diff --git a/advisories/github-reviewed/2018/07/GHSA-6xhf-x49c-m5m6/GHSA-6xhf-x49c-m5m6.json b/advisories/github-reviewed/2018/07/GHSA-6xhf-x49c-m5m6/GHSA-6xhf-x49c-m5m6.json index 20a355cf754..235951f9a64 100644 --- a/advisories/github-reviewed/2018/07/GHSA-6xhf-x49c-m5m6/GHSA-6xhf-x49c-m5m6.json +++ b/advisories/github-reviewed/2018/07/GHSA-6xhf-x49c-m5m6/GHSA-6xhf-x49c-m5m6.json @@ -8,9 +8,7 @@ ], "summary": "Github Token Leak in aegir", "details": "Affected versions of `aegir` bundle and publish the current users github token to npm when `aegir-release` is executed.\n\n\n## Recommendation\n\nUpdate to version 12.0.8 or later.\n\nIf you used this module to do a release for your project you should invalidate the GitHub tokens that were leaked.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-6cw8-7j6c-hccp/GHSA-6cw8-7j6c-hccp.json b/advisories/github-reviewed/2018/10/GHSA-6cw8-7j6c-hccp/GHSA-6cw8-7j6c-hccp.json index 0d8a4cc8ef4..41da559e31a 100644 --- a/advisories/github-reviewed/2018/10/GHSA-6cw8-7j6c-hccp/GHSA-6cw8-7j6c-hccp.json +++ b/advisories/github-reviewed/2018/10/GHSA-6cw8-7j6c-hccp/GHSA-6cw8-7j6c-hccp.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects io.vertx:vertx-core", "details": "In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-7378-6268-4278/GHSA-7378-6268-4278.json b/advisories/github-reviewed/2018/10/GHSA-7378-6268-4278/GHSA-7378-6268-4278.json index 793856bacc1..50f28966e46 100644 --- a/advisories/github-reviewed/2018/10/GHSA-7378-6268-4278/GHSA-7378-6268-4278.json +++ b/advisories/github-reviewed/2018/10/GHSA-7378-6268-4278/GHSA-7378-6268-4278.json @@ -8,9 +8,7 @@ ], "summary": "High severity vulnerability that affects DotNetZip", "details": "DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-73cq-fhp3-8rpw/GHSA-73cq-fhp3-8rpw.json b/advisories/github-reviewed/2018/10/GHSA-73cq-fhp3-8rpw/GHSA-73cq-fhp3-8rpw.json index 47f5ae881ce..ae79956ccb8 100644 --- a/advisories/github-reviewed/2018/10/GHSA-73cq-fhp3-8rpw/GHSA-73cq-fhp3-8rpw.json +++ b/advisories/github-reviewed/2018/10/GHSA-73cq-fhp3-8rpw/GHSA-73cq-fhp3-8rpw.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects org.restlet.jse:org.restlet", "details": "Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-6fvw-7vch-x489/GHSA-6fvw-7vch-x489.json b/advisories/github-reviewed/2019/02/GHSA-6fvw-7vch-x489/GHSA-6fvw-7vch-x489.json index fe381ea74ab..c03c416661e 100644 --- a/advisories/github-reviewed/2019/02/GHSA-6fvw-7vch-x489/GHSA-6fvw-7vch-x489.json +++ b/advisories/github-reviewed/2019/02/GHSA-6fvw-7vch-x489/GHSA-6fvw-7vch-x489.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in selenium-portal", "details": "Affected versions of `selenium-portal` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `selenium-portal`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package has not seen an update since 2014.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-6jx3-rqcx-g3ww/GHSA-6jx3-rqcx-g3ww.json b/advisories/github-reviewed/2019/02/GHSA-6jx3-rqcx-g3ww/GHSA-6jx3-rqcx-g3ww.json index 04e33996494..877ecd98bd0 100644 --- a/advisories/github-reviewed/2019/02/GHSA-6jx3-rqcx-g3ww/GHSA-6jx3-rqcx-g3ww.json +++ b/advisories/github-reviewed/2019/02/GHSA-6jx3-rqcx-g3ww/GHSA-6jx3-rqcx-g3ww.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in air-sdk", "details": "Affected versions of `air-sdk` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `air-sdk`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package hasn't seen an update since 2015.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-6p48-xfj3-jw67/GHSA-6p48-xfj3-jw67.json b/advisories/github-reviewed/2019/02/GHSA-6p48-xfj3-jw67/GHSA-6p48-xfj3-jw67.json index c5be8fc4fb8..50e806eec1a 100644 --- a/advisories/github-reviewed/2019/02/GHSA-6p48-xfj3-jw67/GHSA-6p48-xfj3-jw67.json +++ b/advisories/github-reviewed/2019/02/GHSA-6p48-xfj3-jw67/GHSA-6p48-xfj3-jw67.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in fibjs", "details": "Affected versions of `fibjs` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `fibjs`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-6pwf-whc8-hjf6/GHSA-6pwf-whc8-hjf6.json b/advisories/github-reviewed/2019/02/GHSA-6pwf-whc8-hjf6/GHSA-6pwf-whc8-hjf6.json index ce4f9d5f756..a3f3263606e 100644 --- a/advisories/github-reviewed/2019/02/GHSA-6pwf-whc8-hjf6/GHSA-6pwf-whc8-hjf6.json +++ b/advisories/github-reviewed/2019/02/GHSA-6pwf-whc8-hjf6/GHSA-6pwf-whc8-hjf6.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in baryton-saxophone", "details": "Affected versions of `baryton-saxophone` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `baryton-saxophone`.\n\n\n## Recommendation\n\nUpdate to version 3.0.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-722q-3g9x-vp8q/GHSA-722q-3g9x-vp8q.json b/advisories/github-reviewed/2019/02/GHSA-722q-3g9x-vp8q/GHSA-722q-3g9x-vp8q.json index d623e0b5948..95533353ed2 100644 --- a/advisories/github-reviewed/2019/02/GHSA-722q-3g9x-vp8q/GHSA-722q-3g9x-vp8q.json +++ b/advisories/github-reviewed/2019/02/GHSA-722q-3g9x-vp8q/GHSA-722q-3g9x-vp8q.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in tomita-parser", "details": "Affected versions of `tomita-parser` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `tomita-parser`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and the package has not seen an update since 2015.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-735c-r4vc-6gm9/GHSA-735c-r4vc-6gm9.json b/advisories/github-reviewed/2019/02/GHSA-735c-r4vc-6gm9/GHSA-735c-r4vc-6gm9.json index ab722d2ad7a..919d8aff073 100644 --- a/advisories/github-reviewed/2019/02/GHSA-735c-r4vc-6gm9/GHSA-735c-r4vc-6gm9.json +++ b/advisories/github-reviewed/2019/02/GHSA-735c-r4vc-6gm9/GHSA-735c-r4vc-6gm9.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in bionode-sra", "details": "Affected versions of `bionode-sra` insecurely downloads resources over HTTP. \n\nIn scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. The author of this package has suggested using [urllib-sync](https://www.npmjs.com/package/urllib-sync).\n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json b/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json index 206786e3f8b..bfc2b53c8f8 100644 --- a/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json +++ b/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json @@ -3,9 +3,7 @@ "id": "GHSA-6jg8-7333-554w", "modified": "2021-09-02T16:40:48Z", "published": "2019-10-04T17:56:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout in realms-shim", "details": "Versions of `realms-shim` prior to 1.2.0 are vulnerable to a Sandbox Breakout. `Reflect.construct` can be used on the sandboxed Function constructor to reach the prototypes of the primal Realm, which may allow an attacker to escape the sandbox and execute arbitrary code.\n\n\n## Recommendation\n\nUpgrade to version 1.2.0 or later.", "severity": [ @@ -93,9 +91,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:19:30Z", diff --git a/advisories/github-reviewed/2023/07/GHSA-58qw-p7qm-5rvh/GHSA-58qw-p7qm-5rvh.json b/advisories/github-reviewed/2023/07/GHSA-58qw-p7qm-5rvh/GHSA-58qw-p7qm-5rvh.json index 97da429b604..b7b8fb85fff 100644 --- a/advisories/github-reviewed/2023/07/GHSA-58qw-p7qm-5rvh/GHSA-58qw-p7qm-5rvh.json +++ b/advisories/github-reviewed/2023/07/GHSA-58qw-p7qm-5rvh/GHSA-58qw-p7qm-5rvh.json @@ -3,9 +3,7 @@ "id": "GHSA-58qw-p7qm-5rvh", "modified": "2024-09-10T17:16:50Z", "published": "2023-07-10T21:52:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations", "details": "### From the reporter\n\n> `XmlParser` is vulnerable to XML external entity (XXE) vulnerability.\n> XmlParser is being used when parsing Jetty’s xml configuration files. An attacker might exploit\n> this vulnerability in order to achieve SSRF or cause a denial of service.\n> One possible scenario is importing a (remote) malicious WAR into a Jetty’s server, while the\n> WAR includes a malicious web.xml.\n\n### Impact\nThere are no circumstances in a normally deployed Jetty server where potentially hostile XML is given to the XmlParser class without the attacker already having arbitrary access to the server. I.e. in order to exploit `XmlParser` the attacker would already have the ability to deploy and execute hostile code. Specifically, Jetty has no protection against malicious web application and potentially hostile web applications should only be run on an isolated virtualisation. \n\nThus this is not considered a vulnerability of the Jetty server itself, as any such usage of the jetty XmlParser is equally vulnerable as a direct usage of the JVM supplied SAX parser. No CVE will be allocated to this advisory.\n\nHowever, any direct usage of the `XmlParser` class by an application may be vulnerable. The impact would greatly depend on how the application uses `XmlParser`, but it could be a denial of service due to large entity expansion, or possibly the revealing local files if the XML results are accessible remotely.\n\n### Patches\nAbility to configure the SAXParserFactory to fit the needs of your particular XML parser implementation have been merged as part of PR #10067\n\n### Workarounds\nDon't use `XmlParser` to parse data from users.\n\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json b/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json index f9f957db008..5bad5526f04 100644 --- a/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json +++ b/advisories/github-reviewed/2024/04/GHSA-4v52-7q2x-v4xj/GHSA-4v52-7q2x-v4xj.json @@ -3,9 +3,7 @@ "id": "GHSA-4v52-7q2x-v4xj", "modified": "2024-04-05T15:08:53Z", "published": "2024-04-05T15:08:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "eyre: Parts of Report are dropped as the wrong type during downcast", "details": "In affected versions, after a `Report` is constructed using `wrap_err` or `wrap_err_with` to attach a message of type `D` onto an error of type `E`, then using `downcast` to recover ownership of either the value of type `D` or the value of type `E`, one of two things can go wrong:\n\n- If downcasting to `E`, there remains a value of type `D` to be dropped. It is incorrectly \"dropped\" by running `E`'s drop behavior, rather than `D`'s. For example if `D` is `&str` and `E` is `std::io::Error`, there would be a call of `std::io::Error::drop` in which the reference received by the `Drop` impl does not refer to a valid value of type `std::io::Error`, but instead to `&str`.\n\n- If downcasting to `D`, there remains a value of type `E` to be dropped. When `D` and `E` do not happen to be the same size, `E`'s drop behavior is incorrectly executed in the wrong location. The reference received by the `Drop` impl may point left or right of the real `E` value that is meant to be getting dropped.\n\nIn both cases, when the `Report` contains an error `E` that has nontrivial drop behavior, the most likely outcome is memory corruption.\n\nWhen the `Report` contains an error `E` that has trivial drop behavior (for example a `Utf8Error`) but where `D` has nontrivial drop behavior (such as `String`), the most likely outcome is that downcasting to `E` would leak `D`.", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json b/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json index 9eb1481665a..ef3fc0bc2b5 100644 --- a/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json +++ b/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json @@ -3,9 +3,7 @@ "id": "GHSA-5gmm-6m36-r7jh", "modified": "2024-04-05T15:41:34Z", "published": "2024-04-05T15:41:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "transpose: Buffer overflow due to integer overflow", "details": "Given the function `transpose::transpose`:\n```rust\nfn transpose(input: &[T], output: &mut [T], input_width: usize, input_height: usize)\n```\n\nThe safety check `input_width * input_height == output.len()` can fail due to `input_width * input_height` overflowing in such a way that it equals `output.len()`.\nAs a result of failing the safety check, memory past the end of `output` is written to. This only occurs in release mode since `*` panics on overflow in debug mode.\n\nExploiting this issue requires the caller to pass `input_width` and `input_height` arguments such that multiplying them overflows, and the overflown result equals the lengths of input and output slices.\n", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json b/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json index e3bd29f2cc3..7e189967ff1 100644 --- a/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json +++ b/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json @@ -4,9 +4,7 @@ "modified": "2024-06-05T17:11:58Z", "published": "2024-04-06T06:31:08Z", "withdrawn": "2024-06-05T17:11:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "PyMongo Out-of-bounds Read in the bson module ", "details": "Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.\n\nThis advisory was initially published as CVE-2024-21506, which has since been rejected as a duplicate of CVE-2024-5629.", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json b/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json index e91e39b284a..9ddf4751569 100644 --- a/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json +++ b/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json @@ -3,9 +3,7 @@ "id": "GHSA-j496-crgh-34mx", "modified": "2024-04-05T17:16:01Z", "published": "2024-04-05T17:16:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooks", "details": "**Name**: ASA-2024-007: Potential Reentrancy using Timeout Callbacks in ibc-hooks\n**Component**: ibc-go\n**Criticality**: Critical ([ACMv1](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md): I:Critical; L:AlmostCertain)\n**Affected versions**: < v4.6.0, < v5.4.0, < v6.3.0, < v7.4.0, < v8.2.0\n**Affected users**: Chain Builders + Maintainers\n\n# Summary\n\nThrough the deployment and subsequent use of a malicious CosmWasm contract via IBC interactions, an attacker could potentially execute the same `MsgTimeout` inside the IBC hook for the `OnTimeout` callback before the packet commitment is deleted. On chains where ibc-hooks wraps ICS-20, this vulnerability may allow for the logic of the `OnTimeout` callback of the transfer application to be recursively executed, leading to a condition that may present the opportunity for the loss of funds from the escrow account or unexpected minting of tokens.\n\n# Affected Configurations\n\nChains which satisfy all of the following requirements are considered to be impacted by this vulnerability:\n* Chain is IBC-enabled and uses a vulnerable version of ibc-go\n* Chain is CosmWasm-enabled and allows code uploads for wasm contracts by anyone, or by authorized parties (to a lesser extent)\n* Chain utilizes the ibc-hooks middleware and wraps ICS-20 transfer application\n\n# Next Steps for Impacted Chain Builders and Maintainers\n\nIt is advised to immediately upgrade to the latest patch fix version of ibc-go for your chain. If you have already applied a soft-patch through private coordination, we recommend additionally updating to the latest ibc-go version via normal software upgrade governance.\n\nIf you have not upgraded your chain yet, and you desire to mitigate exposure to this vulnerability in the meantime, it is advisable to limit code uploading for contracts to trusted parties on your chain.\n\n**If your chain only allows permissioned, access-controlled contract uploads, it is still strongly recommended to update to the latest patched ibc-go version for your chain per your normal software upgrade process.**\n\n# Preparing for future coordination\n\nIf your chain would like to be included in future coordination efforts, please ensure your chain has a prominently displayed or otherwise easily available up-to-date email address for technical security contact available. A security.md file in the root of your projects’ code repository should contain this information. Additionally, please test this security contact with an unaffiliated email to ensure it works as expected and can receive emails from outside of your domain.\n\nTo ensure that your chain is included in future impact assessments, please keep your chain information up to date in the [Cosmos Chain Registry](https://github.com/cosmos/chain-registry) with code location, network name, and public RPC and API endpoints in the details.\n\nWe recommend that all chains configure and practice the use of the [Circuit Breaker module](https://docs.cosmos.network/main/build/modules/circuit) in the Cosmos SDK, as future vulnerability notifications may require the use of this mechanism as a mitigation against exploitation.\n\n# Recognition\n\nThis issue was reported to the Cosmos Bug Bounty Program on HackerOne on 3/26/24 by Maxwell Dulin (Strikeout) at [Asymmetric Research](https://www.asymmetric.re/). If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\n# Notes\n\nDue to the critical nature of this issue, both the ibc-go team and Amulet independently performed impact assessments for the ecosystem, which informed a risk-driven private patching effort that preceded this public release. This private patching effort significantly reduced the exposure of the ecosystem to this vulnerability. We appreciate the diligence and professionalism of all chains and validators involved with this effort – your ability to move quickly while maintaining confidentiality was instrumental in protecting the wider Interchain Ecosystem. \n\nIf you ever have questions about security coordination efforts, public or private, please reach out to our official communication channel at [security@interchain.io](mailto:security@interchain.io).\n\nFor more information about ibc-go, please see https://ibc.cosmos.network/main.\n\nFor more information about the Interchain Foundation’s engagement with Amulet, please see https://github.com/interchainio/security.\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json b/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json index c84112d12a8..f9d3c821c52 100644 --- a/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json +++ b/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json @@ -3,9 +3,7 @@ "id": "GHSA-mc39-h54g-pvw6", "modified": "2024-04-05T15:42:39Z", "published": "2024-04-05T15:42:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "libdav1d-sys affected by dav1d AV1 decoder integer overflow", "details": "An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading to version 0.7.0 of libdav1d-sys, which includes dav1d 1.4.0.\n", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json b/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json index 2f3543ed255..7576ca987cd 100644 --- a/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json +++ b/advisories/github-reviewed/2024/04/GHSA-w7hm-hmxv-pvhf/GHSA-w7hm-hmxv-pvhf.json @@ -3,9 +3,7 @@ "id": "GHSA-w7hm-hmxv-pvhf", "modified": "2024-04-05T15:06:27Z", "published": "2024-04-05T15:06:27Z", - "aliases": [ - - ], + "aliases": [], "summary": "HPACK decoder panics on invalid input", "details": "Due to insufficient checking of input data, decoding certain data sequences can lead to _Decoder::decode_ panicking rather than returning an error.\n\nExample code that triggers this vulnerability looks like this:\n\n```rust\nuse hpack::Decoder;\n\npub fn main() {\n let input = &[0x3f];\n let mut decoder = Decoder::new();\n let _ = decoder.decode(input);\n}\n```\n\nhpack is unmaintained. A crate with the panics fixed has been published as [hpack-patched](https://crates.io/crates/hpack-patched).\n\nAlso consider using [fluke-hpack](https://crates.io/crates/fluke-hpack) or [httlib-huffman](https://crates.io/crates/httlib-huffman) as an alternative.", "severity": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json b/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json index c000ef289b1..bdc9374b9e7 100644 --- a/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json +++ b/advisories/github-reviewed/2024/04/GHSA-xfhw-6mc4-mgxf/GHSA-xfhw-6mc4-mgxf.json @@ -3,9 +3,7 @@ "id": "GHSA-xfhw-6mc4-mgxf", "modified": "2024-04-05T15:40:40Z", "published": "2024-04-05T15:40:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "crayon: ObjectPool creates uninitialized memory when freeing objects", "details": "As of version 0.6.0, the ObjectPool explicitly creates an uninitialized instance of its type parameter when it attempts to free an object, and swaps it into the storage. This causes instant undefined behavior due to reading the uninitialized memory in order to write it to the pool storage.\n\nExtremely basic usage of the crate can trigger this issue, e.g. this code from a doctest:\n\n```rust\nuse crayon::prelude::*;\napplication::oneshot().unwrap();\n\nlet mut params = MeshParams::default();\n\nlet mesh = video::create_mesh(params, None).unwrap();\n\n// Deletes the mesh object.\nvideo::delete_mesh(mesh); // <-- UB\n```\n\nThe Clippy warning for this code was silenced in commit c2fde19caf6149d91faa504263f0bc5cafc35de5.\n\nDiscovered via https://asan.saethlin.dev/ub?crate=crayon&version=0.7.1\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-3c5g-73f7-grvm/GHSA-3c5g-73f7-grvm.json b/advisories/github-reviewed/2024/05/GHSA-3c5g-73f7-grvm/GHSA-3c5g-73f7-grvm.json index 55df10c214f..d4ffcbdc10b 100644 --- a/advisories/github-reviewed/2024/05/GHSA-3c5g-73f7-grvm/GHSA-3c5g-73f7-grvm.json +++ b/advisories/github-reviewed/2024/05/GHSA-3c5g-73f7-grvm/GHSA-3c5g-73f7-grvm.json @@ -3,9 +3,7 @@ "id": "GHSA-3c5g-73f7-grvm", "modified": "2024-05-17T22:54:47Z", "published": "2024-05-17T22:54:47Z", - "aliases": [ - - ], + "aliases": [], "summary": "Neos Information Disclosure Security Note", "details": "Due to reports it has been validated that internal workspaces in Neos are accessible without authentication. Some users assumed this is a planned feature but it is not. A workspace preview should be an additional feature with respective security measures in place.\n\nNote that this only allows reading of internal workspaces not writing. And for clarification, an internal workspace is a workspace that is non public and doesn't have an owner.\n\nGiven that an internal workspace exists in your installation, it is possible to view a page in context of that workspace by opening a link in this format:\n\nhttps://domain/path/to/page.html@workspace-name\n\nThe issue is quite problematic when exploited but at the same time slightly less impactful than it sounds. First of all there is no default internal workspace, so the issue affects only workspaces created by users. That also means the workspace-name, which will also always include a hash is individual to a project and an exploiter must get hold of the workspace-name including the hash. This is non trivial as there is no indication of the existence of it, but obviously brute force and educated guessed can be made.", "severity": [ @@ -183,9 +181,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-17T22:54:47Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-3fmq-x9q6-wm39/GHSA-3fmq-x9q6-wm39.json b/advisories/github-reviewed/2024/05/GHSA-3fmq-x9q6-wm39/GHSA-3fmq-x9q6-wm39.json index 57e4aeeb24c..614b0365b4a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-3fmq-x9q6-wm39/GHSA-3fmq-x9q6-wm39.json +++ b/advisories/github-reviewed/2024/05/GHSA-3fmq-x9q6-wm39/GHSA-3fmq-x9q6-wm39.json @@ -3,14 +3,10 @@ "id": "GHSA-3fmq-x9q6-wm39", "modified": "2024-05-17T23:27:19Z", "published": "2024-05-17T23:27:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "random_compat Uses insecure CSPRNG", "details": "random_compat versions prior to 2.0 are affected by a security vulnerability related to the insecure usage of Cryptographically Secure Pseudo-Random Number Generators (CSPRNG). The affected versions use openssl_random_pseudo_bytes(), which may result in insufficient entropy and compromise the security of generated random numbers.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/05/GHSA-43cf-7f3h-38rg/GHSA-43cf-7f3h-38rg.json b/advisories/github-reviewed/2024/05/GHSA-43cf-7f3h-38rg/GHSA-43cf-7f3h-38rg.json index 18d79bcfd1d..66ccb233af6 100644 --- a/advisories/github-reviewed/2024/05/GHSA-43cf-7f3h-38rg/GHSA-43cf-7f3h-38rg.json +++ b/advisories/github-reviewed/2024/05/GHSA-43cf-7f3h-38rg/GHSA-43cf-7f3h-38rg.json @@ -3,9 +3,7 @@ "id": "GHSA-43cf-7f3h-38rg", "modified": "2024-05-17T23:03:46Z", "published": "2024-05-17T23:03:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Privilege Escalation in TYPO3 Neos", "details": "It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation. Logged in editors could access, create and modify content nodes that exist in the workspace of other editors.", "severity": [ @@ -69,9 +67,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-17T23:03:46Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-4rr6-gf59-ggw5/GHSA-4rr6-gf59-ggw5.json b/advisories/github-reviewed/2024/05/GHSA-4rr6-gf59-ggw5/GHSA-4rr6-gf59-ggw5.json index d8cabe2c1fa..0366c66936f 100644 --- a/advisories/github-reviewed/2024/05/GHSA-4rr6-gf59-ggw5/GHSA-4rr6-gf59-ggw5.json +++ b/advisories/github-reviewed/2024/05/GHSA-4rr6-gf59-ggw5/GHSA-4rr6-gf59-ggw5.json @@ -3,14 +3,10 @@ "id": "GHSA-4rr6-gf59-ggw5", "modified": "2024-05-17T22:31:44Z", "published": "2024-05-17T22:31:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "namshi/jose - Verification bypass", "details": "Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-17T22:31:44Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-5vv7-j593-mgjc/GHSA-5vv7-j593-mgjc.json b/advisories/github-reviewed/2024/05/GHSA-5vv7-j593-mgjc/GHSA-5vv7-j593-mgjc.json index c4024cafeec..0ff5a3b2a45 100644 --- a/advisories/github-reviewed/2024/05/GHSA-5vv7-j593-mgjc/GHSA-5vv7-j593-mgjc.json +++ b/advisories/github-reviewed/2024/05/GHSA-5vv7-j593-mgjc/GHSA-5vv7-j593-mgjc.json @@ -3,14 +3,10 @@ "id": "GHSA-5vv7-j593-mgjc", "modified": "2024-05-17T22:54:43Z", "published": "2024-05-17T22:54:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Neos Flow Arbitrary file upload and XML External Entity processing", "details": "It has been discovered that Flow 3.0.0 allows arbitrary file uploads, inlcuding server-side scripts, posing the risk of attacks. If those scripts are executed by the server when accessed through their public URL, anything not blocked through other means is possible (information disclosure, placement of backdoors, data removal, …).\n\nNote: The upload of files is only possible if the application built on Flow provides means to do so, and whether or not the upload of files poses a risk is dependent on the system setup. If uploaded script files are not executed by the server, there is no risk. In versions prior to 3.0.0 the upload of files with the extension php was blocked.\n\nIn Flow 2.3.0 to 2.3.6 a potential XML External Entity processing vulnerability has been discovered in the MediaTypeConverter.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -66,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-17T22:54:42Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-6cj3-rc4p-f38f/GHSA-6cj3-rc4p-f38f.json b/advisories/github-reviewed/2024/05/GHSA-6cj3-rc4p-f38f/GHSA-6cj3-rc4p-f38f.json index 476a957ca0e..085b6133bb0 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6cj3-rc4p-f38f/GHSA-6cj3-rc4p-f38f.json +++ b/advisories/github-reviewed/2024/05/GHSA-6cj3-rc4p-f38f/GHSA-6cj3-rc4p-f38f.json @@ -3,14 +3,10 @@ "id": "GHSA-6cj3-rc4p-f38f", "modified": "2024-05-17T23:04:02Z", "published": "2024-05-17T23:04:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "Cross-site Scripting vulnerabilities in Neos", "details": "It has been discovered that Neos is vulnerable to several XSS attacks. Through these vulnerabilities, an attacker could tamper with page rendering, redirect victims to a fake login page, or capture user credentials (such as cookies). With the potential backdoor upload an attacker could gain access to the server itself, to an extent mainly limited by the server setup.\n\n### Reflected Cross-Site Scripting (SXSS) with authentication\nA Neos backend user with permission to modify content can insert JavaScript instructions into content elements. The browser will execute the script in \"Print\" preview mode.\nA Neos backend user who can modify his profile information (\"Title\", \"First Name\", \"Last name\", \"Middle Name\", \"Other Name\") can inject JavaScript instructions in those parameters. Once set up, an administrator who wants to edit this user account will execute the code.\nBoth attack vectors require a valid Neos backend user account.\n\n### Reflected Cross-Site Scripting (RXSS) without authentication\nA non-persistent XSS using parameters passed during plugin execution is possible. If invalid parameters are passed, an error message may be shown (depending on the context Neos runs in and how the parameters are handled) that contains the unescaped parameter value.\n\nNote: Through the HTML content type the inclusion of arbitrary JavaScript is still possible for users with a valid Neos backend account. If you want to prohibit that, disable the nodetype or restrict access.\n\n### Potential backdoor upload\nThrough an issue with the underlying Flow framework (see the related Flow advisory Flow-SA-2015-001) any editor with access to the Media Management module can upload server side script files (when using Neos 2.0.x). If those scripts are executed by the server when accessed through their public URL, anything not blocked through other means is possible (information disclosure, placement of backdoors, data removal, …).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/05/GHSA-6pq8-67pw-j6hw/GHSA-6pq8-67pw-j6hw.json b/advisories/github-reviewed/2024/05/GHSA-6pq8-67pw-j6hw/GHSA-6pq8-67pw-j6hw.json index c62f5d142b5..44df3d7219d 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6pq8-67pw-j6hw/GHSA-6pq8-67pw-j6hw.json +++ b/advisories/github-reviewed/2024/05/GHSA-6pq8-67pw-j6hw/GHSA-6pq8-67pw-j6hw.json @@ -3,9 +3,7 @@ "id": "GHSA-6pq8-67pw-j6hw", "modified": "2024-05-17T23:03:25Z", "published": "2024-05-17T23:03:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Time-Based Information Disclosure Vulnerability in Flow", "details": "The PersistedUsernamePasswordProvider was prone to a information disclosure of account existance based on timing attacks as the hashing of passwords was only done in case an account was found. We changed the core so that the provider always does a password comparison in case credentials were submitted at all.\n\n", "severity": [ @@ -126,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-17T23:03:25Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-7h74-7vcw-4mwp/GHSA-7h74-7vcw-4mwp.json b/advisories/github-reviewed/2024/05/GHSA-7h74-7vcw-4mwp/GHSA-7h74-7vcw-4mwp.json index b1040a9689a..86bfc65615a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-7h74-7vcw-4mwp/GHSA-7h74-7vcw-4mwp.json +++ b/advisories/github-reviewed/2024/05/GHSA-7h74-7vcw-4mwp/GHSA-7h74-7vcw-4mwp.json @@ -3,9 +3,7 @@ "id": "GHSA-7h74-7vcw-4mwp", "modified": "2024-05-17T22:32:12Z", "published": "2024-05-17T22:32:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "Insecure deserialize Vulnerability in FLOW3", "details": "Due to a missing signature (HMAC) for a request argument, an attacker could unserialize arbitrary objects within FLOW3.\n\nTo our knowledge it is neither possible to inject code through this vulnerability, nor are there exploitable objects within the FLOW3 Base Distribution. However, there might be exploitable objects within user applications.", "severity": [ @@ -50,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-05-17T22:32:12Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-9cw3-j7wg-jwj8/GHSA-9cw3-j7wg-jwj8.json b/advisories/github-reviewed/2024/05/GHSA-9cw3-j7wg-jwj8/GHSA-9cw3-j7wg-jwj8.json index ce1ed68e3b0..c8d6d7ff3cc 100644 --- a/advisories/github-reviewed/2024/05/GHSA-9cw3-j7wg-jwj8/GHSA-9cw3-j7wg-jwj8.json +++ b/advisories/github-reviewed/2024/05/GHSA-9cw3-j7wg-jwj8/GHSA-9cw3-j7wg-jwj8.json @@ -3,9 +3,7 @@ "id": "GHSA-9cw3-j7wg-jwj8", "modified": "2024-05-17T22:54:45Z", "published": "2024-05-17T22:54:45Z", - "aliases": [ - - ], + "aliases": [], "summary": "Neos Flow Information disclosure in entity security", "details": "If you had used entity security and wanted to secure entities not just based on the user's role, but on some property of the user (like the company he belongs to), entity security did not work properly together with the doctrine query cache. This could lead to other users re-using SQL queries from the cache which were built for other users; and thus users could see entities which were not destined for them.\n\n### Am I affected?\n\n- Do you use Entity Security? if no, you are not affected.\n- You disabled the Doctrine Cache (Flow_Persistence_Doctrine)? If this is the case, you are not affected.\n- You use Entity Security in custom Flow or Neos applications. Read on.\n - If you only used Entity Security based on roles (i.e. role A was allowed to see entities, but role B was denied): In this case, you are not affected.\n - If you did more advanced stuff using Entity Security (like checking that a customer only sees his own orders; or a hotel only sees its own bookings), you very likely needed to register a custom global object in Neos.Flow.aop.globalObjects. In this case, you are affected by the issue; and need to implement the CacheAwareInterface in your global object for proper caching.\n\nAll Flow versions (starting in version 3.0, where Entity Security was introduced) were affected.", "severity": [ @@ -126,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-17T22:54:45Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-9wrw-p9rm-r782/GHSA-9wrw-p9rm-r782.json b/advisories/github-reviewed/2024/05/GHSA-9wrw-p9rm-r782/GHSA-9wrw-p9rm-r782.json index f601e2a2d1a..3709dc674a4 100644 --- a/advisories/github-reviewed/2024/05/GHSA-9wrw-p9rm-r782/GHSA-9wrw-p9rm-r782.json +++ b/advisories/github-reviewed/2024/05/GHSA-9wrw-p9rm-r782/GHSA-9wrw-p9rm-r782.json @@ -3,14 +3,10 @@ "id": "GHSA-9wrw-p9rm-r782", "modified": "2024-05-17T23:06:54Z", "published": "2024-05-17T23:06:54Z", - "aliases": [ - - ], + "aliases": [], "summary": "onelogin/php-saml Improper signature validation on LogoutRequest/LogoutResponse.", "details": "In order to verify Signatures on Logoutrequests and LogoutResponses we use\nthe verifySignature of the class XMLSecurityKey from the xmlseclibs library.\nThat method end up calling openssl_verify() depending on the signature algorithm used.\n\nThe openssl_verify() function returns 1 when the signature was successfully verified,\n0 if it failed to verify with the given key, and -1 in case an error occurs.\nPHP allows translating numerical values to boolean implicitly, with the following correspondences:\n- 0 equals false.\n- Non-zero equals true.\n\nThis means that an implicit conversion to boolean of the values returned by openssl_verify()\nwill convert an error state, signaled by the value -1, to a successful verification of the\nsignature (represented by the boolean true).\n\nThe LogoutRequest/LogoutResponse signature validator was performing an implicit conversion to boolean\nof the values returned by the verify() method, which subsequently will return the same output\nas openssl_verify() under most circumstances.\nThis means an error during signature verification is treated as a successful verification by the method.\n\nSince the signature validation of SAMLResponses were not affected, the impact of this security\nvulnerability is lower, but an update of the php-saml toolkit is recommended.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-05-17T23:06:54Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-g48f-pgwh-wwxx/GHSA-g48f-pgwh-wwxx.json b/advisories/github-reviewed/2024/05/GHSA-g48f-pgwh-wwxx/GHSA-g48f-pgwh-wwxx.json index 0d7e43b2dc7..8207c8c20d4 100644 --- a/advisories/github-reviewed/2024/05/GHSA-g48f-pgwh-wwxx/GHSA-g48f-pgwh-wwxx.json +++ b/advisories/github-reviewed/2024/05/GHSA-g48f-pgwh-wwxx/GHSA-g48f-pgwh-wwxx.json @@ -8,9 +8,7 @@ ], "summary": "onelogin/php-saml signature wrapping attacks", "details": "Vulnerability in onelogin/php-saml versions prior to 2.10.0 allows signature Wrapping attacks which may result in a malicious user gaining unauthorized access to a system.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-17T23:06:55Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-hxhc-wmg8-xrqf/GHSA-hxhc-wmg8-xrqf.json b/advisories/github-reviewed/2024/05/GHSA-hxhc-wmg8-xrqf/GHSA-hxhc-wmg8-xrqf.json index 6c4b721c2c2..550c5b7a9ca 100644 --- a/advisories/github-reviewed/2024/05/GHSA-hxhc-wmg8-xrqf/GHSA-hxhc-wmg8-xrqf.json +++ b/advisories/github-reviewed/2024/05/GHSA-hxhc-wmg8-xrqf/GHSA-hxhc-wmg8-xrqf.json @@ -3,14 +3,10 @@ "id": "GHSA-hxhc-wmg8-xrqf", "modified": "2024-05-17T22:31:42Z", "published": "2024-05-17T22:31:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "namshi/jose insecure JSON Web Signatures (JWS)", "details": "namshi/jose allows the acceptance of unsecure JSON Web Signatures (JWS) by default. The vulnerability arises from the $allowUnsecure flag, which, when set to true during the loading of JWSes, permits tokens signed with 'none' algorithms to be processed. This behavior poses a significant security risk as it could allow an attacker to impersonate users by crafting a valid jwt token.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-17T22:31:42Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-r2r8-36pq-27cm/GHSA-r2r8-36pq-27cm.json b/advisories/github-reviewed/2024/05/GHSA-r2r8-36pq-27cm/GHSA-r2r8-36pq-27cm.json index 862093a8115..89fba79dee0 100644 --- a/advisories/github-reviewed/2024/05/GHSA-r2r8-36pq-27cm/GHSA-r2r8-36pq-27cm.json +++ b/advisories/github-reviewed/2024/05/GHSA-r2r8-36pq-27cm/GHSA-r2r8-36pq-27cm.json @@ -3,14 +3,10 @@ "id": "GHSA-r2r8-36pq-27cm", "modified": "2024-05-17T23:06:52Z", "published": "2024-05-17T23:06:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values", "details": "Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext.\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -70,9 +66,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-17T23:06:52Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-rq6q-hjvh-5mwh/GHSA-rq6q-hjvh-5mwh.json b/advisories/github-reviewed/2024/05/GHSA-rq6q-hjvh-5mwh/GHSA-rq6q-hjvh-5mwh.json index 3f9530e2cf4..b3e6cd57851 100644 --- a/advisories/github-reviewed/2024/05/GHSA-rq6q-hjvh-5mwh/GHSA-rq6q-hjvh-5mwh.json +++ b/advisories/github-reviewed/2024/05/GHSA-rq6q-hjvh-5mwh/GHSA-rq6q-hjvh-5mwh.json @@ -3,14 +3,10 @@ "id": "GHSA-rq6q-hjvh-5mwh", "modified": "2024-05-17T23:06:50Z", "published": "2024-05-17T23:06:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Flow Swift Mailer package Remote code execution", "details": "A remote code execution vulnerability has been found in the Swift Mailer library (swiftmailer/swiftmailer) recently. [See this advisory for details](http://legalhackers.com/advisories/SwiftMailer-Exploit-Remote-Code-Exec-CVE-2016-10074-Vuln.html). If you are not using the default mail() transport, this particular problem does not affect you. Upgrading is of course still recommended!", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-17T23:06:50Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-2p4f-vc9q-r5vp/GHSA-2p4f-vc9q-r5vp.json b/advisories/github-reviewed/2024/06/GHSA-2p4f-vc9q-r5vp/GHSA-2p4f-vc9q-r5vp.json index 273ae995c68..b5c5fcbcbcd 100644 --- a/advisories/github-reviewed/2024/06/GHSA-2p4f-vc9q-r5vp/GHSA-2p4f-vc9q-r5vp.json +++ b/advisories/github-reviewed/2024/06/GHSA-2p4f-vc9q-r5vp/GHSA-2p4f-vc9q-r5vp.json @@ -3,14 +3,10 @@ "id": "GHSA-2p4f-vc9q-r5vp", "modified": "2024-06-05T18:26:34Z", "published": "2024-06-05T18:26:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Typo3 Arbitrary file upload and XML External Entity processing", "details": "It has been discovered that Flow 3.0.0 allows arbitrary file uploads, inlcuding server-side scripts, posing the risk of attacks. If those scripts are executed by the server when accessed through their public URL, anything not blocked through other means is possible (information disclosure, placement of backdoors, data removal, …).\n\nNote: The upload of files is only possible if the application built on Flow provides means to do so, and whether or not the upload of files poses a risk is dependent on the system setup. If uploaded script files are not executed by the server, there is no risk. In versions prior to 3.0.0 the upload of files with the extension php was blocked.\n\nIn Flow 2.3.0 to 2.3.6 a potential XML External Entity processing vulnerability has been discovered in the MediaTypeConverter.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -62,9 +58,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-06-05T18:26:34Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-g4xv-r3qw-v3q2/GHSA-g4xv-r3qw-v3q2.json b/advisories/github-reviewed/2024/06/GHSA-g4xv-r3qw-v3q2/GHSA-g4xv-r3qw-v3q2.json index b3253c07f8f..5925623a753 100644 --- a/advisories/github-reviewed/2024/06/GHSA-g4xv-r3qw-v3q2/GHSA-g4xv-r3qw-v3q2.json +++ b/advisories/github-reviewed/2024/06/GHSA-g4xv-r3qw-v3q2/GHSA-g4xv-r3qw-v3q2.json @@ -3,14 +3,10 @@ "id": "GHSA-g4xv-r3qw-v3q2", "modified": "2024-06-05T18:33:01Z", "published": "2024-06-05T18:33:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "typo3 Information Disclosure Security Note", "details": "Due to reports it has been validated that internal workspaces in Neos are accessible without authentication. Some users assumed this is a planned feature but it is not. A workspace preview should be an additional feature with respective security measures in place.\n\nNote that this only allows reading of internal workspaces not writing. And for clarification, an internal workspace is a workspace that is non public and doesn't have an owner.\n\nGiven that an internal workspace exists in your installation, it is possible to view a page in context of that workspace by opening a link in this format:\n\nhttps://domain/path/to/page.html@workspace-name\n\nThe issue is quite problematic when exploited but at the same time slightly less impactful than it sounds. First of all there is no default internal workspace, so the issue affects only workspaces created by users. That also means the workspace-name, which will also always include a hash is individual to a project and an exploiter must get hold of the workspace-name including the hash. This is non trivial as there is no indication of the existence of it, but obviously brute force and educated guessed can be made.\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -199,9 +195,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-06-05T18:33:01Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-m2hp-5x78-74mg/GHSA-m2hp-5x78-74mg.json b/advisories/github-reviewed/2024/06/GHSA-m2hp-5x78-74mg/GHSA-m2hp-5x78-74mg.json index 72e00fc0e0a..37dd50a1cb6 100644 --- a/advisories/github-reviewed/2024/06/GHSA-m2hp-5x78-74mg/GHSA-m2hp-5x78-74mg.json +++ b/advisories/github-reviewed/2024/06/GHSA-m2hp-5x78-74mg/GHSA-m2hp-5x78-74mg.json @@ -3,14 +3,10 @@ "id": "GHSA-m2hp-5x78-74mg", "modified": "2024-06-05T20:47:07Z", "published": "2024-06-05T20:47:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "Insecure Unserialize Vulnerability in FLOW3", "details": "Due to a missing signature (HMAC) for a request argument, an attacker could unserialize arbitrary objects within FLOW3.\n\nTo our knowledge it is neither possible to inject code through this vulnerability, nor are there exploitable objects within the FLOW3 Base Distribution. However, there might be exploitable objects within user applications.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-06-05T20:47:07Z", diff --git a/advisories/github-reviewed/2024/06/GHSA-xjw3-5r5c-m5ph/GHSA-xjw3-5r5c-m5ph.json b/advisories/github-reviewed/2024/06/GHSA-xjw3-5r5c-m5ph/GHSA-xjw3-5r5c-m5ph.json index f12336515a9..cb755108fe5 100644 --- a/advisories/github-reviewed/2024/06/GHSA-xjw3-5r5c-m5ph/GHSA-xjw3-5r5c-m5ph.json +++ b/advisories/github-reviewed/2024/06/GHSA-xjw3-5r5c-m5ph/GHSA-xjw3-5r5c-m5ph.json @@ -3,14 +3,10 @@ "id": "GHSA-xjw3-5r5c-m5ph", "modified": "2024-06-05T20:47:53Z", "published": "2024-06-05T20:47:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "typo3 Security fix for Flow Swift Mailer package", "details": "A remote code execution vulnerability has been found in the Swift Mailer library (swiftmailer/swiftmailer) recently. See this advisory for details. If you are not using the default mail() transport, this particular problem does not affect you. Upgrading is of course still recommended!", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -66,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-06-05T20:47:53Z", diff --git a/advisories/unreviewed/2022/05/GHSA-2244-rvc8-pc38/GHSA-2244-rvc8-pc38.json b/advisories/unreviewed/2022/05/GHSA-2244-rvc8-pc38/GHSA-2244-rvc8-pc38.json index b345fedce2c..3a4b4c5eccf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2244-rvc8-pc38/GHSA-2244-rvc8-pc38.json +++ b/advisories/unreviewed/2022/05/GHSA-2244-rvc8-pc38/GHSA-2244-rvc8-pc38.json @@ -7,12 +7,8 @@ "CVE-2019-7549" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control,", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-235j-w393-fq4f/GHSA-235j-w393-fq4f.json b/advisories/unreviewed/2022/05/GHSA-235j-w393-fq4f/GHSA-235j-w393-fq4f.json index cdc99540ccf..a73c123bfa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-235j-w393-fq4f/GHSA-235j-w393-fq4f.json +++ b/advisories/unreviewed/2022/05/GHSA-235j-w393-fq4f/GHSA-235j-w393-fq4f.json @@ -7,12 +7,8 @@ "CVE-2007-2897" ], "details": "Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23c5-vp3g-x496/GHSA-23c5-vp3g-x496.json b/advisories/unreviewed/2022/05/GHSA-23c5-vp3g-x496/GHSA-23c5-vp3g-x496.json index ad978e59b74..e4d20f624b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-23c5-vp3g-x496/GHSA-23c5-vp3g-x496.json +++ b/advisories/unreviewed/2022/05/GHSA-23c5-vp3g-x496/GHSA-23c5-vp3g-x496.json @@ -7,12 +7,8 @@ "CVE-2007-2839" ], "details": "gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23pq-p852-m3j7/GHSA-23pq-p852-m3j7.json b/advisories/unreviewed/2022/05/GHSA-23pq-p852-m3j7/GHSA-23pq-p852-m3j7.json index 32e3ace5aeb..2965e6fe894 100644 --- a/advisories/unreviewed/2022/05/GHSA-23pq-p852-m3j7/GHSA-23pq-p852-m3j7.json +++ b/advisories/unreviewed/2022/05/GHSA-23pq-p852-m3j7/GHSA-23pq-p852-m3j7.json @@ -7,12 +7,8 @@ "CVE-2007-3033" ], "details": "Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly removed and are rendered in the local zone.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25vc-xphv-5v97/GHSA-25vc-xphv-5v97.json b/advisories/unreviewed/2022/05/GHSA-25vc-xphv-5v97/GHSA-25vc-xphv-5v97.json index 4da91869cd1..3438e5296fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-25vc-xphv-5v97/GHSA-25vc-xphv-5v97.json +++ b/advisories/unreviewed/2022/05/GHSA-25vc-xphv-5v97/GHSA-25vc-xphv-5v97.json @@ -7,12 +7,8 @@ "CVE-2007-2981" ], "details": "Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28xp-4g73-5mqv/GHSA-28xp-4g73-5mqv.json b/advisories/unreviewed/2022/05/GHSA-28xp-4g73-5mqv/GHSA-28xp-4g73-5mqv.json index da78e9f3a6e..53c468a8633 100644 --- a/advisories/unreviewed/2022/05/GHSA-28xp-4g73-5mqv/GHSA-28xp-4g73-5mqv.json +++ b/advisories/unreviewed/2022/05/GHSA-28xp-4g73-5mqv/GHSA-28xp-4g73-5mqv.json @@ -7,12 +7,8 @@ "CVE-2007-3269" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in a GET request or (2) the Title field of a visitor comment, and (3) allow remote authenticated users to inject arbitrary web script or HTML via a message to another user. NOTE: vector (2) might overlap CVE-2006-3571.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29mq-gwwx-vg5f/GHSA-29mq-gwwx-vg5f.json b/advisories/unreviewed/2022/05/GHSA-29mq-gwwx-vg5f/GHSA-29mq-gwwx-vg5f.json index a78743b90e2..fd3d66d4948 100644 --- a/advisories/unreviewed/2022/05/GHSA-29mq-gwwx-vg5f/GHSA-29mq-gwwx-vg5f.json +++ b/advisories/unreviewed/2022/05/GHSA-29mq-gwwx-vg5f/GHSA-29mq-gwwx-vg5f.json @@ -7,12 +7,8 @@ "CVE-2007-3130" ], "details": "Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29p8-p94j-7f9c/GHSA-29p8-p94j-7f9c.json b/advisories/unreviewed/2022/05/GHSA-29p8-p94j-7f9c/GHSA-29p8-p94j-7f9c.json index bf95e885e55..38f54f1b936 100644 --- a/advisories/unreviewed/2022/05/GHSA-29p8-p94j-7f9c/GHSA-29p8-p94j-7f9c.json +++ b/advisories/unreviewed/2022/05/GHSA-29p8-p94j-7f9c/GHSA-29p8-p94j-7f9c.json @@ -7,12 +7,8 @@ "CVE-2007-3260" ], "details": "HP System Management Homepage (SMH) before 2.1.9 for Linux, when used with Novell eDirectory, assigns the eDirectory members to the root group, which allows remote authenticated eDirectory users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c4w-43w5-h44q/GHSA-2c4w-43w5-h44q.json b/advisories/unreviewed/2022/05/GHSA-2c4w-43w5-h44q/GHSA-2c4w-43w5-h44q.json index b051654f008..ef30aec4302 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c4w-43w5-h44q/GHSA-2c4w-43w5-h44q.json +++ b/advisories/unreviewed/2022/05/GHSA-2c4w-43w5-h44q/GHSA-2c4w-43w5-h44q.json @@ -7,12 +7,8 @@ "CVE-2007-3177" ], "details": "Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cg6-2qh8-qh5p/GHSA-2cg6-2qh8-qh5p.json b/advisories/unreviewed/2022/05/GHSA-2cg6-2qh8-qh5p/GHSA-2cg6-2qh8-qh5p.json index 82899e08409..c68c50b60f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cg6-2qh8-qh5p/GHSA-2cg6-2qh8-qh5p.json +++ b/advisories/unreviewed/2022/05/GHSA-2cg6-2qh8-qh5p/GHSA-2cg6-2qh8-qh5p.json @@ -7,12 +7,8 @@ "CVE-2007-3187" ], "details": "Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a denial of service or execute arbitrary code, possibly involving memory corruption, and a different issue from CVE-2007-3185 and CVE-2007-3186. NOTE: as of 20070612, the original disclosure has no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json b/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json index 0fc7217ac7e..827e593b235 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json +++ b/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g9h-j7jv-49v3/GHSA-2g9h-j7jv-49v3.json b/advisories/unreviewed/2022/05/GHSA-2g9h-j7jv-49v3/GHSA-2g9h-j7jv-49v3.json index bc6532b160b..3e1026262b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g9h-j7jv-49v3/GHSA-2g9h-j7jv-49v3.json +++ b/advisories/unreviewed/2022/05/GHSA-2g9h-j7jv-49v3/GHSA-2g9h-j7jv-49v3.json @@ -7,12 +7,8 @@ "CVE-2007-2962" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gwf-h3h6-j5rq/GHSA-2gwf-h3h6-j5rq.json b/advisories/unreviewed/2022/05/GHSA-2gwf-h3h6-j5rq/GHSA-2gwf-h3h6-j5rq.json index 20fee61bda8..1eb34d098e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gwf-h3h6-j5rq/GHSA-2gwf-h3h6-j5rq.json +++ b/advisories/unreviewed/2022/05/GHSA-2gwf-h3h6-j5rq/GHSA-2gwf-h3h6-j5rq.json @@ -7,12 +7,8 @@ "CVE-2007-3271" ], "details": "PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hj6-52jv-mj58/GHSA-2hj6-52jv-mj58.json b/advisories/unreviewed/2022/05/GHSA-2hj6-52jv-mj58/GHSA-2hj6-52jv-mj58.json index d38734729fd..5a4e8c543d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hj6-52jv-mj58/GHSA-2hj6-52jv-mj58.json +++ b/advisories/unreviewed/2022/05/GHSA-2hj6-52jv-mj58/GHSA-2hj6-52jv-mj58.json @@ -7,12 +7,8 @@ "CVE-2007-3085" ], "details": "Multiple PHP remote file inclusion vulnerabilities in PBSite allow remote attackers to execute arbitrary PHP code via a URL in the (1) dbpath parameter to (a) useronline.php, (b) ucp.php, (c) setcookie.php, (d) sendpm.php, (e) search.php, (f) register.php, (g) profile.php, (h) post.php, (i) pmpshow.php, (j) pm.php, (k) ntopic.php, (l) nreply.php, (m) news.php, (n) memberslist.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (u) editpost.php, (v) delpost.php, (w) delpm.php, (x) confirm.php, (y) board.php, (z) admin2.php, (aa) admin.php, or (bb) templates/pb/css/formstyles.php; or the (2) temppath parameter to (a) useronline.php, (c) setcookie.php, (e) search.php, (f) register.php, (h) post.php, (l) nreply.php, (m) news.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (w) delpm.php, (x) confirm.php, or (y) board.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -148,9 +144,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jp3-xwf9-m84m/GHSA-2jp3-xwf9-m84m.json b/advisories/unreviewed/2022/05/GHSA-2jp3-xwf9-m84m/GHSA-2jp3-xwf9-m84m.json index 6c615a60ca0..6b1a1e0e028 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jp3-xwf9-m84m/GHSA-2jp3-xwf9-m84m.json +++ b/advisories/unreviewed/2022/05/GHSA-2jp3-xwf9-m84m/GHSA-2jp3-xwf9-m84m.json @@ -7,12 +7,8 @@ "CVE-2007-3253" ], "details": "Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers to cause a denial of service via (1) certain email, which stops the SMTP Proxy during scanning; (2) certain HTTP traffic, which stops or slows down the HTTP proxy during HTTP responses containing virus scanned web pages; and (3) a disconnection during a streaming session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jp8-mrvc-f3jf/GHSA-2jp8-mrvc-f3jf.json b/advisories/unreviewed/2022/05/GHSA-2jp8-mrvc-f3jf/GHSA-2jp8-mrvc-f3jf.json index b45400cbda0..9aafa0a0b18 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jp8-mrvc-f3jf/GHSA-2jp8-mrvc-f3jf.json +++ b/advisories/unreviewed/2022/05/GHSA-2jp8-mrvc-f3jf/GHSA-2jp8-mrvc-f3jf.json @@ -7,12 +7,8 @@ "CVE-2007-2964" ], "details": "The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mqp-wcww-qxh6/GHSA-2mqp-wcww-qxh6.json b/advisories/unreviewed/2022/05/GHSA-2mqp-wcww-qxh6/GHSA-2mqp-wcww-qxh6.json index c8e58debe7e..0fb25b90f0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mqp-wcww-qxh6/GHSA-2mqp-wcww-qxh6.json +++ b/advisories/unreviewed/2022/05/GHSA-2mqp-wcww-qxh6/GHSA-2mqp-wcww-qxh6.json @@ -7,12 +7,8 @@ "CVE-2019-1010222" ], "details": "aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The component is: filterbank. The attack vector is: pass invalid arguments to new_aubio_filterbank. The fixed version is: after commit eda95c9c22b4f0b466ae94c4708765eaae6e709e.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mqq-gv4v-qfqf/GHSA-2mqq-gv4v-qfqf.json b/advisories/unreviewed/2022/05/GHSA-2mqq-gv4v-qfqf/GHSA-2mqq-gv4v-qfqf.json index f6b8d6b086c..bb2ae3f7ff9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mqq-gv4v-qfqf/GHSA-2mqq-gv4v-qfqf.json +++ b/advisories/unreviewed/2022/05/GHSA-2mqq-gv4v-qfqf/GHSA-2mqq-gv4v-qfqf.json @@ -7,12 +7,8 @@ "CVE-2007-2915" ], "details": "Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2q68-vqm6-gwxg/GHSA-2q68-vqm6-gwxg.json b/advisories/unreviewed/2022/05/GHSA-2q68-vqm6-gwxg/GHSA-2q68-vqm6-gwxg.json index dbf866388a9..53a0214092e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q68-vqm6-gwxg/GHSA-2q68-vqm6-gwxg.json +++ b/advisories/unreviewed/2022/05/GHSA-2q68-vqm6-gwxg/GHSA-2q68-vqm6-gwxg.json @@ -7,12 +7,8 @@ "CVE-2007-2913" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in ClonusWiki .5 allows remote attackers to inject arbitrary web script or HTML via the query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qw7-4f4v-5pqm/GHSA-2qw7-4f4v-5pqm.json b/advisories/unreviewed/2022/05/GHSA-2qw7-4f4v-5pqm/GHSA-2qw7-4f4v-5pqm.json index 84b843ff5d2..dfda125c7aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qw7-4f4v-5pqm/GHSA-2qw7-4f4v-5pqm.json +++ b/advisories/unreviewed/2022/05/GHSA-2qw7-4f4v-5pqm/GHSA-2qw7-4f4v-5pqm.json @@ -7,12 +7,8 @@ "CVE-2007-2946" ], "details": "Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long DestinationPath property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2r2x-23j6-jmj3/GHSA-2r2x-23j6-jmj3.json b/advisories/unreviewed/2022/05/GHSA-2r2x-23j6-jmj3/GHSA-2r2x-23j6-jmj3.json index aaf556207f3..c7335ef0c8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r2x-23j6-jmj3/GHSA-2r2x-23j6-jmj3.json +++ b/advisories/unreviewed/2022/05/GHSA-2r2x-23j6-jmj3/GHSA-2r2x-23j6-jmj3.json @@ -7,12 +7,8 @@ "CVE-2007-3025" ], "details": "Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service (hang) via unknown vectors related to the isURL function and regular expressions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2r68-xqjc-633p/GHSA-2r68-xqjc-633p.json b/advisories/unreviewed/2022/05/GHSA-2r68-xqjc-633p/GHSA-2r68-xqjc-633p.json index 06c0911f157..16ee5c84289 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r68-xqjc-633p/GHSA-2r68-xqjc-633p.json +++ b/advisories/unreviewed/2022/05/GHSA-2r68-xqjc-633p/GHSA-2r68-xqjc-633p.json @@ -7,12 +7,8 @@ "CVE-2007-2929" ], "details": "The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rm4-pxv9-x75c/GHSA-2rm4-pxv9-x75c.json b/advisories/unreviewed/2022/05/GHSA-2rm4-pxv9-x75c/GHSA-2rm4-pxv9-x75c.json index a7f849da68b..cc7f11c107c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rm4-pxv9-x75c/GHSA-2rm4-pxv9-x75c.json +++ b/advisories/unreviewed/2022/05/GHSA-2rm4-pxv9-x75c/GHSA-2rm4-pxv9-x75c.json @@ -7,12 +7,8 @@ "CVE-2007-2756" ], "details": "The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -268,9 +264,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w2x-v275-f37c/GHSA-2w2x-v275-f37c.json b/advisories/unreviewed/2022/05/GHSA-2w2x-v275-f37c/GHSA-2w2x-v275-f37c.json index 4198a78c191..9b65c5619b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w2x-v275-f37c/GHSA-2w2x-v275-f37c.json +++ b/advisories/unreviewed/2022/05/GHSA-2w2x-v275-f37c/GHSA-2w2x-v275-f37c.json @@ -7,12 +7,8 @@ "CVE-2007-3110" ], "details": "Cross-site scripting (XSS) vulnerability in the Andy Frank Beatnik 1.0 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via an RSS feed. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wj8-f7pq-vfpf/GHSA-2wj8-f7pq-vfpf.json b/advisories/unreviewed/2022/05/GHSA-2wj8-f7pq-vfpf/GHSA-2wj8-f7pq-vfpf.json index 6bc0aa1d3f8..27e86b0156b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wj8-f7pq-vfpf/GHSA-2wj8-f7pq-vfpf.json +++ b/advisories/unreviewed/2022/05/GHSA-2wj8-f7pq-vfpf/GHSA-2wj8-f7pq-vfpf.json @@ -7,12 +7,8 @@ "CVE-2007-2855" ], "details": "Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2856.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2ww5-g3p9-xg2r/GHSA-2ww5-g3p9-xg2r.json b/advisories/unreviewed/2022/05/GHSA-2ww5-g3p9-xg2r/GHSA-2ww5-g3p9-xg2r.json index 88589d0ee32..bd845080e47 100644 --- a/advisories/unreviewed/2022/05/GHSA-2ww5-g3p9-xg2r/GHSA-2ww5-g3p9-xg2r.json +++ b/advisories/unreviewed/2022/05/GHSA-2ww5-g3p9-xg2r/GHSA-2ww5-g3p9-xg2r.json @@ -7,12 +7,8 @@ "CVE-2007-2891" ], "details": "Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xc6-gj77-5g2j/GHSA-2xc6-gj77-5g2j.json b/advisories/unreviewed/2022/05/GHSA-2xc6-gj77-5g2j/GHSA-2xc6-gj77-5g2j.json index d78a4887434..3827c6fd88c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xc6-gj77-5g2j/GHSA-2xc6-gj77-5g2j.json +++ b/advisories/unreviewed/2022/05/GHSA-2xc6-gj77-5g2j/GHSA-2xc6-gj77-5g2j.json @@ -7,12 +7,8 @@ "CVE-2007-2691" ], "details": "MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -148,9 +144,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32vj-x8fv-x955/GHSA-32vj-x8fv-x955.json b/advisories/unreviewed/2022/05/GHSA-32vj-x8fv-x955/GHSA-32vj-x8fv-x955.json index 5c159d5f6e6..c1331592510 100644 --- a/advisories/unreviewed/2022/05/GHSA-32vj-x8fv-x955/GHSA-32vj-x8fv-x955.json +++ b/advisories/unreviewed/2022/05/GHSA-32vj-x8fv-x955/GHSA-32vj-x8fv-x955.json @@ -7,12 +7,8 @@ "CVE-2007-3116" ], "details": "Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3114 and CVE-2007-3115.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33ff-q632-5gfm/GHSA-33ff-q632-5gfm.json b/advisories/unreviewed/2022/05/GHSA-33ff-q632-5gfm/GHSA-33ff-q632-5gfm.json index b290ff20e94..80d2de199bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-33ff-q632-5gfm/GHSA-33ff-q632-5gfm.json +++ b/advisories/unreviewed/2022/05/GHSA-33ff-q632-5gfm/GHSA-33ff-q632-5gfm.json @@ -7,12 +7,8 @@ "CVE-2019-12196" ], "details": "A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-348j-4g33-25p9/GHSA-348j-4g33-25p9.json b/advisories/unreviewed/2022/05/GHSA-348j-4g33-25p9/GHSA-348j-4g33-25p9.json index 9cbc151d109..97c6cd25610 100644 --- a/advisories/unreviewed/2022/05/GHSA-348j-4g33-25p9/GHSA-348j-4g33-25p9.json +++ b/advisories/unreviewed/2022/05/GHSA-348j-4g33-25p9/GHSA-348j-4g33-25p9.json @@ -7,12 +7,8 @@ "CVE-2007-2787" ], "details": "Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34fg-jm9v-7hg8/GHSA-34fg-jm9v-7hg8.json b/advisories/unreviewed/2022/05/GHSA-34fg-jm9v-7hg8/GHSA-34fg-jm9v-7hg8.json index bc17651ada8..9b9bb4c2c4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-34fg-jm9v-7hg8/GHSA-34fg-jm9v-7hg8.json +++ b/advisories/unreviewed/2022/05/GHSA-34fg-jm9v-7hg8/GHSA-34fg-jm9v-7hg8.json @@ -7,12 +7,8 @@ "CVE-2007-2746" ], "details": "The viewList function in lib/WebGUI/Asset/Wobject/DataForm.pm in Plain Black WebGUI before 7.3.14 does not properly use data structures containing privilege information, which allows remote authenticated users to obtain sensitive information or possibly have other unspecified impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34q7-j45w-p4jq/GHSA-34q7-j45w-p4jq.json b/advisories/unreviewed/2022/05/GHSA-34q7-j45w-p4jq/GHSA-34q7-j45w-p4jq.json index c0019e8ca29..6e649816cf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-34q7-j45w-p4jq/GHSA-34q7-j45w-p4jq.json +++ b/advisories/unreviewed/2022/05/GHSA-34q7-j45w-p4jq/GHSA-34q7-j45w-p4jq.json @@ -7,12 +7,8 @@ "CVE-2019-4139" ], "details": "IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158335.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34wx-3364-j343/GHSA-34wx-3364-j343.json b/advisories/unreviewed/2022/05/GHSA-34wx-3364-j343/GHSA-34wx-3364-j343.json index ed23a46e24e..d114fb5eee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-34wx-3364-j343/GHSA-34wx-3364-j343.json +++ b/advisories/unreviewed/2022/05/GHSA-34wx-3364-j343/GHSA-34wx-3364-j343.json @@ -7,12 +7,8 @@ "CVE-2007-2937" ], "details": "PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-355h-9qx6-6qfx/GHSA-355h-9qx6-6qfx.json b/advisories/unreviewed/2022/05/GHSA-355h-9qx6-6qfx/GHSA-355h-9qx6-6qfx.json index 6c3aebf3c28..b75fa4869fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-355h-9qx6-6qfx/GHSA-355h-9qx6-6qfx.json +++ b/advisories/unreviewed/2022/05/GHSA-355h-9qx6-6qfx/GHSA-355h-9qx6-6qfx.json @@ -7,12 +7,8 @@ "CVE-2007-2980" ], "details": "Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35jw-fp6x-xpxj/GHSA-35jw-fp6x-xpxj.json b/advisories/unreviewed/2022/05/GHSA-35jw-fp6x-xpxj/GHSA-35jw-fp6x-xpxj.json index 71674ef7bcb..9e6c2d37c75 100644 --- a/advisories/unreviewed/2022/05/GHSA-35jw-fp6x-xpxj/GHSA-35jw-fp6x-xpxj.json +++ b/advisories/unreviewed/2022/05/GHSA-35jw-fp6x-xpxj/GHSA-35jw-fp6x-xpxj.json @@ -7,12 +7,8 @@ "CVE-2007-2945" ], "details": "RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35qg-2852-82xj/GHSA-35qg-2852-82xj.json b/advisories/unreviewed/2022/05/GHSA-35qg-2852-82xj/GHSA-35qg-2852-82xj.json index 98ea9719b9d..7a5d952715f 100644 --- a/advisories/unreviewed/2022/05/GHSA-35qg-2852-82xj/GHSA-35qg-2852-82xj.json +++ b/advisories/unreviewed/2022/05/GHSA-35qg-2852-82xj/GHSA-35qg-2852-82xj.json @@ -7,12 +7,8 @@ "CVE-2007-3087" ], "details": "Peercast places a cleartext password in a query string, which might allow attackers to obtain sensitive information by sniffing the network, or obtaining Referer or browser history information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36fx-rf6c-vc8x/GHSA-36fx-rf6c-vc8x.json b/advisories/unreviewed/2022/05/GHSA-36fx-rf6c-vc8x/GHSA-36fx-rf6c-vc8x.json index 8e1577b4ad0..1f6f6afbf8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-36fx-rf6c-vc8x/GHSA-36fx-rf6c-vc8x.json +++ b/advisories/unreviewed/2022/05/GHSA-36fx-rf6c-vc8x/GHSA-36fx-rf6c-vc8x.json @@ -7,12 +7,8 @@ "CVE-2007-3113" ], "details": "Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36pp-h6qf-9x8p/GHSA-36pp-h6qf-9x8p.json b/advisories/unreviewed/2022/05/GHSA-36pp-h6qf-9x8p/GHSA-36pp-h6qf-9x8p.json index c9ad877edd3..b0f167a0cfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-36pp-h6qf-9x8p/GHSA-36pp-h6qf-9x8p.json +++ b/advisories/unreviewed/2022/05/GHSA-36pp-h6qf-9x8p/GHSA-36pp-h6qf-9x8p.json @@ -7,12 +7,8 @@ "CVE-2007-2955" ], "details": "Multiple unspecified \"input validation error\" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly property to AxSysListView32OAA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37vj-pmvf-vxpc/GHSA-37vj-pmvf-vxpc.json b/advisories/unreviewed/2022/05/GHSA-37vj-pmvf-vxpc/GHSA-37vj-pmvf-vxpc.json index 17cb03ddf01..a1b7949991d 100644 --- a/advisories/unreviewed/2022/05/GHSA-37vj-pmvf-vxpc/GHSA-37vj-pmvf-vxpc.json +++ b/advisories/unreviewed/2022/05/GHSA-37vj-pmvf-vxpc/GHSA-37vj-pmvf-vxpc.json @@ -7,12 +7,8 @@ "CVE-2007-2993" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to inject arbitrary web script or HTML via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38rr-jh2c-6vfp/GHSA-38rr-jh2c-6vfp.json b/advisories/unreviewed/2022/05/GHSA-38rr-jh2c-6vfp/GHSA-38rr-jh2c-6vfp.json index c38f0b51d8d..f94b9a687ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-38rr-jh2c-6vfp/GHSA-38rr-jh2c-6vfp.json +++ b/advisories/unreviewed/2022/05/GHSA-38rr-jh2c-6vfp/GHSA-38rr-jh2c-6vfp.json @@ -7,12 +7,8 @@ "CVE-2007-2832" ], "details": "Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38wr-8jpj-263v/GHSA-38wr-8jpj-263v.json b/advisories/unreviewed/2022/05/GHSA-38wr-8jpj-263v/GHSA-38wr-8jpj-263v.json index 062a83aa0ca..6fa7f22d2c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-38wr-8jpj-263v/GHSA-38wr-8jpj-263v.json +++ b/advisories/unreviewed/2022/05/GHSA-38wr-8jpj-263v/GHSA-38wr-8jpj-263v.json @@ -7,12 +7,8 @@ "CVE-2007-2864" ], "details": "Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39cr-9663-62x5/GHSA-39cr-9663-62x5.json b/advisories/unreviewed/2022/05/GHSA-39cr-9663-62x5/GHSA-39cr-9663-62x5.json index 00dc7f8bf52..970647eb141 100644 --- a/advisories/unreviewed/2022/05/GHSA-39cr-9663-62x5/GHSA-39cr-9663-62x5.json +++ b/advisories/unreviewed/2022/05/GHSA-39cr-9663-62x5/GHSA-39cr-9663-62x5.json @@ -7,12 +7,8 @@ "CVE-2019-12963" ], "details": "LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f2f-gr4w-hx4f/GHSA-3f2f-gr4w-hx4f.json b/advisories/unreviewed/2022/05/GHSA-3f2f-gr4w-hx4f/GHSA-3f2f-gr4w-hx4f.json index 9ee38a4486c..79e2572938e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f2f-gr4w-hx4f/GHSA-3f2f-gr4w-hx4f.json +++ b/advisories/unreviewed/2022/05/GHSA-3f2f-gr4w-hx4f/GHSA-3f2f-gr4w-hx4f.json @@ -7,12 +7,8 @@ "CVE-2007-3029" ], "details": "Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f6v-hh22-p99q/GHSA-3f6v-hh22-p99q.json b/advisories/unreviewed/2022/05/GHSA-3f6v-hh22-p99q/GHSA-3f6v-hh22-p99q.json index 86b61b98d11..258248cae8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f6v-hh22-p99q/GHSA-3f6v-hh22-p99q.json +++ b/advisories/unreviewed/2022/05/GHSA-3f6v-hh22-p99q/GHSA-3f6v-hh22-p99q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fwf-33ww-5w45/GHSA-3fwf-33ww-5w45.json b/advisories/unreviewed/2022/05/GHSA-3fwf-33ww-5w45/GHSA-3fwf-33ww-5w45.json index d6e8626aba6..a1083ed755d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fwf-33ww-5w45/GHSA-3fwf-33ww-5w45.json +++ b/advisories/unreviewed/2022/05/GHSA-3fwf-33ww-5w45/GHSA-3fwf-33ww-5w45.json @@ -7,12 +7,8 @@ "CVE-2007-3135" ], "details": "Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom Photoblog 1.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tag parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fwp-mfw4-gm5c/GHSA-3fwp-mfw4-gm5c.json b/advisories/unreviewed/2022/05/GHSA-3fwp-mfw4-gm5c/GHSA-3fwp-mfw4-gm5c.json index fd19f12fc16..dfe3077b548 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fwp-mfw4-gm5c/GHSA-3fwp-mfw4-gm5c.json +++ b/advisories/unreviewed/2022/05/GHSA-3fwp-mfw4-gm5c/GHSA-3fwp-mfw4-gm5c.json @@ -7,12 +7,8 @@ "CVE-2017-11739" ], "details": "In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a \"Utility Widget\" with a \"Custom HTML or Text\" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a \"Utility Widget\" that contains malicious JavaScript code, aka XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g6m-rmr3-g7cf/GHSA-3g6m-rmr3-g7cf.json b/advisories/unreviewed/2022/05/GHSA-3g6m-rmr3-g7cf/GHSA-3g6m-rmr3-g7cf.json index c55114f881e..e3fbc8575bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g6m-rmr3-g7cf/GHSA-3g6m-rmr3-g7cf.json +++ b/advisories/unreviewed/2022/05/GHSA-3g6m-rmr3-g7cf/GHSA-3g6m-rmr3-g7cf.json @@ -7,12 +7,8 @@ "CVE-2007-3071" ], "details": "Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3j5p-c9jq-rrfh/GHSA-3j5p-c9jq-rrfh.json b/advisories/unreviewed/2022/05/GHSA-3j5p-c9jq-rrfh/GHSA-3j5p-c9jq-rrfh.json index 90b77c52916..eb8b09ac961 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j5p-c9jq-rrfh/GHSA-3j5p-c9jq-rrfh.json +++ b/advisories/unreviewed/2022/05/GHSA-3j5p-c9jq-rrfh/GHSA-3j5p-c9jq-rrfh.json @@ -7,12 +7,8 @@ "CVE-2007-2998" ], "details": "The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jc5-hhm5-7cxf/GHSA-3jc5-hhm5-7cxf.json b/advisories/unreviewed/2022/05/GHSA-3jc5-hhm5-7cxf/GHSA-3jc5-hhm5-7cxf.json index 24a41456eb3..335a16d6192 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jc5-hhm5-7cxf/GHSA-3jc5-hhm5-7cxf.json +++ b/advisories/unreviewed/2022/05/GHSA-3jc5-hhm5-7cxf/GHSA-3jc5-hhm5-7cxf.json @@ -7,12 +7,8 @@ "CVE-2007-3178" ], "details": "Multiple SQL injection vulnerabilities in Zindizayn Okul Web Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) pass parameter to (a) mezungiris.asp or (b) ogretmenkontrol.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jv6-9q5f-rc7v/GHSA-3jv6-9q5f-rc7v.json b/advisories/unreviewed/2022/05/GHSA-3jv6-9q5f-rc7v/GHSA-3jv6-9q5f-rc7v.json index b909fbc4813..d4934fb2d79 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jv6-9q5f-rc7v/GHSA-3jv6-9q5f-rc7v.json +++ b/advisories/unreviewed/2022/05/GHSA-3jv6-9q5f-rc7v/GHSA-3jv6-9q5f-rc7v.json @@ -7,12 +7,8 @@ "CVE-2007-3155" ], "details": "Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jwg-934c-hf4r/GHSA-3jwg-934c-hf4r.json b/advisories/unreviewed/2022/05/GHSA-3jwg-934c-hf4r/GHSA-3jwg-934c-hf4r.json index e5fd7c25261..3f648a1e0d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jwg-934c-hf4r/GHSA-3jwg-934c-hf4r.json +++ b/advisories/unreviewed/2022/05/GHSA-3jwg-934c-hf4r/GHSA-3jwg-934c-hf4r.json @@ -7,12 +7,8 @@ "CVE-2007-2693" ], "details": "MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3m6f-4r6r-cmjq/GHSA-3m6f-4r6r-cmjq.json b/advisories/unreviewed/2022/05/GHSA-3m6f-4r6r-cmjq/GHSA-3m6f-4r6r-cmjq.json index 6f70413a768..5baedfa063a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m6f-4r6r-cmjq/GHSA-3m6f-4r6r-cmjq.json +++ b/advisories/unreviewed/2022/05/GHSA-3m6f-4r6r-cmjq/GHSA-3m6f-4r6r-cmjq.json @@ -7,12 +7,8 @@ "CVE-2007-2737" ], "details": "SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mj5-5ph7-ggjq/GHSA-3mj5-5ph7-ggjq.json b/advisories/unreviewed/2022/05/GHSA-3mj5-5ph7-ggjq/GHSA-3mj5-5ph7-ggjq.json index 0b6bc731aa0..059e208d97b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mj5-5ph7-ggjq/GHSA-3mj5-5ph7-ggjq.json +++ b/advisories/unreviewed/2022/05/GHSA-3mj5-5ph7-ggjq/GHSA-3mj5-5ph7-ggjq.json @@ -7,12 +7,8 @@ "CVE-2007-3129" ], "details": "Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q4r-h353-x973/GHSA-3q4r-h353-x973.json b/advisories/unreviewed/2022/05/GHSA-3q4r-h353-x973/GHSA-3q4r-h353-x973.json index 8992a111f2f..02aa6451402 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q4r-h353-x973/GHSA-3q4r-h353-x973.json +++ b/advisories/unreviewed/2022/05/GHSA-3q4r-h353-x973/GHSA-3q4r-h353-x973.json @@ -7,12 +7,8 @@ "CVE-2007-2775" ], "details": "AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r63-4qp5-jppx/GHSA-3r63-4qp5-jppx.json b/advisories/unreviewed/2022/05/GHSA-3r63-4qp5-jppx/GHSA-3r63-4qp5-jppx.json index 25738d7e7dd..6f23a8f279d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r63-4qp5-jppx/GHSA-3r63-4qp5-jppx.json +++ b/advisories/unreviewed/2022/05/GHSA-3r63-4qp5-jppx/GHSA-3r63-4qp5-jppx.json @@ -7,12 +7,8 @@ "CVE-2007-2876" ], "details": "The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cause a denial of service by causing certain invalid states that trigger a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -140,9 +136,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rx7-xcvr-j7v2/GHSA-3rx7-xcvr-j7v2.json b/advisories/unreviewed/2022/05/GHSA-3rx7-xcvr-j7v2/GHSA-3rx7-xcvr-j7v2.json index b0e1bc09af5..e9128c1605a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rx7-xcvr-j7v2/GHSA-3rx7-xcvr-j7v2.json +++ b/advisories/unreviewed/2022/05/GHSA-3rx7-xcvr-j7v2/GHSA-3rx7-xcvr-j7v2.json @@ -7,12 +7,8 @@ "CVE-2007-2939" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wj7-jcqx-7j5f/GHSA-3wj7-jcqx-7j5f.json b/advisories/unreviewed/2022/05/GHSA-3wj7-jcqx-7j5f/GHSA-3wj7-jcqx-7j5f.json index da7d09c192c..57c149c16ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wj7-jcqx-7j5f/GHSA-3wj7-jcqx-7j5f.json +++ b/advisories/unreviewed/2022/05/GHSA-3wj7-jcqx-7j5f/GHSA-3wj7-jcqx-7j5f.json @@ -7,12 +7,8 @@ "CVE-2007-3112" ], "details": "graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wqr-6335-7cpw/GHSA-3wqr-6335-7cpw.json b/advisories/unreviewed/2022/05/GHSA-3wqr-6335-7cpw/GHSA-3wqr-6335-7cpw.json index 9c6d80cb88b..0a15556096a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wqr-6335-7cpw/GHSA-3wqr-6335-7cpw.json +++ b/advisories/unreviewed/2022/05/GHSA-3wqr-6335-7cpw/GHSA-3wqr-6335-7cpw.json @@ -7,12 +7,8 @@ "CVE-2007-2869" ], "details": "The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-422c-878v-38j5/GHSA-422c-878v-38j5.json b/advisories/unreviewed/2022/05/GHSA-422c-878v-38j5/GHSA-422c-878v-38j5.json index deebaac1d37..7b29cd49bb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-422c-878v-38j5/GHSA-422c-878v-38j5.json +++ b/advisories/unreviewed/2022/05/GHSA-422c-878v-38j5/GHSA-422c-878v-38j5.json @@ -7,12 +7,8 @@ "CVE-2007-2974" ], "details": "Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an \"integer cast around.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4352-wv85-hjf8/GHSA-4352-wv85-hjf8.json b/advisories/unreviewed/2022/05/GHSA-4352-wv85-hjf8/GHSA-4352-wv85-hjf8.json index e3b67086509..bae279f9c03 100644 --- a/advisories/unreviewed/2022/05/GHSA-4352-wv85-hjf8/GHSA-4352-wv85-hjf8.json +++ b/advisories/unreviewed/2022/05/GHSA-4352-wv85-hjf8/GHSA-4352-wv85-hjf8.json @@ -7,12 +7,8 @@ "CVE-2007-2805" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-439f-hv4q-rmc5/GHSA-439f-hv4q-rmc5.json b/advisories/unreviewed/2022/05/GHSA-439f-hv4q-rmc5/GHSA-439f-hv4q-rmc5.json index 7d7608e75a2..42604a08b62 100644 --- a/advisories/unreviewed/2022/05/GHSA-439f-hv4q-rmc5/GHSA-439f-hv4q-rmc5.json +++ b/advisories/unreviewed/2022/05/GHSA-439f-hv4q-rmc5/GHSA-439f-hv4q-rmc5.json @@ -7,12 +7,8 @@ "CVE-2007-2925" ], "details": "The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-439r-73qm-6346/GHSA-439r-73qm-6346.json b/advisories/unreviewed/2022/05/GHSA-439r-73qm-6346/GHSA-439r-73qm-6346.json index 73d101f5cda..52dc93e7b01 100644 --- a/advisories/unreviewed/2022/05/GHSA-439r-73qm-6346/GHSA-439r-73qm-6346.json +++ b/advisories/unreviewed/2022/05/GHSA-439r-73qm-6346/GHSA-439r-73qm-6346.json @@ -7,12 +7,8 @@ "CVE-2019-11226" ], "details": "CMS Made Simple 2.2.10 has XSS via the m1_name parameter in \"Add Article\" under Content -> Content Manager -> News.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43c9-q639-gwmv/GHSA-43c9-q639-gwmv.json b/advisories/unreviewed/2022/05/GHSA-43c9-q639-gwmv/GHSA-43c9-q639-gwmv.json index cf4d79acd35..988a6d454c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-43c9-q639-gwmv/GHSA-43c9-q639-gwmv.json +++ b/advisories/unreviewed/2022/05/GHSA-43c9-q639-gwmv/GHSA-43c9-q639-gwmv.json @@ -7,12 +7,8 @@ "CVE-2007-2921" ], "details": "Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43jh-vm7w-2m63/GHSA-43jh-vm7w-2m63.json b/advisories/unreviewed/2022/05/GHSA-43jh-vm7w-2m63/GHSA-43jh-vm7w-2m63.json index bc0763ad92b..9de7706d931 100644 --- a/advisories/unreviewed/2022/05/GHSA-43jh-vm7w-2m63/GHSA-43jh-vm7w-2m63.json +++ b/advisories/unreviewed/2022/05/GHSA-43jh-vm7w-2m63/GHSA-43jh-vm7w-2m63.json @@ -7,12 +7,8 @@ "CVE-2007-2879" ], "details": "Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-453c-xr7g-2ph7/GHSA-453c-xr7g-2ph7.json b/advisories/unreviewed/2022/05/GHSA-453c-xr7g-2ph7/GHSA-453c-xr7g-2ph7.json index 41bb34abc6c..93359f8f8df 100644 --- a/advisories/unreviewed/2022/05/GHSA-453c-xr7g-2ph7/GHSA-453c-xr7g-2ph7.json +++ b/advisories/unreviewed/2022/05/GHSA-453c-xr7g-2ph7/GHSA-453c-xr7g-2ph7.json @@ -7,12 +7,8 @@ "CVE-2007-3156" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4594-3h26-2mp7/GHSA-4594-3h26-2mp7.json b/advisories/unreviewed/2022/05/GHSA-4594-3h26-2mp7/GHSA-4594-3h26-2mp7.json index 7d548c6b5f9..0dcc4d5597e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4594-3h26-2mp7/GHSA-4594-3h26-2mp7.json +++ b/advisories/unreviewed/2022/05/GHSA-4594-3h26-2mp7/GHSA-4594-3h26-2mp7.json @@ -7,12 +7,8 @@ "CVE-2007-2884" ], "details": "Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-459q-5pr3-cwfv/GHSA-459q-5pr3-cwfv.json b/advisories/unreviewed/2022/05/GHSA-459q-5pr3-cwfv/GHSA-459q-5pr3-cwfv.json index bf70470e778..1308ec08c74 100644 --- a/advisories/unreviewed/2022/05/GHSA-459q-5pr3-cwfv/GHSA-459q-5pr3-cwfv.json +++ b/advisories/unreviewed/2022/05/GHSA-459q-5pr3-cwfv/GHSA-459q-5pr3-cwfv.json @@ -7,12 +7,8 @@ "CVE-2007-2738" ], "details": "SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-462h-7vhv-4jpp/GHSA-462h-7vhv-4jpp.json b/advisories/unreviewed/2022/05/GHSA-462h-7vhv-4jpp/GHSA-462h-7vhv-4jpp.json index 12867ff7616..e98bd9380c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-462h-7vhv-4jpp/GHSA-462h-7vhv-4jpp.json +++ b/advisories/unreviewed/2022/05/GHSA-462h-7vhv-4jpp/GHSA-462h-7vhv-4jpp.json @@ -7,12 +7,8 @@ "CVE-2007-2870" ], "details": "Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4698-4fhw-m884/GHSA-4698-4fhw-m884.json b/advisories/unreviewed/2022/05/GHSA-4698-4fhw-m884/GHSA-4698-4fhw-m884.json index e517d94394a..24627ab270b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4698-4fhw-m884/GHSA-4698-4fhw-m884.json +++ b/advisories/unreviewed/2022/05/GHSA-4698-4fhw-m884/GHSA-4698-4fhw-m884.json @@ -7,12 +7,8 @@ "CVE-2007-3099" ], "details": "usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or iSCSI connection loss).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46cj-j92w-jf4m/GHSA-46cj-j92w-jf4m.json b/advisories/unreviewed/2022/05/GHSA-46cj-j92w-jf4m/GHSA-46cj-j92w-jf4m.json index bbc75a6153d..54a4f05f444 100644 --- a/advisories/unreviewed/2022/05/GHSA-46cj-j92w-jf4m/GHSA-46cj-j92w-jf4m.json +++ b/advisories/unreviewed/2022/05/GHSA-46cj-j92w-jf4m/GHSA-46cj-j92w-jf4m.json @@ -7,12 +7,8 @@ "CVE-2007-3057" ], "details": "PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46ww-whr4-c365/GHSA-46ww-whr4-c365.json b/advisories/unreviewed/2022/05/GHSA-46ww-whr4-c365/GHSA-46ww-whr4-c365.json index c999c58453c..8662384838e 100644 --- a/advisories/unreviewed/2022/05/GHSA-46ww-whr4-c365/GHSA-46ww-whr4-c365.json +++ b/advisories/unreviewed/2022/05/GHSA-46ww-whr4-c365/GHSA-46ww-whr4-c365.json @@ -7,12 +7,8 @@ "CVE-2007-3046" ], "details": "Buffer overflow in Advanced Software Production Line Vortex Library before 1.0.3 allows remote attackers to cause a denial of service (listener crash) via unspecified vectors related to the select I/O implementation and the file set buffer. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-475w-6gxw-mj33/GHSA-475w-6gxw-mj33.json b/advisories/unreviewed/2022/05/GHSA-475w-6gxw-mj33/GHSA-475w-6gxw-mj33.json index 927fa01d539..cc1c35d17ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-475w-6gxw-mj33/GHSA-475w-6gxw-mj33.json +++ b/advisories/unreviewed/2022/05/GHSA-475w-6gxw-mj33/GHSA-475w-6gxw-mj33.json @@ -7,12 +7,8 @@ "CVE-2007-2813" ], "details": "Cisco IOS 12.4 and earlier, when using the crypto packages and SSL support is enabled, allows remote attackers to cause a denial of service via a malformed (1) ClientHello, (2) ChangeCipherSpec, or (3) Finished message during an SSL session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47g7-45f4-j83m/GHSA-47g7-45f4-j83m.json b/advisories/unreviewed/2022/05/GHSA-47g7-45f4-j83m/GHSA-47g7-45f4-j83m.json index 1b549e98f5c..674cff2e05d 100644 --- a/advisories/unreviewed/2022/05/GHSA-47g7-45f4-j83m/GHSA-47g7-45f4-j83m.json +++ b/advisories/unreviewed/2022/05/GHSA-47g7-45f4-j83m/GHSA-47g7-45f4-j83m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47jj-pq3c-8pjm/GHSA-47jj-pq3c-8pjm.json b/advisories/unreviewed/2022/05/GHSA-47jj-pq3c-8pjm/GHSA-47jj-pq3c-8pjm.json index 38c82dc9920..7a336069bd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-47jj-pq3c-8pjm/GHSA-47jj-pq3c-8pjm.json +++ b/advisories/unreviewed/2022/05/GHSA-47jj-pq3c-8pjm/GHSA-47jj-pq3c-8pjm.json @@ -7,12 +7,8 @@ "CVE-2007-2702" ], "details": "Cross-site scripting (XSS) vulnerability in the GroupSpace application in BEA WebLogic Portal 9.2 GA allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the rich text editor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4845-x49f-5m4r/GHSA-4845-x49f-5m4r.json b/advisories/unreviewed/2022/05/GHSA-4845-x49f-5m4r/GHSA-4845-x49f-5m4r.json index 2eed242cddc..f7fc14fe750 100644 --- a/advisories/unreviewed/2022/05/GHSA-4845-x49f-5m4r/GHSA-4845-x49f-5m4r.json +++ b/advisories/unreviewed/2022/05/GHSA-4845-x49f-5m4r/GHSA-4845-x49f-5m4r.json @@ -7,12 +7,8 @@ "CVE-2007-2724" ], "details": "Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web script or HTML via the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-484m-c8g4-232f/GHSA-484m-c8g4-232f.json b/advisories/unreviewed/2022/05/GHSA-484m-c8g4-232f/GHSA-484m-c8g4-232f.json index d9255ca9b4b..039aeb94ad5 100644 --- a/advisories/unreviewed/2022/05/GHSA-484m-c8g4-232f/GHSA-484m-c8g4-232f.json +++ b/advisories/unreviewed/2022/05/GHSA-484m-c8g4-232f/GHSA-484m-c8g4-232f.json @@ -7,12 +7,8 @@ "CVE-2019-10848" ], "details": "Computrols CBAS 18.0.0 allows Username Enumeration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48c8-gm7m-5q7v/GHSA-48c8-gm7m-5q7v.json b/advisories/unreviewed/2022/05/GHSA-48c8-gm7m-5q7v/GHSA-48c8-gm7m-5q7v.json index d84fc5f73b7..5de54a0be42 100644 --- a/advisories/unreviewed/2022/05/GHSA-48c8-gm7m-5q7v/GHSA-48c8-gm7m-5q7v.json +++ b/advisories/unreviewed/2022/05/GHSA-48c8-gm7m-5q7v/GHSA-48c8-gm7m-5q7v.json @@ -7,12 +7,8 @@ "CVE-2007-2782" ], "details": "Packeteer PacketShaper uses fixed increments in TCP initial sequence number (ISN) values, which allows remote attackers to predict the ISN value, and perform session hijacking or disruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48vm-j68p-34jm/GHSA-48vm-j68p-34jm.json b/advisories/unreviewed/2022/05/GHSA-48vm-j68p-34jm/GHSA-48vm-j68p-34jm.json index 324b4be05e2..1a3f7dc84bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-48vm-j68p-34jm/GHSA-48vm-j68p-34jm.json +++ b/advisories/unreviewed/2022/05/GHSA-48vm-j68p-34jm/GHSA-48vm-j68p-34jm.json @@ -7,12 +7,8 @@ "CVE-2007-2969" ], "details": "PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48wf-gfw2-hm84/GHSA-48wf-gfw2-hm84.json b/advisories/unreviewed/2022/05/GHSA-48wf-gfw2-hm84/GHSA-48wf-gfw2-hm84.json index 4605613e3b7..f9ad614f7f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-48wf-gfw2-hm84/GHSA-48wf-gfw2-hm84.json +++ b/advisories/unreviewed/2022/05/GHSA-48wf-gfw2-hm84/GHSA-48wf-gfw2-hm84.json @@ -7,12 +7,8 @@ "CVE-2007-3133" ], "details": "SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4976-43c2-72xp/GHSA-4976-43c2-72xp.json b/advisories/unreviewed/2022/05/GHSA-4976-43c2-72xp/GHSA-4976-43c2-72xp.json index c98149d7d38..88b827d3c46 100644 --- a/advisories/unreviewed/2022/05/GHSA-4976-43c2-72xp/GHSA-4976-43c2-72xp.json +++ b/advisories/unreviewed/2022/05/GHSA-4976-43c2-72xp/GHSA-4976-43c2-72xp.json @@ -7,12 +7,8 @@ "CVE-2017-17060" ], "details": "OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49h7-2wvc-5jgm/GHSA-49h7-2wvc-5jgm.json b/advisories/unreviewed/2022/05/GHSA-49h7-2wvc-5jgm/GHSA-49h7-2wvc-5jgm.json index 02816327ede..5dbd8be47c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-49h7-2wvc-5jgm/GHSA-49h7-2wvc-5jgm.json +++ b/advisories/unreviewed/2022/05/GHSA-49h7-2wvc-5jgm/GHSA-49h7-2wvc-5jgm.json @@ -7,12 +7,8 @@ "CVE-2007-2735" ], "details": "SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id_reserv parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cc9-rg2f-q698/GHSA-4cc9-rg2f-q698.json b/advisories/unreviewed/2022/05/GHSA-4cc9-rg2f-q698/GHSA-4cc9-rg2f-q698.json index b4e5a0b5964..66cdc8585e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cc9-rg2f-q698/GHSA-4cc9-rg2f-q698.json +++ b/advisories/unreviewed/2022/05/GHSA-4cc9-rg2f-q698/GHSA-4cc9-rg2f-q698.json @@ -7,12 +7,8 @@ "CVE-2007-3160" ], "details": "PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f58-4q55-p757/GHSA-4f58-4q55-p757.json b/advisories/unreviewed/2022/05/GHSA-4f58-4q55-p757/GHSA-4f58-4q55-p757.json index dd8ac0d4b23..6674f8bf031 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f58-4q55-p757/GHSA-4f58-4q55-p757.json +++ b/advisories/unreviewed/2022/05/GHSA-4f58-4q55-p757/GHSA-4f58-4q55-p757.json @@ -7,12 +7,8 @@ "CVE-2007-2893" ], "details": "Heap-based buffer overflow in the bx_ne2k_c::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system via vectors that cause TXCNT register values to exceed the device memory size, aka \"RX Frame heap overflow.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f9q-x5w6-mrmh/GHSA-4f9q-x5w6-mrmh.json b/advisories/unreviewed/2022/05/GHSA-4f9q-x5w6-mrmh/GHSA-4f9q-x5w6-mrmh.json index b19b159e9c4..4a1bb1a70e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f9q-x5w6-mrmh/GHSA-4f9q-x5w6-mrmh.json +++ b/advisories/unreviewed/2022/05/GHSA-4f9q-x5w6-mrmh/GHSA-4f9q-x5w6-mrmh.json @@ -7,12 +7,8 @@ "CVE-2007-2733" ], "details": "Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g5w-xvm5-q8wh/GHSA-4g5w-xvm5-q8wh.json b/advisories/unreviewed/2022/05/GHSA-4g5w-xvm5-q8wh/GHSA-4g5w-xvm5-q8wh.json index 5957fd4bed0..9f35eeb6195 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g5w-xvm5-q8wh/GHSA-4g5w-xvm5-q8wh.json +++ b/advisories/unreviewed/2022/05/GHSA-4g5w-xvm5-q8wh/GHSA-4g5w-xvm5-q8wh.json @@ -7,12 +7,8 @@ "CVE-2007-3251" ], "details": "Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the adminlang cookie to admin/functions.php or (2) read arbitrary local files via the img parameter to admin/show_img.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gc8-34fv-2837/GHSA-4gc8-34fv-2837.json b/advisories/unreviewed/2022/05/GHSA-4gc8-34fv-2837/GHSA-4gc8-34fv-2837.json index d11058a7031..f8a6f8f46f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gc8-34fv-2837/GHSA-4gc8-34fv-2837.json +++ b/advisories/unreviewed/2022/05/GHSA-4gc8-34fv-2837/GHSA-4gc8-34fv-2837.json @@ -7,12 +7,8 @@ "CVE-2007-2947" ], "details": "Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gfg-qwj4-89qg/GHSA-4gfg-qwj4-89qg.json b/advisories/unreviewed/2022/05/GHSA-4gfg-qwj4-89qg/GHSA-4gfg-qwj4-89qg.json index 78f6e78c687..56b7ca43ccd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gfg-qwj4-89qg/GHSA-4gfg-qwj4-89qg.json +++ b/advisories/unreviewed/2022/05/GHSA-4gfg-qwj4-89qg/GHSA-4gfg-qwj4-89qg.json @@ -7,12 +7,8 @@ "CVE-2007-2749" ], "details": "SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4j4f-jw3x-9gm3/GHSA-4j4f-jw3x-9gm3.json b/advisories/unreviewed/2022/05/GHSA-4j4f-jw3x-9gm3/GHSA-4j4f-jw3x-9gm3.json index 163ce96561c..791996d3c79 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j4f-jw3x-9gm3/GHSA-4j4f-jw3x-9gm3.json +++ b/advisories/unreviewed/2022/05/GHSA-4j4f-jw3x-9gm3/GHSA-4j4f-jw3x-9gm3.json @@ -7,12 +7,8 @@ "CVE-2007-2727" ], "details": "The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4j84-wchp-pj9r/GHSA-4j84-wchp-pj9r.json b/advisories/unreviewed/2022/05/GHSA-4j84-wchp-pj9r/GHSA-4j84-wchp-pj9r.json index a996e8e598d..73fdefb34d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j84-wchp-pj9r/GHSA-4j84-wchp-pj9r.json +++ b/advisories/unreviewed/2022/05/GHSA-4j84-wchp-pj9r/GHSA-4j84-wchp-pj9r.json @@ -7,12 +7,8 @@ "CVE-2007-3203" ], "details": "Stack-based buffer overflow in smtpdll.dll in the SMTP service in 602Pro LAN SUITE 2003 2003.0.03.0828 allows remote attackers to execute arbitrary code via an e-mail message with a long address. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jhf-wc6q-v8gq/GHSA-4jhf-wc6q-v8gq.json b/advisories/unreviewed/2022/05/GHSA-4jhf-wc6q-v8gq/GHSA-4jhf-wc6q-v8gq.json index 8dea837d116..93cc8cc68ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jhf-wc6q-v8gq/GHSA-4jhf-wc6q-v8gq.json +++ b/advisories/unreviewed/2022/05/GHSA-4jhf-wc6q-v8gq/GHSA-4jhf-wc6q-v8gq.json @@ -7,12 +7,8 @@ "CVE-2019-13977" ], "details": "index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m39-5qw8-66hm/GHSA-4m39-5qw8-66hm.json b/advisories/unreviewed/2022/05/GHSA-4m39-5qw8-66hm/GHSA-4m39-5qw8-66hm.json index 31bb86ac0fb..40bb1221038 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m39-5qw8-66hm/GHSA-4m39-5qw8-66hm.json +++ b/advisories/unreviewed/2022/05/GHSA-4m39-5qw8-66hm/GHSA-4m39-5qw8-66hm.json @@ -7,12 +7,8 @@ "CVE-2007-2714" ], "details": "Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mrv-mjwm-cjf7/GHSA-4mrv-mjwm-cjf7.json b/advisories/unreviewed/2022/05/GHSA-4mrv-mjwm-cjf7/GHSA-4mrv-mjwm-cjf7.json index eafbb44daf8..eee21a5e17c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mrv-mjwm-cjf7/GHSA-4mrv-mjwm-cjf7.json +++ b/advisories/unreviewed/2022/05/GHSA-4mrv-mjwm-cjf7/GHSA-4mrv-mjwm-cjf7.json @@ -7,12 +7,8 @@ "CVE-2007-2966" ], "details": "Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4q2f-5x5g-pwm5/GHSA-4q2f-5x5g-pwm5.json b/advisories/unreviewed/2022/05/GHSA-4q2f-5x5g-pwm5/GHSA-4q2f-5x5g-pwm5.json index 16acba45736..706c380f200 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q2f-5x5g-pwm5/GHSA-4q2f-5x5g-pwm5.json +++ b/advisories/unreviewed/2022/05/GHSA-4q2f-5x5g-pwm5/GHSA-4q2f-5x5g-pwm5.json @@ -7,12 +7,8 @@ "CVE-2007-3047" ], "details": "The Vonage VoIP Telephone Adapter has a default administrator username \"user\" and password \"user,\" which allows remote attackers to obtain administrative access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q5w-6hq6-9x4p/GHSA-4q5w-6hq6-9x4p.json b/advisories/unreviewed/2022/05/GHSA-4q5w-6hq6-9x4p/GHSA-4q5w-6hq6-9x4p.json index dd3ee146204..df74c87ee30 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q5w-6hq6-9x4p/GHSA-4q5w-6hq6-9x4p.json +++ b/advisories/unreviewed/2022/05/GHSA-4q5w-6hq6-9x4p/GHSA-4q5w-6hq6-9x4p.json @@ -7,12 +7,8 @@ "CVE-2007-2784" ], "details": "Unspecified vulnerability in globus-job-manager in Globus Toolkit 4.1.1 and earlier (globus_nexus-6.6 and earlier) allows remote attackers to cause a denial of service (resource exhaustion and system crash) via certain requests to temporary TCP ports for a GRAM2 job or its MPICH-G2 applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rjw-m2mm-7r9g/GHSA-4rjw-m2mm-7r9g.json b/advisories/unreviewed/2022/05/GHSA-4rjw-m2mm-7r9g/GHSA-4rjw-m2mm-7r9g.json index b5a21568d2b..91acd94c6d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rjw-m2mm-7r9g/GHSA-4rjw-m2mm-7r9g.json +++ b/advisories/unreviewed/2022/05/GHSA-4rjw-m2mm-7r9g/GHSA-4rjw-m2mm-7r9g.json @@ -7,12 +7,8 @@ "CVE-2007-3049" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Buttercup web file manager (BWFM) May 2007 allows remote attackers to inject arbitrary web script or HTML via the title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v5r-3fh9-hjh3/GHSA-4v5r-3fh9-hjh3.json b/advisories/unreviewed/2022/05/GHSA-4v5r-3fh9-hjh3/GHSA-4v5r-3fh9-hjh3.json index 1d3f1dbc12d..3cb8235ce88 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v5r-3fh9-hjh3/GHSA-4v5r-3fh9-hjh3.json +++ b/advisories/unreviewed/2022/05/GHSA-4v5r-3fh9-hjh3/GHSA-4v5r-3fh9-hjh3.json @@ -7,12 +7,8 @@ "CVE-2007-2849" ], "details": "KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v9x-p3f6-cp58/GHSA-4v9x-p3f6-cp58.json b/advisories/unreviewed/2022/05/GHSA-4v9x-p3f6-cp58/GHSA-4v9x-p3f6-cp58.json index 0246f92a683..54c8b933387 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v9x-p3f6-cp58/GHSA-4v9x-p3f6-cp58.json +++ b/advisories/unreviewed/2022/05/GHSA-4v9x-p3f6-cp58/GHSA-4v9x-p3f6-cp58.json @@ -7,12 +7,8 @@ "CVE-2007-2717" ], "details": "SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vc4-pm9p-xmjm/GHSA-4vc4-pm9p-xmjm.json b/advisories/unreviewed/2022/05/GHSA-4vc4-pm9p-xmjm/GHSA-4vc4-pm9p-xmjm.json index f3615999ce1..044b9578ca6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vc4-pm9p-xmjm/GHSA-4vc4-pm9p-xmjm.json +++ b/advisories/unreviewed/2022/05/GHSA-4vc4-pm9p-xmjm/GHSA-4vc4-pm9p-xmjm.json @@ -7,12 +7,8 @@ "CVE-2019-12865" ], "details": "In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vhr-6jhx-vf2q/GHSA-4vhr-6jhx-vf2q.json b/advisories/unreviewed/2022/05/GHSA-4vhr-6jhx-vf2q/GHSA-4vhr-6jhx-vf2q.json index 6f0a52b18d4..3a09e517ed3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vhr-6jhx-vf2q/GHSA-4vhr-6jhx-vf2q.json +++ b/advisories/unreviewed/2022/05/GHSA-4vhr-6jhx-vf2q/GHSA-4vhr-6jhx-vf2q.json @@ -7,12 +7,8 @@ "CVE-2007-3126" ], "details": "Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json b/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json index 401645d9859..3ebdf9985b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json +++ b/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w74-rhp7-w923/GHSA-4w74-rhp7-w923.json b/advisories/unreviewed/2022/05/GHSA-4w74-rhp7-w923/GHSA-4w74-rhp7-w923.json index ac047244be1..b8436c26205 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w74-rhp7-w923/GHSA-4w74-rhp7-w923.json +++ b/advisories/unreviewed/2022/05/GHSA-4w74-rhp7-w923/GHSA-4w74-rhp7-w923.json @@ -7,12 +7,8 @@ "CVE-2007-3202" ], "details": "Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wvj-6mmr-g6xj/GHSA-4wvj-6mmr-g6xj.json b/advisories/unreviewed/2022/05/GHSA-4wvj-6mmr-g6xj/GHSA-4wvj-6mmr-g6xj.json index a73cbf5470e..ef2795064e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wvj-6mmr-g6xj/GHSA-4wvj-6mmr-g6xj.json +++ b/advisories/unreviewed/2022/05/GHSA-4wvj-6mmr-g6xj/GHSA-4wvj-6mmr-g6xj.json @@ -7,12 +7,8 @@ "CVE-2007-2918" ], "details": "Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xpg-4j7x-7mgm/GHSA-4xpg-4j7x-7mgm.json b/advisories/unreviewed/2022/05/GHSA-4xpg-4j7x-7mgm/GHSA-4xpg-4j7x-7mgm.json index ec4a1ceb172..cb9c6fa8710 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xpg-4j7x-7mgm/GHSA-4xpg-4j7x-7mgm.json +++ b/advisories/unreviewed/2022/05/GHSA-4xpg-4j7x-7mgm/GHSA-4xpg-4j7x-7mgm.json @@ -7,12 +7,8 @@ "CVE-2007-2759" ], "details": "Multiple SQL injection vulnerabilities in the insert function in the ValuePreference class (grid/ed/ValuePreference.java) in Adempiere before 3.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) m_Attribute or (2) m_Value parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-522h-48w5-75fm/GHSA-522h-48w5-75fm.json b/advisories/unreviewed/2022/05/GHSA-522h-48w5-75fm/GHSA-522h-48w5-75fm.json index 2517cc80fc8..c1d148b4bc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-522h-48w5-75fm/GHSA-522h-48w5-75fm.json +++ b/advisories/unreviewed/2022/05/GHSA-522h-48w5-75fm/GHSA-522h-48w5-75fm.json @@ -7,12 +7,8 @@ "CVE-2007-3008" ], "details": "Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53jq-24h8-vh5c/GHSA-53jq-24h8-vh5c.json b/advisories/unreviewed/2022/05/GHSA-53jq-24h8-vh5c/GHSA-53jq-24h8-vh5c.json index dc11899c1af..07fbae40242 100644 --- a/advisories/unreviewed/2022/05/GHSA-53jq-24h8-vh5c/GHSA-53jq-24h8-vh5c.json +++ b/advisories/unreviewed/2022/05/GHSA-53jq-24h8-vh5c/GHSA-53jq-24h8-vh5c.json @@ -7,12 +7,8 @@ "CVE-2007-2994" ], "details": "SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a fullnews action, a different vector than CVE-2007-0693.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54qp-96v6-w8fj/GHSA-54qp-96v6-w8fj.json b/advisories/unreviewed/2022/05/GHSA-54qp-96v6-w8fj/GHSA-54qp-96v6-w8fj.json index dcf1b036de4..3bfa73443f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-54qp-96v6-w8fj/GHSA-54qp-96v6-w8fj.json +++ b/advisories/unreviewed/2022/05/GHSA-54qp-96v6-w8fj/GHSA-54qp-96v6-w8fj.json @@ -7,12 +7,8 @@ "CVE-2007-3014" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54vh-g6cf-895j/GHSA-54vh-g6cf-895j.json b/advisories/unreviewed/2022/05/GHSA-54vh-g6cf-895j/GHSA-54vh-g6cf-895j.json index 18e4be6f211..06d3923ff58 100644 --- a/advisories/unreviewed/2022/05/GHSA-54vh-g6cf-895j/GHSA-54vh-g6cf-895j.json +++ b/advisories/unreviewed/2022/05/GHSA-54vh-g6cf-895j/GHSA-54vh-g6cf-895j.json @@ -7,12 +7,8 @@ "CVE-2007-3200" ], "details": "NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55g2-9cpw-88hj/GHSA-55g2-9cpw-88hj.json b/advisories/unreviewed/2022/05/GHSA-55g2-9cpw-88hj/GHSA-55g2-9cpw-88hj.json index 79231147b72..0c96a132369 100644 --- a/advisories/unreviewed/2022/05/GHSA-55g2-9cpw-88hj/GHSA-55g2-9cpw-88hj.json +++ b/advisories/unreviewed/2022/05/GHSA-55g2-9cpw-88hj/GHSA-55g2-9cpw-88hj.json @@ -7,12 +7,8 @@ "CVE-2007-3172" ], "details": "Directory traversal vulnerability in demo/pop3/error.php in Uebimiau Webmail allows remote attackers to determine the existence of arbitrary directories via an absolute pathname and .. (dot dot) in the selected_theme parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55hw-334h-rx8x/GHSA-55hw-334h-rx8x.json b/advisories/unreviewed/2022/05/GHSA-55hw-334h-rx8x/GHSA-55hw-334h-rx8x.json index 901945ff6f0..ab568f9cd8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-55hw-334h-rx8x/GHSA-55hw-334h-rx8x.json +++ b/advisories/unreviewed/2022/05/GHSA-55hw-334h-rx8x/GHSA-55hw-334h-rx8x.json @@ -7,12 +7,8 @@ "CVE-2019-12961" ], "details": "LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55v5-p5xp-vc55/GHSA-55v5-p5xp-vc55.json b/advisories/unreviewed/2022/05/GHSA-55v5-p5xp-vc55/GHSA-55v5-p5xp-vc55.json index 0dbf96aff29..0fb297c28fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-55v5-p5xp-vc55/GHSA-55v5-p5xp-vc55.json +++ b/advisories/unreviewed/2022/05/GHSA-55v5-p5xp-vc55/GHSA-55v5-p5xp-vc55.json @@ -7,12 +7,8 @@ "CVE-2007-3147" ], "details": "Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-563c-38v4-f6vp/GHSA-563c-38v4-f6vp.json b/advisories/unreviewed/2022/05/GHSA-563c-38v4-f6vp/GHSA-563c-38v4-f6vp.json index ca8019dc7b5..1d01e315eb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-563c-38v4-f6vp/GHSA-563c-38v4-f6vp.json +++ b/advisories/unreviewed/2022/05/GHSA-563c-38v4-f6vp/GHSA-563c-38v4-f6vp.json @@ -7,12 +7,8 @@ "CVE-2007-2726" ], "details": "BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated \"../A\" or \"A/../\" patterns.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-567j-485w-cxr5/GHSA-567j-485w-cxr5.json b/advisories/unreviewed/2022/05/GHSA-567j-485w-cxr5/GHSA-567j-485w-cxr5.json index b6d68e73832..f5503835194 100644 --- a/advisories/unreviewed/2022/05/GHSA-567j-485w-cxr5/GHSA-567j-485w-cxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-567j-485w-cxr5/GHSA-567j-485w-cxr5.json @@ -7,12 +7,8 @@ "CVE-2007-2927" ], "details": "Unspecified vulnerability in Atheros 802.11 a/b/g wireless adapter drivers before 5.3.0.35, and 6.x before 6.0.3.67, on Windows allows remote attackers to cause a denial of service via a crafted 802.11 management frame.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57f3-hxhr-253c/GHSA-57f3-hxhr-253c.json b/advisories/unreviewed/2022/05/GHSA-57f3-hxhr-253c/GHSA-57f3-hxhr-253c.json index a332dccadd5..9f426de7720 100644 --- a/advisories/unreviewed/2022/05/GHSA-57f3-hxhr-253c/GHSA-57f3-hxhr-253c.json +++ b/advisories/unreviewed/2022/05/GHSA-57f3-hxhr-253c/GHSA-57f3-hxhr-253c.json @@ -7,12 +7,8 @@ "CVE-2007-3180" ], "details": "Buffer overflow in Help and Support Center before 4.4 C on HP Windows systems allows remote attackers to read or write arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57rv-jhpv-gq99/GHSA-57rv-jhpv-gq99.json b/advisories/unreviewed/2022/05/GHSA-57rv-jhpv-gq99/GHSA-57rv-jhpv-gq99.json index fc802cb67c4..08e473fb8a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-57rv-jhpv-gq99/GHSA-57rv-jhpv-gq99.json +++ b/advisories/unreviewed/2022/05/GHSA-57rv-jhpv-gq99/GHSA-57rv-jhpv-gq99.json @@ -7,12 +7,8 @@ "CVE-2007-2802" ], "details": "Cross-site scripting (XSS) vulnerability in cp/ps/Main/login/Login in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the d parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5948-rq4r-74p5/GHSA-5948-rq4r-74p5.json b/advisories/unreviewed/2022/05/GHSA-5948-rq4r-74p5/GHSA-5948-rq4r-74p5.json index 8cbccfbbd1d..479d41472e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5948-rq4r-74p5/GHSA-5948-rq4r-74p5.json +++ b/advisories/unreviewed/2022/05/GHSA-5948-rq4r-74p5/GHSA-5948-rq4r-74p5.json @@ -7,12 +7,8 @@ "CVE-2007-3270" ], "details": "PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59mg-34v2-9hq3/GHSA-59mg-34v2-9hq3.json b/advisories/unreviewed/2022/05/GHSA-59mg-34v2-9hq3/GHSA-59mg-34v2-9hq3.json index d053610a980..df55f2f3407 100644 --- a/advisories/unreviewed/2022/05/GHSA-59mg-34v2-9hq3/GHSA-59mg-34v2-9hq3.json +++ b/advisories/unreviewed/2022/05/GHSA-59mg-34v2-9hq3/GHSA-59mg-34v2-9hq3.json @@ -7,12 +7,8 @@ "CVE-2007-3142" ], "details": "Visual truncation vulnerability in Opera 9.21 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after 34 characters, as demonstrated by a phishing attack using HTTP Basic Authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cgw-m3rf-cfxj/GHSA-5cgw-m3rf-cfxj.json b/advisories/unreviewed/2022/05/GHSA-5cgw-m3rf-cfxj/GHSA-5cgw-m3rf-cfxj.json index d6b6632bc18..9cf44b8be05 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cgw-m3rf-cfxj/GHSA-5cgw-m3rf-cfxj.json +++ b/advisories/unreviewed/2022/05/GHSA-5cgw-m3rf-cfxj/GHSA-5cgw-m3rf-cfxj.json @@ -7,12 +7,8 @@ "CVE-2007-3167" ], "details": "Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to execute arbitrary code via a long PtzUrl property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cpw-9435-x536/GHSA-5cpw-9435-x536.json b/advisories/unreviewed/2022/05/GHSA-5cpw-9435-x536/GHSA-5cpw-9435-x536.json index 7d7fc012cc9..aa39e6639d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cpw-9435-x536/GHSA-5cpw-9435-x536.json +++ b/advisories/unreviewed/2022/05/GHSA-5cpw-9435-x536/GHSA-5cpw-9435-x536.json @@ -7,12 +7,8 @@ "CVE-2007-2906" ], "details": "Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cqh-65ph-mxcx/GHSA-5cqh-65ph-mxcx.json b/advisories/unreviewed/2022/05/GHSA-5cqh-65ph-mxcx/GHSA-5cqh-65ph-mxcx.json index ffbb24fbd19..242f23686cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cqh-65ph-mxcx/GHSA-5cqh-65ph-mxcx.json +++ b/advisories/unreviewed/2022/05/GHSA-5cqh-65ph-mxcx/GHSA-5cqh-65ph-mxcx.json @@ -7,12 +7,8 @@ "CVE-2007-2763" ], "details": "Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in Sienzo Digital Music Mentor (DMM) 2.6.0.4 allows remote attackers to execute arbitrary code via a long string in the second argument, a different issue than CVE-2007-2564.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f5m-56ch-x6w9/GHSA-5f5m-56ch-x6w9.json b/advisories/unreviewed/2022/05/GHSA-5f5m-56ch-x6w9/GHSA-5f5m-56ch-x6w9.json index cb19ec2ed8b..c91e4af4ca3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f5m-56ch-x6w9/GHSA-5f5m-56ch-x6w9.json +++ b/advisories/unreviewed/2022/05/GHSA-5f5m-56ch-x6w9/GHSA-5f5m-56ch-x6w9.json @@ -7,12 +7,8 @@ "CVE-2007-2816" ], "details": "Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php, (7) test2.php, (8) test3.php, (9) test4.php, (10) test5.php, (11) test6.php, (12) frames1_left.php, and (13) frames1_center.php in themes/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f5w-qmh6-6cwf/GHSA-5f5w-qmh6-6cwf.json b/advisories/unreviewed/2022/05/GHSA-5f5w-qmh6-6cwf/GHSA-5f5w-qmh6-6cwf.json index 41fa20338c8..b1b8299d87d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f5w-qmh6-6cwf/GHSA-5f5w-qmh6-6cwf.json +++ b/advisories/unreviewed/2022/05/GHSA-5f5w-qmh6-6cwf/GHSA-5f5w-qmh6-6cwf.json @@ -7,12 +7,8 @@ "CVE-2007-3104" ], "details": "The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributions, allows users to cause a denial of service (kernel OOPS) by dereferencing a null pointer to an inode in a dentry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fh4-xfhx-rv3x/GHSA-5fh4-xfhx-rv3x.json b/advisories/unreviewed/2022/05/GHSA-5fh4-xfhx-rv3x/GHSA-5fh4-xfhx-rv3x.json index 693ad9bd668..aa7aaf91e78 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fh4-xfhx-rv3x/GHSA-5fh4-xfhx-rv3x.json +++ b/advisories/unreviewed/2022/05/GHSA-5fh4-xfhx-rv3x/GHSA-5fh4-xfhx-rv3x.json @@ -7,12 +7,8 @@ "CVE-2007-2818" ], "details": "Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the strJobIDs parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hhv-2pjm-ghc2/GHSA-5hhv-2pjm-ghc2.json b/advisories/unreviewed/2022/05/GHSA-5hhv-2pjm-ghc2/GHSA-5hhv-2pjm-ghc2.json index fd1f88c619b..485b6d31781 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hhv-2pjm-ghc2/GHSA-5hhv-2pjm-ghc2.json +++ b/advisories/unreviewed/2022/05/GHSA-5hhv-2pjm-ghc2/GHSA-5hhv-2pjm-ghc2.json @@ -7,12 +7,8 @@ "CVE-2007-2950" ], "details": "Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hvq-2wj6-mp7m/GHSA-5hvq-2wj6-mp7m.json b/advisories/unreviewed/2022/05/GHSA-5hvq-2wj6-mp7m/GHSA-5hvq-2wj6-mp7m.json index 0b16e2890dc..7d14476eea6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hvq-2wj6-mp7m/GHSA-5hvq-2wj6-mp7m.json +++ b/advisories/unreviewed/2022/05/GHSA-5hvq-2wj6-mp7m/GHSA-5hvq-2wj6-mp7m.json @@ -7,12 +7,8 @@ "CVE-2007-2781" ], "details": "Cross-site scripting (XSS) vulnerability in include/sessionRegister.php in WikyBlog before 1.4.13 allows remote attackers to inject arbitrary web script or HTML, probably via vectors related to a certain data2 array element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jh3-6rj9-m2g2/GHSA-5jh3-6rj9-m2g2.json b/advisories/unreviewed/2022/05/GHSA-5jh3-6rj9-m2g2/GHSA-5jh3-6rj9-m2g2.json index 663f05aa4fd..d0139db50cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jh3-6rj9-m2g2/GHSA-5jh3-6rj9-m2g2.json +++ b/advisories/unreviewed/2022/05/GHSA-5jh3-6rj9-m2g2/GHSA-5jh3-6rj9-m2g2.json @@ -7,12 +7,8 @@ "CVE-2007-2987" ], "details": "Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) DebugMsgLog or (2) DoFileProperties methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m34-c4j8-7mfx/GHSA-5m34-c4j8-7mfx.json b/advisories/unreviewed/2022/05/GHSA-5m34-c4j8-7mfx/GHSA-5m34-c4j8-7mfx.json index 6ca790f7e2c..5ca60869abd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m34-c4j8-7mfx/GHSA-5m34-c4j8-7mfx.json +++ b/advisories/unreviewed/2022/05/GHSA-5m34-c4j8-7mfx/GHSA-5m34-c4j8-7mfx.json @@ -7,12 +7,8 @@ "CVE-2007-2965" ], "details": "Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request packet (IRP), related to IOCTL (Input/Output Control) and \"access validation of the address space.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mjm-4r4g-qvjq/GHSA-5mjm-4r4g-qvjq.json b/advisories/unreviewed/2022/05/GHSA-5mjm-4r4g-qvjq/GHSA-5mjm-4r4g-qvjq.json index d65ae56c4bc..aa4a79d37c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mjm-4r4g-qvjq/GHSA-5mjm-4r4g-qvjq.json +++ b/advisories/unreviewed/2022/05/GHSA-5mjm-4r4g-qvjq/GHSA-5mjm-4r4g-qvjq.json @@ -7,12 +7,8 @@ "CVE-2007-2729" ], "details": "Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mv8-f7x7-hxw9/GHSA-5mv8-f7x7-hxw9.json b/advisories/unreviewed/2022/05/GHSA-5mv8-f7x7-hxw9/GHSA-5mv8-f7x7-hxw9.json index b123da1287e..ac39bc92973 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mv8-f7x7-hxw9/GHSA-5mv8-f7x7-hxw9.json +++ b/advisories/unreviewed/2022/05/GHSA-5mv8-f7x7-hxw9/GHSA-5mv8-f7x7-hxw9.json @@ -7,12 +7,8 @@ "CVE-2007-2908" ], "details": "Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pvj-vp73-v747/GHSA-5pvj-vp73-v747.json b/advisories/unreviewed/2022/05/GHSA-5pvj-vp73-v747/GHSA-5pvj-vp73-v747.json index c39667ac819..3b5960293f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pvj-vp73-v747/GHSA-5pvj-vp73-v747.json +++ b/advisories/unreviewed/2022/05/GHSA-5pvj-vp73-v747/GHSA-5pvj-vp73-v747.json @@ -7,12 +7,8 @@ "CVE-2007-2705" ], "details": "Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through SP6, when \"deployed in an exploded format,\" allows remote attackers to list a WebLogic Workshop Directory (wlwdir) parent directory via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q24-x96v-89c5/GHSA-5q24-x96v-89c5.json b/advisories/unreviewed/2022/05/GHSA-5q24-x96v-89c5/GHSA-5q24-x96v-89c5.json index 108d9582cd3..e44b81ee393 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q24-x96v-89c5/GHSA-5q24-x96v-89c5.json +++ b/advisories/unreviewed/2022/05/GHSA-5q24-x96v-89c5/GHSA-5q24-x96v-89c5.json @@ -7,12 +7,8 @@ "CVE-2007-2905" ], "details": "SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the post_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q87-vwr4-8q5m/GHSA-5q87-vwr4-8q5m.json b/advisories/unreviewed/2022/05/GHSA-5q87-vwr4-8q5m/GHSA-5q87-vwr4-8q5m.json index a4ff782bfa2..a6bad766be7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q87-vwr4-8q5m/GHSA-5q87-vwr4-8q5m.json +++ b/advisories/unreviewed/2022/05/GHSA-5q87-vwr4-8q5m/GHSA-5q87-vwr4-8q5m.json @@ -7,12 +7,8 @@ "CVE-2007-2796" ], "details": "Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IP option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qf9-hm4c-wq4h/GHSA-5qf9-hm4c-wq4h.json b/advisories/unreviewed/2022/05/GHSA-5qf9-hm4c-wq4h/GHSA-5qf9-hm4c-wq4h.json index 90c5f8d4e40..51234f2e648 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qf9-hm4c-wq4h/GHSA-5qf9-hm4c-wq4h.json +++ b/advisories/unreviewed/2022/05/GHSA-5qf9-hm4c-wq4h/GHSA-5qf9-hm4c-wq4h.json @@ -7,12 +7,8 @@ "CVE-2007-2862" ], "details": "Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an include directory, related to missing sanitization of the $option variable and possibly cookie modification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qg9-jjv7-fhcw/GHSA-5qg9-jjv7-fhcw.json b/advisories/unreviewed/2022/05/GHSA-5qg9-jjv7-fhcw/GHSA-5qg9-jjv7-fhcw.json index 15997539f98..c820b11d3ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qg9-jjv7-fhcw/GHSA-5qg9-jjv7-fhcw.json +++ b/advisories/unreviewed/2022/05/GHSA-5qg9-jjv7-fhcw/GHSA-5qg9-jjv7-fhcw.json @@ -7,12 +7,8 @@ "CVE-2007-3137" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qhh-6wc6-7j7p/GHSA-5qhh-6wc6-7j7p.json b/advisories/unreviewed/2022/05/GHSA-5qhh-6wc6-7j7p/GHSA-5qhh-6wc6-7j7p.json index 806a0d117e0..2f856c1d82b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qhh-6wc6-7j7p/GHSA-5qhh-6wc6-7j7p.json +++ b/advisories/unreviewed/2022/05/GHSA-5qhh-6wc6-7j7p/GHSA-5qhh-6wc6-7j7p.json @@ -7,12 +7,8 @@ "CVE-2007-3027" ], "details": "Race condition in Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to install multiple language packs in a way that triggers memory corruption, aka \"Language Pack Installation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r42-m99q-q58f/GHSA-5r42-m99q-q58f.json b/advisories/unreviewed/2022/05/GHSA-5r42-m99q-q58f/GHSA-5r42-m99q-q58f.json index 938c39fbf0c..37d7d69a594 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r42-m99q-q58f/GHSA-5r42-m99q-q58f.json +++ b/advisories/unreviewed/2022/05/GHSA-5r42-m99q-q58f/GHSA-5r42-m99q-q58f.json @@ -7,12 +7,8 @@ "CVE-2007-2916" ], "details": "Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music Distro 1.2 allows remote attackers to inject arbitrary web script or HTML via the st parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rj7-r576-8c8h/GHSA-5rj7-r576-8c8h.json b/advisories/unreviewed/2022/05/GHSA-5rj7-r576-8c8h/GHSA-5rj7-r576-8c8h.json index cae0e6cbd00..db5870407cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rj7-r576-8c8h/GHSA-5rj7-r576-8c8h.json +++ b/advisories/unreviewed/2022/05/GHSA-5rj7-r576-8c8h/GHSA-5rj7-r576-8c8h.json @@ -7,12 +7,8 @@ "CVE-2007-2928" ], "details": "Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wgc-pxqv-7226/GHSA-5wgc-pxqv-7226.json b/advisories/unreviewed/2022/05/GHSA-5wgc-pxqv-7226/GHSA-5wgc-pxqv-7226.json index db60a876a2b..211c0fc423a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wgc-pxqv-7226/GHSA-5wgc-pxqv-7226.json +++ b/advisories/unreviewed/2022/05/GHSA-5wgc-pxqv-7226/GHSA-5wgc-pxqv-7226.json @@ -7,12 +7,8 @@ "CVE-2007-2712" ], "details": "Unspecified vulnerability in MH Software Connect Daily before 3.3.3 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x93-92vm-jw5m/GHSA-5x93-92vm-jw5m.json b/advisories/unreviewed/2022/05/GHSA-5x93-92vm-jw5m/GHSA-5x93-92vm-jw5m.json index 56b8c4b249d..1284ac9de86 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x93-92vm-jw5m/GHSA-5x93-92vm-jw5m.json +++ b/advisories/unreviewed/2022/05/GHSA-5x93-92vm-jw5m/GHSA-5x93-92vm-jw5m.json @@ -7,12 +7,8 @@ "CVE-2019-12735" ], "details": "getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63cx-4687-wjvx/GHSA-63cx-4687-wjvx.json b/advisories/unreviewed/2022/05/GHSA-63cx-4687-wjvx/GHSA-63cx-4687-wjvx.json index a62c57c4b9a..d238476c80c 100644 --- a/advisories/unreviewed/2022/05/GHSA-63cx-4687-wjvx/GHSA-63cx-4687-wjvx.json +++ b/advisories/unreviewed/2022/05/GHSA-63cx-4687-wjvx/GHSA-63cx-4687-wjvx.json @@ -7,12 +7,8 @@ "CVE-2007-2694" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0 GA, and 9.1 GA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6492-5m8p-9p4g/GHSA-6492-5m8p-9p4g.json b/advisories/unreviewed/2022/05/GHSA-6492-5m8p-9p4g/GHSA-6492-5m8p-9p4g.json index 9afc5b091e0..250d589cdf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6492-5m8p-9p4g/GHSA-6492-5m8p-9p4g.json +++ b/advisories/unreviewed/2022/05/GHSA-6492-5m8p-9p4g/GHSA-6492-5m8p-9p4g.json @@ -7,12 +7,8 @@ "CVE-2017-11738" ], "details": "In Zoho ManageEngine Application Manager 13.1 Build 13100, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64m4-j593-v86j/GHSA-64m4-j593-v86j.json b/advisories/unreviewed/2022/05/GHSA-64m4-j593-v86j/GHSA-64m4-j593-v86j.json index c65c8c893fb..12dc68c37cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-64m4-j593-v86j/GHSA-64m4-j593-v86j.json +++ b/advisories/unreviewed/2022/05/GHSA-64m4-j593-v86j/GHSA-64m4-j593-v86j.json @@ -7,12 +7,8 @@ "CVE-2007-2770" ], "details": "Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning about a possible buffer overflow exploit to trigger this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65rw-2rrx-gqv4/GHSA-65rw-2rrx-gqv4.json b/advisories/unreviewed/2022/05/GHSA-65rw-2rrx-gqv4/GHSA-65rw-2rrx-gqv4.json index 3ac99c2f517..ff586da3f84 100644 --- a/advisories/unreviewed/2022/05/GHSA-65rw-2rrx-gqv4/GHSA-65rw-2rrx-gqv4.json +++ b/advisories/unreviewed/2022/05/GHSA-65rw-2rrx-gqv4/GHSA-65rw-2rrx-gqv4.json @@ -7,12 +7,8 @@ "CVE-2019-12457" ], "details": "FileRun 2019.05.21 allows images/extjs Directory Listing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6746-wpr7-g7jp/GHSA-6746-wpr7-g7jp.json b/advisories/unreviewed/2022/05/GHSA-6746-wpr7-g7jp/GHSA-6746-wpr7-g7jp.json index ba6e6792961..a7bc8917ebd 100644 --- a/advisories/unreviewed/2022/05/GHSA-6746-wpr7-g7jp/GHSA-6746-wpr7-g7jp.json +++ b/advisories/unreviewed/2022/05/GHSA-6746-wpr7-g7jp/GHSA-6746-wpr7-g7jp.json @@ -7,12 +7,8 @@ "CVE-2007-3145" ], "details": "Visual truncation vulnerability in Galeon 2.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c4m-qwcg-cwgv/GHSA-6c4m-qwcg-cwgv.json b/advisories/unreviewed/2022/05/GHSA-6c4m-qwcg-cwgv/GHSA-6c4m-qwcg-cwgv.json index 9bc313b4d77..cb896c1acd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c4m-qwcg-cwgv/GHSA-6c4m-qwcg-cwgv.json +++ b/advisories/unreviewed/2022/05/GHSA-6c4m-qwcg-cwgv/GHSA-6c4m-qwcg-cwgv.json @@ -7,12 +7,8 @@ "CVE-2007-2857" ], "details": "PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c7j-gh7x-rw3h/GHSA-6c7j-gh7x-rw3h.json b/advisories/unreviewed/2022/05/GHSA-6c7j-gh7x-rw3h/GHSA-6c7j-gh7x-rw3h.json index ab2f57286bb..62561e8978c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c7j-gh7x-rw3h/GHSA-6c7j-gh7x-rw3h.json +++ b/advisories/unreviewed/2022/05/GHSA-6c7j-gh7x-rw3h/GHSA-6c7j-gh7x-rw3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c8f-vwhh-x9ch/GHSA-6c8f-vwhh-x9ch.json b/advisories/unreviewed/2022/05/GHSA-6c8f-vwhh-x9ch/GHSA-6c8f-vwhh-x9ch.json index acffb219737..56a47d1fb7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c8f-vwhh-x9ch/GHSA-6c8f-vwhh-x9ch.json +++ b/advisories/unreviewed/2022/05/GHSA-6c8f-vwhh-x9ch/GHSA-6c8f-vwhh-x9ch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cg2-v7g4-7r8c/GHSA-6cg2-v7g4-7r8c.json b/advisories/unreviewed/2022/05/GHSA-6cg2-v7g4-7r8c/GHSA-6cg2-v7g4-7r8c.json index 55016baff09..43fe81f2453 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cg2-v7g4-7r8c/GHSA-6cg2-v7g4-7r8c.json +++ b/advisories/unreviewed/2022/05/GHSA-6cg2-v7g4-7r8c/GHSA-6cg2-v7g4-7r8c.json @@ -7,12 +7,8 @@ "CVE-2007-3037" ], "details": "Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based buffer overflow, aka \"Windows Media Player Code Execution Vulnerability Parsing Skins.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6ch6-7fx5-4326/GHSA-6ch6-7fx5-4326.json b/advisories/unreviewed/2022/05/GHSA-6ch6-7fx5-4326/GHSA-6ch6-7fx5-4326.json index c8e8e171e79..cd751f73be8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ch6-7fx5-4326/GHSA-6ch6-7fx5-4326.json +++ b/advisories/unreviewed/2022/05/GHSA-6ch6-7fx5-4326/GHSA-6ch6-7fx5-4326.json @@ -7,12 +7,8 @@ "CVE-2007-2903" ], "details": "Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6chh-6wqr-3697/GHSA-6chh-6wqr-3697.json b/advisories/unreviewed/2022/05/GHSA-6chh-6wqr-3697/GHSA-6chh-6wqr-3697.json index 83f87f3c9b9..30ac9fecc5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6chh-6wqr-3697/GHSA-6chh-6wqr-3697.json +++ b/advisories/unreviewed/2022/05/GHSA-6chh-6wqr-3697/GHSA-6chh-6wqr-3697.json @@ -7,12 +7,8 @@ "CVE-2019-10967" ], "details": "In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f8p-6cw3-m7m5/GHSA-6f8p-6cw3-m7m5.json b/advisories/unreviewed/2022/05/GHSA-6f8p-6cw3-m7m5/GHSA-6f8p-6cw3-m7m5.json index ac31b26ce0b..a2d9389c3f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f8p-6cw3-m7m5/GHSA-6f8p-6cw3-m7m5.json +++ b/advisories/unreviewed/2022/05/GHSA-6f8p-6cw3-m7m5/GHSA-6f8p-6cw3-m7m5.json @@ -7,12 +7,8 @@ "CVE-2007-3052" ], "details": "SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gg9-j293-hp7q/GHSA-6gg9-j293-hp7q.json b/advisories/unreviewed/2022/05/GHSA-6gg9-j293-hp7q/GHSA-6gg9-j293-hp7q.json index 1d743fe6dd5..b8bbce4ffcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gg9-j293-hp7q/GHSA-6gg9-j293-hp7q.json +++ b/advisories/unreviewed/2022/05/GHSA-6gg9-j293-hp7q/GHSA-6gg9-j293-hp7q.json @@ -7,12 +7,8 @@ "CVE-2019-7956" ], "details": "Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gjf-xqgg-vxr8/GHSA-6gjf-xqgg-vxr8.json b/advisories/unreviewed/2022/05/GHSA-6gjf-xqgg-vxr8/GHSA-6gjf-xqgg-vxr8.json index 87511d8648a..e0e820bb567 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gjf-xqgg-vxr8/GHSA-6gjf-xqgg-vxr8.json +++ b/advisories/unreviewed/2022/05/GHSA-6gjf-xqgg-vxr8/GHSA-6gjf-xqgg-vxr8.json @@ -7,12 +7,8 @@ "CVE-2007-2878" ], "details": "The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gx3-qg8f-9vmw/GHSA-6gx3-qg8f-9vmw.json b/advisories/unreviewed/2022/05/GHSA-6gx3-qg8f-9vmw/GHSA-6gx3-qg8f-9vmw.json index ee358d76907..37d121553de 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gx3-qg8f-9vmw/GHSA-6gx3-qg8f-9vmw.json +++ b/advisories/unreviewed/2022/05/GHSA-6gx3-qg8f-9vmw/GHSA-6gx3-qg8f-9vmw.json @@ -7,12 +7,8 @@ "CVE-2007-2973" ], "details": "Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed TAR archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j56-64r4-665f/GHSA-6j56-64r4-665f.json b/advisories/unreviewed/2022/05/GHSA-6j56-64r4-665f/GHSA-6j56-64r4-665f.json index eef44eda3f8..180c014e64a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j56-64r4-665f/GHSA-6j56-64r4-665f.json +++ b/advisories/unreviewed/2022/05/GHSA-6j56-64r4-665f/GHSA-6j56-64r4-665f.json @@ -7,12 +7,8 @@ "CVE-2007-3121" ], "details": "Buffer overflow in the CCdecode function in contrib/ntsc-cc.c in the zvbi-ntsc-cc tool in Zapping VBI Library (ZVBI) before 0.2.25 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long data during a reception error. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6m47-ccpp-66vx/GHSA-6m47-ccpp-66vx.json b/advisories/unreviewed/2022/05/GHSA-6m47-ccpp-66vx/GHSA-6m47-ccpp-66vx.json index e97e9cd52ce..b7f8b438dc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m47-ccpp-66vx/GHSA-6m47-ccpp-66vx.json +++ b/advisories/unreviewed/2022/05/GHSA-6m47-ccpp-66vx/GHSA-6m47-ccpp-66vx.json @@ -7,12 +7,8 @@ "CVE-2007-3267" ], "details": "Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6m7m-rcm4-5f85/GHSA-6m7m-rcm4-5f85.json b/advisories/unreviewed/2022/05/GHSA-6m7m-rcm4-5f85/GHSA-6m7m-rcm4-5f85.json index e2051f3385a..041efc28ef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m7m-rcm4-5f85/GHSA-6m7m-rcm4-5f85.json +++ b/advisories/unreviewed/2022/05/GHSA-6m7m-rcm4-5f85/GHSA-6m7m-rcm4-5f85.json @@ -7,12 +7,8 @@ "CVE-2007-2750" ], "details": "SQL injection vulnerability in print.php in SimpNews 2.40.01 and earlier allows remote attackers to execute arbitrary SQL commands via the newsnr parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mjp-x9f5-mxvr/GHSA-6mjp-x9f5-mxvr.json b/advisories/unreviewed/2022/05/GHSA-6mjp-x9f5-mxvr/GHSA-6mjp-x9f5-mxvr.json index 9e094f78452..7323fcd5319 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mjp-x9f5-mxvr/GHSA-6mjp-x9f5-mxvr.json +++ b/advisories/unreviewed/2022/05/GHSA-6mjp-x9f5-mxvr/GHSA-6mjp-x9f5-mxvr.json @@ -7,12 +7,8 @@ "CVE-2007-2709" ], "details": "PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mq6-hxrx-fj5v/GHSA-6mq6-hxrx-fj5v.json b/advisories/unreviewed/2022/05/GHSA-6mq6-hxrx-fj5v/GHSA-6mq6-hxrx-fj5v.json index 8e2a4876773..3b7cf0272d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mq6-hxrx-fj5v/GHSA-6mq6-hxrx-fj5v.json +++ b/advisories/unreviewed/2022/05/GHSA-6mq6-hxrx-fj5v/GHSA-6mq6-hxrx-fj5v.json @@ -7,12 +7,8 @@ "CVE-2007-2852" ], "details": "Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p3j-529j-2cwq/GHSA-6p3j-529j-2cwq.json b/advisories/unreviewed/2022/05/GHSA-6p3j-529j-2cwq/GHSA-6p3j-529j-2cwq.json index 4a5a7f54894..fc7d1f02bdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p3j-529j-2cwq/GHSA-6p3j-529j-2cwq.json +++ b/advisories/unreviewed/2022/05/GHSA-6p3j-529j-2cwq/GHSA-6p3j-529j-2cwq.json @@ -7,12 +7,8 @@ "CVE-2007-3017" ], "details": "The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qmf-r9mg-qg6v/GHSA-6qmf-r9mg-qg6v.json b/advisories/unreviewed/2022/05/GHSA-6qmf-r9mg-qg6v/GHSA-6qmf-r9mg-qg6v.json index 99b167d5a71..3afe50950b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qmf-r9mg-qg6v/GHSA-6qmf-r9mg-qg6v.json +++ b/advisories/unreviewed/2022/05/GHSA-6qmf-r9mg-qg6v/GHSA-6qmf-r9mg-qg6v.json @@ -7,12 +7,8 @@ "CVE-2007-3176" ], "details": "Unspecified vulnerability in Ingate Firewall and SIParator before 4.5.2 allows remote authenticated users without full privileges to download a Support Report.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qp6-cqhg-xcrm/GHSA-6qp6-cqhg-xcrm.json b/advisories/unreviewed/2022/05/GHSA-6qp6-cqhg-xcrm/GHSA-6qp6-cqhg-xcrm.json index d51caf95d16..6e1f73e2100 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qp6-cqhg-xcrm/GHSA-6qp6-cqhg-xcrm.json +++ b/advisories/unreviewed/2022/05/GHSA-6qp6-cqhg-xcrm/GHSA-6qp6-cqhg-xcrm.json @@ -7,12 +7,8 @@ "CVE-2007-2716" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) listmembers.php and (2) stats.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qvq-hqc7-q3cj/GHSA-6qvq-hqc7-q3cj.json b/advisories/unreviewed/2022/05/GHSA-6qvq-hqc7-q3cj/GHSA-6qvq-hqc7-q3cj.json index 43ecc38bb85..63743a9abbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qvq-hqc7-q3cj/GHSA-6qvq-hqc7-q3cj.json +++ b/advisories/unreviewed/2022/05/GHSA-6qvq-hqc7-q3cj/GHSA-6qvq-hqc7-q3cj.json @@ -7,12 +7,8 @@ "CVE-2007-2856" ], "details": "Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r98-74p7-26hq/GHSA-6r98-74p7-26hq.json b/advisories/unreviewed/2022/05/GHSA-6r98-74p7-26hq/GHSA-6r98-74p7-26hq.json index 0594dd6d33d..051dbf6594a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r98-74p7-26hq/GHSA-6r98-74p7-26hq.json +++ b/advisories/unreviewed/2022/05/GHSA-6r98-74p7-26hq/GHSA-6r98-74p7-26hq.json @@ -7,12 +7,8 @@ "CVE-2007-2979" ], "details": "Techno Dreams Web Directory / Search Engine 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w5r-99x5-qx74/GHSA-6w5r-99x5-qx74.json b/advisories/unreviewed/2022/05/GHSA-6w5r-99x5-qx74/GHSA-6w5r-99x5-qx74.json index 5cd0e526900..76c9b96e7c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w5r-99x5-qx74/GHSA-6w5r-99x5-qx74.json +++ b/advisories/unreviewed/2022/05/GHSA-6w5r-99x5-qx74/GHSA-6w5r-99x5-qx74.json @@ -7,12 +7,8 @@ "CVE-2007-3148" ], "details": "Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w73-7qpj-v2vh/GHSA-6w73-7qpj-v2vh.json b/advisories/unreviewed/2022/05/GHSA-6w73-7qpj-v2vh/GHSA-6w73-7qpj-v2vh.json index 7a601e4cbba..6ee0939a94f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w73-7qpj-v2vh/GHSA-6w73-7qpj-v2vh.json +++ b/advisories/unreviewed/2022/05/GHSA-6w73-7qpj-v2vh/GHSA-6w73-7qpj-v2vh.json @@ -7,12 +7,8 @@ "CVE-2007-3122" ], "details": "The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wcx-jx84-v629/GHSA-6wcx-jx84-v629.json b/advisories/unreviewed/2022/05/GHSA-6wcx-jx84-v629/GHSA-6wcx-jx84-v629.json index b47bf01fff6..99ebedfe188 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wcx-jx84-v629/GHSA-6wcx-jx84-v629.json +++ b/advisories/unreviewed/2022/05/GHSA-6wcx-jx84-v629/GHSA-6wcx-jx84-v629.json @@ -7,12 +7,8 @@ "CVE-2007-2935" ], "details": "core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dict parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xp2-37x8-82p9/GHSA-6xp2-37x8-82p9.json b/advisories/unreviewed/2022/05/GHSA-6xp2-37x8-82p9/GHSA-6xp2-37x8-82p9.json index 5b29eb484ec..0104cd83655 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xp2-37x8-82p9/GHSA-6xp2-37x8-82p9.json +++ b/advisories/unreviewed/2022/05/GHSA-6xp2-37x8-82p9/GHSA-6xp2-37x8-82p9.json @@ -7,12 +7,8 @@ "CVE-2019-12461" ], "details": "Web Port 1.19.1 allows XSS via the /log type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75rq-v3pc-4j5h/GHSA-75rq-v3pc-4j5h.json b/advisories/unreviewed/2022/05/GHSA-75rq-v3pc-4j5h/GHSA-75rq-v3pc-4j5h.json index ad30ac126b0..d06b741ce1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-75rq-v3pc-4j5h/GHSA-75rq-v3pc-4j5h.json +++ b/advisories/unreviewed/2022/05/GHSA-75rq-v3pc-4j5h/GHSA-75rq-v3pc-4j5h.json @@ -7,12 +7,8 @@ "CVE-2017-5211" ], "details": "Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7662-vxhr-5m52/GHSA-7662-vxhr-5m52.json b/advisories/unreviewed/2022/05/GHSA-7662-vxhr-5m52/GHSA-7662-vxhr-5m52.json index 3bfa532ec0d..ea339f0def3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7662-vxhr-5m52/GHSA-7662-vxhr-5m52.json +++ b/advisories/unreviewed/2022/05/GHSA-7662-vxhr-5m52/GHSA-7662-vxhr-5m52.json @@ -7,12 +7,8 @@ "CVE-2007-3083" ], "details": "Z-Blog 1.7 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for zblog.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76mc-v29j-9797/GHSA-76mc-v29j-9797.json b/advisories/unreviewed/2022/05/GHSA-76mc-v29j-9797/GHSA-76mc-v29j-9797.json index 7f049ac06e5..6764b615369 100644 --- a/advisories/unreviewed/2022/05/GHSA-76mc-v29j-9797/GHSA-76mc-v29j-9797.json +++ b/advisories/unreviewed/2022/05/GHSA-76mc-v29j-9797/GHSA-76mc-v29j-9797.json @@ -7,12 +7,8 @@ "CVE-2007-2976" ], "details": "Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null (\"%00\") character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76r6-9f6m-grxr/GHSA-76r6-9f6m-grxr.json b/advisories/unreviewed/2022/05/GHSA-76r6-9f6m-grxr/GHSA-76r6-9f6m-grxr.json index 56c9221e6a3..f89de1768c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-76r6-9f6m-grxr/GHSA-76r6-9f6m-grxr.json +++ b/advisories/unreviewed/2022/05/GHSA-76r6-9f6m-grxr/GHSA-76r6-9f6m-grxr.json @@ -7,12 +7,8 @@ "CVE-2007-2940" ], "details": "Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76wc-mqwv-wjv2/GHSA-76wc-mqwv-wjv2.json b/advisories/unreviewed/2022/05/GHSA-76wc-mqwv-wjv2/GHSA-76wc-mqwv-wjv2.json index 54823afe8cd..b5e3ba84dae 100644 --- a/advisories/unreviewed/2022/05/GHSA-76wc-mqwv-wjv2/GHSA-76wc-mqwv-wjv2.json +++ b/advisories/unreviewed/2022/05/GHSA-76wc-mqwv-wjv2/GHSA-76wc-mqwv-wjv2.json @@ -7,12 +7,8 @@ "CVE-2007-3149" ], "details": "sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be \"a user, who can already log into your system, and can already use sudo.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77x3-jh2q-2qvx/GHSA-77x3-jh2q-2qvx.json b/advisories/unreviewed/2022/05/GHSA-77x3-jh2q-2qvx/GHSA-77x3-jh2q-2qvx.json index eadfe1a6e3a..f91b0015c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-77x3-jh2q-2qvx/GHSA-77x3-jh2q-2qvx.json +++ b/advisories/unreviewed/2022/05/GHSA-77x3-jh2q-2qvx/GHSA-77x3-jh2q-2qvx.json @@ -7,12 +7,8 @@ "CVE-2007-3152" ], "details": "c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78c4-84wg-rmcr/GHSA-78c4-84wg-rmcr.json b/advisories/unreviewed/2022/05/GHSA-78c4-84wg-rmcr/GHSA-78c4-84wg-rmcr.json index d441d920043..e25bed1c1b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-78c4-84wg-rmcr/GHSA-78c4-84wg-rmcr.json +++ b/advisories/unreviewed/2022/05/GHSA-78c4-84wg-rmcr/GHSA-78c4-84wg-rmcr.json @@ -7,12 +7,8 @@ "CVE-2007-3032" ], "details": "Unspecified vulnerability in Windows Vista Contacts Gadget in Windows Vista allows user-assisted remote attackers to execute arbitrary code via crafted contact information that is not properly handled when it is imported.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79cm-6v35-w78p/GHSA-79cm-6v35-w78p.json b/advisories/unreviewed/2022/05/GHSA-79cm-6v35-w78p/GHSA-79cm-6v35-w78p.json index 2ab3f247ce8..707683ee508 100644 --- a/advisories/unreviewed/2022/05/GHSA-79cm-6v35-w78p/GHSA-79cm-6v35-w78p.json +++ b/advisories/unreviewed/2022/05/GHSA-79cm-6v35-w78p/GHSA-79cm-6v35-w78p.json @@ -7,12 +7,8 @@ "CVE-2007-2941" ], "details": "Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7c33-39g7-9rjm/GHSA-7c33-39g7-9rjm.json b/advisories/unreviewed/2022/05/GHSA-7c33-39g7-9rjm/GHSA-7c33-39g7-9rjm.json index 3ffc6e5612c..b83ffb3ac0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c33-39g7-9rjm/GHSA-7c33-39g7-9rjm.json +++ b/advisories/unreviewed/2022/05/GHSA-7c33-39g7-9rjm/GHSA-7c33-39g7-9rjm.json @@ -7,12 +7,8 @@ "CVE-2007-2768" ], "details": "OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cxq-2xvg-8j3w/GHSA-7cxq-2xvg-8j3w.json b/advisories/unreviewed/2022/05/GHSA-7cxq-2xvg-8j3w/GHSA-7cxq-2xvg-8j3w.json index 57585404314..3f86f779d45 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cxq-2xvg-8j3w/GHSA-7cxq-2xvg-8j3w.json +++ b/advisories/unreviewed/2022/05/GHSA-7cxq-2xvg-8j3w/GHSA-7cxq-2xvg-8j3w.json @@ -7,12 +7,8 @@ "CVE-2007-2892" ], "details": "Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f94-825q-j49j/GHSA-7f94-825q-j49j.json b/advisories/unreviewed/2022/05/GHSA-7f94-825q-j49j/GHSA-7f94-825q-j49j.json index 0d39205f1d5..c2093fdcbbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f94-825q-j49j/GHSA-7f94-825q-j49j.json +++ b/advisories/unreviewed/2022/05/GHSA-7f94-825q-j49j/GHSA-7f94-825q-j49j.json @@ -7,12 +7,8 @@ "CVE-2007-2910" ], "details": "Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml update, a related issue to CVE-2007-2909.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g4v-qxp4-r6gw/GHSA-7g4v-qxp4-r6gw.json b/advisories/unreviewed/2022/05/GHSA-7g4v-qxp4-r6gw/GHSA-7g4v-qxp4-r6gw.json index f38859e8fac..64bd23e9667 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g4v-qxp4-r6gw/GHSA-7g4v-qxp4-r6gw.json +++ b/advisories/unreviewed/2022/05/GHSA-7g4v-qxp4-r6gw/GHSA-7g4v-qxp4-r6gw.json @@ -7,12 +7,8 @@ "CVE-2007-2861" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Simple Accessible XHTML Online News (SAXON) 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the template parameter to (1) news.php, (2) preview.php, or (3) archive-display.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7gcj-qh23-qmgf/GHSA-7gcj-qh23-qmgf.json b/advisories/unreviewed/2022/05/GHSA-7gcj-qh23-qmgf/GHSA-7gcj-qh23-qmgf.json index 3f56b1beadd..d13175487b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gcj-qh23-qmgf/GHSA-7gcj-qh23-qmgf.json +++ b/advisories/unreviewed/2022/05/GHSA-7gcj-qh23-qmgf/GHSA-7gcj-qh23-qmgf.json @@ -7,12 +7,8 @@ "CVE-2007-3139" ], "details": "config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOTE: this can be leveraged to upload and execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hhc-h979-hpwg/GHSA-7hhc-h979-hpwg.json b/advisories/unreviewed/2022/05/GHSA-7hhc-h979-hpwg/GHSA-7hhc-h979-hpwg.json index 77dbd7083cc..feb996eebbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hhc-h979-hpwg/GHSA-7hhc-h979-hpwg.json +++ b/advisories/unreviewed/2022/05/GHSA-7hhc-h979-hpwg/GHSA-7hhc-h979-hpwg.json @@ -7,12 +7,8 @@ "CVE-2007-2853" ], "details": "The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j47-pqh4-2284/GHSA-7j47-pqh4-2284.json b/advisories/unreviewed/2022/05/GHSA-7j47-pqh4-2284/GHSA-7j47-pqh4-2284.json index ed59a4d74df..6d1141f747a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j47-pqh4-2284/GHSA-7j47-pqh4-2284.json +++ b/advisories/unreviewed/2022/05/GHSA-7j47-pqh4-2284/GHSA-7j47-pqh4-2284.json @@ -7,12 +7,8 @@ "CVE-2007-3063" ], "details": "SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7v7m-grfx-ghf2/GHSA-7v7m-grfx-ghf2.json b/advisories/unreviewed/2022/05/GHSA-7v7m-grfx-ghf2/GHSA-7v7m-grfx-ghf2.json index e85ca2891aa..698bbbca6f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v7m-grfx-ghf2/GHSA-7v7m-grfx-ghf2.json +++ b/advisories/unreviewed/2022/05/GHSA-7v7m-grfx-ghf2/GHSA-7v7m-grfx-ghf2.json @@ -7,12 +7,8 @@ "CVE-2007-3158" ], "details": "download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7w8v-wwc3-ghf7/GHSA-7w8v-wwc3-ghf7.json b/advisories/unreviewed/2022/05/GHSA-7w8v-wwc3-ghf7/GHSA-7w8v-wwc3-ghf7.json index 8a2ef972686..25ef37106f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w8v-wwc3-ghf7/GHSA-7w8v-wwc3-ghf7.json +++ b/advisories/unreviewed/2022/05/GHSA-7w8v-wwc3-ghf7/GHSA-7w8v-wwc3-ghf7.json @@ -7,12 +7,8 @@ "CVE-2007-3138" ], "details": "Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an sLanguage cookie, which is used to define a value in config/general.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xh6-3wvw-j67f/GHSA-7xh6-3wvw-j67f.json b/advisories/unreviewed/2022/05/GHSA-7xh6-3wvw-j67f/GHSA-7xh6-3wvw-j67f.json index 65a56965af9..52fea37c60b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xh6-3wvw-j67f/GHSA-7xh6-3wvw-j67f.json +++ b/advisories/unreviewed/2022/05/GHSA-7xh6-3wvw-j67f/GHSA-7xh6-3wvw-j67f.json @@ -7,12 +7,8 @@ "CVE-2007-3159" ], "details": "http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xxc-93r3-wgqh/GHSA-7xxc-93r3-wgqh.json b/advisories/unreviewed/2022/05/GHSA-7xxc-93r3-wgqh/GHSA-7xxc-93r3-wgqh.json index efd7d5e17e4..3ac6abe0da0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xxc-93r3-wgqh/GHSA-7xxc-93r3-wgqh.json +++ b/advisories/unreviewed/2022/05/GHSA-7xxc-93r3-wgqh/GHSA-7xxc-93r3-wgqh.json @@ -7,12 +7,8 @@ "CVE-2007-3060" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to (a) chat.php, (2) LANG[DEFAULT_BRANDING] and (3) PHPLIVE_VERSION parameters to (b) help.php, the (4) admin[name] parameter to (c) admin/header.php, and the (5) BASE_URL parameter to (d) super/info.php, and in some cases, the LANG[DEFAULT_BRANDING], PHPLIVE_VERSION, and (6) nav_line parameters to setup/footer.php, different vectors than CVE-2006-6769.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8328-r6wp-frw2/GHSA-8328-r6wp-frw2.json b/advisories/unreviewed/2022/05/GHSA-8328-r6wp-frw2/GHSA-8328-r6wp-frw2.json index fd3cb71f18c..17da6c4aa55 100644 --- a/advisories/unreviewed/2022/05/GHSA-8328-r6wp-frw2/GHSA-8328-r6wp-frw2.json +++ b/advisories/unreviewed/2022/05/GHSA-8328-r6wp-frw2/GHSA-8328-r6wp-frw2.json @@ -7,12 +7,8 @@ "CVE-2007-2703" ], "details": "BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-84x4-866j-6jxg/GHSA-84x4-866j-6jxg.json b/advisories/unreviewed/2022/05/GHSA-84x4-866j-6jxg/GHSA-84x4-866j-6jxg.json index d527b926d4f..5cd6bdb9a63 100644 --- a/advisories/unreviewed/2022/05/GHSA-84x4-866j-6jxg/GHSA-84x4-866j-6jxg.json +++ b/advisories/unreviewed/2022/05/GHSA-84x4-866j-6jxg/GHSA-84x4-866j-6jxg.json @@ -7,12 +7,8 @@ "CVE-2007-3035" ], "details": "Unspecified vulnerability in Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that is not properly handled during decompression, aka \"Windows Media Player Code Execution Vulnerability Decompressing Skins.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85ch-cqhr-r5qp/GHSA-85ch-cqhr-r5qp.json b/advisories/unreviewed/2022/05/GHSA-85ch-cqhr-r5qp/GHSA-85ch-cqhr-r5qp.json index 4b4bc8be011..a09934ae3d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-85ch-cqhr-r5qp/GHSA-85ch-cqhr-r5qp.json +++ b/advisories/unreviewed/2022/05/GHSA-85ch-cqhr-r5qp/GHSA-85ch-cqhr-r5qp.json @@ -7,12 +7,8 @@ "CVE-2007-2747" ], "details": "Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85mm-pwj3-cp83/GHSA-85mm-pwj3-cp83.json b/advisories/unreviewed/2022/05/GHSA-85mm-pwj3-cp83/GHSA-85mm-pwj3-cp83.json index b57c0ac54b3..f0582aaacef 100644 --- a/advisories/unreviewed/2022/05/GHSA-85mm-pwj3-cp83/GHSA-85mm-pwj3-cp83.json +++ b/advisories/unreviewed/2022/05/GHSA-85mm-pwj3-cp83/GHSA-85mm-pwj3-cp83.json @@ -7,12 +7,8 @@ "CVE-2007-3252" ], "details": "PortalApp stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for 8691.mdb, a different vector than CVE-2004-1786.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8685-7gm6-6pc6/GHSA-8685-7gm6-6pc6.json b/advisories/unreviewed/2022/05/GHSA-8685-7gm6-6pc6/GHSA-8685-7gm6-6pc6.json index 8e9ea0db9b3..b7165b6ed18 100644 --- a/advisories/unreviewed/2022/05/GHSA-8685-7gm6-6pc6/GHSA-8685-7gm6-6pc6.json +++ b/advisories/unreviewed/2022/05/GHSA-8685-7gm6-6pc6/GHSA-8685-7gm6-6pc6.json @@ -7,12 +7,8 @@ "CVE-2007-2982" ], "details": "Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86f6-f7gx-x5qm/GHSA-86f6-f7gx-x5qm.json b/advisories/unreviewed/2022/05/GHSA-86f6-f7gx-x5qm/GHSA-86f6-f7gx-x5qm.json index 2b5ee74d39f..1878f5bcc44 100644 --- a/advisories/unreviewed/2022/05/GHSA-86f6-f7gx-x5qm/GHSA-86f6-f7gx-x5qm.json +++ b/advisories/unreviewed/2022/05/GHSA-86f6-f7gx-x5qm/GHSA-86f6-f7gx-x5qm.json @@ -7,12 +7,8 @@ "CVE-2007-2815" ], "details": "The \"hit-highlighting\" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86qr-6927-cr5c/GHSA-86qr-6927-cr5c.json b/advisories/unreviewed/2022/05/GHSA-86qr-6927-cr5c/GHSA-86qr-6927-cr5c.json index d48650963a5..bc11a712514 100644 --- a/advisories/unreviewed/2022/05/GHSA-86qr-6927-cr5c/GHSA-86qr-6927-cr5c.json +++ b/advisories/unreviewed/2022/05/GHSA-86qr-6927-cr5c/GHSA-86qr-6927-cr5c.json @@ -7,12 +7,8 @@ "CVE-2007-2924" ], "details": "Multiple buffer overflows in RealNetworks GameHouse dldisplay ActiveX control (ghdlctl.dll) allow remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87rf-xcxq-w82r/GHSA-87rf-xcxq-w82r.json b/advisories/unreviewed/2022/05/GHSA-87rf-xcxq-w82r/GHSA-87rf-xcxq-w82r.json index c38082e5be6..762bc4d8408 100644 --- a/advisories/unreviewed/2022/05/GHSA-87rf-xcxq-w82r/GHSA-87rf-xcxq-w82r.json +++ b/advisories/unreviewed/2022/05/GHSA-87rf-xcxq-w82r/GHSA-87rf-xcxq-w82r.json @@ -7,12 +7,8 @@ "CVE-2007-2833" ], "details": "Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8852-2r8v-3mch/GHSA-8852-2r8v-3mch.json b/advisories/unreviewed/2022/05/GHSA-8852-2r8v-3mch/GHSA-8852-2r8v-3mch.json index 0ba648a75bb..9f0428a7396 100644 --- a/advisories/unreviewed/2022/05/GHSA-8852-2r8v-3mch/GHSA-8852-2r8v-3mch.json +++ b/advisories/unreviewed/2022/05/GHSA-8852-2r8v-3mch/GHSA-8852-2r8v-3mch.json @@ -7,12 +7,8 @@ "CVE-2007-2710" ], "details": "PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8977-4jwc-24g8/GHSA-8977-4jwc-24g8.json b/advisories/unreviewed/2022/05/GHSA-8977-4jwc-24g8/GHSA-8977-4jwc-24g8.json index 0a80bb9c6ec..c77b2e51129 100644 --- a/advisories/unreviewed/2022/05/GHSA-8977-4jwc-24g8/GHSA-8977-4jwc-24g8.json +++ b/advisories/unreviewed/2022/05/GHSA-8977-4jwc-24g8/GHSA-8977-4jwc-24g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89ff-6c66-w9m5/GHSA-89ff-6c66-w9m5.json b/advisories/unreviewed/2022/05/GHSA-89ff-6c66-w9m5/GHSA-89ff-6c66-w9m5.json index 52d53458c0b..6987775d8b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-89ff-6c66-w9m5/GHSA-89ff-6c66-w9m5.json +++ b/advisories/unreviewed/2022/05/GHSA-89ff-6c66-w9m5/GHSA-89ff-6c66-w9m5.json @@ -7,12 +7,8 @@ "CVE-2019-12564" ], "details": "In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89rj-vjfv-q48m/GHSA-89rj-vjfv-q48m.json b/advisories/unreviewed/2022/05/GHSA-89rj-vjfv-q48m/GHSA-89rj-vjfv-q48m.json index 6988c5935d1..9cc52838b7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-89rj-vjfv-q48m/GHSA-89rj-vjfv-q48m.json +++ b/advisories/unreviewed/2022/05/GHSA-89rj-vjfv-q48m/GHSA-89rj-vjfv-q48m.json @@ -7,12 +7,8 @@ "CVE-2019-7113" ], "details": "Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8f4j-6g66-v4jj/GHSA-8f4j-6g66-v4jj.json b/advisories/unreviewed/2022/05/GHSA-8f4j-6g66-v4jj/GHSA-8f4j-6g66-v4jj.json index 2f1a6f05bbd..a40a8e0b29c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f4j-6g66-v4jj/GHSA-8f4j-6g66-v4jj.json +++ b/advisories/unreviewed/2022/05/GHSA-8f4j-6g66-v4jj/GHSA-8f4j-6g66-v4jj.json @@ -7,12 +7,8 @@ "CVE-2007-2701" ], "details": "The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a username and password, or when the connection URL is not defined, allows remote attackers to bypass the security access policy and \"send unauthorized messages to a protected queue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fc5-f67m-p222/GHSA-8fc5-f67m-p222.json b/advisories/unreviewed/2022/05/GHSA-8fc5-f67m-p222/GHSA-8fc5-f67m-p222.json index 5a1ea3dd4ad..8e0c1057d5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fc5-f67m-p222/GHSA-8fc5-f67m-p222.json +++ b/advisories/unreviewed/2022/05/GHSA-8fc5-f67m-p222/GHSA-8fc5-f67m-p222.json @@ -7,12 +7,8 @@ "CVE-2007-3092" ], "details": "Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls. NOTE: this issue can be leveraged for phishing and other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gmh-pv77-jhpg/GHSA-8gmh-pv77-jhpg.json b/advisories/unreviewed/2022/05/GHSA-8gmh-pv77-jhpg/GHSA-8gmh-pv77-jhpg.json index f97e2632b48..1552708b1a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gmh-pv77-jhpg/GHSA-8gmh-pv77-jhpg.json +++ b/advisories/unreviewed/2022/05/GHSA-8gmh-pv77-jhpg/GHSA-8gmh-pv77-jhpg.json @@ -7,12 +7,8 @@ "CVE-2007-2793" ], "details": "PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gvv-4642-9f2m/GHSA-8gvv-4642-9f2m.json b/advisories/unreviewed/2022/05/GHSA-8gvv-4642-9f2m/GHSA-8gvv-4642-9f2m.json index 314d331b9a7..f6751a39f50 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gvv-4642-9f2m/GHSA-8gvv-4642-9f2m.json +++ b/advisories/unreviewed/2022/05/GHSA-8gvv-4642-9f2m/GHSA-8gvv-4642-9f2m.json @@ -7,12 +7,8 @@ "CVE-2007-3013" ], "details": "SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h2c-4857-vvxf/GHSA-8h2c-4857-vvxf.json b/advisories/unreviewed/2022/05/GHSA-8h2c-4857-vvxf/GHSA-8h2c-4857-vvxf.json index f648ce0e698..2dfeeec3cfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h2c-4857-vvxf/GHSA-8h2c-4857-vvxf.json +++ b/advisories/unreviewed/2022/05/GHSA-8h2c-4857-vvxf/GHSA-8h2c-4857-vvxf.json @@ -7,12 +7,8 @@ "CVE-2007-2744" ], "details": "Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote attackers to cause a denial of service (Internet Explorer 6 crash), and possibly execute arbitrary code, via a long argument to the SaveBarCode method. NOTE: this issue might overlap CVE-2007-2657.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h4q-hf82-q8rj/GHSA-8h4q-hf82-q8rj.json b/advisories/unreviewed/2022/05/GHSA-8h4q-hf82-q8rj/GHSA-8h4q-hf82-q8rj.json index 816a12ed860..468cc6f9edf 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h4q-hf82-q8rj/GHSA-8h4q-hf82-q8rj.json +++ b/advisories/unreviewed/2022/05/GHSA-8h4q-hf82-q8rj/GHSA-8h4q-hf82-q8rj.json @@ -7,12 +7,8 @@ "CVE-2007-2734" ], "details": "The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8hcp-6984-m9g2/GHSA-8hcp-6984-m9g2.json b/advisories/unreviewed/2022/05/GHSA-8hcp-6984-m9g2/GHSA-8hcp-6984-m9g2.json index 2c4d9504993..8f7ce4bd27a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hcp-6984-m9g2/GHSA-8hcp-6984-m9g2.json +++ b/advisories/unreviewed/2022/05/GHSA-8hcp-6984-m9g2/GHSA-8hcp-6984-m9g2.json @@ -7,12 +7,8 @@ "CVE-2007-2706" ], "details": "PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8hwp-2gqx-7258/GHSA-8hwp-2gqx-7258.json b/advisories/unreviewed/2022/05/GHSA-8hwp-2gqx-7258/GHSA-8hwp-2gqx-7258.json index ed792badc27..2b0443e152d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hwp-2gqx-7258/GHSA-8hwp-2gqx-7258.json +++ b/advisories/unreviewed/2022/05/GHSA-8hwp-2gqx-7258/GHSA-8hwp-2gqx-7258.json @@ -7,12 +7,8 @@ "CVE-2019-1010224" ], "details": "aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash (DoS). The component is: onset. The fixed version is: after commit e4e0861cffbc8d3a53dcd18f9ae85797690d67c7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jxr-w97p-qwwv/GHSA-8jxr-w97p-qwwv.json b/advisories/unreviewed/2022/05/GHSA-8jxr-w97p-qwwv/GHSA-8jxr-w97p-qwwv.json index ffa14eadbf3..ddcb5a71c37 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jxr-w97p-qwwv/GHSA-8jxr-w97p-qwwv.json +++ b/advisories/unreviewed/2022/05/GHSA-8jxr-w97p-qwwv/GHSA-8jxr-w97p-qwwv.json @@ -7,12 +7,8 @@ "CVE-2007-3026" ], "details": "Integer overflow in Panda Software AdminSecure allows remote attackers to execute arbitrary code via crafted packets with modified length values to TCP ports 19226 or 19227, resulting in a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8m5r-mf8j-3hfx/GHSA-8m5r-mf8j-3hfx.json b/advisories/unreviewed/2022/05/GHSA-8m5r-mf8j-3hfx/GHSA-8m5r-mf8j-3hfx.json index 91310c01c76..6839cbba873 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m5r-mf8j-3hfx/GHSA-8m5r-mf8j-3hfx.json +++ b/advisories/unreviewed/2022/05/GHSA-8m5r-mf8j-3hfx/GHSA-8m5r-mf8j-3hfx.json @@ -7,12 +7,8 @@ "CVE-2007-2930" ], "details": "The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -132,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mjq-99fv-7g2j/GHSA-8mjq-99fv-7g2j.json b/advisories/unreviewed/2022/05/GHSA-8mjq-99fv-7g2j/GHSA-8mjq-99fv-7g2j.json index eded997acd3..35a79b25a0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mjq-99fv-7g2j/GHSA-8mjq-99fv-7g2j.json +++ b/advisories/unreviewed/2022/05/GHSA-8mjq-99fv-7g2j/GHSA-8mjq-99fv-7g2j.json @@ -7,12 +7,8 @@ "CVE-2007-3136" ], "details": "PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL in the newsSync_NUKE_PATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mrm-5w2c-vxmx/GHSA-8mrm-5w2c-vxmx.json b/advisories/unreviewed/2022/05/GHSA-8mrm-5w2c-vxmx/GHSA-8mrm-5w2c-vxmx.json index 77fdd17eb68..f419cbe96ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mrm-5w2c-vxmx/GHSA-8mrm-5w2c-vxmx.json +++ b/advisories/unreviewed/2022/05/GHSA-8mrm-5w2c-vxmx/GHSA-8mrm-5w2c-vxmx.json @@ -7,12 +7,8 @@ "CVE-2019-3397" ], "details": "Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q49-xx2f-95qc/GHSA-8q49-xx2f-95qc.json b/advisories/unreviewed/2022/05/GHSA-8q49-xx2f-95qc/GHSA-8q49-xx2f-95qc.json index be15fea3a3e..891190bdb2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q49-xx2f-95qc/GHSA-8q49-xx2f-95qc.json +++ b/advisories/unreviewed/2022/05/GHSA-8q49-xx2f-95qc/GHSA-8q49-xx2f-95qc.json @@ -7,12 +7,8 @@ "CVE-2007-3143" ], "details": "Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r38-vv5x-w6gc/GHSA-8r38-vv5x-w6gc.json b/advisories/unreviewed/2022/05/GHSA-8r38-vv5x-w6gc/GHSA-8r38-vv5x-w6gc.json index 3bba882b3c8..9f7e6eaa03b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r38-vv5x-w6gc/GHSA-8r38-vv5x-w6gc.json +++ b/advisories/unreviewed/2022/05/GHSA-8r38-vv5x-w6gc/GHSA-8r38-vv5x-w6gc.json @@ -7,12 +7,8 @@ "CVE-2017-11740" ], "details": "In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w3g-9w9q-5mjf/GHSA-8w3g-9w9q-5mjf.json b/advisories/unreviewed/2022/05/GHSA-8w3g-9w9q-5mjf/GHSA-8w3g-9w9q-5mjf.json index ce5bc8405a4..4501d3d8a40 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w3g-9w9q-5mjf/GHSA-8w3g-9w9q-5mjf.json +++ b/advisories/unreviewed/2022/05/GHSA-8w3g-9w9q-5mjf/GHSA-8w3g-9w9q-5mjf.json @@ -7,12 +7,8 @@ "CVE-2007-2732" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w8g-mrpm-gm4f/GHSA-8w8g-mrpm-gm4f.json b/advisories/unreviewed/2022/05/GHSA-8w8g-mrpm-gm4f/GHSA-8w8g-mrpm-gm4f.json index ab1a1680027..199e96b833f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w8g-mrpm-gm4f/GHSA-8w8g-mrpm-gm4f.json +++ b/advisories/unreviewed/2022/05/GHSA-8w8g-mrpm-gm4f/GHSA-8w8g-mrpm-gm4f.json @@ -7,12 +7,8 @@ "CVE-2007-2896" ], "details": "Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8whf-2phw-rrxr/GHSA-8whf-2phw-rrxr.json b/advisories/unreviewed/2022/05/GHSA-8whf-2phw-rrxr/GHSA-8whf-2phw-rrxr.json index ebaa629261b..0d03fbf1627 100644 --- a/advisories/unreviewed/2022/05/GHSA-8whf-2phw-rrxr/GHSA-8whf-2phw-rrxr.json +++ b/advisories/unreviewed/2022/05/GHSA-8whf-2phw-rrxr/GHSA-8whf-2phw-rrxr.json @@ -7,12 +7,8 @@ "CVE-2007-2767" ], "details": "Unspecified vulnerability in BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 allows remote attackers to list filesystem contents and obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wp2-w85w-9q24/GHSA-8wp2-w85w-9q24.json b/advisories/unreviewed/2022/05/GHSA-8wp2-w85w-9q24/GHSA-8wp2-w85w-9q24.json index 1877dc573e6..6bf914c3832 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wp2-w85w-9q24/GHSA-8wp2-w85w-9q24.json +++ b/advisories/unreviewed/2022/05/GHSA-8wp2-w85w-9q24/GHSA-8wp2-w85w-9q24.json @@ -7,12 +7,8 @@ "CVE-2019-7941" ], "details": "Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wpj-m56g-3m4r/GHSA-8wpj-m56g-3m4r.json b/advisories/unreviewed/2022/05/GHSA-8wpj-m56g-3m4r/GHSA-8wpj-m56g-3m4r.json index a50a498c590..43b6f405422 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wpj-m56g-3m4r/GHSA-8wpj-m56g-3m4r.json +++ b/advisories/unreviewed/2022/05/GHSA-8wpj-m56g-3m4r/GHSA-8wpj-m56g-3m4r.json @@ -7,12 +7,8 @@ "CVE-2017-5212" ], "details": "Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8x4r-rqvf-7mgm/GHSA-8x4r-rqvf-7mgm.json b/advisories/unreviewed/2022/05/GHSA-8x4r-rqvf-7mgm/GHSA-8x4r-rqvf-7mgm.json index 188793930c1..6b705e931f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x4r-rqvf-7mgm/GHSA-8x4r-rqvf-7mgm.json +++ b/advisories/unreviewed/2022/05/GHSA-8x4r-rqvf-7mgm/GHSA-8x4r-rqvf-7mgm.json @@ -7,12 +7,8 @@ "CVE-2007-2848" ], "details": "Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xj5-mgrv-g748/GHSA-8xj5-mgrv-g748.json b/advisories/unreviewed/2022/05/GHSA-8xj5-mgrv-g748/GHSA-8xj5-mgrv-g748.json index 9efc1e342d6..e18502c6dab 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xj5-mgrv-g748/GHSA-8xj5-mgrv-g748.json +++ b/advisories/unreviewed/2022/05/GHSA-8xj5-mgrv-g748/GHSA-8xj5-mgrv-g748.json @@ -7,12 +7,8 @@ "CVE-2007-3022" ], "details": "Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xvj-fhgm-cmm2/GHSA-8xvj-fhgm-cmm2.json b/advisories/unreviewed/2022/05/GHSA-8xvj-fhgm-cmm2/GHSA-8xvj-fhgm-cmm2.json index 045157037fa..c5d7b6fd540 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xvj-fhgm-cmm2/GHSA-8xvj-fhgm-cmm2.json +++ b/advisories/unreviewed/2022/05/GHSA-8xvj-fhgm-cmm2/GHSA-8xvj-fhgm-cmm2.json @@ -7,12 +7,8 @@ "CVE-2007-3279" ], "details": "PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote attackers to create and execute functions, as demonstrated by functions that perform local brute-force password guessing attacks, which may evade intrusion detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9377-22wr-749v/GHSA-9377-22wr-749v.json b/advisories/unreviewed/2022/05/GHSA-9377-22wr-749v/GHSA-9377-22wr-749v.json index 425e015464b..091f4cd5d45 100644 --- a/advisories/unreviewed/2022/05/GHSA-9377-22wr-749v/GHSA-9377-22wr-749v.json +++ b/advisories/unreviewed/2022/05/GHSA-9377-22wr-749v/GHSA-9377-22wr-749v.json @@ -7,12 +7,8 @@ "CVE-2007-2968" ], "details": "Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93m3-4vp5-23qr/GHSA-93m3-4vp5-23qr.json b/advisories/unreviewed/2022/05/GHSA-93m3-4vp5-23qr/GHSA-93m3-4vp5-23qr.json index 00af8bdedbc..24bbcdd1bfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-93m3-4vp5-23qr/GHSA-93m3-4vp5-23qr.json +++ b/advisories/unreviewed/2022/05/GHSA-93m3-4vp5-23qr/GHSA-93m3-4vp5-23qr.json @@ -7,12 +7,8 @@ "CVE-2018-15131" ], "details": "An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-948g-p2xw-85hh/GHSA-948g-p2xw-85hh.json b/advisories/unreviewed/2022/05/GHSA-948g-p2xw-85hh/GHSA-948g-p2xw-85hh.json index 8f21c2ffd8d..5a7126cdc1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-948g-p2xw-85hh/GHSA-948g-p2xw-85hh.json +++ b/advisories/unreviewed/2022/05/GHSA-948g-p2xw-85hh/GHSA-948g-p2xw-85hh.json @@ -7,12 +7,8 @@ "CVE-2007-3070" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-94qq-cxch-9vpm/GHSA-94qq-cxch-9vpm.json b/advisories/unreviewed/2022/05/GHSA-94qq-cxch-9vpm/GHSA-94qq-cxch-9vpm.json index be895acba3a..1ac5cd76fd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-94qq-cxch-9vpm/GHSA-94qq-cxch-9vpm.json +++ b/advisories/unreviewed/2022/05/GHSA-94qq-cxch-9vpm/GHSA-94qq-cxch-9vpm.json @@ -7,12 +7,8 @@ "CVE-2007-3082" ], "details": "Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9553-79qx-ghfw/GHSA-9553-79qx-ghfw.json b/advisories/unreviewed/2022/05/GHSA-9553-79qx-ghfw/GHSA-9553-79qx-ghfw.json index b18c1ea20b6..495d724483a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9553-79qx-ghfw/GHSA-9553-79qx-ghfw.json +++ b/advisories/unreviewed/2022/05/GHSA-9553-79qx-ghfw/GHSA-9553-79qx-ghfw.json @@ -7,12 +7,8 @@ "CVE-2007-3173" ], "details": "Almnzm allows remote attackers to obtain sensitive information via an activateorder request to index.php with an invalid orderid parameter, probably related to '[' and ']' characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-955q-2rmr-5vhw/GHSA-955q-2rmr-5vhw.json b/advisories/unreviewed/2022/05/GHSA-955q-2rmr-5vhw/GHSA-955q-2rmr-5vhw.json index 2851543bc17..7e37146704e 100644 --- a/advisories/unreviewed/2022/05/GHSA-955q-2rmr-5vhw/GHSA-955q-2rmr-5vhw.json +++ b/advisories/unreviewed/2022/05/GHSA-955q-2rmr-5vhw/GHSA-955q-2rmr-5vhw.json @@ -7,12 +7,8 @@ "CVE-2007-2850" ], "details": "The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95gg-5hq9-f76w/GHSA-95gg-5hq9-f76w.json b/advisories/unreviewed/2022/05/GHSA-95gg-5hq9-f76w/GHSA-95gg-5hq9-f76w.json index 32dcb74eede..1baf7499e9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-95gg-5hq9-f76w/GHSA-95gg-5hq9-f76w.json +++ b/advisories/unreviewed/2022/05/GHSA-95gg-5hq9-f76w/GHSA-95gg-5hq9-f76w.json @@ -7,12 +7,8 @@ "CVE-2007-2923" ], "details": "The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95hp-m576-m42x/GHSA-95hp-m576-m42x.json b/advisories/unreviewed/2022/05/GHSA-95hp-m576-m42x/GHSA-95hp-m576-m42x.json index 42ca46392e2..705a54b2a03 100644 --- a/advisories/unreviewed/2022/05/GHSA-95hp-m576-m42x/GHSA-95hp-m576-m42x.json +++ b/advisories/unreviewed/2022/05/GHSA-95hp-m576-m42x/GHSA-95hp-m576-m42x.json @@ -7,12 +7,8 @@ "CVE-2019-9732" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95px-2q98-cxrr/GHSA-95px-2q98-cxrr.json b/advisories/unreviewed/2022/05/GHSA-95px-2q98-cxrr/GHSA-95px-2q98-cxrr.json index 86df8f6de45..5fb849956b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-95px-2q98-cxrr/GHSA-95px-2q98-cxrr.json +++ b/advisories/unreviewed/2022/05/GHSA-95px-2q98-cxrr/GHSA-95px-2q98-cxrr.json @@ -7,12 +7,8 @@ "CVE-2007-3044" ], "details": "Unspecified vulnerability in the Map I/O Service (xpwmap) in Hitachi XP/W on HI-UX/WE2 before 20070319, and XP/W on HP-UX before 20070405, allows remote attackers to cause a denial of service via certain data to the service port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-965p-cx7m-h7ph/GHSA-965p-cx7m-h7ph.json b/advisories/unreviewed/2022/05/GHSA-965p-cx7m-h7ph/GHSA-965p-cx7m-h7ph.json index 844841b7c46..59cc0d988a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-965p-cx7m-h7ph/GHSA-965p-cx7m-h7ph.json +++ b/advisories/unreviewed/2022/05/GHSA-965p-cx7m-h7ph/GHSA-965p-cx7m-h7ph.json @@ -7,12 +7,8 @@ "CVE-2007-3166" ], "details": "Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96vp-7vcr-rp4h/GHSA-96vp-7vcr-rp4h.json b/advisories/unreviewed/2022/05/GHSA-96vp-7vcr-rp4h/GHSA-96vp-7vcr-rp4h.json index 73b0b3c89ae..69dec7573c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-96vp-7vcr-rp4h/GHSA-96vp-7vcr-rp4h.json +++ b/advisories/unreviewed/2022/05/GHSA-96vp-7vcr-rp4h/GHSA-96vp-7vcr-rp4h.json @@ -7,12 +7,8 @@ "CVE-2019-12155" ], "details": "interface_release_resource in hw/display/qxl.c in QEMU 4.0.0 has a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-976c-hwhm-53hx/GHSA-976c-hwhm-53hx.json b/advisories/unreviewed/2022/05/GHSA-976c-hwhm-53hx/GHSA-976c-hwhm-53hx.json index 58294882049..42966e5cade 100644 --- a/advisories/unreviewed/2022/05/GHSA-976c-hwhm-53hx/GHSA-976c-hwhm-53hx.json +++ b/advisories/unreviewed/2022/05/GHSA-976c-hwhm-53hx/GHSA-976c-hwhm-53hx.json @@ -7,12 +7,8 @@ "CVE-2007-3164" ], "details": "Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels, as demonstrated by displaying xn--theshmogroup-bgk.com only in the status bar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97c5-v5qw-8wg6/GHSA-97c5-v5qw-8wg6.json b/advisories/unreviewed/2022/05/GHSA-97c5-v5qw-8wg6/GHSA-97c5-v5qw-8wg6.json index cc5690ab568..c9173c92d07 100644 --- a/advisories/unreviewed/2022/05/GHSA-97c5-v5qw-8wg6/GHSA-97c5-v5qw-8wg6.json +++ b/advisories/unreviewed/2022/05/GHSA-97c5-v5qw-8wg6/GHSA-97c5-v5qw-8wg6.json @@ -7,12 +7,8 @@ "CVE-2007-3039" ], "details": "Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97v5-8m6g-4h8j/GHSA-97v5-8m6g-4h8j.json b/advisories/unreviewed/2022/05/GHSA-97v5-8m6g-4h8j/GHSA-97v5-8m6g-4h8j.json index fa87db6a4e0..35af8e3c5f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-97v5-8m6g-4h8j/GHSA-97v5-8m6g-4h8j.json +++ b/advisories/unreviewed/2022/05/GHSA-97v5-8m6g-4h8j/GHSA-97v5-8m6g-4h8j.json @@ -7,12 +7,8 @@ "CVE-2007-2865" ], "details": "Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9859-7vpf-8wx3/GHSA-9859-7vpf-8wx3.json b/advisories/unreviewed/2022/05/GHSA-9859-7vpf-8wx3/GHSA-9859-7vpf-8wx3.json index 71b4f58f987..4373c571fc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9859-7vpf-8wx3/GHSA-9859-7vpf-8wx3.json +++ b/advisories/unreviewed/2022/05/GHSA-9859-7vpf-8wx3/GHSA-9859-7vpf-8wx3.json @@ -7,12 +7,8 @@ "CVE-2007-3040" ], "details": "Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9999-48p6-pf3h/GHSA-9999-48p6-pf3h.json b/advisories/unreviewed/2022/05/GHSA-9999-48p6-pf3h/GHSA-9999-48p6-pf3h.json index 314741c5028..6b529cf2ce8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9999-48p6-pf3h/GHSA-9999-48p6-pf3h.json +++ b/advisories/unreviewed/2022/05/GHSA-9999-48p6-pf3h/GHSA-9999-48p6-pf3h.json @@ -7,12 +7,8 @@ "CVE-2007-2899" ], "details": "Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99jx-pmgj-g477/GHSA-99jx-pmgj-g477.json b/advisories/unreviewed/2022/05/GHSA-99jx-pmgj-g477/GHSA-99jx-pmgj-g477.json index 5f8be0a0646..62289e2f4e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-99jx-pmgj-g477/GHSA-99jx-pmgj-g477.json +++ b/advisories/unreviewed/2022/05/GHSA-99jx-pmgj-g477/GHSA-99jx-pmgj-g477.json @@ -7,12 +7,8 @@ "CVE-2007-3146" ], "details": "Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cx5-r6r6-gxwj/GHSA-9cx5-r6r6-gxwj.json b/advisories/unreviewed/2022/05/GHSA-9cx5-r6r6-gxwj/GHSA-9cx5-r6r6-gxwj.json index dd0adbe62e7..dbcb6c3de1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cx5-r6r6-gxwj/GHSA-9cx5-r6r6-gxwj.json +++ b/advisories/unreviewed/2022/05/GHSA-9cx5-r6r6-gxwj/GHSA-9cx5-r6r6-gxwj.json @@ -7,12 +7,8 @@ "CVE-2007-2943" ], "details": "PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9f5f-33gh-h7gp/GHSA-9f5f-33gh-h7gp.json b/advisories/unreviewed/2022/05/GHSA-9f5f-33gh-h7gp/GHSA-9f5f-33gh-h7gp.json index 0b2f8cd866e..076b6272355 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f5f-33gh-h7gp/GHSA-9f5f-33gh-h7gp.json +++ b/advisories/unreviewed/2022/05/GHSA-9f5f-33gh-h7gp/GHSA-9f5f-33gh-h7gp.json @@ -7,12 +7,8 @@ "CVE-2007-2745" ], "details": "Cross-site scripting (XSS) vulnerability in printcal.pl in vDesk Webmail 4.03 allows remote attackers to inject arbitrary web script or HTML via the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f7x-h9hj-824m/GHSA-9f7x-h9hj-824m.json b/advisories/unreviewed/2022/05/GHSA-9f7x-h9hj-824m/GHSA-9f7x-h9hj-824m.json index bf18da6dd0b..44490161180 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f7x-h9hj-824m/GHSA-9f7x-h9hj-824m.json +++ b/advisories/unreviewed/2022/05/GHSA-9f7x-h9hj-824m/GHSA-9f7x-h9hj-824m.json @@ -7,12 +7,8 @@ "CVE-2007-2971" ], "details": "SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fm8-x8j3-w9mx/GHSA-9fm8-x8j3-w9mx.json b/advisories/unreviewed/2022/05/GHSA-9fm8-x8j3-w9mx/GHSA-9fm8-x8j3-w9mx.json index 57f07cc1094..78ab56ba0ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fm8-x8j3-w9mx/GHSA-9fm8-x8j3-w9mx.json +++ b/advisories/unreviewed/2022/05/GHSA-9fm8-x8j3-w9mx/GHSA-9fm8-x8j3-w9mx.json @@ -7,12 +7,8 @@ "CVE-2007-2722" ], "details": "Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a \"%s\" sequence, a \"%Y\" sequence, a \"%%\" sequence, and an \"n,\" sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gwf-94xq-7cr5/GHSA-9gwf-94xq-7cr5.json b/advisories/unreviewed/2022/05/GHSA-9gwf-94xq-7cr5/GHSA-9gwf-94xq-7cr5.json index ac6e803939b..fb0c59c021a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gwf-94xq-7cr5/GHSA-9gwf-94xq-7cr5.json +++ b/advisories/unreviewed/2022/05/GHSA-9gwf-94xq-7cr5/GHSA-9gwf-94xq-7cr5.json @@ -7,12 +7,8 @@ "CVE-2007-2887" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9h6w-vrgg-m9q9/GHSA-9h6w-vrgg-m9q9.json b/advisories/unreviewed/2022/05/GHSA-9h6w-vrgg-m9q9/GHSA-9h6w-vrgg-m9q9.json index ffaf9c92ecd..51baf455475 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h6w-vrgg-m9q9/GHSA-9h6w-vrgg-m9q9.json +++ b/advisories/unreviewed/2022/05/GHSA-9h6w-vrgg-m9q9/GHSA-9h6w-vrgg-m9q9.json @@ -7,12 +7,8 @@ "CVE-2007-3098" ], "details": "The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j75-9wp3-854g/GHSA-9j75-9wp3-854g.json b/advisories/unreviewed/2022/05/GHSA-9j75-9wp3-854g/GHSA-9j75-9wp3-854g.json index 1df9b0abf47..42c5f9b8995 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j75-9wp3-854g/GHSA-9j75-9wp3-854g.json +++ b/advisories/unreviewed/2022/05/GHSA-9j75-9wp3-854g/GHSA-9j75-9wp3-854g.json @@ -7,12 +7,8 @@ "CVE-2007-2831" ], "details": "Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local users to cause a denial of service (system crash), possibly obtain kernel memory contents, and possibly execute arbitrary code via a large negative array index value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j84-7rq9-w2fq/GHSA-9j84-7rq9-w2fq.json b/advisories/unreviewed/2022/05/GHSA-9j84-7rq9-w2fq/GHSA-9j84-7rq9-w2fq.json index 67c236e9543..dd4bb458c7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j84-7rq9-w2fq/GHSA-9j84-7rq9-w2fq.json +++ b/advisories/unreviewed/2022/05/GHSA-9j84-7rq9-w2fq/GHSA-9j84-7rq9-w2fq.json @@ -7,12 +7,8 @@ "CVE-2007-3205" ], "details": "The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jcg-45pr-7qhw/GHSA-9jcg-45pr-7qhw.json b/advisories/unreviewed/2022/05/GHSA-9jcg-45pr-7qhw/GHSA-9jcg-45pr-7qhw.json index 583e77d9df3..75526a9a3c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jcg-45pr-7qhw/GHSA-9jcg-45pr-7qhw.json +++ b/advisories/unreviewed/2022/05/GHSA-9jcg-45pr-7qhw/GHSA-9jcg-45pr-7qhw.json @@ -7,12 +7,8 @@ "CVE-2007-2912" ], "details": "Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to see the infraction \"red flag\" for a deleted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jqp-8h2q-6wcg/GHSA-9jqp-8h2q-6wcg.json b/advisories/unreviewed/2022/05/GHSA-9jqp-8h2q-6wcg/GHSA-9jqp-8h2q-6wcg.json index 86dee2ea248..269bf5a76e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jqp-8h2q-6wcg/GHSA-9jqp-8h2q-6wcg.json +++ b/advisories/unreviewed/2022/05/GHSA-9jqp-8h2q-6wcg/GHSA-9jqp-8h2q-6wcg.json @@ -7,12 +7,8 @@ "CVE-2007-2963" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) module_bbcodeloader.php, (2) module_div.php, (3) module_email.php, (4) module_image.php, (5) module_link.php, or (6) the editorid parameter to module_table.php in jscripts/folder_rte_files/. NOTE: some details were obtained from third party sources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pv6-4w7h-vppx/GHSA-9pv6-4w7h-vppx.json b/advisories/unreviewed/2022/05/GHSA-9pv6-4w7h-vppx/GHSA-9pv6-4w7h-vppx.json index 7321053aaa4..11a98233327 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pv6-4w7h-vppx/GHSA-9pv6-4w7h-vppx.json +++ b/advisories/unreviewed/2022/05/GHSA-9pv6-4w7h-vppx/GHSA-9pv6-4w7h-vppx.json @@ -7,12 +7,8 @@ "CVE-2007-2721" ], "details": "The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qxj-4gqc-f4hg/GHSA-9qxj-4gqc-f4hg.json b/advisories/unreviewed/2022/05/GHSA-9qxj-4gqc-f4hg/GHSA-9qxj-4gqc-f4hg.json index 05a6b6f8447..683aecbce80 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qxj-4gqc-f4hg/GHSA-9qxj-4gqc-f4hg.json +++ b/advisories/unreviewed/2022/05/GHSA-9qxj-4gqc-f4hg/GHSA-9qxj-4gqc-f4hg.json @@ -7,12 +7,8 @@ "CVE-2007-2713" ], "details": "ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r45-r3gh-h92p/GHSA-9r45-r3gh-h92p.json b/advisories/unreviewed/2022/05/GHSA-9r45-r3gh-h92p/GHSA-9r45-r3gh-h92p.json index e51ea2839e6..f600051ff26 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r45-r3gh-h92p/GHSA-9r45-r3gh-h92p.json +++ b/advisories/unreviewed/2022/05/GHSA-9r45-r3gh-h92p/GHSA-9r45-r3gh-h92p.json @@ -7,12 +7,8 @@ "CVE-2007-2991" ], "details": "Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r4h-2cr5-xvhv/GHSA-9r4h-2cr5-xvhv.json b/advisories/unreviewed/2022/05/GHSA-9r4h-2cr5-xvhv/GHSA-9r4h-2cr5-xvhv.json index b99ea6c7b03..ba5a486cf22 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r4h-2cr5-xvhv/GHSA-9r4h-2cr5-xvhv.json +++ b/advisories/unreviewed/2022/05/GHSA-9r4h-2cr5-xvhv/GHSA-9r4h-2cr5-xvhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v5f-jqpv-mfv4/GHSA-9v5f-jqpv-mfv4.json b/advisories/unreviewed/2022/05/GHSA-9v5f-jqpv-mfv4/GHSA-9v5f-jqpv-mfv4.json index 0a6f757bb2c..c860b60f88e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5f-jqpv-mfv4/GHSA-9v5f-jqpv-mfv4.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5f-jqpv-mfv4/GHSA-9v5f-jqpv-mfv4.json @@ -7,12 +7,8 @@ "CVE-2007-2690" ], "details": "Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vj3-8mhr-2vxc/GHSA-9vj3-8mhr-2vxc.json b/advisories/unreviewed/2022/05/GHSA-9vj3-8mhr-2vxc/GHSA-9vj3-8mhr-2vxc.json index b74bdd37be3..f6b7159d17e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vj3-8mhr-2vxc/GHSA-9vj3-8mhr-2vxc.json +++ b/advisories/unreviewed/2022/05/GHSA-9vj3-8mhr-2vxc/GHSA-9vj3-8mhr-2vxc.json @@ -7,12 +7,8 @@ "CVE-2007-2834" ], "details": "Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vjj-7p4g-wpmp/GHSA-9vjj-7p4g-wpmp.json b/advisories/unreviewed/2022/05/GHSA-9vjj-7p4g-wpmp/GHSA-9vjj-7p4g-wpmp.json index d61455856fe..160f4f856fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vjj-7p4g-wpmp/GHSA-9vjj-7p4g-wpmp.json +++ b/advisories/unreviewed/2022/05/GHSA-9vjj-7p4g-wpmp/GHSA-9vjj-7p4g-wpmp.json @@ -7,12 +7,8 @@ "CVE-2019-9177" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption (issue 2 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vrx-rxrx-2pgp/GHSA-9vrx-rxrx-2pgp.json b/advisories/unreviewed/2022/05/GHSA-9vrx-rxrx-2pgp/GHSA-9vrx-rxrx-2pgp.json index f68d278187d..67d6eb466eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vrx-rxrx-2pgp/GHSA-9vrx-rxrx-2pgp.json +++ b/advisories/unreviewed/2022/05/GHSA-9vrx-rxrx-2pgp/GHSA-9vrx-rxrx-2pgp.json @@ -7,12 +7,8 @@ "CVE-2007-3103" ], "details": "The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wp7-w3q3-3886/GHSA-9wp7-w3q3-3886.json b/advisories/unreviewed/2022/05/GHSA-9wp7-w3q3-3886/GHSA-9wp7-w3q3-3886.json index e23dd4ef508..daaa18ada91 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wp7-w3q3-3886/GHSA-9wp7-w3q3-3886.json +++ b/advisories/unreviewed/2022/05/GHSA-9wp7-w3q3-3886/GHSA-9wp7-w3q3-3886.json @@ -7,12 +7,8 @@ "CVE-2019-7027" ], "details": "Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x4m-g7mf-vc5f/GHSA-9x4m-g7mf-vc5f.json b/advisories/unreviewed/2022/05/GHSA-9x4m-g7mf-vc5f/GHSA-9x4m-g7mf-vc5f.json index 0d600f71e7c..bb0a406b6bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x4m-g7mf-vc5f/GHSA-9x4m-g7mf-vc5f.json +++ b/advisories/unreviewed/2022/05/GHSA-9x4m-g7mf-vc5f/GHSA-9x4m-g7mf-vc5f.json @@ -7,12 +7,8 @@ "CVE-2007-3000" ], "details": "Multiple SQL injection vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to execute arbitrary SQL commands via (1) the iCategoryUnq parameter to G_Display.php or (2) the iSearchID parameter to Search/DisplayResults.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xhx-93rq-hw56/GHSA-9xhx-93rq-hw56.json b/advisories/unreviewed/2022/05/GHSA-9xhx-93rq-hw56/GHSA-9xhx-93rq-hw56.json index 9805b6cfa32..06ce8b18752 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xhx-93rq-hw56/GHSA-9xhx-93rq-hw56.json +++ b/advisories/unreviewed/2022/05/GHSA-9xhx-93rq-hw56/GHSA-9xhx-93rq-hw56.json @@ -7,12 +7,8 @@ "CVE-2007-3188" ], "details": "SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xqv-m887-7cxj/GHSA-9xqv-m887-7cxj.json b/advisories/unreviewed/2022/05/GHSA-9xqv-m887-7cxj/GHSA-9xqv-m887-7cxj.json index 9295539a7c3..250e2596af0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xqv-m887-7cxj/GHSA-9xqv-m887-7cxj.json +++ b/advisories/unreviewed/2022/05/GHSA-9xqv-m887-7cxj/GHSA-9xqv-m887-7cxj.json @@ -7,12 +7,8 @@ "CVE-2007-2919" ], "details": "Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3) PAGENO, (4) LaunchMode, (5) SubID, (6) BookID, (7) LibraryID, (8) SubURL, and (9) LoadOpf properties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xvr-vmq9-hmhp/GHSA-9xvr-vmq9-hmhp.json b/advisories/unreviewed/2022/05/GHSA-9xvr-vmq9-hmhp/GHSA-9xvr-vmq9-hmhp.json index 69e71edf1db..5e05f55ccd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xvr-vmq9-hmhp/GHSA-9xvr-vmq9-hmhp.json +++ b/advisories/unreviewed/2022/05/GHSA-9xvr-vmq9-hmhp/GHSA-9xvr-vmq9-hmhp.json @@ -7,12 +7,8 @@ "CVE-2019-10852" ], "details": "Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2f8-wr7x-447x/GHSA-c2f8-wr7x-447x.json b/advisories/unreviewed/2022/05/GHSA-c2f8-wr7x-447x/GHSA-c2f8-wr7x-447x.json index 13fbd036230..2987b91a740 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2f8-wr7x-447x/GHSA-c2f8-wr7x-447x.json +++ b/advisories/unreviewed/2022/05/GHSA-c2f8-wr7x-447x/GHSA-c2f8-wr7x-447x.json @@ -7,12 +7,8 @@ "CVE-2007-3190" ], "details": "Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2qp-6h6r-wffg/GHSA-c2qp-6h6r-wffg.json b/advisories/unreviewed/2022/05/GHSA-c2qp-6h6r-wffg/GHSA-c2qp-6h6r-wffg.json index 7791ba22e76..e8ab525c0d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2qp-6h6r-wffg/GHSA-c2qp-6h6r-wffg.json +++ b/advisories/unreviewed/2022/05/GHSA-c2qp-6h6r-wffg/GHSA-c2qp-6h6r-wffg.json @@ -7,12 +7,8 @@ "CVE-2007-3207" ], "details": "Buffer overflow in the NFS mount daemon (XNFS.NLM) in Novell NetWare 6.5 SP6, and probably earlier, allows remote attackers to cause a denial of service (abend) via a long path in a mount request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2r6-w3hh-33v8/GHSA-c2r6-w3hh-33v8.json b/advisories/unreviewed/2022/05/GHSA-c2r6-w3hh-33v8/GHSA-c2r6-w3hh-33v8.json index 44f663c48a9..bf98db4342d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2r6-w3hh-33v8/GHSA-c2r6-w3hh-33v8.json +++ b/advisories/unreviewed/2022/05/GHSA-c2r6-w3hh-33v8/GHSA-c2r6-w3hh-33v8.json @@ -7,12 +7,8 @@ "CVE-2007-3181" ], "details": "Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to \"an InterBase version of gds32.dll.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3jp-9rg8-8vx4/GHSA-c3jp-9rg8-8vx4.json b/advisories/unreviewed/2022/05/GHSA-c3jp-9rg8-8vx4/GHSA-c3jp-9rg8-8vx4.json index 3634ff570dc..8d7fcd99704 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3jp-9rg8-8vx4/GHSA-c3jp-9rg8-8vx4.json +++ b/advisories/unreviewed/2022/05/GHSA-c3jp-9rg8-8vx4/GHSA-c3jp-9rg8-8vx4.json @@ -7,12 +7,8 @@ "CVE-2007-3282" ], "details": "Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c44m-qg9v-cxxm/GHSA-c44m-qg9v-cxxm.json b/advisories/unreviewed/2022/05/GHSA-c44m-qg9v-cxxm/GHSA-c44m-qg9v-cxxm.json index be029e1cc59..25c1a6f13d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c44m-qg9v-cxxm/GHSA-c44m-qg9v-cxxm.json +++ b/advisories/unreviewed/2022/05/GHSA-c44m-qg9v-cxxm/GHSA-c44m-qg9v-cxxm.json @@ -7,12 +7,8 @@ "CVE-2007-3144" ], "details": "Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c67p-2c36-mvjf/GHSA-c67p-2c36-mvjf.json b/advisories/unreviewed/2022/05/GHSA-c67p-2c36-mvjf/GHSA-c67p-2c36-mvjf.json index 3f3d66ca86e..becefd09fd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c67p-2c36-mvjf/GHSA-c67p-2c36-mvjf.json +++ b/advisories/unreviewed/2022/05/GHSA-c67p-2c36-mvjf/GHSA-c67p-2c36-mvjf.json @@ -7,12 +7,8 @@ "CVE-2007-2883" ], "details": "Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the product is intended to protect the data on a stolen computer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6fg-jhfr-pxqg/GHSA-c6fg-jhfr-pxqg.json b/advisories/unreviewed/2022/05/GHSA-c6fg-jhfr-pxqg/GHSA-c6fg-jhfr-pxqg.json index fdcb2ec4ebe..3d944d968be 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6fg-jhfr-pxqg/GHSA-c6fg-jhfr-pxqg.json +++ b/advisories/unreviewed/2022/05/GHSA-c6fg-jhfr-pxqg/GHSA-c6fg-jhfr-pxqg.json @@ -7,12 +7,8 @@ "CVE-2007-3073" ], "details": "Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6hq-hjpv-xp97/GHSA-c6hq-hjpv-xp97.json b/advisories/unreviewed/2022/05/GHSA-c6hq-hjpv-xp97/GHSA-c6hq-hjpv-xp97.json index 5014abcdbb4..fc82dbfed3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6hq-hjpv-xp97/GHSA-c6hq-hjpv-xp97.json +++ b/advisories/unreviewed/2022/05/GHSA-c6hq-hjpv-xp97/GHSA-c6hq-hjpv-xp97.json @@ -7,12 +7,8 @@ "CVE-2007-2786" ], "details": "Ratbox IRC Daemon (aka ircd-ratbox) 2.2.5 and earlier allows remote attackers to cause a denial of service (resource exhaustion) by making many requests from a single client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6mp-c9vc-3gwg/GHSA-c6mp-c9vc-3gwg.json b/advisories/unreviewed/2022/05/GHSA-c6mp-c9vc-3gwg/GHSA-c6mp-c9vc-3gwg.json index 13a2ac024ac..508007f5564 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6mp-c9vc-3gwg/GHSA-c6mp-c9vc-3gwg.json +++ b/advisories/unreviewed/2022/05/GHSA-c6mp-c9vc-3gwg/GHSA-c6mp-c9vc-3gwg.json @@ -7,12 +7,8 @@ "CVE-2007-2992" ], "details": "Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7g8-wrqq-9vrp/GHSA-c7g8-wrqq-9vrp.json b/advisories/unreviewed/2022/05/GHSA-c7g8-wrqq-9vrp/GHSA-c7g8-wrqq-9vrp.json index 5d2d898308e..67a79dde11c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7g8-wrqq-9vrp/GHSA-c7g8-wrqq-9vrp.json +++ b/advisories/unreviewed/2022/05/GHSA-c7g8-wrqq-9vrp/GHSA-c7g8-wrqq-9vrp.json @@ -7,12 +7,8 @@ "CVE-2007-2933" ], "details": "SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7pf-pq89-8795/GHSA-c7pf-pq89-8795.json b/advisories/unreviewed/2022/05/GHSA-c7pf-pq89-8795/GHSA-c7pf-pq89-8795.json index 5cba06a3266..e22ca78ebb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7pf-pq89-8795/GHSA-c7pf-pq89-8795.json +++ b/advisories/unreviewed/2022/05/GHSA-c7pf-pq89-8795/GHSA-c7pf-pq89-8795.json @@ -7,12 +7,8 @@ "CVE-2007-2824" ], "details": "SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c857-vg8v-gj88/GHSA-c857-vg8v-gj88.json b/advisories/unreviewed/2022/05/GHSA-c857-vg8v-gj88/GHSA-c857-vg8v-gj88.json index b9cdc98ffee..d7bd9ee48cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-c857-vg8v-gj88/GHSA-c857-vg8v-gj88.json +++ b/advisories/unreviewed/2022/05/GHSA-c857-vg8v-gj88/GHSA-c857-vg8v-gj88.json @@ -7,12 +7,8 @@ "CVE-2007-2739" ], "details": "Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8f9-5w72-xw7p/GHSA-c8f9-5w72-xw7p.json b/advisories/unreviewed/2022/05/GHSA-c8f9-5w72-xw7p/GHSA-c8f9-5w72-xw7p.json index 18f4b80d6f0..fe0a10ba28a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8f9-5w72-xw7p/GHSA-c8f9-5w72-xw7p.json +++ b/advisories/unreviewed/2022/05/GHSA-c8f9-5w72-xw7p/GHSA-c8f9-5w72-xw7p.json @@ -7,12 +7,8 @@ "CVE-2007-3001" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary web script or HTML via (1) the sUName parameter to UserArea/Authenticate.php, (2) the sAccountUnq parameter to UserArea/NewAccounts/index.php, or the (3) iCategoryUnq, (4) iDBLoc, (5) iTtlNumItems, (6) iNumPerPage, or (7) sSort parameter to G_Display.php, different vectors than CVE-2005-4239.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9fg-253c-5m34/GHSA-c9fg-253c-5m34.json b/advisories/unreviewed/2022/05/GHSA-c9fg-253c-5m34/GHSA-c9fg-253c-5m34.json index 1948db1252a..aa10ca8c6c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9fg-253c-5m34/GHSA-c9fg-253c-5m34.json +++ b/advisories/unreviewed/2022/05/GHSA-c9fg-253c-5m34/GHSA-c9fg-253c-5m34.json @@ -7,12 +7,8 @@ "CVE-2019-5588" ], "details": "A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the \"err\" parameter of the error process HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc8w-j726-c7gj/GHSA-cc8w-j726-c7gj.json b/advisories/unreviewed/2022/05/GHSA-cc8w-j726-c7gj/GHSA-cc8w-j726-c7gj.json index d0aa752e560..b1bf703166d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc8w-j726-c7gj/GHSA-cc8w-j726-c7gj.json +++ b/advisories/unreviewed/2022/05/GHSA-cc8w-j726-c7gj/GHSA-cc8w-j726-c7gj.json @@ -7,12 +7,8 @@ "CVE-2019-12480" ], "details": "BACnet Protocol Stack through 0.8.6 could allow an unauthenticated, remote attacker to cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ccc3-2rqr-qrvv/GHSA-ccc3-2rqr-qrvv.json b/advisories/unreviewed/2022/05/GHSA-ccc3-2rqr-qrvv/GHSA-ccc3-2rqr-qrvv.json index 098c0d11a24..30b9b77c4b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccc3-2rqr-qrvv/GHSA-ccc3-2rqr-qrvv.json +++ b/advisories/unreviewed/2022/05/GHSA-ccc3-2rqr-qrvv/GHSA-ccc3-2rqr-qrvv.json @@ -7,12 +7,8 @@ "CVE-2007-2741" ], "details": "Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfr5-cx7m-pm9g/GHSA-cfr5-cx7m-pm9g.json b/advisories/unreviewed/2022/05/GHSA-cfr5-cx7m-pm9g/GHSA-cfr5-cx7m-pm9g.json index dc223d36d91..91535cdcd7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfr5-cx7m-pm9g/GHSA-cfr5-cx7m-pm9g.json +++ b/advisories/unreviewed/2022/05/GHSA-cfr5-cx7m-pm9g/GHSA-cfr5-cx7m-pm9g.json @@ -7,12 +7,8 @@ "CVE-2007-3007" ], "details": "PHP 5 before 5.2.3 does not enforce the open_basedir or safe_mode restriction in certain cases, which allows context-dependent attackers to determine the existence of arbitrary files by checking if the readfile function returns a string. NOTE: this issue might also involve the realpath function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfwh-jh9q-xhc3/GHSA-cfwh-jh9q-xhc3.json b/advisories/unreviewed/2022/05/GHSA-cfwh-jh9q-xhc3/GHSA-cfwh-jh9q-xhc3.json index 0132f375f9b..77dbb3ce888 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfwh-jh9q-xhc3/GHSA-cfwh-jh9q-xhc3.json +++ b/advisories/unreviewed/2022/05/GHSA-cfwh-jh9q-xhc3/GHSA-cfwh-jh9q-xhc3.json @@ -7,12 +7,8 @@ "CVE-2007-2999" ], "details": "Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgqf-q6r9-fgph/GHSA-cgqf-q6r9-fgph.json b/advisories/unreviewed/2022/05/GHSA-cgqf-q6r9-fgph/GHSA-cgqf-q6r9-fgph.json index 22550f7e5fa..88d50464897 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgqf-q6r9-fgph/GHSA-cgqf-q6r9-fgph.json +++ b/advisories/unreviewed/2022/05/GHSA-cgqf-q6r9-fgph/GHSA-cgqf-q6r9-fgph.json @@ -7,12 +7,8 @@ "CVE-2007-3011" ], "details": "The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chc8-7fq5-5hhg/GHSA-chc8-7fq5-5hhg.json b/advisories/unreviewed/2022/05/GHSA-chc8-7fq5-5hhg/GHSA-chc8-7fq5-5hhg.json index a67e861b052..5793910b592 100644 --- a/advisories/unreviewed/2022/05/GHSA-chc8-7fq5-5hhg/GHSA-chc8-7fq5-5hhg.json +++ b/advisories/unreviewed/2022/05/GHSA-chc8-7fq5-5hhg/GHSA-chc8-7fq5-5hhg.json @@ -7,12 +7,8 @@ "CVE-2007-2851" ], "details": "A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to overwrite arbitrary files via the WriteDataToFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjwj-wvcj-rr5c/GHSA-cjwj-wvcj-rr5c.json b/advisories/unreviewed/2022/05/GHSA-cjwj-wvcj-rr5c/GHSA-cjwj-wvcj-rr5c.json index c1d7f40e916..3fb0977d737 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjwj-wvcj-rr5c/GHSA-cjwj-wvcj-rr5c.json +++ b/advisories/unreviewed/2022/05/GHSA-cjwj-wvcj-rr5c/GHSA-cjwj-wvcj-rr5c.json @@ -7,12 +7,8 @@ "CVE-2007-2788" ], "details": "Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -252,9 +248,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjx9-q8g7-cf62/GHSA-cjx9-q8g7-cf62.json b/advisories/unreviewed/2022/05/GHSA-cjx9-q8g7-cf62/GHSA-cjx9-q8g7-cf62.json index 1320b64b766..97410314f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjx9-q8g7-cf62/GHSA-cjx9-q8g7-cf62.json +++ b/advisories/unreviewed/2022/05/GHSA-cjx9-q8g7-cf62/GHSA-cjx9-q8g7-cf62.json @@ -7,12 +7,8 @@ "CVE-2007-2958" ], "details": "Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm7v-8rv2-7p5w/GHSA-cm7v-8rv2-7p5w.json b/advisories/unreviewed/2022/05/GHSA-cm7v-8rv2-7p5w/GHSA-cm7v-8rv2-7p5w.json index 9e22852f672..dfb55571cd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm7v-8rv2-7p5w/GHSA-cm7v-8rv2-7p5w.json +++ b/advisories/unreviewed/2022/05/GHSA-cm7v-8rv2-7p5w/GHSA-cm7v-8rv2-7p5w.json @@ -7,12 +7,8 @@ "CVE-2007-3051" ], "details": "SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to execute arbitrary SQL commands via the revokebb_user cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cv25-vxqx-939x/GHSA-cv25-vxqx-939x.json b/advisories/unreviewed/2022/05/GHSA-cv25-vxqx-939x/GHSA-cv25-vxqx-939x.json index 6c52533bdb6..6d1ba94ca75 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv25-vxqx-939x/GHSA-cv25-vxqx-939x.json +++ b/advisories/unreviewed/2022/05/GHSA-cv25-vxqx-939x/GHSA-cv25-vxqx-939x.json @@ -7,12 +7,8 @@ "CVE-2007-3266" ], "details": "Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw63-w4qg-mxf4/GHSA-cw63-w4qg-mxf4.json b/advisories/unreviewed/2022/05/GHSA-cw63-w4qg-mxf4/GHSA-cw63-w4qg-mxf4.json index 9bea4afcdeb..92455dd4128 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw63-w4qg-mxf4/GHSA-cw63-w4qg-mxf4.json +++ b/advisories/unreviewed/2022/05/GHSA-cw63-w4qg-mxf4/GHSA-cw63-w4qg-mxf4.json @@ -7,12 +7,8 @@ "CVE-2007-3197" ], "details": "SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxg5-jqhx-8cv4/GHSA-cxg5-jqhx-8cv4.json b/advisories/unreviewed/2022/05/GHSA-cxg5-jqhx-8cv4/GHSA-cxg5-jqhx-8cv4.json index d8b0a016bfa..6941016dfd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxg5-jqhx-8cv4/GHSA-cxg5-jqhx-8cv4.json +++ b/advisories/unreviewed/2022/05/GHSA-cxg5-jqhx-8cv4/GHSA-cxg5-jqhx-8cv4.json @@ -7,12 +7,8 @@ "CVE-2007-2836" ], "details": "Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxh3-p9rw-hjrr/GHSA-cxh3-p9rw-hjrr.json b/advisories/unreviewed/2022/05/GHSA-cxh3-p9rw-hjrr/GHSA-cxh3-p9rw-hjrr.json index a5165060c40..4cf96c3bf9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxh3-p9rw-hjrr/GHSA-cxh3-p9rw-hjrr.json +++ b/advisories/unreviewed/2022/05/GHSA-cxh3-p9rw-hjrr/GHSA-cxh3-p9rw-hjrr.json @@ -7,12 +7,8 @@ "CVE-2007-2975" ], "details": "The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute arbitrary code by accessing functionality that is exposed through DWR, as demonstrated using the downloader.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxq4-49hh-68j9/GHSA-cxq4-49hh-68j9.json b/advisories/unreviewed/2022/05/GHSA-cxq4-49hh-68j9/GHSA-cxq4-49hh-68j9.json index 6de5530a9f4..bc6686812ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxq4-49hh-68j9/GHSA-cxq4-49hh-68j9.json +++ b/advisories/unreviewed/2022/05/GHSA-cxq4-49hh-68j9/GHSA-cxq4-49hh-68j9.json @@ -7,12 +7,8 @@ "CVE-2007-2829" ], "details": "The 802.11 network stack in net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system hang) via a crafted length field in nested 802.3 Ethernet frames in Fast Frame packets, which results in a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f223-vx2m-xx3j/GHSA-f223-vx2m-xx3j.json b/advisories/unreviewed/2022/05/GHSA-f223-vx2m-xx3j/GHSA-f223-vx2m-xx3j.json index 5aa8c59bb88..d12a6fbbb1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f223-vx2m-xx3j/GHSA-f223-vx2m-xx3j.json +++ b/advisories/unreviewed/2022/05/GHSA-f223-vx2m-xx3j/GHSA-f223-vx2m-xx3j.json @@ -7,12 +7,8 @@ "CVE-2007-2730" ], "details": "Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2jw-776x-83xf/GHSA-f2jw-776x-83xf.json b/advisories/unreviewed/2022/05/GHSA-f2jw-776x-83xf/GHSA-f2jw-776x-83xf.json index 326ed2c3a18..c1b9a16d381 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2jw-776x-83xf/GHSA-f2jw-776x-83xf.json +++ b/advisories/unreviewed/2022/05/GHSA-f2jw-776x-83xf/GHSA-f2jw-776x-83xf.json @@ -7,12 +7,8 @@ "CVE-2007-2894" ], "details": "The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2rh-9mv9-vrw7/GHSA-f2rh-9mv9-vrw7.json b/advisories/unreviewed/2022/05/GHSA-f2rh-9mv9-vrw7/GHSA-f2rh-9mv9-vrw7.json index 3f57cab9d72..9c2416bb6e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2rh-9mv9-vrw7/GHSA-f2rh-9mv9-vrw7.json +++ b/advisories/unreviewed/2022/05/GHSA-f2rh-9mv9-vrw7/GHSA-f2rh-9mv9-vrw7.json @@ -7,12 +7,8 @@ "CVE-2007-3101" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f38h-8whh-fx2q/GHSA-f38h-8whh-fx2q.json b/advisories/unreviewed/2022/05/GHSA-f38h-8whh-fx2q/GHSA-f38h-8whh-fx2q.json index 3114c9c4a14..4192cde9b93 100644 --- a/advisories/unreviewed/2022/05/GHSA-f38h-8whh-fx2q/GHSA-f38h-8whh-fx2q.json +++ b/advisories/unreviewed/2022/05/GHSA-f38h-8whh-fx2q/GHSA-f38h-8whh-fx2q.json @@ -7,12 +7,8 @@ "CVE-2007-3050" ], "details": "Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f39q-cfgm-mvqg/GHSA-f39q-cfgm-mvqg.json b/advisories/unreviewed/2022/05/GHSA-f39q-cfgm-mvqg/GHSA-f39q-cfgm-mvqg.json index 82123d26f33..31883e4f147 100644 --- a/advisories/unreviewed/2022/05/GHSA-f39q-cfgm-mvqg/GHSA-f39q-cfgm-mvqg.json +++ b/advisories/unreviewed/2022/05/GHSA-f39q-cfgm-mvqg/GHSA-f39q-cfgm-mvqg.json @@ -7,12 +7,8 @@ "CVE-2007-2901" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f67h-gv29-49cj/GHSA-f67h-gv29-49cj.json b/advisories/unreviewed/2022/05/GHSA-f67h-gv29-49cj/GHSA-f67h-gv29-49cj.json index 3c0204a7447..61092114493 100644 --- a/advisories/unreviewed/2022/05/GHSA-f67h-gv29-49cj/GHSA-f67h-gv29-49cj.json +++ b/advisories/unreviewed/2022/05/GHSA-f67h-gv29-49cj/GHSA-f67h-gv29-49cj.json @@ -7,12 +7,8 @@ "CVE-2007-3162" ], "details": "Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f6x6-3cm4-fjmc/GHSA-f6x6-3cm4-fjmc.json b/advisories/unreviewed/2022/05/GHSA-f6x6-3cm4-fjmc/GHSA-f6x6-3cm4-fjmc.json index cdac8e19f0b..70b71792344 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6x6-3cm4-fjmc/GHSA-f6x6-3cm4-fjmc.json +++ b/advisories/unreviewed/2022/05/GHSA-f6x6-3cm4-fjmc/GHSA-f6x6-3cm4-fjmc.json @@ -7,12 +7,8 @@ "CVE-2007-3002" ], "details": "PHP JackKnife (PHPJK) allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid value of the iParentUnq[] parameter, or a request to G_Display.php with an invalid (2) iCategoryUnq[] or (3) sSort[] array parameter, which reveals the path in various error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7pf-c3hc-f37c/GHSA-f7pf-c3hc-f37c.json b/advisories/unreviewed/2022/05/GHSA-f7pf-c3hc-f37c/GHSA-f7pf-c3hc-f37c.json index 6506088e232..f874b8be843 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7pf-c3hc-f37c/GHSA-f7pf-c3hc-f37c.json +++ b/advisories/unreviewed/2022/05/GHSA-f7pf-c3hc-f37c/GHSA-f7pf-c3hc-f37c.json @@ -7,12 +7,8 @@ "CVE-2007-2776" ], "details": "AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f835-5m23-xhv7/GHSA-f835-5m23-xhv7.json b/advisories/unreviewed/2022/05/GHSA-f835-5m23-xhv7/GHSA-f835-5m23-xhv7.json index 7a6c5eff21e..c52cbb9cada 100644 --- a/advisories/unreviewed/2022/05/GHSA-f835-5m23-xhv7/GHSA-f835-5m23-xhv7.json +++ b/advisories/unreviewed/2022/05/GHSA-f835-5m23-xhv7/GHSA-f835-5m23-xhv7.json @@ -7,12 +7,8 @@ "CVE-2007-3055" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9hv-v3mm-j4mv/GHSA-f9hv-v3mm-j4mv.json b/advisories/unreviewed/2022/05/GHSA-f9hv-v3mm-j4mv/GHSA-f9hv-v3mm-j4mv.json index bb01ac48272..c5ee809b915 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9hv-v3mm-j4mv/GHSA-f9hv-v3mm-j4mv.json +++ b/advisories/unreviewed/2022/05/GHSA-f9hv-v3mm-j4mv/GHSA-f9hv-v3mm-j4mv.json @@ -7,12 +7,8 @@ "CVE-2019-7272" ], "details": "Optergy Proton/Enterprise devices allow Username Disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcc5-g273-rp3g/GHSA-fcc5-g273-rp3g.json b/advisories/unreviewed/2022/05/GHSA-fcc5-g273-rp3g/GHSA-fcc5-g273-rp3g.json index 4057133587b..78c0a76fe5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcc5-g273-rp3g/GHSA-fcc5-g273-rp3g.json +++ b/advisories/unreviewed/2022/05/GHSA-fcc5-g273-rp3g/GHSA-fcc5-g273-rp3g.json @@ -7,12 +7,8 @@ "CVE-2007-2970" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cgi/block.cgi in 8e6 R3000 Internet Filter allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) CAT, and (3) USER parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgx3-3w99-wc79/GHSA-fgx3-3w99-wc79.json b/advisories/unreviewed/2022/05/GHSA-fgx3-3w99-wc79/GHSA-fgx3-3w99-wc79.json index e0c9b2847ea..618f7ac7f87 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgx3-3w99-wc79/GHSA-fgx3-3w99-wc79.json +++ b/advisories/unreviewed/2022/05/GHSA-fgx3-3w99-wc79/GHSA-fgx3-3w99-wc79.json @@ -7,12 +7,8 @@ "CVE-2007-2944" ], "details": "WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/wabcmsn.mdb. NOTE: this issue was originally reported for \"webCMS,\" but this was an error by an unreliable researcher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmjp-wxp5-gjh3/GHSA-fmjp-wxp5-gjh3.json b/advisories/unreviewed/2022/05/GHSA-fmjp-wxp5-gjh3/GHSA-fmjp-wxp5-gjh3.json index 83a98f3aa46..40870b51f15 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmjp-wxp5-gjh3/GHSA-fmjp-wxp5-gjh3.json +++ b/advisories/unreviewed/2022/05/GHSA-fmjp-wxp5-gjh3/GHSA-fmjp-wxp5-gjh3.json @@ -7,12 +7,8 @@ "CVE-2007-2972" ], "details": "The file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a crafted UPX compressed file, which triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmjr-33qp-379x/GHSA-fmjr-33qp-379x.json b/advisories/unreviewed/2022/05/GHSA-fmjr-33qp-379x/GHSA-fmjr-33qp-379x.json index e61b46aeae1..c7707d33346 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmjr-33qp-379x/GHSA-fmjr-33qp-379x.json +++ b/advisories/unreviewed/2022/05/GHSA-fmjr-33qp-379x/GHSA-fmjr-33qp-379x.json @@ -7,12 +7,8 @@ "CVE-2007-3045" ], "details": "Unspecified vulnerability in Hitachi TP1/NET/OSI-TP-Extended on HI-UX/WE2 before 20070213, and on HP-UX before 20070314, allows remote attackers to cause a denial of service via certain data to a port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp29-9qg5-fwm3/GHSA-fp29-9qg5-fwm3.json b/advisories/unreviewed/2022/05/GHSA-fp29-9qg5-fwm3/GHSA-fp29-9qg5-fwm3.json index b0c7e88fc07..e63c397c870 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp29-9qg5-fwm3/GHSA-fp29-9qg5-fwm3.json +++ b/advisories/unreviewed/2022/05/GHSA-fp29-9qg5-fwm3/GHSA-fp29-9qg5-fwm3.json @@ -7,12 +7,8 @@ "CVE-2007-3134" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using \"Approve Comments.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpf2-5gv4-8ffg/GHSA-fpf2-5gv4-8ffg.json b/advisories/unreviewed/2022/05/GHSA-fpf2-5gv4-8ffg/GHSA-fpf2-5gv4-8ffg.json index 6cc8ded9935..e322891f270 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpf2-5gv4-8ffg/GHSA-fpf2-5gv4-8ffg.json +++ b/advisories/unreviewed/2022/05/GHSA-fpf2-5gv4-8ffg/GHSA-fpf2-5gv4-8ffg.json @@ -7,12 +7,8 @@ "CVE-2007-3204" ], "details": "SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr3w-j4xg-gwmq/GHSA-fr3w-j4xg-gwmq.json b/advisories/unreviewed/2022/05/GHSA-fr3w-j4xg-gwmq/GHSA-fr3w-j4xg-gwmq.json index 915ee3296c3..73aebf17654 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr3w-j4xg-gwmq/GHSA-fr3w-j4xg-gwmq.json +++ b/advisories/unreviewed/2022/05/GHSA-fr3w-j4xg-gwmq/GHSA-fr3w-j4xg-gwmq.json @@ -7,12 +7,8 @@ "CVE-2007-2715" ], "details": "Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv98-6q86-3fpp/GHSA-fv98-6q86-3fpp.json b/advisories/unreviewed/2022/05/GHSA-fv98-6q86-3fpp/GHSA-fv98-6q86-3fpp.json index 395bac37a48..dd652387de3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv98-6q86-3fpp/GHSA-fv98-6q86-3fpp.json +++ b/advisories/unreviewed/2022/05/GHSA-fv98-6q86-3fpp/GHSA-fv98-6q86-3fpp.json @@ -7,12 +7,8 @@ "CVE-2007-3118" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the scdir parameter to (1) action.php, (2) subs.php, or (3) unsubs.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvjg-w742-28hw/GHSA-fvjg-w742-28hw.json b/advisories/unreviewed/2022/05/GHSA-fvjg-w742-28hw/GHSA-fvjg-w742-28hw.json index 3a40f514e90..be2f261af13 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvjg-w742-28hw/GHSA-fvjg-w742-28hw.json +++ b/advisories/unreviewed/2022/05/GHSA-fvjg-w742-28hw/GHSA-fvjg-w742-28hw.json @@ -7,12 +7,8 @@ "CVE-2007-3023" ], "details": "unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvrh-vqfq-rcp7/GHSA-fvrh-vqfq-rcp7.json b/advisories/unreviewed/2022/05/GHSA-fvrh-vqfq-rcp7/GHSA-fvrh-vqfq-rcp7.json index 1c06f1ab9b6..450f190e3cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvrh-vqfq-rcp7/GHSA-fvrh-vqfq-rcp7.json +++ b/advisories/unreviewed/2022/05/GHSA-fvrh-vqfq-rcp7/GHSA-fvrh-vqfq-rcp7.json @@ -7,12 +7,8 @@ "CVE-2007-3080" ], "details": "SQL injection vulnerability in haberoku.asp in Hunkaray Okul Portaly 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw9q-42wp-7h55/GHSA-fw9q-42wp-7h55.json b/advisories/unreviewed/2022/05/GHSA-fw9q-42wp-7h55/GHSA-fw9q-42wp-7h55.json index 5869300c559..bbc57282251 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw9q-42wp-7h55/GHSA-fw9q-42wp-7h55.json +++ b/advisories/unreviewed/2022/05/GHSA-fw9q-42wp-7h55/GHSA-fw9q-42wp-7h55.json @@ -7,12 +7,8 @@ "CVE-2007-2880" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwcg-wgp8-qrmr/GHSA-fwcg-wgp8-qrmr.json b/advisories/unreviewed/2022/05/GHSA-fwcg-wgp8-qrmr/GHSA-fwcg-wgp8-qrmr.json index b2fef2f4637..a4923a3629e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwcg-wgp8-qrmr/GHSA-fwcg-wgp8-qrmr.json +++ b/advisories/unreviewed/2022/05/GHSA-fwcg-wgp8-qrmr/GHSA-fwcg-wgp8-qrmr.json @@ -7,12 +7,8 @@ "CVE-2007-3069" ], "details": "xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwpj-2768-6hfr/GHSA-fwpj-2768-6hfr.json b/advisories/unreviewed/2022/05/GHSA-fwpj-2768-6hfr/GHSA-fwpj-2768-6hfr.json index 639012e8ae4..b6fb998ce8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwpj-2768-6hfr/GHSA-fwpj-2768-6hfr.json +++ b/advisories/unreviewed/2022/05/GHSA-fwpj-2768-6hfr/GHSA-fwpj-2768-6hfr.json @@ -7,12 +7,8 @@ "CVE-2007-2719" ], "details": "Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxqv-wg5x-xxgc/GHSA-fxqv-wg5x-xxgc.json b/advisories/unreviewed/2022/05/GHSA-fxqv-wg5x-xxgc/GHSA-fxqv-wg5x-xxgc.json index b720bd20f97..8533090d311 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxqv-wg5x-xxgc/GHSA-fxqv-wg5x-xxgc.json +++ b/advisories/unreviewed/2022/05/GHSA-fxqv-wg5x-xxgc/GHSA-fxqv-wg5x-xxgc.json @@ -7,12 +7,8 @@ "CVE-2007-3184" ], "details": "Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2p3-j47p-8cwj/GHSA-g2p3-j47p-8cwj.json b/advisories/unreviewed/2022/05/GHSA-g2p3-j47p-8cwj/GHSA-g2p3-j47p-8cwj.json index 2762809f3a0..2809b90ae69 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2p3-j47p-8cwj/GHSA-g2p3-j47p-8cwj.json +++ b/advisories/unreviewed/2022/05/GHSA-g2p3-j47p-8cwj/GHSA-g2p3-j47p-8cwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3vg-q854-qppq/GHSA-g3vg-q854-qppq.json b/advisories/unreviewed/2022/05/GHSA-g3vg-q854-qppq/GHSA-g3vg-q854-qppq.json index 43c7685352a..6274519c908 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3vg-q854-qppq/GHSA-g3vg-q854-qppq.json +++ b/advisories/unreviewed/2022/05/GHSA-g3vg-q854-qppq/GHSA-g3vg-q854-qppq.json @@ -7,12 +7,8 @@ "CVE-2007-3084" ], "details": "PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter, a different vector than CVE-2006-5441.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g4f6-c395-3jhj/GHSA-g4f6-c395-3jhj.json b/advisories/unreviewed/2022/05/GHSA-g4f6-c395-3jhj/GHSA-g4f6-c395-3jhj.json index cae02c569e2..df891dd8150 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4f6-c395-3jhj/GHSA-g4f6-c395-3jhj.json +++ b/advisories/unreviewed/2022/05/GHSA-g4f6-c395-3jhj/GHSA-g4f6-c395-3jhj.json @@ -7,12 +7,8 @@ "CVE-2007-2809" ], "details": "Buffer overflow in the transfer manager in Opera before 9.21 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted torrent file. NOTE: due to the lack of details, it is not clear if this is the same issue as CVE-2007-2274.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g53j-8c3f-8rrj/GHSA-g53j-8c3f-8rrj.json b/advisories/unreviewed/2022/05/GHSA-g53j-8c3f-8rrj/GHSA-g53j-8c3f-8rrj.json index 50a483bfd0a..d1b5ddcb4e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g53j-8c3f-8rrj/GHSA-g53j-8c3f-8rrj.json +++ b/advisories/unreviewed/2022/05/GHSA-g53j-8c3f-8rrj/GHSA-g53j-8c3f-8rrj.json @@ -7,12 +7,8 @@ "CVE-2019-13391" ], "details": "In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g58w-3x65-p39p/GHSA-g58w-3x65-p39p.json b/advisories/unreviewed/2022/05/GHSA-g58w-3x65-p39p/GHSA-g58w-3x65-p39p.json index d002e84d887..9810b477caf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g58w-3x65-p39p/GHSA-g58w-3x65-p39p.json +++ b/advisories/unreviewed/2022/05/GHSA-g58w-3x65-p39p/GHSA-g58w-3x65-p39p.json @@ -7,12 +7,8 @@ "CVE-2007-3009" ], "details": "Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a \"GET %n://localhost:80/\" request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5vp-ppp7-gmw8/GHSA-g5vp-ppp7-gmw8.json b/advisories/unreviewed/2022/05/GHSA-g5vp-ppp7-gmw8/GHSA-g5vp-ppp7-gmw8.json index c2cf8c561b9..7c60d89da27 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5vp-ppp7-gmw8/GHSA-g5vp-ppp7-gmw8.json +++ b/advisories/unreviewed/2022/05/GHSA-g5vp-ppp7-gmw8/GHSA-g5vp-ppp7-gmw8.json @@ -7,12 +7,8 @@ "CVE-2007-3111" ], "details": "Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6mx-39hp-44rm/GHSA-g6mx-39hp-44rm.json b/advisories/unreviewed/2022/05/GHSA-g6mx-39hp-44rm/GHSA-g6mx-39hp-44rm.json index c309e55895c..857e7fce5be 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6mx-39hp-44rm/GHSA-g6mx-39hp-44rm.json +++ b/advisories/unreviewed/2022/05/GHSA-g6mx-39hp-44rm/GHSA-g6mx-39hp-44rm.json @@ -7,12 +7,8 @@ "CVE-2007-3163" ], "details": "Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g74r-f7v2-952m/GHSA-g74r-f7v2-952m.json b/advisories/unreviewed/2022/05/GHSA-g74r-f7v2-952m/GHSA-g74r-f7v2-952m.json index 97d3e2c0041..2611db297f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g74r-f7v2-952m/GHSA-g74r-f7v2-952m.json +++ b/advisories/unreviewed/2022/05/GHSA-g74r-f7v2-952m/GHSA-g74r-f7v2-952m.json @@ -7,12 +7,8 @@ "CVE-2007-2825" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ReadMsg.php in @Mail 5.02 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) links and (2) images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g79j-r2mj-4w72/GHSA-g79j-r2mj-4w72.json b/advisories/unreviewed/2022/05/GHSA-g79j-r2mj-4w72/GHSA-g79j-r2mj-4w72.json index 9cfb690d06d..1f348d7544a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g79j-r2mj-4w72/GHSA-g79j-r2mj-4w72.json +++ b/advisories/unreviewed/2022/05/GHSA-g79j-r2mj-4w72/GHSA-g79j-r2mj-4w72.json @@ -7,12 +7,8 @@ "CVE-2007-3150" ], "details": "Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV=\"refresh\" that targets a www.google.com search for a local .exe file, which is displayed in the \"results stored on your computer\" portion of the search results, and when clicked invokes Google Desktop to execute this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7c8-49c3-qh57/GHSA-g7c8-49c3-qh57.json b/advisories/unreviewed/2022/05/GHSA-g7c8-49c3-qh57/GHSA-g7c8-49c3-qh57.json index 6402fec9369..883ac894e62 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7c8-49c3-qh57/GHSA-g7c8-49c3-qh57.json +++ b/advisories/unreviewed/2022/05/GHSA-g7c8-49c3-qh57/GHSA-g7c8-49c3-qh57.json @@ -7,12 +7,8 @@ "CVE-2007-3006" ], "details": "Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF element containing a long string in the HREF attribute. NOTE: it was later claimed that 4.51 Build 147 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7pw-mfx9-c9h5/GHSA-g7pw-mfx9-c9h5.json b/advisories/unreviewed/2022/05/GHSA-g7pw-mfx9-c9h5/GHSA-g7pw-mfx9-c9h5.json index eb8d5cce980..77756cd17e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7pw-mfx9-c9h5/GHSA-g7pw-mfx9-c9h5.json +++ b/advisories/unreviewed/2022/05/GHSA-g7pw-mfx9-c9h5/GHSA-g7pw-mfx9-c9h5.json @@ -7,12 +7,8 @@ "CVE-2007-3161" ], "details": "Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7rw-6q9w-p2m5/GHSA-g7rw-6q9w-p2m5.json b/advisories/unreviewed/2022/05/GHSA-g7rw-6q9w-p2m5/GHSA-g7rw-6q9w-p2m5.json index 466f9fd3d83..d882954af42 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7rw-6q9w-p2m5/GHSA-g7rw-6q9w-p2m5.json +++ b/advisories/unreviewed/2022/05/GHSA-g7rw-6q9w-p2m5/GHSA-g7rw-6q9w-p2m5.json @@ -7,12 +7,8 @@ "CVE-2007-2718" ], "details": "Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g882-xj52-3jj3/GHSA-g882-xj52-3jj3.json b/advisories/unreviewed/2022/05/GHSA-g882-xj52-3jj3/GHSA-g882-xj52-3jj3.json index 2617a81351d..e9a7677c4f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-g882-xj52-3jj3/GHSA-g882-xj52-3jj3.json +++ b/advisories/unreviewed/2022/05/GHSA-g882-xj52-3jj3/GHSA-g882-xj52-3jj3.json @@ -7,12 +7,8 @@ "CVE-2007-2803" ], "details": "SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a haberdetay action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8m9-qrr9-p2v9/GHSA-g8m9-qrr9-p2v9.json b/advisories/unreviewed/2022/05/GHSA-g8m9-qrr9-p2v9/GHSA-g8m9-qrr9-p2v9.json index 335d4787253..08e8269ca04 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8m9-qrr9-p2v9/GHSA-g8m9-qrr9-p2v9.json +++ b/advisories/unreviewed/2022/05/GHSA-g8m9-qrr9-p2v9/GHSA-g8m9-qrr9-p2v9.json @@ -7,12 +7,8 @@ "CVE-2007-2990" ], "details": "Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g97r-97g8-642h/GHSA-g97r-97g8-642h.json b/advisories/unreviewed/2022/05/GHSA-g97r-97g8-642h/GHSA-g97r-97g8-642h.json index ccab5c7e076..ab8acc177b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g97r-97g8-642h/GHSA-g97r-97g8-642h.json +++ b/advisories/unreviewed/2022/05/GHSA-g97r-97g8-642h/GHSA-g97r-97g8-642h.json @@ -7,12 +7,8 @@ "CVE-2007-3131" ], "details": "Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh9c-cfrp-6xww/GHSA-gh9c-cfrp-6xww.json b/advisories/unreviewed/2022/05/GHSA-gh9c-cfrp-6xww/GHSA-gh9c-cfrp-6xww.json index 0ae0baef88c..8c3ebc5210d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh9c-cfrp-6xww/GHSA-gh9c-cfrp-6xww.json +++ b/advisories/unreviewed/2022/05/GHSA-gh9c-cfrp-6xww/GHSA-gh9c-cfrp-6xww.json @@ -7,12 +7,8 @@ "CVE-2007-2812" ], "details": "Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.35, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj2v-jr84-7j79/GHSA-gj2v-jr84-7j79.json b/advisories/unreviewed/2022/05/GHSA-gj2v-jr84-7j79/GHSA-gj2v-jr84-7j79.json index ca83516f71e..6f1cc96efa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj2v-jr84-7j79/GHSA-gj2v-jr84-7j79.json +++ b/advisories/unreviewed/2022/05/GHSA-gj2v-jr84-7j79/GHSA-gj2v-jr84-7j79.json @@ -7,12 +7,8 @@ "CVE-2019-12615" ], "details": "An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj6f-vjc9-2qq7/GHSA-gj6f-vjc9-2qq7.json b/advisories/unreviewed/2022/05/GHSA-gj6f-vjc9-2qq7/GHSA-gj6f-vjc9-2qq7.json index f69ddbf4d24..b486c470bab 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj6f-vjc9-2qq7/GHSA-gj6f-vjc9-2qq7.json +++ b/advisories/unreviewed/2022/05/GHSA-gj6f-vjc9-2qq7/GHSA-gj6f-vjc9-2qq7.json @@ -7,12 +7,8 @@ "CVE-2007-3038" ], "details": "The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka \"Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjr5-xrxx-mv2c/GHSA-gjr5-xrxx-mv2c.json b/advisories/unreviewed/2022/05/GHSA-gjr5-xrxx-mv2c/GHSA-gjr5-xrxx-mv2c.json index f867493c056..a07a5664e65 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjr5-xrxx-mv2c/GHSA-gjr5-xrxx-mv2c.json +++ b/advisories/unreviewed/2022/05/GHSA-gjr5-xrxx-mv2c/GHSA-gjr5-xrxx-mv2c.json @@ -7,12 +7,8 @@ "CVE-2007-2985" ], "details": "Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm69-6gh3-7539/GHSA-gm69-6gh3-7539.json b/advisories/unreviewed/2022/05/GHSA-gm69-6gh3-7539/GHSA-gm69-6gh3-7539.json index ae6a4bc98d9..03a72185b9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm69-6gh3-7539/GHSA-gm69-6gh3-7539.json +++ b/advisories/unreviewed/2022/05/GHSA-gm69-6gh3-7539/GHSA-gm69-6gh3-7539.json @@ -7,12 +7,8 @@ "CVE-2007-3213" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in Sporum Forum 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) mode parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json b/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json index a923ce4b513..b69a0e4e91b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json +++ b/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmrh-7jr3-v9qp/GHSA-gmrh-7jr3-v9qp.json b/advisories/unreviewed/2022/05/GHSA-gmrh-7jr3-v9qp/GHSA-gmrh-7jr3-v9qp.json index d2eb5a77715..bc531b995b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmrh-7jr3-v9qp/GHSA-gmrh-7jr3-v9qp.json +++ b/advisories/unreviewed/2022/05/GHSA-gmrh-7jr3-v9qp/GHSA-gmrh-7jr3-v9qp.json @@ -7,12 +7,8 @@ "CVE-2007-3096" ], "details": "Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gp67-3fvq-8r37/GHSA-gp67-3fvq-8r37.json b/advisories/unreviewed/2022/05/GHSA-gp67-3fvq-8r37/GHSA-gp67-3fvq-8r37.json index d68af0307c8..fffb1b95c24 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp67-3fvq-8r37/GHSA-gp67-3fvq-8r37.json +++ b/advisories/unreviewed/2022/05/GHSA-gp67-3fvq-8r37/GHSA-gp67-3fvq-8r37.json @@ -7,12 +7,8 @@ "CVE-2007-3191" ], "details": "Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gp7x-938x-q5x3/GHSA-gp7x-938x-q5x3.json b/advisories/unreviewed/2022/05/GHSA-gp7x-938x-q5x3/GHSA-gp7x-938x-q5x3.json index 3bfe66532c2..53bb4f8fb8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp7x-938x-q5x3/GHSA-gp7x-938x-q5x3.json +++ b/advisories/unreviewed/2022/05/GHSA-gp7x-938x-q5x3/GHSA-gp7x-938x-q5x3.json @@ -7,12 +7,8 @@ "CVE-2007-3196" ], "details": "SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gp9h-9phm-hw9m/GHSA-gp9h-9phm-hw9m.json b/advisories/unreviewed/2022/05/GHSA-gp9h-9phm-hw9m/GHSA-gp9h-9phm-hw9m.json index 9c118faf446..ccc2146f177 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp9h-9phm-hw9m/GHSA-gp9h-9phm-hw9m.json +++ b/advisories/unreviewed/2022/05/GHSA-gp9h-9phm-hw9m/GHSA-gp9h-9phm-hw9m.json @@ -7,12 +7,8 @@ "CVE-2019-12458" ], "details": "FileRun 2019.05.21 allows css/ext-ux Directory Listing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpm3-3x52-7vhw/GHSA-gpm3-3x52-7vhw.json b/advisories/unreviewed/2022/05/GHSA-gpm3-3x52-7vhw/GHSA-gpm3-3x52-7vhw.json index 5098fc9b566..031a14d7b69 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpm3-3x52-7vhw/GHSA-gpm3-3x52-7vhw.json +++ b/advisories/unreviewed/2022/05/GHSA-gpm3-3x52-7vhw/GHSA-gpm3-3x52-7vhw.json @@ -7,12 +7,8 @@ "CVE-2007-2823" ], "details": "Multiple buffer overflows in HT Editor before 2.0.6 might allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the editor display width. NOTE: some of the details were obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqfm-cqpj-28j8/GHSA-gqfm-cqpj-28j8.json b/advisories/unreviewed/2022/05/GHSA-gqfm-cqpj-28j8/GHSA-gqfm-cqpj-28j8.json index fefeb79fdac..03db1cc0bcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqfm-cqpj-28j8/GHSA-gqfm-cqpj-28j8.json +++ b/advisories/unreviewed/2022/05/GHSA-gqfm-cqpj-28j8/GHSA-gqfm-cqpj-28j8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqfp-5799-p5g4/GHSA-gqfp-5799-p5g4.json b/advisories/unreviewed/2022/05/GHSA-gqfp-5799-p5g4/GHSA-gqfp-5799-p5g4.json index dc924ac9870..0cda21b845e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqfp-5799-p5g4/GHSA-gqfp-5799-p5g4.json +++ b/advisories/unreviewed/2022/05/GHSA-gqfp-5799-p5g4/GHSA-gqfp-5799-p5g4.json @@ -7,12 +7,8 @@ "CVE-2007-2742" ], "details": "Unrestricted file upload vulnerability in labs.beffa.org w2box 4.0.0 Beta4 allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as .php.jpg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqp8-2w4f-r5wh/GHSA-gqp8-2w4f-r5wh.json b/advisories/unreviewed/2022/05/GHSA-gqp8-2w4f-r5wh/GHSA-gqp8-2w4f-r5wh.json index 9fc536ffdab..641069a065d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqp8-2w4f-r5wh/GHSA-gqp8-2w4f-r5wh.json +++ b/advisories/unreviewed/2022/05/GHSA-gqp8-2w4f-r5wh/GHSA-gqp8-2w4f-r5wh.json @@ -7,12 +7,8 @@ "CVE-2019-12481" ], "details": "An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvj3-g3g4-cwmm/GHSA-gvj3-g3g4-cwmm.json b/advisories/unreviewed/2022/05/GHSA-gvj3-g3g4-cwmm/GHSA-gvj3-g3g4-cwmm.json index a2b8ba759fa..011a56ebcdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvj3-g3g4-cwmm/GHSA-gvj3-g3g4-cwmm.json +++ b/advisories/unreviewed/2022/05/GHSA-gvj3-g3g4-cwmm/GHSA-gvj3-g3g4-cwmm.json @@ -7,12 +7,8 @@ "CVE-2007-3077" ], "details": "SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwcj-8rpj-q3qx/GHSA-gwcj-8rpj-q3qx.json b/advisories/unreviewed/2022/05/GHSA-gwcj-8rpj-q3qx/GHSA-gwcj-8rpj-q3qx.json index c6cdc5e22b4..7766cd8063c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwcj-8rpj-q3qx/GHSA-gwcj-8rpj-q3qx.json +++ b/advisories/unreviewed/2022/05/GHSA-gwcj-8rpj-q3qx/GHSA-gwcj-8rpj-q3qx.json @@ -7,12 +7,8 @@ "CVE-2007-2920" ], "details": "Multiple stack-based buffer overflows in the Zoomify Viewer ActiveX control in ZActiveX.dll might allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwjg-g7fp-9349/GHSA-gwjg-g7fp-9349.json b/advisories/unreviewed/2022/05/GHSA-gwjg-g7fp-9349/GHSA-gwjg-g7fp-9349.json index 2619a06363c..e6c7830e790 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwjg-g7fp-9349/GHSA-gwjg-g7fp-9349.json +++ b/advisories/unreviewed/2022/05/GHSA-gwjg-g7fp-9349/GHSA-gwjg-g7fp-9349.json @@ -7,12 +7,8 @@ "CVE-2007-3079" ], "details": "listmembers.php in EQdkp 1.3.2c and earlier allows remote attackers to obtain sensitive information via an invalid compare parameter, which reveals the path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwpx-qg6m-mrg3/GHSA-gwpx-qg6m-mrg3.json b/advisories/unreviewed/2022/05/GHSA-gwpx-qg6m-mrg3/GHSA-gwpx-qg6m-mrg3.json index f46ddc15813..ba17d3735b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwpx-qg6m-mrg3/GHSA-gwpx-qg6m-mrg3.json +++ b/advisories/unreviewed/2022/05/GHSA-gwpx-qg6m-mrg3/GHSA-gwpx-qg6m-mrg3.json @@ -7,12 +7,8 @@ "CVE-2007-3192" ], "details": "admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx56-w6x8-7fjx/GHSA-gx56-w6x8-7fjx.json b/advisories/unreviewed/2022/05/GHSA-gx56-w6x8-7fjx/GHSA-gx56-w6x8-7fjx.json index a6331d48c22..308571dda3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx56-w6x8-7fjx/GHSA-gx56-w6x8-7fjx.json +++ b/advisories/unreviewed/2022/05/GHSA-gx56-w6x8-7fjx/GHSA-gx56-w6x8-7fjx.json @@ -7,12 +7,8 @@ "CVE-2019-10849" ], "details": "Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxjw-9699-jx3p/GHSA-gxjw-9699-jx3p.json b/advisories/unreviewed/2022/05/GHSA-gxjw-9699-jx3p/GHSA-gxjw-9699-jx3p.json index e77da71f23b..c3b3f9a3a47 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxjw-9699-jx3p/GHSA-gxjw-9699-jx3p.json +++ b/advisories/unreviewed/2022/05/GHSA-gxjw-9699-jx3p/GHSA-gxjw-9699-jx3p.json @@ -7,12 +7,8 @@ "CVE-2007-3062" ], "details": "Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2cw-8x87-xw5g/GHSA-h2cw-8x87-xw5g.json b/advisories/unreviewed/2022/05/GHSA-h2cw-8x87-xw5g/GHSA-h2cw-8x87-xw5g.json index 1cc99f3c112..ae8878bf63b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2cw-8x87-xw5g/GHSA-h2cw-8x87-xw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-h2cw-8x87-xw5g/GHSA-h2cw-8x87-xw5g.json @@ -7,12 +7,8 @@ "CVE-2007-3120" ], "details": "Cross-site scripting (XSS) vulnerability in public/code/cp_dpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HTML via the aiocp_dp parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2gp-f8gp-53cr/GHSA-h2gp-f8gp-53cr.json b/advisories/unreviewed/2022/05/GHSA-h2gp-f8gp-53cr/GHSA-h2gp-f8gp-53cr.json index 3ad6ba2812d..b256932bfa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2gp-f8gp-53cr/GHSA-h2gp-f8gp-53cr.json +++ b/advisories/unreviewed/2022/05/GHSA-h2gp-f8gp-53cr/GHSA-h2gp-f8gp-53cr.json @@ -7,12 +7,8 @@ "CVE-2007-3030" ], "details": "Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the \"denoting [of] the start of a Workspace designation\", which results in memory corruption, aka the \"Workbook Memory Corruption Vulnerability\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3c7-f29j-r2px/GHSA-h3c7-f29j-r2px.json b/advisories/unreviewed/2022/05/GHSA-h3c7-f29j-r2px/GHSA-h3c7-f29j-r2px.json index bb5ff013fd3..6c903a2f1ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3c7-f29j-r2px/GHSA-h3c7-f29j-r2px.json +++ b/advisories/unreviewed/2022/05/GHSA-h3c7-f29j-r2px/GHSA-h3c7-f29j-r2px.json @@ -7,12 +7,8 @@ "CVE-2007-2986" ], "details": "PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h48c-63vf-pv25/GHSA-h48c-63vf-pv25.json b/advisories/unreviewed/2022/05/GHSA-h48c-63vf-pv25/GHSA-h48c-63vf-pv25.json index c43350433a7..2e08883700c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h48c-63vf-pv25/GHSA-h48c-63vf-pv25.json +++ b/advisories/unreviewed/2022/05/GHSA-h48c-63vf-pv25/GHSA-h48c-63vf-pv25.json @@ -7,12 +7,8 @@ "CVE-2007-2900" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4wm-q3c7-xjx3/GHSA-h4wm-q3c7-xjx3.json b/advisories/unreviewed/2022/05/GHSA-h4wm-q3c7-xjx3/GHSA-h4wm-q3c7-xjx3.json index 59edb0b28d3..0521cb2c4ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4wm-q3c7-xjx3/GHSA-h4wm-q3c7-xjx3.json +++ b/advisories/unreviewed/2022/05/GHSA-h4wm-q3c7-xjx3/GHSA-h4wm-q3c7-xjx3.json @@ -7,12 +7,8 @@ "CVE-2007-3210" ], "details": "Stack-based buffer overflow in nptoken.mox in the Cellosoft Tokens Object 2.0.0.6 extension for Vitalize! allows remote attackers to execute arbitrary code via a long string argument to the RemoveChr method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5c9-c4h7-3ccq/GHSA-h5c9-c4h7-3ccq.json b/advisories/unreviewed/2022/05/GHSA-h5c9-c4h7-3ccq/GHSA-h5c9-c4h7-3ccq.json index c656783e4c4..fd24cf168f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5c9-c4h7-3ccq/GHSA-h5c9-c4h7-3ccq.json +++ b/advisories/unreviewed/2022/05/GHSA-h5c9-c4h7-3ccq/GHSA-h5c9-c4h7-3ccq.json @@ -7,12 +7,8 @@ "CVE-2007-2808" ], "details": "Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5fh-vcjp-29p9/GHSA-h5fh-vcjp-29p9.json b/advisories/unreviewed/2022/05/GHSA-h5fh-vcjp-29p9/GHSA-h5fh-vcjp-29p9.json index e3f3076664c..77aeb082333 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5fh-vcjp-29p9/GHSA-h5fh-vcjp-29p9.json +++ b/advisories/unreviewed/2022/05/GHSA-h5fh-vcjp-29p9/GHSA-h5fh-vcjp-29p9.json @@ -7,12 +7,8 @@ "CVE-2007-2811" ], "details": "Cross-site scripting (XSS) vulnerability in OSK Advance-Flow 4.41 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5fq-66m8-wp4v/GHSA-h5fq-66m8-wp4v.json b/advisories/unreviewed/2022/05/GHSA-h5fq-66m8-wp4v/GHSA-h5fq-66m8-wp4v.json index 4bf3dad1a21..c50a4823ed5 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5fq-66m8-wp4v/GHSA-h5fq-66m8-wp4v.json +++ b/advisories/unreviewed/2022/05/GHSA-h5fq-66m8-wp4v/GHSA-h5fq-66m8-wp4v.json @@ -7,12 +7,8 @@ "CVE-2019-9218" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6wh-9428-q73r/GHSA-h6wh-9428-q73r.json b/advisories/unreviewed/2022/05/GHSA-h6wh-9428-q73r/GHSA-h6wh-9428-q73r.json index ed67e847be9..5d242457bf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wh-9428-q73r/GHSA-h6wh-9428-q73r.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wh-9428-q73r/GHSA-h6wh-9428-q73r.json @@ -7,12 +7,8 @@ "CVE-2019-12614" ], "details": "An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6wj-gcf6-rxw5/GHSA-h6wj-gcf6-rxw5.json b/advisories/unreviewed/2022/05/GHSA-h6wj-gcf6-rxw5/GHSA-h6wj-gcf6-rxw5.json index 485bcda81c3..94b59754be1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wj-gcf6-rxw5/GHSA-h6wj-gcf6-rxw5.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wj-gcf6-rxw5/GHSA-h6wj-gcf6-rxw5.json @@ -7,12 +7,8 @@ "CVE-2019-5586" ], "details": "A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the \"param\" parameter of the error process HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h79x-vhj6-x5xh/GHSA-h79x-vhj6-x5xh.json b/advisories/unreviewed/2022/05/GHSA-h79x-vhj6-x5xh/GHSA-h79x-vhj6-x5xh.json index 8dea0b2c536..1d584b97bb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h79x-vhj6-x5xh/GHSA-h79x-vhj6-x5xh.json +++ b/advisories/unreviewed/2022/05/GHSA-h79x-vhj6-x5xh/GHSA-h79x-vhj6-x5xh.json @@ -7,12 +7,8 @@ "CVE-2007-2708" ], "details": "PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h847-vwmq-pp6m/GHSA-h847-vwmq-pp6m.json b/advisories/unreviewed/2022/05/GHSA-h847-vwmq-pp6m/GHSA-h847-vwmq-pp6m.json index f5a04d880c4..59d2d26e26b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h847-vwmq-pp6m/GHSA-h847-vwmq-pp6m.json +++ b/advisories/unreviewed/2022/05/GHSA-h847-vwmq-pp6m/GHSA-h847-vwmq-pp6m.json @@ -7,12 +7,8 @@ "CVE-2007-2886" ], "details": "Unspecified vulnerability in the Nortel CS 1000 M media card in Enterprise VoIP-Core-CS 1000E, 1000M, and 1000S 04.50W before 20070523 in Meridian/CS 1000 allows remote attackers to cause a denial of service (card hang) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9cp-8fw3-4wc5/GHSA-h9cp-8fw3-4wc5.json b/advisories/unreviewed/2022/05/GHSA-h9cp-8fw3-4wc5/GHSA-h9cp-8fw3-4wc5.json index 16f9c8a6cb9..b5044151dd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9cp-8fw3-4wc5/GHSA-h9cp-8fw3-4wc5.json +++ b/advisories/unreviewed/2022/05/GHSA-h9cp-8fw3-4wc5/GHSA-h9cp-8fw3-4wc5.json @@ -7,12 +7,8 @@ "CVE-2018-18836" ], "details": "An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/api/web_api_v1.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hc4f-pv87-6q3g/GHSA-hc4f-pv87-6q3g.json b/advisories/unreviewed/2022/05/GHSA-hc4f-pv87-6q3g/GHSA-hc4f-pv87-6q3g.json index f1c1fb43601..5fbea921968 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc4f-pv87-6q3g/GHSA-hc4f-pv87-6q3g.json +++ b/advisories/unreviewed/2022/05/GHSA-hc4f-pv87-6q3g/GHSA-hc4f-pv87-6q3g.json @@ -7,12 +7,8 @@ "CVE-2007-3094" ], "details": "Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to execute arbitrary code via unspecified vectors, related to the WBEM server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcvg-3vrp-pjx9/GHSA-hcvg-3vrp-pjx9.json b/advisories/unreviewed/2022/05/GHSA-hcvg-3vrp-pjx9/GHSA-hcvg-3vrp-pjx9.json index d30a2b04640..8b3417528e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcvg-3vrp-pjx9/GHSA-hcvg-3vrp-pjx9.json +++ b/advisories/unreviewed/2022/05/GHSA-hcvg-3vrp-pjx9/GHSA-hcvg-3vrp-pjx9.json @@ -7,12 +7,8 @@ "CVE-2007-3028" ], "details": "The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check \"the number of convertible attributes\", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to \"client sent LDAP request logic,\" aka \"Windows Active Directory Denial of Service Vulnerability\". NOTE: this is probably a different issue than CVE-2007-0040.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp47-jvh8-33rq/GHSA-hp47-jvh8-33rq.json b/advisories/unreviewed/2022/05/GHSA-hp47-jvh8-33rq/GHSA-hp47-jvh8-33rq.json index 8dc8b659b73..dd1ad2f55ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp47-jvh8-33rq/GHSA-hp47-jvh8-33rq.json +++ b/advisories/unreviewed/2022/05/GHSA-hp47-jvh8-33rq/GHSA-hp47-jvh8-33rq.json @@ -7,12 +7,8 @@ "CVE-2007-2978" ], "details": "Session fixation vulnerability in eggblog 3.1.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp9h-7wrh-x4j5/GHSA-hp9h-7wrh-x4j5.json b/advisories/unreviewed/2022/05/GHSA-hp9h-7wrh-x4j5/GHSA-hp9h-7wrh-x4j5.json index 28fcc93aa97..1b60b7f1c37 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp9h-7wrh-x4j5/GHSA-hp9h-7wrh-x4j5.json +++ b/advisories/unreviewed/2022/05/GHSA-hp9h-7wrh-x4j5/GHSA-hp9h-7wrh-x4j5.json @@ -7,12 +7,8 @@ "CVE-2007-2845" ], "details": "Heap-based buffer overflow in the CAB unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted CAB archive, resulting from an \"integer cast around\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpx5-r3q5-52m2/GHSA-hpx5-r3q5-52m2.json b/advisories/unreviewed/2022/05/GHSA-hpx5-r3q5-52m2/GHSA-hpx5-r3q5-52m2.json index 0524207d5ad..89f5f27646e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpx5-r3q5-52m2/GHSA-hpx5-r3q5-52m2.json +++ b/advisories/unreviewed/2022/05/GHSA-hpx5-r3q5-52m2/GHSA-hpx5-r3q5-52m2.json @@ -7,12 +7,8 @@ "CVE-2007-2932" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqjm-6mrv-23c6/GHSA-hqjm-6mrv-23c6.json b/advisories/unreviewed/2022/05/GHSA-hqjm-6mrv-23c6/GHSA-hqjm-6mrv-23c6.json index 475e6db9c6e..da9db933b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqjm-6mrv-23c6/GHSA-hqjm-6mrv-23c6.json +++ b/advisories/unreviewed/2022/05/GHSA-hqjm-6mrv-23c6/GHSA-hqjm-6mrv-23c6.json @@ -7,12 +7,8 @@ "CVE-2007-3086" ], "details": "Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqw6-cpc6-hr59/GHSA-hqw6-cpc6-hr59.json b/advisories/unreviewed/2022/05/GHSA-hqw6-cpc6-hr59/GHSA-hqw6-cpc6-hr59.json index ca810fe6c1f..a6bef3b191f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqw6-cpc6-hr59/GHSA-hqw6-cpc6-hr59.json +++ b/advisories/unreviewed/2022/05/GHSA-hqw6-cpc6-hr59/GHSA-hqw6-cpc6-hr59.json @@ -7,12 +7,8 @@ "CVE-2007-3119" ], "details": "SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqwx-gq78-vv2g/GHSA-hqwx-gq78-vv2g.json b/advisories/unreviewed/2022/05/GHSA-hqwx-gq78-vv2g/GHSA-hqwx-gq78-vv2g.json index d14bf66889a..c37f72a253e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqwx-gq78-vv2g/GHSA-hqwx-gq78-vv2g.json +++ b/advisories/unreviewed/2022/05/GHSA-hqwx-gq78-vv2g/GHSA-hqwx-gq78-vv2g.json @@ -7,12 +7,8 @@ "CVE-2007-2983" ], "details": "Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr3x-f276-3rmg/GHSA-hr3x-f276-3rmg.json b/advisories/unreviewed/2022/05/GHSA-hr3x-f276-3rmg/GHSA-hr3x-f276-3rmg.json index bc28c2702ea..2dbc4e98236 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr3x-f276-3rmg/GHSA-hr3x-f276-3rmg.json +++ b/advisories/unreviewed/2022/05/GHSA-hr3x-f276-3rmg/GHSA-hr3x-f276-3rmg.json @@ -7,12 +7,8 @@ "CVE-2007-2866" ], "details": "Multiple SQL injection vulnerabilities in modules/admin/modules/gallery.php in PHPEcho CMS 2.0-rc1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter and possibly other parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrr8-7rwv-p26v/GHSA-hrr8-7rwv-p26v.json b/advisories/unreviewed/2022/05/GHSA-hrr8-7rwv-p26v/GHSA-hrr8-7rwv-p26v.json index f9f5b8705f6..849603f8dea 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrr8-7rwv-p26v/GHSA-hrr8-7rwv-p26v.json +++ b/advisories/unreviewed/2022/05/GHSA-hrr8-7rwv-p26v/GHSA-hrr8-7rwv-p26v.json @@ -7,12 +7,8 @@ "CVE-2007-2760" ], "details": "The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvjc-v463-hr2w/GHSA-hvjc-v463-hr2w.json b/advisories/unreviewed/2022/05/GHSA-hvjc-v463-hr2w/GHSA-hvjc-v463-hr2w.json index 89847182fea..cba02124a7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvjc-v463-hr2w/GHSA-hvjc-v463-hr2w.json +++ b/advisories/unreviewed/2022/05/GHSA-hvjc-v463-hr2w/GHSA-hvjc-v463-hr2w.json @@ -7,12 +7,8 @@ "CVE-2007-3058" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Madirish Webmail 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter to (1) calendar.php, (2) compose.php, and (3) index.php, different vectors than CVE-2007-2826. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx46-fxf5-4hff/GHSA-hx46-fxf5-4hff.json b/advisories/unreviewed/2022/05/GHSA-hx46-fxf5-4hff/GHSA-hx46-fxf5-4hff.json index 71d82bf9309..5523ea6eda4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx46-fxf5-4hff/GHSA-hx46-fxf5-4hff.json +++ b/advisories/unreviewed/2022/05/GHSA-hx46-fxf5-4hff/GHSA-hx46-fxf5-4hff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxj4-xq5m-hh5h/GHSA-hxj4-xq5m-hh5h.json b/advisories/unreviewed/2022/05/GHSA-hxj4-xq5m-hh5h/GHSA-hxj4-xq5m-hh5h.json index 22cd9af5eb2..aa6c25e9fdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxj4-xq5m-hh5h/GHSA-hxj4-xq5m-hh5h.json +++ b/advisories/unreviewed/2022/05/GHSA-hxj4-xq5m-hh5h/GHSA-hxj4-xq5m-hh5h.json @@ -7,12 +7,8 @@ "CVE-2007-3024" ], "details": "libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxx4-229m-wgjj/GHSA-hxx4-229m-wgjj.json b/advisories/unreviewed/2022/05/GHSA-hxx4-229m-wgjj/GHSA-hxx4-229m-wgjj.json index 921f7972d6a..e68e74bc6a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxx4-229m-wgjj/GHSA-hxx4-229m-wgjj.json +++ b/advisories/unreviewed/2022/05/GHSA-hxx4-229m-wgjj/GHSA-hxx4-229m-wgjj.json @@ -7,12 +7,8 @@ "CVE-2007-2748" ], "details": "The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j38q-x2h8-gv86/GHSA-j38q-x2h8-gv86.json b/advisories/unreviewed/2022/05/GHSA-j38q-x2h8-gv86/GHSA-j38q-x2h8-gv86.json index 24af23db384..e3cfb3ac98e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j38q-x2h8-gv86/GHSA-j38q-x2h8-gv86.json +++ b/advisories/unreviewed/2022/05/GHSA-j38q-x2h8-gv86/GHSA-j38q-x2h8-gv86.json @@ -7,12 +7,8 @@ "CVE-2007-3265" ], "details": "Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j45j-wm3x-xr92/GHSA-j45j-wm3x-xr92.json b/advisories/unreviewed/2022/05/GHSA-j45j-wm3x-xr92/GHSA-j45j-wm3x-xr92.json index 09fac8e60d6..ba956932a50 100644 --- a/advisories/unreviewed/2022/05/GHSA-j45j-wm3x-xr92/GHSA-j45j-wm3x-xr92.json +++ b/advisories/unreviewed/2022/05/GHSA-j45j-wm3x-xr92/GHSA-j45j-wm3x-xr92.json @@ -7,12 +7,8 @@ "CVE-2007-3021" ], "details": "Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations of a file that is created during data export.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json b/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json index 0995e9351f3..20c3a05d169 100644 --- a/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json +++ b/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5hx-5prc-g52j/GHSA-j5hx-5prc-g52j.json b/advisories/unreviewed/2022/05/GHSA-j5hx-5prc-g52j/GHSA-j5hx-5prc-g52j.json index 9373d5e8e22..c0b034e7253 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5hx-5prc-g52j/GHSA-j5hx-5prc-g52j.json +++ b/advisories/unreviewed/2022/05/GHSA-j5hx-5prc-g52j/GHSA-j5hx-5prc-g52j.json @@ -7,12 +7,8 @@ "CVE-2007-2967" ], "details": "Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6px-5p94-m528/GHSA-j6px-5p94-m528.json b/advisories/unreviewed/2022/05/GHSA-j6px-5p94-m528/GHSA-j6px-5p94-m528.json index 57911f53704..5daac474a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6px-5p94-m528/GHSA-j6px-5p94-m528.json +++ b/advisories/unreviewed/2022/05/GHSA-j6px-5p94-m528/GHSA-j6px-5p94-m528.json @@ -7,12 +7,8 @@ "CVE-2007-2783" ], "details": "Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors. NOTE: this issue has no actionable information, and perhaps should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j7hr-hq3j-vpv3/GHSA-j7hr-hq3j-vpv3.json b/advisories/unreviewed/2022/05/GHSA-j7hr-hq3j-vpv3/GHSA-j7hr-hq3j-vpv3.json index 7f9fb796a3c..8cbae810ff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7hr-hq3j-vpv3/GHSA-j7hr-hq3j-vpv3.json +++ b/advisories/unreviewed/2022/05/GHSA-j7hr-hq3j-vpv3/GHSA-j7hr-hq3j-vpv3.json @@ -7,12 +7,8 @@ "CVE-2007-2791" ], "details": "Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified vectors, probably related to timing attacks and AuthInteractiveFailureRandomTimeout.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j7rr-c7j7-hfq3/GHSA-j7rr-c7j7-hfq3.json b/advisories/unreviewed/2022/05/GHSA-j7rr-c7j7-hfq3/GHSA-j7rr-c7j7-hfq3.json index c12ba486c35..0cfa3f2892c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7rr-c7j7-hfq3/GHSA-j7rr-c7j7-hfq3.json +++ b/advisories/unreviewed/2022/05/GHSA-j7rr-c7j7-hfq3/GHSA-j7rr-c7j7-hfq3.json @@ -7,12 +7,8 @@ "CVE-2007-3041" ], "details": "Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka \"ActiveX Object Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j85c-g589-f83h/GHSA-j85c-g589-f83h.json b/advisories/unreviewed/2022/05/GHSA-j85c-g589-f83h/GHSA-j85c-g589-f83h.json index d3f9f858d70..3d94ab0f983 100644 --- a/advisories/unreviewed/2022/05/GHSA-j85c-g589-f83h/GHSA-j85c-g589-f83h.json +++ b/advisories/unreviewed/2022/05/GHSA-j85c-g589-f83h/GHSA-j85c-g589-f83h.json @@ -7,12 +7,8 @@ "CVE-2019-7254" ], "details": "Linear eMerge E3-Series devices allow File Inclusion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc3p-c5fp-9h84/GHSA-jc3p-c5fp-9h84.json b/advisories/unreviewed/2022/05/GHSA-jc3p-c5fp-9h84/GHSA-jc3p-c5fp-9h84.json index 6848b6b217d..2a6b7ff6f8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc3p-c5fp-9h84/GHSA-jc3p-c5fp-9h84.json +++ b/advisories/unreviewed/2022/05/GHSA-jc3p-c5fp-9h84/GHSA-jc3p-c5fp-9h84.json @@ -7,12 +7,8 @@ "CVE-2007-3168" ], "details": "A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcx2-5qw3-59p6/GHSA-jcx2-5qw3-59p6.json b/advisories/unreviewed/2022/05/GHSA-jcx2-5qw3-59p6/GHSA-jcx2-5qw3-59p6.json index d839e068f0c..0c6134362aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcx2-5qw3-59p6/GHSA-jcx2-5qw3-59p6.json +++ b/advisories/unreviewed/2022/05/GHSA-jcx2-5qw3-59p6/GHSA-jcx2-5qw3-59p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf2x-r8ch-mw45/GHSA-jf2x-r8ch-mw45.json b/advisories/unreviewed/2022/05/GHSA-jf2x-r8ch-mw45/GHSA-jf2x-r8ch-mw45.json index 61676d31502..b0dec9130a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf2x-r8ch-mw45/GHSA-jf2x-r8ch-mw45.json +++ b/advisories/unreviewed/2022/05/GHSA-jf2x-r8ch-mw45/GHSA-jf2x-r8ch-mw45.json @@ -7,12 +7,8 @@ "CVE-2007-2720" ], "details": "Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfjq-j227-4x5v/GHSA-jfjq-j227-4x5v.json b/advisories/unreviewed/2022/05/GHSA-jfjq-j227-4x5v/GHSA-jfjq-j227-4x5v.json index 9fc811f6737..d1ec35749b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfjq-j227-4x5v/GHSA-jfjq-j227-4x5v.json +++ b/advisories/unreviewed/2022/05/GHSA-jfjq-j227-4x5v/GHSA-jfjq-j227-4x5v.json @@ -7,12 +7,8 @@ "CVE-2007-3036" ], "details": "Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to \"certain setuid binary files.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jg2m-4r5v-h2j3/GHSA-jg2m-4r5v-h2j3.json b/advisories/unreviewed/2022/05/GHSA-jg2m-4r5v-h2j3/GHSA-jg2m-4r5v-h2j3.json index 8a72dcc3e4d..0ee3c92299d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg2m-4r5v-h2j3/GHSA-jg2m-4r5v-h2j3.json +++ b/advisories/unreviewed/2022/05/GHSA-jg2m-4r5v-h2j3/GHSA-jg2m-4r5v-h2j3.json @@ -7,12 +7,8 @@ "CVE-2007-2777" ], "details": "Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgp8-v927-5p6w/GHSA-jgp8-v927-5p6w.json b/advisories/unreviewed/2022/05/GHSA-jgp8-v927-5p6w/GHSA-jgp8-v927-5p6w.json index fee043ddca4..2127525c2bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgp8-v927-5p6w/GHSA-jgp8-v927-5p6w.json +++ b/advisories/unreviewed/2022/05/GHSA-jgp8-v927-5p6w/GHSA-jgp8-v927-5p6w.json @@ -7,12 +7,8 @@ "CVE-2007-3100" ], "details": "usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the semaphore.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhjg-xq9m-h835/GHSA-jhjg-xq9m-h835.json b/advisories/unreviewed/2022/05/GHSA-jhjg-xq9m-h835/GHSA-jhjg-xq9m-h835.json index a84e2b3e1e3..41a7baac0ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhjg-xq9m-h835/GHSA-jhjg-xq9m-h835.json +++ b/advisories/unreviewed/2022/05/GHSA-jhjg-xq9m-h835/GHSA-jhjg-xq9m-h835.json @@ -7,12 +7,8 @@ "CVE-2007-2854" ], "details": "Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhr5-vpqc-9g55/GHSA-jhr5-vpqc-9g55.json b/advisories/unreviewed/2022/05/GHSA-jhr5-vpqc-9g55/GHSA-jhr5-vpqc-9g55.json index 78c35da8e49..b935f035a61 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhr5-vpqc-9g55/GHSA-jhr5-vpqc-9g55.json +++ b/advisories/unreviewed/2022/05/GHSA-jhr5-vpqc-9g55/GHSA-jhr5-vpqc-9g55.json @@ -7,12 +7,8 @@ "CVE-2007-2934" ], "details": "Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jhx6-4qw4-hqm9/GHSA-jhx6-4qw4-hqm9.json b/advisories/unreviewed/2022/05/GHSA-jhx6-4qw4-hqm9/GHSA-jhx6-4qw4-hqm9.json index a6f95c42229..65d2be04a80 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhx6-4qw4-hqm9/GHSA-jhx6-4qw4-hqm9.json +++ b/advisories/unreviewed/2022/05/GHSA-jhx6-4qw4-hqm9/GHSA-jhx6-4qw4-hqm9.json @@ -7,12 +7,8 @@ "CVE-2007-2757" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) wp-content/themes/redoable/searchloop.php or (2) wp-content/themes/redoable/header.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj5w-3whp-qx28/GHSA-jj5w-3whp-qx28.json b/advisories/unreviewed/2022/05/GHSA-jj5w-3whp-qx28/GHSA-jj5w-3whp-qx28.json index 060f5a8e4d8..74ede2894e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj5w-3whp-qx28/GHSA-jj5w-3whp-qx28.json +++ b/advisories/unreviewed/2022/05/GHSA-jj5w-3whp-qx28/GHSA-jj5w-3whp-qx28.json @@ -7,12 +7,8 @@ "CVE-2007-2769" ], "details": "BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 does not properly handle compressed files, which allows remote attackers to upload arbitrary files or execute arbitrary commands via a crafted compressed file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjj8-598g-q254/GHSA-jjj8-598g-q254.json b/advisories/unreviewed/2022/05/GHSA-jjj8-598g-q254/GHSA-jjj8-598g-q254.json index 1ac31824a12..bad32c4638c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjj8-598g-q254/GHSA-jjj8-598g-q254.json +++ b/advisories/unreviewed/2022/05/GHSA-jjj8-598g-q254/GHSA-jjj8-598g-q254.json @@ -7,12 +7,8 @@ "CVE-2019-9866" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm2g-5vc2-gxvp/GHSA-jm2g-5vc2-gxvp.json b/advisories/unreviewed/2022/05/GHSA-jm2g-5vc2-gxvp/GHSA-jm2g-5vc2-gxvp.json index c845dc0854d..0043841fe67 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm2g-5vc2-gxvp/GHSA-jm2g-5vc2-gxvp.json +++ b/advisories/unreviewed/2022/05/GHSA-jm2g-5vc2-gxvp/GHSA-jm2g-5vc2-gxvp.json @@ -7,12 +7,8 @@ "CVE-2007-2881" ], "details": "Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm6r-w7q8-g8qp/GHSA-jm6r-w7q8-g8qp.json b/advisories/unreviewed/2022/05/GHSA-jm6r-w7q8-g8qp/GHSA-jm6r-w7q8-g8qp.json index b21bc8a98bc..541c7312a24 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm6r-w7q8-g8qp/GHSA-jm6r-w7q8-g8qp.json +++ b/advisories/unreviewed/2022/05/GHSA-jm6r-w7q8-g8qp/GHSA-jm6r-w7q8-g8qp.json @@ -7,12 +7,8 @@ "CVE-2007-2804" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in scripts/prodList.asp in CandyPress Store 3.5.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) brand and (2) Msg parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmhg-9v9c-3m3w/GHSA-jmhg-9v9c-3m3w.json b/advisories/unreviewed/2022/05/GHSA-jmhg-9v9c-3m3w/GHSA-jmhg-9v9c-3m3w.json index 778018c72bd..1c8d30d4363 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmhg-9v9c-3m3w/GHSA-jmhg-9v9c-3m3w.json +++ b/advisories/unreviewed/2022/05/GHSA-jmhg-9v9c-3m3w/GHSA-jmhg-9v9c-3m3w.json @@ -7,12 +7,8 @@ "CVE-2019-12459" ], "details": "FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp79-fxch-h3xw/GHSA-jp79-fxch-h3xw.json b/advisories/unreviewed/2022/05/GHSA-jp79-fxch-h3xw/GHSA-jp79-fxch-h3xw.json index 9a077c9b128..2eba9530d6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp79-fxch-h3xw/GHSA-jp79-fxch-h3xw.json +++ b/advisories/unreviewed/2022/05/GHSA-jp79-fxch-h3xw/GHSA-jp79-fxch-h3xw.json @@ -7,12 +7,8 @@ "CVE-2007-3157" ], "details": "IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related to the IPv6 support for IPSec.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jpmq-qfmj-5ch7/GHSA-jpmq-qfmj-5ch7.json b/advisories/unreviewed/2022/05/GHSA-jpmq-qfmj-5ch7/GHSA-jpmq-qfmj-5ch7.json index 1e8b804ca19..9f0a0754a75 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpmq-qfmj-5ch7/GHSA-jpmq-qfmj-5ch7.json +++ b/advisories/unreviewed/2022/05/GHSA-jpmq-qfmj-5ch7/GHSA-jpmq-qfmj-5ch7.json @@ -7,12 +7,8 @@ "CVE-2007-2764" ], "details": "The embedded Linux kernel in certain Sun-Brocade SilkWorm switches before 20070516 does not properly handle a situation in which a non-root user creates a kernel process, which allows attackers to cause a denial of service (oops and device reboot) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqwq-jvmr-qgmq/GHSA-jqwq-jvmr-qgmq.json b/advisories/unreviewed/2022/05/GHSA-jqwq-jvmr-qgmq/GHSA-jqwq-jvmr-qgmq.json index 3d033406599..30dff08114c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqwq-jvmr-qgmq/GHSA-jqwq-jvmr-qgmq.json +++ b/advisories/unreviewed/2022/05/GHSA-jqwq-jvmr-qgmq/GHSA-jqwq-jvmr-qgmq.json @@ -7,12 +7,8 @@ "CVE-2007-2989" ], "details": "The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain pointer, which allows remote attackers to cause a denial of service (in.iked daemon crash) by sending certain UDP packets with a source port different from 500. NOTE: this issue might overlap CVE-2006-2298.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrpj-fwwj-f68f/GHSA-jrpj-fwwj-f68f.json b/advisories/unreviewed/2022/05/GHSA-jrpj-fwwj-f68f/GHSA-jrpj-fwwj-f68f.json index 8f623d6a01f..cf1c2649330 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrpj-fwwj-f68f/GHSA-jrpj-fwwj-f68f.json +++ b/advisories/unreviewed/2022/05/GHSA-jrpj-fwwj-f68f/GHSA-jrpj-fwwj-f68f.json @@ -7,12 +7,8 @@ "CVE-2007-2977" ], "details": "Buffer overflow in the receive function in submit/submitcommon.c in the submit daemon in DOMjudge before 2.0.0RC1 allows remote attackers to cause a denial of service or have other unspecified impact. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv45-xgw6-mfrv/GHSA-jv45-xgw6-mfrv.json b/advisories/unreviewed/2022/05/GHSA-jv45-xgw6-mfrv/GHSA-jv45-xgw6-mfrv.json index 3a829782c69..332578a7887 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv45-xgw6-mfrv/GHSA-jv45-xgw6-mfrv.json +++ b/advisories/unreviewed/2022/05/GHSA-jv45-xgw6-mfrv/GHSA-jv45-xgw6-mfrv.json @@ -7,12 +7,8 @@ "CVE-2007-3154" ], "details": "Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv5q-xqwr-9h7w/GHSA-jv5q-xqwr-9h7w.json b/advisories/unreviewed/2022/05/GHSA-jv5q-xqwr-9h7w/GHSA-jv5q-xqwr-9h7w.json index 91efbf4fa99..c82559ea5fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv5q-xqwr-9h7w/GHSA-jv5q-xqwr-9h7w.json +++ b/advisories/unreviewed/2022/05/GHSA-jv5q-xqwr-9h7w/GHSA-jv5q-xqwr-9h7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv9r-x7xj-jg33/GHSA-jv9r-x7xj-jg33.json b/advisories/unreviewed/2022/05/GHSA-jv9r-x7xj-jg33/GHSA-jv9r-x7xj-jg33.json index 2af33e2b13c..9d4f6fedb89 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv9r-x7xj-jg33/GHSA-jv9r-x7xj-jg33.json +++ b/advisories/unreviewed/2022/05/GHSA-jv9r-x7xj-jg33/GHSA-jv9r-x7xj-jg33.json @@ -7,12 +7,8 @@ "CVE-2007-2889" ], "details": "SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw59-w7qw-w79g/GHSA-jw59-w7qw-w79g.json b/advisories/unreviewed/2022/05/GHSA-jw59-w7qw-w79g/GHSA-jw59-w7qw-w79g.json index 6b8c3ca6883..87403b62317 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw59-w7qw-w79g/GHSA-jw59-w7qw-w79g.json +++ b/advisories/unreviewed/2022/05/GHSA-jw59-w7qw-w79g/GHSA-jw59-w7qw-w79g.json @@ -7,12 +7,8 @@ "CVE-2019-0709" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0620, CVE-2019-0722.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxgf-rqvh-c65h/GHSA-jxgf-rqvh-c65h.json b/advisories/unreviewed/2022/05/GHSA-jxgf-rqvh-c65h/GHSA-jxgf-rqvh-c65h.json index 8298d5e7107..14209981786 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxgf-rqvh-c65h/GHSA-jxgf-rqvh-c65h.json +++ b/advisories/unreviewed/2022/05/GHSA-jxgf-rqvh-c65h/GHSA-jxgf-rqvh-c65h.json @@ -7,12 +7,8 @@ "CVE-2007-3115" ], "details": "Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x before 1.3.05, allow remote attackers to cause a denial of service (memory consumption) via (1) reverse lookups or (2) requests for records in a class other than Internet (IN), a different set of affected versions than CVE-2007-3114 and CVE-2007-3116.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2w7-3369-7579/GHSA-m2w7-3369-7579.json b/advisories/unreviewed/2022/05/GHSA-m2w7-3369-7579/GHSA-m2w7-3369-7579.json index aea67525488..bf0dfe364a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2w7-3369-7579/GHSA-m2w7-3369-7579.json +++ b/advisories/unreviewed/2022/05/GHSA-m2w7-3369-7579/GHSA-m2w7-3369-7579.json @@ -7,12 +7,8 @@ "CVE-2019-12483" ], "details": "An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m33j-fr64-8f4j/GHSA-m33j-fr64-8f4j.json b/advisories/unreviewed/2022/05/GHSA-m33j-fr64-8f4j/GHSA-m33j-fr64-8f4j.json index 1a7532af5a8..1744a9fa242 100644 --- a/advisories/unreviewed/2022/05/GHSA-m33j-fr64-8f4j/GHSA-m33j-fr64-8f4j.json +++ b/advisories/unreviewed/2022/05/GHSA-m33j-fr64-8f4j/GHSA-m33j-fr64-8f4j.json @@ -7,12 +7,8 @@ "CVE-2007-2961" ], "details": "Unrestricted file upload vulnerability in FileCloset before 1.1.5 allows remote attackers to upload arbitrary PHP files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m425-pqwf-xvhx/GHSA-m425-pqwf-xvhx.json b/advisories/unreviewed/2022/05/GHSA-m425-pqwf-xvhx/GHSA-m425-pqwf-xvhx.json index 73a8c4458d4..a876aae0d91 100644 --- a/advisories/unreviewed/2022/05/GHSA-m425-pqwf-xvhx/GHSA-m425-pqwf-xvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-m425-pqwf-xvhx/GHSA-m425-pqwf-xvhx.json @@ -7,12 +7,8 @@ "CVE-2007-3140" ], "details": "SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m42c-4x98-67jv/GHSA-m42c-4x98-67jv.json b/advisories/unreviewed/2022/05/GHSA-m42c-4x98-67jv/GHSA-m42c-4x98-67jv.json index 74c1ad2c5be..446649b48d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-m42c-4x98-67jv/GHSA-m42c-4x98-67jv.json +++ b/advisories/unreviewed/2022/05/GHSA-m42c-4x98-67jv/GHSA-m42c-4x98-67jv.json @@ -7,12 +7,8 @@ "CVE-2007-2810" ], "details": "SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4gg-hpqm-qpq6/GHSA-m4gg-hpqm-qpq6.json b/advisories/unreviewed/2022/05/GHSA-m4gg-hpqm-qpq6/GHSA-m4gg-hpqm-qpq6.json index 29096d9cf57..f7840dbad40 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4gg-hpqm-qpq6/GHSA-m4gg-hpqm-qpq6.json +++ b/advisories/unreviewed/2022/05/GHSA-m4gg-hpqm-qpq6/GHSA-m4gg-hpqm-qpq6.json @@ -7,12 +7,8 @@ "CVE-2007-2743" ], "details": "PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m626-h8f2-6w6v/GHSA-m626-h8f2-6w6v.json b/advisories/unreviewed/2022/05/GHSA-m626-h8f2-6w6v/GHSA-m626-h8f2-6w6v.json index 93876b5c713..acb13734461 100644 --- a/advisories/unreviewed/2022/05/GHSA-m626-h8f2-6w6v/GHSA-m626-h8f2-6w6v.json +++ b/advisories/unreviewed/2022/05/GHSA-m626-h8f2-6w6v/GHSA-m626-h8f2-6w6v.json @@ -7,12 +7,8 @@ "CVE-2007-2698" ], "details": "The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration creation, which allows remote attackers to obtain sensitive credential information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m688-42p9-r3mv/GHSA-m688-42p9-r3mv.json b/advisories/unreviewed/2022/05/GHSA-m688-42p9-r3mv/GHSA-m688-42p9-r3mv.json index e197a6d91b5..b596b125205 100644 --- a/advisories/unreviewed/2022/05/GHSA-m688-42p9-r3mv/GHSA-m688-42p9-r3mv.json +++ b/advisories/unreviewed/2022/05/GHSA-m688-42p9-r3mv/GHSA-m688-42p9-r3mv.json @@ -7,12 +7,8 @@ "CVE-2007-3074" ], "details": "Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6wc-4572-7jp5/GHSA-m6wc-4572-7jp5.json b/advisories/unreviewed/2022/05/GHSA-m6wc-4572-7jp5/GHSA-m6wc-4572-7jp5.json index 6ac25ae8a8f..5fe7da16342 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6wc-4572-7jp5/GHSA-m6wc-4572-7jp5.json +++ b/advisories/unreviewed/2022/05/GHSA-m6wc-4572-7jp5/GHSA-m6wc-4572-7jp5.json @@ -7,12 +7,8 @@ "CVE-2019-4184" ], "details": "IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m77f-h2h6-5qw4/GHSA-m77f-h2h6-5qw4.json b/advisories/unreviewed/2022/05/GHSA-m77f-h2h6-5qw4/GHSA-m77f-h2h6-5qw4.json index 939cd669d5a..5106daf6839 100644 --- a/advisories/unreviewed/2022/05/GHSA-m77f-h2h6-5qw4/GHSA-m77f-h2h6-5qw4.json +++ b/advisories/unreviewed/2022/05/GHSA-m77f-h2h6-5qw4/GHSA-m77f-h2h6-5qw4.json @@ -7,12 +7,8 @@ "CVE-2007-2699" ], "details": "The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m782-qx46-pj8h/GHSA-m782-qx46-pj8h.json b/advisories/unreviewed/2022/05/GHSA-m782-qx46-pj8h/GHSA-m782-qx46-pj8h.json index e4df6d5596d..af43c1d107b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m782-qx46-pj8h/GHSA-m782-qx46-pj8h.json +++ b/advisories/unreviewed/2022/05/GHSA-m782-qx46-pj8h/GHSA-m782-qx46-pj8h.json @@ -7,12 +7,8 @@ "CVE-2007-2957" ], "details": "Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large length value in an authentication packet, which results in a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7r6-qj76-m5p5/GHSA-m7r6-qj76-m5p5.json b/advisories/unreviewed/2022/05/GHSA-m7r6-qj76-m5p5/GHSA-m7r6-qj76-m5p5.json index d4344395209..48f884bec77 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7r6-qj76-m5p5/GHSA-m7r6-qj76-m5p5.json +++ b/advisories/unreviewed/2022/05/GHSA-m7r6-qj76-m5p5/GHSA-m7r6-qj76-m5p5.json @@ -7,12 +7,8 @@ "CVE-2007-2960" ], "details": "Multiple directory traversal vulnerabilities in Scallywag 2005-04-25 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin_name parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/, a different vector than CVE-2007-2900. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m84v-2393-94pr/GHSA-m84v-2393-94pr.json b/advisories/unreviewed/2022/05/GHSA-m84v-2393-94pr/GHSA-m84v-2393-94pr.json index 8689fc9ba1d..5e110313ffe 100644 --- a/advisories/unreviewed/2022/05/GHSA-m84v-2393-94pr/GHSA-m84v-2393-94pr.json +++ b/advisories/unreviewed/2022/05/GHSA-m84v-2393-94pr/GHSA-m84v-2393-94pr.json @@ -7,12 +7,8 @@ "CVE-2007-3081" ], "details": "PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8v5-w6hc-47fv/GHSA-m8v5-w6hc-47fv.json b/advisories/unreviewed/2022/05/GHSA-m8v5-w6hc-47fv/GHSA-m8v5-w6hc-47fv.json index 7e85bf1f321..670cc00cf3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8v5-w6hc-47fv/GHSA-m8v5-w6hc-47fv.json +++ b/advisories/unreviewed/2022/05/GHSA-m8v5-w6hc-47fv/GHSA-m8v5-w6hc-47fv.json @@ -7,12 +7,8 @@ "CVE-2007-2785" ], "details": "manage-admins.php in eSyndiCat Pro 1.x allows remote attackers to create additional administrative accounts, and have other unspecified impact, via modified username, new_pass, new_pass2, status, super, and certain other parameters in an add action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mc6v-395f-vxpf/GHSA-mc6v-395f-vxpf.json b/advisories/unreviewed/2022/05/GHSA-mc6v-395f-vxpf/GHSA-mc6v-395f-vxpf.json index 994ad5dd1fa..e058d85db26 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc6v-395f-vxpf/GHSA-mc6v-395f-vxpf.json +++ b/advisories/unreviewed/2022/05/GHSA-mc6v-395f-vxpf/GHSA-mc6v-395f-vxpf.json @@ -7,12 +7,8 @@ "CVE-2007-3273" ], "details": "SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfjr-6vvr-q43r/GHSA-mfjr-6vvr-q43r.json b/advisories/unreviewed/2022/05/GHSA-mfjr-6vvr-q43r/GHSA-mfjr-6vvr-q43r.json index b51db78d2d8..52f5e21f214 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfjr-6vvr-q43r/GHSA-mfjr-6vvr-q43r.json +++ b/advisories/unreviewed/2022/05/GHSA-mfjr-6vvr-q43r/GHSA-mfjr-6vvr-q43r.json @@ -7,12 +7,8 @@ "CVE-2007-2898" ], "details": "SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgh9-r97v-cgxx/GHSA-mgh9-r97v-cgxx.json b/advisories/unreviewed/2022/05/GHSA-mgh9-r97v-cgxx/GHSA-mgh9-r97v-cgxx.json index 514024c595e..8180342b0d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgh9-r97v-cgxx/GHSA-mgh9-r97v-cgxx.json +++ b/advisories/unreviewed/2022/05/GHSA-mgh9-r97v-cgxx/GHSA-mgh9-r97v-cgxx.json @@ -7,12 +7,8 @@ "CVE-2007-2895" ], "details": "Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbitrary code via a long Directory property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgqw-w778-9gp5/GHSA-mgqw-w778-9gp5.json b/advisories/unreviewed/2022/05/GHSA-mgqw-w778-9gp5/GHSA-mgqw-w778-9gp5.json index 3030d78b2b6..64ae5d8b00b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgqw-w778-9gp5/GHSA-mgqw-w778-9gp5.json +++ b/advisories/unreviewed/2022/05/GHSA-mgqw-w778-9gp5/GHSA-mgqw-w778-9gp5.json @@ -7,12 +7,8 @@ "CVE-2007-3174" ], "details": "Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the adtype parameter, a different vector than CVE-2006-1980.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhx5-rch7-28pg/GHSA-mhx5-rch7-28pg.json b/advisories/unreviewed/2022/05/GHSA-mhx5-rch7-28pg/GHSA-mhx5-rch7-28pg.json index a95db87cd9e..7d883fcc437 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhx5-rch7-28pg/GHSA-mhx5-rch7-28pg.json +++ b/advisories/unreviewed/2022/05/GHSA-mhx5-rch7-28pg/GHSA-mhx5-rch7-28pg.json @@ -7,12 +7,8 @@ "CVE-2007-3109" ], "details": "The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjv5-2mq2-xxr6/GHSA-mjv5-2mq2-xxr6.json b/advisories/unreviewed/2022/05/GHSA-mjv5-2mq2-xxr6/GHSA-mjv5-2mq2-xxr6.json index 0b27f46902c..ee54c381585 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjv5-2mq2-xxr6/GHSA-mjv5-2mq2-xxr6.json +++ b/advisories/unreviewed/2022/05/GHSA-mjv5-2mq2-xxr6/GHSA-mjv5-2mq2-xxr6.json @@ -7,12 +7,8 @@ "CVE-2007-3065" ], "details": "SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjv9-7j58-57cp/GHSA-mjv9-7j58-57cp.json b/advisories/unreviewed/2022/05/GHSA-mjv9-7j58-57cp/GHSA-mjv9-7j58-57cp.json index a4570970c9d..d899c7c0233 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjv9-7j58-57cp/GHSA-mjv9-7j58-57cp.json +++ b/advisories/unreviewed/2022/05/GHSA-mjv9-7j58-57cp/GHSA-mjv9-7j58-57cp.json @@ -7,12 +7,8 @@ "CVE-2007-2847" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007-0840 and CVE-2007-2812.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmwq-426x-572r/GHSA-mmwq-426x-572r.json b/advisories/unreviewed/2022/05/GHSA-mmwq-426x-572r/GHSA-mmwq-426x-572r.json index ce79c944a87..9228e83ce9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmwq-426x-572r/GHSA-mmwq-426x-572r.json +++ b/advisories/unreviewed/2022/05/GHSA-mmwq-426x-572r/GHSA-mmwq-426x-572r.json @@ -7,12 +7,8 @@ "CVE-2007-2792" ], "details": "SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpjm-vcr7-5x83/GHSA-mpjm-vcr7-5x83.json b/advisories/unreviewed/2022/05/GHSA-mpjm-vcr7-5x83/GHSA-mpjm-vcr7-5x83.json index ed853750a66..ecb9c02e71c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpjm-vcr7-5x83/GHSA-mpjm-vcr7-5x83.json +++ b/advisories/unreviewed/2022/05/GHSA-mpjm-vcr7-5x83/GHSA-mpjm-vcr7-5x83.json @@ -7,12 +7,8 @@ "CVE-2007-3012" ], "details": "The web interface in Fujitsu-Siemens Computers PRIMERGY BX300 Switch Blade allows remote attackers to obtain sensitive information by canceling the authentication dialog when accessing a sub-page, which still displays the form field contents of the sub-page, as demonstrated using (1) config/ip_management.htm and (2) config/snmp_config.htm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq47-wx4f-vq7g/GHSA-mq47-wx4f-vq7g.json b/advisories/unreviewed/2022/05/GHSA-mq47-wx4f-vq7g/GHSA-mq47-wx4f-vq7g.json index 57a2545dbf1..7033c84a959 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq47-wx4f-vq7g/GHSA-mq47-wx4f-vq7g.json +++ b/advisories/unreviewed/2022/05/GHSA-mq47-wx4f-vq7g/GHSA-mq47-wx4f-vq7g.json @@ -7,12 +7,8 @@ "CVE-2007-2948" ], "details": "Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mqfh-xmrq-fccm/GHSA-mqfh-xmrq-fccm.json b/advisories/unreviewed/2022/05/GHSA-mqfh-xmrq-fccm/GHSA-mqfh-xmrq-fccm.json index 9fcc950a1f1..3877acd0b08 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqfh-xmrq-fccm/GHSA-mqfh-xmrq-fccm.json +++ b/advisories/unreviewed/2022/05/GHSA-mqfh-xmrq-fccm/GHSA-mqfh-xmrq-fccm.json @@ -7,12 +7,8 @@ "CVE-2007-2867" ], "details": "Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqq9-ff7p-g68r/GHSA-mqq9-ff7p-g68r.json b/advisories/unreviewed/2022/05/GHSA-mqq9-ff7p-g68r/GHSA-mqq9-ff7p-g68r.json index f6dbf589b18..7f8bcadf26a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqq9-ff7p-g68r/GHSA-mqq9-ff7p-g68r.json +++ b/advisories/unreviewed/2022/05/GHSA-mqq9-ff7p-g68r/GHSA-mqq9-ff7p-g68r.json @@ -7,12 +7,8 @@ "CVE-2007-3277" ], "details": "Unspecified vulnerability in the localization before 1.2 module for WIKINDX allows attackers to access certain administrative capabilities via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrjq-p33j-h2vf/GHSA-mrjq-p33j-h2vf.json b/advisories/unreviewed/2022/05/GHSA-mrjq-p33j-h2vf/GHSA-mrjq-p33j-h2vf.json index d48f53a5445..9a143e37041 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrjq-p33j-h2vf/GHSA-mrjq-p33j-h2vf.json +++ b/advisories/unreviewed/2022/05/GHSA-mrjq-p33j-h2vf/GHSA-mrjq-p33j-h2vf.json @@ -7,12 +7,8 @@ "CVE-2007-3153" ], "details": "The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrvw-6mc5-72hq/GHSA-mrvw-6mc5-72hq.json b/advisories/unreviewed/2022/05/GHSA-mrvw-6mc5-72hq/GHSA-mrvw-6mc5-72hq.json index 520bd979cbc..e1632363271 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrvw-6mc5-72hq/GHSA-mrvw-6mc5-72hq.json +++ b/advisories/unreviewed/2022/05/GHSA-mrvw-6mc5-72hq/GHSA-mrvw-6mc5-72hq.json @@ -7,12 +7,8 @@ "CVE-2007-3201" ], "details": "Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mv85-vhf6-fp37/GHSA-mv85-vhf6-fp37.json b/advisories/unreviewed/2022/05/GHSA-mv85-vhf6-fp37/GHSA-mv85-vhf6-fp37.json index 67a15fda51c..e16426e964c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv85-vhf6-fp37/GHSA-mv85-vhf6-fp37.json +++ b/advisories/unreviewed/2022/05/GHSA-mv85-vhf6-fp37/GHSA-mv85-vhf6-fp37.json @@ -7,12 +7,8 @@ "CVE-2019-9485" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mvq6-6vw6-prj5/GHSA-mvq6-6vw6-prj5.json b/advisories/unreviewed/2022/05/GHSA-mvq6-6vw6-prj5/GHSA-mvq6-6vw6-prj5.json index a8a4d6a7b15..8b0d6efdfb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvq6-6vw6-prj5/GHSA-mvq6-6vw6-prj5.json +++ b/advisories/unreviewed/2022/05/GHSA-mvq6-6vw6-prj5/GHSA-mvq6-6vw6-prj5.json @@ -7,12 +7,8 @@ "CVE-2007-2907" ], "details": "Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the forwardTo parameter to redirect.do. NOTE: the impact might be cross-site scripting (XSS) or HTTP request smuggling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwg2-x42f-3jxf/GHSA-mwg2-x42f-3jxf.json b/advisories/unreviewed/2022/05/GHSA-mwg2-x42f-3jxf/GHSA-mwg2-x42f-3jxf.json index 4d6050b3b38..c388a801129 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwg2-x42f-3jxf/GHSA-mwg2-x42f-3jxf.json +++ b/advisories/unreviewed/2022/05/GHSA-mwg2-x42f-3jxf/GHSA-mwg2-x42f-3jxf.json @@ -7,12 +7,8 @@ "CVE-2007-2954" ], "details": "Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx33-34w5-h7mc/GHSA-mx33-34w5-h7mc.json b/advisories/unreviewed/2022/05/GHSA-mx33-34w5-h7mc/GHSA-mx33-34w5-h7mc.json index ec30e1afc7d..3c90706bc72 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx33-34w5-h7mc/GHSA-mx33-34w5-h7mc.json +++ b/advisories/unreviewed/2022/05/GHSA-mx33-34w5-h7mc/GHSA-mx33-34w5-h7mc.json @@ -7,12 +7,8 @@ "CVE-2007-3059" ], "details": "SendCard 3.3.0 allows remote attackers to obtain sensitive information via an invalid sc_language parameter to sendcard.php, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mx7w-m9v5-mxpf/GHSA-mx7w-m9v5-mxpf.json b/advisories/unreviewed/2022/05/GHSA-mx7w-m9v5-mxpf/GHSA-mx7w-m9v5-mxpf.json index e75abfec989..7f49cd2d968 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx7w-m9v5-mxpf/GHSA-mx7w-m9v5-mxpf.json +++ b/advisories/unreviewed/2022/05/GHSA-mx7w-m9v5-mxpf/GHSA-mx7w-m9v5-mxpf.json @@ -7,12 +7,8 @@ "CVE-2007-2902" ], "details": "SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxr5-j46q-jg86/GHSA-mxr5-j46q-jg86.json b/advisories/unreviewed/2022/05/GHSA-mxr5-j46q-jg86/GHSA-mxr5-j46q-jg86.json index 8ccef0e104b..eecf4aadba7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxr5-j46q-jg86/GHSA-mxr5-j46q-jg86.json +++ b/advisories/unreviewed/2022/05/GHSA-mxr5-j46q-jg86/GHSA-mxr5-j46q-jg86.json @@ -7,12 +7,8 @@ "CVE-2007-2797" ], "details": "xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2h5-374v-r86q/GHSA-p2h5-374v-r86q.json b/advisories/unreviewed/2022/05/GHSA-p2h5-374v-r86q/GHSA-p2h5-374v-r86q.json index c0102d9013c..500ed0e3b55 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2h5-374v-r86q/GHSA-p2h5-374v-r86q.json +++ b/advisories/unreviewed/2022/05/GHSA-p2h5-374v-r86q/GHSA-p2h5-374v-r86q.json @@ -7,12 +7,8 @@ "CVE-2007-3165" ], "details": "Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p35w-cvx7-7v49/GHSA-p35w-cvx7-7v49.json b/advisories/unreviewed/2022/05/GHSA-p35w-cvx7-7v49/GHSA-p35w-cvx7-7v49.json index ba71ad0a7a4..7a30abc50ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-p35w-cvx7-7v49/GHSA-p35w-cvx7-7v49.json +++ b/advisories/unreviewed/2022/05/GHSA-p35w-cvx7-7v49/GHSA-p35w-cvx7-7v49.json @@ -7,12 +7,8 @@ "CVE-2007-2807" ], "details": "Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5c6-4h74-5798/GHSA-p5c6-4h74-5798.json b/advisories/unreviewed/2022/05/GHSA-p5c6-4h74-5798/GHSA-p5c6-4h74-5798.json index 1017106e848..d761138037e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5c6-4h74-5798/GHSA-p5c6-4h74-5798.json +++ b/advisories/unreviewed/2022/05/GHSA-p5c6-4h74-5798/GHSA-p5c6-4h74-5798.json @@ -7,12 +7,8 @@ "CVE-2007-3056" ], "details": "Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN 2.0rc4, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p66m-xpxp-c4gr/GHSA-p66m-xpxp-c4gr.json b/advisories/unreviewed/2022/05/GHSA-p66m-xpxp-c4gr/GHSA-p66m-xpxp-c4gr.json index 7cb6330786b..d76c95ae220 100644 --- a/advisories/unreviewed/2022/05/GHSA-p66m-xpxp-c4gr/GHSA-p66m-xpxp-c4gr.json +++ b/advisories/unreviewed/2022/05/GHSA-p66m-xpxp-c4gr/GHSA-p66m-xpxp-c4gr.json @@ -7,12 +7,8 @@ "CVE-2007-2806" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6c8-6rxx-gxvw/GHSA-p6c8-6rxx-gxvw.json b/advisories/unreviewed/2022/05/GHSA-p6c8-6rxx-gxvw/GHSA-p6c8-6rxx-gxvw.json index 5dee2122594..552cc71601b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6c8-6rxx-gxvw/GHSA-p6c8-6rxx-gxvw.json +++ b/advisories/unreviewed/2022/05/GHSA-p6c8-6rxx-gxvw/GHSA-p6c8-6rxx-gxvw.json @@ -7,12 +7,8 @@ "CVE-2007-2827" ], "details": "Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6mf-3wgh-x6fj/GHSA-p6mf-3wgh-x6fj.json b/advisories/unreviewed/2022/05/GHSA-p6mf-3wgh-x6fj/GHSA-p6mf-3wgh-x6fj.json index 69f5366ab10..7603b5243c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6mf-3wgh-x6fj/GHSA-p6mf-3wgh-x6fj.json +++ b/advisories/unreviewed/2022/05/GHSA-p6mf-3wgh-x6fj/GHSA-p6mf-3wgh-x6fj.json @@ -7,12 +7,8 @@ "CVE-2007-2771" ], "details": "Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6wm-3j7x-m2fv/GHSA-p6wm-3j7x-m2fv.json b/advisories/unreviewed/2022/05/GHSA-p6wm-3j7x-m2fv/GHSA-p6wm-3j7x-m2fv.json index a2f82af0e1f..f84d11e1ca3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6wm-3j7x-m2fv/GHSA-p6wm-3j7x-m2fv.json +++ b/advisories/unreviewed/2022/05/GHSA-p6wm-3j7x-m2fv/GHSA-p6wm-3j7x-m2fv.json @@ -7,12 +7,8 @@ "CVE-2007-3054" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the kword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p73m-v6fq-jvc8/GHSA-p73m-v6fq-jvc8.json b/advisories/unreviewed/2022/05/GHSA-p73m-v6fq-jvc8/GHSA-p73m-v6fq-jvc8.json index a5d95f45ba4..5c50a185f08 100644 --- a/advisories/unreviewed/2022/05/GHSA-p73m-v6fq-jvc8/GHSA-p73m-v6fq-jvc8.json +++ b/advisories/unreviewed/2022/05/GHSA-p73m-v6fq-jvc8/GHSA-p73m-v6fq-jvc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p759-pfvw-7vmx/GHSA-p759-pfvw-7vmx.json b/advisories/unreviewed/2022/05/GHSA-p759-pfvw-7vmx/GHSA-p759-pfvw-7vmx.json index aea68a14b11..51d88710af0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p759-pfvw-7vmx/GHSA-p759-pfvw-7vmx.json +++ b/advisories/unreviewed/2022/05/GHSA-p759-pfvw-7vmx/GHSA-p759-pfvw-7vmx.json @@ -7,12 +7,8 @@ "CVE-2007-2692" ], "details": "The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7c7-98j2-8p2x/GHSA-p7c7-98j2-8p2x.json b/advisories/unreviewed/2022/05/GHSA-p7c7-98j2-8p2x/GHSA-p7c7-98j2-8p2x.json index ae498494685..1e75acf90e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7c7-98j2-8p2x/GHSA-p7c7-98j2-8p2x.json +++ b/advisories/unreviewed/2022/05/GHSA-p7c7-98j2-8p2x/GHSA-p7c7-98j2-8p2x.json @@ -7,12 +7,8 @@ "CVE-2007-3108" ], "details": "The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -204,9 +200,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7hf-3f2v-764r/GHSA-p7hf-3f2v-764r.json b/advisories/unreviewed/2022/05/GHSA-p7hf-3f2v-764r/GHSA-p7hf-3f2v-764r.json index a3058d78c27..9c9ddbf721c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7hf-3f2v-764r/GHSA-p7hf-3f2v-764r.json +++ b/advisories/unreviewed/2022/05/GHSA-p7hf-3f2v-764r/GHSA-p7hf-3f2v-764r.json @@ -7,12 +7,8 @@ "CVE-2007-2911" ], "details": "SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the \"Attached After\" field (GPC['search']['datelineafter'] variable), a related issue to CVE-2007-1573.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8gx-6w38-hg6g/GHSA-p8gx-6w38-hg6g.json b/advisories/unreviewed/2022/05/GHSA-p8gx-6w38-hg6g/GHSA-p8gx-6w38-hg6g.json index 45833e43085..5a16af64e66 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8gx-6w38-hg6g/GHSA-p8gx-6w38-hg6g.json +++ b/advisories/unreviewed/2022/05/GHSA-p8gx-6w38-hg6g/GHSA-p8gx-6w38-hg6g.json @@ -7,12 +7,8 @@ "CVE-2007-3272" ], "details": "Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter in a register action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8pr-h875-42wj/GHSA-p8pr-h875-42wj.json b/advisories/unreviewed/2022/05/GHSA-p8pr-h875-42wj/GHSA-p8pr-h875-42wj.json index 6d103eced35..263ea0ec3fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8pr-h875-42wj/GHSA-p8pr-h875-42wj.json +++ b/advisories/unreviewed/2022/05/GHSA-p8pr-h875-42wj/GHSA-p8pr-h875-42wj.json @@ -7,12 +7,8 @@ "CVE-2007-2888" ], "details": "Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p97m-3j95-cgxq/GHSA-p97m-3j95-cgxq.json b/advisories/unreviewed/2022/05/GHSA-p97m-3j95-cgxq/GHSA-p97m-3j95-cgxq.json index 4ac4ca33e6f..f84c81f2838 100644 --- a/advisories/unreviewed/2022/05/GHSA-p97m-3j95-cgxq/GHSA-p97m-3j95-cgxq.json +++ b/advisories/unreviewed/2022/05/GHSA-p97m-3j95-cgxq/GHSA-p97m-3j95-cgxq.json @@ -7,12 +7,8 @@ "CVE-2007-2780" ], "details": "PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf3v-wfmw-4fxc/GHSA-pf3v-wfmw-4fxc.json b/advisories/unreviewed/2022/05/GHSA-pf3v-wfmw-4fxc/GHSA-pf3v-wfmw-4fxc.json index 96baf551210..3ad413b53e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf3v-wfmw-4fxc/GHSA-pf3v-wfmw-4fxc.json +++ b/advisories/unreviewed/2022/05/GHSA-pf3v-wfmw-4fxc/GHSA-pf3v-wfmw-4fxc.json @@ -7,12 +7,8 @@ "CVE-2007-3097" ], "details": "my.activation.php3 in F5 FirePass 4100 SSL VPN allows remote attackers to execute arbitrary shell commands via shell metacharacters in the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgr7-wppm-2gmp/GHSA-pgr7-wppm-2gmp.json b/advisories/unreviewed/2022/05/GHSA-pgr7-wppm-2gmp/GHSA-pgr7-wppm-2gmp.json index 115baf5638b..c7ec8e3fb02 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgr7-wppm-2gmp/GHSA-pgr7-wppm-2gmp.json +++ b/advisories/unreviewed/2022/05/GHSA-pgr7-wppm-2gmp/GHSA-pgr7-wppm-2gmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phj5-x533-9pvq/GHSA-phj5-x533-9pvq.json b/advisories/unreviewed/2022/05/GHSA-phj5-x533-9pvq/GHSA-phj5-x533-9pvq.json index c2b3c963aa7..f1af8212a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-phj5-x533-9pvq/GHSA-phj5-x533-9pvq.json +++ b/advisories/unreviewed/2022/05/GHSA-phj5-x533-9pvq/GHSA-phj5-x533-9pvq.json @@ -7,12 +7,8 @@ "CVE-2007-3175" ], "details": "Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocPay parameter to DocPay.w2b.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj47-8289-x6r4/GHSA-pj47-8289-x6r4.json b/advisories/unreviewed/2022/05/GHSA-pj47-8289-x6r4/GHSA-pj47-8289-x6r4.json index 3b9fe1448af..acbe329bbd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj47-8289-x6r4/GHSA-pj47-8289-x6r4.json +++ b/advisories/unreviewed/2022/05/GHSA-pj47-8289-x6r4/GHSA-pj47-8289-x6r4.json @@ -7,12 +7,8 @@ "CVE-2019-7955" ], "details": "Adobe Experience Manager version 6.4 and ealier have a Reflected Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj5m-7gqr-5h69/GHSA-pj5m-7gqr-5h69.json b/advisories/unreviewed/2022/05/GHSA-pj5m-7gqr-5h69/GHSA-pj5m-7gqr-5h69.json index 0617c452e99..bc339650b74 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj5m-7gqr-5h69/GHSA-pj5m-7gqr-5h69.json +++ b/advisories/unreviewed/2022/05/GHSA-pj5m-7gqr-5h69/GHSA-pj5m-7gqr-5h69.json @@ -7,12 +7,8 @@ "CVE-2007-2700" ], "details": "The WLST script generated by the configToScript command in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not encrypt certain attributes in configuration files when creating a new domain, which allows remote authenticated users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pjxv-8cr6-cx99/GHSA-pjxv-8cr6-cx99.json b/advisories/unreviewed/2022/05/GHSA-pjxv-8cr6-cx99/GHSA-pjxv-8cr6-cx99.json index 79fd540c6b6..21c7f16f21b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjxv-8cr6-cx99/GHSA-pjxv-8cr6-cx99.json +++ b/advisories/unreviewed/2022/05/GHSA-pjxv-8cr6-cx99/GHSA-pjxv-8cr6-cx99.json @@ -7,12 +7,8 @@ "CVE-2007-3102" ], "details": "Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pm3f-h97g-5966/GHSA-pm3f-h97g-5966.json b/advisories/unreviewed/2022/05/GHSA-pm3f-h97g-5966/GHSA-pm3f-h97g-5966.json index 673f23abf30..77188e5093c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm3f-h97g-5966/GHSA-pm3f-h97g-5966.json +++ b/advisories/unreviewed/2022/05/GHSA-pm3f-h97g-5966/GHSA-pm3f-h97g-5966.json @@ -7,12 +7,8 @@ "CVE-2019-7125" ], "details": "Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pm7m-p6hw-c94g/GHSA-pm7m-p6hw-c94g.json b/advisories/unreviewed/2022/05/GHSA-pm7m-p6hw-c94g/GHSA-pm7m-p6hw-c94g.json index 61d24b2dad6..a3b004e14ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm7m-p6hw-c94g/GHSA-pm7m-p6hw-c94g.json +++ b/advisories/unreviewed/2022/05/GHSA-pm7m-p6hw-c94g/GHSA-pm7m-p6hw-c94g.json @@ -7,12 +7,8 @@ "CVE-2007-2830" ], "details": "The ath_beacon_config function in if_ath.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system crash) via crafted beacon interval information when scanning for access points, which triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp8q-gj99-pr4x/GHSA-pp8q-gj99-pr4x.json b/advisories/unreviewed/2022/05/GHSA-pp8q-gj99-pr4x/GHSA-pp8q-gj99-pr4x.json index 498a57dc98a..7897ea08510 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp8q-gj99-pr4x/GHSA-pp8q-gj99-pr4x.json +++ b/advisories/unreviewed/2022/05/GHSA-pp8q-gj99-pr4x/GHSA-pp8q-gj99-pr4x.json @@ -7,12 +7,8 @@ "CVE-2007-3199" ], "details": "Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp9g-j95w-j9r8/GHSA-pp9g-j95w-j9r8.json b/advisories/unreviewed/2022/05/GHSA-pp9g-j95w-j9r8/GHSA-pp9g-j95w-j9r8.json index f21060bf613..878e37271f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp9g-j95w-j9r8/GHSA-pp9g-j95w-j9r8.json +++ b/advisories/unreviewed/2022/05/GHSA-pp9g-j95w-j9r8/GHSA-pp9g-j95w-j9r8.json @@ -7,12 +7,8 @@ "CVE-2007-2820" ], "details": "Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary code via long arguments to the (1) SWAT_Init, (2) SWAT_InitEx, (3) SWAT_InitEx2, (4) SWAT_InitEx3, and (5) SWAT_Login functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppjx-2jv5-vpwr/GHSA-ppjx-2jv5-vpwr.json b/advisories/unreviewed/2022/05/GHSA-ppjx-2jv5-vpwr/GHSA-ppjx-2jv5-vpwr.json index 36c0786262f..91c8dd77bf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppjx-2jv5-vpwr/GHSA-ppjx-2jv5-vpwr.json +++ b/advisories/unreviewed/2022/05/GHSA-ppjx-2jv5-vpwr/GHSA-ppjx-2jv5-vpwr.json @@ -7,12 +7,8 @@ "CVE-2007-2736" ], "details": "PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prqh-jf6r-x39w/GHSA-prqh-jf6r-x39w.json b/advisories/unreviewed/2022/05/GHSA-prqh-jf6r-x39w/GHSA-prqh-jf6r-x39w.json index 6284b2255be..3a49a7cca16 100644 --- a/advisories/unreviewed/2022/05/GHSA-prqh-jf6r-x39w/GHSA-prqh-jf6r-x39w.json +++ b/advisories/unreviewed/2022/05/GHSA-prqh-jf6r-x39w/GHSA-prqh-jf6r-x39w.json @@ -7,12 +7,8 @@ "CVE-2007-2751" ], "details": "Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter to (1) admin/inc/change_action.php or (2) admin/inc/add.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv38-gpw3-w7g5/GHSA-pv38-gpw3-w7g5.json b/advisories/unreviewed/2022/05/GHSA-pv38-gpw3-w7g5/GHSA-pv38-gpw3-w7g5.json index 69a86c1f275..49b6ed333a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv38-gpw3-w7g5/GHSA-pv38-gpw3-w7g5.json +++ b/advisories/unreviewed/2022/05/GHSA-pv38-gpw3-w7g5/GHSA-pv38-gpw3-w7g5.json @@ -7,12 +7,8 @@ "CVE-2007-2882" ], "details": "Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvr3-h264-ggm4/GHSA-pvr3-h264-ggm4.json b/advisories/unreviewed/2022/05/GHSA-pvr3-h264-ggm4/GHSA-pvr3-h264-ggm4.json index 8faa197f34a..56167276372 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvr3-h264-ggm4/GHSA-pvr3-h264-ggm4.json +++ b/advisories/unreviewed/2022/05/GHSA-pvr3-h264-ggm4/GHSA-pvr3-h264-ggm4.json @@ -7,12 +7,8 @@ "CVE-2007-2790" ], "details": "Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pw5q-w49m-4p9r/GHSA-pw5q-w49m-4p9r.json b/advisories/unreviewed/2022/05/GHSA-pw5q-w49m-4p9r/GHSA-pw5q-w49m-4p9r.json index 39a14b210ca..d717a97b0b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw5q-w49m-4p9r/GHSA-pw5q-w49m-4p9r.json +++ b/advisories/unreviewed/2022/05/GHSA-pw5q-w49m-4p9r/GHSA-pw5q-w49m-4p9r.json @@ -7,12 +7,8 @@ "CVE-2007-3263" ], "details": "Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to \"incorrect authorization on a remote interface to the SDO repository.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxp4-5rm6-xqjp/GHSA-pxp4-5rm6-xqjp.json b/advisories/unreviewed/2022/05/GHSA-pxp4-5rm6-xqjp/GHSA-pxp4-5rm6-xqjp.json index 7dde4bb2e3b..4b2c7c43ae2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxp4-5rm6-xqjp/GHSA-pxp4-5rm6-xqjp.json +++ b/advisories/unreviewed/2022/05/GHSA-pxp4-5rm6-xqjp/GHSA-pxp4-5rm6-xqjp.json @@ -7,12 +7,8 @@ "CVE-2007-2846" ], "details": "Heap-based buffer overflow in the SIS unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted SIS archive, resulting from an \"integer cast around.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3gx-7gwv-xv6q/GHSA-q3gx-7gwv-xv6q.json b/advisories/unreviewed/2022/05/GHSA-q3gx-7gwv-xv6q/GHSA-q3gx-7gwv-xv6q.json index fd78293df54..c86de10d021 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3gx-7gwv-xv6q/GHSA-q3gx-7gwv-xv6q.json +++ b/advisories/unreviewed/2022/05/GHSA-q3gx-7gwv-xv6q/GHSA-q3gx-7gwv-xv6q.json @@ -7,12 +7,8 @@ "CVE-2019-10847" ], "details": "Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3qc-2xhc-r4r3/GHSA-q3qc-2xhc-r4r3.json b/advisories/unreviewed/2022/05/GHSA-q3qc-2xhc-r4r3/GHSA-q3qc-2xhc-r4r3.json index 16df992dabe..0a4ed4aa8e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3qc-2xhc-r4r3/GHSA-q3qc-2xhc-r4r3.json +++ b/advisories/unreviewed/2022/05/GHSA-q3qc-2xhc-r4r3/GHSA-q3qc-2xhc-r4r3.json @@ -7,12 +7,8 @@ "CVE-2007-3117" ], "details": "Cross-site scripting (XSS) vulnerability in the SEO module in ADPLAN 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTTP headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q45m-2998-2qff/GHSA-q45m-2998-2qff.json b/advisories/unreviewed/2022/05/GHSA-q45m-2998-2qff/GHSA-q45m-2998-2qff.json index ab79318c6f7..2dd21b724f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q45m-2998-2qff/GHSA-q45m-2998-2qff.json +++ b/advisories/unreviewed/2022/05/GHSA-q45m-2998-2qff/GHSA-q45m-2998-2qff.json @@ -7,12 +7,8 @@ "CVE-2007-3066" ], "details": "Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) view.inc.php, (2) users.inc.php, (3) updatecms.inc.php, and (4) polls.inc.php in inc/; and other unspecified files, different vectors than CVE-2006-3983.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q5p6-j9r8-w7gx/GHSA-q5p6-j9r8-w7gx.json b/advisories/unreviewed/2022/05/GHSA-q5p6-j9r8-w7gx/GHSA-q5p6-j9r8-w7gx.json index 8ec674f2cab..eece70971d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5p6-j9r8-w7gx/GHSA-q5p6-j9r8-w7gx.json +++ b/advisories/unreviewed/2022/05/GHSA-q5p6-j9r8-w7gx/GHSA-q5p6-j9r8-w7gx.json @@ -7,12 +7,8 @@ "CVE-2007-2725" ], "details": "The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary files via the SaveToFile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q792-v8x9-mh56/GHSA-q792-v8x9-mh56.json b/advisories/unreviewed/2022/05/GHSA-q792-v8x9-mh56/GHSA-q792-v8x9-mh56.json index 1cb8b10bbdb..df737ec88d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q792-v8x9-mh56/GHSA-q792-v8x9-mh56.json +++ b/advisories/unreviewed/2022/05/GHSA-q792-v8x9-mh56/GHSA-q792-v8x9-mh56.json @@ -7,12 +7,8 @@ "CVE-2019-12964" ], "details": "LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q8v3-c8gc-fgpv/GHSA-q8v3-c8gc-fgpv.json b/advisories/unreviewed/2022/05/GHSA-q8v3-c8gc-fgpv/GHSA-q8v3-c8gc-fgpv.json index adb99fd8815..a51ebcc8042 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8v3-c8gc-fgpv/GHSA-q8v3-c8gc-fgpv.json +++ b/advisories/unreviewed/2022/05/GHSA-q8v3-c8gc-fgpv/GHSA-q8v3-c8gc-fgpv.json @@ -7,12 +7,8 @@ "CVE-2018-15737" ], "details": "An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x80002043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcg2-jxgh-mwh9/GHSA-qcg2-jxgh-mwh9.json b/advisories/unreviewed/2022/05/GHSA-qcg2-jxgh-mwh9/GHSA-qcg2-jxgh-mwh9.json index 0faef57daaa..a54b0b478dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcg2-jxgh-mwh9/GHSA-qcg2-jxgh-mwh9.json +++ b/advisories/unreviewed/2022/05/GHSA-qcg2-jxgh-mwh9/GHSA-qcg2-jxgh-mwh9.json @@ -7,12 +7,8 @@ "CVE-2007-3076" ], "details": "A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to the client system via the DownloadFile function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcgp-mc8p-3mq3/GHSA-qcgp-mc8p-3mq3.json b/advisories/unreviewed/2022/05/GHSA-qcgp-mc8p-3mq3/GHSA-qcgp-mc8p-3mq3.json index 1397fd51266..bf131c6211b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcgp-mc8p-3mq3/GHSA-qcgp-mc8p-3mq3.json +++ b/advisories/unreviewed/2022/05/GHSA-qcgp-mc8p-3mq3/GHSA-qcgp-mc8p-3mq3.json @@ -7,12 +7,8 @@ "CVE-2007-2740" ], "details": "Unspecified vulnerability in xajax before 0.2.5 has unknown impact and attack vectors, not related to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcxw-vm6f-5prv/GHSA-qcxw-vm6f-5prv.json b/advisories/unreviewed/2022/05/GHSA-qcxw-vm6f-5prv/GHSA-qcxw-vm6f-5prv.json index 6d658f8fe98..c6fc5594cac 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcxw-vm6f-5prv/GHSA-qcxw-vm6f-5prv.json +++ b/advisories/unreviewed/2022/05/GHSA-qcxw-vm6f-5prv/GHSA-qcxw-vm6f-5prv.json @@ -7,12 +7,8 @@ "CVE-2007-2707" ], "details": "PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh3c-3w95-fqwg/GHSA-qh3c-3w95-fqwg.json b/advisories/unreviewed/2022/05/GHSA-qh3c-3w95-fqwg/GHSA-qh3c-3w95-fqwg.json index c1a5936080d..e7140ad857e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh3c-3w95-fqwg/GHSA-qh3c-3w95-fqwg.json +++ b/advisories/unreviewed/2022/05/GHSA-qh3c-3w95-fqwg/GHSA-qh3c-3w95-fqwg.json @@ -7,12 +7,8 @@ "CVE-2007-2988" ], "details": "A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh6f-3fxw-39g8/GHSA-qh6f-3fxw-39g8.json b/advisories/unreviewed/2022/05/GHSA-qh6f-3fxw-39g8/GHSA-qh6f-3fxw-39g8.json index 1972bb26ec1..d1c899ce39d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh6f-3fxw-39g8/GHSA-qh6f-3fxw-39g8.json +++ b/advisories/unreviewed/2022/05/GHSA-qh6f-3fxw-39g8/GHSA-qh6f-3fxw-39g8.json @@ -7,12 +7,8 @@ "CVE-2007-3088" ], "details": "SQL injection vulnerability in index.php in Comicsense allows remote attackers to execute arbitrary SQL commands via the epi parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj7c-fg22-22mw/GHSA-qj7c-fg22-22mw.json b/advisories/unreviewed/2022/05/GHSA-qj7c-fg22-22mw/GHSA-qj7c-fg22-22mw.json index 0d69ae4179a..5215aab9cf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj7c-fg22-22mw/GHSA-qj7c-fg22-22mw.json +++ b/advisories/unreviewed/2022/05/GHSA-qj7c-fg22-22mw/GHSA-qj7c-fg22-22mw.json @@ -7,12 +7,8 @@ "CVE-2007-2936" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj7f-j2rv-wvc7/GHSA-qj7f-j2rv-wvc7.json b/advisories/unreviewed/2022/05/GHSA-qj7f-j2rv-wvc7/GHSA-qj7f-j2rv-wvc7.json index 17fb51fa931..e9ec9e1e32e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj7f-j2rv-wvc7/GHSA-qj7f-j2rv-wvc7.json +++ b/advisories/unreviewed/2022/05/GHSA-qj7f-j2rv-wvc7/GHSA-qj7f-j2rv-wvc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjjc-g2m4-cgrc/GHSA-qjjc-g2m4-cgrc.json b/advisories/unreviewed/2022/05/GHSA-qjjc-g2m4-cgrc/GHSA-qjjc-g2m4-cgrc.json index 741f670e096..04cc390559e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjjc-g2m4-cgrc/GHSA-qjjc-g2m4-cgrc.json +++ b/advisories/unreviewed/2022/05/GHSA-qjjc-g2m4-cgrc/GHSA-qjjc-g2m4-cgrc.json @@ -7,12 +7,8 @@ "CVE-2007-2822" ], "details": "TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjw4-fv8h-3vrh/GHSA-qjw4-fv8h-3vrh.json b/advisories/unreviewed/2022/05/GHSA-qjw4-fv8h-3vrh/GHSA-qjw4-fv8h-3vrh.json index 8785fb65cf8..014de52103e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjw4-fv8h-3vrh/GHSA-qjw4-fv8h-3vrh.json +++ b/advisories/unreviewed/2022/05/GHSA-qjw4-fv8h-3vrh/GHSA-qjw4-fv8h-3vrh.json @@ -7,12 +7,8 @@ "CVE-2019-10637" ], "details": "Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices are vulnerable in manipulating a combination of IO pins to bypass the secure boot protection mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmjh-wr8q-wg89/GHSA-qmjh-wr8q-wg89.json b/advisories/unreviewed/2022/05/GHSA-qmjh-wr8q-wg89/GHSA-qmjh-wr8q-wg89.json index 36d7ceea84d..02bb6b4e917 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmjh-wr8q-wg89/GHSA-qmjh-wr8q-wg89.json +++ b/advisories/unreviewed/2022/05/GHSA-qmjh-wr8q-wg89/GHSA-qmjh-wr8q-wg89.json @@ -7,12 +7,8 @@ "CVE-2007-2885" ], "details": "The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmv4-vpv5-c294/GHSA-qmv4-vpv5-c294.json b/advisories/unreviewed/2022/05/GHSA-qmv4-vpv5-c294/GHSA-qmv4-vpv5-c294.json index 37a6c5b227f..9f127480ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmv4-vpv5-c294/GHSA-qmv4-vpv5-c294.json +++ b/advisories/unreviewed/2022/05/GHSA-qmv4-vpv5-c294/GHSA-qmv4-vpv5-c294.json @@ -7,12 +7,8 @@ "CVE-2019-13290" ], "details": "Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmx9-339h-ff9p/GHSA-qmx9-339h-ff9p.json b/advisories/unreviewed/2022/05/GHSA-qmx9-339h-ff9p/GHSA-qmx9-339h-ff9p.json index 603f44ab9c4..6bcf0fb152c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmx9-339h-ff9p/GHSA-qmx9-339h-ff9p.json +++ b/advisories/unreviewed/2022/05/GHSA-qmx9-339h-ff9p/GHSA-qmx9-339h-ff9p.json @@ -7,12 +7,8 @@ "CVE-2017-6261" ], "details": "NVIDIA?s Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection mechanisms are insufficient, may lead to denial of service or information disclosure", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqjp-vjgm-w3p3/GHSA-qqjp-vjgm-w3p3.json b/advisories/unreviewed/2022/05/GHSA-qqjp-vjgm-w3p3/GHSA-qqjp-vjgm-w3p3.json index aa3d105933a..43fa943603e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqjp-vjgm-w3p3/GHSA-qqjp-vjgm-w3p3.json +++ b/advisories/unreviewed/2022/05/GHSA-qqjp-vjgm-w3p3/GHSA-qqjp-vjgm-w3p3.json @@ -7,12 +7,8 @@ "CVE-2007-3151" ], "details": "rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqr6-7wx3-g97v/GHSA-qqr6-7wx3-g97v.json b/advisories/unreviewed/2022/05/GHSA-qqr6-7wx3-g97v/GHSA-qqr6-7wx3-g97v.json index 495342aa5d9..87d7a347227 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqr6-7wx3-g97v/GHSA-qqr6-7wx3-g97v.json +++ b/advisories/unreviewed/2022/05/GHSA-qqr6-7wx3-g97v/GHSA-qqr6-7wx3-g97v.json @@ -7,12 +7,8 @@ "CVE-2007-3193" ], "details": "lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr9j-9cgw-6r5h/GHSA-qr9j-9cgw-6r5h.json b/advisories/unreviewed/2022/05/GHSA-qr9j-9cgw-6r5h/GHSA-qr9j-9cgw-6r5h.json index e8b3f526ee9..9409df94fc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr9j-9cgw-6r5h/GHSA-qr9j-9cgw-6r5h.json +++ b/advisories/unreviewed/2022/05/GHSA-qr9j-9cgw-6r5h/GHSA-qr9j-9cgw-6r5h.json @@ -7,12 +7,8 @@ "CVE-2007-2755" ], "details": "The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitrary files via a full pathname to the SaveToFile function, a different vulnerability than CVE-2007-2744.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qv6x-rpvf-56qw/GHSA-qv6x-rpvf-56qw.json b/advisories/unreviewed/2022/05/GHSA-qv6x-rpvf-56qw/GHSA-qv6x-rpvf-56qw.json index cb1b7b15396..e55826e3044 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv6x-rpvf-56qw/GHSA-qv6x-rpvf-56qw.json +++ b/advisories/unreviewed/2022/05/GHSA-qv6x-rpvf-56qw/GHSA-qv6x-rpvf-56qw.json @@ -7,12 +7,8 @@ "CVE-2007-2762" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qvcr-p33x-3v45/GHSA-qvcr-p33x-3v45.json b/advisories/unreviewed/2022/05/GHSA-qvcr-p33x-3v45/GHSA-qvcr-p33x-3v45.json index 9bb43c3fe1c..ead56281e77 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvcr-p33x-3v45/GHSA-qvcr-p33x-3v45.json +++ b/advisories/unreviewed/2022/05/GHSA-qvcr-p33x-3v45/GHSA-qvcr-p33x-3v45.json @@ -7,12 +7,8 @@ "CVE-2019-12730" ], "details": "aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 does not check for sscanf failure and consequently allows use of uninitialized variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r232-36wc-2wq9/GHSA-r232-36wc-2wq9.json b/advisories/unreviewed/2022/05/GHSA-r232-36wc-2wq9/GHSA-r232-36wc-2wq9.json index b9d3c13fe94..7aea324e9e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r232-36wc-2wq9/GHSA-r232-36wc-2wq9.json +++ b/advisories/unreviewed/2022/05/GHSA-r232-36wc-2wq9/GHSA-r232-36wc-2wq9.json @@ -7,12 +7,8 @@ "CVE-2007-2814" ], "details": "Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3) CreatePictureExA, (4) DefineImage, (5) DefineImageEx, (6) DefineImageFox, (7) CopyBufToClipExA, (8) LoadEx, (9) LoadFox, and other functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r248-9gqj-qp62/GHSA-r248-9gqj-qp62.json b/advisories/unreviewed/2022/05/GHSA-r248-9gqj-qp62/GHSA-r248-9gqj-qp62.json index 9c6bf1aa2e5..fa407c8032f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r248-9gqj-qp62/GHSA-r248-9gqj-qp62.json +++ b/advisories/unreviewed/2022/05/GHSA-r248-9gqj-qp62/GHSA-r248-9gqj-qp62.json @@ -7,12 +7,8 @@ "CVE-2007-3274" ], "details": "Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2rm-h2qg-g2vc/GHSA-r2rm-h2qg-g2vc.json b/advisories/unreviewed/2022/05/GHSA-r2rm-h2qg-g2vc/GHSA-r2rm-h2qg-g2vc.json index 77e9e2b06ea..2cd713ead22 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2rm-h2qg-g2vc/GHSA-r2rm-h2qg-g2vc.json +++ b/advisories/unreviewed/2022/05/GHSA-r2rm-h2qg-g2vc/GHSA-r2rm-h2qg-g2vc.json @@ -7,12 +7,8 @@ "CVE-2007-3128" ], "details": "SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4f4-2vcp-525p/GHSA-r4f4-2vcp-525p.json b/advisories/unreviewed/2022/05/GHSA-r4f4-2vcp-525p/GHSA-r4f4-2vcp-525p.json index 9139cbb3ad8..dbea16ba75b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4f4-2vcp-525p/GHSA-r4f4-2vcp-525p.json +++ b/advisories/unreviewed/2022/05/GHSA-r4f4-2vcp-525p/GHSA-r4f4-2vcp-525p.json @@ -7,12 +7,8 @@ "CVE-2007-2931" ], "details": "Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5g6-p8gj-vr5r/GHSA-r5g6-p8gj-vr5r.json b/advisories/unreviewed/2022/05/GHSA-r5g6-p8gj-vr5r/GHSA-r5g6-p8gj-vr5r.json index 3d834c90e3d..45fab7fd0d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5g6-p8gj-vr5r/GHSA-r5g6-p8gj-vr5r.json +++ b/advisories/unreviewed/2022/05/GHSA-r5g6-p8gj-vr5r/GHSA-r5g6-p8gj-vr5r.json @@ -7,12 +7,8 @@ "CVE-2007-3034" ], "details": "Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5v9-gmqf-rc88/GHSA-r5v9-gmqf-rc88.json b/advisories/unreviewed/2022/05/GHSA-r5v9-gmqf-rc88/GHSA-r5v9-gmqf-rc88.json index 43d83fbc90f..2cf8c82833e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5v9-gmqf-rc88/GHSA-r5v9-gmqf-rc88.json +++ b/advisories/unreviewed/2022/05/GHSA-r5v9-gmqf-rc88/GHSA-r5v9-gmqf-rc88.json @@ -7,12 +7,8 @@ "CVE-2017-5210" ], "details": "Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5wh-4xhf-r4xr/GHSA-r5wh-4xhf-r4xr.json b/advisories/unreviewed/2022/05/GHSA-r5wh-4xhf-r4xr/GHSA-r5wh-4xhf-r4xr.json index 12dabf06f31..420dd8611af 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5wh-4xhf-r4xr/GHSA-r5wh-4xhf-r4xr.json +++ b/advisories/unreviewed/2022/05/GHSA-r5wh-4xhf-r4xr/GHSA-r5wh-4xhf-r4xr.json @@ -7,12 +7,8 @@ "CVE-2007-2789" ], "details": "The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -232,9 +228,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r673-h2m2-rrv9/GHSA-r673-h2m2-rrv9.json b/advisories/unreviewed/2022/05/GHSA-r673-h2m2-rrv9/GHSA-r673-h2m2-rrv9.json index 529584cf1e4..6dbd9feccc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-r673-h2m2-rrv9/GHSA-r673-h2m2-rrv9.json +++ b/advisories/unreviewed/2022/05/GHSA-r673-h2m2-rrv9/GHSA-r673-h2m2-rrv9.json @@ -7,12 +7,8 @@ "CVE-2007-3185" ], "details": "Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6qg-rjj8-7pcm/GHSA-r6qg-rjj8-7pcm.json b/advisories/unreviewed/2022/05/GHSA-r6qg-rjj8-7pcm/GHSA-r6qg-rjj8-7pcm.json index 7469f695a22..112cb75336a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6qg-rjj8-7pcm/GHSA-r6qg-rjj8-7pcm.json +++ b/advisories/unreviewed/2022/05/GHSA-r6qg-rjj8-7pcm/GHSA-r6qg-rjj8-7pcm.json @@ -7,12 +7,8 @@ "CVE-2007-2837" ], "details": "The (1) getRule and (2) getChains functions in server/rules.cpp in fireflierd (fireflier-server) in FireFlier 1.1.6 allow local users to overwrite arbitrary files via a symlink attack on the /tmp/fireflier.rules temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r887-px26-87mj/GHSA-r887-px26-87mj.json b/advisories/unreviewed/2022/05/GHSA-r887-px26-87mj/GHSA-r887-px26-87mj.json index d254284d4a2..ed6359aa6e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-r887-px26-87mj/GHSA-r887-px26-87mj.json +++ b/advisories/unreviewed/2022/05/GHSA-r887-px26-87mj/GHSA-r887-px26-87mj.json @@ -7,12 +7,8 @@ "CVE-2007-3179" ], "details": "Multiple SQL injection vulnerabilities in archives.php in Particle Blogger 1.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the month parameter and other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r8g9-4v2m-5v25/GHSA-r8g9-4v2m-5v25.json b/advisories/unreviewed/2022/05/GHSA-r8g9-4v2m-5v25/GHSA-r8g9-4v2m-5v25.json index af12290f60c..93895241c95 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8g9-4v2m-5v25/GHSA-r8g9-4v2m-5v25.json +++ b/advisories/unreviewed/2022/05/GHSA-r8g9-4v2m-5v25/GHSA-r8g9-4v2m-5v25.json @@ -7,12 +7,8 @@ "CVE-2007-2938" ], "details": "Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9w6-3mf7-q4xx/GHSA-r9w6-3mf7-q4xx.json b/advisories/unreviewed/2022/05/GHSA-r9w6-3mf7-q4xx/GHSA-r9w6-3mf7-q4xx.json index 0e388dc4574..9e68728abbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9w6-3mf7-q4xx/GHSA-r9w6-3mf7-q4xx.json +++ b/advisories/unreviewed/2022/05/GHSA-r9w6-3mf7-q4xx/GHSA-r9w6-3mf7-q4xx.json @@ -7,12 +7,8 @@ "CVE-2019-0711" ], "details": "A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0710, CVE-2019-0713.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9wp-938m-vwh5/GHSA-r9wp-938m-vwh5.json b/advisories/unreviewed/2022/05/GHSA-r9wp-938m-vwh5/GHSA-r9wp-938m-vwh5.json index 71252e99ef2..2b95e28794b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9wp-938m-vwh5/GHSA-r9wp-938m-vwh5.json +++ b/advisories/unreviewed/2022/05/GHSA-r9wp-938m-vwh5/GHSA-r9wp-938m-vwh5.json @@ -7,12 +7,8 @@ "CVE-2007-2952" ], "details": "Multiple stack-based buffer overflows in the filter service (aka k9filter.exe) in Blue Coat K9 Web Protection 3.2.44 with Filter 3.2.32 allow (1) remote attackers to execute arbitrary code via a long HTTP Referer header to the K9 Web Protection Administration interface and (2) man-in-the-middle attackers to execute arbitrary code via an HTTP response with a long HTTP version field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcgq-m943-xxx6/GHSA-rcgq-m943-xxx6.json b/advisories/unreviewed/2022/05/GHSA-rcgq-m943-xxx6/GHSA-rcgq-m943-xxx6.json index f5bedf24337..b6b60a3b9cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcgq-m943-xxx6/GHSA-rcgq-m943-xxx6.json +++ b/advisories/unreviewed/2022/05/GHSA-rcgq-m943-xxx6/GHSA-rcgq-m943-xxx6.json @@ -7,12 +7,8 @@ "CVE-2007-2826" ], "details": "PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcpp-55w2-w526/GHSA-rcpp-55w2-w526.json b/advisories/unreviewed/2022/05/GHSA-rcpp-55w2-w526/GHSA-rcpp-55w2-w526.json index 1f1373c1901..c086e07db9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcpp-55w2-w526/GHSA-rcpp-55w2-w526.json +++ b/advisories/unreviewed/2022/05/GHSA-rcpp-55w2-w526/GHSA-rcpp-55w2-w526.json @@ -7,12 +7,8 @@ "CVE-2007-2858" ], "details": "SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf62-2x4x-fp7h/GHSA-rf62-2x4x-fp7h.json b/advisories/unreviewed/2022/05/GHSA-rf62-2x4x-fp7h/GHSA-rf62-2x4x-fp7h.json index a46e16bceb9..f2b0b18f0a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf62-2x4x-fp7h/GHSA-rf62-2x4x-fp7h.json +++ b/advisories/unreviewed/2022/05/GHSA-rf62-2x4x-fp7h/GHSA-rf62-2x4x-fp7h.json @@ -7,12 +7,8 @@ "CVE-2007-2801" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that \"eTicket is not designed to work with register_globals On.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfmh-p3q6-h73x/GHSA-rfmh-p3q6-h73x.json b/advisories/unreviewed/2022/05/GHSA-rfmh-p3q6-h73x/GHSA-rfmh-p3q6-h73x.json index 4b830e0f09b..ecf5822b9ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfmh-p3q6-h73x/GHSA-rfmh-p3q6-h73x.json +++ b/advisories/unreviewed/2022/05/GHSA-rfmh-p3q6-h73x/GHSA-rfmh-p3q6-h73x.json @@ -7,12 +7,8 @@ "CVE-2007-2995" ], "details": "Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rh8f-rv8h-m4gm/GHSA-rh8f-rv8h-m4gm.json b/advisories/unreviewed/2022/05/GHSA-rh8f-rv8h-m4gm/GHSA-rh8f-rv8h-m4gm.json index b4d3e557a35..486285ef3f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh8f-rv8h-m4gm/GHSA-rh8f-rv8h-m4gm.json +++ b/advisories/unreviewed/2022/05/GHSA-rh8f-rv8h-m4gm/GHSA-rh8f-rv8h-m4gm.json @@ -7,12 +7,8 @@ "CVE-2007-2871" ], "details": "Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -168,9 +164,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rj6r-wvm4-496w/GHSA-rj6r-wvm4-496w.json b/advisories/unreviewed/2022/05/GHSA-rj6r-wvm4-496w/GHSA-rj6r-wvm4-496w.json index 0af0c97325b..43536d9c8e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj6r-wvm4-496w/GHSA-rj6r-wvm4-496w.json +++ b/advisories/unreviewed/2022/05/GHSA-rj6r-wvm4-496w/GHSA-rj6r-wvm4-496w.json @@ -7,12 +7,8 @@ "CVE-2007-2838" ], "details": "The populate_conns function in src/populate_conns.c in GSAMBAD 0.1.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gsambadtmp temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjc5-hv86-58mm/GHSA-rjc5-hv86-58mm.json b/advisories/unreviewed/2022/05/GHSA-rjc5-hv86-58mm/GHSA-rjc5-hv86-58mm.json index 6cc287a93ef..30ffd546fbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjc5-hv86-58mm/GHSA-rjc5-hv86-58mm.json +++ b/advisories/unreviewed/2022/05/GHSA-rjc5-hv86-58mm/GHSA-rjc5-hv86-58mm.json @@ -7,12 +7,8 @@ "CVE-2007-2696" ], "details": "The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queues via direct requests to the JMS back-end server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjp4-hv4f-vvf6/GHSA-rjp4-hv4f-vvf6.json b/advisories/unreviewed/2022/05/GHSA-rjp4-hv4f-vvf6/GHSA-rjp4-hv4f-vvf6.json index b5870e9b6e5..55333d45881 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjp4-hv4f-vvf6/GHSA-rjp4-hv4f-vvf6.json +++ b/advisories/unreviewed/2022/05/GHSA-rjp4-hv4f-vvf6/GHSA-rjp4-hv4f-vvf6.json @@ -7,12 +7,8 @@ "CVE-2007-2765" ], "details": "blockhosts.py in BlockHosts before 2.0.3 does not properly parse daemon log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by logging in through ssh using a login name containing certain strings with an IP address, which is not properly handled by a regular expression, a related issue to CVE-2006-6301.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjv2-78g6-p67p/GHSA-rjv2-78g6-p67p.json b/advisories/unreviewed/2022/05/GHSA-rjv2-78g6-p67p/GHSA-rjv2-78g6-p67p.json index a052f8095d4..71c28647f0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjv2-78g6-p67p/GHSA-rjv2-78g6-p67p.json +++ b/advisories/unreviewed/2022/05/GHSA-rjv2-78g6-p67p/GHSA-rjv2-78g6-p67p.json @@ -7,12 +7,8 @@ "CVE-2007-2844" ], "details": "PHP 4.x and 5.x before 5.2.1, when running on multi-threaded systems, does not ensure thread safety for libc crypt function calls using protection schemes such as a mutex, which creates race conditions that allow remote attackers to overwrite internal program memory and gain system access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmc9-mpj8-qjrc/GHSA-rmc9-mpj8-qjrc.json b/advisories/unreviewed/2022/05/GHSA-rmc9-mpj8-qjrc/GHSA-rmc9-mpj8-qjrc.json index 16779a9a898..810f80a6c41 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmc9-mpj8-qjrc/GHSA-rmc9-mpj8-qjrc.json +++ b/advisories/unreviewed/2022/05/GHSA-rmc9-mpj8-qjrc/GHSA-rmc9-mpj8-qjrc.json @@ -7,12 +7,8 @@ "CVE-2007-2828" ], "details": "Cross-site request forgery (CSRF) vulnerability in adsense-deluxe.php in the AdSense-Deluxe 0.x plugin for WordPress allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq22-m835-836h/GHSA-rq22-m835-836h.json b/advisories/unreviewed/2022/05/GHSA-rq22-m835-836h/GHSA-rq22-m835-836h.json index ad08c2600b3..69453b34645 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq22-m835-836h/GHSA-rq22-m835-836h.json +++ b/advisories/unreviewed/2022/05/GHSA-rq22-m835-836h/GHSA-rq22-m835-836h.json @@ -7,12 +7,8 @@ "CVE-2007-3114" ], "details": "Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.3.03, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3115 and CVE-2007-3116.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqwf-xggc-pc3c/GHSA-rqwf-xggc-pc3c.json b/advisories/unreviewed/2022/05/GHSA-rqwf-xggc-pc3c/GHSA-rqwf-xggc-pc3c.json index 9e5c83cc01a..f4814bd4edf 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqwf-xggc-pc3c/GHSA-rqwf-xggc-pc3c.json +++ b/advisories/unreviewed/2022/05/GHSA-rqwf-xggc-pc3c/GHSA-rqwf-xggc-pc3c.json @@ -7,12 +7,8 @@ "CVE-2007-2863" ], "details": "Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rw68-9482-3m38/GHSA-rw68-9482-3m38.json b/advisories/unreviewed/2022/05/GHSA-rw68-9482-3m38/GHSA-rw68-9482-3m38.json index 3745b47d9ab..9869be6ed1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw68-9482-3m38/GHSA-rw68-9482-3m38.json +++ b/advisories/unreviewed/2022/05/GHSA-rw68-9482-3m38/GHSA-rw68-9482-3m38.json @@ -7,12 +7,8 @@ "CVE-2007-2758" ], "details": "Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow during extraction, or (2) a heap-based buffer overflow during traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json b/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json index 8409af0d443..452613e725c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json +++ b/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxjp-7p4j-7mmw/GHSA-rxjp-7p4j-7mmw.json b/advisories/unreviewed/2022/05/GHSA-rxjp-7p4j-7mmw/GHSA-rxjp-7p4j-7mmw.json index 67ede4b40f5..17e43fcb1ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxjp-7p4j-7mmw/GHSA-rxjp-7p4j-7mmw.json +++ b/advisories/unreviewed/2022/05/GHSA-rxjp-7p4j-7mmw/GHSA-rxjp-7p4j-7mmw.json @@ -7,12 +7,8 @@ "CVE-2007-2909" ], "details": "Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxv3-78hr-873g/GHSA-rxv3-78hr-873g.json b/advisories/unreviewed/2022/05/GHSA-rxv3-78hr-873g/GHSA-rxv3-78hr-873g.json index 67a684a58c6..9bff2a14ab8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxv3-78hr-873g/GHSA-rxv3-78hr-873g.json +++ b/advisories/unreviewed/2022/05/GHSA-rxv3-78hr-873g/GHSA-rxv3-78hr-873g.json @@ -7,12 +7,8 @@ "CVE-2007-3195" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in ERFAN WIKI 1.00 allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxw2-hmg4-5x6g/GHSA-rxw2-hmg4-5x6g.json b/advisories/unreviewed/2022/05/GHSA-rxw2-hmg4-5x6g/GHSA-rxw2-hmg4-5x6g.json index 1f93d09f93b..9ec80897f92 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxw2-hmg4-5x6g/GHSA-rxw2-hmg4-5x6g.json +++ b/advisories/unreviewed/2022/05/GHSA-rxw2-hmg4-5x6g/GHSA-rxw2-hmg4-5x6g.json @@ -7,12 +7,8 @@ "CVE-2007-3141" ], "details": "PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter. NOTE: the editor_insert_bottom vector is already covered by CVE-2006-6042.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2mm-669p-w2xg/GHSA-v2mm-669p-w2xg.json b/advisories/unreviewed/2022/05/GHSA-v2mm-669p-w2xg/GHSA-v2mm-669p-w2xg.json index 2389a369c5f..16abbafe679 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2mm-669p-w2xg/GHSA-v2mm-669p-w2xg.json +++ b/advisories/unreviewed/2022/05/GHSA-v2mm-669p-w2xg/GHSA-v2mm-669p-w2xg.json @@ -7,12 +7,8 @@ "CVE-2007-2753" ], "details": "RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v43p-v75m-q643/GHSA-v43p-v75m-q643.json b/advisories/unreviewed/2022/05/GHSA-v43p-v75m-q643/GHSA-v43p-v75m-q643.json index bafdbeb6f67..7c79d533382 100644 --- a/advisories/unreviewed/2022/05/GHSA-v43p-v75m-q643/GHSA-v43p-v75m-q643.json +++ b/advisories/unreviewed/2022/05/GHSA-v43p-v75m-q643/GHSA-v43p-v75m-q643.json @@ -7,12 +7,8 @@ "CVE-2007-2821" ], "details": "SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4v9-22qq-fqvv/GHSA-v4v9-22qq-fqvv.json b/advisories/unreviewed/2022/05/GHSA-v4v9-22qq-fqvv/GHSA-v4v9-22qq-fqvv.json index a794b1d9992..af5e01fa0f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4v9-22qq-fqvv/GHSA-v4v9-22qq-fqvv.json +++ b/advisories/unreviewed/2022/05/GHSA-v4v9-22qq-fqvv/GHSA-v4v9-22qq-fqvv.json @@ -7,12 +7,8 @@ "CVE-2019-7953" ], "details": "Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4w9-xgx3-w3p2/GHSA-v4w9-xgx3-w3p2.json b/advisories/unreviewed/2022/05/GHSA-v4w9-xgx3-w3p2/GHSA-v4w9-xgx3-w3p2.json index 2783eabe82f..9a503f2ee03 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4w9-xgx3-w3p2/GHSA-v4w9-xgx3-w3p2.json +++ b/advisories/unreviewed/2022/05/GHSA-v4w9-xgx3-w3p2/GHSA-v4w9-xgx3-w3p2.json @@ -7,12 +7,8 @@ "CVE-2007-2795" ], "details": "Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7h9-2x3v-fr2q/GHSA-v7h9-2x3v-fr2q.json b/advisories/unreviewed/2022/05/GHSA-v7h9-2x3v-fr2q/GHSA-v7h9-2x3v-fr2q.json index 44da9b0f381..2744ba83e75 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7h9-2x3v-fr2q/GHSA-v7h9-2x3v-fr2q.json +++ b/advisories/unreviewed/2022/05/GHSA-v7h9-2x3v-fr2q/GHSA-v7h9-2x3v-fr2q.json @@ -7,12 +7,8 @@ "CVE-2007-2752" ], "details": "SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v885-jj2f-cf66/GHSA-v885-jj2f-cf66.json b/advisories/unreviewed/2022/05/GHSA-v885-jj2f-cf66/GHSA-v885-jj2f-cf66.json index 0859a920a11..1ad3dac7c8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v885-jj2f-cf66/GHSA-v885-jj2f-cf66.json +++ b/advisories/unreviewed/2022/05/GHSA-v885-jj2f-cf66/GHSA-v885-jj2f-cf66.json @@ -7,12 +7,8 @@ "CVE-2007-2835" ], "details": "Multiple stack-based buffer overflows in (1) CCE_pinyin.c and (2) xl_pinyin.c in ImmModules/cce/ in unicon-imc2 3.0.4, as used by zhcon and other applications, allow local users to gain privileges via a long HOME environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8rv-4qvw-rgmx/GHSA-v8rv-4qvw-rgmx.json b/advisories/unreviewed/2022/05/GHSA-v8rv-4qvw-rgmx/GHSA-v8rv-4qvw-rgmx.json index d2b2911eabf..4959e8317f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8rv-4qvw-rgmx/GHSA-v8rv-4qvw-rgmx.json +++ b/advisories/unreviewed/2022/05/GHSA-v8rv-4qvw-rgmx/GHSA-v8rv-4qvw-rgmx.json @@ -7,12 +7,8 @@ "CVE-2007-3169" ], "details": "Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9f3-cc3c-vxrv/GHSA-v9f3-cc3c-vxrv.json b/advisories/unreviewed/2022/05/GHSA-v9f3-cc3c-vxrv/GHSA-v9f3-cc3c-vxrv.json index d60562b24d0..bd37c744973 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9f3-cc3c-vxrv/GHSA-v9f3-cc3c-vxrv.json +++ b/advisories/unreviewed/2022/05/GHSA-v9f3-cc3c-vxrv/GHSA-v9f3-cc3c-vxrv.json @@ -7,12 +7,8 @@ "CVE-2007-2711" ], "details": "Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9fc-8cwf-fm4g/GHSA-v9fc-8cwf-fm4g.json b/advisories/unreviewed/2022/05/GHSA-v9fc-8cwf-fm4g/GHSA-v9fc-8cwf-fm4g.json index abee4babe9f..e0f120bc2a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9fc-8cwf-fm4g/GHSA-v9fc-8cwf-fm4g.json +++ b/advisories/unreviewed/2022/05/GHSA-v9fc-8cwf-fm4g/GHSA-v9fc-8cwf-fm4g.json @@ -7,12 +7,8 @@ "CVE-2018-15665" ], "details": "An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9w7-r2r2-67qg/GHSA-v9w7-r2r2-67qg.json b/advisories/unreviewed/2022/05/GHSA-v9w7-r2r2-67qg/GHSA-v9w7-r2r2-67qg.json index 43a5bf4e0ea..d2435e4164f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9w7-r2r2-67qg/GHSA-v9w7-r2r2-67qg.json +++ b/advisories/unreviewed/2022/05/GHSA-v9w7-r2r2-67qg/GHSA-v9w7-r2r2-67qg.json @@ -7,12 +7,8 @@ "CVE-2007-2949" ], "details": "Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9xh-q86x-28v3/GHSA-v9xh-q86x-28v3.json b/advisories/unreviewed/2022/05/GHSA-v9xh-q86x-28v3/GHSA-v9xh-q86x-28v3.json index 9e0d8974de3..50fcfce5da2 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9xh-q86x-28v3/GHSA-v9xh-q86x-28v3.json +++ b/advisories/unreviewed/2022/05/GHSA-v9xh-q86x-28v3/GHSA-v9xh-q86x-28v3.json @@ -7,12 +7,8 @@ "CVE-2019-1010223" ], "details": "aubio 0.4.8 and earlier is affected by: Buffer Overflow. The impact is: buffer overflow in strcpy. The component is: tempo. The fixed version is: after commit b1559f4c9ce2b304d8d27ffdc7128b6795ca82e5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vc8g-53j3-cqx4/GHSA-vc8g-53j3-cqx4.json b/advisories/unreviewed/2022/05/GHSA-vc8g-53j3-cqx4/GHSA-vc8g-53j3-cqx4.json index c2527a6dd73..5c2c3736e1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc8g-53j3-cqx4/GHSA-vc8g-53j3-cqx4.json +++ b/advisories/unreviewed/2022/05/GHSA-vc8g-53j3-cqx4/GHSA-vc8g-53j3-cqx4.json @@ -7,12 +7,8 @@ "CVE-2019-10846" ], "details": "Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcwj-pfx9-w44m/GHSA-vcwj-pfx9-w44m.json b/advisories/unreviewed/2022/05/GHSA-vcwj-pfx9-w44m/GHSA-vcwj-pfx9-w44m.json index 194ee922ae6..f92ee867306 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcwj-pfx9-w44m/GHSA-vcwj-pfx9-w44m.json +++ b/advisories/unreviewed/2022/05/GHSA-vcwj-pfx9-w44m/GHSA-vcwj-pfx9-w44m.json @@ -7,12 +7,8 @@ "CVE-2007-2731" ], "details": "CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A) sequences in the subject parameter, a related issue to CVE-2007-1898.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vffx-jvr5-wcx9/GHSA-vffx-jvr5-wcx9.json b/advisories/unreviewed/2022/05/GHSA-vffx-jvr5-wcx9/GHSA-vffx-jvr5-wcx9.json index 83f66b7e6c7..252912b0027 100644 --- a/advisories/unreviewed/2022/05/GHSA-vffx-jvr5-wcx9/GHSA-vffx-jvr5-wcx9.json +++ b/advisories/unreviewed/2022/05/GHSA-vffx-jvr5-wcx9/GHSA-vffx-jvr5-wcx9.json @@ -7,12 +7,8 @@ "CVE-2007-3067" ], "details": "Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the (1) keyshow, (2) sortkey, and (3) show parameters to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfwg-qrxc-vgjm/GHSA-vfwg-qrxc-vgjm.json b/advisories/unreviewed/2022/05/GHSA-vfwg-qrxc-vgjm/GHSA-vfwg-qrxc-vgjm.json index e0df4e28fbd..734dd8ec6ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfwg-qrxc-vgjm/GHSA-vfwg-qrxc-vgjm.json +++ b/advisories/unreviewed/2022/05/GHSA-vfwg-qrxc-vgjm/GHSA-vfwg-qrxc-vgjm.json @@ -7,12 +7,8 @@ "CVE-2007-3072" ], "details": "Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh73-v9g2-4q7c/GHSA-vh73-v9g2-4q7c.json b/advisories/unreviewed/2022/05/GHSA-vh73-v9g2-4q7c/GHSA-vh73-v9g2-4q7c.json index 6ae8ef0cb8c..5b58034f87b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh73-v9g2-4q7c/GHSA-vh73-v9g2-4q7c.json +++ b/advisories/unreviewed/2022/05/GHSA-vh73-v9g2-4q7c/GHSA-vh73-v9g2-4q7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj5g-3v6m-vj2j/GHSA-vj5g-3v6m-vj2j.json b/advisories/unreviewed/2022/05/GHSA-vj5g-3v6m-vj2j/GHSA-vj5g-3v6m-vj2j.json index f1c2233f11e..6a4fee866bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj5g-3v6m-vj2j/GHSA-vj5g-3v6m-vj2j.json +++ b/advisories/unreviewed/2022/05/GHSA-vj5g-3v6m-vj2j/GHSA-vj5g-3v6m-vj2j.json @@ -7,12 +7,8 @@ "CVE-2007-2800" ], "details": "index.php in eTicket 1.5.5.1 and earlier allows remote attackers to obtain sensitive information via the (1) name[], (2) email[], (3) phone[], or (4) subject[] parameters, which reveals the installation path in the resulting error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjqc-7xg4-968v/GHSA-vjqc-7xg4-968v.json b/advisories/unreviewed/2022/05/GHSA-vjqc-7xg4-968v/GHSA-vjqc-7xg4-968v.json index e969a08da9f..c9c1d254bd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjqc-7xg4-968v/GHSA-vjqc-7xg4-968v.json +++ b/advisories/unreviewed/2022/05/GHSA-vjqc-7xg4-968v/GHSA-vjqc-7xg4-968v.json @@ -7,12 +7,8 @@ "CVE-2007-2695" ], "details": "The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process \"external requests on behalf of a system identity,\" which allows remote attackers to access administrative data or functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm56-wpf4-p9wq/GHSA-vm56-wpf4-p9wq.json b/advisories/unreviewed/2022/05/GHSA-vm56-wpf4-p9wq/GHSA-vm56-wpf4-p9wq.json index f8ea6a5f762..8819c908cb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm56-wpf4-p9wq/GHSA-vm56-wpf4-p9wq.json +++ b/advisories/unreviewed/2022/05/GHSA-vm56-wpf4-p9wq/GHSA-vm56-wpf4-p9wq.json @@ -7,12 +7,8 @@ "CVE-2007-3132" ], "details": "Multiple vulnerabilities in Symantec Ghost Solution Suite 2.0.0 and earlier, with Ghost 8.0.992 and possibly other versions, allow remote attackers to cause a denial of service (client or server crash) via malformed requests to the daemon port, 1346/udp or 1347/udp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm76-33jx-q8x5/GHSA-vm76-33jx-q8x5.json b/advisories/unreviewed/2022/05/GHSA-vm76-33jx-q8x5/GHSA-vm76-33jx-q8x5.json index 0f25518e315..f7766e400a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm76-33jx-q8x5/GHSA-vm76-33jx-q8x5.json +++ b/advisories/unreviewed/2022/05/GHSA-vm76-33jx-q8x5/GHSA-vm76-33jx-q8x5.json @@ -7,12 +7,8 @@ "CVE-2019-12460" ], "details": "Web Port 1.19.1 allows XSS via the /access/setup type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmh6-vv2c-7hw5/GHSA-vmh6-vv2c-7hw5.json b/advisories/unreviewed/2022/05/GHSA-vmh6-vv2c-7hw5/GHSA-vmh6-vv2c-7hw5.json index 3c2158a6ac5..f5ff00f82c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmh6-vv2c-7hw5/GHSA-vmh6-vv2c-7hw5.json +++ b/advisories/unreviewed/2022/05/GHSA-vmh6-vv2c-7hw5/GHSA-vmh6-vv2c-7hw5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpv4-p4r8-4223/GHSA-vpv4-p4r8-4223.json b/advisories/unreviewed/2022/05/GHSA-vpv4-p4r8-4223/GHSA-vpv4-p4r8-4223.json index 6d45936f072..6786d7d0085 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpv4-p4r8-4223/GHSA-vpv4-p4r8-4223.json +++ b/advisories/unreviewed/2022/05/GHSA-vpv4-p4r8-4223/GHSA-vpv4-p4r8-4223.json @@ -7,12 +7,8 @@ "CVE-2007-2859" ], "details": "Multiple PHP remote file inclusion vulnerabilities in SimpGB 1.46.0 allow remote attackers to execute arbitrary PHP code via a URL in the path_simpgb parameter to (1) guestbook.php, (2) search.php, (3) mailer.php, (4) avatars.php, (5) ccode.php, (6) comments.php, (7) emoticons.php, (8) gbdownload.php, and possibly other PHP scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vr38-8gfv-mcvj/GHSA-vr38-8gfv-mcvj.json b/advisories/unreviewed/2022/05/GHSA-vr38-8gfv-mcvj/GHSA-vr38-8gfv-mcvj.json index 48ab7fc6611..e4ece0d172c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr38-8gfv-mcvj/GHSA-vr38-8gfv-mcvj.json +++ b/advisories/unreviewed/2022/05/GHSA-vr38-8gfv-mcvj/GHSA-vr38-8gfv-mcvj.json @@ -7,12 +7,8 @@ "CVE-2007-2914" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats 3.0.6b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) awards.php, (2) login.php, (3) register.php, (4) weapons.php, and possibly other unspecified files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrgq-6vpp-w7j5/GHSA-vrgq-6vpp-w7j5.json b/advisories/unreviewed/2022/05/GHSA-vrgq-6vpp-w7j5/GHSA-vrgq-6vpp-w7j5.json index 16d74686eea..6680054a42c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrgq-6vpp-w7j5/GHSA-vrgq-6vpp-w7j5.json +++ b/advisories/unreviewed/2022/05/GHSA-vrgq-6vpp-w7j5/GHSA-vrgq-6vpp-w7j5.json @@ -7,12 +7,8 @@ "CVE-2007-3198" ], "details": "Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vvgp-7gw4-m5xw/GHSA-vvgp-7gw4-m5xw.json b/advisories/unreviewed/2022/05/GHSA-vvgp-7gw4-m5xw/GHSA-vvgp-7gw4-m5xw.json index 5a88ab30129..032272bf5e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvgp-7gw4-m5xw/GHSA-vvgp-7gw4-m5xw.json +++ b/advisories/unreviewed/2022/05/GHSA-vvgp-7gw4-m5xw/GHSA-vvgp-7gw4-m5xw.json @@ -7,12 +7,8 @@ "CVE-2007-2951" ], "details": "The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw25-hvx4-pmx5/GHSA-vw25-hvx4-pmx5.json b/advisories/unreviewed/2022/05/GHSA-vw25-hvx4-pmx5/GHSA-vw25-hvx4-pmx5.json index 7e6887f93bd..ee080c30ddf 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw25-hvx4-pmx5/GHSA-vw25-hvx4-pmx5.json +++ b/advisories/unreviewed/2022/05/GHSA-vw25-hvx4-pmx5/GHSA-vw25-hvx4-pmx5.json @@ -7,12 +7,8 @@ "CVE-2019-7850" ], "details": "Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw78-hqhc-j4hj/GHSA-vw78-hqhc-j4hj.json b/advisories/unreviewed/2022/05/GHSA-vw78-hqhc-j4hj/GHSA-vw78-hqhc-j4hj.json index 051a794ef9e..c54a56b65bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw78-hqhc-j4hj/GHSA-vw78-hqhc-j4hj.json +++ b/advisories/unreviewed/2022/05/GHSA-vw78-hqhc-j4hj/GHSA-vw78-hqhc-j4hj.json @@ -7,12 +7,8 @@ "CVE-2019-12293" ], "details": "In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwm7-fg3f-ffjr/GHSA-vwm7-fg3f-ffjr.json b/advisories/unreviewed/2022/05/GHSA-vwm7-fg3f-ffjr/GHSA-vwm7-fg3f-ffjr.json index 7ee3dcb4176..fb11a7ff9c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwm7-fg3f-ffjr/GHSA-vwm7-fg3f-ffjr.json +++ b/advisories/unreviewed/2022/05/GHSA-vwm7-fg3f-ffjr/GHSA-vwm7-fg3f-ffjr.json @@ -7,12 +7,8 @@ "CVE-2007-2956" ], "details": "Stack-based buffer overflow in the readRadianceHeader function in (1) src/fileformat/rgbeio.cpp in pfstools 1.6.2 and (2) src/Fileformat/rgbeio.cpp in Qtpfsgui 1.8.11 allows remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w254-6wjf-3v8j/GHSA-w254-6wjf-3v8j.json b/advisories/unreviewed/2022/05/GHSA-w254-6wjf-3v8j/GHSA-w254-6wjf-3v8j.json index 28e3fbb2747..df8f9524ffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w254-6wjf-3v8j/GHSA-w254-6wjf-3v8j.json +++ b/advisories/unreviewed/2022/05/GHSA-w254-6wjf-3v8j/GHSA-w254-6wjf-3v8j.json @@ -7,12 +7,8 @@ "CVE-2007-3171" ], "details": "Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w27x-wj47-p6m7/GHSA-w27x-wj47-p6m7.json b/advisories/unreviewed/2022/05/GHSA-w27x-wj47-p6m7/GHSA-w27x-wj47-p6m7.json index 25d4def1890..ea7df50e801 100644 --- a/advisories/unreviewed/2022/05/GHSA-w27x-wj47-p6m7/GHSA-w27x-wj47-p6m7.json +++ b/advisories/unreviewed/2022/05/GHSA-w27x-wj47-p6m7/GHSA-w27x-wj47-p6m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3p6-2cc8-h63h/GHSA-w3p6-2cc8-h63h.json b/advisories/unreviewed/2022/05/GHSA-w3p6-2cc8-h63h/GHSA-w3p6-2cc8-h63h.json index 83824c29590..c29a557d189 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3p6-2cc8-h63h/GHSA-w3p6-2cc8-h63h.json +++ b/advisories/unreviewed/2022/05/GHSA-w3p6-2cc8-h63h/GHSA-w3p6-2cc8-h63h.json @@ -7,12 +7,8 @@ "CVE-2007-2873" ], "details": "SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5hg-3r67-9c4q/GHSA-w5hg-3r67-9c4q.json b/advisories/unreviewed/2022/05/GHSA-w5hg-3r67-9c4q/GHSA-w5hg-3r67-9c4q.json index ffecbbc7471..fdba0f23943 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5hg-3r67-9c4q/GHSA-w5hg-3r67-9c4q.json +++ b/advisories/unreviewed/2022/05/GHSA-w5hg-3r67-9c4q/GHSA-w5hg-3r67-9c4q.json @@ -7,12 +7,8 @@ "CVE-2007-3042" ], "details": "Cross-site scripting (XSS) vulnerability in Meneame before 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6j8-rrq7-6j99/GHSA-w6j8-rrq7-6j99.json b/advisories/unreviewed/2022/05/GHSA-w6j8-rrq7-6j99/GHSA-w6j8-rrq7-6j99.json index ff134735442..a6b1f621b76 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6j8-rrq7-6j99/GHSA-w6j8-rrq7-6j99.json +++ b/advisories/unreviewed/2022/05/GHSA-w6j8-rrq7-6j99/GHSA-w6j8-rrq7-6j99.json @@ -7,12 +7,8 @@ "CVE-2007-2697" ], "details": "The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6rg-8v6j-5336/GHSA-w6rg-8v6j-5336.json b/advisories/unreviewed/2022/05/GHSA-w6rg-8v6j-5336/GHSA-w6rg-8v6j-5336.json index b73b0a55d4d..76baca684fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6rg-8v6j-5336/GHSA-w6rg-8v6j-5336.json +++ b/advisories/unreviewed/2022/05/GHSA-w6rg-8v6j-5336/GHSA-w6rg-8v6j-5336.json @@ -7,12 +7,8 @@ "CVE-2007-3183" ], "details": "Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to cal_search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6wh-wcvg-h33m/GHSA-w6wh-wcvg-h33m.json b/advisories/unreviewed/2022/05/GHSA-w6wh-wcvg-h33m/GHSA-w6wh-wcvg-h33m.json index 8364015aa8a..948560638df 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6wh-wcvg-h33m/GHSA-w6wh-wcvg-h33m.json +++ b/advisories/unreviewed/2022/05/GHSA-w6wh-wcvg-h33m/GHSA-w6wh-wcvg-h33m.json @@ -7,12 +7,8 @@ "CVE-2007-3255" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w792-393v-4wjj/GHSA-w792-393v-4wjj.json b/advisories/unreviewed/2022/05/GHSA-w792-393v-4wjj/GHSA-w792-393v-4wjj.json index 6382d75c03d..20afee8abe6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w792-393v-4wjj/GHSA-w792-393v-4wjj.json +++ b/advisories/unreviewed/2022/05/GHSA-w792-393v-4wjj/GHSA-w792-393v-4wjj.json @@ -7,12 +7,8 @@ "CVE-2007-3075" ], "details": "Directory traversal vulnerability in Microsoft Internet Explorer allows remote attackers to read arbitrary files via directory traversal sequences in a URI with a certain scheme, possibly related to \"..%5C\" (encoded backslash) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8v7-qqmc-4325/GHSA-w8v7-qqmc-4325.json b/advisories/unreviewed/2022/05/GHSA-w8v7-qqmc-4325/GHSA-w8v7-qqmc-4325.json index b58a4e2845c..9a13cf1a0a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8v7-qqmc-4325/GHSA-w8v7-qqmc-4325.json +++ b/advisories/unreviewed/2022/05/GHSA-w8v7-qqmc-4325/GHSA-w8v7-qqmc-4325.json @@ -7,12 +7,8 @@ "CVE-2007-2819" ], "details": "Cross-site scripting (XSS) vulnerability in reportItem.do in Track+ 3.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the projId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w99m-9m8w-9wj5/GHSA-w99m-9m8w-9wj5.json b/advisories/unreviewed/2022/05/GHSA-w99m-9m8w-9wj5/GHSA-w99m-9m8w-9wj5.json index 8445fbfc493..4929f922043 100644 --- a/advisories/unreviewed/2022/05/GHSA-w99m-9m8w-9wj5/GHSA-w99m-9m8w-9wj5.json +++ b/advisories/unreviewed/2022/05/GHSA-w99m-9m8w-9wj5/GHSA-w99m-9m8w-9wj5.json @@ -7,12 +7,8 @@ "CVE-2007-2766" ], "details": "lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9hq-9p5j-3m24/GHSA-w9hq-9p5j-3m24.json b/advisories/unreviewed/2022/05/GHSA-w9hq-9p5j-3m24/GHSA-w9hq-9p5j-3m24.json index 2d4bad7f584..69fb45df28c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9hq-9p5j-3m24/GHSA-w9hq-9p5j-3m24.json +++ b/advisories/unreviewed/2022/05/GHSA-w9hq-9p5j-3m24/GHSA-w9hq-9p5j-3m24.json @@ -7,12 +7,8 @@ "CVE-2007-2868" ], "details": "Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc6r-vh5v-h5gh/GHSA-wc6r-vh5v-h5gh.json b/advisories/unreviewed/2022/05/GHSA-wc6r-vh5v-h5gh/GHSA-wc6r-vh5v-h5gh.json index b74f0393f8c..937288c46c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc6r-vh5v-h5gh/GHSA-wc6r-vh5v-h5gh.json +++ b/advisories/unreviewed/2022/05/GHSA-wc6r-vh5v-h5gh/GHSA-wc6r-vh5v-h5gh.json @@ -7,12 +7,8 @@ "CVE-2007-3127" ], "details": "content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a \"';\" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcg5-m57p-577j/GHSA-wcg5-m57p-577j.json b/advisories/unreviewed/2022/05/GHSA-wcg5-m57p-577j/GHSA-wcg5-m57p-577j.json index 87154db49a8..d8c7320a88b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcg5-m57p-577j/GHSA-wcg5-m57p-577j.json +++ b/advisories/unreviewed/2022/05/GHSA-wcg5-m57p-577j/GHSA-wcg5-m57p-577j.json @@ -7,12 +7,8 @@ "CVE-2007-2773" ], "details": "SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcmg-qwjm-g6w9/GHSA-wcmg-qwjm-g6w9.json b/advisories/unreviewed/2022/05/GHSA-wcmg-qwjm-g6w9/GHSA-wcmg-qwjm-g6w9.json index 2a869e584a2..0d0ca9b7cd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcmg-qwjm-g6w9/GHSA-wcmg-qwjm-g6w9.json +++ b/advisories/unreviewed/2022/05/GHSA-wcmg-qwjm-g6w9/GHSA-wcmg-qwjm-g6w9.json @@ -7,12 +7,8 @@ "CVE-2007-3078" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Aigaion before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter (Authors and Publication titles) to (1) authoractions.php or (2) publicationactions.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wgrx-pwq8-49g7/GHSA-wgrx-pwq8-49g7.json b/advisories/unreviewed/2022/05/GHSA-wgrx-pwq8-49g7/GHSA-wgrx-pwq8-49g7.json index dcceabe37a7..948ef859019 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgrx-pwq8-49g7/GHSA-wgrx-pwq8-49g7.json +++ b/advisories/unreviewed/2022/05/GHSA-wgrx-pwq8-49g7/GHSA-wgrx-pwq8-49g7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp36-xpj5-g4w9/GHSA-wp36-xpj5-g4w9.json b/advisories/unreviewed/2022/05/GHSA-wp36-xpj5-g4w9/GHSA-wp36-xpj5-g4w9.json index a48a047aa24..0cc9360d22b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp36-xpj5-g4w9/GHSA-wp36-xpj5-g4w9.json +++ b/advisories/unreviewed/2022/05/GHSA-wp36-xpj5-g4w9/GHSA-wp36-xpj5-g4w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp3f-h574-r296/GHSA-wp3f-h574-r296.json b/advisories/unreviewed/2022/05/GHSA-wp3f-h574-r296/GHSA-wp3f-h574-r296.json index 08da7ffbe3c..46b1f800338 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp3f-h574-r296/GHSA-wp3f-h574-r296.json +++ b/advisories/unreviewed/2022/05/GHSA-wp3f-h574-r296/GHSA-wp3f-h574-r296.json @@ -7,12 +7,8 @@ "CVE-2007-2917" ], "details": "Multiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wp63-7hgq-8f4j/GHSA-wp63-7hgq-8f4j.json b/advisories/unreviewed/2022/05/GHSA-wp63-7hgq-8f4j/GHSA-wp63-7hgq-8f4j.json index 0ee0c47366d..09050f27160 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp63-7hgq-8f4j/GHSA-wp63-7hgq-8f4j.json +++ b/advisories/unreviewed/2022/05/GHSA-wp63-7hgq-8f4j/GHSA-wp63-7hgq-8f4j.json @@ -7,12 +7,8 @@ "CVE-2007-3061" ], "details": "Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq5q-28hc-6vmg/GHSA-wq5q-28hc-6vmg.json b/advisories/unreviewed/2022/05/GHSA-wq5q-28hc-6vmg/GHSA-wq5q-28hc-6vmg.json index 28e4cef6ffc..4b2efb20fdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq5q-28hc-6vmg/GHSA-wq5q-28hc-6vmg.json +++ b/advisories/unreviewed/2022/05/GHSA-wq5q-28hc-6vmg/GHSA-wq5q-28hc-6vmg.json @@ -7,12 +7,8 @@ "CVE-2007-3186" ], "details": "Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq8f-5m2c-qq4c/GHSA-wq8f-5m2c-qq4c.json b/advisories/unreviewed/2022/05/GHSA-wq8f-5m2c-qq4c/GHSA-wq8f-5m2c-qq4c.json index 00dc8399de6..d913b6a05e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq8f-5m2c-qq4c/GHSA-wq8f-5m2c-qq4c.json +++ b/advisories/unreviewed/2022/05/GHSA-wq8f-5m2c-qq4c/GHSA-wq8f-5m2c-qq4c.json @@ -7,12 +7,8 @@ "CVE-2007-3053" ], "details": "Session fixation vulnerability in Calimero.CMS 3.3.1232 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqh3-26vv-cwq2/GHSA-wqh3-26vv-cwq2.json b/advisories/unreviewed/2022/05/GHSA-wqh3-26vv-cwq2/GHSA-wqh3-26vv-cwq2.json index 3d4b8c176a7..3c98e46d857 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqh3-26vv-cwq2/GHSA-wqh3-26vv-cwq2.json +++ b/advisories/unreviewed/2022/05/GHSA-wqh3-26vv-cwq2/GHSA-wqh3-26vv-cwq2.json @@ -7,12 +7,8 @@ "CVE-2007-2774" ], "details": "Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqm6-5c97-8fxm/GHSA-wqm6-5c97-8fxm.json b/advisories/unreviewed/2022/05/GHSA-wqm6-5c97-8fxm/GHSA-wqm6-5c97-8fxm.json index 912def73dff..6b21199f535 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqm6-5c97-8fxm/GHSA-wqm6-5c97-8fxm.json +++ b/advisories/unreviewed/2022/05/GHSA-wqm6-5c97-8fxm/GHSA-wqm6-5c97-8fxm.json @@ -7,12 +7,8 @@ "CVE-2007-3093" ], "details": "Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv42-64hv-5wfc/GHSA-wv42-64hv-5wfc.json b/advisories/unreviewed/2022/05/GHSA-wv42-64hv-5wfc/GHSA-wv42-64hv-5wfc.json index 92ba7f2cd3f..db97fa7806f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv42-64hv-5wfc/GHSA-wv42-64hv-5wfc.json +++ b/advisories/unreviewed/2022/05/GHSA-wv42-64hv-5wfc/GHSA-wv42-64hv-5wfc.json @@ -7,12 +7,8 @@ "CVE-2007-2877" ], "details": "Buffer overflow in tcl/win/tclWinReg.c in Tcl (Tcl/Tk) before 8.5a6 allows local users to gain privileges via long registry key paths.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvg9-9p7v-gc5m/GHSA-wvg9-9p7v-gc5m.json b/advisories/unreviewed/2022/05/GHSA-wvg9-9p7v-gc5m/GHSA-wvg9-9p7v-gc5m.json index 0a136dad792..1c6dc5917a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvg9-9p7v-gc5m/GHSA-wvg9-9p7v-gc5m.json +++ b/advisories/unreviewed/2022/05/GHSA-wvg9-9p7v-gc5m/GHSA-wvg9-9p7v-gc5m.json @@ -7,12 +7,8 @@ "CVE-2018-6134" ], "details": "Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww88-w43v-h5h7/GHSA-ww88-w43v-h5h7.json b/advisories/unreviewed/2022/05/GHSA-ww88-w43v-h5h7/GHSA-ww88-w43v-h5h7.json index 7d0bffbde40..4f12e0eca3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww88-w43v-h5h7/GHSA-ww88-w43v-h5h7.json +++ b/advisories/unreviewed/2022/05/GHSA-ww88-w43v-h5h7/GHSA-ww88-w43v-h5h7.json @@ -7,12 +7,8 @@ "CVE-2007-2942" ], "details": "SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwf3-q373-cwc9/GHSA-wwf3-q373-cwc9.json b/advisories/unreviewed/2022/05/GHSA-wwf3-q373-cwc9/GHSA-wwf3-q373-cwc9.json index beac0f51e56..dce29b71f4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwf3-q373-cwc9/GHSA-wwf3-q373-cwc9.json +++ b/advisories/unreviewed/2022/05/GHSA-wwf3-q373-cwc9/GHSA-wwf3-q373-cwc9.json @@ -7,12 +7,8 @@ "CVE-2007-3064" ], "details": "Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwhq-r6wg-r4rh/GHSA-wwhq-r6wg-r4rh.json b/advisories/unreviewed/2022/05/GHSA-wwhq-r6wg-r4rh/GHSA-wwhq-r6wg-r4rh.json index 1efa92151ce..adaa97e45b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwhq-r6wg-r4rh/GHSA-wwhq-r6wg-r4rh.json +++ b/advisories/unreviewed/2022/05/GHSA-wwhq-r6wg-r4rh/GHSA-wwhq-r6wg-r4rh.json @@ -7,12 +7,8 @@ "CVE-2007-3170" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to redirect.php or (2) the selected_theme parameter to demo/pop3/error.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwv5-v5pq-x484/GHSA-wwv5-v5pq-x484.json b/advisories/unreviewed/2022/05/GHSA-wwv5-v5pq-x484/GHSA-wwv5-v5pq-x484.json index 9de985eda78..e8e008e0f21 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwv5-v5pq-x484/GHSA-wwv5-v5pq-x484.json +++ b/advisories/unreviewed/2022/05/GHSA-wwv5-v5pq-x484/GHSA-wwv5-v5pq-x484.json @@ -7,12 +7,8 @@ "CVE-2007-3095" ], "details": "Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to \"disable the authentication system\" and bypass authentication via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx6x-cx9j-ghxj/GHSA-wx6x-cx9j-ghxj.json b/advisories/unreviewed/2022/05/GHSA-wx6x-cx9j-ghxj/GHSA-wx6x-cx9j-ghxj.json index a21240ceb02..43c029c24ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx6x-cx9j-ghxj/GHSA-wx6x-cx9j-ghxj.json +++ b/advisories/unreviewed/2022/05/GHSA-wx6x-cx9j-ghxj/GHSA-wx6x-cx9j-ghxj.json @@ -7,12 +7,8 @@ "CVE-2007-2772" ], "details": "(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x26v-vj6m-f8j8/GHSA-x26v-vj6m-f8j8.json b/advisories/unreviewed/2022/05/GHSA-x26v-vj6m-f8j8/GHSA-x26v-vj6m-f8j8.json index acdb95ae092..7c1a3c83233 100644 --- a/advisories/unreviewed/2022/05/GHSA-x26v-vj6m-f8j8/GHSA-x26v-vj6m-f8j8.json +++ b/advisories/unreviewed/2022/05/GHSA-x26v-vj6m-f8j8/GHSA-x26v-vj6m-f8j8.json @@ -7,12 +7,8 @@ "CVE-2007-2761" ], "details": "Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3c3-8c4j-3cfx/GHSA-x3c3-8c4j-3cfx.json b/advisories/unreviewed/2022/05/GHSA-x3c3-8c4j-3cfx/GHSA-x3c3-8c4j-3cfx.json index 6a59ef6bfdc..221778c0817 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3c3-8c4j-3cfx/GHSA-x3c3-8c4j-3cfx.json +++ b/advisories/unreviewed/2022/05/GHSA-x3c3-8c4j-3cfx/GHSA-x3c3-8c4j-3cfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3rv-wp8j-hfgm/GHSA-x3rv-wp8j-hfgm.json b/advisories/unreviewed/2022/05/GHSA-x3rv-wp8j-hfgm/GHSA-x3rv-wp8j-hfgm.json index 5b58e7a940d..501a9d8db0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3rv-wp8j-hfgm/GHSA-x3rv-wp8j-hfgm.json +++ b/advisories/unreviewed/2022/05/GHSA-x3rv-wp8j-hfgm/GHSA-x3rv-wp8j-hfgm.json @@ -7,12 +7,8 @@ "CVE-2007-2778" ], "details": "Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to index.php and other unspecified PHP scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x47j-hhhf-c437/GHSA-x47j-hhhf-c437.json b/advisories/unreviewed/2022/05/GHSA-x47j-hhhf-c437/GHSA-x47j-hhhf-c437.json index bbe4807f240..075a1b4dd56 100644 --- a/advisories/unreviewed/2022/05/GHSA-x47j-hhhf-c437/GHSA-x47j-hhhf-c437.json +++ b/advisories/unreviewed/2022/05/GHSA-x47j-hhhf-c437/GHSA-x47j-hhhf-c437.json @@ -7,12 +7,8 @@ "CVE-2007-2904" ], "details": "Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4cq-f9rj-m6f7/GHSA-x4cq-f9rj-m6f7.json b/advisories/unreviewed/2022/05/GHSA-x4cq-f9rj-m6f7/GHSA-x4cq-f9rj-m6f7.json index ac78a41c777..25e77111a85 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4cq-f9rj-m6f7/GHSA-x4cq-f9rj-m6f7.json +++ b/advisories/unreviewed/2022/05/GHSA-x4cq-f9rj-m6f7/GHSA-x4cq-f9rj-m6f7.json @@ -7,12 +7,8 @@ "CVE-2007-3018" ], "details": "activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4f5-q2qx-hmgg/GHSA-x4f5-q2qx-hmgg.json b/advisories/unreviewed/2022/05/GHSA-x4f5-q2qx-hmgg/GHSA-x4f5-q2qx-hmgg.json index 52813848996..00acd506660 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4f5-q2qx-hmgg/GHSA-x4f5-q2qx-hmgg.json +++ b/advisories/unreviewed/2022/05/GHSA-x4f5-q2qx-hmgg/GHSA-x4f5-q2qx-hmgg.json @@ -7,12 +7,8 @@ "CVE-2007-3123" ], "details": "unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vm_codesize value, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4mc-g97r-xrh2/GHSA-x4mc-g97r-xrh2.json b/advisories/unreviewed/2022/05/GHSA-x4mc-g97r-xrh2/GHSA-x4mc-g97r-xrh2.json index ec67a115b43..42bbd12c8d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4mc-g97r-xrh2/GHSA-x4mc-g97r-xrh2.json +++ b/advisories/unreviewed/2022/05/GHSA-x4mc-g97r-xrh2/GHSA-x4mc-g97r-xrh2.json @@ -7,12 +7,8 @@ "CVE-2007-2704" ], "details": "BEA WebLogic Server 9.0 through 9.2 allows remote attackers to cause a denial of service (SSL port unavailability) by accessing a half-closed SSL socket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6m5-g86w-pv2v/GHSA-x6m5-g86w-pv2v.json b/advisories/unreviewed/2022/05/GHSA-x6m5-g86w-pv2v/GHSA-x6m5-g86w-pv2v.json index 7f6232a6c4a..c44350f4b88 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6m5-g86w-pv2v/GHSA-x6m5-g86w-pv2v.json +++ b/advisories/unreviewed/2022/05/GHSA-x6m5-g86w-pv2v/GHSA-x6m5-g86w-pv2v.json @@ -7,12 +7,8 @@ "CVE-2019-12958" ], "details": "In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6m6-8vmr-89mp/GHSA-x6m6-8vmr-89mp.json b/advisories/unreviewed/2022/05/GHSA-x6m6-8vmr-89mp/GHSA-x6m6-8vmr-89mp.json index be9dfccd433..f50b6d98f90 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6m6-8vmr-89mp/GHSA-x6m6-8vmr-89mp.json +++ b/advisories/unreviewed/2022/05/GHSA-x6m6-8vmr-89mp/GHSA-x6m6-8vmr-89mp.json @@ -7,12 +7,8 @@ "CVE-2007-3003" ], "details": "Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x735-fr7j-4w5v/GHSA-x735-fr7j-4w5v.json b/advisories/unreviewed/2022/05/GHSA-x735-fr7j-4w5v/GHSA-x735-fr7j-4w5v.json index 18336e7762a..8d84a935f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-x735-fr7j-4w5v/GHSA-x735-fr7j-4w5v.json +++ b/advisories/unreviewed/2022/05/GHSA-x735-fr7j-4w5v/GHSA-x735-fr7j-4w5v.json @@ -7,12 +7,8 @@ "CVE-2017-15652" ], "details": "Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7r8-w5cc-xpgr/GHSA-x7r8-w5cc-xpgr.json b/advisories/unreviewed/2022/05/GHSA-x7r8-w5cc-xpgr/GHSA-x7r8-w5cc-xpgr.json index c45f6964432..fc3a039e073 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7r8-w5cc-xpgr/GHSA-x7r8-w5cc-xpgr.json +++ b/advisories/unreviewed/2022/05/GHSA-x7r8-w5cc-xpgr/GHSA-x7r8-w5cc-xpgr.json @@ -7,12 +7,8 @@ "CVE-2017-13668" ], "details": "OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x875-hm5f-p38r/GHSA-x875-hm5f-p38r.json b/advisories/unreviewed/2022/05/GHSA-x875-hm5f-p38r/GHSA-x875-hm5f-p38r.json index 20f7fe6c26e..cd02a74857a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x875-hm5f-p38r/GHSA-x875-hm5f-p38r.json +++ b/advisories/unreviewed/2022/05/GHSA-x875-hm5f-p38r/GHSA-x875-hm5f-p38r.json @@ -7,12 +7,8 @@ "CVE-2007-2890" ], "details": "SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8j5-q5mq-p85w/GHSA-x8j5-q5mq-p85w.json b/advisories/unreviewed/2022/05/GHSA-x8j5-q5mq-p85w/GHSA-x8j5-q5mq-p85w.json index c738a8b5657..3ff87d9ffaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8j5-q5mq-p85w/GHSA-x8j5-q5mq-p85w.json +++ b/advisories/unreviewed/2022/05/GHSA-x8j5-q5mq-p85w/GHSA-x8j5-q5mq-p85w.json @@ -7,12 +7,8 @@ "CVE-2007-2984" ], "details": "Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc5v-qgqr-fghf/GHSA-xc5v-qgqr-fghf.json b/advisories/unreviewed/2022/05/GHSA-xc5v-qgqr-fghf/GHSA-xc5v-qgqr-fghf.json index 2ab8a54b0a6..87a27882e97 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc5v-qgqr-fghf/GHSA-xc5v-qgqr-fghf.json +++ b/advisories/unreviewed/2022/05/GHSA-xc5v-qgqr-fghf/GHSA-xc5v-qgqr-fghf.json @@ -7,12 +7,8 @@ "CVE-2007-2959" ], "details": "SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcg5-vp9v-hx6x/GHSA-xcg5-vp9v-hx6x.json b/advisories/unreviewed/2022/05/GHSA-xcg5-vp9v-hx6x/GHSA-xcg5-vp9v-hx6x.json index c537a87da28..1e1524a96dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcg5-vp9v-hx6x/GHSA-xcg5-vp9v-hx6x.json +++ b/advisories/unreviewed/2022/05/GHSA-xcg5-vp9v-hx6x/GHSA-xcg5-vp9v-hx6x.json @@ -7,12 +7,8 @@ "CVE-2007-2875" ], "details": "Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xh8w-m2v6-88j8/GHSA-xh8w-m2v6-88j8.json b/advisories/unreviewed/2022/05/GHSA-xh8w-m2v6-88j8/GHSA-xh8w-m2v6-88j8.json index d47d8265da4..0f114600492 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh8w-m2v6-88j8/GHSA-xh8w-m2v6-88j8.json +++ b/advisories/unreviewed/2022/05/GHSA-xh8w-m2v6-88j8/GHSA-xh8w-m2v6-88j8.json @@ -7,12 +7,8 @@ "CVE-2007-3068" ], "details": "Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjcq-phj7-g2fh/GHSA-xjcq-phj7-g2fh.json b/advisories/unreviewed/2022/05/GHSA-xjcq-phj7-g2fh/GHSA-xjcq-phj7-g2fh.json index 9caae6e4b86..b4d346920f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjcq-phj7-g2fh/GHSA-xjcq-phj7-g2fh.json +++ b/advisories/unreviewed/2022/05/GHSA-xjcq-phj7-g2fh/GHSA-xjcq-phj7-g2fh.json @@ -7,12 +7,8 @@ "CVE-2007-2860" ], "details": "user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjfh-8597-7v3j/GHSA-xjfh-8597-7v3j.json b/advisories/unreviewed/2022/05/GHSA-xjfh-8597-7v3j/GHSA-xjfh-8597-7v3j.json index 8d2b61a43cf..82505a4015c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjfh-8597-7v3j/GHSA-xjfh-8597-7v3j.json +++ b/advisories/unreviewed/2022/05/GHSA-xjfh-8597-7v3j/GHSA-xjfh-8597-7v3j.json @@ -7,12 +7,8 @@ "CVE-2007-2874" ], "details": "Buffer overflow in the wpa_printf function in the debugging code in wpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7 allows user-assisted remote attackers to execute arbitrary code via malformed frames on a WPA2 network. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjj4-w934-3vj9/GHSA-xjj4-w934-3vj9.json b/advisories/unreviewed/2022/05/GHSA-xjj4-w934-3vj9/GHSA-xjj4-w934-3vj9.json index 2711cd82924..ad87e3c3b38 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjj4-w934-3vj9/GHSA-xjj4-w934-3vj9.json +++ b/advisories/unreviewed/2022/05/GHSA-xjj4-w934-3vj9/GHSA-xjj4-w934-3vj9.json @@ -7,12 +7,8 @@ "CVE-2007-2843" ], "details": "Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xmw2-8pp9-3q4c/GHSA-xmw2-8pp9-3q4c.json b/advisories/unreviewed/2022/05/GHSA-xmw2-8pp9-3q4c/GHSA-xmw2-8pp9-3q4c.json index 83617e20759..093b199a2e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmw2-8pp9-3q4c/GHSA-xmw2-8pp9-3q4c.json +++ b/advisories/unreviewed/2022/05/GHSA-xmw2-8pp9-3q4c/GHSA-xmw2-8pp9-3q4c.json @@ -7,12 +7,8 @@ "CVE-2007-2817" ], "details": "SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json b/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json index 74380edf492..2f959bec657 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json +++ b/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpc8-q78m-cqrv/GHSA-xpc8-q78m-cqrv.json b/advisories/unreviewed/2022/05/GHSA-xpc8-q78m-cqrv/GHSA-xpc8-q78m-cqrv.json index d18f119d32c..539dc5b3254 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpc8-q78m-cqrv/GHSA-xpc8-q78m-cqrv.json +++ b/advisories/unreviewed/2022/05/GHSA-xpc8-q78m-cqrv/GHSA-xpc8-q78m-cqrv.json @@ -7,12 +7,8 @@ "CVE-2007-3182" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xqr6-xwgv-r3rg/GHSA-xqr6-xwgv-r3rg.json b/advisories/unreviewed/2022/05/GHSA-xqr6-xwgv-r3rg/GHSA-xqr6-xwgv-r3rg.json index 2a75f5a73fa..d24b62ad7b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqr6-xwgv-r3rg/GHSA-xqr6-xwgv-r3rg.json +++ b/advisories/unreviewed/2022/05/GHSA-xqr6-xwgv-r3rg/GHSA-xqr6-xwgv-r3rg.json @@ -7,12 +7,8 @@ "CVE-2007-2779" ], "details": "PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr5q-pj6q-cgc5/GHSA-xr5q-pj6q-cgc5.json b/advisories/unreviewed/2022/05/GHSA-xr5q-pj6q-cgc5/GHSA-xr5q-pj6q-cgc5.json index 89ce05b5d5c..8b6abbfe9ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr5q-pj6q-cgc5/GHSA-xr5q-pj6q-cgc5.json +++ b/advisories/unreviewed/2022/05/GHSA-xr5q-pj6q-cgc5/GHSA-xr5q-pj6q-cgc5.json @@ -7,12 +7,8 @@ "CVE-2007-3189" ], "details": "Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json b/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json index 7bfb54d7dc5..b10f5f1b0b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json +++ b/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw2f-wfxf-vxq4/GHSA-xw2f-wfxf-vxq4.json b/advisories/unreviewed/2022/05/GHSA-xw2f-wfxf-vxq4/GHSA-xw2f-wfxf-vxq4.json index 3703d1e344a..f7818497cee 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw2f-wfxf-vxq4/GHSA-xw2f-wfxf-vxq4.json +++ b/advisories/unreviewed/2022/05/GHSA-xw2f-wfxf-vxq4/GHSA-xw2f-wfxf-vxq4.json @@ -7,12 +7,8 @@ "CVE-2018-15736" ], "details": "An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x8000204F.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw7j-prhw-8j4h/GHSA-xw7j-prhw-8j4h.json b/advisories/unreviewed/2022/05/GHSA-xw7j-prhw-8j4h/GHSA-xw7j-prhw-8j4h.json index 00f9fc0efc3..a743d709d68 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw7j-prhw-8j4h/GHSA-xw7j-prhw-8j4h.json +++ b/advisories/unreviewed/2022/05/GHSA-xw7j-prhw-8j4h/GHSA-xw7j-prhw-8j4h.json @@ -7,12 +7,8 @@ "CVE-2019-7112" ], "details": "Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwm7-qf33-7c64/GHSA-xwm7-qf33-7c64.json b/advisories/unreviewed/2022/05/GHSA-xwm7-qf33-7c64/GHSA-xwm7-qf33-7c64.json index e9b975b16b5..627bf58cb40 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwm7-qf33-7c64/GHSA-xwm7-qf33-7c64.json +++ b/advisories/unreviewed/2022/05/GHSA-xwm7-qf33-7c64/GHSA-xwm7-qf33-7c64.json @@ -7,12 +7,8 @@ "CVE-2007-3256" ], "details": "Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwpv-xmw2-88gc/GHSA-xwpv-xmw2-88gc.json b/advisories/unreviewed/2022/05/GHSA-xwpv-xmw2-88gc/GHSA-xwpv-xmw2-88gc.json index 652d7908869..49699efaef4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwpv-xmw2-88gc/GHSA-xwpv-xmw2-88gc.json +++ b/advisories/unreviewed/2022/05/GHSA-xwpv-xmw2-88gc/GHSA-xwpv-xmw2-88gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwx6-2367-24jg/GHSA-xwx6-2367-24jg.json b/advisories/unreviewed/2022/05/GHSA-xwx6-2367-24jg/GHSA-xwx6-2367-24jg.json index 545a40cb4a5..c198b74cd22 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwx6-2367-24jg/GHSA-xwx6-2367-24jg.json +++ b/advisories/unreviewed/2022/05/GHSA-xwx6-2367-24jg/GHSA-xwx6-2367-24jg.json @@ -7,12 +7,8 @@ "CVE-2007-3043" ], "details": "Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxjw-jphq-5x96/GHSA-xxjw-jphq-5x96.json b/advisories/unreviewed/2022/05/GHSA-xxjw-jphq-5x96/GHSA-xxjw-jphq-5x96.json index 8fce775f26c..bdcac13e71a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxjw-jphq-5x96/GHSA-xxjw-jphq-5x96.json +++ b/advisories/unreviewed/2022/05/GHSA-xxjw-jphq-5x96/GHSA-xxjw-jphq-5x96.json @@ -7,12 +7,8 @@ "CVE-2007-3107" ], "details": "The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/06/GHSA-6jp4-943r-3w3x/GHSA-6jp4-943r-3w3x.json b/advisories/unreviewed/2022/06/GHSA-6jp4-943r-3w3x/GHSA-6jp4-943r-3w3x.json index b8676978b90..6f2824990d2 100644 --- a/advisories/unreviewed/2022/06/GHSA-6jp4-943r-3w3x/GHSA-6jp4-943r-3w3x.json +++ b/advisories/unreviewed/2022/06/GHSA-6jp4-943r-3w3x/GHSA-6jp4-943r-3w3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/06/GHSA-c3gg-844m-3p5q/GHSA-c3gg-844m-3p5q.json b/advisories/unreviewed/2022/06/GHSA-c3gg-844m-3p5q/GHSA-c3gg-844m-3p5q.json index dfac0563221..066571149e1 100644 --- a/advisories/unreviewed/2022/06/GHSA-c3gg-844m-3p5q/GHSA-c3gg-844m-3p5q.json +++ b/advisories/unreviewed/2022/06/GHSA-c3gg-844m-3p5q/GHSA-c3gg-844m-3p5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json b/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json index b7bf6f78cfc..3cdcd48315b 100644 --- a/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json +++ b/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json b/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json index 4bf5fe7a5a8..2d1d2732f9d 100644 --- a/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json +++ b/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-p939-r66p-8wwm/GHSA-p939-r66p-8wwm.json b/advisories/unreviewed/2022/12/GHSA-p939-r66p-8wwm/GHSA-p939-r66p-8wwm.json index a4112443aa5..82632fcdab3 100644 --- a/advisories/unreviewed/2022/12/GHSA-p939-r66p-8wwm/GHSA-p939-r66p-8wwm.json +++ b/advisories/unreviewed/2022/12/GHSA-p939-r66p-8wwm/GHSA-p939-r66p-8wwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m73h-5f8p-xrgj/GHSA-m73h-5f8p-xrgj.json b/advisories/unreviewed/2023/04/GHSA-m73h-5f8p-xrgj/GHSA-m73h-5f8p-xrgj.json index bf686b41eb2..55ebe3d9487 100644 --- a/advisories/unreviewed/2023/04/GHSA-m73h-5f8p-xrgj/GHSA-m73h-5f8p-xrgj.json +++ b/advisories/unreviewed/2023/04/GHSA-m73h-5f8p-xrgj/GHSA-m73h-5f8p-xrgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-m9qx-f7m5-x2m6/GHSA-m9qx-f7m5-x2m6.json b/advisories/unreviewed/2023/04/GHSA-m9qx-f7m5-x2m6/GHSA-m9qx-f7m5-x2m6.json index a0336350e82..91a59216803 100644 --- a/advisories/unreviewed/2023/04/GHSA-m9qx-f7m5-x2m6/GHSA-m9qx-f7m5-x2m6.json +++ b/advisories/unreviewed/2023/04/GHSA-m9qx-f7m5-x2m6/GHSA-m9qx-f7m5-x2m6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-wxpj-f564-69x8/GHSA-wxpj-f564-69x8.json b/advisories/unreviewed/2023/04/GHSA-wxpj-f564-69x8/GHSA-wxpj-f564-69x8.json index 19dba477f50..1a4b604f6fd 100644 --- a/advisories/unreviewed/2023/04/GHSA-wxpj-f564-69x8/GHSA-wxpj-f564-69x8.json +++ b/advisories/unreviewed/2023/04/GHSA-wxpj-f564-69x8/GHSA-wxpj-f564-69x8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-wm73-m5xh-qj3h/GHSA-wm73-m5xh-qj3h.json b/advisories/unreviewed/2023/08/GHSA-wm73-m5xh-qj3h/GHSA-wm73-m5xh-qj3h.json index 713c5a2b80b..78e0a16602a 100644 --- a/advisories/unreviewed/2023/08/GHSA-wm73-m5xh-qj3h/GHSA-wm73-m5xh-qj3h.json +++ b/advisories/unreviewed/2023/08/GHSA-wm73-m5xh-qj3h/GHSA-wm73-m5xh-qj3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json b/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json index be5b1519b12..cbc0b1db1c5 100644 --- a/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json +++ b/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json b/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json index 21d1b7e2f20..88726c29e7b 100644 --- a/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json +++ b/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-46ph-452x-f4g5/GHSA-46ph-452x-f4g5.json b/advisories/unreviewed/2023/10/GHSA-46ph-452x-f4g5/GHSA-46ph-452x-f4g5.json index d5be269b523..0840d5461bb 100644 --- a/advisories/unreviewed/2023/10/GHSA-46ph-452x-f4g5/GHSA-46ph-452x-f4g5.json +++ b/advisories/unreviewed/2023/10/GHSA-46ph-452x-f4g5/GHSA-46ph-452x-f4g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json index 03a981b7c9f..e0e349c61d9 100644 --- a/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json +++ b/advisories/unreviewed/2023/10/GHSA-8xq6-frf7-63cg/GHSA-8xq6-frf7-63cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json b/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json index 511d1f71e2f..6feb6a18687 100644 --- a/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json +++ b/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-h552-rv29-f87f/GHSA-h552-rv29-f87f.json b/advisories/unreviewed/2023/10/GHSA-h552-rv29-f87f/GHSA-h552-rv29-f87f.json index 982babcfdf9..9a54dd9ffdf 100644 --- a/advisories/unreviewed/2023/10/GHSA-h552-rv29-f87f/GHSA-h552-rv29-f87f.json +++ b/advisories/unreviewed/2023/10/GHSA-h552-rv29-f87f/GHSA-h552-rv29-f87f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json b/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json index 77635a65c85..f163804fc15 100644 --- a/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json +++ b/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-q74x-62w7-247x/GHSA-q74x-62w7-247x.json b/advisories/unreviewed/2023/10/GHSA-q74x-62w7-247x/GHSA-q74x-62w7-247x.json index 7ce4a97ff15..a70a7817dc9 100644 --- a/advisories/unreviewed/2023/10/GHSA-q74x-62w7-247x/GHSA-q74x-62w7-247x.json +++ b/advisories/unreviewed/2023/10/GHSA-q74x-62w7-247x/GHSA-q74x-62w7-247x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json b/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json index 774ba027ffa..e0c60d170ec 100644 --- a/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json +++ b/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json b/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json index 52a8f7265ed..5b88433ac78 100644 --- a/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json +++ b/advisories/unreviewed/2023/10/GHSA-w3ff-vvc7-jg8f/GHSA-w3ff-vvc7-jg8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json b/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json index 55881d6c5be..3d3a6f3d809 100644 --- a/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json +++ b/advisories/unreviewed/2023/10/GHSA-wmqw-xg54-ch38/GHSA-wmqw-xg54-ch38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json index e8d51be6c63..398164aa542 100644 --- a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json +++ b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json b/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json index 4ee75523dee..308840bd023 100644 --- a/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json +++ b/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-88q8-78jp-fcv6/GHSA-88q8-78jp-fcv6.json b/advisories/unreviewed/2023/11/GHSA-88q8-78jp-fcv6/GHSA-88q8-78jp-fcv6.json index cf09ce60263..cdf95889fe9 100644 --- a/advisories/unreviewed/2023/11/GHSA-88q8-78jp-fcv6/GHSA-88q8-78jp-fcv6.json +++ b/advisories/unreviewed/2023/11/GHSA-88q8-78jp-fcv6/GHSA-88q8-78jp-fcv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-gprp-2vjm-m5gj/GHSA-gprp-2vjm-m5gj.json b/advisories/unreviewed/2023/11/GHSA-gprp-2vjm-m5gj/GHSA-gprp-2vjm-m5gj.json index 8e60d618963..1a92e94eb80 100644 --- a/advisories/unreviewed/2023/11/GHSA-gprp-2vjm-m5gj/GHSA-gprp-2vjm-m5gj.json +++ b/advisories/unreviewed/2023/11/GHSA-gprp-2vjm-m5gj/GHSA-gprp-2vjm-m5gj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-mq9c-j62j-h6cj/GHSA-mq9c-j62j-h6cj.json b/advisories/unreviewed/2023/11/GHSA-mq9c-j62j-h6cj/GHSA-mq9c-j62j-h6cj.json index 02365adca6f..a5629f1dec6 100644 --- a/advisories/unreviewed/2023/11/GHSA-mq9c-j62j-h6cj/GHSA-mq9c-j62j-h6cj.json +++ b/advisories/unreviewed/2023/11/GHSA-mq9c-j62j-h6cj/GHSA-mq9c-j62j-h6cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json b/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json index cd2ff4ca1f9..6c8104a0a16 100644 --- a/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json +++ b/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json b/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json index 74837af8b67..17b1ccc7e31 100644 --- a/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json +++ b/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json b/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json index 7ba7b3afeca..0e7f1b76613 100644 --- a/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json +++ b/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json b/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json index 2c5d6c77c20..3151ce75acb 100644 --- a/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json +++ b/advisories/unreviewed/2024/01/GHSA-9xm4-hw5v-jpjg/GHSA-9xm4-hw5v-jpjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json b/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json index baf72d7431b..839279611e2 100644 --- a/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json +++ b/advisories/unreviewed/2024/01/GHSA-c67q-c83x-f549/GHSA-c67q-c83x-f549.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json b/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json index 8eac0d04bea..028de89107a 100644 --- a/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json +++ b/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json b/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json index 16318db177a..b4a9d5ce65f 100644 --- a/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json +++ b/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json b/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json index 668f0a44523..bab5cb1d05d 100644 --- a/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json +++ b/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json b/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json index b26cbbecffa..b9107333933 100644 --- a/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json +++ b/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json b/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json index dd9ebc20b63..ab7b69ac582 100644 --- a/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json +++ b/advisories/unreviewed/2024/02/GHSA-gqvq-6r9g-ff5p/GHSA-gqvq-6r9g-ff5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jmjh-9cw7-275h/GHSA-jmjh-9cw7-275h.json b/advisories/unreviewed/2024/02/GHSA-jmjh-9cw7-275h/GHSA-jmjh-9cw7-275h.json index a0da2a6d2ac..6226a58a3b5 100644 --- a/advisories/unreviewed/2024/02/GHSA-jmjh-9cw7-275h/GHSA-jmjh-9cw7-275h.json +++ b/advisories/unreviewed/2024/02/GHSA-jmjh-9cw7-275h/GHSA-jmjh-9cw7-275h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-m3wg-jr4x-9483/GHSA-m3wg-jr4x-9483.json b/advisories/unreviewed/2024/02/GHSA-m3wg-jr4x-9483/GHSA-m3wg-jr4x-9483.json index d8bc33d2a0d..f32813d3b36 100644 --- a/advisories/unreviewed/2024/02/GHSA-m3wg-jr4x-9483/GHSA-m3wg-jr4x-9483.json +++ b/advisories/unreviewed/2024/02/GHSA-m3wg-jr4x-9483/GHSA-m3wg-jr4x-9483.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json b/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json index 8071d5c933a..5991d8f0747 100644 --- a/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json +++ b/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-pfv6-3f5p-j5c6/GHSA-pfv6-3f5p-j5c6.json b/advisories/unreviewed/2024/02/GHSA-pfv6-3f5p-j5c6/GHSA-pfv6-3f5p-j5c6.json index d15046b6322..d58a78cf114 100644 --- a/advisories/unreviewed/2024/02/GHSA-pfv6-3f5p-j5c6/GHSA-pfv6-3f5p-j5c6.json +++ b/advisories/unreviewed/2024/02/GHSA-pfv6-3f5p-j5c6/GHSA-pfv6-3f5p-j5c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-q3m2-hxcv-vxp6/GHSA-q3m2-hxcv-vxp6.json b/advisories/unreviewed/2024/02/GHSA-q3m2-hxcv-vxp6/GHSA-q3m2-hxcv-vxp6.json index 031078fa3d2..a7a19272960 100644 --- a/advisories/unreviewed/2024/02/GHSA-q3m2-hxcv-vxp6/GHSA-q3m2-hxcv-vxp6.json +++ b/advisories/unreviewed/2024/02/GHSA-q3m2-hxcv-vxp6/GHSA-q3m2-hxcv-vxp6.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json b/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json index 6897925c43b..6666f451a8a 100644 --- a/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json +++ b/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json b/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json index f3a9039f7fb..d2182c17f01 100644 --- a/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json +++ b/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json b/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json index 10c7acc1988..53f5ddbb232 100644 --- a/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json +++ b/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-54qr-qrfv-pmc3/GHSA-54qr-qrfv-pmc3.json b/advisories/unreviewed/2024/03/GHSA-54qr-qrfv-pmc3/GHSA-54qr-qrfv-pmc3.json index c48ce66ccf0..86817140c3e 100644 --- a/advisories/unreviewed/2024/03/GHSA-54qr-qrfv-pmc3/GHSA-54qr-qrfv-pmc3.json +++ b/advisories/unreviewed/2024/03/GHSA-54qr-qrfv-pmc3/GHSA-54qr-qrfv-pmc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json b/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json index 6e04c1c9fc4..f3f49315439 100644 --- a/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json +++ b/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json b/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json index f57c041c3b6..4ff13b04367 100644 --- a/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json +++ b/advisories/unreviewed/2024/03/GHSA-85v9-53x3-q4xp/GHSA-85v9-53x3-q4xp.json @@ -7,12 +7,8 @@ "CVE-2023-52577" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndccp: fix dccp_v4_err()/dccp_v6_err() again\n\ndh->dccph_x is the 9th byte (offset 8) in \"struct dccp_hdr\",\nnot in the \"byte 7\" as Jann claimed.\n\nWe need to make sure the ICMP messages are big enough,\nusing more standard ways (no more assumptions).\n\nsyzbot reported:\nBUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]\nBUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline]\nBUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94\npskb_may_pull_reason include/linux/skbuff.h:2667 [inline]\npskb_may_pull include/linux/skbuff.h:2681 [inline]\ndccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94\nicmpv6_notify+0x4c7/0x880 net/ipv6/icmp.c:867\nicmpv6_rcv+0x19d5/0x30d0\nip6_protocol_deliver_rcu+0xda6/0x2a60 net/ipv6/ip6_input.c:438\nip6_input_finish net/ipv6/ip6_input.c:483 [inline]\nNF_HOOK include/linux/netfilter.h:304 [inline]\nip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492\nip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586\ndst_input include/net/dst.h:468 [inline]\nip6_rcv_finish+0x5db/0x870 net/ipv6/ip6_input.c:79\nNF_HOOK include/linux/netfilter.h:304 [inline]\nipv6_rcv+0xda/0x390 net/ipv6/ip6_input.c:310\n__netif_receive_skb_one_core net/core/dev.c:5523 [inline]\n__netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5637\nnetif_receive_skb_internal net/core/dev.c:5723 [inline]\nnetif_receive_skb+0x58/0x660 net/core/dev.c:5782\ntun_rx_batched+0x83b/0x920\ntun_get_user+0x564c/0x6940 drivers/net/tun.c:2002\ntun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\ncall_write_iter include/linux/fs.h:1985 [inline]\nnew_sync_write fs/read_write.c:491 [inline]\nvfs_write+0x8ef/0x15c0 fs/read_write.c:584\nksys_write+0x20f/0x4c0 fs/read_write.c:637\n__do_sys_write fs/read_write.c:649 [inline]\n__se_sys_write fs/read_write.c:646 [inline]\n__x64_sys_write+0x93/0xd0 fs/read_write.c:646\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nUninit was created at:\nslab_post_alloc_hook+0x12f/0xb70 mm/slab.h:767\nslab_alloc_node mm/slub.c:3478 [inline]\nkmem_cache_alloc_node+0x577/0xa80 mm/slub.c:3523\nkmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:559\n__alloc_skb+0x318/0x740 net/core/skbuff.c:650\nalloc_skb include/linux/skbuff.h:1286 [inline]\nalloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6313\nsock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2795\ntun_alloc_skb drivers/net/tun.c:1531 [inline]\ntun_get_user+0x23cf/0x6940 drivers/net/tun.c:1846\ntun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\ncall_write_iter include/linux/fs.h:1985 [inline]\nnew_sync_write fs/read_write.c:491 [inline]\nvfs_write+0x8ef/0x15c0 fs/read_write.c:584\nksys_write+0x20f/0x4c0 fs/read_write.c:637\n__do_sys_write fs/read_write.c:649 [inline]\n__se_sys_write fs/read_write.c:646 [inline]\n__x64_sys_write+0x93/0xd0 fs/read_write.c:646\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nCPU: 0 PID: 4995 Comm: syz-executor153 Not tainted 6.6.0-rc1-syzkaller-00014-ga747acc0b752 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json b/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json index ee078c86c5a..b1ff84254e3 100644 --- a/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json +++ b/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c3wj-m54r-wfgq/GHSA-c3wj-m54r-wfgq.json b/advisories/unreviewed/2024/03/GHSA-c3wj-m54r-wfgq/GHSA-c3wj-m54r-wfgq.json index 3d6688be1e2..aedef077f07 100644 --- a/advisories/unreviewed/2024/03/GHSA-c3wj-m54r-wfgq/GHSA-c3wj-m54r-wfgq.json +++ b/advisories/unreviewed/2024/03/GHSA-c3wj-m54r-wfgq/GHSA-c3wj-m54r-wfgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json b/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json index 81544b6ca17..70850dbfc2e 100644 --- a/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json +++ b/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json b/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json index c14bc8628a5..d7197fdb8f7 100644 --- a/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json +++ b/advisories/unreviewed/2024/03/GHSA-frvc-6356-58xm/GHSA-frvc-6356-58xm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-hmf4-wxg4-957f/GHSA-hmf4-wxg4-957f.json b/advisories/unreviewed/2024/03/GHSA-hmf4-wxg4-957f/GHSA-hmf4-wxg4-957f.json index f3ef7ff959c..363dd0668cb 100644 --- a/advisories/unreviewed/2024/03/GHSA-hmf4-wxg4-957f/GHSA-hmf4-wxg4-957f.json +++ b/advisories/unreviewed/2024/03/GHSA-hmf4-wxg4-957f/GHSA-hmf4-wxg4-957f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-p8rh-8mxv-5w8q/GHSA-p8rh-8mxv-5w8q.json b/advisories/unreviewed/2024/03/GHSA-p8rh-8mxv-5w8q/GHSA-p8rh-8mxv-5w8q.json index b4c49dfd59f..ddacd601cc4 100644 --- a/advisories/unreviewed/2024/03/GHSA-p8rh-8mxv-5w8q/GHSA-p8rh-8mxv-5w8q.json +++ b/advisories/unreviewed/2024/03/GHSA-p8rh-8mxv-5w8q/GHSA-p8rh-8mxv-5w8q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-r9x9-fwpc-8mmv/GHSA-r9x9-fwpc-8mmv.json b/advisories/unreviewed/2024/03/GHSA-r9x9-fwpc-8mmv/GHSA-r9x9-fwpc-8mmv.json index 3af77830f88..d6cac3bce84 100644 --- a/advisories/unreviewed/2024/03/GHSA-r9x9-fwpc-8mmv/GHSA-r9x9-fwpc-8mmv.json +++ b/advisories/unreviewed/2024/03/GHSA-r9x9-fwpc-8mmv/GHSA-r9x9-fwpc-8mmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rpcv-9583-9pr7/GHSA-rpcv-9583-9pr7.json b/advisories/unreviewed/2024/03/GHSA-rpcv-9583-9pr7/GHSA-rpcv-9583-9pr7.json index 82d7360422f..4100a253434 100644 --- a/advisories/unreviewed/2024/03/GHSA-rpcv-9583-9pr7/GHSA-rpcv-9583-9pr7.json +++ b/advisories/unreviewed/2024/03/GHSA-rpcv-9583-9pr7/GHSA-rpcv-9583-9pr7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json b/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json index 722d903a8f5..969cac72781 100644 --- a/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json +++ b/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json b/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json index 37bd41a30d1..ca9e232ab34 100644 --- a/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json +++ b/advisories/unreviewed/2024/03/GHSA-xqf9-qrgq-fxfv/GHSA-xqf9-qrgq-fxfv.json @@ -7,12 +7,8 @@ "CVE-2023-52525" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet\n\nOnly skip the code path trying to access the rfc1042 headers when the\nbuffer is too small, so the driver can still process packets without\nrfc1042 headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json index 55a9ccf7b77..f0f4e0cbb0b 100644 --- a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json +++ b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json @@ -7,12 +7,8 @@ "CVE-2023-52359" ], "details": "Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module.\nImpact: Successful exploitation of this vulnerability will affect availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json b/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json index 7b13da5e6ef..bcd7e48cb28 100644 --- a/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json +++ b/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json @@ -7,12 +7,8 @@ "CVE-2024-30413" ], "details": "Vulnerability of improper permission control in the window management module.\nImpact: Successful exploitation of this vulnerability will affect availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json b/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json index 814ab4d891b..8d3f1b2f7e7 100644 --- a/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json +++ b/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json b/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json index 47dbe7faae2..3c68d2ae9d7 100644 --- a/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json +++ b/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json index 6a774229c84..2258bce3559 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json +++ b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json @@ -7,12 +7,8 @@ "CVE-2024-26710" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/kasan: Limit KASAN thread size increase to 32KB\n\nKASAN is seen to increase stack usage, to the point that it was reported\nto lead to stack overflow on some 32-bit machines (see link).\n\nTo avoid overflows the stack size was doubled for KASAN builds in\ncommit 3e8635fb2e07 (\"powerpc/kasan: Force thread size increase with\nKASAN\").\n\nHowever with a 32KB stack size to begin with, the doubling leads to a\n64KB stack, which causes build errors:\n arch/powerpc/kernel/switch.S:249: Error: operand out of range (0x000000000000fe50 is not between 0xffffffffffff8000 and 0x0000000000007fff)\n\nAlthough the asm could be reworked, in practice a 32KB stack seems\nsufficient even for KASAN builds - the additional usage seems to be in\nthe 2-3KB range for a 64-bit KASAN build.\n\nSo only increase the stack for KASAN if the stack size is < 32KB.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json b/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json index 71507795db7..665b0b51232 100644 --- a/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json +++ b/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json b/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json index e662aa51e68..2222af67b0b 100644 --- a/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json +++ b/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json b/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json index 400298e25af..1de51650281 100644 --- a/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json +++ b/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json b/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json index f4027c0e0ef..5291806f8c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json +++ b/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json b/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json index 01bc3962060..f7afa8c7d37 100644 --- a/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json +++ b/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json @@ -7,12 +7,8 @@ "CVE-2024-31950" ], "details": "In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json b/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json index cc9859f6810..df7b10e1d7b 100644 --- a/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json +++ b/advisories/unreviewed/2024/04/GHSA-3h96-p8ww-vw66/GHSA-3h96-p8ww-vw66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json b/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json index ac4e8dc9748..bc3f08cd614 100644 --- a/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json +++ b/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json b/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json index f505707004e..d3dc4325238 100644 --- a/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json +++ b/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json @@ -7,12 +7,8 @@ "CVE-2024-1588" ], "details": "The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json b/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json index c7cc9909205..52e97cfb866 100644 --- a/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json +++ b/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json b/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json index 177d6611cfd..af2e9acbd23 100644 --- a/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json +++ b/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json b/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json index e40f9ec4afb..c413bd1674e 100644 --- a/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json +++ b/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json index 6fb21fba0e7..e9e13c5a517 100644 --- a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json +++ b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json @@ -7,12 +7,8 @@ "CVE-2023-52540" ], "details": "Vulnerability of improper authentication in the Iaware module.\nImpact: Successful exploitation of this vulnerability will affect availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json b/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json index 299335f3050..4a943477931 100644 --- a/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json +++ b/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json b/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json index dfff1315381..d826e02808d 100644 --- a/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json +++ b/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json b/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json index f1693bf98c8..4e354bc5f3b 100644 --- a/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json +++ b/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json b/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json index 757eadf347b..81d58051ce0 100644 --- a/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json +++ b/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json b/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json index 02996e6b0f1..928f6ad29a5 100644 --- a/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json +++ b/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json b/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json index e0fb4319edd..a7b95fdf3f9 100644 --- a/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json +++ b/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json b/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json index 9e535f6a231..95e1bc8c5e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json +++ b/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json b/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json index 62e253293b3..72f26974197 100644 --- a/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json +++ b/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json b/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json index 2cd3a2f6457..f7c5fc8ea11 100644 --- a/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json +++ b/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json b/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json index 0d1bd9faa02..5bff9a8738e 100644 --- a/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json +++ b/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json b/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json index cfd02257e51..fb77afcfa7e 100644 --- a/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json +++ b/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json b/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json index 460f84c4042..6c129920cdc 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json +++ b/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json b/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json index 30a24d3e666..a6f7a78c5ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json +++ b/advisories/unreviewed/2024/04/GHSA-7qqv-8pwc-x4xc/GHSA-7qqv-8pwc-x4xc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json b/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json index 4d6acaea28c..270689a3785 100644 --- a/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json +++ b/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json b/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json index 468f5c8da7d..a6b8f491df7 100644 --- a/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json +++ b/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json b/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json index dc9ec5636c4..d56e1380339 100644 --- a/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json +++ b/advisories/unreviewed/2024/04/GHSA-96rw-9jfw-gw2m/GHSA-96rw-9jfw-gw2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json b/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json index fc0745059ba..2f5e57b420b 100644 --- a/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json +++ b/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json b/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json index 09a4b41f7c3..535aa9198fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json +++ b/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json b/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json index 1f92d2d3f40..0ea8686aea6 100644 --- a/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json +++ b/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json b/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json index 1a12668d8b1..df3e11a73bf 100644 --- a/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json +++ b/advisories/unreviewed/2024/04/GHSA-9m65-6pjm-r78p/GHSA-9m65-6pjm-r78p.json @@ -7,12 +7,8 @@ "CVE-2024-27981" ], "details": "A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device.\n\nAffected Products:\nUniFi Network Application (Version 8.0.28 and earlier) .\n \nMitigation:\nUpdate UniFi Network Application to Version 8.1.113 or later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json b/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json index f7a17197ec6..9f7448b6d8e 100644 --- a/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json +++ b/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json b/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json index 8cb0f2a1450..3fe23f9ea84 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json +++ b/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json b/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json index 831d8683ea0..5bbbe12eabc 100644 --- a/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json +++ b/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json b/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json index 3fb9be27711..d6137a6f1a8 100644 --- a/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json +++ b/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json b/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json index 8e5dc52eeb0..e3924c9c505 100644 --- a/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json +++ b/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json b/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json index cac5d744cf3..9a3bd69f0b1 100644 --- a/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json +++ b/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json b/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json index 768b69cd450..53fbae79b1a 100644 --- a/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json +++ b/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json b/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json index 91b92377efe..47bdc68905e 100644 --- a/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json +++ b/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json b/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json index 2827c517067..44d0b78f1d5 100644 --- a/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json +++ b/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json b/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json index 227d0a1e7d7..b2cf7d48125 100644 --- a/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json +++ b/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json b/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json index c6a582f603b..be237da91ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json +++ b/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json b/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json index 61fdf112dc7..33203815128 100644 --- a/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json +++ b/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json b/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json index 130a29c2479..d5be7dc5a61 100644 --- a/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json +++ b/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json b/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json index 4abcb2269b7..a250e836abf 100644 --- a/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json +++ b/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json b/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json index f8cce012dae..39d68fdc340 100644 --- a/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json +++ b/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json b/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json index 6f74b1e8793..5a059301f2e 100644 --- a/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json +++ b/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json b/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json index cf3a77930c3..d943d96d038 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json +++ b/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json b/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json index 6fa471b9bbd..a482e3336ac 100644 --- a/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json +++ b/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json b/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json index 73342e3a294..6c8b7a75475 100644 --- a/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json +++ b/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json b/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json index 83f1a1c2618..4d698ab8c2d 100644 --- a/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json +++ b/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json b/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json index 206b5224b51..36280aa7323 100644 --- a/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json +++ b/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json b/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json index 1706b2356b1..9abd3f46d93 100644 --- a/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json +++ b/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json b/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json index fd7bb824fa9..73a7e5516f5 100644 --- a/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json +++ b/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json index cc92392eb43..777d26e580a 100644 --- a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json +++ b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json b/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json index 04dd3cf970c..1abda6f545d 100644 --- a/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json +++ b/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json b/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json index e58114ee288..78442122310 100644 --- a/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json +++ b/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json b/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json index 8405515931a..deddedfa56e 100644 --- a/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json +++ b/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json @@ -7,12 +7,8 @@ "CVE-2024-30417" ], "details": "Path traversal vulnerability in the Bluetooth-based sharing module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json b/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json index 2f837128ff4..658444af4cc 100644 --- a/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json +++ b/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json b/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json index e57f47b39e4..d8884d2333f 100644 --- a/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json +++ b/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json b/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json index 42fb044769b..b7a8e91466c 100644 --- a/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json +++ b/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json b/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json index 6525aa301b3..3cc71c39c0f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json +++ b/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json b/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json index bcb45795568..aaff8348abe 100644 --- a/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json +++ b/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json b/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json index 136c1a08b6c..4e1a71a04df 100644 --- a/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json +++ b/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json b/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json index f0086020a4b..ac28f038c67 100644 --- a/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json +++ b/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json index a537e7cba5c..45b1891fac5 100644 --- a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json +++ b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json @@ -7,12 +7,8 @@ "CVE-2023-52715" ], "details": "The SystemUI module has a vulnerability in permission management.\nImpact: Successful exploitation of this vulnerability may affect availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json b/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json index 2e73df39b62..a378bb876fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json +++ b/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json b/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json index 6c049d915ae..b5537768c13 100644 --- a/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json +++ b/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json b/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json index 1bb451f4b57..0dc34a7fc87 100644 --- a/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json +++ b/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json @@ -7,12 +7,8 @@ "CVE-2024-1956" ], "details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json b/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json index c55899a24f9..0f502c18c22 100644 --- a/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json +++ b/advisories/unreviewed/2024/04/GHSA-vm4m-6mf9-8885/GHSA-vm4m-6mf9-8885.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json b/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json index 2f6d529cb00..396102f72c0 100644 --- a/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json +++ b/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json b/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json index dc729fc510c..403e79dc926 100644 --- a/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json +++ b/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json index 1cf03bd38e9..3c54786a275 100644 --- a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json +++ b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json @@ -7,12 +7,8 @@ "CVE-2024-1958" ], "details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json b/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json index f70ddfaf145..ebaae334671 100644 --- a/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json +++ b/advisories/unreviewed/2024/04/GHSA-w9gh-mc2w-wrg3/GHSA-w9gh-mc2w-wrg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json b/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json index 03e8acf2f4d..c4e59369f19 100644 --- a/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json +++ b/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json b/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json index 8c75d33bb44..e3bd5c1e239 100644 --- a/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json +++ b/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json b/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json index 2a3f6782eca..3ff7ffc55b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json +++ b/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json b/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json index 043ca500010..f510c8d61e9 100644 --- a/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json +++ b/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json b/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json index fb94151665f..27dbccc7427 100644 --- a/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json +++ b/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json b/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json index a39a1ac4d21..8dfd83cb870 100644 --- a/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json +++ b/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2xxp-mhvm-26p5/GHSA-2xxp-mhvm-26p5.json b/advisories/unreviewed/2024/05/GHSA-2xxp-mhvm-26p5/GHSA-2xxp-mhvm-26p5.json index d42022151d5..b5975f3a203 100644 --- a/advisories/unreviewed/2024/05/GHSA-2xxp-mhvm-26p5/GHSA-2xxp-mhvm-26p5.json +++ b/advisories/unreviewed/2024/05/GHSA-2xxp-mhvm-26p5/GHSA-2xxp-mhvm-26p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-362q-j64x-4ggr/GHSA-362q-j64x-4ggr.json b/advisories/unreviewed/2024/05/GHSA-362q-j64x-4ggr/GHSA-362q-j64x-4ggr.json index 9b088a00d7b..7d3375cfbf4 100644 --- a/advisories/unreviewed/2024/05/GHSA-362q-j64x-4ggr/GHSA-362q-j64x-4ggr.json +++ b/advisories/unreviewed/2024/05/GHSA-362q-j64x-4ggr/GHSA-362q-j64x-4ggr.json @@ -7,12 +7,8 @@ "CVE-2024-35856" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: mediatek: Fix double free of skb in coredump\n\nhci_devcd_append() would free the skb on error so the caller don't\nhave to free it again otherwise it would cause the double free of skb.\n\nReported-by : Dan Carpenter ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3h45-h6mj-8qm2/GHSA-3h45-h6mj-8qm2.json b/advisories/unreviewed/2024/05/GHSA-3h45-h6mj-8qm2/GHSA-3h45-h6mj-8qm2.json index b9f56d3feb9..b85c023c594 100644 --- a/advisories/unreviewed/2024/05/GHSA-3h45-h6mj-8qm2/GHSA-3h45-h6mj-8qm2.json +++ b/advisories/unreviewed/2024/05/GHSA-3h45-h6mj-8qm2/GHSA-3h45-h6mj-8qm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-454p-4wfm-4wpx/GHSA-454p-4wfm-4wpx.json b/advisories/unreviewed/2024/05/GHSA-454p-4wfm-4wpx/GHSA-454p-4wfm-4wpx.json index 145b7ce25b3..b5d4350856d 100644 --- a/advisories/unreviewed/2024/05/GHSA-454p-4wfm-4wpx/GHSA-454p-4wfm-4wpx.json +++ b/advisories/unreviewed/2024/05/GHSA-454p-4wfm-4wpx/GHSA-454p-4wfm-4wpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-483r-g2gh-jg53/GHSA-483r-g2gh-jg53.json b/advisories/unreviewed/2024/05/GHSA-483r-g2gh-jg53/GHSA-483r-g2gh-jg53.json index 4cdce2047cf..bd5d0b7be7b 100644 --- a/advisories/unreviewed/2024/05/GHSA-483r-g2gh-jg53/GHSA-483r-g2gh-jg53.json +++ b/advisories/unreviewed/2024/05/GHSA-483r-g2gh-jg53/GHSA-483r-g2gh-jg53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4g6g-5g88-76v5/GHSA-4g6g-5g88-76v5.json b/advisories/unreviewed/2024/05/GHSA-4g6g-5g88-76v5/GHSA-4g6g-5g88-76v5.json index 5c153dab7e7..f0a7d2a2d58 100644 --- a/advisories/unreviewed/2024/05/GHSA-4g6g-5g88-76v5/GHSA-4g6g-5g88-76v5.json +++ b/advisories/unreviewed/2024/05/GHSA-4g6g-5g88-76v5/GHSA-4g6g-5g88-76v5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4gg5-g35c-mghx/GHSA-4gg5-g35c-mghx.json b/advisories/unreviewed/2024/05/GHSA-4gg5-g35c-mghx/GHSA-4gg5-g35c-mghx.json index cfab554e042..a159852b298 100644 --- a/advisories/unreviewed/2024/05/GHSA-4gg5-g35c-mghx/GHSA-4gg5-g35c-mghx.json +++ b/advisories/unreviewed/2024/05/GHSA-4gg5-g35c-mghx/GHSA-4gg5-g35c-mghx.json @@ -7,12 +7,8 @@ "CVE-2024-35818" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Define the __io_aw() hook as mmiowb()\n\nCommit fb24ea52f78e0d595852e (\"drivers: Remove explicit invocations of\nmmiowb()\") remove all mmiowb() in drivers, but it says:\n\n\"NOTE: mmiowb() has only ever guaranteed ordering in conjunction with\nspin_unlock(). However, pairing each mmiowb() removal in this patch with\nthe corresponding call to spin_unlock() is not at all trivial, so there\nis a small chance that this change may regress any drivers incorrectly\nrelying on mmiowb() to order MMIO writes between CPUs using lock-free\nsynchronisation.\"\n\nThe mmio in radeon_ring_commit() is protected by a mutex rather than a\nspinlock, but in the mutex fastpath it behaves similar to spinlock. We\ncan add mmiowb() calls in the radeon driver but the maintainer says he\ndoesn't like such a workaround, and radeon is not the only example of\nmutex protected mmio.\n\nSo we should extend the mmiowb tracking system from spinlock to mutex,\nand maybe other locking primitives. This is not easy and error prone, so\nwe solve it in the architectural code, by simply defining the __io_aw()\nhook as mmiowb(). And we no longer need to override queued_spin_unlock()\nso use the generic definition.\n\nWithout this, we get such an error when run 'glxgears' on weak ordering\narchitectures such as LoongArch:\n\nradeon 0000:04:00.0: ring 0 stalled for more than 10324msec\nradeon 0000:04:00.0: ring 3 stalled for more than 10240msec\nradeon 0000:04:00.0: GPU lockup (current fence id 0x000000000001f412 last fence id 0x000000000001f414 on ring 3)\nradeon 0000:04:00.0: GPU lockup (current fence id 0x000000000000f940 last fence id 0x000000000000f941 on ring 0)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)\nradeon 0000:04:00.0: scheduling IB failed (-35).\n[drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-64vh-gcrh-6whf/GHSA-64vh-gcrh-6whf.json b/advisories/unreviewed/2024/05/GHSA-64vh-gcrh-6whf/GHSA-64vh-gcrh-6whf.json index 177913dc093..217d7d7e4a3 100644 --- a/advisories/unreviewed/2024/05/GHSA-64vh-gcrh-6whf/GHSA-64vh-gcrh-6whf.json +++ b/advisories/unreviewed/2024/05/GHSA-64vh-gcrh-6whf/GHSA-64vh-gcrh-6whf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6579-jp4w-xm59/GHSA-6579-jp4w-xm59.json b/advisories/unreviewed/2024/05/GHSA-6579-jp4w-xm59/GHSA-6579-jp4w-xm59.json index 58c46fd5907..6e9bd505798 100644 --- a/advisories/unreviewed/2024/05/GHSA-6579-jp4w-xm59/GHSA-6579-jp4w-xm59.json +++ b/advisories/unreviewed/2024/05/GHSA-6579-jp4w-xm59/GHSA-6579-jp4w-xm59.json @@ -7,12 +7,8 @@ "CVE-2024-35851" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NULL-deref on non-serdev suspend\n\nQualcomm ROME controllers can be registered from the Bluetooth line\ndiscipline and in this case the HCI UART serdev pointer is NULL.\n\nAdd the missing sanity check to prevent a NULL-pointer dereference when\nwakeup() is called for a non-serdev controller during suspend.\n\nJust return true for now to restore the original behaviour and address\nthe crash with pre-6.2 kernels, which do not have commit e9b3e5b8c657\n(\"Bluetooth: hci_qca: only assign wakeup with serial port support\") that\ncauses the crash to happen already at setup() time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-657p-cp5v-hvxv/GHSA-657p-cp5v-hvxv.json b/advisories/unreviewed/2024/05/GHSA-657p-cp5v-hvxv/GHSA-657p-cp5v-hvxv.json index 4718d981711..3fd9954db06 100644 --- a/advisories/unreviewed/2024/05/GHSA-657p-cp5v-hvxv/GHSA-657p-cp5v-hvxv.json +++ b/advisories/unreviewed/2024/05/GHSA-657p-cp5v-hvxv/GHSA-657p-cp5v-hvxv.json @@ -7,12 +7,8 @@ "CVE-2024-35846" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: zswap: fix shrinker NULL crash with cgroup_disable=memory\n\nChristian reports a NULL deref in zswap that he bisected down to the zswap\nshrinker. The issue also cropped up in the bug trackers of libguestfs [1]\nand the Red Hat bugzilla [2].\n\nThe problem is that when memcg is disabled with the boot time flag, the\nzswap shrinker might get called with sc->memcg == NULL. This is okay in\nmany places, like the lruvec operations. But it crashes in\nmemcg_page_state() - which is only used due to the non-node accounting of\ncgroup's the zswap memory to begin with.\n\nNhat spotted that the memcg can be NULL in the memcg-disabled case, and I\nwas then able to reproduce the crash locally as well.\n\n[1] https://github.com/libguestfs/libguestfs/issues/139\n[2] https://bugzilla.redhat.com/show_bug.cgi?id=2275252", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-65r5-237m-62hm/GHSA-65r5-237m-62hm.json b/advisories/unreviewed/2024/05/GHSA-65r5-237m-62hm/GHSA-65r5-237m-62hm.json index ebf6ccb0802..a666fc0386c 100644 --- a/advisories/unreviewed/2024/05/GHSA-65r5-237m-62hm/GHSA-65r5-237m-62hm.json +++ b/advisories/unreviewed/2024/05/GHSA-65r5-237m-62hm/GHSA-65r5-237m-62hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-682g-jf8v-94jw/GHSA-682g-jf8v-94jw.json b/advisories/unreviewed/2024/05/GHSA-682g-jf8v-94jw/GHSA-682g-jf8v-94jw.json index 745542e7572..f9e3d064ae4 100644 --- a/advisories/unreviewed/2024/05/GHSA-682g-jf8v-94jw/GHSA-682g-jf8v-94jw.json +++ b/advisories/unreviewed/2024/05/GHSA-682g-jf8v-94jw/GHSA-682g-jf8v-94jw.json @@ -7,12 +7,8 @@ "CVE-2024-35810" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix the lifetime of the bo cursor memory\n\nThe cleanup can be dispatched while the atomic update is still active,\nwhich means that the memory acquired in the atomic update needs to\nnot be invalidated by the cleanup. The buffer objects in vmw_plane_state\ninstead of using the builtin map_and_cache were trying to handle\nthe lifetime of the mapped memory themselves, leading to crashes.\n\nUse the map_and_cache instead of trying to manage the lifetime of the\nbuffer objects held by the vmw_plane_state.\n\nFixes kernel oops'es in IGT's kms_cursor_legacy forked-bo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6q9q-x3xj-g3m7/GHSA-6q9q-x3xj-g3m7.json b/advisories/unreviewed/2024/05/GHSA-6q9q-x3xj-g3m7/GHSA-6q9q-x3xj-g3m7.json index 00c6c5d2c26..c311b465194 100644 --- a/advisories/unreviewed/2024/05/GHSA-6q9q-x3xj-g3m7/GHSA-6q9q-x3xj-g3m7.json +++ b/advisories/unreviewed/2024/05/GHSA-6q9q-x3xj-g3m7/GHSA-6q9q-x3xj-g3m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6rw2-3pw4-264h/GHSA-6rw2-3pw4-264h.json b/advisories/unreviewed/2024/05/GHSA-6rw2-3pw4-264h/GHSA-6rw2-3pw4-264h.json index 8ed077739fc..ab815c0587d 100644 --- a/advisories/unreviewed/2024/05/GHSA-6rw2-3pw4-264h/GHSA-6rw2-3pw4-264h.json +++ b/advisories/unreviewed/2024/05/GHSA-6rw2-3pw4-264h/GHSA-6rw2-3pw4-264h.json @@ -7,12 +7,8 @@ "CVE-2024-35836" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpll: fix pin dump crash for rebound module\n\nWhen a kernel module is unbound but the pin resources were not entirely\nfreed (other kernel module instance of the same PCI device have had kept\nthe reference to that pin), and kernel module is again bound, the pin\nproperties would not be updated (the properties are only assigned when\nmemory for the pin is allocated), prop pointer still points to the\nkernel module memory of the kernel module which was deallocated on the\nunbind.\n\nIf the pin dump is invoked in this state, the result is a kernel crash.\nPrevent the crash by storing persistent pin properties in dpll subsystem,\ncopy the content from the kernel module when pin is allocated, instead of\nusing memory of the kernel module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7cmv-p5w7-7vqq/GHSA-7cmv-p5w7-7vqq.json b/advisories/unreviewed/2024/05/GHSA-7cmv-p5w7-7vqq/GHSA-7cmv-p5w7-7vqq.json index b539aa65a6a..120499f778f 100644 --- a/advisories/unreviewed/2024/05/GHSA-7cmv-p5w7-7vqq/GHSA-7cmv-p5w7-7vqq.json +++ b/advisories/unreviewed/2024/05/GHSA-7cmv-p5w7-7vqq/GHSA-7cmv-p5w7-7vqq.json @@ -7,12 +7,8 @@ "CVE-2023-52671" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix hang/underflow when transitioning to ODM4:1\n\n[Why]\nUnder some circumstances, disabling an OPTC and attempting to reclaim\nits OPP(s) for a different OPTC could cause a hang/underflow due to OPPs\nnot being properly disconnected from the disabled OPTC.\n\n[How]\nEnsure that all OPPs are unassigned from an OPTC when it gets disabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7hqf-f5qc-8535/GHSA-7hqf-f5qc-8535.json b/advisories/unreviewed/2024/05/GHSA-7hqf-f5qc-8535/GHSA-7hqf-f5qc-8535.json index e13b3fa99a0..fcccb06b282 100644 --- a/advisories/unreviewed/2024/05/GHSA-7hqf-f5qc-8535/GHSA-7hqf-f5qc-8535.json +++ b/advisories/unreviewed/2024/05/GHSA-7hqf-f5qc-8535/GHSA-7hqf-f5qc-8535.json @@ -7,12 +7,8 @@ "CVE-2024-35827" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/net: fix overflow check in io_recvmsg_mshot_prep()\n\nThe \"controllen\" variable is type size_t (unsigned long). Casting it\nto int could lead to an integer underflow.\n\nThe check_add_overflow() function considers the type of the destination\nwhich is type int. If we add two positive values and the result cannot\nfit in an integer then that's counted as an overflow.\n\nHowever, if we cast \"controllen\" to an int and it turns negative, then\nnegative values *can* fit into an int type so there is no overflow.\n\nGood: 100 + (unsigned long)-4 = 96 <-- overflow\n Bad: 100 + (int)-4 = 96 <-- no overflow\n\nI deleted the cast of the sizeof() as well. That's not a bug but the\ncast is unnecessary.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json b/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json index aa4b5be540c..e3c07520b4a 100644 --- a/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json +++ b/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json @@ -7,12 +7,8 @@ "CVE-2023-52667" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: fix a potential double-free in fs_any_create_groups\n\nWhen kcalloc() for ft->g succeeds but kvzalloc() for in fails,\nfs_any_create_groups() will free ft->g. However, its caller\nfs_any_create_table() will free ft->g again through calling\nmlx5e_destroy_flow_table(), which will lead to a double-free.\nFix this by setting ft->g to NULL in fs_any_create_groups().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8g5c-5h6j-rxcw/GHSA-8g5c-5h6j-rxcw.json b/advisories/unreviewed/2024/05/GHSA-8g5c-5h6j-rxcw/GHSA-8g5c-5h6j-rxcw.json index 4f7d0c6636c..914e71066f7 100644 --- a/advisories/unreviewed/2024/05/GHSA-8g5c-5h6j-rxcw/GHSA-8g5c-5h6j-rxcw.json +++ b/advisories/unreviewed/2024/05/GHSA-8g5c-5h6j-rxcw/GHSA-8g5c-5h6j-rxcw.json @@ -7,12 +7,8 @@ "CVE-2023-52677" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Check if the code to patch lies in the exit section\n\nOtherwise we fall through to vmalloc_to_page() which panics since the\naddress does not lie in the vmalloc region.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9268-35c3-9w2w/GHSA-9268-35c3-9w2w.json b/advisories/unreviewed/2024/05/GHSA-9268-35c3-9w2w/GHSA-9268-35c3-9w2w.json index 7079cc279ac..8348e3442ec 100644 --- a/advisories/unreviewed/2024/05/GHSA-9268-35c3-9w2w/GHSA-9268-35c3-9w2w.json +++ b/advisories/unreviewed/2024/05/GHSA-9268-35c3-9w2w/GHSA-9268-35c3-9w2w.json @@ -7,12 +7,8 @@ "CVE-2024-35840" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect()\n\nsubflow_finish_connect() uses four fields (backup, join_id, thmac, none)\nthat may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set\nin mptcp_parse_option()", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-92vm-p8p9-g4x5/GHSA-92vm-p8p9-g4x5.json b/advisories/unreviewed/2024/05/GHSA-92vm-p8p9-g4x5/GHSA-92vm-p8p9-g4x5.json index e932cb4f53d..6598df5a4c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-92vm-p8p9-g4x5/GHSA-92vm-p8p9-g4x5.json +++ b/advisories/unreviewed/2024/05/GHSA-92vm-p8p9-g4x5/GHSA-92vm-p8p9-g4x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-97xm-5mr2-683x/GHSA-97xm-5mr2-683x.json b/advisories/unreviewed/2024/05/GHSA-97xm-5mr2-683x/GHSA-97xm-5mr2-683x.json index 0cb2619d459..d66f0269f86 100644 --- a/advisories/unreviewed/2024/05/GHSA-97xm-5mr2-683x/GHSA-97xm-5mr2-683x.json +++ b/advisories/unreviewed/2024/05/GHSA-97xm-5mr2-683x/GHSA-97xm-5mr2-683x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9r2m-vj3f-vcph/GHSA-9r2m-vj3f-vcph.json b/advisories/unreviewed/2024/05/GHSA-9r2m-vj3f-vcph/GHSA-9r2m-vj3f-vcph.json index 0057eff6e60..e39177bcad2 100644 --- a/advisories/unreviewed/2024/05/GHSA-9r2m-vj3f-vcph/GHSA-9r2m-vj3f-vcph.json +++ b/advisories/unreviewed/2024/05/GHSA-9r2m-vj3f-vcph/GHSA-9r2m-vj3f-vcph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-frv5-mfr5-q7h5/GHSA-frv5-mfr5-q7h5.json b/advisories/unreviewed/2024/05/GHSA-frv5-mfr5-q7h5/GHSA-frv5-mfr5-q7h5.json index d438fac0a1b..f600804c239 100644 --- a/advisories/unreviewed/2024/05/GHSA-frv5-mfr5-q7h5/GHSA-frv5-mfr5-q7h5.json +++ b/advisories/unreviewed/2024/05/GHSA-frv5-mfr5-q7h5/GHSA-frv5-mfr5-q7h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gw6v-2949-7c2m/GHSA-gw6v-2949-7c2m.json b/advisories/unreviewed/2024/05/GHSA-gw6v-2949-7c2m/GHSA-gw6v-2949-7c2m.json index eede0b47dc4..67e185812c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-gw6v-2949-7c2m/GHSA-gw6v-2949-7c2m.json +++ b/advisories/unreviewed/2024/05/GHSA-gw6v-2949-7c2m/GHSA-gw6v-2949-7c2m.json @@ -7,12 +7,8 @@ "CVE-2024-35839" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: replace physindev with physinif in nf_bridge_info\n\nAn skb can be added to a neigh->arp_queue while waiting for an arp\nreply. Where original skb's skb->dev can be different to neigh's\nneigh->dev. For instance in case of bridging dnated skb from one veth to\nanother, the skb would be added to a neigh->arp_queue of the bridge.\n\nAs skb->dev can be reset back to nf_bridge->physindev and used, and as\nthere is no explicit mechanism that prevents this physindev from been\nfreed under us (for instance neigh_flush_dev doesn't cleanup skbs from\ndifferent device's neigh queue) we can crash on e.g. this stack:\n\narp_process\n neigh_update\n skb = __skb_dequeue(&neigh->arp_queue)\n neigh_resolve_output(..., skb)\n ...\n br_nf_dev_xmit\n br_nf_pre_routing_finish_bridge_slow\n skb->dev = nf_bridge->physindev\n br_handle_frame_finish\n\nLet's use plain ifindex instead of net_device link. To peek into the\noriginal net_device we will use dev_get_by_index_rcu(). Thus either we\nget device and are safe to use it or we don't get it and drop skb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hchj-593h-jx3r/GHSA-hchj-593h-jx3r.json b/advisories/unreviewed/2024/05/GHSA-hchj-593h-jx3r/GHSA-hchj-593h-jx3r.json index 292ccb647c0..a3a927c0e34 100644 --- a/advisories/unreviewed/2024/05/GHSA-hchj-593h-jx3r/GHSA-hchj-593h-jx3r.json +++ b/advisories/unreviewed/2024/05/GHSA-hchj-593h-jx3r/GHSA-hchj-593h-jx3r.json @@ -7,12 +7,8 @@ "CVE-2024-35800" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: fix panic in kdump kernel\n\nCheck if get_next_variable() is actually valid pointer before\ncalling it. In kdump kernel this method is set to NULL that causes\npanic during the kexec-ed kernel boot.\n\nTested with QEMU and OVMF firmware.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hhcf-pxch-r4cf/GHSA-hhcf-pxch-r4cf.json b/advisories/unreviewed/2024/05/GHSA-hhcf-pxch-r4cf/GHSA-hhcf-pxch-r4cf.json index 3257a1293dd..adeef2cef2b 100644 --- a/advisories/unreviewed/2024/05/GHSA-hhcf-pxch-r4cf/GHSA-hhcf-pxch-r4cf.json +++ b/advisories/unreviewed/2024/05/GHSA-hhcf-pxch-r4cf/GHSA-hhcf-pxch-r4cf.json @@ -7,12 +7,8 @@ "CVE-2024-35831" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: Fix release of pinned pages when __io_uaddr_map fails\n\nLooking at the error path of __io_uaddr_map, if we fail after pinning\nthe pages for any reasons, ret will be set to -EINVAL and the error\nhandler won't properly release the pinned pages.\n\nI didn't manage to trigger it without forcing a failure, but it can\nhappen in real life when memory is heavily fragmented.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hm94-45pm-xvx4/GHSA-hm94-45pm-xvx4.json b/advisories/unreviewed/2024/05/GHSA-hm94-45pm-xvx4/GHSA-hm94-45pm-xvx4.json index fb35ab99441..ab113d93982 100644 --- a/advisories/unreviewed/2024/05/GHSA-hm94-45pm-xvx4/GHSA-hm94-45pm-xvx4.json +++ b/advisories/unreviewed/2024/05/GHSA-hm94-45pm-xvx4/GHSA-hm94-45pm-xvx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-j2m8-8r6c-36x2/GHSA-j2m8-8r6c-36x2.json b/advisories/unreviewed/2024/05/GHSA-j2m8-8r6c-36x2/GHSA-j2m8-8r6c-36x2.json index e23895e4e6a..bc5b311aba8 100644 --- a/advisories/unreviewed/2024/05/GHSA-j2m8-8r6c-36x2/GHSA-j2m8-8r6c-36x2.json +++ b/advisories/unreviewed/2024/05/GHSA-j2m8-8r6c-36x2/GHSA-j2m8-8r6c-36x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jrj6-7p65-rqf2/GHSA-jrj6-7p65-rqf2.json b/advisories/unreviewed/2024/05/GHSA-jrj6-7p65-rqf2/GHSA-jrj6-7p65-rqf2.json index 068a5d2f544..9ba0f3f7156 100644 --- a/advisories/unreviewed/2024/05/GHSA-jrj6-7p65-rqf2/GHSA-jrj6-7p65-rqf2.json +++ b/advisories/unreviewed/2024/05/GHSA-jrj6-7p65-rqf2/GHSA-jrj6-7p65-rqf2.json @@ -7,12 +7,8 @@ "CVE-2024-35842" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: sof-common: Add NULL check for normal_link string\n\nIt's not granted that all entries of struct sof_conn_stream declare\na `normal_link` (a non-SOF, direct link) string, and this is the case\nfor SoCs that support only SOF paths (hence do not support both direct\nand SOF usecases).\n\nFor example, in the case of MT8188 there is no normal_link string in\nany of the sof_conn_stream entries and there will be more drivers\ndoing that in the future.\n\nTo avoid possible NULL pointer KPs, add a NULL check for `normal_link`.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jw9q-cpgg-x45m/GHSA-jw9q-cpgg-x45m.json b/advisories/unreviewed/2024/05/GHSA-jw9q-cpgg-x45m/GHSA-jw9q-cpgg-x45m.json index 6a936a83157..2dee5f13889 100644 --- a/advisories/unreviewed/2024/05/GHSA-jw9q-cpgg-x45m/GHSA-jw9q-cpgg-x45m.json +++ b/advisories/unreviewed/2024/05/GHSA-jw9q-cpgg-x45m/GHSA-jw9q-cpgg-x45m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-jwj4-6vq9-qvx8/GHSA-jwj4-6vq9-qvx8.json b/advisories/unreviewed/2024/05/GHSA-jwj4-6vq9-qvx8/GHSA-jwj4-6vq9-qvx8.json index 40524e165f1..b310c244107 100644 --- a/advisories/unreviewed/2024/05/GHSA-jwj4-6vq9-qvx8/GHSA-jwj4-6vq9-qvx8.json +++ b/advisories/unreviewed/2024/05/GHSA-jwj4-6vq9-qvx8/GHSA-jwj4-6vq9-qvx8.json @@ -7,12 +7,8 @@ "CVE-2024-35832" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit\n\nbch_fs::snapshots is allocated by kvzalloc in __snapshot_t_mut.\nIt should be freed by kvfree not kfree.\nOr umount will triger:\n\n[ 406.829178 ] BUG: unable to handle page fault for address: ffffe7b487148008\n[ 406.830676 ] #PF: supervisor read access in kernel mode\n[ 406.831643 ] #PF: error_code(0x0000) - not-present page\n[ 406.832487 ] PGD 0 P4D 0\n[ 406.832898 ] Oops: 0000 [#1] PREEMPT SMP PTI\n[ 406.833512 ] CPU: 2 PID: 1754 Comm: umount Kdump: loaded Tainted: G OE 6.7.0-rc7-custom+ #90\n[ 406.834746 ] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n[ 406.835796 ] RIP: 0010:kfree+0x62/0x140\n[ 406.836197 ] Code: 80 48 01 d8 0f 82 e9 00 00 00 48 c7 c2 00 00 00 80 48 2b 15 78 9f 1f 01 48 01 d0 48 c1 e8 0c 48 c1 e0 06 48 03 05 56 9f 1f 01 <48> 8b 50 08 48 89 c7 f6 c2 01 0f 85 b0 00 00 00 66 90 48 8b 07 f6\n[ 406.837810 ] RSP: 0018:ffffb9d641607e48 EFLAGS: 00010286\n[ 406.838213 ] RAX: ffffe7b487148000 RBX: ffffb9d645200000 RCX: ffffb9d641607dc4\n[ 406.838738 ] RDX: 000065bb00000000 RSI: ffffffffc0d88b84 RDI: ffffb9d645200000\n[ 406.839217 ] RBP: ffff9a4625d00068 R08: 0000000000000001 R09: 0000000000000001\n[ 406.839650 ] R10: 0000000000000001 R11: 000000000000001f R12: ffff9a4625d4da80\n[ 406.840055 ] R13: ffff9a4625d00000 R14: ffffffffc0e2eb20 R15: 0000000000000000\n[ 406.840451 ] FS: 00007f0a264ffb80(0000) GS:ffff9a4e2d500000(0000) knlGS:0000000000000000\n[ 406.840851 ] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 406.841125 ] CR2: ffffe7b487148008 CR3: 000000018c4d2000 CR4: 00000000000006f0\n[ 406.841464 ] Call Trace:\n[ 406.841583 ] \n[ 406.841682 ] ? __die+0x1f/0x70\n[ 406.841828 ] ? page_fault_oops+0x159/0x470\n[ 406.842014 ] ? fixup_exception+0x22/0x310\n[ 406.842198 ] ? exc_page_fault+0x1ed/0x200\n[ 406.842382 ] ? asm_exc_page_fault+0x22/0x30\n[ 406.842574 ] ? bch2_fs_release+0x54/0x280 [bcachefs]\n[ 406.842842 ] ? kfree+0x62/0x140\n[ 406.842988 ] ? kfree+0x104/0x140\n[ 406.843138 ] bch2_fs_release+0x54/0x280 [bcachefs]\n[ 406.843390 ] kobject_put+0xb7/0x170\n[ 406.843552 ] deactivate_locked_super+0x2f/0xa0\n[ 406.843756 ] cleanup_mnt+0xba/0x150\n[ 406.843917 ] task_work_run+0x59/0xa0\n[ 406.844083 ] exit_to_user_mode_prepare+0x197/0x1a0\n[ 406.844302 ] syscall_exit_to_user_mode+0x16/0x40\n[ 406.844510 ] do_syscall_64+0x4e/0xf0\n[ 406.844675 ] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[ 406.844907 ] RIP: 0033:0x7f0a2664e4fb", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mcgh-62x5-2v7c/GHSA-mcgh-62x5-2v7c.json b/advisories/unreviewed/2024/05/GHSA-mcgh-62x5-2v7c/GHSA-mcgh-62x5-2v7c.json index 67edf249b87..0b2ea0324f7 100644 --- a/advisories/unreviewed/2024/05/GHSA-mcgh-62x5-2v7c/GHSA-mcgh-62x5-2v7c.json +++ b/advisories/unreviewed/2024/05/GHSA-mcgh-62x5-2v7c/GHSA-mcgh-62x5-2v7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mf8v-4v5x-g329/GHSA-mf8v-4v5x-g329.json b/advisories/unreviewed/2024/05/GHSA-mf8v-4v5x-g329/GHSA-mf8v-4v5x-g329.json index 2c059dc72c6..8f8a958e2e6 100644 --- a/advisories/unreviewed/2024/05/GHSA-mf8v-4v5x-g329/GHSA-mf8v-4v5x-g329.json +++ b/advisories/unreviewed/2024/05/GHSA-mf8v-4v5x-g329/GHSA-mf8v-4v5x-g329.json @@ -7,12 +7,8 @@ "CVE-2023-52680" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: scarlett2: Add missing error checks to *_ctl_get()\n\nThe *_ctl_get() functions which call scarlett2_update_*() were not\nchecking the return value. Fix to check the return value and pass to\nthe caller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-prp3-hg6j-pj6f/GHSA-prp3-hg6j-pj6f.json b/advisories/unreviewed/2024/05/GHSA-prp3-hg6j-pj6f/GHSA-prp3-hg6j-pj6f.json index 17cae7b78c8..ac259c81b89 100644 --- a/advisories/unreviewed/2024/05/GHSA-prp3-hg6j-pj6f/GHSA-prp3-hg6j-pj6f.json +++ b/advisories/unreviewed/2024/05/GHSA-prp3-hg6j-pj6f/GHSA-prp3-hg6j-pj6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pvp3-22v7-6xcv/GHSA-pvp3-22v7-6xcv.json b/advisories/unreviewed/2024/05/GHSA-pvp3-22v7-6xcv/GHSA-pvp3-22v7-6xcv.json index 56a124e14f7..8f3a04b56d3 100644 --- a/advisories/unreviewed/2024/05/GHSA-pvp3-22v7-6xcv/GHSA-pvp3-22v7-6xcv.json +++ b/advisories/unreviewed/2024/05/GHSA-pvp3-22v7-6xcv/GHSA-pvp3-22v7-6xcv.json @@ -7,12 +7,8 @@ "CVE-2023-52681" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefivarfs: Free s_fs_info on unmount\n\nNow that we allocate a s_fs_info struct on fs context creation, we\nshould ensure that we free it again when the superblock goes away.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qjp9-7h46-6fpj/GHSA-qjp9-7h46-6fpj.json b/advisories/unreviewed/2024/05/GHSA-qjp9-7h46-6fpj/GHSA-qjp9-7h46-6fpj.json index bafc98743be..cd2eb2b8a54 100644 --- a/advisories/unreviewed/2024/05/GHSA-qjp9-7h46-6fpj/GHSA-qjp9-7h46-6fpj.json +++ b/advisories/unreviewed/2024/05/GHSA-qjp9-7h46-6fpj/GHSA-qjp9-7h46-6fpj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qx57-q6j5-g6mg/GHSA-qx57-q6j5-g6mg.json b/advisories/unreviewed/2024/05/GHSA-qx57-q6j5-g6mg/GHSA-qx57-q6j5-g6mg.json index 94e879f8cd8..5e1d4958725 100644 --- a/advisories/unreviewed/2024/05/GHSA-qx57-q6j5-g6mg/GHSA-qx57-q6j5-g6mg.json +++ b/advisories/unreviewed/2024/05/GHSA-qx57-q6j5-g6mg/GHSA-qx57-q6j5-g6mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r4wq-hmj7-qrcp/GHSA-r4wq-hmj7-qrcp.json b/advisories/unreviewed/2024/05/GHSA-r4wq-hmj7-qrcp/GHSA-r4wq-hmj7-qrcp.json index 54e014d3543..1012ca37166 100644 --- a/advisories/unreviewed/2024/05/GHSA-r4wq-hmj7-qrcp/GHSA-r4wq-hmj7-qrcp.json +++ b/advisories/unreviewed/2024/05/GHSA-r4wq-hmj7-qrcp/GHSA-r4wq-hmj7-qrcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-r5rh-f6h6-v872/GHSA-r5rh-f6h6-v872.json b/advisories/unreviewed/2024/05/GHSA-r5rh-f6h6-v872/GHSA-r5rh-f6h6-v872.json index a44ee38cfcf..fae439d7519 100644 --- a/advisories/unreviewed/2024/05/GHSA-r5rh-f6h6-v872/GHSA-r5rh-f6h6-v872.json +++ b/advisories/unreviewed/2024/05/GHSA-r5rh-f6h6-v872/GHSA-r5rh-f6h6-v872.json @@ -7,12 +7,8 @@ "CVE-2024-35817" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag\n\nOtherwise after the GTT bo is released, the GTT and gart space is freed\nbut amdgpu_ttm_backend_unbind will not clear the gart page table entry\nand leave valid mapping entry pointing to the stale system page. Then\nif GPU access the gart address mistakely, it will read undefined value\ninstead page fault, harder to debug and reproduce the real issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rf65-fc2p-2gjv/GHSA-rf65-fc2p-2gjv.json b/advisories/unreviewed/2024/05/GHSA-rf65-fc2p-2gjv/GHSA-rf65-fc2p-2gjv.json index 2bda3f439c6..546e79d800b 100644 --- a/advisories/unreviewed/2024/05/GHSA-rf65-fc2p-2gjv/GHSA-rf65-fc2p-2gjv.json +++ b/advisories/unreviewed/2024/05/GHSA-rf65-fc2p-2gjv/GHSA-rf65-fc2p-2gjv.json @@ -7,12 +7,8 @@ "CVE-2024-34997" ], "details": "joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json b/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json index 96970a31fab..c33bab909ed 100644 --- a/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json +++ b/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v8fm-4cx6-7vh8/GHSA-v8fm-4cx6-7vh8.json b/advisories/unreviewed/2024/05/GHSA-v8fm-4cx6-7vh8/GHSA-v8fm-4cx6-7vh8.json index fb1d42557b6..8cd844fa6e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8fm-4cx6-7vh8/GHSA-v8fm-4cx6-7vh8.json +++ b/advisories/unreviewed/2024/05/GHSA-v8fm-4cx6-7vh8/GHSA-v8fm-4cx6-7vh8.json @@ -7,12 +7,8 @@ "CVE-2024-35838" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix potential sta-link leak\n\nWhen a station is allocated, links are added but not\nset to valid yet (e.g. during connection to an AP MLD),\nwe might remove the station without ever marking links\nvalid, and leak them. Fix that.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vmrr-46g9-357m/GHSA-vmrr-46g9-357m.json b/advisories/unreviewed/2024/05/GHSA-vmrr-46g9-357m/GHSA-vmrr-46g9-357m.json index aec02059db5..07a40b53c9b 100644 --- a/advisories/unreviewed/2024/05/GHSA-vmrr-46g9-357m/GHSA-vmrr-46g9-357m.json +++ b/advisories/unreviewed/2024/05/GHSA-vmrr-46g9-357m/GHSA-vmrr-46g9-357m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json b/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json index 91219fd7e40..5a10209893c 100644 --- a/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json +++ b/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json @@ -7,12 +7,8 @@ "CVE-2023-52662" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node\n\nWhen ida_alloc_max fails, resources allocated before should be freed,\nincluding *res allocated by kmalloc and ttm_resource_init.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w77r-vc72-rx49/GHSA-w77r-vc72-rx49.json b/advisories/unreviewed/2024/05/GHSA-w77r-vc72-rx49/GHSA-w77r-vc72-rx49.json index 890c7323565..b48af6aa14e 100644 --- a/advisories/unreviewed/2024/05/GHSA-w77r-vc72-rx49/GHSA-w77r-vc72-rx49.json +++ b/advisories/unreviewed/2024/05/GHSA-w77r-vc72-rx49/GHSA-w77r-vc72-rx49.json @@ -7,12 +7,8 @@ "CVE-2024-35803" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/efistub: Call mixed mode boot services on the firmware's stack\n\nNormally, the EFI stub calls into the EFI boot services using the stack\nthat was live when the stub was entered. According to the UEFI spec,\nthis stack needs to be at least 128k in size - this might seem large but\nall asynchronous processing and event handling in EFI runs from the same\nstack and so quite a lot of space may be used in practice.\n\nIn mixed mode, the situation is a bit different: the bootloader calls\nthe 32-bit EFI stub entry point, which calls the decompressor's 32-bit\nentry point, where the boot stack is set up, using a fixed allocation\nof 16k. This stack is still in use when the EFI stub is started in\n64-bit mode, and so all calls back into the EFI firmware will be using\nthe decompressor's limited boot stack.\n\nDue to the placement of the boot stack right after the boot heap, any\nstack overruns have gone unnoticed. However, commit\n\n 5c4feadb0011983b (\"x86/decompressor: Move global symbol references to C code\")\n\nmoved the definition of the boot heap into C code, and now the boot\nstack is placed right at the base of BSS, where any overruns will\ncorrupt the end of the .data section.\n\nWhile it would be possible to work around this by increasing the size of\nthe boot stack, doing so would affect all x86 systems, and mixed mode\nsystems are a tiny (and shrinking) fraction of the x86 installed base.\n\nSo instead, record the firmware stack pointer value when entering from\nthe 32-bit firmware, and switch to this stack every time a EFI boot\nservice call is made.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w9qv-8mcj-wh8f/GHSA-w9qv-8mcj-wh8f.json b/advisories/unreviewed/2024/05/GHSA-w9qv-8mcj-wh8f/GHSA-w9qv-8mcj-wh8f.json index 8bf70f2bed3..aa4637acf4b 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9qv-8mcj-wh8f/GHSA-w9qv-8mcj-wh8f.json +++ b/advisories/unreviewed/2024/05/GHSA-w9qv-8mcj-wh8f/GHSA-w9qv-8mcj-wh8f.json @@ -7,12 +7,8 @@ "CVE-2024-35798" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race in read_extent_buffer_pages()\n\nThere are reports from tree-checker that detects corrupted nodes,\nwithout any obvious pattern so possibly an overwrite in memory.\nAfter some debugging it turns out there's a race when reading an extent\nbuffer the uptodate status can be missed.\n\nTo prevent concurrent reads for the same extent buffer,\nread_extent_buffer_pages() performs these checks:\n\n /* (1) */\n if (test_bit(EXTENT_BUFFER_UPTODATE, &eb->bflags))\n return 0;\n\n /* (2) */\n if (test_and_set_bit(EXTENT_BUFFER_READING, &eb->bflags))\n goto done;\n\nAt this point, it seems safe to start the actual read operation. Once\nthat completes, end_bbio_meta_read() does\n\n /* (3) */\n set_extent_buffer_uptodate(eb);\n\n /* (4) */\n clear_bit(EXTENT_BUFFER_READING, &eb->bflags);\n\nNormally, this is enough to ensure only one read happens, and all other\ncallers wait for it to finish before returning. Unfortunately, there is\na racey interleaving:\n\n Thread A | Thread B | Thread C\n ---------+----------+---------\n (1) | |\n | (1) |\n (2) | |\n (3) | |\n (4) | |\n | (2) |\n | | (1)\n\nWhen this happens, thread B kicks of an unnecessary read. Worse, thread\nC will see UPTODATE set and return immediately, while the read from\nthread B is still in progress. This race could result in tree-checker\nerrors like this as the extent buffer is concurrently modified:\n\n BTRFS critical (device dm-0): corrupted node, root=256\n block=8550954455682405139 owner mismatch, have 11858205567642294356\n expect [256, 18446744073709551360]\n\nFix it by testing UPTODATE again after setting the READING bit, and if\nit's been set, skip the unnecessary read.\n\n[ minor update of changelog ]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x25x-hhpj-pjqp/GHSA-x25x-hhpj-pjqp.json b/advisories/unreviewed/2024/05/GHSA-x25x-hhpj-pjqp/GHSA-x25x-hhpj-pjqp.json index 38d52753e9d..5af9f968627 100644 --- a/advisories/unreviewed/2024/05/GHSA-x25x-hhpj-pjqp/GHSA-x25x-hhpj-pjqp.json +++ b/advisories/unreviewed/2024/05/GHSA-x25x-hhpj-pjqp/GHSA-x25x-hhpj-pjqp.json @@ -7,12 +7,8 @@ "CVE-2023-52676" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard stack limits against 32bit overflow\n\nThis patch promotes the arithmetic around checking stack bounds to be\ndone in the 64-bit domain, instead of the current 32bit. The arithmetic\nimplies adding together a 64-bit register with a int offset. The\nregister was checked to be below 1<<29 when it was variable, but not\nwhen it was fixed. The offset either comes from an instruction (in which\ncase it is 16 bit), from another register (in which case the caller\nchecked it to be below 1<<29 [1]), or from the size of an argument to a\nkfunc (in which case it can be a u32 [2]). Between the register being\ninconsistently checked to be below 1<<29, and the offset being up to an\nu32, it appears that we were open to overflowing the `int`s which were\ncurrently used for arithmetic.\n\n[1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498\n[2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xmxx-577p-gqgc/GHSA-xmxx-577p-gqgc.json b/advisories/unreviewed/2024/05/GHSA-xmxx-577p-gqgc/GHSA-xmxx-577p-gqgc.json index 71054169b3f..30989f859b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmxx-577p-gqgc/GHSA-xmxx-577p-gqgc.json +++ b/advisories/unreviewed/2024/05/GHSA-xmxx-577p-gqgc/GHSA-xmxx-577p-gqgc.json @@ -7,12 +7,8 @@ "CVE-2023-52689" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: scarlett2: Add missing mutex lock around get meter levels\n\nAs scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex\nshould be locked while accessing it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xrfx-97x9-43cq/GHSA-xrfx-97x9-43cq.json b/advisories/unreviewed/2024/05/GHSA-xrfx-97x9-43cq/GHSA-xrfx-97x9-43cq.json index b440cc139ff..ccdf789649f 100644 --- a/advisories/unreviewed/2024/05/GHSA-xrfx-97x9-43cq/GHSA-xrfx-97x9-43cq.json +++ b/advisories/unreviewed/2024/05/GHSA-xrfx-97x9-43cq/GHSA-xrfx-97x9-43cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-xwgm-hj5f-p996/GHSA-xwgm-hj5f-p996.json b/advisories/unreviewed/2024/05/GHSA-xwgm-hj5f-p996/GHSA-xwgm-hj5f-p996.json index e3377002802..cd79d7f55cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-xwgm-hj5f-p996/GHSA-xwgm-hj5f-p996.json +++ b/advisories/unreviewed/2024/05/GHSA-xwgm-hj5f-p996/GHSA-xwgm-hj5f-p996.json @@ -7,12 +7,8 @@ "CVE-2024-35816" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: ohci: prevent leak of left-over IRQ on unbind\n\nCommit 5a95f1ded28691e6 (\"firewire: ohci: use devres for requested IRQ\")\nalso removed the call to free_irq() in pci_remove(), leading to a\nleftover irq of devm_request_irq() at pci_disable_msi() in pci_remove()\nwhen unbinding the driver from the device\n\nremove_proc_entry: removing non-empty directory 'irq/136', leaking at\nleast 'firewire_ohci'\nCall Trace:\n ? remove_proc_entry+0x19c/0x1c0\n ? __warn+0x81/0x130\n ? remove_proc_entry+0x19c/0x1c0\n ? report_bug+0x171/0x1a0\n ? console_unlock+0x78/0x120\n ? handle_bug+0x3c/0x80\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? remove_proc_entry+0x19c/0x1c0\n unregister_irq_proc+0xf4/0x120\n free_desc+0x3d/0xe0\n ? kfree+0x29f/0x2f0\n irq_free_descs+0x47/0x70\n msi_domain_free_locked.part.0+0x19d/0x1d0\n msi_domain_free_irqs_all_locked+0x81/0xc0\n pci_free_msi_irqs+0x12/0x40\n pci_disable_msi+0x4c/0x60\n pci_remove+0x9d/0xc0 [firewire_ohci\n 01b483699bebf9cb07a3d69df0aa2bee71db1b26]\n pci_device_remove+0x37/0xa0\n device_release_driver_internal+0x19f/0x200\n unbind_store+0xa1/0xb0\n\nremove irq with devm_free_irq() before pci_disable_msi()\nalso remove it in fail_msi: of pci_probe() as this would lead to\nan identical leak", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xx3r-74m7-rjg4/GHSA-xx3r-74m7-rjg4.json b/advisories/unreviewed/2024/05/GHSA-xx3r-74m7-rjg4/GHSA-xx3r-74m7-rjg4.json index 4063810b90a..3ffc1a9d034 100644 --- a/advisories/unreviewed/2024/05/GHSA-xx3r-74m7-rjg4/GHSA-xx3r-74m7-rjg4.json +++ b/advisories/unreviewed/2024/05/GHSA-xx3r-74m7-rjg4/GHSA-xx3r-74m7-rjg4.json @@ -7,12 +7,8 @@ "CVE-2024-35808" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/dm-raid: don't call md_reap_sync_thread() directly\n\nCurrently md_reap_sync_thread() is called from raid_message() directly\nwithout holding 'reconfig_mutex', this is definitely unsafe because\nmd_reap_sync_thread() can change many fields that is protected by\n'reconfig_mutex'.\n\nHowever, hold 'reconfig_mutex' here is still problematic because this\nwill cause deadlock, for example, commit 130443d60b1b (\"md: refactor\nidle/frozen_sync_thread() to fix deadlock\").\n\nFix this problem by using stop_sync_thread() to unregister sync_thread,\nlike md/raid did.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-236g-v823-mwh3/GHSA-236g-v823-mwh3.json b/advisories/unreviewed/2024/06/GHSA-236g-v823-mwh3/GHSA-236g-v823-mwh3.json index 855017bdebb..3b04bc734ff 100644 --- a/advisories/unreviewed/2024/06/GHSA-236g-v823-mwh3/GHSA-236g-v823-mwh3.json +++ b/advisories/unreviewed/2024/06/GHSA-236g-v823-mwh3/GHSA-236g-v823-mwh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-2g92-xwm3-3x93/GHSA-2g92-xwm3-3x93.json b/advisories/unreviewed/2024/06/GHSA-2g92-xwm3-3x93/GHSA-2g92-xwm3-3x93.json index 84a52178577..f7d9e7d5889 100644 --- a/advisories/unreviewed/2024/06/GHSA-2g92-xwm3-3x93/GHSA-2g92-xwm3-3x93.json +++ b/advisories/unreviewed/2024/06/GHSA-2g92-xwm3-3x93/GHSA-2g92-xwm3-3x93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json b/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json index c0d63e5ee65..d230ac594c1 100644 --- a/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json +++ b/advisories/unreviewed/2024/06/GHSA-3g6v-jwwm-8gj3/GHSA-3g6v-jwwm-8gj3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3p7r-f88q-xv28/GHSA-3p7r-f88q-xv28.json b/advisories/unreviewed/2024/06/GHSA-3p7r-f88q-xv28/GHSA-3p7r-f88q-xv28.json index 8bee3a5e4cd..e2da2b1300c 100644 --- a/advisories/unreviewed/2024/06/GHSA-3p7r-f88q-xv28/GHSA-3p7r-f88q-xv28.json +++ b/advisories/unreviewed/2024/06/GHSA-3p7r-f88q-xv28/GHSA-3p7r-f88q-xv28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3w5m-mfmj-cpcf/GHSA-3w5m-mfmj-cpcf.json b/advisories/unreviewed/2024/06/GHSA-3w5m-mfmj-cpcf/GHSA-3w5m-mfmj-cpcf.json index 7f16ac880b4..4b826803e64 100644 --- a/advisories/unreviewed/2024/06/GHSA-3w5m-mfmj-cpcf/GHSA-3w5m-mfmj-cpcf.json +++ b/advisories/unreviewed/2024/06/GHSA-3w5m-mfmj-cpcf/GHSA-3w5m-mfmj-cpcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-48hw-jvvh-pj8q/GHSA-48hw-jvvh-pj8q.json b/advisories/unreviewed/2024/06/GHSA-48hw-jvvh-pj8q/GHSA-48hw-jvvh-pj8q.json index 349410156ae..f6491f74210 100644 --- a/advisories/unreviewed/2024/06/GHSA-48hw-jvvh-pj8q/GHSA-48hw-jvvh-pj8q.json +++ b/advisories/unreviewed/2024/06/GHSA-48hw-jvvh-pj8q/GHSA-48hw-jvvh-pj8q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json b/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json index d75d0e61616..e4a5511c508 100644 --- a/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json +++ b/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-587h-8hv9-9pgh/GHSA-587h-8hv9-9pgh.json b/advisories/unreviewed/2024/06/GHSA-587h-8hv9-9pgh/GHSA-587h-8hv9-9pgh.json index 7eb0ecd3c49..853e32dd3c4 100644 --- a/advisories/unreviewed/2024/06/GHSA-587h-8hv9-9pgh/GHSA-587h-8hv9-9pgh.json +++ b/advisories/unreviewed/2024/06/GHSA-587h-8hv9-9pgh/GHSA-587h-8hv9-9pgh.json @@ -7,12 +7,8 @@ "CVE-2024-31625" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json b/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json index 3838972a8dc..cf8b9d9b87d 100644 --- a/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json +++ b/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json b/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json index 64af9f68f7b..e0071249f12 100644 --- a/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json +++ b/advisories/unreviewed/2024/06/GHSA-5q48-pjg9-33x2/GHSA-5q48-pjg9-33x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-723x-qp2v-v2fc/GHSA-723x-qp2v-v2fc.json b/advisories/unreviewed/2024/06/GHSA-723x-qp2v-v2fc/GHSA-723x-qp2v-v2fc.json index 57d84a6d917..2379aefa4aa 100644 --- a/advisories/unreviewed/2024/06/GHSA-723x-qp2v-v2fc/GHSA-723x-qp2v-v2fc.json +++ b/advisories/unreviewed/2024/06/GHSA-723x-qp2v-v2fc/GHSA-723x-qp2v-v2fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-765q-773v-w2f8/GHSA-765q-773v-w2f8.json b/advisories/unreviewed/2024/06/GHSA-765q-773v-w2f8/GHSA-765q-773v-w2f8.json index a4ac1e0f21e..97b00898c7e 100644 --- a/advisories/unreviewed/2024/06/GHSA-765q-773v-w2f8/GHSA-765q-773v-w2f8.json +++ b/advisories/unreviewed/2024/06/GHSA-765q-773v-w2f8/GHSA-765q-773v-w2f8.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7chp-4mhh-fxp2/GHSA-7chp-4mhh-fxp2.json b/advisories/unreviewed/2024/06/GHSA-7chp-4mhh-fxp2/GHSA-7chp-4mhh-fxp2.json index 2cd81387a10..602d2f6795b 100644 --- a/advisories/unreviewed/2024/06/GHSA-7chp-4mhh-fxp2/GHSA-7chp-4mhh-fxp2.json +++ b/advisories/unreviewed/2024/06/GHSA-7chp-4mhh-fxp2/GHSA-7chp-4mhh-fxp2.json @@ -7,12 +7,8 @@ "CVE-2024-31628" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-84vh-7gqv-ww85/GHSA-84vh-7gqv-ww85.json b/advisories/unreviewed/2024/06/GHSA-84vh-7gqv-ww85/GHSA-84vh-7gqv-ww85.json index 86942663ddd..ee590c94de3 100644 --- a/advisories/unreviewed/2024/06/GHSA-84vh-7gqv-ww85/GHSA-84vh-7gqv-ww85.json +++ b/advisories/unreviewed/2024/06/GHSA-84vh-7gqv-ww85/GHSA-84vh-7gqv-ww85.json @@ -7,12 +7,8 @@ "CVE-2024-31630" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-8g56-f5px-3gw9/GHSA-8g56-f5px-3gw9.json b/advisories/unreviewed/2024/06/GHSA-8g56-f5px-3gw9/GHSA-8g56-f5px-3gw9.json index 0f8f619086f..de417afa5d0 100644 --- a/advisories/unreviewed/2024/06/GHSA-8g56-f5px-3gw9/GHSA-8g56-f5px-3gw9.json +++ b/advisories/unreviewed/2024/06/GHSA-8g56-f5px-3gw9/GHSA-8g56-f5px-3gw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json b/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json index 89c493ff5e0..976b514f080 100644 --- a/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json +++ b/advisories/unreviewed/2024/06/GHSA-8xpj-rxm7-wgf9/GHSA-8xpj-rxm7-wgf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9p45-vf85-gjxg/GHSA-9p45-vf85-gjxg.json b/advisories/unreviewed/2024/06/GHSA-9p45-vf85-gjxg/GHSA-9p45-vf85-gjxg.json index 8b3967e8810..30b950bf668 100644 --- a/advisories/unreviewed/2024/06/GHSA-9p45-vf85-gjxg/GHSA-9p45-vf85-gjxg.json +++ b/advisories/unreviewed/2024/06/GHSA-9p45-vf85-gjxg/GHSA-9p45-vf85-gjxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json b/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json index 301018232af..a475bf21b70 100644 --- a/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json +++ b/advisories/unreviewed/2024/06/GHSA-9qw6-wc53-f6x9/GHSA-9qw6-wc53-f6x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9v48-g4gh-2566/GHSA-9v48-g4gh-2566.json b/advisories/unreviewed/2024/06/GHSA-9v48-g4gh-2566/GHSA-9v48-g4gh-2566.json index 6eb93be67b3..5bfd6919609 100644 --- a/advisories/unreviewed/2024/06/GHSA-9v48-g4gh-2566/GHSA-9v48-g4gh-2566.json +++ b/advisories/unreviewed/2024/06/GHSA-9v48-g4gh-2566/GHSA-9v48-g4gh-2566.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fmgc-qjr6-w2jp/GHSA-fmgc-qjr6-w2jp.json b/advisories/unreviewed/2024/06/GHSA-fmgc-qjr6-w2jp/GHSA-fmgc-qjr6-w2jp.json index c5d62ec8533..132de6c8de9 100644 --- a/advisories/unreviewed/2024/06/GHSA-fmgc-qjr6-w2jp/GHSA-fmgc-qjr6-w2jp.json +++ b/advisories/unreviewed/2024/06/GHSA-fmgc-qjr6-w2jp/GHSA-fmgc-qjr6-w2jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h4m2-x7c7-9j2j/GHSA-h4m2-x7c7-9j2j.json b/advisories/unreviewed/2024/06/GHSA-h4m2-x7c7-9j2j/GHSA-h4m2-x7c7-9j2j.json index bd6dbbc70e3..0bc953063e3 100644 --- a/advisories/unreviewed/2024/06/GHSA-h4m2-x7c7-9j2j/GHSA-h4m2-x7c7-9j2j.json +++ b/advisories/unreviewed/2024/06/GHSA-h4m2-x7c7-9j2j/GHSA-h4m2-x7c7-9j2j.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-jv6q-m92f-5fmr/GHSA-jv6q-m92f-5fmr.json b/advisories/unreviewed/2024/06/GHSA-jv6q-m92f-5fmr/GHSA-jv6q-m92f-5fmr.json index b2d1167df17..47c37613d67 100644 --- a/advisories/unreviewed/2024/06/GHSA-jv6q-m92f-5fmr/GHSA-jv6q-m92f-5fmr.json +++ b/advisories/unreviewed/2024/06/GHSA-jv6q-m92f-5fmr/GHSA-jv6q-m92f-5fmr.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m9g4-v75g-m92j/GHSA-m9g4-v75g-m92j.json b/advisories/unreviewed/2024/06/GHSA-m9g4-v75g-m92j/GHSA-m9g4-v75g-m92j.json index 7ede05363b8..775d1a706a3 100644 --- a/advisories/unreviewed/2024/06/GHSA-m9g4-v75g-m92j/GHSA-m9g4-v75g-m92j.json +++ b/advisories/unreviewed/2024/06/GHSA-m9g4-v75g-m92j/GHSA-m9g4-v75g-m92j.json @@ -7,12 +7,8 @@ "CVE-2024-31629" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-qpv7-56jv-92v7/GHSA-qpv7-56jv-92v7.json b/advisories/unreviewed/2024/06/GHSA-qpv7-56jv-92v7/GHSA-qpv7-56jv-92v7.json index d6578a1d61e..d9d5c791dee 100644 --- a/advisories/unreviewed/2024/06/GHSA-qpv7-56jv-92v7/GHSA-qpv7-56jv-92v7.json +++ b/advisories/unreviewed/2024/06/GHSA-qpv7-56jv-92v7/GHSA-qpv7-56jv-92v7.json @@ -7,12 +7,8 @@ "CVE-2024-31623" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-qx3m-6x5p-6m3p/GHSA-qx3m-6x5p-6m3p.json b/advisories/unreviewed/2024/06/GHSA-qx3m-6x5p-6m3p/GHSA-qx3m-6x5p-6m3p.json index 8fabf4a1b69..8d7e051ec8b 100644 --- a/advisories/unreviewed/2024/06/GHSA-qx3m-6x5p-6m3p/GHSA-qx3m-6x5p-6m3p.json +++ b/advisories/unreviewed/2024/06/GHSA-qx3m-6x5p-6m3p/GHSA-qx3m-6x5p-6m3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r4gp-r2fv-c7gg/GHSA-r4gp-r2fv-c7gg.json b/advisories/unreviewed/2024/06/GHSA-r4gp-r2fv-c7gg/GHSA-r4gp-r2fv-c7gg.json index efd19fd0672..6c2db275de3 100644 --- a/advisories/unreviewed/2024/06/GHSA-r4gp-r2fv-c7gg/GHSA-r4gp-r2fv-c7gg.json +++ b/advisories/unreviewed/2024/06/GHSA-r4gp-r2fv-c7gg/GHSA-r4gp-r2fv-c7gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-r4hv-f4m8-f2vr/GHSA-r4hv-f4m8-f2vr.json b/advisories/unreviewed/2024/06/GHSA-r4hv-f4m8-f2vr/GHSA-r4hv-f4m8-f2vr.json index 60e3768d618..4284a6166f9 100644 --- a/advisories/unreviewed/2024/06/GHSA-r4hv-f4m8-f2vr/GHSA-r4hv-f4m8-f2vr.json +++ b/advisories/unreviewed/2024/06/GHSA-r4hv-f4m8-f2vr/GHSA-r4hv-f4m8-f2vr.json @@ -7,12 +7,8 @@ "CVE-2024-31627" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-r74v-xg7r-p9h2/GHSA-r74v-xg7r-p9h2.json b/advisories/unreviewed/2024/06/GHSA-r74v-xg7r-p9h2/GHSA-r74v-xg7r-p9h2.json index 56c456bc922..fb43bc49830 100644 --- a/advisories/unreviewed/2024/06/GHSA-r74v-xg7r-p9h2/GHSA-r74v-xg7r-p9h2.json +++ b/advisories/unreviewed/2024/06/GHSA-r74v-xg7r-p9h2/GHSA-r74v-xg7r-p9h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rf2c-hv95-gmj5/GHSA-rf2c-hv95-gmj5.json b/advisories/unreviewed/2024/06/GHSA-rf2c-hv95-gmj5/GHSA-rf2c-hv95-gmj5.json index dcc38933770..084f96b1200 100644 --- a/advisories/unreviewed/2024/06/GHSA-rf2c-hv95-gmj5/GHSA-rf2c-hv95-gmj5.json +++ b/advisories/unreviewed/2024/06/GHSA-rf2c-hv95-gmj5/GHSA-rf2c-hv95-gmj5.json @@ -7,12 +7,8 @@ "CVE-2024-31631" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-v43m-6g73-cw85/GHSA-v43m-6g73-cw85.json b/advisories/unreviewed/2024/06/GHSA-v43m-6g73-cw85/GHSA-v43m-6g73-cw85.json index 2b3ca376492..2ceedeb7f1f 100644 --- a/advisories/unreviewed/2024/06/GHSA-v43m-6g73-cw85/GHSA-v43m-6g73-cw85.json +++ b/advisories/unreviewed/2024/06/GHSA-v43m-6g73-cw85/GHSA-v43m-6g73-cw85.json @@ -7,12 +7,8 @@ "CVE-2024-31624" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-wxf6-9g76-hmx6/GHSA-wxf6-9g76-hmx6.json b/advisories/unreviewed/2024/06/GHSA-wxf6-9g76-hmx6/GHSA-wxf6-9g76-hmx6.json index 20b0e912126..876910e9f86 100644 --- a/advisories/unreviewed/2024/06/GHSA-wxf6-9g76-hmx6/GHSA-wxf6-9g76-hmx6.json +++ b/advisories/unreviewed/2024/06/GHSA-wxf6-9g76-hmx6/GHSA-wxf6-9g76-hmx6.json @@ -7,12 +7,8 @@ "CVE-2024-31626" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-xrg8-rx83-pg44/GHSA-xrg8-rx83-pg44.json b/advisories/unreviewed/2024/06/GHSA-xrg8-rx83-pg44/GHSA-xrg8-rx83-pg44.json index 23055a03816..02284529c67 100644 --- a/advisories/unreviewed/2024/06/GHSA-xrg8-rx83-pg44/GHSA-xrg8-rx83-pg44.json +++ b/advisories/unreviewed/2024/06/GHSA-xrg8-rx83-pg44/GHSA-xrg8-rx83-pg44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json b/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json index 033a4f6c819..a69cfc020db 100644 --- a/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json +++ b/advisories/unreviewed/2024/06/GHSA-xw37-xfrp-pmwc/GHSA-xw37-xfrp-pmwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2963-qpfw-w3r2/GHSA-2963-qpfw-w3r2.json b/advisories/unreviewed/2024/07/GHSA-2963-qpfw-w3r2/GHSA-2963-qpfw-w3r2.json index 0d740054b90..0787c7056c0 100644 --- a/advisories/unreviewed/2024/07/GHSA-2963-qpfw-w3r2/GHSA-2963-qpfw-w3r2.json +++ b/advisories/unreviewed/2024/07/GHSA-2963-qpfw-w3r2/GHSA-2963-qpfw-w3r2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json b/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json index 1f269fe4c44..9655a560cfa 100644 --- a/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json +++ b/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json b/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json index 9cfd73a34c7..f3dc66239c1 100644 --- a/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json +++ b/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3g8x-wqfp-q876/GHSA-3g8x-wqfp-q876.json b/advisories/unreviewed/2024/07/GHSA-3g8x-wqfp-q876/GHSA-3g8x-wqfp-q876.json index f86b927cd1c..392b77539dd 100644 --- a/advisories/unreviewed/2024/07/GHSA-3g8x-wqfp-q876/GHSA-3g8x-wqfp-q876.json +++ b/advisories/unreviewed/2024/07/GHSA-3g8x-wqfp-q876/GHSA-3g8x-wqfp-q876.json @@ -7,12 +7,8 @@ "CVE-2024-3596" ], "details": "RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json b/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json index b411037bd9f..b6fad5865a6 100644 --- a/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json +++ b/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json b/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json index 128d4962161..0da9053a774 100644 --- a/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json +++ b/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json b/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json index 4b6edc453a2..0bac0dbaf61 100644 --- a/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json +++ b/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-6573-9ww9-37v2/GHSA-6573-9ww9-37v2.json b/advisories/unreviewed/2024/07/GHSA-6573-9ww9-37v2/GHSA-6573-9ww9-37v2.json index 0c2d6bfda32..f2c6159bf1c 100644 --- a/advisories/unreviewed/2024/07/GHSA-6573-9ww9-37v2/GHSA-6573-9ww9-37v2.json +++ b/advisories/unreviewed/2024/07/GHSA-6573-9ww9-37v2/GHSA-6573-9ww9-37v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json b/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json index 4eecdc10795..dec2a80241e 100644 --- a/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json +++ b/advisories/unreviewed/2024/07/GHSA-659h-c7mc-5hrw/GHSA-659h-c7mc-5hrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json b/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json index dcab17c3c7d..b4618fdabd0 100644 --- a/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json +++ b/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json b/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json index 58ad4396e18..fc701326389 100644 --- a/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json +++ b/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-6hr2-22jp-cfqq/GHSA-6hr2-22jp-cfqq.json b/advisories/unreviewed/2024/07/GHSA-6hr2-22jp-cfqq/GHSA-6hr2-22jp-cfqq.json index 21f4c0dae83..f3e4dd73d95 100644 --- a/advisories/unreviewed/2024/07/GHSA-6hr2-22jp-cfqq/GHSA-6hr2-22jp-cfqq.json +++ b/advisories/unreviewed/2024/07/GHSA-6hr2-22jp-cfqq/GHSA-6hr2-22jp-cfqq.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json b/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json index 9ed4046700c..24d5ea6dee7 100644 --- a/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json +++ b/advisories/unreviewed/2024/07/GHSA-6mjp-g2rf-hh5w/GHSA-6mjp-g2rf-hh5w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-72w8-4vgg-vh67/GHSA-72w8-4vgg-vh67.json b/advisories/unreviewed/2024/07/GHSA-72w8-4vgg-vh67/GHSA-72w8-4vgg-vh67.json index 4c3e5ca9417..3ee2aff3898 100644 --- a/advisories/unreviewed/2024/07/GHSA-72w8-4vgg-vh67/GHSA-72w8-4vgg-vh67.json +++ b/advisories/unreviewed/2024/07/GHSA-72w8-4vgg-vh67/GHSA-72w8-4vgg-vh67.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json b/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json index 6397080aebe..3ff2445ad77 100644 --- a/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json +++ b/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json b/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json index 1be9bbc16f1..328b916194b 100644 --- a/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json +++ b/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7w48-pvwh-5mfm/GHSA-7w48-pvwh-5mfm.json b/advisories/unreviewed/2024/07/GHSA-7w48-pvwh-5mfm/GHSA-7w48-pvwh-5mfm.json index ccaac58616c..7bdc69d4d55 100644 --- a/advisories/unreviewed/2024/07/GHSA-7w48-pvwh-5mfm/GHSA-7w48-pvwh-5mfm.json +++ b/advisories/unreviewed/2024/07/GHSA-7w48-pvwh-5mfm/GHSA-7w48-pvwh-5mfm.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json b/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json index f591cde0e26..18874334fea 100644 --- a/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json +++ b/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json b/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json index 0506cd72df1..eb732d61483 100644 --- a/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json +++ b/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json b/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json index a6375d34867..ce1a86ebe73 100644 --- a/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json +++ b/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json b/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json index 4cca4f50f08..989c5c2a01e 100644 --- a/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json +++ b/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json b/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json index f1465f5a29e..a7c18648d26 100644 --- a/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json +++ b/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json b/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json index 3f433dc5836..0dc91290c0e 100644 --- a/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json +++ b/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json b/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json index 7b13853abdd..0203cf92ace 100644 --- a/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json +++ b/advisories/unreviewed/2024/07/GHSA-c2jh-qjfq-m6h4/GHSA-c2jh-qjfq-m6h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-c4r6-f85c-jjjm/GHSA-c4r6-f85c-jjjm.json b/advisories/unreviewed/2024/07/GHSA-c4r6-f85c-jjjm/GHSA-c4r6-f85c-jjjm.json index 85071d84423..d8e6b5e936b 100644 --- a/advisories/unreviewed/2024/07/GHSA-c4r6-f85c-jjjm/GHSA-c4r6-f85c-jjjm.json +++ b/advisories/unreviewed/2024/07/GHSA-c4r6-f85c-jjjm/GHSA-c4r6-f85c-jjjm.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-c77h-m7f7-v4v8/GHSA-c77h-m7f7-v4v8.json b/advisories/unreviewed/2024/07/GHSA-c77h-m7f7-v4v8/GHSA-c77h-m7f7-v4v8.json index 6530bfcbfe1..b132135b048 100644 --- a/advisories/unreviewed/2024/07/GHSA-c77h-m7f7-v4v8/GHSA-c77h-m7f7-v4v8.json +++ b/advisories/unreviewed/2024/07/GHSA-c77h-m7f7-v4v8/GHSA-c77h-m7f7-v4v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json b/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json index 29b0b029389..fa5eaa7b015 100644 --- a/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json +++ b/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json b/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json index db82f4f449c..e678d478068 100644 --- a/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json +++ b/advisories/unreviewed/2024/07/GHSA-chhh-4xrf-42pg/GHSA-chhh-4xrf-42pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json b/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json index bbd579397af..08b2bf745bd 100644 --- a/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json +++ b/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json b/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json index 9c211b13a91..888fcd9a283 100644 --- a/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json +++ b/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json b/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json index 83360913b24..fe98fcb41e2 100644 --- a/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json +++ b/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json b/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json index 3344af2f3c7..2c8669f950a 100644 --- a/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json +++ b/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gg23-w2rg-qj4q/GHSA-gg23-w2rg-qj4q.json b/advisories/unreviewed/2024/07/GHSA-gg23-w2rg-qj4q/GHSA-gg23-w2rg-qj4q.json index 5ebd96d1eda..b3633077ae6 100644 --- a/advisories/unreviewed/2024/07/GHSA-gg23-w2rg-qj4q/GHSA-gg23-w2rg-qj4q.json +++ b/advisories/unreviewed/2024/07/GHSA-gg23-w2rg-qj4q/GHSA-gg23-w2rg-qj4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json b/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json index 5c7eb2cd84a..0012b43415d 100644 --- a/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json +++ b/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json b/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json index 8484d1afc4e..ef573fa929c 100644 --- a/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json +++ b/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-hvqc-vj9x-r2qv/GHSA-hvqc-vj9x-r2qv.json b/advisories/unreviewed/2024/07/GHSA-hvqc-vj9x-r2qv/GHSA-hvqc-vj9x-r2qv.json index bc97c2a2299..dce9eb42d93 100644 --- a/advisories/unreviewed/2024/07/GHSA-hvqc-vj9x-r2qv/GHSA-hvqc-vj9x-r2qv.json +++ b/advisories/unreviewed/2024/07/GHSA-hvqc-vj9x-r2qv/GHSA-hvqc-vj9x-r2qv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-j69h-px6j-9v8q/GHSA-j69h-px6j-9v8q.json b/advisories/unreviewed/2024/07/GHSA-j69h-px6j-9v8q/GHSA-j69h-px6j-9v8q.json index 4b56089eae9..8f645be593f 100644 --- a/advisories/unreviewed/2024/07/GHSA-j69h-px6j-9v8q/GHSA-j69h-px6j-9v8q.json +++ b/advisories/unreviewed/2024/07/GHSA-j69h-px6j-9v8q/GHSA-j69h-px6j-9v8q.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json b/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json index a11fd25d262..cd9e2b351e0 100644 --- a/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json +++ b/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json b/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json index 94d07e4b491..1a2584f9f10 100644 --- a/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json +++ b/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-jrq9-x3g5-75ph/GHSA-jrq9-x3g5-75ph.json b/advisories/unreviewed/2024/07/GHSA-jrq9-x3g5-75ph/GHSA-jrq9-x3g5-75ph.json index 987cca867d9..29e3d383256 100644 --- a/advisories/unreviewed/2024/07/GHSA-jrq9-x3g5-75ph/GHSA-jrq9-x3g5-75ph.json +++ b/advisories/unreviewed/2024/07/GHSA-jrq9-x3g5-75ph/GHSA-jrq9-x3g5-75ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json b/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json index 2a385f34233..eb5bf4f01c8 100644 --- a/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json +++ b/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json b/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json index d20897fe3a1..a676e61d3f4 100644 --- a/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json +++ b/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json b/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json index 4bcd7918b4f..138dc165639 100644 --- a/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json +++ b/advisories/unreviewed/2024/07/GHSA-p7hh-r4jx-72fm/GHSA-p7hh-r4jx-72fm.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json b/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json index 85f2112d589..430627d1dba 100644 --- a/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json +++ b/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-pw8x-jq9m-hmc9/GHSA-pw8x-jq9m-hmc9.json b/advisories/unreviewed/2024/07/GHSA-pw8x-jq9m-hmc9/GHSA-pw8x-jq9m-hmc9.json index 8af6a08c31a..e70d33471a8 100644 --- a/advisories/unreviewed/2024/07/GHSA-pw8x-jq9m-hmc9/GHSA-pw8x-jq9m-hmc9.json +++ b/advisories/unreviewed/2024/07/GHSA-pw8x-jq9m-hmc9/GHSA-pw8x-jq9m-hmc9.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json b/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json index 0e5c8263984..3056dea0bf5 100644 --- a/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json +++ b/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-r5w6-vhvv-2q6g/GHSA-r5w6-vhvv-2q6g.json b/advisories/unreviewed/2024/07/GHSA-r5w6-vhvv-2q6g/GHSA-r5w6-vhvv-2q6g.json index b3ba682e850..af2d73ca1c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-r5w6-vhvv-2q6g/GHSA-r5w6-vhvv-2q6g.json +++ b/advisories/unreviewed/2024/07/GHSA-r5w6-vhvv-2q6g/GHSA-r5w6-vhvv-2q6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json b/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json index ec9982240fd..626c460383c 100644 --- a/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json +++ b/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json b/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json index 3d97d851a49..9038117c0c2 100644 --- a/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json +++ b/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w8j4-89h3-r854/GHSA-w8j4-89h3-r854.json b/advisories/unreviewed/2024/07/GHSA-w8j4-89h3-r854/GHSA-w8j4-89h3-r854.json index 667985cea0d..77304106911 100644 --- a/advisories/unreviewed/2024/07/GHSA-w8j4-89h3-r854/GHSA-w8j4-89h3-r854.json +++ b/advisories/unreviewed/2024/07/GHSA-w8j4-89h3-r854/GHSA-w8j4-89h3-r854.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-whg9-chpc-qg83/GHSA-whg9-chpc-qg83.json b/advisories/unreviewed/2024/07/GHSA-whg9-chpc-qg83/GHSA-whg9-chpc-qg83.json index 64c6f066cc6..fca905fd6b0 100644 --- a/advisories/unreviewed/2024/07/GHSA-whg9-chpc-qg83/GHSA-whg9-chpc-qg83.json +++ b/advisories/unreviewed/2024/07/GHSA-whg9-chpc-qg83/GHSA-whg9-chpc-qg83.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json b/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json index 55ab4cdc2b1..05f6be0b9a2 100644 --- a/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json +++ b/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json b/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json index bdded9a4c03..955ce972414 100644 --- a/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json +++ b/advisories/unreviewed/2024/07/GHSA-x66j-2fj9-7c64/GHSA-x66j-2fj9-7c64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json b/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json index ce17c42bf87..119b63732d4 100644 --- a/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json +++ b/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json index ad70c5450cb..593bd30c572 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json b/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json index 66f9194749d..bb0652d3168 100644 --- a/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json +++ b/advisories/unreviewed/2024/10/GHSA-74x7-28x6-q6gc/GHSA-74x7-28x6-q6gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json b/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json index 24e15524388..b284cdae9d9 100644 --- a/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json +++ b/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-46qx-h248-6h75/GHSA-46qx-h248-6h75.json b/advisories/unreviewed/2024/11/GHSA-46qx-h248-6h75/GHSA-46qx-h248-6h75.json index 9be4c14f513..d4caad2b873 100644 --- a/advisories/unreviewed/2024/11/GHSA-46qx-h248-6h75/GHSA-46qx-h248-6h75.json +++ b/advisories/unreviewed/2024/11/GHSA-46qx-h248-6h75/GHSA-46qx-h248-6h75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json b/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json index cbccf6e583c..cf2f4377fff 100644 --- a/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json +++ b/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json @@ -7,12 +7,8 @@ "CVE-2024-53095" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free of network namespace.\n\nRecently, we got a customer report that CIFS triggers oops while\nreconnecting to a server. [0]\n\nThe workload runs on Kubernetes, and some pods mount CIFS servers\nin non-root network namespaces. The problem rarely happened, but\nit was always while the pod was dying.\n\nThe root cause is wrong reference counting for network namespace.\n\nCIFS uses kernel sockets, which do not hold refcnt of the netns that\nthe socket belongs to. That means CIFS must ensure the socket is\nalways freed before its netns; otherwise, use-after-free happens.\n\nThe repro steps are roughly:\n\n 1. mount CIFS in a non-root netns\n 2. drop packets from the netns\n 3. destroy the netns\n 4. unmount CIFS\n\nWe can reproduce the issue quickly with the script [1] below and see\nthe splat [2] if CONFIG_NET_NS_REFCNT_TRACKER is enabled.\n\nWhen the socket is TCP, it is hard to guarantee the netns lifetime\nwithout holding refcnt due to async timers.\n\nLet's hold netns refcnt for each socket as done for SMC in commit\n9744d2bf1976 (\"smc: Fix use-after-free in tcp_write_timer_handler().\").\n\nNote that we need to move put_net() from cifs_put_tcp_session() to\nclean_demultiplex_info(); otherwise, __sock_create() still could touch a\nfreed netns while cifsd tries to reconnect from cifs_demultiplex_thread().\n\nAlso, maybe_get_net() cannot be put just before __sock_create() because\nthe code is not under RCU and there is a small chance that the same\naddress happened to be reallocated to another netns.\n\n[0]:\nCIFS: VFS: \\\\XXXXXXXXXXX has not responded in 15 seconds. Reconnecting...\nCIFS: Serverclose failed 4 times, giving up\nUnable to handle kernel paging request at virtual address 14de99e461f84a07\nMem abort info:\n ESR = 0x0000000096000004\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\nData abort info:\n ISV = 0, ISS = 0x00000004\n CM = 0, WnR = 0\n[14de99e461f84a07] address between user and kernel address ranges\nInternal error: Oops: 0000000096000004 [#1] SMP\nModules linked in: cls_bpf sch_ingress nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver tcp_diag inet_diag veth xt_state xt_connmark nf_conntrack_netlink xt_nat xt_statistic xt_MASQUERADE xt_mark xt_addrtype ipt_REJECT nf_reject_ipv4 nft_chain_nat nf_nat xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xt_comment nft_compat nf_tables nfnetlink overlay nls_ascii nls_cp437 sunrpc vfat fat aes_ce_blk aes_ce_cipher ghash_ce sm4_ce_cipher sm4 sm3_ce sm3 sha3_ce sha512_ce sha512_arm64 sha1_ce ena button sch_fq_codel loop fuse configfs dmi_sysfs sha2_ce sha256_arm64 dm_mirror dm_region_hash dm_log dm_mod dax efivarfs\nCPU: 5 PID: 2690970 Comm: cifsd Not tainted 6.1.103-109.184.amzn2023.aarch64 #1\nHardware name: Amazon EC2 r7g.4xlarge/, BIOS 1.0 11/1/2018\npstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : fib_rules_lookup+0x44/0x238\nlr : __fib_lookup+0x64/0xbc\nsp : ffff8000265db790\nx29: ffff8000265db790 x28: 0000000000000000 x27: 000000000000bd01\nx26: 0000000000000000 x25: ffff000b4baf8000 x24: ffff00047b5e4580\nx23: ffff8000265db7e0 x22: 0000000000000000 x21: ffff00047b5e4500\nx20: ffff0010e3f694f8 x19: 14de99e461f849f7 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\nx14: 0000000000000000 x13: 0000000000000000 x12: 3f92800abd010002\nx11: 0000000000000001 x10: ffff0010e3f69420 x9 : ffff800008a6f294\nx8 : 0000000000000000 x7 : 0000000000000006 x6 : 0000000000000000\nx5 : 0000000000000001 x4 : ffff001924354280 x3 : ffff8000265db7e0\nx2 : 0000000000000000 x1 : ffff0010e3f694f8 x0 : ffff00047b5e4500\nCall trace:\n fib_rules_lookup+0x44/0x238\n __fib_lookup+0x64/0xbc\n ip_route_output_key_hash_rcu+0x2c4/0x398\n ip_route_output_key_hash+0x60/0x8c\n tcp_v4_connect+0x290/0x488\n __inet_stream_connect+0x108/0x3d0\n inet_stream_connect+0x50/0x78\n kernel_connect+0x6c/0xac\n generic_ip_conne\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json b/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json index 55f287ae0ac..c863605ab9a 100644 --- a/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json +++ b/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json b/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json index f56ff45c439..fbd2fffc66e 100644 --- a/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json +++ b/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7h56-8w9m-w78x/GHSA-7h56-8w9m-w78x.json b/advisories/unreviewed/2024/11/GHSA-7h56-8w9m-w78x/GHSA-7h56-8w9m-w78x.json index e6c2b96189c..67fde0da81b 100644 --- a/advisories/unreviewed/2024/11/GHSA-7h56-8w9m-w78x/GHSA-7h56-8w9m-w78x.json +++ b/advisories/unreviewed/2024/11/GHSA-7h56-8w9m-w78x/GHSA-7h56-8w9m-w78x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8jxm-phrp-w2j4/GHSA-8jxm-phrp-w2j4.json b/advisories/unreviewed/2024/11/GHSA-8jxm-phrp-w2j4/GHSA-8jxm-phrp-w2j4.json index bbfedb72e25..6b4ef947a2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-8jxm-phrp-w2j4/GHSA-8jxm-phrp-w2j4.json +++ b/advisories/unreviewed/2024/11/GHSA-8jxm-phrp-w2j4/GHSA-8jxm-phrp-w2j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8qh2-vgp4-89x7/GHSA-8qh2-vgp4-89x7.json b/advisories/unreviewed/2024/11/GHSA-8qh2-vgp4-89x7/GHSA-8qh2-vgp4-89x7.json index 4030a8d4e85..6026eabb39e 100644 --- a/advisories/unreviewed/2024/11/GHSA-8qh2-vgp4-89x7/GHSA-8qh2-vgp4-89x7.json +++ b/advisories/unreviewed/2024/11/GHSA-8qh2-vgp4-89x7/GHSA-8qh2-vgp4-89x7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8vxc-ww8x-mxp8/GHSA-8vxc-ww8x-mxp8.json b/advisories/unreviewed/2024/11/GHSA-8vxc-ww8x-mxp8/GHSA-8vxc-ww8x-mxp8.json index 4615cb4db66..37977abd28c 100644 --- a/advisories/unreviewed/2024/11/GHSA-8vxc-ww8x-mxp8/GHSA-8vxc-ww8x-mxp8.json +++ b/advisories/unreviewed/2024/11/GHSA-8vxc-ww8x-mxp8/GHSA-8vxc-ww8x-mxp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-927w-gc63-2rh7/GHSA-927w-gc63-2rh7.json b/advisories/unreviewed/2024/11/GHSA-927w-gc63-2rh7/GHSA-927w-gc63-2rh7.json index 61154d52bfd..9ae14f710fd 100644 --- a/advisories/unreviewed/2024/11/GHSA-927w-gc63-2rh7/GHSA-927w-gc63-2rh7.json +++ b/advisories/unreviewed/2024/11/GHSA-927w-gc63-2rh7/GHSA-927w-gc63-2rh7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json b/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json index 736211e28e5..fd3a2e1766e 100644 --- a/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json +++ b/advisories/unreviewed/2024/11/GHSA-97cw-cf8m-4xxc/GHSA-97cw-cf8m-4xxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json b/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json index 0ec52a91cb8..4aec78a8bce 100644 --- a/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json +++ b/advisories/unreviewed/2024/11/GHSA-9wf4-422v-6w3j/GHSA-9wf4-422v-6w3j.json @@ -7,12 +7,8 @@ "CVE-2024-51365" ], "details": "An arbitrary file upload vulnerability in the importSettings method of VisiCut v2.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-cqg5-xfgj-qvgx/GHSA-cqg5-xfgj-qvgx.json b/advisories/unreviewed/2024/11/GHSA-cqg5-xfgj-qvgx/GHSA-cqg5-xfgj-qvgx.json index 83b7bcbeeb3..7017b69b685 100644 --- a/advisories/unreviewed/2024/11/GHSA-cqg5-xfgj-qvgx/GHSA-cqg5-xfgj-qvgx.json +++ b/advisories/unreviewed/2024/11/GHSA-cqg5-xfgj-qvgx/GHSA-cqg5-xfgj-qvgx.json @@ -7,12 +7,8 @@ "CVE-2024-53089" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Mark hrtimer to expire in hard interrupt context\n\nLike commit 2c0d278f3293f (\"KVM: LAPIC: Mark hrtimer to expire in hard\ninterrupt context\") and commit 9090825fa9974 (\"KVM: arm/arm64: Let the\ntimer expire in hardirq context on RT\"), On PREEMPT_RT enabled kernels\nunmarked hrtimers are moved into soft interrupt expiry mode by default.\nThen the timers are canceled from an preempt-notifier which is invoked\nwith disabled preemption which is not allowed on PREEMPT_RT.\n\nThe timer callback is short so in could be invoked in hard-IRQ context.\nSo let the timer expire on hard-IRQ context even on -RT.\n\nThis fix a \"scheduling while atomic\" bug for PREEMPT_RT enabled kernels:\n\n BUG: scheduling while atomic: qemu-system-loo/1011/0x00000002\n Modules linked in: amdgpu rfkill nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ns\n CPU: 1 UID: 0 PID: 1011 Comm: qemu-system-loo Tainted: G W 6.12.0-rc2+ #1774\n Tainted: [W]=WARN\n Hardware name: Loongson Loongson-3A5000-7A1000-1w-CRB/Loongson-LS3A5000-7A1000-1w-CRB, BIOS vUDK2018-LoongArch-V2.0.0-prebeta9 10/21/2022\n Stack : ffffffffffffffff 0000000000000000 9000000004e3ea38 9000000116744000\n 90000001167475a0 0000000000000000 90000001167475a8 9000000005644830\n 90000000058dc000 90000000058dbff8 9000000116747420 0000000000000001\n 0000000000000001 6a613fc938313980 000000000790c000 90000001001c1140\n 00000000000003fe 0000000000000001 000000000000000d 0000000000000003\n 0000000000000030 00000000000003f3 000000000790c000 9000000116747830\n 90000000057ef000 0000000000000000 9000000005644830 0000000000000004\n 0000000000000000 90000000057f4b58 0000000000000001 9000000116747868\n 900000000451b600 9000000005644830 9000000003a13998 0000000010000020\n 00000000000000b0 0000000000000004 0000000000000000 0000000000071c1d\n ...\n Call Trace:\n [<9000000003a13998>] show_stack+0x38/0x180\n [<9000000004e3ea34>] dump_stack_lvl+0x84/0xc0\n [<9000000003a71708>] __schedule_bug+0x48/0x60\n [<9000000004e45734>] __schedule+0x1114/0x1660\n [<9000000004e46040>] schedule_rtlock+0x20/0x60\n [<9000000004e4e330>] rtlock_slowlock_locked+0x3f0/0x10a0\n [<9000000004e4f038>] rt_spin_lock+0x58/0x80\n [<9000000003b02d68>] hrtimer_cancel_wait_running+0x68/0xc0\n [<9000000003b02e30>] hrtimer_cancel+0x70/0x80\n [] kvm_restore_timer+0x50/0x1a0 [kvm]\n [] kvm_arch_vcpu_load+0x68/0x2a0 [kvm]\n [] kvm_sched_in+0x34/0x60 [kvm]\n [<9000000003a749a0>] finish_task_switch.isra.0+0x140/0x2e0\n [<9000000004e44a70>] __schedule+0x450/0x1660\n [<9000000004e45cb0>] schedule+0x30/0x180\n [] kvm_vcpu_block+0x70/0x120 [kvm]\n [] kvm_vcpu_halt+0x60/0x3e0 [kvm]\n [] kvm_handle_gspr+0x3f4/0x4e0 [kvm]\n [] kvm_handle_exit+0x1c8/0x260 [kvm]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-f3pg-hppr-jf6f/GHSA-f3pg-hppr-jf6f.json b/advisories/unreviewed/2024/11/GHSA-f3pg-hppr-jf6f/GHSA-f3pg-hppr-jf6f.json index f4e9d538d91..1d9c3a7a998 100644 --- a/advisories/unreviewed/2024/11/GHSA-f3pg-hppr-jf6f/GHSA-f3pg-hppr-jf6f.json +++ b/advisories/unreviewed/2024/11/GHSA-f3pg-hppr-jf6f/GHSA-f3pg-hppr-jf6f.json @@ -7,12 +7,8 @@ "CVE-2024-53090" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix lock recursion\n\nafs_wake_up_async_call() can incur lock recursion. The problem is that it\nis called from AF_RXRPC whilst holding the ->notify_lock, but it tries to\ntake a ref on the afs_call struct in order to pass it to a work queue - but\nif the afs_call is already queued, we then have an extraneous ref that must\nbe put... calling afs_put_call() may call back down into AF_RXRPC through\nrxrpc_kernel_shutdown_call(), however, which might try taking the\n->notify_lock again.\n\nThis case isn't very common, however, so defer it to a workqueue. The oops\nlooks something like:\n\n BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646\n lock: 0xffff888141399b30, .magic: dead4ead, .owner: krxrpcio/7001/1646, .owner_cpu: 0\n CPU: 0 UID: 0 PID: 1646 Comm: krxrpcio/7001 Not tainted 6.12.0-rc2-build3+ #4351\n Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014\n Call Trace:\n \n dump_stack_lvl+0x47/0x70\n do_raw_spin_lock+0x3c/0x90\n rxrpc_kernel_shutdown_call+0x83/0xb0\n afs_put_call+0xd7/0x180\n rxrpc_notify_socket+0xa0/0x190\n rxrpc_input_split_jumbo+0x198/0x1d0\n rxrpc_input_data+0x14b/0x1e0\n ? rxrpc_input_call_packet+0xc2/0x1f0\n rxrpc_input_call_event+0xad/0x6b0\n rxrpc_input_packet_on_conn+0x1e1/0x210\n rxrpc_input_packet+0x3f2/0x4d0\n rxrpc_io_thread+0x243/0x410\n ? __pfx_rxrpc_io_thread+0x10/0x10\n kthread+0xcf/0xe0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x24/0x40\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-f655-5h7w-g749/GHSA-f655-5h7w-g749.json b/advisories/unreviewed/2024/11/GHSA-f655-5h7w-g749/GHSA-f655-5h7w-g749.json index b0e3edbbd91..d59cc251031 100644 --- a/advisories/unreviewed/2024/11/GHSA-f655-5h7w-g749/GHSA-f655-5h7w-g749.json +++ b/advisories/unreviewed/2024/11/GHSA-f655-5h7w-g749/GHSA-f655-5h7w-g749.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-f8fj-469m-8mrj/GHSA-f8fj-469m-8mrj.json b/advisories/unreviewed/2024/11/GHSA-f8fj-469m-8mrj/GHSA-f8fj-469m-8mrj.json index cf3596f8679..c3fd11a46d4 100644 --- a/advisories/unreviewed/2024/11/GHSA-f8fj-469m-8mrj/GHSA-f8fj-469m-8mrj.json +++ b/advisories/unreviewed/2024/11/GHSA-f8fj-469m-8mrj/GHSA-f8fj-469m-8mrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-grq5-97jg-xjfp/GHSA-grq5-97jg-xjfp.json b/advisories/unreviewed/2024/11/GHSA-grq5-97jg-xjfp/GHSA-grq5-97jg-xjfp.json index 767974b7ff6..89817ca6bfd 100644 --- a/advisories/unreviewed/2024/11/GHSA-grq5-97jg-xjfp/GHSA-grq5-97jg-xjfp.json +++ b/advisories/unreviewed/2024/11/GHSA-grq5-97jg-xjfp/GHSA-grq5-97jg-xjfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h534-5p7w-q7vf/GHSA-h534-5p7w-q7vf.json b/advisories/unreviewed/2024/11/GHSA-h534-5p7w-q7vf/GHSA-h534-5p7w-q7vf.json index 36700956fd4..b4b705c5ba2 100644 --- a/advisories/unreviewed/2024/11/GHSA-h534-5p7w-q7vf/GHSA-h534-5p7w-q7vf.json +++ b/advisories/unreviewed/2024/11/GHSA-h534-5p7w-q7vf/GHSA-h534-5p7w-q7vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h8rg-j4g6-9v99/GHSA-h8rg-j4g6-9v99.json b/advisories/unreviewed/2024/11/GHSA-h8rg-j4g6-9v99/GHSA-h8rg-j4g6-9v99.json index ec5af4451e8..85cb001d503 100644 --- a/advisories/unreviewed/2024/11/GHSA-h8rg-j4g6-9v99/GHSA-h8rg-j4g6-9v99.json +++ b/advisories/unreviewed/2024/11/GHSA-h8rg-j4g6-9v99/GHSA-h8rg-j4g6-9v99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h9rp-4669-xxx3/GHSA-h9rp-4669-xxx3.json b/advisories/unreviewed/2024/11/GHSA-h9rp-4669-xxx3/GHSA-h9rp-4669-xxx3.json index 12ea360f1aa..e9319df3e9f 100644 --- a/advisories/unreviewed/2024/11/GHSA-h9rp-4669-xxx3/GHSA-h9rp-4669-xxx3.json +++ b/advisories/unreviewed/2024/11/GHSA-h9rp-4669-xxx3/GHSA-h9rp-4669-xxx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-jh47-c26g-fr5q/GHSA-jh47-c26g-fr5q.json b/advisories/unreviewed/2024/11/GHSA-jh47-c26g-fr5q/GHSA-jh47-c26g-fr5q.json index 4c561a35a87..8d72a8714cc 100644 --- a/advisories/unreviewed/2024/11/GHSA-jh47-c26g-fr5q/GHSA-jh47-c26g-fr5q.json +++ b/advisories/unreviewed/2024/11/GHSA-jh47-c26g-fr5q/GHSA-jh47-c26g-fr5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json b/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json index 32953971944..caab49e11e2 100644 --- a/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json +++ b/advisories/unreviewed/2024/11/GHSA-p4fj-vmm6-h453/GHSA-p4fj-vmm6-h453.json @@ -7,12 +7,8 @@ "CVE-2024-51366" ], "details": "An arbitrary file upload vulnerability in the component \\Roaming\\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-p6w4-xmxx-7gmj/GHSA-p6w4-xmxx-7gmj.json b/advisories/unreviewed/2024/11/GHSA-p6w4-xmxx-7gmj/GHSA-p6w4-xmxx-7gmj.json index 97c754aedef..0d5db45d07f 100644 --- a/advisories/unreviewed/2024/11/GHSA-p6w4-xmxx-7gmj/GHSA-p6w4-xmxx-7gmj.json +++ b/advisories/unreviewed/2024/11/GHSA-p6w4-xmxx-7gmj/GHSA-p6w4-xmxx-7gmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-p7x7-vrh2-wvvc/GHSA-p7x7-vrh2-wvvc.json b/advisories/unreviewed/2024/11/GHSA-p7x7-vrh2-wvvc/GHSA-p7x7-vrh2-wvvc.json index 2118bcd64d1..36eff171760 100644 --- a/advisories/unreviewed/2024/11/GHSA-p7x7-vrh2-wvvc/GHSA-p7x7-vrh2-wvvc.json +++ b/advisories/unreviewed/2024/11/GHSA-p7x7-vrh2-wvvc/GHSA-p7x7-vrh2-wvvc.json @@ -7,12 +7,8 @@ "CVE-2024-53092" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_pci: Fix admin vq cleanup by using correct info pointer\n\nvp_modern_avq_cleanup() and vp_del_vqs() clean up admin vq\nresources by virtio_pci_vq_info pointer. The info pointer of admin\nvq is stored in vp_dev->admin_vq.info instead of vp_dev->vqs[].\nUsing the info pointer from vp_dev->vqs[] for admin vq causes a\nkernel NULL pointer dereference bug.\nIn vp_modern_avq_cleanup() and vp_del_vqs(), get the info pointer\nfrom vp_dev->admin_vq.info for admin vq to clean up the resources.\nAlso make info ptr as argument of vp_del_vq() to be symmetric with\nvp_setup_vq().\n\nvp_reset calls vp_modern_avq_cleanup, and causes the Call Trace:\n==================================================================\nBUG: kernel NULL pointer dereference, address:0000000000000000\n...\nCPU: 49 UID: 0 PID: 4439 Comm: modprobe Not tainted 6.11.0-rc5 #1\nRIP: 0010:vp_reset+0x57/0x90 [virtio_pci]\nCall Trace:\n \n...\n ? vp_reset+0x57/0x90 [virtio_pci]\n ? vp_reset+0x38/0x90 [virtio_pci]\n virtio_reset_device+0x1d/0x30\n remove_vq_common+0x1c/0x1a0 [virtio_net]\n virtnet_remove+0xa1/0xc0 [virtio_net]\n virtio_dev_remove+0x46/0xa0\n...\n virtio_pci_driver_exit+0x14/0x810 [virtio_pci]\n==================================================================", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-p9fm-3qq2-rmm2/GHSA-p9fm-3qq2-rmm2.json b/advisories/unreviewed/2024/11/GHSA-p9fm-3qq2-rmm2/GHSA-p9fm-3qq2-rmm2.json index bf309bb123b..782d765e3ac 100644 --- a/advisories/unreviewed/2024/11/GHSA-p9fm-3qq2-rmm2/GHSA-p9fm-3qq2-rmm2.json +++ b/advisories/unreviewed/2024/11/GHSA-p9fm-3qq2-rmm2/GHSA-p9fm-3qq2-rmm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-q7cg-9vqh-8mc2/GHSA-q7cg-9vqh-8mc2.json b/advisories/unreviewed/2024/11/GHSA-q7cg-9vqh-8mc2/GHSA-q7cg-9vqh-8mc2.json index d2c0aa4c2ec..fe7aca5257b 100644 --- a/advisories/unreviewed/2024/11/GHSA-q7cg-9vqh-8mc2/GHSA-q7cg-9vqh-8mc2.json +++ b/advisories/unreviewed/2024/11/GHSA-q7cg-9vqh-8mc2/GHSA-q7cg-9vqh-8mc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-qccg-86w9-x648/GHSA-qccg-86w9-x648.json b/advisories/unreviewed/2024/11/GHSA-qccg-86w9-x648/GHSA-qccg-86w9-x648.json index 0d69a993d67..8d7a9f678ee 100644 --- a/advisories/unreviewed/2024/11/GHSA-qccg-86w9-x648/GHSA-qccg-86w9-x648.json +++ b/advisories/unreviewed/2024/11/GHSA-qccg-86w9-x648/GHSA-qccg-86w9-x648.json @@ -7,12 +7,8 @@ "CVE-2024-53091" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx\n\nAs the introduction of the support for vsock and unix sockets in sockmap,\ntls_sw_has_ctx_tx/rx cannot presume the socket passed in must be IS_ICSK.\nvsock and af_unix sockets have vsock_sock and unix_sock instead of\ninet_connection_sock. For these sockets, tls_get_ctx may return an invalid\npointer and cause page fault in function tls_sw_ctx_rx.\n\nBUG: unable to handle page fault for address: 0000000000040030\nWorkqueue: vsock-loopback vsock_loopback_work\nRIP: 0010:sk_psock_strp_data_ready+0x23/0x60\nCall Trace:\n ? __die+0x81/0xc3\n ? no_context+0x194/0x350\n ? do_page_fault+0x30/0x110\n ? async_page_fault+0x3e/0x50\n ? sk_psock_strp_data_ready+0x23/0x60\n virtio_transport_recv_pkt+0x750/0x800\n ? update_load_avg+0x7e/0x620\n vsock_loopback_work+0xd0/0x100\n process_one_work+0x1a7/0x360\n worker_thread+0x30/0x390\n ? create_worker+0x1a0/0x1a0\n kthread+0x112/0x130\n ? __kthread_cancel_work+0x40/0x40\n ret_from_fork+0x1f/0x40\n\nv2:\n - Add IS_ICSK check\nv3:\n - Update the commits in Fixes", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-r2q9-5f64-27vx/GHSA-r2q9-5f64-27vx.json b/advisories/unreviewed/2024/11/GHSA-r2q9-5f64-27vx/GHSA-r2q9-5f64-27vx.json index 60589c267b6..513598e2e15 100644 --- a/advisories/unreviewed/2024/11/GHSA-r2q9-5f64-27vx/GHSA-r2q9-5f64-27vx.json +++ b/advisories/unreviewed/2024/11/GHSA-r2q9-5f64-27vx/GHSA-r2q9-5f64-27vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rw6f-qwrg-vhvv/GHSA-rw6f-qwrg-vhvv.json b/advisories/unreviewed/2024/11/GHSA-rw6f-qwrg-vhvv/GHSA-rw6f-qwrg-vhvv.json index 80ace6e405c..fed3ddff2cb 100644 --- a/advisories/unreviewed/2024/11/GHSA-rw6f-qwrg-vhvv/GHSA-rw6f-qwrg-vhvv.json +++ b/advisories/unreviewed/2024/11/GHSA-rw6f-qwrg-vhvv/GHSA-rw6f-qwrg-vhvv.json @@ -7,12 +7,8 @@ "CVE-2024-53093" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-multipath: defer partition scanning\n\nWe need to suppress the partition scan from occuring within the\ncontroller's scan_work context. If a path error occurs here, the IO will\nwait until a path becomes available or all paths are torn down, but that\naction also occurs within scan_work, so it would deadlock. Defer the\npartion scan to a different context that does not block scan_work.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-w7c6-4vwf-466q/GHSA-w7c6-4vwf-466q.json b/advisories/unreviewed/2024/11/GHSA-w7c6-4vwf-466q/GHSA-w7c6-4vwf-466q.json index a4f0631af68..bd560c6a880 100644 --- a/advisories/unreviewed/2024/11/GHSA-w7c6-4vwf-466q/GHSA-w7c6-4vwf-466q.json +++ b/advisories/unreviewed/2024/11/GHSA-w7c6-4vwf-466q/GHSA-w7c6-4vwf-466q.json @@ -7,12 +7,8 @@ "CVE-2024-53094" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES\n\nWhile running ISER over SIW, the initiator machine encounters a warning\nfrom skb_splice_from_iter() indicating that a slab page is being used in\nsend_page. To address this, it is better to add a sendpage_ok() check\nwithin the driver itself, and if it returns 0, then MSG_SPLICE_PAGES flag\nshould be disabled before entering the network stack.\n\nA similar issue has been discussed for NVMe in this thread:\nhttps://lore.kernel.org/all/20240530142417.146696-1-ofir.gal@volumez.com/\n\n WARNING: CPU: 0 PID: 5342 at net/core/skbuff.c:7140 skb_splice_from_iter+0x173/0x320\n Call Trace:\n tcp_sendmsg_locked+0x368/0xe40\n siw_tx_hdt+0x695/0xa40 [siw]\n siw_qp_sq_process+0x102/0xb00 [siw]\n siw_sq_resume+0x39/0x110 [siw]\n siw_run_sq+0x74/0x160 [siw]\n kthread+0xd2/0x100\n ret_from_fork+0x34/0x40\n ret_from_fork_asm+0x1a/0x30", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json b/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json index 4a63d61457a..3471a2dc1aa 100644 --- a/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json +++ b/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json b/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json index e83807da202..acbc0b5d638 100644 --- a/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json +++ b/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",