From 6b458cfe752df7fda5568112c332095120a61609 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 8 Dec 2024 05:07:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../09/GHSA-56r9-v65c-34jm/GHSA-56r9-v65c-34jm.json | 12 +++--------- .../09/GHSA-84qj-9qf2-q92r/GHSA-84qj-9qf2-q92r.json | 12 +++--------- .../05/GHSA-2hw2-h3mf-c2j9/GHSA-2hw2-h3mf-c2j9.json | 4 +--- .../05/GHSA-2jcw-r79x-4r5v/GHSA-2jcw-r79x-4r5v.json | 4 +--- .../05/GHSA-35pr-gqm6-r366/GHSA-35pr-gqm6-r366.json | 4 +--- .../05/GHSA-36cm-vrqh-8p98/GHSA-36cm-vrqh-8p98.json | 8 ++------ .../05/GHSA-44xp-wj24-9xxj/GHSA-44xp-wj24-9xxj.json | 4 +--- .../05/GHSA-454r-4cjv-vc9h/GHSA-454r-4cjv-vc9h.json | 4 +--- .../05/GHSA-4ppg-2mx6-fqx9/GHSA-4ppg-2mx6-fqx9.json | 8 ++------ .../05/GHSA-622h-cjgg-5mx6/GHSA-622h-cjgg-5mx6.json | 8 ++------ .../05/GHSA-688p-pgj4-77hh/GHSA-688p-pgj4-77hh.json | 4 +--- .../05/GHSA-6r7x-6q98-qcqp/GHSA-6r7x-6q98-qcqp.json | 4 +--- .../05/GHSA-6wfj-2mw7-p5cg/GHSA-6wfj-2mw7-p5cg.json | 4 +--- .../05/GHSA-79jf-ccm8-43w7/GHSA-79jf-ccm8-43w7.json | 4 +--- .../05/GHSA-9fmw-m4qx-6cq8/GHSA-9fmw-m4qx-6cq8.json | 4 +--- .../05/GHSA-c87j-9rrq-h3j8/GHSA-c87j-9rrq-h3j8.json | 4 +--- .../05/GHSA-cm4r-58pj-h2ph/GHSA-cm4r-58pj-h2ph.json | 4 +--- .../05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json | 4 +--- .../05/GHSA-fp4h-j22r-vwcv/GHSA-fp4h-j22r-vwcv.json | 8 ++------ .../05/GHSA-fqrg-vmvj-jv3x/GHSA-fqrg-vmvj-jv3x.json | 4 +--- .../05/GHSA-g892-9h8m-r69r/GHSA-g892-9h8m-r69r.json | 4 +--- .../05/GHSA-gphj-63h8-r9vq/GHSA-gphj-63h8-r9vq.json | 4 +--- .../05/GHSA-h798-h7ff-93xv/GHSA-h798-h7ff-93xv.json | 4 +--- .../05/GHSA-hhq7-jf2p-hw9c/GHSA-hhq7-jf2p-hw9c.json | 4 +--- .../05/GHSA-mfmj-gwg3-vhw7/GHSA-mfmj-gwg3-vhw7.json | 8 ++------ .../05/GHSA-mm9q-3847-m48x/GHSA-mm9q-3847-m48x.json | 4 +--- .../05/GHSA-pvr5-84gr-g985/GHSA-pvr5-84gr-g985.json | 4 +--- .../05/GHSA-rpc6-h455-3rx5/GHSA-rpc6-h455-3rx5.json | 4 +--- .../05/GHSA-v3wp-35g3-m9mm/GHSA-v3wp-35g3-m9mm.json | 8 ++------ .../05/GHSA-x8xr-rm9r-7mvf/GHSA-x8xr-rm9r-7mvf.json | 4 +--- .../07/GHSA-f2gr-7299-487h/GHSA-f2gr-7299-487h.json | 8 ++------ .../01/GHSA-j94p-hv25-rm5g/GHSA-j94p-hv25-rm5g.json | 4 +--- .../01/GHSA-r3gm-jwf4-xgv2/GHSA-r3gm-jwf4-xgv2.json | 4 +--- .../02/GHSA-mc8h-8q98-g5hr/GHSA-mc8h-8q98-g5hr.json | 8 ++------ .../07/GHSA-h9wq-xcqx-mqxm/GHSA-h9wq-xcqx-mqxm.json | 12 +++--------- .../06/GHSA-rvj4-q8q5-8grf/GHSA-rvj4-q8q5-8grf.json | 4 +--- .../11/GHSA-4xx3-xg55-3wr5/GHSA-4xx3-xg55-3wr5.json | 4 +--- .../11/GHSA-xrj7-4gfh-q9h7/GHSA-xrj7-4gfh-q9h7.json | 4 +--- .../02/GHSA-8p3j-58qw-jhp4/GHSA-8p3j-58qw-jhp4.json | 8 ++------ .../03/GHSA-4qpc-hphm-xpmc/GHSA-4qpc-hphm-xpmc.json | 4 +--- .../03/GHSA-4rqg-f28v-3gvx/GHSA-4rqg-f28v-3gvx.json | 4 +--- .../03/GHSA-5h3c-wjf7-3r26/GHSA-5h3c-wjf7-3r26.json | 4 +--- .../03/GHSA-g9pm-vppm-577q/GHSA-g9pm-vppm-577q.json | 4 +--- .../03/GHSA-h7v8-mphj-jp2g/GHSA-h7v8-mphj-jp2g.json | 4 +--- .../03/GHSA-v2q7-x3pw-jc98/GHSA-v2q7-x3pw-jc98.json | 4 +--- .../04/GHSA-349g-pr27-x5hf/GHSA-349g-pr27-x5hf.json | 8 ++------ .../04/GHSA-cg66-grw3-w6j2/GHSA-cg66-grw3-w6j2.json | 8 ++------ .../04/GHSA-fwc5-m56h-x5g6/GHSA-fwc5-m56h-x5g6.json | 8 ++------ .../04/GHSA-q76p-969x-phhf/GHSA-q76p-969x-phhf.json | 4 +--- .../04/GHSA-xj93-8hff-x47c/GHSA-xj93-8hff-x47c.json | 4 +--- .../05/GHSA-23hf-jhww-867g/GHSA-23hf-jhww-867g.json | 8 ++------ .../05/GHSA-23jc-mx6c-hh36/GHSA-23jc-mx6c-hh36.json | 8 ++------ .../05/GHSA-242r-53mf-qx5c/GHSA-242r-53mf-qx5c.json | 12 +++--------- .../05/GHSA-25vm-4wwp-79cp/GHSA-25vm-4wwp-79cp.json | 12 +++--------- .../05/GHSA-26j8-6884-fcqw/GHSA-26j8-6884-fcqw.json | 4 +--- .../05/GHSA-273c-3m7m-qmj2/GHSA-273c-3m7m-qmj2.json | 12 +++--------- .../05/GHSA-276g-j28x-jvcr/GHSA-276g-j28x-jvcr.json | 12 +++--------- .../05/GHSA-276p-837g-mvv4/GHSA-276p-837g-mvv4.json | 12 +++--------- .../05/GHSA-2874-9wc2-224f/GHSA-2874-9wc2-224f.json | 4 +--- .../05/GHSA-2c46-3v56-p8mq/GHSA-2c46-3v56-p8mq.json | 8 ++------ .../05/GHSA-2cx8-vq8f-mwm5/GHSA-2cx8-vq8f-mwm5.json | 8 ++------ .../05/GHSA-2f2x-36r8-vr6x/GHSA-2f2x-36r8-vr6x.json | 4 +--- .../05/GHSA-2f9c-jj4r-fr8x/GHSA-2f9c-jj4r-fr8x.json | 4 +--- .../05/GHSA-2fg3-h938-jr6f/GHSA-2fg3-h938-jr6f.json | 8 ++------ .../05/GHSA-2fh8-hvqx-49wh/GHSA-2fh8-hvqx-49wh.json | 8 ++------ .../05/GHSA-2g47-r557-h83r/GHSA-2g47-r557-h83r.json | 4 +--- .../05/GHSA-2gjm-hvmq-383v/GHSA-2gjm-hvmq-383v.json | 4 +--- .../05/GHSA-2hc3-647x-j4pq/GHSA-2hc3-647x-j4pq.json | 12 +++--------- .../05/GHSA-2hm9-33m6-xf92/GHSA-2hm9-33m6-xf92.json | 8 ++------ .../05/GHSA-2jp5-f326-8qj7/GHSA-2jp5-f326-8qj7.json | 12 +++--------- .../05/GHSA-2m5h-fr2p-prrm/GHSA-2m5h-fr2p-prrm.json | 8 ++------ .../05/GHSA-2mgp-6265-vwf6/GHSA-2mgp-6265-vwf6.json | 12 +++--------- .../05/GHSA-2qr5-c6ch-9wr8/GHSA-2qr5-c6ch-9wr8.json | 4 +--- .../05/GHSA-2r3r-854p-xjfr/GHSA-2r3r-854p-xjfr.json | 4 +--- .../05/GHSA-2rcq-4r2f-jhv9/GHSA-2rcq-4r2f-jhv9.json | 12 +++--------- .../05/GHSA-2rfq-4jx8-3hp9/GHSA-2rfq-4jx8-3hp9.json | 4 +--- .../05/GHSA-2rp9-ffvm-xjc8/GHSA-2rp9-ffvm-xjc8.json | 8 ++------ .../05/GHSA-2v77-vf4r-42vf/GHSA-2v77-vf4r-42vf.json | 8 ++------ .../05/GHSA-2w2h-4fp7-2gq3/GHSA-2w2h-4fp7-2gq3.json | 8 ++------ .../05/GHSA-2x85-3pxc-c227/GHSA-2x85-3pxc-c227.json | 8 ++------ .../05/GHSA-2x9h-q6q9-gfvw/GHSA-2x9h-q6q9-gfvw.json | 12 +++--------- .../05/GHSA-2xfm-mgc4-j8fx/GHSA-2xfm-mgc4-j8fx.json | 4 +--- .../05/GHSA-2xx9-w5qw-9796/GHSA-2xx9-w5qw-9796.json | 12 +++--------- .../05/GHSA-326g-xf83-pf2m/GHSA-326g-xf83-pf2m.json | 4 +--- .../05/GHSA-342q-q4xm-99r7/GHSA-342q-q4xm-99r7.json | 4 +--- .../05/GHSA-34xx-9q37-gww9/GHSA-34xx-9q37-gww9.json | 12 +++--------- .../05/GHSA-3562-xr8f-cfw7/GHSA-3562-xr8f-cfw7.json | 4 +--- .../05/GHSA-384q-gq9c-w4g3/GHSA-384q-gq9c-w4g3.json | 4 +--- .../05/GHSA-38xc-j7pw-37v9/GHSA-38xc-j7pw-37v9.json | 8 ++------ .../05/GHSA-39w5-pgjj-2hx6/GHSA-39w5-pgjj-2hx6.json | 12 +++--------- .../05/GHSA-3c54-vg5v-pqpf/GHSA-3c54-vg5v-pqpf.json | 12 +++--------- .../05/GHSA-3jwh-g5rj-5hgj/GHSA-3jwh-g5rj-5hgj.json | 12 +++--------- .../05/GHSA-3m88-9p3h-xpvh/GHSA-3m88-9p3h-xpvh.json | 4 +--- .../05/GHSA-3mqx-hc7r-v3c4/GHSA-3mqx-hc7r-v3c4.json | 4 +--- .../05/GHSA-3q95-xjvq-cqjf/GHSA-3q95-xjvq-cqjf.json | 12 +++--------- .../05/GHSA-3qqm-2wjh-qxhf/GHSA-3qqm-2wjh-qxhf.json | 12 +++--------- .../05/GHSA-3v23-qhr8-m9w2/GHSA-3v23-qhr8-m9w2.json | 12 +++--------- .../05/GHSA-3v56-6hxf-8799/GHSA-3v56-6hxf-8799.json | 8 ++------ .../05/GHSA-3v56-chv5-rchw/GHSA-3v56-chv5-rchw.json | 12 +++--------- .../05/GHSA-3v88-mwpf-89qm/GHSA-3v88-mwpf-89qm.json | 12 +++--------- .../05/GHSA-3vcc-qrc9-5rvw/GHSA-3vcc-qrc9-5rvw.json | 12 +++--------- .../05/GHSA-3vxc-f4m6-vwxh/GHSA-3vxc-f4m6-vwxh.json | 12 +++--------- .../05/GHSA-3wcg-3hq8-89r6/GHSA-3wcg-3hq8-89r6.json | 4 +--- .../05/GHSA-3wwx-c927-c5wg/GHSA-3wwx-c927-c5wg.json | 12 +++--------- .../05/GHSA-3x6j-h8cp-mc44/GHSA-3x6j-h8cp-mc44.json | 4 +--- .../05/GHSA-3xpw-25qv-r984/GHSA-3xpw-25qv-r984.json | 4 +--- .../05/GHSA-44xf-m62f-7h7r/GHSA-44xf-m62f-7h7r.json | 4 +--- .../05/GHSA-45m3-v8w2-94m4/GHSA-45m3-v8w2-94m4.json | 4 +--- .../05/GHSA-4625-wrpx-f52j/GHSA-4625-wrpx-f52j.json | 12 +++--------- .../05/GHSA-46w4-5g46-6h8f/GHSA-46w4-5g46-6h8f.json | 8 ++------ .../05/GHSA-47pc-84xg-qf5p/GHSA-47pc-84xg-qf5p.json | 12 +++--------- .../05/GHSA-49c5-7mr2-4w43/GHSA-49c5-7mr2-4w43.json | 4 +--- .../05/GHSA-4h5r-2hfh-8prm/GHSA-4h5r-2hfh-8prm.json | 12 +++--------- .../05/GHSA-4hq6-rhmw-hgw9/GHSA-4hq6-rhmw-hgw9.json | 12 +++--------- .../05/GHSA-4jv2-f9mw-9vh9/GHSA-4jv2-f9mw-9vh9.json | 4 +--- .../05/GHSA-4jx4-8xx2-8r3h/GHSA-4jx4-8xx2-8r3h.json | 12 +++--------- .../05/GHSA-4pj4-x8fv-v6vm/GHSA-4pj4-x8fv-v6vm.json | 12 +++--------- .../05/GHSA-4pjf-x44m-95hq/GHSA-4pjf-x44m-95hq.json | 4 +--- .../05/GHSA-4pv4-8h84-4vg6/GHSA-4pv4-8h84-4vg6.json | 12 +++--------- .../05/GHSA-4qm4-wr42-6jxh/GHSA-4qm4-wr42-6jxh.json | 12 +++--------- .../05/GHSA-4qv9-vq3r-p2rx/GHSA-4qv9-vq3r-p2rx.json | 12 +++--------- .../05/GHSA-4rj8-hc4w-2f6v/GHSA-4rj8-hc4w-2f6v.json | 12 +++--------- .../05/GHSA-4v9j-mhhp-7qmp/GHSA-4v9j-mhhp-7qmp.json | 4 +--- .../05/GHSA-4vgf-c8vc-m3fj/GHSA-4vgf-c8vc-m3fj.json | 12 +++--------- .../05/GHSA-4w5r-2wjg-hq97/GHSA-4w5r-2wjg-hq97.json | 12 +++--------- .../05/GHSA-4w66-5376-wj8w/GHSA-4w66-5376-wj8w.json | 12 +++--------- .../05/GHSA-4xp9-9mj9-535w/GHSA-4xp9-9mj9-535w.json | 12 +++--------- .../05/GHSA-4xqw-p5g4-297h/GHSA-4xqw-p5g4-297h.json | 4 +--- .../05/GHSA-4xqx-mhgm-2732/GHSA-4xqx-mhgm-2732.json | 4 +--- .../05/GHSA-4xxj-wpww-f4p9/GHSA-4xxj-wpww-f4p9.json | 4 +--- .../05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json | 4 +--- .../05/GHSA-54gm-47p9-xr3r/GHSA-54gm-47p9-xr3r.json | 12 +++--------- .../05/GHSA-55g5-wxj5-7cv9/GHSA-55g5-wxj5-7cv9.json | 12 +++--------- .../05/GHSA-563g-v6qf-95gq/GHSA-563g-v6qf-95gq.json | 8 ++------ .../05/GHSA-5665-6v3f-928v/GHSA-5665-6v3f-928v.json | 12 +++--------- .../05/GHSA-56qr-6hfh-52cg/GHSA-56qr-6hfh-52cg.json | 4 +--- .../05/GHSA-56rf-q4xp-9h6w/GHSA-56rf-q4xp-9h6w.json | 12 +++--------- .../05/GHSA-58pm-hq3j-r3vx/GHSA-58pm-hq3j-r3vx.json | 12 +++--------- .../05/GHSA-59wp-qpx3-fcf5/GHSA-59wp-qpx3-fcf5.json | 4 +--- .../05/GHSA-59wx-wx8g-cfcx/GHSA-59wx-wx8g-cfcx.json | 4 +--- .../05/GHSA-5cpx-m8gp-jj7j/GHSA-5cpx-m8gp-jj7j.json | 4 +--- .../05/GHSA-5hph-h6w5-vcf5/GHSA-5hph-h6w5-vcf5.json | 12 +++--------- .../05/GHSA-5j8w-g8hc-6222/GHSA-5j8w-g8hc-6222.json | 8 ++------ .../05/GHSA-5pjh-5gpx-359v/GHSA-5pjh-5gpx-359v.json | 4 +--- .../05/GHSA-5prc-43fj-m4f2/GHSA-5prc-43fj-m4f2.json | 8 ++------ .../05/GHSA-5r54-r4m5-pjhw/GHSA-5r54-r4m5-pjhw.json | 12 +++--------- .../05/GHSA-5r8v-mwp7-jjxq/GHSA-5r8v-mwp7-jjxq.json | 4 +--- .../05/GHSA-5rrr-3j22-6ppf/GHSA-5rrr-3j22-6ppf.json | 12 +++--------- .../05/GHSA-5v46-5c9p-j4mg/GHSA-5v46-5c9p-j4mg.json | 4 +--- .../05/GHSA-5v9c-c23v-56m3/GHSA-5v9c-c23v-56m3.json | 12 +++--------- .../05/GHSA-5wfq-p3hq-jw4m/GHSA-5wfq-p3hq-jw4m.json | 4 +--- .../05/GHSA-5xj7-h235-qpx8/GHSA-5xj7-h235-qpx8.json | 8 ++------ .../05/GHSA-62j3-37pc-h32g/GHSA-62j3-37pc-h32g.json | 4 +--- .../05/GHSA-62rf-fp64-gxpc/GHSA-62rf-fp64-gxpc.json | 4 +--- .../05/GHSA-632m-3qm6-rpqw/GHSA-632m-3qm6-rpqw.json | 4 +--- .../05/GHSA-6464-wc5j-3x4p/GHSA-6464-wc5j-3x4p.json | 12 +++--------- .../05/GHSA-65qj-84mc-xh49/GHSA-65qj-84mc-xh49.json | 12 +++--------- .../05/GHSA-6642-6xcj-fvp6/GHSA-6642-6xcj-fvp6.json | 12 +++--------- .../05/GHSA-664g-32r8-gj3v/GHSA-664g-32r8-gj3v.json | 12 +++--------- .../05/GHSA-67fq-99w3-mv56/GHSA-67fq-99w3-mv56.json | 4 +--- .../05/GHSA-6837-f96c-5j64/GHSA-6837-f96c-5j64.json | 4 +--- .../05/GHSA-683h-m32r-vcgg/GHSA-683h-m32r-vcgg.json | 4 +--- .../05/GHSA-68xv-2p42-wm3q/GHSA-68xv-2p42-wm3q.json | 4 +--- .../05/GHSA-699f-vfp8-xj53/GHSA-699f-vfp8-xj53.json | 12 +++--------- .../05/GHSA-69gq-m98f-jh3r/GHSA-69gq-m98f-jh3r.json | 12 +++--------- .../05/GHSA-69xr-64hc-h4r8/GHSA-69xr-64hc-h4r8.json | 12 +++--------- .../05/GHSA-6c53-pfqv-mx96/GHSA-6c53-pfqv-mx96.json | 12 +++--------- .../05/GHSA-6fq2-2mw9-3j26/GHSA-6fq2-2mw9-3j26.json | 4 +--- .../05/GHSA-6gr3-gw4j-hphq/GHSA-6gr3-gw4j-hphq.json | 4 +--- .../05/GHSA-6hgm-wcrx-jjw5/GHSA-6hgm-wcrx-jjw5.json | 8 ++------ .../05/GHSA-6j2f-925p-c58v/GHSA-6j2f-925p-c58v.json | 12 +++--------- .../05/GHSA-6j5v-g8wm-9r98/GHSA-6j5v-g8wm-9r98.json | 4 +--- .../05/GHSA-6jwq-rcg9-g7r3/GHSA-6jwq-rcg9-g7r3.json | 12 +++--------- .../05/GHSA-6mpj-9376-4g2w/GHSA-6mpj-9376-4g2w.json | 12 +++--------- .../05/GHSA-6mrp-f323-h9mx/GHSA-6mrp-f323-h9mx.json | 12 +++--------- .../05/GHSA-6p8w-pqqx-8fpc/GHSA-6p8w-pqqx-8fpc.json | 12 +++--------- .../05/GHSA-6q52-cg2r-w8jw/GHSA-6q52-cg2r-w8jw.json | 12 +++--------- .../05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json | 4 +--- .../05/GHSA-6qh9-2jmr-mwmj/GHSA-6qh9-2jmr-mwmj.json | 4 +--- .../05/GHSA-6r93-m2cp-hhmf/GHSA-6r93-m2cp-hhmf.json | 4 +--- .../05/GHSA-6vgf-xpr3-4724/GHSA-6vgf-xpr3-4724.json | 4 +--- .../05/GHSA-6wr5-v37w-q3rj/GHSA-6wr5-v37w-q3rj.json | 12 +++--------- .../05/GHSA-7226-rhpg-6rjh/GHSA-7226-rhpg-6rjh.json | 4 +--- .../05/GHSA-724h-f4rh-cc47/GHSA-724h-f4rh-cc47.json | 4 +--- .../05/GHSA-725m-pg3w-h3c9/GHSA-725m-pg3w-h3c9.json | 12 +++--------- .../05/GHSA-72r5-4jgc-xj7v/GHSA-72r5-4jgc-xj7v.json | 12 +++--------- .../05/GHSA-7573-qg6f-w5c4/GHSA-7573-qg6f-w5c4.json | 8 ++------ .../05/GHSA-7577-f2mx-w9rc/GHSA-7577-f2mx-w9rc.json | 4 +--- .../05/GHSA-75v7-h9gp-f766/GHSA-75v7-h9gp-f766.json | 12 +++--------- .../05/GHSA-76h7-m86v-wq78/GHSA-76h7-m86v-wq78.json | 12 +++--------- .../05/GHSA-76p6-vjx7-f4xh/GHSA-76p6-vjx7-f4xh.json | 12 +++--------- .../05/GHSA-77m2-2x4h-2jg6/GHSA-77m2-2x4h-2jg6.json | 8 ++------ .../05/GHSA-79mw-6jhw-7997/GHSA-79mw-6jhw-7997.json | 8 ++------ .../05/GHSA-79pw-9mjh-72cp/GHSA-79pw-9mjh-72cp.json | 12 +++--------- .../05/GHSA-79v6-3g86-v959/GHSA-79v6-3g86-v959.json | 4 +--- .../05/GHSA-7g2v-29mr-2f42/GHSA-7g2v-29mr-2f42.json | 12 +++--------- .../05/GHSA-7gjg-3mrx-xxf9/GHSA-7gjg-3mrx-xxf9.json | 4 +--- .../05/GHSA-7j2p-qr4g-pg5x/GHSA-7j2p-qr4g-pg5x.json | 4 +--- .../05/GHSA-7jqv-hh4c-ww3h/GHSA-7jqv-hh4c-ww3h.json | 12 +++--------- .../05/GHSA-7m2c-p89r-q8ff/GHSA-7m2c-p89r-q8ff.json | 12 +++--------- .../05/GHSA-7pcf-w384-7jc9/GHSA-7pcf-w384-7jc9.json | 12 +++--------- .../05/GHSA-7qw8-88j7-x8gr/GHSA-7qw8-88j7-x8gr.json | 8 ++------ .../05/GHSA-7rp3-hp6r-f2pw/GHSA-7rp3-hp6r-f2pw.json | 12 +++--------- .../05/GHSA-7vv7-v9gp-whmr/GHSA-7vv7-v9gp-whmr.json | 8 ++------ .../05/GHSA-7w4w-2hxm-8cc6/GHSA-7w4w-2hxm-8cc6.json | 4 +--- .../05/GHSA-7wgm-pvjv-p545/GHSA-7wgm-pvjv-p545.json | 4 +--- .../05/GHSA-83fw-4w4c-4v29/GHSA-83fw-4w4c-4v29.json | 4 +--- .../05/GHSA-83pj-f384-34m7/GHSA-83pj-f384-34m7.json | 12 +++--------- .../05/GHSA-83vv-q4vw-p24m/GHSA-83vv-q4vw-p24m.json | 4 +--- .../05/GHSA-84r2-hp76-hh77/GHSA-84r2-hp76-hh77.json | 12 +++--------- .../05/GHSA-85m9-wggc-372h/GHSA-85m9-wggc-372h.json | 4 +--- .../05/GHSA-864h-5wf6-hrwh/GHSA-864h-5wf6-hrwh.json | 12 +++--------- .../05/GHSA-8926-mj52-jxcv/GHSA-8926-mj52-jxcv.json | 12 +++--------- .../05/GHSA-89jr-435v-r2g3/GHSA-89jr-435v-r2g3.json | 12 +++--------- .../05/GHSA-8cc7-m958-9r87/GHSA-8cc7-m958-9r87.json | 8 ++------ .../05/GHSA-8g7j-8p7x-qq3c/GHSA-8g7j-8p7x-qq3c.json | 12 +++--------- .../05/GHSA-8gq5-wmr9-rcvv/GHSA-8gq5-wmr9-rcvv.json | 12 +++--------- .../05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json | 12 +++--------- .../05/GHSA-8j47-63h6-77w9/GHSA-8j47-63h6-77w9.json | 8 ++------ .../05/GHSA-8m8m-7fgv-2g6f/GHSA-8m8m-7fgv-2g6f.json | 4 +--- .../05/GHSA-8p2v-rvpv-92r3/GHSA-8p2v-rvpv-92r3.json | 4 +--- .../05/GHSA-8p3x-34c5-5pmx/GHSA-8p3x-34c5-5pmx.json | 4 +--- .../05/GHSA-8q94-gg4r-q969/GHSA-8q94-gg4r-q969.json | 4 +--- .../05/GHSA-8qh9-rx3v-4wvr/GHSA-8qh9-rx3v-4wvr.json | 12 +++--------- .../05/GHSA-8w85-7w79-ghh7/GHSA-8w85-7w79-ghh7.json | 12 +++--------- .../05/GHSA-8x2j-pw29-3r92/GHSA-8x2j-pw29-3r92.json | 12 +++--------- .../05/GHSA-8xm7-mq63-gv2r/GHSA-8xm7-mq63-gv2r.json | 12 +++--------- .../05/GHSA-92ph-vwr5-g5f4/GHSA-92ph-vwr5-g5f4.json | 4 +--- .../05/GHSA-936g-2f5c-q2w8/GHSA-936g-2f5c-q2w8.json | 4 +--- .../05/GHSA-93p9-8fj5-vjv2/GHSA-93p9-8fj5-vjv2.json | 8 ++------ .../05/GHSA-93rr-wh56-p8fw/GHSA-93rr-wh56-p8fw.json | 8 ++------ .../05/GHSA-93x7-x38m-p7mr/GHSA-93x7-x38m-p7mr.json | 12 +++--------- .../05/GHSA-95g7-22q2-6wmq/GHSA-95g7-22q2-6wmq.json | 4 +--- .../05/GHSA-9779-jfg9-frm3/GHSA-9779-jfg9-frm3.json | 4 +--- .../05/GHSA-98v2-gwqr-qc6m/GHSA-98v2-gwqr-qc6m.json | 12 +++--------- .../05/GHSA-9crc-xjgp-v484/GHSA-9crc-xjgp-v484.json | 4 +--- .../05/GHSA-9gh7-98rg-65p8/GHSA-9gh7-98rg-65p8.json | 12 +++--------- .../05/GHSA-9hxx-97w4-fh95/GHSA-9hxx-97w4-fh95.json | 8 ++------ .../05/GHSA-9j4w-mccp-p9wv/GHSA-9j4w-mccp-p9wv.json | 4 +--- .../05/GHSA-9mm5-jxqx-9fjx/GHSA-9mm5-jxqx-9fjx.json | 4 +--- .../05/GHSA-9mpm-cpqp-766f/GHSA-9mpm-cpqp-766f.json | 12 +++--------- .../05/GHSA-9r58-49jg-hrq7/GHSA-9r58-49jg-hrq7.json | 4 +--- .../05/GHSA-9r5h-92x4-fxx8/GHSA-9r5h-92x4-fxx8.json | 8 ++------ .../05/GHSA-9v6q-8j73-8fcr/GHSA-9v6q-8j73-8fcr.json | 4 +--- .../05/GHSA-9v7f-rj28-9x3v/GHSA-9v7f-rj28-9x3v.json | 4 +--- .../05/GHSA-9vw8-5c3c-w435/GHSA-9vw8-5c3c-w435.json | 12 +++--------- .../05/GHSA-9wg8-9g4x-8c9p/GHSA-9wg8-9g4x-8c9p.json | 4 +--- .../05/GHSA-9wpg-w4pv-72hf/GHSA-9wpg-w4pv-72hf.json | 12 +++--------- .../05/GHSA-9x53-5f6r-73cq/GHSA-9x53-5f6r-73cq.json | 8 ++------ .../05/GHSA-9x9m-9jh5-6gwf/GHSA-9x9m-9jh5-6gwf.json | 12 +++--------- .../05/GHSA-c22m-cqmp-648p/GHSA-c22m-cqmp-648p.json | 12 +++--------- .../05/GHSA-c3x6-px6w-wrxq/GHSA-c3x6-px6w-wrxq.json | 4 +--- .../05/GHSA-c424-83vr-r34f/GHSA-c424-83vr-r34f.json | 12 +++--------- .../05/GHSA-c4wx-x65q-h4fx/GHSA-c4wx-x65q-h4fx.json | 8 ++------ .../05/GHSA-c55r-2684-gw89/GHSA-c55r-2684-gw89.json | 12 +++--------- .../05/GHSA-c637-jwvm-g57q/GHSA-c637-jwvm-g57q.json | 12 +++--------- .../05/GHSA-c8pj-xcf4-vhc8/GHSA-c8pj-xcf4-vhc8.json | 4 +--- .../05/GHSA-c9v9-47m5-62h4/GHSA-c9v9-47m5-62h4.json | 12 +++--------- .../05/GHSA-cfh8-rvcx-v326/GHSA-cfh8-rvcx-v326.json | 8 ++------ .../05/GHSA-cgpj-vcc9-76qx/GHSA-cgpj-vcc9-76qx.json | 4 +--- .../05/GHSA-ch38-2px8-5wrr/GHSA-ch38-2px8-5wrr.json | 4 +--- .../05/GHSA-cm63-q44g-45j5/GHSA-cm63-q44g-45j5.json | 4 +--- .../05/GHSA-cmfj-gv9j-wp76/GHSA-cmfj-gv9j-wp76.json | 12 +++--------- .../05/GHSA-cmr2-gmfq-rgq8/GHSA-cmr2-gmfq-rgq8.json | 8 ++------ .../05/GHSA-cpjp-485v-mmmr/GHSA-cpjp-485v-mmmr.json | 12 +++--------- .../05/GHSA-cr64-644f-pj24/GHSA-cr64-644f-pj24.json | 8 ++------ .../05/GHSA-cv25-9hfx-33wj/GHSA-cv25-9hfx-33wj.json | 8 ++------ .../05/GHSA-cvp9-xf77-46mc/GHSA-cvp9-xf77-46mc.json | 4 +--- .../05/GHSA-cx34-9hmm-493f/GHSA-cx34-9hmm-493f.json | 8 ++------ .../05/GHSA-f2vm-77f3-vpcq/GHSA-f2vm-77f3-vpcq.json | 4 +--- .../05/GHSA-f64w-cj85-9j8w/GHSA-f64w-cj85-9j8w.json | 12 +++--------- .../05/GHSA-f7c3-85h7-v4f4/GHSA-f7c3-85h7-v4f4.json | 4 +--- .../05/GHSA-f8wp-7ph4-863c/GHSA-f8wp-7ph4-863c.json | 12 +++--------- .../05/GHSA-fc4h-7x45-5wrw/GHSA-fc4h-7x45-5wrw.json | 12 +++--------- .../05/GHSA-fhc7-95hq-9w87/GHSA-fhc7-95hq-9w87.json | 8 ++------ .../05/GHSA-fhcf-vpm9-jphv/GHSA-fhcf-vpm9-jphv.json | 8 ++------ .../05/GHSA-fm58-52q7-gpvg/GHSA-fm58-52q7-gpvg.json | 4 +--- .../05/GHSA-fm7p-vqmh-43rf/GHSA-fm7p-vqmh-43rf.json | 12 +++--------- .../05/GHSA-fmq3-2qp8-v6g9/GHSA-fmq3-2qp8-v6g9.json | 4 +--- .../05/GHSA-fppp-3vhq-pxxg/GHSA-fppp-3vhq-pxxg.json | 12 +++--------- .../05/GHSA-fq63-9c29-w9fw/GHSA-fq63-9c29-w9fw.json | 12 +++--------- .../05/GHSA-fqv6-g44j-5jx7/GHSA-fqv6-g44j-5jx7.json | 4 +--- .../05/GHSA-frqm-xpj3-g9h5/GHSA-frqm-xpj3-g9h5.json | 12 +++--------- .../05/GHSA-frwj-2gwg-74jv/GHSA-frwj-2gwg-74jv.json | 12 +++--------- .../05/GHSA-fvqv-6788-x824/GHSA-fvqv-6788-x824.json | 12 +++--------- .../05/GHSA-g442-4wgf-h9jr/GHSA-g442-4wgf-h9jr.json | 4 +--- .../05/GHSA-g6g8-jgp3-m382/GHSA-g6g8-jgp3-m382.json | 8 ++------ .../05/GHSA-g6jr-fq7m-6v6x/GHSA-g6jr-fq7m-6v6x.json | 12 +++--------- .../05/GHSA-g759-wxh6-x7jp/GHSA-g759-wxh6-x7jp.json | 12 +++--------- .../05/GHSA-g7xg-hcq2-r768/GHSA-g7xg-hcq2-r768.json | 12 +++--------- .../05/GHSA-g8m6-5j3r-8xg4/GHSA-g8m6-5j3r-8xg4.json | 4 +--- .../05/GHSA-g96v-26x6-4jrf/GHSA-g96v-26x6-4jrf.json | 12 +++--------- .../05/GHSA-g97q-g4qr-rcgw/GHSA-g97q-g4qr-rcgw.json | 4 +--- .../05/GHSA-g99j-vfcp-3vmf/GHSA-g99j-vfcp-3vmf.json | 8 ++------ .../05/GHSA-g9gm-m3h7-634p/GHSA-g9gm-m3h7-634p.json | 8 ++------ .../05/GHSA-g9j3-3283-g3gq/GHSA-g9j3-3283-g3gq.json | 4 +--- .../05/GHSA-gc95-jc79-5q6h/GHSA-gc95-jc79-5q6h.json | 4 +--- .../05/GHSA-gfx4-r3v9-vph4/GHSA-gfx4-r3v9-vph4.json | 8 ++------ .../05/GHSA-ggq9-q258-r9g6/GHSA-ggq9-q258-r9g6.json | 12 +++--------- .../05/GHSA-ghm3-x9vf-px32/GHSA-ghm3-x9vf-px32.json | 4 +--- .../05/GHSA-gjvf-862f-699c/GHSA-gjvf-862f-699c.json | 4 +--- .../05/GHSA-gpqc-5qx7-8qm2/GHSA-gpqc-5qx7-8qm2.json | 4 +--- .../05/GHSA-gpvp-m39p-pc77/GHSA-gpvp-m39p-pc77.json | 4 +--- .../05/GHSA-gq3m-8xxj-8v3w/GHSA-gq3m-8xxj-8v3w.json | 12 +++--------- .../05/GHSA-gq5h-q589-jxr5/GHSA-gq5h-q589-jxr5.json | 4 +--- .../05/GHSA-gqcf-3mp9-v4ch/GHSA-gqcf-3mp9-v4ch.json | 12 +++--------- .../05/GHSA-gr62-2592-229q/GHSA-gr62-2592-229q.json | 8 ++------ .../05/GHSA-grvp-x94j-hv4j/GHSA-grvp-x94j-hv4j.json | 4 +--- .../05/GHSA-gv6x-hf8m-5p66/GHSA-gv6x-hf8m-5p66.json | 4 +--- .../05/GHSA-h27g-g76x-xqpw/GHSA-h27g-g76x-xqpw.json | 8 ++------ .../05/GHSA-h2jw-98ww-486c/GHSA-h2jw-98ww-486c.json | 4 +--- .../05/GHSA-h36q-74vp-w85q/GHSA-h36q-74vp-w85q.json | 4 +--- .../05/GHSA-h68p-8jj4-mh9x/GHSA-h68p-8jj4-mh9x.json | 8 ++------ .../05/GHSA-h6c2-frm7-53hm/GHSA-h6c2-frm7-53hm.json | 4 +--- .../05/GHSA-h6jq-rjm8-48vf/GHSA-h6jq-rjm8-48vf.json | 4 +--- .../05/GHSA-h782-gpqc-8hjh/GHSA-h782-gpqc-8hjh.json | 4 +--- .../05/GHSA-h8pg-g57w-hfr9/GHSA-h8pg-g57w-hfr9.json | 12 +++--------- .../05/GHSA-h9j3-p28g-73q9/GHSA-h9j3-p28g-73q9.json | 12 +++--------- .../05/GHSA-hfpc-f259-2f2x/GHSA-hfpc-f259-2f2x.json | 12 +++--------- .../05/GHSA-hfr6-3rjr-jmhf/GHSA-hfr6-3rjr-jmhf.json | 12 +++--------- .../05/GHSA-hgpp-34xq-jfxg/GHSA-hgpp-34xq-jfxg.json | 12 +++--------- .../05/GHSA-hgv9-5rhc-jpgp/GHSA-hgv9-5rhc-jpgp.json | 4 +--- .../05/GHSA-hhhq-qgvm-w5hp/GHSA-hhhq-qgvm-w5hp.json | 12 +++--------- .../05/GHSA-hj8w-jv52-fv86/GHSA-hj8w-jv52-fv86.json | 4 +--- .../05/GHSA-hjqr-gcv7-w67w/GHSA-hjqr-gcv7-w67w.json | 12 +++--------- .../05/GHSA-hmhc-2w2f-2ch3/GHSA-hmhc-2w2f-2ch3.json | 12 +++--------- .../05/GHSA-hr4j-wcw8-qq3j/GHSA-hr4j-wcw8-qq3j.json | 12 +++--------- .../05/GHSA-hrmr-jgrx-82h5/GHSA-hrmr-jgrx-82h5.json | 12 +++--------- .../05/GHSA-hv3f-fvpg-gw6q/GHSA-hv3f-fvpg-gw6q.json | 12 +++--------- .../05/GHSA-j28m-hq2p-7rq8/GHSA-j28m-hq2p-7rq8.json | 12 +++--------- .../05/GHSA-j2mv-rmhw-vq9m/GHSA-j2mv-rmhw-vq9m.json | 8 ++------ .../05/GHSA-j334-7fp4-rx7r/GHSA-j334-7fp4-rx7r.json | 12 +++--------- .../05/GHSA-j339-cxg8-wjf2/GHSA-j339-cxg8-wjf2.json | 4 +--- .../05/GHSA-j4xv-vq4c-x7jr/GHSA-j4xv-vq4c-x7jr.json | 4 +--- .../05/GHSA-j595-32pw-xr9x/GHSA-j595-32pw-xr9x.json | 12 +++--------- .../05/GHSA-j59g-6qmh-6hh4/GHSA-j59g-6qmh-6hh4.json | 12 +++--------- .../05/GHSA-j7pw-5g39-c2cj/GHSA-j7pw-5g39-c2cj.json | 4 +--- .../05/GHSA-j85m-6hm4-8243/GHSA-j85m-6hm4-8243.json | 4 +--- .../05/GHSA-j939-hwr4-9qqc/GHSA-j939-hwr4-9qqc.json | 8 ++------ .../05/GHSA-j983-4xw8-9w9m/GHSA-j983-4xw8-9w9m.json | 12 +++--------- .../05/GHSA-j98f-h9mx-xrxq/GHSA-j98f-h9mx-xrxq.json | 8 ++------ .../05/GHSA-j9pj-q5cf-g476/GHSA-j9pj-q5cf-g476.json | 12 +++--------- .../05/GHSA-jc7v-m8xx-gcf7/GHSA-jc7v-m8xx-gcf7.json | 12 +++--------- .../05/GHSA-jcvv-h5v4-vg3r/GHSA-jcvv-h5v4-vg3r.json | 12 +++--------- .../05/GHSA-jfmw-rhf3-688h/GHSA-jfmw-rhf3-688h.json | 4 +--- .../05/GHSA-jg69-hq9p-75r5/GHSA-jg69-hq9p-75r5.json | 8 ++------ .../05/GHSA-jg7x-2whq-4cvh/GHSA-jg7x-2whq-4cvh.json | 12 +++--------- .../05/GHSA-jhrc-gxxh-2cqh/GHSA-jhrc-gxxh-2cqh.json | 12 +++--------- .../05/GHSA-jhv9-9wc2-f5gg/GHSA-jhv9-9wc2-f5gg.json | 4 +--- .../05/GHSA-jhx8-jg6w-gwhp/GHSA-jhx8-jg6w-gwhp.json | 8 ++------ .../05/GHSA-jj9q-c2r3-cv43/GHSA-jj9q-c2r3-cv43.json | 8 ++------ .../05/GHSA-jmgr-533j-34jh/GHSA-jmgr-533j-34jh.json | 4 +--- .../05/GHSA-jp4c-v6vq-9m4m/GHSA-jp4c-v6vq-9m4m.json | 4 +--- .../05/GHSA-jq73-mhwg-56vq/GHSA-jq73-mhwg-56vq.json | 8 ++------ .../05/GHSA-jqpq-g57p-mp22/GHSA-jqpq-g57p-mp22.json | 12 +++--------- .../05/GHSA-jr92-378w-gjp5/GHSA-jr92-378w-gjp5.json | 12 +++--------- .../05/GHSA-jv42-7p6p-f2c8/GHSA-jv42-7p6p-f2c8.json | 12 +++--------- .../05/GHSA-jwvj-q24w-q3xh/GHSA-jwvj-q24w-q3xh.json | 12 +++--------- .../05/GHSA-jxcc-245j-87v3/GHSA-jxcc-245j-87v3.json | 12 +++--------- .../05/GHSA-jxch-3gjv-mgxj/GHSA-jxch-3gjv-mgxj.json | 4 +--- .../05/GHSA-jxmc-5jm4-w9r5/GHSA-jxmc-5jm4-w9r5.json | 4 +--- .../05/GHSA-m35x-hj4x-3cp2/GHSA-m35x-hj4x-3cp2.json | 12 +++--------- .../05/GHSA-m366-vqxx-9f69/GHSA-m366-vqxx-9f69.json | 4 +--- .../05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json | 4 +--- .../05/GHSA-m44h-7xq3-2hh7/GHSA-m44h-7xq3-2hh7.json | 4 +--- .../05/GHSA-m45f-m7gh-g6mh/GHSA-m45f-m7gh-g6mh.json | 12 +++--------- .../05/GHSA-m4gf-qxgm-f565/GHSA-m4gf-qxgm-f565.json | 12 +++--------- .../05/GHSA-m4vw-c8vh-3c9g/GHSA-m4vw-c8vh-3c9g.json | 8 ++------ .../05/GHSA-m5px-2q2g-hxc2/GHSA-m5px-2q2g-hxc2.json | 4 +--- .../05/GHSA-m662-7xcg-f6rg/GHSA-m662-7xcg-f6rg.json | 4 +--- .../05/GHSA-m67p-4364-8xgh/GHSA-m67p-4364-8xgh.json | 4 +--- .../05/GHSA-m7jv-h3ph-p6cg/GHSA-m7jv-h3ph-p6cg.json | 4 +--- .../05/GHSA-m7mv-qphm-p8rq/GHSA-m7mv-qphm-p8rq.json | 8 ++------ .../05/GHSA-m823-4p4w-x3cg/GHSA-m823-4p4w-x3cg.json | 12 +++--------- .../05/GHSA-m9vp-847v-2qr3/GHSA-m9vp-847v-2qr3.json | 4 +--- .../05/GHSA-mcgx-x3rr-p246/GHSA-mcgx-x3rr-p246.json | 8 ++------ .../05/GHSA-mfjh-x56p-qx6f/GHSA-mfjh-x56p-qx6f.json | 12 +++--------- .../05/GHSA-mfw8-6m9g-8vvr/GHSA-mfw8-6m9g-8vvr.json | 4 +--- .../05/GHSA-mfwf-2cj2-j29m/GHSA-mfwf-2cj2-j29m.json | 4 +--- .../05/GHSA-mgrj-fw6g-5692/GHSA-mgrj-fw6g-5692.json | 12 +++--------- .../05/GHSA-mgxg-5jhr-xcq8/GHSA-mgxg-5jhr-xcq8.json | 12 +++--------- .../05/GHSA-mhfh-8w59-m7cx/GHSA-mhfh-8w59-m7cx.json | 12 +++--------- .../05/GHSA-mhv7-384m-mmrf/GHSA-mhv7-384m-mmrf.json | 12 +++--------- .../05/GHSA-mj9m-8g64-3hhp/GHSA-mj9m-8g64-3hhp.json | 12 +++--------- .../05/GHSA-mjp6-fq4v-qgrp/GHSA-mjp6-fq4v-qgrp.json | 12 +++--------- .../05/GHSA-mm9v-95j4-52gp/GHSA-mm9v-95j4-52gp.json | 4 +--- .../05/GHSA-mw8m-jhfq-5hv9/GHSA-mw8m-jhfq-5hv9.json | 8 ++------ .../05/GHSA-mx52-g499-r9jm/GHSA-mx52-g499-r9jm.json | 4 +--- .../05/GHSA-mx9j-5cm7-gv82/GHSA-mx9j-5cm7-gv82.json | 4 +--- .../05/GHSA-p2pj-jx8f-jw9f/GHSA-p2pj-jx8f-jw9f.json | 4 +--- .../05/GHSA-p2w2-rrf2-qqmj/GHSA-p2w2-rrf2-qqmj.json | 4 +--- .../05/GHSA-p5cg-gfxr-62pm/GHSA-p5cg-gfxr-62pm.json | 4 +--- .../05/GHSA-p5f9-4qvw-vrhw/GHSA-p5f9-4qvw-vrhw.json | 4 +--- .../05/GHSA-p6mx-xx2r-f2hh/GHSA-p6mx-xx2r-f2hh.json | 12 +++--------- .../05/GHSA-p6p3-chv5-mwrq/GHSA-p6p3-chv5-mwrq.json | 4 +--- .../05/GHSA-p72g-8563-4jg8/GHSA-p72g-8563-4jg8.json | 8 ++------ .../05/GHSA-p785-ww3c-xg46/GHSA-p785-ww3c-xg46.json | 12 +++--------- .../05/GHSA-p83g-f9xr-p3gp/GHSA-p83g-f9xr-p3gp.json | 8 ++------ .../05/GHSA-p87v-9j2v-6w24/GHSA-p87v-9j2v-6w24.json | 4 +--- .../05/GHSA-pc2w-jhrj-hpff/GHSA-pc2w-jhrj-hpff.json | 12 +++--------- .../05/GHSA-pc57-hj73-639x/GHSA-pc57-hj73-639x.json | 12 +++--------- .../05/GHSA-pfm3-fqrj-vmfw/GHSA-pfm3-fqrj-vmfw.json | 4 +--- .../05/GHSA-pm95-5cg4-7h69/GHSA-pm95-5cg4-7h69.json | 12 +++--------- .../05/GHSA-ppp5-ggm8-7mmf/GHSA-ppp5-ggm8-7mmf.json | 4 +--- .../05/GHSA-pq2h-hxv7-w669/GHSA-pq2h-hxv7-w669.json | 12 +++--------- .../05/GHSA-pq6j-c37f-96x2/GHSA-pq6j-c37f-96x2.json | 4 +--- .../05/GHSA-pqg7-ghrf-8r7w/GHSA-pqg7-ghrf-8r7w.json | 4 +--- .../05/GHSA-pqhq-pv8w-43hj/GHSA-pqhq-pv8w-43hj.json | 12 +++--------- .../05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json | 12 +++--------- .../05/GHSA-pvp6-8jxg-p694/GHSA-pvp6-8jxg-p694.json | 12 +++--------- .../05/GHSA-pw77-5cwc-848f/GHSA-pw77-5cwc-848f.json | 12 +++--------- .../05/GHSA-px2q-6q9w-p7wc/GHSA-px2q-6q9w-p7wc.json | 4 +--- .../05/GHSA-q2xx-h2wh-wv97/GHSA-q2xx-h2wh-wv97.json | 8 ++------ .../05/GHSA-q3cq-46x3-3mxj/GHSA-q3cq-46x3-3mxj.json | 4 +--- .../05/GHSA-q4gr-p99g-9293/GHSA-q4gr-p99g-9293.json | 12 +++--------- .../05/GHSA-q4ww-p8r5-7x42/GHSA-q4ww-p8r5-7x42.json | 4 +--- .../05/GHSA-q6h4-g972-8qqw/GHSA-q6h4-g972-8qqw.json | 12 +++--------- .../05/GHSA-q6qf-823c-5r9g/GHSA-q6qf-823c-5r9g.json | 12 +++--------- .../05/GHSA-q833-7p8r-rcqc/GHSA-q833-7p8r-rcqc.json | 12 +++--------- .../05/GHSA-qc3j-qcr3-434w/GHSA-qc3j-qcr3-434w.json | 4 +--- .../05/GHSA-qchr-cfhp-6334/GHSA-qchr-cfhp-6334.json | 4 +--- .../05/GHSA-qfjp-wwwg-jp27/GHSA-qfjp-wwwg-jp27.json | 8 ++------ .../05/GHSA-qfxm-h9jr-5w92/GHSA-qfxm-h9jr-5w92.json | 4 +--- .../05/GHSA-qgw6-cgvx-vw2g/GHSA-qgw6-cgvx-vw2g.json | 4 +--- .../05/GHSA-qh6p-mxm9-68mc/GHSA-qh6p-mxm9-68mc.json | 12 +++--------- .../05/GHSA-qhc9-mv9r-wv6m/GHSA-qhc9-mv9r-wv6m.json | 8 ++------ .../05/GHSA-qhg6-x5p3-8653/GHSA-qhg6-x5p3-8653.json | 8 ++------ .../05/GHSA-qj25-jwcw-gvf6/GHSA-qj25-jwcw-gvf6.json | 12 +++--------- .../05/GHSA-qjfp-xc6m-h4xx/GHSA-qjfp-xc6m-h4xx.json | 4 +--- .../05/GHSA-qjq8-6wjp-3w9f/GHSA-qjq8-6wjp-3w9f.json | 4 +--- .../05/GHSA-qmhh-9528-j6c2/GHSA-qmhh-9528-j6c2.json | 12 +++--------- .../05/GHSA-qp9h-mj96-rrv3/GHSA-qp9h-mj96-rrv3.json | 4 +--- .../05/GHSA-qrcv-45vg-jfwm/GHSA-qrcv-45vg-jfwm.json | 12 +++--------- .../05/GHSA-qwrg-2m8j-ppj3/GHSA-qwrg-2m8j-ppj3.json | 8 ++------ .../05/GHSA-qx45-wmfv-9pxq/GHSA-qx45-wmfv-9pxq.json | 4 +--- .../05/GHSA-qxq3-p28m-qc36/GHSA-qxq3-p28m-qc36.json | 4 +--- .../05/GHSA-qxrm-24v6-5c8c/GHSA-qxrm-24v6-5c8c.json | 12 +++--------- .../05/GHSA-r2c4-53pj-jrgp/GHSA-r2c4-53pj-jrgp.json | 12 +++--------- .../05/GHSA-r3xx-53c7-m93v/GHSA-r3xx-53c7-m93v.json | 8 ++------ .../05/GHSA-r446-qh2r-fgc7/GHSA-r446-qh2r-fgc7.json | 8 ++------ .../05/GHSA-r56g-9xx6-cwq3/GHSA-r56g-9xx6-cwq3.json | 8 ++------ .../05/GHSA-r754-r2fw-63fg/GHSA-r754-r2fw-63fg.json | 4 +--- .../05/GHSA-r7ph-g2h5-66hm/GHSA-r7ph-g2h5-66hm.json | 12 +++--------- .../05/GHSA-r8hg-9pmc-pqq2/GHSA-r8hg-9pmc-pqq2.json | 12 +++--------- .../05/GHSA-r8xc-5v3r-xg8r/GHSA-r8xc-5v3r-xg8r.json | 12 +++--------- .../05/GHSA-rcw3-hp7x-jvp6/GHSA-rcw3-hp7x-jvp6.json | 8 ++------ .../05/GHSA-rhcj-jwww-2qpj/GHSA-rhcj-jwww-2qpj.json | 8 ++------ .../05/GHSA-rj5f-f43f-cfhc/GHSA-rj5f-f43f-cfhc.json | 8 ++------ .../05/GHSA-rm92-8pw8-34fm/GHSA-rm92-8pw8-34fm.json | 4 +--- .../05/GHSA-rm9j-4357-597x/GHSA-rm9j-4357-597x.json | 4 +--- .../05/GHSA-rp7p-6rw5-m696/GHSA-rp7p-6rw5-m696.json | 4 +--- .../05/GHSA-rpg4-8g9f-9p3r/GHSA-rpg4-8g9f-9p3r.json | 8 ++------ .../05/GHSA-rq6c-pcm6-q4r9/GHSA-rq6c-pcm6-q4r9.json | 4 +--- .../05/GHSA-rq94-cx6g-vxm4/GHSA-rq94-cx6g-vxm4.json | 12 +++--------- .../05/GHSA-rrr4-gx86-2xc7/GHSA-rrr4-gx86-2xc7.json | 12 +++--------- .../05/GHSA-rrw6-f33h-795h/GHSA-rrw6-f33h-795h.json | 4 +--- .../05/GHSA-rwhw-r234-9p3m/GHSA-rwhw-r234-9p3m.json | 4 +--- .../05/GHSA-rx6r-3q7r-fm48/GHSA-rx6r-3q7r-fm48.json | 12 +++--------- .../05/GHSA-rxx5-6r7x-q8xv/GHSA-rxx5-6r7x-q8xv.json | 4 +--- .../05/GHSA-v36v-c6xp-cpv3/GHSA-v36v-c6xp-cpv3.json | 8 ++------ .../05/GHSA-v36x-fh5g-gvf8/GHSA-v36x-fh5g-gvf8.json | 8 ++------ .../05/GHSA-v3hw-wjfp-h8fp/GHSA-v3hw-wjfp-h8fp.json | 8 ++------ .../05/GHSA-v3x2-gf8f-p55r/GHSA-v3x2-gf8f-p55r.json | 12 +++--------- .../05/GHSA-v6mx-fmfw-p682/GHSA-v6mx-fmfw-p682.json | 4 +--- .../05/GHSA-v7rr-mcc8-3mqh/GHSA-v7rr-mcc8-3mqh.json | 4 +--- .../05/GHSA-vc4m-fgcj-7cmm/GHSA-vc4m-fgcj-7cmm.json | 12 +++--------- .../05/GHSA-vcm5-7xhj-3h4c/GHSA-vcm5-7xhj-3h4c.json | 12 +++--------- .../05/GHSA-vf5v-h8cw-pwgf/GHSA-vf5v-h8cw-pwgf.json | 12 +++--------- .../05/GHSA-vgxc-rq2p-x5qw/GHSA-vgxc-rq2p-x5qw.json | 4 +--- .../05/GHSA-vh7m-2x7g-3h5v/GHSA-vh7m-2x7g-3h5v.json | 12 +++--------- .../05/GHSA-vhxc-xrx4-c2rp/GHSA-vhxc-xrx4-c2rp.json | 12 +++--------- .../05/GHSA-vm5j-x654-r2ww/GHSA-vm5j-x654-r2ww.json | 12 +++--------- .../05/GHSA-vpxp-m77w-89hf/GHSA-vpxp-m77w-89hf.json | 8 ++------ .../05/GHSA-vq9p-965j-5xf8/GHSA-vq9p-965j-5xf8.json | 4 +--- .../05/GHSA-vqj4-45vx-v6r9/GHSA-vqj4-45vx-v6r9.json | 4 +--- .../05/GHSA-vqwf-pqwm-mrf6/GHSA-vqwf-pqwm-mrf6.json | 4 +--- .../05/GHSA-vv37-c88j-jq3p/GHSA-vv37-c88j-jq3p.json | 4 +--- .../05/GHSA-vv88-7m9v-j3pp/GHSA-vv88-7m9v-j3pp.json | 8 ++------ .../05/GHSA-vvf9-jwf6-834q/GHSA-vvf9-jwf6-834q.json | 4 +--- .../05/GHSA-vvq6-j7g6-xgmc/GHSA-vvq6-j7g6-xgmc.json | 12 +++--------- .../05/GHSA-vvrq-j22m-3x47/GHSA-vvrq-j22m-3x47.json | 4 +--- .../05/GHSA-vw33-cr89-4v6m/GHSA-vw33-cr89-4v6m.json | 12 +++--------- .../05/GHSA-vx7g-wv5m-2rrx/GHSA-vx7g-wv5m-2rrx.json | 4 +--- .../05/GHSA-w3m3-6r64-x8g3/GHSA-w3m3-6r64-x8g3.json | 12 +++--------- .../05/GHSA-w4v8-5vx5-rr7f/GHSA-w4v8-5vx5-rr7f.json | 12 +++--------- .../05/GHSA-w593-3gmv-8w94/GHSA-w593-3gmv-8w94.json | 12 +++--------- .../05/GHSA-w5mv-8mc9-wcpv/GHSA-w5mv-8mc9-wcpv.json | 4 +--- .../05/GHSA-w5w9-f25c-x66m/GHSA-w5w9-f25c-x66m.json | 4 +--- .../05/GHSA-w66j-g6v2-qcq8/GHSA-w66j-g6v2-qcq8.json | 12 +++--------- .../05/GHSA-w7c2-h36x-prj9/GHSA-w7c2-h36x-prj9.json | 4 +--- .../05/GHSA-w8g8-fw4x-36vp/GHSA-w8g8-fw4x-36vp.json | 4 +--- .../05/GHSA-w9h9-fwvq-fg6r/GHSA-w9h9-fwvq-fg6r.json | 4 +--- .../05/GHSA-wccp-c983-j22q/GHSA-wccp-c983-j22q.json | 4 +--- .../05/GHSA-wcrq-92cw-q282/GHSA-wcrq-92cw-q282.json | 12 +++--------- .../05/GHSA-wgr5-c2c6-vp3h/GHSA-wgr5-c2c6-vp3h.json | 12 +++--------- .../05/GHSA-whr2-9mvm-j8xq/GHSA-whr2-9mvm-j8xq.json | 12 +++--------- .../05/GHSA-wmmx-qvvm-hr27/GHSA-wmmx-qvvm-hr27.json | 4 +--- .../05/GHSA-wmp8-c7xc-v29x/GHSA-wmp8-c7xc-v29x.json | 12 +++--------- .../05/GHSA-wmwh-42hh-xj9m/GHSA-wmwh-42hh-xj9m.json | 12 +++--------- .../05/GHSA-wpvg-xwcw-g8rx/GHSA-wpvg-xwcw-g8rx.json | 4 +--- .../05/GHSA-wq2j-24r5-rxj2/GHSA-wq2j-24r5-rxj2.json | 4 +--- .../05/GHSA-wvhx-f4v3-x2m8/GHSA-wvhx-f4v3-x2m8.json | 4 +--- .../05/GHSA-wwrh-gqqp-fjq5/GHSA-wwrh-gqqp-fjq5.json | 4 +--- .../05/GHSA-wwwg-pjr9-fqw9/GHSA-wwwg-pjr9-fqw9.json | 4 +--- .../05/GHSA-x43r-h4j8-j6gq/GHSA-x43r-h4j8-j6gq.json | 12 +++--------- .../05/GHSA-x48h-f8p3-4qv4/GHSA-x48h-f8p3-4qv4.json | 8 ++------ .../05/GHSA-x5q7-74fg-9cp7/GHSA-x5q7-74fg-9cp7.json | 12 +++--------- .../05/GHSA-x664-jh9h-xwcq/GHSA-x664-jh9h-xwcq.json | 8 ++------ .../05/GHSA-x6fh-2jjp-6486/GHSA-x6fh-2jjp-6486.json | 12 +++--------- .../05/GHSA-x7vj-fhcx-5fpj/GHSA-x7vj-fhcx-5fpj.json | 12 +++--------- .../05/GHSA-x86w-ghh6-6vwx/GHSA-x86w-ghh6-6vwx.json | 12 +++--------- .../05/GHSA-x8jx-65f6-p7vf/GHSA-x8jx-65f6-p7vf.json | 12 +++--------- .../05/GHSA-x98q-xccc-62q7/GHSA-x98q-xccc-62q7.json | 12 +++--------- .../05/GHSA-x9pc-w5jc-9r92/GHSA-x9pc-w5jc-9r92.json | 12 +++--------- .../05/GHSA-xf38-h9fv-rf8v/GHSA-xf38-h9fv-rf8v.json | 4 +--- .../05/GHSA-xf7c-hpj8-f7wx/GHSA-xf7c-hpj8-f7wx.json | 4 +--- .../05/GHSA-xfjc-xc6h-589q/GHSA-xfjc-xc6h-589q.json | 8 ++------ .../05/GHSA-xfqf-cw5p-jvwq/GHSA-xfqf-cw5p-jvwq.json | 8 ++------ .../05/GHSA-xg28-jx54-8mvj/GHSA-xg28-jx54-8mvj.json | 12 +++--------- .../05/GHSA-xh3q-xjjx-vm95/GHSA-xh3q-xjjx-vm95.json | 12 +++--------- .../05/GHSA-xh5m-phq6-h38j/GHSA-xh5m-phq6-h38j.json | 12 +++--------- .../05/GHSA-xhj3-gjcc-48pc/GHSA-xhj3-gjcc-48pc.json | 4 +--- .../05/GHSA-xj4j-67v3-3wr4/GHSA-xj4j-67v3-3wr4.json | 12 +++--------- .../05/GHSA-xj6c-4x5p-6pj3/GHSA-xj6c-4x5p-6pj3.json | 4 +--- .../05/GHSA-xm4h-c38c-8h36/GHSA-xm4h-c38c-8h36.json | 12 +++--------- .../05/GHSA-xmfq-7h44-9457/GHSA-xmfq-7h44-9457.json | 12 +++--------- .../05/GHSA-xmpq-jcv6-q64p/GHSA-xmpq-jcv6-q64p.json | 4 +--- .../05/GHSA-xmx7-fph6-xq27/GHSA-xmx7-fph6-xq27.json | 12 +++--------- .../05/GHSA-xqh9-7jpx-wc6w/GHSA-xqh9-7jpx-wc6w.json | 12 +++--------- .../05/GHSA-xqp3-6vpp-g4f2/GHSA-xqp3-6vpp-g4f2.json | 4 +--- .../05/GHSA-xqxv-72j5-c846/GHSA-xqxv-72j5-c846.json | 12 +++--------- .../05/GHSA-xr2p-8p3f-gvvg/GHSA-xr2p-8p3f-gvvg.json | 12 +++--------- .../05/GHSA-xvf7-379r-cpg2/GHSA-xvf7-379r-cpg2.json | 8 ++------ .../05/GHSA-xvg3-g835-ccc9/GHSA-xvg3-g835-ccc9.json | 12 +++--------- .../05/GHSA-xw7x-jg7g-86qj/GHSA-xw7x-jg7g-86qj.json | 8 ++------ .../06/GHSA-2fww-xpgm-c42v/GHSA-2fww-xpgm-c42v.json | 8 ++------ .../06/GHSA-382w-v37j-732p/GHSA-382w-v37j-732p.json | 8 ++------ .../06/GHSA-4p34-j86v-c444/GHSA-4p34-j86v-c444.json | 8 ++------ .../06/GHSA-4v3j-q36m-pfpg/GHSA-4v3j-q36m-pfpg.json | 8 ++------ .../06/GHSA-54mc-mr89-22hq/GHSA-54mc-mr89-22hq.json | 4 +--- .../06/GHSA-566f-w63p-987f/GHSA-566f-w63p-987f.json | 4 +--- .../06/GHSA-59xg-vgg8-c39x/GHSA-59xg-vgg8-c39x.json | 4 +--- .../06/GHSA-5m2c-33c5-mhvp/GHSA-5m2c-33c5-mhvp.json | 4 +--- .../06/GHSA-5qhr-wxg8-2347/GHSA-5qhr-wxg8-2347.json | 4 +--- .../06/GHSA-5wxx-482m-3pgp/GHSA-5wxx-482m-3pgp.json | 4 +--- .../06/GHSA-6rcj-vxjg-f6mw/GHSA-6rcj-vxjg-f6mw.json | 4 +--- .../06/GHSA-8mfg-j7q8-363c/GHSA-8mfg-j7q8-363c.json | 8 ++------ .../06/GHSA-92vx-8g27-6pcv/GHSA-92vx-8g27-6pcv.json | 4 +--- .../06/GHSA-99c3-m3cj-vh2x/GHSA-99c3-m3cj-vh2x.json | 4 +--- .../06/GHSA-9g48-j535-x6f7/GHSA-9g48-j535-x6f7.json | 4 +--- .../06/GHSA-cgfq-p4fh-7mg7/GHSA-cgfq-p4fh-7mg7.json | 4 +--- .../06/GHSA-g42h-fv2r-29vh/GHSA-g42h-fv2r-29vh.json | 8 ++------ .../06/GHSA-ggvq-gj5r-78q8/GHSA-ggvq-gj5r-78q8.json | 4 +--- .../06/GHSA-hr8p-p44m-q8x6/GHSA-hr8p-p44m-q8x6.json | 4 +--- .../06/GHSA-j2vc-96xv-2jh3/GHSA-j2vc-96xv-2jh3.json | 8 ++------ .../06/GHSA-p4hr-cr9g-pfgg/GHSA-p4hr-cr9g-pfgg.json | 4 +--- .../06/GHSA-pj8j-v9wg-f4qf/GHSA-pj8j-v9wg-f4qf.json | 8 ++------ .../06/GHSA-pqfx-xc8v-xv5m/GHSA-pqfx-xc8v-xv5m.json | 4 +--- .../06/GHSA-q8gv-2pxf-545v/GHSA-q8gv-2pxf-545v.json | 4 +--- .../06/GHSA-q9xx-f6h6-9qpp/GHSA-q9xx-f6h6-9qpp.json | 8 ++------ .../06/GHSA-rq6p-6w22-rpjc/GHSA-rq6p-6w22-rpjc.json | 4 +--- .../06/GHSA-v29h-c7w3-f6xp/GHSA-v29h-c7w3-f6xp.json | 8 ++------ .../06/GHSA-v3v8-hmcm-pghv/GHSA-v3v8-hmcm-pghv.json | 4 +--- .../06/GHSA-vh8m-7c3c-7m5c/GHSA-vh8m-7c3c-7m5c.json | 4 +--- .../06/GHSA-w638-qwh4-x86h/GHSA-w638-qwh4-x86h.json | 8 ++------ .../06/GHSA-wpg4-frxw-9c28/GHSA-wpg4-frxw-9c28.json | 4 +--- .../07/GHSA-23qj-c6v6-57hx/GHSA-23qj-c6v6-57hx.json | 4 +--- .../07/GHSA-254c-2j77-4hhm/GHSA-254c-2j77-4hhm.json | 4 +--- .../07/GHSA-294h-9fqc-xfq7/GHSA-294h-9fqc-xfq7.json | 4 +--- .../07/GHSA-2hgw-j3xf-7pv3/GHSA-2hgw-j3xf-7pv3.json | 8 ++------ .../07/GHSA-2jgc-hhfj-xjj5/GHSA-2jgc-hhfj-xjj5.json | 4 +--- .../07/GHSA-2q65-c69r-5v5v/GHSA-2q65-c69r-5v5v.json | 4 +--- .../07/GHSA-2xcc-5x48-fhp2/GHSA-2xcc-5x48-fhp2.json | 4 +--- .../07/GHSA-37xv-hhg6-7q67/GHSA-37xv-hhg6-7q67.json | 4 +--- .../07/GHSA-39jx-jr53-979c/GHSA-39jx-jr53-979c.json | 4 +--- .../07/GHSA-3f45-mmr7-7f4p/GHSA-3f45-mmr7-7f4p.json | 4 +--- .../07/GHSA-3h9p-3h8j-3hm9/GHSA-3h9p-3h8j-3hm9.json | 4 +--- .../07/GHSA-3ww8-8v8c-wrr2/GHSA-3ww8-8v8c-wrr2.json | 4 +--- .../07/GHSA-44qv-5wxp-8xqv/GHSA-44qv-5wxp-8xqv.json | 4 +--- .../07/GHSA-4549-5m2c-669v/GHSA-4549-5m2c-669v.json | 4 +--- .../07/GHSA-4fjp-3mcp-2938/GHSA-4fjp-3mcp-2938.json | 4 +--- .../07/GHSA-4fx5-9xw5-pjw9/GHSA-4fx5-9xw5-pjw9.json | 4 +--- .../07/GHSA-4m86-r24j-6qw7/GHSA-4m86-r24j-6qw7.json | 4 +--- .../07/GHSA-4pqh-76jg-2w88/GHSA-4pqh-76jg-2w88.json | 4 +--- .../07/GHSA-4q2g-gv2p-pg7h/GHSA-4q2g-gv2p-pg7h.json | 4 +--- .../07/GHSA-4qc6-v635-j7j2/GHSA-4qc6-v635-j7j2.json | 8 ++------ .../07/GHSA-4qjq-8mg6-84cv/GHSA-4qjq-8mg6-84cv.json | 4 +--- .../07/GHSA-4w83-58w6-759f/GHSA-4w83-58w6-759f.json | 4 +--- .../07/GHSA-4wc6-q22j-fx9w/GHSA-4wc6-q22j-fx9w.json | 4 +--- .../07/GHSA-528h-92p5-h95c/GHSA-528h-92p5-h95c.json | 4 +--- .../07/GHSA-55h5-46g3-x75j/GHSA-55h5-46g3-x75j.json | 4 +--- .../07/GHSA-55jw-5gmv-2f63/GHSA-55jw-5gmv-2f63.json | 4 +--- .../07/GHSA-599w-rmp9-p3vv/GHSA-599w-rmp9-p3vv.json | 4 +--- .../07/GHSA-5cg7-76g8-crjv/GHSA-5cg7-76g8-crjv.json | 4 +--- .../07/GHSA-5g9x-j9pv-6g6f/GHSA-5g9x-j9pv-6g6f.json | 4 +--- .../07/GHSA-5grx-2mjv-5xqv/GHSA-5grx-2mjv-5xqv.json | 4 +--- .../07/GHSA-5j9x-fgqv-7rqf/GHSA-5j9x-fgqv-7rqf.json | 4 +--- .../07/GHSA-5w4w-f8gg-22rw/GHSA-5w4w-f8gg-22rw.json | 4 +--- .../07/GHSA-5w8m-frg7-38qf/GHSA-5w8m-frg7-38qf.json | 4 +--- .../07/GHSA-5wm5-xf8r-2r7j/GHSA-5wm5-xf8r-2r7j.json | 4 +--- .../07/GHSA-5xq9-crf7-769q/GHSA-5xq9-crf7-769q.json | 4 +--- .../07/GHSA-63vv-f5j8-wjcr/GHSA-63vv-f5j8-wjcr.json | 4 +--- .../07/GHSA-64vr-2vhr-px3r/GHSA-64vr-2vhr-px3r.json | 4 +--- .../07/GHSA-6f36-fmqj-839g/GHSA-6f36-fmqj-839g.json | 4 +--- .../07/GHSA-6g8w-cg76-v39h/GHSA-6g8w-cg76-v39h.json | 4 +--- .../07/GHSA-6wm6-mv83-v9qj/GHSA-6wm6-mv83-v9qj.json | 4 +--- .../07/GHSA-6x5h-m5fm-7333/GHSA-6x5h-m5fm-7333.json | 4 +--- .../07/GHSA-72cr-h3c5-r58j/GHSA-72cr-h3c5-r58j.json | 8 ++------ .../07/GHSA-7grg-hghp-g8f4/GHSA-7grg-hghp-g8f4.json | 4 +--- .../07/GHSA-84xc-hmvp-jp6q/GHSA-84xc-hmvp-jp6q.json | 4 +--- .../07/GHSA-8fhq-w2g2-8jw6/GHSA-8fhq-w2g2-8jw6.json | 4 +--- .../07/GHSA-8fph-2g4q-jf26/GHSA-8fph-2g4q-jf26.json | 4 +--- .../07/GHSA-942p-539x-69rq/GHSA-942p-539x-69rq.json | 8 ++------ .../07/GHSA-9493-q4p5-ff5v/GHSA-9493-q4p5-ff5v.json | 8 ++------ .../07/GHSA-94g5-26f2-52x8/GHSA-94g5-26f2-52x8.json | 4 +--- .../07/GHSA-95rh-674f-3m8c/GHSA-95rh-674f-3m8c.json | 4 +--- .../07/GHSA-9h5m-6q6q-76qg/GHSA-9h5m-6q6q-76qg.json | 4 +--- .../07/GHSA-9mrv-m6p6-5v76/GHSA-9mrv-m6p6-5v76.json | 4 +--- .../07/GHSA-9wfx-xq2g-33pv/GHSA-9wfx-xq2g-33pv.json | 8 ++------ .../07/GHSA-c338-6j9p-j624/GHSA-c338-6j9p-j624.json | 4 +--- .../07/GHSA-c4x2-h5wg-89g7/GHSA-c4x2-h5wg-89g7.json | 4 +--- .../07/GHSA-c73c-584x-2rjh/GHSA-c73c-584x-2rjh.json | 8 ++------ .../07/GHSA-cfjq-497f-x88w/GHSA-cfjq-497f-x88w.json | 8 ++------ .../07/GHSA-cghv-q5fj-8mvp/GHSA-cghv-q5fj-8mvp.json | 4 +--- .../07/GHSA-cx7q-2256-5x68/GHSA-cx7q-2256-5x68.json | 4 +--- .../07/GHSA-cxc2-v3v8-ggcp/GHSA-cxc2-v3v8-ggcp.json | 4 +--- .../07/GHSA-cxwr-rc7w-x3fr/GHSA-cxwr-rc7w-x3fr.json | 4 +--- .../07/GHSA-f38m-5f6j-rh34/GHSA-f38m-5f6j-rh34.json | 4 +--- .../07/GHSA-f3g5-424c-vfvp/GHSA-f3g5-424c-vfvp.json | 8 ++------ .../07/GHSA-f4q4-57gp-qprm/GHSA-f4q4-57gp-qprm.json | 4 +--- .../07/GHSA-ffw9-pm3q-4cmj/GHSA-ffw9-pm3q-4cmj.json | 4 +--- .../07/GHSA-ffxp-v57g-86fj/GHSA-ffxp-v57g-86fj.json | 4 +--- .../07/GHSA-gfj2-5hv5-w3x2/GHSA-gfj2-5hv5-w3x2.json | 4 +--- .../07/GHSA-gjc2-3jfg-ggjp/GHSA-gjc2-3jfg-ggjp.json | 4 +--- .../07/GHSA-gx2q-25q6-r3h9/GHSA-gx2q-25q6-r3h9.json | 4 +--- .../07/GHSA-h3jh-pfjg-56mv/GHSA-h3jh-pfjg-56mv.json | 4 +--- .../07/GHSA-h92h-2qmp-8jfq/GHSA-h92h-2qmp-8jfq.json | 4 +--- .../07/GHSA-hg6q-c3g8-36q3/GHSA-hg6q-c3g8-36q3.json | 8 ++------ .../07/GHSA-hqq5-5427-9hvf/GHSA-hqq5-5427-9hvf.json | 4 +--- .../07/GHSA-j2rf-4mjj-hmjv/GHSA-j2rf-4mjj-hmjv.json | 4 +--- .../07/GHSA-j522-6wqq-55hp/GHSA-j522-6wqq-55hp.json | 4 +--- .../07/GHSA-j955-9fm5-hg33/GHSA-j955-9fm5-hg33.json | 4 +--- .../07/GHSA-jggv-66h3-9g2m/GHSA-jggv-66h3-9g2m.json | 4 +--- .../07/GHSA-jh99-8qr7-cf7m/GHSA-jh99-8qr7-cf7m.json | 4 +--- .../07/GHSA-jrx8-vcr5-x9fg/GHSA-jrx8-vcr5-x9fg.json | 4 +--- .../07/GHSA-jxm8-9pq4-3f8c/GHSA-jxm8-9pq4-3f8c.json | 4 +--- .../07/GHSA-m2j4-gwp6-p4h2/GHSA-m2j4-gwp6-p4h2.json | 4 +--- .../07/GHSA-m8mj-rx2h-m764/GHSA-m8mj-rx2h-m764.json | 4 +--- .../07/GHSA-mc44-gpw6-529m/GHSA-mc44-gpw6-529m.json | 4 +--- .../07/GHSA-mg4p-mp8h-xq7m/GHSA-mg4p-mp8h-xq7m.json | 4 +--- .../07/GHSA-mmwx-xh4f-qfrm/GHSA-mmwx-xh4f-qfrm.json | 4 +--- .../07/GHSA-mphf-mf2v-25ff/GHSA-mphf-mf2v-25ff.json | 4 +--- .../07/GHSA-mqfm-vc95-gg95/GHSA-mqfm-vc95-gg95.json | 4 +--- .../07/GHSA-mr6x-v529-vfj8/GHSA-mr6x-v529-vfj8.json | 4 +--- .../07/GHSA-mxgw-4fpv-6f32/GHSA-mxgw-4fpv-6f32.json | 4 +--- .../07/GHSA-p48j-9rw2-x9q6/GHSA-p48j-9rw2-x9q6.json | 4 +--- .../07/GHSA-p666-f25r-h8ww/GHSA-p666-f25r-h8ww.json | 4 +--- .../07/GHSA-p6vv-528x-4p42/GHSA-p6vv-528x-4p42.json | 4 +--- .../07/GHSA-p9f4-jf4w-hf2c/GHSA-p9f4-jf4w-hf2c.json | 4 +--- .../07/GHSA-pghx-4h7p-74v7/GHSA-pghx-4h7p-74v7.json | 4 +--- .../07/GHSA-pgr9-jh2q-25mp/GHSA-pgr9-jh2q-25mp.json | 4 +--- .../07/GHSA-ph58-3qm4-jpww/GHSA-ph58-3qm4-jpww.json | 4 +--- .../07/GHSA-ph9m-9rj3-8hwg/GHSA-ph9m-9rj3-8hwg.json | 4 +--- .../07/GHSA-ph9w-qjq9-57qq/GHSA-ph9w-qjq9-57qq.json | 4 +--- .../07/GHSA-phvj-gf52-xmvx/GHSA-phvj-gf52-xmvx.json | 4 +--- .../07/GHSA-pjqh-cwf4-prqq/GHSA-pjqh-cwf4-prqq.json | 4 +--- .../07/GHSA-prr3-qqqx-275v/GHSA-prr3-qqqx-275v.json | 8 ++------ .../07/GHSA-pvm7-rp3m-8gh2/GHSA-pvm7-rp3m-8gh2.json | 8 ++------ .../07/GHSA-pxx8-pch9-8mxv/GHSA-pxx8-pch9-8mxv.json | 4 +--- .../07/GHSA-q874-xrmj-fh8q/GHSA-q874-xrmj-fh8q.json | 4 +--- .../07/GHSA-qhmc-hgm8-7h94/GHSA-qhmc-hgm8-7h94.json | 4 +--- .../07/GHSA-qmj9-5xc6-fc5c/GHSA-qmj9-5xc6-fc5c.json | 4 +--- .../07/GHSA-qqww-fq7f-mvvq/GHSA-qqww-fq7f-mvvq.json | 4 +--- .../07/GHSA-qrcp-h79f-78w4/GHSA-qrcp-h79f-78w4.json | 4 +--- .../07/GHSA-qw22-v7wv-prpm/GHSA-qw22-v7wv-prpm.json | 4 +--- .../07/GHSA-r62j-2rmf-5729/GHSA-r62j-2rmf-5729.json | 4 +--- .../07/GHSA-rr43-pphm-pr72/GHSA-rr43-pphm-pr72.json | 4 +--- .../07/GHSA-v23v-q365-pjwr/GHSA-v23v-q365-pjwr.json | 4 +--- .../07/GHSA-v6m4-pjc9-xw4q/GHSA-v6m4-pjc9-xw4q.json | 4 +--- .../07/GHSA-v8c2-c47q-hx7x/GHSA-v8c2-c47q-hx7x.json | 4 +--- .../07/GHSA-v8vg-mxf6-5vgh/GHSA-v8vg-mxf6-5vgh.json | 4 +--- .../07/GHSA-v9x2-v49g-3v4c/GHSA-v9x2-v49g-3v4c.json | 4 +--- .../07/GHSA-vh3j-h3x7-5qfq/GHSA-vh3j-h3x7-5qfq.json | 4 +--- .../07/GHSA-vjrr-3c22-j86f/GHSA-vjrr-3c22-j86f.json | 4 +--- .../07/GHSA-vm9r-p8vp-v2fj/GHSA-vm9r-p8vp-v2fj.json | 4 +--- .../07/GHSA-vqvr-2j5x-jr4h/GHSA-vqvr-2j5x-jr4h.json | 4 +--- .../07/GHSA-vw6g-874r-7fhr/GHSA-vw6g-874r-7fhr.json | 4 +--- .../07/GHSA-w2jx-mj4v-3vrh/GHSA-w2jx-mj4v-3vrh.json | 4 +--- .../07/GHSA-w5h3-hfjg-f58j/GHSA-w5h3-hfjg-f58j.json | 4 +--- .../07/GHSA-wcff-cj33-xw4g/GHSA-wcff-cj33-xw4g.json | 8 ++------ .../07/GHSA-wfjj-ff3q-m3vm/GHSA-wfjj-ff3q-m3vm.json | 4 +--- .../07/GHSA-wjjc-m6gv-3m9m/GHSA-wjjc-m6gv-3m9m.json | 4 +--- .../07/GHSA-wwv2-wrcw-m85g/GHSA-wwv2-wrcw-m85g.json | 8 ++------ .../07/GHSA-x2j4-7cp7-cff7/GHSA-x2j4-7cp7-cff7.json | 4 +--- .../07/GHSA-x327-f57f-h5w6/GHSA-x327-f57f-h5w6.json | 8 ++------ .../07/GHSA-x3mq-2fq2-xjvj/GHSA-x3mq-2fq2-xjvj.json | 4 +--- .../07/GHSA-x3q2-q8jj-f7gj/GHSA-x3q2-q8jj-f7gj.json | 4 +--- .../07/GHSA-x873-cfw9-v3qx/GHSA-x873-cfw9-v3qx.json | 4 +--- .../07/GHSA-xff5-584g-7f5g/GHSA-xff5-584g-7f5g.json | 4 +--- .../07/GHSA-xmwf-p8f2-x77m/GHSA-xmwf-p8f2-x77m.json | 4 +--- .../07/GHSA-xw9w-8g3x-5g2r/GHSA-xw9w-8g3x-5g2r.json | 4 +--- .../07/GHSA-xwhg-vr3r-8xvq/GHSA-xwhg-vr3r-8xvq.json | 4 +--- .../09/GHSA-42gm-5937-wx6g/GHSA-42gm-5937-wx6g.json | 4 +--- .../09/GHSA-43gg-3jq2-xwfh/GHSA-43gg-3jq2-xwfh.json | 4 +--- .../09/GHSA-6prw-46fm-57hj/GHSA-6prw-46fm-57hj.json | 4 +--- .../09/GHSA-pvw2-9h4r-c5cr/GHSA-pvw2-9h4r-c5cr.json | 4 +--- .../10/GHSA-mxwg-58m3-frx5/GHSA-mxwg-58m3-frx5.json | 4 +--- .../11/GHSA-35hg-hj3j-7whc/GHSA-35hg-hj3j-7whc.json | 4 +--- .../11/GHSA-37q9-c8hw-9pvg/GHSA-37q9-c8hw-9pvg.json | 4 +--- .../11/GHSA-5wf4-668w-4pp5/GHSA-5wf4-668w-4pp5.json | 4 +--- .../11/GHSA-65h8-8v7v-fpc7/GHSA-65h8-8v7v-fpc7.json | 4 +--- .../11/GHSA-9f3q-2p9h-qmq9/GHSA-9f3q-2p9h-qmq9.json | 8 ++------ .../11/GHSA-gmfr-f9pg-xc4h/GHSA-gmfr-f9pg-xc4h.json | 4 +--- .../11/GHSA-mpfj-v9c5-37v6/GHSA-mpfj-v9c5-37v6.json | 4 +--- .../11/GHSA-pq25-x76j-wrfp/GHSA-pq25-x76j-wrfp.json | 4 +--- .../11/GHSA-px5q-x4wp-pg95/GHSA-px5q-x4wp-pg95.json | 8 ++------ .../11/GHSA-qgc9-3m4w-r9w2/GHSA-qgc9-3m4w-r9w2.json | 4 +--- .../11/GHSA-qmvv-qv49-vc54/GHSA-qmvv-qv49-vc54.json | 4 +--- .../11/GHSA-vgp5-qc33-722h/GHSA-vgp5-qc33-722h.json | 4 +--- .../12/GHSA-88jc-7q78-58rq/GHSA-88jc-7q78-58rq.json | 4 +--- .../12/GHSA-cm9p-43gv-wxfx/GHSA-cm9p-43gv-wxfx.json | 4 +--- .../12/GHSA-cr4w-fcq2-h6q4/GHSA-cr4w-fcq2-h6q4.json | 4 +--- .../12/GHSA-h976-379x-5948/GHSA-h976-379x-5948.json | 4 +--- .../12/GHSA-qf7x-w4mc-mcp8/GHSA-qf7x-w4mc-mcp8.json | 4 +--- .../01/GHSA-2gpw-j23v-c8gm/GHSA-2gpw-j23v-c8gm.json | 4 +--- .../01/GHSA-2mj4-vmwc-44q4/GHSA-2mj4-vmwc-44q4.json | 4 +--- .../01/GHSA-2pj3-5xr5-pwgr/GHSA-2pj3-5xr5-pwgr.json | 4 +--- .../01/GHSA-3356-grh4-xpc8/GHSA-3356-grh4-xpc8.json | 4 +--- .../01/GHSA-3457-52fq-g3fc/GHSA-3457-52fq-g3fc.json | 4 +--- .../01/GHSA-35g7-p3m9-m7r9/GHSA-35g7-p3m9-m7r9.json | 4 +--- .../01/GHSA-39p7-8vm9-rjp3/GHSA-39p7-8vm9-rjp3.json | 4 +--- .../01/GHSA-3gpp-6hjc-7c4m/GHSA-3gpp-6hjc-7c4m.json | 4 +--- .../01/GHSA-45r7-w6hj-284x/GHSA-45r7-w6hj-284x.json | 4 +--- .../01/GHSA-49jx-ww47-3jcw/GHSA-49jx-ww47-3jcw.json | 4 +--- .../01/GHSA-4fww-p27m-7jcw/GHSA-4fww-p27m-7jcw.json | 4 +--- .../01/GHSA-4qqx-g5v3-6fmx/GHSA-4qqx-g5v3-6fmx.json | 4 +--- .../01/GHSA-4x7c-4p58-rg9q/GHSA-4x7c-4p58-rg9q.json | 4 +--- .../01/GHSA-554c-wmjx-8cxj/GHSA-554c-wmjx-8cxj.json | 4 +--- .../01/GHSA-5ccq-w6wj-jcqq/GHSA-5ccq-w6wj-jcqq.json | 4 +--- .../01/GHSA-5g4x-5gfw-cp2f/GHSA-5g4x-5gfw-cp2f.json | 4 +--- .../01/GHSA-5hc9-87rc-xcgq/GHSA-5hc9-87rc-xcgq.json | 4 +--- .../01/GHSA-5hw3-2hv2-fqmc/GHSA-5hw3-2hv2-fqmc.json | 4 +--- .../01/GHSA-5jfc-qpvr-j873/GHSA-5jfc-qpvr-j873.json | 4 +--- .../01/GHSA-5pph-5f85-479x/GHSA-5pph-5f85-479x.json | 4 +--- .../01/GHSA-5rx9-6x57-42f7/GHSA-5rx9-6x57-42f7.json | 4 +--- .../01/GHSA-62v7-879r-436c/GHSA-62v7-879r-436c.json | 4 +--- .../01/GHSA-6629-529f-2h95/GHSA-6629-529f-2h95.json | 4 +--- .../01/GHSA-66rw-9q89-rr6x/GHSA-66rw-9q89-rr6x.json | 4 +--- .../01/GHSA-6mjm-3w8w-26jh/GHSA-6mjm-3w8w-26jh.json | 4 +--- .../01/GHSA-6x6q-ghqw-xcmg/GHSA-6x6q-ghqw-xcmg.json | 4 +--- .../01/GHSA-7h3q-5g85-47vw/GHSA-7h3q-5g85-47vw.json | 4 +--- .../01/GHSA-7hrc-f2hg-5rgj/GHSA-7hrc-f2hg-5rgj.json | 4 +--- .../01/GHSA-7qp6-c6xr-wmfc/GHSA-7qp6-c6xr-wmfc.json | 4 +--- .../01/GHSA-7vc4-ggq5-xrmg/GHSA-7vc4-ggq5-xrmg.json | 4 +--- .../01/GHSA-7w5v-94w3-9cq7/GHSA-7w5v-94w3-9cq7.json | 8 ++------ .../01/GHSA-7wc5-3phx-38h6/GHSA-7wc5-3phx-38h6.json | 4 +--- .../01/GHSA-8jq4-8fq5-jfp2/GHSA-8jq4-8fq5-jfp2.json | 4 +--- .../01/GHSA-8qwh-h2px-grw6/GHSA-8qwh-h2px-grw6.json | 4 +--- .../01/GHSA-8x5q-8c77-vq49/GHSA-8x5q-8c77-vq49.json | 4 +--- .../01/GHSA-9432-j67m-gv59/GHSA-9432-j67m-gv59.json | 4 +--- .../01/GHSA-995h-6wg6-p6f7/GHSA-995h-6wg6-p6f7.json | 4 +--- .../01/GHSA-9vqq-hghw-wh47/GHSA-9vqq-hghw-wh47.json | 4 +--- .../01/GHSA-c79f-c6jm-4rrj/GHSA-c79f-c6jm-4rrj.json | 4 +--- .../01/GHSA-cg47-x3p7-3jwj/GHSA-cg47-x3p7-3jwj.json | 4 +--- .../01/GHSA-ch8j-q2rq-5c87/GHSA-ch8j-q2rq-5c87.json | 4 +--- .../01/GHSA-chq7-m4fp-95ff/GHSA-chq7-m4fp-95ff.json | 4 +--- .../01/GHSA-cpj5-8p43-2gqc/GHSA-cpj5-8p43-2gqc.json | 4 +--- .../01/GHSA-f28r-c98m-qr3r/GHSA-f28r-c98m-qr3r.json | 4 +--- .../01/GHSA-f6rh-cxxv-wq7g/GHSA-f6rh-cxxv-wq7g.json | 4 +--- .../01/GHSA-f84x-96pr-hfjw/GHSA-f84x-96pr-hfjw.json | 4 +--- .../01/GHSA-f99q-3688-gw8p/GHSA-f99q-3688-gw8p.json | 4 +--- .../01/GHSA-frvj-8w9j-wxvc/GHSA-frvj-8w9j-wxvc.json | 4 +--- .../01/GHSA-g64c-rxmq-vwm7/GHSA-g64c-rxmq-vwm7.json | 4 +--- .../01/GHSA-g892-qv2j-3m88/GHSA-g892-qv2j-3m88.json | 4 +--- .../01/GHSA-gmq4-pgww-w7c9/GHSA-gmq4-pgww-w7c9.json | 4 +--- .../01/GHSA-gpcx-87wj-hh4w/GHSA-gpcx-87wj-hh4w.json | 4 +--- .../01/GHSA-gpxg-5hhc-fxc2/GHSA-gpxg-5hhc-fxc2.json | 4 +--- .../01/GHSA-h3h4-3r2q-9m76/GHSA-h3h4-3r2q-9m76.json | 4 +--- .../01/GHSA-h6h4-9666-mq74/GHSA-h6h4-9666-mq74.json | 4 +--- .../01/GHSA-hqr2-p4fq-45vv/GHSA-hqr2-p4fq-45vv.json | 4 +--- .../01/GHSA-hv2m-9xxw-fjr7/GHSA-hv2m-9xxw-fjr7.json | 4 +--- .../01/GHSA-hxx9-636q-j4p5/GHSA-hxx9-636q-j4p5.json | 4 +--- .../01/GHSA-jg95-rrp5-h9rc/GHSA-jg95-rrp5-h9rc.json | 4 +--- .../01/GHSA-m8q2-vq96-6mwj/GHSA-m8q2-vq96-6mwj.json | 4 +--- .../01/GHSA-mj4g-q8gh-hp8q/GHSA-mj4g-q8gh-hp8q.json | 4 +--- .../01/GHSA-p2c4-5gxh-4qv6/GHSA-p2c4-5gxh-4qv6.json | 4 +--- .../01/GHSA-p4fh-pf6m-qq74/GHSA-p4fh-pf6m-qq74.json | 4 +--- .../01/GHSA-p576-j8jp-6qr7/GHSA-p576-j8jp-6qr7.json | 4 +--- .../01/GHSA-ph43-q49h-r73x/GHSA-ph43-q49h-r73x.json | 4 +--- .../01/GHSA-pjx3-rq8r-cfr8/GHSA-pjx3-rq8r-cfr8.json | 4 +--- .../01/GHSA-pp8m-mqhc-4cj3/GHSA-pp8m-mqhc-4cj3.json | 4 +--- .../01/GHSA-prq7-8x29-rfm8/GHSA-prq7-8x29-rfm8.json | 4 +--- .../01/GHSA-px83-ph6q-f3rv/GHSA-px83-ph6q-f3rv.json | 4 +--- .../01/GHSA-q257-jh5g-vh5c/GHSA-q257-jh5g-vh5c.json | 4 +--- .../01/GHSA-r3j2-7g54-8mxw/GHSA-r3j2-7g54-8mxw.json | 4 +--- .../01/GHSA-r74c-ppq4-773h/GHSA-r74c-ppq4-773h.json | 4 +--- .../01/GHSA-rmqp-v4mv-mmxm/GHSA-rmqp-v4mv-mmxm.json | 4 +--- .../01/GHSA-rp39-4v75-4gx6/GHSA-rp39-4v75-4gx6.json | 4 +--- .../01/GHSA-rq58-x623-8hc9/GHSA-rq58-x623-8hc9.json | 4 +--- .../01/GHSA-rr65-f966-j89f/GHSA-rr65-f966-j89f.json | 4 +--- .../01/GHSA-v433-p5gw-hpq7/GHSA-v433-p5gw-hpq7.json | 4 +--- .../01/GHSA-v5vf-vv9f-927q/GHSA-v5vf-vv9f-927q.json | 4 +--- .../01/GHSA-v6ch-vjv9-2847/GHSA-v6ch-vjv9-2847.json | 4 +--- .../01/GHSA-vg5w-63rx-p8mm/GHSA-vg5w-63rx-p8mm.json | 4 +--- .../01/GHSA-vj5w-88wc-3p42/GHSA-vj5w-88wc-3p42.json | 4 +--- .../01/GHSA-vmjq-6j74-qm6f/GHSA-vmjq-6j74-qm6f.json | 4 +--- .../01/GHSA-vqm2-ch9v-r2fm/GHSA-vqm2-ch9v-r2fm.json | 4 +--- .../01/GHSA-w4cx-v96x-c4g8/GHSA-w4cx-v96x-c4g8.json | 4 +--- .../01/GHSA-w62c-99j3-8frh/GHSA-w62c-99j3-8frh.json | 4 +--- .../01/GHSA-w7wh-q7m2-wjxw/GHSA-w7wh-q7m2-wjxw.json | 4 +--- .../01/GHSA-wgpq-5gwx-2wxh/GHSA-wgpq-5gwx-2wxh.json | 4 +--- .../01/GHSA-wmmh-q5mq-35hq/GHSA-wmmh-q5mq-35hq.json | 4 +--- .../01/GHSA-wvg7-h75h-6w38/GHSA-wvg7-h75h-6w38.json | 4 +--- .../01/GHSA-x3px-p2f4-4p27/GHSA-x3px-p2f4-4p27.json | 4 +--- .../01/GHSA-x7w4-2pc2-rw2m/GHSA-x7w4-2pc2-rw2m.json | 4 +--- .../01/GHSA-x9h5-22vg-fr6q/GHSA-x9h5-22vg-fr6q.json | 4 +--- .../01/GHSA-xqqr-m249-5wxh/GHSA-xqqr-m249-5wxh.json | 4 +--- .../01/GHSA-xrr5-3hrr-35jx/GHSA-xrr5-3hrr-35jx.json | 4 +--- .../01/GHSA-xwgm-fp55-vxq4/GHSA-xwgm-fp55-vxq4.json | 4 +--- .../01/GHSA-xxpq-f82j-29cp/GHSA-xxpq-f82j-29cp.json | 4 +--- .../02/GHSA-5x44-jjpr-vq97/GHSA-5x44-jjpr-vq97.json | 4 +--- .../02/GHSA-6qcj-7675-pvc9/GHSA-6qcj-7675-pvc9.json | 4 +--- .../02/GHSA-74cc-qrjm-qwjc/GHSA-74cc-qrjm-qwjc.json | 4 +--- .../02/GHSA-fh9m-5jrx-26qp/GHSA-fh9m-5jrx-26qp.json | 4 +--- .../02/GHSA-fq5p-5w22-52xh/GHSA-fq5p-5w22-52xh.json | 4 +--- .../02/GHSA-fvwr-2rpv-2cq7/GHSA-fvwr-2rpv-2cq7.json | 4 +--- .../02/GHSA-jcr4-843q-3v56/GHSA-jcr4-843q-3v56.json | 4 +--- .../02/GHSA-p6jp-vhc2-xhh9/GHSA-p6jp-vhc2-xhh9.json | 8 ++------ .../02/GHSA-q74f-hvfr-7jqc/GHSA-q74f-hvfr-7jqc.json | 4 +--- .../02/GHSA-rqjh-2xp3-wp52/GHSA-rqjh-2xp3-wp52.json | 4 +--- .../02/GHSA-vcf7-32c8-3rmw/GHSA-vcf7-32c8-3rmw.json | 4 +--- .../02/GHSA-vqp6-3hff-2h3w/GHSA-vqp6-3hff-2h3w.json | 4 +--- .../02/GHSA-vw4j-wqq5-5pv6/GHSA-vw4j-wqq5-5pv6.json | 4 +--- .../02/GHSA-x2hm-ghg4-c67m/GHSA-x2hm-ghg4-c67m.json | 4 +--- .../03/GHSA-9r72-hcvp-4c2x/GHSA-9r72-hcvp-4c2x.json | 4 +--- .../11/GHSA-2hmr-w3hv-h898/GHSA-2hmr-w3hv-h898.json | 4 +--- .../11/GHSA-2r79-jc6j-hh65/GHSA-2r79-jc6j-hh65.json | 4 +--- .../11/GHSA-3w3w-vm78-84r8/GHSA-3w3w-vm78-84r8.json | 4 +--- .../11/GHSA-53v5-7h5p-m6g9/GHSA-53v5-7h5p-m6g9.json | 8 ++------ .../11/GHSA-569x-g759-whjj/GHSA-569x-g759-whjj.json | 4 +--- .../11/GHSA-596w-g2cr-x93q/GHSA-596w-g2cr-x93q.json | 4 +--- .../11/GHSA-75j8-mr4c-4x59/GHSA-75j8-mr4c-4x59.json | 4 +--- .../11/GHSA-857f-w8mj-5g2g/GHSA-857f-w8mj-5g2g.json | 4 +--- .../11/GHSA-8993-7526-7h8g/GHSA-8993-7526-7h8g.json | 4 +--- .../11/GHSA-9752-mq4c-65h9/GHSA-9752-mq4c-65h9.json | 4 +--- .../11/GHSA-gp9m-gvxj-6q3h/GHSA-gp9m-gvxj-6q3h.json | 4 +--- .../11/GHSA-h5g7-j26q-32pp/GHSA-h5g7-j26q-32pp.json | 4 +--- .../11/GHSA-mgqv-g9mm-hg88/GHSA-mgqv-g9mm-hg88.json | 4 +--- .../11/GHSA-pg75-xxxv-pv8j/GHSA-pg75-xxxv-pv8j.json | 4 +--- .../11/GHSA-q5h6-hfv2-xr6w/GHSA-q5h6-hfv2-xr6w.json | 4 +--- .../06/GHSA-2f9c-gcww-48v7/GHSA-2f9c-gcww-48v7.json | 12 +++--------- .../06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json | 12 +++--------- .../06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json | 12 +++--------- .../06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json | 12 +++--------- .../06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json | 12 +++--------- .../06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json | 12 +++--------- .../06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json | 12 +++--------- .../06/GHSA-4rhg-qwrc-fj7f/GHSA-4rhg-qwrc-fj7f.json | 4 +--- .../06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json | 12 +++--------- .../06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json | 12 +++--------- .../06/GHSA-6jjp-xcg6-63r6/GHSA-6jjp-xcg6-63r6.json | 8 ++------ .../06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json | 12 +++--------- .../06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json | 12 +++--------- .../06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json | 4 +--- .../06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json | 4 +--- .../06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json | 12 +++--------- .../06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json | 12 +++--------- .../06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json | 12 +++--------- .../06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json | 4 +--- .../06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json | 12 +++--------- .../06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json | 12 +++--------- .../06/GHSA-c4p5-rq8v-r8c2/GHSA-c4p5-rq8v-r8c2.json | 4 +--- .../06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json | 4 +--- .../06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json | 4 +--- .../06/GHSA-g6g5-9p5r-64mp/GHSA-g6g5-9p5r-64mp.json | 8 ++------ .../06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json | 12 +++--------- .../06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json | 12 +++--------- .../06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json | 12 +++--------- .../06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json | 12 +++--------- .../06/GHSA-jhwr-fg7p-675f/GHSA-jhwr-fg7p-675f.json | 8 ++------ .../06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json | 12 +++--------- .../06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json | 12 +++--------- .../06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json | 4 +--- .../06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json | 12 +++--------- .../06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json | 12 +++--------- .../06/GHSA-rpr4-fpwh-9vfr/GHSA-rpr4-fpwh-9vfr.json | 8 ++------ .../06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json | 4 +--- .../06/GHSA-v247-54w9-fjrm/GHSA-v247-54w9-fjrm.json | 4 +--- .../06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json | 12 +++--------- .../06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json | 12 +++--------- .../06/GHSA-w5cf-hpvv-9q7v/GHSA-w5cf-hpvv-9q7v.json | 4 +--- .../06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json | 4 +--- .../06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json | 12 +++--------- .../06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json | 12 +++--------- .../06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json | 12 +++--------- 895 files changed, 1517 insertions(+), 4551 deletions(-) diff --git a/advisories/github-reviewed/2020/09/GHSA-56r9-v65c-34jm/GHSA-56r9-v65c-34jm.json b/advisories/github-reviewed/2020/09/GHSA-56r9-v65c-34jm/GHSA-56r9-v65c-34jm.json index 93fae60bc97..a0aea5d42ec 100644 --- a/advisories/github-reviewed/2020/09/GHSA-56r9-v65c-34jm/GHSA-56r9-v65c-34jm.json +++ b/advisories/github-reviewed/2020/09/GHSA-56r9-v65c-34jm/GHSA-56r9-v65c-34jm.json @@ -3,14 +3,10 @@ "id": "GHSA-56r9-v65c-34jm", "modified": "2023-07-13T21:05:58Z", "published": "2020-09-03T02:33:37Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in radicjs", "details": "Version 0.2.1 of `radicjs` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised. Users may downgrade to 0.2.0", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -29,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:41:24Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-84qj-9qf2-q92r/GHSA-84qj-9qf2-q92r.json b/advisories/github-reviewed/2020/09/GHSA-84qj-9qf2-q92r/GHSA-84qj-9qf2-q92r.json index ecb9b4e3725..60151b5eafb 100644 --- a/advisories/github-reviewed/2020/09/GHSA-84qj-9qf2-q92r/GHSA-84qj-9qf2-q92r.json +++ b/advisories/github-reviewed/2020/09/GHSA-84qj-9qf2-q92r/GHSA-84qj-9qf2-q92r.json @@ -3,14 +3,10 @@ "id": "GHSA-84qj-9qf2-q92r", "modified": "2023-07-13T21:06:36Z", "published": "2020-09-03T00:32:30Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in pm-controls", "details": "Version 1.1.8 of `pm-controls` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised. Users may downgrade to 1.1.7", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -29,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:41:38Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-2hw2-h3mf-c2j9/GHSA-2hw2-h3mf-c2j9.json b/advisories/github-reviewed/2022/05/GHSA-2hw2-h3mf-c2j9/GHSA-2hw2-h3mf-c2j9.json index 34445f62a40..9bcda2729cd 100644 --- a/advisories/github-reviewed/2022/05/GHSA-2hw2-h3mf-c2j9/GHSA-2hw2-h3mf-c2j9.json +++ b/advisories/github-reviewed/2022/05/GHSA-2hw2-h3mf-c2j9/GHSA-2hw2-h3mf-c2j9.json @@ -116,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-26T01:14:09Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-2jcw-r79x-4r5v/GHSA-2jcw-r79x-4r5v.json b/advisories/github-reviewed/2022/05/GHSA-2jcw-r79x-4r5v/GHSA-2jcw-r79x-4r5v.json index 0840ba746c2..7e0554f09cd 100644 --- a/advisories/github-reviewed/2022/05/GHSA-2jcw-r79x-4r5v/GHSA-2jcw-r79x-4r5v.json +++ b/advisories/github-reviewed/2022/05/GHSA-2jcw-r79x-4r5v/GHSA-2jcw-r79x-4r5v.json @@ -8,9 +8,7 @@ ], "summary": "Moodle does not set the RISK_XSS bit for graders", "details": "access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-35pr-gqm6-r366/GHSA-35pr-gqm6-r366.json b/advisories/github-reviewed/2022/05/GHSA-35pr-gqm6-r366/GHSA-35pr-gqm6-r366.json index a19a4abee20..b7e9d29c324 100644 --- a/advisories/github-reviewed/2022/05/GHSA-35pr-gqm6-r366/GHSA-35pr-gqm6-r366.json +++ b/advisories/github-reviewed/2022/05/GHSA-35pr-gqm6-r366/GHSA-35pr-gqm6-r366.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information", "details": "message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-36cm-vrqh-8p98/GHSA-36cm-vrqh-8p98.json b/advisories/github-reviewed/2022/05/GHSA-36cm-vrqh-8p98/GHSA-36cm-vrqh-8p98.json index 20440f3a548..614dce056f0 100644 --- a/advisories/github-reviewed/2022/05/GHSA-36cm-vrqh-8p98/GHSA-36cm-vrqh-8p98.json +++ b/advisories/github-reviewed/2022/05/GHSA-36cm-vrqh-8p98/GHSA-36cm-vrqh-8p98.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to cause a denial of service", "details": "filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -121,9 +119,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-25T20:55:36Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-44xp-wj24-9xxj/GHSA-44xp-wj24-9xxj.json b/advisories/github-reviewed/2022/05/GHSA-44xp-wj24-9xxj/GHSA-44xp-wj24-9xxj.json index 7675670b1bc..0c0f1366f54 100644 --- a/advisories/github-reviewed/2022/05/GHSA-44xp-wj24-9xxj/GHSA-44xp-wj24-9xxj.json +++ b/advisories/github-reviewed/2022/05/GHSA-44xp-wj24-9xxj/GHSA-44xp-wj24-9xxj.json @@ -116,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-26T01:54:41Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-454r-4cjv-vc9h/GHSA-454r-4cjv-vc9h.json b/advisories/github-reviewed/2022/05/GHSA-454r-4cjv-vc9h/GHSA-454r-4cjv-vc9h.json index fe6c7fc3cb3..ad87dde35db 100644 --- a/advisories/github-reviewed/2022/05/GHSA-454r-4cjv-vc9h/GHSA-454r-4cjv-vc9h.json +++ b/advisories/github-reviewed/2022/05/GHSA-454r-4cjv-vc9h/GHSA-454r-4cjv-vc9h.json @@ -116,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-26T01:55:04Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-4ppg-2mx6-fqx9/GHSA-4ppg-2mx6-fqx9.json b/advisories/github-reviewed/2022/05/GHSA-4ppg-2mx6-fqx9/GHSA-4ppg-2mx6-fqx9.json index f529bece85a..bccee210d48 100644 --- a/advisories/github-reviewed/2022/05/GHSA-4ppg-2mx6-fqx9/GHSA-4ppg-2mx6-fqx9.json +++ b/advisories/github-reviewed/2022/05/GHSA-4ppg-2mx6-fqx9/GHSA-4ppg-2mx6-fqx9.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to bypass intended login restrictions", "details": "login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -117,9 +115,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-01-26T01:10:53Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-622h-cjgg-5mx6/GHSA-622h-cjgg-5mx6.json b/advisories/github-reviewed/2022/05/GHSA-622h-cjgg-5mx6/GHSA-622h-cjgg-5mx6.json index bfa08e26063..a7ea5a7d36f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-622h-cjgg-5mx6/GHSA-622h-cjgg-5mx6.json +++ b/advisories/github-reviewed/2022/05/GHSA-622h-cjgg-5mx6/GHSA-622h-cjgg-5mx6.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to bypass file-management restrictions", "details": "files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -117,9 +115,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-26T01:13:10Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-688p-pgj4-77hh/GHSA-688p-pgj4-77hh.json b/advisories/github-reviewed/2022/05/GHSA-688p-pgj4-77hh/GHSA-688p-pgj4-77hh.json index ca1f7f9556b..35c05d855b0 100644 --- a/advisories/github-reviewed/2022/05/GHSA-688p-pgj4-77hh/GHSA-688p-pgj4-77hh.json +++ b/advisories/github-reviewed/2022/05/GHSA-688p-pgj4-77hh/GHSA-688p-pgj4-77hh.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to obtain sensitive course-structure information", "details": "lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-6r7x-6q98-qcqp/GHSA-6r7x-6q98-qcqp.json b/advisories/github-reviewed/2022/05/GHSA-6r7x-6q98-qcqp/GHSA-6r7x-6q98-qcqp.json index cd54529a2c5..c2d22740a1a 100644 --- a/advisories/github-reviewed/2022/05/GHSA-6r7x-6q98-qcqp/GHSA-6r7x-6q98-qcqp.json +++ b/advisories/github-reviewed/2022/05/GHSA-6r7x-6q98-qcqp/GHSA-6r7x-6q98-qcqp.json @@ -8,9 +8,7 @@ ], "summary": "Moodle does not set the RISK_XSS bit for graders", "details": "mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-6wfj-2mw7-p5cg/GHSA-6wfj-2mw7-p5cg.json b/advisories/github-reviewed/2022/05/GHSA-6wfj-2mw7-p5cg/GHSA-6wfj-2mw7-p5cg.json index c30f649a3be..267280e28c6 100644 --- a/advisories/github-reviewed/2022/05/GHSA-6wfj-2mw7-p5cg/GHSA-6wfj-2mw7-p5cg.json +++ b/advisories/github-reviewed/2022/05/GHSA-6wfj-2mw7-p5cg/GHSA-6wfj-2mw7-p5cg.json @@ -8,9 +8,7 @@ ], "summary": "phpMyAdmin micro history Implementation XSS Vulnerability", "details": "Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-79jf-ccm8-43w7/GHSA-79jf-ccm8-43w7.json b/advisories/github-reviewed/2022/05/GHSA-79jf-ccm8-43w7/GHSA-79jf-ccm8-43w7.json index 81165a22a9a..50a89135ae7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-79jf-ccm8-43w7/GHSA-79jf-ccm8-43w7.json +++ b/advisories/github-reviewed/2022/05/GHSA-79jf-ccm8-43w7/GHSA-79jf-ccm8-43w7.json @@ -8,9 +8,7 @@ ], "summary": "ceph-deploy uses world-readable permissions on client.admin key", "details": "The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for `/etc/ceph/ceph.client.admin.keyring`, which allows local users to obtain sensitive information by reading the file.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-9fmw-m4qx-6cq8/GHSA-9fmw-m4qx-6cq8.json b/advisories/github-reviewed/2022/05/GHSA-9fmw-m4qx-6cq8/GHSA-9fmw-m4qx-6cq8.json index e65965fb312..4782a540e5f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-9fmw-m4qx-6cq8/GHSA-9fmw-m4qx-6cq8.json +++ b/advisories/github-reviewed/2022/05/GHSA-9fmw-m4qx-6cq8/GHSA-9fmw-m4qx-6cq8.json @@ -8,9 +8,7 @@ ], "summary": "Moodle cross-site scripting (XSS) vulnerability", "details": "Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-c87j-9rrq-h3j8/GHSA-c87j-9rrq-h3j8.json b/advisories/github-reviewed/2022/05/GHSA-c87j-9rrq-h3j8/GHSA-c87j-9rrq-h3j8.json index ab7b7946f96..6da379f367c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-c87j-9rrq-h3j8/GHSA-c87j-9rrq-h3j8.json +++ b/advisories/github-reviewed/2022/05/GHSA-c87j-9rrq-h3j8/GHSA-c87j-9rrq-h3j8.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to trigger the generation of arbitrary messages", "details": "The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-cm4r-58pj-h2ph/GHSA-cm4r-58pj-h2ph.json b/advisories/github-reviewed/2022/05/GHSA-cm4r-58pj-h2ph/GHSA-cm4r-58pj-h2ph.json index 8575e0448da..fa4a4149c33 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cm4r-58pj-h2ph/GHSA-cm4r-58pj-h2ph.json +++ b/advisories/github-reviewed/2022/05/GHSA-cm4r-58pj-h2ph/GHSA-cm4r-58pj-h2ph.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to extract archives to arbitrary directories", "details": "mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json b/advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json index 300c8f9c8ae..bcc18757569 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json +++ b/advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json @@ -8,9 +8,7 @@ ], "summary": "OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting", "details": "Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-fp4h-j22r-vwcv/GHSA-fp4h-j22r-vwcv.json b/advisories/github-reviewed/2022/05/GHSA-fp4h-j22r-vwcv/GHSA-fp4h-j22r-vwcv.json index b94c2cd9452..29ed77aaa99 100644 --- a/advisories/github-reviewed/2022/05/GHSA-fp4h-j22r-vwcv/GHSA-fp4h-j22r-vwcv.json +++ b/advisories/github-reviewed/2022/05/GHSA-fp4h-j22r-vwcv/GHSA-fp4h-j22r-vwcv.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers to obtain sensitive course information", "details": "lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows remote attackers to obtain sensitive course information via unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -109,9 +107,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-25T20:56:28Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-fqrg-vmvj-jv3x/GHSA-fqrg-vmvj-jv3x.json b/advisories/github-reviewed/2022/05/GHSA-fqrg-vmvj-jv3x/GHSA-fqrg-vmvj-jv3x.json index 69f92464e02..d66e7c921ef 100644 --- a/advisories/github-reviewed/2022/05/GHSA-fqrg-vmvj-jv3x/GHSA-fqrg-vmvj-jv3x.json +++ b/advisories/github-reviewed/2022/05/GHSA-fqrg-vmvj-jv3x/GHSA-fqrg-vmvj-jv3x.json @@ -8,9 +8,7 @@ ], "summary": "Moodle allows attackers obtain full-name information", "details": "The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-g892-9h8m-r69r/GHSA-g892-9h8m-r69r.json b/advisories/github-reviewed/2022/05/GHSA-g892-9h8m-r69r/GHSA-g892-9h8m-r69r.json index 80333d0eb5c..7992491d301 100644 --- a/advisories/github-reviewed/2022/05/GHSA-g892-9h8m-r69r/GHSA-g892-9h8m-r69r.json +++ b/advisories/github-reviewed/2022/05/GHSA-g892-9h8m-r69r/GHSA-g892-9h8m-r69r.json @@ -8,9 +8,7 @@ ], "summary": "Libcloud does not properly scrub data when destroying a DigitalOcean node", "details": "Libcloud 0.12.3 through 0.13.2 does not set the `scrub_data parameter` for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-gphj-63h8-r9vq/GHSA-gphj-63h8-r9vq.json b/advisories/github-reviewed/2022/05/GHSA-gphj-63h8-r9vq/GHSA-gphj-63h8-r9vq.json index 48a8fac8f88..56093b50a99 100644 --- a/advisories/github-reviewed/2022/05/GHSA-gphj-63h8-r9vq/GHSA-gphj-63h8-r9vq.json +++ b/advisories/github-reviewed/2022/05/GHSA-gphj-63h8-r9vq/GHSA-gphj-63h8-r9vq.json @@ -8,9 +8,7 @@ ], "summary": "Moodle directory traversal vulnerability", "details": "Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-h798-h7ff-93xv/GHSA-h798-h7ff-93xv.json b/advisories/github-reviewed/2022/05/GHSA-h798-h7ff-93xv/GHSA-h798-h7ff-93xv.json index b63e7775f52..2507788d985 100644 --- a/advisories/github-reviewed/2022/05/GHSA-h798-h7ff-93xv/GHSA-h798-h7ff-93xv.json +++ b/advisories/github-reviewed/2022/05/GHSA-h798-h7ff-93xv/GHSA-h798-h7ff-93xv.json @@ -8,9 +8,7 @@ ], "summary": "Moodle Arbitrary Redirect", "details": "Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-hhq7-jf2p-hw9c/GHSA-hhq7-jf2p-hw9c.json b/advisories/github-reviewed/2022/05/GHSA-hhq7-jf2p-hw9c/GHSA-hhq7-jf2p-hw9c.json index a1dfac51cf2..05fe875a999 100644 --- a/advisories/github-reviewed/2022/05/GHSA-hhq7-jf2p-hw9c/GHSA-hhq7-jf2p-hw9c.json +++ b/advisories/github-reviewed/2022/05/GHSA-hhq7-jf2p-hw9c/GHSA-hhq7-jf2p-hw9c.json @@ -8,9 +8,7 @@ ], "summary": "Moodle multiple cross-site request forgery (CSRF) vulnerabilities", "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allow remote attackers to hijack the authentication of unspecified victims.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-mfmj-gwg3-vhw7/GHSA-mfmj-gwg3-vhw7.json b/advisories/github-reviewed/2022/05/GHSA-mfmj-gwg3-vhw7/GHSA-mfmj-gwg3-vhw7.json index 65b9c268c40..9701b8b9451 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mfmj-gwg3-vhw7/GHSA-mfmj-gwg3-vhw7.json +++ b/advisories/github-reviewed/2022/05/GHSA-mfmj-gwg3-vhw7/GHSA-mfmj-gwg3-vhw7.json @@ -8,9 +8,7 @@ ], "summary": "OpenStack Compute (nova) allows remote authenticated users to cause a denial of service", "details": "OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -98,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-02-08T18:00:14Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-mm9q-3847-m48x/GHSA-mm9q-3847-m48x.json b/advisories/github-reviewed/2022/05/GHSA-mm9q-3847-m48x/GHSA-mm9q-3847-m48x.json index b563c27dc8e..6fc1c4ef675 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mm9q-3847-m48x/GHSA-mm9q-3847-m48x.json +++ b/advisories/github-reviewed/2022/05/GHSA-mm9q-3847-m48x/GHSA-mm9q-3847-m48x.json @@ -140,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-26T01:54:17Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-pvr5-84gr-g985/GHSA-pvr5-84gr-g985.json b/advisories/github-reviewed/2022/05/GHSA-pvr5-84gr-g985/GHSA-pvr5-84gr-g985.json index b60e91375ba..b110cc42844 100644 --- a/advisories/github-reviewed/2022/05/GHSA-pvr5-84gr-g985/GHSA-pvr5-84gr-g985.json +++ b/advisories/github-reviewed/2022/05/GHSA-pvr5-84gr-g985/GHSA-pvr5-84gr-g985.json @@ -8,9 +8,7 @@ ], "summary": "phpMyAdmin Implementation XSS Vulnerability on Server Monitor Page", "details": "Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the `libraries/DatabaseInterface.class.php` code for SQL debug output and the `js/server_status_monitor.js` code for the server monitor page.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-rpc6-h455-3rx5/GHSA-rpc6-h455-3rx5.json b/advisories/github-reviewed/2022/05/GHSA-rpc6-h455-3rx5/GHSA-rpc6-h455-3rx5.json index df8c9495b1c..0cf12d8ced0 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rpc6-h455-3rx5/GHSA-rpc6-h455-3rx5.json +++ b/advisories/github-reviewed/2022/05/GHSA-rpc6-h455-3rx5/GHSA-rpc6-h455-3rx5.json @@ -8,9 +8,7 @@ ], "summary": "Celery local privilege escalation vulnerability", "details": "Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, celeryd-multi, and celeryev, which allows local users to gain privileges via vectors involving crafted code that is executed by the worker process.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-v3wp-35g3-m9mm/GHSA-v3wp-35g3-m9mm.json b/advisories/github-reviewed/2022/05/GHSA-v3wp-35g3-m9mm/GHSA-v3wp-35g3-m9mm.json index 4c2cdc20273..16409e93478 100644 --- a/advisories/github-reviewed/2022/05/GHSA-v3wp-35g3-m9mm/GHSA-v3wp-35g3-m9mm.json +++ b/advisories/github-reviewed/2022/05/GHSA-v3wp-35g3-m9mm/GHSA-v3wp-35g3-m9mm.json @@ -8,9 +8,7 @@ ], "summary": "Moodle does not consider the moodle/tag:flag capability", "details": "tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the \"Flag as inappropriate\" feature.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -109,9 +107,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-25T20:57:19Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-x8xr-rm9r-7mvf/GHSA-x8xr-rm9r-7mvf.json b/advisories/github-reviewed/2022/05/GHSA-x8xr-rm9r-7mvf/GHSA-x8xr-rm9r-7mvf.json index 4d300608a9b..fb2efd6d1da 100644 --- a/advisories/github-reviewed/2022/05/GHSA-x8xr-rm9r-7mvf/GHSA-x8xr-rm9r-7mvf.json +++ b/advisories/github-reviewed/2022/05/GHSA-x8xr-rm9r-7mvf/GHSA-x8xr-rm9r-7mvf.json @@ -8,9 +8,7 @@ ], "summary": "OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity", "details": "OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/07/GHSA-f2gr-7299-487h/GHSA-f2gr-7299-487h.json b/advisories/github-reviewed/2022/07/GHSA-f2gr-7299-487h/GHSA-f2gr-7299-487h.json index 1cc8483ae56..222e8dc157e 100644 --- a/advisories/github-reviewed/2022/07/GHSA-f2gr-7299-487h/GHSA-f2gr-7299-487h.json +++ b/advisories/github-reviewed/2022/07/GHSA-f2gr-7299-487h/GHSA-f2gr-7299-487h.json @@ -3,14 +3,10 @@ "id": "GHSA-f2gr-7299-487h", "modified": "2022-07-06T20:06:56Z", "published": "2022-07-06T20:06:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "DOS and excessive memory usage when passing untrusted user input to to dag import", "details": "### Impact\ngo-ipfs nodes crash when trying to import certain malformed CAR files due to an issue in the go-car dependency. This impacts nodes running `ipfs dag import` on untrusted user inputs, for example, pinning services with a car ingest endpoint.\nThis include the corresponding [HTTP RPC API `v0/dag/import`](https://docs.ipfs.io/reference/http/api/#api-v0-dag-import) endpoint.\n\nAn attacker controlling the car file passed in can also make the node allocate arbitrary sized buffers creating memory exhaustion attacks.\n\n### Patches\n0.13.1, 0.14 and later.\n\n#### Forks\nFor those running on forked versions of go-ipfs, simply updating the version of `github.com/ipld/go-car/v2` you are using to >= v2.4.0 should resolve the issue.\n\n#### Libraries consumers\nAny users of libraries within the go-ipfs ecosystem, even if not the go-ipfs package or binary itself, may be affected and should upgrade their dependency on go-car.\n\nYou can check if your Go module has a dependency on go-car by running a command such as `go mod graph | grep go-car` in your module root.\n\nNote: if you are using other libraries, some parts of go-car (`github.com/ipld/go-car/v2/index/...`) have not fully been fixed yet. Please see [go-car's security advisory](https://github.com/ipld/go-car/security/advisories/GHSA-9x4h-8wgm-8xfg) for more information. go-ipfs do not make use of this code.\n\n### Workarounds\nThe best way to work around this is to control exposure to the [HTTP RPC API endpoint for CAR imports](https://docs.ipfs.io/reference/http/api/#api-v0-dag-import) to only work with trusted data.\n\nYou can also validate that the car will not crash go-ipfs by running `car verify` on it first (`go install github.com/ipld/go-car/cmd/car@latest`).\n\n### References\nSee also the [go-car security advisory](https://github.com/ipld/go-car/security/advisories/GHSA-9x4h-8wgm-8xfg).\n\n### For more information\nIf you have any questions or comments about this advisory:\n1. Ask in the [IPFS Discourse](discuss.ipfs.io/)\n1. Ask in the [IPFS Discord #ipld-chatter](https://discord.gg/ipfs)\n1. Open an issue in [go-ipfs](https://github.com/ipfs/go-ipfs)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/01/GHSA-j94p-hv25-rm5g/GHSA-j94p-hv25-rm5g.json b/advisories/github-reviewed/2023/01/GHSA-j94p-hv25-rm5g/GHSA-j94p-hv25-rm5g.json index 750be6ff318..48b588f7eb0 100644 --- a/advisories/github-reviewed/2023/01/GHSA-j94p-hv25-rm5g/GHSA-j94p-hv25-rm5g.json +++ b/advisories/github-reviewed/2023/01/GHSA-j94p-hv25-rm5g/GHSA-j94p-hv25-rm5g.json @@ -65,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-01-03T12:28:06Z", diff --git a/advisories/github-reviewed/2023/01/GHSA-r3gm-jwf4-xgv2/GHSA-r3gm-jwf4-xgv2.json b/advisories/github-reviewed/2023/01/GHSA-r3gm-jwf4-xgv2/GHSA-r3gm-jwf4-xgv2.json index d7acdf5e253..b87bc1e7075 100644 --- a/advisories/github-reviewed/2023/01/GHSA-r3gm-jwf4-xgv2/GHSA-r3gm-jwf4-xgv2.json +++ b/advisories/github-reviewed/2023/01/GHSA-r3gm-jwf4-xgv2/GHSA-r3gm-jwf4-xgv2.json @@ -8,9 +8,7 @@ ], "summary": "Cross-site request forgery vulnerability in Jenkins JIRA Pipeline Steps Plugin", "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/02/GHSA-mc8h-8q98-g5hr/GHSA-mc8h-8q98-g5hr.json b/advisories/github-reviewed/2023/02/GHSA-mc8h-8q98-g5hr/GHSA-mc8h-8q98-g5hr.json index 9392924afe4..cdb781b40fc 100644 --- a/advisories/github-reviewed/2023/02/GHSA-mc8h-8q98-g5hr/GHSA-mc8h-8q98-g5hr.json +++ b/advisories/github-reviewed/2023/02/GHSA-mc8h-8q98-g5hr/GHSA-mc8h-8q98-g5hr.json @@ -3,14 +3,10 @@ "id": "GHSA-mc8h-8q98-g5hr", "modified": "2023-02-24T16:23:59Z", "published": "2023-02-24T16:23:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all", "details": "The `remove_dir_all` crate is a Rust library that offers additional features over the Rust standard library `fs::remove_dir_all` function. It suffers the same class of failure as the code it was layering over: TOCTOU race conditions, with the ability to cause arbitrary paths to be deleted by substituting a symlink for a path after the type of the path was checked.\n\nThanks to the Rust security team for identifying the problem and alerting us to it.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/07/GHSA-h9wq-xcqx-mqxm/GHSA-h9wq-xcqx-mqxm.json b/advisories/github-reviewed/2023/07/GHSA-h9wq-xcqx-mqxm/GHSA-h9wq-xcqx-mqxm.json index dd209f6c732..b64ed104439 100644 --- a/advisories/github-reviewed/2023/07/GHSA-h9wq-xcqx-mqxm/GHSA-h9wq-xcqx-mqxm.json +++ b/advisories/github-reviewed/2023/07/GHSA-h9wq-xcqx-mqxm/GHSA-h9wq-xcqx-mqxm.json @@ -3,14 +3,10 @@ "id": "GHSA-h9wq-xcqx-mqxm", "modified": "2023-07-11T22:46:19Z", "published": "2023-07-11T22:46:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Vendure Cross Site Request Forgery vulnerability impacting all API requests", "details": "### Impact\nVendure is an e-commerce GraphQL framework with a number of APIs and different levels of\nauthorization. By default the Cookie settings are insecure, having the SameSite setting as false\nwhich results in not having one (originates from the cookie-session npm package’s default\nsettings).\n\n### Patches\nIn progress\n\n### Workarounds\nManually set the `authOptions.cookieOptions.sameSite` configuration option to `'strict'`, `'lax'` or `true`.\n\n### References\n_Are there any links users can visit to find out more?_\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-07-11T22:46:19Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-rvj4-q8q5-8grf/GHSA-rvj4-q8q5-8grf.json b/advisories/github-reviewed/2024/06/GHSA-rvj4-q8q5-8grf/GHSA-rvj4-q8q5-8grf.json index 1f71a4831ba..c9d0b2c5499 100644 --- a/advisories/github-reviewed/2024/06/GHSA-rvj4-q8q5-8grf/GHSA-rvj4-q8q5-8grf.json +++ b/advisories/github-reviewed/2024/06/GHSA-rvj4-q8q5-8grf/GHSA-rvj4-q8q5-8grf.json @@ -3,9 +3,7 @@ "id": "GHSA-rvj4-q8q5-8grf", "modified": "2024-06-20T16:20:25Z", "published": "2024-06-20T16:20:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability", "details": "### Impact\n\nThere is a vulnerability in [Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability](https://nvd.nist.gov/vuln/detail/CVE-2024-35255).\n\n### References\n\n- [CVE-2024-35255](https://nvd.nist.gov/vuln/detail/CVE-2024-35255)\n\n### Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.5\n- https://github.com/traefik/traefik/releases/tag/v3.0.3\n\n### Workarounds\n\nNo workaround.\n\n### For more information\n\nIf you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).", "severity": [ diff --git a/advisories/unreviewed/2021/11/GHSA-4xx3-xg55-3wr5/GHSA-4xx3-xg55-3wr5.json b/advisories/unreviewed/2021/11/GHSA-4xx3-xg55-3wr5/GHSA-4xx3-xg55-3wr5.json index 79477524811..78357e86e75 100644 --- a/advisories/unreviewed/2021/11/GHSA-4xx3-xg55-3wr5/GHSA-4xx3-xg55-3wr5.json +++ b/advisories/unreviewed/2021/11/GHSA-4xx3-xg55-3wr5/GHSA-4xx3-xg55-3wr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-xrj7-4gfh-q9h7/GHSA-xrj7-4gfh-q9h7.json b/advisories/unreviewed/2021/11/GHSA-xrj7-4gfh-q9h7/GHSA-xrj7-4gfh-q9h7.json index 21c9039b7fc..afe3ec54fc4 100644 --- a/advisories/unreviewed/2021/11/GHSA-xrj7-4gfh-q9h7/GHSA-xrj7-4gfh-q9h7.json +++ b/advisories/unreviewed/2021/11/GHSA-xrj7-4gfh-q9h7/GHSA-xrj7-4gfh-q9h7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-8p3j-58qw-jhp4/GHSA-8p3j-58qw-jhp4.json b/advisories/unreviewed/2022/02/GHSA-8p3j-58qw-jhp4/GHSA-8p3j-58qw-jhp4.json index b685bb48a28..043c8d81f98 100644 --- a/advisories/unreviewed/2022/02/GHSA-8p3j-58qw-jhp4/GHSA-8p3j-58qw-jhp4.json +++ b/advisories/unreviewed/2022/02/GHSA-8p3j-58qw-jhp4/GHSA-8p3j-58qw-jhp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -67,9 +65,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-4qpc-hphm-xpmc/GHSA-4qpc-hphm-xpmc.json b/advisories/unreviewed/2022/03/GHSA-4qpc-hphm-xpmc/GHSA-4qpc-hphm-xpmc.json index cb0979b88e2..2c5e5c175ca 100644 --- a/advisories/unreviewed/2022/03/GHSA-4qpc-hphm-xpmc/GHSA-4qpc-hphm-xpmc.json +++ b/advisories/unreviewed/2022/03/GHSA-4qpc-hphm-xpmc/GHSA-4qpc-hphm-xpmc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-4rqg-f28v-3gvx/GHSA-4rqg-f28v-3gvx.json b/advisories/unreviewed/2022/03/GHSA-4rqg-f28v-3gvx/GHSA-4rqg-f28v-3gvx.json index f7bc84c45ae..317febbdddb 100644 --- a/advisories/unreviewed/2022/03/GHSA-4rqg-f28v-3gvx/GHSA-4rqg-f28v-3gvx.json +++ b/advisories/unreviewed/2022/03/GHSA-4rqg-f28v-3gvx/GHSA-4rqg-f28v-3gvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-5h3c-wjf7-3r26/GHSA-5h3c-wjf7-3r26.json b/advisories/unreviewed/2022/03/GHSA-5h3c-wjf7-3r26/GHSA-5h3c-wjf7-3r26.json index 86ca816dab2..58c85396c2e 100644 --- a/advisories/unreviewed/2022/03/GHSA-5h3c-wjf7-3r26/GHSA-5h3c-wjf7-3r26.json +++ b/advisories/unreviewed/2022/03/GHSA-5h3c-wjf7-3r26/GHSA-5h3c-wjf7-3r26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-g9pm-vppm-577q/GHSA-g9pm-vppm-577q.json b/advisories/unreviewed/2022/03/GHSA-g9pm-vppm-577q/GHSA-g9pm-vppm-577q.json index 09da2e10fe0..c6f81a1eb09 100644 --- a/advisories/unreviewed/2022/03/GHSA-g9pm-vppm-577q/GHSA-g9pm-vppm-577q.json +++ b/advisories/unreviewed/2022/03/GHSA-g9pm-vppm-577q/GHSA-g9pm-vppm-577q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-h7v8-mphj-jp2g/GHSA-h7v8-mphj-jp2g.json b/advisories/unreviewed/2022/03/GHSA-h7v8-mphj-jp2g/GHSA-h7v8-mphj-jp2g.json index 94ffb7766b4..dd1d813028e 100644 --- a/advisories/unreviewed/2022/03/GHSA-h7v8-mphj-jp2g/GHSA-h7v8-mphj-jp2g.json +++ b/advisories/unreviewed/2022/03/GHSA-h7v8-mphj-jp2g/GHSA-h7v8-mphj-jp2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-v2q7-x3pw-jc98/GHSA-v2q7-x3pw-jc98.json b/advisories/unreviewed/2022/03/GHSA-v2q7-x3pw-jc98/GHSA-v2q7-x3pw-jc98.json index 85e73584368..51640865d91 100644 --- a/advisories/unreviewed/2022/03/GHSA-v2q7-x3pw-jc98/GHSA-v2q7-x3pw-jc98.json +++ b/advisories/unreviewed/2022/03/GHSA-v2q7-x3pw-jc98/GHSA-v2q7-x3pw-jc98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-349g-pr27-x5hf/GHSA-349g-pr27-x5hf.json b/advisories/unreviewed/2022/04/GHSA-349g-pr27-x5hf/GHSA-349g-pr27-x5hf.json index be49490900e..99568aaee85 100644 --- a/advisories/unreviewed/2022/04/GHSA-349g-pr27-x5hf/GHSA-349g-pr27-x5hf.json +++ b/advisories/unreviewed/2022/04/GHSA-349g-pr27-x5hf/GHSA-349g-pr27-x5hf.json @@ -7,12 +7,8 @@ "CVE-2004-1852" ], "details": "DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cg66-grw3-w6j2/GHSA-cg66-grw3-w6j2.json b/advisories/unreviewed/2022/04/GHSA-cg66-grw3-w6j2/GHSA-cg66-grw3-w6j2.json index aae99c8bf76..e4fb7f8bbe1 100644 --- a/advisories/unreviewed/2022/04/GHSA-cg66-grw3-w6j2/GHSA-cg66-grw3-w6j2.json +++ b/advisories/unreviewed/2022/04/GHSA-cg66-grw3-w6j2/GHSA-cg66-grw3-w6j2.json @@ -7,12 +7,8 @@ "CVE-2004-2257" ], "details": "phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-fwc5-m56h-x5g6/GHSA-fwc5-m56h-x5g6.json b/advisories/unreviewed/2022/04/GHSA-fwc5-m56h-x5g6/GHSA-fwc5-m56h-x5g6.json index da15cf28754..d16ee40cf98 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwc5-m56h-x5g6/GHSA-fwc5-m56h-x5g6.json +++ b/advisories/unreviewed/2022/04/GHSA-fwc5-m56h-x5g6/GHSA-fwc5-m56h-x5g6.json @@ -7,12 +7,8 @@ "CVE-2004-2144" ], "details": "Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q76p-969x-phhf/GHSA-q76p-969x-phhf.json b/advisories/unreviewed/2022/04/GHSA-q76p-969x-phhf/GHSA-q76p-969x-phhf.json index 4a7663d77d9..9def8b18c62 100644 --- a/advisories/unreviewed/2022/04/GHSA-q76p-969x-phhf/GHSA-q76p-969x-phhf.json +++ b/advisories/unreviewed/2022/04/GHSA-q76p-969x-phhf/GHSA-q76p-969x-phhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xj93-8hff-x47c/GHSA-xj93-8hff-x47c.json b/advisories/unreviewed/2022/04/GHSA-xj93-8hff-x47c/GHSA-xj93-8hff-x47c.json index 3f4e476264e..798bfae5bf1 100644 --- a/advisories/unreviewed/2022/04/GHSA-xj93-8hff-x47c/GHSA-xj93-8hff-x47c.json +++ b/advisories/unreviewed/2022/04/GHSA-xj93-8hff-x47c/GHSA-xj93-8hff-x47c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23hf-jhww-867g/GHSA-23hf-jhww-867g.json b/advisories/unreviewed/2022/05/GHSA-23hf-jhww-867g/GHSA-23hf-jhww-867g.json index 587be8f91f4..b24bd1af411 100644 --- a/advisories/unreviewed/2022/05/GHSA-23hf-jhww-867g/GHSA-23hf-jhww-867g.json +++ b/advisories/unreviewed/2022/05/GHSA-23hf-jhww-867g/GHSA-23hf-jhww-867g.json @@ -7,12 +7,8 @@ "CVE-2011-2491" ], "details": "The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23jc-mx6c-hh36/GHSA-23jc-mx6c-hh36.json b/advisories/unreviewed/2022/05/GHSA-23jc-mx6c-hh36/GHSA-23jc-mx6c-hh36.json index d5dd7bd9fe4..1cd063415f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-23jc-mx6c-hh36/GHSA-23jc-mx6c-hh36.json +++ b/advisories/unreviewed/2022/05/GHSA-23jc-mx6c-hh36/GHSA-23jc-mx6c-hh36.json @@ -7,12 +7,8 @@ "CVE-2010-3849" ], "details": "The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-242r-53mf-qx5c/GHSA-242r-53mf-qx5c.json b/advisories/unreviewed/2022/05/GHSA-242r-53mf-qx5c/GHSA-242r-53mf-qx5c.json index 6072064985e..7a9f452708c 100644 --- a/advisories/unreviewed/2022/05/GHSA-242r-53mf-qx5c/GHSA-242r-53mf-qx5c.json +++ b/advisories/unreviewed/2022/05/GHSA-242r-53mf-qx5c/GHSA-242r-53mf-qx5c.json @@ -7,12 +7,8 @@ "CVE-2019-3925" ], "details": "Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25vm-4wwp-79cp/GHSA-25vm-4wwp-79cp.json b/advisories/unreviewed/2022/05/GHSA-25vm-4wwp-79cp/GHSA-25vm-4wwp-79cp.json index 606584d3ce0..94f78e1bc1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-25vm-4wwp-79cp/GHSA-25vm-4wwp-79cp.json +++ b/advisories/unreviewed/2022/05/GHSA-25vm-4wwp-79cp/GHSA-25vm-4wwp-79cp.json @@ -7,12 +7,8 @@ "CVE-2019-2713" ], "details": "Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Merchandising. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Merchandising accessible data as well as unauthorized read access to a subset of Oracle Commerce Merchandising accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26j8-6884-fcqw/GHSA-26j8-6884-fcqw.json b/advisories/unreviewed/2022/05/GHSA-26j8-6884-fcqw/GHSA-26j8-6884-fcqw.json index 71dc2f0a59e..90ad1412723 100644 --- a/advisories/unreviewed/2022/05/GHSA-26j8-6884-fcqw/GHSA-26j8-6884-fcqw.json +++ b/advisories/unreviewed/2022/05/GHSA-26j8-6884-fcqw/GHSA-26j8-6884-fcqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-273c-3m7m-qmj2/GHSA-273c-3m7m-qmj2.json b/advisories/unreviewed/2022/05/GHSA-273c-3m7m-qmj2/GHSA-273c-3m7m-qmj2.json index 06638706ef7..b88c881016b 100644 --- a/advisories/unreviewed/2022/05/GHSA-273c-3m7m-qmj2/GHSA-273c-3m7m-qmj2.json +++ b/advisories/unreviewed/2022/05/GHSA-273c-3m7m-qmj2/GHSA-273c-3m7m-qmj2.json @@ -7,12 +7,8 @@ "CVE-2019-2640" ], "details": "Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-276g-j28x-jvcr/GHSA-276g-j28x-jvcr.json b/advisories/unreviewed/2022/05/GHSA-276g-j28x-jvcr/GHSA-276g-j28x-jvcr.json index 6f78b6e5749..da98050caa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-276g-j28x-jvcr/GHSA-276g-j28x-jvcr.json +++ b/advisories/unreviewed/2022/05/GHSA-276g-j28x-jvcr/GHSA-276g-j28x-jvcr.json @@ -7,12 +7,8 @@ "CVE-2019-2678" ], "details": "Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-276p-837g-mvv4/GHSA-276p-837g-mvv4.json b/advisories/unreviewed/2022/05/GHSA-276p-837g-mvv4/GHSA-276p-837g-mvv4.json index 78e7380842c..edb4db8e104 100644 --- a/advisories/unreviewed/2022/05/GHSA-276p-837g-mvv4/GHSA-276p-837g-mvv4.json +++ b/advisories/unreviewed/2022/05/GHSA-276p-837g-mvv4/GHSA-276p-837g-mvv4.json @@ -7,12 +7,8 @@ "CVE-2019-2517" ], "details": "Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having DBFS_ROLE privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Core RDBMS. CVSS 3.0 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2874-9wc2-224f/GHSA-2874-9wc2-224f.json b/advisories/unreviewed/2022/05/GHSA-2874-9wc2-224f/GHSA-2874-9wc2-224f.json index e79e3e9d53c..2338bfab683 100644 --- a/advisories/unreviewed/2022/05/GHSA-2874-9wc2-224f/GHSA-2874-9wc2-224f.json +++ b/advisories/unreviewed/2022/05/GHSA-2874-9wc2-224f/GHSA-2874-9wc2-224f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c46-3v56-p8mq/GHSA-2c46-3v56-p8mq.json b/advisories/unreviewed/2022/05/GHSA-2c46-3v56-p8mq/GHSA-2c46-3v56-p8mq.json index 98f72a80002..73099d4e4ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c46-3v56-p8mq/GHSA-2c46-3v56-p8mq.json +++ b/advisories/unreviewed/2022/05/GHSA-2c46-3v56-p8mq/GHSA-2c46-3v56-p8mq.json @@ -7,12 +7,8 @@ "CVE-2011-1748" ], "details": "The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cx8-vq8f-mwm5/GHSA-2cx8-vq8f-mwm5.json b/advisories/unreviewed/2022/05/GHSA-2cx8-vq8f-mwm5/GHSA-2cx8-vq8f-mwm5.json index 5b0cb0846f8..3f9b82251c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cx8-vq8f-mwm5/GHSA-2cx8-vq8f-mwm5.json +++ b/advisories/unreviewed/2022/05/GHSA-2cx8-vq8f-mwm5/GHSA-2cx8-vq8f-mwm5.json @@ -7,12 +7,8 @@ "CVE-2019-9794" ], "details": "A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f2x-36r8-vr6x/GHSA-2f2x-36r8-vr6x.json b/advisories/unreviewed/2022/05/GHSA-2f2x-36r8-vr6x/GHSA-2f2x-36r8-vr6x.json index ee00e5090dc..b4cf036c0c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f2x-36r8-vr6x/GHSA-2f2x-36r8-vr6x.json +++ b/advisories/unreviewed/2022/05/GHSA-2f2x-36r8-vr6x/GHSA-2f2x-36r8-vr6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f9c-jj4r-fr8x/GHSA-2f9c-jj4r-fr8x.json b/advisories/unreviewed/2022/05/GHSA-2f9c-jj4r-fr8x/GHSA-2f9c-jj4r-fr8x.json index 24eeda9fc6f..326374632a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f9c-jj4r-fr8x/GHSA-2f9c-jj4r-fr8x.json +++ b/advisories/unreviewed/2022/05/GHSA-2f9c-jj4r-fr8x/GHSA-2f9c-jj4r-fr8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fg3-h938-jr6f/GHSA-2fg3-h938-jr6f.json b/advisories/unreviewed/2022/05/GHSA-2fg3-h938-jr6f/GHSA-2fg3-h938-jr6f.json index a22e81493d8..c28588d0051 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fg3-h938-jr6f/GHSA-2fg3-h938-jr6f.json +++ b/advisories/unreviewed/2022/05/GHSA-2fg3-h938-jr6f/GHSA-2fg3-h938-jr6f.json @@ -7,12 +7,8 @@ "CVE-2010-2226" ], "details": "The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fh8-hvqx-49wh/GHSA-2fh8-hvqx-49wh.json b/advisories/unreviewed/2022/05/GHSA-2fh8-hvqx-49wh/GHSA-2fh8-hvqx-49wh.json index d41daf33982..c713dbd1734 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fh8-hvqx-49wh/GHSA-2fh8-hvqx-49wh.json +++ b/advisories/unreviewed/2022/05/GHSA-2fh8-hvqx-49wh/GHSA-2fh8-hvqx-49wh.json @@ -7,12 +7,8 @@ "CVE-2019-9799" ], "details": "Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g47-r557-h83r/GHSA-2g47-r557-h83r.json b/advisories/unreviewed/2022/05/GHSA-2g47-r557-h83r/GHSA-2g47-r557-h83r.json index 6bb68372173..5d14686f4f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g47-r557-h83r/GHSA-2g47-r557-h83r.json +++ b/advisories/unreviewed/2022/05/GHSA-2g47-r557-h83r/GHSA-2g47-r557-h83r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gjm-hvmq-383v/GHSA-2gjm-hvmq-383v.json b/advisories/unreviewed/2022/05/GHSA-2gjm-hvmq-383v/GHSA-2gjm-hvmq-383v.json index bff07499496..678be97a98b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gjm-hvmq-383v/GHSA-2gjm-hvmq-383v.json +++ b/advisories/unreviewed/2022/05/GHSA-2gjm-hvmq-383v/GHSA-2gjm-hvmq-383v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hc3-647x-j4pq/GHSA-2hc3-647x-j4pq.json b/advisories/unreviewed/2022/05/GHSA-2hc3-647x-j4pq/GHSA-2hc3-647x-j4pq.json index e4722b8dae5..53dc399fcb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hc3-647x-j4pq/GHSA-2hc3-647x-j4pq.json +++ b/advisories/unreviewed/2022/05/GHSA-2hc3-647x-j4pq/GHSA-2hc3-647x-j4pq.json @@ -7,12 +7,8 @@ "CVE-2019-10710" ], "details": "Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hm9-33m6-xf92/GHSA-2hm9-33m6-xf92.json b/advisories/unreviewed/2022/05/GHSA-2hm9-33m6-xf92/GHSA-2hm9-33m6-xf92.json index 2ce5b797261..1f4322b13bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hm9-33m6-xf92/GHSA-2hm9-33m6-xf92.json +++ b/advisories/unreviewed/2022/05/GHSA-2hm9-33m6-xf92/GHSA-2hm9-33m6-xf92.json @@ -7,12 +7,8 @@ "CVE-2011-4091" ], "details": "The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jp5-f326-8qj7/GHSA-2jp5-f326-8qj7.json b/advisories/unreviewed/2022/05/GHSA-2jp5-f326-8qj7/GHSA-2jp5-f326-8qj7.json index ba9e0c76ebc..804d05fea4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jp5-f326-8qj7/GHSA-2jp5-f326-8qj7.json +++ b/advisories/unreviewed/2022/05/GHSA-2jp5-f326-8qj7/GHSA-2jp5-f326-8qj7.json @@ -7,12 +7,8 @@ "CVE-2019-2603" ], "details": "Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m5h-fr2p-prrm/GHSA-2m5h-fr2p-prrm.json b/advisories/unreviewed/2022/05/GHSA-2m5h-fr2p-prrm/GHSA-2m5h-fr2p-prrm.json index 30aba0a70f5..f09c2141fa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m5h-fr2p-prrm/GHSA-2m5h-fr2p-prrm.json +++ b/advisories/unreviewed/2022/05/GHSA-2m5h-fr2p-prrm/GHSA-2m5h-fr2p-prrm.json @@ -7,12 +7,8 @@ "CVE-2012-3358" ], "details": "Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mgp-6265-vwf6/GHSA-2mgp-6265-vwf6.json b/advisories/unreviewed/2022/05/GHSA-2mgp-6265-vwf6/GHSA-2mgp-6265-vwf6.json index f4d229090ca..910b34ef7e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mgp-6265-vwf6/GHSA-2mgp-6265-vwf6.json +++ b/advisories/unreviewed/2022/05/GHSA-2mgp-6265-vwf6/GHSA-2mgp-6265-vwf6.json @@ -7,12 +7,8 @@ "CVE-2018-18512" ], "details": "A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qr5-c6ch-9wr8/GHSA-2qr5-c6ch-9wr8.json b/advisories/unreviewed/2022/05/GHSA-2qr5-c6ch-9wr8/GHSA-2qr5-c6ch-9wr8.json index 6a992185b2f..9bd1fe81c33 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qr5-c6ch-9wr8/GHSA-2qr5-c6ch-9wr8.json +++ b/advisories/unreviewed/2022/05/GHSA-2qr5-c6ch-9wr8/GHSA-2qr5-c6ch-9wr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r3r-854p-xjfr/GHSA-2r3r-854p-xjfr.json b/advisories/unreviewed/2022/05/GHSA-2r3r-854p-xjfr/GHSA-2r3r-854p-xjfr.json index f46bc24c3c0..0a7476e5803 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r3r-854p-xjfr/GHSA-2r3r-854p-xjfr.json +++ b/advisories/unreviewed/2022/05/GHSA-2r3r-854p-xjfr/GHSA-2r3r-854p-xjfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rcq-4r2f-jhv9/GHSA-2rcq-4r2f-jhv9.json b/advisories/unreviewed/2022/05/GHSA-2rcq-4r2f-jhv9/GHSA-2rcq-4r2f-jhv9.json index 10fd3890396..45a68967dd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rcq-4r2f-jhv9/GHSA-2rcq-4r2f-jhv9.json +++ b/advisories/unreviewed/2022/05/GHSA-2rcq-4r2f-jhv9/GHSA-2rcq-4r2f-jhv9.json @@ -7,12 +7,8 @@ "CVE-2019-10950" ], "details": "Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access the underlying operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rfq-4jx8-3hp9/GHSA-2rfq-4jx8-3hp9.json b/advisories/unreviewed/2022/05/GHSA-2rfq-4jx8-3hp9/GHSA-2rfq-4jx8-3hp9.json index bb77bdcd903..8accd462341 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rfq-4jx8-3hp9/GHSA-2rfq-4jx8-3hp9.json +++ b/advisories/unreviewed/2022/05/GHSA-2rfq-4jx8-3hp9/GHSA-2rfq-4jx8-3hp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rp9-ffvm-xjc8/GHSA-2rp9-ffvm-xjc8.json b/advisories/unreviewed/2022/05/GHSA-2rp9-ffvm-xjc8/GHSA-2rp9-ffvm-xjc8.json index cfd662f588a..3ac58ac6c67 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rp9-ffvm-xjc8/GHSA-2rp9-ffvm-xjc8.json +++ b/advisories/unreviewed/2022/05/GHSA-2rp9-ffvm-xjc8/GHSA-2rp9-ffvm-xjc8.json @@ -7,12 +7,8 @@ "CVE-2019-10919" ], "details": "A vulnerability has been identified in LOGO!8 BM (All versions). Attackers with access to port 10005/tcp could perform device reconfigurations and obtain project files from the devices. The system manual recommends to protect access to this port. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v77-vf4r-42vf/GHSA-2v77-vf4r-42vf.json b/advisories/unreviewed/2022/05/GHSA-2v77-vf4r-42vf/GHSA-2v77-vf4r-42vf.json index a6237ae1cc1..e648185278d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v77-vf4r-42vf/GHSA-2v77-vf4r-42vf.json +++ b/advisories/unreviewed/2022/05/GHSA-2v77-vf4r-42vf/GHSA-2v77-vf4r-42vf.json @@ -7,12 +7,8 @@ "CVE-2019-11411" ], "details": "An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w2h-4fp7-2gq3/GHSA-2w2h-4fp7-2gq3.json b/advisories/unreviewed/2022/05/GHSA-2w2h-4fp7-2gq3/GHSA-2w2h-4fp7-2gq3.json index dd5ad290853..690748be6de 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w2h-4fp7-2gq3/GHSA-2w2h-4fp7-2gq3.json +++ b/advisories/unreviewed/2022/05/GHSA-2w2h-4fp7-2gq3/GHSA-2w2h-4fp7-2gq3.json @@ -7,12 +7,8 @@ "CVE-2019-10920" ], "details": "A vulnerability has been identified in LOGO!8 BM (All versions). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption key. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x85-3pxc-c227/GHSA-2x85-3pxc-c227.json b/advisories/unreviewed/2022/05/GHSA-2x85-3pxc-c227/GHSA-2x85-3pxc-c227.json index 6f1c0f4d707..47b78b5107f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x85-3pxc-c227/GHSA-2x85-3pxc-c227.json +++ b/advisories/unreviewed/2022/05/GHSA-2x85-3pxc-c227/GHSA-2x85-3pxc-c227.json @@ -7,12 +7,8 @@ "CVE-2010-4165" ], "details": "The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x9h-q6q9-gfvw/GHSA-2x9h-q6q9-gfvw.json b/advisories/unreviewed/2022/05/GHSA-2x9h-q6q9-gfvw/GHSA-2x9h-q6q9-gfvw.json index 764b1a53a3d..07f458cd504 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x9h-q6q9-gfvw/GHSA-2x9h-q6q9-gfvw.json +++ b/advisories/unreviewed/2022/05/GHSA-2x9h-q6q9-gfvw/GHSA-2x9h-q6q9-gfvw.json @@ -7,12 +7,8 @@ "CVE-2019-2576" ], "details": "Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xfm-mgc4-j8fx/GHSA-2xfm-mgc4-j8fx.json b/advisories/unreviewed/2022/05/GHSA-2xfm-mgc4-j8fx/GHSA-2xfm-mgc4-j8fx.json index 6846a5f5e9a..c8308ff102d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xfm-mgc4-j8fx/GHSA-2xfm-mgc4-j8fx.json +++ b/advisories/unreviewed/2022/05/GHSA-2xfm-mgc4-j8fx/GHSA-2xfm-mgc4-j8fx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xx9-w5qw-9796/GHSA-2xx9-w5qw-9796.json b/advisories/unreviewed/2022/05/GHSA-2xx9-w5qw-9796/GHSA-2xx9-w5qw-9796.json index 3047397eacd..9a89778e1f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xx9-w5qw-9796/GHSA-2xx9-w5qw-9796.json +++ b/advisories/unreviewed/2022/05/GHSA-2xx9-w5qw-9796/GHSA-2xx9-w5qw-9796.json @@ -7,12 +7,8 @@ "CVE-2019-2612" ], "details": "Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-326g-xf83-pf2m/GHSA-326g-xf83-pf2m.json b/advisories/unreviewed/2022/05/GHSA-326g-xf83-pf2m/GHSA-326g-xf83-pf2m.json index 3e4e0516048..a72e08bec4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-326g-xf83-pf2m/GHSA-326g-xf83-pf2m.json +++ b/advisories/unreviewed/2022/05/GHSA-326g-xf83-pf2m/GHSA-326g-xf83-pf2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-342q-q4xm-99r7/GHSA-342q-q4xm-99r7.json b/advisories/unreviewed/2022/05/GHSA-342q-q4xm-99r7/GHSA-342q-q4xm-99r7.json index 9e392e8a4ce..1f5837b54b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-342q-q4xm-99r7/GHSA-342q-q4xm-99r7.json +++ b/advisories/unreviewed/2022/05/GHSA-342q-q4xm-99r7/GHSA-342q-q4xm-99r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34xx-9q37-gww9/GHSA-34xx-9q37-gww9.json b/advisories/unreviewed/2022/05/GHSA-34xx-9q37-gww9/GHSA-34xx-9q37-gww9.json index 2a669eb7590..0192c4e17e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-34xx-9q37-gww9/GHSA-34xx-9q37-gww9.json +++ b/advisories/unreviewed/2022/05/GHSA-34xx-9q37-gww9/GHSA-34xx-9q37-gww9.json @@ -7,12 +7,8 @@ "CVE-2019-2572" ], "details": "Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle SOA Suite accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3562-xr8f-cfw7/GHSA-3562-xr8f-cfw7.json b/advisories/unreviewed/2022/05/GHSA-3562-xr8f-cfw7/GHSA-3562-xr8f-cfw7.json index ffddd595288..7d19da77fb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3562-xr8f-cfw7/GHSA-3562-xr8f-cfw7.json +++ b/advisories/unreviewed/2022/05/GHSA-3562-xr8f-cfw7/GHSA-3562-xr8f-cfw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-384q-gq9c-w4g3/GHSA-384q-gq9c-w4g3.json b/advisories/unreviewed/2022/05/GHSA-384q-gq9c-w4g3/GHSA-384q-gq9c-w4g3.json index ee0dcfa90d5..269db6031bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-384q-gq9c-w4g3/GHSA-384q-gq9c-w4g3.json +++ b/advisories/unreviewed/2022/05/GHSA-384q-gq9c-w4g3/GHSA-384q-gq9c-w4g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38xc-j7pw-37v9/GHSA-38xc-j7pw-37v9.json b/advisories/unreviewed/2022/05/GHSA-38xc-j7pw-37v9/GHSA-38xc-j7pw-37v9.json index 31ec2fafd43..ecbdc8af5a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-38xc-j7pw-37v9/GHSA-38xc-j7pw-37v9.json +++ b/advisories/unreviewed/2022/05/GHSA-38xc-j7pw-37v9/GHSA-38xc-j7pw-37v9.json @@ -7,12 +7,8 @@ "CVE-2019-10053" ], "details": "An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \\n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \\r results in an integer underflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39w5-pgjj-2hx6/GHSA-39w5-pgjj-2hx6.json b/advisories/unreviewed/2022/05/GHSA-39w5-pgjj-2hx6/GHSA-39w5-pgjj-2hx6.json index a660b258725..10c7041fc01 100644 --- a/advisories/unreviewed/2022/05/GHSA-39w5-pgjj-2hx6/GHSA-39w5-pgjj-2hx6.json +++ b/advisories/unreviewed/2022/05/GHSA-39w5-pgjj-2hx6/GHSA-39w5-pgjj-2hx6.json @@ -7,12 +7,8 @@ "CVE-2019-2618" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c54-vg5v-pqpf/GHSA-3c54-vg5v-pqpf.json b/advisories/unreviewed/2022/05/GHSA-3c54-vg5v-pqpf/GHSA-3c54-vg5v-pqpf.json index 7c5ac2dc6d1..8622f8f8d85 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c54-vg5v-pqpf/GHSA-3c54-vg5v-pqpf.json +++ b/advisories/unreviewed/2022/05/GHSA-3c54-vg5v-pqpf/GHSA-3c54-vg5v-pqpf.json @@ -7,12 +7,8 @@ "CVE-2018-19442" ], "details": "A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a nucleo.neatocloud.com:4443/vendors/neato/robots/[robot_serial]/messages Neato cloud URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jwh-g5rj-5hgj/GHSA-3jwh-g5rj-5hgj.json b/advisories/unreviewed/2022/05/GHSA-3jwh-g5rj-5hgj/GHSA-3jwh-g5rj-5hgj.json index f64a5c7c300..94e90cfc583 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jwh-g5rj-5hgj/GHSA-3jwh-g5rj-5hgj.json +++ b/advisories/unreviewed/2022/05/GHSA-3jwh-g5rj-5hgj/GHSA-3jwh-g5rj-5hgj.json @@ -7,12 +7,8 @@ "CVE-2019-11629" ], "details": "Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3m88-9p3h-xpvh/GHSA-3m88-9p3h-xpvh.json b/advisories/unreviewed/2022/05/GHSA-3m88-9p3h-xpvh/GHSA-3m88-9p3h-xpvh.json index 9088ed7a284..5b30be4d32e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m88-9p3h-xpvh/GHSA-3m88-9p3h-xpvh.json +++ b/advisories/unreviewed/2022/05/GHSA-3m88-9p3h-xpvh/GHSA-3m88-9p3h-xpvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mqx-hc7r-v3c4/GHSA-3mqx-hc7r-v3c4.json b/advisories/unreviewed/2022/05/GHSA-3mqx-hc7r-v3c4/GHSA-3mqx-hc7r-v3c4.json index 88669543127..95a4d061a84 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mqx-hc7r-v3c4/GHSA-3mqx-hc7r-v3c4.json +++ b/advisories/unreviewed/2022/05/GHSA-3mqx-hc7r-v3c4/GHSA-3mqx-hc7r-v3c4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q95-xjvq-cqjf/GHSA-3q95-xjvq-cqjf.json b/advisories/unreviewed/2022/05/GHSA-3q95-xjvq-cqjf/GHSA-3q95-xjvq-cqjf.json index 3b6b101fd5b..3093e2800b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q95-xjvq-cqjf/GHSA-3q95-xjvq-cqjf.json +++ b/advisories/unreviewed/2022/05/GHSA-3q95-xjvq-cqjf/GHSA-3q95-xjvq-cqjf.json @@ -7,12 +7,8 @@ "CVE-2019-6574" ], "details": "A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46), SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46). An improperly configured Parameter Read/Write execution via Field bus network may cause the controller to restart. The vulnerability could be exploited by an attacker with network access to the device. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qqm-2wjh-qxhf/GHSA-3qqm-2wjh-qxhf.json b/advisories/unreviewed/2022/05/GHSA-3qqm-2wjh-qxhf/GHSA-3qqm-2wjh-qxhf.json index e0b92d7fb9d..6dca4b862cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qqm-2wjh-qxhf/GHSA-3qqm-2wjh-qxhf.json +++ b/advisories/unreviewed/2022/05/GHSA-3qqm-2wjh-qxhf/GHSA-3qqm-2wjh-qxhf.json @@ -7,12 +7,8 @@ "CVE-2019-2665" ], "details": "Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: CRM User Management Framework). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v23-qhr8-m9w2/GHSA-3v23-qhr8-m9w2.json b/advisories/unreviewed/2022/05/GHSA-3v23-qhr8-m9w2/GHSA-3v23-qhr8-m9w2.json index 6b50a2b9665..46306920d1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v23-qhr8-m9w2/GHSA-3v23-qhr8-m9w2.json +++ b/advisories/unreviewed/2022/05/GHSA-3v23-qhr8-m9w2/GHSA-3v23-qhr8-m9w2.json @@ -7,12 +7,8 @@ "CVE-2019-11597" ], "details": "In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v56-6hxf-8799/GHSA-3v56-6hxf-8799.json b/advisories/unreviewed/2022/05/GHSA-3v56-6hxf-8799/GHSA-3v56-6hxf-8799.json index 3b40cdbe549..b4bca7b12a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v56-6hxf-8799/GHSA-3v56-6hxf-8799.json +++ b/advisories/unreviewed/2022/05/GHSA-3v56-6hxf-8799/GHSA-3v56-6hxf-8799.json @@ -7,12 +7,8 @@ "CVE-2010-4346" ], "details": "The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v56-chv5-rchw/GHSA-3v56-chv5-rchw.json b/advisories/unreviewed/2022/05/GHSA-3v56-chv5-rchw/GHSA-3v56-chv5-rchw.json index 3b6f06080f0..f29e7dfefde 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v56-chv5-rchw/GHSA-3v56-chv5-rchw.json +++ b/advisories/unreviewed/2022/05/GHSA-3v56-chv5-rchw/GHSA-3v56-chv5-rchw.json @@ -7,12 +7,8 @@ "CVE-2019-2655" ], "details": "Vulnerability in the Oracle Interaction Center Intelligence component of Oracle E-Business Suite (subcomponent: Business Intelligence (OLTP)). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Interaction Center Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Interaction Center Intelligence, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Interaction Center Intelligence accessible data as well as unauthorized update, insert or delete access to some of Oracle Interaction Center Intelligence accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3v88-mwpf-89qm/GHSA-3v88-mwpf-89qm.json b/advisories/unreviewed/2022/05/GHSA-3v88-mwpf-89qm/GHSA-3v88-mwpf-89qm.json index 4ba5bb5ba80..de5c251c345 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v88-mwpf-89qm/GHSA-3v88-mwpf-89qm.json +++ b/advisories/unreviewed/2022/05/GHSA-3v88-mwpf-89qm/GHSA-3v88-mwpf-89qm.json @@ -7,12 +7,8 @@ "CVE-2019-2712" ], "details": "Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). Supported versions that are affected are 11.2.0.3 and 11.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vcc-qrc9-5rvw/GHSA-3vcc-qrc9-5rvw.json b/advisories/unreviewed/2022/05/GHSA-3vcc-qrc9-5rvw/GHSA-3vcc-qrc9-5rvw.json index 14ca00ad233..f0e90292b9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vcc-qrc9-5rvw/GHSA-3vcc-qrc9-5rvw.json +++ b/advisories/unreviewed/2022/05/GHSA-3vcc-qrc9-5rvw/GHSA-3vcc-qrc9-5rvw.json @@ -7,12 +7,8 @@ "CVE-2019-2579" ], "details": "Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vxc-f4m6-vwxh/GHSA-3vxc-f4m6-vwxh.json b/advisories/unreviewed/2022/05/GHSA-3vxc-f4m6-vwxh/GHSA-3vxc-f4m6-vwxh.json index 4835b0af9c4..af0f66fa09f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vxc-f4m6-vwxh/GHSA-3vxc-f4m6-vwxh.json +++ b/advisories/unreviewed/2022/05/GHSA-3vxc-f4m6-vwxh/GHSA-3vxc-f4m6-vwxh.json @@ -7,12 +7,8 @@ "CVE-2018-16623" ], "details": "Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the \"Site options\" in the admin panel dashboard dropdown.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wcg-3hq8-89r6/GHSA-3wcg-3hq8-89r6.json b/advisories/unreviewed/2022/05/GHSA-3wcg-3hq8-89r6/GHSA-3wcg-3hq8-89r6.json index 2bde3d35b61..03e5fc8ff59 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wcg-3hq8-89r6/GHSA-3wcg-3hq8-89r6.json +++ b/advisories/unreviewed/2022/05/GHSA-3wcg-3hq8-89r6/GHSA-3wcg-3hq8-89r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wwx-c927-c5wg/GHSA-3wwx-c927-c5wg.json b/advisories/unreviewed/2022/05/GHSA-3wwx-c927-c5wg/GHSA-3wwx-c927-c5wg.json index 666cfe0cb86..baf2cca251e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wwx-c927-c5wg/GHSA-3wwx-c927-c5wg.json +++ b/advisories/unreviewed/2022/05/GHSA-3wwx-c927-c5wg/GHSA-3wwx-c927-c5wg.json @@ -7,12 +7,8 @@ "CVE-2019-2588" ], "details": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x6j-h8cp-mc44/GHSA-3x6j-h8cp-mc44.json b/advisories/unreviewed/2022/05/GHSA-3x6j-h8cp-mc44/GHSA-3x6j-h8cp-mc44.json index ef3c15fb9f8..ad0f0dc74fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x6j-h8cp-mc44/GHSA-3x6j-h8cp-mc44.json +++ b/advisories/unreviewed/2022/05/GHSA-3x6j-h8cp-mc44/GHSA-3x6j-h8cp-mc44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xpw-25qv-r984/GHSA-3xpw-25qv-r984.json b/advisories/unreviewed/2022/05/GHSA-3xpw-25qv-r984/GHSA-3xpw-25qv-r984.json index 8bd0ec6daa3..c6bf9e04c0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xpw-25qv-r984/GHSA-3xpw-25qv-r984.json +++ b/advisories/unreviewed/2022/05/GHSA-3xpw-25qv-r984/GHSA-3xpw-25qv-r984.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44xf-m62f-7h7r/GHSA-44xf-m62f-7h7r.json b/advisories/unreviewed/2022/05/GHSA-44xf-m62f-7h7r/GHSA-44xf-m62f-7h7r.json index 06731d88fb1..86ac1d5f2af 100644 --- a/advisories/unreviewed/2022/05/GHSA-44xf-m62f-7h7r/GHSA-44xf-m62f-7h7r.json +++ b/advisories/unreviewed/2022/05/GHSA-44xf-m62f-7h7r/GHSA-44xf-m62f-7h7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45m3-v8w2-94m4/GHSA-45m3-v8w2-94m4.json b/advisories/unreviewed/2022/05/GHSA-45m3-v8w2-94m4/GHSA-45m3-v8w2-94m4.json index ae2e81ca33c..e21623fbcbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-45m3-v8w2-94m4/GHSA-45m3-v8w2-94m4.json +++ b/advisories/unreviewed/2022/05/GHSA-45m3-v8w2-94m4/GHSA-45m3-v8w2-94m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4625-wrpx-f52j/GHSA-4625-wrpx-f52j.json b/advisories/unreviewed/2022/05/GHSA-4625-wrpx-f52j/GHSA-4625-wrpx-f52j.json index 7b5a13b2659..8c6cd67e7b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4625-wrpx-f52j/GHSA-4625-wrpx-f52j.json +++ b/advisories/unreviewed/2022/05/GHSA-4625-wrpx-f52j/GHSA-4625-wrpx-f52j.json @@ -7,12 +7,8 @@ "CVE-2019-2621" ], "details": "Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46w4-5g46-6h8f/GHSA-46w4-5g46-6h8f.json b/advisories/unreviewed/2022/05/GHSA-46w4-5g46-6h8f/GHSA-46w4-5g46-6h8f.json index abe24a54e4a..0b9351d670e 100644 --- a/advisories/unreviewed/2022/05/GHSA-46w4-5g46-6h8f/GHSA-46w4-5g46-6h8f.json +++ b/advisories/unreviewed/2022/05/GHSA-46w4-5g46-6h8f/GHSA-46w4-5g46-6h8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47pc-84xg-qf5p/GHSA-47pc-84xg-qf5p.json b/advisories/unreviewed/2022/05/GHSA-47pc-84xg-qf5p/GHSA-47pc-84xg-qf5p.json index c3fff8e88bc..5c6460a7006 100644 --- a/advisories/unreviewed/2022/05/GHSA-47pc-84xg-qf5p/GHSA-47pc-84xg-qf5p.json +++ b/advisories/unreviewed/2022/05/GHSA-47pc-84xg-qf5p/GHSA-47pc-84xg-qf5p.json @@ -7,12 +7,8 @@ "CVE-2019-5677" ], "details": "NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DeviceIoControl where the software reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49c5-7mr2-4w43/GHSA-49c5-7mr2-4w43.json b/advisories/unreviewed/2022/05/GHSA-49c5-7mr2-4w43/GHSA-49c5-7mr2-4w43.json index 5e34a3f1b49..5138ca7b5bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-49c5-7mr2-4w43/GHSA-49c5-7mr2-4w43.json +++ b/advisories/unreviewed/2022/05/GHSA-49c5-7mr2-4w43/GHSA-49c5-7mr2-4w43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h5r-2hfh-8prm/GHSA-4h5r-2hfh-8prm.json b/advisories/unreviewed/2022/05/GHSA-4h5r-2hfh-8prm/GHSA-4h5r-2hfh-8prm.json index cafff68491a..92227b454a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h5r-2hfh-8prm/GHSA-4h5r-2hfh-8prm.json +++ b/advisories/unreviewed/2022/05/GHSA-4h5r-2hfh-8prm/GHSA-4h5r-2hfh-8prm.json @@ -7,12 +7,8 @@ "CVE-2019-2708" ], "details": "Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138, prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Data Store. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hq6-rhmw-hgw9/GHSA-4hq6-rhmw-hgw9.json b/advisories/unreviewed/2022/05/GHSA-4hq6-rhmw-hgw9/GHSA-4hq6-rhmw-hgw9.json index 5544523abbb..7f295a60229 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hq6-rhmw-hgw9/GHSA-4hq6-rhmw-hgw9.json +++ b/advisories/unreviewed/2022/05/GHSA-4hq6-rhmw-hgw9/GHSA-4hq6-rhmw-hgw9.json @@ -7,12 +7,8 @@ "CVE-2019-11366" ], "details": "An issue was discovered in atftpd in atftp 0.7.1. It does not lock the thread_list_mutex mutex before assigning the current thread data structure. As a result, the daemon is vulnerable to a denial of service attack due to a NULL pointer dereference. If thread_data is NULL when assigned to current, and modified by another thread before a certain tftpd_list.c check, there is a crash when dereferencing current->next.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jv2-f9mw-9vh9/GHSA-4jv2-f9mw-9vh9.json b/advisories/unreviewed/2022/05/GHSA-4jv2-f9mw-9vh9/GHSA-4jv2-f9mw-9vh9.json index 81844efc8fc..3f53ddba935 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jv2-f9mw-9vh9/GHSA-4jv2-f9mw-9vh9.json +++ b/advisories/unreviewed/2022/05/GHSA-4jv2-f9mw-9vh9/GHSA-4jv2-f9mw-9vh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jx4-8xx2-8r3h/GHSA-4jx4-8xx2-8r3h.json b/advisories/unreviewed/2022/05/GHSA-4jx4-8xx2-8r3h/GHSA-4jx4-8xx2-8r3h.json index d7c33510e97..e64e99e8c46 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jx4-8xx2-8r3h/GHSA-4jx4-8xx2-8r3h.json +++ b/advisories/unreviewed/2022/05/GHSA-4jx4-8xx2-8r3h/GHSA-4jx4-8xx2-8r3h.json @@ -7,12 +7,8 @@ "CVE-2019-2594" ], "details": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Server). Supported versions that are affected are 8.55, 8.56 and 8.57. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pj4-x8fv-v6vm/GHSA-4pj4-x8fv-v6vm.json b/advisories/unreviewed/2022/05/GHSA-4pj4-x8fv-v6vm/GHSA-4pj4-x8fv-v6vm.json index 9fcb6b17145..97130173b32 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pj4-x8fv-v6vm/GHSA-4pj4-x8fv-v6vm.json +++ b/advisories/unreviewed/2022/05/GHSA-4pj4-x8fv-v6vm/GHSA-4pj4-x8fv-v6vm.json @@ -7,12 +7,8 @@ "CVE-2013-4159" ], "details": "ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to \"several temp file vulnerabilities\" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pjf-x44m-95hq/GHSA-4pjf-x44m-95hq.json b/advisories/unreviewed/2022/05/GHSA-4pjf-x44m-95hq/GHSA-4pjf-x44m-95hq.json index f1c737c2426..236d73f36d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pjf-x44m-95hq/GHSA-4pjf-x44m-95hq.json +++ b/advisories/unreviewed/2022/05/GHSA-4pjf-x44m-95hq/GHSA-4pjf-x44m-95hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pv4-8h84-4vg6/GHSA-4pv4-8h84-4vg6.json b/advisories/unreviewed/2022/05/GHSA-4pv4-8h84-4vg6/GHSA-4pv4-8h84-4vg6.json index 369c80f19d3..4af3ae05f89 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pv4-8h84-4vg6/GHSA-4pv4-8h84-4vg6.json +++ b/advisories/unreviewed/2022/05/GHSA-4pv4-8h84-4vg6/GHSA-4pv4-8h84-4vg6.json @@ -7,12 +7,8 @@ "CVE-2019-0819" ], "details": "An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qm4-wr42-6jxh/GHSA-4qm4-wr42-6jxh.json b/advisories/unreviewed/2022/05/GHSA-4qm4-wr42-6jxh/GHSA-4qm4-wr42-6jxh.json index 183ae6f5eb0..821a587c5e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qm4-wr42-6jxh/GHSA-4qm4-wr42-6jxh.json +++ b/advisories/unreviewed/2022/05/GHSA-4qm4-wr42-6jxh/GHSA-4qm4-wr42-6jxh.json @@ -7,12 +7,8 @@ "CVE-2019-2661" ], "details": "Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qv9-vq3r-p2rx/GHSA-4qv9-vq3r-p2rx.json b/advisories/unreviewed/2022/05/GHSA-4qv9-vq3r-p2rx/GHSA-4qv9-vq3r-p2rx.json index 693f05af7f1..8f525414d0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qv9-vq3r-p2rx/GHSA-4qv9-vq3r-p2rx.json +++ b/advisories/unreviewed/2022/05/GHSA-4qv9-vq3r-p2rx/GHSA-4qv9-vq3r-p2rx.json @@ -7,12 +7,8 @@ "CVE-2019-0884" ], "details": "A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0911, CVE-2019-0918.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rj8-hc4w-2f6v/GHSA-4rj8-hc4w-2f6v.json b/advisories/unreviewed/2022/05/GHSA-4rj8-hc4w-2f6v/GHSA-4rj8-hc4w-2f6v.json index 235d7da188c..b96a1284f5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rj8-hc4w-2f6v/GHSA-4rj8-hc4w-2f6v.json +++ b/advisories/unreviewed/2022/05/GHSA-4rj8-hc4w-2f6v/GHSA-4rj8-hc4w-2f6v.json @@ -7,12 +7,8 @@ "CVE-2019-2646" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v9j-mhhp-7qmp/GHSA-4v9j-mhhp-7qmp.json b/advisories/unreviewed/2022/05/GHSA-4v9j-mhhp-7qmp/GHSA-4v9j-mhhp-7qmp.json index 7d5205138fa..acbee771431 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v9j-mhhp-7qmp/GHSA-4v9j-mhhp-7qmp.json +++ b/advisories/unreviewed/2022/05/GHSA-4v9j-mhhp-7qmp/GHSA-4v9j-mhhp-7qmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vgf-c8vc-m3fj/GHSA-4vgf-c8vc-m3fj.json b/advisories/unreviewed/2022/05/GHSA-4vgf-c8vc-m3fj/GHSA-4vgf-c8vc-m3fj.json index 6ae5f85f857..167b1fa6d36 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vgf-c8vc-m3fj/GHSA-4vgf-c8vc-m3fj.json +++ b/advisories/unreviewed/2022/05/GHSA-4vgf-c8vc-m3fj/GHSA-4vgf-c8vc-m3fj.json @@ -7,12 +7,8 @@ "CVE-2019-0727" ], "details": "An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Diagnostic Hub Standard Collector, Visual Studio Standard Collector Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4w5r-2wjg-hq97/GHSA-4w5r-2wjg-hq97.json b/advisories/unreviewed/2022/05/GHSA-4w5r-2wjg-hq97/GHSA-4w5r-2wjg-hq97.json index ca9456e387e..9d203c83650 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w5r-2wjg-hq97/GHSA-4w5r-2wjg-hq97.json +++ b/advisories/unreviewed/2022/05/GHSA-4w5r-2wjg-hq97/GHSA-4w5r-2wjg-hq97.json @@ -7,12 +7,8 @@ "CVE-2019-2700" ], "details": "Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4w66-5376-wj8w/GHSA-4w66-5376-wj8w.json b/advisories/unreviewed/2022/05/GHSA-4w66-5376-wj8w/GHSA-4w66-5376-wj8w.json index 66530b5ec2e..6020dec9b7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w66-5376-wj8w/GHSA-4w66-5376-wj8w.json +++ b/advisories/unreviewed/2022/05/GHSA-4w66-5376-wj8w/GHSA-4w66-5376-wj8w.json @@ -7,12 +7,8 @@ "CVE-2019-2696" ], "details": "Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xp9-9mj9-535w/GHSA-4xp9-9mj9-535w.json b/advisories/unreviewed/2022/05/GHSA-4xp9-9mj9-535w/GHSA-4xp9-9mj9-535w.json index f36e5cbdfb7..548c0dff769 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xp9-9mj9-535w/GHSA-4xp9-9mj9-535w.json +++ b/advisories/unreviewed/2022/05/GHSA-4xp9-9mj9-535w/GHSA-4xp9-9mj9-535w.json @@ -7,12 +7,8 @@ "CVE-2019-11845" ], "details": "An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xqw-p5g4-297h/GHSA-4xqw-p5g4-297h.json b/advisories/unreviewed/2022/05/GHSA-4xqw-p5g4-297h/GHSA-4xqw-p5g4-297h.json index f9d73c28465..fa312837c23 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xqw-p5g4-297h/GHSA-4xqw-p5g4-297h.json +++ b/advisories/unreviewed/2022/05/GHSA-4xqw-p5g4-297h/GHSA-4xqw-p5g4-297h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xqx-mhgm-2732/GHSA-4xqx-mhgm-2732.json b/advisories/unreviewed/2022/05/GHSA-4xqx-mhgm-2732/GHSA-4xqx-mhgm-2732.json index 122c7650d19..e66f8bb0991 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xqx-mhgm-2732/GHSA-4xqx-mhgm-2732.json +++ b/advisories/unreviewed/2022/05/GHSA-4xqx-mhgm-2732/GHSA-4xqx-mhgm-2732.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xxj-wpww-f4p9/GHSA-4xxj-wpww-f4p9.json b/advisories/unreviewed/2022/05/GHSA-4xxj-wpww-f4p9/GHSA-4xxj-wpww-f4p9.json index 4d79d7741ea..5d0a5454eb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xxj-wpww-f4p9/GHSA-4xxj-wpww-f4p9.json +++ b/advisories/unreviewed/2022/05/GHSA-4xxj-wpww-f4p9/GHSA-4xxj-wpww-f4p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json b/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json index a59ac8fc0bc..156f41545d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json +++ b/advisories/unreviewed/2022/05/GHSA-53qf-272p-ghf6/GHSA-53qf-272p-ghf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54gm-47p9-xr3r/GHSA-54gm-47p9-xr3r.json b/advisories/unreviewed/2022/05/GHSA-54gm-47p9-xr3r/GHSA-54gm-47p9-xr3r.json index 7faf935bcd0..97561f0ae9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-54gm-47p9-xr3r/GHSA-54gm-47p9-xr3r.json +++ b/advisories/unreviewed/2022/05/GHSA-54gm-47p9-xr3r/GHSA-54gm-47p9-xr3r.json @@ -7,12 +7,8 @@ "CVE-2019-11219" ], "details": "The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55g5-wxj5-7cv9/GHSA-55g5-wxj5-7cv9.json b/advisories/unreviewed/2022/05/GHSA-55g5-wxj5-7cv9/GHSA-55g5-wxj5-7cv9.json index c94d0154343..a2a846cec7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-55g5-wxj5-7cv9/GHSA-55g5-wxj5-7cv9.json +++ b/advisories/unreviewed/2022/05/GHSA-55g5-wxj5-7cv9/GHSA-55g5-wxj5-7cv9.json @@ -7,12 +7,8 @@ "CVE-2019-2664" ], "details": "Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-563g-v6qf-95gq/GHSA-563g-v6qf-95gq.json b/advisories/unreviewed/2022/05/GHSA-563g-v6qf-95gq/GHSA-563g-v6qf-95gq.json index bc26812eaaf..4cee7517557 100644 --- a/advisories/unreviewed/2022/05/GHSA-563g-v6qf-95gq/GHSA-563g-v6qf-95gq.json +++ b/advisories/unreviewed/2022/05/GHSA-563g-v6qf-95gq/GHSA-563g-v6qf-95gq.json @@ -7,12 +7,8 @@ "CVE-2019-11017" ], "details": "On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5665-6v3f-928v/GHSA-5665-6v3f-928v.json b/advisories/unreviewed/2022/05/GHSA-5665-6v3f-928v/GHSA-5665-6v3f-928v.json index a37e38a8dd2..b03c7284641 100644 --- a/advisories/unreviewed/2022/05/GHSA-5665-6v3f-928v/GHSA-5665-6v3f-928v.json +++ b/advisories/unreviewed/2022/05/GHSA-5665-6v3f-928v/GHSA-5665-6v3f-928v.json @@ -7,12 +7,8 @@ "CVE-2019-2662" ], "details": "Vulnerability in the Oracle Territory Management component of Oracle E-Business Suite (subcomponent: Territory Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Territory Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Territory Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Territory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Territory Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56qr-6hfh-52cg/GHSA-56qr-6hfh-52cg.json b/advisories/unreviewed/2022/05/GHSA-56qr-6hfh-52cg/GHSA-56qr-6hfh-52cg.json index 2d11f312145..15b5a758c8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-56qr-6hfh-52cg/GHSA-56qr-6hfh-52cg.json +++ b/advisories/unreviewed/2022/05/GHSA-56qr-6hfh-52cg/GHSA-56qr-6hfh-52cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56rf-q4xp-9h6w/GHSA-56rf-q4xp-9h6w.json b/advisories/unreviewed/2022/05/GHSA-56rf-q4xp-9h6w/GHSA-56rf-q4xp-9h6w.json index f1ee30c1e9d..a63af133979 100644 --- a/advisories/unreviewed/2022/05/GHSA-56rf-q4xp-9h6w/GHSA-56rf-q4xp-9h6w.json +++ b/advisories/unreviewed/2022/05/GHSA-56rf-q4xp-9h6w/GHSA-56rf-q4xp-9h6w.json @@ -7,12 +7,8 @@ "CVE-2019-11319" ], "details": "An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58pm-hq3j-r3vx/GHSA-58pm-hq3j-r3vx.json b/advisories/unreviewed/2022/05/GHSA-58pm-hq3j-r3vx/GHSA-58pm-hq3j-r3vx.json index 63d4b9bfb24..1bd61a77c0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-58pm-hq3j-r3vx/GHSA-58pm-hq3j-r3vx.json +++ b/advisories/unreviewed/2022/05/GHSA-58pm-hq3j-r3vx/GHSA-58pm-hq3j-r3vx.json @@ -7,12 +7,8 @@ "CVE-2019-11415" ], "details": "An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \\\"\"} string to v1/system/login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59wp-qpx3-fcf5/GHSA-59wp-qpx3-fcf5.json b/advisories/unreviewed/2022/05/GHSA-59wp-qpx3-fcf5/GHSA-59wp-qpx3-fcf5.json index faabf407b70..31d8a90a54e 100644 --- a/advisories/unreviewed/2022/05/GHSA-59wp-qpx3-fcf5/GHSA-59wp-qpx3-fcf5.json +++ b/advisories/unreviewed/2022/05/GHSA-59wp-qpx3-fcf5/GHSA-59wp-qpx3-fcf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59wx-wx8g-cfcx/GHSA-59wx-wx8g-cfcx.json b/advisories/unreviewed/2022/05/GHSA-59wx-wx8g-cfcx/GHSA-59wx-wx8g-cfcx.json index 12eff7b3ea1..a051059b852 100644 --- a/advisories/unreviewed/2022/05/GHSA-59wx-wx8g-cfcx/GHSA-59wx-wx8g-cfcx.json +++ b/advisories/unreviewed/2022/05/GHSA-59wx-wx8g-cfcx/GHSA-59wx-wx8g-cfcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cpx-m8gp-jj7j/GHSA-5cpx-m8gp-jj7j.json b/advisories/unreviewed/2022/05/GHSA-5cpx-m8gp-jj7j/GHSA-5cpx-m8gp-jj7j.json index fd153765703..fa38193a6b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cpx-m8gp-jj7j/GHSA-5cpx-m8gp-jj7j.json +++ b/advisories/unreviewed/2022/05/GHSA-5cpx-m8gp-jj7j/GHSA-5cpx-m8gp-jj7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hph-h6w5-vcf5/GHSA-5hph-h6w5-vcf5.json b/advisories/unreviewed/2022/05/GHSA-5hph-h6w5-vcf5/GHSA-5hph-h6w5-vcf5.json index b3a9d798b0f..0c41d2d3fb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hph-h6w5-vcf5/GHSA-5hph-h6w5-vcf5.json +++ b/advisories/unreviewed/2022/05/GHSA-5hph-h6w5-vcf5/GHSA-5hph-h6w5-vcf5.json @@ -7,12 +7,8 @@ "CVE-2019-2582" ], "details": "Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Core RDBMS accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5j8w-g8hc-6222/GHSA-5j8w-g8hc-6222.json b/advisories/unreviewed/2022/05/GHSA-5j8w-g8hc-6222/GHSA-5j8w-g8hc-6222.json index f1e18c66b29..302d01f6104 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j8w-g8hc-6222/GHSA-5j8w-g8hc-6222.json +++ b/advisories/unreviewed/2022/05/GHSA-5j8w-g8hc-6222/GHSA-5j8w-g8hc-6222.json @@ -7,12 +7,8 @@ "CVE-2012-2330" ], "details": "The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pjh-5gpx-359v/GHSA-5pjh-5gpx-359v.json b/advisories/unreviewed/2022/05/GHSA-5pjh-5gpx-359v/GHSA-5pjh-5gpx-359v.json index 065368243fb..7a1080ebf1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pjh-5gpx-359v/GHSA-5pjh-5gpx-359v.json +++ b/advisories/unreviewed/2022/05/GHSA-5pjh-5gpx-359v/GHSA-5pjh-5gpx-359v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5prc-43fj-m4f2/GHSA-5prc-43fj-m4f2.json b/advisories/unreviewed/2022/05/GHSA-5prc-43fj-m4f2/GHSA-5prc-43fj-m4f2.json index 525a344e108..2075d4b76fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5prc-43fj-m4f2/GHSA-5prc-43fj-m4f2.json +++ b/advisories/unreviewed/2022/05/GHSA-5prc-43fj-m4f2/GHSA-5prc-43fj-m4f2.json @@ -7,12 +7,8 @@ "CVE-2019-8452" ], "details": "A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r54-r4m5-pjhw/GHSA-5r54-r4m5-pjhw.json b/advisories/unreviewed/2022/05/GHSA-5r54-r4m5-pjhw/GHSA-5r54-r4m5-pjhw.json index d7d85a78d13..0531587f093 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r54-r4m5-pjhw/GHSA-5r54-r4m5-pjhw.json +++ b/advisories/unreviewed/2022/05/GHSA-5r54-r4m5-pjhw/GHSA-5r54-r4m5-pjhw.json @@ -7,12 +7,8 @@ "CVE-2019-2647" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r8v-mwp7-jjxq/GHSA-5r8v-mwp7-jjxq.json b/advisories/unreviewed/2022/05/GHSA-5r8v-mwp7-jjxq/GHSA-5r8v-mwp7-jjxq.json index fc02b57bab9..ba1b29dda4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r8v-mwp7-jjxq/GHSA-5r8v-mwp7-jjxq.json +++ b/advisories/unreviewed/2022/05/GHSA-5r8v-mwp7-jjxq/GHSA-5r8v-mwp7-jjxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5rrr-3j22-6ppf/GHSA-5rrr-3j22-6ppf.json b/advisories/unreviewed/2022/05/GHSA-5rrr-3j22-6ppf/GHSA-5rrr-3j22-6ppf.json index f49ddf5ef7c..310e84280c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rrr-3j22-6ppf/GHSA-5rrr-3j22-6ppf.json +++ b/advisories/unreviewed/2022/05/GHSA-5rrr-3j22-6ppf/GHSA-5rrr-3j22-6ppf.json @@ -7,12 +7,8 @@ "CVE-2019-2642" ], "details": "Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v46-5c9p-j4mg/GHSA-5v46-5c9p-j4mg.json b/advisories/unreviewed/2022/05/GHSA-5v46-5c9p-j4mg/GHSA-5v46-5c9p-j4mg.json index ea791df1c61..b8146b22e3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v46-5c9p-j4mg/GHSA-5v46-5c9p-j4mg.json +++ b/advisories/unreviewed/2022/05/GHSA-5v46-5c9p-j4mg/GHSA-5v46-5c9p-j4mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v9c-c23v-56m3/GHSA-5v9c-c23v-56m3.json b/advisories/unreviewed/2022/05/GHSA-5v9c-c23v-56m3/GHSA-5v9c-c23v-56m3.json index 01177376a0c..192ec2d7db8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v9c-c23v-56m3/GHSA-5v9c-c23v-56m3.json +++ b/advisories/unreviewed/2022/05/GHSA-5v9c-c23v-56m3/GHSA-5v9c-c23v-56m3.json @@ -7,12 +7,8 @@ "CVE-2019-1781" ], "details": "A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need administrator credentials to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wfq-p3hq-jw4m/GHSA-5wfq-p3hq-jw4m.json b/advisories/unreviewed/2022/05/GHSA-5wfq-p3hq-jw4m/GHSA-5wfq-p3hq-jw4m.json index efe5720e0a9..27635f96a2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wfq-p3hq-jw4m/GHSA-5wfq-p3hq-jw4m.json +++ b/advisories/unreviewed/2022/05/GHSA-5wfq-p3hq-jw4m/GHSA-5wfq-p3hq-jw4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xj7-h235-qpx8/GHSA-5xj7-h235-qpx8.json b/advisories/unreviewed/2022/05/GHSA-5xj7-h235-qpx8/GHSA-5xj7-h235-qpx8.json index fb8b5ae3e77..77e17c1f303 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xj7-h235-qpx8/GHSA-5xj7-h235-qpx8.json +++ b/advisories/unreviewed/2022/05/GHSA-5xj7-h235-qpx8/GHSA-5xj7-h235-qpx8.json @@ -7,12 +7,8 @@ "CVE-2010-4248" ], "details": "Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and the selection of a new thread group leader in the de_thread function in fs/exec.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62j3-37pc-h32g/GHSA-62j3-37pc-h32g.json b/advisories/unreviewed/2022/05/GHSA-62j3-37pc-h32g/GHSA-62j3-37pc-h32g.json index cba8bbdad6a..f82179df790 100644 --- a/advisories/unreviewed/2022/05/GHSA-62j3-37pc-h32g/GHSA-62j3-37pc-h32g.json +++ b/advisories/unreviewed/2022/05/GHSA-62j3-37pc-h32g/GHSA-62j3-37pc-h32g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62rf-fp64-gxpc/GHSA-62rf-fp64-gxpc.json b/advisories/unreviewed/2022/05/GHSA-62rf-fp64-gxpc/GHSA-62rf-fp64-gxpc.json index 798df9e55da..4a92ca62183 100644 --- a/advisories/unreviewed/2022/05/GHSA-62rf-fp64-gxpc/GHSA-62rf-fp64-gxpc.json +++ b/advisories/unreviewed/2022/05/GHSA-62rf-fp64-gxpc/GHSA-62rf-fp64-gxpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-632m-3qm6-rpqw/GHSA-632m-3qm6-rpqw.json b/advisories/unreviewed/2022/05/GHSA-632m-3qm6-rpqw/GHSA-632m-3qm6-rpqw.json index 83b36e88533..0aef6b7da32 100644 --- a/advisories/unreviewed/2022/05/GHSA-632m-3qm6-rpqw/GHSA-632m-3qm6-rpqw.json +++ b/advisories/unreviewed/2022/05/GHSA-632m-3qm6-rpqw/GHSA-632m-3qm6-rpqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6464-wc5j-3x4p/GHSA-6464-wc5j-3x4p.json b/advisories/unreviewed/2022/05/GHSA-6464-wc5j-3x4p/GHSA-6464-wc5j-3x4p.json index 59f88997f00..cd25f0b0379 100644 --- a/advisories/unreviewed/2022/05/GHSA-6464-wc5j-3x4p/GHSA-6464-wc5j-3x4p.json +++ b/advisories/unreviewed/2022/05/GHSA-6464-wc5j-3x4p/GHSA-6464-wc5j-3x4p.json @@ -7,12 +7,8 @@ "CVE-2019-2600" ], "details": "Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65qj-84mc-xh49/GHSA-65qj-84mc-xh49.json b/advisories/unreviewed/2022/05/GHSA-65qj-84mc-xh49/GHSA-65qj-84mc-xh49.json index 194d2876c14..7a879300868 100644 --- a/advisories/unreviewed/2022/05/GHSA-65qj-84mc-xh49/GHSA-65qj-84mc-xh49.json +++ b/advisories/unreviewed/2022/05/GHSA-65qj-84mc-xh49/GHSA-65qj-84mc-xh49.json @@ -7,12 +7,8 @@ "CVE-2019-1790" ], "details": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with valid administrator credentials to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6642-6xcj-fvp6/GHSA-6642-6xcj-fvp6.json b/advisories/unreviewed/2022/05/GHSA-6642-6xcj-fvp6/GHSA-6642-6xcj-fvp6.json index 58370125a93..d32fff69da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6642-6xcj-fvp6/GHSA-6642-6xcj-fvp6.json +++ b/advisories/unreviewed/2022/05/GHSA-6642-6xcj-fvp6/GHSA-6642-6xcj-fvp6.json @@ -7,12 +7,8 @@ "CVE-2019-2558" ], "details": "Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Infrastructure). Supported versions that are affected are 13.4, 14.0 and 14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Point-of-Service. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Point-of-Service accessible data as well as unauthorized read access to a subset of Oracle Retail Point-of-Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Point-of-Service. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-664g-32r8-gj3v/GHSA-664g-32r8-gj3v.json b/advisories/unreviewed/2022/05/GHSA-664g-32r8-gj3v/GHSA-664g-32r8-gj3v.json index 9e40f302694..ec4c36971c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-664g-32r8-gj3v/GHSA-664g-32r8-gj3v.json +++ b/advisories/unreviewed/2022/05/GHSA-664g-32r8-gj3v/GHSA-664g-32r8-gj3v.json @@ -7,12 +7,8 @@ "CVE-2019-2604" ], "details": "Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67fq-99w3-mv56/GHSA-67fq-99w3-mv56.json b/advisories/unreviewed/2022/05/GHSA-67fq-99w3-mv56/GHSA-67fq-99w3-mv56.json index 182559aa093..37611e86674 100644 --- a/advisories/unreviewed/2022/05/GHSA-67fq-99w3-mv56/GHSA-67fq-99w3-mv56.json +++ b/advisories/unreviewed/2022/05/GHSA-67fq-99w3-mv56/GHSA-67fq-99w3-mv56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6837-f96c-5j64/GHSA-6837-f96c-5j64.json b/advisories/unreviewed/2022/05/GHSA-6837-f96c-5j64/GHSA-6837-f96c-5j64.json index ba696683501..d7200d41bc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6837-f96c-5j64/GHSA-6837-f96c-5j64.json +++ b/advisories/unreviewed/2022/05/GHSA-6837-f96c-5j64/GHSA-6837-f96c-5j64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-683h-m32r-vcgg/GHSA-683h-m32r-vcgg.json b/advisories/unreviewed/2022/05/GHSA-683h-m32r-vcgg/GHSA-683h-m32r-vcgg.json index 949e6d84146..07b44c17890 100644 --- a/advisories/unreviewed/2022/05/GHSA-683h-m32r-vcgg/GHSA-683h-m32r-vcgg.json +++ b/advisories/unreviewed/2022/05/GHSA-683h-m32r-vcgg/GHSA-683h-m32r-vcgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68xv-2p42-wm3q/GHSA-68xv-2p42-wm3q.json b/advisories/unreviewed/2022/05/GHSA-68xv-2p42-wm3q/GHSA-68xv-2p42-wm3q.json index bf7787e0a3d..947558c0dcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-68xv-2p42-wm3q/GHSA-68xv-2p42-wm3q.json +++ b/advisories/unreviewed/2022/05/GHSA-68xv-2p42-wm3q/GHSA-68xv-2p42-wm3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-699f-vfp8-xj53/GHSA-699f-vfp8-xj53.json b/advisories/unreviewed/2022/05/GHSA-699f-vfp8-xj53/GHSA-699f-vfp8-xj53.json index b26d986d03c..7709fecd2c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-699f-vfp8-xj53/GHSA-699f-vfp8-xj53.json +++ b/advisories/unreviewed/2022/05/GHSA-699f-vfp8-xj53/GHSA-699f-vfp8-xj53.json @@ -7,12 +7,8 @@ "CVE-2019-2611" ], "details": "Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69gq-m98f-jh3r/GHSA-69gq-m98f-jh3r.json b/advisories/unreviewed/2022/05/GHSA-69gq-m98f-jh3r/GHSA-69gq-m98f-jh3r.json index 9f438397bc9..e57c1b5efa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-69gq-m98f-jh3r/GHSA-69gq-m98f-jh3r.json +++ b/advisories/unreviewed/2022/05/GHSA-69gq-m98f-jh3r/GHSA-69gq-m98f-jh3r.json @@ -7,12 +7,8 @@ "CVE-2019-2671" ], "details": "Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69xr-64hc-h4r8/GHSA-69xr-64hc-h4r8.json b/advisories/unreviewed/2022/05/GHSA-69xr-64hc-h4r8/GHSA-69xr-64hc-h4r8.json index fb8b510c93d..bbcb5c52e1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-69xr-64hc-h4r8/GHSA-69xr-64hc-h4r8.json +++ b/advisories/unreviewed/2022/05/GHSA-69xr-64hc-h4r8/GHSA-69xr-64hc-h4r8.json @@ -7,12 +7,8 @@ "CVE-2019-2583" ], "details": "Vulnerability in the Oracle iSupplier Portal component of Oracle E-Business Suite (subcomponent: Attachments). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupplier Portal, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupplier Portal accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c53-pfqv-mx96/GHSA-6c53-pfqv-mx96.json b/advisories/unreviewed/2022/05/GHSA-6c53-pfqv-mx96/GHSA-6c53-pfqv-mx96.json index 89f7999682d..1bdd39b609f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c53-pfqv-mx96/GHSA-6c53-pfqv-mx96.json +++ b/advisories/unreviewed/2022/05/GHSA-6c53-pfqv-mx96/GHSA-6c53-pfqv-mx96.json @@ -7,12 +7,8 @@ "CVE-2019-9798" ], "details": "On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fq2-2mw9-3j26/GHSA-6fq2-2mw9-3j26.json b/advisories/unreviewed/2022/05/GHSA-6fq2-2mw9-3j26/GHSA-6fq2-2mw9-3j26.json index 749cf4688ba..701b3dcac89 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fq2-2mw9-3j26/GHSA-6fq2-2mw9-3j26.json +++ b/advisories/unreviewed/2022/05/GHSA-6fq2-2mw9-3j26/GHSA-6fq2-2mw9-3j26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gr3-gw4j-hphq/GHSA-6gr3-gw4j-hphq.json b/advisories/unreviewed/2022/05/GHSA-6gr3-gw4j-hphq/GHSA-6gr3-gw4j-hphq.json index b9c3acac3a9..6ea6171854e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gr3-gw4j-hphq/GHSA-6gr3-gw4j-hphq.json +++ b/advisories/unreviewed/2022/05/GHSA-6gr3-gw4j-hphq/GHSA-6gr3-gw4j-hphq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hgm-wcrx-jjw5/GHSA-6hgm-wcrx-jjw5.json b/advisories/unreviewed/2022/05/GHSA-6hgm-wcrx-jjw5/GHSA-6hgm-wcrx-jjw5.json index 829a753668d..3560b8cae26 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hgm-wcrx-jjw5/GHSA-6hgm-wcrx-jjw5.json +++ b/advisories/unreviewed/2022/05/GHSA-6hgm-wcrx-jjw5/GHSA-6hgm-wcrx-jjw5.json @@ -7,12 +7,8 @@ "CVE-2019-3719" ], "details": "Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j2f-925p-c58v/GHSA-6j2f-925p-c58v.json b/advisories/unreviewed/2022/05/GHSA-6j2f-925p-c58v/GHSA-6j2f-925p-c58v.json index 8d913e614b8..2fe65c0f939 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j2f-925p-c58v/GHSA-6j2f-925p-c58v.json +++ b/advisories/unreviewed/2022/05/GHSA-6j2f-925p-c58v/GHSA-6j2f-925p-c58v.json @@ -7,12 +7,8 @@ "CVE-2019-10922" ], "details": "A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions). An attacker with network access to affected installations, which are configured without \"Encrypted Communication\", can execute arbitrary code. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected installation. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j5v-g8wm-9r98/GHSA-6j5v-g8wm-9r98.json b/advisories/unreviewed/2022/05/GHSA-6j5v-g8wm-9r98/GHSA-6j5v-g8wm-9r98.json index 6cb0fdd6815..36189337d04 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j5v-g8wm-9r98/GHSA-6j5v-g8wm-9r98.json +++ b/advisories/unreviewed/2022/05/GHSA-6j5v-g8wm-9r98/GHSA-6j5v-g8wm-9r98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jwq-rcg9-g7r3/GHSA-6jwq-rcg9-g7r3.json b/advisories/unreviewed/2022/05/GHSA-6jwq-rcg9-g7r3/GHSA-6jwq-rcg9-g7r3.json index 393b48b6da0..4c1d9f84c7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jwq-rcg9-g7r3/GHSA-6jwq-rcg9-g7r3.json +++ b/advisories/unreviewed/2022/05/GHSA-6jwq-rcg9-g7r3/GHSA-6jwq-rcg9-g7r3.json @@ -7,12 +7,8 @@ "CVE-2018-18823" ], "details": "WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mpj-9376-4g2w/GHSA-6mpj-9376-4g2w.json b/advisories/unreviewed/2022/05/GHSA-6mpj-9376-4g2w/GHSA-6mpj-9376-4g2w.json index cf6a7398eac..cc31f16a976 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mpj-9376-4g2w/GHSA-6mpj-9376-4g2w.json +++ b/advisories/unreviewed/2022/05/GHSA-6mpj-9376-4g2w/GHSA-6mpj-9376-4g2w.json @@ -7,12 +7,8 @@ "CVE-2018-18366" ], "details": "Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mrp-f323-h9mx/GHSA-6mrp-f323-h9mx.json b/advisories/unreviewed/2022/05/GHSA-6mrp-f323-h9mx/GHSA-6mrp-f323-h9mx.json index 8d04af3d0a5..9fd679c9cad 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mrp-f323-h9mx/GHSA-6mrp-f323-h9mx.json +++ b/advisories/unreviewed/2022/05/GHSA-6mrp-f323-h9mx/GHSA-6mrp-f323-h9mx.json @@ -7,12 +7,8 @@ "CVE-2019-2567" ], "details": "Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: Active Model Generation). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p8w-pqqx-8fpc/GHSA-6p8w-pqqx-8fpc.json b/advisories/unreviewed/2022/05/GHSA-6p8w-pqqx-8fpc/GHSA-6p8w-pqqx-8fpc.json index 79ac6d279d2..983aea96462 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p8w-pqqx-8fpc/GHSA-6p8w-pqqx-8fpc.json +++ b/advisories/unreviewed/2022/05/GHSA-6p8w-pqqx-8fpc/GHSA-6p8w-pqqx-8fpc.json @@ -7,12 +7,8 @@ "CVE-2019-11384" ], "details": "The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), which allows a non-root user to find out the username/password of a valid user via /data/data/com.zalora.android/shared_prefs/login_data.xml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q52-cg2r-w8jw/GHSA-6q52-cg2r-w8jw.json b/advisories/unreviewed/2022/05/GHSA-6q52-cg2r-w8jw/GHSA-6q52-cg2r-w8jw.json index c36ffa811d0..e0dc211e727 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q52-cg2r-w8jw/GHSA-6q52-cg2r-w8jw.json +++ b/advisories/unreviewed/2022/05/GHSA-6q52-cg2r-w8jw/GHSA-6q52-cg2r-w8jw.json @@ -7,12 +7,8 @@ "CVE-2016-10749" ], "details": "parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a \" character and ends with a \\ character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json b/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json index c4ea86bffca..65002e30480 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json +++ b/advisories/unreviewed/2022/05/GHSA-6q52-mr9g-rhrv/GHSA-6q52-mr9g-rhrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qh9-2jmr-mwmj/GHSA-6qh9-2jmr-mwmj.json b/advisories/unreviewed/2022/05/GHSA-6qh9-2jmr-mwmj/GHSA-6qh9-2jmr-mwmj.json index 8605c571b59..fe25b4ce97c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qh9-2jmr-mwmj/GHSA-6qh9-2jmr-mwmj.json +++ b/advisories/unreviewed/2022/05/GHSA-6qh9-2jmr-mwmj/GHSA-6qh9-2jmr-mwmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r93-m2cp-hhmf/GHSA-6r93-m2cp-hhmf.json b/advisories/unreviewed/2022/05/GHSA-6r93-m2cp-hhmf/GHSA-6r93-m2cp-hhmf.json index 3b684f3fb12..98a26ed6e93 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r93-m2cp-hhmf/GHSA-6r93-m2cp-hhmf.json +++ b/advisories/unreviewed/2022/05/GHSA-6r93-m2cp-hhmf/GHSA-6r93-m2cp-hhmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vgf-xpr3-4724/GHSA-6vgf-xpr3-4724.json b/advisories/unreviewed/2022/05/GHSA-6vgf-xpr3-4724/GHSA-6vgf-xpr3-4724.json index f067c2308fd..0027706bfd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vgf-xpr3-4724/GHSA-6vgf-xpr3-4724.json +++ b/advisories/unreviewed/2022/05/GHSA-6vgf-xpr3-4724/GHSA-6vgf-xpr3-4724.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wr5-v37w-q3rj/GHSA-6wr5-v37w-q3rj.json b/advisories/unreviewed/2022/05/GHSA-6wr5-v37w-q3rj/GHSA-6wr5-v37w-q3rj.json index 607b5dd703c..d06973c5dbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wr5-v37w-q3rj/GHSA-6wr5-v37w-q3rj.json +++ b/advisories/unreviewed/2022/05/GHSA-6wr5-v37w-q3rj/GHSA-6wr5-v37w-q3rj.json @@ -7,12 +7,8 @@ "CVE-2019-1730" ], "details": "A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute commands at the privilege level of a network-admin user outside of the Guest Shell. The attacker must authenticate with valid administrator device credentials. The vulnerability is due to the incorrect implementation of a CLI command that allows a Bash command to be incorrectly invoked on the Guest Shell CLI. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Guest Shell prompt. A successful exploit could allow the attacker to issue commands that should be restricted by a Guest Shell account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7226-rhpg-6rjh/GHSA-7226-rhpg-6rjh.json b/advisories/unreviewed/2022/05/GHSA-7226-rhpg-6rjh/GHSA-7226-rhpg-6rjh.json index 55c92043d85..d303e839b6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7226-rhpg-6rjh/GHSA-7226-rhpg-6rjh.json +++ b/advisories/unreviewed/2022/05/GHSA-7226-rhpg-6rjh/GHSA-7226-rhpg-6rjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-724h-f4rh-cc47/GHSA-724h-f4rh-cc47.json b/advisories/unreviewed/2022/05/GHSA-724h-f4rh-cc47/GHSA-724h-f4rh-cc47.json index 069474a3372..ce12b67e0fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-724h-f4rh-cc47/GHSA-724h-f4rh-cc47.json +++ b/advisories/unreviewed/2022/05/GHSA-724h-f4rh-cc47/GHSA-724h-f4rh-cc47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-725m-pg3w-h3c9/GHSA-725m-pg3w-h3c9.json b/advisories/unreviewed/2022/05/GHSA-725m-pg3w-h3c9/GHSA-725m-pg3w-h3c9.json index 60df8e63a45..04a0f684678 100644 --- a/advisories/unreviewed/2022/05/GHSA-725m-pg3w-h3c9/GHSA-725m-pg3w-h3c9.json +++ b/advisories/unreviewed/2022/05/GHSA-725m-pg3w-h3c9/GHSA-725m-pg3w-h3c9.json @@ -7,12 +7,8 @@ "CVE-2019-2656" ], "details": "Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72r5-4jgc-xj7v/GHSA-72r5-4jgc-xj7v.json b/advisories/unreviewed/2022/05/GHSA-72r5-4jgc-xj7v/GHSA-72r5-4jgc-xj7v.json index be2b3733046..a42dcb68858 100644 --- a/advisories/unreviewed/2022/05/GHSA-72r5-4jgc-xj7v/GHSA-72r5-4jgc-xj7v.json +++ b/advisories/unreviewed/2022/05/GHSA-72r5-4jgc-xj7v/GHSA-72r5-4jgc-xj7v.json @@ -7,12 +7,8 @@ "CVE-2019-2516" ], "details": "Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7573-qg6f-w5c4/GHSA-7573-qg6f-w5c4.json b/advisories/unreviewed/2022/05/GHSA-7573-qg6f-w5c4/GHSA-7573-qg6f-w5c4.json index cc24da6f654..99d30669b30 100644 --- a/advisories/unreviewed/2022/05/GHSA-7573-qg6f-w5c4/GHSA-7573-qg6f-w5c4.json +++ b/advisories/unreviewed/2022/05/GHSA-7573-qg6f-w5c4/GHSA-7573-qg6f-w5c4.json @@ -7,12 +7,8 @@ "CVE-2019-11417" ], "details": "system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7577-f2mx-w9rc/GHSA-7577-f2mx-w9rc.json b/advisories/unreviewed/2022/05/GHSA-7577-f2mx-w9rc/GHSA-7577-f2mx-w9rc.json index ace4862e393..f000192a936 100644 --- a/advisories/unreviewed/2022/05/GHSA-7577-f2mx-w9rc/GHSA-7577-f2mx-w9rc.json +++ b/advisories/unreviewed/2022/05/GHSA-7577-f2mx-w9rc/GHSA-7577-f2mx-w9rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75v7-h9gp-f766/GHSA-75v7-h9gp-f766.json b/advisories/unreviewed/2022/05/GHSA-75v7-h9gp-f766/GHSA-75v7-h9gp-f766.json index 97f31e44b8f..69a025bcc45 100644 --- a/advisories/unreviewed/2022/05/GHSA-75v7-h9gp-f766/GHSA-75v7-h9gp-f766.json +++ b/advisories/unreviewed/2022/05/GHSA-75v7-h9gp-f766/GHSA-75v7-h9gp-f766.json @@ -7,12 +7,8 @@ "CVE-2019-7745" ], "details": "JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the wpa_security_key field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76h7-m86v-wq78/GHSA-76h7-m86v-wq78.json b/advisories/unreviewed/2022/05/GHSA-76h7-m86v-wq78/GHSA-76h7-m86v-wq78.json index 2581c34ce69..9774539d0ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-76h7-m86v-wq78/GHSA-76h7-m86v-wq78.json +++ b/advisories/unreviewed/2022/05/GHSA-76h7-m86v-wq78/GHSA-76h7-m86v-wq78.json @@ -7,12 +7,8 @@ "CVE-2019-3705" ], "details": "Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76p6-vjx7-f4xh/GHSA-76p6-vjx7-f4xh.json b/advisories/unreviewed/2022/05/GHSA-76p6-vjx7-f4xh/GHSA-76p6-vjx7-f4xh.json index 328d16d427c..e4c5619767b 100644 --- a/advisories/unreviewed/2022/05/GHSA-76p6-vjx7-f4xh/GHSA-76p6-vjx7-f4xh.json +++ b/advisories/unreviewed/2022/05/GHSA-76p6-vjx7-f4xh/GHSA-76p6-vjx7-f4xh.json @@ -7,12 +7,8 @@ "CVE-2019-2651" ], "details": "Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77m2-2x4h-2jg6/GHSA-77m2-2x4h-2jg6.json b/advisories/unreviewed/2022/05/GHSA-77m2-2x4h-2jg6/GHSA-77m2-2x4h-2jg6.json index 38128abd020..6e9a4ebc842 100644 --- a/advisories/unreviewed/2022/05/GHSA-77m2-2x4h-2jg6/GHSA-77m2-2x4h-2jg6.json +++ b/advisories/unreviewed/2022/05/GHSA-77m2-2x4h-2jg6/GHSA-77m2-2x4h-2jg6.json @@ -7,12 +7,8 @@ "CVE-2013-4542" ], "details": "The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79mw-6jhw-7997/GHSA-79mw-6jhw-7997.json b/advisories/unreviewed/2022/05/GHSA-79mw-6jhw-7997/GHSA-79mw-6jhw-7997.json index 7948a873716..e0687fad9df 100644 --- a/advisories/unreviewed/2022/05/GHSA-79mw-6jhw-7997/GHSA-79mw-6jhw-7997.json +++ b/advisories/unreviewed/2022/05/GHSA-79mw-6jhw-7997/GHSA-79mw-6jhw-7997.json @@ -7,12 +7,8 @@ "CVE-2010-3301" ], "details": "The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79pw-9mjh-72cp/GHSA-79pw-9mjh-72cp.json b/advisories/unreviewed/2022/05/GHSA-79pw-9mjh-72cp/GHSA-79pw-9mjh-72cp.json index 449b0722929..51c4b1e1afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-79pw-9mjh-72cp/GHSA-79pw-9mjh-72cp.json +++ b/advisories/unreviewed/2022/05/GHSA-79pw-9mjh-72cp/GHSA-79pw-9mjh-72cp.json @@ -7,12 +7,8 @@ "CVE-2018-1720" ], "details": "IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 147294.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79v6-3g86-v959/GHSA-79v6-3g86-v959.json b/advisories/unreviewed/2022/05/GHSA-79v6-3g86-v959/GHSA-79v6-3g86-v959.json index dea09c7f689..24382d6e4a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-79v6-3g86-v959/GHSA-79v6-3g86-v959.json +++ b/advisories/unreviewed/2022/05/GHSA-79v6-3g86-v959/GHSA-79v6-3g86-v959.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g2v-29mr-2f42/GHSA-7g2v-29mr-2f42.json b/advisories/unreviewed/2022/05/GHSA-7g2v-29mr-2f42/GHSA-7g2v-29mr-2f42.json index 6a04102e6e2..6160f9d43c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g2v-29mr-2f42/GHSA-7g2v-29mr-2f42.json +++ b/advisories/unreviewed/2022/05/GHSA-7g2v-29mr-2f42/GHSA-7g2v-29mr-2f42.json @@ -7,12 +7,8 @@ "CVE-2019-7564" ], "details": "An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7gjg-3mrx-xxf9/GHSA-7gjg-3mrx-xxf9.json b/advisories/unreviewed/2022/05/GHSA-7gjg-3mrx-xxf9/GHSA-7gjg-3mrx-xxf9.json index 2606d9728e5..df61d00fb08 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gjg-3mrx-xxf9/GHSA-7gjg-3mrx-xxf9.json +++ b/advisories/unreviewed/2022/05/GHSA-7gjg-3mrx-xxf9/GHSA-7gjg-3mrx-xxf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j2p-qr4g-pg5x/GHSA-7j2p-qr4g-pg5x.json b/advisories/unreviewed/2022/05/GHSA-7j2p-qr4g-pg5x/GHSA-7j2p-qr4g-pg5x.json index 46050930386..b4dd637eaf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j2p-qr4g-pg5x/GHSA-7j2p-qr4g-pg5x.json +++ b/advisories/unreviewed/2022/05/GHSA-7j2p-qr4g-pg5x/GHSA-7j2p-qr4g-pg5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jqv-hh4c-ww3h/GHSA-7jqv-hh4c-ww3h.json b/advisories/unreviewed/2022/05/GHSA-7jqv-hh4c-ww3h/GHSA-7jqv-hh4c-ww3h.json index 6d25d511b8c..052f6e354a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jqv-hh4c-ww3h/GHSA-7jqv-hh4c-ww3h.json +++ b/advisories/unreviewed/2022/05/GHSA-7jqv-hh4c-ww3h/GHSA-7jqv-hh4c-ww3h.json @@ -7,12 +7,8 @@ "CVE-2011-1951" ], "details": "lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7m2c-p89r-q8ff/GHSA-7m2c-p89r-q8ff.json b/advisories/unreviewed/2022/05/GHSA-7m2c-p89r-q8ff/GHSA-7m2c-p89r-q8ff.json index dec4ab30ff1..8695f94084f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m2c-p89r-q8ff/GHSA-7m2c-p89r-q8ff.json +++ b/advisories/unreviewed/2022/05/GHSA-7m2c-p89r-q8ff/GHSA-7m2c-p89r-q8ff.json @@ -7,12 +7,8 @@ "CVE-2019-2565" ], "details": "Vulnerability in the JD Edwards World Technical Foundation component of Oracle JD Edwards Products (subcomponent: Service Enablement). Supported versions that are affected are A9.2, A9.3.1 and A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Technical Foundation. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards World Technical Foundation accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pcf-w384-7jc9/GHSA-7pcf-w384-7jc9.json b/advisories/unreviewed/2022/05/GHSA-7pcf-w384-7jc9/GHSA-7pcf-w384-7jc9.json index fc59e5cc929..f4d144f035e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pcf-w384-7jc9/GHSA-7pcf-w384-7jc9.json +++ b/advisories/unreviewed/2022/05/GHSA-7pcf-w384-7jc9/GHSA-7pcf-w384-7jc9.json @@ -7,12 +7,8 @@ "CVE-2019-2424" ], "details": "Vulnerability in the Oracle Retail Convenience Store Back Office component of Oracle Retail Applications (subcomponent: Level 3 Maintenance Functions). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Convenience Store Back Office. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Convenience Store Back Office accessible data as well as unauthorized read access to a subset of Oracle Retail Convenience Store Back Office accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Convenience Store Back Office. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qw8-88j7-x8gr/GHSA-7qw8-88j7-x8gr.json b/advisories/unreviewed/2022/05/GHSA-7qw8-88j7-x8gr/GHSA-7qw8-88j7-x8gr.json index 71421c8d95b..ea91bf9eb71 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qw8-88j7-x8gr/GHSA-7qw8-88j7-x8gr.json +++ b/advisories/unreviewed/2022/05/GHSA-7qw8-88j7-x8gr/GHSA-7qw8-88j7-x8gr.json @@ -7,12 +7,8 @@ "CVE-2019-3493" ], "details": "A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions. The vulnerability could be remotely exploited to Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rp3-hp6r-f2pw/GHSA-7rp3-hp6r-f2pw.json b/advisories/unreviewed/2022/05/GHSA-7rp3-hp6r-f2pw/GHSA-7rp3-hp6r-f2pw.json index fd63d6763a1..6e4ef9d9e1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rp3-hp6r-f2pw/GHSA-7rp3-hp6r-f2pw.json +++ b/advisories/unreviewed/2022/05/GHSA-7rp3-hp6r-f2pw/GHSA-7rp3-hp6r-f2pw.json @@ -7,12 +7,8 @@ "CVE-2019-1791" ], "details": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vv7-v9gp-whmr/GHSA-7vv7-v9gp-whmr.json b/advisories/unreviewed/2022/05/GHSA-7vv7-v9gp-whmr/GHSA-7vv7-v9gp-whmr.json index 76bc3696c1c..4b5194b56ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vv7-v9gp-whmr/GHSA-7vv7-v9gp-whmr.json +++ b/advisories/unreviewed/2022/05/GHSA-7vv7-v9gp-whmr/GHSA-7vv7-v9gp-whmr.json @@ -7,12 +7,8 @@ "CVE-2019-3558" ], "details": "Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w4w-2hxm-8cc6/GHSA-7w4w-2hxm-8cc6.json b/advisories/unreviewed/2022/05/GHSA-7w4w-2hxm-8cc6/GHSA-7w4w-2hxm-8cc6.json index 31c67cc5f1e..2c97fab6feb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w4w-2hxm-8cc6/GHSA-7w4w-2hxm-8cc6.json +++ b/advisories/unreviewed/2022/05/GHSA-7w4w-2hxm-8cc6/GHSA-7w4w-2hxm-8cc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wgm-pvjv-p545/GHSA-7wgm-pvjv-p545.json b/advisories/unreviewed/2022/05/GHSA-7wgm-pvjv-p545/GHSA-7wgm-pvjv-p545.json index cbd079a9359..361d8c45fee 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wgm-pvjv-p545/GHSA-7wgm-pvjv-p545.json +++ b/advisories/unreviewed/2022/05/GHSA-7wgm-pvjv-p545/GHSA-7wgm-pvjv-p545.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83fw-4w4c-4v29/GHSA-83fw-4w4c-4v29.json b/advisories/unreviewed/2022/05/GHSA-83fw-4w4c-4v29/GHSA-83fw-4w4c-4v29.json index bae185955ed..c95baa19d8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-83fw-4w4c-4v29/GHSA-83fw-4w4c-4v29.json +++ b/advisories/unreviewed/2022/05/GHSA-83fw-4w4c-4v29/GHSA-83fw-4w4c-4v29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83pj-f384-34m7/GHSA-83pj-f384-34m7.json b/advisories/unreviewed/2022/05/GHSA-83pj-f384-34m7/GHSA-83pj-f384-34m7.json index 260c8756aef..88fa620c8e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-83pj-f384-34m7/GHSA-83pj-f384-34m7.json +++ b/advisories/unreviewed/2022/05/GHSA-83pj-f384-34m7/GHSA-83pj-f384-34m7.json @@ -7,12 +7,8 @@ "CVE-2019-2663" ], "details": "Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83vv-q4vw-p24m/GHSA-83vv-q4vw-p24m.json b/advisories/unreviewed/2022/05/GHSA-83vv-q4vw-p24m/GHSA-83vv-q4vw-p24m.json index 756061ab63e..3f9f3ac79fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-83vv-q4vw-p24m/GHSA-83vv-q4vw-p24m.json +++ b/advisories/unreviewed/2022/05/GHSA-83vv-q4vw-p24m/GHSA-83vv-q4vw-p24m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84r2-hp76-hh77/GHSA-84r2-hp76-hh77.json b/advisories/unreviewed/2022/05/GHSA-84r2-hp76-hh77/GHSA-84r2-hp76-hh77.json index 15856ce27fc..2a7b1cbd9e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-84r2-hp76-hh77/GHSA-84r2-hp76-hh77.json +++ b/advisories/unreviewed/2022/05/GHSA-84r2-hp76-hh77/GHSA-84r2-hp76-hh77.json @@ -7,12 +7,8 @@ "CVE-2019-11472" ], "details": "ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85m9-wggc-372h/GHSA-85m9-wggc-372h.json b/advisories/unreviewed/2022/05/GHSA-85m9-wggc-372h/GHSA-85m9-wggc-372h.json index 4e663b093ea..49defc779c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-85m9-wggc-372h/GHSA-85m9-wggc-372h.json +++ b/advisories/unreviewed/2022/05/GHSA-85m9-wggc-372h/GHSA-85m9-wggc-372h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-864h-5wf6-hrwh/GHSA-864h-5wf6-hrwh.json b/advisories/unreviewed/2022/05/GHSA-864h-5wf6-hrwh/GHSA-864h-5wf6-hrwh.json index d623fee8755..a74b8a39c18 100644 --- a/advisories/unreviewed/2022/05/GHSA-864h-5wf6-hrwh/GHSA-864h-5wf6-hrwh.json +++ b/advisories/unreviewed/2022/05/GHSA-864h-5wf6-hrwh/GHSA-864h-5wf6-hrwh.json @@ -7,12 +7,8 @@ "CVE-2018-18824" ], "details": "WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8926-mj52-jxcv/GHSA-8926-mj52-jxcv.json b/advisories/unreviewed/2022/05/GHSA-8926-mj52-jxcv/GHSA-8926-mj52-jxcv.json index 44f17f37e35..c827fdaf58b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8926-mj52-jxcv/GHSA-8926-mj52-jxcv.json +++ b/advisories/unreviewed/2022/05/GHSA-8926-mj52-jxcv/GHSA-8926-mj52-jxcv.json @@ -7,12 +7,8 @@ "CVE-2019-3927" ], "details": "Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to change the admin or moderator user's password and gain access to restricted areas on the HTTP interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89jr-435v-r2g3/GHSA-89jr-435v-r2g3.json b/advisories/unreviewed/2022/05/GHSA-89jr-435v-r2g3/GHSA-89jr-435v-r2g3.json index 9c83ba794e1..9e78647c6e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-89jr-435v-r2g3/GHSA-89jr-435v-r2g3.json +++ b/advisories/unreviewed/2022/05/GHSA-89jr-435v-r2g3/GHSA-89jr-435v-r2g3.json @@ -7,12 +7,8 @@ "CVE-2019-2677" ], "details": "Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cc7-m958-9r87/GHSA-8cc7-m958-9r87.json b/advisories/unreviewed/2022/05/GHSA-8cc7-m958-9r87/GHSA-8cc7-m958-9r87.json index b2da2accd4c..df9bf899da4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cc7-m958-9r87/GHSA-8cc7-m958-9r87.json +++ b/advisories/unreviewed/2022/05/GHSA-8cc7-m958-9r87/GHSA-8cc7-m958-9r87.json @@ -7,12 +7,8 @@ "CVE-2010-3698" ], "details": "The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g7j-8p7x-qq3c/GHSA-8g7j-8p7x-qq3c.json b/advisories/unreviewed/2022/05/GHSA-8g7j-8p7x-qq3c/GHSA-8g7j-8p7x-qq3c.json index 563235bc55b..603448eb992 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g7j-8p7x-qq3c/GHSA-8g7j-8p7x-qq3c.json +++ b/advisories/unreviewed/2022/05/GHSA-8g7j-8p7x-qq3c/GHSA-8g7j-8p7x-qq3c.json @@ -7,12 +7,8 @@ "CVE-2019-11888" ], "details": "Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gq5-wmr9-rcvv/GHSA-8gq5-wmr9-rcvv.json b/advisories/unreviewed/2022/05/GHSA-8gq5-wmr9-rcvv/GHSA-8gq5-wmr9-rcvv.json index e8cdce9f0c5..8fc7b06a1bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gq5-wmr9-rcvv/GHSA-8gq5-wmr9-rcvv.json +++ b/advisories/unreviewed/2022/05/GHSA-8gq5-wmr9-rcvv/GHSA-8gq5-wmr9-rcvv.json @@ -7,12 +7,8 @@ "CVE-2019-2601" ], "details": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data as well as unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json b/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json index dccfba9e5a9..3909b562a44 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json +++ b/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json @@ -7,12 +7,8 @@ "CVE-2019-2616" ], "details": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8j47-63h6-77w9/GHSA-8j47-63h6-77w9.json b/advisories/unreviewed/2022/05/GHSA-8j47-63h6-77w9/GHSA-8j47-63h6-77w9.json index b57c27c5eac..c7b03c5b562 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j47-63h6-77w9/GHSA-8j47-63h6-77w9.json +++ b/advisories/unreviewed/2022/05/GHSA-8j47-63h6-77w9/GHSA-8j47-63h6-77w9.json @@ -7,12 +7,8 @@ "CVE-2017-18279" ], "details": "Lack of check of buffer length before copying can lead to buffer overflow in camera module in Small Cell SoC, Snapdragon Mobile, Snapdragon Wear in FSM9055, FSM9955, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, SDX20, Snapdragon_High_Med_2016.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m8m-7fgv-2g6f/GHSA-8m8m-7fgv-2g6f.json b/advisories/unreviewed/2022/05/GHSA-8m8m-7fgv-2g6f/GHSA-8m8m-7fgv-2g6f.json index cc3f7ac8339..d18a91be1b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m8m-7fgv-2g6f/GHSA-8m8m-7fgv-2g6f.json +++ b/advisories/unreviewed/2022/05/GHSA-8m8m-7fgv-2g6f/GHSA-8m8m-7fgv-2g6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p2v-rvpv-92r3/GHSA-8p2v-rvpv-92r3.json b/advisories/unreviewed/2022/05/GHSA-8p2v-rvpv-92r3/GHSA-8p2v-rvpv-92r3.json index c50dc5b5948..07e09f57579 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p2v-rvpv-92r3/GHSA-8p2v-rvpv-92r3.json +++ b/advisories/unreviewed/2022/05/GHSA-8p2v-rvpv-92r3/GHSA-8p2v-rvpv-92r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p3x-34c5-5pmx/GHSA-8p3x-34c5-5pmx.json b/advisories/unreviewed/2022/05/GHSA-8p3x-34c5-5pmx/GHSA-8p3x-34c5-5pmx.json index 9b7180f604a..a536b5b6b2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p3x-34c5-5pmx/GHSA-8p3x-34c5-5pmx.json +++ b/advisories/unreviewed/2022/05/GHSA-8p3x-34c5-5pmx/GHSA-8p3x-34c5-5pmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q94-gg4r-q969/GHSA-8q94-gg4r-q969.json b/advisories/unreviewed/2022/05/GHSA-8q94-gg4r-q969/GHSA-8q94-gg4r-q969.json index 7a655176e15..89ffe975cc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q94-gg4r-q969/GHSA-8q94-gg4r-q969.json +++ b/advisories/unreviewed/2022/05/GHSA-8q94-gg4r-q969/GHSA-8q94-gg4r-q969.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qh9-rx3v-4wvr/GHSA-8qh9-rx3v-4wvr.json b/advisories/unreviewed/2022/05/GHSA-8qh9-rx3v-4wvr/GHSA-8qh9-rx3v-4wvr.json index 70e7a0bd801..4aa997ff652 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qh9-rx3v-4wvr/GHSA-8qh9-rx3v-4wvr.json +++ b/advisories/unreviewed/2022/05/GHSA-8qh9-rx3v-4wvr/GHSA-8qh9-rx3v-4wvr.json @@ -7,12 +7,8 @@ "CVE-2019-2638" ], "details": "Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w85-7w79-ghh7/GHSA-8w85-7w79-ghh7.json b/advisories/unreviewed/2022/05/GHSA-8w85-7w79-ghh7/GHSA-8w85-7w79-ghh7.json index d2779d47538..58fbba9f975 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w85-7w79-ghh7/GHSA-8w85-7w79-ghh7.json +++ b/advisories/unreviewed/2022/05/GHSA-8w85-7w79-ghh7/GHSA-8w85-7w79-ghh7.json @@ -7,12 +7,8 @@ "CVE-2019-11218" ], "details": "Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8x2j-pw29-3r92/GHSA-8x2j-pw29-3r92.json b/advisories/unreviewed/2022/05/GHSA-8x2j-pw29-3r92/GHSA-8x2j-pw29-3r92.json index 88bb91e2ff9..c98288555ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x2j-pw29-3r92/GHSA-8x2j-pw29-3r92.json +++ b/advisories/unreviewed/2022/05/GHSA-8x2j-pw29-3r92/GHSA-8x2j-pw29-3r92.json @@ -7,12 +7,8 @@ "CVE-2019-2570" ], "details": "Vulnerability in the Siebel Core - Server BizLogic Script component of Oracle Siebel CRM (subcomponent: Integration - Scripting). The supported version that is affected is 19.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Core - Server BizLogic Script. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel Core - Server BizLogic Script accessible data as well as unauthorized read access to a subset of Siebel Core - Server BizLogic Script accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Core - Server BizLogic Script. CVSS 3.0 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xm7-mq63-gv2r/GHSA-8xm7-mq63-gv2r.json b/advisories/unreviewed/2022/05/GHSA-8xm7-mq63-gv2r/GHSA-8xm7-mq63-gv2r.json index 0672430e713..9fa69939f0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xm7-mq63-gv2r/GHSA-8xm7-mq63-gv2r.json +++ b/advisories/unreviewed/2022/05/GHSA-8xm7-mq63-gv2r/GHSA-8xm7-mq63-gv2r.json @@ -7,12 +7,8 @@ "CVE-2019-2682" ], "details": "Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92ph-vwr5-g5f4/GHSA-92ph-vwr5-g5f4.json b/advisories/unreviewed/2022/05/GHSA-92ph-vwr5-g5f4/GHSA-92ph-vwr5-g5f4.json index 4e486f4a929..f8bb0e11808 100644 --- a/advisories/unreviewed/2022/05/GHSA-92ph-vwr5-g5f4/GHSA-92ph-vwr5-g5f4.json +++ b/advisories/unreviewed/2022/05/GHSA-92ph-vwr5-g5f4/GHSA-92ph-vwr5-g5f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-936g-2f5c-q2w8/GHSA-936g-2f5c-q2w8.json b/advisories/unreviewed/2022/05/GHSA-936g-2f5c-q2w8/GHSA-936g-2f5c-q2w8.json index 2b04e712524..4da6667d30f 100644 --- a/advisories/unreviewed/2022/05/GHSA-936g-2f5c-q2w8/GHSA-936g-2f5c-q2w8.json +++ b/advisories/unreviewed/2022/05/GHSA-936g-2f5c-q2w8/GHSA-936g-2f5c-q2w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93p9-8fj5-vjv2/GHSA-93p9-8fj5-vjv2.json b/advisories/unreviewed/2022/05/GHSA-93p9-8fj5-vjv2/GHSA-93p9-8fj5-vjv2.json index e272a051d19..6eba92b3878 100644 --- a/advisories/unreviewed/2022/05/GHSA-93p9-8fj5-vjv2/GHSA-93p9-8fj5-vjv2.json +++ b/advisories/unreviewed/2022/05/GHSA-93p9-8fj5-vjv2/GHSA-93p9-8fj5-vjv2.json @@ -7,12 +7,8 @@ "CVE-2010-3705" ], "details": "The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93rr-wh56-p8fw/GHSA-93rr-wh56-p8fw.json b/advisories/unreviewed/2022/05/GHSA-93rr-wh56-p8fw/GHSA-93rr-wh56-p8fw.json index c4ab05a1003..2a1f9eb76c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-93rr-wh56-p8fw/GHSA-93rr-wh56-p8fw.json +++ b/advisories/unreviewed/2022/05/GHSA-93rr-wh56-p8fw/GHSA-93rr-wh56-p8fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -71,9 +69,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93x7-x38m-p7mr/GHSA-93x7-x38m-p7mr.json b/advisories/unreviewed/2022/05/GHSA-93x7-x38m-p7mr/GHSA-93x7-x38m-p7mr.json index 50e1883373c..fa89f80c6ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-93x7-x38m-p7mr/GHSA-93x7-x38m-p7mr.json +++ b/advisories/unreviewed/2022/05/GHSA-93x7-x38m-p7mr/GHSA-93x7-x38m-p7mr.json @@ -7,12 +7,8 @@ "CVE-2019-2709" ], "details": "Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.3.7, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95g7-22q2-6wmq/GHSA-95g7-22q2-6wmq.json b/advisories/unreviewed/2022/05/GHSA-95g7-22q2-6wmq/GHSA-95g7-22q2-6wmq.json index b0bbf0a2332..61623e19133 100644 --- a/advisories/unreviewed/2022/05/GHSA-95g7-22q2-6wmq/GHSA-95g7-22q2-6wmq.json +++ b/advisories/unreviewed/2022/05/GHSA-95g7-22q2-6wmq/GHSA-95g7-22q2-6wmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9779-jfg9-frm3/GHSA-9779-jfg9-frm3.json b/advisories/unreviewed/2022/05/GHSA-9779-jfg9-frm3/GHSA-9779-jfg9-frm3.json index 610d8ffcf5d..d21b6c4e647 100644 --- a/advisories/unreviewed/2022/05/GHSA-9779-jfg9-frm3/GHSA-9779-jfg9-frm3.json +++ b/advisories/unreviewed/2022/05/GHSA-9779-jfg9-frm3/GHSA-9779-jfg9-frm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98v2-gwqr-qc6m/GHSA-98v2-gwqr-qc6m.json b/advisories/unreviewed/2022/05/GHSA-98v2-gwqr-qc6m/GHSA-98v2-gwqr-qc6m.json index 82b66a35e96..e260bf8b552 100644 --- a/advisories/unreviewed/2022/05/GHSA-98v2-gwqr-qc6m/GHSA-98v2-gwqr-qc6m.json +++ b/advisories/unreviewed/2022/05/GHSA-98v2-gwqr-qc6m/GHSA-98v2-gwqr-qc6m.json @@ -7,12 +7,8 @@ "CVE-2019-2613" ], "details": "Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9crc-xjgp-v484/GHSA-9crc-xjgp-v484.json b/advisories/unreviewed/2022/05/GHSA-9crc-xjgp-v484/GHSA-9crc-xjgp-v484.json index 6375963d55c..8ba557dc1a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9crc-xjgp-v484/GHSA-9crc-xjgp-v484.json +++ b/advisories/unreviewed/2022/05/GHSA-9crc-xjgp-v484/GHSA-9crc-xjgp-v484.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gh7-98rg-65p8/GHSA-9gh7-98rg-65p8.json b/advisories/unreviewed/2022/05/GHSA-9gh7-98rg-65p8/GHSA-9gh7-98rg-65p8.json index 0848b7342f3..02b8790194a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gh7-98rg-65p8/GHSA-9gh7-98rg-65p8.json +++ b/advisories/unreviewed/2022/05/GHSA-9gh7-98rg-65p8/GHSA-9gh7-98rg-65p8.json @@ -7,12 +7,8 @@ "CVE-2019-2673" ], "details": "Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hxx-97w4-fh95/GHSA-9hxx-97w4-fh95.json b/advisories/unreviewed/2022/05/GHSA-9hxx-97w4-fh95/GHSA-9hxx-97w4-fh95.json index e223f12c909..cb21462b1f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hxx-97w4-fh95/GHSA-9hxx-97w4-fh95.json +++ b/advisories/unreviewed/2022/05/GHSA-9hxx-97w4-fh95/GHSA-9hxx-97w4-fh95.json @@ -7,12 +7,8 @@ "CVE-2019-1804" ], "details": "A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user. The vulnerability is due to the presence of a default SSH key pair that is present in all devices. An attacker could exploit this vulnerability by opening an SSH connection via IPv6 to a targeted device using the extracted key materials. An exploit could allow the attacker to access the system with the privileges of the root user. This vulnerability is only exploitable over IPv6; IPv4 is not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j4w-mccp-p9wv/GHSA-9j4w-mccp-p9wv.json b/advisories/unreviewed/2022/05/GHSA-9j4w-mccp-p9wv/GHSA-9j4w-mccp-p9wv.json index 5171d70f934..895606d7eaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j4w-mccp-p9wv/GHSA-9j4w-mccp-p9wv.json +++ b/advisories/unreviewed/2022/05/GHSA-9j4w-mccp-p9wv/GHSA-9j4w-mccp-p9wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mm5-jxqx-9fjx/GHSA-9mm5-jxqx-9fjx.json b/advisories/unreviewed/2022/05/GHSA-9mm5-jxqx-9fjx/GHSA-9mm5-jxqx-9fjx.json index e455ee03acb..847063af0c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mm5-jxqx-9fjx/GHSA-9mm5-jxqx-9fjx.json +++ b/advisories/unreviewed/2022/05/GHSA-9mm5-jxqx-9fjx/GHSA-9mm5-jxqx-9fjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mpm-cpqp-766f/GHSA-9mpm-cpqp-766f.json b/advisories/unreviewed/2022/05/GHSA-9mpm-cpqp-766f/GHSA-9mpm-cpqp-766f.json index c61b1583326..cf14f085ce5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mpm-cpqp-766f/GHSA-9mpm-cpqp-766f.json +++ b/advisories/unreviewed/2022/05/GHSA-9mpm-cpqp-766f/GHSA-9mpm-cpqp-766f.json @@ -7,12 +7,8 @@ "CVE-2019-2690" ], "details": "Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r58-49jg-hrq7/GHSA-9r58-49jg-hrq7.json b/advisories/unreviewed/2022/05/GHSA-9r58-49jg-hrq7/GHSA-9r58-49jg-hrq7.json index d53bbea70fd..e3f6b317376 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r58-49jg-hrq7/GHSA-9r58-49jg-hrq7.json +++ b/advisories/unreviewed/2022/05/GHSA-9r58-49jg-hrq7/GHSA-9r58-49jg-hrq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r5h-92x4-fxx8/GHSA-9r5h-92x4-fxx8.json b/advisories/unreviewed/2022/05/GHSA-9r5h-92x4-fxx8/GHSA-9r5h-92x4-fxx8.json index 3e4642a8491..faab755dc94 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r5h-92x4-fxx8/GHSA-9r5h-92x4-fxx8.json +++ b/advisories/unreviewed/2022/05/GHSA-9r5h-92x4-fxx8/GHSA-9r5h-92x4-fxx8.json @@ -7,12 +7,8 @@ "CVE-2019-7476" ], "details": "A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v6q-8j73-8fcr/GHSA-9v6q-8j73-8fcr.json b/advisories/unreviewed/2022/05/GHSA-9v6q-8j73-8fcr/GHSA-9v6q-8j73-8fcr.json index 46c537bb77b..b5a7f05a8fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v6q-8j73-8fcr/GHSA-9v6q-8j73-8fcr.json +++ b/advisories/unreviewed/2022/05/GHSA-9v6q-8j73-8fcr/GHSA-9v6q-8j73-8fcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v7f-rj28-9x3v/GHSA-9v7f-rj28-9x3v.json b/advisories/unreviewed/2022/05/GHSA-9v7f-rj28-9x3v/GHSA-9v7f-rj28-9x3v.json index 3d72db51ee1..34b41a74ea0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v7f-rj28-9x3v/GHSA-9v7f-rj28-9x3v.json +++ b/advisories/unreviewed/2022/05/GHSA-9v7f-rj28-9x3v/GHSA-9v7f-rj28-9x3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vw8-5c3c-w435/GHSA-9vw8-5c3c-w435.json b/advisories/unreviewed/2022/05/GHSA-9vw8-5c3c-w435/GHSA-9vw8-5c3c-w435.json index b4517b31ccc..447c44e122a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vw8-5c3c-w435/GHSA-9vw8-5c3c-w435.json +++ b/advisories/unreviewed/2022/05/GHSA-9vw8-5c3c-w435/GHSA-9vw8-5c3c-w435.json @@ -7,12 +7,8 @@ "CVE-2019-3566" ], "details": "A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wg8-9g4x-8c9p/GHSA-9wg8-9g4x-8c9p.json b/advisories/unreviewed/2022/05/GHSA-9wg8-9g4x-8c9p/GHSA-9wg8-9g4x-8c9p.json index f8b840086a1..28b6f6e5d5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wg8-9g4x-8c9p/GHSA-9wg8-9g4x-8c9p.json +++ b/advisories/unreviewed/2022/05/GHSA-9wg8-9g4x-8c9p/GHSA-9wg8-9g4x-8c9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wpg-w4pv-72hf/GHSA-9wpg-w4pv-72hf.json b/advisories/unreviewed/2022/05/GHSA-9wpg-w4pv-72hf/GHSA-9wpg-w4pv-72hf.json index efea1fe5a2b..598ce393a06 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wpg-w4pv-72hf/GHSA-9wpg-w4pv-72hf.json +++ b/advisories/unreviewed/2022/05/GHSA-9wpg-w4pv-72hf/GHSA-9wpg-w4pv-72hf.json @@ -7,12 +7,8 @@ "CVE-2019-2590" ], "details": "Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager component of Oracle PeopleSoft Products (subcomponent: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Talent Acquisition Manager accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Talent Acquisition Manager accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x53-5f6r-73cq/GHSA-9x53-5f6r-73cq.json b/advisories/unreviewed/2022/05/GHSA-9x53-5f6r-73cq/GHSA-9x53-5f6r-73cq.json index a812ad6139e..4732966374d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x53-5f6r-73cq/GHSA-9x53-5f6r-73cq.json +++ b/advisories/unreviewed/2022/05/GHSA-9x53-5f6r-73cq/GHSA-9x53-5f6r-73cq.json @@ -7,12 +7,8 @@ "CVE-2010-4158" ], "details": "The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x9m-9jh5-6gwf/GHSA-9x9m-9jh5-6gwf.json b/advisories/unreviewed/2022/05/GHSA-9x9m-9jh5-6gwf/GHSA-9x9m-9jh5-6gwf.json index 21403bca4f7..d08740aefba 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x9m-9jh5-6gwf/GHSA-9x9m-9jh5-6gwf.json +++ b/advisories/unreviewed/2022/05/GHSA-9x9m-9jh5-6gwf/GHSA-9x9m-9jh5-6gwf.json @@ -7,12 +7,8 @@ "CVE-2019-7409" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c22m-cqmp-648p/GHSA-c22m-cqmp-648p.json b/advisories/unreviewed/2022/05/GHSA-c22m-cqmp-648p/GHSA-c22m-cqmp-648p.json index 1650e127b78..735693ef705 100644 --- a/advisories/unreviewed/2022/05/GHSA-c22m-cqmp-648p/GHSA-c22m-cqmp-648p.json +++ b/advisories/unreviewed/2022/05/GHSA-c22m-cqmp-648p/GHSA-c22m-cqmp-648p.json @@ -7,12 +7,8 @@ "CVE-2019-2652" ], "details": "Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3x6-px6w-wrxq/GHSA-c3x6-px6w-wrxq.json b/advisories/unreviewed/2022/05/GHSA-c3x6-px6w-wrxq/GHSA-c3x6-px6w-wrxq.json index cafebc2f1b2..e797ce71bf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3x6-px6w-wrxq/GHSA-c3x6-px6w-wrxq.json +++ b/advisories/unreviewed/2022/05/GHSA-c3x6-px6w-wrxq/GHSA-c3x6-px6w-wrxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c424-83vr-r34f/GHSA-c424-83vr-r34f.json b/advisories/unreviewed/2022/05/GHSA-c424-83vr-r34f/GHSA-c424-83vr-r34f.json index 62132e37861..cd7e0be4105 100644 --- a/advisories/unreviewed/2022/05/GHSA-c424-83vr-r34f/GHSA-c424-83vr-r34f.json +++ b/advisories/unreviewed/2022/05/GHSA-c424-83vr-r34f/GHSA-c424-83vr-r34f.json @@ -7,12 +7,8 @@ "CVE-2019-2707" ], "details": "Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management component of Oracle PeopleSoft Products (subcomponent: Application Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM Enterprise Learning Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise ELM Enterprise Learning Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM Enterprise Learning Management accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise ELM Enterprise Learning Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4wx-x65q-h4fx/GHSA-c4wx-x65q-h4fx.json b/advisories/unreviewed/2022/05/GHSA-c4wx-x65q-h4fx/GHSA-c4wx-x65q-h4fx.json index 2c8a75ddd99..c16890580a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4wx-x65q-h4fx/GHSA-c4wx-x65q-h4fx.json +++ b/advisories/unreviewed/2022/05/GHSA-c4wx-x65q-h4fx/GHSA-c4wx-x65q-h4fx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c55r-2684-gw89/GHSA-c55r-2684-gw89.json b/advisories/unreviewed/2022/05/GHSA-c55r-2684-gw89/GHSA-c55r-2684-gw89.json index 5ba38298e0d..e5bf56b85c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c55r-2684-gw89/GHSA-c55r-2684-gw89.json +++ b/advisories/unreviewed/2022/05/GHSA-c55r-2684-gw89/GHSA-c55r-2684-gw89.json @@ -7,12 +7,8 @@ "CVE-2019-2615" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c637-jwvm-g57q/GHSA-c637-jwvm-g57q.json b/advisories/unreviewed/2022/05/GHSA-c637-jwvm-g57q/GHSA-c637-jwvm-g57q.json index c3e7e4a72e9..338caa437ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-c637-jwvm-g57q/GHSA-c637-jwvm-g57q.json +++ b/advisories/unreviewed/2022/05/GHSA-c637-jwvm-g57q/GHSA-c637-jwvm-g57q.json @@ -7,12 +7,8 @@ "CVE-2019-2649" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8pj-xcf4-vhc8/GHSA-c8pj-xcf4-vhc8.json b/advisories/unreviewed/2022/05/GHSA-c8pj-xcf4-vhc8/GHSA-c8pj-xcf4-vhc8.json index 6ac31e94304..56d0d6cabcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8pj-xcf4-vhc8/GHSA-c8pj-xcf4-vhc8.json +++ b/advisories/unreviewed/2022/05/GHSA-c8pj-xcf4-vhc8/GHSA-c8pj-xcf4-vhc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9v9-47m5-62h4/GHSA-c9v9-47m5-62h4.json b/advisories/unreviewed/2022/05/GHSA-c9v9-47m5-62h4/GHSA-c9v9-47m5-62h4.json index e9131701e63..2d133d3ee9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9v9-47m5-62h4/GHSA-c9v9-47m5-62h4.json +++ b/advisories/unreviewed/2022/05/GHSA-c9v9-47m5-62h4/GHSA-c9v9-47m5-62h4.json @@ -7,12 +7,8 @@ "CVE-2019-1735" ], "details": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid user credentials to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfh8-rvcx-v326/GHSA-cfh8-rvcx-v326.json b/advisories/unreviewed/2022/05/GHSA-cfh8-rvcx-v326/GHSA-cfh8-rvcx-v326.json index 633d43c9878..9dc2d35cb29 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfh8-rvcx-v326/GHSA-cfh8-rvcx-v326.json +++ b/advisories/unreviewed/2022/05/GHSA-cfh8-rvcx-v326/GHSA-cfh8-rvcx-v326.json @@ -7,12 +7,8 @@ "CVE-2012-3535" ], "details": "Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgpj-vcc9-76qx/GHSA-cgpj-vcc9-76qx.json b/advisories/unreviewed/2022/05/GHSA-cgpj-vcc9-76qx/GHSA-cgpj-vcc9-76qx.json index 360d73d52a7..e7098ba9fa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgpj-vcc9-76qx/GHSA-cgpj-vcc9-76qx.json +++ b/advisories/unreviewed/2022/05/GHSA-cgpj-vcc9-76qx/GHSA-cgpj-vcc9-76qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch38-2px8-5wrr/GHSA-ch38-2px8-5wrr.json b/advisories/unreviewed/2022/05/GHSA-ch38-2px8-5wrr/GHSA-ch38-2px8-5wrr.json index be8167e5139..9f806de68f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch38-2px8-5wrr/GHSA-ch38-2px8-5wrr.json +++ b/advisories/unreviewed/2022/05/GHSA-ch38-2px8-5wrr/GHSA-ch38-2px8-5wrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm63-q44g-45j5/GHSA-cm63-q44g-45j5.json b/advisories/unreviewed/2022/05/GHSA-cm63-q44g-45j5/GHSA-cm63-q44g-45j5.json index c6377f6c743..7b28e4dc101 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm63-q44g-45j5/GHSA-cm63-q44g-45j5.json +++ b/advisories/unreviewed/2022/05/GHSA-cm63-q44g-45j5/GHSA-cm63-q44g-45j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmfj-gv9j-wp76/GHSA-cmfj-gv9j-wp76.json b/advisories/unreviewed/2022/05/GHSA-cmfj-gv9j-wp76/GHSA-cmfj-gv9j-wp76.json index 95ef247ed8f..7756828909b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmfj-gv9j-wp76/GHSA-cmfj-gv9j-wp76.json +++ b/advisories/unreviewed/2022/05/GHSA-cmfj-gv9j-wp76/GHSA-cmfj-gv9j-wp76.json @@ -7,12 +7,8 @@ "CVE-2019-2648" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmr2-gmfq-rgq8/GHSA-cmr2-gmfq-rgq8.json b/advisories/unreviewed/2022/05/GHSA-cmr2-gmfq-rgq8/GHSA-cmr2-gmfq-rgq8.json index e7e449dfe3c..97fe1d6b98e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmr2-gmfq-rgq8/GHSA-cmr2-gmfq-rgq8.json +++ b/advisories/unreviewed/2022/05/GHSA-cmr2-gmfq-rgq8/GHSA-cmr2-gmfq-rgq8.json @@ -7,12 +7,8 @@ "CVE-2019-11413" ], "details": "An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpjp-485v-mmmr/GHSA-cpjp-485v-mmmr.json b/advisories/unreviewed/2022/05/GHSA-cpjp-485v-mmmr/GHSA-cpjp-485v-mmmr.json index 52280191b7b..46cb57f94b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpjp-485v-mmmr/GHSA-cpjp-485v-mmmr.json +++ b/advisories/unreviewed/2022/05/GHSA-cpjp-485v-mmmr/GHSA-cpjp-485v-mmmr.json @@ -7,12 +7,8 @@ "CVE-2019-2629" ], "details": "Vulnerability in the Oracle Health Sciences Data Management Workbench component of Oracle Health Sciences Applications (subcomponent: User Interface). The supported version that is affected is 2.4.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences Data Management Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences Data Management Workbench accessible data as well as unauthorized read access to a subset of Oracle Health Sciences Data Management Workbench accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cr64-644f-pj24/GHSA-cr64-644f-pj24.json b/advisories/unreviewed/2022/05/GHSA-cr64-644f-pj24/GHSA-cr64-644f-pj24.json index e7cab8706a5..8cb7e57196e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr64-644f-pj24/GHSA-cr64-644f-pj24.json +++ b/advisories/unreviewed/2022/05/GHSA-cr64-644f-pj24/GHSA-cr64-644f-pj24.json @@ -7,12 +7,8 @@ "CVE-2019-9136" ], "details": "DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv25-9hfx-33wj/GHSA-cv25-9hfx-33wj.json b/advisories/unreviewed/2022/05/GHSA-cv25-9hfx-33wj/GHSA-cv25-9hfx-33wj.json index cabf0fbbffd..9cf84145f1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv25-9hfx-33wj/GHSA-cv25-9hfx-33wj.json +++ b/advisories/unreviewed/2022/05/GHSA-cv25-9hfx-33wj/GHSA-cv25-9hfx-33wj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvp9-xf77-46mc/GHSA-cvp9-xf77-46mc.json b/advisories/unreviewed/2022/05/GHSA-cvp9-xf77-46mc/GHSA-cvp9-xf77-46mc.json index aa0d6c4d2ae..5e187012c78 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvp9-xf77-46mc/GHSA-cvp9-xf77-46mc.json +++ b/advisories/unreviewed/2022/05/GHSA-cvp9-xf77-46mc/GHSA-cvp9-xf77-46mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx34-9hmm-493f/GHSA-cx34-9hmm-493f.json b/advisories/unreviewed/2022/05/GHSA-cx34-9hmm-493f/GHSA-cx34-9hmm-493f.json index 6a92976a9f1..7c72e16854d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx34-9hmm-493f/GHSA-cx34-9hmm-493f.json +++ b/advisories/unreviewed/2022/05/GHSA-cx34-9hmm-493f/GHSA-cx34-9hmm-493f.json @@ -7,12 +7,8 @@ "CVE-2010-4169" ], "details": "Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2vm-77f3-vpcq/GHSA-f2vm-77f3-vpcq.json b/advisories/unreviewed/2022/05/GHSA-f2vm-77f3-vpcq/GHSA-f2vm-77f3-vpcq.json index 7176f448f59..a35b2617321 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2vm-77f3-vpcq/GHSA-f2vm-77f3-vpcq.json +++ b/advisories/unreviewed/2022/05/GHSA-f2vm-77f3-vpcq/GHSA-f2vm-77f3-vpcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f64w-cj85-9j8w/GHSA-f64w-cj85-9j8w.json b/advisories/unreviewed/2022/05/GHSA-f64w-cj85-9j8w/GHSA-f64w-cj85-9j8w.json index dc26209bb1d..7a71e3d9990 100644 --- a/advisories/unreviewed/2022/05/GHSA-f64w-cj85-9j8w/GHSA-f64w-cj85-9j8w.json +++ b/advisories/unreviewed/2022/05/GHSA-f64w-cj85-9j8w/GHSA-f64w-cj85-9j8w.json @@ -7,12 +7,8 @@ "CVE-2019-2654" ], "details": "Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7c3-85h7-v4f4/GHSA-f7c3-85h7-v4f4.json b/advisories/unreviewed/2022/05/GHSA-f7c3-85h7-v4f4/GHSA-f7c3-85h7-v4f4.json index f764a4786ff..d23b8f30c5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7c3-85h7-v4f4/GHSA-f7c3-85h7-v4f4.json +++ b/advisories/unreviewed/2022/05/GHSA-f7c3-85h7-v4f4/GHSA-f7c3-85h7-v4f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8wp-7ph4-863c/GHSA-f8wp-7ph4-863c.json b/advisories/unreviewed/2022/05/GHSA-f8wp-7ph4-863c/GHSA-f8wp-7ph4-863c.json index e7f32093040..b8c69f1eab6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8wp-7ph4-863c/GHSA-f8wp-7ph4-863c.json +++ b/advisories/unreviewed/2022/05/GHSA-f8wp-7ph4-863c/GHSA-f8wp-7ph4-863c.json @@ -7,12 +7,8 @@ "CVE-2019-2660" ], "details": "Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: Setup, Admin). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc4h-7x45-5wrw/GHSA-fc4h-7x45-5wrw.json b/advisories/unreviewed/2022/05/GHSA-fc4h-7x45-5wrw/GHSA-fc4h-7x45-5wrw.json index 20d2cd0d111..c47c970ddd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc4h-7x45-5wrw/GHSA-fc4h-7x45-5wrw.json +++ b/advisories/unreviewed/2022/05/GHSA-fc4h-7x45-5wrw/GHSA-fc4h-7x45-5wrw.json @@ -7,12 +7,8 @@ "CVE-2019-5430" ], "details": "In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhc7-95hq-9w87/GHSA-fhc7-95hq-9w87.json b/advisories/unreviewed/2022/05/GHSA-fhc7-95hq-9w87/GHSA-fhc7-95hq-9w87.json index b85b108d031..ee7e0f27c7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhc7-95hq-9w87/GHSA-fhc7-95hq-9w87.json +++ b/advisories/unreviewed/2022/05/GHSA-fhc7-95hq-9w87/GHSA-fhc7-95hq-9w87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -71,9 +69,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhcf-vpm9-jphv/GHSA-fhcf-vpm9-jphv.json b/advisories/unreviewed/2022/05/GHSA-fhcf-vpm9-jphv/GHSA-fhcf-vpm9-jphv.json index 7bd63d5b727..f230b271b0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhcf-vpm9-jphv/GHSA-fhcf-vpm9-jphv.json +++ b/advisories/unreviewed/2022/05/GHSA-fhcf-vpm9-jphv/GHSA-fhcf-vpm9-jphv.json @@ -7,12 +7,8 @@ "CVE-2019-10131" ], "details": "An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm58-52q7-gpvg/GHSA-fm58-52q7-gpvg.json b/advisories/unreviewed/2022/05/GHSA-fm58-52q7-gpvg/GHSA-fm58-52q7-gpvg.json index 31a20778a4d..fc201f1cf2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm58-52q7-gpvg/GHSA-fm58-52q7-gpvg.json +++ b/advisories/unreviewed/2022/05/GHSA-fm58-52q7-gpvg/GHSA-fm58-52q7-gpvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm7p-vqmh-43rf/GHSA-fm7p-vqmh-43rf.json b/advisories/unreviewed/2022/05/GHSA-fm7p-vqmh-43rf/GHSA-fm7p-vqmh-43rf.json index da8c73c20c8..2c824aa90ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm7p-vqmh-43rf/GHSA-fm7p-vqmh-43rf.json +++ b/advisories/unreviewed/2022/05/GHSA-fm7p-vqmh-43rf/GHSA-fm7p-vqmh-43rf.json @@ -7,12 +7,8 @@ "CVE-2019-2577" ], "details": "Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: File Locking Services). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmq3-2qp8-v6g9/GHSA-fmq3-2qp8-v6g9.json b/advisories/unreviewed/2022/05/GHSA-fmq3-2qp8-v6g9/GHSA-fmq3-2qp8-v6g9.json index 6863e073c44..5740f7c4f57 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmq3-2qp8-v6g9/GHSA-fmq3-2qp8-v6g9.json +++ b/advisories/unreviewed/2022/05/GHSA-fmq3-2qp8-v6g9/GHSA-fmq3-2qp8-v6g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fppp-3vhq-pxxg/GHSA-fppp-3vhq-pxxg.json b/advisories/unreviewed/2022/05/GHSA-fppp-3vhq-pxxg/GHSA-fppp-3vhq-pxxg.json index 3aa1122573c..52f07163faf 100644 --- a/advisories/unreviewed/2022/05/GHSA-fppp-3vhq-pxxg/GHSA-fppp-3vhq-pxxg.json +++ b/advisories/unreviewed/2022/05/GHSA-fppp-3vhq-pxxg/GHSA-fppp-3vhq-pxxg.json @@ -7,12 +7,8 @@ "CVE-2019-11598" ], "details": "In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file. This is related to SetGrayscaleImage in MagickCore/quantize.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq63-9c29-w9fw/GHSA-fq63-9c29-w9fw.json b/advisories/unreviewed/2022/05/GHSA-fq63-9c29-w9fw/GHSA-fq63-9c29-w9fw.json index a8dcfccdbb9..8c91f36a6c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq63-9c29-w9fw/GHSA-fq63-9c29-w9fw.json +++ b/advisories/unreviewed/2022/05/GHSA-fq63-9c29-w9fw/GHSA-fq63-9c29-w9fw.json @@ -7,12 +7,8 @@ "CVE-2011-3638" ], "details": "fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent splitting, which allows local users to cause a denial of service (system crash) via vectors involving ext4 umount and mount operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqv6-g44j-5jx7/GHSA-fqv6-g44j-5jx7.json b/advisories/unreviewed/2022/05/GHSA-fqv6-g44j-5jx7/GHSA-fqv6-g44j-5jx7.json index 5220a973c40..b675c752310 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqv6-g44j-5jx7/GHSA-fqv6-g44j-5jx7.json +++ b/advisories/unreviewed/2022/05/GHSA-fqv6-g44j-5jx7/GHSA-fqv6-g44j-5jx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frqm-xpj3-g9h5/GHSA-frqm-xpj3-g9h5.json b/advisories/unreviewed/2022/05/GHSA-frqm-xpj3-g9h5/GHSA-frqm-xpj3-g9h5.json index 0965911b21b..5e842fcdb3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-frqm-xpj3-g9h5/GHSA-frqm-xpj3-g9h5.json +++ b/advisories/unreviewed/2022/05/GHSA-frqm-xpj3-g9h5/GHSA-frqm-xpj3-g9h5.json @@ -7,12 +7,8 @@ "CVE-2019-2632" ], "details": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frwj-2gwg-74jv/GHSA-frwj-2gwg-74jv.json b/advisories/unreviewed/2022/05/GHSA-frwj-2gwg-74jv/GHSA-frwj-2gwg-74jv.json index d228e2643f2..28d7985d348 100644 --- a/advisories/unreviewed/2022/05/GHSA-frwj-2gwg-74jv/GHSA-frwj-2gwg-74jv.json +++ b/advisories/unreviewed/2022/05/GHSA-frwj-2gwg-74jv/GHSA-frwj-2gwg-74jv.json @@ -7,12 +7,8 @@ "CVE-2019-2641" ], "details": "Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvqv-6788-x824/GHSA-fvqv-6788-x824.json b/advisories/unreviewed/2022/05/GHSA-fvqv-6788-x824/GHSA-fvqv-6788-x824.json index 87afdd81c8d..e5df186cd16 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvqv-6788-x824/GHSA-fvqv-6788-x824.json +++ b/advisories/unreviewed/2022/05/GHSA-fvqv-6788-x824/GHSA-fvqv-6788-x824.json @@ -7,12 +7,8 @@ "CVE-2019-2669" ], "details": "Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g442-4wgf-h9jr/GHSA-g442-4wgf-h9jr.json b/advisories/unreviewed/2022/05/GHSA-g442-4wgf-h9jr/GHSA-g442-4wgf-h9jr.json index 652a422e517..ed543869c1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g442-4wgf-h9jr/GHSA-g442-4wgf-h9jr.json +++ b/advisories/unreviewed/2022/05/GHSA-g442-4wgf-h9jr/GHSA-g442-4wgf-h9jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6g8-jgp3-m382/GHSA-g6g8-jgp3-m382.json b/advisories/unreviewed/2022/05/GHSA-g6g8-jgp3-m382/GHSA-g6g8-jgp3-m382.json index a20ab4499e7..642995ea39e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6g8-jgp3-m382/GHSA-g6g8-jgp3-m382.json +++ b/advisories/unreviewed/2022/05/GHSA-g6g8-jgp3-m382/GHSA-g6g8-jgp3-m382.json @@ -7,12 +7,8 @@ "CVE-2010-4249" ], "details": "The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted use of the socketpair and sendmsg system calls for SOCK_SEQPACKET sockets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6jr-fq7m-6v6x/GHSA-g6jr-fq7m-6v6x.json b/advisories/unreviewed/2022/05/GHSA-g6jr-fq7m-6v6x/GHSA-g6jr-fq7m-6v6x.json index 1004245f2d9..8595dbdfe21 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6jr-fq7m-6v6x/GHSA-g6jr-fq7m-6v6x.json +++ b/advisories/unreviewed/2022/05/GHSA-g6jr-fq7m-6v6x/GHSA-g6jr-fq7m-6v6x.json @@ -7,12 +7,8 @@ "CVE-2019-1731" ], "details": "A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an authenticated, local attacker to expose a user's private SSH key to all authenticated users on the targeted device. The attacker must authenticate with valid administrator device credentials. The vulnerability is due to incomplete error handling if a specific error type occurs during the SSH key export. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the CLI. A successful exploit could allow the attacker to expose a user's private SSH key. In addition, a similar type of error in the SSH key import could cause the passphrase-protected private SSH key to be imported unintentionally.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g759-wxh6-x7jp/GHSA-g759-wxh6-x7jp.json b/advisories/unreviewed/2022/05/GHSA-g759-wxh6-x7jp/GHSA-g759-wxh6-x7jp.json index 3decdf1a2ed..f0ddffa453a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g759-wxh6-x7jp/GHSA-g759-wxh6-x7jp.json +++ b/advisories/unreviewed/2022/05/GHSA-g759-wxh6-x7jp/GHSA-g759-wxh6-x7jp.json @@ -7,12 +7,8 @@ "CVE-2018-18524" ], "details": "Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7xg-hcq2-r768/GHSA-g7xg-hcq2-r768.json b/advisories/unreviewed/2022/05/GHSA-g7xg-hcq2-r768/GHSA-g7xg-hcq2-r768.json index 7db745196c0..314df611b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7xg-hcq2-r768/GHSA-g7xg-hcq2-r768.json +++ b/advisories/unreviewed/2022/05/GHSA-g7xg-hcq2-r768/GHSA-g7xg-hcq2-r768.json @@ -7,12 +7,8 @@ "CVE-2019-2637" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8m6-5j3r-8xg4/GHSA-g8m6-5j3r-8xg4.json b/advisories/unreviewed/2022/05/GHSA-g8m6-5j3r-8xg4/GHSA-g8m6-5j3r-8xg4.json index 860dcbcbfdf..53a9c1d7bb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8m6-5j3r-8xg4/GHSA-g8m6-5j3r-8xg4.json +++ b/advisories/unreviewed/2022/05/GHSA-g8m6-5j3r-8xg4/GHSA-g8m6-5j3r-8xg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g96v-26x6-4jrf/GHSA-g96v-26x6-4jrf.json b/advisories/unreviewed/2022/05/GHSA-g96v-26x6-4jrf/GHSA-g96v-26x6-4jrf.json index b45e6b32ac5..1a580e293dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-g96v-26x6-4jrf/GHSA-g96v-26x6-4jrf.json +++ b/advisories/unreviewed/2022/05/GHSA-g96v-26x6-4jrf/GHSA-g96v-26x6-4jrf.json @@ -7,12 +7,8 @@ "CVE-2019-1783" ], "details": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g97q-g4qr-rcgw/GHSA-g97q-g4qr-rcgw.json b/advisories/unreviewed/2022/05/GHSA-g97q-g4qr-rcgw/GHSA-g97q-g4qr-rcgw.json index a295a279d7e..dfe74a276bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g97q-g4qr-rcgw/GHSA-g97q-g4qr-rcgw.json +++ b/advisories/unreviewed/2022/05/GHSA-g97q-g4qr-rcgw/GHSA-g97q-g4qr-rcgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g99j-vfcp-3vmf/GHSA-g99j-vfcp-3vmf.json b/advisories/unreviewed/2022/05/GHSA-g99j-vfcp-3vmf/GHSA-g99j-vfcp-3vmf.json index a721e0f1918..e7d95f8a38e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g99j-vfcp-3vmf/GHSA-g99j-vfcp-3vmf.json +++ b/advisories/unreviewed/2022/05/GHSA-g99j-vfcp-3vmf/GHSA-g99j-vfcp-3vmf.json @@ -7,12 +7,8 @@ "CVE-2013-4222" ], "details": "OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9gm-m3h7-634p/GHSA-g9gm-m3h7-634p.json b/advisories/unreviewed/2022/05/GHSA-g9gm-m3h7-634p/GHSA-g9gm-m3h7-634p.json index 918d548719b..c7de69ee3c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9gm-m3h7-634p/GHSA-g9gm-m3h7-634p.json +++ b/advisories/unreviewed/2022/05/GHSA-g9gm-m3h7-634p/GHSA-g9gm-m3h7-634p.json @@ -7,12 +7,8 @@ "CVE-2010-3873" ], "details": "The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different vulnerability than CVE-2010-4164.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9j3-3283-g3gq/GHSA-g9j3-3283-g3gq.json b/advisories/unreviewed/2022/05/GHSA-g9j3-3283-g3gq/GHSA-g9j3-3283-g3gq.json index b5f644e1597..f050bcb066c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9j3-3283-g3gq/GHSA-g9j3-3283-g3gq.json +++ b/advisories/unreviewed/2022/05/GHSA-g9j3-3283-g3gq/GHSA-g9j3-3283-g3gq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc95-jc79-5q6h/GHSA-gc95-jc79-5q6h.json b/advisories/unreviewed/2022/05/GHSA-gc95-jc79-5q6h/GHSA-gc95-jc79-5q6h.json index fc9ec80212a..f5b95fbd32e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc95-jc79-5q6h/GHSA-gc95-jc79-5q6h.json +++ b/advisories/unreviewed/2022/05/GHSA-gc95-jc79-5q6h/GHSA-gc95-jc79-5q6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfx4-r3v9-vph4/GHSA-gfx4-r3v9-vph4.json b/advisories/unreviewed/2022/05/GHSA-gfx4-r3v9-vph4/GHSA-gfx4-r3v9-vph4.json index 93ee0da113a..3e8496ac481 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfx4-r3v9-vph4/GHSA-gfx4-r3v9-vph4.json +++ b/advisories/unreviewed/2022/05/GHSA-gfx4-r3v9-vph4/GHSA-gfx4-r3v9-vph4.json @@ -7,12 +7,8 @@ "CVE-2011-2689" ], "details": "The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggq9-q258-r9g6/GHSA-ggq9-q258-r9g6.json b/advisories/unreviewed/2022/05/GHSA-ggq9-q258-r9g6/GHSA-ggq9-q258-r9g6.json index 6a3949f9dea..4347ee89733 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggq9-q258-r9g6/GHSA-ggq9-q258-r9g6.json +++ b/advisories/unreviewed/2022/05/GHSA-ggq9-q258-r9g6/GHSA-ggq9-q258-r9g6.json @@ -7,12 +7,8 @@ "CVE-2019-3586" ], "details": "Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious sites where the GTI reputation is carefully manipulated and does not correctly trigger the ENS Firewall to block the connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghm3-x9vf-px32/GHSA-ghm3-x9vf-px32.json b/advisories/unreviewed/2022/05/GHSA-ghm3-x9vf-px32/GHSA-ghm3-x9vf-px32.json index 255bd0ce281..b9b5f7fea71 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghm3-x9vf-px32/GHSA-ghm3-x9vf-px32.json +++ b/advisories/unreviewed/2022/05/GHSA-ghm3-x9vf-px32/GHSA-ghm3-x9vf-px32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjvf-862f-699c/GHSA-gjvf-862f-699c.json b/advisories/unreviewed/2022/05/GHSA-gjvf-862f-699c/GHSA-gjvf-862f-699c.json index 3958232d414..37edfcd5a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjvf-862f-699c/GHSA-gjvf-862f-699c.json +++ b/advisories/unreviewed/2022/05/GHSA-gjvf-862f-699c/GHSA-gjvf-862f-699c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpqc-5qx7-8qm2/GHSA-gpqc-5qx7-8qm2.json b/advisories/unreviewed/2022/05/GHSA-gpqc-5qx7-8qm2/GHSA-gpqc-5qx7-8qm2.json index 2da96c2a1f4..432f3252d5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpqc-5qx7-8qm2/GHSA-gpqc-5qx7-8qm2.json +++ b/advisories/unreviewed/2022/05/GHSA-gpqc-5qx7-8qm2/GHSA-gpqc-5qx7-8qm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpvp-m39p-pc77/GHSA-gpvp-m39p-pc77.json b/advisories/unreviewed/2022/05/GHSA-gpvp-m39p-pc77/GHSA-gpvp-m39p-pc77.json index 7c52992cbb8..7d7d0dd5bae 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpvp-m39p-pc77/GHSA-gpvp-m39p-pc77.json +++ b/advisories/unreviewed/2022/05/GHSA-gpvp-m39p-pc77/GHSA-gpvp-m39p-pc77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq3m-8xxj-8v3w/GHSA-gq3m-8xxj-8v3w.json b/advisories/unreviewed/2022/05/GHSA-gq3m-8xxj-8v3w/GHSA-gq3m-8xxj-8v3w.json index cdd7e1b8a09..cfc38f89513 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq3m-8xxj-8v3w/GHSA-gq3m-8xxj-8v3w.json +++ b/advisories/unreviewed/2022/05/GHSA-gq3m-8xxj-8v3w/GHSA-gq3m-8xxj-8v3w.json @@ -7,12 +7,8 @@ "CVE-2019-2586" ], "details": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: RemoteCall). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq5h-q589-jxr5/GHSA-gq5h-q589-jxr5.json b/advisories/unreviewed/2022/05/GHSA-gq5h-q589-jxr5/GHSA-gq5h-q589-jxr5.json index 369bc6a60f7..95976218230 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq5h-q589-jxr5/GHSA-gq5h-q589-jxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-gq5h-q589-jxr5/GHSA-gq5h-q589-jxr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqcf-3mp9-v4ch/GHSA-gqcf-3mp9-v4ch.json b/advisories/unreviewed/2022/05/GHSA-gqcf-3mp9-v4ch/GHSA-gqcf-3mp9-v4ch.json index 098e3baa041..7acf03c25dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqcf-3mp9-v4ch/GHSA-gqcf-3mp9-v4ch.json +++ b/advisories/unreviewed/2022/05/GHSA-gqcf-3mp9-v4ch/GHSA-gqcf-3mp9-v4ch.json @@ -7,12 +7,8 @@ "CVE-2019-3934" ], "details": "Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulnerability to download the current slide image without knowing the access code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr62-2592-229q/GHSA-gr62-2592-229q.json b/advisories/unreviewed/2022/05/GHSA-gr62-2592-229q/GHSA-gr62-2592-229q.json index 61cddf16bfe..28b91a02ca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr62-2592-229q/GHSA-gr62-2592-229q.json +++ b/advisories/unreviewed/2022/05/GHSA-gr62-2592-229q/GHSA-gr62-2592-229q.json @@ -7,12 +7,8 @@ "CVE-2010-1634" ], "details": "Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grvp-x94j-hv4j/GHSA-grvp-x94j-hv4j.json b/advisories/unreviewed/2022/05/GHSA-grvp-x94j-hv4j/GHSA-grvp-x94j-hv4j.json index 9304110b1e6..a5a6af1d323 100644 --- a/advisories/unreviewed/2022/05/GHSA-grvp-x94j-hv4j/GHSA-grvp-x94j-hv4j.json +++ b/advisories/unreviewed/2022/05/GHSA-grvp-x94j-hv4j/GHSA-grvp-x94j-hv4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv6x-hf8m-5p66/GHSA-gv6x-hf8m-5p66.json b/advisories/unreviewed/2022/05/GHSA-gv6x-hf8m-5p66/GHSA-gv6x-hf8m-5p66.json index eb407f3b637..dcf5746ed00 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv6x-hf8m-5p66/GHSA-gv6x-hf8m-5p66.json +++ b/advisories/unreviewed/2022/05/GHSA-gv6x-hf8m-5p66/GHSA-gv6x-hf8m-5p66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h27g-g76x-xqpw/GHSA-h27g-g76x-xqpw.json b/advisories/unreviewed/2022/05/GHSA-h27g-g76x-xqpw/GHSA-h27g-g76x-xqpw.json index 1c01b9aa012..670b527216d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h27g-g76x-xqpw/GHSA-h27g-g76x-xqpw.json +++ b/advisories/unreviewed/2022/05/GHSA-h27g-g76x-xqpw/GHSA-h27g-g76x-xqpw.json @@ -7,12 +7,8 @@ "CVE-2019-3552" ], "details": "C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2jw-98ww-486c/GHSA-h2jw-98ww-486c.json b/advisories/unreviewed/2022/05/GHSA-h2jw-98ww-486c/GHSA-h2jw-98ww-486c.json index 8dcfadc7bd5..bba1e885684 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2jw-98ww-486c/GHSA-h2jw-98ww-486c.json +++ b/advisories/unreviewed/2022/05/GHSA-h2jw-98ww-486c/GHSA-h2jw-98ww-486c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h36q-74vp-w85q/GHSA-h36q-74vp-w85q.json b/advisories/unreviewed/2022/05/GHSA-h36q-74vp-w85q/GHSA-h36q-74vp-w85q.json index a49ecb09c45..08b2b93da0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h36q-74vp-w85q/GHSA-h36q-74vp-w85q.json +++ b/advisories/unreviewed/2022/05/GHSA-h36q-74vp-w85q/GHSA-h36q-74vp-w85q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h68p-8jj4-mh9x/GHSA-h68p-8jj4-mh9x.json b/advisories/unreviewed/2022/05/GHSA-h68p-8jj4-mh9x/GHSA-h68p-8jj4-mh9x.json index 50ed782d227..01fe91d0c2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h68p-8jj4-mh9x/GHSA-h68p-8jj4-mh9x.json +++ b/advisories/unreviewed/2022/05/GHSA-h68p-8jj4-mh9x/GHSA-h68p-8jj4-mh9x.json @@ -7,12 +7,8 @@ "CVE-2010-4162" ], "details": "Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6c2-frm7-53hm/GHSA-h6c2-frm7-53hm.json b/advisories/unreviewed/2022/05/GHSA-h6c2-frm7-53hm/GHSA-h6c2-frm7-53hm.json index d1e8ce095f4..15aaefa7cc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6c2-frm7-53hm/GHSA-h6c2-frm7-53hm.json +++ b/advisories/unreviewed/2022/05/GHSA-h6c2-frm7-53hm/GHSA-h6c2-frm7-53hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6jq-rjm8-48vf/GHSA-h6jq-rjm8-48vf.json b/advisories/unreviewed/2022/05/GHSA-h6jq-rjm8-48vf/GHSA-h6jq-rjm8-48vf.json index 5c9b59f5648..c4cea3f8ca2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6jq-rjm8-48vf/GHSA-h6jq-rjm8-48vf.json +++ b/advisories/unreviewed/2022/05/GHSA-h6jq-rjm8-48vf/GHSA-h6jq-rjm8-48vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h782-gpqc-8hjh/GHSA-h782-gpqc-8hjh.json b/advisories/unreviewed/2022/05/GHSA-h782-gpqc-8hjh/GHSA-h782-gpqc-8hjh.json index 200822b98ca..272895d613d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h782-gpqc-8hjh/GHSA-h782-gpqc-8hjh.json +++ b/advisories/unreviewed/2022/05/GHSA-h782-gpqc-8hjh/GHSA-h782-gpqc-8hjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8pg-g57w-hfr9/GHSA-h8pg-g57w-hfr9.json b/advisories/unreviewed/2022/05/GHSA-h8pg-g57w-hfr9/GHSA-h8pg-g57w-hfr9.json index 413f748fe0b..6a01150877c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8pg-g57w-hfr9/GHSA-h8pg-g57w-hfr9.json +++ b/advisories/unreviewed/2022/05/GHSA-h8pg-g57w-hfr9/GHSA-h8pg-g57w-hfr9.json @@ -7,12 +7,8 @@ "CVE-2010-3435" ], "details": "The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9j3-p28g-73q9/GHSA-h9j3-p28g-73q9.json b/advisories/unreviewed/2022/05/GHSA-h9j3-p28g-73q9/GHSA-h9j3-p28g-73q9.json index 5b638ac8364..3df9ae6dc4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9j3-p28g-73q9/GHSA-h9j3-p28g-73q9.json +++ b/advisories/unreviewed/2022/05/GHSA-h9j3-p28g-73q9/GHSA-h9j3-p28g-73q9.json @@ -7,12 +7,8 @@ "CVE-2019-1727" ], "details": "A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and issue arbitrary commands to elevate the attacker's privilege level. The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions in the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands to elevate the attacker's privilege level. To exploit this vulnerability, the attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfpc-f259-2f2x/GHSA-hfpc-f259-2f2x.json b/advisories/unreviewed/2022/05/GHSA-hfpc-f259-2f2x/GHSA-hfpc-f259-2f2x.json index db19f14b09e..5637b7d76ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfpc-f259-2f2x/GHSA-hfpc-f259-2f2x.json +++ b/advisories/unreviewed/2022/05/GHSA-hfpc-f259-2f2x/GHSA-hfpc-f259-2f2x.json @@ -7,12 +7,8 @@ "CVE-2013-4509" ], "details": "The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfr6-3rjr-jmhf/GHSA-hfr6-3rjr-jmhf.json b/advisories/unreviewed/2022/05/GHSA-hfr6-3rjr-jmhf/GHSA-hfr6-3rjr-jmhf.json index 664e2e9b1ce..695725382ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfr6-3rjr-jmhf/GHSA-hfr6-3rjr-jmhf.json +++ b/advisories/unreviewed/2022/05/GHSA-hfr6-3rjr-jmhf/GHSA-hfr6-3rjr-jmhf.json @@ -7,12 +7,8 @@ "CVE-2018-14999" ], "details": "The Leagoo P1 device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.wtk.factory (versionCode=1, versionName=1.0) that contains an exported broadcast receiver named com.wtk.factory.MMITestReceiver allows any app co-located on the device to programmatically initiate a factory reset. In addition, the app initiating the factory reset does not require any permissions. A factory reset will remove all user data and apps from the device. This will result in the loss of any data that have not been backed up or synced externally. The capability to perform a factory reset is not directly available to third-party apps (those that the user installs themselves with the exception of enabled Mobile Device Management (MDM) apps), although this capability can be obtained by leveraging an unprotected app component of a pre-installed platform app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgpp-34xq-jfxg/GHSA-hgpp-34xq-jfxg.json b/advisories/unreviewed/2022/05/GHSA-hgpp-34xq-jfxg/GHSA-hgpp-34xq-jfxg.json index d0843ffdd9d..e1a20f978dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgpp-34xq-jfxg/GHSA-hgpp-34xq-jfxg.json +++ b/advisories/unreviewed/2022/05/GHSA-hgpp-34xq-jfxg/GHSA-hgpp-34xq-jfxg.json @@ -7,12 +7,8 @@ "CVE-2019-2706" ], "details": "Vulnerability in the Oracle Business Process Management Suite component of Oracle Fusion Middleware (subcomponent: BPM Foundation Services). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Process Management Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgv9-5rhc-jpgp/GHSA-hgv9-5rhc-jpgp.json b/advisories/unreviewed/2022/05/GHSA-hgv9-5rhc-jpgp/GHSA-hgv9-5rhc-jpgp.json index 6418d847862..7e071268267 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgv9-5rhc-jpgp/GHSA-hgv9-5rhc-jpgp.json +++ b/advisories/unreviewed/2022/05/GHSA-hgv9-5rhc-jpgp/GHSA-hgv9-5rhc-jpgp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhhq-qgvm-w5hp/GHSA-hhhq-qgvm-w5hp.json b/advisories/unreviewed/2022/05/GHSA-hhhq-qgvm-w5hp/GHSA-hhhq-qgvm-w5hp.json index 1987c6a25d6..2d0e7c691b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhhq-qgvm-w5hp/GHSA-hhhq-qgvm-w5hp.json +++ b/advisories/unreviewed/2022/05/GHSA-hhhq-qgvm-w5hp/GHSA-hhhq-qgvm-w5hp.json @@ -7,12 +7,8 @@ "CVE-2019-7303" ], "details": "A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hj8w-jv52-fv86/GHSA-hj8w-jv52-fv86.json b/advisories/unreviewed/2022/05/GHSA-hj8w-jv52-fv86/GHSA-hj8w-jv52-fv86.json index 951b9308e6a..ec9b4c8b0ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj8w-jv52-fv86/GHSA-hj8w-jv52-fv86.json +++ b/advisories/unreviewed/2022/05/GHSA-hj8w-jv52-fv86/GHSA-hj8w-jv52-fv86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjqr-gcv7-w67w/GHSA-hjqr-gcv7-w67w.json b/advisories/unreviewed/2022/05/GHSA-hjqr-gcv7-w67w/GHSA-hjqr-gcv7-w67w.json index 058fbc9e6fa..3bb293dc1dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjqr-gcv7-w67w/GHSA-hjqr-gcv7-w67w.json +++ b/advisories/unreviewed/2022/05/GHSA-hjqr-gcv7-w67w/GHSA-hjqr-gcv7-w67w.json @@ -7,12 +7,8 @@ "CVE-2019-2675" ], "details": "Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hmhc-2w2f-2ch3/GHSA-hmhc-2w2f-2ch3.json b/advisories/unreviewed/2022/05/GHSA-hmhc-2w2f-2ch3/GHSA-hmhc-2w2f-2ch3.json index 5df330392aa..177c4423fbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmhc-2w2f-2ch3/GHSA-hmhc-2w2f-2ch3.json +++ b/advisories/unreviewed/2022/05/GHSA-hmhc-2w2f-2ch3/GHSA-hmhc-2w2f-2ch3.json @@ -7,12 +7,8 @@ "CVE-2019-2702" ], "details": "Vulnerability in the Oracle Hospitality Cruise Dining Room Management component of Oracle Hospitality Applications (subcomponent: Web Service). The supported version that is affected is 8.0.80. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Dining Room Management. While the vulnerability is in Oracle Hospitality Cruise Dining Room Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Cruise Dining Room Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Dining Room Management accessible data. CVSS 3.0 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hr4j-wcw8-qq3j/GHSA-hr4j-wcw8-qq3j.json b/advisories/unreviewed/2022/05/GHSA-hr4j-wcw8-qq3j/GHSA-hr4j-wcw8-qq3j.json index 2757e97d35b..38193841a1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr4j-wcw8-qq3j/GHSA-hr4j-wcw8-qq3j.json +++ b/advisories/unreviewed/2022/05/GHSA-hr4j-wcw8-qq3j/GHSA-hr4j-wcw8-qq3j.json @@ -7,12 +7,8 @@ "CVE-2019-2571" ], "details": "Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise RDBMS DataPump. Successful attacks of this vulnerability can result in takeover of RDBMS DataPump. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrmr-jgrx-82h5/GHSA-hrmr-jgrx-82h5.json b/advisories/unreviewed/2022/05/GHSA-hrmr-jgrx-82h5/GHSA-hrmr-jgrx-82h5.json index aee4267ce2c..9a87daceb4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrmr-jgrx-82h5/GHSA-hrmr-jgrx-82h5.json +++ b/advisories/unreviewed/2022/05/GHSA-hrmr-jgrx-82h5/GHSA-hrmr-jgrx-82h5.json @@ -7,12 +7,8 @@ "CVE-2019-11886" ], "details": "The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv3f-fvpg-gw6q/GHSA-hv3f-fvpg-gw6q.json b/advisories/unreviewed/2022/05/GHSA-hv3f-fvpg-gw6q/GHSA-hv3f-fvpg-gw6q.json index 38d7007da0e..cbb2e96f82b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv3f-fvpg-gw6q/GHSA-hv3f-fvpg-gw6q.json +++ b/advisories/unreviewed/2022/05/GHSA-hv3f-fvpg-gw6q/GHSA-hv3f-fvpg-gw6q.json @@ -7,12 +7,8 @@ "CVE-2018-20819" ], "details": "io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j28m-hq2p-7rq8/GHSA-j28m-hq2p-7rq8.json b/advisories/unreviewed/2022/05/GHSA-j28m-hq2p-7rq8/GHSA-j28m-hq2p-7rq8.json index a36822c050a..90dc70acb22 100644 --- a/advisories/unreviewed/2022/05/GHSA-j28m-hq2p-7rq8/GHSA-j28m-hq2p-7rq8.json +++ b/advisories/unreviewed/2022/05/GHSA-j28m-hq2p-7rq8/GHSA-j28m-hq2p-7rq8.json @@ -7,12 +7,8 @@ "CVE-2019-2619" ], "details": "Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2mv-rmhw-vq9m/GHSA-j2mv-rmhw-vq9m.json b/advisories/unreviewed/2022/05/GHSA-j2mv-rmhw-vq9m/GHSA-j2mv-rmhw-vq9m.json index ec4428888ed..4099d1ca94e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2mv-rmhw-vq9m/GHSA-j2mv-rmhw-vq9m.json +++ b/advisories/unreviewed/2022/05/GHSA-j2mv-rmhw-vq9m/GHSA-j2mv-rmhw-vq9m.json @@ -7,12 +7,8 @@ "CVE-2010-3858" ], "details": "The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, which allows local users to cause a denial of service (system crash) via a crafted exec system call, a related issue to CVE-2010-2240.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j334-7fp4-rx7r/GHSA-j334-7fp4-rx7r.json b/advisories/unreviewed/2022/05/GHSA-j334-7fp4-rx7r/GHSA-j334-7fp4-rx7r.json index f9e9c4a815e..5aa4810b6c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-j334-7fp4-rx7r/GHSA-j334-7fp4-rx7r.json +++ b/advisories/unreviewed/2022/05/GHSA-j334-7fp4-rx7r/GHSA-j334-7fp4-rx7r.json @@ -7,12 +7,8 @@ "CVE-2019-2704" ], "details": "Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: IPS Package Manager). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j339-cxg8-wjf2/GHSA-j339-cxg8-wjf2.json b/advisories/unreviewed/2022/05/GHSA-j339-cxg8-wjf2/GHSA-j339-cxg8-wjf2.json index b670e0cbcec..099d3f1fa26 100644 --- a/advisories/unreviewed/2022/05/GHSA-j339-cxg8-wjf2/GHSA-j339-cxg8-wjf2.json +++ b/advisories/unreviewed/2022/05/GHSA-j339-cxg8-wjf2/GHSA-j339-cxg8-wjf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4xv-vq4c-x7jr/GHSA-j4xv-vq4c-x7jr.json b/advisories/unreviewed/2022/05/GHSA-j4xv-vq4c-x7jr/GHSA-j4xv-vq4c-x7jr.json index 7de046961ed..ee80cc5c729 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4xv-vq4c-x7jr/GHSA-j4xv-vq4c-x7jr.json +++ b/advisories/unreviewed/2022/05/GHSA-j4xv-vq4c-x7jr/GHSA-j4xv-vq4c-x7jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j595-32pw-xr9x/GHSA-j595-32pw-xr9x.json b/advisories/unreviewed/2022/05/GHSA-j595-32pw-xr9x/GHSA-j595-32pw-xr9x.json index 3809138fff2..b3425d8b25d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j595-32pw-xr9x/GHSA-j595-32pw-xr9x.json +++ b/advisories/unreviewed/2022/05/GHSA-j595-32pw-xr9x/GHSA-j595-32pw-xr9x.json @@ -7,12 +7,8 @@ "CVE-2019-2564" ], "details": "Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j59g-6qmh-6hh4/GHSA-j59g-6qmh-6hh4.json b/advisories/unreviewed/2022/05/GHSA-j59g-6qmh-6hh4/GHSA-j59g-6qmh-6hh4.json index f40f336a849..b77c98c2dfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-j59g-6qmh-6hh4/GHSA-j59g-6qmh-6hh4.json +++ b/advisories/unreviewed/2022/05/GHSA-j59g-6qmh-6hh4/GHSA-j59g-6qmh-6hh4.json @@ -7,12 +7,8 @@ "CVE-2019-2551" ], "details": "Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j7pw-5g39-c2cj/GHSA-j7pw-5g39-c2cj.json b/advisories/unreviewed/2022/05/GHSA-j7pw-5g39-c2cj/GHSA-j7pw-5g39-c2cj.json index 226a2c826bd..48f7ce37548 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7pw-5g39-c2cj/GHSA-j7pw-5g39-c2cj.json +++ b/advisories/unreviewed/2022/05/GHSA-j7pw-5g39-c2cj/GHSA-j7pw-5g39-c2cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j85m-6hm4-8243/GHSA-j85m-6hm4-8243.json b/advisories/unreviewed/2022/05/GHSA-j85m-6hm4-8243/GHSA-j85m-6hm4-8243.json index 112e96b741b..c92cb399528 100644 --- a/advisories/unreviewed/2022/05/GHSA-j85m-6hm4-8243/GHSA-j85m-6hm4-8243.json +++ b/advisories/unreviewed/2022/05/GHSA-j85m-6hm4-8243/GHSA-j85m-6hm4-8243.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j939-hwr4-9qqc/GHSA-j939-hwr4-9qqc.json b/advisories/unreviewed/2022/05/GHSA-j939-hwr4-9qqc/GHSA-j939-hwr4-9qqc.json index fd7d463e536..801da5b05e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j939-hwr4-9qqc/GHSA-j939-hwr4-9qqc.json +++ b/advisories/unreviewed/2022/05/GHSA-j939-hwr4-9qqc/GHSA-j939-hwr4-9qqc.json @@ -7,12 +7,8 @@ "CVE-2010-3298" ], "details": "The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j983-4xw8-9w9m/GHSA-j983-4xw8-9w9m.json b/advisories/unreviewed/2022/05/GHSA-j983-4xw8-9w9m/GHSA-j983-4xw8-9w9m.json index 4fa5dddd522..78200876b6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j983-4xw8-9w9m/GHSA-j983-4xw8-9w9m.json +++ b/advisories/unreviewed/2022/05/GHSA-j983-4xw8-9w9m/GHSA-j983-4xw8-9w9m.json @@ -7,12 +7,8 @@ "CVE-2019-2566" ], "details": "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Plug-in). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j98f-h9mx-xrxq/GHSA-j98f-h9mx-xrxq.json b/advisories/unreviewed/2022/05/GHSA-j98f-h9mx-xrxq/GHSA-j98f-h9mx-xrxq.json index 0e0334ba440..f5314f5d5e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j98f-h9mx-xrxq/GHSA-j98f-h9mx-xrxq.json +++ b/advisories/unreviewed/2022/05/GHSA-j98f-h9mx-xrxq/GHSA-j98f-h9mx-xrxq.json @@ -7,12 +7,8 @@ "CVE-2019-3565" ], "details": "Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9pj-q5cf-g476/GHSA-j9pj-q5cf-g476.json b/advisories/unreviewed/2022/05/GHSA-j9pj-q5cf-g476/GHSA-j9pj-q5cf-g476.json index 3863e93efd6..9ace7a708ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9pj-q5cf-g476/GHSA-j9pj-q5cf-g476.json +++ b/advisories/unreviewed/2022/05/GHSA-j9pj-q5cf-g476/GHSA-j9pj-q5cf-g476.json @@ -7,12 +7,8 @@ "CVE-2019-2676" ], "details": "Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc7v-m8xx-gcf7/GHSA-jc7v-m8xx-gcf7.json b/advisories/unreviewed/2022/05/GHSA-jc7v-m8xx-gcf7/GHSA-jc7v-m8xx-gcf7.json index 69b95dd330c..6321b9b579e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc7v-m8xx-gcf7/GHSA-jc7v-m8xx-gcf7.json +++ b/advisories/unreviewed/2022/05/GHSA-jc7v-m8xx-gcf7/GHSA-jc7v-m8xx-gcf7.json @@ -7,12 +7,8 @@ "CVE-2018-14478" ], "details": "ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcvv-h5v4-vg3r/GHSA-jcvv-h5v4-vg3r.json b/advisories/unreviewed/2022/05/GHSA-jcvv-h5v4-vg3r/GHSA-jcvv-h5v4-vg3r.json index 005e801e3b3..1b9c2c5a618 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcvv-h5v4-vg3r/GHSA-jcvv-h5v4-vg3r.json +++ b/advisories/unreviewed/2022/05/GHSA-jcvv-h5v4-vg3r/GHSA-jcvv-h5v4-vg3r.json @@ -7,12 +7,8 @@ "CVE-2019-2670" ], "details": "Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfmw-rhf3-688h/GHSA-jfmw-rhf3-688h.json b/advisories/unreviewed/2022/05/GHSA-jfmw-rhf3-688h/GHSA-jfmw-rhf3-688h.json index 12f8e5e817c..e8c480391e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfmw-rhf3-688h/GHSA-jfmw-rhf3-688h.json +++ b/advisories/unreviewed/2022/05/GHSA-jfmw-rhf3-688h/GHSA-jfmw-rhf3-688h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg69-hq9p-75r5/GHSA-jg69-hq9p-75r5.json b/advisories/unreviewed/2022/05/GHSA-jg69-hq9p-75r5/GHSA-jg69-hq9p-75r5.json index c2578d1b0b6..09605b1c920 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg69-hq9p-75r5/GHSA-jg69-hq9p-75r5.json +++ b/advisories/unreviewed/2022/05/GHSA-jg69-hq9p-75r5/GHSA-jg69-hq9p-75r5.json @@ -7,12 +7,8 @@ "CVE-2010-3848" ], "details": "Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg7x-2whq-4cvh/GHSA-jg7x-2whq-4cvh.json b/advisories/unreviewed/2022/05/GHSA-jg7x-2whq-4cvh/GHSA-jg7x-2whq-4cvh.json index 81ebc917b86..6058c18171a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg7x-2whq-4cvh/GHSA-jg7x-2whq-4cvh.json +++ b/advisories/unreviewed/2022/05/GHSA-jg7x-2whq-4cvh/GHSA-jg7x-2whq-4cvh.json @@ -7,12 +7,8 @@ "CVE-2019-7217" ], "details": "Citrix ShareFile through 19.1 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhrc-gxxh-2cqh/GHSA-jhrc-gxxh-2cqh.json b/advisories/unreviewed/2022/05/GHSA-jhrc-gxxh-2cqh/GHSA-jhrc-gxxh-2cqh.json index 4a7e8369831..5003eaac225 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhrc-gxxh-2cqh/GHSA-jhrc-gxxh-2cqh.json +++ b/advisories/unreviewed/2022/05/GHSA-jhrc-gxxh-2cqh/GHSA-jhrc-gxxh-2cqh.json @@ -7,12 +7,8 @@ "CVE-2019-0733" ], "details": "A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhv9-9wc2-f5gg/GHSA-jhv9-9wc2-f5gg.json b/advisories/unreviewed/2022/05/GHSA-jhv9-9wc2-f5gg/GHSA-jhv9-9wc2-f5gg.json index 069a253e453..a693835a0c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhv9-9wc2-f5gg/GHSA-jhv9-9wc2-f5gg.json +++ b/advisories/unreviewed/2022/05/GHSA-jhv9-9wc2-f5gg/GHSA-jhv9-9wc2-f5gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhx8-jg6w-gwhp/GHSA-jhx8-jg6w-gwhp.json b/advisories/unreviewed/2022/05/GHSA-jhx8-jg6w-gwhp/GHSA-jhx8-jg6w-gwhp.json index 118695abd00..e8d04dabdb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhx8-jg6w-gwhp/GHSA-jhx8-jg6w-gwhp.json +++ b/advisories/unreviewed/2022/05/GHSA-jhx8-jg6w-gwhp/GHSA-jhx8-jg6w-gwhp.json @@ -7,12 +7,8 @@ "CVE-2019-9135" ], "details": "DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jj9q-c2r3-cv43/GHSA-jj9q-c2r3-cv43.json b/advisories/unreviewed/2022/05/GHSA-jj9q-c2r3-cv43/GHSA-jj9q-c2r3-cv43.json index 36f4b458347..f7aa8165826 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj9q-c2r3-cv43/GHSA-jj9q-c2r3-cv43.json +++ b/advisories/unreviewed/2022/05/GHSA-jj9q-c2r3-cv43/GHSA-jj9q-c2r3-cv43.json @@ -7,12 +7,8 @@ "CVE-2010-3877" ], "details": "The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmgr-533j-34jh/GHSA-jmgr-533j-34jh.json b/advisories/unreviewed/2022/05/GHSA-jmgr-533j-34jh/GHSA-jmgr-533j-34jh.json index 1498346417c..85518f09f60 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmgr-533j-34jh/GHSA-jmgr-533j-34jh.json +++ b/advisories/unreviewed/2022/05/GHSA-jmgr-533j-34jh/GHSA-jmgr-533j-34jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp4c-v6vq-9m4m/GHSA-jp4c-v6vq-9m4m.json b/advisories/unreviewed/2022/05/GHSA-jp4c-v6vq-9m4m/GHSA-jp4c-v6vq-9m4m.json index cc23f5bb8b0..8d3125d6531 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp4c-v6vq-9m4m/GHSA-jp4c-v6vq-9m4m.json +++ b/advisories/unreviewed/2022/05/GHSA-jp4c-v6vq-9m4m/GHSA-jp4c-v6vq-9m4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq73-mhwg-56vq/GHSA-jq73-mhwg-56vq.json b/advisories/unreviewed/2022/05/GHSA-jq73-mhwg-56vq/GHSA-jq73-mhwg-56vq.json index 5169e348e30..6f7e8fa2ea3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq73-mhwg-56vq/GHSA-jq73-mhwg-56vq.json +++ b/advisories/unreviewed/2022/05/GHSA-jq73-mhwg-56vq/GHSA-jq73-mhwg-56vq.json @@ -7,12 +7,8 @@ "CVE-2019-10245" ], "details": "In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqpq-g57p-mp22/GHSA-jqpq-g57p-mp22.json b/advisories/unreviewed/2022/05/GHSA-jqpq-g57p-mp22/GHSA-jqpq-g57p-mp22.json index 7abf7640372..6073b111f94 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqpq-g57p-mp22/GHSA-jqpq-g57p-mp22.json +++ b/advisories/unreviewed/2022/05/GHSA-jqpq-g57p-mp22/GHSA-jqpq-g57p-mp22.json @@ -7,12 +7,8 @@ "CVE-2019-6618" ], "details": "On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allows modifications to user objects and is contrary to our definition for the Resource Administrator (RA) role restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jr92-378w-gjp5/GHSA-jr92-378w-gjp5.json b/advisories/unreviewed/2022/05/GHSA-jr92-378w-gjp5/GHSA-jr92-378w-gjp5.json index 4c020e60cae..0bb1dbc8d16 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr92-378w-gjp5/GHSA-jr92-378w-gjp5.json +++ b/advisories/unreviewed/2022/05/GHSA-jr92-378w-gjp5/GHSA-jr92-378w-gjp5.json @@ -7,12 +7,8 @@ "CVE-2019-2721" ], "details": "Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv42-7p6p-f2c8/GHSA-jv42-7p6p-f2c8.json b/advisories/unreviewed/2022/05/GHSA-jv42-7p6p-f2c8/GHSA-jv42-7p6p-f2c8.json index 1a519ba696d..f9957d42e3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv42-7p6p-f2c8/GHSA-jv42-7p6p-f2c8.json +++ b/advisories/unreviewed/2022/05/GHSA-jv42-7p6p-f2c8/GHSA-jv42-7p6p-f2c8.json @@ -7,12 +7,8 @@ "CVE-2019-2597" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwvj-q24w-q3xh/GHSA-jwvj-q24w-q3xh.json b/advisories/unreviewed/2022/05/GHSA-jwvj-q24w-q3xh/GHSA-jwvj-q24w-q3xh.json index ef77ec347f9..5199095c309 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwvj-q24w-q3xh/GHSA-jwvj-q24w-q3xh.json +++ b/advisories/unreviewed/2022/05/GHSA-jwvj-q24w-q3xh/GHSA-jwvj-q24w-q3xh.json @@ -7,12 +7,8 @@ "CVE-2019-11844" ], "details": "An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxcc-245j-87v3/GHSA-jxcc-245j-87v3.json b/advisories/unreviewed/2022/05/GHSA-jxcc-245j-87v3/GHSA-jxcc-245j-87v3.json index 3c08e933f65..2688e9c6123 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxcc-245j-87v3/GHSA-jxcc-245j-87v3.json +++ b/advisories/unreviewed/2022/05/GHSA-jxcc-245j-87v3/GHSA-jxcc-245j-87v3.json @@ -7,12 +7,8 @@ "CVE-2018-11691" ], "details": "Emerson VE6046 09.0.12 devices have hardcoded admin credentials allowing remote connection to the Emerson Smart Switch administrative interface via HTTP or SNMPv3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxch-3gjv-mgxj/GHSA-jxch-3gjv-mgxj.json b/advisories/unreviewed/2022/05/GHSA-jxch-3gjv-mgxj/GHSA-jxch-3gjv-mgxj.json index 28368432d53..cb48951a851 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxch-3gjv-mgxj/GHSA-jxch-3gjv-mgxj.json +++ b/advisories/unreviewed/2022/05/GHSA-jxch-3gjv-mgxj/GHSA-jxch-3gjv-mgxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxmc-5jm4-w9r5/GHSA-jxmc-5jm4-w9r5.json b/advisories/unreviewed/2022/05/GHSA-jxmc-5jm4-w9r5/GHSA-jxmc-5jm4-w9r5.json index 4e382a50746..e0ed06105ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxmc-5jm4-w9r5/GHSA-jxmc-5jm4-w9r5.json +++ b/advisories/unreviewed/2022/05/GHSA-jxmc-5jm4-w9r5/GHSA-jxmc-5jm4-w9r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m35x-hj4x-3cp2/GHSA-m35x-hj4x-3cp2.json b/advisories/unreviewed/2022/05/GHSA-m35x-hj4x-3cp2/GHSA-m35x-hj4x-3cp2.json index 0bf244198b5..3e526223379 100644 --- a/advisories/unreviewed/2022/05/GHSA-m35x-hj4x-3cp2/GHSA-m35x-hj4x-3cp2.json +++ b/advisories/unreviewed/2022/05/GHSA-m35x-hj4x-3cp2/GHSA-m35x-hj4x-3cp2.json @@ -7,12 +7,8 @@ "CVE-2019-2573" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage & Navigation). Supported versions that are affected are 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m366-vqxx-9f69/GHSA-m366-vqxx-9f69.json b/advisories/unreviewed/2022/05/GHSA-m366-vqxx-9f69/GHSA-m366-vqxx-9f69.json index 43a13ad5f93..7a8f0f39744 100644 --- a/advisories/unreviewed/2022/05/GHSA-m366-vqxx-9f69/GHSA-m366-vqxx-9f69.json +++ b/advisories/unreviewed/2022/05/GHSA-m366-vqxx-9f69/GHSA-m366-vqxx-9f69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json b/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json index e1278cc2b28..b32c35ad37b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json +++ b/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m44h-7xq3-2hh7/GHSA-m44h-7xq3-2hh7.json b/advisories/unreviewed/2022/05/GHSA-m44h-7xq3-2hh7/GHSA-m44h-7xq3-2hh7.json index f37b0ce7646..37d52fbb433 100644 --- a/advisories/unreviewed/2022/05/GHSA-m44h-7xq3-2hh7/GHSA-m44h-7xq3-2hh7.json +++ b/advisories/unreviewed/2022/05/GHSA-m44h-7xq3-2hh7/GHSA-m44h-7xq3-2hh7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m45f-m7gh-g6mh/GHSA-m45f-m7gh-g6mh.json b/advisories/unreviewed/2022/05/GHSA-m45f-m7gh-g6mh/GHSA-m45f-m7gh-g6mh.json index 3f4bea0c60a..2fc601d26cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-m45f-m7gh-g6mh/GHSA-m45f-m7gh-g6mh.json +++ b/advisories/unreviewed/2022/05/GHSA-m45f-m7gh-g6mh/GHSA-m45f-m7gh-g6mh.json @@ -7,12 +7,8 @@ "CVE-2019-2591" ], "details": "Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HRMS, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HRMS accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HRMS accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4gf-qxgm-f565/GHSA-m4gf-qxgm-f565.json b/advisories/unreviewed/2022/05/GHSA-m4gf-qxgm-f565/GHSA-m4gf-qxgm-f565.json index a26151f9610..a65dc996b51 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4gf-qxgm-f565/GHSA-m4gf-qxgm-f565.json +++ b/advisories/unreviewed/2022/05/GHSA-m4gf-qxgm-f565/GHSA-m4gf-qxgm-f565.json @@ -7,12 +7,8 @@ "CVE-2019-2658" ], "details": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4vw-c8vh-3c9g/GHSA-m4vw-c8vh-3c9g.json b/advisories/unreviewed/2022/05/GHSA-m4vw-c8vh-3c9g/GHSA-m4vw-c8vh-3c9g.json index bd7abe5e962..e7a56be745f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4vw-c8vh-3c9g/GHSA-m4vw-c8vh-3c9g.json +++ b/advisories/unreviewed/2022/05/GHSA-m4vw-c8vh-3c9g/GHSA-m4vw-c8vh-3c9g.json @@ -7,12 +7,8 @@ "CVE-2019-10917" ], "details": "A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC WinCC (TIA Portal) V13 (All versions), SIMATIC WinCC (TIA Portal) V14 (All versions), SIMATIC WinCC (TIA Portal) V15 (All versions), SIMATIC WinCC Runtime Professional (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 Upd3). An attacker with local access to the project file could cause a Denial-of-Service condition on the affected product while the project file is loaded. Successful exploitation requires access to the project file. An attacker could use the vulnerability to compromise availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5px-2q2g-hxc2/GHSA-m5px-2q2g-hxc2.json b/advisories/unreviewed/2022/05/GHSA-m5px-2q2g-hxc2/GHSA-m5px-2q2g-hxc2.json index 971e2231739..f0f3bf97803 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5px-2q2g-hxc2/GHSA-m5px-2q2g-hxc2.json +++ b/advisories/unreviewed/2022/05/GHSA-m5px-2q2g-hxc2/GHSA-m5px-2q2g-hxc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m662-7xcg-f6rg/GHSA-m662-7xcg-f6rg.json b/advisories/unreviewed/2022/05/GHSA-m662-7xcg-f6rg/GHSA-m662-7xcg-f6rg.json index 3beabc73bcd..f19ee130967 100644 --- a/advisories/unreviewed/2022/05/GHSA-m662-7xcg-f6rg/GHSA-m662-7xcg-f6rg.json +++ b/advisories/unreviewed/2022/05/GHSA-m662-7xcg-f6rg/GHSA-m662-7xcg-f6rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m67p-4364-8xgh/GHSA-m67p-4364-8xgh.json b/advisories/unreviewed/2022/05/GHSA-m67p-4364-8xgh/GHSA-m67p-4364-8xgh.json index 748753fbf71..bc31adf8cda 100644 --- a/advisories/unreviewed/2022/05/GHSA-m67p-4364-8xgh/GHSA-m67p-4364-8xgh.json +++ b/advisories/unreviewed/2022/05/GHSA-m67p-4364-8xgh/GHSA-m67p-4364-8xgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7jv-h3ph-p6cg/GHSA-m7jv-h3ph-p6cg.json b/advisories/unreviewed/2022/05/GHSA-m7jv-h3ph-p6cg/GHSA-m7jv-h3ph-p6cg.json index 2722f2f784d..5f59e2adef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7jv-h3ph-p6cg/GHSA-m7jv-h3ph-p6cg.json +++ b/advisories/unreviewed/2022/05/GHSA-m7jv-h3ph-p6cg/GHSA-m7jv-h3ph-p6cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7mv-qphm-p8rq/GHSA-m7mv-qphm-p8rq.json b/advisories/unreviewed/2022/05/GHSA-m7mv-qphm-p8rq/GHSA-m7mv-qphm-p8rq.json index 8f875ecb63a..9bd876e6ed1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7mv-qphm-p8rq/GHSA-m7mv-qphm-p8rq.json +++ b/advisories/unreviewed/2022/05/GHSA-m7mv-qphm-p8rq/GHSA-m7mv-qphm-p8rq.json @@ -7,12 +7,8 @@ "CVE-2019-10921" ], "details": "A vulnerability has been identified in LOGO!8 BM (All versions). Unencrypted storage of passwords in the project could allow an attacker with access to port 10005/tcp to obtain passwords of the device. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was known", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m823-4p4w-x3cg/GHSA-m823-4p4w-x3cg.json b/advisories/unreviewed/2022/05/GHSA-m823-4p4w-x3cg/GHSA-m823-4p4w-x3cg.json index ff618686b8d..cfd9943d405 100644 --- a/advisories/unreviewed/2022/05/GHSA-m823-4p4w-x3cg/GHSA-m823-4p4w-x3cg.json +++ b/advisories/unreviewed/2022/05/GHSA-m823-4p4w-x3cg/GHSA-m823-4p4w-x3cg.json @@ -7,12 +7,8 @@ "CVE-2019-11220" ], "details": "An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device traffic in cleartext, including video streams and device credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9vp-847v-2qr3/GHSA-m9vp-847v-2qr3.json b/advisories/unreviewed/2022/05/GHSA-m9vp-847v-2qr3/GHSA-m9vp-847v-2qr3.json index d8280d72469..cceca7d0513 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9vp-847v-2qr3/GHSA-m9vp-847v-2qr3.json +++ b/advisories/unreviewed/2022/05/GHSA-m9vp-847v-2qr3/GHSA-m9vp-847v-2qr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcgx-x3rr-p246/GHSA-mcgx-x3rr-p246.json b/advisories/unreviewed/2022/05/GHSA-mcgx-x3rr-p246/GHSA-mcgx-x3rr-p246.json index 2201a81cb4f..2c3191cce39 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcgx-x3rr-p246/GHSA-mcgx-x3rr-p246.json +++ b/advisories/unreviewed/2022/05/GHSA-mcgx-x3rr-p246/GHSA-mcgx-x3rr-p246.json @@ -7,12 +7,8 @@ "CVE-2019-1724" ], "details": "A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. An attacker could use this impersonated session to create a new user account or otherwise control the device with the privileges of the hijacked session. The vulnerability is due to a lack of proper session management controls. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted device. A successful exploit could allow the attacker to take control of an existing user session on the device. Exploitation of the vulnerability requires that an authorized user session is active and that the attacker can craft an HTTP request to impersonate that session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfjh-x56p-qx6f/GHSA-mfjh-x56p-qx6f.json b/advisories/unreviewed/2022/05/GHSA-mfjh-x56p-qx6f/GHSA-mfjh-x56p-qx6f.json index ce3f28a37f5..d7b8ddd9792 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfjh-x56p-qx6f/GHSA-mfjh-x56p-qx6f.json +++ b/advisories/unreviewed/2022/05/GHSA-mfjh-x56p-qx6f/GHSA-mfjh-x56p-qx6f.json @@ -7,12 +7,8 @@ "CVE-2019-2659" ], "details": "Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfw8-6m9g-8vvr/GHSA-mfw8-6m9g-8vvr.json b/advisories/unreviewed/2022/05/GHSA-mfw8-6m9g-8vvr/GHSA-mfw8-6m9g-8vvr.json index 3ef2be93fd2..5f48a3316a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfw8-6m9g-8vvr/GHSA-mfw8-6m9g-8vvr.json +++ b/advisories/unreviewed/2022/05/GHSA-mfw8-6m9g-8vvr/GHSA-mfw8-6m9g-8vvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfwf-2cj2-j29m/GHSA-mfwf-2cj2-j29m.json b/advisories/unreviewed/2022/05/GHSA-mfwf-2cj2-j29m/GHSA-mfwf-2cj2-j29m.json index ca1b8b78f80..041d0f7506b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfwf-2cj2-j29m/GHSA-mfwf-2cj2-j29m.json +++ b/advisories/unreviewed/2022/05/GHSA-mfwf-2cj2-j29m/GHSA-mfwf-2cj2-j29m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgrj-fw6g-5692/GHSA-mgrj-fw6g-5692.json b/advisories/unreviewed/2022/05/GHSA-mgrj-fw6g-5692/GHSA-mgrj-fw6g-5692.json index eb45a2d826e..eb9b255ec47 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgrj-fw6g-5692/GHSA-mgrj-fw6g-5692.json +++ b/advisories/unreviewed/2022/05/GHSA-mgrj-fw6g-5692/GHSA-mgrj-fw6g-5692.json @@ -7,12 +7,8 @@ "CVE-2019-0734" ], "details": "An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0936.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgxg-5jhr-xcq8/GHSA-mgxg-5jhr-xcq8.json b/advisories/unreviewed/2022/05/GHSA-mgxg-5jhr-xcq8/GHSA-mgxg-5jhr-xcq8.json index af686d3977a..2ce288220fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgxg-5jhr-xcq8/GHSA-mgxg-5jhr-xcq8.json +++ b/advisories/unreviewed/2022/05/GHSA-mgxg-5jhr-xcq8/GHSA-mgxg-5jhr-xcq8.json @@ -7,12 +7,8 @@ "CVE-2019-2679" ], "details": "Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhfh-8w59-m7cx/GHSA-mhfh-8w59-m7cx.json b/advisories/unreviewed/2022/05/GHSA-mhfh-8w59-m7cx/GHSA-mhfh-8w59-m7cx.json index 25254b75bc7..62aed4d17f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhfh-8w59-m7cx/GHSA-mhfh-8w59-m7cx.json +++ b/advisories/unreviewed/2022/05/GHSA-mhfh-8w59-m7cx/GHSA-mhfh-8w59-m7cx.json @@ -7,12 +7,8 @@ "CVE-2019-2643" ], "details": "Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhv7-384m-mmrf/GHSA-mhv7-384m-mmrf.json b/advisories/unreviewed/2022/05/GHSA-mhv7-384m-mmrf/GHSA-mhv7-384m-mmrf.json index 8c26aa78974..c8e4fec468c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhv7-384m-mmrf/GHSA-mhv7-384m-mmrf.json +++ b/advisories/unreviewed/2022/05/GHSA-mhv7-384m-mmrf/GHSA-mhv7-384m-mmrf.json @@ -7,12 +7,8 @@ "CVE-2019-1784" ], "details": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mj9m-8g64-3hhp/GHSA-mj9m-8g64-3hhp.json b/advisories/unreviewed/2022/05/GHSA-mj9m-8g64-3hhp/GHSA-mj9m-8g64-3hhp.json index 3ff71b8392f..65feb4226fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj9m-8g64-3hhp/GHSA-mj9m-8g64-3hhp.json +++ b/advisories/unreviewed/2022/05/GHSA-mj9m-8g64-3hhp/GHSA-mj9m-8g64-3hhp.json @@ -7,12 +7,8 @@ "CVE-2019-2610" ], "details": "Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjp6-fq4v-qgrp/GHSA-mjp6-fq4v-qgrp.json b/advisories/unreviewed/2022/05/GHSA-mjp6-fq4v-qgrp/GHSA-mjp6-fq4v-qgrp.json index f30e72f9cc0..e0d69440290 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp6-fq4v-qgrp/GHSA-mjp6-fq4v-qgrp.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp6-fq4v-qgrp/GHSA-mjp6-fq4v-qgrp.json @@ -7,12 +7,8 @@ "CVE-2019-8350" ], "details": "The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionality. Third-party Android keyboards that capture the password may store this password in cleartext, or transmit the password to third-party services for keyboard customization purposes. A compromise of any datastore that contains keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm9v-95j4-52gp/GHSA-mm9v-95j4-52gp.json b/advisories/unreviewed/2022/05/GHSA-mm9v-95j4-52gp/GHSA-mm9v-95j4-52gp.json index ee5f2a786a4..ca1bd97ca1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm9v-95j4-52gp/GHSA-mm9v-95j4-52gp.json +++ b/advisories/unreviewed/2022/05/GHSA-mm9v-95j4-52gp/GHSA-mm9v-95j4-52gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw8m-jhfq-5hv9/GHSA-mw8m-jhfq-5hv9.json b/advisories/unreviewed/2022/05/GHSA-mw8m-jhfq-5hv9/GHSA-mw8m-jhfq-5hv9.json index dee44f26c43..ebd263e2071 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw8m-jhfq-5hv9/GHSA-mw8m-jhfq-5hv9.json +++ b/advisories/unreviewed/2022/05/GHSA-mw8m-jhfq-5hv9/GHSA-mw8m-jhfq-5hv9.json @@ -7,12 +7,8 @@ "CVE-2012-6075" ], "details": "Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx52-g499-r9jm/GHSA-mx52-g499-r9jm.json b/advisories/unreviewed/2022/05/GHSA-mx52-g499-r9jm/GHSA-mx52-g499-r9jm.json index 2014e08d2ff..9055c067ed9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx52-g499-r9jm/GHSA-mx52-g499-r9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-mx52-g499-r9jm/GHSA-mx52-g499-r9jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx9j-5cm7-gv82/GHSA-mx9j-5cm7-gv82.json b/advisories/unreviewed/2022/05/GHSA-mx9j-5cm7-gv82/GHSA-mx9j-5cm7-gv82.json index 1af18d7d1c6..745df220c92 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx9j-5cm7-gv82/GHSA-mx9j-5cm7-gv82.json +++ b/advisories/unreviewed/2022/05/GHSA-mx9j-5cm7-gv82/GHSA-mx9j-5cm7-gv82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2pj-jx8f-jw9f/GHSA-p2pj-jx8f-jw9f.json b/advisories/unreviewed/2022/05/GHSA-p2pj-jx8f-jw9f/GHSA-p2pj-jx8f-jw9f.json index 2ba7272410d..9218737a264 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2pj-jx8f-jw9f/GHSA-p2pj-jx8f-jw9f.json +++ b/advisories/unreviewed/2022/05/GHSA-p2pj-jx8f-jw9f/GHSA-p2pj-jx8f-jw9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2w2-rrf2-qqmj/GHSA-p2w2-rrf2-qqmj.json b/advisories/unreviewed/2022/05/GHSA-p2w2-rrf2-qqmj/GHSA-p2w2-rrf2-qqmj.json index 5cb62c8df22..34f3da01a7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2w2-rrf2-qqmj/GHSA-p2w2-rrf2-qqmj.json +++ b/advisories/unreviewed/2022/05/GHSA-p2w2-rrf2-qqmj/GHSA-p2w2-rrf2-qqmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5cg-gfxr-62pm/GHSA-p5cg-gfxr-62pm.json b/advisories/unreviewed/2022/05/GHSA-p5cg-gfxr-62pm/GHSA-p5cg-gfxr-62pm.json index 5a57014ea66..cf2648e43b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5cg-gfxr-62pm/GHSA-p5cg-gfxr-62pm.json +++ b/advisories/unreviewed/2022/05/GHSA-p5cg-gfxr-62pm/GHSA-p5cg-gfxr-62pm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5f9-4qvw-vrhw/GHSA-p5f9-4qvw-vrhw.json b/advisories/unreviewed/2022/05/GHSA-p5f9-4qvw-vrhw/GHSA-p5f9-4qvw-vrhw.json index c1020f30fc9..77f26961ef2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5f9-4qvw-vrhw/GHSA-p5f9-4qvw-vrhw.json +++ b/advisories/unreviewed/2022/05/GHSA-p5f9-4qvw-vrhw/GHSA-p5f9-4qvw-vrhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6mx-xx2r-f2hh/GHSA-p6mx-xx2r-f2hh.json b/advisories/unreviewed/2022/05/GHSA-p6mx-xx2r-f2hh/GHSA-p6mx-xx2r-f2hh.json index cc46f9a7cee..78539a05d74 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6mx-xx2r-f2hh/GHSA-p6mx-xx2r-f2hh.json +++ b/advisories/unreviewed/2022/05/GHSA-p6mx-xx2r-f2hh/GHSA-p6mx-xx2r-f2hh.json @@ -7,12 +7,8 @@ "CVE-2019-8349" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6p3-chv5-mwrq/GHSA-p6p3-chv5-mwrq.json b/advisories/unreviewed/2022/05/GHSA-p6p3-chv5-mwrq/GHSA-p6p3-chv5-mwrq.json index 9b22f864af3..06d408d030a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6p3-chv5-mwrq/GHSA-p6p3-chv5-mwrq.json +++ b/advisories/unreviewed/2022/05/GHSA-p6p3-chv5-mwrq/GHSA-p6p3-chv5-mwrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p72g-8563-4jg8/GHSA-p72g-8563-4jg8.json b/advisories/unreviewed/2022/05/GHSA-p72g-8563-4jg8/GHSA-p72g-8563-4jg8.json index e256ceb1d8b..59613f1889c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p72g-8563-4jg8/GHSA-p72g-8563-4jg8.json +++ b/advisories/unreviewed/2022/05/GHSA-p72g-8563-4jg8/GHSA-p72g-8563-4jg8.json @@ -7,12 +7,8 @@ "CVE-2019-1732" ], "details": "A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which could lead to arbitrary command injection. The vulnerability is due to the lack of a proper locking mechanism on critical variables that need to stay static until used. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a set of RPM-related CLI commands. A successful exploit could allow the attacker to perform arbitrary command injection. The attacker would need administrator credentials for the targeted device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p785-ww3c-xg46/GHSA-p785-ww3c-xg46.json b/advisories/unreviewed/2022/05/GHSA-p785-ww3c-xg46/GHSA-p785-ww3c-xg46.json index c2b571f6923..341a12aa739 100644 --- a/advisories/unreviewed/2022/05/GHSA-p785-ww3c-xg46/GHSA-p785-ww3c-xg46.json +++ b/advisories/unreviewed/2022/05/GHSA-p785-ww3c-xg46/GHSA-p785-ww3c-xg46.json @@ -7,12 +7,8 @@ "CVE-2019-11596" ], "details": "In memcached before 1.5.14, a NULL pointer dereference was found in the \"lru mode\" and \"lru temp_ttl\" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p83g-f9xr-p3gp/GHSA-p83g-f9xr-p3gp.json b/advisories/unreviewed/2022/05/GHSA-p83g-f9xr-p3gp/GHSA-p83g-f9xr-p3gp.json index 2256a05c2b6..e9afaafb009 100644 --- a/advisories/unreviewed/2022/05/GHSA-p83g-f9xr-p3gp/GHSA-p83g-f9xr-p3gp.json +++ b/advisories/unreviewed/2022/05/GHSA-p83g-f9xr-p3gp/GHSA-p83g-f9xr-p3gp.json @@ -7,12 +7,8 @@ "CVE-2010-4157" ], "details": "Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p87v-9j2v-6w24/GHSA-p87v-9j2v-6w24.json b/advisories/unreviewed/2022/05/GHSA-p87v-9j2v-6w24/GHSA-p87v-9j2v-6w24.json index 0528df9066f..b88b1b3cc96 100644 --- a/advisories/unreviewed/2022/05/GHSA-p87v-9j2v-6w24/GHSA-p87v-9j2v-6w24.json +++ b/advisories/unreviewed/2022/05/GHSA-p87v-9j2v-6w24/GHSA-p87v-9j2v-6w24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc2w-jhrj-hpff/GHSA-pc2w-jhrj-hpff.json b/advisories/unreviewed/2022/05/GHSA-pc2w-jhrj-hpff/GHSA-pc2w-jhrj-hpff.json index ac8f41c89b8..cab723ca8c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc2w-jhrj-hpff/GHSA-pc2w-jhrj-hpff.json +++ b/advisories/unreviewed/2022/05/GHSA-pc2w-jhrj-hpff/GHSA-pc2w-jhrj-hpff.json @@ -7,12 +7,8 @@ "CVE-2019-2705" ], "details": "Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology as well as unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc57-hj73-639x/GHSA-pc57-hj73-639x.json b/advisories/unreviewed/2022/05/GHSA-pc57-hj73-639x/GHSA-pc57-hj73-639x.json index b956c2e6726..ba402a4b0ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc57-hj73-639x/GHSA-pc57-hj73-639x.json +++ b/advisories/unreviewed/2022/05/GHSA-pc57-hj73-639x/GHSA-pc57-hj73-639x.json @@ -7,12 +7,8 @@ "CVE-2019-2598" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: SQR). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfm3-fqrj-vmfw/GHSA-pfm3-fqrj-vmfw.json b/advisories/unreviewed/2022/05/GHSA-pfm3-fqrj-vmfw/GHSA-pfm3-fqrj-vmfw.json index 3e5b24a1e4d..f18b9d2200d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfm3-fqrj-vmfw/GHSA-pfm3-fqrj-vmfw.json +++ b/advisories/unreviewed/2022/05/GHSA-pfm3-fqrj-vmfw/GHSA-pfm3-fqrj-vmfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm95-5cg4-7h69/GHSA-pm95-5cg4-7h69.json b/advisories/unreviewed/2022/05/GHSA-pm95-5cg4-7h69/GHSA-pm95-5cg4-7h69.json index 987e5d291b5..253b2449ac7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm95-5cg4-7h69/GHSA-pm95-5cg4-7h69.json +++ b/advisories/unreviewed/2022/05/GHSA-pm95-5cg4-7h69/GHSA-pm95-5cg4-7h69.json @@ -7,12 +7,8 @@ "CVE-2019-0758" ], "details": "An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppp5-ggm8-7mmf/GHSA-ppp5-ggm8-7mmf.json b/advisories/unreviewed/2022/05/GHSA-ppp5-ggm8-7mmf/GHSA-ppp5-ggm8-7mmf.json index 3063d21116c..f838e8be547 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppp5-ggm8-7mmf/GHSA-ppp5-ggm8-7mmf.json +++ b/advisories/unreviewed/2022/05/GHSA-ppp5-ggm8-7mmf/GHSA-ppp5-ggm8-7mmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq2h-hxv7-w669/GHSA-pq2h-hxv7-w669.json b/advisories/unreviewed/2022/05/GHSA-pq2h-hxv7-w669/GHSA-pq2h-hxv7-w669.json index 8c81d51249e..70f2c61c70b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq2h-hxv7-w669/GHSA-pq2h-hxv7-w669.json +++ b/advisories/unreviewed/2022/05/GHSA-pq2h-hxv7-w669/GHSA-pq2h-hxv7-w669.json @@ -7,12 +7,8 @@ "CVE-2019-11321" ], "details": "An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pq6j-c37f-96x2/GHSA-pq6j-c37f-96x2.json b/advisories/unreviewed/2022/05/GHSA-pq6j-c37f-96x2/GHSA-pq6j-c37f-96x2.json index 9ddf1d8ed7b..56fc7efa882 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq6j-c37f-96x2/GHSA-pq6j-c37f-96x2.json +++ b/advisories/unreviewed/2022/05/GHSA-pq6j-c37f-96x2/GHSA-pq6j-c37f-96x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqg7-ghrf-8r7w/GHSA-pqg7-ghrf-8r7w.json b/advisories/unreviewed/2022/05/GHSA-pqg7-ghrf-8r7w/GHSA-pqg7-ghrf-8r7w.json index 16094670f48..bc89da8563e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqg7-ghrf-8r7w/GHSA-pqg7-ghrf-8r7w.json +++ b/advisories/unreviewed/2022/05/GHSA-pqg7-ghrf-8r7w/GHSA-pqg7-ghrf-8r7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqhq-pv8w-43hj/GHSA-pqhq-pv8w-43hj.json b/advisories/unreviewed/2022/05/GHSA-pqhq-pv8w-43hj/GHSA-pqhq-pv8w-43hj.json index ceac47e86af..e812259a104 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqhq-pv8w-43hj/GHSA-pqhq-pv8w-43hj.json +++ b/advisories/unreviewed/2022/05/GHSA-pqhq-pv8w-43hj/GHSA-pqhq-pv8w-43hj.json @@ -7,12 +7,8 @@ "CVE-2019-10640" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json b/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json index be58b19dc26..563a86649a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json +++ b/advisories/unreviewed/2022/05/GHSA-pr66-gfw7-8w5p/GHSA-pr66-gfw7-8w5p.json @@ -7,12 +7,8 @@ "CVE-2019-6516" ], "details": "An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvp6-8jxg-p694/GHSA-pvp6-8jxg-p694.json b/advisories/unreviewed/2022/05/GHSA-pvp6-8jxg-p694/GHSA-pvp6-8jxg-p694.json index c5be227babe..72aad94a288 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvp6-8jxg-p694/GHSA-pvp6-8jxg-p694.json +++ b/advisories/unreviewed/2022/05/GHSA-pvp6-8jxg-p694/GHSA-pvp6-8jxg-p694.json @@ -7,12 +7,8 @@ "CVE-2019-2605" ], "details": "Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Web Catalog). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pw77-5cwc-848f/GHSA-pw77-5cwc-848f.json b/advisories/unreviewed/2022/05/GHSA-pw77-5cwc-848f/GHSA-pw77-5cwc-848f.json index 05d37e7c514..55ee2df68d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw77-5cwc-848f/GHSA-pw77-5cwc-848f.json +++ b/advisories/unreviewed/2022/05/GHSA-pw77-5cwc-848f/GHSA-pw77-5cwc-848f.json @@ -7,12 +7,8 @@ "CVE-2019-9618" ], "details": "The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the \"cfg\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-px2q-6q9w-p7wc/GHSA-px2q-6q9w-p7wc.json b/advisories/unreviewed/2022/05/GHSA-px2q-6q9w-p7wc/GHSA-px2q-6q9w-p7wc.json index f12e6a9f810..398a64d7b14 100644 --- a/advisories/unreviewed/2022/05/GHSA-px2q-6q9w-p7wc/GHSA-px2q-6q9w-p7wc.json +++ b/advisories/unreviewed/2022/05/GHSA-px2q-6q9w-p7wc/GHSA-px2q-6q9w-p7wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2xx-h2wh-wv97/GHSA-q2xx-h2wh-wv97.json b/advisories/unreviewed/2022/05/GHSA-q2xx-h2wh-wv97/GHSA-q2xx-h2wh-wv97.json index cd1a763d131..e0609effb3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2xx-h2wh-wv97/GHSA-q2xx-h2wh-wv97.json +++ b/advisories/unreviewed/2022/05/GHSA-q2xx-h2wh-wv97/GHSA-q2xx-h2wh-wv97.json @@ -7,12 +7,8 @@ "CVE-2019-4055" ], "details": "IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3cq-46x3-3mxj/GHSA-q3cq-46x3-3mxj.json b/advisories/unreviewed/2022/05/GHSA-q3cq-46x3-3mxj/GHSA-q3cq-46x3-3mxj.json index 496d8dcff38..f7307e82dcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3cq-46x3-3mxj/GHSA-q3cq-46x3-3mxj.json +++ b/advisories/unreviewed/2022/05/GHSA-q3cq-46x3-3mxj/GHSA-q3cq-46x3-3mxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4gr-p99g-9293/GHSA-q4gr-p99g-9293.json b/advisories/unreviewed/2022/05/GHSA-q4gr-p99g-9293/GHSA-q4gr-p99g-9293.json index 72c2ea7bd95..195f1638da7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4gr-p99g-9293/GHSA-q4gr-p99g-9293.json +++ b/advisories/unreviewed/2022/05/GHSA-q4gr-p99g-9293/GHSA-q4gr-p99g-9293.json @@ -7,12 +7,8 @@ "CVE-2019-12047" ], "details": "Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the \"nested.smm.vmxon and end up with both\nvmxon=false and smm.vmxon=false, but all other nVMX state allocated.\n\nDon't attempt to gracefully handle the transition as (a) most transitions\nare nonsencial, e.g. forcing SMM while L2 is running, (b) there isn't\nsufficient information to handle all transitions, e.g. SVM wants access\nto the SMRAM save state, and (c) KVM_SET_VCPU_EVENTS must precede\nKVM_SET_NESTED_STATE during state restore as the latter disallows putting\nthe vCPU into L2 if SMM is active, and disallows tagging the vCPU as\nbeing post-VMXON in SMM if SMM is not active.\n\nAbuse of KVM_SET_VCPU_EVENTS manifests as a WARN and memory leak in nVMX\ndue to failure to free vmcs01's shadow VMCS, but the bug goes far beyond\njust a memory leak, e.g. toggling SMM on while L2 is active puts the vCPU\nin an architecturally impossible state.\n\n WARNING: CPU: 0 PID: 3606 at free_loaded_vmcs arch/x86/kvm/vmx/vmx.c:2665 [inline]\n WARNING: CPU: 0 PID: 3606 at free_loaded_vmcs+0x158/0x1a0 arch/x86/kvm/vmx/vmx.c:2656\n Modules linked in:\n CPU: 1 PID: 3606 Comm: syz-executor725 Not tainted 5.17.0-rc1-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\n RIP: 0010:free_loaded_vmcs arch/x86/kvm/vmx/vmx.c:2665 [inline]\n RIP: 0010:free_loaded_vmcs+0x158/0x1a0 arch/x86/kvm/vmx/vmx.c:2656\n Code: <0f> 0b eb b3 e8 8f 4d 9f 00 e9 f7 fe ff ff 48 89 df e8 92 4d 9f 00\n Call Trace:\n \n kvm_arch_vcpu_destroy+0x72/0x2f0 arch/x86/kvm/x86.c:11123\n kvm_vcpu_destroy arch/x86/kvm/../../../virt/kvm/kvm_main.c:441 [inline]\n kvm_destroy_vcpus+0x11f/0x290 arch/x86/kvm/../../../virt/kvm/kvm_main.c:460\n kvm_free_vcpus arch/x86/kvm/x86.c:11564 [inline]\n kvm_arch_destroy_vm+0x2e8/0x470 arch/x86/kvm/x86.c:11676\n kvm_destroy_vm arch/x86/kvm/../../../virt/kvm/kvm_main.c:1217 [inline]\n kvm_put_kvm+0x4fa/0xb00 arch/x86/kvm/../../../virt/kvm/kvm_main.c:1250\n kvm_vm_release+0x3f/0x50 arch/x86/kvm/../../../virt/kvm/kvm_main.c:1273\n __fput+0x286/0x9f0 fs/file_table.c:311\n task_work_run+0xdd/0x1a0 kernel/task_work.c:164\n exit_task_work include/linux/task_work.h:32 [inline]\n do_exit+0xb29/0x2a30 kernel/exit.c:806\n do_group_exit+0xd2/0x2f0 kernel/exit.c:935\n get_signal+0x4b0/0x28c0 kernel/signal.c:2862\n arch_do_signal_or_restart+0x2a9/0x1c40 arch/x86/kernel/signal.c:868\n handle_signal_work kernel/entry/common.c:148 [inline]\n exit_to_user_mode_loop kernel/entry/common.c:172 [inline]\n exit_to_user_mode_prepare+0x17d/0x290 kernel/entry/common.c:207\n __syscall_exit_to_user_mode_work kernel/entry/common.c:289 [inline]\n syscall_exit_to_user_mode+0x19/0x60 kernel/entry/common.c:300\n do_syscall_64+0x42/0xb0 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json b/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json index 364b15bf416..897652b27af 100644 --- a/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json +++ b/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json @@ -7,12 +7,8 @@ "CVE-2022-48766" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU.\n\nMirrors the logic for dcn30. Cue lots of WARNs and some\nkernel panics without this fix.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json b/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json index 361ea125f53..07cb08ebfb7 100644 --- a/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json +++ b/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json @@ -7,12 +7,8 @@ "CVE-2022-48758" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bnx2fc: Flush destroy_work queue before calling bnx2fc_interface_put()\n\nThe bnx2fc_destroy() functions are removing the interface before calling\ndestroy_work. This results multiple WARNings from sysfs_remove_group() as\nthe controller rport device attributes are removed too early.\n\nReplace the fcoe_port's destroy_work queue. It's not needed.\n\nThe problem is easily reproducible with the following steps.\n\nExample:\n\n $ dmesg -w &\n $ systemctl enable --now fcoe\n $ fipvlan -s -c ens2f1\n $ fcoeadm -d ens2f1.802\n [ 583.464488] host2: libfc: Link down on port (7500a1)\n [ 583.472651] bnx2fc: 7500a1 - rport not created Yet!!\n [ 583.490468] ------------[ cut here ]------------\n [ 583.538725] sysfs group 'power' not found for kobject 'rport-2:0-0'\n [ 583.568814] WARNING: CPU: 3 PID: 192 at fs/sysfs/group.c:279 sysfs_remove_group+0x6f/0x80\n [ 583.607130] Modules linked in: dm_service_time 8021q garp mrp stp llc bnx2fc cnic uio rpcsec_gss_krb5 auth_rpcgss nfsv4 ...\n [ 583.942994] CPU: 3 PID: 192 Comm: kworker/3:2 Kdump: loaded Not tainted 5.14.0-39.el9.x86_64 #1\n [ 583.984105] Hardware name: HP ProLiant DL120 G7, BIOS J01 07/01/2013\n [ 584.016535] Workqueue: fc_wq_2 fc_rport_final_delete [scsi_transport_fc]\n [ 584.050691] RIP: 0010:sysfs_remove_group+0x6f/0x80\n [ 584.074725] Code: ff 5b 48 89 ef 5d 41 5c e9 ee c0 ff ff 48 89 ef e8 f6 b8 ff ff eb d1 49 8b 14 24 48 8b 33 48 c7 c7 ...\n [ 584.162586] RSP: 0018:ffffb567c15afdc0 EFLAGS: 00010282\n [ 584.188225] RAX: 0000000000000000 RBX: ffffffff8eec4220 RCX: 0000000000000000\n [ 584.221053] RDX: ffff8c1586ce84c0 RSI: ffff8c1586cd7cc0 RDI: ffff8c1586cd7cc0\n [ 584.255089] RBP: 0000000000000000 R08: 0000000000000000 R09: ffffb567c15afc00\n [ 584.287954] R10: ffffb567c15afbf8 R11: ffffffff8fbe7f28 R12: ffff8c1486326400\n [ 584.322356] R13: ffff8c1486326480 R14: ffff8c1483a4a000 R15: 0000000000000004\n [ 584.355379] FS: 0000000000000000(0000) GS:ffff8c1586cc0000(0000) knlGS:0000000000000000\n [ 584.394419] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [ 584.421123] CR2: 00007fe95a6f7840 CR3: 0000000107674002 CR4: 00000000000606e0\n [ 584.454888] Call Trace:\n [ 584.466108] device_del+0xb2/0x3e0\n [ 584.481701] device_unregister+0x13/0x60\n [ 584.501306] bsg_unregister_queue+0x5b/0x80\n [ 584.522029] bsg_remove_queue+0x1c/0x40\n [ 584.541884] fc_rport_final_delete+0xf3/0x1d0 [scsi_transport_fc]\n [ 584.573823] process_one_work+0x1e3/0x3b0\n [ 584.592396] worker_thread+0x50/0x3b0\n [ 584.609256] ? rescuer_thread+0x370/0x370\n [ 584.628877] kthread+0x149/0x170\n [ 584.643673] ? set_kthread_struct+0x40/0x40\n [ 584.662909] ret_from_fork+0x22/0x30\n [ 584.680002] ---[ end trace 53575ecefa942ece ]---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json b/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json index 697b7abc5b5..cc17708e699 100644 --- a/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json +++ b/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json @@ -7,12 +7,8 @@ "CVE-2022-48752" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/perf: Fix power_pmu_disable to call clear_pmi_irq_pending only if PMI is pending\n\nRunning selftest with CONFIG_PPC_IRQ_SOFT_MASK_DEBUG enabled in kernel\ntriggered below warning:\n\n[ 172.851380] ------------[ cut here ]------------\n[ 172.851391] WARNING: CPU: 8 PID: 2901 at arch/powerpc/include/asm/hw_irq.h:246 power_pmu_disable+0x270/0x280\n[ 172.851402] Modules linked in: dm_mod bonding nft_ct nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables rfkill nfnetlink sunrpc xfs libcrc32c pseries_rng xts vmx_crypto uio_pdrv_genirq uio sch_fq_codel ip_tables ext4 mbcache jbd2 sd_mod t10_pi sg ibmvscsi ibmveth scsi_transport_srp fuse\n[ 172.851442] CPU: 8 PID: 2901 Comm: lost_exception_ Not tainted 5.16.0-rc5-03218-g798527287598 #2\n[ 172.851451] NIP: c00000000013d600 LR: c00000000013d5a4 CTR: c00000000013b180\n[ 172.851458] REGS: c000000017687860 TRAP: 0700 Not tainted (5.16.0-rc5-03218-g798527287598)\n[ 172.851465] MSR: 8000000000029033 CR: 48004884 XER: 20040000\n[ 172.851482] CFAR: c00000000013d5b4 IRQMASK: 1\n[ 172.851482] GPR00: c00000000013d5a4 c000000017687b00 c000000002a10600 0000000000000004\n[ 172.851482] GPR04: 0000000082004000 c0000008ba08f0a8 0000000000000000 00000008b7ed0000\n[ 172.851482] GPR08: 00000000446194f6 0000000000008000 c00000000013b118 c000000000d58e68\n[ 172.851482] GPR12: c00000000013d390 c00000001ec54a80 0000000000000000 0000000000000000\n[ 172.851482] GPR16: 0000000000000000 0000000000000000 c000000015d5c708 c0000000025396d0\n[ 172.851482] GPR20: 0000000000000000 0000000000000000 c00000000a3bbf40 0000000000000003\n[ 172.851482] GPR24: 0000000000000000 c0000008ba097400 c0000000161e0d00 c00000000a3bb600\n[ 172.851482] GPR28: c000000015d5c700 0000000000000001 0000000082384090 c0000008ba0020d8\n[ 172.851549] NIP [c00000000013d600] power_pmu_disable+0x270/0x280\n[ 172.851557] LR [c00000000013d5a4] power_pmu_disable+0x214/0x280\n[ 172.851565] Call Trace:\n[ 172.851568] [c000000017687b00] [c00000000013d5a4] power_pmu_disable+0x214/0x280 (unreliable)\n[ 172.851579] [c000000017687b40] [c0000000003403ac] perf_pmu_disable+0x4c/0x60\n[ 172.851588] [c000000017687b60] [c0000000003445e4] __perf_event_task_sched_out+0x1d4/0x660\n[ 172.851596] [c000000017687c50] [c000000000d1175c] __schedule+0xbcc/0x12a0\n[ 172.851602] [c000000017687d60] [c000000000d11ea8] schedule+0x78/0x140\n[ 172.851608] [c000000017687d90] [c0000000001a8080] sys_sched_yield+0x20/0x40\n[ 172.851615] [c000000017687db0] [c0000000000334dc] system_call_exception+0x18c/0x380\n[ 172.851622] [c000000017687e10] [c00000000000c74c] system_call_common+0xec/0x268\n\nThe warning indicates that MSR_EE being set(interrupt enabled) when\nthere was an overflown PMC detected. This could happen in\npower_pmu_disable since it runs under interrupt soft disable\ncondition ( local_irq_save ) and not with interrupts hard disabled.\ncommit 2c9ac51b850d (\"powerpc/perf: Fix PMU callbacks to clear\npending PMI before resetting an overflown PMC\") intended to clear\nPMI pending bit in Paca when disabling the PMU. It could happen\nthat PMC gets overflown while code is in power_pmu_disable\ncallback function. Hence add a check to see if PMI pending bit\nis set in Paca before clearing it via clear_pmi_pending.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json b/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json index 9fc87ad41b4..b273f7544fb 100644 --- a/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json +++ b/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json @@ -7,12 +7,8 @@ "CVE-2022-48755" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc64/bpf: Limit 'ldbrx' to processors compliant with ISA v2.06\n\nJohan reported the below crash with test_bpf on ppc64 e5500:\n\n test_bpf: #296 ALU_END_FROM_LE 64: 0x0123456789abcdef -> 0x67452301 jited:1\n Oops: Exception in kernel mode, sig: 4 [#1]\n BE PAGE_SIZE=4K SMP NR_CPUS=24 QEMU e500\n Modules linked in: test_bpf(+)\n CPU: 0 PID: 76 Comm: insmod Not tainted 5.14.0-03771-g98c2059e008a-dirty #1\n NIP: 8000000000061c3c LR: 80000000006dea64 CTR: 8000000000061c18\n REGS: c0000000032d3420 TRAP: 0700 Not tainted (5.14.0-03771-g98c2059e008a-dirty)\n MSR: 0000000080089000 CR: 88002822 XER: 20000000 IRQMASK: 0\n <...>\n NIP [8000000000061c3c] 0x8000000000061c3c\n LR [80000000006dea64] .__run_one+0x104/0x17c [test_bpf]\n Call Trace:\n .__run_one+0x60/0x17c [test_bpf] (unreliable)\n .test_bpf_init+0x6a8/0xdc8 [test_bpf]\n .do_one_initcall+0x6c/0x28c\n .do_init_module+0x68/0x28c\n .load_module+0x2460/0x2abc\n .__do_sys_init_module+0x120/0x18c\n .system_call_exception+0x110/0x1b8\n system_call_common+0xf0/0x210\n --- interrupt: c00 at 0x101d0acc\n <...>\n ---[ end trace 47b2bf19090bb3d0 ]---\n\n Illegal instruction\n\nThe illegal instruction turned out to be 'ldbrx' emitted for\nBPF_FROM_[L|B]E, which was only introduced in ISA v2.06. Guard use of\nthe same and implement an alternative approach for older processors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json b/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json index 57c206dbb0c..deebe5a41c3 100644 --- a/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json +++ b/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json @@ -7,12 +7,8 @@ "CVE-2022-48760" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: core: Fix hang in usb_kill_urb by adding memory barriers\n\nThe syzbot fuzzer has identified a bug in which processes hang waiting\nfor usb_kill_urb() to return. It turns out the issue is not unlinking\nthe URB; that works just fine. Rather, the problem arises when the\nwakeup notification that the URB has completed is not received.\n\nThe reason is memory-access ordering on SMP systems. In outline form,\nusb_kill_urb() and __usb_hcd_giveback_urb() operating concurrently on\ndifferent CPUs perform the following actions:\n\nCPU 0\t\t\t\t\tCPU 1\n----------------------------\t\t---------------------------------\nusb_kill_urb():\t\t\t\t__usb_hcd_giveback_urb():\n ...\t\t\t\t\t ...\n atomic_inc(&urb->reject);\t\t atomic_dec(&urb->use_count);\n ...\t\t\t\t\t ...\n wait_event(usb_kill_urb_queue,\n\tatomic_read(&urb->use_count) == 0);\n\t\t\t\t\t if (atomic_read(&urb->reject))\n\t\t\t\t\t\twake_up(&usb_kill_urb_queue);\n\nConfining your attention to urb->reject and urb->use_count, you can\nsee that the overall pattern of accesses on CPU 0 is:\n\n\twrite urb->reject, then read urb->use_count;\n\nwhereas the overall pattern of accesses on CPU 1 is:\n\n\twrite urb->use_count, then read urb->reject.\n\nThis pattern is referred to in memory-model circles as SB (for \"Store\nBuffering\"), and it is well known that without suitable enforcement of\nthe desired order of accesses -- in the form of memory barriers -- it\nis entirely possible for one or both CPUs to execute their reads ahead\nof their writes. The end result will be that sometimes CPU 0 sees the\nold un-decremented value of urb->use_count while CPU 1 sees the old\nun-incremented value of urb->reject. Consequently CPU 0 ends up on\nthe wait queue and never gets woken up, leading to the observed hang\nin usb_kill_urb().\n\nThe same pattern of accesses occurs in usb_poison_urb() and the\nfailure pathway of usb_hcd_submit_urb().\n\nThe problem is fixed by adding suitable memory barriers. To provide\nproper memory-access ordering in the SB pattern, a full barrier is\nrequired on both CPUs. The atomic_inc() and atomic_dec() accesses\nthemselves don't provide any memory ordering, but since they are\npresent, we can use the optimized smp_mb__after_atomic() memory\nbarrier in the various routines to obtain the desired effect.\n\nThis patch adds the necessary memory barriers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json b/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json index 30e3a97531e..c3a0ff0c6a3 100644 --- a/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json +++ b/advisories/unreviewed/2024/06/GHSA-4p75-m8gf-m966/GHSA-4p75-m8gf-m966.json @@ -7,12 +7,8 @@ "CVE-2020-35161" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-4rhg-qwrc-fj7f/GHSA-4rhg-qwrc-fj7f.json b/advisories/unreviewed/2024/06/GHSA-4rhg-qwrc-fj7f/GHSA-4rhg-qwrc-fj7f.json index 8426f8a09e0..ea429b3f162 100644 --- a/advisories/unreviewed/2024/06/GHSA-4rhg-qwrc-fj7f/GHSA-4rhg-qwrc-fj7f.json +++ b/advisories/unreviewed/2024/06/GHSA-4rhg-qwrc-fj7f/GHSA-4rhg-qwrc-fj7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json b/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json index 49f107af8a3..167f95cd285 100644 --- a/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json +++ b/advisories/unreviewed/2024/06/GHSA-52jj-4q75-g96j/GHSA-52jj-4q75-g96j.json @@ -7,12 +7,8 @@ "CVE-2020-35156" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json b/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json index dc5d3d142fa..ac6a4c79a0b 100644 --- a/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json +++ b/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json @@ -7,12 +7,8 @@ "CVE-2022-48765" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: LAPIC: Also cancel preemption timer during SET_LAPIC\n\nThe below warning is splatting during guest reboot.\n\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 1931 at arch/x86/kvm/x86.c:10322 kvm_arch_vcpu_ioctl_run+0x874/0x880 [kvm]\n CPU: 0 PID: 1931 Comm: qemu-system-x86 Tainted: G I 5.17.0-rc1+ #5\n RIP: 0010:kvm_arch_vcpu_ioctl_run+0x874/0x880 [kvm]\n Call Trace:\n \n kvm_vcpu_ioctl+0x279/0x710 [kvm]\n __x64_sys_ioctl+0x83/0xb0\n do_syscall_64+0x3b/0xc0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7fd39797350b\n\nThis can be triggered by not exposing tsc-deadline mode and doing a reboot in\nthe guest. The lapic_shutdown() function which is called in sys_reboot path\nwill not disarm the flying timer, it just masks LVTT. lapic_shutdown() clears\nAPIC state w/ LVT_MASKED and timer-mode bit is 0, this can trigger timer-mode\nswitch between tsc-deadline and oneshot/periodic, which can result in preemption\ntimer be cancelled in apic_update_lvtt(). However, We can't depend on this when\nnot exposing tsc-deadline mode and oneshot/periodic modes emulated by preemption\ntimer. Qemu will synchronise states around reset, let's cancel preemption timer\nunder KVM_SET_LAPIC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-6jjp-xcg6-63r6/GHSA-6jjp-xcg6-63r6.json b/advisories/unreviewed/2024/06/GHSA-6jjp-xcg6-63r6/GHSA-6jjp-xcg6-63r6.json index 71ad5aefeb8..7cf46508c05 100644 --- a/advisories/unreviewed/2024/06/GHSA-6jjp-xcg6-63r6/GHSA-6jjp-xcg6-63r6.json +++ b/advisories/unreviewed/2024/06/GHSA-6jjp-xcg6-63r6/GHSA-6jjp-xcg6-63r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json b/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json index 22db3b7606e..b7a001829d2 100644 --- a/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json +++ b/advisories/unreviewed/2024/06/GHSA-75gh-r85f-8vjg/GHSA-75gh-r85f-8vjg.json @@ -7,12 +7,8 @@ "CVE-2020-35162" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json b/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json index fd7129bb99f..f2510bc6f90 100644 --- a/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json +++ b/advisories/unreviewed/2024/06/GHSA-779j-fcpp-pwc7/GHSA-779j-fcpp-pwc7.json @@ -7,12 +7,8 @@ "CVE-2020-35160" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json b/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json index 03f697afe6a..fdadd69975e 100644 --- a/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json +++ b/advisories/unreviewed/2024/06/GHSA-7ghr-qrgp-2cq4/GHSA-7ghr-qrgp-2cq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json b/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json index a86c6f3bd5b..9183fdc2fb3 100644 --- a/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json +++ b/advisories/unreviewed/2024/06/GHSA-823f-vx3m-4692/GHSA-823f-vx3m-4692.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json b/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json index abfa01a21c1..24d7f079b16 100644 --- a/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json +++ b/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json @@ -7,12 +7,8 @@ "CVE-2022-48739" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: hdmi-codec: Fix OOB memory accesses\n\nCorrect size of iec_status array by changing it to the size of status\narray of the struct snd_aes_iec958. This fixes out-of-bounds slab\nread accesses made by memcpy() of the hdmi-codec driver. This problem\nis reported by KASAN.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json b/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json index 48e0991db5b..c202b489e3b 100644 --- a/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json +++ b/advisories/unreviewed/2024/06/GHSA-8ggh-gmc9-j7xp/GHSA-8ggh-gmc9-j7xp.json @@ -7,12 +7,8 @@ "CVE-2020-35155" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json b/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json index c5952a5d06b..93893554745 100644 --- a/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json +++ b/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json @@ -7,12 +7,8 @@ "CVE-2022-48744" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Avoid field-overflowing memcpy()\n\nIn preparation for FORTIFY_SOURCE performing compile-time and run-time\nfield bounds checking for memcpy(), memmove(), and memset(), avoid\nintentionally writing across neighboring fields.\n\nUse flexible arrays instead of zero-element arrays (which look like they\nare always overflowing) and split the cross-field memcpy() into two halves\nthat can be appropriately bounds-checked by the compiler.\n\nWe were doing:\n\n\t#define ETH_HLEN 14\n\t#define VLAN_HLEN 4\n\t...\n\t#define MLX5E_XDP_MIN_INLINE (ETH_HLEN + VLAN_HLEN)\n\t...\n struct mlx5e_tx_wqe *wqe = mlx5_wq_cyc_get_wqe(wq, pi);\n\t...\n struct mlx5_wqe_eth_seg *eseg = &wqe->eth;\n struct mlx5_wqe_data_seg *dseg = wqe->data;\n\t...\n\tmemcpy(eseg->inline_hdr.start, xdptxd->data, MLX5E_XDP_MIN_INLINE);\n\ntarget is wqe->eth.inline_hdr.start (which the compiler sees as being\n2 bytes in size), but copying 18, intending to write across start\n(really vlan_tci, 2 bytes). The remaining 16 bytes get written into\nwqe->data[0], covering byte_count (4 bytes), lkey (4 bytes), and addr\n(8 bytes).\n\nstruct mlx5e_tx_wqe {\n struct mlx5_wqe_ctrl_seg ctrl; /* 0 16 */\n struct mlx5_wqe_eth_seg eth; /* 16 16 */\n struct mlx5_wqe_data_seg data[]; /* 32 0 */\n\n /* size: 32, cachelines: 1, members: 3 */\n /* last cacheline: 32 bytes */\n};\n\nstruct mlx5_wqe_eth_seg {\n u8 swp_outer_l4_offset; /* 0 1 */\n u8 swp_outer_l3_offset; /* 1 1 */\n u8 swp_inner_l4_offset; /* 2 1 */\n u8 swp_inner_l3_offset; /* 3 1 */\n u8 cs_flags; /* 4 1 */\n u8 swp_flags; /* 5 1 */\n __be16 mss; /* 6 2 */\n __be32 flow_table_metadata; /* 8 4 */\n union {\n struct {\n __be16 sz; /* 12 2 */\n u8 start[2]; /* 14 2 */\n } inline_hdr; /* 12 4 */\n struct {\n __be16 type; /* 12 2 */\n __be16 vlan_tci; /* 14 2 */\n } insert; /* 12 4 */\n __be32 trailer; /* 12 4 */\n }; /* 12 4 */\n\n /* size: 16, cachelines: 1, members: 9 */\n /* last cacheline: 16 bytes */\n};\n\nstruct mlx5_wqe_data_seg {\n __be32 byte_count; /* 0 4 */\n __be32 lkey; /* 4 4 */\n __be64 addr; /* 8 8 */\n\n /* size: 16, cachelines: 1, members: 3 */\n /* last cacheline: 16 bytes */\n};\n\nSo, split the memcpy() so the compiler can reason about the buffer\nsizes.\n\n\"pahole\" shows no size nor member offset changes to struct mlx5e_tx_wqe\nnor struct mlx5e_umr_wqe. \"objdump -d\" shows no meaningful object\ncode changes (i.e. only source line number induced differences and\noptimizations).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json b/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json index 760beba708d..d6ed208f300 100644 --- a/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json +++ b/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json b/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json index d870328a982..7f41e35d3bc 100644 --- a/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json +++ b/advisories/unreviewed/2024/06/GHSA-9mp6-9h4v-jqg2/GHSA-9mp6-9h4v-jqg2.json @@ -7,12 +7,8 @@ "CVE-2020-35158" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json b/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json index 57f0be5eeaf..73112806fca 100644 --- a/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json +++ b/advisories/unreviewed/2024/06/GHSA-c2w9-h5r4-gc47/GHSA-c2w9-h5r4-gc47.json @@ -7,12 +7,8 @@ "CVE-2022-41324" ], "details": "Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-c4p5-rq8v-r8c2/GHSA-c4p5-rq8v-r8c2.json b/advisories/unreviewed/2024/06/GHSA-c4p5-rq8v-r8c2/GHSA-c4p5-rq8v-r8c2.json index f879baab1b7..27f97979708 100644 --- a/advisories/unreviewed/2024/06/GHSA-c4p5-rq8v-r8c2/GHSA-c4p5-rq8v-r8c2.json +++ b/advisories/unreviewed/2024/06/GHSA-c4p5-rq8v-r8c2/GHSA-c4p5-rq8v-r8c2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json b/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json index 30f325188fb..2205aea0655 100644 --- a/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json +++ b/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json b/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json index 85d7d108980..167e0acb349 100644 --- a/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json +++ b/advisories/unreviewed/2024/06/GHSA-fpjq-wfvr-wx93/GHSA-fpjq-wfvr-wx93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g6g5-9p5r-64mp/GHSA-g6g5-9p5r-64mp.json b/advisories/unreviewed/2024/06/GHSA-g6g5-9p5r-64mp/GHSA-g6g5-9p5r-64mp.json index 0827433c04a..d373e630212 100644 --- a/advisories/unreviewed/2024/06/GHSA-g6g5-9p5r-64mp/GHSA-g6g5-9p5r-64mp.json +++ b/advisories/unreviewed/2024/06/GHSA-g6g5-9p5r-64mp/GHSA-g6g5-9p5r-64mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json b/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json index fc746059a2d..f9ee74d5265 100644 --- a/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json +++ b/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json @@ -7,12 +7,8 @@ "CVE-2022-48745" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Use del_timer_sync in fw reset flow of halting poll\n\nSubstitute del_timer() with del_timer_sync() in fw reset polling\ndeactivation flow, in order to prevent a race condition which occurs\nwhen del_timer() is called and timer is deactivated while another\nprocess is handling the timer interrupt. A situation that led to\nthe following call trace:\n\tRIP: 0010:run_timer_softirq+0x137/0x420\n\t\n\trecalibrate_cpu_khz+0x10/0x10\n\tktime_get+0x3e/0xa0\n\t? sched_clock_cpu+0xb/0xc0\n\t__do_softirq+0xf5/0x2ea\n\tirq_exit_rcu+0xc1/0xf0\n\tsysvec_apic_timer_interrupt+0x9e/0xc0\n\tasm_sysvec_apic_timer_interrupt+0x12/0x20\n\t", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json b/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json index 8e702c3f093..a82cf6bf5be 100644 --- a/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json +++ b/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json @@ -7,12 +7,8 @@ "CVE-2022-48771" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix stale file descriptors on failed usercopy\n\nA failing usercopy of the fence_rep object will lead to a stale entry in\nthe file descriptor table as put_unused_fd() won't release it. This\nenables userland to refer to a dangling 'file' object through that still\nvalid file descriptor, leading to all kinds of use-after-free\nexploitation scenarios.\n\nFix this by deferring the call to fd_install() until after the usercopy\nhas succeeded.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json b/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json index 8a3f71420f0..f9991d2f578 100644 --- a/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json +++ b/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json @@ -7,12 +7,8 @@ "CVE-2022-48751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: Transitional solution for clcsock race issue\n\nWe encountered a crash in smc_setsockopt() and it is caused by\naccessing smc->clcsock after clcsock was released.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000020\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 50309 Comm: nginx Kdump: loaded Tainted: G E 5.16.0-rc4+ #53\n RIP: 0010:smc_setsockopt+0x59/0x280 [smc]\n Call Trace:\n \n __sys_setsockopt+0xfc/0x190\n __x64_sys_setsockopt+0x20/0x30\n do_syscall_64+0x34/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7f16ba83918e\n \n\nThis patch tries to fix it by holding clcsock_release_lock and\nchecking whether clcsock has already been released before access.\n\nIn case that a crash of the same reason happens in smc_getsockopt()\nor smc_switch_to_fallback(), this patch also checkes smc->clcsock\nin them too. And the caller of smc_switch_to_fallback() will identify\nwhether fallback succeeds according to the return value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json b/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json index c74cd0a20b5..aea5babc91a 100644 --- a/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json +++ b/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json @@ -7,12 +7,8 @@ "CVE-2022-48746" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix handling of wrong devices during bond netevent\n\nCurrent implementation of bond netevent handler only check if\nthe handled netdev is VF representor and it missing a check if\nthe VF representor is on the same phys device of the bond handling\nthe netevent.\n\nFix by adding the missing check and optimizing the check if\nthe netdev is VF representor so it will not access uninitialized\nprivate data and crashes.\n\nBUG: kernel NULL pointer dereference, address: 000000000000036c\nPGD 0 P4D 0\nOops: 0000 [#1] SMP NOPTI\nWorkqueue: eth3bond0 bond_mii_monitor [bonding]\nRIP: 0010:mlx5e_is_uplink_rep+0xc/0x50 [mlx5_core]\nRSP: 0018:ffff88812d69fd60 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff8881cf800000 RCX: 0000000000000000\nRDX: ffff88812d69fe10 RSI: 000000000000001b RDI: ffff8881cf800880\nRBP: ffff8881cf800000 R08: 00000445cabccf2b R09: 0000000000000008\nR10: 0000000000000004 R11: 0000000000000008 R12: ffff88812d69fe10\nR13: 00000000fffffffe R14: ffff88820c0f9000 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff88846fb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000000000036c CR3: 0000000103d80006 CR4: 0000000000370ea0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n mlx5e_eswitch_uplink_rep+0x31/0x40 [mlx5_core]\n mlx5e_rep_is_lag_netdev+0x94/0xc0 [mlx5_core]\n mlx5e_rep_esw_bond_netevent+0xeb/0x3d0 [mlx5_core]\n raw_notifier_call_chain+0x41/0x60\n call_netdevice_notifiers_info+0x34/0x80\n netdev_lower_state_changed+0x4e/0xa0\n bond_mii_monitor+0x56b/0x640 [bonding]\n process_one_work+0x1b9/0x390\n worker_thread+0x4d/0x3d0\n ? rescuer_thread+0x350/0x350\n kthread+0x124/0x150\n ? set_kthread_struct+0x40/0x40\n ret_from_fork+0x1f/0x30", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-jhwr-fg7p-675f/GHSA-jhwr-fg7p-675f.json b/advisories/unreviewed/2024/06/GHSA-jhwr-fg7p-675f/GHSA-jhwr-fg7p-675f.json index a29524ecd0c..703fa2e9b55 100644 --- a/advisories/unreviewed/2024/06/GHSA-jhwr-fg7p-675f/GHSA-jhwr-fg7p-675f.json +++ b/advisories/unreviewed/2024/06/GHSA-jhwr-fg7p-675f/GHSA-jhwr-fg7p-675f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json b/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json index 13cdbf5bdb1..83f467c71ec 100644 --- a/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json +++ b/advisories/unreviewed/2024/06/GHSA-m82v-cwh2-mrvc/GHSA-m82v-cwh2-mrvc.json @@ -7,12 +7,8 @@ "CVE-2020-35157" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json b/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json index 4dd22ab672c..1fb327a3387 100644 --- a/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json +++ b/advisories/unreviewed/2024/06/GHSA-mg6v-q43w-88rw/GHSA-mg6v-q43w-88rw.json @@ -7,12 +7,8 @@ "CVE-2019-15798" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json b/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json index 5f1f44b3df6..7ef1811b748 100644 --- a/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json +++ b/advisories/unreviewed/2024/06/GHSA-p4vx-3hhc-h6c9/GHSA-p4vx-3hhc-h6c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json b/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json index 4081fd72a32..0fe08a51148 100644 --- a/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json +++ b/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json @@ -7,12 +7,8 @@ "CVE-2022-48770" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard against accessing NULL pt_regs in bpf_get_task_stack()\n\ntask_pt_regs() can return NULL on powerpc for kernel threads. This is\nthen used in __bpf_get_stack() to check for user mode, resulting in a\nkernel oops. Guard against this by checking return value of\ntask_pt_regs() before trying to obtain the call chain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json b/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json index 53a7b246b31..e550d855a0c 100644 --- a/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json +++ b/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json @@ -7,12 +7,8 @@ "CVE-2022-48759" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrpmsg: char: Fix race between the release of rpmsg_ctrldev and cdev\n\nstruct rpmsg_ctrldev contains a struct cdev. The current code frees\nthe rpmsg_ctrldev struct in rpmsg_ctrldev_release_device(), but the\ncdev is a managed object, therefore its release is not predictable\nand the rpmsg_ctrldev could be freed before the cdev is entirely\nreleased, as in the backtrace below.\n\n[ 93.625603] ODEBUG: free active (active state 0) object type: timer_list hint: delayed_work_timer_fn+0x0/0x7c\n[ 93.636115] WARNING: CPU: 0 PID: 12 at lib/debugobjects.c:488 debug_print_object+0x13c/0x1b0\n[ 93.644799] Modules linked in: veth xt_cgroup xt_MASQUERADE rfcomm algif_hash algif_skcipher af_alg uinput ip6table_nat fuse uvcvideo videobuf2_vmalloc venus_enc venus_dec videobuf2_dma_contig hci_uart btandroid btqca snd_soc_rt5682_i2c bluetooth qcom_spmi_temp_alarm snd_soc_rt5682v\n[ 93.715175] CPU: 0 PID: 12 Comm: kworker/0:1 Tainted: G B 5.4.163-lockdep #26\n[ 93.723855] Hardware name: Google Lazor (rev3 - 8) with LTE (DT)\n[ 93.730055] Workqueue: events kobject_delayed_cleanup\n[ 93.735271] pstate: 60c00009 (nZCv daif +PAN +UAO)\n[ 93.740216] pc : debug_print_object+0x13c/0x1b0\n[ 93.744890] lr : debug_print_object+0x13c/0x1b0\n[ 93.749555] sp : ffffffacf5bc7940\n[ 93.752978] x29: ffffffacf5bc7940 x28: dfffffd000000000\n[ 93.758448] x27: ffffffacdb11a800 x26: dfffffd000000000\n[ 93.763916] x25: ffffffd0734f856c x24: dfffffd000000000\n[ 93.769389] x23: 0000000000000000 x22: ffffffd0733c35b0\n[ 93.774860] x21: ffffffd0751994a0 x20: ffffffd075ec27c0\n[ 93.780338] x19: ffffffd075199100 x18: 00000000000276e0\n[ 93.785814] x17: 0000000000000000 x16: dfffffd000000000\n[ 93.791291] x15: ffffffffffffffff x14: 6e6968207473696c\n[ 93.796768] x13: 0000000000000000 x12: ffffffd075e2b000\n[ 93.802244] x11: 0000000000000001 x10: 0000000000000000\n[ 93.807723] x9 : d13400dff1921900 x8 : d13400dff1921900\n[ 93.813200] x7 : 0000000000000000 x6 : 0000000000000000\n[ 93.818676] x5 : 0000000000000080 x4 : 0000000000000000\n[ 93.824152] x3 : ffffffd0732a0fa4 x2 : 0000000000000001\n[ 93.829628] x1 : ffffffacf5bc7580 x0 : 0000000000000061\n[ 93.835104] Call trace:\n[ 93.837644] debug_print_object+0x13c/0x1b0\n[ 93.841963] __debug_check_no_obj_freed+0x25c/0x3c0\n[ 93.846987] debug_check_no_obj_freed+0x18/0x20\n[ 93.851669] slab_free_freelist_hook+0xbc/0x1e4\n[ 93.856346] kfree+0xfc/0x2f4\n[ 93.859416] rpmsg_ctrldev_release_device+0x78/0xb8\n[ 93.864445] device_release+0x84/0x168\n[ 93.868310] kobject_cleanup+0x12c/0x298\n[ 93.872356] kobject_delayed_cleanup+0x10/0x18\n[ 93.876948] process_one_work+0x578/0x92c\n[ 93.881086] worker_thread+0x804/0xcf8\n[ 93.884963] kthread+0x2a8/0x314\n[ 93.888303] ret_from_fork+0x10/0x18\n\nThe cdev_device_add/del() API was created to address this issue (see\ncommit '233ed09d7fda (\"chardev: add helper function to register char\ndevs with a struct device\")'), use it instead of cdev add/del().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-rpr4-fpwh-9vfr/GHSA-rpr4-fpwh-9vfr.json b/advisories/unreviewed/2024/06/GHSA-rpr4-fpwh-9vfr/GHSA-rpr4-fpwh-9vfr.json index 78f099c149a..6144d8ac65f 100644 --- a/advisories/unreviewed/2024/06/GHSA-rpr4-fpwh-9vfr/GHSA-rpr4-fpwh-9vfr.json +++ b/advisories/unreviewed/2024/06/GHSA-rpr4-fpwh-9vfr/GHSA-rpr4-fpwh-9vfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json b/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json index f9c90687e35..a93d64413c1 100644 --- a/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json +++ b/advisories/unreviewed/2024/06/GHSA-rqr4-mc25-2cvq/GHSA-rqr4-mc25-2cvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v247-54w9-fjrm/GHSA-v247-54w9-fjrm.json b/advisories/unreviewed/2024/06/GHSA-v247-54w9-fjrm/GHSA-v247-54w9-fjrm.json index 2bace648d22..aac34f6f0ce 100644 --- a/advisories/unreviewed/2024/06/GHSA-v247-54w9-fjrm/GHSA-v247-54w9-fjrm.json +++ b/advisories/unreviewed/2024/06/GHSA-v247-54w9-fjrm/GHSA-v247-54w9-fjrm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json b/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json index a09daf07436..d703a508a78 100644 --- a/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json +++ b/advisories/unreviewed/2024/06/GHSA-v7h7-9h84-r622/GHSA-v7h7-9h84-r622.json @@ -7,12 +7,8 @@ "CVE-2019-15797" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json b/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json index e5d97ff61b3..5ad479843a7 100644 --- a/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json +++ b/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json @@ -7,12 +7,8 @@ "CVE-2022-48757" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix information leakage in /proc/net/ptype\n\nIn one net namespace, after creating a packet socket without binding\nit to a device, users in other net namespaces can observe the new\n`packet_type` added by this packet socket by reading `/proc/net/ptype`\nfile. This is minor information leakage as packet socket is\nnamespace aware.\n\nAdd a net pointer in `packet_type` to keep the net namespace of\nof corresponding packet socket. In `ptype_seq_show`, this net pointer\nmust be checked when it is not NULL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-w5cf-hpvv-9q7v/GHSA-w5cf-hpvv-9q7v.json b/advisories/unreviewed/2024/06/GHSA-w5cf-hpvv-9q7v/GHSA-w5cf-hpvv-9q7v.json index 940e27ed213..b43c5573c08 100644 --- a/advisories/unreviewed/2024/06/GHSA-w5cf-hpvv-9q7v/GHSA-w5cf-hpvv-9q7v.json +++ b/advisories/unreviewed/2024/06/GHSA-w5cf-hpvv-9q7v/GHSA-w5cf-hpvv-9q7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json b/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json index a70b8b461e1..aa6e2da48a4 100644 --- a/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json +++ b/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json b/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json index 2a9f7dbf36d..7d28040a30d 100644 --- a/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json +++ b/advisories/unreviewed/2024/06/GHSA-wm6m-893q-83gj/GHSA-wm6m-893q-83gj.json @@ -7,12 +7,8 @@ "CVE-2020-35159" ], "details": "Rejected reason: CVE ID was once reserved, but never used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json b/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json index 30b34b0c31d..96fd4c673d8 100644 --- a/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json +++ b/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json @@ -7,12 +7,8 @@ "CVE-2022-48738" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Reject out of bounds values in snd_soc_put_volsw()\n\nWe don't currently validate that the values being set are within the range\nwe advertised to userspace as being valid, do so and reject any values\nthat are out of range.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json b/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json index 85edc8fc70e..0706ddb4eb5 100644 --- a/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json +++ b/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json @@ -7,12 +7,8 @@ "CVE-2022-48769" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: runtime: avoid EFIv2 runtime services on Apple x86 machines\n\nAditya reports [0] that his recent MacbookPro crashes in the firmware\nwhen using the variable services at runtime. The culprit appears to be a\ncall to QueryVariableInfo(), which we did not use to call on Apple x86\nmachines in the past as they only upgraded from EFI v1.10 to EFI v2.40\nfirmware fairly recently, and QueryVariableInfo() (along with\nUpdateCapsule() et al) was added in EFI v2.00.\n\nThe only runtime service introduced in EFI v2.00 that we actually use in\nLinux is QueryVariableInfo(), as the capsule based ones are optional,\ngenerally not used at runtime (all the LVFS/fwupd firmware update\ninfrastructure uses helper EFI programs that invoke capsule update at\nboot time, not runtime), and not implemented by Apple machines in the\nfirst place. QueryVariableInfo() is used to 'safely' set variables,\ni.e., only when there is enough space. This prevents machines with buggy\nfirmwares from corrupting their NVRAMs when they run out of space.\n\nGiven that Apple machines have been using EFI v1.10 services only for\nthe longest time (the EFI v2.0 spec was released in 2006, and Linux\nsupport for the newly introduced runtime services was added in 2011, but\nthe MacbookPro12,1 released in 2015 still claims to be EFI v1.10 only),\nlet's avoid the EFI v2.0 ones on all Apple x86 machines.\n\n[0] https://lore.kernel.org/all/6D757C75-65B1-468B-842D-10410081A8E4@live.com/", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null,