diff --git a/advisories/github-reviewed/2021/05/GHSA-3wxm-m9m4-cprj/GHSA-3wxm-m9m4-cprj.json b/advisories/github-reviewed/2021/05/GHSA-3wxm-m9m4-cprj/GHSA-3wxm-m9m4-cprj.json index 8dbc9a953d2..f044775f7bd 100644 --- a/advisories/github-reviewed/2021/05/GHSA-3wxm-m9m4-cprj/GHSA-3wxm-m9m4-cprj.json +++ b/advisories/github-reviewed/2021/05/GHSA-3wxm-m9m4-cprj/GHSA-3wxm-m9m4-cprj.json @@ -3,14 +3,10 @@ "id": "GHSA-3wxm-m9m4-cprj", "modified": "2021-05-20T20:24:22Z", "published": "2021-05-21T16:24:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Import of incorrectly embargoed keys could cause early publication", "details": "### Impact\n\nIf your installation is using the `export-importer` service, there is potential impact.\nIf your installation is not importing keys via the `export-importer` services, your installation is not impacted.\n\nIn versions `0.19.1` and earlier, the `export-importer` service assumed that the server it was importing from had properly embargoed keys for at least 2 hours after their expiry time. There are now known instances of servers that did not properly embargo keys.\n\nThis could allow allow for imported keys to be re-published before they have expired, allowing for potential replay of RPIs.\n\n### Patches\n\nThis is patched in `v0.18.3` and all versions `0.19.2` and later.\n\n### Workarounds\n\nEnsure that the servers you are importing export zip files from are not publishing keys too early. \n\n### References\n\nn/a\n\n### For more information\n\nIf you have any questions or comments about this advisory\n* Open an issue in [exposure-notifications-server](https://github.com/google/exposure-notifications-server/)\n* Email us at [exposure-notifications-feedback@google.com](mailto:exposure-notifications-feedback@google.com)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -58,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-05-20T20:24:22Z", diff --git a/advisories/github-reviewed/2021/05/GHSA-4g53-vp7q-gfjv/GHSA-4g53-vp7q-gfjv.json b/advisories/github-reviewed/2021/05/GHSA-4g53-vp7q-gfjv/GHSA-4g53-vp7q-gfjv.json index 6ee2dfd38fc..dfbc79e9b4d 100644 --- a/advisories/github-reviewed/2021/05/GHSA-4g53-vp7q-gfjv/GHSA-4g53-vp7q-gfjv.json +++ b/advisories/github-reviewed/2021/05/GHSA-4g53-vp7q-gfjv/GHSA-4g53-vp7q-gfjv.json @@ -3,14 +3,10 @@ "id": "GHSA-4g53-vp7q-gfjv", "modified": "2021-05-27T22:24:49Z", "published": "2021-05-28T19:18:28Z", - "aliases": [ - - ], + "aliases": [], "summary": "constructEvent does not verify header", "details": "### Impact\nAnyone verifying a Stripe webhook request via this library's `constructEvent` function.\n\n### Patches\nUpgrade to 1.1.4. \n\n### Workarounds\nUse `await verifyHeader(...)` directly instead of `constructEvent`.\n\n### References\nhttps://github.com/worker-tools/stripe-webhook/issues/1\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-05-27T22:24:49Z", diff --git a/advisories/github-reviewed/2021/05/GHSA-5684-g483-2249/GHSA-5684-g483-2249.json b/advisories/github-reviewed/2021/05/GHSA-5684-g483-2249/GHSA-5684-g483-2249.json index d2ce06f01b2..9bc9bb0573c 100644 --- a/advisories/github-reviewed/2021/05/GHSA-5684-g483-2249/GHSA-5684-g483-2249.json +++ b/advisories/github-reviewed/2021/05/GHSA-5684-g483-2249/GHSA-5684-g483-2249.json @@ -3,14 +3,10 @@ "id": "GHSA-5684-g483-2249", "modified": "2021-10-05T17:07:09Z", "published": "2021-05-24T16:59:47Z", - "aliases": [ - - ], + "aliases": [], "summary": "Signature Validation Bypass", "details": "### Impact\nGiven a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one.\n\nThis enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response.\n\n### Patches\nA patch is available, users of gosaml2 should upgrade to v0.5.0 or higher.\n\n### References\nSee the [underlying advisory on goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7) for more details.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/05/GHSA-5vm8-hhgr-jcjp/GHSA-5vm8-hhgr-jcjp.json b/advisories/github-reviewed/2021/05/GHSA-5vm8-hhgr-jcjp/GHSA-5vm8-hhgr-jcjp.json index 796a3b1a1a5..e7ae8ee5a74 100644 --- a/advisories/github-reviewed/2021/05/GHSA-5vm8-hhgr-jcjp/GHSA-5vm8-hhgr-jcjp.json +++ b/advisories/github-reviewed/2021/05/GHSA-5vm8-hhgr-jcjp/GHSA-5vm8-hhgr-jcjp.json @@ -3,14 +3,10 @@ "id": "GHSA-5vm8-hhgr-jcjp", "modified": "2021-05-27T21:29:43Z", "published": "2021-05-28T19:18:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "Cross-site scripting vulnerability in TinyMCE", "details": "### Impact\nA cross-site scripting (XSS) vulnerability was discovered in the URL sanitization logic of the core parser for `form` elements. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor using the clipboard or APIs, and then submitting the form. However, as TinyMCE does not allow forms to be submitted while editing, the vulnerability could only be triggered when the content was previewed or rendered outside of the editor. This impacts all users who are using TinyMCE 5.7.0 or lower.\n\n### Patches\nThis vulnerability has been patched in TinyMCE 5.7.1 by improved URL sanitization logic.\n\n### Workarounds\nTo work around this vulnerability, either:\n- Upgrade to TinyMCE 5.7.1 or higher\n- Manually sanitize `form` URL attributes using a [TinyMCE node filter](https://www.tiny.cloud/docs/api/tinymce.html/tinymce.html.domparser/#addnodefilter).\n- Disable `form` elements in your content using the [invalid_elements](https://www.tiny.cloud/docs/configure/content-filtering/#invalid_elements) setting.\n\n#### Example: Sanitizing using a node filter\n```js\neditor.parser.addNodeFilter('form', function(nodes) {\n nodes.forEach(function(node) {\n if (node.attributes) {\n node.attributes.forEach(function(attr) {\n var name = attr.name;\n var value = attr.value;\n // Sanitize the attribute value here or remove it entirely\n var sanitizedValue = ...;\n node.attr(name, santizedValue);\n });\n }\n });\n});\n```\n\n#### Example: Using invalid_elements\n```js\ninvalid_elements: 'form'\n```\n\n### Acknowledgements\nTiny Technologies would like to thank Mikhail Khramenkov at Solar Security Research Team for discovering this vulnerability.\n\n### References\nhttps://www.tiny.cloud/docs/release-notes/release-notes571/#securityfixes\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues)\n* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/05/GHSA-6w87-g839-9wv7/GHSA-6w87-g839-9wv7.json b/advisories/github-reviewed/2021/05/GHSA-6w87-g839-9wv7/GHSA-6w87-g839-9wv7.json index 0decfdf90b0..abc431e8f1c 100644 --- a/advisories/github-reviewed/2021/05/GHSA-6w87-g839-9wv7/GHSA-6w87-g839-9wv7.json +++ b/advisories/github-reviewed/2021/05/GHSA-6w87-g839-9wv7/GHSA-6w87-g839-9wv7.json @@ -3,9 +3,7 @@ "id": "GHSA-6w87-g839-9wv7", "modified": "2021-10-05T16:35:57Z", "published": "2021-05-21T14:31:28Z", - "aliases": [ - - ], + "aliases": [], "summary": "Helm OCI credentials leaked into Argo CD logs", "details": "### Impact\n\nWhen Argo CD was connected to a Helm OCI repository with authentication enabled, the credentials used for accessing the remote repository were logged.\n\nAnyone with access to the pod logs - either via access with appropriate permissions to the Kubernetes control plane or a third party log management system where the logs from Argo CD were aggregated - could have potentially obtained the credentials to the Helm OCI repository.\n\nIf you are using Helm OCI repositories with Argo CD, it is strongly recommended to upgrade Argo CD to the latest patch version and to change the credentials used to access the repositories.\n\n### Patches\n\nA patch for this vulnerability is available with the v1.8.7 and v1.7.14 releases of Argo CD.\n\n### Workarounds\n\nNo workaround available\n\n### References\n\nN/A\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)\n* Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel `#argo-cd`\n\n### Credits\n\nThis vulnerability was found and reported by a third-party who wishes to stay anonymous. We want to thank this third-party for disclosing this vulnerability to us in a responsible manner.", "severity": [ diff --git a/advisories/github-reviewed/2021/05/GHSA-c66w-hq56-4q97/GHSA-c66w-hq56-4q97.json b/advisories/github-reviewed/2021/05/GHSA-c66w-hq56-4q97/GHSA-c66w-hq56-4q97.json index 5e9c778d53e..66dc89904ff 100644 --- a/advisories/github-reviewed/2021/05/GHSA-c66w-hq56-4q97/GHSA-c66w-hq56-4q97.json +++ b/advisories/github-reviewed/2021/05/GHSA-c66w-hq56-4q97/GHSA-c66w-hq56-4q97.json @@ -3,14 +3,10 @@ "id": "GHSA-c66w-hq56-4q97", "modified": "2021-05-21T14:09:14Z", "published": "2021-05-21T14:32:37Z", - "aliases": [ - - ], + "aliases": [], "summary": "Network policy may be bypassed by some ICMP Echo Requests", "details": "## Impact\n\nUnder certain conditions, ICMP Echo Request sent to a Cilium endpoint from an actor may bypass a network policy which _disallows_ access from the actor to the endpoint, but _allows_ from the endpoint to the actor. This does _NOT_ apply to UDP and TCP traffic.\n\nThe actor is either a pod or a cluster host or a remote host.\n\nThe following conditions must be met:\n1. Network policies have been created which:\n a) do not allow access from the actor to the endpoint;\n b) allow access from the endpoint to the actor and does not specify neither protocol nor port. \n2. The endpoint has sent ICMP Echo Request to the actor with the ICMP identifier X.\n3. The actor sends ICMP Echo Request to the endpoint with the same ICMP identifier X.\n4. The request from the actor (3.) is sent before the Cilium's conntrack GC has removed the previously created conntrack entry (2.).\n\n## Detailed description\n\nSee https://github.com/cilium/cilium/commit/dfb008a9099c4da1e0fd964c899c43ee13280b0e (v1.9.x), https://github.com/cilium/cilium/commit/ff6ebae6efca1bd991302b464dea428512823e79 (v1.8.x), https://github.com/cilium/cilium/commit/472bbeff75161979c317ab21d563f826291b5f37 (v1.7.x).\n\n## Example\n\n```\n$ kubectl run server --image=quay.io/cilium/net-test:v1.0.0 --restart=Never -- sleep 3600\n$ kubectl run client --image=quay.io/cilium/net-test:v1.0.0 --restart=Never -- sleep 3600\n$ cat <server\nspec:\n podSelector:\n matchLabels:\n run: server\n ingress:\n - from:\n - podSelector:\n matchLabels:\n run: client\n policyTypes:\n - Ingress\n---\napiVersion: networking.k8s.io/v1\nkind: NetworkPolicy\nmetadata:\n name: client-netpol # deny any->client\nspec:\n podSelector:\n matchLabels:\n run: client\n policyTypes:\n - Ingress\nEOF\n\n$ kubectl exec -ti server -- xping -c1 -x666 $CLIENT_POD_IP\nPING 10.154.0.50 (10.154.0.50): 56 data bytes\n^C\n--- 10.154.0.50 ping statistics ---\n1 packets transmitted, 0 packets received, 100% packet loss <--- \"client-netpol\" policy denied\ncommand terminated with exit code 1\n\n$ kubectl exec -ti client -- xping -c1 -x666 $SERVER_POD_IP\nPING 10.154.1.16 (10.154.1.16): 56 data bytes\n64 bytes from 10.154.1.16: seq=0 ttl=60 time=0.822 ms\n\n--- 10.154.1.16 ping statistics ---\n1 packets transmitted, 1 packets received, 0% packet loss <--- \"server-netpol\" policy allowed\nround-trip min/avg/max = 0.822/0.822/0.822 ms\n\n$ kubectl exec -ti server -- xping -c1 -x666 $CLIENT_POD_IP\nPING 10.154.0.50 (10.154.0.50): 56 data bytes\n64 bytes from 10.154.0.50: seq=0 ttl=60 time=0.527 ms\n\n--- 10.154.0.50 ping statistics ---\n1 packets transmitted, 1 packets received, 0% packet loss <--- \"client-netpol\" policy bypassed\nround-trip min/avg/max = 0.527/0.527/0.527 ms\n```\n\n## For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [Cilium Issues](https://github.com/cilium/cilium/issues)\n- Email us at security@cilium.io", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -86,9 +82,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-05-21T14:09:14Z", diff --git a/advisories/github-reviewed/2021/05/GHSA-g636-q5fc-4pr7/GHSA-g636-q5fc-4pr7.json b/advisories/github-reviewed/2021/05/GHSA-g636-q5fc-4pr7/GHSA-g636-q5fc-4pr7.json index 74559e91816..c4e4c977c41 100644 --- a/advisories/github-reviewed/2021/05/GHSA-g636-q5fc-4pr7/GHSA-g636-q5fc-4pr7.json +++ b/advisories/github-reviewed/2021/05/GHSA-g636-q5fc-4pr7/GHSA-g636-q5fc-4pr7.json @@ -3,14 +3,10 @@ "id": "GHSA-g636-q5fc-4pr7", "modified": "2021-05-21T22:11:53Z", "published": "2021-05-24T17:00:27Z", - "aliases": [ - - ], + "aliases": [], "summary": "accounts: Hash account number using Salt", "details": "@alovak found that currently when we build hash of account number we do not \"salt\" it. Which makes it vulnerable to rainbow table attack.\n\n**What did you expect to see?**\nI expected salt (some random number from configuration) to be used in [hash.AccountNumber](https://github.com/moov-io/customers/blob/master/pkg/secrets/hash/account_number.go#L13)\n\nI would generate salt per tenant at least (maybe per organization).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-05-21T22:11:53Z", diff --git a/advisories/github-reviewed/2021/05/GHSA-gmq2-39ff-f5qg/GHSA-gmq2-39ff-f5qg.json b/advisories/github-reviewed/2021/05/GHSA-gmq2-39ff-f5qg/GHSA-gmq2-39ff-f5qg.json index 4c7d251149b..6fd48ef2606 100644 --- a/advisories/github-reviewed/2021/05/GHSA-gmq2-39ff-f5qg/GHSA-gmq2-39ff-f5qg.json +++ b/advisories/github-reviewed/2021/05/GHSA-gmq2-39ff-f5qg/GHSA-gmq2-39ff-f5qg.json @@ -3,14 +3,10 @@ "id": "GHSA-gmq2-39ff-f5qg", "modified": "2021-05-21T14:40:36Z", "published": "2021-05-21T16:25:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "A failed upgrade may lead to hung goroutines", "details": "### Impact\nProcesses using tableflip may encounter hung goroutines in the parent process, after a failed upgrade.\n\nThe Go runtime has annoying behaviour around setting and clearing\nO_NONBLOCK: exec.Cmd.Start() ends up calling os.File.Fd() for any\nfile in exec.Cmd.ExtraFiles. os.File.Fd() disables both the use\nof the runtime poller for the file and clears O_NONBLOCK from\nthe underlying open file descriptor.\n\nThis can lead to goroutines hanging in a parent process, after at least\none failed upgrade. The bug manifests in goroutines which rely on\neither a deadline or interruption via Close() to be unblocked being stuck\nin read or accept like syscalls. As far as I can tell we've not experienced\nthis problem in production, so it's most likely quite rare.\n\n### Patches\nThe problem has been fixed in v1.2.2.\n\n### Workarounds\nNone.\n\n### References\n* https://github.com/cloudflare/tableflip/commit/cae714b289e199db5da5f08af861ea65be6232c0", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -46,9 +42,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-05-21T14:40:36Z", diff --git a/advisories/github-reviewed/2021/05/GHSA-gwj5-3vfq-q992/GHSA-gwj5-3vfq-q992.json b/advisories/github-reviewed/2021/05/GHSA-gwj5-3vfq-q992/GHSA-gwj5-3vfq-q992.json index 78d6c5df631..5e347f62132 100644 --- a/advisories/github-reviewed/2021/05/GHSA-gwj5-3vfq-q992/GHSA-gwj5-3vfq-q992.json +++ b/advisories/github-reviewed/2021/05/GHSA-gwj5-3vfq-q992/GHSA-gwj5-3vfq-q992.json @@ -3,9 +3,7 @@ "id": "GHSA-gwj5-3vfq-q992", "modified": "2021-05-20T21:07:16Z", "published": "2021-05-21T16:22:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "Import loops in account imports, nats-server DoS", "details": "(This advisory is canonically )\n\n## Problem Description\n\nAn export/import cycle between accounts could crash the nats-server, after consuming CPU and memory.\n\nThis issue was fixed publicly in in November 2020.\n\nThe need to call this out as a security issue was highlighted by `snyk.io` and we are grateful for their assistance in doing so.\n\nOrganizations which run a NATS service providing access to accounts run by untrusted third parties are affected.\nSee below for an important caveat if running such a service.\n\n\n## Affected versions\n\n#### NATS Server\n\n * Version 2 prior to 2.2.0\n + 2.0.0 through and including 2.1.9 are vulnerable.\n * fixed with nats-io/nats-server PR 1731, commit 2e3c226729\n\n\n## Impact\n\nThe nats-server could be killed, after consuming resources.\n\n\n## Workaround\n\nThe import cycle requires at least two accounts to work; if you have open account sign-up, then restricting new account sign-up might hinder an attacker.\n\n\n## Solution\n\nUpgrade the nats-server.\n\n\n## Caveat on NATS with untrusted users\n\nRunning a NATS service which is exposed to untrusted users presents a heightened risk.\n\nAny remote execution flaw or equivalent seriousness, or denial-of-service by unauthenticated users, will lead to prompt releases by the NATS maintainers.\n\nFixes for denial of service issues with no threat of remote execution, when limited to account holders, are likely to just be committed to the main development branch with no special attention.\n\nThose who are running such services are encouraged to build regularly from git.", "severity": [ diff --git a/advisories/github-reviewed/2021/05/GHSA-jcgr-9698-82jx/GHSA-jcgr-9698-82jx.json b/advisories/github-reviewed/2021/05/GHSA-jcgr-9698-82jx/GHSA-jcgr-9698-82jx.json index b5fb80708b6..75038054d4f 100644 --- a/advisories/github-reviewed/2021/05/GHSA-jcgr-9698-82jx/GHSA-jcgr-9698-82jx.json +++ b/advisories/github-reviewed/2021/05/GHSA-jcgr-9698-82jx/GHSA-jcgr-9698-82jx.json @@ -3,14 +3,10 @@ "id": "GHSA-jcgr-9698-82jx", "modified": "2021-05-27T21:05:29Z", "published": "2021-05-28T15:53:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Neutralization of Special Elements used in a Command ('Command Injection') in @floffah/build", "details": "### Impact\nIf you are using the esbuild target or command you are at risk of code/option injection. Attackers can use the command line option to maliciously change your settings in order to damage your project.\n\n### Patches\nThe problem has been patched in v1.0.0 as it uses a proper method to pass configs to esbuild/estrella.\n\n### Workarounds\nThere is no work around. You should update asap.\n\n### Notes\nThis notice is mainly just to make sure people update to the latest version. This isn't that bad, but should encourage you to update.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/05/GHSA-qmfx-75ff-8mw6/GHSA-qmfx-75ff-8mw6.json b/advisories/github-reviewed/2021/05/GHSA-qmfx-75ff-8mw6/GHSA-qmfx-75ff-8mw6.json index 1e5e0193ce1..7b3a9fadc72 100644 --- a/advisories/github-reviewed/2021/05/GHSA-qmfx-75ff-8mw6/GHSA-qmfx-75ff-8mw6.json +++ b/advisories/github-reviewed/2021/05/GHSA-qmfx-75ff-8mw6/GHSA-qmfx-75ff-8mw6.json @@ -3,14 +3,10 @@ "id": "GHSA-qmfx-75ff-8mw6", "modified": "2021-05-24T21:22:08Z", "published": "2021-05-27T18:41:00Z", - "aliases": [ - - ], + "aliases": [], "summary": "Listing of upload directory contents possible", "details": "There's an security issue in prosody-filer versions **< 1.0.1** which leads to unwanted directory listings of download directories. \n\nAn attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than `/upload/` (or the corresponding user defined root dir)\n\nVersion 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-05-24T21:22:08Z", diff --git a/advisories/github-reviewed/2021/05/GHSA-rrfw-hg9m-j47h/GHSA-rrfw-hg9m-j47h.json b/advisories/github-reviewed/2021/05/GHSA-rrfw-hg9m-j47h/GHSA-rrfw-hg9m-j47h.json index 59568d3fce7..3665f232224 100644 --- a/advisories/github-reviewed/2021/05/GHSA-rrfw-hg9m-j47h/GHSA-rrfw-hg9m-j47h.json +++ b/advisories/github-reviewed/2021/05/GHSA-rrfw-hg9m-j47h/GHSA-rrfw-hg9m-j47h.json @@ -3,14 +3,10 @@ "id": "GHSA-rrfw-hg9m-j47h", "modified": "2021-10-08T21:25:26Z", "published": "2021-05-24T16:59:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Signature Validation Bypass", "details": "### Impact\n\nAn authentication bypass exists in the [goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7) this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.\n\n### Patches\n\nVersion 0.4.2 bumps the dependency which should fix the issue.\n\n### For more information\n\nPlease see [the advisory in goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7)\n\n## Credits\n\nThe original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/05/GHSA-rrqv-vjrw-hrcr/GHSA-rrqv-vjrw-hrcr.json b/advisories/github-reviewed/2021/05/GHSA-rrqv-vjrw-hrcr/GHSA-rrqv-vjrw-hrcr.json index 3bebd423bb7..9e929157abc 100644 --- a/advisories/github-reviewed/2021/05/GHSA-rrqv-vjrw-hrcr/GHSA-rrqv-vjrw-hrcr.json +++ b/advisories/github-reviewed/2021/05/GHSA-rrqv-vjrw-hrcr/GHSA-rrqv-vjrw-hrcr.json @@ -3,14 +3,10 @@ "id": "GHSA-rrqv-vjrw-hrcr", "modified": "2021-05-26T19:57:10Z", "published": "2021-05-26T19:59:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Arbitrary Code Execution in json-ptr", "details": "There is a security vulnerability in `json-ptr` versions prior to v2.1.0 in which an unscrupulous actor may execute arbitrary code. If your code sends un-sanitized user input to json-ptr's .get() method, your project is vulnerable to this injection-style vulnerability.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/05/GHSA-x5c7-x7m2-rhmf/GHSA-x5c7-x7m2-rhmf.json b/advisories/github-reviewed/2021/05/GHSA-x5c7-x7m2-rhmf/GHSA-x5c7-x7m2-rhmf.json index 94d7b883417..d320b9ed688 100644 --- a/advisories/github-reviewed/2021/05/GHSA-x5c7-x7m2-rhmf/GHSA-x5c7-x7m2-rhmf.json +++ b/advisories/github-reviewed/2021/05/GHSA-x5c7-x7m2-rhmf/GHSA-x5c7-x7m2-rhmf.json @@ -3,14 +3,10 @@ "id": "GHSA-x5c7-x7m2-rhmf", "modified": "2021-05-20T16:50:13Z", "published": "2021-05-20T16:50:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Local directory executable lookup in sops (Windows-only)", "details": "### Impact\nWindows users using the sops direct editor option (`sops file.yaml`) can have a local executable named either `vi`, `vim`, or `nano` executed if running sops from `cmd.exe`\n\nThis attack is only viable if an attacker is able to place a malicious binary within the directory you are running sops from. As well, this attack will only work when using `cmd.exe` or the Windows C library [SearchPath function](https://docs.microsoft.com/en-us/windows/win32/api/processenv/nf-processenv-searchpatha). This is a result of these Windows tools including `.` within their `PATH` by default.\n\n**If you are using sops within untrusted directories on Windows via `cmd.exe`, please upgrade immediately** \n\n**As well, if you have `.` within your default $PATH, please upgrade immediately.**\n\nMore information can be found on the official Go blog: https://blog.golang.org/path-security\n\n### Patches\nThe problem has been resolved in v3.7.1\n\nNow, if Windows users using cmd.exe run into this issue, a warning message will be printed:\n`vim resolves to executable in current directory (.\\vim.exe)`\n\n### References\n* https://blog.golang.org/path-security\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a discussion in [sops](https://github.com/mozilla/sops/discussions)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-05-20T16:50:13Z", diff --git a/advisories/github-reviewed/2021/06/GHSA-433w-mm6h-rv9p/GHSA-433w-mm6h-rv9p.json b/advisories/github-reviewed/2021/06/GHSA-433w-mm6h-rv9p/GHSA-433w-mm6h-rv9p.json index 9427b62441f..c88296a44c6 100644 --- a/advisories/github-reviewed/2021/06/GHSA-433w-mm6h-rv9p/GHSA-433w-mm6h-rv9p.json +++ b/advisories/github-reviewed/2021/06/GHSA-433w-mm6h-rv9p/GHSA-433w-mm6h-rv9p.json @@ -3,14 +3,10 @@ "id": "GHSA-433w-mm6h-rv9p", "modified": "2021-05-21T20:47:30Z", "published": "2021-06-23T17:29:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Auth bypass in SAML provider", "details": "### Impact\n\nThe following vulnerabilities have been disclosed, which impact users leveraging the SAML auth provider:\n\n- [`goxmldsig` - Signature Validation Bypass](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7)\n- [`gosaml2` - Authentication Bypass](https://github.com/russellhaering/gosaml2/security/advisories/GHSA-xhqq-x44f-9fgg)\n\n### Patches\n\n[Patch available](https://github.com/netlify/gotrue/pull/274)\n\nPlease upgrade to v1.0.0 or commit hash `a2b4dd6bc4ef7562d1df044098b303f564eefa90`\n\n### Workarounds\n\nNo known workarounds.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [gotrue](https://github.com/netlify/gotrue/issues)\n* Email us at [security@netlify.com](mailto:security@netlify.com)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-05-21T20:47:30Z", diff --git a/advisories/github-reviewed/2021/06/GHSA-55xh-53m6-936r/GHSA-55xh-53m6-936r.json b/advisories/github-reviewed/2021/06/GHSA-55xh-53m6-936r/GHSA-55xh-53m6-936r.json index dd6db7bed06..2a9596073ea 100644 --- a/advisories/github-reviewed/2021/06/GHSA-55xh-53m6-936r/GHSA-55xh-53m6-936r.json +++ b/advisories/github-reviewed/2021/06/GHSA-55xh-53m6-936r/GHSA-55xh-53m6-936r.json @@ -3,14 +3,10 @@ "id": "GHSA-55xh-53m6-936r", "modified": "2021-06-01T19:14:06Z", "published": "2021-06-01T21:17:36Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Verification of Cryptographic Signature in aws-encryption-sdk-java", "details": "### Impact\n\nThis advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages. \n\nThis update addresses an issue where certain invalid ECDSA signatures incorrectly passed validation. These signatures provide defense in depth and there is no impact on the integrity of decrypted plaintext.\n\nThis ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated. In addition to these signatures, the ESDK uses AES-GCM encryption and all plaintext is verified before being released to a caller. There is no impact on the integrity of the ciphertext or decrypted plaintext, however some callers may rely on the the ECDSA signature for non-repudiation. Without validating the ECDSA signature, an actor with trusted KMS permissions to decrypt a message may also be able to encrypt messages. This update introduces a new API for callers who wish to stream only unsigned messages. \n\nFor customers who process ESDK messages from untrusted sources, this update also introduces a new configuration to limit the number of Encrypted Data Keys (EDKs) that the ESDK will attempt to process per message. This configuration provides customers with a way to limit the number of AWS KMS Decrypt API calls that the ESDK will make per message. This setting will reject messages with more EDKs than the configured limit.\n\nFinally, this update adds early rejection of invalid messages with certain invalid combinations of algorithm suite and header data.\n\n### Patches\n\nFixed in versions 1.9 and 2.2. We recommend that all users upgrade to address these issues.\n\nCustomers leveraging the ESDK’s streaming features have several options to protect signature validation. One is to ensure that client code reads to the end of the stream before using released plaintext. With this release, using the new API for streaming and falling back to the non-streaming decrypt API for signed messages prevents using any plaintext from signed data before the signature is validated. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\nUsers processing ESDK messages from untrusted sources should use the new maximum encrypted data keys parameter. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\n### Workarounds\n\nNone\n\n### For more information\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/concepts.html#digital-sigs\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-89v2-g37m-g3ff/GHSA-89v2-g37m-g3ff.json b/advisories/github-reviewed/2021/06/GHSA-89v2-g37m-g3ff/GHSA-89v2-g37m-g3ff.json index d555f772de6..c6452c08322 100644 --- a/advisories/github-reviewed/2021/06/GHSA-89v2-g37m-g3ff/GHSA-89v2-g37m-g3ff.json +++ b/advisories/github-reviewed/2021/06/GHSA-89v2-g37m-g3ff/GHSA-89v2-g37m-g3ff.json @@ -3,14 +3,10 @@ "id": "GHSA-89v2-g37m-g3ff", "modified": "2021-06-01T18:53:10Z", "published": "2021-06-01T21:18:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Verification of Cryptographic Signature in aws-encryption-sdk-cli", "details": "### Impact\n\nThis advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages. \n\nThis ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated. In addition to these signatures, the ESDK uses AES-GCM encryption and all plaintext is verified before being released to a caller. There is no impact on the integrity of the ciphertext or decrypted plaintext, however some callers may rely on the the ECDSA signature for non-repudiation. Without validating the ECDSA signature, an actor with trusted KMS permissions to decrypt a message may also be able to encrypt messages. This update introduces a new API for callers who wish to stream only unsigned messages. \n\nFor customers who process ESDK messages from untrusted sources, this update also introduces a new configuration to limit the number of Encrypted Data Keys (EDKs) that the ESDK will attempt to process per message. This configuration provides customers with a way to limit the number of AWS KMS Decrypt API calls that the ESDK will make per message. This setting will reject messages with more EDKs than the configured limit.\n\nFinally, this update adds early rejection of invalid messages with certain invalid combinations of algorithm suite and header data.\n\n### Patches\n\nFixed in versions 1.9 and 2.2. We recommend that all users upgrade to address these issues.\n\nCustomers leveraging the ESDK’s streaming features have several options to protect signature validation. One is to ensure that client code reads to the end of the stream before using released plaintext. With this release, using the new API for streaming and falling back to the non-streaming decrypt API for signed messages prevents using any plaintext from signed data before the signature is validated. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\nUsers processing ESDK messages from untrusted sources should use the new maximum encrypted data keys parameter. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\n### Workarounds\n\nNone\n\n### For more information\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/concepts.html#digital-sigs\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-8fxc-qm65-vpxg/GHSA-8fxc-qm65-vpxg.json b/advisories/github-reviewed/2021/06/GHSA-8fxc-qm65-vpxg/GHSA-8fxc-qm65-vpxg.json index 7129f0ba5ac..70ecd535be7 100644 --- a/advisories/github-reviewed/2021/06/GHSA-8fxc-qm65-vpxg/GHSA-8fxc-qm65-vpxg.json +++ b/advisories/github-reviewed/2021/06/GHSA-8fxc-qm65-vpxg/GHSA-8fxc-qm65-vpxg.json @@ -8,9 +8,7 @@ ], "summary": "Temporary urls leaked via logging", "details": "In OpenStack Swift prior to 2.15.2, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-9hx4-qm7h-x84j/GHSA-9hx4-qm7h-x84j.json b/advisories/github-reviewed/2021/06/GHSA-9hx4-qm7h-x84j/GHSA-9hx4-qm7h-x84j.json index e4458998584..ee8f8ce161d 100644 --- a/advisories/github-reviewed/2021/06/GHSA-9hx4-qm7h-x84j/GHSA-9hx4-qm7h-x84j.json +++ b/advisories/github-reviewed/2021/06/GHSA-9hx4-qm7h-x84j/GHSA-9hx4-qm7h-x84j.json @@ -8,9 +8,7 @@ ], "summary": "Cross-site Scripting in Gogs", "details": "Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.8 allows remote attackers to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-h45p-w933-jxh3/GHSA-h45p-w933-jxh3.json b/advisories/github-reviewed/2021/06/GHSA-h45p-w933-jxh3/GHSA-h45p-w933-jxh3.json index 1d6c5cc7930..880fdcb7871 100644 --- a/advisories/github-reviewed/2021/06/GHSA-h45p-w933-jxh3/GHSA-h45p-w933-jxh3.json +++ b/advisories/github-reviewed/2021/06/GHSA-h45p-w933-jxh3/GHSA-h45p-w933-jxh3.json @@ -3,14 +3,10 @@ "id": "GHSA-h45p-w933-jxh3", "modified": "2021-06-01T18:59:14Z", "published": "2021-06-01T21:20:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript ", "details": "### Impact\n\nThis advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages. \n\nThis ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated. In addition to these signatures, the ESDK uses AES-GCM encryption and all plaintext is verified before being released to a caller. There is no impact on the integrity of the ciphertext or decrypted plaintext, however some callers may rely on the the ECDSA signature for non-repudiation. Without validating the ECDSA signature, an actor with trusted KMS permissions to decrypt a message may also be able to encrypt messages. This update introduces a new API for callers who wish to stream only unsigned messages. \n\nFor customers who process ESDK messages from untrusted sources, this update also introduces a new configuration to limit the number of Encrypted Data Keys (EDKs) that the ESDK will attempt to process per message. This configuration provides customers with a way to limit the number of AWS KMS Decrypt API calls that the ESDK will make per message. This setting will reject messages with more EDKs than the configured limit.\n\nFinally, this update adds early rejection of invalid messages with certain invalid combinations of algorithm suite and header data.\n\n### Patches\n\nFixed in versions 1.9 and 2.2. We recommend that all users upgrade to address these issues.\n\nCustomers leveraging the ESDK’s streaming features have several options to protect signature validation. One is to ensure that client code reads to the end of the stream before using released plaintext. With this release, using the new API for streaming and falling back to the non-streaming decrypt API for signed messages prevents using any plaintext from signed data before the signature is validated. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\nUsers processing ESDK messages from untrusted sources should use the new maximum encrypted data keys parameter. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\n### Workarounds\n\nNone\n\n### For more information\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/concepts.html#digital-sigs\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-jq42-hfch-42f3/GHSA-jq42-hfch-42f3.json b/advisories/github-reviewed/2021/06/GHSA-jq42-hfch-42f3/GHSA-jq42-hfch-42f3.json index 311e5530a72..8bb802de715 100644 --- a/advisories/github-reviewed/2021/06/GHSA-jq42-hfch-42f3/GHSA-jq42-hfch-42f3.json +++ b/advisories/github-reviewed/2021/06/GHSA-jq42-hfch-42f3/GHSA-jq42-hfch-42f3.json @@ -3,9 +3,7 @@ "id": "GHSA-jq42-hfch-42f3", "modified": "2021-10-05T17:22:08Z", "published": "2021-06-01T21:20:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint", "details": "# Impact\nDue to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint.\n\nAn attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container.\n\nOnly action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint.\n\n# Patches\nAll users should upgrade to Singularity 3.7.4 or later.\n\n# Workarounds\nUsers who only interact with the default remote endpoint or do not use the library:// url are not affected.\n\nInstallations with an execution control list configured to restrict execution to containers signed with specific secure keys are not affected.\n\n# Acknowledgements\nThis issue was found by Mike Frisch and brought to our attention by Sylabs. Sylabs is making a [coordinated disclosure](https://github.com/sylabs/singularity/security/advisories/GHSA-5mv9-q7fq-9394).\n\n# For more information\nGeneral questions about the impact of the advisory can be asked in the:\n\n[Singularity Slack Channel](https://join.slack.com/t/hpcng/shared_invite/zt-qda4h1ls-OP0Uouq6sSmVE6i_0NrWdw)\n[Singularity Mailing List](https://groups.google.com/a/lbl.gov/g/singularity)\nAny sensitive security concerns should be directed to: [singularity-security@hpcng.org](mailto:singularity-security@hpcng.org)\n", "severity": [ diff --git a/advisories/github-reviewed/2021/06/GHSA-m6gx-rhvj-fh52/GHSA-m6gx-rhvj-fh52.json b/advisories/github-reviewed/2021/06/GHSA-m6gx-rhvj-fh52/GHSA-m6gx-rhvj-fh52.json index f65c288236c..8071fd151de 100644 --- a/advisories/github-reviewed/2021/06/GHSA-m6gx-rhvj-fh52/GHSA-m6gx-rhvj-fh52.json +++ b/advisories/github-reviewed/2021/06/GHSA-m6gx-rhvj-fh52/GHSA-m6gx-rhvj-fh52.json @@ -3,14 +3,10 @@ "id": "GHSA-m6gx-rhvj-fh52", "modified": "2021-10-08T21:25:42Z", "published": "2021-06-29T21:13:54Z", - "aliases": [ - - ], + "aliases": [], "summary": "Denial of service in go-ethereum due to CVE-2020-28362", "details": "### Impact\nVersions of Geth built with Go `<1.15.5` or `<1.14.12` are most likely affected by a critical DoS-related security vulnerability. The golang team has registered the underlying flaw as ‘CVE-2020-28362’.\n\nWe recommend all users to rebuild (ideally `v1.9.24`) with Go `1.15.5` or `1.14.12`, to avoid node crashes. Alternatively, if you are running binaries distributed via one of our official channels, we’re going to release `v1.9.24` ourselves built with Go `1.15.5`.\n\n### Patches\nThis is not an issue in go-ethereum, rebuilding an older version with Go `1.15.5` or `1.14.12` will suffice to address the vulnerability. \n\n### Workarounds\nRebuilding with Go `1.15.5` or `1.14.12` will suffice to address the vulnerability. \n\n### References\n- https://blog.ethereum.org/2020/11/12/geth_security_release/\n- https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum)\n* Email us at [security@ethereum.org](mailto:security@ethereum.org)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-05-21T21:49:12Z", diff --git a/advisories/github-reviewed/2021/06/GHSA-r37h-j483-cjjm/GHSA-r37h-j483-cjjm.json b/advisories/github-reviewed/2021/06/GHSA-r37h-j483-cjjm/GHSA-r37h-j483-cjjm.json index a6564d0c22e..a550cf411ae 100644 --- a/advisories/github-reviewed/2021/06/GHSA-r37h-j483-cjjm/GHSA-r37h-j483-cjjm.json +++ b/advisories/github-reviewed/2021/06/GHSA-r37h-j483-cjjm/GHSA-r37h-j483-cjjm.json @@ -8,9 +8,7 @@ ], "summary": "Improper rate limiting in Koel", "details": "Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/06/GHSA-x5h4-9gqw-942j/GHSA-x5h4-9gqw-942j.json b/advisories/github-reviewed/2021/06/GHSA-x5h4-9gqw-942j/GHSA-x5h4-9gqw-942j.json index d528b948e20..ce49c664957 100644 --- a/advisories/github-reviewed/2021/06/GHSA-x5h4-9gqw-942j/GHSA-x5h4-9gqw-942j.json +++ b/advisories/github-reviewed/2021/06/GHSA-x5h4-9gqw-942j/GHSA-x5h4-9gqw-942j.json @@ -3,14 +3,10 @@ "id": "GHSA-x5h4-9gqw-942j", "modified": "2021-06-01T19:12:22Z", "published": "2021-06-01T21:17:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Verification of Cryptographic Signature in aws-encryption-sdk", "details": "### Impact\n\nThis advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages. \n\nThis ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated. In addition to these signatures, the ESDK uses AES-GCM encryption and all plaintext is verified before being released to a caller. There is no impact on the integrity of the ciphertext or decrypted plaintext, however some callers may rely on the the ECDSA signature for non-repudiation. Without validating the ECDSA signature, an actor with trusted KMS permissions to decrypt a message may also be able to encrypt messages. This update introduces a new API for callers who wish to stream only unsigned messages. \n\nFor customers who process ESDK messages from untrusted sources, this update also introduces a new configuration to limit the number of Encrypted Data Keys (EDKs) that the ESDK will attempt to process per message. This configuration provides customers with a way to limit the number of AWS KMS Decrypt API calls that the ESDK will make per message. This setting will reject messages with more EDKs than the configured limit.\n\nFinally, this update adds early rejection of invalid messages with certain invalid combinations of algorithm suite and header data.\n\n### Patches\n\nFixed in versions 1.9 and 2.2. We recommend that all users upgrade to address these issues.\n\nCustomers leveraging the ESDK’s streaming features have several options to protect signature validation. One is to ensure that client code reads to the end of the stream before using released plaintext. With this release, using the new API for streaming and falling back to the non-streaming decrypt API for signed messages prevents using any plaintext from signed data before the signature is validated. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\nUsers processing ESDK messages from untrusted sources should use the new maximum encrypted data keys parameter. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n\n### Workarounds\n\nNone\n\n### For more information\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/concepts.html#digital-sigs\n\nhttps://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/about-versions.html#version2.2.x\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/12/GHSA-f3w5-v9xx-rp8p/GHSA-f3w5-v9xx-rp8p.json b/advisories/github-reviewed/2021/12/GHSA-f3w5-v9xx-rp8p/GHSA-f3w5-v9xx-rp8p.json index f2bf0781293..da9bf90a2cd 100644 --- a/advisories/github-reviewed/2021/12/GHSA-f3w5-v9xx-rp8p/GHSA-f3w5-v9xx-rp8p.json +++ b/advisories/github-reviewed/2021/12/GHSA-f3w5-v9xx-rp8p/GHSA-f3w5-v9xx-rp8p.json @@ -3,14 +3,10 @@ "id": "GHSA-f3w5-v9xx-rp8p", "modified": "2021-05-20T20:10:47Z", "published": "2021-12-20T18:17:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Signature verification failure in Tendermint", "details": "_The root cause of this security vulnerability is in the Tendermint specification, and this advisory is a duplicate of https://github.com/tendermint/spec/security/advisories/GHSA-jqfc-687g-59pw._\n\n\n### Impact\nTendermint light clients running versions 0.34.0 to 0.34.8 are unable to detect and punish a new kind of attack. We’re calling this a “forward lunatic attack,” or FLA. The severity of this vulnerability is _moderate_. \n\nNote that an FLA cannot be successfully executed unless there are already ⅓+ Byzantine validators, and therefore outside of Tendermint’s security model; however, it is important to be able to detect and punish these kinds of attacks in order to incentivize correct behavior.\n\nIn an FLA, an attacking validator (with ⅓+ voting power) signs commit messages for arbitrary application state associated with a block height that hasn’t been seen yet, hence the name “forward lunatic attacks.” A malicious validator effectively executes a [lunatic attack](https://docs.tendermint.com/master/spec/light-client/accountability/#the-misbehavior-of-faulty-validators), but signs messages for a target block that is higher than the current block. This can be dangerous: Typically, misbehavior evidence is only created when there are conflicting blocks at the same height, but by targeting a block height that is far “ahead” of the current chain height, it’s possible that the chain will not produce a (conflicting) block at the target height in time to create evidence. \n\nPrior to Tendermint v0.34.9, the light client could accept a bad header from its primary witness, and would not be able to form evidence of this deception, even if all the secondary witnesses were correct. Because the light client is responsible for verifying cross-chain state for IBC, a successful FLA could result in loss of funds. However, it is important to note that FLAs are only possible outside the Tendermint security model. \n\nAll FLAs, attempted and successful, leave traces of provable misbehavior on-chain. A faulty header contains signatures from the faulty validator, and even in unpatched versions of Tendermint Core, networks could use social consensus (off-chain action) to recover the network. The patches introduced in Tendermint Core v0.34.9 handle all evidence automatically and on-chain. \n\nNote that this fix also allows for successful automatic reporting of FLAs, even after a chain halt. By adding a time to FetchBlock, light clients effectively have a backup way to determine if a halted chain should have continued, and it will be able to submit evidence as soon as the chain resumes. \n\n### Patches\nThis problem has been patched in Tendermint Core v0.34.9. \n\n### Workarounds\nThere are no workarounds. All users are recommended to upgrade to Tendermint Core v0.34.9 at their earliest possible convenience. \n\n### Credits\n\nThank you to @MaximilianDiez for originally surfacing this issue, and to @cmwaters, @josef-widder, and @milosevic for creating fixes at both the implementation and specification level.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [tendermint/tendermint](https://github.com/tendermint/tendermint)\n* Email us at [security@tendermint.com](mailto:security@tendermint.com)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/12/GHSA-g54h-m393-cpwq/GHSA-g54h-m393-cpwq.json b/advisories/github-reviewed/2021/12/GHSA-g54h-m393-cpwq/GHSA-g54h-m393-cpwq.json index 30b0cb42873..5a2f04c99fe 100644 --- a/advisories/github-reviewed/2021/12/GHSA-g54h-m393-cpwq/GHSA-g54h-m393-cpwq.json +++ b/advisories/github-reviewed/2021/12/GHSA-g54h-m393-cpwq/GHSA-g54h-m393-cpwq.json @@ -3,14 +3,10 @@ "id": "GHSA-g54h-m393-cpwq", "modified": "2021-05-24T20:46:53Z", "published": "2021-12-20T18:21:54Z", - "aliases": [ - - ], + "aliases": [], "summary": "devices resource list treated as a blacklist by default", "details": "### Impact\nContrary to the [OCI runtime specification](https://github.com/opencontainers/runtime-spec/blob/v1.0.2/config-linux.md#device-whitelist), `runc`'s implementation of the `linux.resources.devices` list was a black-list by default. This means that users who created their own `config.json` objects and didn't prefix a deny-all rule (`{\"allow\": false, \"permissions\": \"rwm\"}` or equivalent) were not provided protection by the `devices` cgroup. This would allow malicious containers (with sufficient privileges) to create arbitrary device inodes (assuming they have `CAP_MKNOD`) and operate on any device inodes they may have access to (assuming they have regular Unix DAC permissions).\n\nHowever, most (if not all) programs that make use of `runc` include this deny-all rule. This was most likely added before the specification mandated a white-list of devices, and the fact that all programs wrote their own deny-all rule obscured the existence of this bug for several years. In fact, even the specification's examples include a default deny-all rule! We therefore believe that while this is a security bug (and has been fixed as such), it was almost certainly not exploitable in the wild due to the inclusion of default deny-all rules by all known users of `runc` -- hence why this advisory has low severity.\n\n### Patches\nThis issue has been fixed in [a patch that was part of a larger rework of the devices cgroup code in runc](https://github.com/opencontainers/runc/pull/2391) -- which lead to the discovery of this security bug. Users should upgrade to 1.0.0-rc91 as soon as it is released, or wait for your distribution to backport the relevant fixes.\n\n### Workarounds\nIf you are using `runc` directly, ensure that there is a deny-all entry at the beginning of `linux.resources.devices` -- such an entry would look like `{\"allow\": false, \"permissions\": \"rwm\"}` (all other fields are ignored, though `type` must be set to `\"a\"` or `null` if it is present).\n\nUsers which consume `runc` through another program should check whether their containers are operating under a white-list -- this can be done by reading `/sys/fs/cgroup/devices/devices.list` inside the container. If the file contains only the entry `a *:* rwm` (meaning the cgroup is in black-list mode, which likely means \"allow all device access\") then your containers are vulnerable to this issue.\n\nAs always, we recommend **in the strongest possible terms** that all of our users enable user namespaces on all of their workloads (or pressure their vendors to do so). User namespaces are one of the most significant defense-in-depth protections you can enable for containers, and have prevented many container-related vulnerabilities (both kernel 0days as well as bugs in container runtimes, such as this one).\n\n### References\n* https://www.kernel.org/doc/html/latest/admin-guide/cgroup-v1/devices.html\n* [opencontainers/runtime-spec/config-linux.md#device-whitelist](https://github.com/opencontainers/runtime-spec/blob/v1.0.2/config-linux.md#device-whitelist)\n* https://github.com/opencontainers/runc/pull/2391\n\n### For more information\nIf you have any questions or comments about this advisory:\n* [Open an issue in this repo](https://github.com/opencontainers/runc/issues/new).\n* Email us at .", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -42,9 +38,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2021-05-24T20:46:53Z", diff --git a/advisories/github-reviewed/2022/02/GHSA-g7v2-2qxx-wjrw/GHSA-g7v2-2qxx-wjrw.json b/advisories/github-reviewed/2022/02/GHSA-g7v2-2qxx-wjrw/GHSA-g7v2-2qxx-wjrw.json index 4269336438a..0db49b99b81 100644 --- a/advisories/github-reviewed/2022/02/GHSA-g7v2-2qxx-wjrw/GHSA-g7v2-2qxx-wjrw.json +++ b/advisories/github-reviewed/2022/02/GHSA-g7v2-2qxx-wjrw/GHSA-g7v2-2qxx-wjrw.json @@ -8,9 +8,7 @@ ], "summary": "Symlink Attack in Libcontainer and Docker Engine", "details": "Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/02/GHSA-w3wf-cfx3-6gcx/GHSA-w3wf-cfx3-6gcx.json b/advisories/github-reviewed/2022/02/GHSA-w3wf-cfx3-6gcx/GHSA-w3wf-cfx3-6gcx.json index 85a3186172d..4fb98d68816 100644 --- a/advisories/github-reviewed/2022/02/GHSA-w3wf-cfx3-6gcx/GHSA-w3wf-cfx3-6gcx.json +++ b/advisories/github-reviewed/2022/02/GHSA-w3wf-cfx3-6gcx/GHSA-w3wf-cfx3-6gcx.json @@ -8,9 +8,7 @@ ], "summary": "SAML authentication vulnerability due to stdlib XML parsing", "details": "### Impact\nDue to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP.\n\nUsers that configure Fleet with SSO login may be vulnerable to this issue.\n\n### Patches\nThis issue is patched in 3.5.1 using https://github.com/mattermost/xml-roundtrip-validator.\n\n### Workarounds\nIf upgrade to 3.5.1 is not possible, users should disable SSO authentication in Fleet.\n\n### References\nSee https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ for more information about the underlying vulnerabilities.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@fleetdm.com](mailto:security@fleetdm.com)\n* Join #fleet in [osquery Slack](https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEw)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-4793-8wwh-jxxr/GHSA-4793-8wwh-jxxr.json b/advisories/github-reviewed/2022/05/GHSA-4793-8wwh-jxxr/GHSA-4793-8wwh-jxxr.json index 99dc34b449e..76e87f88dec 100644 --- a/advisories/github-reviewed/2022/05/GHSA-4793-8wwh-jxxr/GHSA-4793-8wwh-jxxr.json +++ b/advisories/github-reviewed/2022/05/GHSA-4793-8wwh-jxxr/GHSA-4793-8wwh-jxxr.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-06-06T21:19:22Z", diff --git a/advisories/github-reviewed/2022/08/GHSA-2fvv-qxrq-7jq6/GHSA-2fvv-qxrq-7jq6.json b/advisories/github-reviewed/2022/08/GHSA-2fvv-qxrq-7jq6/GHSA-2fvv-qxrq-7jq6.json index 09664421abc..47c6d0bc14f 100644 --- a/advisories/github-reviewed/2022/08/GHSA-2fvv-qxrq-7jq6/GHSA-2fvv-qxrq-7jq6.json +++ b/advisories/github-reviewed/2022/08/GHSA-2fvv-qxrq-7jq6/GHSA-2fvv-qxrq-7jq6.json @@ -3,14 +3,10 @@ "id": "GHSA-2fvv-qxrq-7jq6", "modified": "2022-08-18T18:55:01Z", "published": "2022-08-18T18:55:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page", "details": "### Impact\n\nThe default landing page contained HTML to display a sample `curl` command which is made visible if the full landing page bundle could not be fetched from Apollo's CDN. The server's URL is directly interpolated into this command inside the browser from `window.location.href`. On some older browsers such as IE11, this value is not URI-encoded. On such browsers, opening a malicious URL pointing at an Apollo Router could cause execution of attacker-controlled JavaScript.\n\nThis only affects Apollo Server with the [default landing page](https://www.apollographql.com/docs/apollo-server/api/plugin/landing-pages/) enabled. Old browsers visiting your server may be affected if ANY of these apply:\n- You do not pass any landing page plugin to the `plugins` option of `new ApolloServer`.\n- You pass `ApolloServerPluginLandingPageLocalDefault()` or `ApolloServerPluginLandingPageProductionDefault()` to the `plugins` option of `new ApolloServer`.\n\nBrowsers visiting your server are NOT affected if ANY of these apply:\n- You pass `ApolloServerPluginLandingPageDisabled()` to the `plugins` option of `new ApolloServer`.\n- You pass `ApolloServerPluginLandingPageGraphQLPlayground()` to the `plugins` option of `new ApolloServer`.\n- You pass a custom plugin implementing the `renderLandingPage` hook to the `plugins` option of `new ApolloServer`.\n\nThis issue was introduced in v3.0.0 when the landing page feature was added.\n\n### Patches\nTo avoid this, the sample `curl` command has been removed in release 3.10.1.\n\n### Workarounds\n\nDisabling the landing page removes the possibility of exploit:\n\n```ts\nimport { ApolloServerPluginLandingPageDisabled } from 'apollo-server-core';\n\nnew ApolloServer({\n plugins: [ApolloServerPluginLandingPageDisabled()],\n // ...\n});\n```\n\n### See also\nA similar issue exists in the landing page of Apollo Router. See the corresponding [Apollo Router security advisory](https://github.com/apollographql/router/security/advisories/GHSA-p5q6-hhww-f999).\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the Apollo Server repository](https://github.com/apollographql/apollo-server/)\n* Email us at [security@apollographql.com](mailto:security@apollographql.com)\n\n### Credits\n\nThis issue was discovered by Adrian Denkiewicz of [Doyensec](https://doyensec.com/research.html).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/08/GHSA-2jq9-6xx7-3h29/GHSA-2jq9-6xx7-3h29.json b/advisories/github-reviewed/2022/08/GHSA-2jq9-6xx7-3h29/GHSA-2jq9-6xx7-3h29.json index 1b94d446de6..f6afff25129 100644 --- a/advisories/github-reviewed/2022/08/GHSA-2jq9-6xx7-3h29/GHSA-2jq9-6xx7-3h29.json +++ b/advisories/github-reviewed/2022/08/GHSA-2jq9-6xx7-3h29/GHSA-2jq9-6xx7-3h29.json @@ -3,14 +3,10 @@ "id": "GHSA-2jq9-6xx7-3h29", "modified": "2023-06-13T22:08:06Z", "published": "2022-08-11T18:10:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "`temporary` makes use of uninitialized memory", "details": "Uninitialized memory is used as a RNG seed in temporary. This has been resolved in the 0.6.4 release. The crate is not intended to be used outside of a testing environment. For a general purpose crate to create temporary directories, [`tempfile`](https://crates.io/crates/tempfile) is an alternative for this crate.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-08-11T18:10:52Z", diff --git a/advisories/github-reviewed/2022/08/GHSA-h864-m8vm-3xvj/GHSA-h864-m8vm-3xvj.json b/advisories/github-reviewed/2022/08/GHSA-h864-m8vm-3xvj/GHSA-h864-m8vm-3xvj.json index 05de7bd48bf..ef89ce18ddf 100644 --- a/advisories/github-reviewed/2022/08/GHSA-h864-m8vm-3xvj/GHSA-h864-m8vm-3xvj.json +++ b/advisories/github-reviewed/2022/08/GHSA-h864-m8vm-3xvj/GHSA-h864-m8vm-3xvj.json @@ -3,14 +3,10 @@ "id": "GHSA-h864-m8vm-3xvj", "modified": "2022-08-18T19:06:39Z", "published": "2022-08-18T19:06:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken", "details": "Ward Beullens found a practical key-recovery attack against Rainbow.\nThe level I parametersets are removed from liboqs starting from version `0.7.2`.\nFind the scientific details in [Breaking Rainbow Takes a Weekend on a Laptop](https://eprint.iacr.org/2022/214).\n\nThis means all the `oqs::sig::Algorithm::RainbowI*` variants are insecure.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-08-18T19:06:39Z", diff --git a/advisories/github-reviewed/2022/08/GHSA-hrjv-pf36-jpmr/GHSA-hrjv-pf36-jpmr.json b/advisories/github-reviewed/2022/08/GHSA-hrjv-pf36-jpmr/GHSA-hrjv-pf36-jpmr.json index b3cdb200d1f..be396d40350 100644 --- a/advisories/github-reviewed/2022/08/GHSA-hrjv-pf36-jpmr/GHSA-hrjv-pf36-jpmr.json +++ b/advisories/github-reviewed/2022/08/GHSA-hrjv-pf36-jpmr/GHSA-hrjv-pf36-jpmr.json @@ -3,14 +3,10 @@ "id": "GHSA-hrjv-pf36-jpmr", "modified": "2022-08-18T19:01:15Z", "published": "2022-08-18T19:01:15Z", - "aliases": [ - - ], + "aliases": [], "summary": "oqs's Post-Quantum Key Encapsulation Mechanism SIKE broken", "details": "Wouter Castryck and Thomas Decru presented an efficient key recovery attack on the SIDH protocol.\nAs a result, the secret key of SIKEp751 can be recovered in a matter of hours.\nThe SIKE and SIDH schemes will be removed from oqs 0.7.2.\n\n[An efficient key recovery attack on SIDH (preliminary version)](https://eprint.iacr.org/2022/975)\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -47,9 +43,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-08-18T19:01:15Z", diff --git a/advisories/github-reviewed/2022/08/GHSA-qrqq-9c63-xfrg/GHSA-qrqq-9c63-xfrg.json b/advisories/github-reviewed/2022/08/GHSA-qrqq-9c63-xfrg/GHSA-qrqq-9c63-xfrg.json index 385169c143c..6c397fbcada 100644 --- a/advisories/github-reviewed/2022/08/GHSA-qrqq-9c63-xfrg/GHSA-qrqq-9c63-xfrg.json +++ b/advisories/github-reviewed/2022/08/GHSA-qrqq-9c63-xfrg/GHSA-qrqq-9c63-xfrg.json @@ -3,14 +3,10 @@ "id": "GHSA-qrqq-9c63-xfrg", "modified": "2022-08-11T15:36:42Z", "published": "2022-08-11T15:36:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "tower-http's improper validation of Windows paths could lead to directory traversal attack", "details": "`tower_http::services::fs::ServeDir` didn't correctly validate Windows paths, meaning paths like `/foo/bar/c:/windows/web/screen/img101.png` would be allowed and respond with the contents of `c:/windows/web/screen/img101.png`. Thus users could potentially read files anywhere on the filesystem.\n\nThis only impacts Windows. Linux and other unix likes are not impacted by this.\n\nSee [tower-http#204] for more details.\n\n[tower-http#204]: https://github.com/tower-rs/tower-http/pull/204\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -79,9 +75,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-08-11T15:36:42Z", diff --git a/advisories/github-reviewed/2023/02/GHSA-hxp2-xqf3-v83h/GHSA-hxp2-xqf3-v83h.json b/advisories/github-reviewed/2023/02/GHSA-hxp2-xqf3-v83h/GHSA-hxp2-xqf3-v83h.json index 02e5f396acc..0e37e7940ba 100644 --- a/advisories/github-reviewed/2023/02/GHSA-hxp2-xqf3-v83h/GHSA-hxp2-xqf3-v83h.json +++ b/advisories/github-reviewed/2023/02/GHSA-hxp2-xqf3-v83h/GHSA-hxp2-xqf3-v83h.json @@ -3,9 +3,7 @@ "id": "GHSA-hxp2-xqf3-v83h", "modified": "2023-06-13T23:50:59Z", "published": "2023-02-07T18:24:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2", "details": "### Impact\n\nWhen attempting to unmarshal a Server Hello request we could attempt to unmarshal into a buffer that was too small. This could result in a panic leading the program to crash.\n\nThis issue could be abused to cause a denial of service.\n\n### Workaround\n\nNone", "severity": [ diff --git a/advisories/github-reviewed/2023/11/GHSA-392c-vjfv-h7wr/GHSA-392c-vjfv-h7wr.json b/advisories/github-reviewed/2023/11/GHSA-392c-vjfv-h7wr/GHSA-392c-vjfv-h7wr.json index 009a2b1e998..0b3240bc32f 100644 --- a/advisories/github-reviewed/2023/11/GHSA-392c-vjfv-h7wr/GHSA-392c-vjfv-h7wr.json +++ b/advisories/github-reviewed/2023/11/GHSA-392c-vjfv-h7wr/GHSA-392c-vjfv-h7wr.json @@ -4,9 +4,7 @@ "modified": "2024-01-10T19:17:39Z", "published": "2023-11-27T12:30:55Z", "withdrawn": "2024-01-10T19:16:30Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: Apache Superset - Elevation of Privilege", "details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-f678-j579-4xf5. This link is maintained to preserve external references.\n\n### Original Description\n\nImproper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially crafted CTE SQL statement could change data on the metadata database. This weakness could result on tampering with the authentication/authorization data.\n\n", "severity": [ diff --git a/advisories/unreviewed/2022/02/GHSA-43rr-wcj9-h45w/GHSA-43rr-wcj9-h45w.json b/advisories/unreviewed/2022/02/GHSA-43rr-wcj9-h45w/GHSA-43rr-wcj9-h45w.json index f84e63b110e..25f187ecfc5 100644 --- a/advisories/unreviewed/2022/02/GHSA-43rr-wcj9-h45w/GHSA-43rr-wcj9-h45w.json +++ b/advisories/unreviewed/2022/02/GHSA-43rr-wcj9-h45w/GHSA-43rr-wcj9-h45w.json @@ -14,9 +14,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rf5r-cr88-cr97/GHSA-rf5r-cr88-cr97.json b/advisories/unreviewed/2022/02/GHSA-rf5r-cr88-cr97/GHSA-rf5r-cr88-cr97.json index 8c7333b915e..e8442722621 100644 --- a/advisories/unreviewed/2022/02/GHSA-rf5r-cr88-cr97/GHSA-rf5r-cr88-cr97.json +++ b/advisories/unreviewed/2022/02/GHSA-rf5r-cr88-cr97/GHSA-rf5r-cr88-cr97.json @@ -14,9 +14,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7x5p-7hrm-m9rp/GHSA-7x5p-7hrm-m9rp.json b/advisories/unreviewed/2022/04/GHSA-7x5p-7hrm-m9rp/GHSA-7x5p-7hrm-m9rp.json index c3cf48ff911..5844c5ba9dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-7x5p-7hrm-m9rp/GHSA-7x5p-7hrm-m9rp.json +++ b/advisories/unreviewed/2022/04/GHSA-7x5p-7hrm-m9rp/GHSA-7x5p-7hrm-m9rp.json @@ -7,12 +7,8 @@ "CVE-2011-1234" ], "details": "Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other \"Vulnerability Type 1\" CVEs listed in MS11-034, aka \"Win32k Use After Free Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2234-4vjh-rwjg/GHSA-2234-4vjh-rwjg.json b/advisories/unreviewed/2022/05/GHSA-2234-4vjh-rwjg/GHSA-2234-4vjh-rwjg.json index 8c02bc78d37..a9ed0fa858d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2234-4vjh-rwjg/GHSA-2234-4vjh-rwjg.json +++ b/advisories/unreviewed/2022/05/GHSA-2234-4vjh-rwjg/GHSA-2234-4vjh-rwjg.json @@ -7,12 +7,8 @@ "CVE-2008-3667" ], "details": "Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-257h-jgf3-638q/GHSA-257h-jgf3-638q.json b/advisories/unreviewed/2022/05/GHSA-257h-jgf3-638q/GHSA-257h-jgf3-638q.json index 2b4ded69129..93120f67e32 100644 --- a/advisories/unreviewed/2022/05/GHSA-257h-jgf3-638q/GHSA-257h-jgf3-638q.json +++ b/advisories/unreviewed/2022/05/GHSA-257h-jgf3-638q/GHSA-257h-jgf3-638q.json @@ -7,12 +7,8 @@ "CVE-2008-3252" ], "details": "Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via a news article containing a large number of lines starting with a period.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2634-g837-vwpm/GHSA-2634-g837-vwpm.json b/advisories/unreviewed/2022/05/GHSA-2634-g837-vwpm/GHSA-2634-g837-vwpm.json index df6a0780f6d..c1ed7483af1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2634-g837-vwpm/GHSA-2634-g837-vwpm.json +++ b/advisories/unreviewed/2022/05/GHSA-2634-g837-vwpm/GHSA-2634-g837-vwpm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26m8-fjr7-qf85/GHSA-26m8-fjr7-qf85.json b/advisories/unreviewed/2022/05/GHSA-26m8-fjr7-qf85/GHSA-26m8-fjr7-qf85.json index 41552e537b9..3a0007aba9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-26m8-fjr7-qf85/GHSA-26m8-fjr7-qf85.json +++ b/advisories/unreviewed/2022/05/GHSA-26m8-fjr7-qf85/GHSA-26m8-fjr7-qf85.json @@ -7,12 +7,8 @@ "CVE-2008-3465" ], "details": "Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka \"GDI Heap Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28jm-hff2-853w/GHSA-28jm-hff2-853w.json b/advisories/unreviewed/2022/05/GHSA-28jm-hff2-853w/GHSA-28jm-hff2-853w.json index 82a9988dc55..c7db5e04040 100644 --- a/advisories/unreviewed/2022/05/GHSA-28jm-hff2-853w/GHSA-28jm-hff2-853w.json +++ b/advisories/unreviewed/2022/05/GHSA-28jm-hff2-853w/GHSA-28jm-hff2-853w.json @@ -7,12 +7,8 @@ "CVE-2008-3675" ], "details": "Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29rc-j772-rjx8/GHSA-29rc-j772-rjx8.json b/advisories/unreviewed/2022/05/GHSA-29rc-j772-rjx8/GHSA-29rc-j772-rjx8.json index 724903fe828..b431b03155d 100644 --- a/advisories/unreviewed/2022/05/GHSA-29rc-j772-rjx8/GHSA-29rc-j772-rjx8.json +++ b/advisories/unreviewed/2022/05/GHSA-29rc-j772-rjx8/GHSA-29rc-j772-rjx8.json @@ -7,12 +7,8 @@ "CVE-2008-3629" ], "details": "Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29rf-p7cr-3mg7/GHSA-29rf-p7cr-3mg7.json b/advisories/unreviewed/2022/05/GHSA-29rf-p7cr-3mg7/GHSA-29rf-p7cr-3mg7.json index 236cc9b9d10..bf7eb700eb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-29rf-p7cr-3mg7/GHSA-29rf-p7cr-3mg7.json +++ b/advisories/unreviewed/2022/05/GHSA-29rf-p7cr-3mg7/GHSA-29rf-p7cr-3mg7.json @@ -7,12 +7,8 @@ "CVE-2008-3785" ], "details": "Multiple SQL injection vulnerabilities in the com_content component in MiaCMS 4.6.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) view, (2) category, or (3) blogsection action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c8r-x33h-7828/GHSA-2c8r-x33h-7828.json b/advisories/unreviewed/2022/05/GHSA-2c8r-x33h-7828/GHSA-2c8r-x33h-7828.json index bd180eef995..30a2d47f853 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c8r-x33h-7828/GHSA-2c8r-x33h-7828.json +++ b/advisories/unreviewed/2022/05/GHSA-2c8r-x33h-7828/GHSA-2c8r-x33h-7828.json @@ -7,12 +7,8 @@ "CVE-2008-3715" ], "details": "Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f4q-m35h-pw25/GHSA-2f4q-m35h-pw25.json b/advisories/unreviewed/2022/05/GHSA-2f4q-m35h-pw25/GHSA-2f4q-m35h-pw25.json index 304c152b79c..3a813c2af3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f4q-m35h-pw25/GHSA-2f4q-m35h-pw25.json +++ b/advisories/unreviewed/2022/05/GHSA-2f4q-m35h-pw25/GHSA-2f4q-m35h-pw25.json @@ -7,12 +7,8 @@ "CVE-2008-3547" ], "details": "Buffer overflow in the server in OpenTTD 0.6.1 and earlier allows remote authenticated users to cause a denial of service (persistent game disruption) or possibly execute arbitrary code via vectors involving many long names for \"companies and clients.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fvc-ghrc-w588/GHSA-2fvc-ghrc-w588.json b/advisories/unreviewed/2022/05/GHSA-2fvc-ghrc-w588/GHSA-2fvc-ghrc-w588.json index 269bd643bec..a4505db8573 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fvc-ghrc-w588/GHSA-2fvc-ghrc-w588.json +++ b/advisories/unreviewed/2022/05/GHSA-2fvc-ghrc-w588/GHSA-2fvc-ghrc-w588.json @@ -7,12 +7,8 @@ "CVE-2008-3783" ], "details": "Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gfx-p78c-mv7h/GHSA-2gfx-p78c-mv7h.json b/advisories/unreviewed/2022/05/GHSA-2gfx-p78c-mv7h/GHSA-2gfx-p78c-mv7h.json index 9a83096231d..841583ca5ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gfx-p78c-mv7h/GHSA-2gfx-p78c-mv7h.json +++ b/advisories/unreviewed/2022/05/GHSA-2gfx-p78c-mv7h/GHSA-2gfx-p78c-mv7h.json @@ -7,12 +7,8 @@ "CVE-2008-3660" ], "details": "PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h3w-9mqf-3gfh/GHSA-2h3w-9mqf-3gfh.json b/advisories/unreviewed/2022/05/GHSA-2h3w-9mqf-3gfh/GHSA-2h3w-9mqf-3gfh.json index 7a07249e7f0..f098de251ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h3w-9mqf-3gfh/GHSA-2h3w-9mqf-3gfh.json +++ b/advisories/unreviewed/2022/05/GHSA-2h3w-9mqf-3gfh/GHSA-2h3w-9mqf-3gfh.json @@ -7,12 +7,8 @@ "CVE-2008-3230" ], "details": "The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h7p-vfr5-8mvf/GHSA-2h7p-vfr5-8mvf.json b/advisories/unreviewed/2022/05/GHSA-2h7p-vfr5-8mvf/GHSA-2h7p-vfr5-8mvf.json index 2e89731c533..2943c882955 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h7p-vfr5-8mvf/GHSA-2h7p-vfr5-8mvf.json +++ b/advisories/unreviewed/2022/05/GHSA-2h7p-vfr5-8mvf/GHSA-2h7p-vfr5-8mvf.json @@ -7,12 +7,8 @@ "CVE-2008-3386" ], "details": "SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the UID parameter, a different vector than CVE-2007-4086.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m97-x65p-qfv6/GHSA-2m97-x65p-qfv6.json b/advisories/unreviewed/2022/05/GHSA-2m97-x65p-qfv6/GHSA-2m97-x65p-qfv6.json index 1567ffae6b9..6b9a7b2bcf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m97-x65p-qfv6/GHSA-2m97-x65p-qfv6.json +++ b/advisories/unreviewed/2022/05/GHSA-2m97-x65p-qfv6/GHSA-2m97-x65p-qfv6.json @@ -7,12 +7,8 @@ "CVE-2008-3599" ], "details": "SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pp8-6rm9-qr6v/GHSA-2pp8-6rm9-qr6v.json b/advisories/unreviewed/2022/05/GHSA-2pp8-6rm9-qr6v/GHSA-2pp8-6rm9-qr6v.json index 6cd378daf49..9a6228b8ebd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pp8-6rm9-qr6v/GHSA-2pp8-6rm9-qr6v.json +++ b/advisories/unreviewed/2022/05/GHSA-2pp8-6rm9-qr6v/GHSA-2pp8-6rm9-qr6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2pwh-3g57-fmcq/GHSA-2pwh-3g57-fmcq.json b/advisories/unreviewed/2022/05/GHSA-2pwh-3g57-fmcq/GHSA-2pwh-3g57-fmcq.json index 0238a75031e..f52acd22039 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pwh-3g57-fmcq/GHSA-2pwh-3g57-fmcq.json +++ b/advisories/unreviewed/2022/05/GHSA-2pwh-3g57-fmcq/GHSA-2pwh-3g57-fmcq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rmx-8hf9-hm7v/GHSA-2rmx-8hf9-hm7v.json b/advisories/unreviewed/2022/05/GHSA-2rmx-8hf9-hm7v/GHSA-2rmx-8hf9-hm7v.json index 070ee4df25c..1c279ad5fc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rmx-8hf9-hm7v/GHSA-2rmx-8hf9-hm7v.json +++ b/advisories/unreviewed/2022/05/GHSA-2rmx-8hf9-hm7v/GHSA-2rmx-8hf9-hm7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rrj-r6g7-f5gj/GHSA-2rrj-r6g7-f5gj.json b/advisories/unreviewed/2022/05/GHSA-2rrj-r6g7-f5gj/GHSA-2rrj-r6g7-f5gj.json index 99cae6ca8a1..1fd3a83bcd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rrj-r6g7-f5gj/GHSA-2rrj-r6g7-f5gj.json +++ b/advisories/unreviewed/2022/05/GHSA-2rrj-r6g7-f5gj/GHSA-2rrj-r6g7-f5gj.json @@ -7,12 +7,8 @@ "CVE-2008-3514" ], "details": "VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side \"enabled/disabled functionality\" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an \"attempt to assign permissions to other system users.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v6g-j89f-4p2g/GHSA-2v6g-j89f-4p2g.json b/advisories/unreviewed/2022/05/GHSA-2v6g-j89f-4p2g/GHSA-2v6g-j89f-4p2g.json index 6e573c38a79..a2bf9f09329 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v6g-j89f-4p2g/GHSA-2v6g-j89f-4p2g.json +++ b/advisories/unreviewed/2022/05/GHSA-2v6g-j89f-4p2g/GHSA-2v6g-j89f-4p2g.json @@ -7,12 +7,8 @@ "CVE-2008-3330" ], "details": "Cross-site scripting (XSS) vulnerability in services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote attackers to inject arbitrary web script or HTML via the contact name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v8f-3jfm-64p5/GHSA-2v8f-3jfm-64p5.json b/advisories/unreviewed/2022/05/GHSA-2v8f-3jfm-64p5/GHSA-2v8f-3jfm-64p5.json index bf230cb97f3..53228a566e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v8f-3jfm-64p5/GHSA-2v8f-3jfm-64p5.json +++ b/advisories/unreviewed/2022/05/GHSA-2v8f-3jfm-64p5/GHSA-2v8f-3jfm-64p5.json @@ -7,12 +7,8 @@ "CVE-2008-3217" ], "details": "PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w89-g5fw-9c76/GHSA-2w89-g5fw-9c76.json b/advisories/unreviewed/2022/05/GHSA-2w89-g5fw-9c76/GHSA-2w89-g5fw-9c76.json index 215b9f80465..017f62c1245 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w89-g5fw-9c76/GHSA-2w89-g5fw-9c76.json +++ b/advisories/unreviewed/2022/05/GHSA-2w89-g5fw-9c76/GHSA-2w89-g5fw-9c76.json @@ -7,12 +7,8 @@ "CVE-2008-3368" ], "details": "PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wgr-66p6-6x84/GHSA-2wgr-66p6-6x84.json b/advisories/unreviewed/2022/05/GHSA-2wgr-66p6-6x84/GHSA-2wgr-66p6-6x84.json index e38b88a29fa..4cb81859135 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wgr-66p6-6x84/GHSA-2wgr-66p6-6x84.json +++ b/advisories/unreviewed/2022/05/GHSA-2wgr-66p6-6x84/GHSA-2wgr-66p6-6x84.json @@ -7,12 +7,8 @@ "CVE-2008-3505" ], "details": "Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-322f-wqw7-87q6/GHSA-322f-wqw7-87q6.json b/advisories/unreviewed/2022/05/GHSA-322f-wqw7-87q6/GHSA-322f-wqw7-87q6.json index 7d5f330906e..1bc965fd044 100644 --- a/advisories/unreviewed/2022/05/GHSA-322f-wqw7-87q6/GHSA-322f-wqw7-87q6.json +++ b/advisories/unreviewed/2022/05/GHSA-322f-wqw7-87q6/GHSA-322f-wqw7-87q6.json @@ -7,12 +7,8 @@ "CVE-2008-3402" ], "details": "Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-329c-2fc2-h43q/GHSA-329c-2fc2-h43q.json b/advisories/unreviewed/2022/05/GHSA-329c-2fc2-h43q/GHSA-329c-2fc2-h43q.json index d3478cfc41a..4210735a323 100644 --- a/advisories/unreviewed/2022/05/GHSA-329c-2fc2-h43q/GHSA-329c-2fc2-h43q.json +++ b/advisories/unreviewed/2022/05/GHSA-329c-2fc2-h43q/GHSA-329c-2fc2-h43q.json @@ -7,12 +7,8 @@ "CVE-2008-3243" ], "details": "Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an ASPack-compressed file, which triggers an engine crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-329x-5gjj-9v6c/GHSA-329x-5gjj-9v6c.json b/advisories/unreviewed/2022/05/GHSA-329x-5gjj-9v6c/GHSA-329x-5gjj-9v6c.json index 2a0744ae464..69d78f71468 100644 --- a/advisories/unreviewed/2022/05/GHSA-329x-5gjj-9v6c/GHSA-329x-5gjj-9v6c.json +++ b/advisories/unreviewed/2022/05/GHSA-329x-5gjj-9v6c/GHSA-329x-5gjj-9v6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32m2-5wjp-2hcg/GHSA-32m2-5wjp-2hcg.json b/advisories/unreviewed/2022/05/GHSA-32m2-5wjp-2hcg/GHSA-32m2-5wjp-2hcg.json index 73fa103ee78..63ad82942fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-32m2-5wjp-2hcg/GHSA-32m2-5wjp-2hcg.json +++ b/advisories/unreviewed/2022/05/GHSA-32m2-5wjp-2hcg/GHSA-32m2-5wjp-2hcg.json @@ -7,12 +7,8 @@ "CVE-2008-3332" ], "details": "Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32w3-h3vm-6rj2/GHSA-32w3-h3vm-6rj2.json b/advisories/unreviewed/2022/05/GHSA-32w3-h3vm-6rj2/GHSA-32w3-h3vm-6rj2.json index 39e2cb8e49c..19acaa05060 100644 --- a/advisories/unreviewed/2022/05/GHSA-32w3-h3vm-6rj2/GHSA-32w3-h3vm-6rj2.json +++ b/advisories/unreviewed/2022/05/GHSA-32w3-h3vm-6rj2/GHSA-32w3-h3vm-6rj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32wh-5vv8-c8px/GHSA-32wh-5vv8-c8px.json b/advisories/unreviewed/2022/05/GHSA-32wh-5vv8-c8px/GHSA-32wh-5vv8-c8px.json index 74b04f6e997..4f1460b6517 100644 --- a/advisories/unreviewed/2022/05/GHSA-32wh-5vv8-c8px/GHSA-32wh-5vv8-c8px.json +++ b/advisories/unreviewed/2022/05/GHSA-32wh-5vv8-c8px/GHSA-32wh-5vv8-c8px.json @@ -7,12 +7,8 @@ "CVE-2008-3387" ], "details": "SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3354-gp3f-v5mx/GHSA-3354-gp3f-v5mx.json b/advisories/unreviewed/2022/05/GHSA-3354-gp3f-v5mx/GHSA-3354-gp3f-v5mx.json index acfbb5737ab..ba9a8777f4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3354-gp3f-v5mx/GHSA-3354-gp3f-v5mx.json +++ b/advisories/unreviewed/2022/05/GHSA-3354-gp3f-v5mx/GHSA-3354-gp3f-v5mx.json @@ -7,12 +7,8 @@ "CVE-2008-3429" ], "details": "Buffer overflow in URI processing in HTTrack and WinHTTrack before 3.42-3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33jf-4rqx-933q/GHSA-33jf-4rqx-933q.json b/advisories/unreviewed/2022/05/GHSA-33jf-4rqx-933q/GHSA-33jf-4rqx-933q.json index 272e5ef7afd..7243eb632b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-33jf-4rqx-933q/GHSA-33jf-4rqx-933q.json +++ b/advisories/unreviewed/2022/05/GHSA-33jf-4rqx-933q/GHSA-33jf-4rqx-933q.json @@ -7,12 +7,8 @@ "CVE-2008-3259" ], "details": "OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-353r-5p99-mj3w/GHSA-353r-5p99-mj3w.json b/advisories/unreviewed/2022/05/GHSA-353r-5p99-mj3w/GHSA-353r-5p99-mj3w.json index b7cb34dee63..3fa63540a6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-353r-5p99-mj3w/GHSA-353r-5p99-mj3w.json +++ b/advisories/unreviewed/2022/05/GHSA-353r-5p99-mj3w/GHSA-353r-5p99-mj3w.json @@ -7,12 +7,8 @@ "CVE-2008-3759" ], "details": "Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-359h-2745-5v76/GHSA-359h-2745-5v76.json b/advisories/unreviewed/2022/05/GHSA-359h-2745-5v76/GHSA-359h-2745-5v76.json index 6e6634031f9..7d6d2406712 100644 --- a/advisories/unreviewed/2022/05/GHSA-359h-2745-5v76/GHSA-359h-2745-5v76.json +++ b/advisories/unreviewed/2022/05/GHSA-359h-2745-5v76/GHSA-359h-2745-5v76.json @@ -7,12 +7,8 @@ "CVE-2008-3454" ], "details": "JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the \"adm\" cookie value to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35hv-q2xv-q24x/GHSA-35hv-q2xv-q24x.json b/advisories/unreviewed/2022/05/GHSA-35hv-q2xv-q24x/GHSA-35hv-q2xv-q24x.json index 004c5a5f8da..e7bc9e5d4ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-35hv-q2xv-q24x/GHSA-35hv-q2xv-q24x.json +++ b/advisories/unreviewed/2022/05/GHSA-35hv-q2xv-q24x/GHSA-35hv-q2xv-q24x.json @@ -7,12 +7,8 @@ "CVE-2008-3362" ], "details": "Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-363p-mgpx-cphf/GHSA-363p-mgpx-cphf.json b/advisories/unreviewed/2022/05/GHSA-363p-mgpx-cphf/GHSA-363p-mgpx-cphf.json index d00c8bdfbc5..b136ed27e38 100644 --- a/advisories/unreviewed/2022/05/GHSA-363p-mgpx-cphf/GHSA-363p-mgpx-cphf.json +++ b/advisories/unreviewed/2022/05/GHSA-363p-mgpx-cphf/GHSA-363p-mgpx-cphf.json @@ -7,12 +7,8 @@ "CVE-2008-3648" ], "details": "nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38vp-pppf-865m/GHSA-38vp-pppf-865m.json b/advisories/unreviewed/2022/05/GHSA-38vp-pppf-865m/GHSA-38vp-pppf-865m.json index 55f7af74540..1dd92f644d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-38vp-pppf-865m/GHSA-38vp-pppf-865m.json +++ b/advisories/unreviewed/2022/05/GHSA-38vp-pppf-865m/GHSA-38vp-pppf-865m.json @@ -7,12 +7,8 @@ "CVE-2008-3662" ], "details": "Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-398v-5g69-w972/GHSA-398v-5g69-w972.json b/advisories/unreviewed/2022/05/GHSA-398v-5g69-w972/GHSA-398v-5g69-w972.json index 2d98b63c246..8f2fd796a30 100644 --- a/advisories/unreviewed/2022/05/GHSA-398v-5g69-w972/GHSA-398v-5g69-w972.json +++ b/advisories/unreviewed/2022/05/GHSA-398v-5g69-w972/GHSA-398v-5g69-w972.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39rg-8h92-xq56/GHSA-39rg-8h92-xq56.json b/advisories/unreviewed/2022/05/GHSA-39rg-8h92-xq56/GHSA-39rg-8h92-xq56.json index 7c03dd03b48..9433d80ccaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-39rg-8h92-xq56/GHSA-39rg-8h92-xq56.json +++ b/advisories/unreviewed/2022/05/GHSA-39rg-8h92-xq56/GHSA-39rg-8h92-xq56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c25-qgc5-wqhf/GHSA-3c25-qgc5-wqhf.json b/advisories/unreviewed/2022/05/GHSA-3c25-qgc5-wqhf/GHSA-3c25-qgc5-wqhf.json index c5b418da707..c3167816bd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c25-qgc5-wqhf/GHSA-3c25-qgc5-wqhf.json +++ b/advisories/unreviewed/2022/05/GHSA-3c25-qgc5-wqhf/GHSA-3c25-qgc5-wqhf.json @@ -7,12 +7,8 @@ "CVE-2008-3262" ], "details": "Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirement for the previous password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cgx-ccxm-mmrm/GHSA-3cgx-ccxm-mmrm.json b/advisories/unreviewed/2022/05/GHSA-3cgx-ccxm-mmrm/GHSA-3cgx-ccxm-mmrm.json index 61024bcef5f..80af394dc8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cgx-ccxm-mmrm/GHSA-3cgx-ccxm-mmrm.json +++ b/advisories/unreviewed/2022/05/GHSA-3cgx-ccxm-mmrm/GHSA-3cgx-ccxm-mmrm.json @@ -7,12 +7,8 @@ "CVE-2008-3682" ], "details": "SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cqf-vpcc-4f22/GHSA-3cqf-vpcc-4f22.json b/advisories/unreviewed/2022/05/GHSA-3cqf-vpcc-4f22/GHSA-3cqf-vpcc-4f22.json index f5d285007f0..fb2af34f1c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cqf-vpcc-4f22/GHSA-3cqf-vpcc-4f22.json +++ b/advisories/unreviewed/2022/05/GHSA-3cqf-vpcc-4f22/GHSA-3cqf-vpcc-4f22.json @@ -7,12 +7,8 @@ "CVE-2008-3244" ], "details": "The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fr5-4pxq-h7qw/GHSA-3fr5-4pxq-h7qw.json b/advisories/unreviewed/2022/05/GHSA-3fr5-4pxq-h7qw/GHSA-3fr5-4pxq-h7qw.json index 7f77ec197e5..ae423ac13e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fr5-4pxq-h7qw/GHSA-3fr5-4pxq-h7qw.json +++ b/advisories/unreviewed/2022/05/GHSA-3fr5-4pxq-h7qw/GHSA-3fr5-4pxq-h7qw.json @@ -7,12 +7,8 @@ "CVE-2008-2249" ], "details": "Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka \"GDI Integer Overflow Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g32-62rm-7wvw/GHSA-3g32-62rm-7wvw.json b/advisories/unreviewed/2022/05/GHSA-3g32-62rm-7wvw/GHSA-3g32-62rm-7wvw.json index c5e9cf69ded..4e8e7ad5604 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g32-62rm-7wvw/GHSA-3g32-62rm-7wvw.json +++ b/advisories/unreviewed/2022/05/GHSA-3g32-62rm-7wvw/GHSA-3g32-62rm-7wvw.json @@ -7,12 +7,8 @@ "CVE-2008-3437" ], "details": "OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g9j-3prp-r5vg/GHSA-3g9j-3prp-r5vg.json b/advisories/unreviewed/2022/05/GHSA-3g9j-3prp-r5vg/GHSA-3g9j-3prp-r5vg.json index c32e957b8da..14f8a66bd3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g9j-3prp-r5vg/GHSA-3g9j-3prp-r5vg.json +++ b/advisories/unreviewed/2022/05/GHSA-3g9j-3prp-r5vg/GHSA-3g9j-3prp-r5vg.json @@ -7,12 +7,8 @@ "CVE-2008-3304" ], "details": "BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gcp-2ghh-2fp8/GHSA-3gcp-2ghh-2fp8.json b/advisories/unreviewed/2022/05/GHSA-3gcp-2ghh-2fp8/GHSA-3gcp-2ghh-2fp8.json index 8d4a89f7a46..7e0bf563eda 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gcp-2ghh-2fp8/GHSA-3gcp-2ghh-2fp8.json +++ b/advisories/unreviewed/2022/05/GHSA-3gcp-2ghh-2fp8/GHSA-3gcp-2ghh-2fp8.json @@ -7,12 +7,8 @@ "CVE-2008-3623" ], "details": "Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3m35-p3mj-c67q/GHSA-3m35-p3mj-c67q.json b/advisories/unreviewed/2022/05/GHSA-3m35-p3mj-c67q/GHSA-3m35-p3mj-c67q.json index d56c0865815..e507a9e5214 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m35-p3mj-c67q/GHSA-3m35-p3mj-c67q.json +++ b/advisories/unreviewed/2022/05/GHSA-3m35-p3mj-c67q/GHSA-3m35-p3mj-c67q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mc3-5mhp-vcrq/GHSA-3mc3-5mhp-vcrq.json b/advisories/unreviewed/2022/05/GHSA-3mc3-5mhp-vcrq/GHSA-3mc3-5mhp-vcrq.json index d8d1b1b8c3c..27fb650f62b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mc3-5mhp-vcrq/GHSA-3mc3-5mhp-vcrq.json +++ b/advisories/unreviewed/2022/05/GHSA-3mc3-5mhp-vcrq/GHSA-3mc3-5mhp-vcrq.json @@ -7,12 +7,8 @@ "CVE-2008-3418" ], "details": "SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mjh-87v6-2677/GHSA-3mjh-87v6-2677.json b/advisories/unreviewed/2022/05/GHSA-3mjh-87v6-2677/GHSA-3mjh-87v6-2677.json index 3fdb0d67851..33db14d702d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mjh-87v6-2677/GHSA-3mjh-87v6-2677.json +++ b/advisories/unreviewed/2022/05/GHSA-3mjh-87v6-2677/GHSA-3mjh-87v6-2677.json @@ -7,12 +7,8 @@ "CVE-2008-3605" ], "details": "Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mjw-wv6f-4q2v/GHSA-3mjw-wv6f-4q2v.json b/advisories/unreviewed/2022/05/GHSA-3mjw-wv6f-4q2v/GHSA-3mjw-wv6f-4q2v.json index 9899a9fa2e3..0b70b1b69f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mjw-wv6f-4q2v/GHSA-3mjw-wv6f-4q2v.json +++ b/advisories/unreviewed/2022/05/GHSA-3mjw-wv6f-4q2v/GHSA-3mjw-wv6f-4q2v.json @@ -7,12 +7,8 @@ "CVE-2008-3349" ], "details": "Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3p8g-7gxj-j8h5/GHSA-3p8g-7gxj-j8h5.json b/advisories/unreviewed/2022/05/GHSA-3p8g-7gxj-j8h5/GHSA-3p8g-7gxj-j8h5.json index c23a305bddc..7c55dbc61f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p8g-7gxj-j8h5/GHSA-3p8g-7gxj-j8h5.json +++ b/advisories/unreviewed/2022/05/GHSA-3p8g-7gxj-j8h5/GHSA-3p8g-7gxj-j8h5.json @@ -7,12 +7,8 @@ "CVE-2008-3632" ], "details": "Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3pxh-9xmr-22jr/GHSA-3pxh-9xmr-22jr.json b/advisories/unreviewed/2022/05/GHSA-3pxh-9xmr-22jr/GHSA-3pxh-9xmr-22jr.json index 13efc542329..8c5e5ba872b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pxh-9xmr-22jr/GHSA-3pxh-9xmr-22jr.json +++ b/advisories/unreviewed/2022/05/GHSA-3pxh-9xmr-22jr/GHSA-3pxh-9xmr-22jr.json @@ -7,12 +7,8 @@ "CVE-2008-3358" ], "details": "Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in a text/plain document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qh3-9c67-f35w/GHSA-3qh3-9c67-f35w.json b/advisories/unreviewed/2022/05/GHSA-3qh3-9c67-f35w/GHSA-3qh3-9c67-f35w.json index 4778d11cb47..c613063298a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qh3-9c67-f35w/GHSA-3qh3-9c67-f35w.json +++ b/advisories/unreviewed/2022/05/GHSA-3qh3-9c67-f35w/GHSA-3qh3-9c67-f35w.json @@ -7,12 +7,8 @@ "CVE-2008-3490" ], "details": "SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qvw-gq22-wm46/GHSA-3qvw-gq22-wm46.json b/advisories/unreviewed/2022/05/GHSA-3qvw-gq22-wm46/GHSA-3qvw-gq22-wm46.json index 12683f0f497..edbb7511ad7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qvw-gq22-wm46/GHSA-3qvw-gq22-wm46.json +++ b/advisories/unreviewed/2022/05/GHSA-3qvw-gq22-wm46/GHSA-3qvw-gq22-wm46.json @@ -7,12 +7,8 @@ "CVE-2008-3247" ], "details": "The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x86_64 platforms uses an incorrect size for ldt_desc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rm2-x64w-wcx9/GHSA-3rm2-x64w-wcx9.json b/advisories/unreviewed/2022/05/GHSA-3rm2-x64w-wcx9/GHSA-3rm2-x64w-wcx9.json index 6ed11410acb..6f77027f6b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rm2-x64w-wcx9/GHSA-3rm2-x64w-wcx9.json +++ b/advisories/unreviewed/2022/05/GHSA-3rm2-x64w-wcx9/GHSA-3rm2-x64w-wcx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rqq-g39w-52xw/GHSA-3rqq-g39w-52xw.json b/advisories/unreviewed/2022/05/GHSA-3rqq-g39w-52xw/GHSA-3rqq-g39w-52xw.json index 8c0989c2f07..157f0b319dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rqq-g39w-52xw/GHSA-3rqq-g39w-52xw.json +++ b/advisories/unreviewed/2022/05/GHSA-3rqq-g39w-52xw/GHSA-3rqq-g39w-52xw.json @@ -7,12 +7,8 @@ "CVE-2008-3472" ], "details": "Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka \"HTML Element Cross-Domain Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vcx-x6r7-phpm/GHSA-3vcx-x6r7-phpm.json b/advisories/unreviewed/2022/05/GHSA-3vcx-x6r7-phpm/GHSA-3vcx-x6r7-phpm.json index a6d6a720b01..37f542c9a10 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vcx-x6r7-phpm/GHSA-3vcx-x6r7-phpm.json +++ b/advisories/unreviewed/2022/05/GHSA-3vcx-x6r7-phpm/GHSA-3vcx-x6r7-phpm.json @@ -7,12 +7,8 @@ "CVE-2008-3369" ], "details": "SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w6m-x2x7-982w/GHSA-3w6m-x2x7-982w.json b/advisories/unreviewed/2022/05/GHSA-3w6m-x2x7-982w/GHSA-3w6m-x2x7-982w.json index 777e6caec86..93ab6ef14cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w6m-x2x7-982w/GHSA-3w6m-x2x7-982w.json +++ b/advisories/unreviewed/2022/05/GHSA-3w6m-x2x7-982w/GHSA-3w6m-x2x7-982w.json @@ -7,12 +7,8 @@ "CVE-2008-3296" ], "details": "Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wc8-mxpj-88pj/GHSA-3wc8-mxpj-88pj.json b/advisories/unreviewed/2022/05/GHSA-3wc8-mxpj-88pj/GHSA-3wc8-mxpj-88pj.json index e15e56151b8..1daa4a92133 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wc8-mxpj-88pj/GHSA-3wc8-mxpj-88pj.json +++ b/advisories/unreviewed/2022/05/GHSA-3wc8-mxpj-88pj/GHSA-3wc8-mxpj-88pj.json @@ -7,12 +7,8 @@ "CVE-2008-3593" ], "details": "Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xc7-4mq4-jmpm/GHSA-3xc7-4mq4-jmpm.json b/advisories/unreviewed/2022/05/GHSA-3xc7-4mq4-jmpm/GHSA-3xc7-4mq4-jmpm.json index b2ac65a1d6f..920025d4394 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xc7-4mq4-jmpm/GHSA-3xc7-4mq4-jmpm.json +++ b/advisories/unreviewed/2022/05/GHSA-3xc7-4mq4-jmpm/GHSA-3xc7-4mq4-jmpm.json @@ -7,12 +7,8 @@ "CVE-2008-3342" ], "details": "Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xcf-9p2f-mwqh/GHSA-3xcf-9p2f-mwqh.json b/advisories/unreviewed/2022/05/GHSA-3xcf-9p2f-mwqh/GHSA-3xcf-9p2f-mwqh.json index bb302ef5247..72b0ca64cc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xcf-9p2f-mwqh/GHSA-3xcf-9p2f-mwqh.json +++ b/advisories/unreviewed/2022/05/GHSA-3xcf-9p2f-mwqh/GHSA-3xcf-9p2f-mwqh.json @@ -7,12 +7,8 @@ "CVE-2008-3407" ], "details": "phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-439r-h9j7-hfrj/GHSA-439r-h9j7-hfrj.json b/advisories/unreviewed/2022/05/GHSA-439r-h9j7-hfrj/GHSA-439r-h9j7-hfrj.json index 06e9d8bdba0..f790a9c12b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-439r-h9j7-hfrj/GHSA-439r-h9j7-hfrj.json +++ b/advisories/unreviewed/2022/05/GHSA-439r-h9j7-hfrj/GHSA-439r-h9j7-hfrj.json @@ -7,12 +7,8 @@ "CVE-2008-3297" ], "details": "Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL commands via (1) an se_user cookie to include/class_user.php or (2) an se_admin cookie to include/class_admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43mj-hmh5-f55h/GHSA-43mj-hmh5-f55h.json b/advisories/unreviewed/2022/05/GHSA-43mj-hmh5-f55h/GHSA-43mj-hmh5-f55h.json index facbc05236e..72a6fc4bc1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-43mj-hmh5-f55h/GHSA-43mj-hmh5-f55h.json +++ b/advisories/unreviewed/2022/05/GHSA-43mj-hmh5-f55h/GHSA-43mj-hmh5-f55h.json @@ -7,12 +7,8 @@ "CVE-2008-3333" ], "details": "Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45jr-jmpw-3gj4/GHSA-45jr-jmpw-3gj4.json b/advisories/unreviewed/2022/05/GHSA-45jr-jmpw-3gj4/GHSA-45jr-jmpw-3gj4.json index 10b65fa8069..f181511d387 100644 --- a/advisories/unreviewed/2022/05/GHSA-45jr-jmpw-3gj4/GHSA-45jr-jmpw-3gj4.json +++ b/advisories/unreviewed/2022/05/GHSA-45jr-jmpw-3gj4/GHSA-45jr-jmpw-3gj4.json @@ -7,12 +7,8 @@ "CVE-2008-3426" ], "details": "Unspecified vulnerability in the Solaris Platform Information and Control Library daemon (picld) in Sun Solaris 8 through 10, and OpenSolaris builds snv_01 through snv_95, allows local users to cause a denial of service via unknown vectors that prevent operation of utilities such as prtdiag, prtpicl, and prtfru.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45qx-8jq2-whqw/GHSA-45qx-8jq2-whqw.json b/advisories/unreviewed/2022/05/GHSA-45qx-8jq2-whqw/GHSA-45qx-8jq2-whqw.json index de9a97367de..beb535c6fb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-45qx-8jq2-whqw/GHSA-45qx-8jq2-whqw.json +++ b/advisories/unreviewed/2022/05/GHSA-45qx-8jq2-whqw/GHSA-45qx-8jq2-whqw.json @@ -7,12 +7,8 @@ "CVE-2008-3640" ], "details": "Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -132,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45qx-gmr7-gchc/GHSA-45qx-gmr7-gchc.json b/advisories/unreviewed/2022/05/GHSA-45qx-gmr7-gchc/GHSA-45qx-gmr7-gchc.json index 7cb57d14c5c..a38697111b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-45qx-gmr7-gchc/GHSA-45qx-gmr7-gchc.json +++ b/advisories/unreviewed/2022/05/GHSA-45qx-gmr7-gchc/GHSA-45qx-gmr7-gchc.json @@ -7,12 +7,8 @@ "CVE-2008-3680" ], "details": "The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4622-4xxq-396h/GHSA-4622-4xxq-396h.json b/advisories/unreviewed/2022/05/GHSA-4622-4xxq-396h/GHSA-4622-4xxq-396h.json index 76d07797bbe..8a1eb2f0549 100644 --- a/advisories/unreviewed/2022/05/GHSA-4622-4xxq-396h/GHSA-4622-4xxq-396h.json +++ b/advisories/unreviewed/2022/05/GHSA-4622-4xxq-396h/GHSA-4622-4xxq-396h.json @@ -7,12 +7,8 @@ "CVE-2008-3590" ], "details": "Multiple SQL injection vulnerabilities in admin/login.asp in E. Z. Poll 2 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4735-fm85-pm92/GHSA-4735-fm85-pm92.json b/advisories/unreviewed/2022/05/GHSA-4735-fm85-pm92/GHSA-4735-fm85-pm92.json index c1b377fc26c..6c0f29698bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4735-fm85-pm92/GHSA-4735-fm85-pm92.json +++ b/advisories/unreviewed/2022/05/GHSA-4735-fm85-pm92/GHSA-4735-fm85-pm92.json @@ -7,12 +7,8 @@ "CVE-2008-3390" ], "details": "Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cj8-p6h5-47jq/GHSA-4cj8-p6h5-47jq.json b/advisories/unreviewed/2022/05/GHSA-4cj8-p6h5-47jq/GHSA-4cj8-p6h5-47jq.json index 1a4335def0f..2e8a237f483 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cj8-p6h5-47jq/GHSA-4cj8-p6h5-47jq.json +++ b/advisories/unreviewed/2022/05/GHSA-4cj8-p6h5-47jq/GHSA-4cj8-p6h5-47jq.json @@ -7,12 +7,8 @@ "CVE-2008-3712" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php and the (2) mosConfig_sitename parameter to administrator/popups/index3pop.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f6x-h2gv-fj5p/GHSA-4f6x-h2gv-fj5p.json b/advisories/unreviewed/2022/05/GHSA-4f6x-h2gv-fj5p/GHSA-4f6x-h2gv-fj5p.json index 5dd557df0dd..5759cc88656 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f6x-h2gv-fj5p/GHSA-4f6x-h2gv-fj5p.json +++ b/advisories/unreviewed/2022/05/GHSA-4f6x-h2gv-fj5p/GHSA-4f6x-h2gv-fj5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fg8-f5cf-42h3/GHSA-4fg8-f5cf-42h3.json b/advisories/unreviewed/2022/05/GHSA-4fg8-f5cf-42h3/GHSA-4fg8-f5cf-42h3.json index 9e571ed0132..3f32c0d8867 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fg8-f5cf-42h3/GHSA-4fg8-f5cf-42h3.json +++ b/advisories/unreviewed/2022/05/GHSA-4fg8-f5cf-42h3/GHSA-4fg8-f5cf-42h3.json @@ -7,12 +7,8 @@ "CVE-2008-3392" ], "details": "Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gq5-gf4j-j5rc/GHSA-4gq5-gf4j-j5rc.json b/advisories/unreviewed/2022/05/GHSA-4gq5-gf4j-j5rc/GHSA-4gq5-gf4j-j5rc.json index 5f8bbd9c4f8..c29b14eed1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gq5-gf4j-j5rc/GHSA-4gq5-gf4j-j5rc.json +++ b/advisories/unreviewed/2022/05/GHSA-4gq5-gf4j-j5rc/GHSA-4gq5-gf4j-j5rc.json @@ -7,12 +7,8 @@ "CVE-2008-3302" ], "details": "SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j7j-qq59-23vv/GHSA-4j7j-qq59-23vv.json b/advisories/unreviewed/2022/05/GHSA-4j7j-qq59-23vv/GHSA-4j7j-qq59-23vv.json index ca8417a547c..bb73ea946e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j7j-qq59-23vv/GHSA-4j7j-qq59-23vv.json +++ b/advisories/unreviewed/2022/05/GHSA-4j7j-qq59-23vv/GHSA-4j7j-qq59-23vv.json @@ -7,12 +7,8 @@ "CVE-2008-3458" ], "details": "Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mcf-r6j9-cvfh/GHSA-4mcf-r6j9-cvfh.json b/advisories/unreviewed/2022/05/GHSA-4mcf-r6j9-cvfh/GHSA-4mcf-r6j9-cvfh.json index c26cd226971..82710767c8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mcf-r6j9-cvfh/GHSA-4mcf-r6j9-cvfh.json +++ b/advisories/unreviewed/2022/05/GHSA-4mcf-r6j9-cvfh/GHSA-4mcf-r6j9-cvfh.json @@ -7,12 +7,8 @@ "CVE-2008-3436" ], "details": "The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mh5-hw23-j38h/GHSA-4mh5-hw23-j38h.json b/advisories/unreviewed/2022/05/GHSA-4mh5-hw23-j38h/GHSA-4mh5-hw23-j38h.json index 79e3d154094..81346e354b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mh5-hw23-j38h/GHSA-4mh5-hw23-j38h.json +++ b/advisories/unreviewed/2022/05/GHSA-4mh5-hw23-j38h/GHSA-4mh5-hw23-j38h.json @@ -7,12 +7,8 @@ "CVE-2008-3533" ], "details": "Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mqf-xqgm-xrqm/GHSA-4mqf-xqgm-xrqm.json b/advisories/unreviewed/2022/05/GHSA-4mqf-xqgm-xrqm/GHSA-4mqf-xqgm-xrqm.json index 4674cad10fa..412ec5c5f9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mqf-xqgm-xrqm/GHSA-4mqf-xqgm-xrqm.json +++ b/advisories/unreviewed/2022/05/GHSA-4mqf-xqgm-xrqm/GHSA-4mqf-xqgm-xrqm.json @@ -7,12 +7,8 @@ "CVE-2008-3666" ], "details": "Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p4x-9m9v-pp3q/GHSA-4p4x-9m9v-pp3q.json b/advisories/unreviewed/2022/05/GHSA-4p4x-9m9v-pp3q/GHSA-4p4x-9m9v-pp3q.json index 7c488ea7706..79eed73bb88 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p4x-9m9v-pp3q/GHSA-4p4x-9m9v-pp3q.json +++ b/advisories/unreviewed/2022/05/GHSA-4p4x-9m9v-pp3q/GHSA-4p4x-9m9v-pp3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pp7-p29p-wcpw/GHSA-4pp7-p29p-wcpw.json b/advisories/unreviewed/2022/05/GHSA-4pp7-p29p-wcpw/GHSA-4pp7-p29p-wcpw.json index ec00f6097e4..26be8d314ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pp7-p29p-wcpw/GHSA-4pp7-p29p-wcpw.json +++ b/advisories/unreviewed/2022/05/GHSA-4pp7-p29p-wcpw/GHSA-4pp7-p29p-wcpw.json @@ -7,12 +7,8 @@ "CVE-2008-3606" ], "details": "Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4prm-c56r-vfmf/GHSA-4prm-c56r-vfmf.json b/advisories/unreviewed/2022/05/GHSA-4prm-c56r-vfmf/GHSA-4prm-c56r-vfmf.json index cdb4ed97541..49c6031e1e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4prm-c56r-vfmf/GHSA-4prm-c56r-vfmf.json +++ b/advisories/unreviewed/2022/05/GHSA-4prm-c56r-vfmf/GHSA-4prm-c56r-vfmf.json @@ -7,12 +7,8 @@ "CVE-2008-3377" ], "details": "SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4q27-w7jf-v3mh/GHSA-4q27-w7jf-v3mh.json b/advisories/unreviewed/2022/05/GHSA-4q27-w7jf-v3mh/GHSA-4q27-w7jf-v3mh.json index 6842010cafd..d0abd731b8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q27-w7jf-v3mh/GHSA-4q27-w7jf-v3mh.json +++ b/advisories/unreviewed/2022/05/GHSA-4q27-w7jf-v3mh/GHSA-4q27-w7jf-v3mh.json @@ -7,12 +7,8 @@ "CVE-2008-3636" ], "details": "Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\\\.\\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q74-745q-555q/GHSA-4q74-745q-555q.json b/advisories/unreviewed/2022/05/GHSA-4q74-745q-555q/GHSA-4q74-745q-555q.json index 8d6236cb2c5..21d59df6d0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q74-745q-555q/GHSA-4q74-745q-555q.json +++ b/advisories/unreviewed/2022/05/GHSA-4q74-745q-555q/GHSA-4q74-745q-555q.json @@ -7,12 +7,8 @@ "CVE-2008-3209" ], "details": "Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control ActiveX control in biimgfrm.ocx. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r59-w36x-w685/GHSA-4r59-w36x-w685.json b/advisories/unreviewed/2022/05/GHSA-4r59-w36x-w685/GHSA-4r59-w36x-w685.json index 0f92ee7b5d1..4dfd05b0d88 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r59-w36x-w685/GHSA-4r59-w36x-w685.json +++ b/advisories/unreviewed/2022/05/GHSA-4r59-w36x-w685/GHSA-4r59-w36x-w685.json @@ -7,12 +7,8 @@ "CVE-2008-3610" ], "details": "Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rj5-2rf5-h49c/GHSA-4rj5-2rf5-h49c.json b/advisories/unreviewed/2022/05/GHSA-4rj5-2rf5-h49c/GHSA-4rj5-2rf5-h49c.json index 3d8e4e2403b..56c6ba23d64 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rj5-2rf5-h49c/GHSA-4rj5-2rf5-h49c.json +++ b/advisories/unreviewed/2022/05/GHSA-4rj5-2rf5-h49c/GHSA-4rj5-2rf5-h49c.json @@ -7,12 +7,8 @@ "CVE-2008-3339" ], "details": "search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vrq-jv2w-m38f/GHSA-4vrq-jv2w-m38f.json b/advisories/unreviewed/2022/05/GHSA-4vrq-jv2w-m38f/GHSA-4vrq-jv2w-m38f.json index 8f3c610edbe..062bfe7e381 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vrq-jv2w-m38f/GHSA-4vrq-jv2w-m38f.json +++ b/advisories/unreviewed/2022/05/GHSA-4vrq-jv2w-m38f/GHSA-4vrq-jv2w-m38f.json @@ -7,12 +7,8 @@ "CVE-2008-3709" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to inject arbitrary web script or HTML via the (1) lOptionsOptions, (2) lNavAdminOptions, or (3) lNavReturn parameter to options.php; or the (4) lNavReturn parameter to subscribe.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vwq-rgw9-5x74/GHSA-4vwq-rgw9-5x74.json b/advisories/unreviewed/2022/05/GHSA-4vwq-rgw9-5x74/GHSA-4vwq-rgw9-5x74.json index 6d9147dbace..1780a0ab427 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vwq-rgw9-5x74/GHSA-4vwq-rgw9-5x74.json +++ b/advisories/unreviewed/2022/05/GHSA-4vwq-rgw9-5x74/GHSA-4vwq-rgw9-5x74.json @@ -7,12 +7,8 @@ "CVE-2008-3699" ], "details": "The MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows local users to overwrite arbitrary files via a symlink attack on the album_info.xml temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wjq-qj5x-j7pq/GHSA-4wjq-qj5x-j7pq.json b/advisories/unreviewed/2022/05/GHSA-4wjq-qj5x-j7pq/GHSA-4wjq-qj5x-j7pq.json index 8d52df9bf22..7bd18259919 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wjq-qj5x-j7pq/GHSA-4wjq-qj5x-j7pq.json +++ b/advisories/unreviewed/2022/05/GHSA-4wjq-qj5x-j7pq/GHSA-4wjq-qj5x-j7pq.json @@ -7,12 +7,8 @@ "CVE-2008-3622" ], "details": "Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka \"persistent JavaScript injection.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52f9-v427-p4gr/GHSA-52f9-v427-p4gr.json b/advisories/unreviewed/2022/05/GHSA-52f9-v427-p4gr/GHSA-52f9-v427-p4gr.json index a80b39554f7..279f66a0319 100644 --- a/advisories/unreviewed/2022/05/GHSA-52f9-v427-p4gr/GHSA-52f9-v427-p4gr.json +++ b/advisories/unreviewed/2022/05/GHSA-52f9-v427-p4gr/GHSA-52f9-v427-p4gr.json @@ -7,12 +7,8 @@ "CVE-2008-3308" ], "details": "PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_archivo parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52pc-7jhr-jrx9/GHSA-52pc-7jhr-jrx9.json b/advisories/unreviewed/2022/05/GHSA-52pc-7jhr-jrx9/GHSA-52pc-7jhr-jrx9.json index cd96a3e6914..87219ef14b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-52pc-7jhr-jrx9/GHSA-52pc-7jhr-jrx9.json +++ b/advisories/unreviewed/2022/05/GHSA-52pc-7jhr-jrx9/GHSA-52pc-7jhr-jrx9.json @@ -7,12 +7,8 @@ "CVE-2008-3382" ], "details": "SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53fw-5wjp-mrqx/GHSA-53fw-5wjp-mrqx.json b/advisories/unreviewed/2022/05/GHSA-53fw-5wjp-mrqx/GHSA-53fw-5wjp-mrqx.json index 2e96d96520a..e09d1fefe45 100644 --- a/advisories/unreviewed/2022/05/GHSA-53fw-5wjp-mrqx/GHSA-53fw-5wjp-mrqx.json +++ b/advisories/unreviewed/2022/05/GHSA-53fw-5wjp-mrqx/GHSA-53fw-5wjp-mrqx.json @@ -7,12 +7,8 @@ "CVE-2008-3581" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53ph-pxh2-3gf4/GHSA-53ph-pxh2-3gf4.json b/advisories/unreviewed/2022/05/GHSA-53ph-pxh2-3gf4/GHSA-53ph-pxh2-3gf4.json index 5566eecccca..b444e0d20ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-53ph-pxh2-3gf4/GHSA-53ph-pxh2-3gf4.json +++ b/advisories/unreviewed/2022/05/GHSA-53ph-pxh2-3gf4/GHSA-53ph-pxh2-3gf4.json @@ -7,12 +7,8 @@ "CVE-2008-3239" ], "details": "Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-555m-5vqw-mv38/GHSA-555m-5vqw-mv38.json b/advisories/unreviewed/2022/05/GHSA-555m-5vqw-mv38/GHSA-555m-5vqw-mv38.json index d16d98227fc..994ca85e802 100644 --- a/advisories/unreviewed/2022/05/GHSA-555m-5vqw-mv38/GHSA-555m-5vqw-mv38.json +++ b/advisories/unreviewed/2022/05/GHSA-555m-5vqw-mv38/GHSA-555m-5vqw-mv38.json @@ -7,12 +7,8 @@ "CVE-2008-3544" ], "details": "Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56f6-4pg5-mvj3/GHSA-56f6-4pg5-mvj3.json b/advisories/unreviewed/2022/05/GHSA-56f6-4pg5-mvj3/GHSA-56f6-4pg5-mvj3.json index 7e9da2f90f9..9cdbac9c1d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-56f6-4pg5-mvj3/GHSA-56f6-4pg5-mvj3.json +++ b/advisories/unreviewed/2022/05/GHSA-56f6-4pg5-mvj3/GHSA-56f6-4pg5-mvj3.json @@ -7,12 +7,8 @@ "CVE-2008-3516" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in files generated by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) viewer.swf and (2) loadflash.js, a different vulnerability than CVE-2008-3515.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56rx-ch74-jh4v/GHSA-56rx-ch74-jh4v.json b/advisories/unreviewed/2022/05/GHSA-56rx-ch74-jh4v/GHSA-56rx-ch74-jh4v.json index 6d9a5ec8552..d5bb7919154 100644 --- a/advisories/unreviewed/2022/05/GHSA-56rx-ch74-jh4v/GHSA-56rx-ch74-jh4v.json +++ b/advisories/unreviewed/2022/05/GHSA-56rx-ch74-jh4v/GHSA-56rx-ch74-jh4v.json @@ -7,12 +7,8 @@ "CVE-2008-3440" ], "details": "Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57w3-7wwx-wp77/GHSA-57w3-7wwx-wp77.json b/advisories/unreviewed/2022/05/GHSA-57w3-7wwx-wp77/GHSA-57w3-7wwx-wp77.json index 008ee765cce..fb376836344 100644 --- a/advisories/unreviewed/2022/05/GHSA-57w3-7wwx-wp77/GHSA-57w3-7wwx-wp77.json +++ b/advisories/unreviewed/2022/05/GHSA-57w3-7wwx-wp77/GHSA-57w3-7wwx-wp77.json @@ -7,12 +7,8 @@ "CVE-2008-3258" ], "details": "Multiple SQL injection vulnerabilities in Zoph before 0.7.0.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59xr-758c-9487/GHSA-59xr-758c-9487.json b/advisories/unreviewed/2022/05/GHSA-59xr-758c-9487/GHSA-59xr-758c-9487.json index 1fc76018d87..a4815e2614d 100644 --- a/advisories/unreviewed/2022/05/GHSA-59xr-758c-9487/GHSA-59xr-758c-9487.json +++ b/advisories/unreviewed/2022/05/GHSA-59xr-758c-9487/GHSA-59xr-758c-9487.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f4p-5ccx-ff9v/GHSA-5f4p-5ccx-ff9v.json b/advisories/unreviewed/2022/05/GHSA-5f4p-5ccx-ff9v/GHSA-5f4p-5ccx-ff9v.json index a26d6e8222d..b4122576cf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f4p-5ccx-ff9v/GHSA-5f4p-5ccx-ff9v.json +++ b/advisories/unreviewed/2022/05/GHSA-5f4p-5ccx-ff9v/GHSA-5f4p-5ccx-ff9v.json @@ -7,12 +7,8 @@ "CVE-2008-3394" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f64-wwgv-qhfq/GHSA-5f64-wwgv-qhfq.json b/advisories/unreviewed/2022/05/GHSA-5f64-wwgv-qhfq/GHSA-5f64-wwgv-qhfq.json index 70953a5e34d..3a3d77b533c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f64-wwgv-qhfq/GHSA-5f64-wwgv-qhfq.json +++ b/advisories/unreviewed/2022/05/GHSA-5f64-wwgv-qhfq/GHSA-5f64-wwgv-qhfq.json @@ -7,12 +7,8 @@ "CVE-2008-3428" ], "details": "Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f6v-fgcw-j5px/GHSA-5f6v-fgcw-j5px.json b/advisories/unreviewed/2022/05/GHSA-5f6v-fgcw-j5px/GHSA-5f6v-fgcw-j5px.json index 8d18fc09443..9ab2b86df60 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f6v-fgcw-j5px/GHSA-5f6v-fgcw-j5px.json +++ b/advisories/unreviewed/2022/05/GHSA-5f6v-fgcw-j5px/GHSA-5f6v-fgcw-j5px.json @@ -7,12 +7,8 @@ "CVE-2008-3657" ], "details": "The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check \"taintness\" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g68-4hrm-mwxw/GHSA-5g68-4hrm-mwxw.json b/advisories/unreviewed/2022/05/GHSA-5g68-4hrm-mwxw/GHSA-5g68-4hrm-mwxw.json index cbf7a60d45c..4ee8d7eb6db 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g68-4hrm-mwxw/GHSA-5g68-4hrm-mwxw.json +++ b/advisories/unreviewed/2022/05/GHSA-5g68-4hrm-mwxw/GHSA-5g68-4hrm-mwxw.json @@ -7,12 +7,8 @@ "CVE-2008-3187" ], "details": "zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package data corruption) via a spoofed key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gj6-w4cr-94x9/GHSA-5gj6-w4cr-94x9.json b/advisories/unreviewed/2022/05/GHSA-5gj6-w4cr-94x9/GHSA-5gj6-w4cr-94x9.json index 1cfe9c78221..13d8e611055 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gj6-w4cr-94x9/GHSA-5gj6-w4cr-94x9.json +++ b/advisories/unreviewed/2022/05/GHSA-5gj6-w4cr-94x9/GHSA-5gj6-w4cr-94x9.json @@ -7,12 +7,8 @@ "CVE-2008-3642" ], "details": "Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gqx-h5hm-67q3/GHSA-5gqx-h5hm-67q3.json b/advisories/unreviewed/2022/05/GHSA-5gqx-h5hm-67q3/GHSA-5gqx-h5hm-67q3.json index acdc0afa27f..45ccd865fa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gqx-h5hm-67q3/GHSA-5gqx-h5hm-67q3.json +++ b/advisories/unreviewed/2022/05/GHSA-5gqx-h5hm-67q3/GHSA-5gqx-h5hm-67q3.json @@ -7,12 +7,8 @@ "CVE-2008-3621" ], "details": "VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5gwj-42jg-vg3v/GHSA-5gwj-42jg-vg3v.json b/advisories/unreviewed/2022/05/GHSA-5gwj-42jg-vg3v/GHSA-5gwj-42jg-vg3v.json index ee4009a7be3..a73d2ef4a7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gwj-42jg-vg3v/GHSA-5gwj-42jg-vg3v.json +++ b/advisories/unreviewed/2022/05/GHSA-5gwj-42jg-vg3v/GHSA-5gwj-42jg-vg3v.json @@ -7,12 +7,8 @@ "CVE-2008-3435" ], "details": "LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gxm-78q7-pwr8/GHSA-5gxm-78q7-pwr8.json b/advisories/unreviewed/2022/05/GHSA-5gxm-78q7-pwr8/GHSA-5gxm-78q7-pwr8.json index 5abe72c5667..9d07efd391c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gxm-78q7-pwr8/GHSA-5gxm-78q7-pwr8.json +++ b/advisories/unreviewed/2022/05/GHSA-5gxm-78q7-pwr8/GHSA-5gxm-78q7-pwr8.json @@ -7,12 +7,8 @@ "CVE-2008-3773" ], "details": "Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when \"Show New Private Message Notification Pop-Up\" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m38-jjgp-q23x/GHSA-5m38-jjgp-q23x.json b/advisories/unreviewed/2022/05/GHSA-5m38-jjgp-q23x/GHSA-5m38-jjgp-q23x.json index 1de41d2ff2d..7667eb8d62c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m38-jjgp-q23x/GHSA-5m38-jjgp-q23x.json +++ b/advisories/unreviewed/2022/05/GHSA-5m38-jjgp-q23x/GHSA-5m38-jjgp-q23x.json @@ -7,12 +7,8 @@ "CVE-2008-3696" ], "details": "Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, and CVE-2008-3695.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pfp-c3pj-vr5r/GHSA-5pfp-c3pj-vr5r.json b/advisories/unreviewed/2022/05/GHSA-5pfp-c3pj-vr5r/GHSA-5pfp-c3pj-vr5r.json index 1ac1995f376..746395805f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pfp-c3pj-vr5r/GHSA-5pfp-c3pj-vr5r.json +++ b/advisories/unreviewed/2022/05/GHSA-5pfp-c3pj-vr5r/GHSA-5pfp-c3pj-vr5r.json @@ -7,12 +7,8 @@ "CVE-2008-3714" ], "details": "Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qpw-8p73-jm26/GHSA-5qpw-8p73-jm26.json b/advisories/unreviewed/2022/05/GHSA-5qpw-8p73-jm26/GHSA-5qpw-8p73-jm26.json index 8e886c4c7be..c94b7a9fb79 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qpw-8p73-jm26/GHSA-5qpw-8p73-jm26.json +++ b/advisories/unreviewed/2022/05/GHSA-5qpw-8p73-jm26/GHSA-5qpw-8p73-jm26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wvv-jg3g-qqqm/GHSA-5wvv-jg3g-qqqm.json b/advisories/unreviewed/2022/05/GHSA-5wvv-jg3g-qqqm/GHSA-5wvv-jg3g-qqqm.json index 1e623ab8226..47657ea9acc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wvv-jg3g-qqqm/GHSA-5wvv-jg3g-qqqm.json +++ b/advisories/unreviewed/2022/05/GHSA-5wvv-jg3g-qqqm/GHSA-5wvv-jg3g-qqqm.json @@ -7,12 +7,8 @@ "CVE-2008-3336" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PunBB before 1.2.19 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) include/parser.php and (2) moderate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xh2-vf22-cccw/GHSA-5xh2-vf22-cccw.json b/advisories/unreviewed/2022/05/GHSA-5xh2-vf22-cccw/GHSA-5xh2-vf22-cccw.json index 0d7d9ba3fd5..db12ee4c717 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xh2-vf22-cccw/GHSA-5xh2-vf22-cccw.json +++ b/advisories/unreviewed/2022/05/GHSA-5xh2-vf22-cccw/GHSA-5xh2-vf22-cccw.json @@ -7,12 +7,8 @@ "CVE-2008-3396" ], "details": "Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xwv-34x4-p6rf/GHSA-5xwv-34x4-p6rf.json b/advisories/unreviewed/2022/05/GHSA-5xwv-34x4-p6rf/GHSA-5xwv-34x4-p6rf.json index e1127c2e37e..fc99f62eef6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xwv-34x4-p6rf/GHSA-5xwv-34x4-p6rf.json +++ b/advisories/unreviewed/2022/05/GHSA-5xwv-34x4-p6rf/GHSA-5xwv-34x4-p6rf.json @@ -7,12 +7,8 @@ "CVE-2008-3319" ], "details": "admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62gp-x3rq-2r53/GHSA-62gp-x3rq-2r53.json b/advisories/unreviewed/2022/05/GHSA-62gp-x3rq-2r53/GHSA-62gp-x3rq-2r53.json index 1678b0b2359..4ca8bb2b307 100644 --- a/advisories/unreviewed/2022/05/GHSA-62gp-x3rq-2r53/GHSA-62gp-x3rq-2r53.json +++ b/advisories/unreviewed/2022/05/GHSA-62gp-x3rq-2r53/GHSA-62gp-x3rq-2r53.json @@ -7,12 +7,8 @@ "CVE-2008-3519" ], "details": "The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62mp-xpvq-4v82/GHSA-62mp-xpvq-4v82.json b/advisories/unreviewed/2022/05/GHSA-62mp-xpvq-4v82/GHSA-62mp-xpvq-4v82.json index f9044c9fbcb..8958efcfc42 100644 --- a/advisories/unreviewed/2022/05/GHSA-62mp-xpvq-4v82/GHSA-62mp-xpvq-4v82.json +++ b/advisories/unreviewed/2022/05/GHSA-62mp-xpvq-4v82/GHSA-62mp-xpvq-4v82.json @@ -7,12 +7,8 @@ "CVE-2008-3201" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Pagefusion 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) acct_fname and (2) acct_lname parameters in an edit action, and the (3) PID, (4) PGID, and (5) rez parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63qp-xf58-q5c5/GHSA-63qp-xf58-q5c5.json b/advisories/unreviewed/2022/05/GHSA-63qp-xf58-q5c5/GHSA-63qp-xf58-q5c5.json index 5edf26a0e23..f6a37240eee 100644 --- a/advisories/unreviewed/2022/05/GHSA-63qp-xf58-q5c5/GHSA-63qp-xf58-q5c5.json +++ b/advisories/unreviewed/2022/05/GHSA-63qp-xf58-q5c5/GHSA-63qp-xf58-q5c5.json @@ -7,12 +7,8 @@ "CVE-2008-3564" ], "details": "Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p, (2) cat, and (3) archive parameters. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6482-pqp2-2q5g/GHSA-6482-pqp2-2q5g.json b/advisories/unreviewed/2022/05/GHSA-6482-pqp2-2q5g/GHSA-6482-pqp2-2q5g.json index 6f08c5194c9..6a744794cc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6482-pqp2-2q5g/GHSA-6482-pqp2-2q5g.json +++ b/advisories/unreviewed/2022/05/GHSA-6482-pqp2-2q5g/GHSA-6482-pqp2-2q5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64q5-hj2m-9w98/GHSA-64q5-hj2m-9w98.json b/advisories/unreviewed/2022/05/GHSA-64q5-hj2m-9w98/GHSA-64q5-hj2m-9w98.json index fdf24bcb5ac..a110a9bb98b 100644 --- a/advisories/unreviewed/2022/05/GHSA-64q5-hj2m-9w98/GHSA-64q5-hj2m-9w98.json +++ b/advisories/unreviewed/2022/05/GHSA-64q5-hj2m-9w98/GHSA-64q5-hj2m-9w98.json @@ -7,12 +7,8 @@ "CVE-2008-3758" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword parameter to people.php, and allow remote authenticated users to inject arbitrary web script or HTML via the (2) Account picture and (3) Icon fields in account.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66pf-7874-v654/GHSA-66pf-7874-v654.json b/advisories/unreviewed/2022/05/GHSA-66pf-7874-v654/GHSA-66pf-7874-v654.json index 432c7f6edbd..07839110792 100644 --- a/advisories/unreviewed/2022/05/GHSA-66pf-7874-v654/GHSA-66pf-7874-v654.json +++ b/advisories/unreviewed/2022/05/GHSA-66pf-7874-v654/GHSA-66pf-7874-v654.json @@ -7,12 +7,8 @@ "CVE-2008-3777" ], "details": "The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-679x-682p-m39r/GHSA-679x-682p-m39r.json b/advisories/unreviewed/2022/05/GHSA-679x-682p-m39r/GHSA-679x-682p-m39r.json index 5245897a549..2d1a14bd226 100644 --- a/advisories/unreviewed/2022/05/GHSA-679x-682p-m39r/GHSA-679x-682p-m39r.json +++ b/advisories/unreviewed/2022/05/GHSA-679x-682p-m39r/GHSA-679x-682p-m39r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67pv-pw2w-f788/GHSA-67pv-pw2w-f788.json b/advisories/unreviewed/2022/05/GHSA-67pv-pw2w-f788/GHSA-67pv-pw2w-f788.json index 77137ca3307..edd4c665ad0 100644 --- a/advisories/unreviewed/2022/05/GHSA-67pv-pw2w-f788/GHSA-67pv-pw2w-f788.json +++ b/advisories/unreviewed/2022/05/GHSA-67pv-pw2w-f788/GHSA-67pv-pw2w-f788.json @@ -7,12 +7,8 @@ "CVE-2008-3496" ], "details": "Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67wp-655f-ffm8/GHSA-67wp-655f-ffm8.json b/advisories/unreviewed/2022/05/GHSA-67wp-655f-ffm8/GHSA-67wp-655f-ffm8.json index 920cb3b313c..a1b6939d3d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-67wp-655f-ffm8/GHSA-67wp-655f-ffm8.json +++ b/advisories/unreviewed/2022/05/GHSA-67wp-655f-ffm8/GHSA-67wp-655f-ffm8.json @@ -7,12 +7,8 @@ "CVE-2008-3448" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67x2-2mj6-rmv7/GHSA-67x2-2mj6-rmv7.json b/advisories/unreviewed/2022/05/GHSA-67x2-2mj6-rmv7/GHSA-67x2-2mj6-rmv7.json index 956ee258bf8..d0adebe5e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-67x2-2mj6-rmv7/GHSA-67x2-2mj6-rmv7.json +++ b/advisories/unreviewed/2022/05/GHSA-67x2-2mj6-rmv7/GHSA-67x2-2mj6-rmv7.json @@ -7,12 +7,8 @@ "CVE-2008-3589" ], "details": "Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69q5-g22v-rfc5/GHSA-69q5-g22v-rfc5.json b/advisories/unreviewed/2022/05/GHSA-69q5-g22v-rfc5/GHSA-69q5-g22v-rfc5.json index f8a8146da4b..2c97a1d5ac7 100644 --- a/advisories/unreviewed/2022/05/GHSA-69q5-g22v-rfc5/GHSA-69q5-g22v-rfc5.json +++ b/advisories/unreviewed/2022/05/GHSA-69q5-g22v-rfc5/GHSA-69q5-g22v-rfc5.json @@ -7,12 +7,8 @@ "CVE-2008-3512" ], "details": "SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69vv-64jh-mh3m/GHSA-69vv-64jh-mh3m.json b/advisories/unreviewed/2022/05/GHSA-69vv-64jh-mh3m/GHSA-69vv-64jh-mh3m.json index f32b0e13360..901dfe8b51a 100644 --- a/advisories/unreviewed/2022/05/GHSA-69vv-64jh-mh3m/GHSA-69vv-64jh-mh3m.json +++ b/advisories/unreviewed/2022/05/GHSA-69vv-64jh-mh3m/GHSA-69vv-64jh-mh3m.json @@ -7,12 +7,8 @@ "CVE-2008-3384" ], "details": "Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) module and (2) file parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f9j-53p6-vfwp/GHSA-6f9j-53p6-vfwp.json b/advisories/unreviewed/2022/05/GHSA-6f9j-53p6-vfwp/GHSA-6f9j-53p6-vfwp.json index c6afa2e3f3e..c613638c64d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f9j-53p6-vfwp/GHSA-6f9j-53p6-vfwp.json +++ b/advisories/unreviewed/2022/05/GHSA-6f9j-53p6-vfwp/GHSA-6f9j-53p6-vfwp.json @@ -7,12 +7,8 @@ "CVE-2008-3312" ], "details": "Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might be an issue in FCKeditor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fwg-7777-r73j/GHSA-6fwg-7777-r73j.json b/advisories/unreviewed/2022/05/GHSA-6fwg-7777-r73j/GHSA-6fwg-7777-r73j.json index bf156b33e28..667f99f3ebb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fwg-7777-r73j/GHSA-6fwg-7777-r73j.json +++ b/advisories/unreviewed/2022/05/GHSA-6fwg-7777-r73j/GHSA-6fwg-7777-r73j.json @@ -7,12 +7,8 @@ "CVE-2008-3641" ], "details": "The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j4p-vq7v-x6g8/GHSA-6j4p-vq7v-x6g8.json b/advisories/unreviewed/2022/05/GHSA-6j4p-vq7v-x6g8/GHSA-6j4p-vq7v-x6g8.json index 870be3477ca..e28c000c06a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j4p-vq7v-x6g8/GHSA-6j4p-vq7v-x6g8.json +++ b/advisories/unreviewed/2022/05/GHSA-6j4p-vq7v-x6g8/GHSA-6j4p-vq7v-x6g8.json @@ -7,12 +7,8 @@ "CVE-2008-3329" ], "details": "Unspecified vulnerability in Links before 2.1, when \"only proxies\" is enabled, has unknown impact and attack vectors related to providing \"URLs to external programs.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mp7-3h68-ch9p/GHSA-6mp7-3h68-ch9p.json b/advisories/unreviewed/2022/05/GHSA-6mp7-3h68-ch9p/GHSA-6mp7-3h68-ch9p.json index 5a78cb7f4b8..3c54126f8e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mp7-3h68-ch9p/GHSA-6mp7-3h68-ch9p.json +++ b/advisories/unreviewed/2022/05/GHSA-6mp7-3h68-ch9p/GHSA-6mp7-3h68-ch9p.json @@ -7,12 +7,8 @@ "CVE-2008-3446" ], "details": "Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q3h-pc9x-4hhc/GHSA-6q3h-pc9x-4hhc.json b/advisories/unreviewed/2022/05/GHSA-6q3h-pc9x-4hhc/GHSA-6q3h-pc9x-4hhc.json index bd6702cce57..f813e7abe06 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q3h-pc9x-4hhc/GHSA-6q3h-pc9x-4hhc.json +++ b/advisories/unreviewed/2022/05/GHSA-6q3h-pc9x-4hhc/GHSA-6q3h-pc9x-4hhc.json @@ -7,12 +7,8 @@ "CVE-2008-3794" ], "details": "Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x4c-v6ww-34gf/GHSA-6x4c-v6ww-34gf.json b/advisories/unreviewed/2022/05/GHSA-6x4c-v6ww-34gf/GHSA-6x4c-v6ww-34gf.json index 6227bba80af..d8d8c5c2f14 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x4c-v6ww-34gf/GHSA-6x4c-v6ww-34gf.json +++ b/advisories/unreviewed/2022/05/GHSA-6x4c-v6ww-34gf/GHSA-6x4c-v6ww-34gf.json @@ -7,12 +7,8 @@ "CVE-2008-3718" ], "details": "Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7254-j628-hmwg/GHSA-7254-j628-hmwg.json b/advisories/unreviewed/2022/05/GHSA-7254-j628-hmwg/GHSA-7254-j628-hmwg.json index 460c8acd702..936ea65c55a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7254-j628-hmwg/GHSA-7254-j628-hmwg.json +++ b/advisories/unreviewed/2022/05/GHSA-7254-j628-hmwg/GHSA-7254-j628-hmwg.json @@ -7,12 +7,8 @@ "CVE-2008-3203" ], "details": "js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72q8-4qfp-hvwx/GHSA-72q8-4qfp-hvwx.json b/advisories/unreviewed/2022/05/GHSA-72q8-4qfp-hvwx/GHSA-72q8-4qfp-hvwx.json index 4856e2690c5..ddafd35f12b 100644 --- a/advisories/unreviewed/2022/05/GHSA-72q8-4qfp-hvwx/GHSA-72q8-4qfp-hvwx.json +++ b/advisories/unreviewed/2022/05/GHSA-72q8-4qfp-hvwx/GHSA-72q8-4qfp-hvwx.json @@ -7,12 +7,8 @@ "CVE-2008-3550" ], "details": "The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72v4-hgcc-57v8/GHSA-72v4-hgcc-57v8.json b/advisories/unreviewed/2022/05/GHSA-72v4-hgcc-57v8/GHSA-72v4-hgcc-57v8.json index 165454e8d62..82470299704 100644 --- a/advisories/unreviewed/2022/05/GHSA-72v4-hgcc-57v8/GHSA-72v4-hgcc-57v8.json +++ b/advisories/unreviewed/2022/05/GHSA-72v4-hgcc-57v8/GHSA-72v4-hgcc-57v8.json @@ -7,12 +7,8 @@ "CVE-2008-3354" ], "details": "Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bbPath[path] parameter to votepolls.php and the (2) bbPath[root_theme] parameter to config.php, different vectors than CVE-2006-0659. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75jw-3q36-9hvj/GHSA-75jw-3q36-9hvj.json b/advisories/unreviewed/2022/05/GHSA-75jw-3q36-9hvj/GHSA-75jw-3q36-9hvj.json index bb423f1d186..d32d0ba8966 100644 --- a/advisories/unreviewed/2022/05/GHSA-75jw-3q36-9hvj/GHSA-75jw-3q36-9hvj.json +++ b/advisories/unreviewed/2022/05/GHSA-75jw-3q36-9hvj/GHSA-75jw-3q36-9hvj.json @@ -7,12 +7,8 @@ "CVE-2008-3760" ], "details": "Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout via a SignOutNow action to people.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78j9-c89m-gjh9/GHSA-78j9-c89m-gjh9.json b/advisories/unreviewed/2022/05/GHSA-78j9-c89m-gjh9/GHSA-78j9-c89m-gjh9.json index e43125fb833..d20f5c49fb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-78j9-c89m-gjh9/GHSA-78j9-c89m-gjh9.json +++ b/advisories/unreviewed/2022/05/GHSA-78j9-c89m-gjh9/GHSA-78j9-c89m-gjh9.json @@ -7,12 +7,8 @@ "CVE-2008-3692" ], "details": "Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78wg-q5pf-wp99/GHSA-78wg-q5pf-wp99.json b/advisories/unreviewed/2022/05/GHSA-78wg-q5pf-wp99/GHSA-78wg-q5pf-wp99.json index 9171e026a24..4761350fbb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-78wg-q5pf-wp99/GHSA-78wg-q5pf-wp99.json +++ b/advisories/unreviewed/2022/05/GHSA-78wg-q5pf-wp99/GHSA-78wg-q5pf-wp99.json @@ -7,12 +7,8 @@ "CVE-2008-3569" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-795w-6gcg-9r8x/GHSA-795w-6gcg-9r8x.json b/advisories/unreviewed/2022/05/GHSA-795w-6gcg-9r8x/GHSA-795w-6gcg-9r8x.json index cc61e5b7ea0..c1b5ccf992d 100644 --- a/advisories/unreviewed/2022/05/GHSA-795w-6gcg-9r8x/GHSA-795w-6gcg-9r8x.json +++ b/advisories/unreviewed/2022/05/GHSA-795w-6gcg-9r8x/GHSA-795w-6gcg-9r8x.json @@ -7,12 +7,8 @@ "CVE-2008-3197" ], "details": "Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the \"Creating a Database\" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79h2-q588-8g28/GHSA-79h2-q588-8g28.json b/advisories/unreviewed/2022/05/GHSA-79h2-q588-8g28/GHSA-79h2-q588-8g28.json index f66f94c79b2..0d6f7e8e969 100644 --- a/advisories/unreviewed/2022/05/GHSA-79h2-q588-8g28/GHSA-79h2-q588-8g28.json +++ b/advisories/unreviewed/2022/05/GHSA-79h2-q588-8g28/GHSA-79h2-q588-8g28.json @@ -7,12 +7,8 @@ "CVE-2008-3545" ], "details": "Unspecified vulnerability in ovtopmd in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536, CVE-2008-3537, and CVE-2008-3544. NOTE: due to insufficient details from the vendor, it is not clear whether this is the same as CVE-2008-1853.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fcj-73p6-72jw/GHSA-7fcj-73p6-72jw.json b/advisories/unreviewed/2022/05/GHSA-7fcj-73p6-72jw/GHSA-7fcj-73p6-72jw.json index cc34dc41127..4f580abfbc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fcj-73p6-72jw/GHSA-7fcj-73p6-72jw.json +++ b/advisories/unreviewed/2022/05/GHSA-7fcj-73p6-72jw/GHSA-7fcj-73p6-72jw.json @@ -7,12 +7,8 @@ "CVE-2008-3787" ], "details": "SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fgq-99qx-hh39/GHSA-7fgq-99qx-hh39.json b/advisories/unreviewed/2022/05/GHSA-7fgq-99qx-hh39/GHSA-7fgq-99qx-hh39.json index c6816e9716e..c6dd866cd93 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fgq-99qx-hh39/GHSA-7fgq-99qx-hh39.json +++ b/advisories/unreviewed/2022/05/GHSA-7fgq-99qx-hh39/GHSA-7fgq-99qx-hh39.json @@ -7,12 +7,8 @@ "CVE-2008-3397" ], "details": "Cross-site scripting (XSS) vulnerability in Runesoft Cerberus CMS before 3_1.4_0.9 allows remote attackers to inject arbitrary web script or HTML via a cerberus_user cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g23-63v6-c2vh/GHSA-7g23-63v6-c2vh.json b/advisories/unreviewed/2022/05/GHSA-7g23-63v6-c2vh/GHSA-7g23-63v6-c2vh.json index 6c195009d3e..6fa92e138df 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g23-63v6-c2vh/GHSA-7g23-63v6-c2vh.json +++ b/advisories/unreviewed/2022/05/GHSA-7g23-63v6-c2vh/GHSA-7g23-63v6-c2vh.json @@ -7,12 +7,8 @@ "CVE-2008-3225" ], "details": "Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing \"LDAP security fix.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7gpj-mrg5-wj8r/GHSA-7gpj-mrg5-wj8r.json b/advisories/unreviewed/2022/05/GHSA-7gpj-mrg5-wj8r/GHSA-7gpj-mrg5-wj8r.json index 513f9483ac7..b5209dacf0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gpj-mrg5-wj8r/GHSA-7gpj-mrg5-wj8r.json +++ b/advisories/unreviewed/2022/05/GHSA-7gpj-mrg5-wj8r/GHSA-7gpj-mrg5-wj8r.json @@ -7,12 +7,8 @@ "CVE-2008-3586" ], "details": "SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hcq-j54w-m8hw/GHSA-7hcq-j54w-m8hw.json b/advisories/unreviewed/2022/05/GHSA-7hcq-j54w-m8hw/GHSA-7hcq-j54w-m8hw.json index 0812c686768..461e635bf00 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hcq-j54w-m8hw/GHSA-7hcq-j54w-m8hw.json +++ b/advisories/unreviewed/2022/05/GHSA-7hcq-j54w-m8hw/GHSA-7hcq-j54w-m8hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hjf-pwxq-24c5/GHSA-7hjf-pwxq-24c5.json b/advisories/unreviewed/2022/05/GHSA-7hjf-pwxq-24c5/GHSA-7hjf-pwxq-24c5.json index 12af7f83593..c3eb64cb75c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hjf-pwxq-24c5/GHSA-7hjf-pwxq-24c5.json +++ b/advisories/unreviewed/2022/05/GHSA-7hjf-pwxq-24c5/GHSA-7hjf-pwxq-24c5.json @@ -7,12 +7,8 @@ "CVE-2008-3557" ], "details": "Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mww-385g-p2jf/GHSA-7mww-385g-p2jf.json b/advisories/unreviewed/2022/05/GHSA-7mww-385g-p2jf/GHSA-7mww-385g-p2jf.json index 19876365e6f..9a7abedacfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mww-385g-p2jf/GHSA-7mww-385g-p2jf.json +++ b/advisories/unreviewed/2022/05/GHSA-7mww-385g-p2jf/GHSA-7mww-385g-p2jf.json @@ -7,12 +7,8 @@ "CVE-2008-3746" ], "details": "neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r38-qg56-j3jr/GHSA-7r38-qg56-j3jr.json b/advisories/unreviewed/2022/05/GHSA-7r38-qg56-j3jr/GHSA-7r38-qg56-j3jr.json index 90a8830a415..ef6cafb6918 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r38-qg56-j3jr/GHSA-7r38-qg56-j3jr.json +++ b/advisories/unreviewed/2022/05/GHSA-7r38-qg56-j3jr/GHSA-7r38-qg56-j3jr.json @@ -7,12 +7,8 @@ "CVE-2008-3363" ], "details": "Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\\ (dot dot backslash) in the include parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r3g-vgrw-wm39/GHSA-7r3g-vgrw-wm39.json b/advisories/unreviewed/2022/05/GHSA-7r3g-vgrw-wm39/GHSA-7r3g-vgrw-wm39.json index 73040489d10..c557d605c6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r3g-vgrw-wm39/GHSA-7r3g-vgrw-wm39.json +++ b/advisories/unreviewed/2022/05/GHSA-7r3g-vgrw-wm39/GHSA-7r3g-vgrw-wm39.json @@ -7,12 +7,8 @@ "CVE-2008-3780" ], "details": "SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL commands via the item_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rjc-f79q-gj8v/GHSA-7rjc-f79q-gj8v.json b/advisories/unreviewed/2022/05/GHSA-7rjc-f79q-gj8v/GHSA-7rjc-f79q-gj8v.json index dd1c71339a9..d5b370ef583 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rjc-f79q-gj8v/GHSA-7rjc-f79q-gj8v.json +++ b/advisories/unreviewed/2022/05/GHSA-7rjc-f79q-gj8v/GHSA-7rjc-f79q-gj8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vxv-78cg-w3q2/GHSA-7vxv-78cg-w3q2.json b/advisories/unreviewed/2022/05/GHSA-7vxv-78cg-w3q2/GHSA-7vxv-78cg-w3q2.json index 313e7777f77..835676e84fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vxv-78cg-w3q2/GHSA-7vxv-78cg-w3q2.json +++ b/advisories/unreviewed/2022/05/GHSA-7vxv-78cg-w3q2/GHSA-7vxv-78cg-w3q2.json @@ -7,12 +7,8 @@ "CVE-2008-3681" ], "details": "components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the \"first enabled user (lowest id)\" password, typically for the administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wxw-4483-3m34/GHSA-7wxw-4483-3m34.json b/advisories/unreviewed/2022/05/GHSA-7wxw-4483-3m34/GHSA-7wxw-4483-3m34.json index ae370634195..591d54ea084 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wxw-4483-3m34/GHSA-7wxw-4483-3m34.json +++ b/advisories/unreviewed/2022/05/GHSA-7wxw-4483-3m34/GHSA-7wxw-4483-3m34.json @@ -7,12 +7,8 @@ "CVE-2022-29361" ], "details": "Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x52-8p86-5px9/GHSA-7x52-8p86-5px9.json b/advisories/unreviewed/2022/05/GHSA-7x52-8p86-5px9/GHSA-7x52-8p86-5px9.json index 2ce14d830f8..5d863af5dfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x52-8p86-5px9/GHSA-7x52-8p86-5px9.json +++ b/advisories/unreviewed/2022/05/GHSA-7x52-8p86-5px9/GHSA-7x52-8p86-5px9.json @@ -7,12 +7,8 @@ "CVE-2008-3531" ], "details": "Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of \"user defined data\" in \"certain error conditions.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x55-hhmx-cg29/GHSA-7x55-hhmx-cg29.json b/advisories/unreviewed/2022/05/GHSA-7x55-hhmx-cg29/GHSA-7x55-hhmx-cg29.json index fc609a5f2dd..a8cf5d9ac86 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x55-hhmx-cg29/GHSA-7x55-hhmx-cg29.json +++ b/advisories/unreviewed/2022/05/GHSA-7x55-hhmx-cg29/GHSA-7x55-hhmx-cg29.json @@ -7,12 +7,8 @@ "CVE-2008-3265" ], "details": "SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_options action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8232-c5fm-5f68/GHSA-8232-c5fm-5f68.json b/advisories/unreviewed/2022/05/GHSA-8232-c5fm-5f68/GHSA-8232-c5fm-5f68.json index 23e24bbd7fb..dc4ba2ee954 100644 --- a/advisories/unreviewed/2022/05/GHSA-8232-c5fm-5f68/GHSA-8232-c5fm-5f68.json +++ b/advisories/unreviewed/2022/05/GHSA-8232-c5fm-5f68/GHSA-8232-c5fm-5f68.json @@ -7,12 +7,8 @@ "CVE-2008-3554" ], "details": "SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-823x-6r7f-v9x6/GHSA-823x-6r7f-v9x6.json b/advisories/unreviewed/2022/05/GHSA-823x-6r7f-v9x6/GHSA-823x-6r7f-v9x6.json index d73a8d2155a..c02930da8ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-823x-6r7f-v9x6/GHSA-823x-6r7f-v9x6.json +++ b/advisories/unreviewed/2022/05/GHSA-823x-6r7f-v9x6/GHSA-823x-6r7f-v9x6.json @@ -7,12 +7,8 @@ "CVE-2008-3656" ], "details": "Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -140,9 +136,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-827c-w44j-24gr/GHSA-827c-w44j-24gr.json b/advisories/unreviewed/2022/05/GHSA-827c-w44j-24gr/GHSA-827c-w44j-24gr.json index 121a32fe4de..7451486dc99 100644 --- a/advisories/unreviewed/2022/05/GHSA-827c-w44j-24gr/GHSA-827c-w44j-24gr.json +++ b/advisories/unreviewed/2022/05/GHSA-827c-w44j-24gr/GHSA-827c-w44j-24gr.json @@ -7,12 +7,8 @@ "CVE-2008-3208" ], "details": "Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82xr-fmv3-39p4/GHSA-82xr-fmv3-39p4.json b/advisories/unreviewed/2022/05/GHSA-82xr-fmv3-39p4/GHSA-82xr-fmv3-39p4.json index 31b581567c7..eb5aa60c289 100644 --- a/advisories/unreviewed/2022/05/GHSA-82xr-fmv3-39p4/GHSA-82xr-fmv3-39p4.json +++ b/advisories/unreviewed/2022/05/GHSA-82xr-fmv3-39p4/GHSA-82xr-fmv3-39p4.json @@ -7,12 +7,8 @@ "CVE-2008-3676" ], "details": "Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83j4-67f2-p565/GHSA-83j4-67f2-p565.json b/advisories/unreviewed/2022/05/GHSA-83j4-67f2-p565/GHSA-83j4-67f2-p565.json index 33404c32c11..5478a669ca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-83j4-67f2-p565/GHSA-83j4-67f2-p565.json +++ b/advisories/unreviewed/2022/05/GHSA-83j4-67f2-p565/GHSA-83j4-67f2-p565.json @@ -7,12 +7,8 @@ "CVE-2008-3520" ], "details": "Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88jr-vwr6-7xqw/GHSA-88jr-vwr6-7xqw.json b/advisories/unreviewed/2022/05/GHSA-88jr-vwr6-7xqw/GHSA-88jr-vwr6-7xqw.json index 81aac61a2c7..c8aeaf83d37 100644 --- a/advisories/unreviewed/2022/05/GHSA-88jr-vwr6-7xqw/GHSA-88jr-vwr6-7xqw.json +++ b/advisories/unreviewed/2022/05/GHSA-88jr-vwr6-7xqw/GHSA-88jr-vwr6-7xqw.json @@ -7,12 +7,8 @@ "CVE-2008-3716" ], "details": "Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save or (2) delete action to an unspecified component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89h8-q7jq-33gw/GHSA-89h8-q7jq-33gw.json b/advisories/unreviewed/2022/05/GHSA-89h8-q7jq-33gw/GHSA-89h8-q7jq-33gw.json index 0ea818d1b42..dd9e1d72e04 100644 --- a/advisories/unreviewed/2022/05/GHSA-89h8-q7jq-33gw/GHSA-89h8-q7jq-33gw.json +++ b/advisories/unreviewed/2022/05/GHSA-89h8-q7jq-33gw/GHSA-89h8-q7jq-33gw.json @@ -7,12 +7,8 @@ "CVE-2008-3449" ], "details": "MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote attackers to cause a denial of service (crash) via multiple IMAP connection requests to the same folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c5h-pgpw-2c92/GHSA-8c5h-pgpw-2c92.json b/advisories/unreviewed/2022/05/GHSA-8c5h-pgpw-2c92/GHSA-8c5h-pgpw-2c92.json index ed72d38be06..c06a7251829 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c5h-pgpw-2c92/GHSA-8c5h-pgpw-2c92.json +++ b/advisories/unreviewed/2022/05/GHSA-8c5h-pgpw-2c92/GHSA-8c5h-pgpw-2c92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cfx-q5cm-x4rc/GHSA-8cfx-q5cm-x4rc.json b/advisories/unreviewed/2022/05/GHSA-8cfx-q5cm-x4rc/GHSA-8cfx-q5cm-x4rc.json index 9737405c6cf..e72c5e20838 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cfx-q5cm-x4rc/GHSA-8cfx-q5cm-x4rc.json +++ b/advisories/unreviewed/2022/05/GHSA-8cfx-q5cm-x4rc/GHSA-8cfx-q5cm-x4rc.json @@ -7,12 +7,8 @@ "CVE-2008-3414" ], "details": "SQL injection vulnerability in line2.php in SiteAdmin allows remote attackers to execute arbitrary SQL commands via the art parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8crm-vpm6-5897/GHSA-8crm-vpm6-5897.json b/advisories/unreviewed/2022/05/GHSA-8crm-vpm6-5897/GHSA-8crm-vpm6-5897.json index 1b7643f7947..b2302873e25 100644 --- a/advisories/unreviewed/2022/05/GHSA-8crm-vpm6-5897/GHSA-8crm-vpm6-5897.json +++ b/advisories/unreviewed/2022/05/GHSA-8crm-vpm6-5897/GHSA-8crm-vpm6-5897.json @@ -7,12 +7,8 @@ "CVE-2008-3617" ], "details": "Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwords that the user believed were longer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8g63-xg9f-396j/GHSA-8g63-xg9f-396j.json b/advisories/unreviewed/2022/05/GHSA-8g63-xg9f-396j/GHSA-8g63-xg9f-396j.json index 890aefe833e..f2d60b8a1dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g63-xg9f-396j/GHSA-8g63-xg9f-396j.json +++ b/advisories/unreviewed/2022/05/GHSA-8g63-xg9f-396j/GHSA-8g63-xg9f-396j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jmp-x4g8-vpg8/GHSA-8jmp-x4g8-vpg8.json b/advisories/unreviewed/2022/05/GHSA-8jmp-x4g8-vpg8/GHSA-8jmp-x4g8-vpg8.json index f115ae788de..cc4f2067816 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jmp-x4g8-vpg8/GHSA-8jmp-x4g8-vpg8.json +++ b/advisories/unreviewed/2022/05/GHSA-8jmp-x4g8-vpg8/GHSA-8jmp-x4g8-vpg8.json @@ -7,12 +7,8 @@ "CVE-2008-3464" ], "details": "afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka \"AFD Kernel Overwrite Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8m46-fv52-2gq6/GHSA-8m46-fv52-2gq6.json b/advisories/unreviewed/2022/05/GHSA-8m46-fv52-2gq6/GHSA-8m46-fv52-2gq6.json index 61e6ca9baf3..8d9131bd299 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m46-fv52-2gq6/GHSA-8m46-fv52-2gq6.json +++ b/advisories/unreviewed/2022/05/GHSA-8m46-fv52-2gq6/GHSA-8m46-fv52-2gq6.json @@ -7,12 +7,8 @@ "CVE-2008-3246" ], "details": "Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m7j-fh9p-8j92/GHSA-8m7j-fh9p-8j92.json b/advisories/unreviewed/2022/05/GHSA-8m7j-fh9p-8j92/GHSA-8m7j-fh9p-8j92.json index 6fecffbbf76..1f3589f9d6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m7j-fh9p-8j92/GHSA-8m7j-fh9p-8j92.json +++ b/advisories/unreviewed/2022/05/GHSA-8m7j-fh9p-8j92/GHSA-8m7j-fh9p-8j92.json @@ -7,12 +7,8 @@ "CVE-2008-3654" ], "details": "Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain \"path and PHP configuration\" via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q2h-5hcv-g245/GHSA-8q2h-5hcv-g245.json b/advisories/unreviewed/2022/05/GHSA-8q2h-5hcv-g245/GHSA-8q2h-5hcv-g245.json index 735c5a86c3c..fa546edcc3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q2h-5hcv-g245/GHSA-8q2h-5hcv-g245.json +++ b/advisories/unreviewed/2022/05/GHSA-8q2h-5hcv-g245/GHSA-8q2h-5hcv-g245.json @@ -7,12 +7,8 @@ "CVE-2008-3784" ], "details": "SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qwf-cxw2-23h9/GHSA-8qwf-cxw2-23h9.json b/advisories/unreviewed/2022/05/GHSA-8qwf-cxw2-23h9/GHSA-8qwf-cxw2-23h9.json index e9bd45ae20f..e29aae205d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qwf-cxw2-23h9/GHSA-8qwf-cxw2-23h9.json +++ b/advisories/unreviewed/2022/05/GHSA-8qwf-cxw2-23h9/GHSA-8qwf-cxw2-23h9.json @@ -7,12 +7,8 @@ "CVE-2008-3216" ], "details": "The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, which allows local users to overwrite arbitrary files via a symlink attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w5w-hcg8-56w5/GHSA-8w5w-hcg8-56w5.json b/advisories/unreviewed/2022/05/GHSA-8w5w-hcg8-56w5/GHSA-8w5w-hcg8-56w5.json index 0e95cf1157c..e6f43afe704 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w5w-hcg8-56w5/GHSA-8w5w-hcg8-56w5.json +++ b/advisories/unreviewed/2022/05/GHSA-8w5w-hcg8-56w5/GHSA-8w5w-hcg8-56w5.json @@ -7,12 +7,8 @@ "CVE-2008-3350" ], "details": "dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an \"unknown client,\" a different vulnerability than CVE-2008-3214.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w65-2vcm-r8rh/GHSA-8w65-2vcm-r8rh.json b/advisories/unreviewed/2022/05/GHSA-8w65-2vcm-r8rh/GHSA-8w65-2vcm-r8rh.json index 5d30859956f..2b5c8f80ff6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w65-2vcm-r8rh/GHSA-8w65-2vcm-r8rh.json +++ b/advisories/unreviewed/2022/05/GHSA-8w65-2vcm-r8rh/GHSA-8w65-2vcm-r8rh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x9m-rr2c-2g59/GHSA-8x9m-rr2c-2g59.json b/advisories/unreviewed/2022/05/GHSA-8x9m-rr2c-2g59/GHSA-8x9m-rr2c-2g59.json index 29cab7d2d12..25e6cff0835 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x9m-rr2c-2g59/GHSA-8x9m-rr2c-2g59.json +++ b/advisories/unreviewed/2022/05/GHSA-8x9m-rr2c-2g59/GHSA-8x9m-rr2c-2g59.json @@ -7,12 +7,8 @@ "CVE-2008-3196" ], "details": "skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an out-of-bounds stack access when the yacc stack pointer points to the end of the stack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xqm-3qm5-qhfv/GHSA-8xqm-3qm5-qhfv.json b/advisories/unreviewed/2022/05/GHSA-8xqm-3qm5-qhfv/GHSA-8xqm-3qm5-qhfv.json index 408d09b8dbc..3e340df98fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xqm-3qm5-qhfv/GHSA-8xqm-3qm5-qhfv.json +++ b/advisories/unreviewed/2022/05/GHSA-8xqm-3qm5-qhfv/GHSA-8xqm-3qm5-qhfv.json @@ -7,12 +7,8 @@ "CVE-2008-3226" ], "details": "The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-926x-7qx8-c8j2/GHSA-926x-7qx8-c8j2.json b/advisories/unreviewed/2022/05/GHSA-926x-7qx8-c8j2/GHSA-926x-7qx8-c8j2.json index f2336960696..af5511fee66 100644 --- a/advisories/unreviewed/2022/05/GHSA-926x-7qx8-c8j2/GHSA-926x-7qx8-c8j2.json +++ b/advisories/unreviewed/2022/05/GHSA-926x-7qx8-c8j2/GHSA-926x-7qx8-c8j2.json @@ -7,12 +7,8 @@ "CVE-2008-3303" ], "details": "admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93cc-m3wp-rrvv/GHSA-93cc-m3wp-rrvv.json b/advisories/unreviewed/2022/05/GHSA-93cc-m3wp-rrvv/GHSA-93cc-m3wp-rrvv.json index 5c982d84435..90998553714 100644 --- a/advisories/unreviewed/2022/05/GHSA-93cc-m3wp-rrvv/GHSA-93cc-m3wp-rrvv.json +++ b/advisories/unreviewed/2022/05/GHSA-93cc-m3wp-rrvv/GHSA-93cc-m3wp-rrvv.json @@ -7,12 +7,8 @@ "CVE-2008-3630" ], "details": "mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93g3-w782-9mvg/GHSA-93g3-w782-9mvg.json b/advisories/unreviewed/2022/05/GHSA-93g3-w782-9mvg/GHSA-93g3-w782-9mvg.json index e7e43564adc..cbb07046bf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-93g3-w782-9mvg/GHSA-93g3-w782-9mvg.json +++ b/advisories/unreviewed/2022/05/GHSA-93g3-w782-9mvg/GHSA-93g3-w782-9mvg.json @@ -7,12 +7,8 @@ "CVE-2008-3190" ], "details": "Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9437-qw97-j6jh/GHSA-9437-qw97-j6jh.json b/advisories/unreviewed/2022/05/GHSA-9437-qw97-j6jh/GHSA-9437-qw97-j6jh.json index 29f704be17b..1c927610bbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-9437-qw97-j6jh/GHSA-9437-qw97-j6jh.json +++ b/advisories/unreviewed/2022/05/GHSA-9437-qw97-j6jh/GHSA-9437-qw97-j6jh.json @@ -7,12 +7,8 @@ "CVE-2008-3497" ], "details": "SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9473-43qc-4q4f/GHSA-9473-43qc-4q4f.json b/advisories/unreviewed/2022/05/GHSA-9473-43qc-4q4f/GHSA-9473-43qc-4q4f.json index fb699a60795..4139e9fb37c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9473-43qc-4q4f/GHSA-9473-43qc-4q4f.json +++ b/advisories/unreviewed/2022/05/GHSA-9473-43qc-4q4f/GHSA-9473-43qc-4q4f.json @@ -7,12 +7,8 @@ "CVE-2008-3664" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php, (5) the last_name parameter to contacts/some.php, (6) the campaign_title parameter to campaigns/some.php, (7) the opportunity_title parameter to opportunities/some.php, (8) the case_title parameter to cases/some.php, (9) the file_id parameter to files/some.php, or (10) the starting parameter to reports/custom/mileage.php, a related issue to CVE-2008-1129.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9523-2mc9-2q3g/GHSA-9523-2mc9-2q3g.json b/advisories/unreviewed/2022/05/GHSA-9523-2mc9-2q3g/GHSA-9523-2mc9-2q3g.json index 0fb88a726b6..8e1dfeb3aa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9523-2mc9-2q3g/GHSA-9523-2mc9-2q3g.json +++ b/advisories/unreviewed/2022/05/GHSA-9523-2mc9-2q3g/GHSA-9523-2mc9-2q3g.json @@ -7,12 +7,8 @@ "CVE-2008-3455" ], "details": "PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95r5-wf73-r6cq/GHSA-95r5-wf73-r6cq.json b/advisories/unreviewed/2022/05/GHSA-95r5-wf73-r6cq/GHSA-95r5-wf73-r6cq.json index 881ac4816ad..380a3e613b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-95r5-wf73-r6cq/GHSA-95r5-wf73-r6cq.json +++ b/advisories/unreviewed/2022/05/GHSA-95r5-wf73-r6cq/GHSA-95r5-wf73-r6cq.json @@ -7,12 +7,8 @@ "CVE-2008-3305" ], "details": "Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or HTML via the m parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95vq-m8f4-gh6c/GHSA-95vq-m8f4-gh6c.json b/advisories/unreviewed/2022/05/GHSA-95vq-m8f4-gh6c/GHSA-95vq-m8f4-gh6c.json index df7fb3f151a..123ebdef7c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-95vq-m8f4-gh6c/GHSA-95vq-m8f4-gh6c.json +++ b/advisories/unreviewed/2022/05/GHSA-95vq-m8f4-gh6c/GHSA-95vq-m8f4-gh6c.json @@ -7,12 +7,8 @@ "CVE-2008-3389" ], "details": "Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-964m-5c8q-r3w3/GHSA-964m-5c8q-r3w3.json b/advisories/unreviewed/2022/05/GHSA-964m-5c8q-r3w3/GHSA-964m-5c8q-r3w3.json index a5d8bf79178..1d9c9e980c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-964m-5c8q-r3w3/GHSA-964m-5c8q-r3w3.json +++ b/advisories/unreviewed/2022/05/GHSA-964m-5c8q-r3w3/GHSA-964m-5c8q-r3w3.json @@ -7,12 +7,8 @@ "CVE-2008-3251" ], "details": "Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the opp parameter to tampereunited/opponent.php; or the id parameter to (2) index.php, (3) player.php, (4) matchdetails.php, or (5) additionalpage.php in tampereunited/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-966g-5893-w2jh/GHSA-966g-5893-w2jh.json b/advisories/unreviewed/2022/05/GHSA-966g-5893-w2jh/GHSA-966g-5893-w2jh.json index 94e47ca60dc..fb261ece69a 100644 --- a/advisories/unreviewed/2022/05/GHSA-966g-5893-w2jh/GHSA-966g-5893-w2jh.json +++ b/advisories/unreviewed/2022/05/GHSA-966g-5893-w2jh/GHSA-966g-5893-w2jh.json @@ -7,12 +7,8 @@ "CVE-2008-3221" ], "details": "Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-969c-936f-xr59/GHSA-969c-936f-xr59.json b/advisories/unreviewed/2022/05/GHSA-969c-936f-xr59/GHSA-969c-936f-xr59.json index ede79c55e30..56dffd949d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-969c-936f-xr59/GHSA-969c-936f-xr59.json +++ b/advisories/unreviewed/2022/05/GHSA-969c-936f-xr59/GHSA-969c-936f-xr59.json @@ -7,12 +7,8 @@ "CVE-2008-3579" ], "details": "Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree. NOTE: this can be leveraged for remote exploitation of CVE-2008-3395. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96jc-f6m3-pf2w/GHSA-96jc-f6m3-pf2w.json b/advisories/unreviewed/2022/05/GHSA-96jc-f6m3-pf2w/GHSA-96jc-f6m3-pf2w.json index 58eebd8f7a8..b829d745cc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-96jc-f6m3-pf2w/GHSA-96jc-f6m3-pf2w.json +++ b/advisories/unreviewed/2022/05/GHSA-96jc-f6m3-pf2w/GHSA-96jc-f6m3-pf2w.json @@ -7,12 +7,8 @@ "CVE-2008-3790" ], "details": "The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an \"XML entity explosion.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96xw-j757-pwp4/GHSA-96xw-j757-pwp4.json b/advisories/unreviewed/2022/05/GHSA-96xw-j757-pwp4/GHSA-96xw-j757-pwp4.json index d74ee2b3890..5449f15dbf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-96xw-j757-pwp4/GHSA-96xw-j757-pwp4.json +++ b/advisories/unreviewed/2022/05/GHSA-96xw-j757-pwp4/GHSA-96xw-j757-pwp4.json @@ -7,12 +7,8 @@ "CVE-2008-3401" ], "details": "PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97x3-pw87-2536/GHSA-97x3-pw87-2536.json b/advisories/unreviewed/2022/05/GHSA-97x3-pw87-2536/GHSA-97x3-pw87-2536.json index 18bc86766bf..6c57cf7b52c 100644 --- a/advisories/unreviewed/2022/05/GHSA-97x3-pw87-2536/GHSA-97x3-pw87-2536.json +++ b/advisories/unreviewed/2022/05/GHSA-97x3-pw87-2536/GHSA-97x3-pw87-2536.json @@ -7,12 +7,8 @@ "CVE-2008-3371" ], "details": "Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9858-8hj9-8c32/GHSA-9858-8hj9-8c32.json b/advisories/unreviewed/2022/05/GHSA-9858-8hj9-8c32/GHSA-9858-8hj9-8c32.json index 2b2aea38a35..6f8c771788b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9858-8hj9-8c32/GHSA-9858-8hj9-8c32.json +++ b/advisories/unreviewed/2022/05/GHSA-9858-8hj9-8c32/GHSA-9858-8hj9-8c32.json @@ -7,12 +7,8 @@ "CVE-2008-3343" ], "details": "SQL injection vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr (trial edition) allows remote attackers to execute arbitrary SQL commands via the read parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98hf-4cc2-h3vx/GHSA-98hf-4cc2-h3vx.json b/advisories/unreviewed/2022/05/GHSA-98hf-4cc2-h3vx/GHSA-98hf-4cc2-h3vx.json index 706a07b00f3..e7e9e5ce42d 100644 --- a/advisories/unreviewed/2022/05/GHSA-98hf-4cc2-h3vx/GHSA-98hf-4cc2-h3vx.json +++ b/advisories/unreviewed/2022/05/GHSA-98hf-4cc2-h3vx/GHSA-98hf-4cc2-h3vx.json @@ -7,12 +7,8 @@ "CVE-2008-3242" ], "details": "Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code via a long argument to the StartUrl method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99mr-vp63-623f/GHSA-99mr-vp63-623f.json b/advisories/unreviewed/2022/05/GHSA-99mr-vp63-623f/GHSA-99mr-vp63-623f.json index 9787960a637..e699f0860f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-99mr-vp63-623f/GHSA-99mr-vp63-623f.json +++ b/advisories/unreviewed/2022/05/GHSA-99mr-vp63-623f/GHSA-99mr-vp63-623f.json @@ -7,12 +7,8 @@ "CVE-2008-3491" ], "details": "SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c82-jpgp-p5fv/GHSA-9c82-jpgp-p5fv.json b/advisories/unreviewed/2022/05/GHSA-9c82-jpgp-p5fv/GHSA-9c82-jpgp-p5fv.json index c84135d0b80..3071d67f42b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c82-jpgp-p5fv/GHSA-9c82-jpgp-p5fv.json +++ b/advisories/unreviewed/2022/05/GHSA-9c82-jpgp-p5fv/GHSA-9c82-jpgp-p5fv.json @@ -7,12 +7,8 @@ "CVE-2008-3577" ], "details": "Buffer overflow in src/openttd.cpp in OpenTTD before 0.6.2 allows local users to execute arbitrary code via a large filename supplied to the \"-g\" parameter in the ttd_main function. NOTE: it is unlikely that this issue would cross privilege boundaries in typical environments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f28-9xr6-9x86/GHSA-9f28-9xr6-9x86.json b/advisories/unreviewed/2022/05/GHSA-9f28-9xr6-9x86/GHSA-9f28-9xr6-9x86.json index daaa274e6d2..5eaf47f2e44 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f28-9xr6-9x86/GHSA-9f28-9xr6-9x86.json +++ b/advisories/unreviewed/2022/05/GHSA-9f28-9xr6-9x86/GHSA-9f28-9xr6-9x86.json @@ -7,12 +7,8 @@ "CVE-2008-3770" ], "details": "Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) includes/events_application_top.php; (2) english/account.php, (3) french/account.php, and (4) french/account_newsletters.php in includes/languages/; (5) includes/modules/faqdesk/faqdesk_article_require.php; (6) includes/modules/newsdesk/newsdesk_article_require.php; (7) card1.php, (8) loginbox.php, and (9) whos_online.php in templates/Freeway/boxes/; and (10) templates/Freeway/mainpage_modules/mainpage.php. NOTE: vector 1 may be the same as CVE-2008-3677.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9ff2-x459-g4fm/GHSA-9ff2-x459-g4fm.json b/advisories/unreviewed/2022/05/GHSA-9ff2-x459-g4fm/GHSA-9ff2-x459-g4fm.json index 9214894cc0d..107e48c7b43 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ff2-x459-g4fm/GHSA-9ff2-x459-g4fm.json +++ b/advisories/unreviewed/2022/05/GHSA-9ff2-x459-g4fm/GHSA-9ff2-x459-g4fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fmh-xr8c-xwr3/GHSA-9fmh-xr8c-xwr3.json b/advisories/unreviewed/2022/05/GHSA-9fmh-xr8c-xwr3/GHSA-9fmh-xr8c-xwr3.json index abbf57da66b..52290c3bab5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fmh-xr8c-xwr3/GHSA-9fmh-xr8c-xwr3.json +++ b/advisories/unreviewed/2022/05/GHSA-9fmh-xr8c-xwr3/GHSA-9fmh-xr8c-xwr3.json @@ -7,12 +7,8 @@ "CVE-2008-3776" ], "details": "Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gcx-wpv9-6wq2/GHSA-9gcx-wpv9-6wq2.json b/advisories/unreviewed/2022/05/GHSA-9gcx-wpv9-6wq2/GHSA-9gcx-wpv9-6wq2.json index a752c845cba..35357c5b904 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gcx-wpv9-6wq2/GHSA-9gcx-wpv9-6wq2.json +++ b/advisories/unreviewed/2022/05/GHSA-9gcx-wpv9-6wq2/GHSA-9gcx-wpv9-6wq2.json @@ -7,12 +7,8 @@ "CVE-2008-3567" ], "details": "Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gpc-3gv5-6qvm/GHSA-9gpc-3gv5-6qvm.json b/advisories/unreviewed/2022/05/GHSA-9gpc-3gv5-6qvm/GHSA-9gpc-3gv5-6qvm.json index 3bc3ad49b63..0f996cb189c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gpc-3gv5-6qvm/GHSA-9gpc-3gv5-6qvm.json +++ b/advisories/unreviewed/2022/05/GHSA-9gpc-3gv5-6qvm/GHSA-9gpc-3gv5-6qvm.json @@ -7,12 +7,8 @@ "CVE-2008-3548" ], "details": "Unspecified vulnerability in the Sun Netra T5220 Server with firmware 7.1.3 allows local users to cause a denial of service (panic) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hxq-m375-pvm5/GHSA-9hxq-m375-pvm5.json b/advisories/unreviewed/2022/05/GHSA-9hxq-m375-pvm5/GHSA-9hxq-m375-pvm5.json index db0bafae0bc..eaf0586c13c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hxq-m375-pvm5/GHSA-9hxq-m375-pvm5.json +++ b/advisories/unreviewed/2022/05/GHSA-9hxq-m375-pvm5/GHSA-9hxq-m375-pvm5.json @@ -7,12 +7,8 @@ "CVE-2008-3425" ], "details": "Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j8p-prj8-xgq2/GHSA-9j8p-prj8-xgq2.json b/advisories/unreviewed/2022/05/GHSA-9j8p-prj8-xgq2/GHSA-9j8p-prj8-xgq2.json index e76647d30c3..43ea6bdf9c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j8p-prj8-xgq2/GHSA-9j8p-prj8-xgq2.json +++ b/advisories/unreviewed/2022/05/GHSA-9j8p-prj8-xgq2/GHSA-9j8p-prj8-xgq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j9v-m448-289r/GHSA-9j9v-m448-289r.json b/advisories/unreviewed/2022/05/GHSA-9j9v-m448-289r/GHSA-9j9v-m448-289r.json index d182c9da3f8..09c4ae6064c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j9v-m448-289r/GHSA-9j9v-m448-289r.json +++ b/advisories/unreviewed/2022/05/GHSA-9j9v-m448-289r/GHSA-9j9v-m448-289r.json @@ -7,12 +7,8 @@ "CVE-2008-3594" ], "details": "SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jwx-rr6x-pc37/GHSA-9jwx-rr6x-pc37.json b/advisories/unreviewed/2022/05/GHSA-9jwx-rr6x-pc37/GHSA-9jwx-rr6x-pc37.json index 1f1e0dc9caa..dcb521bc4fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jwx-rr6x-pc37/GHSA-9jwx-rr6x-pc37.json +++ b/advisories/unreviewed/2022/05/GHSA-9jwx-rr6x-pc37/GHSA-9jwx-rr6x-pc37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m4p-crvg-9php/GHSA-9m4p-crvg-9php.json b/advisories/unreviewed/2022/05/GHSA-9m4p-crvg-9php/GHSA-9m4p-crvg-9php.json index 8c00f09cb40..89e1c456daa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m4p-crvg-9php/GHSA-9m4p-crvg-9php.json +++ b/advisories/unreviewed/2022/05/GHSA-9m4p-crvg-9php/GHSA-9m4p-crvg-9php.json @@ -7,12 +7,8 @@ "CVE-2008-3494" ], "details": "8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text placed before the real Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mw4-6qxp-xf48/GHSA-9mw4-6qxp-xf48.json b/advisories/unreviewed/2022/05/GHSA-9mw4-6qxp-xf48/GHSA-9mw4-6qxp-xf48.json index c1eaa338419..b587c73771a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mw4-6qxp-xf48/GHSA-9mw4-6qxp-xf48.json +++ b/advisories/unreviewed/2022/05/GHSA-9mw4-6qxp-xf48/GHSA-9mw4-6qxp-xf48.json @@ -7,12 +7,8 @@ "CVE-2008-3635" ], "details": "Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9phx-98pq-vfhc/GHSA-9phx-98pq-vfhc.json b/advisories/unreviewed/2022/05/GHSA-9phx-98pq-vfhc/GHSA-9phx-98pq-vfhc.json index 86c52e59c06..9e9b6aed673 100644 --- a/advisories/unreviewed/2022/05/GHSA-9phx-98pq-vfhc/GHSA-9phx-98pq-vfhc.json +++ b/advisories/unreviewed/2022/05/GHSA-9phx-98pq-vfhc/GHSA-9phx-98pq-vfhc.json @@ -7,12 +7,8 @@ "CVE-2008-3267" ], "details": "SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v65-qh6p-rfjx/GHSA-9v65-qh6p-rfjx.json b/advisories/unreviewed/2022/05/GHSA-9v65-qh6p-rfjx/GHSA-9v65-qh6p-rfjx.json index 35a06989005..e58d45bb2b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v65-qh6p-rfjx/GHSA-9v65-qh6p-rfjx.json +++ b/advisories/unreviewed/2022/05/GHSA-9v65-qh6p-rfjx/GHSA-9v65-qh6p-rfjx.json @@ -7,12 +7,8 @@ "CVE-2008-3501" ], "details": "Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vjx-8hr9-q3m8/GHSA-9vjx-8hr9-q3m8.json b/advisories/unreviewed/2022/05/GHSA-9vjx-8hr9-q3m8/GHSA-9vjx-8hr9-q3m8.json index d5fef6cd6d8..0735e11d3c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vjx-8hr9-q3m8/GHSA-9vjx-8hr9-q3m8.json +++ b/advisories/unreviewed/2022/05/GHSA-9vjx-8hr9-q3m8/GHSA-9vjx-8hr9-q3m8.json @@ -7,12 +7,8 @@ "CVE-2008-3575" ], "details": "PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[gsLanguage] parameter, a different vector than CVE-2006-4477 and CVE-2004-0132.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wfv-8j45-cmcm/GHSA-9wfv-8j45-cmcm.json b/advisories/unreviewed/2022/05/GHSA-9wfv-8j45-cmcm/GHSA-9wfv-8j45-cmcm.json index 1b5b01e1044..be994213c51 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wfv-8j45-cmcm/GHSA-9wfv-8j45-cmcm.json +++ b/advisories/unreviewed/2022/05/GHSA-9wfv-8j45-cmcm/GHSA-9wfv-8j45-cmcm.json @@ -7,12 +7,8 @@ "CVE-2008-3510" ], "details": "Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wp7-f3qm-xjw3/GHSA-9wp7-f3qm-xjw3.json b/advisories/unreviewed/2022/05/GHSA-9wp7-f3qm-xjw3/GHSA-9wp7-f3qm-xjw3.json index ecc5cde6678..02f94b64d06 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wp7-f3qm-xjw3/GHSA-9wp7-f3qm-xjw3.json +++ b/advisories/unreviewed/2022/05/GHSA-9wp7-f3qm-xjw3/GHSA-9wp7-f3qm-xjw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wxh-7x8m-qp95/GHSA-9wxh-7x8m-qp95.json b/advisories/unreviewed/2022/05/GHSA-9wxh-7x8m-qp95/GHSA-9wxh-7x8m-qp95.json index 9e64e35ae85..7dbfd6a610b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wxh-7x8m-qp95/GHSA-9wxh-7x8m-qp95.json +++ b/advisories/unreviewed/2022/05/GHSA-9wxh-7x8m-qp95/GHSA-9wxh-7x8m-qp95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wxq-4x84-r573/GHSA-9wxq-4x84-r573.json b/advisories/unreviewed/2022/05/GHSA-9wxq-4x84-r573/GHSA-9wxq-4x84-r573.json index d14b003493f..d28ffbda231 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wxq-4x84-r573/GHSA-9wxq-4x84-r573.json +++ b/advisories/unreviewed/2022/05/GHSA-9wxq-4x84-r573/GHSA-9wxq-4x84-r573.json @@ -7,12 +7,8 @@ "CVE-2008-3451" ], "details": "PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x72-fmxc-qq9c/GHSA-9x72-fmxc-qq9c.json b/advisories/unreviewed/2022/05/GHSA-9x72-fmxc-qq9c/GHSA-9x72-fmxc-qq9c.json index 8f888f94590..9986b9f257f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x72-fmxc-qq9c/GHSA-9x72-fmxc-qq9c.json +++ b/advisories/unreviewed/2022/05/GHSA-9x72-fmxc-qq9c/GHSA-9x72-fmxc-qq9c.json @@ -7,12 +7,8 @@ "CVE-2008-3439" ], "details": "SpeedBit Video Acceleration before 2.2.1.8 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xjm-h68j-x49g/GHSA-9xjm-h68j-x49g.json b/advisories/unreviewed/2022/05/GHSA-9xjm-h68j-x49g/GHSA-9xjm-h68j-x49g.json index 4c5289f4d3b..30535aade97 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xjm-h68j-x49g/GHSA-9xjm-h68j-x49g.json +++ b/advisories/unreviewed/2022/05/GHSA-9xjm-h68j-x49g/GHSA-9xjm-h68j-x49g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2cp-r782-35vp/GHSA-c2cp-r782-35vp.json b/advisories/unreviewed/2022/05/GHSA-c2cp-r782-35vp/GHSA-c2cp-r782-35vp.json index 9cf6b3ec577..6924059d429 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2cp-r782-35vp/GHSA-c2cp-r782-35vp.json +++ b/advisories/unreviewed/2022/05/GHSA-c2cp-r782-35vp/GHSA-c2cp-r782-35vp.json @@ -7,12 +7,8 @@ "CVE-2008-3799" ], "details": "Memory leak in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (memory consumption and voice-service outage) via unspecified valid SIP messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c357-8cjh-v75m/GHSA-c357-8cjh-v75m.json b/advisories/unreviewed/2022/05/GHSA-c357-8cjh-v75m/GHSA-c357-8cjh-v75m.json index f14dea04113..aa4f342a99c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c357-8cjh-v75m/GHSA-c357-8cjh-v75m.json +++ b/advisories/unreviewed/2022/05/GHSA-c357-8cjh-v75m/GHSA-c357-8cjh-v75m.json @@ -7,12 +7,8 @@ "CVE-2008-3508" ], "details": "LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c447-x4qr-v4cm/GHSA-c447-x4qr-v4cm.json b/advisories/unreviewed/2022/05/GHSA-c447-x4qr-v4cm/GHSA-c447-x4qr-v4cm.json index 9523adc2a11..c42aceb12c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c447-x4qr-v4cm/GHSA-c447-x4qr-v4cm.json +++ b/advisories/unreviewed/2022/05/GHSA-c447-x4qr-v4cm/GHSA-c447-x4qr-v4cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c57h-5952-cm7p/GHSA-c57h-5952-cm7p.json b/advisories/unreviewed/2022/05/GHSA-c57h-5952-cm7p/GHSA-c57h-5952-cm7p.json index 0538ecadf2e..2bd2bc6d09f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c57h-5952-cm7p/GHSA-c57h-5952-cm7p.json +++ b/advisories/unreviewed/2022/05/GHSA-c57h-5952-cm7p/GHSA-c57h-5952-cm7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5hx-2xpr-pv5g/GHSA-c5hx-2xpr-pv5g.json b/advisories/unreviewed/2022/05/GHSA-c5hx-2xpr-pv5g/GHSA-c5hx-2xpr-pv5g.json index f3d317bbbdd..cd0c43c3473 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5hx-2xpr-pv5g/GHSA-c5hx-2xpr-pv5g.json +++ b/advisories/unreviewed/2022/05/GHSA-c5hx-2xpr-pv5g/GHSA-c5hx-2xpr-pv5g.json @@ -7,12 +7,8 @@ "CVE-2008-3613" ], "details": "Finder in Apple Mac OS X 10.5.2 through 10.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving a search for a remote disk on the local network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c65v-q2jv-8xhh/GHSA-c65v-q2jv-8xhh.json b/advisories/unreviewed/2022/05/GHSA-c65v-q2jv-8xhh/GHSA-c65v-q2jv-8xhh.json index dcb84843556..8d0258281b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-c65v-q2jv-8xhh/GHSA-c65v-q2jv-8xhh.json +++ b/advisories/unreviewed/2022/05/GHSA-c65v-q2jv-8xhh/GHSA-c65v-q2jv-8xhh.json @@ -7,12 +7,8 @@ "CVE-2008-3383" ], "details": "SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c666-x77g-r6w9/GHSA-c666-x77g-r6w9.json b/advisories/unreviewed/2022/05/GHSA-c666-x77g-r6w9/GHSA-c666-x77g-r6w9.json index 32480032c35..89a9410651c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c666-x77g-r6w9/GHSA-c666-x77g-r6w9.json +++ b/advisories/unreviewed/2022/05/GHSA-c666-x77g-r6w9/GHSA-c666-x77g-r6w9.json @@ -7,12 +7,8 @@ "CVE-2008-3615" ], "details": "ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, accesses uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c72m-36q5-4cfc/GHSA-c72m-36q5-4cfc.json b/advisories/unreviewed/2022/05/GHSA-c72m-36q5-4cfc/GHSA-c72m-36q5-4cfc.json index 2d13c3b628c..b6cbd260dae 100644 --- a/advisories/unreviewed/2022/05/GHSA-c72m-36q5-4cfc/GHSA-c72m-36q5-4cfc.json +++ b/advisories/unreviewed/2022/05/GHSA-c72m-36q5-4cfc/GHSA-c72m-36q5-4cfc.json @@ -7,12 +7,8 @@ "CVE-2008-3563" ], "details": "Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the activate parameter to admin/plog-themes.php, related to theme_dir settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c79h-6wmh-q4mh/GHSA-c79h-6wmh-q4mh.json b/advisories/unreviewed/2022/05/GHSA-c79h-6wmh-q4mh/GHSA-c79h-6wmh-q4mh.json index f13dda4f402..1294aa4697b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c79h-6wmh-q4mh/GHSA-c79h-6wmh-q4mh.json +++ b/advisories/unreviewed/2022/05/GHSA-c79h-6wmh-q4mh/GHSA-c79h-6wmh-q4mh.json @@ -7,12 +7,8 @@ "CVE-2008-3345" ], "details": "SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a pickup action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c83x-rrww-f3c8/GHSA-c83x-rrww-f3c8.json b/advisories/unreviewed/2022/05/GHSA-c83x-rrww-f3c8/GHSA-c83x-rrww-f3c8.json index e25797f526f..311988fe7ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-c83x-rrww-f3c8/GHSA-c83x-rrww-f3c8.json +++ b/advisories/unreviewed/2022/05/GHSA-c83x-rrww-f3c8/GHSA-c83x-rrww-f3c8.json @@ -7,12 +7,8 @@ "CVE-2008-3184" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccq2-jrj3-pw8x/GHSA-ccq2-jrj3-pw8x.json b/advisories/unreviewed/2022/05/GHSA-ccq2-jrj3-pw8x/GHSA-ccq2-jrj3-pw8x.json index 1d48021d720..9373fcb1d41 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccq2-jrj3-pw8x/GHSA-ccq2-jrj3-pw8x.json +++ b/advisories/unreviewed/2022/05/GHSA-ccq2-jrj3-pw8x/GHSA-ccq2-jrj3-pw8x.json @@ -7,12 +7,8 @@ "CVE-2008-3638" ], "details": "Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccv3-c7pp-3326/GHSA-ccv3-c7pp-3326.json b/advisories/unreviewed/2022/05/GHSA-ccv3-c7pp-3326/GHSA-ccv3-c7pp-3326.json index 89b9c3cfe19..80f9b4cd44d 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccv3-c7pp-3326/GHSA-ccv3-c7pp-3326.json +++ b/advisories/unreviewed/2022/05/GHSA-ccv3-c7pp-3326/GHSA-ccv3-c7pp-3326.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfhf-797j-qrrq/GHSA-cfhf-797j-qrrq.json b/advisories/unreviewed/2022/05/GHSA-cfhf-797j-qrrq/GHSA-cfhf-797j-qrrq.json index 66aa18732fe..04e2e044ec0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfhf-797j-qrrq/GHSA-cfhf-797j-qrrq.json +++ b/advisories/unreviewed/2022/05/GHSA-cfhf-797j-qrrq/GHSA-cfhf-797j-qrrq.json @@ -7,12 +7,8 @@ "CVE-2008-3717" ], "details": "Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfxx-rjmh-m6qv/GHSA-cfxx-rjmh-m6qv.json b/advisories/unreviewed/2022/05/GHSA-cfxx-rjmh-m6qv/GHSA-cfxx-rjmh-m6qv.json index 13387fe97ca..8484f7286db 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfxx-rjmh-m6qv/GHSA-cfxx-rjmh-m6qv.json +++ b/advisories/unreviewed/2022/05/GHSA-cfxx-rjmh-m6qv/GHSA-cfxx-rjmh-m6qv.json @@ -7,12 +7,8 @@ "CVE-2008-3592" ], "details": "Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgvm-rcgv-pjm9/GHSA-cgvm-rcgv-pjm9.json b/advisories/unreviewed/2022/05/GHSA-cgvm-rcgv-pjm9/GHSA-cgvm-rcgv-pjm9.json index 32ba9f64352..d4cdea7d7df 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgvm-rcgv-pjm9/GHSA-cgvm-rcgv-pjm9.json +++ b/advisories/unreviewed/2022/05/GHSA-cgvm-rcgv-pjm9/GHSA-cgvm-rcgv-pjm9.json @@ -7,12 +7,8 @@ "CVE-2008-3356" ], "details": "verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chgr-hfpp-gr3r/GHSA-chgr-hfpp-gr3r.json b/advisories/unreviewed/2022/05/GHSA-chgr-hfpp-gr3r/GHSA-chgr-hfpp-gr3r.json index 90c88549950..d9f4f2d3aab 100644 --- a/advisories/unreviewed/2022/05/GHSA-chgr-hfpp-gr3r/GHSA-chgr-hfpp-gr3r.json +++ b/advisories/unreviewed/2022/05/GHSA-chgr-hfpp-gr3r/GHSA-chgr-hfpp-gr3r.json @@ -7,12 +7,8 @@ "CVE-2008-3591" ], "details": "SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chrh-j2xm-f469/GHSA-chrh-j2xm-f469.json b/advisories/unreviewed/2022/05/GHSA-chrh-j2xm-f469/GHSA-chrh-j2xm-f469.json index 2bdcd5e9329..57de3e8890a 100644 --- a/advisories/unreviewed/2022/05/GHSA-chrh-j2xm-f469/GHSA-chrh-j2xm-f469.json +++ b/advisories/unreviewed/2022/05/GHSA-chrh-j2xm-f469/GHSA-chrh-j2xm-f469.json @@ -7,12 +7,8 @@ "CVE-2008-3253" ], "details": "Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise) 4.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj86-94wr-xfx8/GHSA-cj86-94wr-xfx8.json b/advisories/unreviewed/2022/05/GHSA-cj86-94wr-xfx8/GHSA-cj86-94wr-xfx8.json index 0511a693512..469f2e15667 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj86-94wr-xfx8/GHSA-cj86-94wr-xfx8.json +++ b/advisories/unreviewed/2022/05/GHSA-cj86-94wr-xfx8/GHSA-cj86-94wr-xfx8.json @@ -7,12 +7,8 @@ "CVE-2008-3694" ], "details": "Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3695, and CVE-2008-3696.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cp3p-5vfr-phpw/GHSA-cp3p-5vfr-phpw.json b/advisories/unreviewed/2022/05/GHSA-cp3p-5vfr-phpw/GHSA-cp3p-5vfr-phpw.json index a29108db45b..1f57b63d53b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp3p-5vfr-phpw/GHSA-cp3p-5vfr-phpw.json +++ b/advisories/unreviewed/2022/05/GHSA-cp3p-5vfr-phpw/GHSA-cp3p-5vfr-phpw.json @@ -7,12 +7,8 @@ "CVE-2008-3609" ], "details": "The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpvc-xrr4-4rhq/GHSA-cpvc-xrr4-4rhq.json b/advisories/unreviewed/2022/05/GHSA-cpvc-xrr4-4rhq/GHSA-cpvc-xrr4-4rhq.json index 13bed22ac96..97825fac450 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpvc-xrr4-4rhq/GHSA-cpvc-xrr4-4rhq.json +++ b/advisories/unreviewed/2022/05/GHSA-cpvc-xrr4-4rhq/GHSA-cpvc-xrr4-4rhq.json @@ -7,12 +7,8 @@ "CVE-2008-3766" ], "details": "Realtime Internet Band Rehearsal Low-Latency (Internet) Connection tool (llcon) before 2.1.2 allows remote attackers to cause a denial of service (application crash) via malformed protocol messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq7f-73r9-m7cv/GHSA-cq7f-73r9-m7cv.json b/advisories/unreviewed/2022/05/GHSA-cq7f-73r9-m7cv/GHSA-cq7f-73r9-m7cv.json index 12f74b649bb..c765bd47ab5 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq7f-73r9-m7cv/GHSA-cq7f-73r9-m7cv.json +++ b/advisories/unreviewed/2022/05/GHSA-cq7f-73r9-m7cv/GHSA-cq7f-73r9-m7cv.json @@ -7,12 +7,8 @@ "CVE-2008-3551" ], "details": "Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq86-hpwc-gjqj/GHSA-cq86-hpwc-gjqj.json b/advisories/unreviewed/2022/05/GHSA-cq86-hpwc-gjqj/GHSA-cq86-hpwc-gjqj.json index ee1dd408e70..237f1801450 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq86-hpwc-gjqj/GHSA-cq86-hpwc-gjqj.json +++ b/advisories/unreviewed/2022/05/GHSA-cq86-hpwc-gjqj/GHSA-cq86-hpwc-gjqj.json @@ -7,12 +7,8 @@ "CVE-2008-3248" ], "details": "qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem blocks during creation of a file, which allows local users to obtain sensitive information by creating and then reading files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqgj-ggx7-phrm/GHSA-cqgj-ggx7-phrm.json b/advisories/unreviewed/2022/05/GHSA-cqgj-ggx7-phrm/GHSA-cqgj-ggx7-phrm.json index 4c2ef110860..b439b8db3ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqgj-ggx7-phrm/GHSA-cqgj-ggx7-phrm.json +++ b/advisories/unreviewed/2022/05/GHSA-cqgj-ggx7-phrm/GHSA-cqgj-ggx7-phrm.json @@ -7,12 +7,8 @@ "CVE-2008-3761" ], "details": "hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crjv-828m-gjwx/GHSA-crjv-828m-gjwx.json b/advisories/unreviewed/2022/05/GHSA-crjv-828m-gjwx/GHSA-crjv-828m-gjwx.json index 8e3d5d6b160..730ca58664f 100644 --- a/advisories/unreviewed/2022/05/GHSA-crjv-828m-gjwx/GHSA-crjv-828m-gjwx.json +++ b/advisories/unreviewed/2022/05/GHSA-crjv-828m-gjwx/GHSA-crjv-828m-gjwx.json @@ -7,12 +7,8 @@ "CVE-2008-3309" ], "details": "SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv2r-cj8v-q8j3/GHSA-cv2r-cj8v-q8j3.json b/advisories/unreviewed/2022/05/GHSA-cv2r-cj8v-q8j3/GHSA-cv2r-cj8v-q8j3.json index c665f45091c..4fe9584ba52 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv2r-cj8v-q8j3/GHSA-cv2r-cj8v-q8j3.json +++ b/advisories/unreviewed/2022/05/GHSA-cv2r-cj8v-q8j3/GHSA-cv2r-cj8v-q8j3.json @@ -7,12 +7,8 @@ "CVE-2008-3701" ], "details": "SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv7j-8xc6-2mjx/GHSA-cv7j-8xc6-2mjx.json b/advisories/unreviewed/2022/05/GHSA-cv7j-8xc6-2mjx/GHSA-cv7j-8xc6-2mjx.json index d732642815a..9b19d08a25d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv7j-8xc6-2mjx/GHSA-cv7j-8xc6-2mjx.json +++ b/advisories/unreviewed/2022/05/GHSA-cv7j-8xc6-2mjx/GHSA-cv7j-8xc6-2mjx.json @@ -7,12 +7,8 @@ "CVE-2008-3588" ], "details": "Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cw3p-2f69-7g9p/GHSA-cw3p-2f69-7g9p.json b/advisories/unreviewed/2022/05/GHSA-cw3p-2f69-7g9p/GHSA-cw3p-2f69-7g9p.json index 4a97250d9ba..a70fc8aad57 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw3p-2f69-7g9p/GHSA-cw3p-2f69-7g9p.json +++ b/advisories/unreviewed/2022/05/GHSA-cw3p-2f69-7g9p/GHSA-cw3p-2f69-7g9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx6v-x42c-7m46/GHSA-cx6v-x42c-7m46.json b/advisories/unreviewed/2022/05/GHSA-cx6v-x42c-7m46/GHSA-cx6v-x42c-7m46.json index a9c0cc55fd3..f002707bddb 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx6v-x42c-7m46/GHSA-cx6v-x42c-7m46.json +++ b/advisories/unreviewed/2022/05/GHSA-cx6v-x42c-7m46/GHSA-cx6v-x42c-7m46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2v3-6xr6-pwwp/GHSA-f2v3-6xr6-pwwp.json b/advisories/unreviewed/2022/05/GHSA-f2v3-6xr6-pwwp/GHSA-f2v3-6xr6-pwwp.json index 47974eda890..1d524b8e8e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2v3-6xr6-pwwp/GHSA-f2v3-6xr6-pwwp.json +++ b/advisories/unreviewed/2022/05/GHSA-f2v3-6xr6-pwwp/GHSA-f2v3-6xr6-pwwp.json @@ -7,12 +7,8 @@ "CVE-2008-3601" ], "details": "SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f33p-646v-xcq5/GHSA-f33p-646v-xcq5.json b/advisories/unreviewed/2022/05/GHSA-f33p-646v-xcq5/GHSA-f33p-646v-xcq5.json index 2aeb1eb0494..23d20014cea 100644 --- a/advisories/unreviewed/2022/05/GHSA-f33p-646v-xcq5/GHSA-f33p-646v-xcq5.json +++ b/advisories/unreviewed/2022/05/GHSA-f33p-646v-xcq5/GHSA-f33p-646v-xcq5.json @@ -7,12 +7,8 @@ "CVE-2008-3376" ], "details": "Multiple unspecified vulnerabilities in JamRoom before 3.4.0 have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f388-3r3g-88j3/GHSA-f388-3r3g-88j3.json b/advisories/unreviewed/2022/05/GHSA-f388-3r3g-88j3/GHSA-f388-3r3g-88j3.json index cf46d7a42d6..5159ba2bc4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f388-3r3g-88j3/GHSA-f388-3r3g-88j3.json +++ b/advisories/unreviewed/2022/05/GHSA-f388-3r3g-88j3/GHSA-f388-3r3g-88j3.json @@ -7,12 +7,8 @@ "CVE-2008-3763" ], "details": "Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. NOTE: this can be leveraged for code injection by overwriting the language file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3jw-73hj-7rph/GHSA-f3jw-73hj-7rph.json b/advisories/unreviewed/2022/05/GHSA-f3jw-73hj-7rph/GHSA-f3jw-73hj-7rph.json index 357c3a14edf..9b37a3bc55e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3jw-73hj-7rph/GHSA-f3jw-73hj-7rph.json +++ b/advisories/unreviewed/2022/05/GHSA-f3jw-73hj-7rph/GHSA-f3jw-73hj-7rph.json @@ -7,12 +7,8 @@ "CVE-2008-3769" ], "details": "PHP remote file inclusion vulnerability in admin/create_order_new.php in Freeway 1.4.1.171, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the include_page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4vr-m552-cph8/GHSA-f4vr-m552-cph8.json b/advisories/unreviewed/2022/05/GHSA-f4vr-m552-cph8/GHSA-f4vr-m552-cph8.json index 41efdc4e5a7..6bc7da7e6ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4vr-m552-cph8/GHSA-f4vr-m552-cph8.json +++ b/advisories/unreviewed/2022/05/GHSA-f4vr-m552-cph8/GHSA-f4vr-m552-cph8.json @@ -7,12 +7,8 @@ "CVE-2008-3385" ], "details": "Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7p6-v724-mpjf/GHSA-f7p6-v724-mpjf.json b/advisories/unreviewed/2022/05/GHSA-f7p6-v724-mpjf/GHSA-f7p6-v724-mpjf.json index 60cacbba4ba..7ed902d872f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7p6-v724-mpjf/GHSA-f7p6-v724-mpjf.json +++ b/advisories/unreviewed/2022/05/GHSA-f7p6-v724-mpjf/GHSA-f7p6-v724-mpjf.json @@ -7,12 +7,8 @@ "CVE-2008-3566" ], "details": "Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7w4-rqfv-q46v/GHSA-f7w4-rqfv-q46v.json b/advisories/unreviewed/2022/05/GHSA-f7w4-rqfv-q46v/GHSA-f7w4-rqfv-q46v.json index 235860a9067..a711de283e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7w4-rqfv-q46v/GHSA-f7w4-rqfv-q46v.json +++ b/advisories/unreviewed/2022/05/GHSA-f7w4-rqfv-q46v/GHSA-f7w4-rqfv-q46v.json @@ -7,12 +7,8 @@ "CVE-2008-3576" ], "details": "Buffer overflow in the TruncateString function in src/gfx.cpp in OpenTTD before 0.6.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f826-hqvc-j84v/GHSA-f826-hqvc-j84v.json b/advisories/unreviewed/2022/05/GHSA-f826-hqvc-j84v/GHSA-f826-hqvc-j84v.json index f0d4aa0e91c..57fab72d2da 100644 --- a/advisories/unreviewed/2022/05/GHSA-f826-hqvc-j84v/GHSA-f826-hqvc-j84v.json +++ b/advisories/unreviewed/2022/05/GHSA-f826-hqvc-j84v/GHSA-f826-hqvc-j84v.json @@ -7,12 +7,8 @@ "CVE-2008-2251" ], "details": "Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka \"Windows Kernel Unhandled Exception Vulnerability.\" NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f86q-qvqw-xqc3/GHSA-f86q-qvqw-xqc3.json b/advisories/unreviewed/2022/05/GHSA-f86q-qvqw-xqc3/GHSA-f86q-qvqw-xqc3.json index ffe8c462ba8..fcb83a4e9f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-f86q-qvqw-xqc3/GHSA-f86q-qvqw-xqc3.json +++ b/advisories/unreviewed/2022/05/GHSA-f86q-qvqw-xqc3/GHSA-f86q-qvqw-xqc3.json @@ -7,12 +7,8 @@ "CVE-2008-3355" ], "details": "SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8h7-4cf4-xpqq/GHSA-f8h7-4cf4-xpqq.json b/advisories/unreviewed/2022/05/GHSA-f8h7-4cf4-xpqq/GHSA-f8h7-4cf4-xpqq.json index c205c583ee3..c9de32be5a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8h7-4cf4-xpqq/GHSA-f8h7-4cf4-xpqq.json +++ b/advisories/unreviewed/2022/05/GHSA-f8h7-4cf4-xpqq/GHSA-f8h7-4cf4-xpqq.json @@ -7,12 +7,8 @@ "CVE-2008-3206" ], "details": "SQL injection vulnerability in browse.groups.php in Yuhhu Pubs Black Cat allows remote attackers to execute arbitrary SQL commands via the category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8h7-mj89-73w2/GHSA-f8h7-mj89-73w2.json b/advisories/unreviewed/2022/05/GHSA-f8h7-mj89-73w2/GHSA-f8h7-mj89-73w2.json index 1c557de136c..0a2a895429f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8h7-mj89-73w2/GHSA-f8h7-mj89-73w2.json +++ b/advisories/unreviewed/2022/05/GHSA-f8h7-mj89-73w2/GHSA-f8h7-mj89-73w2.json @@ -7,12 +7,8 @@ "CVE-2008-3400" ], "details": "XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f956-cr73-gjv9/GHSA-f956-cr73-gjv9.json b/advisories/unreviewed/2022/05/GHSA-f956-cr73-gjv9/GHSA-f956-cr73-gjv9.json index b929f6aa573..8b2d5c8c176 100644 --- a/advisories/unreviewed/2022/05/GHSA-f956-cr73-gjv9/GHSA-f956-cr73-gjv9.json +++ b/advisories/unreviewed/2022/05/GHSA-f956-cr73-gjv9/GHSA-f956-cr73-gjv9.json @@ -7,12 +7,8 @@ "CVE-2008-3711" ], "details": "SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc6q-rxqx-rpp6/GHSA-fc6q-rxqx-rpp6.json b/advisories/unreviewed/2022/05/GHSA-fc6q-rxqx-rpp6/GHSA-fc6q-rxqx-rpp6.json index e531c9d2200..78baa91bb9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc6q-rxqx-rpp6/GHSA-fc6q-rxqx-rpp6.json +++ b/advisories/unreviewed/2022/05/GHSA-fc6q-rxqx-rpp6/GHSA-fc6q-rxqx-rpp6.json @@ -7,12 +7,8 @@ "CVE-2008-3442" ], "details": "WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcfg-cfrv-8gm5/GHSA-fcfg-cfrv-8gm5.json b/advisories/unreviewed/2022/05/GHSA-fcfg-cfrv-8gm5/GHSA-fcfg-cfrv-8gm5.json index bf199a8fa2e..86e2e03c1ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcfg-cfrv-8gm5/GHSA-fcfg-cfrv-8gm5.json +++ b/advisories/unreviewed/2022/05/GHSA-fcfg-cfrv-8gm5/GHSA-fcfg-cfrv-8gm5.json @@ -7,12 +7,8 @@ "CVE-2008-3393" ], "details": "SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg95-xw2v-r64x/GHSA-fg95-xw2v-r64x.json b/advisories/unreviewed/2022/05/GHSA-fg95-xw2v-r64x/GHSA-fg95-xw2v-r64x.json index 0a75b7ef963..ccd66a64fe4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg95-xw2v-r64x/GHSA-fg95-xw2v-r64x.json +++ b/advisories/unreviewed/2022/05/GHSA-fg95-xw2v-r64x/GHSA-fg95-xw2v-r64x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgjj-wvpm-7wqh/GHSA-fgjj-wvpm-7wqh.json b/advisories/unreviewed/2022/05/GHSA-fgjj-wvpm-7wqh/GHSA-fgjj-wvpm-7wqh.json index b30e4cd4471..0ab4d2a9087 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgjj-wvpm-7wqh/GHSA-fgjj-wvpm-7wqh.json +++ b/advisories/unreviewed/2022/05/GHSA-fgjj-wvpm-7wqh/GHSA-fgjj-wvpm-7wqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjc4-35pc-vj6r/GHSA-fjc4-35pc-vj6r.json b/advisories/unreviewed/2022/05/GHSA-fjc4-35pc-vj6r/GHSA-fjc4-35pc-vj6r.json index 1e34d71c5be..5ee86184b82 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjc4-35pc-vj6r/GHSA-fjc4-35pc-vj6r.json +++ b/advisories/unreviewed/2022/05/GHSA-fjc4-35pc-vj6r/GHSA-fjc4-35pc-vj6r.json @@ -7,12 +7,8 @@ "CVE-2008-3678" ], "details": "Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway before 1.4.2.197 allows remote attackers to inject arbitrary web script or HTML via the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjw8-wpfr-p9rf/GHSA-fjw8-wpfr-p9rf.json b/advisories/unreviewed/2022/05/GHSA-fjw8-wpfr-p9rf/GHSA-fjw8-wpfr-p9rf.json index 09125c94aa2..098bca4e094 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjw8-wpfr-p9rf/GHSA-fjw8-wpfr-p9rf.json +++ b/advisories/unreviewed/2022/05/GHSA-fjw8-wpfr-p9rf/GHSA-fjw8-wpfr-p9rf.json @@ -7,12 +7,8 @@ "CVE-2008-3204" ], "details": "SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmf8-xm3q-3869/GHSA-fmf8-xm3q-3869.json b/advisories/unreviewed/2022/05/GHSA-fmf8-xm3q-3869/GHSA-fmf8-xm3q-3869.json index 4c3837cba4d..851fbad0ab3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmf8-xm3q-3869/GHSA-fmf8-xm3q-3869.json +++ b/advisories/unreviewed/2022/05/GHSA-fmf8-xm3q-3869/GHSA-fmf8-xm3q-3869.json @@ -7,12 +7,8 @@ "CVE-2008-3269" ], "details": "WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet to TCP port 4321.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqmr-q9vp-75fv/GHSA-fqmr-q9vp-75fv.json b/advisories/unreviewed/2022/05/GHSA-fqmr-q9vp-75fv/GHSA-fqmr-q9vp-75fv.json index c7468dcf67b..ee1175a6888 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqmr-q9vp-75fv/GHSA-fqmr-q9vp-75fv.json +++ b/advisories/unreviewed/2022/05/GHSA-fqmr-q9vp-75fv/GHSA-fqmr-q9vp-75fv.json @@ -7,12 +7,8 @@ "CVE-2008-3195" ], "details": "Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv89-5gfc-wwfc/GHSA-fv89-5gfc-wwfc.json b/advisories/unreviewed/2022/05/GHSA-fv89-5gfc-wwfc/GHSA-fv89-5gfc-wwfc.json index 9d55d4faf93..4fd94609152 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv89-5gfc-wwfc/GHSA-fv89-5gfc-wwfc.json +++ b/advisories/unreviewed/2022/05/GHSA-fv89-5gfc-wwfc/GHSA-fv89-5gfc-wwfc.json @@ -7,12 +7,8 @@ "CVE-2008-3474" ], "details": "Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka \"Cross-Domain Information Disclosure Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv8p-rvxx-mpc7/GHSA-fv8p-rvxx-mpc7.json b/advisories/unreviewed/2022/05/GHSA-fv8p-rvxx-mpc7/GHSA-fv8p-rvxx-mpc7.json index 17d603683b1..72ede0e6985 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv8p-rvxx-mpc7/GHSA-fv8p-rvxx-mpc7.json +++ b/advisories/unreviewed/2022/05/GHSA-fv8p-rvxx-mpc7/GHSA-fv8p-rvxx-mpc7.json @@ -7,12 +7,8 @@ "CVE-2008-3543" ], "details": "Unspecified vulnerability in NFS / ONCplus B.11.31_04 and earlier on HP-UX B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv9f-f2rj-77ww/GHSA-fv9f-f2rj-77ww.json b/advisories/unreviewed/2022/05/GHSA-fv9f-f2rj-77ww/GHSA-fv9f-f2rj-77ww.json index 918570fbe0f..b27dca92f25 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv9f-f2rj-77ww/GHSA-fv9f-f2rj-77ww.json +++ b/advisories/unreviewed/2022/05/GHSA-fv9f-f2rj-77ww/GHSA-fv9f-f2rj-77ww.json @@ -7,12 +7,8 @@ "CVE-2008-3193" ], "details": "SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page parameter to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvrc-fh5g-jhh8/GHSA-fvrc-fh5g-jhh8.json b/advisories/unreviewed/2022/05/GHSA-fvrc-fh5g-jhh8/GHSA-fvrc-fh5g-jhh8.json index 3e0c8bd58b6..ee41330bb07 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvrc-fh5g-jhh8/GHSA-fvrc-fh5g-jhh8.json +++ b/advisories/unreviewed/2022/05/GHSA-fvrc-fh5g-jhh8/GHSA-fvrc-fh5g-jhh8.json @@ -7,12 +7,8 @@ "CVE-2008-3649" ], "details": "SQL injection vulnerability in categorydetail.php in Article Friendly Standard allows remote attackers to execute arbitrary SQL commands via the Cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx49-8c29-qffw/GHSA-fx49-8c29-qffw.json b/advisories/unreviewed/2022/05/GHSA-fx49-8c29-qffw/GHSA-fx49-8c29-qffw.json index f879d0b1802..41dccf19c57 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx49-8c29-qffw/GHSA-fx49-8c29-qffw.json +++ b/advisories/unreviewed/2022/05/GHSA-fx49-8c29-qffw/GHSA-fx49-8c29-qffw.json @@ -7,12 +7,8 @@ "CVE-2008-3791" ], "details": "src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g26r-chwp-6c79/GHSA-g26r-chwp-6c79.json b/advisories/unreviewed/2022/05/GHSA-g26r-chwp-6c79/GHSA-g26r-chwp-6c79.json index 6e83e474bf4..c8271929db7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g26r-chwp-6c79/GHSA-g26r-chwp-6c79.json +++ b/advisories/unreviewed/2022/05/GHSA-g26r-chwp-6c79/GHSA-g26r-chwp-6c79.json @@ -7,12 +7,8 @@ "CVE-2008-3344" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a allow remote attackers to inject arbitrary web script or HTML via the (1) ResultHtml, (2) dir, (3) SenderName, (4) RecipientName, (5) SenderMail, and (6) RecipientMail parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2cv-3x8q-cx68/GHSA-g2cv-3x8q-cx68.json b/advisories/unreviewed/2022/05/GHSA-g2cv-3x8q-cx68/GHSA-g2cv-3x8q-cx68.json index 4371116cfed..5e4479690cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2cv-3x8q-cx68/GHSA-g2cv-3x8q-cx68.json +++ b/advisories/unreviewed/2022/05/GHSA-g2cv-3x8q-cx68/GHSA-g2cv-3x8q-cx68.json @@ -7,12 +7,8 @@ "CVE-2008-3559" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g47h-vvvq-23qc/GHSA-g47h-vvvq-23qc.json b/advisories/unreviewed/2022/05/GHSA-g47h-vvvq-23qc/GHSA-g47h-vvvq-23qc.json index 06c1381e11c..456f16d99f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g47h-vvvq-23qc/GHSA-g47h-vvvq-23qc.json +++ b/advisories/unreviewed/2022/05/GHSA-g47h-vvvq-23qc/GHSA-g47h-vvvq-23qc.json @@ -7,12 +7,8 @@ "CVE-2008-3352" ], "details": "SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4f6-qjqx-hhpq/GHSA-g4f6-qjqx-hhpq.json b/advisories/unreviewed/2022/05/GHSA-g4f6-qjqx-hhpq/GHSA-g4f6-qjqx-hhpq.json index 66433a076ec..708a80e5c96 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4f6-qjqx-hhpq/GHSA-g4f6-qjqx-hhpq.json +++ b/advisories/unreviewed/2022/05/GHSA-g4f6-qjqx-hhpq/GHSA-g4f6-qjqx-hhpq.json @@ -7,12 +7,8 @@ "CVE-2008-3409" ], "details": "Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g59v-xw9p-fc4r/GHSA-g59v-xw9p-fc4r.json b/advisories/unreviewed/2022/05/GHSA-g59v-xw9p-fc4r/GHSA-g59v-xw9p-fc4r.json index 2cfeea33959..9ad020f68d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g59v-xw9p-fc4r/GHSA-g59v-xw9p-fc4r.json +++ b/advisories/unreviewed/2022/05/GHSA-g59v-xw9p-fc4r/GHSA-g59v-xw9p-fc4r.json @@ -7,12 +7,8 @@ "CVE-2008-3534" ], "details": "The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrated by the insserv program, related to allocation of \"useless pages\" and improper maintenance of the i_blocks count.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6x7-m6fm-69fg/GHSA-g6x7-m6fm-69fg.json b/advisories/unreviewed/2022/05/GHSA-g6x7-m6fm-69fg/GHSA-g6x7-m6fm-69fg.json index cf32dcae97f..83a542e0ada 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6x7-m6fm-69fg/GHSA-g6x7-m6fm-69fg.json +++ b/advisories/unreviewed/2022/05/GHSA-g6x7-m6fm-69fg/GHSA-g6x7-m6fm-69fg.json @@ -7,12 +7,8 @@ "CVE-2008-3558" ], "details": "Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g72c-ccjw-3g64/GHSA-g72c-ccjw-3g64.json b/advisories/unreviewed/2022/05/GHSA-g72c-ccjw-3g64/GHSA-g72c-ccjw-3g64.json index 9cd4605981d..4a839a14d34 100644 --- a/advisories/unreviewed/2022/05/GHSA-g72c-ccjw-3g64/GHSA-g72c-ccjw-3g64.json +++ b/advisories/unreviewed/2022/05/GHSA-g72c-ccjw-3g64/GHSA-g72c-ccjw-3g64.json @@ -7,12 +7,8 @@ "CVE-2008-2250" ], "details": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka \"Windows Kernel Window Creation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g734-9m5h-rq2w/GHSA-g734-9m5h-rq2w.json b/advisories/unreviewed/2022/05/GHSA-g734-9m5h-rq2w/GHSA-g734-9m5h-rq2w.json index 9b170e1c6c8..367a77edc18 100644 --- a/advisories/unreviewed/2022/05/GHSA-g734-9m5h-rq2w/GHSA-g734-9m5h-rq2w.json +++ b/advisories/unreviewed/2022/05/GHSA-g734-9m5h-rq2w/GHSA-g734-9m5h-rq2w.json @@ -7,12 +7,8 @@ "CVE-2008-3670" ], "details": "SQL injection vulnerability in authordetail.php in Article Friendly Pro allows remote attackers to execute arbitrary SQL commands via the autid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7f8-j599-7426/GHSA-g7f8-j599-7426.json b/advisories/unreviewed/2022/05/GHSA-g7f8-j599-7426/GHSA-g7f8-j599-7426.json index 70131934cf8..032ade54622 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7f8-j599-7426/GHSA-g7f8-j599-7426.json +++ b/advisories/unreviewed/2022/05/GHSA-g7f8-j599-7426/GHSA-g7f8-j599-7426.json @@ -7,12 +7,8 @@ "CVE-2008-3257" ], "details": "Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after \"POST /.jsp\" in an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8mw-h5hw-6g35/GHSA-g8mw-h5hw-6g35.json b/advisories/unreviewed/2022/05/GHSA-g8mw-h5hw-6g35/GHSA-g8mw-h5hw-6g35.json index 82d36558594..fe625a406ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8mw-h5hw-6g35/GHSA-g8mw-h5hw-6g35.json +++ b/advisories/unreviewed/2022/05/GHSA-g8mw-h5hw-6g35/GHSA-g8mw-h5hw-6g35.json @@ -7,12 +7,8 @@ "CVE-2008-3220" ], "details": "Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of \"translated strings.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8wp-9hw5-m25j/GHSA-g8wp-9hw5-m25j.json b/advisories/unreviewed/2022/05/GHSA-g8wp-9hw5-m25j/GHSA-g8wp-9hw5-m25j.json index 7e1ddac84db..0b87b581403 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8wp-9hw5-m25j/GHSA-g8wp-9hw5-m25j.json +++ b/advisories/unreviewed/2022/05/GHSA-g8wp-9hw5-m25j/GHSA-g8wp-9hw5-m25j.json @@ -7,12 +7,8 @@ "CVE-2008-3413" ], "details": "SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g99p-ffv8-649c/GHSA-g99p-ffv8-649c.json b/advisories/unreviewed/2022/05/GHSA-g99p-ffv8-649c/GHSA-g99p-ffv8-649c.json index bc644f069bf..7a1f70a6805 100644 --- a/advisories/unreviewed/2022/05/GHSA-g99p-ffv8-649c/GHSA-g99p-ffv8-649c.json +++ b/advisories/unreviewed/2022/05/GHSA-g99p-ffv8-649c/GHSA-g99p-ffv8-649c.json @@ -7,12 +7,8 @@ "CVE-2008-3685" ], "details": "Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc33-wppm-8h9m/GHSA-gc33-wppm-8h9m.json b/advisories/unreviewed/2022/05/GHSA-gc33-wppm-8h9m/GHSA-gc33-wppm-8h9m.json index bcf9ae24777..4167d42089c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc33-wppm-8h9m/GHSA-gc33-wppm-8h9m.json +++ b/advisories/unreviewed/2022/05/GHSA-gc33-wppm-8h9m/GHSA-gc33-wppm-8h9m.json @@ -7,12 +7,8 @@ "CVE-2008-3237" ], "details": "Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web script or HTML via the productid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcc4-656c-73xw/GHSA-gcc4-656c-73xw.json b/advisories/unreviewed/2022/05/GHSA-gcc4-656c-73xw/GHSA-gcc4-656c-73xw.json index 12748a081a0..37c92d2cbca 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcc4-656c-73xw/GHSA-gcc4-656c-73xw.json +++ b/advisories/unreviewed/2022/05/GHSA-gcc4-656c-73xw/GHSA-gcc4-656c-73xw.json @@ -7,12 +7,8 @@ "CVE-2008-3367" ], "details": "Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcf3-96cg-hh53/GHSA-gcf3-96cg-hh53.json b/advisories/unreviewed/2022/05/GHSA-gcf3-96cg-hh53/GHSA-gcf3-96cg-hh53.json index c301a58a7f1..272547907fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcf3-96cg-hh53/GHSA-gcf3-96cg-hh53.json +++ b/advisories/unreviewed/2022/05/GHSA-gcf3-96cg-hh53/GHSA-gcf3-96cg-hh53.json @@ -7,12 +7,8 @@ "CVE-2008-3457" ], "details": "Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcrw-4mfc-p64j/GHSA-gcrw-4mfc-p64j.json b/advisories/unreviewed/2022/05/GHSA-gcrw-4mfc-p64j/GHSA-gcrw-4mfc-p64j.json index be88122451a..ac755762f6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcrw-4mfc-p64j/GHSA-gcrw-4mfc-p64j.json +++ b/advisories/unreviewed/2022/05/GHSA-gcrw-4mfc-p64j/GHSA-gcrw-4mfc-p64j.json @@ -7,12 +7,8 @@ "CVE-2008-3224" ], "details": "Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to \"urls gone through redirect() being used within login_box().\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcwr-jmc7-prf4/GHSA-gcwr-jmc7-prf4.json b/advisories/unreviewed/2022/05/GHSA-gcwr-jmc7-prf4/GHSA-gcwr-jmc7-prf4.json index 6c0ad59a3a9..4cb16f6bbab 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcwr-jmc7-prf4/GHSA-gcwr-jmc7-prf4.json +++ b/advisories/unreviewed/2022/05/GHSA-gcwr-jmc7-prf4/GHSA-gcwr-jmc7-prf4.json @@ -7,12 +7,8 @@ "CVE-2008-3504" ], "details": "Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to \"manipulation of cookies.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg39-pcxr-j7h6/GHSA-gg39-pcxr-j7h6.json b/advisories/unreviewed/2022/05/GHSA-gg39-pcxr-j7h6/GHSA-gg39-pcxr-j7h6.json index 8fd9aea4410..4e37abfb4ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg39-pcxr-j7h6/GHSA-gg39-pcxr-j7h6.json +++ b/advisories/unreviewed/2022/05/GHSA-gg39-pcxr-j7h6/GHSA-gg39-pcxr-j7h6.json @@ -7,12 +7,8 @@ "CVE-2008-3485" ], "details": "Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gg4p-p5jw-h6q9/GHSA-gg4p-p5jw-h6q9.json b/advisories/unreviewed/2022/05/GHSA-gg4p-p5jw-h6q9/GHSA-gg4p-p5jw-h6q9.json index ab126425f95..63246b0b0bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg4p-p5jw-h6q9/GHSA-gg4p-p5jw-h6q9.json +++ b/advisories/unreviewed/2022/05/GHSA-gg4p-p5jw-h6q9/GHSA-gg4p-p5jw-h6q9.json @@ -7,12 +7,8 @@ "CVE-2008-3702" ], "details": "Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gh58-6q6f-845w/GHSA-gh58-6q6f-845w.json b/advisories/unreviewed/2022/05/GHSA-gh58-6q6f-845w/GHSA-gh58-6q6f-845w.json index 50f1fae3819..6d71eca0fe8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh58-6q6f-845w/GHSA-gh58-6q6f-845w.json +++ b/advisories/unreviewed/2022/05/GHSA-gh58-6q6f-845w/GHSA-gh58-6q6f-845w.json @@ -7,12 +7,8 @@ "CVE-2008-3710" ], "details": "Multiple directory traversal vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) script_path parameter to (a) options.php and the (2) lang_code parameter to (b) copy_vip.php and (c) process_edit_board.php in adminopts/. NOTE: some of these vectors might not be vulnerabilities under proper installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm92-c36m-m7vp/GHSA-gm92-c36m-m7vp.json b/advisories/unreviewed/2022/05/GHSA-gm92-c36m-m7vp/GHSA-gm92-c36m-m7vp.json index 188bbf25f70..701a53e8cc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm92-c36m-m7vp/GHSA-gm92-c36m-m7vp.json +++ b/advisories/unreviewed/2022/05/GHSA-gm92-c36m-m7vp/GHSA-gm92-c36m-m7vp.json @@ -7,12 +7,8 @@ "CVE-2008-3346" ], "details": "SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL commands via the pid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grp2-56hp-6jw2/GHSA-grp2-56hp-6jw2.json b/advisories/unreviewed/2022/05/GHSA-grp2-56hp-6jw2/GHSA-grp2-56hp-6jw2.json index 5fadbceed07..8fd874b20f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-grp2-56hp-6jw2/GHSA-grp2-56hp-6jw2.json +++ b/advisories/unreviewed/2022/05/GHSA-grp2-56hp-6jw2/GHSA-grp2-56hp-6jw2.json @@ -7,12 +7,8 @@ "CVE-2008-3460" ], "details": "WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the \"WPG Image File Heap Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grp6-7p56-hj27/GHSA-grp6-7p56-hj27.json b/advisories/unreviewed/2022/05/GHSA-grp6-7p56-hj27/GHSA-grp6-7p56-hj27.json index 4c382dc7d12..b83cef0a6ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-grp6-7p56-hj27/GHSA-grp6-7p56-hj27.json +++ b/advisories/unreviewed/2022/05/GHSA-grp6-7p56-hj27/GHSA-grp6-7p56-hj27.json @@ -7,12 +7,8 @@ "CVE-2008-3542" ], "details": "Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvcr-fm3r-m2rx/GHSA-gvcr-fm3r-m2rx.json b/advisories/unreviewed/2022/05/GHSA-gvcr-fm3r-m2rx/GHSA-gvcr-fm3r-m2rx.json index c6698ebedb6..c3088082eff 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvcr-fm3r-m2rx/GHSA-gvcr-fm3r-m2rx.json +++ b/advisories/unreviewed/2022/05/GHSA-gvcr-fm3r-m2rx/GHSA-gvcr-fm3r-m2rx.json @@ -7,12 +7,8 @@ "CVE-2008-3334" ], "details": "Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvgq-3h54-77c4/GHSA-gvgq-3h54-77c4.json b/advisories/unreviewed/2022/05/GHSA-gvgq-3h54-77c4/GHSA-gvgq-3h54-77c4.json index 30c62f206a5..2739a33fda3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvgq-3h54-77c4/GHSA-gvgq-3h54-77c4.json +++ b/advisories/unreviewed/2022/05/GHSA-gvgq-3h54-77c4/GHSA-gvgq-3h54-77c4.json @@ -7,12 +7,8 @@ "CVE-2008-3771" ], "details": "Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw79-fmm2-4hcr/GHSA-gw79-fmm2-4hcr.json b/advisories/unreviewed/2022/05/GHSA-gw79-fmm2-4hcr/GHSA-gw79-fmm2-4hcr.json index 27bc2776e16..b2fe051a29d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw79-fmm2-4hcr/GHSA-gw79-fmm2-4hcr.json +++ b/advisories/unreviewed/2022/05/GHSA-gw79-fmm2-4hcr/GHSA-gw79-fmm2-4hcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw9x-p27g-7vv2/GHSA-gw9x-p27g-7vv2.json b/advisories/unreviewed/2022/05/GHSA-gw9x-p27g-7vv2/GHSA-gw9x-p27g-7vv2.json index 6d44e324dd0..b10d3b9fa94 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw9x-p27g-7vv2/GHSA-gw9x-p27g-7vv2.json +++ b/advisories/unreviewed/2022/05/GHSA-gw9x-p27g-7vv2/GHSA-gw9x-p27g-7vv2.json @@ -7,12 +7,8 @@ "CVE-2008-3693" ], "details": "Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx5g-r8jr-pr89/GHSA-gx5g-r8jr-pr89.json b/advisories/unreviewed/2022/05/GHSA-gx5g-r8jr-pr89/GHSA-gx5g-r8jr-pr89.json index 1ec65aed1b0..bdfbb6df503 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx5g-r8jr-pr89/GHSA-gx5g-r8jr-pr89.json +++ b/advisories/unreviewed/2022/05/GHSA-gx5g-r8jr-pr89/GHSA-gx5g-r8jr-pr89.json @@ -7,12 +7,8 @@ "CVE-2008-3430" ], "details": "Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx79-7p8q-959r/GHSA-gx79-7p8q-959r.json b/advisories/unreviewed/2022/05/GHSA-gx79-7p8q-959r/GHSA-gx79-7p8q-959r.json index efa7c96d8f6..d8c84ebb23e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx79-7p8q-959r/GHSA-gx79-7p8q-959r.json +++ b/advisories/unreviewed/2022/05/GHSA-gx79-7p8q-959r/GHSA-gx79-7p8q-959r.json @@ -7,12 +7,8 @@ "CVE-2008-3223" ], "details": "SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to \"an inappropriate placeholder for 'numeric' fields.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx7j-m7w9-jmf5/GHSA-gx7j-m7w9-jmf5.json b/advisories/unreviewed/2022/05/GHSA-gx7j-m7w9-jmf5/GHSA-gx7j-m7w9-jmf5.json index c601b38dcd0..39459809edf 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx7j-m7w9-jmf5/GHSA-gx7j-m7w9-jmf5.json +++ b/advisories/unreviewed/2022/05/GHSA-gx7j-m7w9-jmf5/GHSA-gx7j-m7w9-jmf5.json @@ -7,12 +7,8 @@ "CVE-2008-3522" ], "details": "Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxjg-c2w7-4xfq/GHSA-gxjg-c2w7-4xfq.json b/advisories/unreviewed/2022/05/GHSA-gxjg-c2w7-4xfq/GHSA-gxjg-c2w7-4xfq.json index a2d63b8a24f..9d98620d4fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxjg-c2w7-4xfq/GHSA-gxjg-c2w7-4xfq.json +++ b/advisories/unreviewed/2022/05/GHSA-gxjg-c2w7-4xfq/GHSA-gxjg-c2w7-4xfq.json @@ -7,12 +7,8 @@ "CVE-2008-3587" ], "details": "Cross-site scripting (XSS) vulnerability in result.php in Chris Bunting Homes 4 Sale allows remote attackers to inject arbitrary web script or HTML via the r parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2jf-52qm-348c/GHSA-h2jf-52qm-348c.json b/advisories/unreviewed/2022/05/GHSA-h2jf-52qm-348c/GHSA-h2jf-52qm-348c.json index 0d06976bb66..4dfe76e9702 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2jf-52qm-348c/GHSA-h2jf-52qm-348c.json +++ b/advisories/unreviewed/2022/05/GHSA-h2jf-52qm-348c/GHSA-h2jf-52qm-348c.json @@ -7,12 +7,8 @@ "CVE-2008-3493" ], "details": "vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h383-c583-qjpm/GHSA-h383-c583-qjpm.json b/advisories/unreviewed/2022/05/GHSA-h383-c583-qjpm/GHSA-h383-c583-qjpm.json index da95b32ea28..a2ff07be535 100644 --- a/advisories/unreviewed/2022/05/GHSA-h383-c583-qjpm/GHSA-h383-c583-qjpm.json +++ b/advisories/unreviewed/2022/05/GHSA-h383-c583-qjpm/GHSA-h383-c583-qjpm.json @@ -7,12 +7,8 @@ "CVE-2008-3298" ], "details": "SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h43w-3xqv-6x53/GHSA-h43w-3xqv-6x53.json b/advisories/unreviewed/2022/05/GHSA-h43w-3xqv-6x53/GHSA-h43w-3xqv-6x53.json index e7f8f96c46a..080624c8b16 100644 --- a/advisories/unreviewed/2022/05/GHSA-h43w-3xqv-6x53/GHSA-h43w-3xqv-6x53.json +++ b/advisories/unreviewed/2022/05/GHSA-h43w-3xqv-6x53/GHSA-h43w-3xqv-6x53.json @@ -7,12 +7,8 @@ "CVE-2008-3405" ], "details": "Directory traversal vulnerability in index.php in Ricardo Amaral nzFotolog 0.4.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5vm-5rxm-r6wg/GHSA-h5vm-5rxm-r6wg.json b/advisories/unreviewed/2022/05/GHSA-h5vm-5rxm-r6wg/GHSA-h5vm-5rxm-r6wg.json index de7257f7a5f..c860543be3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5vm-5rxm-r6wg/GHSA-h5vm-5rxm-r6wg.json +++ b/advisories/unreviewed/2022/05/GHSA-h5vm-5rxm-r6wg/GHSA-h5vm-5rxm-r6wg.json @@ -7,12 +7,8 @@ "CVE-2008-3778" ], "details": "The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, proceeds with Core router updates even when a login is invalid, which allows remote attackers to cause a denial of service (messaging outage) or gain privileges via an update request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h84r-rpr3-84pm/GHSA-h84r-rpr3-84pm.json b/advisories/unreviewed/2022/05/GHSA-h84r-rpr3-84pm/GHSA-h84r-rpr3-84pm.json index 88ef4b052da..d9d4b31f584 100644 --- a/advisories/unreviewed/2022/05/GHSA-h84r-rpr3-84pm/GHSA-h84r-rpr3-84pm.json +++ b/advisories/unreviewed/2022/05/GHSA-h84r-rpr3-84pm/GHSA-h84r-rpr3-84pm.json @@ -7,12 +7,8 @@ "CVE-2008-3624" ], "details": "Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8cc-x256-xmjw/GHSA-h8cc-x256-xmjw.json b/advisories/unreviewed/2022/05/GHSA-h8cc-x256-xmjw/GHSA-h8cc-x256-xmjw.json index 46b65e8f567..3c7c5fb1883 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8cc-x256-xmjw/GHSA-h8cc-x256-xmjw.json +++ b/advisories/unreviewed/2022/05/GHSA-h8cc-x256-xmjw/GHSA-h8cc-x256-xmjw.json @@ -7,12 +7,8 @@ "CVE-2008-3231" ], "details": "xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9rq-6vm6-3pm5/GHSA-h9rq-6vm6-3pm5.json b/advisories/unreviewed/2022/05/GHSA-h9rq-6vm6-3pm5/GHSA-h9rq-6vm6-3pm5.json index e39736340e4..c60412b994c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9rq-6vm6-3pm5/GHSA-h9rq-6vm6-3pm5.json +++ b/advisories/unreviewed/2022/05/GHSA-h9rq-6vm6-3pm5/GHSA-h9rq-6vm6-3pm5.json @@ -7,12 +7,8 @@ "CVE-2008-3658" ], "details": "Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9vx-p9q4-3f49/GHSA-h9vx-p9q4-3f49.json b/advisories/unreviewed/2022/05/GHSA-h9vx-p9q4-3f49/GHSA-h9vx-p9q4-3f49.json index 72e4d379de7..27a507ffb51 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9vx-p9q4-3f49/GHSA-h9vx-p9q4-3f49.json +++ b/advisories/unreviewed/2022/05/GHSA-h9vx-p9q4-3f49/GHSA-h9vx-p9q4-3f49.json @@ -7,12 +7,8 @@ "CVE-2008-3498" ], "details": "SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc8j-fxcx-wgcv/GHSA-hc8j-fxcx-wgcv.json b/advisories/unreviewed/2022/05/GHSA-hc8j-fxcx-wgcv/GHSA-hc8j-fxcx-wgcv.json index 2a3cbaf2290..1d5786bb1d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc8j-fxcx-wgcv/GHSA-hc8j-fxcx-wgcv.json +++ b/advisories/unreviewed/2022/05/GHSA-hc8j-fxcx-wgcv/GHSA-hc8j-fxcx-wgcv.json @@ -7,12 +7,8 @@ "CVE-2008-3199" ], "details": "Multiple unspecified vulnerabilities in ReSIProcate before 1.3.4 allow remote attackers to cause a denial of service (stack consumption) via unknown network traffic with a large \"bytes-in-memory/bytes-on-wire ratio.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfgm-j25g-7hc6/GHSA-hfgm-j25g-7hc6.json b/advisories/unreviewed/2022/05/GHSA-hfgm-j25g-7hc6/GHSA-hfgm-j25g-7hc6.json index feb1b596877..3c735eabcfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfgm-j25g-7hc6/GHSA-hfgm-j25g-7hc6.json +++ b/advisories/unreviewed/2022/05/GHSA-hfgm-j25g-7hc6/GHSA-hfgm-j25g-7hc6.json @@ -7,12 +7,8 @@ "CVE-2008-3628" ], "details": "Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, related to an \"invalid pointer issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfq2-325g-vf78/GHSA-hfq2-325g-vf78.json b/advisories/unreviewed/2022/05/GHSA-hfq2-325g-vf78/GHSA-hfq2-325g-vf78.json index 75cee0c1207..150a89a332f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfq2-325g-vf78/GHSA-hfq2-325g-vf78.json +++ b/advisories/unreviewed/2022/05/GHSA-hfq2-325g-vf78/GHSA-hfq2-325g-vf78.json @@ -7,12 +7,8 @@ "CVE-2008-3602" ], "details": "admin/wr_admin.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9.1 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh56-whf8-c572/GHSA-hh56-whf8-c572.json b/advisories/unreviewed/2022/05/GHSA-hh56-whf8-c572/GHSA-hh56-whf8-c572.json index 73449f11bf4..bb059b98fb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh56-whf8-c572/GHSA-hh56-whf8-c572.json +++ b/advisories/unreviewed/2022/05/GHSA-hh56-whf8-c572/GHSA-hh56-whf8-c572.json @@ -7,12 +7,8 @@ "CVE-2008-3691" ], "details": "Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhgj-x6rx-cfm3/GHSA-hhgj-x6rx-cfm3.json b/advisories/unreviewed/2022/05/GHSA-hhgj-x6rx-cfm3/GHSA-hhgj-x6rx-cfm3.json index 58021383bb3..741a679595c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhgj-x6rx-cfm3/GHSA-hhgj-x6rx-cfm3.json +++ b/advisories/unreviewed/2022/05/GHSA-hhgj-x6rx-cfm3/GHSA-hhgj-x6rx-cfm3.json @@ -7,12 +7,8 @@ "CVE-2008-3260" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to document/rqmkhtml.php, or the query string to (2) announcements/announcements.php, (3) calendar/agenda.php, (4) course/index.php, (5) course_description/index.php, (6) document/document.php, (7) exercise/exercise.php, (8) group/group_space.php, (9) phpbb/newtopic.php, (10) phpbb/reply.php, (11) phpbb/viewtopic.php, (12) wiki/wiki.php, or (13) work/work.php in claroline/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj8g-jffw-r6xj/GHSA-hj8g-jffw-r6xj.json b/advisories/unreviewed/2022/05/GHSA-hj8g-jffw-r6xj/GHSA-hj8g-jffw-r6xj.json index 2ec1e8e2082..b7b4cc462f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj8g-jffw-r6xj/GHSA-hj8g-jffw-r6xj.json +++ b/advisories/unreviewed/2022/05/GHSA-hj8g-jffw-r6xj/GHSA-hj8g-jffw-r6xj.json @@ -7,12 +7,8 @@ "CVE-2008-3338" ], "details": "Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11.0.0; and Mainframe Service Tracker before 1.1.0 might allow remote attackers to execute arbitrary code via a crafted message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjjj-ggh5-mcg2/GHSA-hjjj-ggh5-mcg2.json b/advisories/unreviewed/2022/05/GHSA-hjjj-ggh5-mcg2/GHSA-hjjj-ggh5-mcg2.json index 636547e3e2b..2de126e7597 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjjj-ggh5-mcg2/GHSA-hjjj-ggh5-mcg2.json +++ b/advisories/unreviewed/2022/05/GHSA-hjjj-ggh5-mcg2/GHSA-hjjj-ggh5-mcg2.json @@ -7,12 +7,8 @@ "CVE-2008-3364" ], "details": "Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.5 and 3.6; and Worry-Free Business Security (WFBS) 5.0 allows remote attackers to execute arbitrary code via a long string in the Server property, and possibly other properties. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjph-3frw-rvch/GHSA-hjph-3frw-rvch.json b/advisories/unreviewed/2022/05/GHSA-hjph-3frw-rvch/GHSA-hjph-3frw-rvch.json index 2338bd90582..df7e48ac2b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjph-3frw-rvch/GHSA-hjph-3frw-rvch.json +++ b/advisories/unreviewed/2022/05/GHSA-hjph-3frw-rvch/GHSA-hjph-3frw-rvch.json @@ -7,12 +7,8 @@ "CVE-2008-3255" ], "details": "Cross-site scripting (XSS) vulnerability in LunarNight Laboratory WebProxy 1.7.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjxf-26cm-gvwc/GHSA-hjxf-26cm-gvwc.json b/advisories/unreviewed/2022/05/GHSA-hjxf-26cm-gvwc/GHSA-hjxf-26cm-gvwc.json index f23d35e978c..a4ad46906a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjxf-26cm-gvwc/GHSA-hjxf-26cm-gvwc.json +++ b/advisories/unreviewed/2022/05/GHSA-hjxf-26cm-gvwc/GHSA-hjxf-26cm-gvwc.json @@ -7,12 +7,8 @@ "CVE-2008-3361" ], "details": "Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hm72-p3gj-h2cx/GHSA-hm72-p3gj-h2cx.json b/advisories/unreviewed/2022/05/GHSA-hm72-p3gj-h2cx/GHSA-hm72-p3gj-h2cx.json index cb8fda5dace..951492b88b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm72-p3gj-h2cx/GHSA-hm72-p3gj-h2cx.json +++ b/advisories/unreviewed/2022/05/GHSA-hm72-p3gj-h2cx/GHSA-hm72-p3gj-h2cx.json @@ -7,12 +7,8 @@ "CVE-2008-3536" ], "details": "Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3537.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp32-wq7p-3p79/GHSA-hp32-wq7p-3p79.json b/advisories/unreviewed/2022/05/GHSA-hp32-wq7p-3p79/GHSA-hp32-wq7p-3p79.json index b41989a36cb..4aabaf7fb5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp32-wq7p-3p79/GHSA-hp32-wq7p-3p79.json +++ b/advisories/unreviewed/2022/05/GHSA-hp32-wq7p-3p79/GHSA-hp32-wq7p-3p79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrpc-c9c2-pj6w/GHSA-hrpc-c9c2-pj6w.json b/advisories/unreviewed/2022/05/GHSA-hrpc-c9c2-pj6w/GHSA-hrpc-c9c2-pj6w.json index 57bfddb831b..cd67b8c3ebf 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrpc-c9c2-pj6w/GHSA-hrpc-c9c2-pj6w.json +++ b/advisories/unreviewed/2022/05/GHSA-hrpc-c9c2-pj6w/GHSA-hrpc-c9c2-pj6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrpf-8q8g-5rwf/GHSA-hrpf-8q8g-5rwf.json b/advisories/unreviewed/2022/05/GHSA-hrpf-8q8g-5rwf/GHSA-hrpf-8q8g-5rwf.json index 963797e18cf..8d082365684 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrpf-8q8g-5rwf/GHSA-hrpf-8q8g-5rwf.json +++ b/advisories/unreviewed/2022/05/GHSA-hrpf-8q8g-5rwf/GHSA-hrpf-8q8g-5rwf.json @@ -7,12 +7,8 @@ "CVE-2008-3611" ], "details": "Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hv49-wcr2-g2x8/GHSA-hv49-wcr2-g2x8.json b/advisories/unreviewed/2022/05/GHSA-hv49-wcr2-g2x8/GHSA-hv49-wcr2-g2x8.json index 9d9f3138872..ec74159dc7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv49-wcr2-g2x8/GHSA-hv49-wcr2-g2x8.json +++ b/advisories/unreviewed/2022/05/GHSA-hv49-wcr2-g2x8/GHSA-hv49-wcr2-g2x8.json @@ -7,12 +7,8 @@ "CVE-2008-3647" ], "details": "Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwm7-4pmv-pfmp/GHSA-hwm7-4pmv-pfmp.json b/advisories/unreviewed/2022/05/GHSA-hwm7-4pmv-pfmp/GHSA-hwm7-4pmv-pfmp.json index fd9fec05b01..d83b297b6b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwm7-4pmv-pfmp/GHSA-hwm7-4pmv-pfmp.json +++ b/advisories/unreviewed/2022/05/GHSA-hwm7-4pmv-pfmp/GHSA-hwm7-4pmv-pfmp.json @@ -7,12 +7,8 @@ "CVE-2008-3679" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx72-hww2-3246/GHSA-hx72-hww2-3246.json b/advisories/unreviewed/2022/05/GHSA-hx72-hww2-3246/GHSA-hx72-hww2-3246.json index ea63c0b9251..a798672098d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx72-hww2-3246/GHSA-hx72-hww2-3246.json +++ b/advisories/unreviewed/2022/05/GHSA-hx72-hww2-3246/GHSA-hx72-hww2-3246.json @@ -7,12 +7,8 @@ "CVE-2008-3499" ], "details": "Unspecified vulnerability in \"a page in the workarea folder\" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx7f-9jfv-xvrf/GHSA-hx7f-9jfv-xvrf.json b/advisories/unreviewed/2022/05/GHSA-hx7f-9jfv-xvrf/GHSA-hx7f-9jfv-xvrf.json index 15f25dae678..bd4036cf80c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx7f-9jfv-xvrf/GHSA-hx7f-9jfv-xvrf.json +++ b/advisories/unreviewed/2022/05/GHSA-hx7f-9jfv-xvrf/GHSA-hx7f-9jfv-xvrf.json @@ -7,12 +7,8 @@ "CVE-2008-3375" ], "details": "The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx8h-vwmg-rjww/GHSA-hx8h-vwmg-rjww.json b/advisories/unreviewed/2022/05/GHSA-hx8h-vwmg-rjww/GHSA-hx8h-vwmg-rjww.json index c6c36ecc3f2..43741b619ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx8h-vwmg-rjww/GHSA-hx8h-vwmg-rjww.json +++ b/advisories/unreviewed/2022/05/GHSA-hx8h-vwmg-rjww/GHSA-hx8h-vwmg-rjww.json @@ -7,12 +7,8 @@ "CVE-2008-3310" ], "details": "SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7vm-4hvg-39hq/GHSA-j7vm-4hvg-39hq.json b/advisories/unreviewed/2022/05/GHSA-j7vm-4hvg-39hq/GHSA-j7vm-4hvg-39hq.json index 1afe010e523..74d5f70c6fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7vm-4hvg-39hq/GHSA-j7vm-4hvg-39hq.json +++ b/advisories/unreviewed/2022/05/GHSA-j7vm-4hvg-39hq/GHSA-j7vm-4hvg-39hq.json @@ -7,12 +7,8 @@ "CVE-2019-18914" ], "details": "A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7x2-649w-mxwh/GHSA-j7x2-649w-mxwh.json b/advisories/unreviewed/2022/05/GHSA-j7x2-649w-mxwh/GHSA-j7x2-649w-mxwh.json index d8358790d95..5b79c463879 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7x2-649w-mxwh/GHSA-j7x2-649w-mxwh.json +++ b/advisories/unreviewed/2022/05/GHSA-j7x2-649w-mxwh/GHSA-j7x2-649w-mxwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j829-2m6v-p49x/GHSA-j829-2m6v-p49x.json b/advisories/unreviewed/2022/05/GHSA-j829-2m6v-p49x/GHSA-j829-2m6v-p49x.json index 472901cd7d3..3eec89573cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j829-2m6v-p49x/GHSA-j829-2m6v-p49x.json +++ b/advisories/unreviewed/2022/05/GHSA-j829-2m6v-p49x/GHSA-j829-2m6v-p49x.json @@ -7,12 +7,8 @@ "CVE-2019-14625" ], "details": "Improper access control in on-card storage for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8hj-v8wh-2hcf/GHSA-j8hj-v8wh-2hcf.json b/advisories/unreviewed/2022/05/GHSA-j8hj-v8wh-2hcf/GHSA-j8hj-v8wh-2hcf.json index 653fdabd5c5..3b16b7a99aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8hj-v8wh-2hcf/GHSA-j8hj-v8wh-2hcf.json +++ b/advisories/unreviewed/2022/05/GHSA-j8hj-v8wh-2hcf/GHSA-j8hj-v8wh-2hcf.json @@ -7,12 +7,8 @@ "CVE-2008-3416" ], "details": "SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8p2-hh7r-9r58/GHSA-j8p2-hh7r-9r58.json b/advisories/unreviewed/2022/05/GHSA-j8p2-hh7r-9r58/GHSA-j8p2-hh7r-9r58.json index d36b16e2d52..b99952f2a3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8p2-hh7r-9r58/GHSA-j8p2-hh7r-9r58.json +++ b/advisories/unreviewed/2022/05/GHSA-j8p2-hh7r-9r58/GHSA-j8p2-hh7r-9r58.json @@ -7,12 +7,8 @@ "CVE-2021-25980" ], "details": "In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8vg-fqfh-j78f/GHSA-j8vg-fqfh-j78f.json b/advisories/unreviewed/2022/05/GHSA-j8vg-fqfh-j78f/GHSA-j8vg-fqfh-j78f.json index 7a742c934c3..291b83f91ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8vg-fqfh-j78f/GHSA-j8vg-fqfh-j78f.json +++ b/advisories/unreviewed/2022/05/GHSA-j8vg-fqfh-j78f/GHSA-j8vg-fqfh-j78f.json @@ -7,12 +7,8 @@ "CVE-2020-9741" ], "details": "The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9cr-wr26-g3fp/GHSA-j9cr-wr26-g3fp.json b/advisories/unreviewed/2022/05/GHSA-j9cr-wr26-g3fp/GHSA-j9cr-wr26-g3fp.json index 93f36a1aed6..a70576ca15e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9cr-wr26-g3fp/GHSA-j9cr-wr26-g3fp.json +++ b/advisories/unreviewed/2022/05/GHSA-j9cr-wr26-g3fp/GHSA-j9cr-wr26-g3fp.json @@ -7,12 +7,8 @@ "CVE-2008-3546" ], "details": "Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9h4-w7cv-95mg/GHSA-j9h4-w7cv-95mg.json b/advisories/unreviewed/2022/05/GHSA-j9h4-w7cv-95mg/GHSA-j9h4-w7cv-95mg.json index 6628dc85e0a..84300c14bea 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9h4-w7cv-95mg/GHSA-j9h4-w7cv-95mg.json +++ b/advisories/unreviewed/2022/05/GHSA-j9h4-w7cv-95mg/GHSA-j9h4-w7cv-95mg.json @@ -7,12 +7,8 @@ "CVE-2008-3571" ], "details": "The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc2m-5w7r-h5rq/GHSA-jc2m-5w7r-h5rq.json b/advisories/unreviewed/2022/05/GHSA-jc2m-5w7r-h5rq/GHSA-jc2m-5w7r-h5rq.json index 3fda3ac67d3..5a04e670678 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc2m-5w7r-h5rq/GHSA-jc2m-5w7r-h5rq.json +++ b/advisories/unreviewed/2022/05/GHSA-jc2m-5w7r-h5rq/GHSA-jc2m-5w7r-h5rq.json @@ -7,12 +7,8 @@ "CVE-2008-3598" ], "details": "Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc45-r62q-6fv2/GHSA-jc45-r62q-6fv2.json b/advisories/unreviewed/2022/05/GHSA-jc45-r62q-6fv2/GHSA-jc45-r62q-6fv2.json index 8cfa6c0be27..9a15f386674 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc45-r62q-6fv2/GHSA-jc45-r62q-6fv2.json +++ b/advisories/unreviewed/2022/05/GHSA-jc45-r62q-6fv2/GHSA-jc45-r62q-6fv2.json @@ -7,12 +7,8 @@ "CVE-2008-3318" ], "details": "admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc8j-8m78-82j5/GHSA-jc8j-8m78-82j5.json b/advisories/unreviewed/2022/05/GHSA-jc8j-8m78-82j5/GHSA-jc8j-8m78-82j5.json index 9619b24a936..87fbf18e6ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc8j-8m78-82j5/GHSA-jc8j-8m78-82j5.json +++ b/advisories/unreviewed/2022/05/GHSA-jc8j-8m78-82j5/GHSA-jc8j-8m78-82j5.json @@ -7,12 +7,8 @@ "CVE-2021-28208" ], "details": "The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcg4-g8qf-7xgh/GHSA-jcg4-g8qf-7xgh.json b/advisories/unreviewed/2022/05/GHSA-jcg4-g8qf-7xgh/GHSA-jcg4-g8qf-7xgh.json index b06b3a91cfe..9e74df93bc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcg4-g8qf-7xgh/GHSA-jcg4-g8qf-7xgh.json +++ b/advisories/unreviewed/2022/05/GHSA-jcg4-g8qf-7xgh/GHSA-jcg4-g8qf-7xgh.json @@ -7,12 +7,8 @@ "CVE-2008-3535" ], "details": "Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgj9-5874-x5mv/GHSA-jgj9-5874-x5mv.json b/advisories/unreviewed/2022/05/GHSA-jgj9-5874-x5mv/GHSA-jgj9-5874-x5mv.json index 4b19f8b30c7..c99015b5751 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgj9-5874-x5mv/GHSA-jgj9-5874-x5mv.json +++ b/advisories/unreviewed/2022/05/GHSA-jgj9-5874-x5mv/GHSA-jgj9-5874-x5mv.json @@ -7,12 +7,8 @@ "CVE-2021-25923" ], "details": "In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgqm-9mm3-4p7g/GHSA-jgqm-9mm3-4p7g.json b/advisories/unreviewed/2022/05/GHSA-jgqm-9mm3-4p7g/GHSA-jgqm-9mm3-4p7g.json index e13e1823998..0edb1c6e935 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgqm-9mm3-4p7g/GHSA-jgqm-9mm3-4p7g.json +++ b/advisories/unreviewed/2022/05/GHSA-jgqm-9mm3-4p7g/GHSA-jgqm-9mm3-4p7g.json @@ -7,12 +7,8 @@ "CVE-2008-3325" ], "details": "Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhc7-f3vc-4pr5/GHSA-jhc7-f3vc-4pr5.json b/advisories/unreviewed/2022/05/GHSA-jhc7-f3vc-4pr5/GHSA-jhc7-f3vc-4pr5.json index 2843fa21a37..1b3c045e751 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhc7-f3vc-4pr5/GHSA-jhc7-f3vc-4pr5.json +++ b/advisories/unreviewed/2022/05/GHSA-jhc7-f3vc-4pr5/GHSA-jhc7-f3vc-4pr5.json @@ -7,12 +7,8 @@ "CVE-2008-3786" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka \"Gallery or event name\" field) in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhp7-q6m3-qh58/GHSA-jhp7-q6m3-qh58.json b/advisories/unreviewed/2022/05/GHSA-jhp7-q6m3-qh58/GHSA-jhp7-q6m3-qh58.json index 200b5477a9e..c039d0be518 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhp7-q6m3-qh58/GHSA-jhp7-q6m3-qh58.json +++ b/advisories/unreviewed/2022/05/GHSA-jhp7-q6m3-qh58/GHSA-jhp7-q6m3-qh58.json @@ -7,12 +7,8 @@ "CVE-2008-3408" ], "details": "Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a crafted m3u file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhx6-45qh-j9xp/GHSA-jhx6-45qh-j9xp.json b/advisories/unreviewed/2022/05/GHSA-jhx6-45qh-j9xp/GHSA-jhx6-45qh-j9xp.json index be7ab194884..63ee8fe1292 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhx6-45qh-j9xp/GHSA-jhx6-45qh-j9xp.json +++ b/advisories/unreviewed/2022/05/GHSA-jhx6-45qh-j9xp/GHSA-jhx6-45qh-j9xp.json @@ -7,12 +7,8 @@ "CVE-2021-33849" ], "details": "A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjg8-59qg-5373/GHSA-jjg8-59qg-5373.json b/advisories/unreviewed/2022/05/GHSA-jjg8-59qg-5373/GHSA-jjg8-59qg-5373.json index 9b8ef8aebe4..83d382735ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjg8-59qg-5373/GHSA-jjg8-59qg-5373.json +++ b/advisories/unreviewed/2022/05/GHSA-jjg8-59qg-5373/GHSA-jjg8-59qg-5373.json @@ -7,12 +7,8 @@ "CVE-2008-3234" ], "details": "sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjv9-765p-62g3/GHSA-jjv9-765p-62g3.json b/advisories/unreviewed/2022/05/GHSA-jjv9-765p-62g3/GHSA-jjv9-765p-62g3.json index 1a3607ff4a6..42ed2712139 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjv9-765p-62g3/GHSA-jjv9-765p-62g3.json +++ b/advisories/unreviewed/2022/05/GHSA-jjv9-765p-62g3/GHSA-jjv9-765p-62g3.json @@ -7,12 +7,8 @@ "CVE-2008-3495" ], "details": "SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm34-m4qh-33mq/GHSA-jm34-m4qh-33mq.json b/advisories/unreviewed/2022/05/GHSA-jm34-m4qh-33mq/GHSA-jm34-m4qh-33mq.json index 0b3f2817a9c..b1a3ddfdf8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm34-m4qh-33mq/GHSA-jm34-m4qh-33mq.json +++ b/advisories/unreviewed/2022/05/GHSA-jm34-m4qh-33mq/GHSA-jm34-m4qh-33mq.json @@ -7,12 +7,8 @@ "CVE-2008-3410" ], "details": "Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm8w-fg28-xm4m/GHSA-jm8w-fg28-xm4m.json b/advisories/unreviewed/2022/05/GHSA-jm8w-fg28-xm4m/GHSA-jm8w-fg28-xm4m.json index 4b9ae46b58c..ced4a0843b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm8w-fg28-xm4m/GHSA-jm8w-fg28-xm4m.json +++ b/advisories/unreviewed/2022/05/GHSA-jm8w-fg28-xm4m/GHSA-jm8w-fg28-xm4m.json @@ -7,12 +7,8 @@ "CVE-2021-24271" ], "details": "The “Ultimate Addons for Elementorâ€? WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmv6-j76g-xqjp/GHSA-jmv6-j76g-xqjp.json b/advisories/unreviewed/2022/05/GHSA-jmv6-j76g-xqjp/GHSA-jmv6-j76g-xqjp.json index a80c9017cf4..e6d3a83ca37 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmv6-j76g-xqjp/GHSA-jmv6-j76g-xqjp.json +++ b/advisories/unreviewed/2022/05/GHSA-jmv6-j76g-xqjp/GHSA-jmv6-j76g-xqjp.json @@ -7,12 +7,8 @@ "CVE-2021-27467" ], "details": "A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp5w-2f3c-7r7m/GHSA-jp5w-2f3c-7r7m.json b/advisories/unreviewed/2022/05/GHSA-jp5w-2f3c-7r7m/GHSA-jp5w-2f3c-7r7m.json index 6f09ffb76da..54b8ccdc906 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp5w-2f3c-7r7m/GHSA-jp5w-2f3c-7r7m.json +++ b/advisories/unreviewed/2022/05/GHSA-jp5w-2f3c-7r7m/GHSA-jp5w-2f3c-7r7m.json @@ -7,12 +7,8 @@ "CVE-2020-12852" ], "details": "The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. The update process involves downloading the updated binary file from a URL indicated in the update server response, validating its checksum and signature with the provided public key and finally replacing the current application binary. To complete the update process, the application’s service or appliance needs to be restarted. An attacker with administrator access can leverage the software update feature to force the application to download a custom binary that will replace current Pydio Cells binary. When the server or service is eventually restarted the attacker will be able to execute code under the privileges of the user running the application. In the Pydio Cells enterprise appliance this is with the privileges of the user named “pydio”.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jpwr-42jg-v5gg/GHSA-jpwr-42jg-v5gg.json b/advisories/unreviewed/2022/05/GHSA-jpwr-42jg-v5gg/GHSA-jpwr-42jg-v5gg.json index 0801c1c2bef..560d2e6862b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpwr-42jg-v5gg/GHSA-jpwr-42jg-v5gg.json +++ b/advisories/unreviewed/2022/05/GHSA-jpwr-42jg-v5gg/GHSA-jpwr-42jg-v5gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpx9-hmgp-grj6/GHSA-jpx9-hmgp-grj6.json b/advisories/unreviewed/2022/05/GHSA-jpx9-hmgp-grj6/GHSA-jpx9-hmgp-grj6.json index 3ee40eba576..9f5d41a8862 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpx9-hmgp-grj6/GHSA-jpx9-hmgp-grj6.json +++ b/advisories/unreviewed/2022/05/GHSA-jpx9-hmgp-grj6/GHSA-jpx9-hmgp-grj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq2r-g8wh-6q3v/GHSA-jq2r-g8wh-6q3v.json b/advisories/unreviewed/2022/05/GHSA-jq2r-g8wh-6q3v/GHSA-jq2r-g8wh-6q3v.json index c4a4b057cdc..46434a9f75b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq2r-g8wh-6q3v/GHSA-jq2r-g8wh-6q3v.json +++ b/advisories/unreviewed/2022/05/GHSA-jq2r-g8wh-6q3v/GHSA-jq2r-g8wh-6q3v.json @@ -7,12 +7,8 @@ "CVE-2020-9049" ], "details": "A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq6m-2q84-m3m8/GHSA-jq6m-2q84-m3m8.json b/advisories/unreviewed/2022/05/GHSA-jq6m-2q84-m3m8/GHSA-jq6m-2q84-m3m8.json index d2437caada1..770ba070977 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq6m-2q84-m3m8/GHSA-jq6m-2q84-m3m8.json +++ b/advisories/unreviewed/2022/05/GHSA-jq6m-2q84-m3m8/GHSA-jq6m-2q84-m3m8.json @@ -7,12 +7,8 @@ "CVE-2008-3796" ], "details": "Swfdec 0.6 before 0.6.8 allows remote attackers to cause a denial of service (application crash) via a 1x1 JPEG image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqf2-r732-pxp7/GHSA-jqf2-r732-pxp7.json b/advisories/unreviewed/2022/05/GHSA-jqf2-r732-pxp7/GHSA-jqf2-r732-pxp7.json index 3e5cf31fd34..2f0eab61e66 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqf2-r732-pxp7/GHSA-jqf2-r732-pxp7.json +++ b/advisories/unreviewed/2022/05/GHSA-jqf2-r732-pxp7/GHSA-jqf2-r732-pxp7.json @@ -7,12 +7,8 @@ "CVE-2008-3423" ], "details": "IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqpm-r7cv-6j3j/GHSA-jqpm-r7cv-6j3j.json b/advisories/unreviewed/2022/05/GHSA-jqpm-r7cv-6j3j/GHSA-jqpm-r7cv-6j3j.json index 793ef1654a0..f0a2e7e718b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqpm-r7cv-6j3j/GHSA-jqpm-r7cv-6j3j.json +++ b/advisories/unreviewed/2022/05/GHSA-jqpm-r7cv-6j3j/GHSA-jqpm-r7cv-6j3j.json @@ -7,12 +7,8 @@ "CVE-2008-3417" ], "details": "SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqx9-949x-554h/GHSA-jqx9-949x-554h.json b/advisories/unreviewed/2022/05/GHSA-jqx9-949x-554h/GHSA-jqx9-949x-554h.json index f740f2b8ec0..69b92e57820 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqx9-949x-554h/GHSA-jqx9-949x-554h.json +++ b/advisories/unreviewed/2022/05/GHSA-jqx9-949x-554h/GHSA-jqx9-949x-554h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jr3h-47v6-mrhj/GHSA-jr3h-47v6-mrhj.json b/advisories/unreviewed/2022/05/GHSA-jr3h-47v6-mrhj/GHSA-jr3h-47v6-mrhj.json index 1068d8a4265..438117879ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr3h-47v6-mrhj/GHSA-jr3h-47v6-mrhj.json +++ b/advisories/unreviewed/2022/05/GHSA-jr3h-47v6-mrhj/GHSA-jr3h-47v6-mrhj.json @@ -7,12 +7,8 @@ "CVE-2008-3607" ], "details": "The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrjj-g3cm-58m8/GHSA-jrjj-g3cm-58m8.json b/advisories/unreviewed/2022/05/GHSA-jrjj-g3cm-58m8/GHSA-jrjj-g3cm-58m8.json index 5aa7bdfb952..77fbbf6b69b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrjj-g3cm-58m8/GHSA-jrjj-g3cm-58m8.json +++ b/advisories/unreviewed/2022/05/GHSA-jrjj-g3cm-58m8/GHSA-jrjj-g3cm-58m8.json @@ -7,12 +7,8 @@ "CVE-2008-3198" ], "details": "Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvr6-pc69-7w54/GHSA-jvr6-pc69-7w54.json b/advisories/unreviewed/2022/05/GHSA-jvr6-pc69-7w54/GHSA-jvr6-pc69-7w54.json index 9d5d06d71a9..9888db79182 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvr6-pc69-7w54/GHSA-jvr6-pc69-7w54.json +++ b/advisories/unreviewed/2022/05/GHSA-jvr6-pc69-7w54/GHSA-jvr6-pc69-7w54.json @@ -7,12 +7,8 @@ "CVE-2020-15914" ], "details": "A cross-site scripting (XSS) vulnerability exists in the Origin Client that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvv6-hfxg-55hg/GHSA-jvv6-hfxg-55hg.json b/advisories/unreviewed/2022/05/GHSA-jvv6-hfxg-55hg/GHSA-jvv6-hfxg-55hg.json index 614984f2ea5..b2df89abc93 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvv6-hfxg-55hg/GHSA-jvv6-hfxg-55hg.json +++ b/advisories/unreviewed/2022/05/GHSA-jvv6-hfxg-55hg/GHSA-jvv6-hfxg-55hg.json @@ -7,12 +7,8 @@ "CVE-2021-28196" ], "details": "The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw26-hww8-fw75/GHSA-jw26-hww8-fw75.json b/advisories/unreviewed/2022/05/GHSA-jw26-hww8-fw75/GHSA-jw26-hww8-fw75.json index 57296c01a47..e185e3577f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw26-hww8-fw75/GHSA-jw26-hww8-fw75.json +++ b/advisories/unreviewed/2022/05/GHSA-jw26-hww8-fw75/GHSA-jw26-hww8-fw75.json @@ -7,12 +7,8 @@ "CVE-2008-3674" ], "details": "SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw78-mrpv-375c/GHSA-jw78-mrpv-375c.json b/advisories/unreviewed/2022/05/GHSA-jw78-mrpv-375c/GHSA-jw78-mrpv-375c.json index 4b96fffd4b8..f25906f577d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw78-mrpv-375c/GHSA-jw78-mrpv-375c.json +++ b/advisories/unreviewed/2022/05/GHSA-jw78-mrpv-375c/GHSA-jw78-mrpv-375c.json @@ -7,12 +7,8 @@ "CVE-2020-15797" ], "details": "A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to escape from the restricted environment (“kiosk mode”) and access the underlying operating system. Successful exploitation requires direct physical access to the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx26-7xc3-2xc3/GHSA-jx26-7xc3-2xc3.json b/advisories/unreviewed/2022/05/GHSA-jx26-7xc3-2xc3/GHSA-jx26-7xc3-2xc3.json index 236af941999..ceeb651a508 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx26-7xc3-2xc3/GHSA-jx26-7xc3-2xc3.json +++ b/advisories/unreviewed/2022/05/GHSA-jx26-7xc3-2xc3/GHSA-jx26-7xc3-2xc3.json @@ -7,12 +7,8 @@ "CVE-2021-24575" ], "details": "The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx9g-7qh9-qwj2/GHSA-jx9g-7qh9-qwj2.json b/advisories/unreviewed/2022/05/GHSA-jx9g-7qh9-qwj2/GHSA-jx9g-7qh9-qwj2.json index d967cf51b4a..39457b08df0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx9g-7qh9-qwj2/GHSA-jx9g-7qh9-qwj2.json +++ b/advisories/unreviewed/2022/05/GHSA-jx9g-7qh9-qwj2/GHSA-jx9g-7qh9-qwj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxcp-cjx8-wgh3/GHSA-jxcp-cjx8-wgh3.json b/advisories/unreviewed/2022/05/GHSA-jxcp-cjx8-wgh3/GHSA-jxcp-cjx8-wgh3.json index aa13d3ec98f..e3cf671aab8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxcp-cjx8-wgh3/GHSA-jxcp-cjx8-wgh3.json +++ b/advisories/unreviewed/2022/05/GHSA-jxcp-cjx8-wgh3/GHSA-jxcp-cjx8-wgh3.json @@ -7,12 +7,8 @@ "CVE-2008-3322" ], "details": "admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxm8-rf5q-gr35/GHSA-jxm8-rf5q-gr35.json b/advisories/unreviewed/2022/05/GHSA-jxm8-rf5q-gr35/GHSA-jxm8-rf5q-gr35.json index 540a264e6e4..d9fafd9bb40 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxm8-rf5q-gr35/GHSA-jxm8-rf5q-gr35.json +++ b/advisories/unreviewed/2022/05/GHSA-jxm8-rf5q-gr35/GHSA-jxm8-rf5q-gr35.json @@ -7,12 +7,8 @@ "CVE-2008-3645" ], "details": "Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5 allows local users to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m269-mpv8-frq4/GHSA-m269-mpv8-frq4.json b/advisories/unreviewed/2022/05/GHSA-m269-mpv8-frq4/GHSA-m269-mpv8-frq4.json index 945d5ecd366..8cf32b43217 100644 --- a/advisories/unreviewed/2022/05/GHSA-m269-mpv8-frq4/GHSA-m269-mpv8-frq4.json +++ b/advisories/unreviewed/2022/05/GHSA-m269-mpv8-frq4/GHSA-m269-mpv8-frq4.json @@ -7,12 +7,8 @@ "CVE-2008-3552" ], "details": "Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka \"ISSUES 11-15.\" NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m28c-vf5g-3rv9/GHSA-m28c-vf5g-3rv9.json b/advisories/unreviewed/2022/05/GHSA-m28c-vf5g-3rv9/GHSA-m28c-vf5g-3rv9.json index 9260727dd25..132d42281bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-m28c-vf5g-3rv9/GHSA-m28c-vf5g-3rv9.json +++ b/advisories/unreviewed/2022/05/GHSA-m28c-vf5g-3rv9/GHSA-m28c-vf5g-3rv9.json @@ -7,12 +7,8 @@ "CVE-2008-3391" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m29g-2pfv-37px/GHSA-m29g-2pfv-37px.json b/advisories/unreviewed/2022/05/GHSA-m29g-2pfv-37px/GHSA-m29g-2pfv-37px.json index 48caff1e014..bf1a443b229 100644 --- a/advisories/unreviewed/2022/05/GHSA-m29g-2pfv-37px/GHSA-m29g-2pfv-37px.json +++ b/advisories/unreviewed/2022/05/GHSA-m29g-2pfv-37px/GHSA-m29g-2pfv-37px.json @@ -7,12 +7,8 @@ "CVE-2008-3625" ], "details": "Stack-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted (1) maxTilt, (2) minFieldOfView, and (3) maxFieldOfView elements in panorama track PDAT atoms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2mj-c2fg-gwxp/GHSA-m2mj-c2fg-gwxp.json b/advisories/unreviewed/2022/05/GHSA-m2mj-c2fg-gwxp/GHSA-m2mj-c2fg-gwxp.json index 57ae17c223a..47a6ad297a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2mj-c2fg-gwxp/GHSA-m2mj-c2fg-gwxp.json +++ b/advisories/unreviewed/2022/05/GHSA-m2mj-c2fg-gwxp/GHSA-m2mj-c2fg-gwxp.json @@ -7,12 +7,8 @@ "CVE-2008-3506" ], "details": "SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2pg-h6p9-9j46/GHSA-m2pg-h6p9-9j46.json b/advisories/unreviewed/2022/05/GHSA-m2pg-h6p9-9j46/GHSA-m2pg-h6p9-9j46.json index 422887ab91f..fc6cb3fd849 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2pg-h6p9-9j46/GHSA-m2pg-h6p9-9j46.json +++ b/advisories/unreviewed/2022/05/GHSA-m2pg-h6p9-9j46/GHSA-m2pg-h6p9-9j46.json @@ -7,12 +7,8 @@ "CVE-2008-3249" ], "details": "The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3mc-w2qf-4wc3/GHSA-m3mc-w2qf-4wc3.json b/advisories/unreviewed/2022/05/GHSA-m3mc-w2qf-4wc3/GHSA-m3mc-w2qf-4wc3.json index e7efafdb13a..d78fd7f09cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3mc-w2qf-4wc3/GHSA-m3mc-w2qf-4wc3.json +++ b/advisories/unreviewed/2022/05/GHSA-m3mc-w2qf-4wc3/GHSA-m3mc-w2qf-4wc3.json @@ -7,12 +7,8 @@ "CVE-2008-3444" ], "details": "The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains \"a simple set of legitimate HTML tags.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4pp-cj4x-58f6/GHSA-m4pp-cj4x-58f6.json b/advisories/unreviewed/2022/05/GHSA-m4pp-cj4x-58f6/GHSA-m4pp-cj4x-58f6.json index cf92686f614..c2f4b3adca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4pp-cj4x-58f6/GHSA-m4pp-cj4x-58f6.json +++ b/advisories/unreviewed/2022/05/GHSA-m4pp-cj4x-58f6/GHSA-m4pp-cj4x-58f6.json @@ -7,12 +7,8 @@ "CVE-2021-24647" ], "details": "The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4wx-2h8j-2863/GHSA-m4wx-2h8j-2863.json b/advisories/unreviewed/2022/05/GHSA-m4wx-2h8j-2863/GHSA-m4wx-2h8j-2863.json index 643581e090a..24aac4e1e6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4wx-2h8j-2863/GHSA-m4wx-2h8j-2863.json +++ b/advisories/unreviewed/2022/05/GHSA-m4wx-2h8j-2863/GHSA-m4wx-2h8j-2863.json @@ -7,12 +7,8 @@ "CVE-2008-3241" ], "details": "SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m54q-pw67-qrw6/GHSA-m54q-pw67-qrw6.json b/advisories/unreviewed/2022/05/GHSA-m54q-pw67-qrw6/GHSA-m54q-pw67-qrw6.json index 277eeefcb79..e6a9d545edd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m54q-pw67-qrw6/GHSA-m54q-pw67-qrw6.json +++ b/advisories/unreviewed/2022/05/GHSA-m54q-pw67-qrw6/GHSA-m54q-pw67-qrw6.json @@ -7,12 +7,8 @@ "CVE-2008-3366" ], "details": "SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5hv-jx4h-jgff/GHSA-m5hv-jx4h-jgff.json b/advisories/unreviewed/2022/05/GHSA-m5hv-jx4h-jgff/GHSA-m5hv-jx4h-jgff.json index 23a633a228b..8efad90ff2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5hv-jx4h-jgff/GHSA-m5hv-jx4h-jgff.json +++ b/advisories/unreviewed/2022/05/GHSA-m5hv-jx4h-jgff/GHSA-m5hv-jx4h-jgff.json @@ -7,12 +7,8 @@ "CVE-2008-3653" ], "details": "Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m65v-5768-w2rf/GHSA-m65v-5768-w2rf.json b/advisories/unreviewed/2022/05/GHSA-m65v-5768-w2rf/GHSA-m65v-5768-w2rf.json index 921727e35ea..4e4e51e7962 100644 --- a/advisories/unreviewed/2022/05/GHSA-m65v-5768-w2rf/GHSA-m65v-5768-w2rf.json +++ b/advisories/unreviewed/2022/05/GHSA-m65v-5768-w2rf/GHSA-m65v-5768-w2rf.json @@ -7,12 +7,8 @@ "CVE-2021-24706" ], "details": "The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6fm-6936-9w3j/GHSA-m6fm-6936-9w3j.json b/advisories/unreviewed/2022/05/GHSA-m6fm-6936-9w3j/GHSA-m6fm-6936-9w3j.json index bb40bf5fb87..048d2075aab 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6fm-6936-9w3j/GHSA-m6fm-6936-9w3j.json +++ b/advisories/unreviewed/2022/05/GHSA-m6fm-6936-9w3j/GHSA-m6fm-6936-9w3j.json @@ -7,12 +7,8 @@ "CVE-2008-3669" ], "details": "SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6m5-v2j5-7rhr/GHSA-m6m5-v2j5-7rhr.json b/advisories/unreviewed/2022/05/GHSA-m6m5-v2j5-7rhr/GHSA-m6m5-v2j5-7rhr.json index 044d7ccc256..0331250c052 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6m5-v2j5-7rhr/GHSA-m6m5-v2j5-7rhr.json +++ b/advisories/unreviewed/2022/05/GHSA-m6m5-v2j5-7rhr/GHSA-m6m5-v2j5-7rhr.json @@ -7,12 +7,8 @@ "CVE-2008-3560" ], "details": "Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6r9-xv3r-256h/GHSA-m6r9-xv3r-256h.json b/advisories/unreviewed/2022/05/GHSA-m6r9-xv3r-256h/GHSA-m6r9-xv3r-256h.json index 70395e72215..3a88182a0fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6r9-xv3r-256h/GHSA-m6r9-xv3r-256h.json +++ b/advisories/unreviewed/2022/05/GHSA-m6r9-xv3r-256h/GHSA-m6r9-xv3r-256h.json @@ -7,12 +7,8 @@ "CVE-2008-3256" ], "details": "SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7q8-9wff-7rxc/GHSA-m7q8-9wff-7rxc.json b/advisories/unreviewed/2022/05/GHSA-m7q8-9wff-7rxc/GHSA-m7q8-9wff-7rxc.json index 7548b082c30..4fa67d900e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7q8-9wff-7rxc/GHSA-m7q8-9wff-7rxc.json +++ b/advisories/unreviewed/2022/05/GHSA-m7q8-9wff-7rxc/GHSA-m7q8-9wff-7rxc.json @@ -7,12 +7,8 @@ "CVE-2008-3643" ], "details": "Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restart) via a crafted Desktop file that generates an error when producing its icon, related to an \"error recovery issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7qv-8x33-wwfg/GHSA-m7qv-8x33-wwfg.json b/advisories/unreviewed/2022/05/GHSA-m7qv-8x33-wwfg/GHSA-m7qv-8x33-wwfg.json index 512d8b0cf79..6faa6142417 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7qv-8x33-wwfg/GHSA-m7qv-8x33-wwfg.json +++ b/advisories/unreviewed/2022/05/GHSA-m7qv-8x33-wwfg/GHSA-m7qv-8x33-wwfg.json @@ -7,12 +7,8 @@ "CVE-2008-3379" ], "details": "Cross-site scripting (XSS) vulnerability in Snark VisualPic 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the pic parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m82j-jcw6-26r7/GHSA-m82j-jcw6-26r7.json b/advisories/unreviewed/2022/05/GHSA-m82j-jcw6-26r7/GHSA-m82j-jcw6-26r7.json index 105b790c8b5..3da54b0bb4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m82j-jcw6-26r7/GHSA-m82j-jcw6-26r7.json +++ b/advisories/unreviewed/2022/05/GHSA-m82j-jcw6-26r7/GHSA-m82j-jcw6-26r7.json @@ -7,12 +7,8 @@ "CVE-2008-3373" ], "details": "The files parsing engine in Grisoft AVG Anti-Virus before 8.0.156 allows remote attackers to cause a denial of service (engine crash) via a crafted UPX compressed file, which triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m86p-9hj8-wr2g/GHSA-m86p-9hj8-wr2g.json b/advisories/unreviewed/2022/05/GHSA-m86p-9hj8-wr2g/GHSA-m86p-9hj8-wr2g.json index ed9be552c90..74e22a944bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-m86p-9hj8-wr2g/GHSA-m86p-9hj8-wr2g.json +++ b/advisories/unreviewed/2022/05/GHSA-m86p-9hj8-wr2g/GHSA-m86p-9hj8-wr2g.json @@ -7,12 +7,8 @@ "CVE-2021-24196" ], "details": "The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m973-jggp-c9jm/GHSA-m973-jggp-c9jm.json b/advisories/unreviewed/2022/05/GHSA-m973-jggp-c9jm/GHSA-m973-jggp-c9jm.json index b5f1144d4d5..ddcf9bed51d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m973-jggp-c9jm/GHSA-m973-jggp-c9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-m973-jggp-c9jm/GHSA-m973-jggp-c9jm.json @@ -7,12 +7,8 @@ "CVE-2008-3351" ], "details": "SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9hg-4jr5-84jx/GHSA-m9hg-4jr5-84jx.json b/advisories/unreviewed/2022/05/GHSA-m9hg-4jr5-84jx/GHSA-m9hg-4jr5-84jx.json index 7e1a9306b5c..0707646e862 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9hg-4jr5-84jx/GHSA-m9hg-4jr5-84jx.json +++ b/advisories/unreviewed/2022/05/GHSA-m9hg-4jr5-84jx/GHSA-m9hg-4jr5-84jx.json @@ -7,12 +7,8 @@ "CVE-2008-3705" ], "details": "Stack-based buffer overflow in the CLogger::WriteFormated function in echoware/Logger.cpp in EchoVNC Linux before 1.1.2 allows remote echoServers to execute arbitrary code via a large (1) group or (2) user list, aka a \"very crowded echoServer\" attack. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9mx-fh6q-cw99/GHSA-m9mx-fh6q-cw99.json b/advisories/unreviewed/2022/05/GHSA-m9mx-fh6q-cw99/GHSA-m9mx-fh6q-cw99.json index 7775db684a5..683a7c56c77 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9mx-fh6q-cw99/GHSA-m9mx-fh6q-cw99.json +++ b/advisories/unreviewed/2022/05/GHSA-m9mx-fh6q-cw99/GHSA-m9mx-fh6q-cw99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc9c-24hr-w33v/GHSA-mc9c-24hr-w33v.json b/advisories/unreviewed/2022/05/GHSA-mc9c-24hr-w33v/GHSA-mc9c-24hr-w33v.json index 81c26ee127e..882a54ae07c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc9c-24hr-w33v/GHSA-mc9c-24hr-w33v.json +++ b/advisories/unreviewed/2022/05/GHSA-mc9c-24hr-w33v/GHSA-mc9c-24hr-w33v.json @@ -7,12 +7,8 @@ "CVE-2008-3311" ], "details": "PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcwf-vrgj-ww66/GHSA-mcwf-vrgj-ww66.json b/advisories/unreviewed/2022/05/GHSA-mcwf-vrgj-ww66/GHSA-mcwf-vrgj-ww66.json index c5e4cc06eea..5503574e9a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcwf-vrgj-ww66/GHSA-mcwf-vrgj-ww66.json +++ b/advisories/unreviewed/2022/05/GHSA-mcwf-vrgj-ww66/GHSA-mcwf-vrgj-ww66.json @@ -7,12 +7,8 @@ "CVE-2008-3583" ], "details": "Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an IMG element. NOTE: this might be related to CVE-2008-3360. NOTE: it was later reported that 2.08 Beta 4 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf8h-g57h-xqhr/GHSA-mf8h-g57h-xqhr.json b/advisories/unreviewed/2022/05/GHSA-mf8h-g57h-xqhr/GHSA-mf8h-g57h-xqhr.json index fdc2d147bd3..011e0a0e701 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf8h-g57h-xqhr/GHSA-mf8h-g57h-xqhr.json +++ b/advisories/unreviewed/2022/05/GHSA-mf8h-g57h-xqhr/GHSA-mf8h-g57h-xqhr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg8v-h9r6-299j/GHSA-mg8v-h9r6-299j.json b/advisories/unreviewed/2022/05/GHSA-mg8v-h9r6-299j/GHSA-mg8v-h9r6-299j.json index 2be8b03cb04..1d86ae14955 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg8v-h9r6-299j/GHSA-mg8v-h9r6-299j.json +++ b/advisories/unreviewed/2022/05/GHSA-mg8v-h9r6-299j/GHSA-mg8v-h9r6-299j.json @@ -7,12 +7,8 @@ "CVE-2020-14492" ], "details": "OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution of malicious code within the user’s browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgxv-q3xg-wrqj/GHSA-mgxv-q3xg-wrqj.json b/advisories/unreviewed/2022/05/GHSA-mgxv-q3xg-wrqj/GHSA-mgxv-q3xg-wrqj.json index 5728cd85801..bf1b392c034 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgxv-q3xg-wrqj/GHSA-mgxv-q3xg-wrqj.json +++ b/advisories/unreviewed/2022/05/GHSA-mgxv-q3xg-wrqj/GHSA-mgxv-q3xg-wrqj.json @@ -7,12 +7,8 @@ "CVE-2008-3511" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhvw-gjfc-ccqf/GHSA-mhvw-gjfc-ccqf.json b/advisories/unreviewed/2022/05/GHSA-mhvw-gjfc-ccqf/GHSA-mhvw-gjfc-ccqf.json index a934360363d..4a4a269da91 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhvw-gjfc-ccqf/GHSA-mhvw-gjfc-ccqf.json +++ b/advisories/unreviewed/2022/05/GHSA-mhvw-gjfc-ccqf/GHSA-mhvw-gjfc-ccqf.json @@ -7,12 +7,8 @@ "CVE-2021-42839" ], "details": "Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjm8-79v5-5g8h/GHSA-mjm8-79v5-5g8h.json b/advisories/unreviewed/2022/05/GHSA-mjm8-79v5-5g8h/GHSA-mjm8-79v5-5g8h.json index c2395601794..474f3b18840 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjm8-79v5-5g8h/GHSA-mjm8-79v5-5g8h.json +++ b/advisories/unreviewed/2022/05/GHSA-mjm8-79v5-5g8h/GHSA-mjm8-79v5-5g8h.json @@ -7,12 +7,8 @@ "CVE-2020-25445" ], "details": "The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjp9-pgr7-8j62/GHSA-mjp9-pgr7-8j62.json b/advisories/unreviewed/2022/05/GHSA-mjp9-pgr7-8j62/GHSA-mjp9-pgr7-8j62.json index 2274ee87b8f..8deff7bd6a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp9-pgr7-8j62/GHSA-mjp9-pgr7-8j62.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp9-pgr7-8j62/GHSA-mjp9-pgr7-8j62.json @@ -7,12 +7,8 @@ "CVE-2008-3618" ], "details": "The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm94-4mf6-6w8g/GHSA-mm94-4mf6-6w8g.json b/advisories/unreviewed/2022/05/GHSA-mm94-4mf6-6w8g/GHSA-mm94-4mf6-6w8g.json index f3c239400a6..bd68b3c922a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm94-4mf6-6w8g/GHSA-mm94-4mf6-6w8g.json +++ b/advisories/unreviewed/2022/05/GHSA-mm94-4mf6-6w8g/GHSA-mm94-4mf6-6w8g.json @@ -7,12 +7,8 @@ "CVE-2021-24221" ], "details": "The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp93-g9m9-rwh8/GHSA-mp93-g9m9-rwh8.json b/advisories/unreviewed/2022/05/GHSA-mp93-g9m9-rwh8/GHSA-mp93-g9m9-rwh8.json index 0f3c4430fb6..7bec6a07f2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp93-g9m9-rwh8/GHSA-mp93-g9m9-rwh8.json +++ b/advisories/unreviewed/2022/05/GHSA-mp93-g9m9-rwh8/GHSA-mp93-g9m9-rwh8.json @@ -7,12 +7,8 @@ "CVE-2019-5176" ], "details": "An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file.The destination buffer sp+0x40 is overflowed with the call to sprintf() for any gateway values that are greater than 512-len(‘/etc/config-tools/config_default_gateway number=0 state=enabled value=‘) in length. A gateway value of length 0x7e2 will cause the service to crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpcp-76x2-2jrq/GHSA-mpcp-76x2-2jrq.json b/advisories/unreviewed/2022/05/GHSA-mpcp-76x2-2jrq/GHSA-mpcp-76x2-2jrq.json index 937633a53ae..5ba4999b996 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpcp-76x2-2jrq/GHSA-mpcp-76x2-2jrq.json +++ b/advisories/unreviewed/2022/05/GHSA-mpcp-76x2-2jrq/GHSA-mpcp-76x2-2jrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpr2-984f-35c4/GHSA-mpr2-984f-35c4.json b/advisories/unreviewed/2022/05/GHSA-mpr2-984f-35c4/GHSA-mpr2-984f-35c4.json index cf0569e1986..fa14d8f6fa8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpr2-984f-35c4/GHSA-mpr2-984f-35c4.json +++ b/advisories/unreviewed/2022/05/GHSA-mpr2-984f-35c4/GHSA-mpr2-984f-35c4.json @@ -7,12 +7,8 @@ "CVE-2021-3032" ], "details": "An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information may include up to 1024 bytes of the configuration including the username and password in an encrypted form and private keys used in any certificate profiles set for log forwarding server profiles. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq56-39xc-8q38/GHSA-mq56-39xc-8q38.json b/advisories/unreviewed/2022/05/GHSA-mq56-39xc-8q38/GHSA-mq56-39xc-8q38.json index 1737302cbc1..0615f841b45 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq56-39xc-8q38/GHSA-mq56-39xc-8q38.json +++ b/advisories/unreviewed/2022/05/GHSA-mq56-39xc-8q38/GHSA-mq56-39xc-8q38.json @@ -7,12 +7,8 @@ "CVE-2008-3254" ], "details": "SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrmm-m7c9-vvmg/GHSA-mrmm-m7c9-vvmg.json b/advisories/unreviewed/2022/05/GHSA-mrmm-m7c9-vvmg/GHSA-mrmm-m7c9-vvmg.json index 5e4673f0754..6d7865444ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrmm-m7c9-vvmg/GHSA-mrmm-m7c9-vvmg.json +++ b/advisories/unreviewed/2022/05/GHSA-mrmm-m7c9-vvmg/GHSA-mrmm-m7c9-vvmg.json @@ -7,12 +7,8 @@ "CVE-2008-3321" ], "details": "admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrqq-vvqv-64pg/GHSA-mrqq-vvqv-64pg.json b/advisories/unreviewed/2022/05/GHSA-mrqq-vvqv-64pg/GHSA-mrqq-vvqv-64pg.json index 81258931374..188f5c547d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrqq-vvqv-64pg/GHSA-mrqq-vvqv-64pg.json +++ b/advisories/unreviewed/2022/05/GHSA-mrqq-vvqv-64pg/GHSA-mrqq-vvqv-64pg.json @@ -7,12 +7,8 @@ "CVE-2008-3782" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field under Credit/Debit Users, and the (3) FAQ question and (4) FAQ answer fields under Add New FAQ Entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvp3-9f9g-qv99/GHSA-mvp3-9f9g-qv99.json b/advisories/unreviewed/2022/05/GHSA-mvp3-9f9g-qv99/GHSA-mvp3-9f9g-qv99.json index fa3455fbb1d..7f724d73e91 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvp3-9f9g-qv99/GHSA-mvp3-9f9g-qv99.json +++ b/advisories/unreviewed/2022/05/GHSA-mvp3-9f9g-qv99/GHSA-mvp3-9f9g-qv99.json @@ -7,12 +7,8 @@ "CVE-2021-24150" ], "details": "The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw89-4hwr-68gg/GHSA-mw89-4hwr-68gg.json b/advisories/unreviewed/2022/05/GHSA-mw89-4hwr-68gg/GHSA-mw89-4hwr-68gg.json index ca3510d97f5..b5021ebd88d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw89-4hwr-68gg/GHSA-mw89-4hwr-68gg.json +++ b/advisories/unreviewed/2022/05/GHSA-mw89-4hwr-68gg/GHSA-mw89-4hwr-68gg.json @@ -7,12 +7,8 @@ "CVE-2008-3668" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description field of a new scrap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw9v-68m8-wr95/GHSA-mw9v-68m8-wr95.json b/advisories/unreviewed/2022/05/GHSA-mw9v-68m8-wr95/GHSA-mw9v-68m8-wr95.json index 585fcab3107..e73d25a7b0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw9v-68m8-wr95/GHSA-mw9v-68m8-wr95.json +++ b/advisories/unreviewed/2022/05/GHSA-mw9v-68m8-wr95/GHSA-mw9v-68m8-wr95.json @@ -7,12 +7,8 @@ "CVE-2020-15909" ], "details": "SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against multiple sources such as sourceip, MFA claim, etc. as long as the victim stays logged in within N-Central. To take advantage of this, cookie could be stolen and the JSESSIONID can be captured. On its own this is not a surprising result; low security tools allow the cookie to roam from machine to machine. The JSESSION cookie can then be used on the attackers’ workstation by browsing to the victim’s NCentral server URL and replacing the JSESSIONID attribute value by the captured value. Expected behavior would be to check this against a second source and enforce at least a reauthentication or multi factor request as N-Central is a highly privileged service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwm5-47gq-45p5/GHSA-mwm5-47gq-45p5.json b/advisories/unreviewed/2022/05/GHSA-mwm5-47gq-45p5/GHSA-mwm5-47gq-45p5.json index c50bd26fa49..12c6ec64112 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwm5-47gq-45p5/GHSA-mwm5-47gq-45p5.json +++ b/advisories/unreviewed/2022/05/GHSA-mwm5-47gq-45p5/GHSA-mwm5-47gq-45p5.json @@ -7,12 +7,8 @@ "CVE-2008-3341" ], "details": "Multiple SQL injection vulnerabilities in search_result.cfm in Jobbex JobSite allow remote attackers to execute arbitrary SQL commands via the (1) jobcountryid and (2) jobstateid parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwvm-j6jc-8j7r/GHSA-mwvm-j6jc-8j7r.json b/advisories/unreviewed/2022/05/GHSA-mwvm-j6jc-8j7r/GHSA-mwvm-j6jc-8j7r.json index 007ad98f9b3..ce5975a4ef7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwvm-j6jc-8j7r/GHSA-mwvm-j6jc-8j7r.json +++ b/advisories/unreviewed/2022/05/GHSA-mwvm-j6jc-8j7r/GHSA-mwvm-j6jc-8j7r.json @@ -7,12 +7,8 @@ "CVE-2021-21577" ], "details": "Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx7v-jfp8-4wr2/GHSA-mx7v-jfp8-4wr2.json b/advisories/unreviewed/2022/05/GHSA-mx7v-jfp8-4wr2/GHSA-mx7v-jfp8-4wr2.json index a3bb7cb5432..47765db1951 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx7v-jfp8-4wr2/GHSA-mx7v-jfp8-4wr2.json +++ b/advisories/unreviewed/2022/05/GHSA-mx7v-jfp8-4wr2/GHSA-mx7v-jfp8-4wr2.json @@ -7,12 +7,8 @@ "CVE-2021-42534" ], "details": "The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mxr8-pcpg-m23j/GHSA-mxr8-pcpg-m23j.json b/advisories/unreviewed/2022/05/GHSA-mxr8-pcpg-m23j/GHSA-mxr8-pcpg-m23j.json index 4222cc8279e..acdd94462f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxr8-pcpg-m23j/GHSA-mxr8-pcpg-m23j.json +++ b/advisories/unreviewed/2022/05/GHSA-mxr8-pcpg-m23j/GHSA-mxr8-pcpg-m23j.json @@ -7,12 +7,8 @@ "CVE-2008-3228" ], "details": "Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that \"block common exploits\" to SEF URLs, which has unknown impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3g7-9g37-34p3/GHSA-p3g7-9g37-34p3.json b/advisories/unreviewed/2022/05/GHSA-p3g7-9g37-34p3/GHSA-p3g7-9g37-34p3.json index 3938b2b0081..1b3f10eecd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3g7-9g37-34p3/GHSA-p3g7-9g37-34p3.json +++ b/advisories/unreviewed/2022/05/GHSA-p3g7-9g37-34p3/GHSA-p3g7-9g37-34p3.json @@ -7,12 +7,8 @@ "CVE-2008-3372" ], "details": "SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3rh-c6ff-9m2g/GHSA-p3rh-c6ff-9m2g.json b/advisories/unreviewed/2022/05/GHSA-p3rh-c6ff-9m2g/GHSA-p3rh-c6ff-9m2g.json index 56ca6b9a1e0..efdc802fdf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3rh-c6ff-9m2g/GHSA-p3rh-c6ff-9m2g.json +++ b/advisories/unreviewed/2022/05/GHSA-p3rh-c6ff-9m2g/GHSA-p3rh-c6ff-9m2g.json @@ -7,12 +7,8 @@ "CVE-2008-3556" ], "details": "Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action. NOTE: vector 1 might be the same as CVE-2008-2522.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3vw-pmcf-8h54/GHSA-p3vw-pmcf-8h54.json b/advisories/unreviewed/2022/05/GHSA-p3vw-pmcf-8h54/GHSA-p3vw-pmcf-8h54.json index 29a963740c0..6ecd554d040 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3vw-pmcf-8h54/GHSA-p3vw-pmcf-8h54.json +++ b/advisories/unreviewed/2022/05/GHSA-p3vw-pmcf-8h54/GHSA-p3vw-pmcf-8h54.json @@ -7,12 +7,8 @@ "CVE-2021-30172" ], "details": "Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additionally access and manipulate customer’s information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p437-2c77-84p4/GHSA-p437-2c77-84p4.json b/advisories/unreviewed/2022/05/GHSA-p437-2c77-84p4/GHSA-p437-2c77-84p4.json index 3d87169df13..f7ec0a6c5c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p437-2c77-84p4/GHSA-p437-2c77-84p4.json +++ b/advisories/unreviewed/2022/05/GHSA-p437-2c77-84p4/GHSA-p437-2c77-84p4.json @@ -7,12 +7,8 @@ "CVE-2021-25940" ], "details": "In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p44m-m5cf-5q6f/GHSA-p44m-m5cf-5q6f.json b/advisories/unreviewed/2022/05/GHSA-p44m-m5cf-5q6f/GHSA-p44m-m5cf-5q6f.json index 42447c35246..af5bbc174c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p44m-m5cf-5q6f/GHSA-p44m-m5cf-5q6f.json +++ b/advisories/unreviewed/2022/05/GHSA-p44m-m5cf-5q6f/GHSA-p44m-m5cf-5q6f.json @@ -7,12 +7,8 @@ "CVE-2021-24187" ], "details": "The setting page of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin through 6.3 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p49c-32gv-6cc5/GHSA-p49c-32gv-6cc5.json b/advisories/unreviewed/2022/05/GHSA-p49c-32gv-6cc5/GHSA-p49c-32gv-6cc5.json index 39de34c0849..12bac7b2558 100644 --- a/advisories/unreviewed/2022/05/GHSA-p49c-32gv-6cc5/GHSA-p49c-32gv-6cc5.json +++ b/advisories/unreviewed/2022/05/GHSA-p49c-32gv-6cc5/GHSA-p49c-32gv-6cc5.json @@ -7,12 +7,8 @@ "CVE-2021-24242" ], "details": "The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4r6-gxf8-g5v4/GHSA-p4r6-gxf8-g5v4.json b/advisories/unreviewed/2022/05/GHSA-p4r6-gxf8-g5v4/GHSA-p4r6-gxf8-g5v4.json index 847415fb90f..70157e2ba8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4r6-gxf8-g5v4/GHSA-p4r6-gxf8-g5v4.json +++ b/advisories/unreviewed/2022/05/GHSA-p4r6-gxf8-g5v4/GHSA-p4r6-gxf8-g5v4.json @@ -7,12 +7,8 @@ "CVE-2008-3703" ], "details": "The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create \"snapshots schedules\" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p524-ppf2-w36w/GHSA-p524-ppf2-w36w.json b/advisories/unreviewed/2022/05/GHSA-p524-ppf2-w36w/GHSA-p524-ppf2-w36w.json index bf2da07b487..465eb5febb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p524-ppf2-w36w/GHSA-p524-ppf2-w36w.json +++ b/advisories/unreviewed/2022/05/GHSA-p524-ppf2-w36w/GHSA-p524-ppf2-w36w.json @@ -7,12 +7,8 @@ "CVE-2008-3655" ], "details": "Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -148,9 +144,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p52p-hq77-4mj2/GHSA-p52p-hq77-4mj2.json b/advisories/unreviewed/2022/05/GHSA-p52p-hq77-4mj2/GHSA-p52p-hq77-4mj2.json index dfb97264884..5c93e5dee45 100644 --- a/advisories/unreviewed/2022/05/GHSA-p52p-hq77-4mj2/GHSA-p52p-hq77-4mj2.json +++ b/advisories/unreviewed/2022/05/GHSA-p52p-hq77-4mj2/GHSA-p52p-hq77-4mj2.json @@ -7,12 +7,8 @@ "CVE-2008-3434" ], "details": "Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p584-873g-v9x6/GHSA-p584-873g-v9x6.json b/advisories/unreviewed/2022/05/GHSA-p584-873g-v9x6/GHSA-p584-873g-v9x6.json index e38e445da36..ca57e65865f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p584-873g-v9x6/GHSA-p584-873g-v9x6.json +++ b/advisories/unreviewed/2022/05/GHSA-p584-873g-v9x6/GHSA-p584-873g-v9x6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p599-g5cv-9wxc/GHSA-p599-g5cv-9wxc.json b/advisories/unreviewed/2022/05/GHSA-p599-g5cv-9wxc/GHSA-p599-g5cv-9wxc.json index f31dc1a6003..9b25e97d41f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p599-g5cv-9wxc/GHSA-p599-g5cv-9wxc.json +++ b/advisories/unreviewed/2022/05/GHSA-p599-g5cv-9wxc/GHSA-p599-g5cv-9wxc.json @@ -7,12 +7,8 @@ "CVE-2008-3695" ], "details": "Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, and CVE-2008-3696.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5cf-ff3x-jwfr/GHSA-p5cf-ff3x-jwfr.json b/advisories/unreviewed/2022/05/GHSA-p5cf-ff3x-jwfr/GHSA-p5cf-ff3x-jwfr.json index a8553dbdd1c..541e3f70d0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5cf-ff3x-jwfr/GHSA-p5cf-ff3x-jwfr.json +++ b/advisories/unreviewed/2022/05/GHSA-p5cf-ff3x-jwfr/GHSA-p5cf-ff3x-jwfr.json @@ -7,12 +7,8 @@ "CVE-2008-3316" ], "details": "Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5px-xx74-cwjx/GHSA-p5px-xx74-cwjx.json b/advisories/unreviewed/2022/05/GHSA-p5px-xx74-cwjx/GHSA-p5px-xx74-cwjx.json index 28791dd1d0c..bb267294d94 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5px-xx74-cwjx/GHSA-p5px-xx74-cwjx.json +++ b/advisories/unreviewed/2022/05/GHSA-p5px-xx74-cwjx/GHSA-p5px-xx74-cwjx.json @@ -7,12 +7,8 @@ "CVE-2021-22153" ], "details": "A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p633-7rgq-3w9f/GHSA-p633-7rgq-3w9f.json b/advisories/unreviewed/2022/05/GHSA-p633-7rgq-3w9f/GHSA-p633-7rgq-3w9f.json index e85d4cebcbb..75dc8f293e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p633-7rgq-3w9f/GHSA-p633-7rgq-3w9f.json +++ b/advisories/unreviewed/2022/05/GHSA-p633-7rgq-3w9f/GHSA-p633-7rgq-3w9f.json @@ -7,12 +7,8 @@ "CVE-2020-6021" ], "details": "Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p73q-xx6c-487x/GHSA-p73q-xx6c-487x.json b/advisories/unreviewed/2022/05/GHSA-p73q-xx6c-487x/GHSA-p73q-xx6c-487x.json index 4221ee917b8..6376864e53f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p73q-xx6c-487x/GHSA-p73q-xx6c-487x.json +++ b/advisories/unreviewed/2022/05/GHSA-p73q-xx6c-487x/GHSA-p73q-xx6c-487x.json @@ -7,12 +7,8 @@ "CVE-2008-3507" ], "details": "SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p799-qjp6-h93p/GHSA-p799-qjp6-h93p.json b/advisories/unreviewed/2022/05/GHSA-p799-qjp6-h93p/GHSA-p799-qjp6-h93p.json index 3c0abb4dd26..a3a7595ddba 100644 --- a/advisories/unreviewed/2022/05/GHSA-p799-qjp6-h93p/GHSA-p799-qjp6-h93p.json +++ b/advisories/unreviewed/2022/05/GHSA-p799-qjp6-h93p/GHSA-p799-qjp6-h93p.json @@ -7,12 +7,8 @@ "CVE-2021-25968" ], "details": "In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7c7-mv35-5vjr/GHSA-p7c7-mv35-5vjr.json b/advisories/unreviewed/2022/05/GHSA-p7c7-mv35-5vjr/GHSA-p7c7-mv35-5vjr.json index 10f137ad642..ffc5f5d8a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7c7-mv35-5vjr/GHSA-p7c7-mv35-5vjr.json +++ b/advisories/unreviewed/2022/05/GHSA-p7c7-mv35-5vjr/GHSA-p7c7-mv35-5vjr.json @@ -7,12 +7,8 @@ "CVE-2008-3213" ], "details": "SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.php in a tablon action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7r9-324c-364p/GHSA-p7r9-324c-364p.json b/advisories/unreviewed/2022/05/GHSA-p7r9-324c-364p/GHSA-p7r9-324c-364p.json index ce7b77db896..2b7a899c109 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7r9-324c-364p/GHSA-p7r9-324c-364p.json +++ b/advisories/unreviewed/2022/05/GHSA-p7r9-324c-364p/GHSA-p7r9-324c-364p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7xc-v22w-8pjm/GHSA-p7xc-v22w-8pjm.json b/advisories/unreviewed/2022/05/GHSA-p7xc-v22w-8pjm/GHSA-p7xc-v22w-8pjm.json index 860a4efdbab..8d32f135ca9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7xc-v22w-8pjm/GHSA-p7xc-v22w-8pjm.json +++ b/advisories/unreviewed/2022/05/GHSA-p7xc-v22w-8pjm/GHSA-p7xc-v22w-8pjm.json @@ -7,12 +7,8 @@ "CVE-2021-38472" ], "details": "InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the router’s management portal and could lure the administrator to perform changes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8fh-8437-rr8p/GHSA-p8fh-8437-rr8p.json b/advisories/unreviewed/2022/05/GHSA-p8fh-8437-rr8p/GHSA-p8fh-8437-rr8p.json index 296e578d435..27868d52a88 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8fh-8437-rr8p/GHSA-p8fh-8437-rr8p.json +++ b/advisories/unreviewed/2022/05/GHSA-p8fh-8437-rr8p/GHSA-p8fh-8437-rr8p.json @@ -7,12 +7,8 @@ "CVE-2021-38469" ], "details": "Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8mq-xv89-9v46/GHSA-p8mq-xv89-9v46.json b/advisories/unreviewed/2022/05/GHSA-p8mq-xv89-9v46/GHSA-p8mq-xv89-9v46.json index b4db430e1f3..264cd65a421 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8mq-xv89-9v46/GHSA-p8mq-xv89-9v46.json +++ b/advisories/unreviewed/2022/05/GHSA-p8mq-xv89-9v46/GHSA-p8mq-xv89-9v46.json @@ -7,12 +7,8 @@ "CVE-2008-3202" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the current_url parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p98w-wx76-q85h/GHSA-p98w-wx76-q85h.json b/advisories/unreviewed/2022/05/GHSA-p98w-wx76-q85h/GHSA-p98w-wx76-q85h.json index a9319bc9e80..dd1303f7f5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p98w-wx76-q85h/GHSA-p98w-wx76-q85h.json +++ b/advisories/unreviewed/2022/05/GHSA-p98w-wx76-q85h/GHSA-p98w-wx76-q85h.json @@ -7,12 +7,8 @@ "CVE-2008-3619" ], "details": "Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log files, which allows local users to obtain sensitive information by reading these files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9j8-4mf3-42hc/GHSA-p9j8-4mf3-42hc.json b/advisories/unreviewed/2022/05/GHSA-p9j8-4mf3-42hc/GHSA-p9j8-4mf3-42hc.json index 90fcbb96aa4..efa04dcf6bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9j8-4mf3-42hc/GHSA-p9j8-4mf3-42hc.json +++ b/advisories/unreviewed/2022/05/GHSA-p9j8-4mf3-42hc/GHSA-p9j8-4mf3-42hc.json @@ -7,12 +7,8 @@ "CVE-2021-28195" ], "details": "The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9pq-3p4w-g86x/GHSA-p9pq-3p4w-g86x.json b/advisories/unreviewed/2022/05/GHSA-p9pq-3p4w-g86x/GHSA-p9pq-3p4w-g86x.json index 99cd5d7dcf1..5616e2c2ff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9pq-3p4w-g86x/GHSA-p9pq-3p4w-g86x.json +++ b/advisories/unreviewed/2022/05/GHSA-p9pq-3p4w-g86x/GHSA-p9pq-3p4w-g86x.json @@ -7,12 +7,8 @@ "CVE-2008-3212" ], "details": "Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc78-6jfc-54mv/GHSA-pc78-6jfc-54mv.json b/advisories/unreviewed/2022/05/GHSA-pc78-6jfc-54mv/GHSA-pc78-6jfc-54mv.json index 04ddc7a2726..3c19a2765f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc78-6jfc-54mv/GHSA-pc78-6jfc-54mv.json +++ b/advisories/unreviewed/2022/05/GHSA-pc78-6jfc-54mv/GHSA-pc78-6jfc-54mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcxm-p9m5-5732/GHSA-pcxm-p9m5-5732.json b/advisories/unreviewed/2022/05/GHSA-pcxm-p9m5-5732/GHSA-pcxm-p9m5-5732.json index c7ed779936d..dca0804c808 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcxm-p9m5-5732/GHSA-pcxm-p9m5-5732.json +++ b/advisories/unreviewed/2022/05/GHSA-pcxm-p9m5-5732/GHSA-pcxm-p9m5-5732.json @@ -7,12 +7,8 @@ "CVE-2008-3388" ], "details": "Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf3f-93qv-r3rp/GHSA-pf3f-93qv-r3rp.json b/advisories/unreviewed/2022/05/GHSA-pf3f-93qv-r3rp/GHSA-pf3f-93qv-r3rp.json index c65bc204cee..3b278d6fd0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf3f-93qv-r3rp/GHSA-pf3f-93qv-r3rp.json +++ b/advisories/unreviewed/2022/05/GHSA-pf3f-93qv-r3rp/GHSA-pf3f-93qv-r3rp.json @@ -7,12 +7,8 @@ "CVE-2008-3673" ], "details": "SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf3g-p3qp-7mc8/GHSA-pf3g-p3qp-7mc8.json b/advisories/unreviewed/2022/05/GHSA-pf3g-p3qp-7mc8/GHSA-pf3g-p3qp-7mc8.json index 9bcea6948cd..d0fd0ece48b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf3g-p3qp-7mc8/GHSA-pf3g-p3qp-7mc8.json +++ b/advisories/unreviewed/2022/05/GHSA-pf3g-p3qp-7mc8/GHSA-pf3g-p3qp-7mc8.json @@ -7,12 +7,8 @@ "CVE-2020-7477" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (all Versions), and Premium processors with integrated Ethernet (all Versions), which could cause a Denial of Service when sending a specially crafted command over Modbus.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pf3q-84pr-fv6p/GHSA-pf3q-84pr-fv6p.json b/advisories/unreviewed/2022/05/GHSA-pf3q-84pr-fv6p/GHSA-pf3q-84pr-fv6p.json index 47c0e020f76..45a93d2bf99 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf3q-84pr-fv6p/GHSA-pf3q-84pr-fv6p.json +++ b/advisories/unreviewed/2022/05/GHSA-pf3q-84pr-fv6p/GHSA-pf3q-84pr-fv6p.json @@ -7,12 +7,8 @@ "CVE-2021-24220" ], "details": "Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken image optimization engine. By supplying a crafted request in combination with data inserted using the Option Update vulnerability, it was possible to use this endpoint to retrieve malicious code from a remote URL and overwrite an existing file on the site with it or create a new file.This includes executable PHP files that contain malicious code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf43-g47c-f3f8/GHSA-pf43-g47c-f3f8.json b/advisories/unreviewed/2022/05/GHSA-pf43-g47c-f3f8/GHSA-pf43-g47c-f3f8.json index c8b6137510d..6b1849f649a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf43-g47c-f3f8/GHSA-pf43-g47c-f3f8.json +++ b/advisories/unreviewed/2022/05/GHSA-pf43-g47c-f3f8/GHSA-pf43-g47c-f3f8.json @@ -7,12 +7,8 @@ "CVE-2021-24208" ], "details": "The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sending a crafted request - it appears that this widget uses some form of client side validation but not server side validation), all of which are added via the “page_builder_data” parameter when performing the “wppb_page_save” AJAX action. It is also possible to insert malicious JavaScript via the “wppb_page_css” parameter (this can be done by closing out the style tag and opening a script tag) when performing the “wppb_page_save” AJAX action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf5c-8gw5-qm72/GHSA-pf5c-8gw5-qm72.json b/advisories/unreviewed/2022/05/GHSA-pf5c-8gw5-qm72/GHSA-pf5c-8gw5-qm72.json index 48fdaf35dbc..0a80fa5d06e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf5c-8gw5-qm72/GHSA-pf5c-8gw5-qm72.json +++ b/advisories/unreviewed/2022/05/GHSA-pf5c-8gw5-qm72/GHSA-pf5c-8gw5-qm72.json @@ -7,12 +7,8 @@ "CVE-2008-3553" ], "details": "Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka \"ISSUES 3-10.\" NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pff9-9x5h-m85p/GHSA-pff9-9x5h-m85p.json b/advisories/unreviewed/2022/05/GHSA-pff9-9x5h-m85p/GHSA-pff9-9x5h-m85p.json index ab5d4adc608..1757360035e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pff9-9x5h-m85p/GHSA-pff9-9x5h-m85p.json +++ b/advisories/unreviewed/2022/05/GHSA-pff9-9x5h-m85p/GHSA-pff9-9x5h-m85p.json @@ -7,12 +7,8 @@ "CVE-2021-24205" ], "details": "In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg42-7827-374h/GHSA-pg42-7827-374h.json b/advisories/unreviewed/2022/05/GHSA-pg42-7827-374h/GHSA-pg42-7827-374h.json index a2052d4a9c9..c3d03a90b0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg42-7827-374h/GHSA-pg42-7827-374h.json +++ b/advisories/unreviewed/2022/05/GHSA-pg42-7827-374h/GHSA-pg42-7827-374h.json @@ -7,12 +7,8 @@ "CVE-2021-24362" ], "details": "The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgmx-7rcq-jpg9/GHSA-pgmx-7rcq-jpg9.json b/advisories/unreviewed/2022/05/GHSA-pgmx-7rcq-jpg9/GHSA-pgmx-7rcq-jpg9.json index f015f089363..e2af1e6d3c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgmx-7rcq-jpg9/GHSA-pgmx-7rcq-jpg9.json +++ b/advisories/unreviewed/2022/05/GHSA-pgmx-7rcq-jpg9/GHSA-pgmx-7rcq-jpg9.json @@ -7,12 +7,8 @@ "CVE-2019-5175" ], "details": "An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1ea28 the extracted type value from the xml file is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=enabled config-type=<contents of type node> using sprintf(). This command is later executed via a call to system().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgq5-cwpc-m697/GHSA-pgq5-cwpc-m697.json b/advisories/unreviewed/2022/05/GHSA-pgq5-cwpc-m697/GHSA-pgq5-cwpc-m697.json index 4c385871a1c..57abfdf7d0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgq5-cwpc-m697/GHSA-pgq5-cwpc-m697.json +++ b/advisories/unreviewed/2022/05/GHSA-pgq5-cwpc-m697/GHSA-pgq5-cwpc-m697.json @@ -7,12 +7,8 @@ "CVE-2021-24531" ], "details": "The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph39-qv25-h277/GHSA-ph39-qv25-h277.json b/advisories/unreviewed/2022/05/GHSA-ph39-qv25-h277/GHSA-ph39-qv25-h277.json index 0fc8a972307..b7403614e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph39-qv25-h277/GHSA-ph39-qv25-h277.json +++ b/advisories/unreviewed/2022/05/GHSA-ph39-qv25-h277/GHSA-ph39-qv25-h277.json @@ -7,12 +7,8 @@ "CVE-2008-3419" ], "details": "SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph5w-cfvx-frhm/GHSA-ph5w-cfvx-frhm.json b/advisories/unreviewed/2022/05/GHSA-ph5w-cfvx-frhm/GHSA-ph5w-cfvx-frhm.json index 5ef61ccbcc2..9cf89c4ce8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph5w-cfvx-frhm/GHSA-ph5w-cfvx-frhm.json +++ b/advisories/unreviewed/2022/05/GHSA-ph5w-cfvx-frhm/GHSA-ph5w-cfvx-frhm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phgc-94qm-68px/GHSA-phgc-94qm-68px.json b/advisories/unreviewed/2022/05/GHSA-phgc-94qm-68px/GHSA-phgc-94qm-68px.json index 41444e1e49c..99497524b3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-phgc-94qm-68px/GHSA-phgc-94qm-68px.json +++ b/advisories/unreviewed/2022/05/GHSA-phgc-94qm-68px/GHSA-phgc-94qm-68px.json @@ -7,12 +7,8 @@ "CVE-2021-24282" ], "details": "In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phmm-796g-q6c9/GHSA-phmm-796g-q6c9.json b/advisories/unreviewed/2022/05/GHSA-phmm-796g-q6c9/GHSA-phmm-796g-q6c9.json index 804f87af8a0..06eca39711e 100644 --- a/advisories/unreviewed/2022/05/GHSA-phmm-796g-q6c9/GHSA-phmm-796g-q6c9.json +++ b/advisories/unreviewed/2022/05/GHSA-phmm-796g-q6c9/GHSA-phmm-796g-q6c9.json @@ -7,12 +7,8 @@ "CVE-2008-3639" ], "details": "Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj65-hgjq-jjx9/GHSA-pj65-hgjq-jjx9.json b/advisories/unreviewed/2022/05/GHSA-pj65-hgjq-jjx9/GHSA-pj65-hgjq-jjx9.json index ae5a65658e5..dc5e063b810 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj65-hgjq-jjx9/GHSA-pj65-hgjq-jjx9.json +++ b/advisories/unreviewed/2022/05/GHSA-pj65-hgjq-jjx9/GHSA-pj65-hgjq-jjx9.json @@ -7,12 +7,8 @@ "CVE-2008-3395" ], "details": "Calacode @Mail 5.41 on Linux uses weak world-readable permissions for (1) webmail/libs/Atmail/Config.php and (2) webmail/webadmin/.htpasswd, which allows local users to obtain sensitive information by reading these files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pjqf-p7cw-pv8c/GHSA-pjqf-p7cw-pv8c.json b/advisories/unreviewed/2022/05/GHSA-pjqf-p7cw-pv8c/GHSA-pjqf-p7cw-pv8c.json index 061adea0b99..7170bbf7576 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjqf-p7cw-pv8c/GHSA-pjqf-p7cw-pv8c.json +++ b/advisories/unreviewed/2022/05/GHSA-pjqf-p7cw-pv8c/GHSA-pjqf-p7cw-pv8c.json @@ -7,12 +7,8 @@ "CVE-2021-24269" ], "details": "The “Sina Extension for Elementorâ€? WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjrv-f38m-2f55/GHSA-pjrv-f38m-2f55.json b/advisories/unreviewed/2022/05/GHSA-pjrv-f38m-2f55/GHSA-pjrv-f38m-2f55.json index afa35a966fb..f3638f549d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjrv-f38m-2f55/GHSA-pjrv-f38m-2f55.json +++ b/advisories/unreviewed/2022/05/GHSA-pjrv-f38m-2f55/GHSA-pjrv-f38m-2f55.json @@ -7,12 +7,8 @@ "CVE-2008-3441" ], "details": "Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjx3-2523-w68g/GHSA-pjx3-2523-w68g.json b/advisories/unreviewed/2022/05/GHSA-pjx3-2523-w68g/GHSA-pjx3-2523-w68g.json index 387ac8dbb7e..15433378744 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjx3-2523-w68g/GHSA-pjx3-2523-w68g.json +++ b/advisories/unreviewed/2022/05/GHSA-pjx3-2523-w68g/GHSA-pjx3-2523-w68g.json @@ -7,12 +7,8 @@ "CVE-2021-28205" ], "details": "The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm8p-867f-r9w3/GHSA-pm8p-867f-r9w3.json b/advisories/unreviewed/2022/05/GHSA-pm8p-867f-r9w3/GHSA-pm8p-867f-r9w3.json index e76d76160dd..da0c22ec1c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm8p-867f-r9w3/GHSA-pm8p-867f-r9w3.json +++ b/advisories/unreviewed/2022/05/GHSA-pm8p-867f-r9w3/GHSA-pm8p-867f-r9w3.json @@ -7,12 +7,8 @@ "CVE-2021-27208" ], "details": "When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page is too large, this causes a buffer overflow that could lead to arbitrary code execution. Physical access and modification to the Zynq-7000 device is needed to replace the original nand flash memory with a nand flash emulator for this attack to be successful.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmfh-pxqg-pgf4/GHSA-pmfh-pxqg-pgf4.json b/advisories/unreviewed/2022/05/GHSA-pmfh-pxqg-pgf4/GHSA-pmfh-pxqg-pgf4.json index 08ca6398d03..4a0f4960312 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmfh-pxqg-pgf4/GHSA-pmfh-pxqg-pgf4.json +++ b/advisories/unreviewed/2022/05/GHSA-pmfh-pxqg-pgf4/GHSA-pmfh-pxqg-pgf4.json @@ -7,12 +7,8 @@ "CVE-2021-36850" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters \"post_title\", \"filename\", \"lock\". This allows changing the uploaded media title, media file name, and media locking state.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp2x-6q67-cgr6/GHSA-pp2x-6q67-cgr6.json b/advisories/unreviewed/2022/05/GHSA-pp2x-6q67-cgr6/GHSA-pp2x-6q67-cgr6.json index 52a494f9dde..ae8f8501d92 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp2x-6q67-cgr6/GHSA-pp2x-6q67-cgr6.json +++ b/advisories/unreviewed/2022/05/GHSA-pp2x-6q67-cgr6/GHSA-pp2x-6q67-cgr6.json @@ -7,12 +7,8 @@ "CVE-2008-3360" ], "details": "Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability than CVE-2006-2494.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp6m-453g-g6j5/GHSA-pp6m-453g-g6j5.json b/advisories/unreviewed/2022/05/GHSA-pp6m-453g-g6j5/GHSA-pp6m-453g-g6j5.json index e4190a896ab..95f5d5f11d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp6m-453g-g6j5/GHSA-pp6m-453g-g6j5.json +++ b/advisories/unreviewed/2022/05/GHSA-pp6m-453g-g6j5/GHSA-pp6m-453g-g6j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq4m-8wh5-vj6c/GHSA-pq4m-8wh5-vj6c.json b/advisories/unreviewed/2022/05/GHSA-pq4m-8wh5-vj6c/GHSA-pq4m-8wh5-vj6c.json index 4a2633d1a27..73f617db99c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq4m-8wh5-vj6c/GHSA-pq4m-8wh5-vj6c.json +++ b/advisories/unreviewed/2022/05/GHSA-pq4m-8wh5-vj6c/GHSA-pq4m-8wh5-vj6c.json @@ -7,12 +7,8 @@ "CVE-2008-3600" ], "details": "Directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1.5.7 and 1.6-alpha3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter within a modload action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq88-rh4g-43f6/GHSA-pq88-rh4g-43f6.json b/advisories/unreviewed/2022/05/GHSA-pq88-rh4g-43f6/GHSA-pq88-rh4g-43f6.json index e5e2d08a373..0acbc5ef9e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq88-rh4g-43f6/GHSA-pq88-rh4g-43f6.json +++ b/advisories/unreviewed/2022/05/GHSA-pq88-rh4g-43f6/GHSA-pq88-rh4g-43f6.json @@ -7,12 +7,8 @@ "CVE-2020-9784" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqhq-xh7v-ph7c/GHSA-pqhq-xh7v-ph7c.json b/advisories/unreviewed/2022/05/GHSA-pqhq-xh7v-ph7c/GHSA-pqhq-xh7v-ph7c.json index 4fd1d28c999..9ac1d05e087 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqhq-xh7v-ph7c/GHSA-pqhq-xh7v-ph7c.json +++ b/advisories/unreviewed/2022/05/GHSA-pqhq-xh7v-ph7c/GHSA-pqhq-xh7v-ph7c.json @@ -7,12 +7,8 @@ "CVE-2008-3626" ], "details": "The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqr4-7554-v3x8/GHSA-pqr4-7554-v3x8.json b/advisories/unreviewed/2022/05/GHSA-pqr4-7554-v3x8/GHSA-pqr4-7554-v3x8.json index 6d7153b9776..eae8c5dfb1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqr4-7554-v3x8/GHSA-pqr4-7554-v3x8.json +++ b/advisories/unreviewed/2022/05/GHSA-pqr4-7554-v3x8/GHSA-pqr4-7554-v3x8.json @@ -7,12 +7,8 @@ "CVE-2008-3300" ], "details": "AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa_login cookie value to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqww-9fvq-hf8c/GHSA-pqww-9fvq-hf8c.json b/advisories/unreviewed/2022/05/GHSA-pqww-9fvq-hf8c/GHSA-pqww-9fvq-hf8c.json index bbdfadaab18..b44b5c55cf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqww-9fvq-hf8c/GHSA-pqww-9fvq-hf8c.json +++ b/advisories/unreviewed/2022/05/GHSA-pqww-9fvq-hf8c/GHSA-pqww-9fvq-hf8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr66-8cxp-7866/GHSA-pr66-8cxp-7866.json b/advisories/unreviewed/2022/05/GHSA-pr66-8cxp-7866/GHSA-pr66-8cxp-7866.json index bc5f852daaf..e519a27b933 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr66-8cxp-7866/GHSA-pr66-8cxp-7866.json +++ b/advisories/unreviewed/2022/05/GHSA-pr66-8cxp-7866/GHSA-pr66-8cxp-7866.json @@ -7,12 +7,8 @@ "CVE-2021-28182" ], "details": "The Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr6m-xr2g-5w3x/GHSA-pr6m-xr2g-5w3x.json b/advisories/unreviewed/2022/05/GHSA-pr6m-xr2g-5w3x/GHSA-pr6m-xr2g-5w3x.json index 232d96934c5..f31ba132eec 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr6m-xr2g-5w3x/GHSA-pr6m-xr2g-5w3x.json +++ b/advisories/unreviewed/2022/05/GHSA-pr6m-xr2g-5w3x/GHSA-pr6m-xr2g-5w3x.json @@ -7,12 +7,8 @@ "CVE-2020-27278" ], "details": "In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers with physical access to obtain admin privileges for the device’s configuration interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr8r-jp27-hqg7/GHSA-pr8r-jp27-hqg7.json b/advisories/unreviewed/2022/05/GHSA-pr8r-jp27-hqg7/GHSA-pr8r-jp27-hqg7.json index 099d40bd28c..782352d614e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr8r-jp27-hqg7/GHSA-pr8r-jp27-hqg7.json +++ b/advisories/unreviewed/2022/05/GHSA-pr8r-jp27-hqg7/GHSA-pr8r-jp27-hqg7.json @@ -7,12 +7,8 @@ "CVE-2008-3320" ], "details": "admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prpx-5phw-fx4m/GHSA-prpx-5phw-fx4m.json b/advisories/unreviewed/2022/05/GHSA-prpx-5phw-fx4m/GHSA-prpx-5phw-fx4m.json index 3d026f9cc75..b89204d9359 100644 --- a/advisories/unreviewed/2022/05/GHSA-prpx-5phw-fx4m/GHSA-prpx-5phw-fx4m.json +++ b/advisories/unreviewed/2022/05/GHSA-prpx-5phw-fx4m/GHSA-prpx-5phw-fx4m.json @@ -7,12 +7,8 @@ "CVE-2021-23253" ], "details": "Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With the URL being left-aligned, the user will only see the front part (e.g. www.safe.opera.com…) The exact amount depends on the phone screen size but the attacker can craft a number of different domains and target different phones. Starting with version 53.1 Opera Mini displays long URLs with the top-level domain label aligned to the right of the address field which mitigates the issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvj2-qmqv-76p3/GHSA-pvj2-qmqv-76p3.json b/advisories/unreviewed/2022/05/GHSA-pvj2-qmqv-76p3/GHSA-pvj2-qmqv-76p3.json index 82453628cff..f68dbb91a0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvj2-qmqv-76p3/GHSA-pvj2-qmqv-76p3.json +++ b/advisories/unreviewed/2022/05/GHSA-pvj2-qmqv-76p3/GHSA-pvj2-qmqv-76p3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvj3-v8pc-2m39/GHSA-pvj3-v8pc-2m39.json b/advisories/unreviewed/2022/05/GHSA-pvj3-v8pc-2m39/GHSA-pvj3-v8pc-2m39.json index d02b1a9ab2d..7f11ef99b77 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvj3-v8pc-2m39/GHSA-pvj3-v8pc-2m39.json +++ b/advisories/unreviewed/2022/05/GHSA-pvj3-v8pc-2m39/GHSA-pvj3-v8pc-2m39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw6x-r6v2-63cw/GHSA-pw6x-r6v2-63cw.json b/advisories/unreviewed/2022/05/GHSA-pw6x-r6v2-63cw/GHSA-pw6x-r6v2-63cw.json index 4a234ef59fc..0b5e7d2b527 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw6x-r6v2-63cw/GHSA-pw6x-r6v2-63cw.json +++ b/advisories/unreviewed/2022/05/GHSA-pw6x-r6v2-63cw/GHSA-pw6x-r6v2-63cw.json @@ -7,12 +7,8 @@ "CVE-2008-3614" ], "details": "Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-px4c-gw6m-mq7v/GHSA-px4c-gw6m-mq7v.json b/advisories/unreviewed/2022/05/GHSA-px4c-gw6m-mq7v/GHSA-px4c-gw6m-mq7v.json index e887cc4b471..5ae2b311f6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-px4c-gw6m-mq7v/GHSA-px4c-gw6m-mq7v.json +++ b/advisories/unreviewed/2022/05/GHSA-px4c-gw6m-mq7v/GHSA-px4c-gw6m-mq7v.json @@ -7,12 +7,8 @@ "CVE-2021-34382" ], "details": "Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on the size parameter causes the request buffer and the logging buffer to overflow, allowing writes to arbitrary addresses within the kernel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q28h-28x6-hw4r/GHSA-q28h-28x6-hw4r.json b/advisories/unreviewed/2022/05/GHSA-q28h-28x6-hw4r/GHSA-q28h-28x6-hw4r.json index fd357c1aa76..7bae1cc1949 100644 --- a/advisories/unreviewed/2022/05/GHSA-q28h-28x6-hw4r/GHSA-q28h-28x6-hw4r.json +++ b/advisories/unreviewed/2022/05/GHSA-q28h-28x6-hw4r/GHSA-q28h-28x6-hw4r.json @@ -7,12 +7,8 @@ "CVE-2021-21581" ], "details": "Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q354-p7j8-f3fx/GHSA-q354-p7j8-f3fx.json b/advisories/unreviewed/2022/05/GHSA-q354-p7j8-f3fx/GHSA-q354-p7j8-f3fx.json index 71747300ef4..745b59e1f9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q354-p7j8-f3fx/GHSA-q354-p7j8-f3fx.json +++ b/advisories/unreviewed/2022/05/GHSA-q354-p7j8-f3fx/GHSA-q354-p7j8-f3fx.json @@ -7,12 +7,8 @@ "CVE-2008-3214" ], "details": "dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3jf-j7gq-3h67/GHSA-q3jf-j7gq-3h67.json b/advisories/unreviewed/2022/05/GHSA-q3jf-j7gq-3h67/GHSA-q3jf-j7gq-3h67.json index f8abb894003..6c16e4b5e8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3jf-j7gq-3h67/GHSA-q3jf-j7gq-3h67.json +++ b/advisories/unreviewed/2022/05/GHSA-q3jf-j7gq-3h67/GHSA-q3jf-j7gq-3h67.json @@ -7,12 +7,8 @@ "CVE-2008-3191" ], "details": "Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q443-7g5q-hqjr/GHSA-q443-7g5q-hqjr.json b/advisories/unreviewed/2022/05/GHSA-q443-7g5q-hqjr/GHSA-q443-7g5q-hqjr.json index 48ff50a0a0f..e3e90520059 100644 --- a/advisories/unreviewed/2022/05/GHSA-q443-7g5q-hqjr/GHSA-q443-7g5q-hqjr.json +++ b/advisories/unreviewed/2022/05/GHSA-q443-7g5q-hqjr/GHSA-q443-7g5q-hqjr.json @@ -7,12 +7,8 @@ "CVE-2008-3200" ], "details": "SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q47g-v9q4-8q7g/GHSA-q47g-v9q4-8q7g.json b/advisories/unreviewed/2022/05/GHSA-q47g-v9q4-8q7g/GHSA-q47g-v9q4-8q7g.json index 9b6e52aa8bd..71167473d6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q47g-v9q4-8q7g/GHSA-q47g-v9q4-8q7g.json +++ b/advisories/unreviewed/2022/05/GHSA-q47g-v9q4-8q7g/GHSA-q47g-v9q4-8q7g.json @@ -7,12 +7,8 @@ "CVE-2008-3537" ], "details": "Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4hh-4qxq-c529/GHSA-q4hh-4qxq-c529.json b/advisories/unreviewed/2022/05/GHSA-q4hh-4qxq-c529/GHSA-q4hh-4qxq-c529.json index 3956cd1255a..5c95a18be40 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4hh-4qxq-c529/GHSA-q4hh-4qxq-c529.json +++ b/advisories/unreviewed/2022/05/GHSA-q4hh-4qxq-c529/GHSA-q4hh-4qxq-c529.json @@ -7,12 +7,8 @@ "CVE-2008-3661" ], "details": "Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4mf-j4qj-96f2/GHSA-q4mf-j4qj-96f2.json b/advisories/unreviewed/2022/05/GHSA-q4mf-j4qj-96f2/GHSA-q4mf-j4qj-96f2.json index d619fbf8c3d..431f39f5242 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4mf-j4qj-96f2/GHSA-q4mf-j4qj-96f2.json +++ b/advisories/unreviewed/2022/05/GHSA-q4mf-j4qj-96f2/GHSA-q4mf-j4qj-96f2.json @@ -7,12 +7,8 @@ "CVE-2020-12145" ], "details": "Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by introducing an HTTP HOST header set to 127.0.0.1 or localhost. Orchestrator instances that are hosted by customers –on-premise or in a public cloud provider –are affected by this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4q3-596j-p268/GHSA-q4q3-596j-p268.json b/advisories/unreviewed/2022/05/GHSA-q4q3-596j-p268/GHSA-q4q3-596j-p268.json index c8d4b0417b3..6d81028b169 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4q3-596j-p268/GHSA-q4q3-596j-p268.json +++ b/advisories/unreviewed/2022/05/GHSA-q4q3-596j-p268/GHSA-q4q3-596j-p268.json @@ -7,12 +7,8 @@ "CVE-2019-5180" ], "details": "An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination buffer sp+0x440 is overflowed with the call to sprintf() for any ip values that are greater than 1024-len(‘/etc/config-tools/config_interfaces interface=X1 state=enabled ip-address=‘) in length. A ip value of length 0x3da will cause the service to crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4r8-4f4f-m9xf/GHSA-q4r8-4f4f-m9xf.json b/advisories/unreviewed/2022/05/GHSA-q4r8-4f4f-m9xf/GHSA-q4r8-4f4f-m9xf.json index b578a4780a3..e9c3517f10f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4r8-4f4f-m9xf/GHSA-q4r8-4f4f-m9xf.json +++ b/advisories/unreviewed/2022/05/GHSA-q4r8-4f4f-m9xf/GHSA-q4r8-4f4f-m9xf.json @@ -7,12 +7,8 @@ "CVE-2021-23856" ], "details": "The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q53r-vgvg-q6pj/GHSA-q53r-vgvg-q6pj.json b/advisories/unreviewed/2022/05/GHSA-q53r-vgvg-q6pj/GHSA-q53r-vgvg-q6pj.json index 42a864883ad..3507c0dd0e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q53r-vgvg-q6pj/GHSA-q53r-vgvg-q6pj.json +++ b/advisories/unreviewed/2022/05/GHSA-q53r-vgvg-q6pj/GHSA-q53r-vgvg-q6pj.json @@ -7,12 +7,8 @@ "CVE-2008-3608" ], "details": "ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q5r7-v53q-5pgx/GHSA-q5r7-v53q-5pgx.json b/advisories/unreviewed/2022/05/GHSA-q5r7-v53q-5pgx/GHSA-q5r7-v53q-5pgx.json index 8ab55b089d9..5ebe31742b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5r7-v53q-5pgx/GHSA-q5r7-v53q-5pgx.json +++ b/advisories/unreviewed/2022/05/GHSA-q5r7-v53q-5pgx/GHSA-q5r7-v53q-5pgx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6c8-7rvq-2f39/GHSA-q6c8-7rvq-2f39.json b/advisories/unreviewed/2022/05/GHSA-q6c8-7rvq-2f39/GHSA-q6c8-7rvq-2f39.json index 8c071d082a4..37c49237976 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6c8-7rvq-2f39/GHSA-q6c8-7rvq-2f39.json +++ b/advisories/unreviewed/2022/05/GHSA-q6c8-7rvq-2f39/GHSA-q6c8-7rvq-2f39.json @@ -7,12 +7,8 @@ "CVE-2008-3509" ], "details": "LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6fj-qvhw-x524/GHSA-q6fj-qvhw-x524.json b/advisories/unreviewed/2022/05/GHSA-q6fj-qvhw-x524/GHSA-q6fj-qvhw-x524.json index fa5cd47c4a4..d6a474346f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6fj-qvhw-x524/GHSA-q6fj-qvhw-x524.json +++ b/advisories/unreviewed/2022/05/GHSA-q6fj-qvhw-x524/GHSA-q6fj-qvhw-x524.json @@ -7,12 +7,8 @@ "CVE-2008-3189" ], "details": "SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6x3-834v-vr8w/GHSA-q6x3-834v-vr8w.json b/advisories/unreviewed/2022/05/GHSA-q6x3-834v-vr8w/GHSA-q6x3-834v-vr8w.json index cbb1e296d4f..1a5991ff141 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6x3-834v-vr8w/GHSA-q6x3-834v-vr8w.json +++ b/advisories/unreviewed/2022/05/GHSA-q6x3-834v-vr8w/GHSA-q6x3-834v-vr8w.json @@ -7,12 +7,8 @@ "CVE-2008-3240" ], "details": "SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via the pgm parameter in a directory action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7hp-2hjx-488x/GHSA-q7hp-2hjx-488x.json b/advisories/unreviewed/2022/05/GHSA-q7hp-2hjx-488x/GHSA-q7hp-2hjx-488x.json index dd58da7cfa9..541af34e6cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7hp-2hjx-488x/GHSA-q7hp-2hjx-488x.json +++ b/advisories/unreviewed/2022/05/GHSA-q7hp-2hjx-488x/GHSA-q7hp-2hjx-488x.json @@ -7,12 +7,8 @@ "CVE-2008-3398" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q868-27qj-xwfg/GHSA-q868-27qj-xwfg.json b/advisories/unreviewed/2022/05/GHSA-q868-27qj-xwfg/GHSA-q868-27qj-xwfg.json index 15d45cfa82a..f6afdcff4a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q868-27qj-xwfg/GHSA-q868-27qj-xwfg.json +++ b/advisories/unreviewed/2022/05/GHSA-q868-27qj-xwfg/GHSA-q868-27qj-xwfg.json @@ -7,12 +7,8 @@ "CVE-2008-3205" ], "details": "Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q88m-4hg8-4h3h/GHSA-q88m-4hg8-4h3h.json b/advisories/unreviewed/2022/05/GHSA-q88m-4hg8-4h3h/GHSA-q88m-4hg8-4h3h.json index d1af3c454ab..78203b7cdd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q88m-4hg8-4h3h/GHSA-q88m-4hg8-4h3h.json +++ b/advisories/unreviewed/2022/05/GHSA-q88m-4hg8-4h3h/GHSA-q88m-4hg8-4h3h.json @@ -7,12 +7,8 @@ "CVE-2020-26542" ], "details": "An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8v3-m5xx-vj46/GHSA-q8v3-m5xx-vj46.json b/advisories/unreviewed/2022/05/GHSA-q8v3-m5xx-vj46/GHSA-q8v3-m5xx-vj46.json index 8f1c822b521..7c36d7eff68 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8v3-m5xx-vj46/GHSA-q8v3-m5xx-vj46.json +++ b/advisories/unreviewed/2022/05/GHSA-q8v3-m5xx-vj46/GHSA-q8v3-m5xx-vj46.json @@ -7,12 +7,8 @@ "CVE-2021-28187" ], "details": "The specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q93p-853g-487m/GHSA-q93p-853g-487m.json b/advisories/unreviewed/2022/05/GHSA-q93p-853g-487m/GHSA-q93p-853g-487m.json index c460994ae49..3c36b2504d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q93p-853g-487m/GHSA-q93p-853g-487m.json +++ b/advisories/unreviewed/2022/05/GHSA-q93p-853g-487m/GHSA-q93p-853g-487m.json @@ -7,12 +7,8 @@ "CVE-2021-36063" ], "details": "Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9pr-j4ff-xm8w/GHSA-q9pr-j4ff-xm8w.json b/advisories/unreviewed/2022/05/GHSA-q9pr-j4ff-xm8w/GHSA-q9pr-j4ff-xm8w.json index 1a39efa1321..f7b8aca4e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9pr-j4ff-xm8w/GHSA-q9pr-j4ff-xm8w.json +++ b/advisories/unreviewed/2022/05/GHSA-q9pr-j4ff-xm8w/GHSA-q9pr-j4ff-xm8w.json @@ -7,12 +7,8 @@ "CVE-2020-9736" ], "details": "AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when browsing to the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9wh-phxj-rxf5/GHSA-q9wh-phxj-rxf5.json b/advisories/unreviewed/2022/05/GHSA-q9wh-phxj-rxf5/GHSA-q9wh-phxj-rxf5.json index 52922a5c136..5dc4426294e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9wh-phxj-rxf5/GHSA-q9wh-phxj-rxf5.json +++ b/advisories/unreviewed/2022/05/GHSA-q9wh-phxj-rxf5/GHSA-q9wh-phxj-rxf5.json @@ -7,12 +7,8 @@ "CVE-2008-3659" ], "details": "Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to the explode function. NOTE: the scope of this issue is limited since most applications would not use an attacker-controlled delimiter, but local attacks against safe_mode are feasible.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc5m-fq47-qgpw/GHSA-qc5m-fq47-qgpw.json b/advisories/unreviewed/2022/05/GHSA-qc5m-fq47-qgpw/GHSA-qc5m-fq47-qgpw.json index e50a915c0e3..120d1d1b067 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc5m-fq47-qgpw/GHSA-qc5m-fq47-qgpw.json +++ b/advisories/unreviewed/2022/05/GHSA-qc5m-fq47-qgpw/GHSA-qc5m-fq47-qgpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcwg-3qwr-7j8r/GHSA-qcwg-3qwr-7j8r.json b/advisories/unreviewed/2022/05/GHSA-qcwg-3qwr-7j8r/GHSA-qcwg-3qwr-7j8r.json index f0c066e5c9e..9d6dbc85285 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcwg-3qwr-7j8r/GHSA-qcwg-3qwr-7j8r.json +++ b/advisories/unreviewed/2022/05/GHSA-qcwg-3qwr-7j8r/GHSA-qcwg-3qwr-7j8r.json @@ -7,12 +7,8 @@ "CVE-2008-3561" ], "details": "SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf22-cr2w-g2fr/GHSA-qf22-cr2w-g2fr.json b/advisories/unreviewed/2022/05/GHSA-qf22-cr2w-g2fr/GHSA-qf22-cr2w-g2fr.json index 1638f426105..1a12315362b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf22-cr2w-g2fr/GHSA-qf22-cr2w-g2fr.json +++ b/advisories/unreviewed/2022/05/GHSA-qf22-cr2w-g2fr/GHSA-qf22-cr2w-g2fr.json @@ -7,12 +7,8 @@ "CVE-2008-3359" ], "details": "SQL injection vulnerability in register.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf3r-58m2-px2j/GHSA-qf3r-58m2-px2j.json b/advisories/unreviewed/2022/05/GHSA-qf3r-58m2-px2j/GHSA-qf3r-58m2-px2j.json index ca1caa967f4..763bfaae6e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf3r-58m2-px2j/GHSA-qf3r-58m2-px2j.json +++ b/advisories/unreviewed/2022/05/GHSA-qf3r-58m2-px2j/GHSA-qf3r-58m2-px2j.json @@ -7,12 +7,8 @@ "CVE-2008-3236" ], "details": "Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to \"previously encrypted properties\" that are not encrypted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qf52-pvgg-vmm3/GHSA-qf52-pvgg-vmm3.json b/advisories/unreviewed/2022/05/GHSA-qf52-pvgg-vmm3/GHSA-qf52-pvgg-vmm3.json index 5263abbf300..5fa87752e85 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf52-pvgg-vmm3/GHSA-qf52-pvgg-vmm3.json +++ b/advisories/unreviewed/2022/05/GHSA-qf52-pvgg-vmm3/GHSA-qf52-pvgg-vmm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf69-6pwp-9xjf/GHSA-qf69-6pwp-9xjf.json b/advisories/unreviewed/2022/05/GHSA-qf69-6pwp-9xjf/GHSA-qf69-6pwp-9xjf.json index 0872bb63284..0b79d6b90b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf69-6pwp-9xjf/GHSA-qf69-6pwp-9xjf.json +++ b/advisories/unreviewed/2022/05/GHSA-qf69-6pwp-9xjf/GHSA-qf69-6pwp-9xjf.json @@ -7,12 +7,8 @@ "CVE-2020-27258" ], "details": "In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pump’s keypad lock PIN via Bluetooth Low Energy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg88-7w37-mvw6/GHSA-qg88-7w37-mvw6.json b/advisories/unreviewed/2022/05/GHSA-qg88-7w37-mvw6/GHSA-qg88-7w37-mvw6.json index 18f6463f6ec..4bd492400a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg88-7w37-mvw6/GHSA-qg88-7w37-mvw6.json +++ b/advisories/unreviewed/2022/05/GHSA-qg88-7w37-mvw6/GHSA-qg88-7w37-mvw6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgc3-h8cc-6q8c/GHSA-qgc3-h8cc-6q8c.json b/advisories/unreviewed/2022/05/GHSA-qgc3-h8cc-6q8c/GHSA-qgc3-h8cc-6q8c.json index c7b5cb95cba..8eb1d3812a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgc3-h8cc-6q8c/GHSA-qgc3-h8cc-6q8c.json +++ b/advisories/unreviewed/2022/05/GHSA-qgc3-h8cc-6q8c/GHSA-qgc3-h8cc-6q8c.json @@ -7,12 +7,8 @@ "CVE-2008-3207" ], "details": "PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) sourceFolder or (2) moduleFolder parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qggj-r88p-xg6w/GHSA-qggj-r88p-xg6w.json b/advisories/unreviewed/2022/05/GHSA-qggj-r88p-xg6w/GHSA-qggj-r88p-xg6w.json index 77adc3b99da..158be9c2b47 100644 --- a/advisories/unreviewed/2022/05/GHSA-qggj-r88p-xg6w/GHSA-qggj-r88p-xg6w.json +++ b/advisories/unreviewed/2022/05/GHSA-qggj-r88p-xg6w/GHSA-qggj-r88p-xg6w.json @@ -7,12 +7,8 @@ "CVE-2008-3549" ], "details": "Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris before snv_90 allows local users to cause a denial of service (system hang or panic) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgpp-26ch-wf83/GHSA-qgpp-26ch-wf83.json b/advisories/unreviewed/2022/05/GHSA-qgpp-26ch-wf83/GHSA-qgpp-26ch-wf83.json index 8a77f42d53e..2131da35716 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgpp-26ch-wf83/GHSA-qgpp-26ch-wf83.json +++ b/advisories/unreviewed/2022/05/GHSA-qgpp-26ch-wf83/GHSA-qgpp-26ch-wf83.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgww-6vq6-rm44/GHSA-qgww-6vq6-rm44.json b/advisories/unreviewed/2022/05/GHSA-qgww-6vq6-rm44/GHSA-qgww-6vq6-rm44.json index f561a1c19fc..09747c36789 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgww-6vq6-rm44/GHSA-qgww-6vq6-rm44.json +++ b/advisories/unreviewed/2022/05/GHSA-qgww-6vq6-rm44/GHSA-qgww-6vq6-rm44.json @@ -7,12 +7,8 @@ "CVE-2021-25961" ], "details": "In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh44-665f-4v6g/GHSA-qh44-665f-4v6g.json b/advisories/unreviewed/2022/05/GHSA-qh44-665f-4v6g/GHSA-qh44-665f-4v6g.json index 168312d3ebc..19c34c2179b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh44-665f-4v6g/GHSA-qh44-665f-4v6g.json +++ b/advisories/unreviewed/2022/05/GHSA-qh44-665f-4v6g/GHSA-qh44-665f-4v6g.json @@ -7,12 +7,8 @@ "CVE-2021-24239" ], "details": "The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhjp-4vc3-896g/GHSA-qhjp-4vc3-896g.json b/advisories/unreviewed/2022/05/GHSA-qhjp-4vc3-896g/GHSA-qhjp-4vc3-896g.json index dc8d0d1dca1..2c89770eed8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhjp-4vc3-896g/GHSA-qhjp-4vc3-896g.json +++ b/advisories/unreviewed/2022/05/GHSA-qhjp-4vc3-896g/GHSA-qhjp-4vc3-896g.json @@ -7,12 +7,8 @@ "CVE-2020-8267" ], "details": "A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated messages without a valid token.This vulnerability was fixed in UniFi Protect v1.14.11 and newer.This issue does not impact UniFi Cloud Key Gen 2 plus.This issue does not impact UDM-Pro customers with UniFi Protect stopped.Affected Products:UDM-Pro firmware 1.7.2 and earlier.UNVR firmware 1.3.12 and earlier.Mitigation:Update UniFi Protect to v1.14.11 or newer version; the UniFi Protect controller can be updated through your UniFi OS settings.Alternatively, you can update UNVR and UDM-Pro to:- UNVR firmware to 1.3.15 or newer.- UDM-Pro firmware to 1.8.0 or newer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhvj-rhv2-v55x/GHSA-qhvj-rhv2-v55x.json b/advisories/unreviewed/2022/05/GHSA-qhvj-rhv2-v55x/GHSA-qhvj-rhv2-v55x.json index 25f18e84fe4..55376bd874a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhvj-rhv2-v55x/GHSA-qhvj-rhv2-v55x.json +++ b/advisories/unreviewed/2022/05/GHSA-qhvj-rhv2-v55x/GHSA-qhvj-rhv2-v55x.json @@ -7,12 +7,8 @@ "CVE-2008-3484" ], "details": "SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj86-hq7c-367x/GHSA-qj86-hq7c-367x.json b/advisories/unreviewed/2022/05/GHSA-qj86-hq7c-367x/GHSA-qj86-hq7c-367x.json index da4eb30b7e2..f493903a2c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj86-hq7c-367x/GHSA-qj86-hq7c-367x.json +++ b/advisories/unreviewed/2022/05/GHSA-qj86-hq7c-367x/GHSA-qj86-hq7c-367x.json @@ -7,12 +7,8 @@ "CVE-2008-3353" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Pure Software Lore before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) article comments feature and the (2) search log feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjq6-qxx8-cgh5/GHSA-qjq6-qxx8-cgh5.json b/advisories/unreviewed/2022/05/GHSA-qjq6-qxx8-cgh5/GHSA-qjq6-qxx8-cgh5.json index 2a711a051ef..13ff7a24495 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjq6-qxx8-cgh5/GHSA-qjq6-qxx8-cgh5.json +++ b/advisories/unreviewed/2022/05/GHSA-qjq6-qxx8-cgh5/GHSA-qjq6-qxx8-cgh5.json @@ -7,12 +7,8 @@ "CVE-2008-3211" ], "details": "Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm7m-32m9-v63x/GHSA-qm7m-32m9-v63x.json b/advisories/unreviewed/2022/05/GHSA-qm7m-32m9-v63x/GHSA-qm7m-32m9-v63x.json index d8f1113957c..0e83f5a0faa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm7m-32m9-v63x/GHSA-qm7m-32m9-v63x.json +++ b/advisories/unreviewed/2022/05/GHSA-qm7m-32m9-v63x/GHSA-qm7m-32m9-v63x.json @@ -7,12 +7,8 @@ "CVE-2008-3708" ], "details": "Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmc4-q85x-pjh3/GHSA-qmc4-q85x-pjh3.json b/advisories/unreviewed/2022/05/GHSA-qmc4-q85x-pjh3/GHSA-qmc4-q85x-pjh3.json index 4ec0478f3c3..c78083a34ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmc4-q85x-pjh3/GHSA-qmc4-q85x-pjh3.json +++ b/advisories/unreviewed/2022/05/GHSA-qmc4-q85x-pjh3/GHSA-qmc4-q85x-pjh3.json @@ -7,12 +7,8 @@ "CVE-2021-27458" ], "details": "If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions, PC10GE TCC-6464: All versions, PC10P TCC-6372: All versions, PC10P-DP TCC-6726: All versions, PC10P-DP-IO TCC-6752: All versions, PC10B-P TCC-6373: All versions, PC10B TCC-1021: All versions, PC10B-E/C TCU-6521: All versions, PC10E TCC-4737: All versions; TOYOPUC-Plus Series: Plus CPU TCC-6740: All versions, Plus EX TCU-6741: All versions, Plus EX2 TCU-6858: All versions, Plus EFR TCU-6743: All versions, Plus EFR2 TCU-6859: All versions, Plus 2P-EFR TCU-6929: All versions, Plus BUS-EX TCU-6900: All versions; TOYOPUC-PC3J/PC2J Series: FL/ET-T-V2H THU-6289: All versions, 2PORT-EFR THU-6404: All versions) are left in an open state by an attacker, Ethernet communications cannot be established with other devices, depending on the settings of the link parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp38-g7j8-6pgx/GHSA-qp38-g7j8-6pgx.json b/advisories/unreviewed/2022/05/GHSA-qp38-g7j8-6pgx/GHSA-qp38-g7j8-6pgx.json index bb1e1007dc2..c8a042f5b27 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp38-g7j8-6pgx/GHSA-qp38-g7j8-6pgx.json +++ b/advisories/unreviewed/2022/05/GHSA-qp38-g7j8-6pgx/GHSA-qp38-g7j8-6pgx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpjg-r2f6-r5rc/GHSA-qpjg-r2f6-r5rc.json b/advisories/unreviewed/2022/05/GHSA-qpjg-r2f6-r5rc/GHSA-qpjg-r2f6-r5rc.json index abcd457f8ab..58312f73505 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpjg-r2f6-r5rc/GHSA-qpjg-r2f6-r5rc.json +++ b/advisories/unreviewed/2022/05/GHSA-qpjg-r2f6-r5rc/GHSA-qpjg-r2f6-r5rc.json @@ -7,12 +7,8 @@ "CVE-2008-3194" ], "details": "Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) langpref, (2) file, (3) blogpost, or (4) cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqvj-f6m7-hm4p/GHSA-qqvj-f6m7-hm4p.json b/advisories/unreviewed/2022/05/GHSA-qqvj-f6m7-hm4p/GHSA-qqvj-f6m7-hm4p.json index 2233827d2a0..da16c26dfd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqvj-f6m7-hm4p/GHSA-qqvj-f6m7-hm4p.json +++ b/advisories/unreviewed/2022/05/GHSA-qqvj-f6m7-hm4p/GHSA-qqvj-f6m7-hm4p.json @@ -7,12 +7,8 @@ "CVE-2008-3603" ], "details": "SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqwr-jcm9-xc3r/GHSA-qqwr-jcm9-xc3r.json b/advisories/unreviewed/2022/05/GHSA-qqwr-jcm9-xc3r/GHSA-qqwr-jcm9-xc3r.json index 38ae4bfd324..43795dcddae 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqwr-jcm9-xc3r/GHSA-qqwr-jcm9-xc3r.json +++ b/advisories/unreviewed/2022/05/GHSA-qqwr-jcm9-xc3r/GHSA-qqwr-jcm9-xc3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr55-25g7-85f9/GHSA-qr55-25g7-85f9.json b/advisories/unreviewed/2022/05/GHSA-qr55-25g7-85f9/GHSA-qr55-25g7-85f9.json index e88a301f00f..1a0036c6111 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr55-25g7-85f9/GHSA-qr55-25g7-85f9.json +++ b/advisories/unreviewed/2022/05/GHSA-qr55-25g7-85f9/GHSA-qr55-25g7-85f9.json @@ -7,12 +7,8 @@ "CVE-2008-3450" ], "details": "Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrfc-7f76-5vvg/GHSA-qrfc-7f76-5vvg.json b/advisories/unreviewed/2022/05/GHSA-qrfc-7f76-5vvg/GHSA-qrfc-7f76-5vvg.json index 69428e2469f..aa6b2cc05da 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrfc-7f76-5vvg/GHSA-qrfc-7f76-5vvg.json +++ b/advisories/unreviewed/2022/05/GHSA-qrfc-7f76-5vvg/GHSA-qrfc-7f76-5vvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrv7-h49g-2qfw/GHSA-qrv7-h49g-2qfw.json b/advisories/unreviewed/2022/05/GHSA-qrv7-h49g-2qfw/GHSA-qrv7-h49g-2qfw.json index 515c409fa9e..f64600e0391 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrv7-h49g-2qfw/GHSA-qrv7-h49g-2qfw.json +++ b/advisories/unreviewed/2022/05/GHSA-qrv7-h49g-2qfw/GHSA-qrv7-h49g-2qfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvcw-5pgw-6rvg/GHSA-qvcw-5pgw-6rvg.json b/advisories/unreviewed/2022/05/GHSA-qvcw-5pgw-6rvg/GHSA-qvcw-5pgw-6rvg.json index 5af0c1e1273..f22dbf35937 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvcw-5pgw-6rvg/GHSA-qvcw-5pgw-6rvg.json +++ b/advisories/unreviewed/2022/05/GHSA-qvcw-5pgw-6rvg/GHSA-qvcw-5pgw-6rvg.json @@ -7,12 +7,8 @@ "CVE-2008-3403" ], "details": "SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvqj-pfj9-vcvw/GHSA-qvqj-pfj9-vcvw.json b/advisories/unreviewed/2022/05/GHSA-qvqj-pfj9-vcvw/GHSA-qvqj-pfj9-vcvw.json index df44509c2f4..a8617c4f199 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvqj-pfj9-vcvw/GHSA-qvqj-pfj9-vcvw.json +++ b/advisories/unreviewed/2022/05/GHSA-qvqj-pfj9-vcvw/GHSA-qvqj-pfj9-vcvw.json @@ -7,12 +7,8 @@ "CVE-2008-3222" ], "details": "Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules \"terminate the current request during a login event,\" allows remote attackers to hijack web sessions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvw2-2c73-2479/GHSA-qvw2-2c73-2479.json b/advisories/unreviewed/2022/05/GHSA-qvw2-2c73-2479/GHSA-qvw2-2c73-2479.json index df18f53c776..9fe12044793 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvw2-2c73-2479/GHSA-qvw2-2c73-2479.json +++ b/advisories/unreviewed/2022/05/GHSA-qvw2-2c73-2479/GHSA-qvw2-2c73-2479.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvx9-76f4-5j3g/GHSA-qvx9-76f4-5j3g.json b/advisories/unreviewed/2022/05/GHSA-qvx9-76f4-5j3g/GHSA-qvx9-76f4-5j3g.json index b3773977298..48dc9cfce16 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvx9-76f4-5j3g/GHSA-qvx9-76f4-5j3g.json +++ b/advisories/unreviewed/2022/05/GHSA-qvx9-76f4-5j3g/GHSA-qvx9-76f4-5j3g.json @@ -7,12 +7,8 @@ "CVE-2008-3616" ], "details": "Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with \"passing untrusted input\" to unspecified API functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw29-755q-4qgp/GHSA-qw29-755q-4qgp.json b/advisories/unreviewed/2022/05/GHSA-qw29-755q-4qgp/GHSA-qw29-755q-4qgp.json index e4f62aae75f..50232dc53cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw29-755q-4qgp/GHSA-qw29-755q-4qgp.json +++ b/advisories/unreviewed/2022/05/GHSA-qw29-755q-4qgp/GHSA-qw29-755q-4qgp.json @@ -7,12 +7,8 @@ "CVE-2020-8339" ], "details": "A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web site, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the malicious web site. Impact is limited to the normal access restrictions of the user visiting the malicious web site, and subject to the user being logged into AMM, being able to connect to both AMM and the malicious web site while the web browser is open, and using a web browser that does not inherently protect against this class of attack. The JavaScript code is not executed on AMM itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw59-fpqw-7hq5/GHSA-qw59-fpqw-7hq5.json b/advisories/unreviewed/2022/05/GHSA-qw59-fpqw-7hq5/GHSA-qw59-fpqw-7hq5.json index 9a8f1f1070d..9bc10c9fcc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw59-fpqw-7hq5/GHSA-qw59-fpqw-7hq5.json +++ b/advisories/unreviewed/2022/05/GHSA-qw59-fpqw-7hq5/GHSA-qw59-fpqw-7hq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw63-6f9r-7c24/GHSA-qw63-6f9r-7c24.json b/advisories/unreviewed/2022/05/GHSA-qw63-6f9r-7c24/GHSA-qw63-6f9r-7c24.json index ce37f71f076..9dd59ce6822 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw63-6f9r-7c24/GHSA-qw63-6f9r-7c24.json +++ b/advisories/unreviewed/2022/05/GHSA-qw63-6f9r-7c24/GHSA-qw63-6f9r-7c24.json @@ -7,12 +7,8 @@ "CVE-2008-3779" ], "details": "Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw7g-m46h-fcxw/GHSA-qw7g-m46h-fcxw.json b/advisories/unreviewed/2022/05/GHSA-qw7g-m46h-fcxw/GHSA-qw7g-m46h-fcxw.json index c3c60e09572..0e480a723e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw7g-m46h-fcxw/GHSA-qw7g-m46h-fcxw.json +++ b/advisories/unreviewed/2022/05/GHSA-qw7g-m46h-fcxw/GHSA-qw7g-m46h-fcxw.json @@ -7,12 +7,8 @@ "CVE-2008-3698" ], "details": "Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 on Windows allows local host OS users to gain privileges on the host OS via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwwv-cv7g-wc9x/GHSA-qwwv-cv7g-wc9x.json b/advisories/unreviewed/2022/05/GHSA-qwwv-cv7g-wc9x/GHSA-qwwv-cv7g-wc9x.json index 497dbc9c5f4..544d18d0c41 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwwv-cv7g-wc9x/GHSA-qwwv-cv7g-wc9x.json +++ b/advisories/unreviewed/2022/05/GHSA-qwwv-cv7g-wc9x/GHSA-qwwv-cv7g-wc9x.json @@ -7,12 +7,8 @@ "CVE-2008-3562" ], "details": "Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mods parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxj4-46g2-7rv9/GHSA-qxj4-46g2-7rv9.json b/advisories/unreviewed/2022/05/GHSA-qxj4-46g2-7rv9/GHSA-qxj4-46g2-7rv9.json index 2447ff5b2a8..216f81a8edb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxj4-46g2-7rv9/GHSA-qxj4-46g2-7rv9.json +++ b/advisories/unreviewed/2022/05/GHSA-qxj4-46g2-7rv9/GHSA-qxj4-46g2-7rv9.json @@ -7,12 +7,8 @@ "CVE-2019-11292" ], "details": "Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxrp-frj5-r7g8/GHSA-qxrp-frj5-r7g8.json b/advisories/unreviewed/2022/05/GHSA-qxrp-frj5-r7g8/GHSA-qxrp-frj5-r7g8.json index 83e2b472751..c8d44b0e9a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxrp-frj5-r7g8/GHSA-qxrp-frj5-r7g8.json +++ b/advisories/unreviewed/2022/05/GHSA-qxrp-frj5-r7g8/GHSA-qxrp-frj5-r7g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r24c-62mq-w8vq/GHSA-r24c-62mq-w8vq.json b/advisories/unreviewed/2022/05/GHSA-r24c-62mq-w8vq/GHSA-r24c-62mq-w8vq.json index 05defcbfd33..7cba4790d89 100644 --- a/advisories/unreviewed/2022/05/GHSA-r24c-62mq-w8vq/GHSA-r24c-62mq-w8vq.json +++ b/advisories/unreviewed/2022/05/GHSA-r24c-62mq-w8vq/GHSA-r24c-62mq-w8vq.json @@ -7,12 +7,8 @@ "CVE-2021-28178" ], "details": "The UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2jp-926f-m5r3/GHSA-r2jp-926f-m5r3.json b/advisories/unreviewed/2022/05/GHSA-r2jp-926f-m5r3/GHSA-r2jp-926f-m5r3.json index 51732b26947..921ccc4a6a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2jp-926f-m5r3/GHSA-r2jp-926f-m5r3.json +++ b/advisories/unreviewed/2022/05/GHSA-r2jp-926f-m5r3/GHSA-r2jp-926f-m5r3.json @@ -7,12 +7,8 @@ "CVE-2021-24257" ], "details": "The “Premium Addons for Elementorâ€? WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2jr-v83g-c59g/GHSA-r2jr-v83g-c59g.json b/advisories/unreviewed/2022/05/GHSA-r2jr-v83g-c59g/GHSA-r2jr-v83g-c59g.json index eef4773c6ec..c7d31ce4bc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2jr-v83g-c59g/GHSA-r2jr-v83g-c59g.json +++ b/advisories/unreviewed/2022/05/GHSA-r2jr-v83g-c59g/GHSA-r2jr-v83g-c59g.json @@ -7,12 +7,8 @@ "CVE-2019-5181" ], "details": "An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in code execution. An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination buffer sp+0x440 is overflowed with the call to sprintf() for any subnetmask values that are greater than 1024-len(‘/etc/config-tools/config_interfaces interface=X1 state=enabled subnet-mask=‘) in length. A subnetmask value of length 0x3d9 will cause the service to crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2q3-fwwf-666h/GHSA-r2q3-fwwf-666h.json b/advisories/unreviewed/2022/05/GHSA-r2q3-fwwf-666h/GHSA-r2q3-fwwf-666h.json index 57cddc2e5e3..1f717781ad1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2q3-fwwf-666h/GHSA-r2q3-fwwf-666h.json +++ b/advisories/unreviewed/2022/05/GHSA-r2q3-fwwf-666h/GHSA-r2q3-fwwf-666h.json @@ -7,12 +7,8 @@ "CVE-2008-3421" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4f6-vjwc-9238/GHSA-r4f6-vjwc-9238.json b/advisories/unreviewed/2022/05/GHSA-r4f6-vjwc-9238/GHSA-r4f6-vjwc-9238.json index 6c5ae45a0b4..245a236fb84 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4f6-vjwc-9238/GHSA-r4f6-vjwc-9238.json +++ b/advisories/unreviewed/2022/05/GHSA-r4f6-vjwc-9238/GHSA-r4f6-vjwc-9238.json @@ -7,12 +7,8 @@ "CVE-2008-3646" ], "details": "The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4mj-qp8w-wrv9/GHSA-r4mj-qp8w-wrv9.json b/advisories/unreviewed/2022/05/GHSA-r4mj-qp8w-wrv9/GHSA-r4mj-qp8w-wrv9.json index 58ea8996873..4f98c3ba074 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4mj-qp8w-wrv9/GHSA-r4mj-qp8w-wrv9.json +++ b/advisories/unreviewed/2022/05/GHSA-r4mj-qp8w-wrv9/GHSA-r4mj-qp8w-wrv9.json @@ -7,12 +7,8 @@ "CVE-2020-15593" ], "details": "SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC (Inter-Process Communication) primitives to enable the processes to cooperate. Any user in the system is allowed to access the interprocess communication channel AternityAgentAssistantIpc, retrieve a serialized object and call object methods remotely. Among others, the methods allow any user to: (1) Create and/or overwrite arbitrary XML files across the system; (2) Create arbitrary directories across the system; and (3) Load arbitrary plugins (i.e., C# assemblies) from the \"%PROGRAMFILES(X86)/Aternity Information Systems/Assistant/plugins” directory and execute code contained in them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r56h-5pmr-hfmv/GHSA-r56h-5pmr-hfmv.json b/advisories/unreviewed/2022/05/GHSA-r56h-5pmr-hfmv/GHSA-r56h-5pmr-hfmv.json index 9ba9c3145c6..79d28bc0322 100644 --- a/advisories/unreviewed/2022/05/GHSA-r56h-5pmr-hfmv/GHSA-r56h-5pmr-hfmv.json +++ b/advisories/unreviewed/2022/05/GHSA-r56h-5pmr-hfmv/GHSA-r56h-5pmr-hfmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r56q-wqp9-hrw3/GHSA-r56q-wqp9-hrw3.json b/advisories/unreviewed/2022/05/GHSA-r56q-wqp9-hrw3/GHSA-r56q-wqp9-hrw3.json index ea519537f33..08205cf83c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r56q-wqp9-hrw3/GHSA-r56q-wqp9-hrw3.json +++ b/advisories/unreviewed/2022/05/GHSA-r56q-wqp9-hrw3/GHSA-r56q-wqp9-hrw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r592-jw3g-mc38/GHSA-r592-jw3g-mc38.json b/advisories/unreviewed/2022/05/GHSA-r592-jw3g-mc38/GHSA-r592-jw3g-mc38.json index ab956eea56d..d5207063a23 100644 --- a/advisories/unreviewed/2022/05/GHSA-r592-jw3g-mc38/GHSA-r592-jw3g-mc38.json +++ b/advisories/unreviewed/2022/05/GHSA-r592-jw3g-mc38/GHSA-r592-jw3g-mc38.json @@ -7,12 +7,8 @@ "CVE-2008-3232" ], "details": "Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r597-j6c4-p5w2/GHSA-r597-j6c4-p5w2.json b/advisories/unreviewed/2022/05/GHSA-r597-j6c4-p5w2/GHSA-r597-j6c4-p5w2.json index 1471ef20f7b..d16467e32e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r597-j6c4-p5w2/GHSA-r597-j6c4-p5w2.json +++ b/advisories/unreviewed/2022/05/GHSA-r597-j6c4-p5w2/GHSA-r597-j6c4-p5w2.json @@ -7,12 +7,8 @@ "CVE-2020-6873" ], "details": "A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets with valid http links, the remote attackers could use this vulnerability to cause the equipment WEB/TELNET module denial of service and make the equipment be out of management. This affects: ZXR10 2800-4_ALMPUFB(LOW), all versions up to V3.00.40.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5ph-39cp-8mh6/GHSA-r5ph-39cp-8mh6.json b/advisories/unreviewed/2022/05/GHSA-r5ph-39cp-8mh6/GHSA-r5ph-39cp-8mh6.json index 47cea1f27ce..8ac984e87a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5ph-39cp-8mh6/GHSA-r5ph-39cp-8mh6.json +++ b/advisories/unreviewed/2022/05/GHSA-r5ph-39cp-8mh6/GHSA-r5ph-39cp-8mh6.json @@ -7,12 +7,8 @@ "CVE-2008-3585" ], "details": "Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5ph-fc45-cwp3/GHSA-r5ph-fc45-cwp3.json b/advisories/unreviewed/2022/05/GHSA-r5ph-fc45-cwp3/GHSA-r5ph-fc45-cwp3.json index 8e4cf7df0d8..3d0bafc80e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5ph-fc45-cwp3/GHSA-r5ph-fc45-cwp3.json +++ b/advisories/unreviewed/2022/05/GHSA-r5ph-fc45-cwp3/GHSA-r5ph-fc45-cwp3.json @@ -7,12 +7,8 @@ "CVE-2020-20183" ], "details": "Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6jx-rmgv-6hrh/GHSA-r6jx-rmgv-6hrh.json b/advisories/unreviewed/2022/05/GHSA-r6jx-rmgv-6hrh/GHSA-r6jx-rmgv-6hrh.json index a3a24a834d1..6c1246d8695 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6jx-rmgv-6hrh/GHSA-r6jx-rmgv-6hrh.json +++ b/advisories/unreviewed/2022/05/GHSA-r6jx-rmgv-6hrh/GHSA-r6jx-rmgv-6hrh.json @@ -7,12 +7,8 @@ "CVE-2021-26968" ], "details": "A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6r6-6fwh-w3v4/GHSA-r6r6-6fwh-w3v4.json b/advisories/unreviewed/2022/05/GHSA-r6r6-6fwh-w3v4/GHSA-r6r6-6fwh-w3v4.json index 4d48fbaa2ce..b4c9eedca16 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6r6-6fwh-w3v4/GHSA-r6r6-6fwh-w3v4.json +++ b/advisories/unreviewed/2022/05/GHSA-r6r6-6fwh-w3v4/GHSA-r6r6-6fwh-w3v4.json @@ -7,12 +7,8 @@ "CVE-2008-3706" ], "details": "SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6wq-vrxj-qwhf/GHSA-r6wq-vrxj-qwhf.json b/advisories/unreviewed/2022/05/GHSA-r6wq-vrxj-qwhf/GHSA-r6wq-vrxj-qwhf.json index 79744783525..36ccdf02253 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6wq-vrxj-qwhf/GHSA-r6wq-vrxj-qwhf.json +++ b/advisories/unreviewed/2022/05/GHSA-r6wq-vrxj-qwhf/GHSA-r6wq-vrxj-qwhf.json @@ -7,12 +7,8 @@ "CVE-2008-3301" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow remote attackers to inject arbitrary web script or HTML via the (2) titleId parameter to head.php, reachable through index.php; the (3) t_lang[lang_copyright] parameter to footer.php; the (4) content parameter to the default URI under admin/; the (5) url, (6) t_lang[lang_admin_help], (7) t_lang[lang_admin_clear_cache], (8) t_lang[lang_admin_home], and (9) t_lang[lang_admin_logout] parameters to admin/homelink.php; and the (10) t_lang[lang_admin_new_post] parameter to admin/post.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r79h-cpp7-jww6/GHSA-r79h-cpp7-jww6.json b/advisories/unreviewed/2022/05/GHSA-r79h-cpp7-jww6/GHSA-r79h-cpp7-jww6.json index 4371948d510..2e2f2982916 100644 --- a/advisories/unreviewed/2022/05/GHSA-r79h-cpp7-jww6/GHSA-r79h-cpp7-jww6.json +++ b/advisories/unreviewed/2022/05/GHSA-r79h-cpp7-jww6/GHSA-r79h-cpp7-jww6.json @@ -7,12 +7,8 @@ "CVE-2008-3795" ], "details": "Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long \"message response.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7g7-rfqf-6fx5/GHSA-r7g7-rfqf-6fx5.json b/advisories/unreviewed/2022/05/GHSA-r7g7-rfqf-6fx5/GHSA-r7g7-rfqf-6fx5.json index da7007fc324..855cbc7cb3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7g7-rfqf-6fx5/GHSA-r7g7-rfqf-6fx5.json +++ b/advisories/unreviewed/2022/05/GHSA-r7g7-rfqf-6fx5/GHSA-r7g7-rfqf-6fx5.json @@ -7,12 +7,8 @@ "CVE-2021-24267" ], "details": "The “All-in-One Addons for Elementor – WidgetKitâ€? WordPress Plugin before 2.3.10 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7qg-49m3-m675/GHSA-r7qg-49m3-m675.json b/advisories/unreviewed/2022/05/GHSA-r7qg-49m3-m675/GHSA-r7qg-49m3-m675.json index 59470fb86d5..547a5192e2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7qg-49m3-m675/GHSA-r7qg-49m3-m675.json +++ b/advisories/unreviewed/2022/05/GHSA-r7qg-49m3-m675/GHSA-r7qg-49m3-m675.json @@ -7,12 +7,8 @@ "CVE-2008-3331" ], "details": "Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8gq-4fh4-57x5/GHSA-r8gq-4fh4-57x5.json b/advisories/unreviewed/2022/05/GHSA-r8gq-4fh4-57x5/GHSA-r8gq-4fh4-57x5.json index 7dc9ea08b99..76622b2d8f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8gq-4fh4-57x5/GHSA-r8gq-4fh4-57x5.json +++ b/advisories/unreviewed/2022/05/GHSA-r8gq-4fh4-57x5/GHSA-r8gq-4fh4-57x5.json @@ -7,12 +7,8 @@ "CVE-2008-3627" ], "details": "Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within QuickTimeH264.qtx, (2) MDAT atoms in mov video files within QuickTimeH264.scalar, and (3) AVC1 atoms in an unknown media type within an unspecified component, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a crafted, H.264 encoded movie file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r8hm-w595-qcj4/GHSA-r8hm-w595-qcj4.json b/advisories/unreviewed/2022/05/GHSA-r8hm-w595-qcj4/GHSA-r8hm-w595-qcj4.json index d549d564b11..6e36751a33f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8hm-w595-qcj4/GHSA-r8hm-w595-qcj4.json +++ b/advisories/unreviewed/2022/05/GHSA-r8hm-w595-qcj4/GHSA-r8hm-w595-qcj4.json @@ -7,12 +7,8 @@ "CVE-2008-3503" ], "details": "RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8v5-438w-jr88/GHSA-r8v5-438w-jr88.json b/advisories/unreviewed/2022/05/GHSA-r8v5-438w-jr88/GHSA-r8v5-438w-jr88.json index 8eed9083754..8f2b86e8925 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8v5-438w-jr88/GHSA-r8v5-438w-jr88.json +++ b/advisories/unreviewed/2022/05/GHSA-r8v5-438w-jr88/GHSA-r8v5-438w-jr88.json @@ -7,12 +7,8 @@ "CVE-2008-3570" ], "details": "PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r93x-j3p7-8448/GHSA-r93x-j3p7-8448.json b/advisories/unreviewed/2022/05/GHSA-r93x-j3p7-8448/GHSA-r93x-j3p7-8448.json index 50fb3941406..0d7c867d792 100644 --- a/advisories/unreviewed/2022/05/GHSA-r93x-j3p7-8448/GHSA-r93x-j3p7-8448.json +++ b/advisories/unreviewed/2022/05/GHSA-r93x-j3p7-8448/GHSA-r93x-j3p7-8448.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r96q-g7h3-3292/GHSA-r96q-g7h3-3292.json b/advisories/unreviewed/2022/05/GHSA-r96q-g7h3-3292/GHSA-r96q-g7h3-3292.json index eaa5a0cc94f..c2954643601 100644 --- a/advisories/unreviewed/2022/05/GHSA-r96q-g7h3-3292/GHSA-r96q-g7h3-3292.json +++ b/advisories/unreviewed/2022/05/GHSA-r96q-g7h3-3292/GHSA-r96q-g7h3-3292.json @@ -7,12 +7,8 @@ "CVE-2008-3453" ], "details": "Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and \"a few files.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9fr-v6w6-3r8x/GHSA-r9fr-v6w6-3r8x.json b/advisories/unreviewed/2022/05/GHSA-r9fr-v6w6-3r8x/GHSA-r9fr-v6w6-3r8x.json index fc99070fb9a..d736dc97dda 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9fr-v6w6-3r8x/GHSA-r9fr-v6w6-3r8x.json +++ b/advisories/unreviewed/2022/05/GHSA-r9fr-v6w6-3r8x/GHSA-r9fr-v6w6-3r8x.json @@ -7,12 +7,8 @@ "CVE-2021-24167" ], "details": "When visiting a site running Web-Stat < 1.4.0, the \"wts_web_stat_load_init\" function used the visitor’s browser to send an XMLHttpRequest request to https://wts2.one/ajax.htm?action=lookup_WP_account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9hv-2pq4-hp84/GHSA-r9hv-2pq4-hp84.json b/advisories/unreviewed/2022/05/GHSA-r9hv-2pq4-hp84/GHSA-r9hv-2pq4-hp84.json index 14802aa99ff..117fa50a49a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9hv-2pq4-hp84/GHSA-r9hv-2pq4-hp84.json +++ b/advisories/unreviewed/2022/05/GHSA-r9hv-2pq4-hp84/GHSA-r9hv-2pq4-hp84.json @@ -7,12 +7,8 @@ "CVE-2008-3719" ], "details": "SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc27-7vgm-6rx5/GHSA-rc27-7vgm-6rx5.json b/advisories/unreviewed/2022/05/GHSA-rc27-7vgm-6rx5/GHSA-rc27-7vgm-6rx5.json index 4596ea84195..c16845cdb46 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc27-7vgm-6rx5/GHSA-rc27-7vgm-6rx5.json +++ b/advisories/unreviewed/2022/05/GHSA-rc27-7vgm-6rx5/GHSA-rc27-7vgm-6rx5.json @@ -7,12 +7,8 @@ "CVE-2008-3707" ], "details": "Multiple PHP remote file inclusion vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to execute arbitrary PHP code via a URL in the script_path parameter to (1) flat_read.php, (2) post.php, (3) process_post.php, (4) process_search.php, (5) forum.php, (6) process_subscribe.php, (7) read.php, (8) search.php, (9) subscribe.php in path/; and (10) add_ban.php, (11) add_ban_form.php, (12) add_board.php, (13) add_vip.php, (14) add_vip_form.php, (15) copy_ban.php, (16) copy_vip.php, (17) delete_ban.php, (18) delete_board.php, (19) delete_messages.php, (20) delete_vip.php, (21) edit_ban.php, (22) edit_board.php, (23) edit_vip.php, (24) index.php, (25) lock_messages.php, (26) login.php, (27) modify_ban_list.php, (28) modify_vip_list.php, (29) move_messages.php, (30) process_add_board.php, (31) process_ban.php, (32) process_delete_ban.php, (33) process_delete_board.php, (34) process_delete_messages.php, (35) process_delete_vip.php, (36) process_edit_board.php, (37) process_lock_messages.php, (38) process_login.php, (39) process_move_messages.php, (40) process_sticky_messages.php, (41) process_vip.php, and (42) sticky_messages.php in path/adminopts. NOTE: the include/common.php vector is covered by CVE-2006-2871. NOTE: some of these vectors might not be vulnerabilities under proper installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfjv-xp4p-p62x/GHSA-rfjv-xp4p-p62x.json b/advisories/unreviewed/2022/05/GHSA-rfjv-xp4p-p62x/GHSA-rfjv-xp4p-p62x.json index cf2e5eca4cd..7bf81e1e302 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfjv-xp4p-p62x/GHSA-rfjv-xp4p-p62x.json +++ b/advisories/unreviewed/2022/05/GHSA-rfjv-xp4p-p62x/GHSA-rfjv-xp4p-p62x.json @@ -7,12 +7,8 @@ "CVE-2008-3306" ], "details": "SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3307. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg87-qff6-85m5/GHSA-rg87-qff6-85m5.json b/advisories/unreviewed/2022/05/GHSA-rg87-qff6-85m5/GHSA-rg87-qff6-85m5.json index f3e14938354..22409bf5bfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg87-qff6-85m5/GHSA-rg87-qff6-85m5.json +++ b/advisories/unreviewed/2022/05/GHSA-rg87-qff6-85m5/GHSA-rg87-qff6-85m5.json @@ -7,12 +7,8 @@ "CVE-2008-3238" ], "details": "Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id parameter in sellers_othersitem.php, (2) the productid parameter in classifieds.php, and (3) the id parameter in shop.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg96-g93m-wq4r/GHSA-rg96-g93m-wq4r.json b/advisories/unreviewed/2022/05/GHSA-rg96-g93m-wq4r/GHSA-rg96-g93m-wq4r.json index 1d740122049..88229438ca8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg96-g93m-wq4r/GHSA-rg96-g93m-wq4r.json +++ b/advisories/unreviewed/2022/05/GHSA-rg96-g93m-wq4r/GHSA-rg96-g93m-wq4r.json @@ -7,12 +7,8 @@ "CVE-2021-28197" ], "details": "The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhf6-xfw9-38h3/GHSA-rhf6-xfw9-38h3.json b/advisories/unreviewed/2022/05/GHSA-rhf6-xfw9-38h3/GHSA-rhf6-xfw9-38h3.json index d8a98c0e49a..4fcf0e95962 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhf6-xfw9-38h3/GHSA-rhf6-xfw9-38h3.json +++ b/advisories/unreviewed/2022/05/GHSA-rhf6-xfw9-38h3/GHSA-rhf6-xfw9-38h3.json @@ -7,12 +7,8 @@ "CVE-2020-5646" ], "details": "NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QMBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QLBDE CoreOS version ’05.65.00.BD’ and earlier, GT1455HS-QTBDE CoreOS version ’05.65.00.BD’ and earlier, and GT1450HS-QMBDE CoreOS version ’05.65.00.BD’ and earlier) allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhw5-h3r5-p5x5/GHSA-rhw5-h3r5-p5x5.json b/advisories/unreviewed/2022/05/GHSA-rhw5-h3r5-p5x5/GHSA-rhw5-h3r5-p5x5.json index 2fe56785e2a..e9ae8ec31cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhw5-h3r5-p5x5/GHSA-rhw5-h3r5-p5x5.json +++ b/advisories/unreviewed/2022/05/GHSA-rhw5-h3r5-p5x5/GHSA-rhw5-h3r5-p5x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj9p-mrcp-3f7h/GHSA-rj9p-mrcp-3f7h.json b/advisories/unreviewed/2022/05/GHSA-rj9p-mrcp-3f7h/GHSA-rj9p-mrcp-3f7h.json index 91e0dae4d20..b9a50ae61ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj9p-mrcp-3f7h/GHSA-rj9p-mrcp-3f7h.json +++ b/advisories/unreviewed/2022/05/GHSA-rj9p-mrcp-3f7h/GHSA-rj9p-mrcp-3f7h.json @@ -7,12 +7,8 @@ "CVE-2008-3337" ], "details": "PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjf7-p8p7-9xg5/GHSA-rjf7-p8p7-9xg5.json b/advisories/unreviewed/2022/05/GHSA-rjf7-p8p7-9xg5/GHSA-rjf7-p8p7-9xg5.json index e7c4a5ad5b6..343f00052ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjf7-p8p7-9xg5/GHSA-rjf7-p8p7-9xg5.json +++ b/advisories/unreviewed/2022/05/GHSA-rjf7-p8p7-9xg5/GHSA-rjf7-p8p7-9xg5.json @@ -7,12 +7,8 @@ "CVE-2008-3348" ], "details": "Cross-site scripting (XSS) vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the year parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjhm-x289-737r/GHSA-rjhm-x289-737r.json b/advisories/unreviewed/2022/05/GHSA-rjhm-x289-737r/GHSA-rjhm-x289-737r.json index a89a2ec0498..fb8f3010c8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjhm-x289-737r/GHSA-rjhm-x289-737r.json +++ b/advisories/unreviewed/2022/05/GHSA-rjhm-x289-737r/GHSA-rjhm-x289-737r.json @@ -7,12 +7,8 @@ "CVE-2008-3650" ], "details": "Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to \"unescaped output,\" possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjpg-gjcq-25gr/GHSA-rjpg-gjcq-25gr.json b/advisories/unreviewed/2022/05/GHSA-rjpg-gjcq-25gr/GHSA-rjpg-gjcq-25gr.json index a3e46716fe7..a5a5e2942d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjpg-gjcq-25gr/GHSA-rjpg-gjcq-25gr.json +++ b/advisories/unreviewed/2022/05/GHSA-rjpg-gjcq-25gr/GHSA-rjpg-gjcq-25gr.json @@ -7,12 +7,8 @@ "CVE-2008-3798" ], "details": "Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of an SSL session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm2v-88qc-6qxq/GHSA-rm2v-88qc-6qxq.json b/advisories/unreviewed/2022/05/GHSA-rm2v-88qc-6qxq/GHSA-rm2v-88qc-6qxq.json index 7a22871c331..673dcc35913 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm2v-88qc-6qxq/GHSA-rm2v-88qc-6qxq.json +++ b/advisories/unreviewed/2022/05/GHSA-rm2v-88qc-6qxq/GHSA-rm2v-88qc-6qxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rm36-68wg-f77p/GHSA-rm36-68wg-f77p.json b/advisories/unreviewed/2022/05/GHSA-rm36-68wg-f77p/GHSA-rm36-68wg-f77p.json index c3b73806a37..f4c0cfba109 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm36-68wg-f77p/GHSA-rm36-68wg-f77p.json +++ b/advisories/unreviewed/2022/05/GHSA-rm36-68wg-f77p/GHSA-rm36-68wg-f77p.json @@ -7,12 +7,8 @@ "CVE-2008-3399" ], "details": "PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmqr-ppqj-pp99/GHSA-rmqr-ppqj-pp99.json b/advisories/unreviewed/2022/05/GHSA-rmqr-ppqj-pp99/GHSA-rmqr-ppqj-pp99.json index f34e2db0a45..4e33d758be4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmqr-ppqj-pp99/GHSA-rmqr-ppqj-pp99.json +++ b/advisories/unreviewed/2022/05/GHSA-rmqr-ppqj-pp99/GHSA-rmqr-ppqj-pp99.json @@ -7,12 +7,8 @@ "CVE-2008-3578" ], "details": "HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpc4-j6wc-g7m7/GHSA-rpc4-j6wc-g7m7.json b/advisories/unreviewed/2022/05/GHSA-rpc4-j6wc-g7m7/GHSA-rpc4-j6wc-g7m7.json index 78f21b8fac2..579e60b959d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpc4-j6wc-g7m7/GHSA-rpc4-j6wc-g7m7.json +++ b/advisories/unreviewed/2022/05/GHSA-rpc4-j6wc-g7m7/GHSA-rpc4-j6wc-g7m7.json @@ -7,12 +7,8 @@ "CVE-2008-3768" ], "details": "Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpg7-hqjg-pxxj/GHSA-rpg7-hqjg-pxxj.json b/advisories/unreviewed/2022/05/GHSA-rpg7-hqjg-pxxj/GHSA-rpg7-hqjg-pxxj.json index ca65cd3a765..a0354f906e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpg7-hqjg-pxxj/GHSA-rpg7-hqjg-pxxj.json +++ b/advisories/unreviewed/2022/05/GHSA-rpg7-hqjg-pxxj/GHSA-rpg7-hqjg-pxxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpgm-pm3h-88m4/GHSA-rpgm-pm3h-88m4.json b/advisories/unreviewed/2022/05/GHSA-rpgm-pm3h-88m4/GHSA-rpgm-pm3h-88m4.json index ecf43b1c006..d8e3ad6e826 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpgm-pm3h-88m4/GHSA-rpgm-pm3h-88m4.json +++ b/advisories/unreviewed/2022/05/GHSA-rpgm-pm3h-88m4/GHSA-rpgm-pm3h-88m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpxc-53j6-4h69/GHSA-rpxc-53j6-4h69.json b/advisories/unreviewed/2022/05/GHSA-rpxc-53j6-4h69/GHSA-rpxc-53j6-4h69.json index 800ba3a1597..96d461e9744 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpxc-53j6-4h69/GHSA-rpxc-53j6-4h69.json +++ b/advisories/unreviewed/2022/05/GHSA-rpxc-53j6-4h69/GHSA-rpxc-53j6-4h69.json @@ -7,12 +7,8 @@ "CVE-2021-24260" ], "details": "The “Livemesh Addons for Elementorâ€? WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr2q-wg42-c2xp/GHSA-rr2q-wg42-c2xp.json b/advisories/unreviewed/2022/05/GHSA-rr2q-wg42-c2xp/GHSA-rr2q-wg42-c2xp.json index 33a1f6347d7..ad82e0f2edf 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr2q-wg42-c2xp/GHSA-rr2q-wg42-c2xp.json +++ b/advisories/unreviewed/2022/05/GHSA-rr2q-wg42-c2xp/GHSA-rr2q-wg42-c2xp.json @@ -7,12 +7,8 @@ "CVE-2008-3555" ], "details": "Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrqp-7v76-3h43/GHSA-rrqp-7v76-3h43.json b/advisories/unreviewed/2022/05/GHSA-rrqp-7v76-3h43/GHSA-rrqp-7v76-3h43.json index 4f1ec9a638e..e82599b19ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrqp-7v76-3h43/GHSA-rrqp-7v76-3h43.json +++ b/advisories/unreviewed/2022/05/GHSA-rrqp-7v76-3h43/GHSA-rrqp-7v76-3h43.json @@ -7,12 +7,8 @@ "CVE-2008-3365" ], "details": "Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language_full parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrrr-5gqp-f52r/GHSA-rrrr-5gqp-f52r.json b/advisories/unreviewed/2022/05/GHSA-rrrr-5gqp-f52r/GHSA-rrrr-5gqp-f52r.json index 96fe1651a35..da0f8f246b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrrr-5gqp-f52r/GHSA-rrrr-5gqp-f52r.json +++ b/advisories/unreviewed/2022/05/GHSA-rrrr-5gqp-f52r/GHSA-rrrr-5gqp-f52r.json @@ -7,12 +7,8 @@ "CVE-2008-3235" ], "details": "Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv39-23hm-r9j8/GHSA-rv39-23hm-r9j8.json b/advisories/unreviewed/2022/05/GHSA-rv39-23hm-r9j8/GHSA-rv39-23hm-r9j8.json index 42eaa2d640c..5e1483bdbcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv39-23hm-r9j8/GHSA-rv39-23hm-r9j8.json +++ b/advisories/unreviewed/2022/05/GHSA-rv39-23hm-r9j8/GHSA-rv39-23hm-r9j8.json @@ -7,12 +7,8 @@ "CVE-2020-28221" ], "details": "A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvmj-prf9-4422/GHSA-rvmj-prf9-4422.json b/advisories/unreviewed/2022/05/GHSA-rvmj-prf9-4422/GHSA-rvmj-prf9-4422.json index 66b87437d5d..160d5ea65e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvmj-prf9-4422/GHSA-rvmj-prf9-4422.json +++ b/advisories/unreviewed/2022/05/GHSA-rvmj-prf9-4422/GHSA-rvmj-prf9-4422.json @@ -7,12 +7,8 @@ "CVE-2008-3721" ], "details": "PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvxm-h3g5-956x/GHSA-rvxm-h3g5-956x.json b/advisories/unreviewed/2022/05/GHSA-rvxm-h3g5-956x/GHSA-rvxm-h3g5-956x.json index e91ca6230d2..695aa359aa7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvxm-h3g5-956x/GHSA-rvxm-h3g5-956x.json +++ b/advisories/unreviewed/2022/05/GHSA-rvxm-h3g5-956x/GHSA-rvxm-h3g5-956x.json @@ -7,12 +7,8 @@ "CVE-2008-3411" ], "details": "The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/config/Network.html, (3) etc/config/Security.html, (4) cgi-bin/sysconf.cgi, and (5) cgi-bin/route.cgi, which allows remote attackers to change the modem's configuration via direct requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwvw-pgvv-gwch/GHSA-rwvw-pgvv-gwch.json b/advisories/unreviewed/2022/05/GHSA-rwvw-pgvv-gwch/GHSA-rwvw-pgvv-gwch.json index 70f29025189..f1b0d03d064 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwvw-pgvv-gwch/GHSA-rwvw-pgvv-gwch.json +++ b/advisories/unreviewed/2022/05/GHSA-rwvw-pgvv-gwch/GHSA-rwvw-pgvv-gwch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwvx-jmhc-59j8/GHSA-rwvx-jmhc-59j8.json b/advisories/unreviewed/2022/05/GHSA-rwvx-jmhc-59j8/GHSA-rwvx-jmhc-59j8.json index 26b735c76ed..3e0e90e8eeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwvx-jmhc-59j8/GHSA-rwvx-jmhc-59j8.json +++ b/advisories/unreviewed/2022/05/GHSA-rwvx-jmhc-59j8/GHSA-rwvx-jmhc-59j8.json @@ -7,12 +7,8 @@ "CVE-2008-3476" ], "details": "Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka \"HTML Objects Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx7v-38cm-3gxv/GHSA-rx7v-38cm-3gxv.json b/advisories/unreviewed/2022/05/GHSA-rx7v-38cm-3gxv/GHSA-rx7v-38cm-3gxv.json index 468a09af39a..db9217854f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx7v-38cm-3gxv/GHSA-rx7v-38cm-3gxv.json +++ b/advisories/unreviewed/2022/05/GHSA-rx7v-38cm-3gxv/GHSA-rx7v-38cm-3gxv.json @@ -7,12 +7,8 @@ "CVE-2008-3502" ], "details": "Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authenticated users to cause a denial of service (CPU or memory consumption) via unspecified vectors related to the Devel::StackTrace module for Perl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2g8-mp79-j2h2/GHSA-v2g8-mp79-j2h2.json b/advisories/unreviewed/2022/05/GHSA-v2g8-mp79-j2h2/GHSA-v2g8-mp79-j2h2.json index 587cb1664a2..82e8f752e5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2g8-mp79-j2h2/GHSA-v2g8-mp79-j2h2.json +++ b/advisories/unreviewed/2022/05/GHSA-v2g8-mp79-j2h2/GHSA-v2g8-mp79-j2h2.json @@ -7,12 +7,8 @@ "CVE-2008-3634" ], "details": "Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2j7-x7p2-h49g/GHSA-v2j7-x7p2-h49g.json b/advisories/unreviewed/2022/05/GHSA-v2j7-x7p2-h49g/GHSA-v2j7-x7p2-h49g.json index abab68b3dd2..79d028633cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2j7-x7p2-h49g/GHSA-v2j7-x7p2-h49g.json +++ b/advisories/unreviewed/2022/05/GHSA-v2j7-x7p2-h49g/GHSA-v2j7-x7p2-h49g.json @@ -7,12 +7,8 @@ "CVE-2008-3245" ], "details": "SQL injection vulnerability in phpHoo3.php in phpHoo3 4.3.9, 4.3.10, 4.4.8, and 5.2.6 allows remote attackers to execute arbitrary SQL commands via the viewCat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2m6-98xf-3xq5/GHSA-v2m6-98xf-3xq5.json b/advisories/unreviewed/2022/05/GHSA-v2m6-98xf-3xq5/GHSA-v2m6-98xf-3xq5.json index fa632fa91ed..654a5d1c2f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2m6-98xf-3xq5/GHSA-v2m6-98xf-3xq5.json +++ b/advisories/unreviewed/2022/05/GHSA-v2m6-98xf-3xq5/GHSA-v2m6-98xf-3xq5.json @@ -7,12 +7,8 @@ "CVE-2008-3323" ], "details": "setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-middle attackers to execute arbitrary code via a package list containing the MD5 checksum of a Trojan horse package.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2r4-59rh-28xw/GHSA-v2r4-59rh-28xw.json b/advisories/unreviewed/2022/05/GHSA-v2r4-59rh-28xw/GHSA-v2r4-59rh-28xw.json index 3d425b71c35..e2bb2242382 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2r4-59rh-28xw/GHSA-v2r4-59rh-28xw.json +++ b/advisories/unreviewed/2022/05/GHSA-v2r4-59rh-28xw/GHSA-v2r4-59rh-28xw.json @@ -7,12 +7,8 @@ "CVE-2008-3314" ], "details": "ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 command, which triggers a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v339-8wjf-rjvc/GHSA-v339-8wjf-rjvc.json b/advisories/unreviewed/2022/05/GHSA-v339-8wjf-rjvc/GHSA-v339-8wjf-rjvc.json index df8bfda597a..ff74d70cfb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v339-8wjf-rjvc/GHSA-v339-8wjf-rjvc.json +++ b/advisories/unreviewed/2022/05/GHSA-v339-8wjf-rjvc/GHSA-v339-8wjf-rjvc.json @@ -7,12 +7,8 @@ "CVE-2008-3299" ], "details": "eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v36f-fpp3-jjgc/GHSA-v36f-fpp3-jjgc.json b/advisories/unreviewed/2022/05/GHSA-v36f-fpp3-jjgc/GHSA-v36f-fpp3-jjgc.json index 6308ccb40ea..9a3e5a9a2b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v36f-fpp3-jjgc/GHSA-v36f-fpp3-jjgc.json +++ b/advisories/unreviewed/2022/05/GHSA-v36f-fpp3-jjgc/GHSA-v36f-fpp3-jjgc.json @@ -7,12 +7,8 @@ "CVE-2008-3404" ], "details": "Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the link parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3gq-4rfr-3pp4/GHSA-v3gq-4rfr-3pp4.json b/advisories/unreviewed/2022/05/GHSA-v3gq-4rfr-3pp4/GHSA-v3gq-4rfr-3pp4.json index 1c14f5a2861..d5f2aacfec5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3gq-4rfr-3pp4/GHSA-v3gq-4rfr-3pp4.json +++ b/advisories/unreviewed/2022/05/GHSA-v3gq-4rfr-3pp4/GHSA-v3gq-4rfr-3pp4.json @@ -7,12 +7,8 @@ "CVE-2008-3378" ], "details": "SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3gw-6p53-vcfx/GHSA-v3gw-6p53-vcfx.json b/advisories/unreviewed/2022/05/GHSA-v3gw-6p53-vcfx/GHSA-v3gw-6p53-vcfx.json index d3a8b04a806..fdb47744afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3gw-6p53-vcfx/GHSA-v3gw-6p53-vcfx.json +++ b/advisories/unreviewed/2022/05/GHSA-v3gw-6p53-vcfx/GHSA-v3gw-6p53-vcfx.json @@ -7,12 +7,8 @@ "CVE-2008-3595" ], "details": "PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3rc-82pr-v7xw/GHSA-v3rc-82pr-v7xw.json b/advisories/unreviewed/2022/05/GHSA-v3rc-82pr-v7xw/GHSA-v3rc-82pr-v7xw.json index 333f4190844..4c68a224493 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3rc-82pr-v7xw/GHSA-v3rc-82pr-v7xw.json +++ b/advisories/unreviewed/2022/05/GHSA-v3rc-82pr-v7xw/GHSA-v3rc-82pr-v7xw.json @@ -7,12 +7,8 @@ "CVE-2021-38352" ], "details": "The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3wj-j97f-4jgc/GHSA-v3wj-j97f-4jgc.json b/advisories/unreviewed/2022/05/GHSA-v3wj-j97f-4jgc/GHSA-v3wj-j97f-4jgc.json index 211da4fbdd2..c41c5a464c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3wj-j97f-4jgc/GHSA-v3wj-j97f-4jgc.json +++ b/advisories/unreviewed/2022/05/GHSA-v3wj-j97f-4jgc/GHSA-v3wj-j97f-4jgc.json @@ -7,12 +7,8 @@ "CVE-2021-24835" ], "details": "The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4ff-vj6q-v2w9/GHSA-v4ff-vj6q-v2w9.json b/advisories/unreviewed/2022/05/GHSA-v4ff-vj6q-v2w9/GHSA-v4ff-vj6q-v2w9.json index 4a9d27bdaba..ff552ff3b86 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4ff-vj6q-v2w9/GHSA-v4ff-vj6q-v2w9.json +++ b/advisories/unreviewed/2022/05/GHSA-v4ff-vj6q-v2w9/GHSA-v4ff-vj6q-v2w9.json @@ -7,12 +7,8 @@ "CVE-2008-3233" ], "details": "Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4v8-f5rh-744r/GHSA-v4v8-f5rh-744r.json b/advisories/unreviewed/2022/05/GHSA-v4v8-f5rh-744r/GHSA-v4v8-f5rh-744r.json index c6bd48bc665..8b4db49f049 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4v8-f5rh-744r/GHSA-v4v8-f5rh-744r.json +++ b/advisories/unreviewed/2022/05/GHSA-v4v8-f5rh-744r/GHSA-v4v8-f5rh-744r.json @@ -7,12 +7,8 @@ "CVE-2008-3445" ], "details": "SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v57h-2cmj-gqr2/GHSA-v57h-2cmj-gqr2.json b/advisories/unreviewed/2022/05/GHSA-v57h-2cmj-gqr2/GHSA-v57h-2cmj-gqr2.json index 466892b5c70..8717e4c81e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v57h-2cmj-gqr2/GHSA-v57h-2cmj-gqr2.json +++ b/advisories/unreviewed/2022/05/GHSA-v57h-2cmj-gqr2/GHSA-v57h-2cmj-gqr2.json @@ -7,12 +7,8 @@ "CVE-2021-28188" ], "details": "The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5cp-c22v-m9jv/GHSA-v5cp-c22v-m9jv.json b/advisories/unreviewed/2022/05/GHSA-v5cp-c22v-m9jv/GHSA-v5cp-c22v-m9jv.json index 53da73b36b7..d65e25082e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5cp-c22v-m9jv/GHSA-v5cp-c22v-m9jv.json +++ b/advisories/unreviewed/2022/05/GHSA-v5cp-c22v-m9jv/GHSA-v5cp-c22v-m9jv.json @@ -7,12 +7,8 @@ "CVE-2008-3767" ], "details": "SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6r2-c4w2-hh49/GHSA-v6r2-c4w2-hh49.json b/advisories/unreviewed/2022/05/GHSA-v6r2-c4w2-hh49/GHSA-v6r2-c4w2-hh49.json index 955771af23c..b76c8ebba5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6r2-c4w2-hh49/GHSA-v6r2-c4w2-hh49.json +++ b/advisories/unreviewed/2022/05/GHSA-v6r2-c4w2-hh49/GHSA-v6r2-c4w2-hh49.json @@ -7,12 +7,8 @@ "CVE-2008-3683" ], "details": "Unspecified vulnerability in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.5 before SP6 allows remote attackers to cause a denial of service (failure to accept connections) via unknown vectors, probably related to exhaustion of file descriptors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6vw-6gwh-pprh/GHSA-v6vw-6gwh-pprh.json b/advisories/unreviewed/2022/05/GHSA-v6vw-6gwh-pprh/GHSA-v6vw-6gwh-pprh.json index 4144708caf7..948b99a5120 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6vw-6gwh-pprh/GHSA-v6vw-6gwh-pprh.json +++ b/advisories/unreviewed/2022/05/GHSA-v6vw-6gwh-pprh/GHSA-v6vw-6gwh-pprh.json @@ -7,12 +7,8 @@ "CVE-2008-3663" ], "details": "Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7mp-pvc5-pr33/GHSA-v7mp-pvc5-pr33.json b/advisories/unreviewed/2022/05/GHSA-v7mp-pvc5-pr33/GHSA-v7mp-pvc5-pr33.json index a6955daef64..3312748f6bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7mp-pvc5-pr33/GHSA-v7mp-pvc5-pr33.json +++ b/advisories/unreviewed/2022/05/GHSA-v7mp-pvc5-pr33/GHSA-v7mp-pvc5-pr33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7x7-3545-4jq3/GHSA-v7x7-3545-4jq3.json b/advisories/unreviewed/2022/05/GHSA-v7x7-3545-4jq3/GHSA-v7x7-3545-4jq3.json index 81d498090df..b1f590b74c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7x7-3545-4jq3/GHSA-v7x7-3545-4jq3.json +++ b/advisories/unreviewed/2022/05/GHSA-v7x7-3545-4jq3/GHSA-v7x7-3545-4jq3.json @@ -7,12 +7,8 @@ "CVE-2008-3488" ], "details": "Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v838-v88j-gw93/GHSA-v838-v88j-gw93.json b/advisories/unreviewed/2022/05/GHSA-v838-v88j-gw93/GHSA-v838-v88j-gw93.json index d7387a5e57f..4f760047595 100644 --- a/advisories/unreviewed/2022/05/GHSA-v838-v88j-gw93/GHSA-v838-v88j-gw93.json +++ b/advisories/unreviewed/2022/05/GHSA-v838-v88j-gw93/GHSA-v838-v88j-gw93.json @@ -7,12 +7,8 @@ "CVE-2008-3443" ], "details": "The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8rv-c4hj-xh2q/GHSA-v8rv-c4hj-xh2q.json b/advisories/unreviewed/2022/05/GHSA-v8rv-c4hj-xh2q/GHSA-v8rv-c4hj-xh2q.json index 9f9cd6462f1..56a56477192 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8rv-c4hj-xh2q/GHSA-v8rv-c4hj-xh2q.json +++ b/advisories/unreviewed/2022/05/GHSA-v8rv-c4hj-xh2q/GHSA-v8rv-c4hj-xh2q.json @@ -7,12 +7,8 @@ "CVE-2008-3347" ], "details": "SQL injection vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to execute arbitrary SQL commands via the read parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc52-mwgj-fh66/GHSA-vc52-mwgj-fh66.json b/advisories/unreviewed/2022/05/GHSA-vc52-mwgj-fh66/GHSA-vc52-mwgj-fh66.json index 6aaf1452d63..3236beec746 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc52-mwgj-fh66/GHSA-vc52-mwgj-fh66.json +++ b/advisories/unreviewed/2022/05/GHSA-vc52-mwgj-fh66/GHSA-vc52-mwgj-fh66.json @@ -7,12 +7,8 @@ "CVE-2008-3412" ], "details": "SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc6p-gv49-w48x/GHSA-vc6p-gv49-w48x.json b/advisories/unreviewed/2022/05/GHSA-vc6p-gv49-w48x/GHSA-vc6p-gv49-w48x.json index f29b6b1204f..0210c1302c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc6p-gv49-w48x/GHSA-vc6p-gv49-w48x.json +++ b/advisories/unreviewed/2022/05/GHSA-vc6p-gv49-w48x/GHSA-vc6p-gv49-w48x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc9w-9m7m-hx2f/GHSA-vc9w-9m7m-hx2f.json b/advisories/unreviewed/2022/05/GHSA-vc9w-9m7m-hx2f/GHSA-vc9w-9m7m-hx2f.json index c64cfbadac9..512c16e6c12 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc9w-9m7m-hx2f/GHSA-vc9w-9m7m-hx2f.json +++ b/advisories/unreviewed/2022/05/GHSA-vc9w-9m7m-hx2f/GHSA-vc9w-9m7m-hx2f.json @@ -7,12 +7,8 @@ "CVE-2008-3631" ], "details": "Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcvh-qrpm-8cw7/GHSA-vcvh-qrpm-8cw7.json b/advisories/unreviewed/2022/05/GHSA-vcvh-qrpm-8cw7/GHSA-vcvh-qrpm-8cw7.json index 6dd7308971b..be7ce2ea44c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcvh-qrpm-8cw7/GHSA-vcvh-qrpm-8cw7.json +++ b/advisories/unreviewed/2022/05/GHSA-vcvh-qrpm-8cw7/GHSA-vcvh-qrpm-8cw7.json @@ -7,12 +7,8 @@ "CVE-2008-3326" ], "details": "Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcw7-xf7p-mcqf/GHSA-vcw7-xf7p-mcqf.json b/advisories/unreviewed/2022/05/GHSA-vcw7-xf7p-mcqf/GHSA-vcw7-xf7p-mcqf.json index 3646d9fd66c..65c18177385 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcw7-xf7p-mcqf/GHSA-vcw7-xf7p-mcqf.json +++ b/advisories/unreviewed/2022/05/GHSA-vcw7-xf7p-mcqf/GHSA-vcw7-xf7p-mcqf.json @@ -7,12 +7,8 @@ "CVE-2008-3370" ], "details": "SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf33-c85r-62wf/GHSA-vf33-c85r-62wf.json b/advisories/unreviewed/2022/05/GHSA-vf33-c85r-62wf/GHSA-vf33-c85r-62wf.json index e592fb444ee..8de9599a92a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf33-c85r-62wf/GHSA-vf33-c85r-62wf.json +++ b/advisories/unreviewed/2022/05/GHSA-vf33-c85r-62wf/GHSA-vf33-c85r-62wf.json @@ -7,12 +7,8 @@ "CVE-2021-24201" ], "details": "In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh5p-g64v-2w64/GHSA-vh5p-g64v-2w64.json b/advisories/unreviewed/2022/05/GHSA-vh5p-g64v-2w64/GHSA-vh5p-g64v-2w64.json index 4813b383d73..5311af1de10 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh5p-g64v-2w64/GHSA-vh5p-g64v-2w64.json +++ b/advisories/unreviewed/2022/05/GHSA-vh5p-g64v-2w64/GHSA-vh5p-g64v-2w64.json @@ -7,12 +7,8 @@ "CVE-2008-3574" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) lang_install22, (4) titelkop, (5) lang_kop1, (6) lang_kop2, (7) lang_modules, (8) lang_kop4, (9) lang_kop15, (10) lang_kop5, and (11) titelkop parameters to (b) data/inc/header.php; the pluck_version and titelkop parameters to (c) data/inc/header2.php; and the (14) lang_theme6 parameter to (d) data/inc/themeinstall.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm37-4mp6-7m23/GHSA-vm37-4mp6-7m23.json b/advisories/unreviewed/2022/05/GHSA-vm37-4mp6-7m23/GHSA-vm37-4mp6-7m23.json index 62b6db9d43b..8eb69a507a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm37-4mp6-7m23/GHSA-vm37-4mp6-7m23.json +++ b/advisories/unreviewed/2022/05/GHSA-vm37-4mp6-7m23/GHSA-vm37-4mp6-7m23.json @@ -7,12 +7,8 @@ "CVE-2008-3489" ], "details": "SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm4h-83vj-vv8g/GHSA-vm4h-83vj-vv8g.json b/advisories/unreviewed/2022/05/GHSA-vm4h-83vj-vv8g/GHSA-vm4h-83vj-vv8g.json index cbeeb782bff..7db443eab47 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm4h-83vj-vv8g/GHSA-vm4h-83vj-vv8g.json +++ b/advisories/unreviewed/2022/05/GHSA-vm4h-83vj-vv8g/GHSA-vm4h-83vj-vv8g.json @@ -7,12 +7,8 @@ "CVE-2008-3250" ], "details": "SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm6r-qwjc-7jvf/GHSA-vm6r-qwjc-7jvf.json b/advisories/unreviewed/2022/05/GHSA-vm6r-qwjc-7jvf/GHSA-vm6r-qwjc-7jvf.json index 174812f9a2c..31b4418b8e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm6r-qwjc-7jvf/GHSA-vm6r-qwjc-7jvf.json +++ b/advisories/unreviewed/2022/05/GHSA-vm6r-qwjc-7jvf/GHSA-vm6r-qwjc-7jvf.json @@ -7,12 +7,8 @@ "CVE-2021-24363" ], "details": "The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmrv-vjrp-6298/GHSA-vmrv-vjrp-6298.json b/advisories/unreviewed/2022/05/GHSA-vmrv-vjrp-6298/GHSA-vmrv-vjrp-6298.json index 68152d01644..a53d0119c22 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmrv-vjrp-6298/GHSA-vmrv-vjrp-6298.json +++ b/advisories/unreviewed/2022/05/GHSA-vmrv-vjrp-6298/GHSA-vmrv-vjrp-6298.json @@ -7,12 +7,8 @@ "CVE-2008-3596" ], "details": "Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7 allows remote attackers to inject arbitrary web script or HTML via the Username field, which is inserted into logs that could be rendered when viewed by an administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmwg-3qr7-49hp/GHSA-vmwg-3qr7-49hp.json b/advisories/unreviewed/2022/05/GHSA-vmwg-3qr7-49hp/GHSA-vmwg-3qr7-49hp.json index 000d5783fba..21ff64ccf35 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmwg-3qr7-49hp/GHSA-vmwg-3qr7-49hp.json +++ b/advisories/unreviewed/2022/05/GHSA-vmwg-3qr7-49hp/GHSA-vmwg-3qr7-49hp.json @@ -7,12 +7,8 @@ "CVE-2020-24416" ], "details": "Marketo Sales Insight plugin version 1.4355 (and earlier) is affected by a blind stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmx3-v345-ffj8/GHSA-vmx3-v345-ffj8.json b/advisories/unreviewed/2022/05/GHSA-vmx3-v345-ffj8/GHSA-vmx3-v345-ffj8.json index 845f19ab8a7..3e5b835a595 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmx3-v345-ffj8/GHSA-vmx3-v345-ffj8.json +++ b/advisories/unreviewed/2022/05/GHSA-vmx3-v345-ffj8/GHSA-vmx3-v345-ffj8.json @@ -7,12 +7,8 @@ "CVE-2020-9742" ], "details": "AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpgh-3hx2-v733/GHSA-vpgh-3hx2-v733.json b/advisories/unreviewed/2022/05/GHSA-vpgh-3hx2-v733/GHSA-vpgh-3hx2-v733.json index c7a50e99c58..b26b1da1bda 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpgh-3hx2-v733/GHSA-vpgh-3hx2-v733.json +++ b/advisories/unreviewed/2022/05/GHSA-vpgh-3hx2-v733/GHSA-vpgh-3hx2-v733.json @@ -7,12 +7,8 @@ "CVE-2008-3500" ], "details": "Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpgm-r2pm-mcv7/GHSA-vpgm-r2pm-mcv7.json b/advisories/unreviewed/2022/05/GHSA-vpgm-r2pm-mcv7/GHSA-vpgm-r2pm-mcv7.json index 0b0c1d09892..9afda242126 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpgm-r2pm-mcv7/GHSA-vpgm-r2pm-mcv7.json +++ b/advisories/unreviewed/2022/05/GHSA-vpgm-r2pm-mcv7/GHSA-vpgm-r2pm-mcv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpqp-8hvh-698m/GHSA-vpqp-8hvh-698m.json b/advisories/unreviewed/2022/05/GHSA-vpqp-8hvh-698m/GHSA-vpqp-8hvh-698m.json index 38ddbaaa828..e9a3201bf11 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpqp-8hvh-698m/GHSA-vpqp-8hvh-698m.json +++ b/advisories/unreviewed/2022/05/GHSA-vpqp-8hvh-698m/GHSA-vpqp-8hvh-698m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq4h-gf44-5hcq/GHSA-vq4h-gf44-5hcq.json b/advisories/unreviewed/2022/05/GHSA-vq4h-gf44-5hcq/GHSA-vq4h-gf44-5hcq.json index 97a1443e8f4..587f376a79f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq4h-gf44-5hcq/GHSA-vq4h-gf44-5hcq.json +++ b/advisories/unreviewed/2022/05/GHSA-vq4h-gf44-5hcq/GHSA-vq4h-gf44-5hcq.json @@ -7,12 +7,8 @@ "CVE-2021-32455" ], "details": "SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending HTTP requests massively.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq4h-q3pr-mhp2/GHSA-vq4h-q3pr-mhp2.json b/advisories/unreviewed/2022/05/GHSA-vq4h-q3pr-mhp2/GHSA-vq4h-q3pr-mhp2.json index ef6740f8aa3..cd9d0c3f3b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq4h-q3pr-mhp2/GHSA-vq4h-q3pr-mhp2.json +++ b/advisories/unreviewed/2022/05/GHSA-vq4h-q3pr-mhp2/GHSA-vq4h-q3pr-mhp2.json @@ -7,12 +7,8 @@ "CVE-2008-3340" ], "details": "Cross-site scripting (XSS) vulnerability in search_result.cfm in Jobbex JobSite allows remote attackers to inject arbitrary web script or HTML via the searchFor variable (possibly the opt parameter.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw77-6q33-mm53/GHSA-vw77-6q33-mm53.json b/advisories/unreviewed/2022/05/GHSA-vw77-6q33-mm53/GHSA-vw77-6q33-mm53.json index f8075374aee..05c4376ccd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw77-6q33-mm53/GHSA-vw77-6q33-mm53.json +++ b/advisories/unreviewed/2022/05/GHSA-vw77-6q33-mm53/GHSA-vw77-6q33-mm53.json @@ -7,12 +7,8 @@ "CVE-2021-27030" ], "details": "A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwj8-4grf-3r8v/GHSA-vwj8-4grf-3r8v.json b/advisories/unreviewed/2022/05/GHSA-vwj8-4grf-3r8v/GHSA-vwj8-4grf-3r8v.json index 07790e9de3b..5762e5b65ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwj8-4grf-3r8v/GHSA-vwj8-4grf-3r8v.json +++ b/advisories/unreviewed/2022/05/GHSA-vwj8-4grf-3r8v/GHSA-vwj8-4grf-3r8v.json @@ -7,12 +7,8 @@ "CVE-2021-33322" ], "details": "In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwmw-f3cr-593g/GHSA-vwmw-f3cr-593g.json b/advisories/unreviewed/2022/05/GHSA-vwmw-f3cr-593g/GHSA-vwmw-f3cr-593g.json index ecb9a758982..9482698aee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwmw-f3cr-593g/GHSA-vwmw-f3cr-593g.json +++ b/advisories/unreviewed/2022/05/GHSA-vwmw-f3cr-593g/GHSA-vwmw-f3cr-593g.json @@ -7,12 +7,8 @@ "CVE-2021-24599" ], "details": "The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwqv-6c7x-w4pq/GHSA-vwqv-6c7x-w4pq.json b/advisories/unreviewed/2022/05/GHSA-vwqv-6c7x-w4pq/GHSA-vwqv-6c7x-w4pq.json index 7eb2fe85511..95da091f36a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwqv-6c7x-w4pq/GHSA-vwqv-6c7x-w4pq.json +++ b/advisories/unreviewed/2022/05/GHSA-vwqv-6c7x-w4pq/GHSA-vwqv-6c7x-w4pq.json @@ -7,12 +7,8 @@ "CVE-2020-9737" ], "details": "AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxj9-gvcj-83p2/GHSA-vxj9-gvcj-83p2.json b/advisories/unreviewed/2022/05/GHSA-vxj9-gvcj-83p2/GHSA-vxj9-gvcj-83p2.json index 8e0e3971a45..77b0b9f5fc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxj9-gvcj-83p2/GHSA-vxj9-gvcj-83p2.json +++ b/advisories/unreviewed/2022/05/GHSA-vxj9-gvcj-83p2/GHSA-vxj9-gvcj-83p2.json @@ -7,12 +7,8 @@ "CVE-2020-12046" ], "details": "Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w28p-3vfp-xgqp/GHSA-w28p-3vfp-xgqp.json b/advisories/unreviewed/2022/05/GHSA-w28p-3vfp-xgqp/GHSA-w28p-3vfp-xgqp.json index fde50f3b221..da33b950b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-w28p-3vfp-xgqp/GHSA-w28p-3vfp-xgqp.json +++ b/advisories/unreviewed/2022/05/GHSA-w28p-3vfp-xgqp/GHSA-w28p-3vfp-xgqp.json @@ -7,12 +7,8 @@ "CVE-2008-3447" ], "details": "The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w2q9-mc2f-8rr5/GHSA-w2q9-mc2f-8rr5.json b/advisories/unreviewed/2022/05/GHSA-w2q9-mc2f-8rr5/GHSA-w2q9-mc2f-8rr5.json index 1a1fa179640..10ec06f445f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2q9-mc2f-8rr5/GHSA-w2q9-mc2f-8rr5.json +++ b/advisories/unreviewed/2022/05/GHSA-w2q9-mc2f-8rr5/GHSA-w2q9-mc2f-8rr5.json @@ -7,12 +7,8 @@ "CVE-2008-3420" ], "details": "Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to browse.php or (2) the s parameter in an exhibitions action to detail.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2rq-q2p4-c7qq/GHSA-w2rq-q2p4-c7qq.json b/advisories/unreviewed/2022/05/GHSA-w2rq-q2p4-c7qq/GHSA-w2rq-q2p4-c7qq.json index 8d102bfe70a..23860db8671 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2rq-q2p4-c7qq/GHSA-w2rq-q2p4-c7qq.json +++ b/advisories/unreviewed/2022/05/GHSA-w2rq-q2p4-c7qq/GHSA-w2rq-q2p4-c7qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2wp-4q7c-2gw9/GHSA-w2wp-4q7c-2gw9.json b/advisories/unreviewed/2022/05/GHSA-w2wp-4q7c-2gw9/GHSA-w2wp-4q7c-2gw9.json index f82ef4aabcf..90536451239 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2wp-4q7c-2gw9/GHSA-w2wp-4q7c-2gw9.json +++ b/advisories/unreviewed/2022/05/GHSA-w2wp-4q7c-2gw9/GHSA-w2wp-4q7c-2gw9.json @@ -7,12 +7,8 @@ "CVE-2008-3772" ], "details": "SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2ww-4mx4-w7c7/GHSA-w2ww-4mx4-w7c7.json b/advisories/unreviewed/2022/05/GHSA-w2ww-4mx4-w7c7/GHSA-w2ww-4mx4-w7c7.json index 1fcaf52d874..569ee19e082 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2ww-4mx4-w7c7/GHSA-w2ww-4mx4-w7c7.json +++ b/advisories/unreviewed/2022/05/GHSA-w2ww-4mx4-w7c7/GHSA-w2ww-4mx4-w7c7.json @@ -7,12 +7,8 @@ "CVE-2008-3335" ], "details": "Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w34p-wqjq-9xw2/GHSA-w34p-wqjq-9xw2.json b/advisories/unreviewed/2022/05/GHSA-w34p-wqjq-9xw2/GHSA-w34p-wqjq-9xw2.json index a2eeae883ea..7cd9b6408a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w34p-wqjq-9xw2/GHSA-w34p-wqjq-9xw2.json +++ b/advisories/unreviewed/2022/05/GHSA-w34p-wqjq-9xw2/GHSA-w34p-wqjq-9xw2.json @@ -7,12 +7,8 @@ "CVE-2008-3313" ], "details": "Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[document_uri] parameter to _administration/edition_article/edition_article.php and the (2) cfg[base_uri_admin] parameter to _administration/fonctions/get_liste_langue.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3xv-vhr5-qfqw/GHSA-w3xv-vhr5-qfqw.json b/advisories/unreviewed/2022/05/GHSA-w3xv-vhr5-qfqw/GHSA-w3xv-vhr5-qfqw.json index 1873a73fdd9..b940ebfb2e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3xv-vhr5-qfqw/GHSA-w3xv-vhr5-qfqw.json +++ b/advisories/unreviewed/2022/05/GHSA-w3xv-vhr5-qfqw/GHSA-w3xv-vhr5-qfqw.json @@ -7,12 +7,8 @@ "CVE-2008-3263" ], "details": "The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (call-number exhaustion and CPU consumption) by quickly sending a large number of IAX2 (IAX) POKE requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4q8-vj45-jj5g/GHSA-w4q8-vj45-jj5g.json b/advisories/unreviewed/2022/05/GHSA-w4q8-vj45-jj5g/GHSA-w4q8-vj45-jj5g.json index 8f4326537ec..ee622014f37 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4q8-vj45-jj5g/GHSA-w4q8-vj45-jj5g.json +++ b/advisories/unreviewed/2022/05/GHSA-w4q8-vj45-jj5g/GHSA-w4q8-vj45-jj5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4r7-7pqv-hpgf/GHSA-w4r7-7pqv-hpgf.json b/advisories/unreviewed/2022/05/GHSA-w4r7-7pqv-hpgf/GHSA-w4r7-7pqv-hpgf.json index fb418ac73c1..85e415305a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4r7-7pqv-hpgf/GHSA-w4r7-7pqv-hpgf.json +++ b/advisories/unreviewed/2022/05/GHSA-w4r7-7pqv-hpgf/GHSA-w4r7-7pqv-hpgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w587-hm47-h5qm/GHSA-w587-hm47-h5qm.json b/advisories/unreviewed/2022/05/GHSA-w587-hm47-h5qm/GHSA-w587-hm47-h5qm.json index 9d813f895e4..3a65ebcbc41 100644 --- a/advisories/unreviewed/2022/05/GHSA-w587-hm47-h5qm/GHSA-w587-hm47-h5qm.json +++ b/advisories/unreviewed/2022/05/GHSA-w587-hm47-h5qm/GHSA-w587-hm47-h5qm.json @@ -7,12 +7,8 @@ "CVE-2008-3788" ], "details": "Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email and (5) password parameters to (b) _login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5fj-r8j2-jmj9/GHSA-w5fj-r8j2-jmj9.json b/advisories/unreviewed/2022/05/GHSA-w5fj-r8j2-jmj9/GHSA-w5fj-r8j2-jmj9.json index ed7d5a6afca..3cb36e8047d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5fj-r8j2-jmj9/GHSA-w5fj-r8j2-jmj9.json +++ b/advisories/unreviewed/2022/05/GHSA-w5fj-r8j2-jmj9/GHSA-w5fj-r8j2-jmj9.json @@ -7,12 +7,8 @@ "CVE-2008-3515" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in files generated by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) viewer.swf and (2) loadflash.js, a different vulnerability than CVE-2008-3516.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w692-g942-pvjf/GHSA-w692-g942-pvjf.json b/advisories/unreviewed/2022/05/GHSA-w692-g942-pvjf/GHSA-w692-g942-pvjf.json index 8f84456250b..c81a714c40d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w692-g942-pvjf/GHSA-w692-g942-pvjf.json +++ b/advisories/unreviewed/2022/05/GHSA-w692-g942-pvjf/GHSA-w692-g942-pvjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6hg-rmw9-vhr2/GHSA-w6hg-rmw9-vhr2.json b/advisories/unreviewed/2022/05/GHSA-w6hg-rmw9-vhr2/GHSA-w6hg-rmw9-vhr2.json index ac6a1f3903c..c7481080c4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6hg-rmw9-vhr2/GHSA-w6hg-rmw9-vhr2.json +++ b/advisories/unreviewed/2022/05/GHSA-w6hg-rmw9-vhr2/GHSA-w6hg-rmw9-vhr2.json @@ -7,12 +7,8 @@ "CVE-2020-35170" ], "details": "Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users’ sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w763-qv46-5p55/GHSA-w763-qv46-5p55.json b/advisories/unreviewed/2022/05/GHSA-w763-qv46-5p55/GHSA-w763-qv46-5p55.json index bec599db4b4..6bb9dd1aa8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w763-qv46-5p55/GHSA-w763-qv46-5p55.json +++ b/advisories/unreviewed/2022/05/GHSA-w763-qv46-5p55/GHSA-w763-qv46-5p55.json @@ -7,12 +7,8 @@ "CVE-2020-8994" ], "details": "An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then they can read Wi-Fi SSID or password, read the dialogue text files between users and XIAOMI AI speaker, use Text-To-Speech tools pretend XIAOMI speakers' voice achieve social engineering attacks, eavesdrop on users and record what XIAOMI AI speaker hears, delete the entire XIAOMI AI speaker system, modify system files, stop voice assistant service, start the XIAOMI AI speaker’s SSH service as a backdoor", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w76c-7cm8-rpc8/GHSA-w76c-7cm8-rpc8.json b/advisories/unreviewed/2022/05/GHSA-w76c-7cm8-rpc8/GHSA-w76c-7cm8-rpc8.json index 7aec65a2f48..f2edace1c45 100644 --- a/advisories/unreviewed/2022/05/GHSA-w76c-7cm8-rpc8/GHSA-w76c-7cm8-rpc8.json +++ b/advisories/unreviewed/2022/05/GHSA-w76c-7cm8-rpc8/GHSA-w76c-7cm8-rpc8.json @@ -7,12 +7,8 @@ "CVE-2021-38455" ], "details": "The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w779-ggw7-rxjh/GHSA-w779-ggw7-rxjh.json b/advisories/unreviewed/2022/05/GHSA-w779-ggw7-rxjh/GHSA-w779-ggw7-rxjh.json index b570b4617a0..064aeb8a826 100644 --- a/advisories/unreviewed/2022/05/GHSA-w779-ggw7-rxjh/GHSA-w779-ggw7-rxjh.json +++ b/advisories/unreviewed/2022/05/GHSA-w779-ggw7-rxjh/GHSA-w779-ggw7-rxjh.json @@ -7,12 +7,8 @@ "CVE-2008-3459" ], "details": "Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7x3-rwmf-hc38/GHSA-w7x3-rwmf-hc38.json b/advisories/unreviewed/2022/05/GHSA-w7x3-rwmf-hc38/GHSA-w7x3-rwmf-hc38.json index bcbbf289d90..3b7f3b99b0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7x3-rwmf-hc38/GHSA-w7x3-rwmf-hc38.json +++ b/advisories/unreviewed/2022/05/GHSA-w7x3-rwmf-hc38/GHSA-w7x3-rwmf-hc38.json @@ -7,12 +7,8 @@ "CVE-2008-3697" ], "details": "An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8m5-fpqq-3q33/GHSA-w8m5-fpqq-3q33.json b/advisories/unreviewed/2022/05/GHSA-w8m5-fpqq-3q33/GHSA-w8m5-fpqq-3q33.json index cb11086b1e8..6c8f8355cd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8m5-fpqq-3q33/GHSA-w8m5-fpqq-3q33.json +++ b/advisories/unreviewed/2022/05/GHSA-w8m5-fpqq-3q33/GHSA-w8m5-fpqq-3q33.json @@ -7,12 +7,8 @@ "CVE-2019-18576" ], "details": "Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files may use the exposed passwords to gain access to XtremIO with the privileges of the compromised user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8qc-fmpq-5gmp/GHSA-w8qc-fmpq-5gmp.json b/advisories/unreviewed/2022/05/GHSA-w8qc-fmpq-5gmp/GHSA-w8qc-fmpq-5gmp.json index 2ea9893af2f..ca4934aff70 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8qc-fmpq-5gmp/GHSA-w8qc-fmpq-5gmp.json +++ b/advisories/unreviewed/2022/05/GHSA-w8qc-fmpq-5gmp/GHSA-w8qc-fmpq-5gmp.json @@ -7,12 +7,8 @@ "CVE-2020-8481" ], "details": "For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, confidential data is written in an unprotected file. An attacker who successfully exploited this vulnerability could take full control of the computer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8x9-6x9j-pqhj/GHSA-w8x9-6x9j-pqhj.json b/advisories/unreviewed/2022/05/GHSA-w8x9-6x9j-pqhj/GHSA-w8x9-6x9j-pqhj.json index 4fb3b60ee61..78fa7e9db3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8x9-6x9j-pqhj/GHSA-w8x9-6x9j-pqhj.json +++ b/advisories/unreviewed/2022/05/GHSA-w8x9-6x9j-pqhj/GHSA-w8x9-6x9j-pqhj.json @@ -7,12 +7,8 @@ "CVE-2013-3366" ], "details": "Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G�DFdg_24Mhw3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w996-2j6m-83fq/GHSA-w996-2j6m-83fq.json b/advisories/unreviewed/2022/05/GHSA-w996-2j6m-83fq/GHSA-w996-2j6m-83fq.json index b6e18e5051d..e319a484e38 100644 --- a/advisories/unreviewed/2022/05/GHSA-w996-2j6m-83fq/GHSA-w996-2j6m-83fq.json +++ b/advisories/unreviewed/2022/05/GHSA-w996-2j6m-83fq/GHSA-w996-2j6m-83fq.json @@ -7,12 +7,8 @@ "CVE-2008-3539" ], "details": "Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM Tivoli Dir Connector 1.02 and earlier, HPSI TOPSecret Connector 2.22.001 and earlier, HPSI RACF Connector 1.12.001 and earlier, HPSI ACF2 Connector 1.02 and earlier, HPSI OpenLDAP Connector 1.02 and earlier, and HPSI BiDir DirX Connector 1.00.003 and earlier, allows local users to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcw4-x9jg-p334/GHSA-wcw4-x9jg-p334.json b/advisories/unreviewed/2022/05/GHSA-wcw4-x9jg-p334/GHSA-wcw4-x9jg-p334.json index 50fbcc33606..8b84fd2055c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcw4-x9jg-p334/GHSA-wcw4-x9jg-p334.json +++ b/advisories/unreviewed/2022/05/GHSA-wcw4-x9jg-p334/GHSA-wcw4-x9jg-p334.json @@ -7,12 +7,8 @@ "CVE-2008-3672" ], "details": "SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf5r-cxjr-47w7/GHSA-wf5r-cxjr-47w7.json b/advisories/unreviewed/2022/05/GHSA-wf5r-cxjr-47w7/GHSA-wf5r-cxjr-47w7.json index 84147148ad3..7d7397abad2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf5r-cxjr-47w7/GHSA-wf5r-cxjr-47w7.json +++ b/advisories/unreviewed/2022/05/GHSA-wf5r-cxjr-47w7/GHSA-wf5r-cxjr-47w7.json @@ -7,12 +7,8 @@ "CVE-2008-3524" ], "details": "rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfh5-x68w-hvw2/GHSA-wfh5-x68w-hvw2.json b/advisories/unreviewed/2022/05/GHSA-wfh5-x68w-hvw2/GHSA-wfh5-x68w-hvw2.json index f5606a60c4a..64dd1dfe2af 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfh5-x68w-hvw2/GHSA-wfh5-x68w-hvw2.json +++ b/advisories/unreviewed/2022/05/GHSA-wfh5-x68w-hvw2/GHSA-wfh5-x68w-hvw2.json @@ -7,12 +7,8 @@ "CVE-2020-26559" ], "details": "Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfh8-qv3m-93p3/GHSA-wfh8-qv3m-93p3.json b/advisories/unreviewed/2022/05/GHSA-wfh8-qv3m-93p3/GHSA-wfh8-qv3m-93p3.json index 6ce2abe0261..05aa1e74d0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfh8-qv3m-93p3/GHSA-wfh8-qv3m-93p3.json +++ b/advisories/unreviewed/2022/05/GHSA-wfh8-qv3m-93p3/GHSA-wfh8-qv3m-93p3.json @@ -7,12 +7,8 @@ "CVE-2021-24334" ], "details": "The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg4v-4j73-j726/GHSA-wg4v-4j73-j726.json b/advisories/unreviewed/2022/05/GHSA-wg4v-4j73-j726/GHSA-wg4v-4j73-j726.json index c97ecbeae0f..d51c382a2ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg4v-4j73-j726/GHSA-wg4v-4j73-j726.json +++ b/advisories/unreviewed/2022/05/GHSA-wg4v-4j73-j726/GHSA-wg4v-4j73-j726.json @@ -7,12 +7,8 @@ "CVE-2008-3765" ], "details": "SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg6c-vw94-2hf7/GHSA-wg6c-vw94-2hf7.json b/advisories/unreviewed/2022/05/GHSA-wg6c-vw94-2hf7/GHSA-wg6c-vw94-2hf7.json index c51e185b9a1..09a41a2aa3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg6c-vw94-2hf7/GHSA-wg6c-vw94-2hf7.json +++ b/advisories/unreviewed/2022/05/GHSA-wg6c-vw94-2hf7/GHSA-wg6c-vw94-2hf7.json @@ -7,12 +7,8 @@ "CVE-2008-3192" ], "details": "Directory traversal vulnerability in index.php in jSite 1.0 OE allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg79-5fpg-69w9/GHSA-wg79-5fpg-69w9.json b/advisories/unreviewed/2022/05/GHSA-wg79-5fpg-69w9/GHSA-wg79-5fpg-69w9.json index deecf5c2dc1..66db5f6bbfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg79-5fpg-69w9/GHSA-wg79-5fpg-69w9.json +++ b/advisories/unreviewed/2022/05/GHSA-wg79-5fpg-69w9/GHSA-wg79-5fpg-69w9.json @@ -7,12 +7,8 @@ "CVE-2008-3671" ], "details": "Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wggr-rm2m-pxcx/GHSA-wggr-rm2m-pxcx.json b/advisories/unreviewed/2022/05/GHSA-wggr-rm2m-pxcx/GHSA-wggr-rm2m-pxcx.json index e95dbd952d6..18cffec5482 100644 --- a/advisories/unreviewed/2022/05/GHSA-wggr-rm2m-pxcx/GHSA-wggr-rm2m-pxcx.json +++ b/advisories/unreviewed/2022/05/GHSA-wggr-rm2m-pxcx/GHSA-wggr-rm2m-pxcx.json @@ -7,12 +7,8 @@ "CVE-2008-3380" ], "details": "Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgqq-h84j-p8mg/GHSA-wgqq-h84j-p8mg.json b/advisories/unreviewed/2022/05/GHSA-wgqq-h84j-p8mg/GHSA-wgqq-h84j-p8mg.json index 073bbb00dcb..da2d18e9c07 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgqq-h84j-p8mg/GHSA-wgqq-h84j-p8mg.json +++ b/advisories/unreviewed/2022/05/GHSA-wgqq-h84j-p8mg/GHSA-wgqq-h84j-p8mg.json @@ -7,12 +7,8 @@ "CVE-2021-37211" ], "details": "The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general user’s credential to inject JavaScript and execute stored XSS attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgwv-6x26-xh66/GHSA-wgwv-6x26-xh66.json b/advisories/unreviewed/2022/05/GHSA-wgwv-6x26-xh66/GHSA-wgwv-6x26-xh66.json index 71c95fe8171..3570214d1a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgwv-6x26-xh66/GHSA-wgwv-6x26-xh66.json +++ b/advisories/unreviewed/2022/05/GHSA-wgwv-6x26-xh66/GHSA-wgwv-6x26-xh66.json @@ -7,12 +7,8 @@ "CVE-2021-24594" ], "details": "The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh93-gr26-x6q9/GHSA-wh93-gr26-x6q9.json b/advisories/unreviewed/2022/05/GHSA-wh93-gr26-x6q9/GHSA-wh93-gr26-x6q9.json index 5119e22f912..796986e2abe 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh93-gr26-x6q9/GHSA-wh93-gr26-x6q9.json +++ b/advisories/unreviewed/2022/05/GHSA-wh93-gr26-x6q9/GHSA-wh93-gr26-x6q9.json @@ -7,12 +7,8 @@ "CVE-2020-25198" ], "details": "The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whvw-qqj8-2wvw/GHSA-whvw-qqj8-2wvw.json b/advisories/unreviewed/2022/05/GHSA-whvw-qqj8-2wvw/GHSA-whvw-qqj8-2wvw.json index f2821040a8f..03d7922f16c 100644 --- a/advisories/unreviewed/2022/05/GHSA-whvw-qqj8-2wvw/GHSA-whvw-qqj8-2wvw.json +++ b/advisories/unreviewed/2022/05/GHSA-whvw-qqj8-2wvw/GHSA-whvw-qqj8-2wvw.json @@ -7,12 +7,8 @@ "CVE-2008-3644" ], "details": "Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wm46-gchr-6vgg/GHSA-wm46-gchr-6vgg.json b/advisories/unreviewed/2022/05/GHSA-wm46-gchr-6vgg/GHSA-wm46-gchr-6vgg.json index d4e720a76de..a1ddcf3d6ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm46-gchr-6vgg/GHSA-wm46-gchr-6vgg.json +++ b/advisories/unreviewed/2022/05/GHSA-wm46-gchr-6vgg/GHSA-wm46-gchr-6vgg.json @@ -7,12 +7,8 @@ "CVE-2021-28209" ], "details": "The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmhg-j6wx-r9rg/GHSA-wmhg-j6wx-r9rg.json b/advisories/unreviewed/2022/05/GHSA-wmhg-j6wx-r9rg/GHSA-wmhg-j6wx-r9rg.json index d81ef7a912d..87897ba7759 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmhg-j6wx-r9rg/GHSA-wmhg-j6wx-r9rg.json +++ b/advisories/unreviewed/2022/05/GHSA-wmhg-j6wx-r9rg/GHSA-wmhg-j6wx-r9rg.json @@ -7,12 +7,8 @@ "CVE-2008-3229" ], "details": "Stack-based buffer overflow in op before Changeset 563, when xauth support is enabled, allows local users to gain privileges via a long XAUTHORITY environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmmj-gjqw-jvhf/GHSA-wmmj-gjqw-jvhf.json b/advisories/unreviewed/2022/05/GHSA-wmmj-gjqw-jvhf/GHSA-wmmj-gjqw-jvhf.json index 2da475d8995..4a7e7484243 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmmj-gjqw-jvhf/GHSA-wmmj-gjqw-jvhf.json +++ b/advisories/unreviewed/2022/05/GHSA-wmmj-gjqw-jvhf/GHSA-wmmj-gjqw-jvhf.json @@ -7,12 +7,8 @@ "CVE-2021-24251" ], "details": "The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp6x-79v3-v6j2/GHSA-wp6x-79v3-v6j2.json b/advisories/unreviewed/2022/05/GHSA-wp6x-79v3-v6j2/GHSA-wp6x-79v3-v6j2.json index ba80408e469..0f790ecc777 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp6x-79v3-v6j2/GHSA-wp6x-79v3-v6j2.json +++ b/advisories/unreviewed/2022/05/GHSA-wp6x-79v3-v6j2/GHSA-wp6x-79v3-v6j2.json @@ -7,12 +7,8 @@ "CVE-2019-18248" ], "details": "BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to the BIOTRONIK Remote Communication infrastructure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp7h-xq2m-vg36/GHSA-wp7h-xq2m-vg36.json b/advisories/unreviewed/2022/05/GHSA-wp7h-xq2m-vg36/GHSA-wp7h-xq2m-vg36.json index adb751f4f44..e816da8c7d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp7h-xq2m-vg36/GHSA-wp7h-xq2m-vg36.json +++ b/advisories/unreviewed/2022/05/GHSA-wp7h-xq2m-vg36/GHSA-wp7h-xq2m-vg36.json @@ -7,12 +7,8 @@ "CVE-2008-3684" ], "details": "Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wq3f-8fvg-8rw6/GHSA-wq3f-8fvg-8rw6.json b/advisories/unreviewed/2022/05/GHSA-wq3f-8fvg-8rw6/GHSA-wq3f-8fvg-8rw6.json index e6255e44483..0a34ca93c17 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq3f-8fvg-8rw6/GHSA-wq3f-8fvg-8rw6.json +++ b/advisories/unreviewed/2022/05/GHSA-wq3f-8fvg-8rw6/GHSA-wq3f-8fvg-8rw6.json @@ -7,12 +7,8 @@ "CVE-2008-3580" ], "details": "Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wq73-mhj6-vjhc/GHSA-wq73-mhj6-vjhc.json b/advisories/unreviewed/2022/05/GHSA-wq73-mhj6-vjhc/GHSA-wq73-mhj6-vjhc.json index d422618a60f..4f718e2516a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq73-mhj6-vjhc/GHSA-wq73-mhj6-vjhc.json +++ b/advisories/unreviewed/2022/05/GHSA-wq73-mhj6-vjhc/GHSA-wq73-mhj6-vjhc.json @@ -7,12 +7,8 @@ "CVE-2008-3792" ], "details": "net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (NULL pointer dereference and panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst, (7) sctp_getsockopt_active_key, (8) sctp_getsockopt_peer_auth_chunks, or (9) sctp_getsockopt_local_auth_chunks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr8r-jchq-frxg/GHSA-wr8r-jchq-frxg.json b/advisories/unreviewed/2022/05/GHSA-wr8r-jchq-frxg/GHSA-wr8r-jchq-frxg.json index 6f25c286f5d..ecac14f62b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr8r-jchq-frxg/GHSA-wr8r-jchq-frxg.json +++ b/advisories/unreviewed/2022/05/GHSA-wr8r-jchq-frxg/GHSA-wr8r-jchq-frxg.json @@ -7,12 +7,8 @@ "CVE-2008-3406" ], "details": "SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrwg-x39f-9cmf/GHSA-wrwg-x39f-9cmf.json b/advisories/unreviewed/2022/05/GHSA-wrwg-x39f-9cmf/GHSA-wrwg-x39f-9cmf.json index 4aadb89c22f..eaf84b89e0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrwg-x39f-9cmf/GHSA-wrwg-x39f-9cmf.json +++ b/advisories/unreviewed/2022/05/GHSA-wrwg-x39f-9cmf/GHSA-wrwg-x39f-9cmf.json @@ -7,12 +7,8 @@ "CVE-2021-27887" ], "details": "Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrxh-pj75-2vvf/GHSA-wrxh-pj75-2vvf.json b/advisories/unreviewed/2022/05/GHSA-wrxh-pj75-2vvf/GHSA-wrxh-pj75-2vvf.json index ec66fde7ee6..52faf6d413c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrxh-pj75-2vvf/GHSA-wrxh-pj75-2vvf.json +++ b/advisories/unreviewed/2022/05/GHSA-wrxh-pj75-2vvf/GHSA-wrxh-pj75-2vvf.json @@ -7,12 +7,8 @@ "CVE-2008-3452" ], "details": "SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww4h-cg63-x3wx/GHSA-ww4h-cg63-x3wx.json b/advisories/unreviewed/2022/05/GHSA-ww4h-cg63-x3wx/GHSA-ww4h-cg63-x3wx.json index daf5cc9dcc1..c1cff99f6e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww4h-cg63-x3wx/GHSA-ww4h-cg63-x3wx.json +++ b/advisories/unreviewed/2022/05/GHSA-ww4h-cg63-x3wx/GHSA-ww4h-cg63-x3wx.json @@ -7,12 +7,8 @@ "CVE-2008-3573" ], "details": "The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww4m-hgqp-q9hp/GHSA-ww4m-hgqp-q9hp.json b/advisories/unreviewed/2022/05/GHSA-ww4m-hgqp-q9hp/GHSA-ww4m-hgqp-q9hp.json index b4179a0fc14..4cc24f211c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww4m-hgqp-q9hp/GHSA-ww4m-hgqp-q9hp.json +++ b/advisories/unreviewed/2022/05/GHSA-ww4m-hgqp-q9hp/GHSA-ww4m-hgqp-q9hp.json @@ -7,12 +7,8 @@ "CVE-2008-3532" ], "details": "The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwwq-6cv7-vm56/GHSA-wwwq-6cv7-vm56.json b/advisories/unreviewed/2022/05/GHSA-wwwq-6cv7-vm56/GHSA-wwwq-6cv7-vm56.json index 87ad237893b..3647bc40c27 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwwq-6cv7-vm56/GHSA-wwwq-6cv7-vm56.json +++ b/advisories/unreviewed/2022/05/GHSA-wwwq-6cv7-vm56/GHSA-wwwq-6cv7-vm56.json @@ -7,12 +7,8 @@ "CVE-2008-3686" ], "details": "The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which triggers a NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwwx-fgw9-364c/GHSA-wwwx-fgw9-364c.json b/advisories/unreviewed/2022/05/GHSA-wwwx-fgw9-364c/GHSA-wwwx-fgw9-364c.json index 66f9d1a1628..f5eef8e8b8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwwx-fgw9-364c/GHSA-wwwx-fgw9-364c.json +++ b/advisories/unreviewed/2022/05/GHSA-wwwx-fgw9-364c/GHSA-wwwx-fgw9-364c.json @@ -7,12 +7,8 @@ "CVE-2020-4778" ], "details": "IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram application. IBM X-Force ID: 189156.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwxr-688j-6wxx/GHSA-wwxr-688j-6wxx.json b/advisories/unreviewed/2022/05/GHSA-wwxr-688j-6wxx/GHSA-wwxr-688j-6wxx.json index 079d865d6a8..08696d4e48c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwxr-688j-6wxx/GHSA-wwxr-688j-6wxx.json +++ b/advisories/unreviewed/2022/05/GHSA-wwxr-688j-6wxx/GHSA-wwxr-688j-6wxx.json @@ -7,12 +7,8 @@ "CVE-2020-8471" ], "details": "For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, weak file permissions allow an authenticated attacker to block the license handling, escalate his/her privileges and execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx32-m2f2-4j6p/GHSA-wx32-m2f2-4j6p.json b/advisories/unreviewed/2022/05/GHSA-wx32-m2f2-4j6p/GHSA-wx32-m2f2-4j6p.json index 91eb8f42501..242d32a1218 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx32-m2f2-4j6p/GHSA-wx32-m2f2-4j6p.json +++ b/advisories/unreviewed/2022/05/GHSA-wx32-m2f2-4j6p/GHSA-wx32-m2f2-4j6p.json @@ -7,12 +7,8 @@ "CVE-2008-3473" ], "details": "Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka \"Event Handling Cross-Domain Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx48-g6pf-jvc9/GHSA-wx48-g6pf-jvc9.json b/advisories/unreviewed/2022/05/GHSA-wx48-g6pf-jvc9/GHSA-wx48-g6pf-jvc9.json index 57a683957e0..4a6d4ffbd98 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx48-g6pf-jvc9/GHSA-wx48-g6pf-jvc9.json +++ b/advisories/unreviewed/2022/05/GHSA-wx48-g6pf-jvc9/GHSA-wx48-g6pf-jvc9.json @@ -7,12 +7,8 @@ "CVE-2008-3219" ], "details": "The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not \"prevent use of the object HTML tag in administrator input,\" which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx4j-99r4-v8wg/GHSA-wx4j-99r4-v8wg.json b/advisories/unreviewed/2022/05/GHSA-wx4j-99r4-v8wg/GHSA-wx4j-99r4-v8wg.json index e24ef5a25a1..7b1a4305ce9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx4j-99r4-v8wg/GHSA-wx4j-99r4-v8wg.json +++ b/advisories/unreviewed/2022/05/GHSA-wx4j-99r4-v8wg/GHSA-wx4j-99r4-v8wg.json @@ -7,12 +7,8 @@ "CVE-2021-25966" ], "details": "In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxj2-9mc8-8xq5/GHSA-wxj2-9mc8-8xq5.json b/advisories/unreviewed/2022/05/GHSA-wxj2-9mc8-8xq5/GHSA-wxj2-9mc8-8xq5.json index dd998fa74af..1bc991750a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxj2-9mc8-8xq5/GHSA-wxj2-9mc8-8xq5.json +++ b/advisories/unreviewed/2022/05/GHSA-wxj2-9mc8-8xq5/GHSA-wxj2-9mc8-8xq5.json @@ -7,12 +7,8 @@ "CVE-2008-3572" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Pligg 9.9.5 allows remote attackers to inject arbitrary web script or HTML via the category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxw5-4mj8-2m98/GHSA-wxw5-4mj8-2m98.json b/advisories/unreviewed/2022/05/GHSA-wxw5-4mj8-2m98/GHSA-wxw5-4mj8-2m98.json index 3f513d86b26..dfa29e0321a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxw5-4mj8-2m98/GHSA-wxw5-4mj8-2m98.json +++ b/advisories/unreviewed/2022/05/GHSA-wxw5-4mj8-2m98/GHSA-wxw5-4mj8-2m98.json @@ -7,12 +7,8 @@ "CVE-2019-5172" ], "details": "An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e840 the extracted ntp value from the xml file is used as an argument to /etc/config-tools/config_sntp time-server-%d= using sprintf(). This command is later executed via a call to system(). This is done in a loop and there is no limit to how many ntp entries will be parsed from the xml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2v2-2jhp-c5hv/GHSA-x2v2-2jhp-c5hv.json b/advisories/unreviewed/2022/05/GHSA-x2v2-2jhp-c5hv/GHSA-x2v2-2jhp-c5hv.json index ec85ca98dcd..5186571348b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2v2-2jhp-c5hv/GHSA-x2v2-2jhp-c5hv.json +++ b/advisories/unreviewed/2022/05/GHSA-x2v2-2jhp-c5hv/GHSA-x2v2-2jhp-c5hv.json @@ -7,12 +7,8 @@ "CVE-2021-36027" ], "details": "Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x322-xc54-ggg3/GHSA-x322-xc54-ggg3.json b/advisories/unreviewed/2022/05/GHSA-x322-xc54-ggg3/GHSA-x322-xc54-ggg3.json index 923dd006fb6..bd68f33ddca 100644 --- a/advisories/unreviewed/2022/05/GHSA-x322-xc54-ggg3/GHSA-x322-xc54-ggg3.json +++ b/advisories/unreviewed/2022/05/GHSA-x322-xc54-ggg3/GHSA-x322-xc54-ggg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x32h-xc6r-gqf2/GHSA-x32h-xc6r-gqf2.json b/advisories/unreviewed/2022/05/GHSA-x32h-xc6r-gqf2/GHSA-x32h-xc6r-gqf2.json index a7871c1b73f..47892e771c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x32h-xc6r-gqf2/GHSA-x32h-xc6r-gqf2.json +++ b/advisories/unreviewed/2022/05/GHSA-x32h-xc6r-gqf2/GHSA-x32h-xc6r-gqf2.json @@ -7,12 +7,8 @@ "CVE-2008-3261" ], "details": "Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x34x-jj7g-95j8/GHSA-x34x-jj7g-95j8.json b/advisories/unreviewed/2022/05/GHSA-x34x-jj7g-95j8/GHSA-x34x-jj7g-95j8.json index bf810250dfe..3798b12abf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x34x-jj7g-95j8/GHSA-x34x-jj7g-95j8.json +++ b/advisories/unreviewed/2022/05/GHSA-x34x-jj7g-95j8/GHSA-x34x-jj7g-95j8.json @@ -7,12 +7,8 @@ "CVE-2008-3687" ], "details": "Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3wg-p2fp-rpxq/GHSA-x3wg-p2fp-rpxq.json b/advisories/unreviewed/2022/05/GHSA-x3wg-p2fp-rpxq/GHSA-x3wg-p2fp-rpxq.json index 6eeb15721da..208a2d80dfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3wg-p2fp-rpxq/GHSA-x3wg-p2fp-rpxq.json +++ b/advisories/unreviewed/2022/05/GHSA-x3wg-p2fp-rpxq/GHSA-x3wg-p2fp-rpxq.json @@ -7,12 +7,8 @@ "CVE-2020-8142" ], "details": "A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change the e-mail address or the password. It was however possible for anyone with access to a Revive Adserver admin user interface to bypass such check and change e-email address or password of the currently logged in user by altering the form payload.The attack requires physical access to the user interface of a logged in user. If the POST payload was altered by turning the “pwold” parameter into an array, Revive Adserver would fetch and authorise the operation even if no password was provided.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x556-3584-m3v7/GHSA-x556-3584-m3v7.json b/advisories/unreviewed/2022/05/GHSA-x556-3584-m3v7/GHSA-x556-3584-m3v7.json index e8649d19911..86b464ffd01 100644 --- a/advisories/unreviewed/2022/05/GHSA-x556-3584-m3v7/GHSA-x556-3584-m3v7.json +++ b/advisories/unreviewed/2022/05/GHSA-x556-3584-m3v7/GHSA-x556-3584-m3v7.json @@ -7,12 +7,8 @@ "CVE-2008-3704" ], "details": "Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not \"validating property values with boundary checks,\" as exploited in the wild in August 2008, aka \"Masked Edit Control Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x58x-95ff-fvvp/GHSA-x58x-95ff-fvvp.json b/advisories/unreviewed/2022/05/GHSA-x58x-95ff-fvvp/GHSA-x58x-95ff-fvvp.json index 400bfb595dd..e85b0ba074a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x58x-95ff-fvvp/GHSA-x58x-95ff-fvvp.json +++ b/advisories/unreviewed/2022/05/GHSA-x58x-95ff-fvvp/GHSA-x58x-95ff-fvvp.json @@ -7,12 +7,8 @@ "CVE-2021-3034" ], "details": "An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the ‘/var/log/demisto/’ server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2 builds earlier than 98623; Cortex XSOAR 6.1.0 builds earlier than 848144.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5gp-5p79-9xh8/GHSA-x5gp-5p79-9xh8.json b/advisories/unreviewed/2022/05/GHSA-x5gp-5p79-9xh8/GHSA-x5gp-5p79-9xh8.json index 46ca31e398f..5320439abed 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5gp-5p79-9xh8/GHSA-x5gp-5p79-9xh8.json +++ b/advisories/unreviewed/2022/05/GHSA-x5gp-5p79-9xh8/GHSA-x5gp-5p79-9xh8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5hx-jq5q-rrgr/GHSA-x5hx-jq5q-rrgr.json b/advisories/unreviewed/2022/05/GHSA-x5hx-jq5q-rrgr/GHSA-x5hx-jq5q-rrgr.json index 7459a837838..cbae960433f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5hx-jq5q-rrgr/GHSA-x5hx-jq5q-rrgr.json +++ b/advisories/unreviewed/2022/05/GHSA-x5hx-jq5q-rrgr/GHSA-x5hx-jq5q-rrgr.json @@ -7,12 +7,8 @@ "CVE-2021-33073" ], "details": "Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5qv-3jp4-jf27/GHSA-x5qv-3jp4-jf27.json b/advisories/unreviewed/2022/05/GHSA-x5qv-3jp4-jf27/GHSA-x5qv-3jp4-jf27.json index 47329610321..e9cce0df0d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5qv-3jp4-jf27/GHSA-x5qv-3jp4-jf27.json +++ b/advisories/unreviewed/2022/05/GHSA-x5qv-3jp4-jf27/GHSA-x5qv-3jp4-jf27.json @@ -7,12 +7,8 @@ "CVE-2008-3374" ], "details": "SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5xf-58qf-fq5q/GHSA-x5xf-58qf-fq5q.json b/advisories/unreviewed/2022/05/GHSA-x5xf-58qf-fq5q/GHSA-x5xf-58qf-fq5q.json index 0d5d17681a8..99885386626 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5xf-58qf-fq5q/GHSA-x5xf-58qf-fq5q.json +++ b/advisories/unreviewed/2022/05/GHSA-x5xf-58qf-fq5q/GHSA-x5xf-58qf-fq5q.json @@ -7,12 +7,8 @@ "CVE-2008-3568" ], "details": "Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote attackers to include and execute arbitrary local files via a full pathname in the Dirroot parameter, a different vulnerability than CVE-2006-4890.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6c6-rqqc-c89m/GHSA-x6c6-rqqc-c89m.json b/advisories/unreviewed/2022/05/GHSA-x6c6-rqqc-c89m/GHSA-x6c6-rqqc-c89m.json index 2f12f4c51a4..7356b7bedb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6c6-rqqc-c89m/GHSA-x6c6-rqqc-c89m.json +++ b/advisories/unreviewed/2022/05/GHSA-x6c6-rqqc-c89m/GHSA-x6c6-rqqc-c89m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6jh-q873-9r7x/GHSA-x6jh-q873-9r7x.json b/advisories/unreviewed/2022/05/GHSA-x6jh-q873-9r7x/GHSA-x6jh-q873-9r7x.json index 295c70a63c7..9279b6b08e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6jh-q873-9r7x/GHSA-x6jh-q873-9r7x.json +++ b/advisories/unreviewed/2022/05/GHSA-x6jh-q873-9r7x/GHSA-x6jh-q873-9r7x.json @@ -7,12 +7,8 @@ "CVE-2008-3774" ], "details": "SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6r5-r6wc-9hgq/GHSA-x6r5-r6wc-9hgq.json b/advisories/unreviewed/2022/05/GHSA-x6r5-r6wc-9hgq/GHSA-x6r5-r6wc-9hgq.json index 5021f9bf001..44223b712d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6r5-r6wc-9hgq/GHSA-x6r5-r6wc-9hgq.json +++ b/advisories/unreviewed/2022/05/GHSA-x6r5-r6wc-9hgq/GHSA-x6r5-r6wc-9hgq.json @@ -7,12 +7,8 @@ "CVE-2008-3513" ], "details": "SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6v4-jh5f-25pv/GHSA-x6v4-jh5f-25pv.json b/advisories/unreviewed/2022/05/GHSA-x6v4-jh5f-25pv/GHSA-x6v4-jh5f-25pv.json index 09780466963..62a507500ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6v4-jh5f-25pv/GHSA-x6v4-jh5f-25pv.json +++ b/advisories/unreviewed/2022/05/GHSA-x6v4-jh5f-25pv/GHSA-x6v4-jh5f-25pv.json @@ -7,12 +7,8 @@ "CVE-2021-42329" ], "details": "The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x79q-7f37-g9qq/GHSA-x79q-7f37-g9qq.json b/advisories/unreviewed/2022/05/GHSA-x79q-7f37-g9qq/GHSA-x79q-7f37-g9qq.json index 19f56cb818f..eb631ca0ea4 100644 --- a/advisories/unreviewed/2022/05/GHSA-x79q-7f37-g9qq/GHSA-x79q-7f37-g9qq.json +++ b/advisories/unreviewed/2022/05/GHSA-x79q-7f37-g9qq/GHSA-x79q-7f37-g9qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x863-92xc-p6xw/GHSA-x863-92xc-p6xw.json b/advisories/unreviewed/2022/05/GHSA-x863-92xc-p6xw/GHSA-x863-92xc-p6xw.json index c4296d9e6b9..5ecd888ea4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x863-92xc-p6xw/GHSA-x863-92xc-p6xw.json +++ b/advisories/unreviewed/2022/05/GHSA-x863-92xc-p6xw/GHSA-x863-92xc-p6xw.json @@ -7,12 +7,8 @@ "CVE-2008-3415" ], "details": "Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bit parameter, as demonstrated by an upload to avatar/ of a .jpg file containing PHP sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9wv-c8jw-pvg5/GHSA-x9wv-c8jw-pvg5.json b/advisories/unreviewed/2022/05/GHSA-x9wv-c8jw-pvg5/GHSA-x9wv-c8jw-pvg5.json index e0d89785681..c374c91e3b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9wv-c8jw-pvg5/GHSA-x9wv-c8jw-pvg5.json +++ b/advisories/unreviewed/2022/05/GHSA-x9wv-c8jw-pvg5/GHSA-x9wv-c8jw-pvg5.json @@ -7,12 +7,8 @@ "CVE-2021-22859" ], "details": "The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9x9-w57q-4pwm/GHSA-x9x9-w57q-4pwm.json b/advisories/unreviewed/2022/05/GHSA-x9x9-w57q-4pwm/GHSA-x9x9-w57q-4pwm.json index c74728bd4ca..026e8387ddb 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9x9-w57q-4pwm/GHSA-x9x9-w57q-4pwm.json +++ b/advisories/unreviewed/2022/05/GHSA-x9x9-w57q-4pwm/GHSA-x9x9-w57q-4pwm.json @@ -7,12 +7,8 @@ "CVE-2008-2314" ], "details": "Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcfh-h8m8-532v/GHSA-xcfh-h8m8-532v.json b/advisories/unreviewed/2022/05/GHSA-xcfh-h8m8-532v/GHSA-xcfh-h8m8-532v.json index 7d7f282a72a..9b93247b345 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcfh-h8m8-532v/GHSA-xcfh-h8m8-532v.json +++ b/advisories/unreviewed/2022/05/GHSA-xcfh-h8m8-532v/GHSA-xcfh-h8m8-532v.json @@ -7,12 +7,8 @@ "CVE-2020-7546" ], "details": "A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an affected webpage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcgj-2vw3-2j5p/GHSA-xcgj-2vw3-2j5p.json b/advisories/unreviewed/2022/05/GHSA-xcgj-2vw3-2j5p/GHSA-xcgj-2vw3-2j5p.json index f17181075e7..6c2cd2c9de9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcgj-2vw3-2j5p/GHSA-xcgj-2vw3-2j5p.json +++ b/advisories/unreviewed/2022/05/GHSA-xcgj-2vw3-2j5p/GHSA-xcgj-2vw3-2j5p.json @@ -7,12 +7,8 @@ "CVE-2021-24264" ], "details": "The “Image Hover Effects – Elementor Addonâ€? WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfjv-86fq-cc83/GHSA-xfjv-86fq-cc83.json b/advisories/unreviewed/2022/05/GHSA-xfjv-86fq-cc83/GHSA-xfjv-86fq-cc83.json index ddb51201311..a5e5d70eb2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfjv-86fq-cc83/GHSA-xfjv-86fq-cc83.json +++ b/advisories/unreviewed/2022/05/GHSA-xfjv-86fq-cc83/GHSA-xfjv-86fq-cc83.json @@ -7,12 +7,8 @@ "CVE-2008-3538" ], "details": "Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it should be for HP Enterprise Discovery.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfqr-hhpm-c4xx/GHSA-xfqr-hhpm-c4xx.json b/advisories/unreviewed/2022/05/GHSA-xfqr-hhpm-c4xx/GHSA-xfqr-hhpm-c4xx.json index b367eb6f90b..de4bad9e4b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfqr-hhpm-c4xx/GHSA-xfqr-hhpm-c4xx.json +++ b/advisories/unreviewed/2022/05/GHSA-xfqr-hhpm-c4xx/GHSA-xfqr-hhpm-c4xx.json @@ -7,12 +7,8 @@ "CVE-2021-25983" ], "details": "In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “tags” and “category” parameters in the URL. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfv3-wp5f-h673/GHSA-xfv3-wp5f-h673.json b/advisories/unreviewed/2022/05/GHSA-xfv3-wp5f-h673/GHSA-xfv3-wp5f-h673.json index e8220117bf0..edd9d4e909a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfv3-wp5f-h673/GHSA-xfv3-wp5f-h673.json +++ b/advisories/unreviewed/2022/05/GHSA-xfv3-wp5f-h673/GHSA-xfv3-wp5f-h673.json @@ -7,12 +7,8 @@ "CVE-2008-3215" ], "details": "libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: this issue exists because of an incomplete fix for CVE-2008-2713.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfvr-xq7r-qx2q/GHSA-xfvr-xq7r-qx2q.json b/advisories/unreviewed/2022/05/GHSA-xfvr-xq7r-qx2q/GHSA-xfvr-xq7r-qx2q.json index 4dc7c75a492..525ac3920da 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfvr-xq7r-qx2q/GHSA-xfvr-xq7r-qx2q.json +++ b/advisories/unreviewed/2022/05/GHSA-xfvr-xq7r-qx2q/GHSA-xfvr-xq7r-qx2q.json @@ -7,12 +7,8 @@ "CVE-2008-3422" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg4x-58xv-5259/GHSA-xg4x-58xv-5259.json b/advisories/unreviewed/2022/05/GHSA-xg4x-58xv-5259/GHSA-xg4x-58xv-5259.json index 7f7c7e7823f..71ad899830f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg4x-58xv-5259/GHSA-xg4x-58xv-5259.json +++ b/advisories/unreviewed/2022/05/GHSA-xg4x-58xv-5259/GHSA-xg4x-58xv-5259.json @@ -7,12 +7,8 @@ "CVE-2008-3307" ], "details": "SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh4v-c72r-55p6/GHSA-xh4v-c72r-55p6.json b/advisories/unreviewed/2022/05/GHSA-xh4v-c72r-55p6/GHSA-xh4v-c72r-55p6.json index a2a13021e64..cbdb58bbe27 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh4v-c72r-55p6/GHSA-xh4v-c72r-55p6.json +++ b/advisories/unreviewed/2022/05/GHSA-xh4v-c72r-55p6/GHSA-xh4v-c72r-55p6.json @@ -7,12 +7,8 @@ "CVE-2021-22790" ], "details": "A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh64-3cxr-cqq7/GHSA-xh64-3cxr-cqq7.json b/advisories/unreviewed/2022/05/GHSA-xh64-3cxr-cqq7/GHSA-xh64-3cxr-cqq7.json index 78a14b46d7e..5d0e93cfa1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh64-3cxr-cqq7/GHSA-xh64-3cxr-cqq7.json +++ b/advisories/unreviewed/2022/05/GHSA-xh64-3cxr-cqq7/GHSA-xh64-3cxr-cqq7.json @@ -7,12 +7,8 @@ "CVE-2008-3433" ], "details": "SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh8q-wvvw-q9w3/GHSA-xh8q-wvvw-q9w3.json b/advisories/unreviewed/2022/05/GHSA-xh8q-wvvw-q9w3/GHSA-xh8q-wvvw-q9w3.json index c81d1efaef4..4f703295d52 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh8q-wvvw-q9w3/GHSA-xh8q-wvvw-q9w3.json +++ b/advisories/unreviewed/2022/05/GHSA-xh8q-wvvw-q9w3/GHSA-xh8q-wvvw-q9w3.json @@ -7,12 +7,8 @@ "CVE-2021-40711" ], "details": "Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve server-side denial of service. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhc7-qp6w-xmwm/GHSA-xhc7-qp6w-xmwm.json b/advisories/unreviewed/2022/05/GHSA-xhc7-qp6w-xmwm/GHSA-xhc7-qp6w-xmwm.json index 126abb0387a..d749098b89a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhc7-qp6w-xmwm/GHSA-xhc7-qp6w-xmwm.json +++ b/advisories/unreviewed/2022/05/GHSA-xhc7-qp6w-xmwm/GHSA-xhc7-qp6w-xmwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhfv-xvjm-pqh5/GHSA-xhfv-xvjm-pqh5.json b/advisories/unreviewed/2022/05/GHSA-xhfv-xvjm-pqh5/GHSA-xhfv-xvjm-pqh5.json index 9bcb6f1d8ed..9baf0c6f4b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhfv-xvjm-pqh5/GHSA-xhfv-xvjm-pqh5.json +++ b/advisories/unreviewed/2022/05/GHSA-xhfv-xvjm-pqh5/GHSA-xhfv-xvjm-pqh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhgx-q9xg-fg3q/GHSA-xhgx-q9xg-fg3q.json b/advisories/unreviewed/2022/05/GHSA-xhgx-q9xg-fg3q/GHSA-xhgx-q9xg-fg3q.json index dfef6fc1752..001296e4352 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhgx-q9xg-fg3q/GHSA-xhgx-q9xg-fg3q.json +++ b/advisories/unreviewed/2022/05/GHSA-xhgx-q9xg-fg3q/GHSA-xhgx-q9xg-fg3q.json @@ -7,12 +7,8 @@ "CVE-2019-6195" ], "details": "An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xj3x-55gf-j7q8/GHSA-xj3x-55gf-j7q8.json b/advisories/unreviewed/2022/05/GHSA-xj3x-55gf-j7q8/GHSA-xj3x-55gf-j7q8.json index 0c7fec2bd9b..e208fd929b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj3x-55gf-j7q8/GHSA-xj3x-55gf-j7q8.json +++ b/advisories/unreviewed/2022/05/GHSA-xj3x-55gf-j7q8/GHSA-xj3x-55gf-j7q8.json @@ -7,12 +7,8 @@ "CVE-2008-3317" ], "details": "admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmq3-w762-fqmr/GHSA-xmq3-w762-fqmr.json b/advisories/unreviewed/2022/05/GHSA-xmq3-w762-fqmr/GHSA-xmq3-w762-fqmr.json index ef9a9c96346..16f7ce0978a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmq3-w762-fqmr/GHSA-xmq3-w762-fqmr.json +++ b/advisories/unreviewed/2022/05/GHSA-xmq3-w762-fqmr/GHSA-xmq3-w762-fqmr.json @@ -7,12 +7,8 @@ "CVE-2020-9732" ], "details": "The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpcc-cjr7-mgvm/GHSA-xpcc-cjr7-mgvm.json b/advisories/unreviewed/2022/05/GHSA-xpcc-cjr7-mgvm/GHSA-xpcc-cjr7-mgvm.json index 6f61137ef83..4c539d18788 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpcc-cjr7-mgvm/GHSA-xpcc-cjr7-mgvm.json +++ b/advisories/unreviewed/2022/05/GHSA-xpcc-cjr7-mgvm/GHSA-xpcc-cjr7-mgvm.json @@ -7,12 +7,8 @@ "CVE-2020-0583" ], "details": "Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentially enable escalation of privilege via local access. This affects Intel® Smart Sound Technology before versions: 10th Generation Intel® Core™ i7 Processors, version 3431 and 8th Generation Intel® Core™ Processors, version 3349.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xph6-frvr-hq8f/GHSA-xph6-frvr-hq8f.json b/advisories/unreviewed/2022/05/GHSA-xph6-frvr-hq8f/GHSA-xph6-frvr-hq8f.json index 8559a965fda..6f1889be531 100644 --- a/advisories/unreviewed/2022/05/GHSA-xph6-frvr-hq8f/GHSA-xph6-frvr-hq8f.json +++ b/advisories/unreviewed/2022/05/GHSA-xph6-frvr-hq8f/GHSA-xph6-frvr-hq8f.json @@ -7,12 +7,8 @@ "CVE-2021-29954" ], "details": "Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpwf-6m43-7f68/GHSA-xpwf-6m43-7f68.json b/advisories/unreviewed/2022/05/GHSA-xpwf-6m43-7f68/GHSA-xpwf-6m43-7f68.json index b7ee7f25497..7d642af62a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpwf-6m43-7f68/GHSA-xpwf-6m43-7f68.json +++ b/advisories/unreviewed/2022/05/GHSA-xpwf-6m43-7f68/GHSA-xpwf-6m43-7f68.json @@ -7,12 +7,8 @@ "CVE-2008-3477" ], "details": "Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka \"Calendar Object Validation Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json b/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json index edcd7b69388..34107c22caf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json +++ b/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq77-398p-x2hj/GHSA-xq77-398p-x2hj.json b/advisories/unreviewed/2022/05/GHSA-xq77-398p-x2hj/GHSA-xq77-398p-x2hj.json index dff9a3d95d2..849f91edb50 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq77-398p-x2hj/GHSA-xq77-398p-x2hj.json +++ b/advisories/unreviewed/2022/05/GHSA-xq77-398p-x2hj/GHSA-xq77-398p-x2hj.json @@ -7,12 +7,8 @@ "CVE-2021-24266" ], "details": "The “The Plus Addons for Elementor Page Builder Liteâ€? WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqhw-rfc8-5rgf/GHSA-xqhw-rfc8-5rgf.json b/advisories/unreviewed/2022/05/GHSA-xqhw-rfc8-5rgf/GHSA-xqhw-rfc8-5rgf.json index 5603c1fe456..0c1874ab48a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqhw-rfc8-5rgf/GHSA-xqhw-rfc8-5rgf.json +++ b/advisories/unreviewed/2022/05/GHSA-xqhw-rfc8-5rgf/GHSA-xqhw-rfc8-5rgf.json @@ -7,12 +7,8 @@ "CVE-2020-26505" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker to perform unauthorized actions in the application on behalf of legitimate users or spread malware via the application. By using the “Assets Upload” function, an attacker can abuse the upload function to upload a malicious PDF file containing a stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqqq-qrvp-j2jg/GHSA-xqqq-qrvp-j2jg.json b/advisories/unreviewed/2022/05/GHSA-xqqq-qrvp-j2jg/GHSA-xqqq-qrvp-j2jg.json index d8e37dbc328..44fc4ef568f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqqq-qrvp-j2jg/GHSA-xqqq-qrvp-j2jg.json +++ b/advisories/unreviewed/2022/05/GHSA-xqqq-qrvp-j2jg/GHSA-xqqq-qrvp-j2jg.json @@ -7,12 +7,8 @@ "CVE-2008-3456" ], "details": "phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqxx-r4pj-7cv5/GHSA-xqxx-r4pj-7cv5.json b/advisories/unreviewed/2022/05/GHSA-xqxx-r4pj-7cv5/GHSA-xqxx-r4pj-7cv5.json index 22532591c56..eb1a3ee011e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqxx-r4pj-7cv5/GHSA-xqxx-r4pj-7cv5.json +++ b/advisories/unreviewed/2022/05/GHSA-xqxx-r4pj-7cv5/GHSA-xqxx-r4pj-7cv5.json @@ -7,12 +7,8 @@ "CVE-2008-3315" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) query string to (a) announcements/messages.php; (b) lostPassword.php and (c) profile.php in auth/; (d) calendar/myagenda.php; (e) group/group.php; (f) learningPath.php, (g) learningPathList.php, and (h) module.php in learnPath/; (i) phpbb/index.php; (j) courseLog.php, (k) course_access_details.php, (l) delete_course_stats.php, (m) userLog.php, and (n) user_access_details.php in tracking/; (o) user/user.php; and (p) user/userInfo.php; the (2) view parameter to (q) tracking/courseLog.php; and the (3) toolId parameter to (r) tracking/toolaccess_details.php. NOTE: this may overlap CVE-2006-3257 and CVE-2005-1374.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr2h-wg3w-vrcr/GHSA-xr2h-wg3w-vrcr.json b/advisories/unreviewed/2022/05/GHSA-xr2h-wg3w-vrcr/GHSA-xr2h-wg3w-vrcr.json index c15b4bdc223..28f8d373d73 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr2h-wg3w-vrcr/GHSA-xr2h-wg3w-vrcr.json +++ b/advisories/unreviewed/2022/05/GHSA-xr2h-wg3w-vrcr/GHSA-xr2h-wg3w-vrcr.json @@ -7,12 +7,8 @@ "CVE-2008-3565" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr7f-3c69-r77f/GHSA-xr7f-3c69-r77f.json b/advisories/unreviewed/2022/05/GHSA-xr7f-3c69-r77f/GHSA-xr7f-3c69-r77f.json index 5e95df84126..ecfc9985b60 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr7f-3c69-r77f/GHSA-xr7f-3c69-r77f.json +++ b/advisories/unreviewed/2022/05/GHSA-xr7f-3c69-r77f/GHSA-xr7f-3c69-r77f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr8m-fvm3-765w/GHSA-xr8m-fvm3-765w.json b/advisories/unreviewed/2022/05/GHSA-xr8m-fvm3-765w/GHSA-xr8m-fvm3-765w.json index 90e74734584..9caf8be5616 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr8m-fvm3-765w/GHSA-xr8m-fvm3-765w.json +++ b/advisories/unreviewed/2022/05/GHSA-xr8m-fvm3-765w/GHSA-xr8m-fvm3-765w.json @@ -7,12 +7,8 @@ "CVE-2008-3210" ], "details": "rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrmj-v7v7-vhq3/GHSA-xrmj-v7v7-vhq3.json b/advisories/unreviewed/2022/05/GHSA-xrmj-v7v7-vhq3/GHSA-xrmj-v7v7-vhq3.json index ee3c31a8f84..fceda67f13b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrmj-v7v7-vhq3/GHSA-xrmj-v7v7-vhq3.json +++ b/advisories/unreviewed/2022/05/GHSA-xrmj-v7v7-vhq3/GHSA-xrmj-v7v7-vhq3.json @@ -7,12 +7,8 @@ "CVE-2008-3357" ], "details": "Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a \"pointer overwrite vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv52-8ff7-g4jf/GHSA-xv52-8ff7-g4jf.json b/advisories/unreviewed/2022/05/GHSA-xv52-8ff7-g4jf/GHSA-xv52-8ff7-g4jf.json index 15528a37cb7..291dbb645e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv52-8ff7-g4jf/GHSA-xv52-8ff7-g4jf.json +++ b/advisories/unreviewed/2022/05/GHSA-xv52-8ff7-g4jf/GHSA-xv52-8ff7-g4jf.json @@ -7,12 +7,8 @@ "CVE-2021-24669" ], "details": "The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvq3-j3j3-hfjp/GHSA-xvq3-j3j3-hfjp.json b/advisories/unreviewed/2022/05/GHSA-xvq3-j3j3-hfjp/GHSA-xvq3-j3j3-hfjp.json index 007d6bb727f..fc0810f6401 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvq3-j3j3-hfjp/GHSA-xvq3-j3j3-hfjp.json +++ b/advisories/unreviewed/2022/05/GHSA-xvq3-j3j3-hfjp/GHSA-xvq3-j3j3-hfjp.json @@ -7,12 +7,8 @@ "CVE-2008-3582" ], "details": "SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvwq-6652-7rm2/GHSA-xvwq-6652-7rm2.json b/advisories/unreviewed/2022/05/GHSA-xvwq-6652-7rm2/GHSA-xvwq-6652-7rm2.json index 220123787f2..d80fe6d25f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvwq-6652-7rm2/GHSA-xvwq-6652-7rm2.json +++ b/advisories/unreviewed/2022/05/GHSA-xvwq-6652-7rm2/GHSA-xvwq-6652-7rm2.json @@ -7,12 +7,8 @@ "CVE-2008-3781" ], "details": "Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw33-f5cf-9cw7/GHSA-xw33-f5cf-9cw7.json b/advisories/unreviewed/2022/05/GHSA-xw33-f5cf-9cw7/GHSA-xw33-f5cf-9cw7.json index 65a574d08e4..34c61f2b14f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw33-f5cf-9cw7/GHSA-xw33-f5cf-9cw7.json +++ b/advisories/unreviewed/2022/05/GHSA-xw33-f5cf-9cw7/GHSA-xw33-f5cf-9cw7.json @@ -7,12 +7,8 @@ "CVE-2008-3466" ], "details": "Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka \"HIS Command Execution Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw7r-78c6-fpj4/GHSA-xw7r-78c6-fpj4.json b/advisories/unreviewed/2022/05/GHSA-xw7r-78c6-fpj4/GHSA-xw7r-78c6-fpj4.json index e0722d6c462..be6eacc4938 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw7r-78c6-fpj4/GHSA-xw7r-78c6-fpj4.json +++ b/advisories/unreviewed/2022/05/GHSA-xw7r-78c6-fpj4/GHSA-xw7r-78c6-fpj4.json @@ -7,12 +7,8 @@ "CVE-2020-11496" ], "details": "Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks the validation of the input values on the device side, which is provided by the engineering software during parameterization. Attackers with access to local configuration files can therefore insert malicious commands that are executed after compiling them to valid parameter files (“PDLs”), transferring them to the device, and restarting the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxcm-3jff-m2m5/GHSA-xxcm-3jff-m2m5.json b/advisories/unreviewed/2022/05/GHSA-xxcm-3jff-m2m5/GHSA-xxcm-3jff-m2m5.json index 7b5a53f14e8..4068ca9836f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxcm-3jff-m2m5/GHSA-xxcm-3jff-m2m5.json +++ b/advisories/unreviewed/2022/05/GHSA-xxcm-3jff-m2m5/GHSA-xxcm-3jff-m2m5.json @@ -7,12 +7,8 @@ "CVE-2021-24166" ], "details": "The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxqm-cf86-wmxp/GHSA-xxqm-cf86-wmxp.json b/advisories/unreviewed/2022/05/GHSA-xxqm-cf86-wmxp/GHSA-xxqm-cf86-wmxp.json index 8efa8474b43..39be221c4e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxqm-cf86-wmxp/GHSA-xxqm-cf86-wmxp.json +++ b/advisories/unreviewed/2022/05/GHSA-xxqm-cf86-wmxp/GHSA-xxqm-cf86-wmxp.json @@ -7,12 +7,8 @@ "CVE-2008-3700" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxv6-ggg8-68mq/GHSA-xxv6-ggg8-68mq.json b/advisories/unreviewed/2022/05/GHSA-xxv6-ggg8-68mq/GHSA-xxv6-ggg8-68mq.json index 47824f96f6f..374ff07720b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxv6-ggg8-68mq/GHSA-xxv6-ggg8-68mq.json +++ b/advisories/unreviewed/2022/05/GHSA-xxv6-ggg8-68mq/GHSA-xxv6-ggg8-68mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-23qr-p57h-8gx4/GHSA-23qr-p57h-8gx4.json b/advisories/unreviewed/2022/06/GHSA-23qr-p57h-8gx4/GHSA-23qr-p57h-8gx4.json index ebf9f193a04..cd6fa05b8a8 100644 --- a/advisories/unreviewed/2022/06/GHSA-23qr-p57h-8gx4/GHSA-23qr-p57h-8gx4.json +++ b/advisories/unreviewed/2022/06/GHSA-23qr-p57h-8gx4/GHSA-23qr-p57h-8gx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/06/GHSA-34x8-rwh3-j65f/GHSA-34x8-rwh3-j65f.json b/advisories/unreviewed/2022/06/GHSA-34x8-rwh3-j65f/GHSA-34x8-rwh3-j65f.json index 283bad747df..a2940312afe 100644 --- a/advisories/unreviewed/2022/06/GHSA-34x8-rwh3-j65f/GHSA-34x8-rwh3-j65f.json +++ b/advisories/unreviewed/2022/06/GHSA-34x8-rwh3-j65f/GHSA-34x8-rwh3-j65f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json b/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json index 5d00401bcf1..9501555b6ec 100644 --- a/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json +++ b/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-w3cv-3c36-h8j2/GHSA-w3cv-3c36-h8j2.json b/advisories/unreviewed/2022/06/GHSA-w3cv-3c36-h8j2/GHSA-w3cv-3c36-h8j2.json index c27f698b567..5e7ae01f4e1 100644 --- a/advisories/unreviewed/2022/06/GHSA-w3cv-3c36-h8j2/GHSA-w3cv-3c36-h8j2.json +++ b/advisories/unreviewed/2022/06/GHSA-w3cv-3c36-h8j2/GHSA-w3cv-3c36-h8j2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-228q-26qq-7h4m/GHSA-228q-26qq-7h4m.json b/advisories/unreviewed/2022/07/GHSA-228q-26qq-7h4m/GHSA-228q-26qq-7h4m.json index 890ea61cbeb..6d1bb7ba24f 100644 --- a/advisories/unreviewed/2022/07/GHSA-228q-26qq-7h4m/GHSA-228q-26qq-7h4m.json +++ b/advisories/unreviewed/2022/07/GHSA-228q-26qq-7h4m/GHSA-228q-26qq-7h4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-267c-6463-gj35/GHSA-267c-6463-gj35.json b/advisories/unreviewed/2022/07/GHSA-267c-6463-gj35/GHSA-267c-6463-gj35.json index dd69a934fa0..b82b21e6c98 100644 --- a/advisories/unreviewed/2022/07/GHSA-267c-6463-gj35/GHSA-267c-6463-gj35.json +++ b/advisories/unreviewed/2022/07/GHSA-267c-6463-gj35/GHSA-267c-6463-gj35.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json b/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json index 8bea0802e78..cfb6e66c6e2 100644 --- a/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json +++ b/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-f6mg-vq2j-mhhq/GHSA-f6mg-vq2j-mhhq.json b/advisories/unreviewed/2022/07/GHSA-f6mg-vq2j-mhhq/GHSA-f6mg-vq2j-mhhq.json index 72fff95ead7..119b18e44e0 100644 --- a/advisories/unreviewed/2022/07/GHSA-f6mg-vq2j-mhhq/GHSA-f6mg-vq2j-mhhq.json +++ b/advisories/unreviewed/2022/07/GHSA-f6mg-vq2j-mhhq/GHSA-f6mg-vq2j-mhhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-fm9c-xcj2-2j5g/GHSA-fm9c-xcj2-2j5g.json b/advisories/unreviewed/2022/07/GHSA-fm9c-xcj2-2j5g/GHSA-fm9c-xcj2-2j5g.json index 898dd74536a..ea7f73b64a3 100644 --- a/advisories/unreviewed/2022/07/GHSA-fm9c-xcj2-2j5g/GHSA-fm9c-xcj2-2j5g.json +++ b/advisories/unreviewed/2022/07/GHSA-fm9c-xcj2-2j5g/GHSA-fm9c-xcj2-2j5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-j976-mwc8-7r2m/GHSA-j976-mwc8-7r2m.json b/advisories/unreviewed/2022/07/GHSA-j976-mwc8-7r2m/GHSA-j976-mwc8-7r2m.json index 28d92da8666..b67db287811 100644 --- a/advisories/unreviewed/2022/07/GHSA-j976-mwc8-7r2m/GHSA-j976-mwc8-7r2m.json +++ b/advisories/unreviewed/2022/07/GHSA-j976-mwc8-7r2m/GHSA-j976-mwc8-7r2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-q786-p393-rw6q/GHSA-q786-p393-rw6q.json b/advisories/unreviewed/2022/07/GHSA-q786-p393-rw6q/GHSA-q786-p393-rw6q.json index 379b1432d1e..362c5745bd2 100644 --- a/advisories/unreviewed/2022/07/GHSA-q786-p393-rw6q/GHSA-q786-p393-rw6q.json +++ b/advisories/unreviewed/2022/07/GHSA-q786-p393-rw6q/GHSA-q786-p393-rw6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json b/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json index 92b274fc214..a7091a9f023 100644 --- a/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json +++ b/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-vw5c-wp4c-pm7q/GHSA-vw5c-wp4c-pm7q.json b/advisories/unreviewed/2022/07/GHSA-vw5c-wp4c-pm7q/GHSA-vw5c-wp4c-pm7q.json index 244bc2578b0..e2a720fbf7c 100644 --- a/advisories/unreviewed/2022/07/GHSA-vw5c-wp4c-pm7q/GHSA-vw5c-wp4c-pm7q.json +++ b/advisories/unreviewed/2022/07/GHSA-vw5c-wp4c-pm7q/GHSA-vw5c-wp4c-pm7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json b/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json index cd36b02ec42..d99076a4ba5 100644 --- a/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json +++ b/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-2597-6hvw-h9cx/GHSA-2597-6hvw-h9cx.json b/advisories/unreviewed/2022/08/GHSA-2597-6hvw-h9cx/GHSA-2597-6hvw-h9cx.json index 0f85a4fde1e..bcfdea989cd 100644 --- a/advisories/unreviewed/2022/08/GHSA-2597-6hvw-h9cx/GHSA-2597-6hvw-h9cx.json +++ b/advisories/unreviewed/2022/08/GHSA-2597-6hvw-h9cx/GHSA-2597-6hvw-h9cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-3v49-f236-jv89/GHSA-3v49-f236-jv89.json b/advisories/unreviewed/2022/08/GHSA-3v49-f236-jv89/GHSA-3v49-f236-jv89.json index 1546259a3d8..42bef52a9e3 100644 --- a/advisories/unreviewed/2022/08/GHSA-3v49-f236-jv89/GHSA-3v49-f236-jv89.json +++ b/advisories/unreviewed/2022/08/GHSA-3v49-f236-jv89/GHSA-3v49-f236-jv89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-5wg5-mm98-g4ph/GHSA-5wg5-mm98-g4ph.json b/advisories/unreviewed/2022/08/GHSA-5wg5-mm98-g4ph/GHSA-5wg5-mm98-g4ph.json index 4c85f3ade60..5a233231525 100644 --- a/advisories/unreviewed/2022/08/GHSA-5wg5-mm98-g4ph/GHSA-5wg5-mm98-g4ph.json +++ b/advisories/unreviewed/2022/08/GHSA-5wg5-mm98-g4ph/GHSA-5wg5-mm98-g4ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-6w2h-chp9-83wf/GHSA-6w2h-chp9-83wf.json b/advisories/unreviewed/2022/08/GHSA-6w2h-chp9-83wf/GHSA-6w2h-chp9-83wf.json index 6d89353608c..16558cd3f41 100644 --- a/advisories/unreviewed/2022/08/GHSA-6w2h-chp9-83wf/GHSA-6w2h-chp9-83wf.json +++ b/advisories/unreviewed/2022/08/GHSA-6w2h-chp9-83wf/GHSA-6w2h-chp9-83wf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-77qp-52p3-hjc2/GHSA-77qp-52p3-hjc2.json b/advisories/unreviewed/2022/08/GHSA-77qp-52p3-hjc2/GHSA-77qp-52p3-hjc2.json index c420c7b94a2..32244229651 100644 --- a/advisories/unreviewed/2022/08/GHSA-77qp-52p3-hjc2/GHSA-77qp-52p3-hjc2.json +++ b/advisories/unreviewed/2022/08/GHSA-77qp-52p3-hjc2/GHSA-77qp-52p3-hjc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-78r9-qj6x-mw32/GHSA-78r9-qj6x-mw32.json b/advisories/unreviewed/2022/08/GHSA-78r9-qj6x-mw32/GHSA-78r9-qj6x-mw32.json index 9d64b552708..5f19e2704e7 100644 --- a/advisories/unreviewed/2022/08/GHSA-78r9-qj6x-mw32/GHSA-78r9-qj6x-mw32.json +++ b/advisories/unreviewed/2022/08/GHSA-78r9-qj6x-mw32/GHSA-78r9-qj6x-mw32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-7j5v-5pjf-prwc/GHSA-7j5v-5pjf-prwc.json b/advisories/unreviewed/2022/08/GHSA-7j5v-5pjf-prwc/GHSA-7j5v-5pjf-prwc.json index a152e3ea881..54a666f1bc5 100644 --- a/advisories/unreviewed/2022/08/GHSA-7j5v-5pjf-prwc/GHSA-7j5v-5pjf-prwc.json +++ b/advisories/unreviewed/2022/08/GHSA-7j5v-5pjf-prwc/GHSA-7j5v-5pjf-prwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-8jjp-3pj6-xx8j/GHSA-8jjp-3pj6-xx8j.json b/advisories/unreviewed/2022/08/GHSA-8jjp-3pj6-xx8j/GHSA-8jjp-3pj6-xx8j.json index d44ddb799c7..1c218f28401 100644 --- a/advisories/unreviewed/2022/08/GHSA-8jjp-3pj6-xx8j/GHSA-8jjp-3pj6-xx8j.json +++ b/advisories/unreviewed/2022/08/GHSA-8jjp-3pj6-xx8j/GHSA-8jjp-3pj6-xx8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-97hf-7444-8q28/GHSA-97hf-7444-8q28.json b/advisories/unreviewed/2022/08/GHSA-97hf-7444-8q28/GHSA-97hf-7444-8q28.json index 22103bb6fbc..02ff7d46d73 100644 --- a/advisories/unreviewed/2022/08/GHSA-97hf-7444-8q28/GHSA-97hf-7444-8q28.json +++ b/advisories/unreviewed/2022/08/GHSA-97hf-7444-8q28/GHSA-97hf-7444-8q28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-crqx-wmf6-58qf/GHSA-crqx-wmf6-58qf.json b/advisories/unreviewed/2022/08/GHSA-crqx-wmf6-58qf/GHSA-crqx-wmf6-58qf.json index de8fed2a9ba..b6e7dbb347e 100644 --- a/advisories/unreviewed/2022/08/GHSA-crqx-wmf6-58qf/GHSA-crqx-wmf6-58qf.json +++ b/advisories/unreviewed/2022/08/GHSA-crqx-wmf6-58qf/GHSA-crqx-wmf6-58qf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-f3mq-xh7p-7wpv/GHSA-f3mq-xh7p-7wpv.json b/advisories/unreviewed/2022/08/GHSA-f3mq-xh7p-7wpv/GHSA-f3mq-xh7p-7wpv.json index abfcd0f327a..2d986664364 100644 --- a/advisories/unreviewed/2022/08/GHSA-f3mq-xh7p-7wpv/GHSA-f3mq-xh7p-7wpv.json +++ b/advisories/unreviewed/2022/08/GHSA-f3mq-xh7p-7wpv/GHSA-f3mq-xh7p-7wpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-gmfj-x9cj-5fh4/GHSA-gmfj-x9cj-5fh4.json b/advisories/unreviewed/2022/08/GHSA-gmfj-x9cj-5fh4/GHSA-gmfj-x9cj-5fh4.json index 1d8af02da33..305ea1b7726 100644 --- a/advisories/unreviewed/2022/08/GHSA-gmfj-x9cj-5fh4/GHSA-gmfj-x9cj-5fh4.json +++ b/advisories/unreviewed/2022/08/GHSA-gmfj-x9cj-5fh4/GHSA-gmfj-x9cj-5fh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-h28w-8w8h-4gh3/GHSA-h28w-8w8h-4gh3.json b/advisories/unreviewed/2022/08/GHSA-h28w-8w8h-4gh3/GHSA-h28w-8w8h-4gh3.json index aa4e43ee59d..74d2cc18d81 100644 --- a/advisories/unreviewed/2022/08/GHSA-h28w-8w8h-4gh3/GHSA-h28w-8w8h-4gh3.json +++ b/advisories/unreviewed/2022/08/GHSA-h28w-8w8h-4gh3/GHSA-h28w-8w8h-4gh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-jrgj-6p6v-gf22/GHSA-jrgj-6p6v-gf22.json b/advisories/unreviewed/2022/08/GHSA-jrgj-6p6v-gf22/GHSA-jrgj-6p6v-gf22.json index 38196eb0856..243536e32b7 100644 --- a/advisories/unreviewed/2022/08/GHSA-jrgj-6p6v-gf22/GHSA-jrgj-6p6v-gf22.json +++ b/advisories/unreviewed/2022/08/GHSA-jrgj-6p6v-gf22/GHSA-jrgj-6p6v-gf22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-p2vp-m65p-9h8q/GHSA-p2vp-m65p-9h8q.json b/advisories/unreviewed/2022/08/GHSA-p2vp-m65p-9h8q/GHSA-p2vp-m65p-9h8q.json index 197c8446db8..ecb36e8ac69 100644 --- a/advisories/unreviewed/2022/08/GHSA-p2vp-m65p-9h8q/GHSA-p2vp-m65p-9h8q.json +++ b/advisories/unreviewed/2022/08/GHSA-p2vp-m65p-9h8q/GHSA-p2vp-m65p-9h8q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-p3g6-pg7f-ch24/GHSA-p3g6-pg7f-ch24.json b/advisories/unreviewed/2022/08/GHSA-p3g6-pg7f-ch24/GHSA-p3g6-pg7f-ch24.json index 17b040e6f3c..23209bd1079 100644 --- a/advisories/unreviewed/2022/08/GHSA-p3g6-pg7f-ch24/GHSA-p3g6-pg7f-ch24.json +++ b/advisories/unreviewed/2022/08/GHSA-p3g6-pg7f-ch24/GHSA-p3g6-pg7f-ch24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-pjm8-cf8m-q2h9/GHSA-pjm8-cf8m-q2h9.json b/advisories/unreviewed/2022/08/GHSA-pjm8-cf8m-q2h9/GHSA-pjm8-cf8m-q2h9.json index 04060ad04a5..54f108514ee 100644 --- a/advisories/unreviewed/2022/08/GHSA-pjm8-cf8m-q2h9/GHSA-pjm8-cf8m-q2h9.json +++ b/advisories/unreviewed/2022/08/GHSA-pjm8-cf8m-q2h9/GHSA-pjm8-cf8m-q2h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-q2p3-f9cf-5mqp/GHSA-q2p3-f9cf-5mqp.json b/advisories/unreviewed/2022/08/GHSA-q2p3-f9cf-5mqp/GHSA-q2p3-f9cf-5mqp.json index 25727422d14..6cfeca55f27 100644 --- a/advisories/unreviewed/2022/08/GHSA-q2p3-f9cf-5mqp/GHSA-q2p3-f9cf-5mqp.json +++ b/advisories/unreviewed/2022/08/GHSA-q2p3-f9cf-5mqp/GHSA-q2p3-f9cf-5mqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-qj43-c67c-c7c5/GHSA-qj43-c67c-c7c5.json b/advisories/unreviewed/2022/08/GHSA-qj43-c67c-c7c5/GHSA-qj43-c67c-c7c5.json index 7ae656ec37c..ea9ac9090d3 100644 --- a/advisories/unreviewed/2022/08/GHSA-qj43-c67c-c7c5/GHSA-qj43-c67c-c7c5.json +++ b/advisories/unreviewed/2022/08/GHSA-qj43-c67c-c7c5/GHSA-qj43-c67c-c7c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-r3hj-92hh-4g2x/GHSA-r3hj-92hh-4g2x.json b/advisories/unreviewed/2022/08/GHSA-r3hj-92hh-4g2x/GHSA-r3hj-92hh-4g2x.json index 5ba09eb398e..5dc31c3f93a 100644 --- a/advisories/unreviewed/2022/08/GHSA-r3hj-92hh-4g2x/GHSA-r3hj-92hh-4g2x.json +++ b/advisories/unreviewed/2022/08/GHSA-r3hj-92hh-4g2x/GHSA-r3hj-92hh-4g2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-v5p6-gf48-89h4/GHSA-v5p6-gf48-89h4.json b/advisories/unreviewed/2022/08/GHSA-v5p6-gf48-89h4/GHSA-v5p6-gf48-89h4.json index dcdc91c69ea..f9a1267745f 100644 --- a/advisories/unreviewed/2022/08/GHSA-v5p6-gf48-89h4/GHSA-v5p6-gf48-89h4.json +++ b/advisories/unreviewed/2022/08/GHSA-v5p6-gf48-89h4/GHSA-v5p6-gf48-89h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-vhmv-h8q6-8ppm/GHSA-vhmv-h8q6-8ppm.json b/advisories/unreviewed/2022/08/GHSA-vhmv-h8q6-8ppm/GHSA-vhmv-h8q6-8ppm.json index ce20de03949..f8bf5c468cb 100644 --- a/advisories/unreviewed/2022/08/GHSA-vhmv-h8q6-8ppm/GHSA-vhmv-h8q6-8ppm.json +++ b/advisories/unreviewed/2022/08/GHSA-vhmv-h8q6-8ppm/GHSA-vhmv-h8q6-8ppm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-w8gp-j83h-hw8x/GHSA-w8gp-j83h-hw8x.json b/advisories/unreviewed/2022/08/GHSA-w8gp-j83h-hw8x/GHSA-w8gp-j83h-hw8x.json index 466f6025f31..e48e3ce609f 100644 --- a/advisories/unreviewed/2022/08/GHSA-w8gp-j83h-hw8x/GHSA-w8gp-j83h-hw8x.json +++ b/advisories/unreviewed/2022/08/GHSA-w8gp-j83h-hw8x/GHSA-w8gp-j83h-hw8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wh37-3f7v-2w99/GHSA-wh37-3f7v-2w99.json b/advisories/unreviewed/2022/08/GHSA-wh37-3f7v-2w99/GHSA-wh37-3f7v-2w99.json index e7a75542705..930d6cfa182 100644 --- a/advisories/unreviewed/2022/08/GHSA-wh37-3f7v-2w99/GHSA-wh37-3f7v-2w99.json +++ b/advisories/unreviewed/2022/08/GHSA-wh37-3f7v-2w99/GHSA-wh37-3f7v-2w99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-wpp7-hmg7-5vm6/GHSA-wpp7-hmg7-5vm6.json b/advisories/unreviewed/2022/08/GHSA-wpp7-hmg7-5vm6/GHSA-wpp7-hmg7-5vm6.json index ce4e1cc5d8d..a43df7e232d 100644 --- a/advisories/unreviewed/2022/08/GHSA-wpp7-hmg7-5vm6/GHSA-wpp7-hmg7-5vm6.json +++ b/advisories/unreviewed/2022/08/GHSA-wpp7-hmg7-5vm6/GHSA-wpp7-hmg7-5vm6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-wxgh-95h6-c68v/GHSA-wxgh-95h6-c68v.json b/advisories/unreviewed/2022/08/GHSA-wxgh-95h6-c68v/GHSA-wxgh-95h6-c68v.json index 0bbcfa10557..c178e5aad5d 100644 --- a/advisories/unreviewed/2022/08/GHSA-wxgh-95h6-c68v/GHSA-wxgh-95h6-c68v.json +++ b/advisories/unreviewed/2022/08/GHSA-wxgh-95h6-c68v/GHSA-wxgh-95h6-c68v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-xhj3-66vg-p2c8/GHSA-xhj3-66vg-p2c8.json b/advisories/unreviewed/2022/08/GHSA-xhj3-66vg-p2c8/GHSA-xhj3-66vg-p2c8.json index afb0ae33f30..753910aa37e 100644 --- a/advisories/unreviewed/2022/08/GHSA-xhj3-66vg-p2c8/GHSA-xhj3-66vg-p2c8.json +++ b/advisories/unreviewed/2022/08/GHSA-xhj3-66vg-p2c8/GHSA-xhj3-66vg-p2c8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-226r-vp6f-653x/GHSA-226r-vp6f-653x.json b/advisories/unreviewed/2022/09/GHSA-226r-vp6f-653x/GHSA-226r-vp6f-653x.json index a752ff857cd..175800d98aa 100644 --- a/advisories/unreviewed/2022/09/GHSA-226r-vp6f-653x/GHSA-226r-vp6f-653x.json +++ b/advisories/unreviewed/2022/09/GHSA-226r-vp6f-653x/GHSA-226r-vp6f-653x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-56q5-c3xh-qfp3/GHSA-56q5-c3xh-qfp3.json b/advisories/unreviewed/2022/09/GHSA-56q5-c3xh-qfp3/GHSA-56q5-c3xh-qfp3.json index ed612b36178..bd825809dca 100644 --- a/advisories/unreviewed/2022/09/GHSA-56q5-c3xh-qfp3/GHSA-56q5-c3xh-qfp3.json +++ b/advisories/unreviewed/2022/09/GHSA-56q5-c3xh-qfp3/GHSA-56q5-c3xh-qfp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-68cf-8298-f8rx/GHSA-68cf-8298-f8rx.json b/advisories/unreviewed/2022/09/GHSA-68cf-8298-f8rx/GHSA-68cf-8298-f8rx.json index 615fcf6bf2c..54add8c130d 100644 --- a/advisories/unreviewed/2022/09/GHSA-68cf-8298-f8rx/GHSA-68cf-8298-f8rx.json +++ b/advisories/unreviewed/2022/09/GHSA-68cf-8298-f8rx/GHSA-68cf-8298-f8rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-r75j-hjgv-r366/GHSA-r75j-hjgv-r366.json b/advisories/unreviewed/2022/09/GHSA-r75j-hjgv-r366/GHSA-r75j-hjgv-r366.json index 0af25aeb7a0..0ffd21cad30 100644 --- a/advisories/unreviewed/2022/09/GHSA-r75j-hjgv-r366/GHSA-r75j-hjgv-r366.json +++ b/advisories/unreviewed/2022/09/GHSA-r75j-hjgv-r366/GHSA-r75j-hjgv-r366.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-rch5-4wx7-4mgr/GHSA-rch5-4wx7-4mgr.json b/advisories/unreviewed/2022/09/GHSA-rch5-4wx7-4mgr/GHSA-rch5-4wx7-4mgr.json index e9210864152..0e08eb0b085 100644 --- a/advisories/unreviewed/2022/09/GHSA-rch5-4wx7-4mgr/GHSA-rch5-4wx7-4mgr.json +++ b/advisories/unreviewed/2022/09/GHSA-rch5-4wx7-4mgr/GHSA-rch5-4wx7-4mgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-35v6-pv3q-68m3/GHSA-35v6-pv3q-68m3.json b/advisories/unreviewed/2022/10/GHSA-35v6-pv3q-68m3/GHSA-35v6-pv3q-68m3.json index dd0517436b8..f05e48a7b1a 100644 --- a/advisories/unreviewed/2022/10/GHSA-35v6-pv3q-68m3/GHSA-35v6-pv3q-68m3.json +++ b/advisories/unreviewed/2022/10/GHSA-35v6-pv3q-68m3/GHSA-35v6-pv3q-68m3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-3x9p-wvg6-r63g/GHSA-3x9p-wvg6-r63g.json b/advisories/unreviewed/2022/10/GHSA-3x9p-wvg6-r63g/GHSA-3x9p-wvg6-r63g.json index 9a80cf231bc..f195b81479f 100644 --- a/advisories/unreviewed/2022/10/GHSA-3x9p-wvg6-r63g/GHSA-3x9p-wvg6-r63g.json +++ b/advisories/unreviewed/2022/10/GHSA-3x9p-wvg6-r63g/GHSA-3x9p-wvg6-r63g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-5hp7-8m7g-vwm9/GHSA-5hp7-8m7g-vwm9.json b/advisories/unreviewed/2022/10/GHSA-5hp7-8m7g-vwm9/GHSA-5hp7-8m7g-vwm9.json index 5f51af5a976..1f98383beb7 100644 --- a/advisories/unreviewed/2022/10/GHSA-5hp7-8m7g-vwm9/GHSA-5hp7-8m7g-vwm9.json +++ b/advisories/unreviewed/2022/10/GHSA-5hp7-8m7g-vwm9/GHSA-5hp7-8m7g-vwm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-6573-6m2p-m3wh/GHSA-6573-6m2p-m3wh.json b/advisories/unreviewed/2022/10/GHSA-6573-6m2p-m3wh/GHSA-6573-6m2p-m3wh.json index cb2fe3bd669..330665ff925 100644 --- a/advisories/unreviewed/2022/10/GHSA-6573-6m2p-m3wh/GHSA-6573-6m2p-m3wh.json +++ b/advisories/unreviewed/2022/10/GHSA-6573-6m2p-m3wh/GHSA-6573-6m2p-m3wh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-8cfq-6f68-wqmc/GHSA-8cfq-6f68-wqmc.json b/advisories/unreviewed/2022/10/GHSA-8cfq-6f68-wqmc/GHSA-8cfq-6f68-wqmc.json index a1e37bf3dce..239bd3bd184 100644 --- a/advisories/unreviewed/2022/10/GHSA-8cfq-6f68-wqmc/GHSA-8cfq-6f68-wqmc.json +++ b/advisories/unreviewed/2022/10/GHSA-8cfq-6f68-wqmc/GHSA-8cfq-6f68-wqmc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-c9vr-62wv-7xw6/GHSA-c9vr-62wv-7xw6.json b/advisories/unreviewed/2022/10/GHSA-c9vr-62wv-7xw6/GHSA-c9vr-62wv-7xw6.json index dde97b159b7..0e8eebb3e33 100644 --- a/advisories/unreviewed/2022/10/GHSA-c9vr-62wv-7xw6/GHSA-c9vr-62wv-7xw6.json +++ b/advisories/unreviewed/2022/10/GHSA-c9vr-62wv-7xw6/GHSA-c9vr-62wv-7xw6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-f32h-rx5h-cj4v/GHSA-f32h-rx5h-cj4v.json b/advisories/unreviewed/2022/10/GHSA-f32h-rx5h-cj4v/GHSA-f32h-rx5h-cj4v.json index bc2aa50aab8..3c7ddc79e7e 100644 --- a/advisories/unreviewed/2022/10/GHSA-f32h-rx5h-cj4v/GHSA-f32h-rx5h-cj4v.json +++ b/advisories/unreviewed/2022/10/GHSA-f32h-rx5h-cj4v/GHSA-f32h-rx5h-cj4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-hv45-p7vx-9q88/GHSA-hv45-p7vx-9q88.json b/advisories/unreviewed/2022/10/GHSA-hv45-p7vx-9q88/GHSA-hv45-p7vx-9q88.json index d39dafc588b..86c04932a09 100644 --- a/advisories/unreviewed/2022/10/GHSA-hv45-p7vx-9q88/GHSA-hv45-p7vx-9q88.json +++ b/advisories/unreviewed/2022/10/GHSA-hv45-p7vx-9q88/GHSA-hv45-p7vx-9q88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jfp5-78vp-9mh6/GHSA-jfp5-78vp-9mh6.json b/advisories/unreviewed/2022/10/GHSA-jfp5-78vp-9mh6/GHSA-jfp5-78vp-9mh6.json index 456e0757a66..0aab720b1dd 100644 --- a/advisories/unreviewed/2022/10/GHSA-jfp5-78vp-9mh6/GHSA-jfp5-78vp-9mh6.json +++ b/advisories/unreviewed/2022/10/GHSA-jfp5-78vp-9mh6/GHSA-jfp5-78vp-9mh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-p6wg-3r8f-8hp2/GHSA-p6wg-3r8f-8hp2.json b/advisories/unreviewed/2022/10/GHSA-p6wg-3r8f-8hp2/GHSA-p6wg-3r8f-8hp2.json index 95b94e4e238..291cd457838 100644 --- a/advisories/unreviewed/2022/10/GHSA-p6wg-3r8f-8hp2/GHSA-p6wg-3r8f-8hp2.json +++ b/advisories/unreviewed/2022/10/GHSA-p6wg-3r8f-8hp2/GHSA-p6wg-3r8f-8hp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-q2rc-2qhm-p3pw/GHSA-q2rc-2qhm-p3pw.json b/advisories/unreviewed/2022/10/GHSA-q2rc-2qhm-p3pw/GHSA-q2rc-2qhm-p3pw.json index b844f6f9182..db1113ad785 100644 --- a/advisories/unreviewed/2022/10/GHSA-q2rc-2qhm-p3pw/GHSA-q2rc-2qhm-p3pw.json +++ b/advisories/unreviewed/2022/10/GHSA-q2rc-2qhm-p3pw/GHSA-q2rc-2qhm-p3pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-qxm2-676w-hcrm/GHSA-qxm2-676w-hcrm.json b/advisories/unreviewed/2022/10/GHSA-qxm2-676w-hcrm/GHSA-qxm2-676w-hcrm.json index ea66c122143..06cc1728613 100644 --- a/advisories/unreviewed/2022/10/GHSA-qxm2-676w-hcrm/GHSA-qxm2-676w-hcrm.json +++ b/advisories/unreviewed/2022/10/GHSA-qxm2-676w-hcrm/GHSA-qxm2-676w-hcrm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-v4v7-8xxw-56v2/GHSA-v4v7-8xxw-56v2.json b/advisories/unreviewed/2022/10/GHSA-v4v7-8xxw-56v2/GHSA-v4v7-8xxw-56v2.json index 99f8ff17a45..c23a193f041 100644 --- a/advisories/unreviewed/2022/10/GHSA-v4v7-8xxw-56v2/GHSA-v4v7-8xxw-56v2.json +++ b/advisories/unreviewed/2022/10/GHSA-v4v7-8xxw-56v2/GHSA-v4v7-8xxw-56v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-x89m-497r-57rp/GHSA-x89m-497r-57rp.json b/advisories/unreviewed/2022/10/GHSA-x89m-497r-57rp/GHSA-x89m-497r-57rp.json index 9d5ab919548..9b19dc872ce 100644 --- a/advisories/unreviewed/2022/10/GHSA-x89m-497r-57rp/GHSA-x89m-497r-57rp.json +++ b/advisories/unreviewed/2022/10/GHSA-x89m-497r-57rp/GHSA-x89m-497r-57rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-2p92-5rp8-53v2/GHSA-2p92-5rp8-53v2.json b/advisories/unreviewed/2022/11/GHSA-2p92-5rp8-53v2/GHSA-2p92-5rp8-53v2.json index d588312ea73..93eb5f9816f 100644 --- a/advisories/unreviewed/2022/11/GHSA-2p92-5rp8-53v2/GHSA-2p92-5rp8-53v2.json +++ b/advisories/unreviewed/2022/11/GHSA-2p92-5rp8-53v2/GHSA-2p92-5rp8-53v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-jj94-vrcq-56wm/GHSA-jj94-vrcq-56wm.json b/advisories/unreviewed/2022/11/GHSA-jj94-vrcq-56wm/GHSA-jj94-vrcq-56wm.json index 6a98918f325..c3b6130534e 100644 --- a/advisories/unreviewed/2022/11/GHSA-jj94-vrcq-56wm/GHSA-jj94-vrcq-56wm.json +++ b/advisories/unreviewed/2022/11/GHSA-jj94-vrcq-56wm/GHSA-jj94-vrcq-56wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7p75-2vwp-g822/GHSA-7p75-2vwp-g822.json b/advisories/unreviewed/2023/01/GHSA-7p75-2vwp-g822/GHSA-7p75-2vwp-g822.json index 5b3253192e7..2cdb4b4d1d9 100644 --- a/advisories/unreviewed/2023/01/GHSA-7p75-2vwp-g822/GHSA-7p75-2vwp-g822.json +++ b/advisories/unreviewed/2023/01/GHSA-7p75-2vwp-g822/GHSA-7p75-2vwp-g822.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9c8m-hmqf-mhq2/GHSA-9c8m-hmqf-mhq2.json b/advisories/unreviewed/2023/01/GHSA-9c8m-hmqf-mhq2/GHSA-9c8m-hmqf-mhq2.json index 300f70ead19..51a9cec0950 100644 --- a/advisories/unreviewed/2023/01/GHSA-9c8m-hmqf-mhq2/GHSA-9c8m-hmqf-mhq2.json +++ b/advisories/unreviewed/2023/01/GHSA-9c8m-hmqf-mhq2/GHSA-9c8m-hmqf-mhq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json b/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json index 0c0117bbfac..654f66a9426 100644 --- a/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json +++ b/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-2742-frwm-8w65/GHSA-2742-frwm-8w65.json b/advisories/unreviewed/2023/02/GHSA-2742-frwm-8w65/GHSA-2742-frwm-8w65.json index ad8c91c158d..5333a14e722 100644 --- a/advisories/unreviewed/2023/02/GHSA-2742-frwm-8w65/GHSA-2742-frwm-8w65.json +++ b/advisories/unreviewed/2023/02/GHSA-2742-frwm-8w65/GHSA-2742-frwm-8w65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-2v62-25cm-4v7w/GHSA-2v62-25cm-4v7w.json b/advisories/unreviewed/2023/02/GHSA-2v62-25cm-4v7w/GHSA-2v62-25cm-4v7w.json index be8608367ff..084bc8cf1bf 100644 --- a/advisories/unreviewed/2023/02/GHSA-2v62-25cm-4v7w/GHSA-2v62-25cm-4v7w.json +++ b/advisories/unreviewed/2023/02/GHSA-2v62-25cm-4v7w/GHSA-2v62-25cm-4v7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-3865-xcmr-qxp5/GHSA-3865-xcmr-qxp5.json b/advisories/unreviewed/2023/02/GHSA-3865-xcmr-qxp5/GHSA-3865-xcmr-qxp5.json index eed9af2ec6c..125635776eb 100644 --- a/advisories/unreviewed/2023/02/GHSA-3865-xcmr-qxp5/GHSA-3865-xcmr-qxp5.json +++ b/advisories/unreviewed/2023/02/GHSA-3865-xcmr-qxp5/GHSA-3865-xcmr-qxp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-3fr2-jq6q-2hff/GHSA-3fr2-jq6q-2hff.json b/advisories/unreviewed/2023/02/GHSA-3fr2-jq6q-2hff/GHSA-3fr2-jq6q-2hff.json index e83c35f4489..c6d00ef6d1e 100644 --- a/advisories/unreviewed/2023/02/GHSA-3fr2-jq6q-2hff/GHSA-3fr2-jq6q-2hff.json +++ b/advisories/unreviewed/2023/02/GHSA-3fr2-jq6q-2hff/GHSA-3fr2-jq6q-2hff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-5fh2-9qj6-98rq/GHSA-5fh2-9qj6-98rq.json b/advisories/unreviewed/2023/02/GHSA-5fh2-9qj6-98rq/GHSA-5fh2-9qj6-98rq.json index 0883bff8f47..862570e8725 100644 --- a/advisories/unreviewed/2023/02/GHSA-5fh2-9qj6-98rq/GHSA-5fh2-9qj6-98rq.json +++ b/advisories/unreviewed/2023/02/GHSA-5fh2-9qj6-98rq/GHSA-5fh2-9qj6-98rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-6pw4-x3c6-wm8j/GHSA-6pw4-x3c6-wm8j.json b/advisories/unreviewed/2023/02/GHSA-6pw4-x3c6-wm8j/GHSA-6pw4-x3c6-wm8j.json index 880c5fb9a0a..a970f832eae 100644 --- a/advisories/unreviewed/2023/02/GHSA-6pw4-x3c6-wm8j/GHSA-6pw4-x3c6-wm8j.json +++ b/advisories/unreviewed/2023/02/GHSA-6pw4-x3c6-wm8j/GHSA-6pw4-x3c6-wm8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-7gvj-8qmv-p4vc/GHSA-7gvj-8qmv-p4vc.json b/advisories/unreviewed/2023/02/GHSA-7gvj-8qmv-p4vc/GHSA-7gvj-8qmv-p4vc.json index 2482fdabc5a..2d10601784b 100644 --- a/advisories/unreviewed/2023/02/GHSA-7gvj-8qmv-p4vc/GHSA-7gvj-8qmv-p4vc.json +++ b/advisories/unreviewed/2023/02/GHSA-7gvj-8qmv-p4vc/GHSA-7gvj-8qmv-p4vc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-7mcm-wrpj-6fwv/GHSA-7mcm-wrpj-6fwv.json b/advisories/unreviewed/2023/02/GHSA-7mcm-wrpj-6fwv/GHSA-7mcm-wrpj-6fwv.json index 75dbd7f9851..b7c62ee8c11 100644 --- a/advisories/unreviewed/2023/02/GHSA-7mcm-wrpj-6fwv/GHSA-7mcm-wrpj-6fwv.json +++ b/advisories/unreviewed/2023/02/GHSA-7mcm-wrpj-6fwv/GHSA-7mcm-wrpj-6fwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json b/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json index 10124a45d1b..1c4dee22eab 100644 --- a/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json +++ b/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-c8jx-wgmp-xj28/GHSA-c8jx-wgmp-xj28.json b/advisories/unreviewed/2023/02/GHSA-c8jx-wgmp-xj28/GHSA-c8jx-wgmp-xj28.json index b3c605f1880..508191492f5 100644 --- a/advisories/unreviewed/2023/02/GHSA-c8jx-wgmp-xj28/GHSA-c8jx-wgmp-xj28.json +++ b/advisories/unreviewed/2023/02/GHSA-c8jx-wgmp-xj28/GHSA-c8jx-wgmp-xj28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-cm68-wv9q-pqfq/GHSA-cm68-wv9q-pqfq.json b/advisories/unreviewed/2023/02/GHSA-cm68-wv9q-pqfq/GHSA-cm68-wv9q-pqfq.json index 58cbc135e41..1e0fbe35216 100644 --- a/advisories/unreviewed/2023/02/GHSA-cm68-wv9q-pqfq/GHSA-cm68-wv9q-pqfq.json +++ b/advisories/unreviewed/2023/02/GHSA-cm68-wv9q-pqfq/GHSA-cm68-wv9q-pqfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-ff72-hqv3-8pwq/GHSA-ff72-hqv3-8pwq.json b/advisories/unreviewed/2023/02/GHSA-ff72-hqv3-8pwq/GHSA-ff72-hqv3-8pwq.json index 5f7fc98643a..bafec69e724 100644 --- a/advisories/unreviewed/2023/02/GHSA-ff72-hqv3-8pwq/GHSA-ff72-hqv3-8pwq.json +++ b/advisories/unreviewed/2023/02/GHSA-ff72-hqv3-8pwq/GHSA-ff72-hqv3-8pwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-h4gx-6mxf-9g7m/GHSA-h4gx-6mxf-9g7m.json b/advisories/unreviewed/2023/02/GHSA-h4gx-6mxf-9g7m/GHSA-h4gx-6mxf-9g7m.json index 7535642d03b..feec8f08e89 100644 --- a/advisories/unreviewed/2023/02/GHSA-h4gx-6mxf-9g7m/GHSA-h4gx-6mxf-9g7m.json +++ b/advisories/unreviewed/2023/02/GHSA-h4gx-6mxf-9g7m/GHSA-h4gx-6mxf-9g7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-hj2g-q4fc-38mp/GHSA-hj2g-q4fc-38mp.json b/advisories/unreviewed/2023/02/GHSA-hj2g-q4fc-38mp/GHSA-hj2g-q4fc-38mp.json index 0739251b92a..a94ed5e7a45 100644 --- a/advisories/unreviewed/2023/02/GHSA-hj2g-q4fc-38mp/GHSA-hj2g-q4fc-38mp.json +++ b/advisories/unreviewed/2023/02/GHSA-hj2g-q4fc-38mp/GHSA-hj2g-q4fc-38mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json b/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json index e320cc065f4..d5d55963aa3 100644 --- a/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json +++ b/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-hqw6-rjpx-2wf4/GHSA-hqw6-rjpx-2wf4.json b/advisories/unreviewed/2023/02/GHSA-hqw6-rjpx-2wf4/GHSA-hqw6-rjpx-2wf4.json index 482ee08cef9..7e8c040f966 100644 --- a/advisories/unreviewed/2023/02/GHSA-hqw6-rjpx-2wf4/GHSA-hqw6-rjpx-2wf4.json +++ b/advisories/unreviewed/2023/02/GHSA-hqw6-rjpx-2wf4/GHSA-hqw6-rjpx-2wf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-q56j-mjjc-gjf9/GHSA-q56j-mjjc-gjf9.json b/advisories/unreviewed/2023/02/GHSA-q56j-mjjc-gjf9/GHSA-q56j-mjjc-gjf9.json index 90b4aba9fc2..594da3d5c95 100644 --- a/advisories/unreviewed/2023/02/GHSA-q56j-mjjc-gjf9/GHSA-q56j-mjjc-gjf9.json +++ b/advisories/unreviewed/2023/02/GHSA-q56j-mjjc-gjf9/GHSA-q56j-mjjc-gjf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qr8h-mpxp-qw6p/GHSA-qr8h-mpxp-qw6p.json b/advisories/unreviewed/2023/02/GHSA-qr8h-mpxp-qw6p/GHSA-qr8h-mpxp-qw6p.json index 574d381d54c..10cd643e1d5 100644 --- a/advisories/unreviewed/2023/02/GHSA-qr8h-mpxp-qw6p/GHSA-qr8h-mpxp-qw6p.json +++ b/advisories/unreviewed/2023/02/GHSA-qr8h-mpxp-qw6p/GHSA-qr8h-mpxp-qw6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-rw5c-4xxp-6rqm/GHSA-rw5c-4xxp-6rqm.json b/advisories/unreviewed/2023/02/GHSA-rw5c-4xxp-6rqm/GHSA-rw5c-4xxp-6rqm.json index 4fd2795187d..425b7be7f7f 100644 --- a/advisories/unreviewed/2023/02/GHSA-rw5c-4xxp-6rqm/GHSA-rw5c-4xxp-6rqm.json +++ b/advisories/unreviewed/2023/02/GHSA-rw5c-4xxp-6rqm/GHSA-rw5c-4xxp-6rqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-v5mh-2j9w-gwpx/GHSA-v5mh-2j9w-gwpx.json b/advisories/unreviewed/2023/02/GHSA-v5mh-2j9w-gwpx/GHSA-v5mh-2j9w-gwpx.json index f41f9f69478..30c9a186002 100644 --- a/advisories/unreviewed/2023/02/GHSA-v5mh-2j9w-gwpx/GHSA-v5mh-2j9w-gwpx.json +++ b/advisories/unreviewed/2023/02/GHSA-v5mh-2j9w-gwpx/GHSA-v5mh-2j9w-gwpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-v8jx-vx6h-6c48/GHSA-v8jx-vx6h-6c48.json b/advisories/unreviewed/2023/02/GHSA-v8jx-vx6h-6c48/GHSA-v8jx-vx6h-6c48.json index d14f2e7100b..de356bab943 100644 --- a/advisories/unreviewed/2023/02/GHSA-v8jx-vx6h-6c48/GHSA-v8jx-vx6h-6c48.json +++ b/advisories/unreviewed/2023/02/GHSA-v8jx-vx6h-6c48/GHSA-v8jx-vx6h-6c48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-w85w-m9jr-jffx/GHSA-w85w-m9jr-jffx.json b/advisories/unreviewed/2023/02/GHSA-w85w-m9jr-jffx/GHSA-w85w-m9jr-jffx.json index 9d314f60546..cc9c9be7dd7 100644 --- a/advisories/unreviewed/2023/02/GHSA-w85w-m9jr-jffx/GHSA-w85w-m9jr-jffx.json +++ b/advisories/unreviewed/2023/02/GHSA-w85w-m9jr-jffx/GHSA-w85w-m9jr-jffx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-wmmr-frfj-gmmw/GHSA-wmmr-frfj-gmmw.json b/advisories/unreviewed/2023/02/GHSA-wmmr-frfj-gmmw/GHSA-wmmr-frfj-gmmw.json index 96b63618eaf..4f54ac6a14e 100644 --- a/advisories/unreviewed/2023/02/GHSA-wmmr-frfj-gmmw/GHSA-wmmr-frfj-gmmw.json +++ b/advisories/unreviewed/2023/02/GHSA-wmmr-frfj-gmmw/GHSA-wmmr-frfj-gmmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-xcqv-8q74-7h3x/GHSA-xcqv-8q74-7h3x.json b/advisories/unreviewed/2023/02/GHSA-xcqv-8q74-7h3x/GHSA-xcqv-8q74-7h3x.json index 82cc9321314..5ccb52fae20 100644 --- a/advisories/unreviewed/2023/02/GHSA-xcqv-8q74-7h3x/GHSA-xcqv-8q74-7h3x.json +++ b/advisories/unreviewed/2023/02/GHSA-xcqv-8q74-7h3x/GHSA-xcqv-8q74-7h3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json b/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json index 957c79b1593..55d011dfc52 100644 --- a/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json +++ b/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json b/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json index 5a576fe8a7e..49ed1bdd3f9 100644 --- a/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json +++ b/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-crh3-rr47-6rc3/GHSA-crh3-rr47-6rc3.json b/advisories/unreviewed/2023/06/GHSA-crh3-rr47-6rc3/GHSA-crh3-rr47-6rc3.json index 9c72e38a3e9..ef857593abf 100644 --- a/advisories/unreviewed/2023/06/GHSA-crh3-rr47-6rc3/GHSA-crh3-rr47-6rc3.json +++ b/advisories/unreviewed/2023/06/GHSA-crh3-rr47-6rc3/GHSA-crh3-rr47-6rc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-jw67-h578-772q/GHSA-jw67-h578-772q.json b/advisories/unreviewed/2023/06/GHSA-jw67-h578-772q/GHSA-jw67-h578-772q.json index 472fd70271f..de50ef1064c 100644 --- a/advisories/unreviewed/2023/06/GHSA-jw67-h578-772q/GHSA-jw67-h578-772q.json +++ b/advisories/unreviewed/2023/06/GHSA-jw67-h578-772q/GHSA-jw67-h578-772q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-p76q-8wfr-hpf8/GHSA-p76q-8wfr-hpf8.json b/advisories/unreviewed/2023/06/GHSA-p76q-8wfr-hpf8/GHSA-p76q-8wfr-hpf8.json index e1a44dc398a..c91bafe78d8 100644 --- a/advisories/unreviewed/2023/06/GHSA-p76q-8wfr-hpf8/GHSA-p76q-8wfr-hpf8.json +++ b/advisories/unreviewed/2023/06/GHSA-p76q-8wfr-hpf8/GHSA-p76q-8wfr-hpf8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-2cg5-wf8w-mcv4/GHSA-2cg5-wf8w-mcv4.json b/advisories/unreviewed/2023/08/GHSA-2cg5-wf8w-mcv4/GHSA-2cg5-wf8w-mcv4.json index 1029d846dab..6803a8f9ede 100644 --- a/advisories/unreviewed/2023/08/GHSA-2cg5-wf8w-mcv4/GHSA-2cg5-wf8w-mcv4.json +++ b/advisories/unreviewed/2023/08/GHSA-2cg5-wf8w-mcv4/GHSA-2cg5-wf8w-mcv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-h93h-45p3-p324/GHSA-h93h-45p3-p324.json b/advisories/unreviewed/2023/08/GHSA-h93h-45p3-p324/GHSA-h93h-45p3-p324.json index 9d788e1ebb1..85281cfd2d0 100644 --- a/advisories/unreviewed/2023/08/GHSA-h93h-45p3-p324/GHSA-h93h-45p3-p324.json +++ b/advisories/unreviewed/2023/08/GHSA-h93h-45p3-p324/GHSA-h93h-45p3-p324.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-m4g7-w387-qg32/GHSA-m4g7-w387-qg32.json b/advisories/unreviewed/2023/08/GHSA-m4g7-w387-qg32/GHSA-m4g7-w387-qg32.json index 426f436bc35..b9c88333c91 100644 --- a/advisories/unreviewed/2023/08/GHSA-m4g7-w387-qg32/GHSA-m4g7-w387-qg32.json +++ b/advisories/unreviewed/2023/08/GHSA-m4g7-w387-qg32/GHSA-m4g7-w387-qg32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-wcch-rmxq-7x86/GHSA-wcch-rmxq-7x86.json b/advisories/unreviewed/2023/09/GHSA-wcch-rmxq-7x86/GHSA-wcch-rmxq-7x86.json index 115aac2c746..f7cd05af971 100644 --- a/advisories/unreviewed/2023/09/GHSA-wcch-rmxq-7x86/GHSA-wcch-rmxq-7x86.json +++ b/advisories/unreviewed/2023/09/GHSA-wcch-rmxq-7x86/GHSA-wcch-rmxq-7x86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-269c-5w5q-frxq/GHSA-269c-5w5q-frxq.json b/advisories/unreviewed/2023/11/GHSA-269c-5w5q-frxq/GHSA-269c-5w5q-frxq.json index 8c94ec11b88..97671d86b08 100644 --- a/advisories/unreviewed/2023/11/GHSA-269c-5w5q-frxq/GHSA-269c-5w5q-frxq.json +++ b/advisories/unreviewed/2023/11/GHSA-269c-5w5q-frxq/GHSA-269c-5w5q-frxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-2g99-86hw-gx4m/GHSA-2g99-86hw-gx4m.json b/advisories/unreviewed/2023/11/GHSA-2g99-86hw-gx4m/GHSA-2g99-86hw-gx4m.json index 3b99c621df5..9429421e237 100644 --- a/advisories/unreviewed/2023/11/GHSA-2g99-86hw-gx4m/GHSA-2g99-86hw-gx4m.json +++ b/advisories/unreviewed/2023/11/GHSA-2g99-86hw-gx4m/GHSA-2g99-86hw-gx4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-48jp-j5h5-mpgv/GHSA-48jp-j5h5-mpgv.json b/advisories/unreviewed/2023/11/GHSA-48jp-j5h5-mpgv/GHSA-48jp-j5h5-mpgv.json index e002710ca87..e5e16e7bc8f 100644 --- a/advisories/unreviewed/2023/11/GHSA-48jp-j5h5-mpgv/GHSA-48jp-j5h5-mpgv.json +++ b/advisories/unreviewed/2023/11/GHSA-48jp-j5h5-mpgv/GHSA-48jp-j5h5-mpgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-7wx4-fjq2-2hjg/GHSA-7wx4-fjq2-2hjg.json b/advisories/unreviewed/2023/11/GHSA-7wx4-fjq2-2hjg/GHSA-7wx4-fjq2-2hjg.json index 3c8a58df5bc..863b97c1a4a 100644 --- a/advisories/unreviewed/2023/11/GHSA-7wx4-fjq2-2hjg/GHSA-7wx4-fjq2-2hjg.json +++ b/advisories/unreviewed/2023/11/GHSA-7wx4-fjq2-2hjg/GHSA-7wx4-fjq2-2hjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-92xg-872w-r5g2/GHSA-92xg-872w-r5g2.json b/advisories/unreviewed/2023/11/GHSA-92xg-872w-r5g2/GHSA-92xg-872w-r5g2.json index 009bed60d29..4efbb84308b 100644 --- a/advisories/unreviewed/2023/11/GHSA-92xg-872w-r5g2/GHSA-92xg-872w-r5g2.json +++ b/advisories/unreviewed/2023/11/GHSA-92xg-872w-r5g2/GHSA-92xg-872w-r5g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-f462-3w4w-vcj7/GHSA-f462-3w4w-vcj7.json b/advisories/unreviewed/2023/11/GHSA-f462-3w4w-vcj7/GHSA-f462-3w4w-vcj7.json index e4e1acb797c..4f2337a1b54 100644 --- a/advisories/unreviewed/2023/11/GHSA-f462-3w4w-vcj7/GHSA-f462-3w4w-vcj7.json +++ b/advisories/unreviewed/2023/11/GHSA-f462-3w4w-vcj7/GHSA-f462-3w4w-vcj7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-frqc-q27w-5p4j/GHSA-frqc-q27w-5p4j.json b/advisories/unreviewed/2023/11/GHSA-frqc-q27w-5p4j/GHSA-frqc-q27w-5p4j.json index dc70145c36e..01bfa75ec6e 100644 --- a/advisories/unreviewed/2023/11/GHSA-frqc-q27w-5p4j/GHSA-frqc-q27w-5p4j.json +++ b/advisories/unreviewed/2023/11/GHSA-frqc-q27w-5p4j/GHSA-frqc-q27w-5p4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-gq8r-vgwp-9335/GHSA-gq8r-vgwp-9335.json b/advisories/unreviewed/2023/11/GHSA-gq8r-vgwp-9335/GHSA-gq8r-vgwp-9335.json index a516ef0d3e0..48ad04425d0 100644 --- a/advisories/unreviewed/2023/11/GHSA-gq8r-vgwp-9335/GHSA-gq8r-vgwp-9335.json +++ b/advisories/unreviewed/2023/11/GHSA-gq8r-vgwp-9335/GHSA-gq8r-vgwp-9335.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-hhvv-gx6c-p7jj/GHSA-hhvv-gx6c-p7jj.json b/advisories/unreviewed/2023/11/GHSA-hhvv-gx6c-p7jj/GHSA-hhvv-gx6c-p7jj.json index 61c5259ad13..fbd2929df3a 100644 --- a/advisories/unreviewed/2023/11/GHSA-hhvv-gx6c-p7jj/GHSA-hhvv-gx6c-p7jj.json +++ b/advisories/unreviewed/2023/11/GHSA-hhvv-gx6c-p7jj/GHSA-hhvv-gx6c-p7jj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-hq2f-86fm-7823/GHSA-hq2f-86fm-7823.json b/advisories/unreviewed/2023/11/GHSA-hq2f-86fm-7823/GHSA-hq2f-86fm-7823.json index 285c2aee7e6..bb6e97e797b 100644 --- a/advisories/unreviewed/2023/11/GHSA-hq2f-86fm-7823/GHSA-hq2f-86fm-7823.json +++ b/advisories/unreviewed/2023/11/GHSA-hq2f-86fm-7823/GHSA-hq2f-86fm-7823.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-qwf9-ch8q-fhx3/GHSA-qwf9-ch8q-fhx3.json b/advisories/unreviewed/2023/11/GHSA-qwf9-ch8q-fhx3/GHSA-qwf9-ch8q-fhx3.json index 8799088a705..30af0c7e59b 100644 --- a/advisories/unreviewed/2023/11/GHSA-qwf9-ch8q-fhx3/GHSA-qwf9-ch8q-fhx3.json +++ b/advisories/unreviewed/2023/11/GHSA-qwf9-ch8q-fhx3/GHSA-qwf9-ch8q-fhx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-r3j2-4m6m-33vm/GHSA-r3j2-4m6m-33vm.json b/advisories/unreviewed/2023/11/GHSA-r3j2-4m6m-33vm/GHSA-r3j2-4m6m-33vm.json index 1d12c3da223..ac7de9f223a 100644 --- a/advisories/unreviewed/2023/11/GHSA-r3j2-4m6m-33vm/GHSA-r3j2-4m6m-33vm.json +++ b/advisories/unreviewed/2023/11/GHSA-r3j2-4m6m-33vm/GHSA-r3j2-4m6m-33vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-r8pw-p7q7-5244/GHSA-r8pw-p7q7-5244.json b/advisories/unreviewed/2023/11/GHSA-r8pw-p7q7-5244/GHSA-r8pw-p7q7-5244.json index 2cab10f933c..c276dca558c 100644 --- a/advisories/unreviewed/2023/11/GHSA-r8pw-p7q7-5244/GHSA-r8pw-p7q7-5244.json +++ b/advisories/unreviewed/2023/11/GHSA-r8pw-p7q7-5244/GHSA-r8pw-p7q7-5244.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json b/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json index 8875f0b0d98..2df79b83941 100644 --- a/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json +++ b/advisories/unreviewed/2023/11/GHSA-vjx7-957f-w3qg/GHSA-vjx7-957f-w3qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-w9qm-5wjh-3m5x/GHSA-w9qm-5wjh-3m5x.json b/advisories/unreviewed/2023/11/GHSA-w9qm-5wjh-3m5x/GHSA-w9qm-5wjh-3m5x.json index 0b0b0177b43..8f4c2b0a8be 100644 --- a/advisories/unreviewed/2023/11/GHSA-w9qm-5wjh-3m5x/GHSA-w9qm-5wjh-3m5x.json +++ b/advisories/unreviewed/2023/11/GHSA-w9qm-5wjh-3m5x/GHSA-w9qm-5wjh-3m5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json b/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json index 11492641185..121512adc67 100644 --- a/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json +++ b/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json b/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json index 78544e44bce..7e4fbf9764c 100644 --- a/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json +++ b/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json b/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json index bb2ab08c961..857dd951ee6 100644 --- a/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json +++ b/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",