 17.4 versions prior to 17.4R3-S3 on MX Series; 18.1 versions prior to 18.1R3-S11 on MX Series; 18.2 versions prior to 18.2R3-S6 on MX Series; 18.3 versions prior to 18.3R3-S4 on MX Series; 18.4 versions prior to 18.4R3-S6 on MX Series; 19.1 versions prior to 19.1R2-S2, 19.1R3-S3 on MX Series; 19.2 versions prior to 19.2R3-S1 on MX Series; 19.3 versions prior to 19.3R2-S5, 19.3R3-S1 on MX Series; 19.4 versions prior to 19.4R3 on MX Series; 20.1 versions prior to 20.1R2 on MX Series; 20.2 versions prior to 20.2R2 on MX Series;", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppjx-q6h7-v8hx/GHSA-ppjx-q6h7-v8hx.json b/advisories/unreviewed/2022/05/GHSA-ppjx-q6h7-v8hx/GHSA-ppjx-q6h7-v8hx.json index 81b78bd45fe..91ffeb94b70 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppjx-q6h7-v8hx/GHSA-ppjx-q6h7-v8hx.json +++ b/advisories/unreviewed/2022/05/GHSA-ppjx-q6h7-v8hx/GHSA-ppjx-q6h7-v8hx.json @@ -7,12 +7,8 @@ "CVE-2016-9023" ], "details": "Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppx6-vv9m-fpgm/GHSA-ppx6-vv9m-fpgm.json b/advisories/unreviewed/2022/05/GHSA-ppx6-vv9m-fpgm/GHSA-ppx6-vv9m-fpgm.json index eafa3dc5943..ee1aac27507 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppx6-vv9m-fpgm/GHSA-ppx6-vv9m-fpgm.json +++ b/advisories/unreviewed/2022/05/GHSA-ppx6-vv9m-fpgm/GHSA-ppx6-vv9m-fpgm.json @@ -7,12 +7,8 @@ "CVE-2020-24903" ], "details": "Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr3j-rqpg-432w/GHSA-pr3j-rqpg-432w.json b/advisories/unreviewed/2022/05/GHSA-pr3j-rqpg-432w/GHSA-pr3j-rqpg-432w.json index 8883d128c92..f45d1a2a852 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr3j-rqpg-432w/GHSA-pr3j-rqpg-432w.json +++ b/advisories/unreviewed/2022/05/GHSA-pr3j-rqpg-432w/GHSA-pr3j-rqpg-432w.json @@ -7,12 +7,8 @@ "CVE-2020-4892" ], "details": "IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190979.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvpg-9553-f979/GHSA-pvpg-9553-f979.json b/advisories/unreviewed/2022/05/GHSA-pvpg-9553-f979/GHSA-pvpg-9553-f979.json index b47fb665f86..4adcd37844b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvpg-9553-f979/GHSA-pvpg-9553-f979.json +++ b/advisories/unreviewed/2022/05/GHSA-pvpg-9553-f979/GHSA-pvpg-9553-f979.json @@ -7,12 +7,8 @@ "CVE-2020-25476" ], "details": "Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the malicious payload on the username, lastname or surname fields of its own profile, and the malicious payload will be injected and reflected in the calendar of the user who submitted the payload. An attacker could escalate its privileges in case an admin visits the calendar that injected the payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw3w-whq9-h2ww/GHSA-pw3w-whq9-h2ww.json b/advisories/unreviewed/2022/05/GHSA-pw3w-whq9-h2ww/GHSA-pw3w-whq9-h2ww.json index d1b03be54ed..97c12d6db68 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw3w-whq9-h2ww/GHSA-pw3w-whq9-h2ww.json +++ b/advisories/unreviewed/2022/05/GHSA-pw3w-whq9-h2ww/GHSA-pw3w-whq9-h2ww.json @@ -7,12 +7,8 @@ "CVE-2021-1163" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw76-p7mv-vxq5/GHSA-pw76-p7mv-vxq5.json b/advisories/unreviewed/2022/05/GHSA-pw76-p7mv-vxq5/GHSA-pw76-p7mv-vxq5.json index f2db84c3a14..a129695a512 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw76-p7mv-vxq5/GHSA-pw76-p7mv-vxq5.json +++ b/advisories/unreviewed/2022/05/GHSA-pw76-p7mv-vxq5/GHSA-pw76-p7mv-vxq5.json @@ -7,12 +7,8 @@ "CVE-2021-1161" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwh6-hxc9-8cf2/GHSA-pwh6-hxc9-8cf2.json b/advisories/unreviewed/2022/05/GHSA-pwh6-hxc9-8cf2/GHSA-pwh6-hxc9-8cf2.json index b5125eeed80..73aa038f57c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwh6-hxc9-8cf2/GHSA-pwh6-hxc9-8cf2.json +++ b/advisories/unreviewed/2022/05/GHSA-pwh6-hxc9-8cf2/GHSA-pwh6-hxc9-8cf2.json @@ -7,12 +7,8 @@ "CVE-2020-29492" ], "details": "Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwhm-g5xc-f3xm/GHSA-pwhm-g5xc-f3xm.json b/advisories/unreviewed/2022/05/GHSA-pwhm-g5xc-f3xm/GHSA-pwhm-g5xc-f3xm.json index 2cdea534c52..07db097a641 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwhm-g5xc-f3xm/GHSA-pwhm-g5xc-f3xm.json +++ b/advisories/unreviewed/2022/05/GHSA-pwhm-g5xc-f3xm/GHSA-pwhm-g5xc-f3xm.json @@ -7,12 +7,8 @@ "CVE-2020-16030" ], "details": "Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwmw-jmr6-f7c4/GHSA-pwmw-jmr6-f7c4.json b/advisories/unreviewed/2022/05/GHSA-pwmw-jmr6-f7c4/GHSA-pwmw-jmr6-f7c4.json index e6bb192e82f..61d0f656252 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwmw-jmr6-f7c4/GHSA-pwmw-jmr6-f7c4.json +++ b/advisories/unreviewed/2022/05/GHSA-pwmw-jmr6-f7c4/GHSA-pwmw-jmr6-f7c4.json @@ -7,12 +7,8 @@ "CVE-2020-35738" ], "details": "WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later \"unofficial\" releases through 5.3.2, which are also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwpp-fc52-54w9/GHSA-pwpp-fc52-54w9.json b/advisories/unreviewed/2022/05/GHSA-pwpp-fc52-54w9/GHSA-pwpp-fc52-54w9.json index b792c6a8f2c..cfaf0d43a05 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwpp-fc52-54w9/GHSA-pwpp-fc52-54w9.json +++ b/advisories/unreviewed/2022/05/GHSA-pwpp-fc52-54w9/GHSA-pwpp-fc52-54w9.json @@ -7,12 +7,8 @@ "CVE-2020-14098" ], "details": "The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q23c-mjcp-8vj6/GHSA-q23c-mjcp-8vj6.json b/advisories/unreviewed/2022/05/GHSA-q23c-mjcp-8vj6/GHSA-q23c-mjcp-8vj6.json index 8c1da871c27..15e285fe145 100644 --- a/advisories/unreviewed/2022/05/GHSA-q23c-mjcp-8vj6/GHSA-q23c-mjcp-8vj6.json +++ b/advisories/unreviewed/2022/05/GHSA-q23c-mjcp-8vj6/GHSA-q23c-mjcp-8vj6.json @@ -7,12 +7,8 @@ "CVE-2020-8275" ], "details": "Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2g9-chwh-vpqj/GHSA-q2g9-chwh-vpqj.json b/advisories/unreviewed/2022/05/GHSA-q2g9-chwh-vpqj/GHSA-q2g9-chwh-vpqj.json index a54aefd6cd0..db8503297d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2g9-chwh-vpqj/GHSA-q2g9-chwh-vpqj.json +++ b/advisories/unreviewed/2022/05/GHSA-q2g9-chwh-vpqj/GHSA-q2g9-chwh-vpqj.json @@ -7,12 +7,8 @@ "CVE-2020-11832" ], "details": "In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c have not checked the parameters, which causes a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q58p-hm39-45gx/GHSA-q58p-hm39-45gx.json b/advisories/unreviewed/2022/05/GHSA-q58p-hm39-45gx/GHSA-q58p-hm39-45gx.json index 28d11a4e967..1e7ca3049e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q58p-hm39-45gx/GHSA-q58p-hm39-45gx.json +++ b/advisories/unreviewed/2022/05/GHSA-q58p-hm39-45gx/GHSA-q58p-hm39-45gx.json @@ -7,12 +7,8 @@ "CVE-2020-26989" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), JT2Go (V 13.1.0), Solid Edge (All Versions < SE2021MP2), Teamcenter Visualization (All Versions < V13.1.0), Teamcenter Visualization (V 13.1.0). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q58x-r4q4-h596/GHSA-q58x-r4q4-h596.json b/advisories/unreviewed/2022/05/GHSA-q58x-r4q4-h596/GHSA-q58x-r4q4-h596.json index c720a4b7e50..60f1d96d7f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q58x-r4q4-h596/GHSA-q58x-r4q4-h596.json +++ b/advisories/unreviewed/2022/05/GHSA-q58x-r4q4-h596/GHSA-q58x-r4q4-h596.json @@ -7,12 +7,8 @@ "CVE-2020-22550" ], "details": "Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5m9-8685-c94f/GHSA-q5m9-8685-c94f.json b/advisories/unreviewed/2022/05/GHSA-q5m9-8685-c94f/GHSA-q5m9-8685-c94f.json index 456524f4c4f..d524582552e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5m9-8685-c94f/GHSA-q5m9-8685-c94f.json +++ b/advisories/unreviewed/2022/05/GHSA-q5m9-8685-c94f/GHSA-q5m9-8685-c94f.json @@ -7,12 +7,8 @@ "CVE-2019-16281" ], "details": "Ptarmigan before 0.2.3 lacks API token validation, e.g., an \"if (token === apiToken) {return true;} return false;\" code block.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q62r-wv6v-9494/GHSA-q62r-wv6v-9494.json b/advisories/unreviewed/2022/05/GHSA-q62r-wv6v-9494/GHSA-q62r-wv6v-9494.json index c496aef57a5..f7e28b22a1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q62r-wv6v-9494/GHSA-q62r-wv6v-9494.json +++ b/advisories/unreviewed/2022/05/GHSA-q62r-wv6v-9494/GHSA-q62r-wv6v-9494.json @@ -7,12 +7,8 @@ "CVE-2020-26165" ], "details": "qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q688-c68r-qc96/GHSA-q688-c68r-qc96.json b/advisories/unreviewed/2022/05/GHSA-q688-c68r-qc96/GHSA-q688-c68r-qc96.json index e61efa62034..a68c2961e01 100644 --- a/advisories/unreviewed/2022/05/GHSA-q688-c68r-qc96/GHSA-q688-c68r-qc96.json +++ b/advisories/unreviewed/2022/05/GHSA-q688-c68r-qc96/GHSA-q688-c68r-qc96.json @@ -7,12 +7,8 @@ "CVE-2021-1187" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q729-rgv8-6phg/GHSA-q729-rgv8-6phg.json b/advisories/unreviewed/2022/05/GHSA-q729-rgv8-6phg/GHSA-q729-rgv8-6phg.json index 9d6a6b8b1a2..e24a671a04d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q729-rgv8-6phg/GHSA-q729-rgv8-6phg.json +++ b/advisories/unreviewed/2022/05/GHSA-q729-rgv8-6phg/GHSA-q729-rgv8-6phg.json @@ -7,12 +7,8 @@ "CVE-2020-6777" ], "details": "A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an authenticated remote attacker with admin privileges to mount a stored Cross-Site-Scripting (XSS) attack against another user. When the victim logs into the management interface, the stored script code is executed in the context of his browser. A successful exploit would allow an attacker to interact with the management interface with the privileges of the victim. However, as the attacker already needs admin privileges, there is no additional impact on the management interface itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q738-7qq7-r8ff/GHSA-q738-7qq7-r8ff.json b/advisories/unreviewed/2022/05/GHSA-q738-7qq7-r8ff/GHSA-q738-7qq7-r8ff.json index 0e9576f6925..587618868ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-q738-7qq7-r8ff/GHSA-q738-7qq7-r8ff.json +++ b/advisories/unreviewed/2022/05/GHSA-q738-7qq7-r8ff/GHSA-q738-7qq7-r8ff.json @@ -7,12 +7,8 @@ "CVE-2020-10209" ], "details": "Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7cq-6x2w-xg5f/GHSA-q7cq-6x2w-xg5f.json b/advisories/unreviewed/2022/05/GHSA-q7cq-6x2w-xg5f/GHSA-q7cq-6x2w-xg5f.json index 63da36d9bd2..ce0b8624aec 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7cq-6x2w-xg5f/GHSA-q7cq-6x2w-xg5f.json +++ b/advisories/unreviewed/2022/05/GHSA-q7cq-6x2w-xg5f/GHSA-q7cq-6x2w-xg5f.json @@ -7,12 +7,8 @@ "CVE-2020-4897" ], "details": "IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190988.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7h5-v9jq-wx6v/GHSA-q7h5-v9jq-wx6v.json b/advisories/unreviewed/2022/05/GHSA-q7h5-v9jq-wx6v/GHSA-q7h5-v9jq-wx6v.json index d5d55e765c4..e4471e3ca39 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7h5-v9jq-wx6v/GHSA-q7h5-v9jq-wx6v.json +++ b/advisories/unreviewed/2022/05/GHSA-q7h5-v9jq-wx6v/GHSA-q7h5-v9jq-wx6v.json @@ -7,12 +7,8 @@ "CVE-2020-27285" ], "details": "The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7hf-7qcc-gmg8/GHSA-q7hf-7qcc-gmg8.json b/advisories/unreviewed/2022/05/GHSA-q7hf-7qcc-gmg8/GHSA-q7hf-7qcc-gmg8.json index e5d2c82aec6..3b09c858982 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7hf-7qcc-gmg8/GHSA-q7hf-7qcc-gmg8.json +++ b/advisories/unreviewed/2022/05/GHSA-q7hf-7qcc-gmg8/GHSA-q7hf-7qcc-gmg8.json @@ -7,12 +7,8 @@ "CVE-2021-23240" ], "details": "selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q83w-52wv-55jx/GHSA-q83w-52wv-55jx.json b/advisories/unreviewed/2022/05/GHSA-q83w-52wv-55jx/GHSA-q83w-52wv-55jx.json index b469834f624..a341622516a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q83w-52wv-55jx/GHSA-q83w-52wv-55jx.json +++ b/advisories/unreviewed/2022/05/GHSA-q83w-52wv-55jx/GHSA-q83w-52wv-55jx.json @@ -7,12 +7,8 @@ "CVE-2021-21108" ], "details": "Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q868-35f4-p658/GHSA-q868-35f4-p658.json b/advisories/unreviewed/2022/05/GHSA-q868-35f4-p658/GHSA-q868-35f4-p658.json index af93503e9fe..4362c931ac1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q868-35f4-p658/GHSA-q868-35f4-p658.json +++ b/advisories/unreviewed/2022/05/GHSA-q868-35f4-p658/GHSA-q868-35f4-p658.json @@ -7,12 +7,8 @@ "CVE-2020-35962" ], "details": "The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8qf-8pcx-vfw7/GHSA-q8qf-8pcx-vfw7.json b/advisories/unreviewed/2022/05/GHSA-q8qf-8pcx-vfw7/GHSA-q8qf-8pcx-vfw7.json index 3f26024a5a2..3f9f900af24 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8qf-8pcx-vfw7/GHSA-q8qf-8pcx-vfw7.json +++ b/advisories/unreviewed/2022/05/GHSA-q8qf-8pcx-vfw7/GHSA-q8qf-8pcx-vfw7.json @@ -7,12 +7,8 @@ "CVE-2020-35766" ], "details": "The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the \"A number of self-test programs are included here for unit-testing the library\" situation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q949-6jcq-74v3/GHSA-q949-6jcq-74v3.json b/advisories/unreviewed/2022/05/GHSA-q949-6jcq-74v3/GHSA-q949-6jcq-74v3.json index 3f3b110b049..3cb2925d814 100644 --- a/advisories/unreviewed/2022/05/GHSA-q949-6jcq-74v3/GHSA-q949-6jcq-74v3.json +++ b/advisories/unreviewed/2022/05/GHSA-q949-6jcq-74v3/GHSA-q949-6jcq-74v3.json @@ -7,12 +7,8 @@ "CVE-2020-29041" ], "details": "A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q966-hp9v-pw89/GHSA-q966-hp9v-pw89.json b/advisories/unreviewed/2022/05/GHSA-q966-hp9v-pw89/GHSA-q966-hp9v-pw89.json index 6faac09b85d..9cb2479109b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q966-hp9v-pw89/GHSA-q966-hp9v-pw89.json +++ b/advisories/unreviewed/2022/05/GHSA-q966-hp9v-pw89/GHSA-q966-hp9v-pw89.json @@ -7,12 +7,8 @@ "CVE-2018-18688" ], "details": "The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9fg-c965-3f7m/GHSA-q9fg-c965-3f7m.json b/advisories/unreviewed/2022/05/GHSA-q9fg-c965-3f7m/GHSA-q9fg-c965-3f7m.json index f97275f6cb2..a4cadb374ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9fg-c965-3f7m/GHSA-q9fg-c965-3f7m.json +++ b/advisories/unreviewed/2022/05/GHSA-q9fg-c965-3f7m/GHSA-q9fg-c965-3f7m.json @@ -7,12 +7,8 @@ "CVE-2020-26985" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of RGB and SGI files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9fj-r59w-qgwr/GHSA-q9fj-r59w-qgwr.json b/advisories/unreviewed/2022/05/GHSA-q9fj-r59w-qgwr/GHSA-q9fj-r59w-qgwr.json index 5d31e7cb10e..3ce4c846ab0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9fj-r59w-qgwr/GHSA-q9fj-r59w-qgwr.json +++ b/advisories/unreviewed/2022/05/GHSA-q9fj-r59w-qgwr/GHSA-q9fj-r59w-qgwr.json @@ -7,12 +7,8 @@ "CVE-2020-29495" ], "details": "DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This vulnerability is considered critical as it can be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9gg-5799-8666/GHSA-q9gg-5799-8666.json b/advisories/unreviewed/2022/05/GHSA-q9gg-5799-8666/GHSA-q9gg-5799-8666.json index 6e30645a89b..939c5dec74e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9gg-5799-8666/GHSA-q9gg-5799-8666.json +++ b/advisories/unreviewed/2022/05/GHSA-q9gg-5799-8666/GHSA-q9gg-5799-8666.json @@ -7,12 +7,8 @@ "CVE-2020-16021" ], "details": "Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9m8-r9fr-8x4q/GHSA-q9m8-r9fr-8x4q.json b/advisories/unreviewed/2022/05/GHSA-q9m8-r9fr-8x4q/GHSA-q9m8-r9fr-8x4q.json index b95a6d415cd..2add91a1eb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9m8-r9fr-8x4q/GHSA-q9m8-r9fr-8x4q.json +++ b/advisories/unreviewed/2022/05/GHSA-q9m8-r9fr-8x4q/GHSA-q9m8-r9fr-8x4q.json @@ -7,12 +7,8 @@ "CVE-2020-4919" ], "details": "IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-Force ID: 191395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc69-r7wf-6p6c/GHSA-qc69-r7wf-6p6c.json b/advisories/unreviewed/2022/05/GHSA-qc69-r7wf-6p6c/GHSA-qc69-r7wf-6p6c.json index 019170baae8..e6c158a61cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc69-r7wf-6p6c/GHSA-qc69-r7wf-6p6c.json +++ b/advisories/unreviewed/2022/05/GHSA-qc69-r7wf-6p6c/GHSA-qc69-r7wf-6p6c.json @@ -7,12 +7,8 @@ "CVE-2021-1259" ], "details": "\n A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system.\n The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to write arbitrary files on the affected system.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgc6-rvwm-9cf7/GHSA-qgc6-rvwm-9cf7.json b/advisories/unreviewed/2022/05/GHSA-qgc6-rvwm-9cf7/GHSA-qgc6-rvwm-9cf7.json index 83abbbe4750..bbb7eebfb26 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgc6-rvwm-9cf7/GHSA-qgc6-rvwm-9cf7.json +++ b/advisories/unreviewed/2022/05/GHSA-qgc6-rvwm-9cf7/GHSA-qgc6-rvwm-9cf7.json @@ -7,12 +7,8 @@ "CVE-2020-4762" ], "details": "IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgg7-qhjr-6jh4/GHSA-qgg7-qhjr-6jh4.json b/advisories/unreviewed/2022/05/GHSA-qgg7-qhjr-6jh4/GHSA-qgg7-qhjr-6jh4.json index e8128a96266..ee185aa51ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgg7-qhjr-6jh4/GHSA-qgg7-qhjr-6jh4.json +++ b/advisories/unreviewed/2022/05/GHSA-qgg7-qhjr-6jh4/GHSA-qgg7-qhjr-6jh4.json @@ -7,12 +7,8 @@ "CVE-2021-1277" ], "details": "Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests.\n These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhwr-mfcx-qrr9/GHSA-qhwr-mfcx-qrr9.json b/advisories/unreviewed/2022/05/GHSA-qhwr-mfcx-qrr9/GHSA-qhwr-mfcx-qrr9.json index debd9d24489..f884dafc50b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhwr-mfcx-qrr9/GHSA-qhwr-mfcx-qrr9.json +++ b/advisories/unreviewed/2022/05/GHSA-qhwr-mfcx-qrr9/GHSA-qhwr-mfcx-qrr9.json @@ -7,12 +7,8 @@ "CVE-2021-0207" ], "details": "An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through the device upon receipt from an ingress interface filtering certain specific types of traffic which is then being redirected to an egress interface on a different VLAN. This causes a Denial of Service (DoS) to those clients sending these particular types of traffic. Such traffic being sent by a client may appear genuine, but is non-standard in nature and should be considered as potentially malicious, and can be targeted to the device, or destined through it for the issue to occur. This issues affects IPv4 and IPv6 traffic. An indicator of compromise may be found by checking log files. You may find that traffic on the input interface has 100% of traffic flowing into the device, yet the egress interface shows 0 pps leaving the device. For example: [show interfaces \"interface\" statistics detail] Output between two interfaces would reveal something similar to: Ingress, first interface: -------------------- Interface Link Input packets (pps) Output packets (pps) et-0/0/0 Up 9999999999 (9999) 1 (0) -------------------- Egress, second interface: -------------------- Interface Link Input packets (pps) Output packets (pps) et-0/0/1 Up 0 (0) 9999999999 (0) -------------------- Dropped packets will not show up in DDoS monitoring/protection counters as issue is not caused by anti-DDoS protection mechanisms. This issue affects: Juniper Networks Junos OS: 17.3 versions prior to 17.3R3-S7 on NFX250, QFX5K Series, EX4600; 17.4 versions prior to 17.4R2-S11, 17.4R3-S3 on NFX250, QFX5K Series, EX4600; 18.1 versions prior to 18.1R3-S9 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4600; 18.2 versions prior to 18.2R3-S3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600; 18.3 versions prior to 18.3R3-S1 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.2 versions prior to 19.2R1-S5, 19.2R2 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.3 versions prior to 19.3R2-S3, 19.3R3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.4 versions prior to 19.4R1-S2, 19.4R2 on NFX250, NFX350, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series. This issue does not affect Junos OS releases prior to 17.2R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj37-hv9r-mmr8/GHSA-qj37-hv9r-mmr8.json b/advisories/unreviewed/2022/05/GHSA-qj37-hv9r-mmr8/GHSA-qj37-hv9r-mmr8.json index 08f8cc712bc..14453f10260 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj37-hv9r-mmr8/GHSA-qj37-hv9r-mmr8.json +++ b/advisories/unreviewed/2022/05/GHSA-qj37-hv9r-mmr8/GHSA-qj37-hv9r-mmr8.json @@ -7,12 +7,8 @@ "CVE-2020-26033" ], "details": "An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm5r-g6v2-jcgq/GHSA-qm5r-g6v2-jcgq.json b/advisories/unreviewed/2022/05/GHSA-qm5r-g6v2-jcgq/GHSA-qm5r-g6v2-jcgq.json index 9a08bd8abeb..74c0f5edeb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm5r-g6v2-jcgq/GHSA-qm5r-g6v2-jcgq.json +++ b/advisories/unreviewed/2022/05/GHSA-qm5r-g6v2-jcgq/GHSA-qm5r-g6v2-jcgq.json @@ -7,12 +7,8 @@ "CVE-2021-1272" ], "details": "\n A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system.\n This vulnerability is due to insufficient validation of parameters in a specific HTTP request by an attacker. An attacker could exploit this vulnerability by sending a crafted HTTP request to an authenticated user of the DCNM web application. A successful exploit could allow the attacker to bypass access controls and gain unauthorized access to the Device Manager application, which provides access to network devices managed by the system.\n \n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm8q-5g67-7xh5/GHSA-qm8q-5g67-7xh5.json b/advisories/unreviewed/2022/05/GHSA-qm8q-5g67-7xh5/GHSA-qm8q-5g67-7xh5.json index f90eaa3a6fd..672fbbef963 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm8q-5g67-7xh5/GHSA-qm8q-5g67-7xh5.json +++ b/advisories/unreviewed/2022/05/GHSA-qm8q-5g67-7xh5/GHSA-qm8q-5g67-7xh5.json @@ -7,12 +7,8 @@ "CVE-2021-21460" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmv6-2p8v-6766/GHSA-qmv6-2p8v-6766.json b/advisories/unreviewed/2022/05/GHSA-qmv6-2p8v-6766/GHSA-qmv6-2p8v-6766.json index 95382c92885..850e73bc3be 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmv6-2p8v-6766/GHSA-qmv6-2p8v-6766.json +++ b/advisories/unreviewed/2022/05/GHSA-qmv6-2p8v-6766/GHSA-qmv6-2p8v-6766.json @@ -7,12 +7,8 @@ "CVE-2020-36161" ], "details": "An issue was discovered in Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3. By default, on Windows systems, users can create directories under C:\\. A low privileged user can create a directory at the configuration file locations. When the Windows system restarts, a malicious OpenSSL engine could exploit arbitrary code execution as SYSTEM. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp95-2hv6-rp65/GHSA-qp95-2hv6-rp65.json b/advisories/unreviewed/2022/05/GHSA-qp95-2hv6-rp65/GHSA-qp95-2hv6-rp65.json index 492cbaa3338..1aba3874388 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp95-2hv6-rp65/GHSA-qp95-2hv6-rp65.json +++ b/advisories/unreviewed/2022/05/GHSA-qp95-2hv6-rp65/GHSA-qp95-2hv6-rp65.json @@ -7,12 +7,8 @@ "CVE-2021-1253" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpc5-j9g4-58fr/GHSA-qpc5-j9g4-58fr.json b/advisories/unreviewed/2022/05/GHSA-qpc5-j9g4-58fr/GHSA-qpc5-j9g4-58fr.json index 7e151b64207..e4baba0ffd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpc5-j9g4-58fr/GHSA-qpc5-j9g4-58fr.json +++ b/advisories/unreviewed/2022/05/GHSA-qpc5-j9g4-58fr/GHSA-qpc5-j9g4-58fr.json @@ -7,12 +7,8 @@ "CVE-2020-29497" ], "details": "Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code under the device tag. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpx8-mq5g-ppwg/GHSA-qpx8-mq5g-ppwg.json b/advisories/unreviewed/2022/05/GHSA-qpx8-mq5g-ppwg/GHSA-qpx8-mq5g-ppwg.json index b958359fddc..87accd24461 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpx8-mq5g-ppwg/GHSA-qpx8-mq5g-ppwg.json +++ b/advisories/unreviewed/2022/05/GHSA-qpx8-mq5g-ppwg/GHSA-qpx8-mq5g-ppwg.json @@ -7,12 +7,8 @@ "CVE-2021-3184" ], "details": "MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq53-8g57-9gr8/GHSA-qq53-8g57-9gr8.json b/advisories/unreviewed/2022/05/GHSA-qq53-8g57-9gr8/GHSA-qq53-8g57-9gr8.json index 8452a4bfce9..ede90ba1607 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq53-8g57-9gr8/GHSA-qq53-8g57-9gr8.json +++ b/advisories/unreviewed/2022/05/GHSA-qq53-8g57-9gr8/GHSA-qq53-8g57-9gr8.json @@ -7,12 +7,8 @@ "CVE-2021-0303" ], "details": "In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Android ID: A-170407229.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq7v-5jvx-g2r7/GHSA-qq7v-5jvx-g2r7.json b/advisories/unreviewed/2022/05/GHSA-qq7v-5jvx-g2r7/GHSA-qq7v-5jvx-g2r7.json index 6f7c908c1bb..4c3eff11b6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq7v-5jvx-g2r7/GHSA-qq7v-5jvx-g2r7.json +++ b/advisories/unreviewed/2022/05/GHSA-qq7v-5jvx-g2r7/GHSA-qq7v-5jvx-g2r7.json @@ -7,12 +7,8 @@ "CVE-2021-1307" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqc4-654m-g55g/GHSA-qqc4-654m-g55g.json b/advisories/unreviewed/2022/05/GHSA-qqc4-654m-g55g/GHSA-qqc4-654m-g55g.json index 3ab8f33f071..c05242fe719 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqc4-654m-g55g/GHSA-qqc4-654m-g55g.json +++ b/advisories/unreviewed/2022/05/GHSA-qqc4-654m-g55g/GHSA-qqc4-654m-g55g.json @@ -7,12 +7,8 @@ "CVE-2020-26118" ], "details": "In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqg6-4j54-68gr/GHSA-qqg6-4j54-68gr.json b/advisories/unreviewed/2022/05/GHSA-qqg6-4j54-68gr/GHSA-qqg6-4j54-68gr.json index 3e61f1d946c..fdad387f454 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqg6-4j54-68gr/GHSA-qqg6-4j54-68gr.json +++ b/advisories/unreviewed/2022/05/GHSA-qqg6-4j54-68gr/GHSA-qqg6-4j54-68gr.json @@ -7,12 +7,8 @@ "CVE-2020-36178" ], "details": "oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr7j-48q9-7wvf/GHSA-qr7j-48q9-7wvf.json b/advisories/unreviewed/2022/05/GHSA-qr7j-48q9-7wvf/GHSA-qr7j-48q9-7wvf.json index 878bc647d41..ae9ea70bcb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr7j-48q9-7wvf/GHSA-qr7j-48q9-7wvf.json +++ b/advisories/unreviewed/2022/05/GHSA-qr7j-48q9-7wvf/GHSA-qr7j-48q9-7wvf.json @@ -7,12 +7,8 @@ "CVE-2020-36164" ], "details": "An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\\) and the product's installation drive (typically not C:\\): \\Isode\\etc\\ssl\\openssl.cnf (on SMTP Server) or \\user\\ssl\\openssl.cnf (on other affected components). By default, on Windows systems, users can create directories under C:\\. A low privileged user can create a openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This vulnerability only affects a server with MTP Server, SMTP Archiving IMAP Server, IMAP Archiving, Vault Cloud Adapter, NetApp File server, or File System Archiving for NetApp as File Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrhf-q88m-c43r/GHSA-qrhf-q88m-c43r.json b/advisories/unreviewed/2022/05/GHSA-qrhf-q88m-c43r/GHSA-qrhf-q88m-c43r.json index 812d8e5f183..7bf41acb63d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrhf-q88m-c43r/GHSA-qrhf-q88m-c43r.json +++ b/advisories/unreviewed/2022/05/GHSA-qrhf-q88m-c43r/GHSA-qrhf-q88m-c43r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrv4-5384-prhq/GHSA-qrv4-5384-prhq.json b/advisories/unreviewed/2022/05/GHSA-qrv4-5384-prhq/GHSA-qrv4-5384-prhq.json index 5ccffb8e50f..cf4fc4b5d33 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrv4-5384-prhq/GHSA-qrv4-5384-prhq.json +++ b/advisories/unreviewed/2022/05/GHSA-qrv4-5384-prhq/GHSA-qrv4-5384-prhq.json @@ -7,12 +7,8 @@ "CVE-2021-0312" ], "details": "In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-170583712.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv67-8hwr-88xh/GHSA-qv67-8hwr-88xh.json b/advisories/unreviewed/2022/05/GHSA-qv67-8hwr-88xh/GHSA-qv67-8hwr-88xh.json index fc2b4c8fd8b..f028638e6d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv67-8hwr-88xh/GHSA-qv67-8hwr-88xh.json +++ b/advisories/unreviewed/2022/05/GHSA-qv67-8hwr-88xh/GHSA-qv67-8hwr-88xh.json @@ -7,12 +7,8 @@ "CVE-2020-5810" ], "details": "A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwq9-fh29-mw39/GHSA-qwq9-fh29-mw39.json b/advisories/unreviewed/2022/05/GHSA-qwq9-fh29-mw39/GHSA-qwq9-fh29-mw39.json index f2c57926d14..27c4c8fa27a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwq9-fh29-mw39/GHSA-qwq9-fh29-mw39.json +++ b/advisories/unreviewed/2022/05/GHSA-qwq9-fh29-mw39/GHSA-qwq9-fh29-mw39.json @@ -7,12 +7,8 @@ "CVE-2021-23930" ], "details": "OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qx8w-qf9q-g5vp/GHSA-qx8w-qf9q-g5vp.json b/advisories/unreviewed/2022/05/GHSA-qx8w-qf9q-g5vp/GHSA-qx8w-qf9q-g5vp.json index 380115424fd..9753a9186f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx8w-qf9q-g5vp/GHSA-qx8w-qf9q-g5vp.json +++ b/advisories/unreviewed/2022/05/GHSA-qx8w-qf9q-g5vp/GHSA-qx8w-qf9q-g5vp.json @@ -7,12 +7,8 @@ "CVE-2020-26977" ], "details": "By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxh3-5p6c-whgc/GHSA-qxh3-5p6c-whgc.json b/advisories/unreviewed/2022/05/GHSA-qxh3-5p6c-whgc/GHSA-qxh3-5p6c-whgc.json index 4cda06c7c8f..7a4c5d7f1d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxh3-5p6c-whgc/GHSA-qxh3-5p6c-whgc.json +++ b/advisories/unreviewed/2022/05/GHSA-qxh3-5p6c-whgc/GHSA-qxh3-5p6c-whgc.json @@ -7,12 +7,8 @@ "CVE-2021-2040" ], "details": "Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Case Form, Local Affiliate Form). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Argus Safety. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Argus Safety, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Argus Safety accessible data as well as unauthorized read access to a subset of Oracle Argus Safety accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r275-5g72-r3ph/GHSA-r275-5g72-r3ph.json b/advisories/unreviewed/2022/05/GHSA-r275-5g72-r3ph/GHSA-r275-5g72-r3ph.json index cbc1742085c..f1ce924988e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r275-5g72-r3ph/GHSA-r275-5g72-r3ph.json +++ b/advisories/unreviewed/2022/05/GHSA-r275-5g72-r3ph/GHSA-r275-5g72-r3ph.json @@ -7,12 +7,8 @@ "CVE-2020-35951" ], "details": "An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2cj-jqqc-j833/GHSA-r2cj-jqqc-j833.json b/advisories/unreviewed/2022/05/GHSA-r2cj-jqqc-j833/GHSA-r2cj-jqqc-j833.json index 567054817c3..609a378f37a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2cj-jqqc-j833/GHSA-r2cj-jqqc-j833.json +++ b/advisories/unreviewed/2022/05/GHSA-r2cj-jqqc-j833/GHSA-r2cj-jqqc-j833.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r367-9w5p-9666/GHSA-r367-9w5p-9666.json b/advisories/unreviewed/2022/05/GHSA-r367-9w5p-9666/GHSA-r367-9w5p-9666.json index ab6d8539685..c55600a5e84 100644 --- a/advisories/unreviewed/2022/05/GHSA-r367-9w5p-9666/GHSA-r367-9w5p-9666.json +++ b/advisories/unreviewed/2022/05/GHSA-r367-9w5p-9666/GHSA-r367-9w5p-9666.json @@ -7,12 +7,8 @@ "CVE-2020-35830" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r524-g3q7-mjq5/GHSA-r524-g3q7-mjq5.json b/advisories/unreviewed/2022/05/GHSA-r524-g3q7-mjq5/GHSA-r524-g3q7-mjq5.json index d46c9a869f5..e8605a4eac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r524-g3q7-mjq5/GHSA-r524-g3q7-mjq5.json +++ b/advisories/unreviewed/2022/05/GHSA-r524-g3q7-mjq5/GHSA-r524-g3q7-mjq5.json @@ -7,12 +7,8 @@ "CVE-2021-1198" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5pw-3hxj-jmpq/GHSA-r5pw-3hxj-jmpq.json b/advisories/unreviewed/2022/05/GHSA-r5pw-3hxj-jmpq/GHSA-r5pw-3hxj-jmpq.json index 9e93af8e679..0fffe701103 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5pw-3hxj-jmpq/GHSA-r5pw-3hxj-jmpq.json +++ b/advisories/unreviewed/2022/05/GHSA-r5pw-3hxj-jmpq/GHSA-r5pw-3hxj-jmpq.json @@ -7,12 +7,8 @@ "CVE-2020-10656" ], "details": "The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5vx-622x-4rx2/GHSA-r5vx-622x-4rx2.json b/advisories/unreviewed/2022/05/GHSA-r5vx-622x-4rx2/GHSA-r5vx-622x-4rx2.json index 19c1e2c36f6..56f05cc723e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5vx-622x-4rx2/GHSA-r5vx-622x-4rx2.json +++ b/advisories/unreviewed/2022/05/GHSA-r5vx-622x-4rx2/GHSA-r5vx-622x-4rx2.json @@ -7,12 +7,8 @@ "CVE-2020-26034" ], "details": "An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6qr-r386-hmx7/GHSA-r6qr-r386-hmx7.json b/advisories/unreviewed/2022/05/GHSA-r6qr-r386-hmx7/GHSA-r6qr-r386-hmx7.json index 0407fe90e54..b7927af40ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6qr-r386-hmx7/GHSA-r6qr-r386-hmx7.json +++ b/advisories/unreviewed/2022/05/GHSA-r6qr-r386-hmx7/GHSA-r6qr-r386-hmx7.json @@ -7,12 +7,8 @@ "CVE-2020-16024" ], "details": "Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6rm-754v-479j/GHSA-r6rm-754v-479j.json b/advisories/unreviewed/2022/05/GHSA-r6rm-754v-479j/GHSA-r6rm-754v-479j.json index 953fb654448..e1c6bcaae0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6rm-754v-479j/GHSA-r6rm-754v-479j.json +++ b/advisories/unreviewed/2022/05/GHSA-r6rm-754v-479j/GHSA-r6rm-754v-479j.json @@ -7,12 +7,8 @@ "CVE-2019-4687" ], "details": "IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 171823.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6xm-wq7q-jr6c/GHSA-r6xm-wq7q-jr6c.json b/advisories/unreviewed/2022/05/GHSA-r6xm-wq7q-jr6c/GHSA-r6xm-wq7q-jr6c.json index 6bf5657fd5d..2e3327e9c49 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6xm-wq7q-jr6c/GHSA-r6xm-wq7q-jr6c.json +++ b/advisories/unreviewed/2022/05/GHSA-r6xm-wq7q-jr6c/GHSA-r6xm-wq7q-jr6c.json @@ -7,12 +7,8 @@ "CVE-2020-4869" ], "details": "IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r776-v6gr-rxfh/GHSA-r776-v6gr-rxfh.json b/advisories/unreviewed/2022/05/GHSA-r776-v6gr-rxfh/GHSA-r776-v6gr-rxfh.json index 810cf2f9cea..e6fe522e95b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r776-v6gr-rxfh/GHSA-r776-v6gr-rxfh.json +++ b/advisories/unreviewed/2022/05/GHSA-r776-v6gr-rxfh/GHSA-r776-v6gr-rxfh.json @@ -7,12 +7,8 @@ "CVE-2020-35717" ], "details": "zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r89j-f3jf-r787/GHSA-r89j-f3jf-r787.json b/advisories/unreviewed/2022/05/GHSA-r89j-f3jf-r787/GHSA-r89j-f3jf-r787.json index 13e2dce8228..f6363352317 100644 --- a/advisories/unreviewed/2022/05/GHSA-r89j-f3jf-r787/GHSA-r89j-f3jf-r787.json +++ b/advisories/unreviewed/2022/05/GHSA-r89j-f3jf-r787/GHSA-r89j-f3jf-r787.json @@ -7,12 +7,8 @@ "CVE-2021-25325" ], "details": "MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9wc-j38m-fr2f/GHSA-r9wc-j38m-fr2f.json b/advisories/unreviewed/2022/05/GHSA-r9wc-j38m-fr2f/GHSA-r9wc-j38m-fr2f.json index ba673e8ea45..2178f4ba21f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9wc-j38m-fr2f/GHSA-r9wc-j38m-fr2f.json +++ b/advisories/unreviewed/2022/05/GHSA-r9wc-j38m-fr2f/GHSA-r9wc-j38m-fr2f.json @@ -7,12 +7,8 @@ "CVE-2020-23644" ], "details": "XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc5q-3pm2-x989/GHSA-rc5q-3pm2-x989.json b/advisories/unreviewed/2022/05/GHSA-rc5q-3pm2-x989/GHSA-rc5q-3pm2-x989.json index 4efae7dad8b..d71d526899a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc5q-3pm2-x989/GHSA-rc5q-3pm2-x989.json +++ b/advisories/unreviewed/2022/05/GHSA-rc5q-3pm2-x989/GHSA-rc5q-3pm2-x989.json @@ -7,12 +7,8 @@ "CVE-2021-23125" ], "details": "An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcj8-5g6r-c9cg/GHSA-rcj8-5g6r-c9cg.json b/advisories/unreviewed/2022/05/GHSA-rcj8-5g6r-c9cg/GHSA-rcj8-5g6r-c9cg.json index e100cc15b38..b8d6fc5bf43 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcj8-5g6r-c9cg/GHSA-rcj8-5g6r-c9cg.json +++ b/advisories/unreviewed/2022/05/GHSA-rcj8-5g6r-c9cg/GHSA-rcj8-5g6r-c9cg.json @@ -7,12 +7,8 @@ "CVE-2020-35737" ], "details": "In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcq3-m33j-rj5c/GHSA-rcq3-m33j-rj5c.json b/advisories/unreviewed/2022/05/GHSA-rcq3-m33j-rj5c/GHSA-rcq3-m33j-rj5c.json index 70899e4a334..dbe6c93bcc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcq3-m33j-rj5c/GHSA-rcq3-m33j-rj5c.json +++ b/advisories/unreviewed/2022/05/GHSA-rcq3-m33j-rj5c/GHSA-rcq3-m33j-rj5c.json @@ -7,12 +7,8 @@ "CVE-2020-13450" ], "details": "A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfv6-w65g-9xh7/GHSA-rfv6-w65g-9xh7.json b/advisories/unreviewed/2022/05/GHSA-rfv6-w65g-9xh7/GHSA-rfv6-w65g-9xh7.json index 8bc2a9af2ed..7d42d3e939f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfv6-w65g-9xh7/GHSA-rfv6-w65g-9xh7.json +++ b/advisories/unreviewed/2022/05/GHSA-rfv6-w65g-9xh7/GHSA-rfv6-w65g-9xh7.json @@ -7,12 +7,8 @@ "CVE-2019-3405" ], "details": "In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, which will cause other wireless terminals connected to disconnect from the wireless, so as to attack the router wireless by DoS. At present, the vulnerability has been effectively handled, and users can fix the vulnerability after updating the firmware version.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfw8-3q2w-42qv/GHSA-rfw8-3q2w-42qv.json b/advisories/unreviewed/2022/05/GHSA-rfw8-3q2w-42qv/GHSA-rfw8-3q2w-42qv.json index f56a91214e1..311f64a8717 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfw8-3q2w-42qv/GHSA-rfw8-3q2w-42qv.json +++ b/advisories/unreviewed/2022/05/GHSA-rfw8-3q2w-42qv/GHSA-rfw8-3q2w-42qv.json @@ -7,12 +7,8 @@ "CVE-2020-4942" ], "details": "IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhrj-qwv6-j538/GHSA-rhrj-qwv6-j538.json b/advisories/unreviewed/2022/05/GHSA-rhrj-qwv6-j538/GHSA-rhrj-qwv6-j538.json index d98ad99621a..24068ce8744 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhrj-qwv6-j538/GHSA-rhrj-qwv6-j538.json +++ b/advisories/unreviewed/2022/05/GHSA-rhrj-qwv6-j538/GHSA-rhrj-qwv6-j538.json @@ -7,12 +7,8 @@ "CVE-2020-36163" ], "details": "An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create directories under C:\\. If a low privileged user on the Windows system creates an affected path with a library that NetBackup attempts to load, they can execute arbitrary code as SYSTEM or Administrator. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This affects NetBackup master servers, media servers, clients, and OpsCenter servers on the Windows platform. The system is vulnerable during an install or upgrade on all systems and post-install on Master, Media, and OpsCenter servers during normal operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhxm-f2f4-p3p6/GHSA-rhxm-f2f4-p3p6.json b/advisories/unreviewed/2022/05/GHSA-rhxm-f2f4-p3p6/GHSA-rhxm-f2f4-p3p6.json index f65b495764b..6b1b4bb17cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhxm-f2f4-p3p6/GHSA-rhxm-f2f4-p3p6.json +++ b/advisories/unreviewed/2022/05/GHSA-rhxm-f2f4-p3p6/GHSA-rhxm-f2f4-p3p6.json @@ -7,12 +7,8 @@ "CVE-2019-4160" ], "details": "IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjww-mm6p-2h5r/GHSA-rjww-mm6p-2h5r.json b/advisories/unreviewed/2022/05/GHSA-rjww-mm6p-2h5r/GHSA-rjww-mm6p-2h5r.json index a8c571d8cf9..4d734b42534 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjww-mm6p-2h5r/GHSA-rjww-mm6p-2h5r.json +++ b/advisories/unreviewed/2022/05/GHSA-rjww-mm6p-2h5r/GHSA-rjww-mm6p-2h5r.json @@ -7,12 +7,8 @@ "CVE-2020-27287" ], "details": "Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rp5q-m4xm-3f3r/GHSA-rp5q-m4xm-3f3r.json b/advisories/unreviewed/2022/05/GHSA-rp5q-m4xm-3f3r/GHSA-rp5q-m4xm-3f3r.json index bb42e9f54f0..33c388cd219 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp5q-m4xm-3f3r/GHSA-rp5q-m4xm-3f3r.json +++ b/advisories/unreviewed/2022/05/GHSA-rp5q-m4xm-3f3r/GHSA-rp5q-m4xm-3f3r.json @@ -7,12 +7,8 @@ "CVE-2021-25324" ], "details": "MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rp6f-x899-cqm4/GHSA-rp6f-x899-cqm4.json b/advisories/unreviewed/2022/05/GHSA-rp6f-x899-cqm4/GHSA-rp6f-x899-cqm4.json index 3c50c9deede..4efd08d9c6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp6f-x899-cqm4/GHSA-rp6f-x899-cqm4.json +++ b/advisories/unreviewed/2022/05/GHSA-rp6f-x899-cqm4/GHSA-rp6f-x899-cqm4.json @@ -7,12 +7,8 @@ "CVE-2020-24900" ], "details": "The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpgw-phj8-8867/GHSA-rpgw-phj8-8867.json b/advisories/unreviewed/2022/05/GHSA-rpgw-phj8-8867/GHSA-rpgw-phj8-8867.json index e8e8b732769..9bd1d3647bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpgw-phj8-8867/GHSA-rpgw-phj8-8867.json +++ b/advisories/unreviewed/2022/05/GHSA-rpgw-phj8-8867/GHSA-rpgw-phj8-8867.json @@ -7,12 +7,8 @@ "CVE-2020-26995" ], "details": "A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of SGI and RGB files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq2j-wqqr-j8p7/GHSA-rq2j-wqqr-j8p7.json b/advisories/unreviewed/2022/05/GHSA-rq2j-wqqr-j8p7/GHSA-rq2j-wqqr-j8p7.json index cb793dcc60d..f5608ffff8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq2j-wqqr-j8p7/GHSA-rq2j-wqqr-j8p7.json +++ b/advisories/unreviewed/2022/05/GHSA-rq2j-wqqr-j8p7/GHSA-rq2j-wqqr-j8p7.json @@ -7,12 +7,8 @@ "CVE-2020-4664" ], "details": "IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186235.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr5f-wx27-pp65/GHSA-rr5f-wx27-pp65.json b/advisories/unreviewed/2022/05/GHSA-rr5f-wx27-pp65/GHSA-rr5f-wx27-pp65.json index 54421ed7206..da615efe5bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr5f-wx27-pp65/GHSA-rr5f-wx27-pp65.json +++ b/advisories/unreviewed/2022/05/GHSA-rr5f-wx27-pp65/GHSA-rr5f-wx27-pp65.json @@ -7,12 +7,8 @@ "CVE-2020-4674" ], "details": "IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr5p-rpfr-2rwr/GHSA-rr5p-rpfr-2rwr.json b/advisories/unreviewed/2022/05/GHSA-rr5p-rpfr-2rwr/GHSA-rr5p-rpfr-2rwr.json index 53b7dca0d4d..a60ddd97240 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr5p-rpfr-2rwr/GHSA-rr5p-rpfr-2rwr.json +++ b/advisories/unreviewed/2022/05/GHSA-rr5p-rpfr-2rwr/GHSA-rr5p-rpfr-2rwr.json @@ -7,12 +7,8 @@ "CVE-2020-29015" ], "details": "A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr8m-qw97-823v/GHSA-rr8m-qw97-823v.json b/advisories/unreviewed/2022/05/GHSA-rr8m-qw97-823v/GHSA-rr8m-qw97-823v.json index b10ad44c7a3..f39f6bcc20f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr8m-qw97-823v/GHSA-rr8m-qw97-823v.json +++ b/advisories/unreviewed/2022/05/GHSA-rr8m-qw97-823v/GHSA-rr8m-qw97-823v.json @@ -7,12 +7,8 @@ "CVE-2020-10658" ], "details": "The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv8p-hqqg-w3w8/GHSA-rv8p-hqqg-w3w8.json b/advisories/unreviewed/2022/05/GHSA-rv8p-hqqg-w3w8/GHSA-rv8p-hqqg-w3w8.json index 4526bd50d94..76dac6567ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv8p-hqqg-w3w8/GHSA-rv8p-hqqg-w3w8.json +++ b/advisories/unreviewed/2022/05/GHSA-rv8p-hqqg-w3w8/GHSA-rv8p-hqqg-w3w8.json @@ -7,12 +7,8 @@ "CVE-2021-1195" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx44-mqhf-g68j/GHSA-rx44-mqhf-g68j.json b/advisories/unreviewed/2022/05/GHSA-rx44-mqhf-g68j/GHSA-rx44-mqhf-g68j.json index 834668c4227..bed503e11e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx44-mqhf-g68j/GHSA-rx44-mqhf-g68j.json +++ b/advisories/unreviewed/2022/05/GHSA-rx44-mqhf-g68j/GHSA-rx44-mqhf-g68j.json @@ -7,12 +7,8 @@ "CVE-2021-23936" ], "details": "OX App Suite through 7.10.4 allows XSS via the subject of a task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx59-9p4r-r7rq/GHSA-rx59-9p4r-r7rq.json b/advisories/unreviewed/2022/05/GHSA-rx59-9p4r-r7rq/GHSA-rx59-9p4r-r7rq.json index 56f20d728ff..5e7ed6b0eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx59-9p4r-r7rq/GHSA-rx59-9p4r-r7rq.json +++ b/advisories/unreviewed/2022/05/GHSA-rx59-9p4r-r7rq/GHSA-rx59-9p4r-r7rq.json @@ -7,12 +7,8 @@ "CVE-2017-20001" ], "details": "The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxj8-q442-6jcq/GHSA-rxj8-q442-6jcq.json b/advisories/unreviewed/2022/05/GHSA-rxj8-q442-6jcq/GHSA-rxj8-q442-6jcq.json index 783797084e2..8594e29ecf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxj8-q442-6jcq/GHSA-rxj8-q442-6jcq.json +++ b/advisories/unreviewed/2022/05/GHSA-rxj8-q442-6jcq/GHSA-rxj8-q442-6jcq.json @@ -7,12 +7,8 @@ "CVE-2021-1059" ], "details": "NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input index is not validated, which may lead to integer overflow, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v23p-5qjj-x793/GHSA-v23p-5qjj-x793.json b/advisories/unreviewed/2022/05/GHSA-v23p-5qjj-x793/GHSA-v23p-5qjj-x793.json index 051e3ba84c0..c00297fdc4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v23p-5qjj-x793/GHSA-v23p-5qjj-x793.json +++ b/advisories/unreviewed/2022/05/GHSA-v23p-5qjj-x793/GHSA-v23p-5qjj-x793.json @@ -7,12 +7,8 @@ "CVE-2021-1217" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v285-3pr6-cp87/GHSA-v285-3pr6-cp87.json b/advisories/unreviewed/2022/05/GHSA-v285-3pr6-cp87/GHSA-v285-3pr6-cp87.json index 16fd3d18f9f..eccad60a628 100644 --- a/advisories/unreviewed/2022/05/GHSA-v285-3pr6-cp87/GHSA-v285-3pr6-cp87.json +++ b/advisories/unreviewed/2022/05/GHSA-v285-3pr6-cp87/GHSA-v285-3pr6-cp87.json @@ -7,12 +7,8 @@ "CVE-2020-35610" ], "details": "An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v28v-ph75-h265/GHSA-v28v-ph75-h265.json b/advisories/unreviewed/2022/05/GHSA-v28v-ph75-h265/GHSA-v28v-ph75-h265.json index 1e2e5100972..295e4bbb441 100644 --- a/advisories/unreviewed/2022/05/GHSA-v28v-ph75-h265/GHSA-v28v-ph75-h265.json +++ b/advisories/unreviewed/2022/05/GHSA-v28v-ph75-h265/GHSA-v28v-ph75-h265.json @@ -7,12 +7,8 @@ "CVE-2020-36156" ], "details": "An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v298-98c4-32g7/GHSA-v298-98c4-32g7.json b/advisories/unreviewed/2022/05/GHSA-v298-98c4-32g7/GHSA-v298-98c4-32g7.json index 3e2b16c1f90..81537ba609e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v298-98c4-32g7/GHSA-v298-98c4-32g7.json +++ b/advisories/unreviewed/2022/05/GHSA-v298-98c4-32g7/GHSA-v298-98c4-32g7.json @@ -7,12 +7,8 @@ "CVE-2020-26978" ], "details": "Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v29q-fh48-g7j6/GHSA-v29q-fh48-g7j6.json b/advisories/unreviewed/2022/05/GHSA-v29q-fh48-g7j6/GHSA-v29q-fh48-g7j6.json index b000eb86139..597e30f38a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-v29q-fh48-g7j6/GHSA-v29q-fh48-g7j6.json +++ b/advisories/unreviewed/2022/05/GHSA-v29q-fh48-g7j6/GHSA-v29q-fh48-g7j6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2jq-h62v-wr47/GHSA-v2jq-h62v-wr47.json b/advisories/unreviewed/2022/05/GHSA-v2jq-h62v-wr47/GHSA-v2jq-h62v-wr47.json index 6d3f4be7f4d..8d4a16a0f72 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2jq-h62v-wr47/GHSA-v2jq-h62v-wr47.json +++ b/advisories/unreviewed/2022/05/GHSA-v2jq-h62v-wr47/GHSA-v2jq-h62v-wr47.json @@ -7,12 +7,8 @@ "CVE-2020-27059" ], "details": "In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, 11; Android ID: A-159249069.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2p5-mvpw-w7pp/GHSA-v2p5-mvpw-w7pp.json b/advisories/unreviewed/2022/05/GHSA-v2p5-mvpw-w7pp/GHSA-v2p5-mvpw-w7pp.json index b15ddce3a12..fdaa0eeee7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2p5-mvpw-w7pp/GHSA-v2p5-mvpw-w7pp.json +++ b/advisories/unreviewed/2022/05/GHSA-v2p5-mvpw-w7pp/GHSA-v2p5-mvpw-w7pp.json @@ -7,12 +7,8 @@ "CVE-2020-26733" ], "details": "Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v342-j8qr-3849/GHSA-v342-j8qr-3849.json b/advisories/unreviewed/2022/05/GHSA-v342-j8qr-3849/GHSA-v342-j8qr-3849.json index c938d7d1212..e520859e2f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v342-j8qr-3849/GHSA-v342-j8qr-3849.json +++ b/advisories/unreviewed/2022/05/GHSA-v342-j8qr-3849/GHSA-v342-j8qr-3849.json @@ -7,12 +7,8 @@ "CVE-2020-8280" ], "details": "A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3ph-4853-w2q8/GHSA-v3ph-4853-w2q8.json b/advisories/unreviewed/2022/05/GHSA-v3ph-4853-w2q8/GHSA-v3ph-4853-w2q8.json index 55ce08c688e..706648186a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3ph-4853-w2q8/GHSA-v3ph-4853-w2q8.json +++ b/advisories/unreviewed/2022/05/GHSA-v3ph-4853-w2q8/GHSA-v3ph-4853-w2q8.json @@ -7,12 +7,8 @@ "CVE-2021-23934" ], "details": "OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v438-w5c9-9hgq/GHSA-v438-w5c9-9hgq.json b/advisories/unreviewed/2022/05/GHSA-v438-w5c9-9hgq/GHSA-v438-w5c9-9hgq.json index b265a221d92..0f332ec1e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v438-w5c9-9hgq/GHSA-v438-w5c9-9hgq.json +++ b/advisories/unreviewed/2022/05/GHSA-v438-w5c9-9hgq/GHSA-v438-w5c9-9hgq.json @@ -7,12 +7,8 @@ "CVE-2020-35822" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v452-696f-f255/GHSA-v452-696f-f255.json b/advisories/unreviewed/2022/05/GHSA-v452-696f-f255/GHSA-v452-696f-f255.json index 4c278c8f391..689852d5263 100644 --- a/advisories/unreviewed/2022/05/GHSA-v452-696f-f255/GHSA-v452-696f-f255.json +++ b/advisories/unreviewed/2022/05/GHSA-v452-696f-f255/GHSA-v452-696f-f255.json @@ -7,12 +7,8 @@ "CVE-2020-35945" ], "details": "An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v545-xg3x-8p59/GHSA-v545-xg3x-8p59.json b/advisories/unreviewed/2022/05/GHSA-v545-xg3x-8p59/GHSA-v545-xg3x-8p59.json index 4f1a6bc58bb..f92a3a045a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v545-xg3x-8p59/GHSA-v545-xg3x-8p59.json +++ b/advisories/unreviewed/2022/05/GHSA-v545-xg3x-8p59/GHSA-v545-xg3x-8p59.json @@ -7,12 +7,8 @@ "CVE-2021-1054" ], "details": "NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v55m-v2xf-m8qw/GHSA-v55m-v2xf-m8qw.json b/advisories/unreviewed/2022/05/GHSA-v55m-v2xf-m8qw/GHSA-v55m-v2xf-m8qw.json index 9f7768fc464..cae1af6d403 100644 --- a/advisories/unreviewed/2022/05/GHSA-v55m-v2xf-m8qw/GHSA-v55m-v2xf-m8qw.json +++ b/advisories/unreviewed/2022/05/GHSA-v55m-v2xf-m8qw/GHSA-v55m-v2xf-m8qw.json @@ -7,12 +7,8 @@ "CVE-2020-4898" ], "details": "IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190989.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5ff-x4w5-hjhp/GHSA-v5ff-x4w5-hjhp.json b/advisories/unreviewed/2022/05/GHSA-v5ff-x4w5-hjhp/GHSA-v5ff-x4w5-hjhp.json index 582a5a749e5..1dd0a26fb1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5ff-x4w5-hjhp/GHSA-v5ff-x4w5-hjhp.json +++ b/advisories/unreviewed/2022/05/GHSA-v5ff-x4w5-hjhp/GHSA-v5ff-x4w5-hjhp.json @@ -7,12 +7,8 @@ "CVE-2020-35932" ], "details": "Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5v7-mmfp-xmvv/GHSA-v5v7-mmfp-xmvv.json b/advisories/unreviewed/2022/05/GHSA-v5v7-mmfp-xmvv/GHSA-v5v7-mmfp-xmvv.json index 2007f6282f5..0618b292c2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5v7-mmfp-xmvv/GHSA-v5v7-mmfp-xmvv.json +++ b/advisories/unreviewed/2022/05/GHSA-v5v7-mmfp-xmvv/GHSA-v5v7-mmfp-xmvv.json @@ -7,12 +7,8 @@ "CVE-2020-35812" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6vv-p627-g9h9/GHSA-v6vv-p627-g9h9.json b/advisories/unreviewed/2022/05/GHSA-v6vv-p627-g9h9/GHSA-v6vv-p627-g9h9.json index 19634f5bb62..d1683e2465b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6vv-p627-g9h9/GHSA-v6vv-p627-g9h9.json +++ b/advisories/unreviewed/2022/05/GHSA-v6vv-p627-g9h9/GHSA-v6vv-p627-g9h9.json @@ -7,12 +7,8 @@ "CVE-2018-20311" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6vx-mcc3-f8vr/GHSA-v6vx-mcc3-f8vr.json b/advisories/unreviewed/2022/05/GHSA-v6vx-mcc3-f8vr/GHSA-v6vx-mcc3-f8vr.json index 5d13dce4b59..bd99e49508e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6vx-mcc3-f8vr/GHSA-v6vx-mcc3-f8vr.json +++ b/advisories/unreviewed/2022/05/GHSA-v6vx-mcc3-f8vr/GHSA-v6vx-mcc3-f8vr.json @@ -7,12 +7,8 @@ "CVE-2020-9125" ], "details": "There is an out-of-bound read vulnerability in huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2). An attacker with specific permission can exploit this vulnerability by sending crafted packet with specific parameter to the target device. Due to insufficient validation of the parameter, successful exploit can cause the device to behave abnormally.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6x4-5gp4-2g6g/GHSA-v6x4-5gp4-2g6g.json b/advisories/unreviewed/2022/05/GHSA-v6x4-5gp4-2g6g/GHSA-v6x4-5gp4-2g6g.json index 4cc55728ae1..3653ab6e2fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6x4-5gp4-2g6g/GHSA-v6x4-5gp4-2g6g.json +++ b/advisories/unreviewed/2022/05/GHSA-v6x4-5gp4-2g6g/GHSA-v6x4-5gp4-2g6g.json @@ -7,12 +7,8 @@ "CVE-2020-36165" ], "details": "An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\\. A low privileged user can create a C:/ReleaseX64/ssl/openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This impacts DLO server and client installations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v73h-hhxg-x865/GHSA-v73h-hhxg-x865.json b/advisories/unreviewed/2022/05/GHSA-v73h-hhxg-x865/GHSA-v73h-hhxg-x865.json index 60200d68f5f..55f661d90a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v73h-hhxg-x865/GHSA-v73h-hhxg-x865.json +++ b/advisories/unreviewed/2022/05/GHSA-v73h-hhxg-x865/GHSA-v73h-hhxg-x865.json @@ -7,12 +7,8 @@ "CVE-2020-16014" ], "details": "Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7m7-f4jx-vjc4/GHSA-v7m7-f4jx-vjc4.json b/advisories/unreviewed/2022/05/GHSA-v7m7-f4jx-vjc4/GHSA-v7m7-f4jx-vjc4.json index 0db4a43b4cf..a4ab3c351a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7m7-f4jx-vjc4/GHSA-v7m7-f4jx-vjc4.json +++ b/advisories/unreviewed/2022/05/GHSA-v7m7-f4jx-vjc4/GHSA-v7m7-f4jx-vjc4.json @@ -7,12 +7,8 @@ "CVE-2021-1154" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7v6-9p3w-f3m9/GHSA-v7v6-9p3w-f3m9.json b/advisories/unreviewed/2022/05/GHSA-v7v6-9p3w-f3m9/GHSA-v7v6-9p3w-f3m9.json index 80672e30c9e..b2032b22931 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7v6-9p3w-f3m9/GHSA-v7v6-9p3w-f3m9.json +++ b/advisories/unreviewed/2022/05/GHSA-v7v6-9p3w-f3m9/GHSA-v7v6-9p3w-f3m9.json @@ -7,12 +7,8 @@ "CVE-2020-35828" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, XR500 before 2.3.2.56, XR700 before 1.0.1.10, RAX120 before 1.0.0.78, and R7500v2 before 1.0.3.46.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8hr-pgg6-cf38/GHSA-v8hr-pgg6-cf38.json b/advisories/unreviewed/2022/05/GHSA-v8hr-pgg6-cf38/GHSA-v8hr-pgg6-cf38.json index 03421223190..e5b44771475 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8hr-pgg6-cf38/GHSA-v8hr-pgg6-cf38.json +++ b/advisories/unreviewed/2022/05/GHSA-v8hr-pgg6-cf38/GHSA-v8hr-pgg6-cf38.json @@ -7,12 +7,8 @@ "CVE-2021-1212" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v943-hr28-2mp8/GHSA-v943-hr28-2mp8.json b/advisories/unreviewed/2022/05/GHSA-v943-hr28-2mp8/GHSA-v943-hr28-2mp8.json index 90db3870cbe..67028423bc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-v943-hr28-2mp8/GHSA-v943-hr28-2mp8.json +++ b/advisories/unreviewed/2022/05/GHSA-v943-hr28-2mp8/GHSA-v943-hr28-2mp8.json @@ -7,12 +7,8 @@ "CVE-2020-36176" ], "details": "The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v97c-wm3x-xr3x/GHSA-v97c-wm3x-xr3x.json b/advisories/unreviewed/2022/05/GHSA-v97c-wm3x-xr3x/GHSA-v97c-wm3x-xr3x.json index 448594d3913..d53149a29b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v97c-wm3x-xr3x/GHSA-v97c-wm3x-xr3x.json +++ b/advisories/unreviewed/2022/05/GHSA-v97c-wm3x-xr3x/GHSA-v97c-wm3x-xr3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9w5-rf3g-c746/GHSA-v9w5-rf3g-c746.json b/advisories/unreviewed/2022/05/GHSA-v9w5-rf3g-c746/GHSA-v9w5-rf3g-c746.json index 903650b6c5c..12256530d84 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9w5-rf3g-c746/GHSA-v9w5-rf3g-c746.json +++ b/advisories/unreviewed/2022/05/GHSA-v9w5-rf3g-c746/GHSA-v9w5-rf3g-c746.json @@ -7,12 +7,8 @@ "CVE-2020-24640" ], "details": "There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vc53-c78q-93qw/GHSA-vc53-c78q-93qw.json b/advisories/unreviewed/2022/05/GHSA-vc53-c78q-93qw/GHSA-vc53-c78q-93qw.json index c1cd8d7606f..5bf5cf347fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc53-c78q-93qw/GHSA-vc53-c78q-93qw.json +++ b/advisories/unreviewed/2022/05/GHSA-vc53-c78q-93qw/GHSA-vc53-c78q-93qw.json @@ -7,12 +7,8 @@ "CVE-2018-8726" ], "details": "K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfw8-4p7f-cjjh/GHSA-vfw8-4p7f-cjjh.json b/advisories/unreviewed/2022/05/GHSA-vfw8-4p7f-cjjh/GHSA-vfw8-4p7f-cjjh.json index 735d419817a..3efa89ae0ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfw8-4p7f-cjjh/GHSA-vfw8-4p7f-cjjh.json +++ b/advisories/unreviewed/2022/05/GHSA-vfw8-4p7f-cjjh/GHSA-vfw8-4p7f-cjjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg73-6x83-mx7q/GHSA-vg73-6x83-mx7q.json b/advisories/unreviewed/2022/05/GHSA-vg73-6x83-mx7q/GHSA-vg73-6x83-mx7q.json index 64a924236be..d6a7e1dc345 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg73-6x83-mx7q/GHSA-vg73-6x83-mx7q.json +++ b/advisories/unreviewed/2022/05/GHSA-vg73-6x83-mx7q/GHSA-vg73-6x83-mx7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhv6-87pm-667v/GHSA-vhv6-87pm-667v.json b/advisories/unreviewed/2022/05/GHSA-vhv6-87pm-667v/GHSA-vhv6-87pm-667v.json index de026d0bd4d..b25ad2cec9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhv6-87pm-667v/GHSA-vhv6-87pm-667v.json +++ b/advisories/unreviewed/2022/05/GHSA-vhv6-87pm-667v/GHSA-vhv6-87pm-667v.json @@ -7,12 +7,8 @@ "CVE-2018-19941" ], "details": "A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj85-qf86-f23q/GHSA-vj85-qf86-f23q.json b/advisories/unreviewed/2022/05/GHSA-vj85-qf86-f23q/GHSA-vj85-qf86-f23q.json index 80d45be2377..4d85d6d3c09 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj85-qf86-f23q/GHSA-vj85-qf86-f23q.json +++ b/advisories/unreviewed/2022/05/GHSA-vj85-qf86-f23q/GHSA-vj85-qf86-f23q.json @@ -7,12 +7,8 @@ "CVE-2021-3026" ], "details": "Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm7q-8rhw-2wwq/GHSA-vm7q-8rhw-2wwq.json b/advisories/unreviewed/2022/05/GHSA-vm7q-8rhw-2wwq/GHSA-vm7q-8rhw-2wwq.json index 6210adc98ff..364f7897480 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm7q-8rhw-2wwq/GHSA-vm7q-8rhw-2wwq.json +++ b/advisories/unreviewed/2022/05/GHSA-vm7q-8rhw-2wwq/GHSA-vm7q-8rhw-2wwq.json @@ -7,12 +7,8 @@ "CVE-2020-4487" ], "details": "IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpjc-79v8-48cm/GHSA-vpjc-79v8-48cm.json b/advisories/unreviewed/2022/05/GHSA-vpjc-79v8-48cm/GHSA-vpjc-79v8-48cm.json index f78ed97631b..4bd0e79dc75 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpjc-79v8-48cm/GHSA-vpjc-79v8-48cm.json +++ b/advisories/unreviewed/2022/05/GHSA-vpjc-79v8-48cm/GHSA-vpjc-79v8-48cm.json @@ -7,12 +7,8 @@ "CVE-2018-9333" ], "details": "K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpvq-fg2r-frcr/GHSA-vpvq-fg2r-frcr.json b/advisories/unreviewed/2022/05/GHSA-vpvq-fg2r-frcr/GHSA-vpvq-fg2r-frcr.json index cbcbe35845d..fa53f079131 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpvq-fg2r-frcr/GHSA-vpvq-fg2r-frcr.json +++ b/advisories/unreviewed/2022/05/GHSA-vpvq-fg2r-frcr/GHSA-vpvq-fg2r-frcr.json @@ -7,12 +7,8 @@ "CVE-2020-27293" ], "details": "Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpxx-wvjv-769j/GHSA-vpxx-wvjv-769j.json b/advisories/unreviewed/2022/05/GHSA-vpxx-wvjv-769j/GHSA-vpxx-wvjv-769j.json index e985a9469ad..66690f61ccb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpxx-wvjv-769j/GHSA-vpxx-wvjv-769j.json +++ b/advisories/unreviewed/2022/05/GHSA-vpxx-wvjv-769j/GHSA-vpxx-wvjv-769j.json @@ -7,12 +7,8 @@ "CVE-2020-1865" ], "details": "There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could send crafted PIM messages to the device, successful exploit could cause out of bounds read when the system does the certain operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr92-pw33-4fxj/GHSA-vr92-pw33-4fxj.json b/advisories/unreviewed/2022/05/GHSA-vr92-pw33-4fxj/GHSA-vr92-pw33-4fxj.json index f52377a2c94..658a5e58c11 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr92-pw33-4fxj/GHSA-vr92-pw33-4fxj.json +++ b/advisories/unreviewed/2022/05/GHSA-vr92-pw33-4fxj/GHSA-vr92-pw33-4fxj.json @@ -7,12 +7,8 @@ "CVE-2021-1155" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrjw-8hw2-rwm5/GHSA-vrjw-8hw2-rwm5.json b/advisories/unreviewed/2022/05/GHSA-vrjw-8hw2-rwm5/GHSA-vrjw-8hw2-rwm5.json index b206e511503..4cdc5bf7a7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrjw-8hw2-rwm5/GHSA-vrjw-8hw2-rwm5.json +++ b/advisories/unreviewed/2022/05/GHSA-vrjw-8hw2-rwm5/GHSA-vrjw-8hw2-rwm5.json @@ -7,12 +7,8 @@ "CVE-2021-23123" ], "details": "An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrq7-q46g-p2fq/GHSA-vrq7-q46g-p2fq.json b/advisories/unreviewed/2022/05/GHSA-vrq7-q46g-p2fq/GHSA-vrq7-q46g-p2fq.json index cd9ee48b263..ee531e0672a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrq7-q46g-p2fq/GHSA-vrq7-q46g-p2fq.json +++ b/advisories/unreviewed/2022/05/GHSA-vrq7-q46g-p2fq/GHSA-vrq7-q46g-p2fq.json @@ -7,12 +7,8 @@ "CVE-2020-24577" ], "details": "An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the application's response body for a /tmp/var/passwd or /tmp/home/wan_stat URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv8p-qf65-j73w/GHSA-vv8p-qf65-j73w.json b/advisories/unreviewed/2022/05/GHSA-vv8p-qf65-j73w/GHSA-vv8p-qf65-j73w.json index 98a4ecd3c7e..0543cf43c8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv8p-qf65-j73w/GHSA-vv8p-qf65-j73w.json +++ b/advisories/unreviewed/2022/05/GHSA-vv8p-qf65-j73w/GHSA-vv8p-qf65-j73w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvf2-r5qm-w4f7/GHSA-vvf2-r5qm-w4f7.json b/advisories/unreviewed/2022/05/GHSA-vvf2-r5qm-w4f7/GHSA-vvf2-r5qm-w4f7.json index 0ad62637006..af940b9a542 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvf2-r5qm-w4f7/GHSA-vvf2-r5qm-w4f7.json +++ b/advisories/unreviewed/2022/05/GHSA-vvf2-r5qm-w4f7/GHSA-vvf2-r5qm-w4f7.json @@ -7,12 +7,8 @@ "CVE-2021-1360" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvq3-v6fg-g5vw/GHSA-vvq3-v6fg-g5vw.json b/advisories/unreviewed/2022/05/GHSA-vvq3-v6fg-g5vw/GHSA-vvq3-v6fg-g5vw.json index 668cb47b888..3c80f0e6f73 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvq3-v6fg-g5vw/GHSA-vvq3-v6fg-g5vw.json +++ b/advisories/unreviewed/2022/05/GHSA-vvq3-v6fg-g5vw/GHSA-vvq3-v6fg-g5vw.json @@ -7,12 +7,8 @@ "CVE-2020-9208" ], "details": "There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access to the module can exploit this vulnerability to obtain extra information, leading to information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw53-rmxx-2xmr/GHSA-vw53-rmxx-2xmr.json b/advisories/unreviewed/2022/05/GHSA-vw53-rmxx-2xmr/GHSA-vw53-rmxx-2xmr.json index ef13c368e17..64063689b49 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw53-rmxx-2xmr/GHSA-vw53-rmxx-2xmr.json +++ b/advisories/unreviewed/2022/05/GHSA-vw53-rmxx-2xmr/GHSA-vw53-rmxx-2xmr.json @@ -7,12 +7,8 @@ "CVE-2021-3004" ], "details": "The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwcx-ffx9-jw3x/GHSA-vwcx-ffx9-jw3x.json b/advisories/unreviewed/2022/05/GHSA-vwcx-ffx9-jw3x/GHSA-vwcx-ffx9-jw3x.json index fa0808c67f3..64fbbd7235c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwcx-ffx9-jw3x/GHSA-vwcx-ffx9-jw3x.json +++ b/advisories/unreviewed/2022/05/GHSA-vwcx-ffx9-jw3x/GHSA-vwcx-ffx9-jw3x.json @@ -7,12 +7,8 @@ "CVE-2020-4896" ], "details": "IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 190987.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwqf-h7h6-r8gg/GHSA-vwqf-h7h6-r8gg.json b/advisories/unreviewed/2022/05/GHSA-vwqf-h7h6-r8gg/GHSA-vwqf-h7h6-r8gg.json index 3813f9964e4..b17ae7d6680 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwqf-h7h6-r8gg/GHSA-vwqf-h7h6-r8gg.json +++ b/advisories/unreviewed/2022/05/GHSA-vwqf-h7h6-r8gg/GHSA-vwqf-h7h6-r8gg.json @@ -7,12 +7,8 @@ "CVE-2020-26773" ], "details": "Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2j5-7v7j-3j8r/GHSA-w2j5-7v7j-3j8r.json b/advisories/unreviewed/2022/05/GHSA-w2j5-7v7j-3j8r/GHSA-w2j5-7v7j-3j8r.json index 99bc14fb24d..0e2f164bbfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2j5-7v7j-3j8r/GHSA-w2j5-7v7j-3j8r.json +++ b/advisories/unreviewed/2022/05/GHSA-w2j5-7v7j-3j8r/GHSA-w2j5-7v7j-3j8r.json @@ -7,12 +7,8 @@ "CVE-2021-1172" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w44v-8fr4-v7gw/GHSA-w44v-8fr4-v7gw.json b/advisories/unreviewed/2022/05/GHSA-w44v-8fr4-v7gw/GHSA-w44v-8fr4-v7gw.json index 9d0c1a8f4e2..0eaec227eb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w44v-8fr4-v7gw/GHSA-w44v-8fr4-v7gw.json +++ b/advisories/unreviewed/2022/05/GHSA-w44v-8fr4-v7gw/GHSA-w44v-8fr4-v7gw.json @@ -7,12 +7,8 @@ "CVE-2021-1242" ], "details": "A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application interface. A successful exploit could allow the attacker to modify how the shared file name displays within the interface, which could allow the attacker to conduct phishing or spoofing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w46m-mpvw-cv2h/GHSA-w46m-mpvw-cv2h.json b/advisories/unreviewed/2022/05/GHSA-w46m-mpvw-cv2h/GHSA-w46m-mpvw-cv2h.json index 2b76fea5d34..d3067a1a4a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w46m-mpvw-cv2h/GHSA-w46m-mpvw-cv2h.json +++ b/advisories/unreviewed/2022/05/GHSA-w46m-mpvw-cv2h/GHSA-w46m-mpvw-cv2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w479-762h-chxx/GHSA-w479-762h-chxx.json b/advisories/unreviewed/2022/05/GHSA-w479-762h-chxx/GHSA-w479-762h-chxx.json index 807a619b9b9..4999518d9a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w479-762h-chxx/GHSA-w479-762h-chxx.json +++ b/advisories/unreviewed/2022/05/GHSA-w479-762h-chxx/GHSA-w479-762h-chxx.json @@ -7,12 +7,8 @@ "CVE-2021-22495" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung ID is SVE-2020-19174 (January 2021).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4g5-mcc7-3767/GHSA-w4g5-mcc7-3767.json b/advisories/unreviewed/2022/05/GHSA-w4g5-mcc7-3767/GHSA-w4g5-mcc7-3767.json index d2df399ab09..429efecfb91 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4g5-mcc7-3767/GHSA-w4g5-mcc7-3767.json +++ b/advisories/unreviewed/2022/05/GHSA-w4g5-mcc7-3767/GHSA-w4g5-mcc7-3767.json @@ -7,12 +7,8 @@ "CVE-2021-21445" ], "details": "SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4j5-x3m4-x3jx/GHSA-w4j5-x3m4-x3jx.json b/advisories/unreviewed/2022/05/GHSA-w4j5-x3m4-x3jx/GHSA-w4j5-x3m4-x3jx.json index efcfa49650e..5f05cee7602 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4j5-x3m4-x3jx/GHSA-w4j5-x3m4-x3jx.json +++ b/advisories/unreviewed/2022/05/GHSA-w4j5-x3m4-x3jx/GHSA-w4j5-x3m4-x3jx.json @@ -7,12 +7,8 @@ "CVE-2021-21113" ], "details": "Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5fp-2j8v-x63m/GHSA-w5fp-2j8v-x63m.json b/advisories/unreviewed/2022/05/GHSA-w5fp-2j8v-x63m/GHSA-w5fp-2j8v-x63m.json index 2274dfed3a2..c5bc9d1973a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5fp-2j8v-x63m/GHSA-w5fp-2j8v-x63m.json +++ b/advisories/unreviewed/2022/05/GHSA-w5fp-2j8v-x63m/GHSA-w5fp-2j8v-x63m.json @@ -7,12 +7,8 @@ "CVE-2021-1276" ], "details": "Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests.\n These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device.\n For more information about these vulnerabilities, see the Details section of this advisory.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7f7-f46g-r954/GHSA-w7f7-f46g-r954.json b/advisories/unreviewed/2022/05/GHSA-w7f7-f46g-r954/GHSA-w7f7-f46g-r954.json index 9751444ccfe..e4f6d04c8b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7f7-f46g-r954/GHSA-w7f7-f46g-r954.json +++ b/advisories/unreviewed/2022/05/GHSA-w7f7-f46g-r954/GHSA-w7f7-f46g-r954.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7xj-fmh9-68cc/GHSA-w7xj-fmh9-68cc.json b/advisories/unreviewed/2022/05/GHSA-w7xj-fmh9-68cc/GHSA-w7xj-fmh9-68cc.json index cff05a56302..db4b79f62e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7xj-fmh9-68cc/GHSA-w7xj-fmh9-68cc.json +++ b/advisories/unreviewed/2022/05/GHSA-w7xj-fmh9-68cc/GHSA-w7xj-fmh9-68cc.json @@ -7,12 +7,8 @@ "CVE-2021-1144" ], "details": "A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing a password. An authenticated attacker without administrative privileges could exploit this vulnerability by sending a modified HTTP request to an affected device. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w82f-48jf-c4v4/GHSA-w82f-48jf-c4v4.json b/advisories/unreviewed/2022/05/GHSA-w82f-48jf-c4v4/GHSA-w82f-48jf-c4v4.json index e7ca5c7313a..84ec3580f4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w82f-48jf-c4v4/GHSA-w82f-48jf-c4v4.json +++ b/advisories/unreviewed/2022/05/GHSA-w82f-48jf-c4v4/GHSA-w82f-48jf-c4v4.json @@ -7,12 +7,8 @@ "CVE-2020-9142" ], "details": "There is a heap base buffer overflow vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability can cause heap overflow and memory overwriting when the system incorrectly processes the update file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w84r-65r3-58rj/GHSA-w84r-65r3-58rj.json b/advisories/unreviewed/2022/05/GHSA-w84r-65r3-58rj/GHSA-w84r-65r3-58rj.json index dffc6c5bc3d..de4e3ca5604 100644 --- a/advisories/unreviewed/2022/05/GHSA-w84r-65r3-58rj/GHSA-w84r-65r3-58rj.json +++ b/advisories/unreviewed/2022/05/GHSA-w84r-65r3-58rj/GHSA-w84r-65r3-58rj.json @@ -7,12 +7,8 @@ "CVE-2020-4673" ], "details": "IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8j2-273f-92wh/GHSA-w8j2-273f-92wh.json b/advisories/unreviewed/2022/05/GHSA-w8j2-273f-92wh/GHSA-w8j2-273f-92wh.json index ddd663971d1..8606f3acdcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8j2-273f-92wh/GHSA-w8j2-273f-92wh.json +++ b/advisories/unreviewed/2022/05/GHSA-w8j2-273f-92wh/GHSA-w8j2-273f-92wh.json @@ -7,12 +7,8 @@ "CVE-2020-9143" ], "details": "There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability may lead to low-sensitive information exposure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8w2-r9w7-hqwr/GHSA-w8w2-r9w7-hqwr.json b/advisories/unreviewed/2022/05/GHSA-w8w2-r9w7-hqwr/GHSA-w8w2-r9w7-hqwr.json index daa7f7f8356..0a07196c00d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8w2-r9w7-hqwr/GHSA-w8w2-r9w7-hqwr.json +++ b/advisories/unreviewed/2022/05/GHSA-w8w2-r9w7-hqwr/GHSA-w8w2-r9w7-hqwr.json @@ -7,12 +7,8 @@ "CVE-2020-16031" ], "details": "Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w998-mp46-3582/GHSA-w998-mp46-3582.json b/advisories/unreviewed/2022/05/GHSA-w998-mp46-3582/GHSA-w998-mp46-3582.json index 90aebf78ad8..8d57c210bf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w998-mp46-3582/GHSA-w998-mp46-3582.json +++ b/advisories/unreviewed/2022/05/GHSA-w998-mp46-3582/GHSA-w998-mp46-3582.json @@ -7,12 +7,8 @@ "CVE-2020-11835" ], "details": "In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_write in proc_work_mode_write causes a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9rf-wf6f-8c9r/GHSA-w9rf-wf6f-8c9r.json b/advisories/unreviewed/2022/05/GHSA-w9rf-wf6f-8c9r/GHSA-w9rf-wf6f-8c9r.json index f17b8351d39..1bfc4dd52d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9rf-wf6f-8c9r/GHSA-w9rf-wf6f-8c9r.json +++ b/advisories/unreviewed/2022/05/GHSA-w9rf-wf6f-8c9r/GHSA-w9rf-wf6f-8c9r.json @@ -7,12 +7,8 @@ "CVE-2020-35748" ], "details": "Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc4x-mm5r-q4j3/GHSA-wc4x-mm5r-q4j3.json b/advisories/unreviewed/2022/05/GHSA-wc4x-mm5r-q4j3/GHSA-wc4x-mm5r-q4j3.json index 94b9707264e..548d97fbd35 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc4x-mm5r-q4j3/GHSA-wc4x-mm5r-q4j3.json +++ b/advisories/unreviewed/2022/05/GHSA-wc4x-mm5r-q4j3/GHSA-wc4x-mm5r-q4j3.json @@ -7,12 +7,8 @@ "CVE-2021-0309" ], "details": "In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158480899.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc6g-g9wj-mchg/GHSA-wc6g-g9wj-mchg.json b/advisories/unreviewed/2022/05/GHSA-wc6g-g9wj-mchg/GHSA-wc6g-g9wj-mchg.json index 2bfa6909aed..d8a1e193610 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc6g-g9wj-mchg/GHSA-wc6g-g9wj-mchg.json +++ b/advisories/unreviewed/2022/05/GHSA-wc6g-g9wj-mchg/GHSA-wc6g-g9wj-mchg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc7g-h7q8-29g2/GHSA-wc7g-h7q8-29g2.json b/advisories/unreviewed/2022/05/GHSA-wc7g-h7q8-29g2/GHSA-wc7g-h7q8-29g2.json index 62334cadf98..e2da33e9811 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc7g-h7q8-29g2/GHSA-wc7g-h7q8-29g2.json +++ b/advisories/unreviewed/2022/05/GHSA-wc7g-h7q8-29g2/GHSA-wc7g-h7q8-29g2.json @@ -7,12 +7,8 @@ "CVE-2016-20003" ], "details": "The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcf9-3wr2-8wmf/GHSA-wcf9-3wr2-8wmf.json b/advisories/unreviewed/2022/05/GHSA-wcf9-3wr2-8wmf/GHSA-wcf9-3wr2-8wmf.json index c1553a7d27c..c10493198fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcf9-3wr2-8wmf/GHSA-wcf9-3wr2-8wmf.json +++ b/advisories/unreviewed/2022/05/GHSA-wcf9-3wr2-8wmf/GHSA-wcf9-3wr2-8wmf.json @@ -7,12 +7,8 @@ "CVE-2020-13451" ], "details": "An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcrm-5qg4-797w/GHSA-wcrm-5qg4-797w.json b/advisories/unreviewed/2022/05/GHSA-wcrm-5qg4-797w/GHSA-wcrm-5qg4-797w.json index 48605f573cd..44720b23015 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcrm-5qg4-797w/GHSA-wcrm-5qg4-797w.json +++ b/advisories/unreviewed/2022/05/GHSA-wcrm-5qg4-797w/GHSA-wcrm-5qg4-797w.json @@ -7,12 +7,8 @@ "CVE-2021-21463" ], "details": "SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf63-v8gp-v4wv/GHSA-wf63-v8gp-v4wv.json b/advisories/unreviewed/2022/05/GHSA-wf63-v8gp-v4wv/GHSA-wf63-v8gp-v4wv.json index 0ca33ee936b..afa09e78351 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf63-v8gp-v4wv/GHSA-wf63-v8gp-v4wv.json +++ b/advisories/unreviewed/2022/05/GHSA-wf63-v8gp-v4wv/GHSA-wf63-v8gp-v4wv.json @@ -7,12 +7,8 @@ "CVE-2020-16016" ], "details": "Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfrc-r682-56qv/GHSA-wfrc-r682-56qv.json b/advisories/unreviewed/2022/05/GHSA-wfrc-r682-56qv/GHSA-wfrc-r682-56qv.json index 9ada087f154..972db6c95ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfrc-r682-56qv/GHSA-wfrc-r682-56qv.json +++ b/advisories/unreviewed/2022/05/GHSA-wfrc-r682-56qv/GHSA-wfrc-r682-56qv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg6f-7wh7-87pc/GHSA-wg6f-7wh7-87pc.json b/advisories/unreviewed/2022/05/GHSA-wg6f-7wh7-87pc/GHSA-wg6f-7wh7-87pc.json index 82004e8b259..9933d1c3302 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg6f-7wh7-87pc/GHSA-wg6f-7wh7-87pc.json +++ b/advisories/unreviewed/2022/05/GHSA-wg6f-7wh7-87pc/GHSA-wg6f-7wh7-87pc.json @@ -7,12 +7,8 @@ "CVE-2021-0316" ], "details": "In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-168802990.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgc8-c98w-8fvh/GHSA-wgc8-c98w-8fvh.json b/advisories/unreviewed/2022/05/GHSA-wgc8-c98w-8fvh/GHSA-wgc8-c98w-8fvh.json index 29c794a92e0..3babf23a432 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgc8-c98w-8fvh/GHSA-wgc8-c98w-8fvh.json +++ b/advisories/unreviewed/2022/05/GHSA-wgc8-c98w-8fvh/GHSA-wgc8-c98w-8fvh.json @@ -7,12 +7,8 @@ "CVE-2020-17509" ], "details": "ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whgc-86v6-h65r/GHSA-whgc-86v6-h65r.json b/advisories/unreviewed/2022/05/GHSA-whgc-86v6-h65r/GHSA-whgc-86v6-h65r.json index dc53f4ad585..918ca6596ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-whgc-86v6-h65r/GHSA-whgc-86v6-h65r.json +++ b/advisories/unreviewed/2022/05/GHSA-whgc-86v6-h65r/GHSA-whgc-86v6-h65r.json @@ -7,12 +7,8 @@ "CVE-2020-35823" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmxr-9qh6-cpq8/GHSA-wmxr-9qh6-cpq8.json b/advisories/unreviewed/2022/05/GHSA-wmxr-9qh6-cpq8/GHSA-wmxr-9qh6-cpq8.json index ad503c0ed97..474e9e6c62d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmxr-9qh6-cpq8/GHSA-wmxr-9qh6-cpq8.json +++ b/advisories/unreviewed/2022/05/GHSA-wmxr-9qh6-cpq8/GHSA-wmxr-9qh6-cpq8.json @@ -7,12 +7,8 @@ "CVE-2020-4733" ], "details": "IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wq9m-52vr-cc44/GHSA-wq9m-52vr-cc44.json b/advisories/unreviewed/2022/05/GHSA-wq9m-52vr-cc44/GHSA-wq9m-52vr-cc44.json index 9f14593f5de..8b4869e51eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq9m-52vr-cc44/GHSA-wq9m-52vr-cc44.json +++ b/advisories/unreviewed/2022/05/GHSA-wq9m-52vr-cc44/GHSA-wq9m-52vr-cc44.json @@ -7,12 +7,8 @@ "CVE-2020-4916" ], "details": "IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191390.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqm8-5876-3578/GHSA-wqm8-5876-3578.json b/advisories/unreviewed/2022/05/GHSA-wqm8-5876-3578/GHSA-wqm8-5876-3578.json index 5e2848096ab..39b2bf37e78 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqm8-5876-3578/GHSA-wqm8-5876-3578.json +++ b/advisories/unreviewed/2022/05/GHSA-wqm8-5876-3578/GHSA-wqm8-5876-3578.json @@ -7,12 +7,8 @@ "CVE-2020-9209" ], "details": "There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the directory limitation. Attackers can exploit this vulnerability by crafting malicious file to launch privilege escalation. This can compromise normal service of affected products.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqmq-2c4h-8v64/GHSA-wqmq-2c4h-8v64.json b/advisories/unreviewed/2022/05/GHSA-wqmq-2c4h-8v64/GHSA-wqmq-2c4h-8v64.json index defaf31874e..178dc74e8d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqmq-2c4h-8v64/GHSA-wqmq-2c4h-8v64.json +++ b/advisories/unreviewed/2022/05/GHSA-wqmq-2c4h-8v64/GHSA-wqmq-2c4h-8v64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr4v-mm53-3vc3/GHSA-wr4v-mm53-3vc3.json b/advisories/unreviewed/2022/05/GHSA-wr4v-mm53-3vc3/GHSA-wr4v-mm53-3vc3.json index 673f3b055fc..3eb146a2610 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr4v-mm53-3vc3/GHSA-wr4v-mm53-3vc3.json +++ b/advisories/unreviewed/2022/05/GHSA-wr4v-mm53-3vc3/GHSA-wr4v-mm53-3vc3.json @@ -7,12 +7,8 @@ "CVE-2020-35839" ], "details": "Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, XR500 before 2.3.2.56, XR700 before 1.0.1.10, and RAX120 before 1.0.0.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrjw-5qvp-gqcg/GHSA-wrjw-5qvp-gqcg.json b/advisories/unreviewed/2022/05/GHSA-wrjw-5qvp-gqcg/GHSA-wrjw-5qvp-gqcg.json index ee512520295..aeb4fb009e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrjw-5qvp-gqcg/GHSA-wrjw-5qvp-gqcg.json +++ b/advisories/unreviewed/2022/05/GHSA-wrjw-5qvp-gqcg/GHSA-wrjw-5qvp-gqcg.json @@ -7,12 +7,8 @@ "CVE-2018-20315" ], "details": "Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv77-666p-gm5q/GHSA-wv77-666p-gm5q.json b/advisories/unreviewed/2022/05/GHSA-wv77-666p-gm5q/GHSA-wv77-666p-gm5q.json index 32a9b400563..51771c62f22 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv77-666p-gm5q/GHSA-wv77-666p-gm5q.json +++ b/advisories/unreviewed/2022/05/GHSA-wv77-666p-gm5q/GHSA-wv77-666p-gm5q.json @@ -7,12 +7,8 @@ "CVE-2020-25850" ], "details": "The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww34-37gv-7gf7/GHSA-ww34-37gv-7gf7.json b/advisories/unreviewed/2022/05/GHSA-ww34-37gv-7gf7/GHSA-ww34-37gv-7gf7.json index bf515fea677..6b07fcb8666 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww34-37gv-7gf7/GHSA-ww34-37gv-7gf7.json +++ b/advisories/unreviewed/2022/05/GHSA-ww34-37gv-7gf7/GHSA-ww34-37gv-7gf7.json @@ -7,12 +7,8 @@ "CVE-2020-35111" ], "details": "When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww76-wxv4-qwxc/GHSA-ww76-wxv4-qwxc.json b/advisories/unreviewed/2022/05/GHSA-ww76-wxv4-qwxc/GHSA-ww76-wxv4-qwxc.json index 8a140baf065..d53d22729f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww76-wxv4-qwxc/GHSA-ww76-wxv4-qwxc.json +++ b/advisories/unreviewed/2022/05/GHSA-ww76-wxv4-qwxc/GHSA-ww76-wxv4-qwxc.json @@ -7,12 +7,8 @@ "CVE-2021-3018" ], "details": "ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwmg-f4mg-ffmp/GHSA-wwmg-f4mg-ffmp.json b/advisories/unreviewed/2022/05/GHSA-wwmg-f4mg-ffmp/GHSA-wwmg-f4mg-ffmp.json index 770ea5177ff..566d1ac564c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwmg-f4mg-ffmp/GHSA-wwmg-f4mg-ffmp.json +++ b/advisories/unreviewed/2022/05/GHSA-wwmg-f4mg-ffmp/GHSA-wwmg-f4mg-ffmp.json @@ -7,12 +7,8 @@ "CVE-2021-1191" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x26x-3jfm-g5qc/GHSA-x26x-3jfm-g5qc.json b/advisories/unreviewed/2022/05/GHSA-x26x-3jfm-g5qc/GHSA-x26x-3jfm-g5qc.json index 01c4030e882..8edbdae7051 100644 --- a/advisories/unreviewed/2022/05/GHSA-x26x-3jfm-g5qc/GHSA-x26x-3jfm-g5qc.json +++ b/advisories/unreviewed/2022/05/GHSA-x26x-3jfm-g5qc/GHSA-x26x-3jfm-g5qc.json @@ -7,12 +7,8 @@ "CVE-2021-1160" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2q6-5p25-frj9/GHSA-x2q6-5p25-frj9.json b/advisories/unreviewed/2022/05/GHSA-x2q6-5p25-frj9/GHSA-x2q6-5p25-frj9.json index 1e5c643da29..27d0b41da1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2q6-5p25-frj9/GHSA-x2q6-5p25-frj9.json +++ b/advisories/unreviewed/2022/05/GHSA-x2q6-5p25-frj9/GHSA-x2q6-5p25-frj9.json @@ -7,12 +7,8 @@ "CVE-2020-4596" ], "details": "IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184812.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x32h-9jvh-q4wv/GHSA-x32h-9jvh-q4wv.json b/advisories/unreviewed/2022/05/GHSA-x32h-9jvh-q4wv/GHSA-x32h-9jvh-q4wv.json index 089606bfaf1..a8fc1870647 100644 --- a/advisories/unreviewed/2022/05/GHSA-x32h-9jvh-q4wv/GHSA-x32h-9jvh-q4wv.json +++ b/advisories/unreviewed/2022/05/GHSA-x32h-9jvh-q4wv/GHSA-x32h-9jvh-q4wv.json @@ -7,12 +7,8 @@ "CVE-2018-8725" ], "details": "K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x33g-fm74-m47v/GHSA-x33g-fm74-m47v.json b/advisories/unreviewed/2022/05/GHSA-x33g-fm74-m47v/GHSA-x33g-fm74-m47v.json index 08dc4505025..4264aa3248a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x33g-fm74-m47v/GHSA-x33g-fm74-m47v.json +++ b/advisories/unreviewed/2022/05/GHSA-x33g-fm74-m47v/GHSA-x33g-fm74-m47v.json @@ -7,12 +7,8 @@ "CVE-2020-27148" ], "details": "The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4j2-vmqc-w7pq/GHSA-x4j2-vmqc-w7pq.json b/advisories/unreviewed/2022/05/GHSA-x4j2-vmqc-w7pq/GHSA-x4j2-vmqc-w7pq.json index 643b0d97652..17220b319ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4j2-vmqc-w7pq/GHSA-x4j2-vmqc-w7pq.json +++ b/advisories/unreviewed/2022/05/GHSA-x4j2-vmqc-w7pq/GHSA-x4j2-vmqc-w7pq.json @@ -7,12 +7,8 @@ "CVE-2021-23935" ], "details": "OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x58f-3mqq-mj3r/GHSA-x58f-3mqq-mj3r.json b/advisories/unreviewed/2022/05/GHSA-x58f-3mqq-mj3r/GHSA-x58f-3mqq-mj3r.json index bff9fd54088..1ccd37ca155 100644 --- a/advisories/unreviewed/2022/05/GHSA-x58f-3mqq-mj3r/GHSA-x58f-3mqq-mj3r.json +++ b/advisories/unreviewed/2022/05/GHSA-x58f-3mqq-mj3r/GHSA-x58f-3mqq-mj3r.json @@ -7,12 +7,8 @@ "CVE-2020-16025" ], "details": "Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5vr-crjr-r249/GHSA-x5vr-crjr-r249.json b/advisories/unreviewed/2022/05/GHSA-x5vr-crjr-r249/GHSA-x5vr-crjr-r249.json index bd7345cf759..ca55a3c10cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5vr-crjr-r249/GHSA-x5vr-crjr-r249.json +++ b/advisories/unreviewed/2022/05/GHSA-x5vr-crjr-r249/GHSA-x5vr-crjr-r249.json @@ -7,12 +7,8 @@ "CVE-2021-1167" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6rc-q735-q8qg/GHSA-x6rc-q735-q8qg.json b/advisories/unreviewed/2022/05/GHSA-x6rc-q735-q8qg/GHSA-x6rc-q735-q8qg.json index 2c0ef0792c3..65156947fe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6rc-q735-q8qg/GHSA-x6rc-q735-q8qg.json +++ b/advisories/unreviewed/2022/05/GHSA-x6rc-q735-q8qg/GHSA-x6rc-q735-q8qg.json @@ -7,12 +7,8 @@ "CVE-2020-26971" ], "details": "Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7jf-9rq8-cf6r/GHSA-x7jf-9rq8-cf6r.json b/advisories/unreviewed/2022/05/GHSA-x7jf-9rq8-cf6r/GHSA-x7jf-9rq8-cf6r.json index 6edf0435e7e..e9f34a913c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7jf-9rq8-cf6r/GHSA-x7jf-9rq8-cf6r.json +++ b/advisories/unreviewed/2022/05/GHSA-x7jf-9rq8-cf6r/GHSA-x7jf-9rq8-cf6r.json @@ -7,12 +7,8 @@ "CVE-2021-1240" ], "details": "A vulnerability in the loading process of specific DLLs in Cisco Proximity Desktop for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker must have valid credentials on the Windows system. This vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x85r-5p3p-3jxw/GHSA-x85r-5p3p-3jxw.json b/advisories/unreviewed/2022/05/GHSA-x85r-5p3p-3jxw/GHSA-x85r-5p3p-3jxw.json index 9dbadbb180e..0ea66b5c7f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x85r-5p3p-3jxw/GHSA-x85r-5p3p-3jxw.json +++ b/advisories/unreviewed/2022/05/GHSA-x85r-5p3p-3jxw/GHSA-x85r-5p3p-3jxw.json @@ -7,12 +7,8 @@ "CVE-2020-35842" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.76, WNR1000v4 before 1.1.0.62, WNR2020 before 1.1.0.62, and WNR2050 before 1.1.0.62.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x8h5-wv39-rvrw/GHSA-x8h5-wv39-rvrw.json b/advisories/unreviewed/2022/05/GHSA-x8h5-wv39-rvrw/GHSA-x8h5-wv39-rvrw.json index 12bff625fcc..e516e768f40 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8h5-wv39-rvrw/GHSA-x8h5-wv39-rvrw.json +++ b/advisories/unreviewed/2022/05/GHSA-x8h5-wv39-rvrw/GHSA-x8h5-wv39-rvrw.json @@ -7,12 +7,8 @@ "CVE-2021-2047" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc2v-fcxv-wj59/GHSA-xc2v-fcxv-wj59.json b/advisories/unreviewed/2022/05/GHSA-xc2v-fcxv-wj59/GHSA-xc2v-fcxv-wj59.json index 378a5e1dc23..db27272cf0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc2v-fcxv-wj59/GHSA-xc2v-fcxv-wj59.json +++ b/advisories/unreviewed/2022/05/GHSA-xc2v-fcxv-wj59/GHSA-xc2v-fcxv-wj59.json @@ -7,12 +7,8 @@ "CVE-2018-19945" ], "details": "A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xchf-g75x-m4xx/GHSA-xchf-g75x-m4xx.json b/advisories/unreviewed/2022/05/GHSA-xchf-g75x-m4xx/GHSA-xchf-g75x-m4xx.json index 6f404d3b9a5..23118bbe385 100644 --- a/advisories/unreviewed/2022/05/GHSA-xchf-g75x-m4xx/GHSA-xchf-g75x-m4xx.json +++ b/advisories/unreviewed/2022/05/GHSA-xchf-g75x-m4xx/GHSA-xchf-g75x-m4xx.json @@ -7,12 +7,8 @@ "CVE-2020-4910" ], "details": "IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191274.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcj4-r8wq-5rcc/GHSA-xcj4-r8wq-5rcc.json b/advisories/unreviewed/2022/05/GHSA-xcj4-r8wq-5rcc/GHSA-xcj4-r8wq-5rcc.json index 0abbb9820a8..02404cfea5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcj4-r8wq-5rcc/GHSA-xcj4-r8wq-5rcc.json +++ b/advisories/unreviewed/2022/05/GHSA-xcj4-r8wq-5rcc/GHSA-xcj4-r8wq-5rcc.json @@ -7,12 +7,8 @@ "CVE-2021-21106" ], "details": "Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcp4-49mj-2j86/GHSA-xcp4-49mj-2j86.json b/advisories/unreviewed/2022/05/GHSA-xcp4-49mj-2j86/GHSA-xcp4-49mj-2j86.json index ce75716742d..c0fb992e8a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcp4-49mj-2j86/GHSA-xcp4-49mj-2j86.json +++ b/advisories/unreviewed/2022/05/GHSA-xcp4-49mj-2j86/GHSA-xcp4-49mj-2j86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf35-pm29-wrq6/GHSA-xf35-pm29-wrq6.json b/advisories/unreviewed/2022/05/GHSA-xf35-pm29-wrq6/GHSA-xf35-pm29-wrq6.json index 78e190e0d3b..b4c554d0608 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf35-pm29-wrq6/GHSA-xf35-pm29-wrq6.json +++ b/advisories/unreviewed/2022/05/GHSA-xf35-pm29-wrq6/GHSA-xf35-pm29-wrq6.json @@ -7,12 +7,8 @@ "CVE-2020-10210" ], "details": "Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series, Kami7B, an attacker may remotely log in through SSH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf3h-cpcr-5vv3/GHSA-xf3h-cpcr-5vv3.json b/advisories/unreviewed/2022/05/GHSA-xf3h-cpcr-5vv3/GHSA-xf3h-cpcr-5vv3.json index e1bcb5f779a..46f7a1e0c62 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf3h-cpcr-5vv3/GHSA-xf3h-cpcr-5vv3.json +++ b/advisories/unreviewed/2022/05/GHSA-xf3h-cpcr-5vv3/GHSA-xf3h-cpcr-5vv3.json @@ -7,12 +7,8 @@ "CVE-2020-1866" ], "details": "There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg86-vxqv-4j86/GHSA-xg86-vxqv-4j86.json b/advisories/unreviewed/2022/05/GHSA-xg86-vxqv-4j86/GHSA-xg86-vxqv-4j86.json index 136f48d6e30..ac0f25fd7ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg86-vxqv-4j86/GHSA-xg86-vxqv-4j86.json +++ b/advisories/unreviewed/2022/05/GHSA-xg86-vxqv-4j86/GHSA-xg86-vxqv-4j86.json @@ -7,12 +7,8 @@ "CVE-2020-35733" ], "details": "An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgm3-c263-cjqp/GHSA-xgm3-c263-cjqp.json b/advisories/unreviewed/2022/05/GHSA-xgm3-c263-cjqp/GHSA-xgm3-c263-cjqp.json index 1cad6b0f3ce..05b946407eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgm3-c263-cjqp/GHSA-xgm3-c263-cjqp.json +++ b/advisories/unreviewed/2022/05/GHSA-xgm3-c263-cjqp/GHSA-xgm3-c263-cjqp.json @@ -7,12 +7,8 @@ "CVE-2021-1189" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgvj-75pc-8x47/GHSA-xgvj-75pc-8x47.json b/advisories/unreviewed/2022/05/GHSA-xgvj-75pc-8x47/GHSA-xgvj-75pc-8x47.json index 46f3eb01b00..6e7f8b4c574 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgvj-75pc-8x47/GHSA-xgvj-75pc-8x47.json +++ b/advisories/unreviewed/2022/05/GHSA-xgvj-75pc-8x47/GHSA-xgvj-75pc-8x47.json @@ -7,12 +7,8 @@ "CVE-2021-21495" ], "details": "MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhw5-6m93-pmpj/GHSA-xhw5-6m93-pmpj.json b/advisories/unreviewed/2022/05/GHSA-xhw5-6m93-pmpj/GHSA-xhw5-6m93-pmpj.json index d85ab1685a8..47afdda3eab 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhw5-6m93-pmpj/GHSA-xhw5-6m93-pmpj.json +++ b/advisories/unreviewed/2022/05/GHSA-xhw5-6m93-pmpj/GHSA-xhw5-6m93-pmpj.json @@ -7,12 +7,8 @@ "CVE-2020-35947" ], "details": "An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj55-jcm5-7pgm/GHSA-xj55-jcm5-7pgm.json b/advisories/unreviewed/2022/05/GHSA-xj55-jcm5-7pgm/GHSA-xj55-jcm5-7pgm.json index ba9fa78644d..a5d119434a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj55-jcm5-7pgm/GHSA-xj55-jcm5-7pgm.json +++ b/advisories/unreviewed/2022/05/GHSA-xj55-jcm5-7pgm/GHSA-xj55-jcm5-7pgm.json @@ -7,12 +7,8 @@ "CVE-2020-35582" ], "details": "A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php request with the post_title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjw8-23hc-2wq2/GHSA-xjw8-23hc-2wq2.json b/advisories/unreviewed/2022/05/GHSA-xjw8-23hc-2wq2/GHSA-xjw8-23hc-2wq2.json index c22af1b2962..13da1fb5e7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjw8-23hc-2wq2/GHSA-xjw8-23hc-2wq2.json +++ b/advisories/unreviewed/2022/05/GHSA-xjw8-23hc-2wq2/GHSA-xjw8-23hc-2wq2.json @@ -7,12 +7,8 @@ "CVE-2021-1205" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjxp-x9rc-crcf/GHSA-xjxp-x9rc-crcf.json b/advisories/unreviewed/2022/05/GHSA-xjxp-x9rc-crcf/GHSA-xjxp-x9rc-crcf.json index 5fa828d0fb6..dd6be3c0230 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjxp-x9rc-crcf/GHSA-xjxp-x9rc-crcf.json +++ b/advisories/unreviewed/2022/05/GHSA-xjxp-x9rc-crcf/GHSA-xjxp-x9rc-crcf.json @@ -7,12 +7,8 @@ "CVE-2020-29494" ], "details": "Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the arbitrary files stored on the server filesystem, causing deletion of arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmm8-v82g-957c/GHSA-xmm8-v82g-957c.json b/advisories/unreviewed/2022/05/GHSA-xmm8-v82g-957c/GHSA-xmm8-v82g-957c.json index c9ee036973d..c4af99b0265 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmm8-v82g-957c/GHSA-xmm8-v82g-957c.json +++ b/advisories/unreviewed/2022/05/GHSA-xmm8-v82g-957c/GHSA-xmm8-v82g-957c.json @@ -7,12 +7,8 @@ "CVE-2020-29493" ], "details": "DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp87-7m9f-4cr9/GHSA-xp87-7m9f-4cr9.json b/advisories/unreviewed/2022/05/GHSA-xp87-7m9f-4cr9/GHSA-xp87-7m9f-4cr9.json index fd1d8c3d2eb..7c0d57b5c53 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp87-7m9f-4cr9/GHSA-xp87-7m9f-4cr9.json +++ b/advisories/unreviewed/2022/05/GHSA-xp87-7m9f-4cr9/GHSA-xp87-7m9f-4cr9.json @@ -7,12 +7,8 @@ "CVE-2020-28374" ], "details": "In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp9j-q8vg-2xqp/GHSA-xp9j-q8vg-2xqp.json b/advisories/unreviewed/2022/05/GHSA-xp9j-q8vg-2xqp/GHSA-xp9j-q8vg-2xqp.json index b081e7d0320..165f694b572 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp9j-q8vg-2xqp/GHSA-xp9j-q8vg-2xqp.json +++ b/advisories/unreviewed/2022/05/GHSA-xp9j-q8vg-2xqp/GHSA-xp9j-q8vg-2xqp.json @@ -7,12 +7,8 @@ "CVE-2021-1271" ], "details": "\n A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.\n The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpw5-q9mj-2rfm/GHSA-xpw5-q9mj-2rfm.json b/advisories/unreviewed/2022/05/GHSA-xpw5-q9mj-2rfm/GHSA-xpw5-q9mj-2rfm.json index eb1f4570f9f..14dd9442e49 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpw5-q9mj-2rfm/GHSA-xpw5-q9mj-2rfm.json +++ b/advisories/unreviewed/2022/05/GHSA-xpw5-q9mj-2rfm/GHSA-xpw5-q9mj-2rfm.json @@ -7,12 +7,8 @@ "CVE-2018-11005" ], "details": "A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq8c-cw49-4mwf/GHSA-xq8c-cw49-4mwf.json b/advisories/unreviewed/2022/05/GHSA-xq8c-cw49-4mwf/GHSA-xq8c-cw49-4mwf.json index 56684a3f56a..c851dd521d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq8c-cw49-4mwf/GHSA-xq8c-cw49-4mwf.json +++ b/advisories/unreviewed/2022/05/GHSA-xq8c-cw49-4mwf/GHSA-xq8c-cw49-4mwf.json @@ -7,12 +7,8 @@ "CVE-2020-17500" ], "details": "Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq8j-8h49-q9q4/GHSA-xq8j-8h49-q9q4.json b/advisories/unreviewed/2022/05/GHSA-xq8j-8h49-q9q4/GHSA-xq8j-8h49-q9q4.json index 01296928f84..625ea640cd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq8j-8h49-q9q4/GHSA-xq8j-8h49-q9q4.json +++ b/advisories/unreviewed/2022/05/GHSA-xq8j-8h49-q9q4/GHSA-xq8j-8h49-q9q4.json @@ -7,12 +7,8 @@ "CVE-2020-35931" ], "details": "An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv56-v69h-6cw4/GHSA-xv56-v69h-6cw4.json b/advisories/unreviewed/2022/05/GHSA-xv56-v69h-6cw4/GHSA-xv56-v69h-6cw4.json index 684427cb067..2c66040e408 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv56-v69h-6cw4/GHSA-xv56-v69h-6cw4.json +++ b/advisories/unreviewed/2022/05/GHSA-xv56-v69h-6cw4/GHSA-xv56-v69h-6cw4.json @@ -7,12 +7,8 @@ "CVE-2020-35483" ], "details": "AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw74-fx28-hrj8/GHSA-xw74-fx28-hrj8.json b/advisories/unreviewed/2022/05/GHSA-xw74-fx28-hrj8/GHSA-xw74-fx28-hrj8.json index efca77be2ac..2e2ec1c9366 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw74-fx28-hrj8/GHSA-xw74-fx28-hrj8.json +++ b/advisories/unreviewed/2022/05/GHSA-xw74-fx28-hrj8/GHSA-xw74-fx28-hrj8.json @@ -7,12 +7,8 @@ "CVE-2020-29491" ], "details": "Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwfp-hh8f-q7xp/GHSA-xwfp-hh8f-q7xp.json b/advisories/unreviewed/2022/05/GHSA-xwfp-hh8f-q7xp/GHSA-xwfp-hh8f-q7xp.json index 68894905ea9..5ea4bb49174 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwfp-hh8f-q7xp/GHSA-xwfp-hh8f-q7xp.json +++ b/advisories/unreviewed/2022/05/GHSA-xwfp-hh8f-q7xp/GHSA-xwfp-hh8f-q7xp.json @@ -7,12 +7,8 @@ "CVE-2020-35818" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwhw-2q44-qw48/GHSA-xwhw-2q44-qw48.json b/advisories/unreviewed/2022/05/GHSA-xwhw-2q44-qw48/GHSA-xwhw-2q44-qw48.json index 5810bd9dbaf..093a9cdf54f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwhw-2q44-qw48/GHSA-xwhw-2q44-qw48.json +++ b/advisories/unreviewed/2022/05/GHSA-xwhw-2q44-qw48/GHSA-xwhw-2q44-qw48.json @@ -7,12 +7,8 @@ "CVE-2021-23927" ], "details": "OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwmw-hpfw-6rrp/GHSA-xwmw-hpfw-6rrp.json b/advisories/unreviewed/2022/05/GHSA-xwmw-hpfw-6rrp/GHSA-xwmw-hpfw-6rrp.json index 60ae5f224e0..9c5b2189873 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwmw-hpfw-6rrp/GHSA-xwmw-hpfw-6rrp.json +++ b/advisories/unreviewed/2022/05/GHSA-xwmw-hpfw-6rrp/GHSA-xwmw-hpfw-6rrp.json @@ -7,12 +7,8 @@ "CVE-2020-36167" ], "details": "An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from the Installation folder. This library in turn attempts to load the /usr/local/ssl/openssl.cnf configuration file, which may not exist. On Windows systems, this path could translate to :\\usr\\local\\ssl\\openssl.cnf. A low privileged user can create a :\\usr\\local\\ssl\\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. If the system is also an Active Directory domain controller, then this can affect the entire domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-73jx-2vf6-7ffj/GHSA-73jx-2vf6-7ffj.json b/advisories/unreviewed/2022/08/GHSA-73jx-2vf6-7ffj/GHSA-73jx-2vf6-7ffj.json index 495bb6aca1a..dddbe4b1751 100644 --- a/advisories/unreviewed/2022/08/GHSA-73jx-2vf6-7ffj/GHSA-73jx-2vf6-7ffj.json +++ b/advisories/unreviewed/2022/08/GHSA-73jx-2vf6-7ffj/GHSA-73jx-2vf6-7ffj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-7jc3-54w2-9q65/GHSA-7jc3-54w2-9q65.json b/advisories/unreviewed/2022/08/GHSA-7jc3-54w2-9q65/GHSA-7jc3-54w2-9q65.json index 9c12e2445b8..95a3da41d05 100644 --- a/advisories/unreviewed/2022/08/GHSA-7jc3-54w2-9q65/GHSA-7jc3-54w2-9q65.json +++ b/advisories/unreviewed/2022/08/GHSA-7jc3-54w2-9q65/GHSA-7jc3-54w2-9q65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-963w-7frp-mf37/GHSA-963w-7frp-mf37.json b/advisories/unreviewed/2022/08/GHSA-963w-7frp-mf37/GHSA-963w-7frp-mf37.json index 61d3e5365a6..1cfb37f521d 100644 --- a/advisories/unreviewed/2022/08/GHSA-963w-7frp-mf37/GHSA-963w-7frp-mf37.json +++ b/advisories/unreviewed/2022/08/GHSA-963w-7frp-mf37/GHSA-963w-7frp-mf37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-gq7w-5v6q-h6vc/GHSA-gq7w-5v6q-h6vc.json b/advisories/unreviewed/2022/08/GHSA-gq7w-5v6q-h6vc/GHSA-gq7w-5v6q-h6vc.json index df2d76ad440..caa95b5209c 100644 --- a/advisories/unreviewed/2022/08/GHSA-gq7w-5v6q-h6vc/GHSA-gq7w-5v6q-h6vc.json +++ b/advisories/unreviewed/2022/08/GHSA-gq7w-5v6q-h6vc/GHSA-gq7w-5v6q-h6vc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-jgmm-xwf9-46q6/GHSA-jgmm-xwf9-46q6.json b/advisories/unreviewed/2022/08/GHSA-jgmm-xwf9-46q6/GHSA-jgmm-xwf9-46q6.json index 3ee6abfb891..0a3a82f7649 100644 --- a/advisories/unreviewed/2022/08/GHSA-jgmm-xwf9-46q6/GHSA-jgmm-xwf9-46q6.json +++ b/advisories/unreviewed/2022/08/GHSA-jgmm-xwf9-46q6/GHSA-jgmm-xwf9-46q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-p7ww-6g8j-7w56/GHSA-p7ww-6g8j-7w56.json b/advisories/unreviewed/2022/08/GHSA-p7ww-6g8j-7w56/GHSA-p7ww-6g8j-7w56.json index 10c4aa19bdd..e51d9b70bcb 100644 --- a/advisories/unreviewed/2022/08/GHSA-p7ww-6g8j-7w56/GHSA-p7ww-6g8j-7w56.json +++ b/advisories/unreviewed/2022/08/GHSA-p7ww-6g8j-7w56/GHSA-p7ww-6g8j-7w56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-pjg2-878f-mvhc/GHSA-pjg2-878f-mvhc.json b/advisories/unreviewed/2022/08/GHSA-pjg2-878f-mvhc/GHSA-pjg2-878f-mvhc.json index 0251d424249..8de6e2f648c 100644 --- a/advisories/unreviewed/2022/08/GHSA-pjg2-878f-mvhc/GHSA-pjg2-878f-mvhc.json +++ b/advisories/unreviewed/2022/08/GHSA-pjg2-878f-mvhc/GHSA-pjg2-878f-mvhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-pvc4-x6fm-w5wg/GHSA-pvc4-x6fm-w5wg.json b/advisories/unreviewed/2022/08/GHSA-pvc4-x6fm-w5wg/GHSA-pvc4-x6fm-w5wg.json index 731face9944..c7a52b217dd 100644 --- a/advisories/unreviewed/2022/08/GHSA-pvc4-x6fm-w5wg/GHSA-pvc4-x6fm-w5wg.json +++ b/advisories/unreviewed/2022/08/GHSA-pvc4-x6fm-w5wg/GHSA-pvc4-x6fm-w5wg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-rv2q-xwg7-w99w/GHSA-rv2q-xwg7-w99w.json b/advisories/unreviewed/2022/08/GHSA-rv2q-xwg7-w99w/GHSA-rv2q-xwg7-w99w.json index d6e0f894908..8cfc324f40c 100644 --- a/advisories/unreviewed/2022/08/GHSA-rv2q-xwg7-w99w/GHSA-rv2q-xwg7-w99w.json +++ b/advisories/unreviewed/2022/08/GHSA-rv2q-xwg7-w99w/GHSA-rv2q-xwg7-w99w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-rw64-76vh-4phc/GHSA-rw64-76vh-4phc.json b/advisories/unreviewed/2022/08/GHSA-rw64-76vh-4phc/GHSA-rw64-76vh-4phc.json index 7bdd15812a4..e60dccc7f46 100644 --- a/advisories/unreviewed/2022/08/GHSA-rw64-76vh-4phc/GHSA-rw64-76vh-4phc.json +++ b/advisories/unreviewed/2022/08/GHSA-rw64-76vh-4phc/GHSA-rw64-76vh-4phc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-qqx5-8972-3h6c/GHSA-qqx5-8972-3h6c.json b/advisories/unreviewed/2022/10/GHSA-qqx5-8972-3h6c/GHSA-qqx5-8972-3h6c.json index 95adec2a096..d860dd63f49 100644 --- a/advisories/unreviewed/2022/10/GHSA-qqx5-8972-3h6c/GHSA-qqx5-8972-3h6c.json +++ b/advisories/unreviewed/2022/10/GHSA-qqx5-8972-3h6c/GHSA-qqx5-8972-3h6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hcqv-28c5-78g8/GHSA-hcqv-28c5-78g8.json b/advisories/unreviewed/2023/01/GHSA-hcqv-28c5-78g8/GHSA-hcqv-28c5-78g8.json index 5581cfce68f..0e98afb61c4 100644 --- a/advisories/unreviewed/2023/01/GHSA-hcqv-28c5-78g8/GHSA-hcqv-28c5-78g8.json +++ b/advisories/unreviewed/2023/01/GHSA-hcqv-28c5-78g8/GHSA-hcqv-28c5-78g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-89mw-w342-mqrr/GHSA-89mw-w342-mqrr.json b/advisories/unreviewed/2023/02/GHSA-89mw-w342-mqrr/GHSA-89mw-w342-mqrr.json index 4a93d6dce5d..2e0f3e1113d 100644 --- a/advisories/unreviewed/2023/02/GHSA-89mw-w342-mqrr/GHSA-89mw-w342-mqrr.json +++ b/advisories/unreviewed/2023/02/GHSA-89mw-w342-mqrr/GHSA-89mw-w342-mqrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json b/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json index d04b6df39e3..f6e0c5845ee 100644 --- a/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json +++ b/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-xc82-5m89-g4jv/GHSA-xc82-5m89-g4jv.json b/advisories/unreviewed/2023/08/GHSA-xc82-5m89-g4jv/GHSA-xc82-5m89-g4jv.json index 5f103deb003..bc09d9a6287 100644 --- a/advisories/unreviewed/2023/08/GHSA-xc82-5m89-g4jv/GHSA-xc82-5m89-g4jv.json +++ b/advisories/unreviewed/2023/08/GHSA-xc82-5m89-g4jv/GHSA-xc82-5m89-g4jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-22fc-mghg-jrwm/GHSA-22fc-mghg-jrwm.json b/advisories/unreviewed/2024/04/GHSA-22fc-mghg-jrwm/GHSA-22fc-mghg-jrwm.json index fde69ebcc5e..14b0e707325 100644 --- a/advisories/unreviewed/2024/04/GHSA-22fc-mghg-jrwm/GHSA-22fc-mghg-jrwm.json +++ b/advisories/unreviewed/2024/04/GHSA-22fc-mghg-jrwm/GHSA-22fc-mghg-jrwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-52h9-53cv-vm4j/GHSA-52h9-53cv-vm4j.json b/advisories/unreviewed/2024/04/GHSA-52h9-53cv-vm4j/GHSA-52h9-53cv-vm4j.json index 965b5f0b9a0..15d4ca2b90c 100644 --- a/advisories/unreviewed/2024/04/GHSA-52h9-53cv-vm4j/GHSA-52h9-53cv-vm4j.json +++ b/advisories/unreviewed/2024/04/GHSA-52h9-53cv-vm4j/GHSA-52h9-53cv-vm4j.json @@ -7,12 +7,8 @@ "CVE-2023-52646" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naio: fix mremap after fork null-deref\n\nCommit e4a0d3e720e7 (\"aio: Make it possible to remap aio ring\") introduced\na null-deref if mremap is called on an old aio mapping after fork as\nmm->ioctx_table will be set to NULL.\n\n[jmoyer@redhat.com: fix 80 column issue]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5m8f-c344-mvcv/GHSA-5m8f-c344-mvcv.json b/advisories/unreviewed/2024/04/GHSA-5m8f-c344-mvcv/GHSA-5m8f-c344-mvcv.json index 0b0383d25b5..de62f6efc1c 100644 --- a/advisories/unreviewed/2024/04/GHSA-5m8f-c344-mvcv/GHSA-5m8f-c344-mvcv.json +++ b/advisories/unreviewed/2024/04/GHSA-5m8f-c344-mvcv/GHSA-5m8f-c344-mvcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-693f-8j8c-5qr2/GHSA-693f-8j8c-5qr2.json b/advisories/unreviewed/2024/04/GHSA-693f-8j8c-5qr2/GHSA-693f-8j8c-5qr2.json index 6e91fe75e47..8d5dfdd40a6 100644 --- a/advisories/unreviewed/2024/04/GHSA-693f-8j8c-5qr2/GHSA-693f-8j8c-5qr2.json +++ b/advisories/unreviewed/2024/04/GHSA-693f-8j8c-5qr2/GHSA-693f-8j8c-5qr2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json b/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json index 5b6b6a50298..f6dfc09f928 100644 --- a/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json +++ b/advisories/unreviewed/2024/04/GHSA-6pwq-2vrc-6rr6/GHSA-6pwq-2vrc-6rr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-739r-wh9x-q588/GHSA-739r-wh9x-q588.json b/advisories/unreviewed/2024/04/GHSA-739r-wh9x-q588/GHSA-739r-wh9x-q588.json index ee34d6caff1..72f5b3fe3c8 100644 --- a/advisories/unreviewed/2024/04/GHSA-739r-wh9x-q588/GHSA-739r-wh9x-q588.json +++ b/advisories/unreviewed/2024/04/GHSA-739r-wh9x-q588/GHSA-739r-wh9x-q588.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7mfg-57xp-v6gq/GHSA-7mfg-57xp-v6gq.json b/advisories/unreviewed/2024/04/GHSA-7mfg-57xp-v6gq/GHSA-7mfg-57xp-v6gq.json index 961134ace92..c9059fda191 100644 --- a/advisories/unreviewed/2024/04/GHSA-7mfg-57xp-v6gq/GHSA-7mfg-57xp-v6gq.json +++ b/advisories/unreviewed/2024/04/GHSA-7mfg-57xp-v6gq/GHSA-7mfg-57xp-v6gq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7rww-65p2-qxxm/GHSA-7rww-65p2-qxxm.json b/advisories/unreviewed/2024/04/GHSA-7rww-65p2-qxxm/GHSA-7rww-65p2-qxxm.json index b6ef89ffba0..3f96d2323eb 100644 --- a/advisories/unreviewed/2024/04/GHSA-7rww-65p2-qxxm/GHSA-7rww-65p2-qxxm.json +++ b/advisories/unreviewed/2024/04/GHSA-7rww-65p2-qxxm/GHSA-7rww-65p2-qxxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7wmw-pgq8-x3w7/GHSA-7wmw-pgq8-x3w7.json b/advisories/unreviewed/2024/04/GHSA-7wmw-pgq8-x3w7/GHSA-7wmw-pgq8-x3w7.json index 420d970f56d..dc0c94e1b34 100644 --- a/advisories/unreviewed/2024/04/GHSA-7wmw-pgq8-x3w7/GHSA-7wmw-pgq8-x3w7.json +++ b/advisories/unreviewed/2024/04/GHSA-7wmw-pgq8-x3w7/GHSA-7wmw-pgq8-x3w7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json b/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json index 4a5b7f180b1..9d0a779d28a 100644 --- a/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json +++ b/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9wwg-9qf5-q4v9/GHSA-9wwg-9qf5-q4v9.json b/advisories/unreviewed/2024/04/GHSA-9wwg-9qf5-q4v9/GHSA-9wwg-9qf5-q4v9.json index 58ca2305747..5e7a6365d35 100644 --- a/advisories/unreviewed/2024/04/GHSA-9wwg-9qf5-q4v9/GHSA-9wwg-9qf5-q4v9.json +++ b/advisories/unreviewed/2024/04/GHSA-9wwg-9qf5-q4v9/GHSA-9wwg-9qf5-q4v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c4rr-rjwx-4xwh/GHSA-c4rr-rjwx-4xwh.json b/advisories/unreviewed/2024/04/GHSA-c4rr-rjwx-4xwh/GHSA-c4rr-rjwx-4xwh.json index 3f3b848acbc..a1f412e7910 100644 --- a/advisories/unreviewed/2024/04/GHSA-c4rr-rjwx-4xwh/GHSA-c4rr-rjwx-4xwh.json +++ b/advisories/unreviewed/2024/04/GHSA-c4rr-rjwx-4xwh/GHSA-c4rr-rjwx-4xwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-ccj7-29gf-j48r/GHSA-ccj7-29gf-j48r.json b/advisories/unreviewed/2024/04/GHSA-ccj7-29gf-j48r/GHSA-ccj7-29gf-j48r.json index 6f5a26f3b29..c47e275cccb 100644 --- a/advisories/unreviewed/2024/04/GHSA-ccj7-29gf-j48r/GHSA-ccj7-29gf-j48r.json +++ b/advisories/unreviewed/2024/04/GHSA-ccj7-29gf-j48r/GHSA-ccj7-29gf-j48r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cf8f-v932-h337/GHSA-cf8f-v932-h337.json b/advisories/unreviewed/2024/04/GHSA-cf8f-v932-h337/GHSA-cf8f-v932-h337.json index 5999c15d487..10d879463d4 100644 --- a/advisories/unreviewed/2024/04/GHSA-cf8f-v932-h337/GHSA-cf8f-v932-h337.json +++ b/advisories/unreviewed/2024/04/GHSA-cf8f-v932-h337/GHSA-cf8f-v932-h337.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cv8f-mv6h-rf73/GHSA-cv8f-mv6h-rf73.json b/advisories/unreviewed/2024/04/GHSA-cv8f-mv6h-rf73/GHSA-cv8f-mv6h-rf73.json index 68f4c6c1257..26536ae6032 100644 --- a/advisories/unreviewed/2024/04/GHSA-cv8f-mv6h-rf73/GHSA-cv8f-mv6h-rf73.json +++ b/advisories/unreviewed/2024/04/GHSA-cv8f-mv6h-rf73/GHSA-cv8f-mv6h-rf73.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cwvf-gq9g-7g6c/GHSA-cwvf-gq9g-7g6c.json b/advisories/unreviewed/2024/04/GHSA-cwvf-gq9g-7g6c/GHSA-cwvf-gq9g-7g6c.json index f366dbe179a..029b04aea18 100644 --- a/advisories/unreviewed/2024/04/GHSA-cwvf-gq9g-7g6c/GHSA-cwvf-gq9g-7g6c.json +++ b/advisories/unreviewed/2024/04/GHSA-cwvf-gq9g-7g6c/GHSA-cwvf-gq9g-7g6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-f56q-4m6g-3xjv/GHSA-f56q-4m6g-3xjv.json b/advisories/unreviewed/2024/04/GHSA-f56q-4m6g-3xjv/GHSA-f56q-4m6g-3xjv.json index f65e0b8b0d5..5067d970f56 100644 --- a/advisories/unreviewed/2024/04/GHSA-f56q-4m6g-3xjv/GHSA-f56q-4m6g-3xjv.json +++ b/advisories/unreviewed/2024/04/GHSA-f56q-4m6g-3xjv/GHSA-f56q-4m6g-3xjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-ffr6-cv7v-5fr9/GHSA-ffr6-cv7v-5fr9.json b/advisories/unreviewed/2024/04/GHSA-ffr6-cv7v-5fr9/GHSA-ffr6-cv7v-5fr9.json index 16096ed3335..1079651bcd9 100644 --- a/advisories/unreviewed/2024/04/GHSA-ffr6-cv7v-5fr9/GHSA-ffr6-cv7v-5fr9.json +++ b/advisories/unreviewed/2024/04/GHSA-ffr6-cv7v-5fr9/GHSA-ffr6-cv7v-5fr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-h9fj-vwxm-9wf4/GHSA-h9fj-vwxm-9wf4.json b/advisories/unreviewed/2024/04/GHSA-h9fj-vwxm-9wf4/GHSA-h9fj-vwxm-9wf4.json index 48a4c49a295..469a3e8a774 100644 --- a/advisories/unreviewed/2024/04/GHSA-h9fj-vwxm-9wf4/GHSA-h9fj-vwxm-9wf4.json +++ b/advisories/unreviewed/2024/04/GHSA-h9fj-vwxm-9wf4/GHSA-h9fj-vwxm-9wf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hf38-mh8v-7vgj/GHSA-hf38-mh8v-7vgj.json b/advisories/unreviewed/2024/04/GHSA-hf38-mh8v-7vgj/GHSA-hf38-mh8v-7vgj.json index b90b56b0448..117e1de9d54 100644 --- a/advisories/unreviewed/2024/04/GHSA-hf38-mh8v-7vgj/GHSA-hf38-mh8v-7vgj.json +++ b/advisories/unreviewed/2024/04/GHSA-hf38-mh8v-7vgj/GHSA-hf38-mh8v-7vgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hvqv-h887-g62m/GHSA-hvqv-h887-g62m.json b/advisories/unreviewed/2024/04/GHSA-hvqv-h887-g62m/GHSA-hvqv-h887-g62m.json index 10e792c00c5..d798279e9c4 100644 --- a/advisories/unreviewed/2024/04/GHSA-hvqv-h887-g62m/GHSA-hvqv-h887-g62m.json +++ b/advisories/unreviewed/2024/04/GHSA-hvqv-h887-g62m/GHSA-hvqv-h887-g62m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hw63-cg2c-rh7g/GHSA-hw63-cg2c-rh7g.json b/advisories/unreviewed/2024/04/GHSA-hw63-cg2c-rh7g/GHSA-hw63-cg2c-rh7g.json index a7caa7f1e90..e821cf5a7fe 100644 --- a/advisories/unreviewed/2024/04/GHSA-hw63-cg2c-rh7g/GHSA-hw63-cg2c-rh7g.json +++ b/advisories/unreviewed/2024/04/GHSA-hw63-cg2c-rh7g/GHSA-hw63-cg2c-rh7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-j2pj-rx5h-324m/GHSA-j2pj-rx5h-324m.json b/advisories/unreviewed/2024/04/GHSA-j2pj-rx5h-324m/GHSA-j2pj-rx5h-324m.json index a61ce0411b4..77cef7dbb13 100644 --- a/advisories/unreviewed/2024/04/GHSA-j2pj-rx5h-324m/GHSA-j2pj-rx5h-324m.json +++ b/advisories/unreviewed/2024/04/GHSA-j2pj-rx5h-324m/GHSA-j2pj-rx5h-324m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-j64h-79xv-rx9g/GHSA-j64h-79xv-rx9g.json b/advisories/unreviewed/2024/04/GHSA-j64h-79xv-rx9g/GHSA-j64h-79xv-rx9g.json index babfe116f34..d6544b86d56 100644 --- a/advisories/unreviewed/2024/04/GHSA-j64h-79xv-rx9g/GHSA-j64h-79xv-rx9g.json +++ b/advisories/unreviewed/2024/04/GHSA-j64h-79xv-rx9g/GHSA-j64h-79xv-rx9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jg9h-x22w-cq68/GHSA-jg9h-x22w-cq68.json b/advisories/unreviewed/2024/04/GHSA-jg9h-x22w-cq68/GHSA-jg9h-x22w-cq68.json index 3e02a0e0219..e86bb7781ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-jg9h-x22w-cq68/GHSA-jg9h-x22w-cq68.json +++ b/advisories/unreviewed/2024/04/GHSA-jg9h-x22w-cq68/GHSA-jg9h-x22w-cq68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json b/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json index dc4410f757f..38f3ab69736 100644 --- a/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json +++ b/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json @@ -7,12 +7,8 @@ "CVE-2024-3075" ], "details": "The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mcqc-h58c-24vj/GHSA-mcqc-h58c-24vj.json b/advisories/unreviewed/2024/04/GHSA-mcqc-h58c-24vj/GHSA-mcqc-h58c-24vj.json index 9ab889a2845..a086cf9d4ad 100644 --- a/advisories/unreviewed/2024/04/GHSA-mcqc-h58c-24vj/GHSA-mcqc-h58c-24vj.json +++ b/advisories/unreviewed/2024/04/GHSA-mcqc-h58c-24vj/GHSA-mcqc-h58c-24vj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mx9v-h7x6-c37p/GHSA-mx9v-h7x6-c37p.json b/advisories/unreviewed/2024/04/GHSA-mx9v-h7x6-c37p/GHSA-mx9v-h7x6-c37p.json index 4baaf9138f7..79aef1f7a1b 100644 --- a/advisories/unreviewed/2024/04/GHSA-mx9v-h7x6-c37p/GHSA-mx9v-h7x6-c37p.json +++ b/advisories/unreviewed/2024/04/GHSA-mx9v-h7x6-c37p/GHSA-mx9v-h7x6-c37p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p7j9-7qwr-c4hr/GHSA-p7j9-7qwr-c4hr.json b/advisories/unreviewed/2024/04/GHSA-p7j9-7qwr-c4hr/GHSA-p7j9-7qwr-c4hr.json index b6732d3189e..94d641561d4 100644 --- a/advisories/unreviewed/2024/04/GHSA-p7j9-7qwr-c4hr/GHSA-p7j9-7qwr-c4hr.json +++ b/advisories/unreviewed/2024/04/GHSA-p7j9-7qwr-c4hr/GHSA-p7j9-7qwr-c4hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json b/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json index c9e369f332e..4a4af135878 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json +++ b/advisories/unreviewed/2024/04/GHSA-pfc3-5g8j-v982/GHSA-pfc3-5g8j-v982.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pgj3-fh25-fqr8/GHSA-pgj3-fh25-fqr8.json b/advisories/unreviewed/2024/04/GHSA-pgj3-fh25-fqr8/GHSA-pgj3-fh25-fqr8.json index 98032743115..89ba4ec93af 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgj3-fh25-fqr8/GHSA-pgj3-fh25-fqr8.json +++ b/advisories/unreviewed/2024/04/GHSA-pgj3-fh25-fqr8/GHSA-pgj3-fh25-fqr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pp78-fggv-r899/GHSA-pp78-fggv-r899.json b/advisories/unreviewed/2024/04/GHSA-pp78-fggv-r899/GHSA-pp78-fggv-r899.json index 0a9dd09b538..0c12bc5a019 100644 --- a/advisories/unreviewed/2024/04/GHSA-pp78-fggv-r899/GHSA-pp78-fggv-r899.json +++ b/advisories/unreviewed/2024/04/GHSA-pp78-fggv-r899/GHSA-pp78-fggv-r899.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pvgx-c7xr-3j3w/GHSA-pvgx-c7xr-3j3w.json b/advisories/unreviewed/2024/04/GHSA-pvgx-c7xr-3j3w/GHSA-pvgx-c7xr-3j3w.json index 4ceed9d160c..89b4711faf7 100644 --- a/advisories/unreviewed/2024/04/GHSA-pvgx-c7xr-3j3w/GHSA-pvgx-c7xr-3j3w.json +++ b/advisories/unreviewed/2024/04/GHSA-pvgx-c7xr-3j3w/GHSA-pvgx-c7xr-3j3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pvq7-259f-j6f4/GHSA-pvq7-259f-j6f4.json b/advisories/unreviewed/2024/04/GHSA-pvq7-259f-j6f4/GHSA-pvq7-259f-j6f4.json index 256006ec67e..75d6fa4b517 100644 --- a/advisories/unreviewed/2024/04/GHSA-pvq7-259f-j6f4/GHSA-pvq7-259f-j6f4.json +++ b/advisories/unreviewed/2024/04/GHSA-pvq7-259f-j6f4/GHSA-pvq7-259f-j6f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json b/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json index 8be5a4ef4aa..639a74e8ee7 100644 --- a/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json +++ b/advisories/unreviewed/2024/04/GHSA-q4c6-w389-xqq6/GHSA-q4c6-w389-xqq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json b/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json index 5c868cd50c5..9f48d541da0 100644 --- a/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json +++ b/advisories/unreviewed/2024/04/GHSA-q4p9-39fv-h479/GHSA-q4p9-39fv-h479.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qr2x-466f-55hc/GHSA-qr2x-466f-55hc.json b/advisories/unreviewed/2024/04/GHSA-qr2x-466f-55hc/GHSA-qr2x-466f-55hc.json index f4e87b61722..531ac06aadb 100644 --- a/advisories/unreviewed/2024/04/GHSA-qr2x-466f-55hc/GHSA-qr2x-466f-55hc.json +++ b/advisories/unreviewed/2024/04/GHSA-qr2x-466f-55hc/GHSA-qr2x-466f-55hc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json b/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json index 37d5eeea366..71e9071c7a9 100644 --- a/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json +++ b/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rpw4-j7hf-75q9/GHSA-rpw4-j7hf-75q9.json b/advisories/unreviewed/2024/04/GHSA-rpw4-j7hf-75q9/GHSA-rpw4-j7hf-75q9.json index 99e003fb642..746d8bf47bc 100644 --- a/advisories/unreviewed/2024/04/GHSA-rpw4-j7hf-75q9/GHSA-rpw4-j7hf-75q9.json +++ b/advisories/unreviewed/2024/04/GHSA-rpw4-j7hf-75q9/GHSA-rpw4-j7hf-75q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rqwm-368v-fp53/GHSA-rqwm-368v-fp53.json b/advisories/unreviewed/2024/04/GHSA-rqwm-368v-fp53/GHSA-rqwm-368v-fp53.json index decef4bc7f6..81d8df334bc 100644 --- a/advisories/unreviewed/2024/04/GHSA-rqwm-368v-fp53/GHSA-rqwm-368v-fp53.json +++ b/advisories/unreviewed/2024/04/GHSA-rqwm-368v-fp53/GHSA-rqwm-368v-fp53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-v6f7-cqmv-v5gc/GHSA-v6f7-cqmv-v5gc.json b/advisories/unreviewed/2024/04/GHSA-v6f7-cqmv-v5gc/GHSA-v6f7-cqmv-v5gc.json index 224ce2575d3..59b68109304 100644 --- a/advisories/unreviewed/2024/04/GHSA-v6f7-cqmv-v5gc/GHSA-v6f7-cqmv-v5gc.json +++ b/advisories/unreviewed/2024/04/GHSA-v6f7-cqmv-v5gc/GHSA-v6f7-cqmv-v5gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-v9pm-5x6v-2p6p/GHSA-v9pm-5x6v-2p6p.json b/advisories/unreviewed/2024/04/GHSA-v9pm-5x6v-2p6p/GHSA-v9pm-5x6v-2p6p.json index 7a9ec84dd94..119ab580b55 100644 --- a/advisories/unreviewed/2024/04/GHSA-v9pm-5x6v-2p6p/GHSA-v9pm-5x6v-2p6p.json +++ b/advisories/unreviewed/2024/04/GHSA-v9pm-5x6v-2p6p/GHSA-v9pm-5x6v-2p6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vp2r-x5x7-7629/GHSA-vp2r-x5x7-7629.json b/advisories/unreviewed/2024/04/GHSA-vp2r-x5x7-7629/GHSA-vp2r-x5x7-7629.json index 73b7252c102..232e49d8580 100644 --- a/advisories/unreviewed/2024/04/GHSA-vp2r-x5x7-7629/GHSA-vp2r-x5x7-7629.json +++ b/advisories/unreviewed/2024/04/GHSA-vp2r-x5x7-7629/GHSA-vp2r-x5x7-7629.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vqwp-3mpx-9rh4/GHSA-vqwp-3mpx-9rh4.json b/advisories/unreviewed/2024/04/GHSA-vqwp-3mpx-9rh4/GHSA-vqwp-3mpx-9rh4.json index 228ee49234f..e2be876b06c 100644 --- a/advisories/unreviewed/2024/04/GHSA-vqwp-3mpx-9rh4/GHSA-vqwp-3mpx-9rh4.json +++ b/advisories/unreviewed/2024/04/GHSA-vqwp-3mpx-9rh4/GHSA-vqwp-3mpx-9rh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x8vp-jrrr-mxv3/GHSA-x8vp-jrrr-mxv3.json b/advisories/unreviewed/2024/04/GHSA-x8vp-jrrr-mxv3/GHSA-x8vp-jrrr-mxv3.json index 0e81742917d..1230c996da4 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8vp-jrrr-mxv3/GHSA-x8vp-jrrr-mxv3.json +++ b/advisories/unreviewed/2024/04/GHSA-x8vp-jrrr-mxv3/GHSA-x8vp-jrrr-mxv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json b/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json index d6c2397c7dc..2bc9a755c45 100644 --- a/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json +++ b/advisories/unreviewed/2024/04/GHSA-xg8r-x2wg-m4m7/GHSA-xg8r-x2wg-m4m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xmh3-q6gr-4qrp/GHSA-xmh3-q6gr-4qrp.json b/advisories/unreviewed/2024/04/GHSA-xmh3-q6gr-4qrp/GHSA-xmh3-q6gr-4qrp.json index 5879a8a2e43..214259810a6 100644 --- a/advisories/unreviewed/2024/04/GHSA-xmh3-q6gr-4qrp/GHSA-xmh3-q6gr-4qrp.json +++ b/advisories/unreviewed/2024/04/GHSA-xmh3-q6gr-4qrp/GHSA-xmh3-q6gr-4qrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",