diff --git a/advisories/github-reviewed/2019/12/GHSA-2mrj-435v-c2cr/GHSA-2mrj-435v-c2cr.json b/advisories/github-reviewed/2019/12/GHSA-2mrj-435v-c2cr/GHSA-2mrj-435v-c2cr.json index 872a06d79d2..30966f078f8 100644 --- a/advisories/github-reviewed/2019/12/GHSA-2mrj-435v-c2cr/GHSA-2mrj-435v-c2cr.json +++ b/advisories/github-reviewed/2019/12/GHSA-2mrj-435v-c2cr/GHSA-2mrj-435v-c2cr.json @@ -4,14 +4,10 @@ "modified": "2024-09-20T16:46:32Z", "published": "2019-12-02T18:15:31Z", "withdrawn": "2020-06-16T20:15:24Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA", "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-pwfw-mgfj-7g3g. This link is maintained to preserve external references.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2019-12-02T01:15:50Z", diff --git a/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json b/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json index 43176a0b6f0..151dc1156ae 100644 --- a/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json +++ b/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json @@ -78,9 +78,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-03-18T22:40:30Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-4j5j-58j7-6c3w/GHSA-4j5j-58j7-6c3w.json b/advisories/github-reviewed/2022/05/GHSA-4j5j-58j7-6c3w/GHSA-4j5j-58j7-6c3w.json index 53074516da4..c9509704c11 100644 --- a/advisories/github-reviewed/2022/05/GHSA-4j5j-58j7-6c3w/GHSA-4j5j-58j7-6c3w.json +++ b/advisories/github-reviewed/2022/05/GHSA-4j5j-58j7-6c3w/GHSA-4j5j-58j7-6c3w.json @@ -86,9 +86,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-04-30T08:40:04Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-cwwh-4382-6fwr/GHSA-cwwh-4382-6fwr.json b/advisories/github-reviewed/2022/05/GHSA-cwwh-4382-6fwr/GHSA-cwwh-4382-6fwr.json index 56d665f4360..830012d437c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cwwh-4382-6fwr/GHSA-cwwh-4382-6fwr.json +++ b/advisories/github-reviewed/2022/05/GHSA-cwwh-4382-6fwr/GHSA-cwwh-4382-6fwr.json @@ -78,9 +78,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-07-26T18:23:19Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-jjg9-mf63-vqrp/GHSA-jjg9-mf63-vqrp.json b/advisories/github-reviewed/2022/05/GHSA-jjg9-mf63-vqrp/GHSA-jjg9-mf63-vqrp.json index 2e470458639..c6e61d2b720 100644 --- a/advisories/github-reviewed/2022/05/GHSA-jjg9-mf63-vqrp/GHSA-jjg9-mf63-vqrp.json +++ b/advisories/github-reviewed/2022/05/GHSA-jjg9-mf63-vqrp/GHSA-jjg9-mf63-vqrp.json @@ -8,9 +8,7 @@ ], "summary": "Cross-site scripting in yui 2.4.0", "details": "Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-v8wm-g9f2-xjv4/GHSA-v8wm-g9f2-xjv4.json b/advisories/github-reviewed/2022/05/GHSA-v8wm-g9f2-xjv4/GHSA-v8wm-g9f2-xjv4.json index 8c3cfda40c3..95db07f7117 100644 --- a/advisories/github-reviewed/2022/05/GHSA-v8wm-g9f2-xjv4/GHSA-v8wm-g9f2-xjv4.json +++ b/advisories/github-reviewed/2022/05/GHSA-v8wm-g9f2-xjv4/GHSA-v8wm-g9f2-xjv4.json @@ -58,9 +58,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-21T22:50:51Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json b/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json index a6468869ec9..a4c8e4a71ec 100644 --- a/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json +++ b/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json @@ -111,9 +111,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-25T21:57:14Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-wg47-6cqc-q52j/GHSA-wg47-6cqc-q52j.json b/advisories/github-reviewed/2022/05/GHSA-wg47-6cqc-q52j/GHSA-wg47-6cqc-q52j.json index d9c069aac48..5b7b3ac2ea4 100644 --- a/advisories/github-reviewed/2022/05/GHSA-wg47-6cqc-q52j/GHSA-wg47-6cqc-q52j.json +++ b/advisories/github-reviewed/2022/05/GHSA-wg47-6cqc-q52j/GHSA-wg47-6cqc-q52j.json @@ -62,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-07-24T20:14:01Z", diff --git a/advisories/unreviewed/2022/03/GHSA-8rv9-5fv4-653w/GHSA-8rv9-5fv4-653w.json b/advisories/unreviewed/2022/03/GHSA-8rv9-5fv4-653w/GHSA-8rv9-5fv4-653w.json index 6a7d17385e0..5eb7e4197fa 100644 --- a/advisories/unreviewed/2022/03/GHSA-8rv9-5fv4-653w/GHSA-8rv9-5fv4-653w.json +++ b/advisories/unreviewed/2022/03/GHSA-8rv9-5fv4-653w/GHSA-8rv9-5fv4-653w.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-r8jv-c3jp-366j/GHSA-r8jv-c3jp-366j.json b/advisories/unreviewed/2022/03/GHSA-r8jv-c3jp-366j/GHSA-r8jv-c3jp-366j.json index 6b0de9a9f20..3976c76f50e 100644 --- a/advisories/unreviewed/2022/03/GHSA-r8jv-c3jp-366j/GHSA-r8jv-c3jp-366j.json +++ b/advisories/unreviewed/2022/03/GHSA-r8jv-c3jp-366j/GHSA-r8jv-c3jp-366j.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-22p8-j48p-jr45/GHSA-22p8-j48p-jr45.json b/advisories/unreviewed/2022/04/GHSA-22p8-j48p-jr45/GHSA-22p8-j48p-jr45.json index f565aa543e9..4cac81eb5d3 100644 --- a/advisories/unreviewed/2022/04/GHSA-22p8-j48p-jr45/GHSA-22p8-j48p-jr45.json +++ b/advisories/unreviewed/2022/04/GHSA-22p8-j48p-jr45/GHSA-22p8-j48p-jr45.json @@ -7,12 +7,8 @@ "CVE-2002-2103" ], "details": "Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-23f7-xfw7-g3wj/GHSA-23f7-xfw7-g3wj.json b/advisories/unreviewed/2022/04/GHSA-23f7-xfw7-g3wj/GHSA-23f7-xfw7-g3wj.json index b0f1da11ea0..2f87a9b2704 100644 --- a/advisories/unreviewed/2022/04/GHSA-23f7-xfw7-g3wj/GHSA-23f7-xfw7-g3wj.json +++ b/advisories/unreviewed/2022/04/GHSA-23f7-xfw7-g3wj/GHSA-23f7-xfw7-g3wj.json @@ -7,12 +7,8 @@ "CVE-2002-2063" ], "details": "AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-23hc-w3jx-2m5j/GHSA-23hc-w3jx-2m5j.json b/advisories/unreviewed/2022/04/GHSA-23hc-w3jx-2m5j/GHSA-23hc-w3jx-2m5j.json index d0c17399f61..31e20c63961 100644 --- a/advisories/unreviewed/2022/04/GHSA-23hc-w3jx-2m5j/GHSA-23hc-w3jx-2m5j.json +++ b/advisories/unreviewed/2022/04/GHSA-23hc-w3jx-2m5j/GHSA-23hc-w3jx-2m5j.json @@ -7,12 +7,8 @@ "CVE-2002-1888" ], "details": "CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-24cw-v655-38cr/GHSA-24cw-v655-38cr.json b/advisories/unreviewed/2022/04/GHSA-24cw-v655-38cr/GHSA-24cw-v655-38cr.json index 72de873ac07..192be30f3c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-24cw-v655-38cr/GHSA-24cw-v655-38cr.json +++ b/advisories/unreviewed/2022/04/GHSA-24cw-v655-38cr/GHSA-24cw-v655-38cr.json @@ -7,12 +7,8 @@ "CVE-2002-2045" ], "details": "x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-25q4-mg92-89j6/GHSA-25q4-mg92-89j6.json b/advisories/unreviewed/2022/04/GHSA-25q4-mg92-89j6/GHSA-25q4-mg92-89j6.json index 565eb44b03b..64451fdd2e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-25q4-mg92-89j6/GHSA-25q4-mg92-89j6.json +++ b/advisories/unreviewed/2022/04/GHSA-25q4-mg92-89j6/GHSA-25q4-mg92-89j6.json @@ -7,12 +7,8 @@ "CVE-2002-2005" ], "details": "Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-263w-c8fq-43wx/GHSA-263w-c8fq-43wx.json b/advisories/unreviewed/2022/04/GHSA-263w-c8fq-43wx/GHSA-263w-c8fq-43wx.json index 2eff680f991..f291ec9696a 100644 --- a/advisories/unreviewed/2022/04/GHSA-263w-c8fq-43wx/GHSA-263w-c8fq-43wx.json +++ b/advisories/unreviewed/2022/04/GHSA-263w-c8fq-43wx/GHSA-263w-c8fq-43wx.json @@ -7,12 +7,8 @@ "CVE-2002-1894" ], "details": "Cross-site scripting (XSS) vulnerability in viewtopic.php in phpBB 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-26hr-9q73-x3wm/GHSA-26hr-9q73-x3wm.json b/advisories/unreviewed/2022/04/GHSA-26hr-9q73-x3wm/GHSA-26hr-9q73-x3wm.json index c123dd5523e..32b13dc7567 100644 --- a/advisories/unreviewed/2022/04/GHSA-26hr-9q73-x3wm/GHSA-26hr-9q73-x3wm.json +++ b/advisories/unreviewed/2022/04/GHSA-26hr-9q73-x3wm/GHSA-26hr-9q73-x3wm.json @@ -7,12 +7,8 @@ "CVE-2002-1879" ], "details": "SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-26r4-j8xv-5q4j/GHSA-26r4-j8xv-5q4j.json b/advisories/unreviewed/2022/04/GHSA-26r4-j8xv-5q4j/GHSA-26r4-j8xv-5q4j.json index 36843a3dc25..a8e45d72b1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-26r4-j8xv-5q4j/GHSA-26r4-j8xv-5q4j.json +++ b/advisories/unreviewed/2022/04/GHSA-26r4-j8xv-5q4j/GHSA-26r4-j8xv-5q4j.json @@ -7,12 +7,8 @@ "CVE-2002-2101" ], "details": "Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an \"about:\" or \"javascript:\" URI in the href attribute of an \"a\" tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-27g9-qccj-r7jh/GHSA-27g9-qccj-r7jh.json b/advisories/unreviewed/2022/04/GHSA-27g9-qccj-r7jh/GHSA-27g9-qccj-r7jh.json index 2f0370359b3..b11af122b2a 100644 --- a/advisories/unreviewed/2022/04/GHSA-27g9-qccj-r7jh/GHSA-27g9-qccj-r7jh.json +++ b/advisories/unreviewed/2022/04/GHSA-27g9-qccj-r7jh/GHSA-27g9-qccj-r7jh.json @@ -7,12 +7,8 @@ "CVE-2002-2039" ], "details": "/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-288h-f6gm-4vf9/GHSA-288h-f6gm-4vf9.json b/advisories/unreviewed/2022/04/GHSA-288h-f6gm-4vf9/GHSA-288h-f6gm-4vf9.json index 098c7535ff5..7ca33006f9a 100644 --- a/advisories/unreviewed/2022/04/GHSA-288h-f6gm-4vf9/GHSA-288h-f6gm-4vf9.json +++ b/advisories/unreviewed/2022/04/GHSA-288h-f6gm-4vf9/GHSA-288h-f6gm-4vf9.json @@ -7,12 +7,8 @@ "CVE-2002-2029" ], "details": "PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-29gx-388f-w262/GHSA-29gx-388f-w262.json b/advisories/unreviewed/2022/04/GHSA-29gx-388f-w262/GHSA-29gx-388f-w262.json index 1f7775ee249..2c5f58f9fe5 100644 --- a/advisories/unreviewed/2022/04/GHSA-29gx-388f-w262/GHSA-29gx-388f-w262.json +++ b/advisories/unreviewed/2022/04/GHSA-29gx-388f-w262/GHSA-29gx-388f-w262.json @@ -7,12 +7,8 @@ "CVE-2002-1950" ], "details": "Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2gm5-h3fj-mwv3/GHSA-2gm5-h3fj-mwv3.json b/advisories/unreviewed/2022/04/GHSA-2gm5-h3fj-mwv3/GHSA-2gm5-h3fj-mwv3.json index ffdc39b25fb..325cde0cb21 100644 --- a/advisories/unreviewed/2022/04/GHSA-2gm5-h3fj-mwv3/GHSA-2gm5-h3fj-mwv3.json +++ b/advisories/unreviewed/2022/04/GHSA-2gm5-h3fj-mwv3/GHSA-2gm5-h3fj-mwv3.json @@ -7,12 +7,8 @@ "CVE-2002-1865" ], "details": "Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2hp7-f2c6-gmcr/GHSA-2hp7-f2c6-gmcr.json b/advisories/unreviewed/2022/04/GHSA-2hp7-f2c6-gmcr/GHSA-2hp7-f2c6-gmcr.json index 5a42321b3ee..a1370bb1ab7 100644 --- a/advisories/unreviewed/2022/04/GHSA-2hp7-f2c6-gmcr/GHSA-2hp7-f2c6-gmcr.json +++ b/advisories/unreviewed/2022/04/GHSA-2hp7-f2c6-gmcr/GHSA-2hp7-f2c6-gmcr.json @@ -7,12 +7,8 @@ "CVE-2002-2132" ], "details": "Windows File Protection (WFP) in Windows 2000 and XP does not remove old security catalog .CAT files, which could allow local users to replace new files with vulnerable old files that have valid hash codes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jcg-ch57-hfxf/GHSA-2jcg-ch57-hfxf.json b/advisories/unreviewed/2022/04/GHSA-2jcg-ch57-hfxf/GHSA-2jcg-ch57-hfxf.json index c7f3c816c32..85ec00d0c6e 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jcg-ch57-hfxf/GHSA-2jcg-ch57-hfxf.json +++ b/advisories/unreviewed/2022/04/GHSA-2jcg-ch57-hfxf/GHSA-2jcg-ch57-hfxf.json @@ -7,12 +7,8 @@ "CVE-2002-1707" ], "details": "install.php in phpBB 2.0 through 2.0.1, when \"allow_url_fopen\" and \"register_globals\" variables are set to \"on\", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jgm-64f7-ph6p/GHSA-2jgm-64f7-ph6p.json b/advisories/unreviewed/2022/04/GHSA-2jgm-64f7-ph6p/GHSA-2jgm-64f7-ph6p.json index 2691f3fa056..685764f626f 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jgm-64f7-ph6p/GHSA-2jgm-64f7-ph6p.json +++ b/advisories/unreviewed/2022/04/GHSA-2jgm-64f7-ph6p/GHSA-2jgm-64f7-ph6p.json @@ -7,12 +7,8 @@ "CVE-2002-2021" ], "details": "Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2m58-j4rw-6qj5/GHSA-2m58-j4rw-6qj5.json b/advisories/unreviewed/2022/04/GHSA-2m58-j4rw-6qj5/GHSA-2m58-j4rw-6qj5.json index 8a45099829c..1f860688d17 100644 --- a/advisories/unreviewed/2022/04/GHSA-2m58-j4rw-6qj5/GHSA-2m58-j4rw-6qj5.json +++ b/advisories/unreviewed/2022/04/GHSA-2m58-j4rw-6qj5/GHSA-2m58-j4rw-6qj5.json @@ -7,12 +7,8 @@ "CVE-2002-2148" ], "details": "Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information in the response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2pr3-6gwh-9gvq/GHSA-2pr3-6gwh-9gvq.json b/advisories/unreviewed/2022/04/GHSA-2pr3-6gwh-9gvq/GHSA-2pr3-6gwh-9gvq.json index ce4590ad45f..913241b3fde 100644 --- a/advisories/unreviewed/2022/04/GHSA-2pr3-6gwh-9gvq/GHSA-2pr3-6gwh-9gvq.json +++ b/advisories/unreviewed/2022/04/GHSA-2pr3-6gwh-9gvq/GHSA-2pr3-6gwh-9gvq.json @@ -7,12 +7,8 @@ "CVE-2002-1996" ], "details": "Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2q29-9457-5vhh/GHSA-2q29-9457-5vhh.json b/advisories/unreviewed/2022/04/GHSA-2q29-9457-5vhh/GHSA-2q29-9457-5vhh.json index 634a7812634..94871b37750 100644 --- a/advisories/unreviewed/2022/04/GHSA-2q29-9457-5vhh/GHSA-2q29-9457-5vhh.json +++ b/advisories/unreviewed/2022/04/GHSA-2q29-9457-5vhh/GHSA-2q29-9457-5vhh.json @@ -7,12 +7,8 @@ "CVE-2002-2002" ], "details": "Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2q55-878q-4rx4/GHSA-2q55-878q-4rx4.json b/advisories/unreviewed/2022/04/GHSA-2q55-878q-4rx4/GHSA-2q55-878q-4rx4.json index a4d5af617e0..04b5a47f260 100644 --- a/advisories/unreviewed/2022/04/GHSA-2q55-878q-4rx4/GHSA-2q55-878q-4rx4.json +++ b/advisories/unreviewed/2022/04/GHSA-2q55-878q-4rx4/GHSA-2q55-878q-4rx4.json @@ -7,12 +7,8 @@ "CVE-2002-2133" ], "details": "Telindus 1100 ASDL router running firmware 6.0.x uses weak encryption for UDP session traffic, which allows remote attackers to gain unauthorized access by sniffing and decrypting the administrative password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qc3-c6vw-rhw6/GHSA-2qc3-c6vw-rhw6.json b/advisories/unreviewed/2022/04/GHSA-2qc3-c6vw-rhw6/GHSA-2qc3-c6vw-rhw6.json index a46b0f568a2..9095a7a2f49 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qc3-c6vw-rhw6/GHSA-2qc3-c6vw-rhw6.json +++ b/advisories/unreviewed/2022/04/GHSA-2qc3-c6vw-rhw6/GHSA-2qc3-c6vw-rhw6.json @@ -7,12 +7,8 @@ "CVE-2002-2003" ], "details": "ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qj9-3mhh-fqrj/GHSA-2qj9-3mhh-fqrj.json b/advisories/unreviewed/2022/04/GHSA-2qj9-3mhh-fqrj/GHSA-2qj9-3mhh-fqrj.json index 92071c40b20..db8b67ef592 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qj9-3mhh-fqrj/GHSA-2qj9-3mhh-fqrj.json +++ b/advisories/unreviewed/2022/04/GHSA-2qj9-3mhh-fqrj/GHSA-2qj9-3mhh-fqrj.json @@ -7,12 +7,8 @@ "CVE-2002-2115" ], "details": "Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS) Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to inject arbitrary web script or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rcc-vrwm-m429/GHSA-2rcc-vrwm-m429.json b/advisories/unreviewed/2022/04/GHSA-2rcc-vrwm-m429/GHSA-2rcc-vrwm-m429.json index 9a7c44a4602..7751f0e59d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rcc-vrwm-m429/GHSA-2rcc-vrwm-m429.json +++ b/advisories/unreviewed/2022/04/GHSA-2rcc-vrwm-m429/GHSA-2rcc-vrwm-m429.json @@ -7,12 +7,8 @@ "CVE-2002-1923" ], "details": "The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2wgm-3pxj-gmrx/GHSA-2wgm-3pxj-gmrx.json b/advisories/unreviewed/2022/04/GHSA-2wgm-3pxj-gmrx/GHSA-2wgm-3pxj-gmrx.json index 4f8bd7f438e..55f31a4aacf 100644 --- a/advisories/unreviewed/2022/04/GHSA-2wgm-3pxj-gmrx/GHSA-2wgm-3pxj-gmrx.json +++ b/advisories/unreviewed/2022/04/GHSA-2wgm-3pxj-gmrx/GHSA-2wgm-3pxj-gmrx.json @@ -7,12 +7,8 @@ "CVE-2002-2104" ], "details": "graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3248-52cq-vhgx/GHSA-3248-52cq-vhgx.json b/advisories/unreviewed/2022/04/GHSA-3248-52cq-vhgx/GHSA-3248-52cq-vhgx.json index f3dd5f3f9e0..1fbaf9d565e 100644 --- a/advisories/unreviewed/2022/04/GHSA-3248-52cq-vhgx/GHSA-3248-52cq-vhgx.json +++ b/advisories/unreviewed/2022/04/GHSA-3248-52cq-vhgx/GHSA-3248-52cq-vhgx.json @@ -7,12 +7,8 @@ "CVE-2002-1686" ], "details": "Buffer overflow in lscfg of unknown versions of AIX has unknown impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33j6-jcch-j278/GHSA-33j6-jcch-j278.json b/advisories/unreviewed/2022/04/GHSA-33j6-jcch-j278/GHSA-33j6-jcch-j278.json index 22fabd6a8a9..281c7226485 100644 --- a/advisories/unreviewed/2022/04/GHSA-33j6-jcch-j278/GHSA-33j6-jcch-j278.json +++ b/advisories/unreviewed/2022/04/GHSA-33j6-jcch-j278/GHSA-33j6-jcch-j278.json @@ -7,12 +7,8 @@ "CVE-2002-2073" ], "details": "Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-346q-388w-74cv/GHSA-346q-388w-74cv.json b/advisories/unreviewed/2022/04/GHSA-346q-388w-74cv/GHSA-346q-388w-74cv.json index b41ef53722b..3070b4e817b 100644 --- a/advisories/unreviewed/2022/04/GHSA-346q-388w-74cv/GHSA-346q-388w-74cv.json +++ b/advisories/unreviewed/2022/04/GHSA-346q-388w-74cv/GHSA-346q-388w-74cv.json @@ -7,12 +7,8 @@ "CVE-2002-2077" ], "details": "The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an \"alter context\" request, which may allow remote attackers to obtain sensitive information by sniffing the session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3594-g953-ghg8/GHSA-3594-g953-ghg8.json b/advisories/unreviewed/2022/04/GHSA-3594-g953-ghg8/GHSA-3594-g953-ghg8.json index 817d36a46ae..8fc83b607e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-3594-g953-ghg8/GHSA-3594-g953-ghg8.json +++ b/advisories/unreviewed/2022/04/GHSA-3594-g953-ghg8/GHSA-3594-g953-ghg8.json @@ -7,12 +7,8 @@ "CVE-2002-2051" ], "details": "The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-367w-87rf-wcf4/GHSA-367w-87rf-wcf4.json b/advisories/unreviewed/2022/04/GHSA-367w-87rf-wcf4/GHSA-367w-87rf-wcf4.json index 75a6d2b1bad..8dc7566576f 100644 --- a/advisories/unreviewed/2022/04/GHSA-367w-87rf-wcf4/GHSA-367w-87rf-wcf4.json +++ b/advisories/unreviewed/2022/04/GHSA-367w-87rf-wcf4/GHSA-367w-87rf-wcf4.json @@ -7,12 +7,8 @@ "CVE-2002-2159" ], "details": "Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the \"Block WAN\" and \"Remote Admin\" options are disabled, which allows remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3776-jqqc-38j5/GHSA-3776-jqqc-38j5.json b/advisories/unreviewed/2022/04/GHSA-3776-jqqc-38j5/GHSA-3776-jqqc-38j5.json index 6c53079df94..51fc59778c5 100644 --- a/advisories/unreviewed/2022/04/GHSA-3776-jqqc-38j5/GHSA-3776-jqqc-38j5.json +++ b/advisories/unreviewed/2022/04/GHSA-3776-jqqc-38j5/GHSA-3776-jqqc-38j5.json @@ -7,12 +7,8 @@ "CVE-2002-1968" ], "details": "Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a malicious TFTP server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37fm-8p76-8ch8/GHSA-37fm-8p76-8ch8.json b/advisories/unreviewed/2022/04/GHSA-37fm-8p76-8ch8/GHSA-37fm-8p76-8ch8.json index b749238418f..b5be7da2a63 100644 --- a/advisories/unreviewed/2022/04/GHSA-37fm-8p76-8ch8/GHSA-37fm-8p76-8ch8.json +++ b/advisories/unreviewed/2022/04/GHSA-37fm-8p76-8ch8/GHSA-37fm-8p76-8ch8.json @@ -7,12 +7,8 @@ "CVE-2002-1709" ], "details": "SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3843-g524-g26c/GHSA-3843-g524-g26c.json b/advisories/unreviewed/2022/04/GHSA-3843-g524-g26c/GHSA-3843-g524-g26c.json index 1a6a65b34f7..351e0bcbcba 100644 --- a/advisories/unreviewed/2022/04/GHSA-3843-g524-g26c/GHSA-3843-g524-g26c.json +++ b/advisories/unreviewed/2022/04/GHSA-3843-g524-g26c/GHSA-3843-g524-g26c.json @@ -7,12 +7,8 @@ "CVE-2002-1988" ], "details": "Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3853-86vx-xxvj/GHSA-3853-86vx-xxvj.json b/advisories/unreviewed/2022/04/GHSA-3853-86vx-xxvj/GHSA-3853-86vx-xxvj.json index 2fb69669501..3c0af65e053 100644 --- a/advisories/unreviewed/2022/04/GHSA-3853-86vx-xxvj/GHSA-3853-86vx-xxvj.json +++ b/advisories/unreviewed/2022/04/GHSA-3853-86vx-xxvj/GHSA-3853-86vx-xxvj.json @@ -7,12 +7,8 @@ "CVE-2002-1723" ], "details": "Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3cjq-h7vf-r8wr/GHSA-3cjq-h7vf-r8wr.json b/advisories/unreviewed/2022/04/GHSA-3cjq-h7vf-r8wr/GHSA-3cjq-h7vf-r8wr.json index 91a00dc514a..dd03b8b11c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-3cjq-h7vf-r8wr/GHSA-3cjq-h7vf-r8wr.json +++ b/advisories/unreviewed/2022/04/GHSA-3cjq-h7vf-r8wr/GHSA-3cjq-h7vf-r8wr.json @@ -7,12 +7,8 @@ "CVE-2002-1925" ], "details": "Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3g4v-6jw7-xv32/GHSA-3g4v-6jw7-xv32.json b/advisories/unreviewed/2022/04/GHSA-3g4v-6jw7-xv32/GHSA-3g4v-6jw7-xv32.json index a5067ee7b33..d64f1f28cd4 100644 --- a/advisories/unreviewed/2022/04/GHSA-3g4v-6jw7-xv32/GHSA-3g4v-6jw7-xv32.json +++ b/advisories/unreviewed/2022/04/GHSA-3g4v-6jw7-xv32/GHSA-3g4v-6jw7-xv32.json @@ -7,12 +7,8 @@ "CVE-2002-2114" ], "details": "Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3gvh-fmm3-68jq/GHSA-3gvh-fmm3-68jq.json b/advisories/unreviewed/2022/04/GHSA-3gvh-fmm3-68jq/GHSA-3gvh-fmm3-68jq.json index e0edf85c7c9..f2ef4a339d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-3gvh-fmm3-68jq/GHSA-3gvh-fmm3-68jq.json +++ b/advisories/unreviewed/2022/04/GHSA-3gvh-fmm3-68jq/GHSA-3gvh-fmm3-68jq.json @@ -7,12 +7,8 @@ "CVE-2002-2079" ], "details": "mosix-protocol-stack in Multicomputer Operating System for UnIX (MOSIX) 1.5.7 allows remote attackers to cause a denial of service via malformed packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3gw4-wpf3-6rhr/GHSA-3gw4-wpf3-6rhr.json b/advisories/unreviewed/2022/04/GHSA-3gw4-wpf3-6rhr/GHSA-3gw4-wpf3-6rhr.json index 950bb9ccbd5..2aa87f0583d 100644 --- a/advisories/unreviewed/2022/04/GHSA-3gw4-wpf3-6rhr/GHSA-3gw4-wpf3-6rhr.json +++ b/advisories/unreviewed/2022/04/GHSA-3gw4-wpf3-6rhr/GHSA-3gw4-wpf3-6rhr.json @@ -7,12 +7,8 @@ "CVE-2002-1900" ], "details": "Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3j3x-mwxq-3rh3/GHSA-3j3x-mwxq-3rh3.json b/advisories/unreviewed/2022/04/GHSA-3j3x-mwxq-3rh3/GHSA-3j3x-mwxq-3rh3.json index 92a9ebed00c..f3cc79d66eb 100644 --- a/advisories/unreviewed/2022/04/GHSA-3j3x-mwxq-3rh3/GHSA-3j3x-mwxq-3rh3.json +++ b/advisories/unreviewed/2022/04/GHSA-3j3x-mwxq-3rh3/GHSA-3j3x-mwxq-3rh3.json @@ -7,12 +7,8 @@ "CVE-2002-2032" ], "details": "sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3j48-3wc6-hcmv/GHSA-3j48-3wc6-hcmv.json b/advisories/unreviewed/2022/04/GHSA-3j48-3wc6-hcmv/GHSA-3j48-3wc6-hcmv.json index 111c841503b..3df3bf11d0b 100644 --- a/advisories/unreviewed/2022/04/GHSA-3j48-3wc6-hcmv/GHSA-3j48-3wc6-hcmv.json +++ b/advisories/unreviewed/2022/04/GHSA-3j48-3wc6-hcmv/GHSA-3j48-3wc6-hcmv.json @@ -7,12 +7,8 @@ "CVE-2002-1868" ], "details": "Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mhg-g23j-g83p/GHSA-3mhg-g23j-g83p.json b/advisories/unreviewed/2022/04/GHSA-3mhg-g23j-g83p/GHSA-3mhg-g23j-g83p.json index 1425c8fee31..56ba65cf441 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mhg-g23j-g83p/GHSA-3mhg-g23j-g83p.json +++ b/advisories/unreviewed/2022/04/GHSA-3mhg-g23j-g83p/GHSA-3mhg-g23j-g83p.json @@ -7,12 +7,8 @@ "CVE-2002-1893" ], "details": "Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3qrp-9m7h-qrvr/GHSA-3qrp-9m7h-qrvr.json b/advisories/unreviewed/2022/04/GHSA-3qrp-9m7h-qrvr/GHSA-3qrp-9m7h-qrvr.json index 5803d0a2d2a..837e7682a0e 100644 --- a/advisories/unreviewed/2022/04/GHSA-3qrp-9m7h-qrvr/GHSA-3qrp-9m7h-qrvr.json +++ b/advisories/unreviewed/2022/04/GHSA-3qrp-9m7h-qrvr/GHSA-3qrp-9m7h-qrvr.json @@ -7,12 +7,8 @@ "CVE-2002-1964" ], "details": "Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3qrv-qpqp-72x5/GHSA-3qrv-qpqp-72x5.json b/advisories/unreviewed/2022/04/GHSA-3qrv-qpqp-72x5/GHSA-3qrv-qpqp-72x5.json index 8afe9f64ee4..bd4551b530d 100644 --- a/advisories/unreviewed/2022/04/GHSA-3qrv-qpqp-72x5/GHSA-3qrv-qpqp-72x5.json +++ b/advisories/unreviewed/2022/04/GHSA-3qrv-qpqp-72x5/GHSA-3qrv-qpqp-72x5.json @@ -7,12 +7,8 @@ "CVE-2002-1880" ], "details": "LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-47fv-525q-pc45/GHSA-47fv-525q-pc45.json b/advisories/unreviewed/2022/04/GHSA-47fv-525q-pc45/GHSA-47fv-525q-pc45.json index 9ea1acb119b..bf2ecda4106 100644 --- a/advisories/unreviewed/2022/04/GHSA-47fv-525q-pc45/GHSA-47fv-525q-pc45.json +++ b/advisories/unreviewed/2022/04/GHSA-47fv-525q-pc45/GHSA-47fv-525q-pc45.json @@ -7,12 +7,8 @@ "CVE-2002-2010" ], "details": "Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-484g-7whh-w55j/GHSA-484g-7whh-w55j.json b/advisories/unreviewed/2022/04/GHSA-484g-7whh-w55j/GHSA-484g-7whh-w55j.json index 2007b6482ae..bd01141cb2f 100644 --- a/advisories/unreviewed/2022/04/GHSA-484g-7whh-w55j/GHSA-484g-7whh-w55j.json +++ b/advisories/unreviewed/2022/04/GHSA-484g-7whh-w55j/GHSA-484g-7whh-w55j.json @@ -7,12 +7,8 @@ "CVE-2002-2071" ], "details": "Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd, and possibly other services via a TCP SYN scan, as demonstrated using nmap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-497q-g5jr-qr43/GHSA-497q-g5jr-qr43.json b/advisories/unreviewed/2022/04/GHSA-497q-g5jr-qr43/GHSA-497q-g5jr-qr43.json index 1b8d174497a..5bc8303590a 100644 --- a/advisories/unreviewed/2022/04/GHSA-497q-g5jr-qr43/GHSA-497q-g5jr-qr43.json +++ b/advisories/unreviewed/2022/04/GHSA-497q-g5jr-qr43/GHSA-497q-g5jr-qr43.json @@ -7,12 +7,8 @@ "CVE-2002-2095" ], "details": "Joe Testa hellbent 01 webserver allows attackers to read files that are specified in the hellbent.prefs file by creating a file with a similar name in the web root, as demonstrated using (1) index.webroot and (2) index.ipallow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4gv6-wfqc-jvh9/GHSA-4gv6-wfqc-jvh9.json b/advisories/unreviewed/2022/04/GHSA-4gv6-wfqc-jvh9/GHSA-4gv6-wfqc-jvh9.json index e4aeb36bb1d..19b7bd23ca0 100644 --- a/advisories/unreviewed/2022/04/GHSA-4gv6-wfqc-jvh9/GHSA-4gv6-wfqc-jvh9.json +++ b/advisories/unreviewed/2022/04/GHSA-4gv6-wfqc-jvh9/GHSA-4gv6-wfqc-jvh9.json @@ -7,12 +7,8 @@ "CVE-2002-2150" ], "details": "Firewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet flooding attacks such as (1) TCP SYN flood, (2) UDP flood, or (3) Crikey CRC Flood, which causes the firewall to refuse any new connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4h6r-6326-wcw9/GHSA-4h6r-6326-wcw9.json b/advisories/unreviewed/2022/04/GHSA-4h6r-6326-wcw9/GHSA-4h6r-6326-wcw9.json index 216b615b578..1f94f16a580 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h6r-6326-wcw9/GHSA-4h6r-6326-wcw9.json +++ b/advisories/unreviewed/2022/04/GHSA-4h6r-6326-wcw9/GHSA-4h6r-6326-wcw9.json @@ -7,12 +7,8 @@ "CVE-2002-1972" ], "details": "Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hpw-837c-v7wc/GHSA-4hpw-837c-v7wc.json b/advisories/unreviewed/2022/04/GHSA-4hpw-837c-v7wc/GHSA-4hpw-837c-v7wc.json index dad99691cf8..71d51e707e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hpw-837c-v7wc/GHSA-4hpw-837c-v7wc.json +++ b/advisories/unreviewed/2022/04/GHSA-4hpw-837c-v7wc/GHSA-4hpw-837c-v7wc.json @@ -7,12 +7,8 @@ "CVE-2002-1997" ], "details": "ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hx5-8h46-q282/GHSA-4hx5-8h46-q282.json b/advisories/unreviewed/2022/04/GHSA-4hx5-8h46-q282/GHSA-4hx5-8h46-q282.json index 09f604fed98..f063b502614 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hx5-8h46-q282/GHSA-4hx5-8h46-q282.json +++ b/advisories/unreviewed/2022/04/GHSA-4hx5-8h46-q282/GHSA-4hx5-8h46-q282.json @@ -7,12 +7,8 @@ "CVE-2002-1981" ], "details": "Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the \"public\" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4jqh-pmm2-4786/GHSA-4jqh-pmm2-4786.json b/advisories/unreviewed/2022/04/GHSA-4jqh-pmm2-4786/GHSA-4jqh-pmm2-4786.json index 44274c5f8e4..473114a26b0 100644 --- a/advisories/unreviewed/2022/04/GHSA-4jqh-pmm2-4786/GHSA-4jqh-pmm2-4786.json +++ b/advisories/unreviewed/2022/04/GHSA-4jqh-pmm2-4786/GHSA-4jqh-pmm2-4786.json @@ -7,12 +7,8 @@ "CVE-2002-1909" ], "details": "Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4m5f-59vg-v68x/GHSA-4m5f-59vg-v68x.json b/advisories/unreviewed/2022/04/GHSA-4m5f-59vg-v68x/GHSA-4m5f-59vg-v68x.json index 6d1bda4303b..b3ae6e696be 100644 --- a/advisories/unreviewed/2022/04/GHSA-4m5f-59vg-v68x/GHSA-4m5f-59vg-v68x.json +++ b/advisories/unreviewed/2022/04/GHSA-4m5f-59vg-v68x/GHSA-4m5f-59vg-v68x.json @@ -7,12 +7,8 @@ "CVE-2002-2116" ], "details": "Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4mpf-cq6q-387v/GHSA-4mpf-cq6q-387v.json b/advisories/unreviewed/2022/04/GHSA-4mpf-cq6q-387v/GHSA-4mpf-cq6q-387v.json index cc718efaa9d..4d1c29f967e 100644 --- a/advisories/unreviewed/2022/04/GHSA-4mpf-cq6q-387v/GHSA-4mpf-cq6q-387v.json +++ b/advisories/unreviewed/2022/04/GHSA-4mpf-cq6q-387v/GHSA-4mpf-cq6q-387v.json @@ -7,12 +7,8 @@ "CVE-2002-2127" ], "details": "Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \\Device\\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4q65-h4xr-qhqj/GHSA-4q65-h4xr-qhqj.json b/advisories/unreviewed/2022/04/GHSA-4q65-h4xr-qhqj/GHSA-4q65-h4xr-qhqj.json index 2133c6b1ba6..653dd7eae73 100644 --- a/advisories/unreviewed/2022/04/GHSA-4q65-h4xr-qhqj/GHSA-4q65-h4xr-qhqj.json +++ b/advisories/unreviewed/2022/04/GHSA-4q65-h4xr-qhqj/GHSA-4q65-h4xr-qhqj.json @@ -7,12 +7,8 @@ "CVE-2002-1967" ], "details": "Buffer overflow in XiRCON 1.0 Beta 4 allows remote attackers to cause a denial of service (disconnect) via a long (1) ctcp, (2) primsg, (3) msg, or (4) notice command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4wcf-6fv3-7rr5/GHSA-4wcf-6fv3-7rr5.json b/advisories/unreviewed/2022/04/GHSA-4wcf-6fv3-7rr5/GHSA-4wcf-6fv3-7rr5.json index dfe01cbe30c..2b9872cd272 100644 --- a/advisories/unreviewed/2022/04/GHSA-4wcf-6fv3-7rr5/GHSA-4wcf-6fv3-7rr5.json +++ b/advisories/unreviewed/2022/04/GHSA-4wcf-6fv3-7rr5/GHSA-4wcf-6fv3-7rr5.json @@ -7,12 +7,8 @@ "CVE-2002-1911" ], "details": "ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4xg4-rgg3-px2c/GHSA-4xg4-rgg3-px2c.json b/advisories/unreviewed/2022/04/GHSA-4xg4-rgg3-px2c/GHSA-4xg4-rgg3-px2c.json index d395997e6c2..933bc9efce1 100644 --- a/advisories/unreviewed/2022/04/GHSA-4xg4-rgg3-px2c/GHSA-4xg4-rgg3-px2c.json +++ b/advisories/unreviewed/2022/04/GHSA-4xg4-rgg3-px2c/GHSA-4xg4-rgg3-px2c.json @@ -7,12 +7,8 @@ "CVE-2002-2028" ], "details": "The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-527c-8rxj-jcj9/GHSA-527c-8rxj-jcj9.json b/advisories/unreviewed/2022/04/GHSA-527c-8rxj-jcj9/GHSA-527c-8rxj-jcj9.json index 01045e2b61f..e9b84823ed1 100644 --- a/advisories/unreviewed/2022/04/GHSA-527c-8rxj-jcj9/GHSA-527c-8rxj-jcj9.json +++ b/advisories/unreviewed/2022/04/GHSA-527c-8rxj-jcj9/GHSA-527c-8rxj-jcj9.json @@ -7,12 +7,8 @@ "CVE-2002-2102" ], "details": "InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5338-9q8m-65gq/GHSA-5338-9q8m-65gq.json b/advisories/unreviewed/2022/04/GHSA-5338-9q8m-65gq/GHSA-5338-9q8m-65gq.json index 9720995ddac..20c04d0659b 100644 --- a/advisories/unreviewed/2022/04/GHSA-5338-9q8m-65gq/GHSA-5338-9q8m-65gq.json +++ b/advisories/unreviewed/2022/04/GHSA-5338-9q8m-65gq/GHSA-5338-9q8m-65gq.json @@ -7,12 +7,8 @@ "CVE-2002-1881" ], "details": "Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-572p-4m9q-5cx8/GHSA-572p-4m9q-5cx8.json b/advisories/unreviewed/2022/04/GHSA-572p-4m9q-5cx8/GHSA-572p-4m9q-5cx8.json index 2f7348fee5e..8dc4af743e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-572p-4m9q-5cx8/GHSA-572p-4m9q-5cx8.json +++ b/advisories/unreviewed/2022/04/GHSA-572p-4m9q-5cx8/GHSA-572p-4m9q-5cx8.json @@ -7,12 +7,8 @@ "CVE-2002-1901" ], "details": "Cross-site scripting (XSS) vulnerability in Bodo Bauer BBGallery 1.0 allows remote attackers to inject arbitrary web script or HTML via image tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5936-85px-cq43/GHSA-5936-85px-cq43.json b/advisories/unreviewed/2022/04/GHSA-5936-85px-cq43/GHSA-5936-85px-cq43.json index ae00a1decf6..587ebf05342 100644 --- a/advisories/unreviewed/2022/04/GHSA-5936-85px-cq43/GHSA-5936-85px-cq43.json +++ b/advisories/unreviewed/2022/04/GHSA-5936-85px-cq43/GHSA-5936-85px-cq43.json @@ -7,12 +7,8 @@ "CVE-2002-1994" ], "details": "advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5g82-wq8j-r7j5/GHSA-5g82-wq8j-r7j5.json b/advisories/unreviewed/2022/04/GHSA-5g82-wq8j-r7j5/GHSA-5g82-wq8j-r7j5.json index 065065abb20..2a6f45eab85 100644 --- a/advisories/unreviewed/2022/04/GHSA-5g82-wq8j-r7j5/GHSA-5g82-wq8j-r7j5.json +++ b/advisories/unreviewed/2022/04/GHSA-5g82-wq8j-r7j5/GHSA-5g82-wq8j-r7j5.json @@ -7,12 +7,8 @@ "CVE-2002-2130" ], "details": "publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5m2g-w3gj-4763/GHSA-5m2g-w3gj-4763.json b/advisories/unreviewed/2022/04/GHSA-5m2g-w3gj-4763/GHSA-5m2g-w3gj-4763.json index 938a924bfd5..4cb5c5e7194 100644 --- a/advisories/unreviewed/2022/04/GHSA-5m2g-w3gj-4763/GHSA-5m2g-w3gj-4763.json +++ b/advisories/unreviewed/2022/04/GHSA-5m2g-w3gj-4763/GHSA-5m2g-w3gj-4763.json @@ -7,12 +7,8 @@ "CVE-2002-2052" ], "details": "Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1) scanning all ports on a single host and (2) scanning a network of hosts for a single open port through the router. NOTE: the vendor could not reproduce this issue, saying that the original reporter was using an interim release of the software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5q9j-v555-w274/GHSA-5q9j-v555-w274.json b/advisories/unreviewed/2022/04/GHSA-5q9j-v555-w274/GHSA-5q9j-v555-w274.json index 9822fe2a92e..e176cbfc5ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-5q9j-v555-w274/GHSA-5q9j-v555-w274.json +++ b/advisories/unreviewed/2022/04/GHSA-5q9j-v555-w274/GHSA-5q9j-v555-w274.json @@ -7,12 +7,8 @@ "CVE-2002-1941" ], "details": "Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5qv2-c495-gxm4/GHSA-5qv2-c495-gxm4.json b/advisories/unreviewed/2022/04/GHSA-5qv2-c495-gxm4/GHSA-5qv2-c495-gxm4.json index 62923189c6f..cdcbdda3ca6 100644 --- a/advisories/unreviewed/2022/04/GHSA-5qv2-c495-gxm4/GHSA-5qv2-c495-gxm4.json +++ b/advisories/unreviewed/2022/04/GHSA-5qv2-c495-gxm4/GHSA-5qv2-c495-gxm4.json @@ -7,12 +7,8 @@ "CVE-2002-2158" ], "details": "zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5vm4-hjfj-5frm/GHSA-5vm4-hjfj-5frm.json b/advisories/unreviewed/2022/04/GHSA-5vm4-hjfj-5frm/GHSA-5vm4-hjfj-5frm.json index d267012e4a2..ab958a3393c 100644 --- a/advisories/unreviewed/2022/04/GHSA-5vm4-hjfj-5frm/GHSA-5vm4-hjfj-5frm.json +++ b/advisories/unreviewed/2022/04/GHSA-5vm4-hjfj-5frm/GHSA-5vm4-hjfj-5frm.json @@ -7,12 +7,8 @@ "CVE-2002-2020" ], "details": "Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26 uses a default administrator password and accepts admin logins on the external interface, which allows remote attackers to gain privileges if the password is not changed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5vxx-hcff-g2xw/GHSA-5vxx-hcff-g2xw.json b/advisories/unreviewed/2022/04/GHSA-5vxx-hcff-g2xw/GHSA-5vxx-hcff-g2xw.json index c7dd557843d..0e1282e08e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-5vxx-hcff-g2xw/GHSA-5vxx-hcff-g2xw.json +++ b/advisories/unreviewed/2022/04/GHSA-5vxx-hcff-g2xw/GHSA-5vxx-hcff-g2xw.json @@ -7,12 +7,8 @@ "CVE-2002-2075" ], "details": "ICQ 2001a and 2002b allows remote attackers to cause a denial of service (memory consumption and hang) via a contact message with a large contacts number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5x99-3m4j-vwwh/GHSA-5x99-3m4j-vwwh.json b/advisories/unreviewed/2022/04/GHSA-5x99-3m4j-vwwh/GHSA-5x99-3m4j-vwwh.json index fc653ffeb87..5c8353a6825 100644 --- a/advisories/unreviewed/2022/04/GHSA-5x99-3m4j-vwwh/GHSA-5x99-3m4j-vwwh.json +++ b/advisories/unreviewed/2022/04/GHSA-5x99-3m4j-vwwh/GHSA-5x99-3m4j-vwwh.json @@ -7,12 +7,8 @@ "CVE-2002-2100" ], "details": "Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-64rm-hx97-wpqj/GHSA-64rm-hx97-wpqj.json b/advisories/unreviewed/2022/04/GHSA-64rm-hx97-wpqj/GHSA-64rm-hx97-wpqj.json index f70e860ef32..059923e0acc 100644 --- a/advisories/unreviewed/2022/04/GHSA-64rm-hx97-wpqj/GHSA-64rm-hx97-wpqj.json +++ b/advisories/unreviewed/2022/04/GHSA-64rm-hx97-wpqj/GHSA-64rm-hx97-wpqj.json @@ -7,12 +7,8 @@ "CVE-2002-2085" ], "details": "Directory traversal vulnerability in page.cgi of WWWeBBB Forum 3.82 beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-65xq-gc4r-fmm7/GHSA-65xq-gc4r-fmm7.json b/advisories/unreviewed/2022/04/GHSA-65xq-gc4r-fmm7/GHSA-65xq-gc4r-fmm7.json index 2922fd18a01..96614a6a803 100644 --- a/advisories/unreviewed/2022/04/GHSA-65xq-gc4r-fmm7/GHSA-65xq-gc4r-fmm7.json +++ b/advisories/unreviewed/2022/04/GHSA-65xq-gc4r-fmm7/GHSA-65xq-gc4r-fmm7.json @@ -7,12 +7,8 @@ "CVE-2002-1892" ], "details": "NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configuration file is made, which allows local users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-696x-5fgw-5868/GHSA-696x-5fgw-5868.json b/advisories/unreviewed/2022/04/GHSA-696x-5fgw-5868/GHSA-696x-5fgw-5868.json index e3b11c1a37f..98dab270c2e 100644 --- a/advisories/unreviewed/2022/04/GHSA-696x-5fgw-5868/GHSA-696x-5fgw-5868.json +++ b/advisories/unreviewed/2022/04/GHSA-696x-5fgw-5868/GHSA-696x-5fgw-5868.json @@ -7,12 +7,8 @@ "CVE-2002-1979" ], "details": "WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6gm3-644h-2mm9/GHSA-6gm3-644h-2mm9.json b/advisories/unreviewed/2022/04/GHSA-6gm3-644h-2mm9/GHSA-6gm3-644h-2mm9.json index a0860676e27..0e642ea56b8 100644 --- a/advisories/unreviewed/2022/04/GHSA-6gm3-644h-2mm9/GHSA-6gm3-644h-2mm9.json +++ b/advisories/unreviewed/2022/04/GHSA-6gm3-644h-2mm9/GHSA-6gm3-644h-2mm9.json @@ -7,12 +7,8 @@ "CVE-2002-1924" ], "details": "PowerChute plus 5.0.2 creates a \"Pwrchute\" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rj3-hjpx-4fhp/GHSA-6rj3-hjpx-4fhp.json b/advisories/unreviewed/2022/04/GHSA-6rj3-hjpx-4fhp/GHSA-6rj3-hjpx-4fhp.json index a3c41a5a29f..ad69ead611c 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rj3-hjpx-4fhp/GHSA-6rj3-hjpx-4fhp.json +++ b/advisories/unreviewed/2022/04/GHSA-6rj3-hjpx-4fhp/GHSA-6rj3-hjpx-4fhp.json @@ -7,12 +7,8 @@ "CVE-2002-2096" ], "details": "Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6v36-wr64-x57x/GHSA-6v36-wr64-x57x.json b/advisories/unreviewed/2022/04/GHSA-6v36-wr64-x57x/GHSA-6v36-wr64-x57x.json index e82ed892c24..93756932860 100644 --- a/advisories/unreviewed/2022/04/GHSA-6v36-wr64-x57x/GHSA-6v36-wr64-x57x.json +++ b/advisories/unreviewed/2022/04/GHSA-6v36-wr64-x57x/GHSA-6v36-wr64-x57x.json @@ -7,12 +7,8 @@ "CVE-2002-1891" ], "details": "Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6vcj-7xg8-5xfw/GHSA-6vcj-7xg8-5xfw.json b/advisories/unreviewed/2022/04/GHSA-6vcj-7xg8-5xfw/GHSA-6vcj-7xg8-5xfw.json index ffad8636c94..993ee0470f2 100644 --- a/advisories/unreviewed/2022/04/GHSA-6vcj-7xg8-5xfw/GHSA-6vcj-7xg8-5xfw.json +++ b/advisories/unreviewed/2022/04/GHSA-6vcj-7xg8-5xfw/GHSA-6vcj-7xg8-5xfw.json @@ -7,12 +7,8 @@ "CVE-2002-1926" ], "details": "Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-737h-px7x-jjwj/GHSA-737h-px7x-jjwj.json b/advisories/unreviewed/2022/04/GHSA-737h-px7x-jjwj/GHSA-737h-px7x-jjwj.json index 423d6576a91..19edc3a6cad 100644 --- a/advisories/unreviewed/2022/04/GHSA-737h-px7x-jjwj/GHSA-737h-px7x-jjwj.json +++ b/advisories/unreviewed/2022/04/GHSA-737h-px7x-jjwj/GHSA-737h-px7x-jjwj.json @@ -7,12 +7,8 @@ "CVE-2002-2081" ], "details": "cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\\temp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-73mm-2mw9-vjgg/GHSA-73mm-2mw9-vjgg.json b/advisories/unreviewed/2022/04/GHSA-73mm-2mw9-vjgg/GHSA-73mm-2mw9-vjgg.json index 322c0955a72..95fe1eee421 100644 --- a/advisories/unreviewed/2022/04/GHSA-73mm-2mw9-vjgg/GHSA-73mm-2mw9-vjgg.json +++ b/advisories/unreviewed/2022/04/GHSA-73mm-2mw9-vjgg/GHSA-73mm-2mw9-vjgg.json @@ -7,12 +7,8 @@ "CVE-2002-2112" ], "details": "RCA Digital Cable Modem DCM225 and DCM225E, and other modems that must conform to the Data-over-Cable Service Interface Specifications DOCSIS standard, uses the \"public\" community string for SNMP access, which allows remote attackers to read or write MIB information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7556-5p5w-6c84/GHSA-7556-5p5w-6c84.json b/advisories/unreviewed/2022/04/GHSA-7556-5p5w-6c84/GHSA-7556-5p5w-6c84.json index 943c9cf5ca1..ee048dcef7c 100644 --- a/advisories/unreviewed/2022/04/GHSA-7556-5p5w-6c84/GHSA-7556-5p5w-6c84.json +++ b/advisories/unreviewed/2022/04/GHSA-7556-5p5w-6c84/GHSA-7556-5p5w-6c84.json @@ -7,12 +7,8 @@ "CVE-2002-1971" ], "details": "The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-75f5-hjpg-7h4w/GHSA-75f5-hjpg-7h4w.json b/advisories/unreviewed/2022/04/GHSA-75f5-hjpg-7h4w/GHSA-75f5-hjpg-7h4w.json index e5ca90e05d6..fd2d236814a 100644 --- a/advisories/unreviewed/2022/04/GHSA-75f5-hjpg-7h4w/GHSA-75f5-hjpg-7h4w.json +++ b/advisories/unreviewed/2022/04/GHSA-75f5-hjpg-7h4w/GHSA-75f5-hjpg-7h4w.json @@ -7,12 +7,8 @@ "CVE-2002-2025" ], "details": "Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-768p-q28g-4q5f/GHSA-768p-q28g-4q5f.json b/advisories/unreviewed/2022/04/GHSA-768p-q28g-4q5f/GHSA-768p-q28g-4q5f.json index 34ce6a37c02..5f7f06b18e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-768p-q28g-4q5f/GHSA-768p-q28g-4q5f.json +++ b/advisories/unreviewed/2022/04/GHSA-768p-q28g-4q5f/GHSA-768p-q28g-4q5f.json @@ -7,12 +7,8 @@ "CVE-2002-2123" ], "details": "PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-769h-6jjc-vmpj/GHSA-769h-6jjc-vmpj.json b/advisories/unreviewed/2022/04/GHSA-769h-6jjc-vmpj/GHSA-769h-6jjc-vmpj.json index c446f4fff86..b06370372b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-769h-6jjc-vmpj/GHSA-769h-6jjc-vmpj.json +++ b/advisories/unreviewed/2022/04/GHSA-769h-6jjc-vmpj/GHSA-769h-6jjc-vmpj.json @@ -7,12 +7,8 @@ "CVE-2002-1863" ], "details": "Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-76mm-xxrx-cx3g/GHSA-76mm-xxrx-cx3g.json b/advisories/unreviewed/2022/04/GHSA-76mm-xxrx-cx3g/GHSA-76mm-xxrx-cx3g.json index 50e06a017d4..a33df6eb973 100644 --- a/advisories/unreviewed/2022/04/GHSA-76mm-xxrx-cx3g/GHSA-76mm-xxrx-cx3g.json +++ b/advisories/unreviewed/2022/04/GHSA-76mm-xxrx-cx3g/GHSA-76mm-xxrx-cx3g.json @@ -7,12 +7,8 @@ "CVE-2002-1962" ], "details": "Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL with an IP address instead of a hostname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-77fh-vp9q-jhpc/GHSA-77fh-vp9q-jhpc.json b/advisories/unreviewed/2022/04/GHSA-77fh-vp9q-jhpc/GHSA-77fh-vp9q-jhpc.json index 3b54ae30c3a..dfe5f3e4141 100644 --- a/advisories/unreviewed/2022/04/GHSA-77fh-vp9q-jhpc/GHSA-77fh-vp9q-jhpc.json +++ b/advisories/unreviewed/2022/04/GHSA-77fh-vp9q-jhpc/GHSA-77fh-vp9q-jhpc.json @@ -7,12 +7,8 @@ "CVE-2002-1970" ], "details": "SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7873-wxw5-q3wj/GHSA-7873-wxw5-q3wj.json b/advisories/unreviewed/2022/04/GHSA-7873-wxw5-q3wj/GHSA-7873-wxw5-q3wj.json index 87735902cf6..43a19827345 100644 --- a/advisories/unreviewed/2022/04/GHSA-7873-wxw5-q3wj/GHSA-7873-wxw5-q3wj.json +++ b/advisories/unreviewed/2022/04/GHSA-7873-wxw5-q3wj/GHSA-7873-wxw5-q3wj.json @@ -7,12 +7,8 @@ "CVE-2002-1690" ], "details": "Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka \"security issue,\" as fixed by APAR IY28225.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7pr9-q2qp-2jxf/GHSA-7pr9-q2qp-2jxf.json b/advisories/unreviewed/2022/04/GHSA-7pr9-q2qp-2jxf/GHSA-7pr9-q2qp-2jxf.json index 85568715f10..61a91d91547 100644 --- a/advisories/unreviewed/2022/04/GHSA-7pr9-q2qp-2jxf/GHSA-7pr9-q2qp-2jxf.json +++ b/advisories/unreviewed/2022/04/GHSA-7pr9-q2qp-2jxf/GHSA-7pr9-q2qp-2jxf.json @@ -7,12 +7,8 @@ "CVE-2002-1896" ], "details": "Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7q59-v2wm-mrm7/GHSA-7q59-v2wm-mrm7.json b/advisories/unreviewed/2022/04/GHSA-7q59-v2wm-mrm7/GHSA-7q59-v2wm-mrm7.json index 542e825b041..169c830c658 100644 --- a/advisories/unreviewed/2022/04/GHSA-7q59-v2wm-mrm7/GHSA-7q59-v2wm-mrm7.json +++ b/advisories/unreviewed/2022/04/GHSA-7q59-v2wm-mrm7/GHSA-7q59-v2wm-mrm7.json @@ -7,12 +7,8 @@ "CVE-2002-1960" ], "details": "Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7q5c-v9g6-cw6h/GHSA-7q5c-v9g6-cw6h.json b/advisories/unreviewed/2022/04/GHSA-7q5c-v9g6-cw6h/GHSA-7q5c-v9g6-cw6h.json index ead693de82d..9c41a8cccd9 100644 --- a/advisories/unreviewed/2022/04/GHSA-7q5c-v9g6-cw6h/GHSA-7q5c-v9g6-cw6h.json +++ b/advisories/unreviewed/2022/04/GHSA-7q5c-v9g6-cw6h/GHSA-7q5c-v9g6-cw6h.json @@ -7,12 +7,8 @@ "CVE-2002-1873" ], "details": "Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7v25-xm54-46x6/GHSA-7v25-xm54-46x6.json b/advisories/unreviewed/2022/04/GHSA-7v25-xm54-46x6/GHSA-7v25-xm54-46x6.json index 858a00f11f5..2ed782d0baa 100644 --- a/advisories/unreviewed/2022/04/GHSA-7v25-xm54-46x6/GHSA-7v25-xm54-46x6.json +++ b/advisories/unreviewed/2022/04/GHSA-7v25-xm54-46x6/GHSA-7v25-xm54-46x6.json @@ -7,12 +7,8 @@ "CVE-2002-1885" ], "details": "PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7x22-53rm-c366/GHSA-7x22-53rm-c366.json b/advisories/unreviewed/2022/04/GHSA-7x22-53rm-c366/GHSA-7x22-53rm-c366.json index 89c03d4518b..c5b97bb44b2 100644 --- a/advisories/unreviewed/2022/04/GHSA-7x22-53rm-c366/GHSA-7x22-53rm-c366.json +++ b/advisories/unreviewed/2022/04/GHSA-7x22-53rm-c366/GHSA-7x22-53rm-c366.json @@ -7,12 +7,8 @@ "CVE-2002-2134" ], "details": "haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7xxp-g4rj-p93h/GHSA-7xxp-g4rj-p93h.json b/advisories/unreviewed/2022/04/GHSA-7xxp-g4rj-p93h/GHSA-7xxp-g4rj-p93h.json index 6f773a90f15..3d621f9d118 100644 --- a/advisories/unreviewed/2022/04/GHSA-7xxp-g4rj-p93h/GHSA-7xxp-g4rj-p93h.json +++ b/advisories/unreviewed/2022/04/GHSA-7xxp-g4rj-p93h/GHSA-7xxp-g4rj-p93h.json @@ -7,12 +7,8 @@ "CVE-2002-2033" ], "details": "faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-825r-75m8-xqrw/GHSA-825r-75m8-xqrw.json b/advisories/unreviewed/2022/04/GHSA-825r-75m8-xqrw/GHSA-825r-75m8-xqrw.json index e3771868d96..f5ac2d8016c 100644 --- a/advisories/unreviewed/2022/04/GHSA-825r-75m8-xqrw/GHSA-825r-75m8-xqrw.json +++ b/advisories/unreviewed/2022/04/GHSA-825r-75m8-xqrw/GHSA-825r-75m8-xqrw.json @@ -7,12 +7,8 @@ "CVE-2002-1857" ], "details": "jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot (\"WEB-INF.\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-82c4-g244-p5pf/GHSA-82c4-g244-p5pf.json b/advisories/unreviewed/2022/04/GHSA-82c4-g244-p5pf/GHSA-82c4-g244-p5pf.json index 7292ab5ea4f..9effa0b552f 100644 --- a/advisories/unreviewed/2022/04/GHSA-82c4-g244-p5pf/GHSA-82c4-g244-p5pf.json +++ b/advisories/unreviewed/2022/04/GHSA-82c4-g244-p5pf/GHSA-82c4-g244-p5pf.json @@ -7,12 +7,8 @@ "CVE-2002-2143" ], "details": "The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-863q-r39j-7g42/GHSA-863q-r39j-7g42.json b/advisories/unreviewed/2022/04/GHSA-863q-r39j-7g42/GHSA-863q-r39j-7g42.json index e0caffb05af..3d880d40d3b 100644 --- a/advisories/unreviewed/2022/04/GHSA-863q-r39j-7g42/GHSA-863q-r39j-7g42.json +++ b/advisories/unreviewed/2022/04/GHSA-863q-r39j-7g42/GHSA-863q-r39j-7g42.json @@ -7,12 +7,8 @@ "CVE-2002-2131" ], "details": "Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-87p5-fx33-2fh8/GHSA-87p5-fx33-2fh8.json b/advisories/unreviewed/2022/04/GHSA-87p5-fx33-2fh8/GHSA-87p5-fx33-2fh8.json index 534e598c980..a0137613677 100644 --- a/advisories/unreviewed/2022/04/GHSA-87p5-fx33-2fh8/GHSA-87p5-fx33-2fh8.json +++ b/advisories/unreviewed/2022/04/GHSA-87p5-fx33-2fh8/GHSA-87p5-fx33-2fh8.json @@ -7,12 +7,8 @@ "CVE-2002-1983" ], "details": "The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-87pj-wmx5-p5vv/GHSA-87pj-wmx5-p5vv.json b/advisories/unreviewed/2022/04/GHSA-87pj-wmx5-p5vv/GHSA-87pj-wmx5-p5vv.json index b6c71091631..d8271f92565 100644 --- a/advisories/unreviewed/2022/04/GHSA-87pj-wmx5-p5vv/GHSA-87pj-wmx5-p5vv.json +++ b/advisories/unreviewed/2022/04/GHSA-87pj-wmx5-p5vv/GHSA-87pj-wmx5-p5vv.json @@ -7,12 +7,8 @@ "CVE-2002-2014" ], "details": "Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8chj-8rr6-cxcq/GHSA-8chj-8rr6-cxcq.json b/advisories/unreviewed/2022/04/GHSA-8chj-8rr6-cxcq/GHSA-8chj-8rr6-cxcq.json index 842d4a36c09..af8bb254578 100644 --- a/advisories/unreviewed/2022/04/GHSA-8chj-8rr6-cxcq/GHSA-8chj-8rr6-cxcq.json +++ b/advisories/unreviewed/2022/04/GHSA-8chj-8rr6-cxcq/GHSA-8chj-8rr6-cxcq.json @@ -7,12 +7,8 @@ "CVE-2002-2171" ], "details": "Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a \"%db\" request in a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8j6w-vm25-72jv/GHSA-8j6w-vm25-72jv.json b/advisories/unreviewed/2022/04/GHSA-8j6w-vm25-72jv/GHSA-8j6w-vm25-72jv.json index 49045b88334..a3b82aa30e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-8j6w-vm25-72jv/GHSA-8j6w-vm25-72jv.json +++ b/advisories/unreviewed/2022/04/GHSA-8j6w-vm25-72jv/GHSA-8j6w-vm25-72jv.json @@ -7,12 +7,8 @@ "CVE-2002-1986" ], "details": "Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (\".\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8jj7-g8p8-xc3g/GHSA-8jj7-g8p8-xc3g.json b/advisories/unreviewed/2022/04/GHSA-8jj7-g8p8-xc3g/GHSA-8jj7-g8p8-xc3g.json index c8f1dc9371b..c087118c10d 100644 --- a/advisories/unreviewed/2022/04/GHSA-8jj7-g8p8-xc3g/GHSA-8jj7-g8p8-xc3g.json +++ b/advisories/unreviewed/2022/04/GHSA-8jj7-g8p8-xc3g/GHSA-8jj7-g8p8-xc3g.json @@ -7,12 +7,8 @@ "CVE-2002-2098" ], "details": "Buffer overflow in axspawn.c in Axspawn-pam before 0.2.1a allows remote attackers to execute arbitrary code via large packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8pc2-hpvr-6f94/GHSA-8pc2-hpvr-6f94.json b/advisories/unreviewed/2022/04/GHSA-8pc2-hpvr-6f94/GHSA-8pc2-hpvr-6f94.json index 70d563b74b4..595c5ba20a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-8pc2-hpvr-6f94/GHSA-8pc2-hpvr-6f94.json +++ b/advisories/unreviewed/2022/04/GHSA-8pc2-hpvr-6f94/GHSA-8pc2-hpvr-6f94.json @@ -7,12 +7,8 @@ "CVE-2002-1977" ], "details": "Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the \"Passphrase Cache\" option, which could allow attackers to open encrypted files without providing a passphrase.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8q52-w544-h2xc/GHSA-8q52-w544-h2xc.json b/advisories/unreviewed/2022/04/GHSA-8q52-w544-h2xc/GHSA-8q52-w544-h2xc.json index fd83076a857..46844491476 100644 --- a/advisories/unreviewed/2022/04/GHSA-8q52-w544-h2xc/GHSA-8q52-w544-h2xc.json +++ b/advisories/unreviewed/2022/04/GHSA-8q52-w544-h2xc/GHSA-8q52-w544-h2xc.json @@ -7,12 +7,8 @@ "CVE-2002-2015" ], "details": "PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-952x-fg65-rcqp/GHSA-952x-fg65-rcqp.json b/advisories/unreviewed/2022/04/GHSA-952x-fg65-rcqp/GHSA-952x-fg65-rcqp.json index 3a8c409eb06..c5af8bb894f 100644 --- a/advisories/unreviewed/2022/04/GHSA-952x-fg65-rcqp/GHSA-952x-fg65-rcqp.json +++ b/advisories/unreviewed/2022/04/GHSA-952x-fg65-rcqp/GHSA-952x-fg65-rcqp.json @@ -7,12 +7,8 @@ "CVE-2002-1862" ], "details": "SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-95gp-rrqv-44f3/GHSA-95gp-rrqv-44f3.json b/advisories/unreviewed/2022/04/GHSA-95gp-rrqv-44f3/GHSA-95gp-rrqv-44f3.json index ec636792dff..efbede81cce 100644 --- a/advisories/unreviewed/2022/04/GHSA-95gp-rrqv-44f3/GHSA-95gp-rrqv-44f3.json +++ b/advisories/unreviewed/2022/04/GHSA-95gp-rrqv-44f3/GHSA-95gp-rrqv-44f3.json @@ -7,12 +7,8 @@ "CVE-2002-1963" ], "details": "Linux kernel 2.4.1 through 2.4.19 sets root's NR_RESERVED_FILES limit to 10 files, which allows local users to cause a denial of service (resource exhaustion) by opening 10 setuid binaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-96xw-fw95-7838/GHSA-96xw-fw95-7838.json b/advisories/unreviewed/2022/04/GHSA-96xw-fw95-7838/GHSA-96xw-fw95-7838.json index afb8b04f988..6f45ab2df03 100644 --- a/advisories/unreviewed/2022/04/GHSA-96xw-fw95-7838/GHSA-96xw-fw95-7838.json +++ b/advisories/unreviewed/2022/04/GHSA-96xw-fw95-7838/GHSA-96xw-fw95-7838.json @@ -7,12 +7,8 @@ "CVE-2002-1916" ], "details": "Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-97gq-w6wg-79ph/GHSA-97gq-w6wg-79ph.json b/advisories/unreviewed/2022/04/GHSA-97gq-w6wg-79ph/GHSA-97gq-w6wg-79ph.json index 8dfd95e23b3..46c4d3253f0 100644 --- a/advisories/unreviewed/2022/04/GHSA-97gq-w6wg-79ph/GHSA-97gq-w6wg-79ph.json +++ b/advisories/unreviewed/2022/04/GHSA-97gq-w6wg-79ph/GHSA-97gq-w6wg-79ph.json @@ -7,12 +7,8 @@ "CVE-2002-2012" ], "details": "Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause \"unexpected results\" via an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-97p6-pjxh-c948/GHSA-97p6-pjxh-c948.json b/advisories/unreviewed/2022/04/GHSA-97p6-pjxh-c948/GHSA-97p6-pjxh-c948.json index 83d1639f52f..078aeeaaa0c 100644 --- a/advisories/unreviewed/2022/04/GHSA-97p6-pjxh-c948/GHSA-97p6-pjxh-c948.json +++ b/advisories/unreviewed/2022/04/GHSA-97p6-pjxh-c948/GHSA-97p6-pjxh-c948.json @@ -7,12 +7,8 @@ "CVE-2002-1985" ], "details": "iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long \"MAIL FROM\" command, possibly triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-994m-2xmx-fwhg/GHSA-994m-2xmx-fwhg.json b/advisories/unreviewed/2022/04/GHSA-994m-2xmx-fwhg/GHSA-994m-2xmx-fwhg.json index b07a4482b68..c6839132029 100644 --- a/advisories/unreviewed/2022/04/GHSA-994m-2xmx-fwhg/GHSA-994m-2xmx-fwhg.json +++ b/advisories/unreviewed/2022/04/GHSA-994m-2xmx-fwhg/GHSA-994m-2xmx-fwhg.json @@ -7,12 +7,8 @@ "CVE-2002-2111" ], "details": "Fwmon before 1.0.10 allows remote attackers to cause a denial of service (crash) by causing the kernel to return a large packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9f96-5cpf-pvw6/GHSA-9f96-5cpf-pvw6.json b/advisories/unreviewed/2022/04/GHSA-9f96-5cpf-pvw6/GHSA-9f96-5cpf-pvw6.json index 64e0f4eccdd..4e8960349bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-9f96-5cpf-pvw6/GHSA-9f96-5cpf-pvw6.json +++ b/advisories/unreviewed/2022/04/GHSA-9f96-5cpf-pvw6/GHSA-9f96-5cpf-pvw6.json @@ -7,12 +7,8 @@ "CVE-2002-2022" ], "details": "Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9gjx-2rfp-gv42/GHSA-9gjx-2rfp-gv42.json b/advisories/unreviewed/2022/04/GHSA-9gjx-2rfp-gv42/GHSA-9gjx-2rfp-gv42.json index 4fa63adce44..274433af935 100644 --- a/advisories/unreviewed/2022/04/GHSA-9gjx-2rfp-gv42/GHSA-9gjx-2rfp-gv42.json +++ b/advisories/unreviewed/2022/04/GHSA-9gjx-2rfp-gv42/GHSA-9gjx-2rfp-gv42.json @@ -7,12 +7,8 @@ "CVE-2002-2044" ], "details": "Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the phpinfo action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9h6p-23gq-369f/GHSA-9h6p-23gq-369f.json b/advisories/unreviewed/2022/04/GHSA-9h6p-23gq-369f/GHSA-9h6p-23gq-369f.json index 90e784f513f..26f9c3e1717 100644 --- a/advisories/unreviewed/2022/04/GHSA-9h6p-23gq-369f/GHSA-9h6p-23gq-369f.json +++ b/advisories/unreviewed/2022/04/GHSA-9h6p-23gq-369f/GHSA-9h6p-23gq-369f.json @@ -7,12 +7,8 @@ "CVE-2002-2117" ], "details": "Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9jpj-mr88-j5c8/GHSA-9jpj-mr88-j5c8.json b/advisories/unreviewed/2022/04/GHSA-9jpj-mr88-j5c8/GHSA-9jpj-mr88-j5c8.json index ce317c96d93..94cabb33478 100644 --- a/advisories/unreviewed/2022/04/GHSA-9jpj-mr88-j5c8/GHSA-9jpj-mr88-j5c8.json +++ b/advisories/unreviewed/2022/04/GHSA-9jpj-mr88-j5c8/GHSA-9jpj-mr88-j5c8.json @@ -7,12 +7,8 @@ "CVE-2002-2121" ], "details": "SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9r3w-hpj5-5rpw/GHSA-9r3w-hpj5-5rpw.json b/advisories/unreviewed/2022/04/GHSA-9r3w-hpj5-5rpw/GHSA-9r3w-hpj5-5rpw.json index ddb99ca1e6d..cb4787f64c3 100644 --- a/advisories/unreviewed/2022/04/GHSA-9r3w-hpj5-5rpw/GHSA-9r3w-hpj5-5rpw.json +++ b/advisories/unreviewed/2022/04/GHSA-9r3w-hpj5-5rpw/GHSA-9r3w-hpj5-5rpw.json @@ -7,12 +7,8 @@ "CVE-2002-2109" ], "details": "Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9x4q-mqv8-f9qg/GHSA-9x4q-mqv8-f9qg.json b/advisories/unreviewed/2022/04/GHSA-9x4q-mqv8-f9qg/GHSA-9x4q-mqv8-f9qg.json index 8ebb07ea6a2..38c53695e2f 100644 --- a/advisories/unreviewed/2022/04/GHSA-9x4q-mqv8-f9qg/GHSA-9x4q-mqv8-f9qg.json +++ b/advisories/unreviewed/2022/04/GHSA-9x4q-mqv8-f9qg/GHSA-9x4q-mqv8-f9qg.json @@ -7,12 +7,8 @@ "CVE-2002-1934" ], "details": "Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physical password, and other registration information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c26j-wj6j-55xg/GHSA-c26j-wj6j-55xg.json b/advisories/unreviewed/2022/04/GHSA-c26j-wj6j-55xg/GHSA-c26j-wj6j-55xg.json index 77c157bdc45..c68f10fec88 100644 --- a/advisories/unreviewed/2022/04/GHSA-c26j-wj6j-55xg/GHSA-c26j-wj6j-55xg.json +++ b/advisories/unreviewed/2022/04/GHSA-c26j-wj6j-55xg/GHSA-c26j-wj6j-55xg.json @@ -7,12 +7,8 @@ "CVE-2002-2118" ], "details": "Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c36p-446q-54r5/GHSA-c36p-446q-54r5.json b/advisories/unreviewed/2022/04/GHSA-c36p-446q-54r5/GHSA-c36p-446q-54r5.json index 17ff28d2b52..de4fb5763a2 100644 --- a/advisories/unreviewed/2022/04/GHSA-c36p-446q-54r5/GHSA-c36p-446q-54r5.json +++ b/advisories/unreviewed/2022/04/GHSA-c36p-446q-54r5/GHSA-c36p-446q-54r5.json @@ -7,12 +7,8 @@ "CVE-2002-1921" ], "details": "The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c3fg-g4vp-22qm/GHSA-c3fg-g4vp-22qm.json b/advisories/unreviewed/2022/04/GHSA-c3fg-g4vp-22qm/GHSA-c3fg-g4vp-22qm.json index 441af7716cf..0e2f00fc873 100644 --- a/advisories/unreviewed/2022/04/GHSA-c3fg-g4vp-22qm/GHSA-c3fg-g4vp-22qm.json +++ b/advisories/unreviewed/2022/04/GHSA-c3fg-g4vp-22qm/GHSA-c3fg-g4vp-22qm.json @@ -7,12 +7,8 @@ "CVE-2002-1982" ], "details": "Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c494-fxwq-p4x4/GHSA-c494-fxwq-p4x4.json b/advisories/unreviewed/2022/04/GHSA-c494-fxwq-p4x4/GHSA-c494-fxwq-p4x4.json index 578c222ba65..fa6fd71968e 100644 --- a/advisories/unreviewed/2022/04/GHSA-c494-fxwq-p4x4/GHSA-c494-fxwq-p4x4.json +++ b/advisories/unreviewed/2022/04/GHSA-c494-fxwq-p4x4/GHSA-c494-fxwq-p4x4.json @@ -7,12 +7,8 @@ "CVE-2002-1870" ], "details": "Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c7w7-v6qv-rv37/GHSA-c7w7-v6qv-rv37.json b/advisories/unreviewed/2022/04/GHSA-c7w7-v6qv-rv37/GHSA-c7w7-v6qv-rv37.json index 727789724b4..40757f0db9f 100644 --- a/advisories/unreviewed/2022/04/GHSA-c7w7-v6qv-rv37/GHSA-c7w7-v6qv-rv37.json +++ b/advisories/unreviewed/2022/04/GHSA-c7w7-v6qv-rv37/GHSA-c7w7-v6qv-rv37.json @@ -7,12 +7,8 @@ "CVE-2002-1728" ], "details": "askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c8rv-w4qp-vf28/GHSA-c8rv-w4qp-vf28.json b/advisories/unreviewed/2022/04/GHSA-c8rv-w4qp-vf28/GHSA-c8rv-w4qp-vf28.json index a4656261c50..724e63ae1ea 100644 --- a/advisories/unreviewed/2022/04/GHSA-c8rv-w4qp-vf28/GHSA-c8rv-w4qp-vf28.json +++ b/advisories/unreviewed/2022/04/GHSA-c8rv-w4qp-vf28/GHSA-c8rv-w4qp-vf28.json @@ -7,12 +7,8 @@ "CVE-2002-2034" ], "details": "The Email Sanitizer before 1.133 for Procmail allows remote attackers to bypass the mail filter and execute arbitrary code via crafted recursive multipart MIME attachments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c95w-x5wp-6vrm/GHSA-c95w-x5wp-6vrm.json b/advisories/unreviewed/2022/04/GHSA-c95w-x5wp-6vrm/GHSA-c95w-x5wp-6vrm.json index d06b514830d..247f28dd89a 100644 --- a/advisories/unreviewed/2022/04/GHSA-c95w-x5wp-6vrm/GHSA-c95w-x5wp-6vrm.json +++ b/advisories/unreviewed/2022/04/GHSA-c95w-x5wp-6vrm/GHSA-c95w-x5wp-6vrm.json @@ -7,12 +7,8 @@ "CVE-2002-2088" ], "details": "The MOSIX Project clump/os 5.4 creates a default VNC account without a password, which allows remote attackers to gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ccj2-626m-qx98/GHSA-ccj2-626m-qx98.json b/advisories/unreviewed/2022/04/GHSA-ccj2-626m-qx98/GHSA-ccj2-626m-qx98.json index 97df83f3d8d..c9851858aea 100644 --- a/advisories/unreviewed/2022/04/GHSA-ccj2-626m-qx98/GHSA-ccj2-626m-qx98.json +++ b/advisories/unreviewed/2022/04/GHSA-ccj2-626m-qx98/GHSA-ccj2-626m-qx98.json @@ -7,12 +7,8 @@ "CVE-2002-1866" ], "details": "Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cfhj-6c3m-mj6w/GHSA-cfhj-6c3m-mj6w.json b/advisories/unreviewed/2022/04/GHSA-cfhj-6c3m-mj6w/GHSA-cfhj-6c3m-mj6w.json index 4bf567f0122..614c9e21a0a 100644 --- a/advisories/unreviewed/2022/04/GHSA-cfhj-6c3m-mj6w/GHSA-cfhj-6c3m-mj6w.json +++ b/advisories/unreviewed/2022/04/GHSA-cfhj-6c3m-mj6w/GHSA-cfhj-6c3m-mj6w.json @@ -7,12 +7,8 @@ "CVE-2002-1724" ], "details": "Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cgvc-xv84-f929/GHSA-cgvc-xv84-f929.json b/advisories/unreviewed/2022/04/GHSA-cgvc-xv84-f929/GHSA-cgvc-xv84-f929.json index 8ae200a6935..7f9fbf05000 100644 --- a/advisories/unreviewed/2022/04/GHSA-cgvc-xv84-f929/GHSA-cgvc-xv84-f929.json +++ b/advisories/unreviewed/2022/04/GHSA-cgvc-xv84-f929/GHSA-cgvc-xv84-f929.json @@ -7,12 +7,8 @@ "CVE-2002-1958" ], "details": "Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in \"safe\" HTML tags such as the \"b\" tag, or (2) the Subject field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-ch7p-hxpg-4w7q/GHSA-ch7p-hxpg-4w7q.json b/advisories/unreviewed/2022/04/GHSA-ch7p-hxpg-4w7q/GHSA-ch7p-hxpg-4w7q.json index c3ebfc05746..00292aaab64 100644 --- a/advisories/unreviewed/2022/04/GHSA-ch7p-hxpg-4w7q/GHSA-ch7p-hxpg-4w7q.json +++ b/advisories/unreviewed/2022/04/GHSA-ch7p-hxpg-4w7q/GHSA-ch7p-hxpg-4w7q.json @@ -7,12 +7,8 @@ "CVE-2002-1989" ], "details": "Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-chx9-f3px-wq9q/GHSA-chx9-f3px-wq9q.json b/advisories/unreviewed/2022/04/GHSA-chx9-f3px-wq9q/GHSA-chx9-f3px-wq9q.json index f5377e65f24..f204e26b052 100644 --- a/advisories/unreviewed/2022/04/GHSA-chx9-f3px-wq9q/GHSA-chx9-f3px-wq9q.json +++ b/advisories/unreviewed/2022/04/GHSA-chx9-f3px-wq9q/GHSA-chx9-f3px-wq9q.json @@ -7,12 +7,8 @@ "CVE-2002-2090" ], "details": "Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cm9x-cx6v-qx4v/GHSA-cm9x-cx6v-qx4v.json b/advisories/unreviewed/2022/04/GHSA-cm9x-cx6v-qx4v/GHSA-cm9x-cx6v-qx4v.json index e7c97a50776..d7530a0503a 100644 --- a/advisories/unreviewed/2022/04/GHSA-cm9x-cx6v-qx4v/GHSA-cm9x-cx6v-qx4v.json +++ b/advisories/unreviewed/2022/04/GHSA-cm9x-cx6v-qx4v/GHSA-cm9x-cx6v-qx4v.json @@ -7,12 +7,8 @@ "CVE-2002-2036" ], "details": "Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cmg9-c5c7-hvgf/GHSA-cmg9-c5c7-hvgf.json b/advisories/unreviewed/2022/04/GHSA-cmg9-c5c7-hvgf/GHSA-cmg9-c5c7-hvgf.json index 0731e513dca..c01563565d6 100644 --- a/advisories/unreviewed/2022/04/GHSA-cmg9-c5c7-hvgf/GHSA-cmg9-c5c7-hvgf.json +++ b/advisories/unreviewed/2022/04/GHSA-cmg9-c5c7-hvgf/GHSA-cmg9-c5c7-hvgf.json @@ -7,12 +7,8 @@ "CVE-2002-1990" ], "details": "Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqh8-v9mm-8fcx/GHSA-cqh8-v9mm-8fcx.json b/advisories/unreviewed/2022/04/GHSA-cqh8-v9mm-8fcx/GHSA-cqh8-v9mm-8fcx.json index 758a5f171bb..67f82baffda 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqh8-v9mm-8fcx/GHSA-cqh8-v9mm-8fcx.json +++ b/advisories/unreviewed/2022/04/GHSA-cqh8-v9mm-8fcx/GHSA-cqh8-v9mm-8fcx.json @@ -7,12 +7,8 @@ "CVE-2002-2018" ], "details": "sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqxq-6p9g-3g96/GHSA-cqxq-6p9g-3g96.json b/advisories/unreviewed/2022/04/GHSA-cqxq-6p9g-3g96/GHSA-cqxq-6p9g-3g96.json index 823c893fcb9..1020a62ec0a 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqxq-6p9g-3g96/GHSA-cqxq-6p9g-3g96.json +++ b/advisories/unreviewed/2022/04/GHSA-cqxq-6p9g-3g96/GHSA-cqxq-6p9g-3g96.json @@ -7,12 +7,8 @@ "CVE-2002-1708" ], "details": "Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-crh5-hj67-87h4/GHSA-crh5-hj67-87h4.json b/advisories/unreviewed/2022/04/GHSA-crh5-hj67-87h4/GHSA-crh5-hj67-87h4.json index 227beff2f73..5edfa362e80 100644 --- a/advisories/unreviewed/2022/04/GHSA-crh5-hj67-87h4/GHSA-crh5-hj67-87h4.json +++ b/advisories/unreviewed/2022/04/GHSA-crh5-hj67-87h4/GHSA-crh5-hj67-87h4.json @@ -7,12 +7,8 @@ "CVE-2002-2048" ], "details": "Buffer overflow in PFinger 0.7.8 client allows remote attackers to execute arbitrary code via a long query value passed to the (1) finger program, (2) -l, (3) -d, and (4) -t options. NOTE: if PFinger is not setuid or setgid, then this issue would not cross privilege boundaries and would not be considered a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cw9g-xr3h-j8g7/GHSA-cw9g-xr3h-j8g7.json b/advisories/unreviewed/2022/04/GHSA-cw9g-xr3h-j8g7/GHSA-cw9g-xr3h-j8g7.json index 60c12adab07..000b9aef671 100644 --- a/advisories/unreviewed/2022/04/GHSA-cw9g-xr3h-j8g7/GHSA-cw9g-xr3h-j8g7.json +++ b/advisories/unreviewed/2022/04/GHSA-cw9g-xr3h-j8g7/GHSA-cw9g-xr3h-j8g7.json @@ -7,12 +7,8 @@ "CVE-2002-1942" ], "details": "Imatix Xitami 2.5 b5 does not properly terminate certain Keep-Alive connections that have been broken or closed early, which allows remote attackers to cause a denial of service (crash) via a large number of concurrent sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f436-gr4m-qq5w/GHSA-f436-gr4m-qq5w.json b/advisories/unreviewed/2022/04/GHSA-f436-gr4m-qq5w/GHSA-f436-gr4m-qq5w.json index fba6fb435ec..75f1e1928a0 100644 --- a/advisories/unreviewed/2022/04/GHSA-f436-gr4m-qq5w/GHSA-f436-gr4m-qq5w.json +++ b/advisories/unreviewed/2022/04/GHSA-f436-gr4m-qq5w/GHSA-f436-gr4m-qq5w.json @@ -7,12 +7,8 @@ "CVE-2002-2007" ], "details": "The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f474-2mpq-x44c/GHSA-f474-2mpq-x44c.json b/advisories/unreviewed/2022/04/GHSA-f474-2mpq-x44c/GHSA-f474-2mpq-x44c.json index 31ca02e1015..244a2d3946d 100644 --- a/advisories/unreviewed/2022/04/GHSA-f474-2mpq-x44c/GHSA-f474-2mpq-x44c.json +++ b/advisories/unreviewed/2022/04/GHSA-f474-2mpq-x44c/GHSA-f474-2mpq-x44c.json @@ -7,12 +7,8 @@ "CVE-2002-2154" ], "details": "Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f5v8-cx94-qh2x/GHSA-f5v8-cx94-qh2x.json b/advisories/unreviewed/2022/04/GHSA-f5v8-cx94-qh2x/GHSA-f5v8-cx94-qh2x.json index c716e1d1fd8..67ceae10a52 100644 --- a/advisories/unreviewed/2022/04/GHSA-f5v8-cx94-qh2x/GHSA-f5v8-cx94-qh2x.json +++ b/advisories/unreviewed/2022/04/GHSA-f5v8-cx94-qh2x/GHSA-f5v8-cx94-qh2x.json @@ -7,12 +7,8 @@ "CVE-2002-1952" ], "details": "phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f828-3wmc-hg2m/GHSA-f828-3wmc-hg2m.json b/advisories/unreviewed/2022/04/GHSA-f828-3wmc-hg2m/GHSA-f828-3wmc-hg2m.json index 5af6bc1eddf..7dbdff32190 100644 --- a/advisories/unreviewed/2022/04/GHSA-f828-3wmc-hg2m/GHSA-f828-3wmc-hg2m.json +++ b/advisories/unreviewed/2022/04/GHSA-f828-3wmc-hg2m/GHSA-f828-3wmc-hg2m.json @@ -7,12 +7,8 @@ "CVE-2002-2056" ], "details": "Cross-site scripting (XSS) vulnerability in TeeKai Forum 1.2 allows remote attackers to inject arbitrary web script or HTML via the valid_username_online cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f94v-48pw-mw72/GHSA-f94v-48pw-mw72.json b/advisories/unreviewed/2022/04/GHSA-f94v-48pw-mw72/GHSA-f94v-48pw-mw72.json index 871f44ec1fc..9956d422658 100644 --- a/advisories/unreviewed/2022/04/GHSA-f94v-48pw-mw72/GHSA-f94v-48pw-mw72.json +++ b/advisories/unreviewed/2022/04/GHSA-f94v-48pw-mw72/GHSA-f94v-48pw-mw72.json @@ -7,12 +7,8 @@ "CVE-2002-2062" ], "details": "Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with \"Enable folder view for FTP sites\" and \"Enable Web content in folders\" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fc78-m9cw-v737/GHSA-fc78-m9cw-v737.json b/advisories/unreviewed/2022/04/GHSA-fc78-m9cw-v737/GHSA-fc78-m9cw-v737.json index 9450bbcfe7f..9bc415ed128 100644 --- a/advisories/unreviewed/2022/04/GHSA-fc78-m9cw-v737/GHSA-fc78-m9cw-v737.json +++ b/advisories/unreviewed/2022/04/GHSA-fc78-m9cw-v737/GHSA-fc78-m9cw-v737.json @@ -7,12 +7,8 @@ "CVE-2002-1927" ], "details": "Aquonics File Manager 1.5 allows users with edit privileges to modify user accounts by editing the userlist.cgi file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ff7v-6c4c-m994/GHSA-ff7v-6c4c-m994.json b/advisories/unreviewed/2022/04/GHSA-ff7v-6c4c-m994/GHSA-ff7v-6c4c-m994.json index ce867d9985d..5c1fa4e6725 100644 --- a/advisories/unreviewed/2022/04/GHSA-ff7v-6c4c-m994/GHSA-ff7v-6c4c-m994.json +++ b/advisories/unreviewed/2022/04/GHSA-ff7v-6c4c-m994/GHSA-ff7v-6c4c-m994.json @@ -7,12 +7,8 @@ "CVE-2002-1886" ], "details": "TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ffgx-fvwp-vxw9/GHSA-ffgx-fvwp-vxw9.json b/advisories/unreviewed/2022/04/GHSA-ffgx-fvwp-vxw9/GHSA-ffgx-fvwp-vxw9.json index 4f7e78e7ca3..6145718f605 100644 --- a/advisories/unreviewed/2022/04/GHSA-ffgx-fvwp-vxw9/GHSA-ffgx-fvwp-vxw9.json +++ b/advisories/unreviewed/2022/04/GHSA-ffgx-fvwp-vxw9/GHSA-ffgx-fvwp-vxw9.json @@ -7,12 +7,8 @@ "CVE-2002-1957" ], "details": "Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fm29-mfm6-3mjx/GHSA-fm29-mfm6-3mjx.json b/advisories/unreviewed/2022/04/GHSA-fm29-mfm6-3mjx/GHSA-fm29-mfm6-3mjx.json index b64a1b82ec1..40429919c13 100644 --- a/advisories/unreviewed/2022/04/GHSA-fm29-mfm6-3mjx/GHSA-fm29-mfm6-3mjx.json +++ b/advisories/unreviewed/2022/04/GHSA-fm29-mfm6-3mjx/GHSA-fm29-mfm6-3mjx.json @@ -7,12 +7,8 @@ "CVE-2002-2060" ], "details": "Buffer overflow in Links 2.0 pre4 allows remote attackers to crash client browsers and possibly execute arbitrary code via gamma tables in large 16-bit PNG images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fqc4-8m96-pvh3/GHSA-fqc4-8m96-pvh3.json b/advisories/unreviewed/2022/04/GHSA-fqc4-8m96-pvh3/GHSA-fqc4-8m96-pvh3.json index 4a95667f60c..d7224a2ff1e 100644 --- a/advisories/unreviewed/2022/04/GHSA-fqc4-8m96-pvh3/GHSA-fqc4-8m96-pvh3.json +++ b/advisories/unreviewed/2022/04/GHSA-fqc4-8m96-pvh3/GHSA-fqc4-8m96-pvh3.json @@ -7,12 +7,8 @@ "CVE-2002-2040" ], "details": "The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frhv-982p-rjvc/GHSA-frhv-982p-rjvc.json b/advisories/unreviewed/2022/04/GHSA-frhv-982p-rjvc/GHSA-frhv-982p-rjvc.json index 66b4cf4687f..4f46fe6b39e 100644 --- a/advisories/unreviewed/2022/04/GHSA-frhv-982p-rjvc/GHSA-frhv-982p-rjvc.json +++ b/advisories/unreviewed/2022/04/GHSA-frhv-982p-rjvc/GHSA-frhv-982p-rjvc.json @@ -7,12 +7,8 @@ "CVE-2002-2146" ], "details": "cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fvf9-h9qr-4mr9/GHSA-fvf9-h9qr-4mr9.json b/advisories/unreviewed/2022/04/GHSA-fvf9-h9qr-4mr9/GHSA-fvf9-h9qr-4mr9.json index d2d4ebee8b7..45f4abd65f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-fvf9-h9qr-4mr9/GHSA-fvf9-h9qr-4mr9.json +++ b/advisories/unreviewed/2022/04/GHSA-fvf9-h9qr-4mr9/GHSA-fvf9-h9qr-4mr9.json @@ -7,12 +7,8 @@ "CVE-2002-1965" ], "details": "Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events, as demonstrated via an onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fx7c-68rf-m678/GHSA-fx7c-68rf-m678.json b/advisories/unreviewed/2022/04/GHSA-fx7c-68rf-m678/GHSA-fx7c-68rf-m678.json index 580654252cd..5f9e6915d04 100644 --- a/advisories/unreviewed/2022/04/GHSA-fx7c-68rf-m678/GHSA-fx7c-68rf-m678.json +++ b/advisories/unreviewed/2022/04/GHSA-fx7c-68rf-m678/GHSA-fx7c-68rf-m678.json @@ -7,12 +7,8 @@ "CVE-2002-1710" ], "details": "The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g24j-pvr2-f826/GHSA-g24j-pvr2-f826.json b/advisories/unreviewed/2022/04/GHSA-g24j-pvr2-f826/GHSA-g24j-pvr2-f826.json index 2ecd337c4bb..febd6156609 100644 --- a/advisories/unreviewed/2022/04/GHSA-g24j-pvr2-f826/GHSA-g24j-pvr2-f826.json +++ b/advisories/unreviewed/2022/04/GHSA-g24j-pvr2-f826/GHSA-g24j-pvr2-f826.json @@ -7,12 +7,8 @@ "CVE-2002-1945" ], "details": "Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g2vp-rh3j-gg8q/GHSA-g2vp-rh3j-gg8q.json b/advisories/unreviewed/2022/04/GHSA-g2vp-rh3j-gg8q/GHSA-g2vp-rh3j-gg8q.json index 47c6e4b383e..393b90b0ddd 100644 --- a/advisories/unreviewed/2022/04/GHSA-g2vp-rh3j-gg8q/GHSA-g2vp-rh3j-gg8q.json +++ b/advisories/unreviewed/2022/04/GHSA-g2vp-rh3j-gg8q/GHSA-g2vp-rh3j-gg8q.json @@ -7,12 +7,8 @@ "CVE-2002-2011" ], "details": "Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g37w-gc2m-qcrm/GHSA-g37w-gc2m-qcrm.json b/advisories/unreviewed/2022/04/GHSA-g37w-gc2m-qcrm/GHSA-g37w-gc2m-qcrm.json index 0df9656f474..eb86a19c6c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-g37w-gc2m-qcrm/GHSA-g37w-gc2m-qcrm.json +++ b/advisories/unreviewed/2022/04/GHSA-g37w-gc2m-qcrm/GHSA-g37w-gc2m-qcrm.json @@ -7,12 +7,8 @@ "CVE-2002-2046" ], "details": "x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g3q8-m2f7-hmq4/GHSA-g3q8-m2f7-hmq4.json b/advisories/unreviewed/2022/04/GHSA-g3q8-m2f7-hmq4/GHSA-g3q8-m2f7-hmq4.json index ca3a3775ee4..51f9dae88d8 100644 --- a/advisories/unreviewed/2022/04/GHSA-g3q8-m2f7-hmq4/GHSA-g3q8-m2f7-hmq4.json +++ b/advisories/unreviewed/2022/04/GHSA-g3q8-m2f7-hmq4/GHSA-g3q8-m2f7-hmq4.json @@ -7,12 +7,8 @@ "CVE-2002-1908" ], "details": "Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of \"/\" (forward slash) characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4xw-8f63-c5j3/GHSA-g4xw-8f63-c5j3.json b/advisories/unreviewed/2022/04/GHSA-g4xw-8f63-c5j3/GHSA-g4xw-8f63-c5j3.json index ca1f08f4c74..21e13f6ce3c 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4xw-8f63-c5j3/GHSA-g4xw-8f63-c5j3.json +++ b/advisories/unreviewed/2022/04/GHSA-g4xw-8f63-c5j3/GHSA-g4xw-8f63-c5j3.json @@ -7,12 +7,8 @@ "CVE-2002-1906" ], "details": "The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gcg8-r97j-5cjr/GHSA-gcg8-r97j-5cjr.json b/advisories/unreviewed/2022/04/GHSA-gcg8-r97j-5cjr/GHSA-gcg8-r97j-5cjr.json index 76392202e1f..cb78feaaded 100644 --- a/advisories/unreviewed/2022/04/GHSA-gcg8-r97j-5cjr/GHSA-gcg8-r97j-5cjr.json +++ b/advisories/unreviewed/2022/04/GHSA-gcg8-r97j-5cjr/GHSA-gcg8-r97j-5cjr.json @@ -7,12 +7,8 @@ "CVE-2002-2072" ], "details": "java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gf6p-gjjg-j6pg/GHSA-gf6p-gjjg-j6pg.json b/advisories/unreviewed/2022/04/GHSA-gf6p-gjjg-j6pg/GHSA-gf6p-gjjg-j6pg.json index ad2428298f8..8973a3a678d 100644 --- a/advisories/unreviewed/2022/04/GHSA-gf6p-gjjg-j6pg/GHSA-gf6p-gjjg-j6pg.json +++ b/advisories/unreviewed/2022/04/GHSA-gf6p-gjjg-j6pg/GHSA-gf6p-gjjg-j6pg.json @@ -7,12 +7,8 @@ "CVE-2002-2013" ], "details": "Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gh2w-fv67-v5qp/GHSA-gh2w-fv67-v5qp.json b/advisories/unreviewed/2022/04/GHSA-gh2w-fv67-v5qp/GHSA-gh2w-fv67-v5qp.json index c0d9c163355..0b707aa12a4 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh2w-fv67-v5qp/GHSA-gh2w-fv67-v5qp.json +++ b/advisories/unreviewed/2022/04/GHSA-gh2w-fv67-v5qp/GHSA-gh2w-fv67-v5qp.json @@ -7,12 +7,8 @@ "CVE-2002-2120" ], "details": "Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gh38-6r6r-q349/GHSA-gh38-6r6r-q349.json b/advisories/unreviewed/2022/04/GHSA-gh38-6r6r-q349/GHSA-gh38-6r6r-q349.json index 7ea2c8bff73..69fbd0803a3 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh38-6r6r-q349/GHSA-gh38-6r6r-q349.json +++ b/advisories/unreviewed/2022/04/GHSA-gh38-6r6r-q349/GHSA-gh38-6r6r-q349.json @@ -7,12 +7,8 @@ "CVE-2002-1944" ], "details": "Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gjh3-jcfj-99r5/GHSA-gjh3-jcfj-99r5.json b/advisories/unreviewed/2022/04/GHSA-gjh3-jcfj-99r5/GHSA-gjh3-jcfj-99r5.json index e7f68dd08cf..9c02595853c 100644 --- a/advisories/unreviewed/2022/04/GHSA-gjh3-jcfj-99r5/GHSA-gjh3-jcfj-99r5.json +++ b/advisories/unreviewed/2022/04/GHSA-gjh3-jcfj-99r5/GHSA-gjh3-jcfj-99r5.json @@ -7,12 +7,8 @@ "CVE-2002-1871" ], "details": "pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a \"?\" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gpmx-wmq7-fj5h/GHSA-gpmx-wmq7-fj5h.json b/advisories/unreviewed/2022/04/GHSA-gpmx-wmq7-fj5h/GHSA-gpmx-wmq7-fj5h.json index 36454f5c7de..95a0e1d2dd1 100644 --- a/advisories/unreviewed/2022/04/GHSA-gpmx-wmq7-fj5h/GHSA-gpmx-wmq7-fj5h.json +++ b/advisories/unreviewed/2022/04/GHSA-gpmx-wmq7-fj5h/GHSA-gpmx-wmq7-fj5h.json @@ -7,12 +7,8 @@ "CVE-2002-1867" ], "details": "The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gr8x-chfr-hp52/GHSA-gr8x-chfr-hp52.json b/advisories/unreviewed/2022/04/GHSA-gr8x-chfr-hp52/GHSA-gr8x-chfr-hp52.json index b8f3500979e..64db46667c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-gr8x-chfr-hp52/GHSA-gr8x-chfr-hp52.json +++ b/advisories/unreviewed/2022/04/GHSA-gr8x-chfr-hp52/GHSA-gr8x-chfr-hp52.json @@ -7,12 +7,8 @@ "CVE-2002-2065" ], "details": "WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-grhf-jvxv-chm6/GHSA-grhf-jvxv-chm6.json b/advisories/unreviewed/2022/04/GHSA-grhf-jvxv-chm6/GHSA-grhf-jvxv-chm6.json index 9a62626f508..9ddad609c40 100644 --- a/advisories/unreviewed/2022/04/GHSA-grhf-jvxv-chm6/GHSA-grhf-jvxv-chm6.json +++ b/advisories/unreviewed/2022/04/GHSA-grhf-jvxv-chm6/GHSA-grhf-jvxv-chm6.json @@ -7,12 +7,8 @@ "CVE-2002-1720" ], "details": "SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gwww-2pvg-pq5v/GHSA-gwww-2pvg-pq5v.json b/advisories/unreviewed/2022/04/GHSA-gwww-2pvg-pq5v/GHSA-gwww-2pvg-pq5v.json index ebdb1fdd52b..bf6a7daeeee 100644 --- a/advisories/unreviewed/2022/04/GHSA-gwww-2pvg-pq5v/GHSA-gwww-2pvg-pq5v.json +++ b/advisories/unreviewed/2022/04/GHSA-gwww-2pvg-pq5v/GHSA-gwww-2pvg-pq5v.json @@ -7,12 +7,8 @@ "CVE-2002-1959" ], "details": "Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h35x-g9m3-w82q/GHSA-h35x-g9m3-w82q.json b/advisories/unreviewed/2022/04/GHSA-h35x-g9m3-w82q/GHSA-h35x-g9m3-w82q.json index dc3b2556285..719158b83d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-h35x-g9m3-w82q/GHSA-h35x-g9m3-w82q.json +++ b/advisories/unreviewed/2022/04/GHSA-h35x-g9m3-w82q/GHSA-h35x-g9m3-w82q.json @@ -7,12 +7,8 @@ "CVE-2002-2026" ], "details": "Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP \"220\" message reply.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h5c3-vrpw-qjq9/GHSA-h5c3-vrpw-qjq9.json b/advisories/unreviewed/2022/04/GHSA-h5c3-vrpw-qjq9/GHSA-h5c3-vrpw-qjq9.json index 16024430a38..d3326c67e7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-h5c3-vrpw-qjq9/GHSA-h5c3-vrpw-qjq9.json +++ b/advisories/unreviewed/2022/04/GHSA-h5c3-vrpw-qjq9/GHSA-h5c3-vrpw-qjq9.json @@ -7,12 +7,8 @@ "CVE-2002-2156" ], "details": "Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h7hf-87f6-rwx5/GHSA-h7hf-87f6-rwx5.json b/advisories/unreviewed/2022/04/GHSA-h7hf-87f6-rwx5/GHSA-h7hf-87f6-rwx5.json index 275f04c1be0..88ada2eae50 100644 --- a/advisories/unreviewed/2022/04/GHSA-h7hf-87f6-rwx5/GHSA-h7hf-87f6-rwx5.json +++ b/advisories/unreviewed/2022/04/GHSA-h7hf-87f6-rwx5/GHSA-h7hf-87f6-rwx5.json @@ -7,12 +7,8 @@ "CVE-2002-1980" ], "details": "Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hf87-4rwf-j97v/GHSA-hf87-4rwf-j97v.json b/advisories/unreviewed/2022/04/GHSA-hf87-4rwf-j97v/GHSA-hf87-4rwf-j97v.json index 84d07e1692b..09471a52518 100644 --- a/advisories/unreviewed/2022/04/GHSA-hf87-4rwf-j97v/GHSA-hf87-4rwf-j97v.json +++ b/advisories/unreviewed/2022/04/GHSA-hf87-4rwf-j97v/GHSA-hf87-4rwf-j97v.json @@ -7,12 +7,8 @@ "CVE-2002-1874" ], "details": "astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hfpm-j2f9-7gcc/GHSA-hfpm-j2f9-7gcc.json b/advisories/unreviewed/2022/04/GHSA-hfpm-j2f9-7gcc/GHSA-hfpm-j2f9-7gcc.json index 803d2d1f22a..ece63893ba0 100644 --- a/advisories/unreviewed/2022/04/GHSA-hfpm-j2f9-7gcc/GHSA-hfpm-j2f9-7gcc.json +++ b/advisories/unreviewed/2022/04/GHSA-hfpm-j2f9-7gcc/GHSA-hfpm-j2f9-7gcc.json @@ -7,12 +7,8 @@ "CVE-2002-2043" ], "details": "SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hfxc-rg4g-qqv7/GHSA-hfxc-rg4g-qqv7.json b/advisories/unreviewed/2022/04/GHSA-hfxc-rg4g-qqv7/GHSA-hfxc-rg4g-qqv7.json index cfaa4354339..1d04abb325e 100644 --- a/advisories/unreviewed/2022/04/GHSA-hfxc-rg4g-qqv7/GHSA-hfxc-rg4g-qqv7.json +++ b/advisories/unreviewed/2022/04/GHSA-hfxc-rg4g-qqv7/GHSA-hfxc-rg4g-qqv7.json @@ -7,12 +7,8 @@ "CVE-2002-1920" ], "details": "Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hmhx-2jp5-6pxr/GHSA-hmhx-2jp5-6pxr.json b/advisories/unreviewed/2022/04/GHSA-hmhx-2jp5-6pxr/GHSA-hmhx-2jp5-6pxr.json index 3afad0c133d..dac68d1790f 100644 --- a/advisories/unreviewed/2022/04/GHSA-hmhx-2jp5-6pxr/GHSA-hmhx-2jp5-6pxr.json +++ b/advisories/unreviewed/2022/04/GHSA-hmhx-2jp5-6pxr/GHSA-hmhx-2jp5-6pxr.json @@ -7,12 +7,8 @@ "CVE-2002-1715" ], "details": "SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hph5-xf43-8378/GHSA-hph5-xf43-8378.json b/advisories/unreviewed/2022/04/GHSA-hph5-xf43-8378/GHSA-hph5-xf43-8378.json index a3e723da708..cd8d6e451cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-hph5-xf43-8378/GHSA-hph5-xf43-8378.json +++ b/advisories/unreviewed/2022/04/GHSA-hph5-xf43-8378/GHSA-hph5-xf43-8378.json @@ -7,12 +7,8 @@ "CVE-2002-1913" ], "details": "phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hqp5-g78q-23qx/GHSA-hqp5-g78q-23qx.json b/advisories/unreviewed/2022/04/GHSA-hqp5-g78q-23qx/GHSA-hqp5-g78q-23qx.json index bb88ace58b1..5ecd6268161 100644 --- a/advisories/unreviewed/2022/04/GHSA-hqp5-g78q-23qx/GHSA-hqp5-g78q-23qx.json +++ b/advisories/unreviewed/2022/04/GHSA-hqp5-g78q-23qx/GHSA-hqp5-g78q-23qx.json @@ -7,12 +7,8 @@ "CVE-2002-1995" ], "details": "Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hr99-xr7v-22rw/GHSA-hr99-xr7v-22rw.json b/advisories/unreviewed/2022/04/GHSA-hr99-xr7v-22rw/GHSA-hr99-xr7v-22rw.json index a2dec7a01d0..61ae3931efe 100644 --- a/advisories/unreviewed/2022/04/GHSA-hr99-xr7v-22rw/GHSA-hr99-xr7v-22rw.json +++ b/advisories/unreviewed/2022/04/GHSA-hr99-xr7v-22rw/GHSA-hr99-xr7v-22rw.json @@ -7,12 +7,8 @@ "CVE-2002-2138" ], "details": "RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of service (panic) via a malformed UDP packet on port 139.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hr9p-wggg-4pc6/GHSA-hr9p-wggg-4pc6.json b/advisories/unreviewed/2022/04/GHSA-hr9p-wggg-4pc6/GHSA-hr9p-wggg-4pc6.json index a3b70cd4a45..74da5acdf52 100644 --- a/advisories/unreviewed/2022/04/GHSA-hr9p-wggg-4pc6/GHSA-hr9p-wggg-4pc6.json +++ b/advisories/unreviewed/2022/04/GHSA-hr9p-wggg-4pc6/GHSA-hr9p-wggg-4pc6.json @@ -7,12 +7,8 @@ "CVE-2002-1905" ], "details": "Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hrvw-8ffp-h56x/GHSA-hrvw-8ffp-h56x.json b/advisories/unreviewed/2022/04/GHSA-hrvw-8ffp-h56x/GHSA-hrvw-8ffp-h56x.json index 4c8a96159ce..5a437e3d375 100644 --- a/advisories/unreviewed/2022/04/GHSA-hrvw-8ffp-h56x/GHSA-hrvw-8ffp-h56x.json +++ b/advisories/unreviewed/2022/04/GHSA-hrvw-8ffp-h56x/GHSA-hrvw-8ffp-h56x.json @@ -7,12 +7,8 @@ "CVE-2002-1953" ], "details": "Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects \"Get Info\" on the buddy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j2ph-7hwr-86cq/GHSA-j2ph-7hwr-86cq.json b/advisories/unreviewed/2022/04/GHSA-j2ph-7hwr-86cq/GHSA-j2ph-7hwr-86cq.json index fb4e16a41fb..81351c0320d 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2ph-7hwr-86cq/GHSA-j2ph-7hwr-86cq.json +++ b/advisories/unreviewed/2022/04/GHSA-j2ph-7hwr-86cq/GHSA-j2ph-7hwr-86cq.json @@ -7,12 +7,8 @@ "CVE-2002-2108" ], "details": "Unknown vulnerability in the \"VAIO Manual\" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j2q8-q6cm-rx6f/GHSA-j2q8-q6cm-rx6f.json b/advisories/unreviewed/2022/04/GHSA-j2q8-q6cm-rx6f/GHSA-j2q8-q6cm-rx6f.json index 59ec48df8e2..a61b320b801 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2q8-q6cm-rx6f/GHSA-j2q8-q6cm-rx6f.json +++ b/advisories/unreviewed/2022/04/GHSA-j2q8-q6cm-rx6f/GHSA-j2q8-q6cm-rx6f.json @@ -7,12 +7,8 @@ "CVE-2002-1884" ], "details": "index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to \"admin\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j623-g5jp-pq9j/GHSA-j623-g5jp-pq9j.json b/advisories/unreviewed/2022/04/GHSA-j623-g5jp-pq9j/GHSA-j623-g5jp-pq9j.json index 65e196231a6..64288b7fb01 100644 --- a/advisories/unreviewed/2022/04/GHSA-j623-g5jp-pq9j/GHSA-j623-g5jp-pq9j.json +++ b/advisories/unreviewed/2022/04/GHSA-j623-g5jp-pq9j/GHSA-j623-g5jp-pq9j.json @@ -7,12 +7,8 @@ "CVE-2002-2064" ], "details": "isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j7fp-qw4v-74mr/GHSA-j7fp-qw4v-74mr.json b/advisories/unreviewed/2022/04/GHSA-j7fp-qw4v-74mr/GHSA-j7fp-qw4v-74mr.json index 916cc8a8321..d540a260b30 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7fp-qw4v-74mr/GHSA-j7fp-qw4v-74mr.json +++ b/advisories/unreviewed/2022/04/GHSA-j7fp-qw4v-74mr/GHSA-j7fp-qw4v-74mr.json @@ -7,12 +7,8 @@ "CVE-2002-2122" ], "details": "Pointsec before 1.2 for PalmOS stores a user's PIN number in memory in plaintext, which allows a local attacker who steals an unlocked Palm to retrieve the PIN by dumping memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j7q6-wfv5-chr8/GHSA-j7q6-wfv5-chr8.json b/advisories/unreviewed/2022/04/GHSA-j7q6-wfv5-chr8/GHSA-j7q6-wfv5-chr8.json index 5686553c02c..0dee118975a 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7q6-wfv5-chr8/GHSA-j7q6-wfv5-chr8.json +++ b/advisories/unreviewed/2022/04/GHSA-j7q6-wfv5-chr8/GHSA-j7q6-wfv5-chr8.json @@ -7,12 +7,8 @@ "CVE-2002-2105" ], "details": "Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jcg2-2j5q-692h/GHSA-jcg2-2j5q-692h.json b/advisories/unreviewed/2022/04/GHSA-jcg2-2j5q-692h/GHSA-jcg2-2j5q-692h.json index d9b8eaa270d..62241250c86 100644 --- a/advisories/unreviewed/2022/04/GHSA-jcg2-2j5q-692h/GHSA-jcg2-2j5q-692h.json +++ b/advisories/unreviewed/2022/04/GHSA-jcg2-2j5q-692h/GHSA-jcg2-2j5q-692h.json @@ -7,12 +7,8 @@ "CVE-2002-2161" ], "details": "Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jg5f-9v47-rc25/GHSA-jg5f-9v47-rc25.json b/advisories/unreviewed/2022/04/GHSA-jg5f-9v47-rc25/GHSA-jg5f-9v47-rc25.json index 55f2405d85b..39f1e3af181 100644 --- a/advisories/unreviewed/2022/04/GHSA-jg5f-9v47-rc25/GHSA-jg5f-9v47-rc25.json +++ b/advisories/unreviewed/2022/04/GHSA-jg5f-9v47-rc25/GHSA-jg5f-9v47-rc25.json @@ -7,12 +7,8 @@ "CVE-2002-1992" ], "details": "Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jm3j-5x2p-8mj8/GHSA-jm3j-5x2p-8mj8.json b/advisories/unreviewed/2022/04/GHSA-jm3j-5x2p-8mj8/GHSA-jm3j-5x2p-8mj8.json index edbb6ad813f..9f48d7a37bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-jm3j-5x2p-8mj8/GHSA-jm3j-5x2p-8mj8.json +++ b/advisories/unreviewed/2022/04/GHSA-jm3j-5x2p-8mj8/GHSA-jm3j-5x2p-8mj8.json @@ -7,12 +7,8 @@ "CVE-2002-1861" ], "details": "Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot (\"WEB-INF.\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jpqc-r2m5-cwch/GHSA-jpqc-r2m5-cwch.json b/advisories/unreviewed/2022/04/GHSA-jpqc-r2m5-cwch/GHSA-jpqc-r2m5-cwch.json index b3218d79794..df4b814d021 100644 --- a/advisories/unreviewed/2022/04/GHSA-jpqc-r2m5-cwch/GHSA-jpqc-r2m5-cwch.json +++ b/advisories/unreviewed/2022/04/GHSA-jpqc-r2m5-cwch/GHSA-jpqc-r2m5-cwch.json @@ -7,12 +7,8 @@ "CVE-2002-2107" ], "details": "Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jpwh-mhch-4w6m/GHSA-jpwh-mhch-4w6m.json b/advisories/unreviewed/2022/04/GHSA-jpwh-mhch-4w6m/GHSA-jpwh-mhch-4w6m.json index aa028c47791..76dfc1137b0 100644 --- a/advisories/unreviewed/2022/04/GHSA-jpwh-mhch-4w6m/GHSA-jpwh-mhch-4w6m.json +++ b/advisories/unreviewed/2022/04/GHSA-jpwh-mhch-4w6m/GHSA-jpwh-mhch-4w6m.json @@ -7,12 +7,8 @@ "CVE-2002-2141" ], "details": "BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jqxc-j9g5-gv8x/GHSA-jqxc-j9g5-gv8x.json b/advisories/unreviewed/2022/04/GHSA-jqxc-j9g5-gv8x/GHSA-jqxc-j9g5-gv8x.json index 710ddb48532..eb8dc078fe4 100644 --- a/advisories/unreviewed/2022/04/GHSA-jqxc-j9g5-gv8x/GHSA-jqxc-j9g5-gv8x.json +++ b/advisories/unreviewed/2022/04/GHSA-jqxc-j9g5-gv8x/GHSA-jqxc-j9g5-gv8x.json @@ -7,12 +7,8 @@ "CVE-2002-2074" ], "details": "SQL injection vulnerability in Mailidx before 20020105 allows remote attackers to execute arbitrary SQL commands via the search web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jr8h-pxrc-8jcp/GHSA-jr8h-pxrc-8jcp.json b/advisories/unreviewed/2022/04/GHSA-jr8h-pxrc-8jcp/GHSA-jr8h-pxrc-8jcp.json index 054c84129e2..28140f5cc59 100644 --- a/advisories/unreviewed/2022/04/GHSA-jr8h-pxrc-8jcp/GHSA-jr8h-pxrc-8jcp.json +++ b/advisories/unreviewed/2022/04/GHSA-jr8h-pxrc-8jcp/GHSA-jr8h-pxrc-8jcp.json @@ -7,12 +7,8 @@ "CVE-2002-1698" ], "details": "Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jwqr-9pxx-7hrc/GHSA-jwqr-9pxx-7hrc.json b/advisories/unreviewed/2022/04/GHSA-jwqr-9pxx-7hrc/GHSA-jwqr-9pxx-7hrc.json index 026971961f8..42c29b48468 100644 --- a/advisories/unreviewed/2022/04/GHSA-jwqr-9pxx-7hrc/GHSA-jwqr-9pxx-7hrc.json +++ b/advisories/unreviewed/2022/04/GHSA-jwqr-9pxx-7hrc/GHSA-jwqr-9pxx-7hrc.json @@ -7,12 +7,8 @@ "CVE-2002-1917" ], "details": "CRLF injection vulnerability in the \"User Profile: Send Email\" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jx83-rg4p-pm7q/GHSA-jx83-rg4p-pm7q.json b/advisories/unreviewed/2022/04/GHSA-jx83-rg4p-pm7q/GHSA-jx83-rg4p-pm7q.json index a6460e66824..ee911be7c35 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx83-rg4p-pm7q/GHSA-jx83-rg4p-pm7q.json +++ b/advisories/unreviewed/2022/04/GHSA-jx83-rg4p-pm7q/GHSA-jx83-rg4p-pm7q.json @@ -7,12 +7,8 @@ "CVE-2002-2106" ], "details": "PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m2cx-94gr-5629/GHSA-m2cx-94gr-5629.json b/advisories/unreviewed/2022/04/GHSA-m2cx-94gr-5629/GHSA-m2cx-94gr-5629.json index 3d12c4e79b2..70db15a9a4b 100644 --- a/advisories/unreviewed/2022/04/GHSA-m2cx-94gr-5629/GHSA-m2cx-94gr-5629.json +++ b/advisories/unreviewed/2022/04/GHSA-m2cx-94gr-5629/GHSA-m2cx-94gr-5629.json @@ -7,12 +7,8 @@ "CVE-2002-1966" ], "details": "Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m2wq-7cw6-4r7f/GHSA-m2wq-7cw6-4r7f.json b/advisories/unreviewed/2022/04/GHSA-m2wq-7cw6-4r7f/GHSA-m2wq-7cw6-4r7f.json index 818860afea3..98cfebaca70 100644 --- a/advisories/unreviewed/2022/04/GHSA-m2wq-7cw6-4r7f/GHSA-m2wq-7cw6-4r7f.json +++ b/advisories/unreviewed/2022/04/GHSA-m2wq-7cw6-4r7f/GHSA-m2wq-7cw6-4r7f.json @@ -7,12 +7,8 @@ "CVE-2002-1899" ], "details": "Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the \"Full Name\" (addressname) parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m855-px8p-44cq/GHSA-m855-px8p-44cq.json b/advisories/unreviewed/2022/04/GHSA-m855-px8p-44cq/GHSA-m855-px8p-44cq.json index 33d5a90a69d..875a2c48c30 100644 --- a/advisories/unreviewed/2022/04/GHSA-m855-px8p-44cq/GHSA-m855-px8p-44cq.json +++ b/advisories/unreviewed/2022/04/GHSA-m855-px8p-44cq/GHSA-m855-px8p-44cq.json @@ -7,12 +7,8 @@ "CVE-2002-1993" ], "details": "webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m8w6-7rh6-4xj6/GHSA-m8w6-7rh6-4xj6.json b/advisories/unreviewed/2022/04/GHSA-m8w6-7rh6-4xj6/GHSA-m8w6-7rh6-4xj6.json index 32323945ec9..de5e1061de2 100644 --- a/advisories/unreviewed/2022/04/GHSA-m8w6-7rh6-4xj6/GHSA-m8w6-7rh6-4xj6.json +++ b/advisories/unreviewed/2022/04/GHSA-m8w6-7rh6-4xj6/GHSA-m8w6-7rh6-4xj6.json @@ -7,12 +7,8 @@ "CVE-2002-2008" ], "details": "Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m92w-gg3f-9w3h/GHSA-m92w-gg3f-9w3h.json b/advisories/unreviewed/2022/04/GHSA-m92w-gg3f-9w3h/GHSA-m92w-gg3f-9w3h.json index 515b7323abb..f7a4dc0840e 100644 --- a/advisories/unreviewed/2022/04/GHSA-m92w-gg3f-9w3h/GHSA-m92w-gg3f-9w3h.json +++ b/advisories/unreviewed/2022/04/GHSA-m92w-gg3f-9w3h/GHSA-m92w-gg3f-9w3h.json @@ -7,12 +7,8 @@ "CVE-2002-2054" ], "details": "TeeKai Forum 1.2 allows remote attackers to authenticate as the administrator and and gain privileged web forum access by setting the valid_level cookie to admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mgqf-fr4c-62mj/GHSA-mgqf-fr4c-62mj.json b/advisories/unreviewed/2022/04/GHSA-mgqf-fr4c-62mj/GHSA-mgqf-fr4c-62mj.json index 2b13282b129..a1cdc76e426 100644 --- a/advisories/unreviewed/2022/04/GHSA-mgqf-fr4c-62mj/GHSA-mgqf-fr4c-62mj.json +++ b/advisories/unreviewed/2022/04/GHSA-mgqf-fr4c-62mj/GHSA-mgqf-fr4c-62mj.json @@ -7,12 +7,8 @@ "CVE-2002-2047" ], "details": "The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mp9p-r7cc-4959/GHSA-mp9p-r7cc-4959.json b/advisories/unreviewed/2022/04/GHSA-mp9p-r7cc-4959/GHSA-mp9p-r7cc-4959.json index f9f956e2088..74cb186458d 100644 --- a/advisories/unreviewed/2022/04/GHSA-mp9p-r7cc-4959/GHSA-mp9p-r7cc-4959.json +++ b/advisories/unreviewed/2022/04/GHSA-mp9p-r7cc-4959/GHSA-mp9p-r7cc-4959.json @@ -7,12 +7,8 @@ "CVE-2002-2055" ], "details": "Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mr5f-r5qw-mrjr/GHSA-mr5f-r5qw-mrjr.json b/advisories/unreviewed/2022/04/GHSA-mr5f-r5qw-mrjr/GHSA-mr5f-r5qw-mrjr.json index 5f5162e4b11..8d2ecd2b51b 100644 --- a/advisories/unreviewed/2022/04/GHSA-mr5f-r5qw-mrjr/GHSA-mr5f-r5qw-mrjr.json +++ b/advisories/unreviewed/2022/04/GHSA-mr5f-r5qw-mrjr/GHSA-mr5f-r5qw-mrjr.json @@ -7,12 +7,8 @@ "CVE-2002-1903" ], "details": "Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mvxp-q92m-82p3/GHSA-mvxp-q92m-82p3.json b/advisories/unreviewed/2022/04/GHSA-mvxp-q92m-82p3/GHSA-mvxp-q92m-82p3.json index 8b3a9df6465..390900ffb2e 100644 --- a/advisories/unreviewed/2022/04/GHSA-mvxp-q92m-82p3/GHSA-mvxp-q92m-82p3.json +++ b/advisories/unreviewed/2022/04/GHSA-mvxp-q92m-82p3/GHSA-mvxp-q92m-82p3.json @@ -7,12 +7,8 @@ "CVE-2002-2023" ], "details": "The get_parameter_from_freqency_source function in beep2 1.0, 1.1 and 1.2, when installed setuid root, allows local users to read arbitrary files via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mw3c-7pfv-wjvv/GHSA-mw3c-7pfv-wjvv.json b/advisories/unreviewed/2022/04/GHSA-mw3c-7pfv-wjvv/GHSA-mw3c-7pfv-wjvv.json index 44a2d612ed2..2562fa36b89 100644 --- a/advisories/unreviewed/2022/04/GHSA-mw3c-7pfv-wjvv/GHSA-mw3c-7pfv-wjvv.json +++ b/advisories/unreviewed/2022/04/GHSA-mw3c-7pfv-wjvv/GHSA-mw3c-7pfv-wjvv.json @@ -7,12 +7,8 @@ "CVE-2002-1878" ], "details": "PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mw8p-q2r7-qxjq/GHSA-mw8p-q2r7-qxjq.json b/advisories/unreviewed/2022/04/GHSA-mw8p-q2r7-qxjq/GHSA-mw8p-q2r7-qxjq.json index daccde89823..92628261ae5 100644 --- a/advisories/unreviewed/2022/04/GHSA-mw8p-q2r7-qxjq/GHSA-mw8p-q2r7-qxjq.json +++ b/advisories/unreviewed/2022/04/GHSA-mw8p-q2r7-qxjq/GHSA-mw8p-q2r7-qxjq.json @@ -7,12 +7,8 @@ "CVE-2002-2050" ], "details": "Directory traversal vulnerability in processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a .. (dot dot) in the hostname of a log entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p3j2-ppvj-fmgm/GHSA-p3j2-ppvj-fmgm.json b/advisories/unreviewed/2022/04/GHSA-p3j2-ppvj-fmgm/GHSA-p3j2-ppvj-fmgm.json index d096d47d119..35cb518c38f 100644 --- a/advisories/unreviewed/2022/04/GHSA-p3j2-ppvj-fmgm/GHSA-p3j2-ppvj-fmgm.json +++ b/advisories/unreviewed/2022/04/GHSA-p3j2-ppvj-fmgm/GHSA-p3j2-ppvj-fmgm.json @@ -7,12 +7,8 @@ "CVE-2002-1887" ], "details": "PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p3vq-8pv9-cm7f/GHSA-p3vq-8pv9-cm7f.json b/advisories/unreviewed/2022/04/GHSA-p3vq-8pv9-cm7f/GHSA-p3vq-8pv9-cm7f.json index 030d495f7db..f0f1daa9a3f 100644 --- a/advisories/unreviewed/2022/04/GHSA-p3vq-8pv9-cm7f/GHSA-p3vq-8pv9-cm7f.json +++ b/advisories/unreviewed/2022/04/GHSA-p3vq-8pv9-cm7f/GHSA-p3vq-8pv9-cm7f.json @@ -7,12 +7,8 @@ "CVE-2002-2061" ], "details": "Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p57w-8x45-95g7/GHSA-p57w-8x45-95g7.json b/advisories/unreviewed/2022/04/GHSA-p57w-8x45-95g7/GHSA-p57w-8x45-95g7.json index bba8fc61581..c236fda0b65 100644 --- a/advisories/unreviewed/2022/04/GHSA-p57w-8x45-95g7/GHSA-p57w-8x45-95g7.json +++ b/advisories/unreviewed/2022/04/GHSA-p57w-8x45-95g7/GHSA-p57w-8x45-95g7.json @@ -7,12 +7,8 @@ "CVE-2002-2125" ], "details": "Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p7wc-2fjw-3r8x/GHSA-p7wc-2fjw-3r8x.json b/advisories/unreviewed/2022/04/GHSA-p7wc-2fjw-3r8x/GHSA-p7wc-2fjw-3r8x.json index 1a22cf2e548..b4adb4f169a 100644 --- a/advisories/unreviewed/2022/04/GHSA-p7wc-2fjw-3r8x/GHSA-p7wc-2fjw-3r8x.json +++ b/advisories/unreviewed/2022/04/GHSA-p7wc-2fjw-3r8x/GHSA-p7wc-2fjw-3r8x.json @@ -7,12 +7,8 @@ "CVE-2002-1928" ], "details": "602Pro LAN SUITE 2002 allows remote attackers to view the directory tree via an HTTP GET request with a trailing \"~\" (tilde) or \".bak\" extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p8ff-f8wj-v664/GHSA-p8ff-f8wj-v664.json b/advisories/unreviewed/2022/04/GHSA-p8ff-f8wj-v664/GHSA-p8ff-f8wj-v664.json index 4b3bb37fc76..c9d10b69c1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-p8ff-f8wj-v664/GHSA-p8ff-f8wj-v664.json +++ b/advisories/unreviewed/2022/04/GHSA-p8ff-f8wj-v664/GHSA-p8ff-f8wj-v664.json @@ -7,12 +7,8 @@ "CVE-2002-1918" ], "details": "Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p8w8-mxmp-xffm/GHSA-p8w8-mxmp-xffm.json b/advisories/unreviewed/2022/04/GHSA-p8w8-mxmp-xffm/GHSA-p8w8-mxmp-xffm.json index 532d5a742c9..329ef3d6af1 100644 --- a/advisories/unreviewed/2022/04/GHSA-p8w8-mxmp-xffm/GHSA-p8w8-mxmp-xffm.json +++ b/advisories/unreviewed/2022/04/GHSA-p8w8-mxmp-xffm/GHSA-p8w8-mxmp-xffm.json @@ -7,12 +7,8 @@ "CVE-2002-1902" ], "details": "CGIForum 1.0 through 1.05 allows remote attackers to cause a denial of service (infinite recursion) by creating a message board post that is a child of an outdated parent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p955-4pv5-h2rr/GHSA-p955-4pv5-h2rr.json b/advisories/unreviewed/2022/04/GHSA-p955-4pv5-h2rr/GHSA-p955-4pv5-h2rr.json index 59bfc3bbc67..41e361796fc 100644 --- a/advisories/unreviewed/2022/04/GHSA-p955-4pv5-h2rr/GHSA-p955-4pv5-h2rr.json +++ b/advisories/unreviewed/2022/04/GHSA-p955-4pv5-h2rr/GHSA-p955-4pv5-h2rr.json @@ -7,12 +7,8 @@ "CVE-2002-1948" ], "details": "Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p9wh-qxx8-j457/GHSA-p9wh-qxx8-j457.json b/advisories/unreviewed/2022/04/GHSA-p9wh-qxx8-j457/GHSA-p9wh-qxx8-j457.json index b564639cfda..27e66ef39eb 100644 --- a/advisories/unreviewed/2022/04/GHSA-p9wh-qxx8-j457/GHSA-p9wh-qxx8-j457.json +++ b/advisories/unreviewed/2022/04/GHSA-p9wh-qxx8-j457/GHSA-p9wh-qxx8-j457.json @@ -7,12 +7,8 @@ "CVE-2002-1904" ], "details": "Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pcmr-m32w-3hrg/GHSA-pcmr-m32w-3hrg.json b/advisories/unreviewed/2022/04/GHSA-pcmr-m32w-3hrg/GHSA-pcmr-m32w-3hrg.json index bafaa07d1f4..1cea33ddfce 100644 --- a/advisories/unreviewed/2022/04/GHSA-pcmr-m32w-3hrg/GHSA-pcmr-m32w-3hrg.json +++ b/advisories/unreviewed/2022/04/GHSA-pcmr-m32w-3hrg/GHSA-pcmr-m32w-3hrg.json @@ -7,12 +7,8 @@ "CVE-2002-1961" ], "details": "Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL whose hostname portion uses a fully qualified domain name (FQDN) that ends in a \".\" (dot).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pf94-798p-v853/GHSA-pf94-798p-v853.json b/advisories/unreviewed/2022/04/GHSA-pf94-798p-v853/GHSA-pf94-798p-v853.json index fed81320694..f64e924fbc7 100644 --- a/advisories/unreviewed/2022/04/GHSA-pf94-798p-v853/GHSA-pf94-798p-v853.json +++ b/advisories/unreviewed/2022/04/GHSA-pf94-798p-v853/GHSA-pf94-798p-v853.json @@ -7,12 +7,8 @@ "CVE-2002-1955" ], "details": "Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pfj3-rm75-f57j/GHSA-pfj3-rm75-f57j.json b/advisories/unreviewed/2022/04/GHSA-pfj3-rm75-f57j/GHSA-pfj3-rm75-f57j.json index e679b2d70de..8acfe293507 100644 --- a/advisories/unreviewed/2022/04/GHSA-pfj3-rm75-f57j/GHSA-pfj3-rm75-f57j.json +++ b/advisories/unreviewed/2022/04/GHSA-pfj3-rm75-f57j/GHSA-pfj3-rm75-f57j.json @@ -7,12 +7,8 @@ "CVE-2002-2110" ], "details": "The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pfjv-6qjc-mm45/GHSA-pfjv-6qjc-mm45.json b/advisories/unreviewed/2022/04/GHSA-pfjv-6qjc-mm45/GHSA-pfjv-6qjc-mm45.json index 237d4549db0..10592e6ea2c 100644 --- a/advisories/unreviewed/2022/04/GHSA-pfjv-6qjc-mm45/GHSA-pfjv-6qjc-mm45.json +++ b/advisories/unreviewed/2022/04/GHSA-pfjv-6qjc-mm45/GHSA-pfjv-6qjc-mm45.json @@ -7,12 +7,8 @@ "CVE-2002-1956" ], "details": "ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pjq4-wc4r-3mcf/GHSA-pjq4-wc4r-3mcf.json b/advisories/unreviewed/2022/04/GHSA-pjq4-wc4r-3mcf/GHSA-pjq4-wc4r-3mcf.json index 629797b5c31..024fe4f4186 100644 --- a/advisories/unreviewed/2022/04/GHSA-pjq4-wc4r-3mcf/GHSA-pjq4-wc4r-3mcf.json +++ b/advisories/unreviewed/2022/04/GHSA-pjq4-wc4r-3mcf/GHSA-pjq4-wc4r-3mcf.json @@ -7,12 +7,8 @@ "CVE-2002-1951" ], "details": "Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pr2f-mhrf-2734/GHSA-pr2f-mhrf-2734.json b/advisories/unreviewed/2022/04/GHSA-pr2f-mhrf-2734/GHSA-pr2f-mhrf-2734.json index 97546c1e360..998bb889dd9 100644 --- a/advisories/unreviewed/2022/04/GHSA-pr2f-mhrf-2734/GHSA-pr2f-mhrf-2734.json +++ b/advisories/unreviewed/2022/04/GHSA-pr2f-mhrf-2734/GHSA-pr2f-mhrf-2734.json @@ -7,12 +7,8 @@ "CVE-2002-1726" ], "details": "secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pwfv-74pm-g9jw/GHSA-pwfv-74pm-g9jw.json b/advisories/unreviewed/2022/04/GHSA-pwfv-74pm-g9jw/GHSA-pwfv-74pm-g9jw.json index 18afc622391..18dc34363a7 100644 --- a/advisories/unreviewed/2022/04/GHSA-pwfv-74pm-g9jw/GHSA-pwfv-74pm-g9jw.json +++ b/advisories/unreviewed/2022/04/GHSA-pwfv-74pm-g9jw/GHSA-pwfv-74pm-g9jw.json @@ -7,12 +7,8 @@ "CVE-2002-1727" ], "details": "Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q23h-jgcr-4f93/GHSA-q23h-jgcr-4f93.json b/advisories/unreviewed/2022/04/GHSA-q23h-jgcr-4f93/GHSA-q23h-jgcr-4f93.json index 744d6d84649..2292b7aefb9 100644 --- a/advisories/unreviewed/2022/04/GHSA-q23h-jgcr-4f93/GHSA-q23h-jgcr-4f93.json +++ b/advisories/unreviewed/2022/04/GHSA-q23h-jgcr-4f93/GHSA-q23h-jgcr-4f93.json @@ -7,12 +7,8 @@ "CVE-2002-1876" ], "details": "Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q58j-xg5m-x6rj/GHSA-q58j-xg5m-x6rj.json b/advisories/unreviewed/2022/04/GHSA-q58j-xg5m-x6rj/GHSA-q58j-xg5m-x6rj.json index e308f32bf36..012a70fe0a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-q58j-xg5m-x6rj/GHSA-q58j-xg5m-x6rj.json +++ b/advisories/unreviewed/2022/04/GHSA-q58j-xg5m-x6rj/GHSA-q58j-xg5m-x6rj.json @@ -7,12 +7,8 @@ "CVE-2002-2016" ], "details": "User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q877-62m4-8x64/GHSA-q877-62m4-8x64.json b/advisories/unreviewed/2022/04/GHSA-q877-62m4-8x64/GHSA-q877-62m4-8x64.json index 62eb6b5db61..4ab97eadf47 100644 --- a/advisories/unreviewed/2022/04/GHSA-q877-62m4-8x64/GHSA-q877-62m4-8x64.json +++ b/advisories/unreviewed/2022/04/GHSA-q877-62m4-8x64/GHSA-q877-62m4-8x64.json @@ -7,12 +7,8 @@ "CVE-2002-1974" ], "details": "The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q8x4-6vcv-jjgf/GHSA-q8x4-6vcv-jjgf.json b/advisories/unreviewed/2022/04/GHSA-q8x4-6vcv-jjgf/GHSA-q8x4-6vcv-jjgf.json index 65cc91c0ec8..0bcc51fbfbc 100644 --- a/advisories/unreviewed/2022/04/GHSA-q8x4-6vcv-jjgf/GHSA-q8x4-6vcv-jjgf.json +++ b/advisories/unreviewed/2022/04/GHSA-q8x4-6vcv-jjgf/GHSA-q8x4-6vcv-jjgf.json @@ -7,12 +7,8 @@ "CVE-2002-2097" ], "details": "The compression code in MaraDNS before 0.9.01 allows remote attackers to cause a denial of service via crafted DNS packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q8x8-c673-g579/GHSA-q8x8-c673-g579.json b/advisories/unreviewed/2022/04/GHSA-q8x8-c673-g579/GHSA-q8x8-c673-g579.json index 3cb47ca44a0..7c57f5441db 100644 --- a/advisories/unreviewed/2022/04/GHSA-q8x8-c673-g579/GHSA-q8x8-c673-g579.json +++ b/advisories/unreviewed/2022/04/GHSA-q8x8-c673-g579/GHSA-q8x8-c673-g579.json @@ -7,12 +7,8 @@ "CVE-2002-1877" ], "details": "NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qfc2-8jrm-wwvr/GHSA-qfc2-8jrm-wwvr.json b/advisories/unreviewed/2022/04/GHSA-qfc2-8jrm-wwvr/GHSA-qfc2-8jrm-wwvr.json index 89336ca1150..3fc747f1a42 100644 --- a/advisories/unreviewed/2022/04/GHSA-qfc2-8jrm-wwvr/GHSA-qfc2-8jrm-wwvr.json +++ b/advisories/unreviewed/2022/04/GHSA-qfc2-8jrm-wwvr/GHSA-qfc2-8jrm-wwvr.json @@ -7,12 +7,8 @@ "CVE-2002-2035" ], "details": "SQL injection vulnerability in RealityScape MyLogin 2000 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password in the login form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qrqj-x9m6-gcv5/GHSA-qrqj-x9m6-gcv5.json b/advisories/unreviewed/2022/04/GHSA-qrqj-x9m6-gcv5/GHSA-qrqj-x9m6-gcv5.json index 651b48c6377..57618504249 100644 --- a/advisories/unreviewed/2022/04/GHSA-qrqj-x9m6-gcv5/GHSA-qrqj-x9m6-gcv5.json +++ b/advisories/unreviewed/2022/04/GHSA-qrqj-x9m6-gcv5/GHSA-qrqj-x9m6-gcv5.json @@ -7,12 +7,8 @@ "CVE-2002-2128" ], "details": "editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qwpw-w2v5-h4cw/GHSA-qwpw-w2v5-h4cw.json b/advisories/unreviewed/2022/04/GHSA-qwpw-w2v5-h4cw/GHSA-qwpw-w2v5-h4cw.json index 2ec182b1b0c..bd5498e5b54 100644 --- a/advisories/unreviewed/2022/04/GHSA-qwpw-w2v5-h4cw/GHSA-qwpw-w2v5-h4cw.json +++ b/advisories/unreviewed/2022/04/GHSA-qwpw-w2v5-h4cw/GHSA-qwpw-w2v5-h4cw.json @@ -7,12 +7,8 @@ "CVE-2002-1973" ], "details": "Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qxcf-383p-fhf4/GHSA-qxcf-383p-fhf4.json b/advisories/unreviewed/2022/04/GHSA-qxcf-383p-fhf4/GHSA-qxcf-383p-fhf4.json index e464c15f9fe..8f32ad2ab3b 100644 --- a/advisories/unreviewed/2022/04/GHSA-qxcf-383p-fhf4/GHSA-qxcf-383p-fhf4.json +++ b/advisories/unreviewed/2022/04/GHSA-qxcf-383p-fhf4/GHSA-qxcf-383p-fhf4.json @@ -7,12 +7,8 @@ "CVE-2002-1907" ], "details": "TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r48p-j2q3-xw9m/GHSA-r48p-j2q3-xw9m.json b/advisories/unreviewed/2022/04/GHSA-r48p-j2q3-xw9m/GHSA-r48p-j2q3-xw9m.json index 817ecc56144..1527b5254c3 100644 --- a/advisories/unreviewed/2022/04/GHSA-r48p-j2q3-xw9m/GHSA-r48p-j2q3-xw9m.json +++ b/advisories/unreviewed/2022/04/GHSA-r48p-j2q3-xw9m/GHSA-r48p-j2q3-xw9m.json @@ -7,12 +7,8 @@ "CVE-2002-1883" ], "details": "Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r4v6-4cq4-f35j/GHSA-r4v6-4cq4-f35j.json b/advisories/unreviewed/2022/04/GHSA-r4v6-4cq4-f35j/GHSA-r4v6-4cq4-f35j.json index a1b13595754..16ce73c6aa9 100644 --- a/advisories/unreviewed/2022/04/GHSA-r4v6-4cq4-f35j/GHSA-r4v6-4cq4-f35j.json +++ b/advisories/unreviewed/2022/04/GHSA-r4v6-4cq4-f35j/GHSA-r4v6-4cq4-f35j.json @@ -7,12 +7,8 @@ "CVE-2002-2086" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via (1) \"</, (3) 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p53-6566-mqvv/GHSA-6p53-6566-mqvv.json b/advisories/unreviewed/2022/05/GHSA-6p53-6566-mqvv/GHSA-6p53-6566-mqvv.json index 27d03d498b8..092c16f0ef9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p53-6566-mqvv/GHSA-6p53-6566-mqvv.json +++ b/advisories/unreviewed/2022/05/GHSA-6p53-6566-mqvv/GHSA-6p53-6566-mqvv.json @@ -7,12 +7,8 @@ "CVE-2020-21054" ], "details": "Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized \"f\" variable in app\\vars\\vars_textarea.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pr6-2grv-9mc6/GHSA-6pr6-2grv-9mc6.json b/advisories/unreviewed/2022/05/GHSA-6pr6-2grv-9mc6/GHSA-6pr6-2grv-9mc6.json index 943a082a0df..09977f13a71 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pr6-2grv-9mc6/GHSA-6pr6-2grv-9mc6.json +++ b/advisories/unreviewed/2022/05/GHSA-6pr6-2grv-9mc6/GHSA-6pr6-2grv-9mc6.json @@ -7,12 +7,8 @@ "CVE-2020-18220" ], "details": "Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q24-858g-34rg/GHSA-6q24-858g-34rg.json b/advisories/unreviewed/2022/05/GHSA-6q24-858g-34rg/GHSA-6q24-858g-34rg.json index ce54013e85a..0e67df3e57a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q24-858g-34rg/GHSA-6q24-858g-34rg.json +++ b/advisories/unreviewed/2022/05/GHSA-6q24-858g-34rg/GHSA-6q24-858g-34rg.json @@ -7,12 +7,8 @@ "CVE-2021-33181" ], "details": "Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q5v-82v5-mpf9/GHSA-6q5v-82v5-mpf9.json b/advisories/unreviewed/2022/05/GHSA-6q5v-82v5-mpf9/GHSA-6q5v-82v5-mpf9.json index 879da3d07b1..e9a0b551835 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q5v-82v5-mpf9/GHSA-6q5v-82v5-mpf9.json +++ b/advisories/unreviewed/2022/05/GHSA-6q5v-82v5-mpf9/GHSA-6q5v-82v5-mpf9.json @@ -7,12 +7,8 @@ "CVE-2021-22731" ], "details": "Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vx6-7ghj-3776/GHSA-6vx6-7ghj-3776.json b/advisories/unreviewed/2022/05/GHSA-6vx6-7ghj-3776/GHSA-6vx6-7ghj-3776.json index b8630d2ef73..bfcb7f8dc3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vx6-7ghj-3776/GHSA-6vx6-7ghj-3776.json +++ b/advisories/unreviewed/2022/05/GHSA-6vx6-7ghj-3776/GHSA-6vx6-7ghj-3776.json @@ -7,12 +7,8 @@ "CVE-2021-22699" ], "details": "Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wqw-44p4-565j/GHSA-6wqw-44p4-565j.json b/advisories/unreviewed/2022/05/GHSA-6wqw-44p4-565j/GHSA-6wqw-44p4-565j.json index 9838baf5280..1a4745f2005 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wqw-44p4-565j/GHSA-6wqw-44p4-565j.json +++ b/advisories/unreviewed/2022/05/GHSA-6wqw-44p4-565j/GHSA-6wqw-44p4-565j.json @@ -7,12 +7,8 @@ "CVE-2021-22740" ], "details": "Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xwq-33rx-28hg/GHSA-6xwq-33rx-28hg.json b/advisories/unreviewed/2022/05/GHSA-6xwq-33rx-28hg/GHSA-6xwq-33rx-28hg.json index 1bb321213bf..06ef7740976 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xwq-33rx-28hg/GHSA-6xwq-33rx-28hg.json +++ b/advisories/unreviewed/2022/05/GHSA-6xwq-33rx-28hg/GHSA-6xwq-33rx-28hg.json @@ -7,12 +7,8 @@ "CVE-2021-29206" ], "details": "A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xx3-j36r-9j4v/GHSA-6xx3-j36r-9j4v.json b/advisories/unreviewed/2022/05/GHSA-6xx3-j36r-9j4v/GHSA-6xx3-j36r-9j4v.json index 3e4bc061b3c..77e8cc4cb05 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xx3-j36r-9j4v/GHSA-6xx3-j36r-9j4v.json +++ b/advisories/unreviewed/2022/05/GHSA-6xx3-j36r-9j4v/GHSA-6xx3-j36r-9j4v.json @@ -7,12 +7,8 @@ "CVE-2021-22733" ], "details": "Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72xr-97qw-3wch/GHSA-72xr-97qw-3wch.json b/advisories/unreviewed/2022/05/GHSA-72xr-97qw-3wch/GHSA-72xr-97qw-3wch.json index 95ae5ee712d..ebd38baad81 100644 --- a/advisories/unreviewed/2022/05/GHSA-72xr-97qw-3wch/GHSA-72xr-97qw-3wch.json +++ b/advisories/unreviewed/2022/05/GHSA-72xr-97qw-3wch/GHSA-72xr-97qw-3wch.json @@ -7,12 +7,8 @@ "CVE-2021-24300" ], "details": "The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7732-95pg-6pp9/GHSA-7732-95pg-6pp9.json b/advisories/unreviewed/2022/05/GHSA-7732-95pg-6pp9/GHSA-7732-95pg-6pp9.json index a04ecf3bbf6..6972068048a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7732-95pg-6pp9/GHSA-7732-95pg-6pp9.json +++ b/advisories/unreviewed/2022/05/GHSA-7732-95pg-6pp9/GHSA-7732-95pg-6pp9.json @@ -7,12 +7,8 @@ "CVE-2021-20371" ], "details": "IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77vm-hfph-f8g6/GHSA-77vm-hfph-f8g6.json b/advisories/unreviewed/2022/05/GHSA-77vm-hfph-f8g6/GHSA-77vm-hfph-f8g6.json index 5018c642606..0af51aa0104 100644 --- a/advisories/unreviewed/2022/05/GHSA-77vm-hfph-f8g6/GHSA-77vm-hfph-f8g6.json +++ b/advisories/unreviewed/2022/05/GHSA-77vm-hfph-f8g6/GHSA-77vm-hfph-f8g6.json @@ -7,12 +7,8 @@ "CVE-2021-24313" ], "details": "The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c98-4wpw-92jq/GHSA-7c98-4wpw-92jq.json b/advisories/unreviewed/2022/05/GHSA-7c98-4wpw-92jq/GHSA-7c98-4wpw-92jq.json index cac91390a62..e6507fabc32 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c98-4wpw-92jq/GHSA-7c98-4wpw-92jq.json +++ b/advisories/unreviewed/2022/05/GHSA-7c98-4wpw-92jq/GHSA-7c98-4wpw-92jq.json @@ -7,12 +7,8 @@ "CVE-2021-3480" ], "details": "A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h2p-2h3r-mgq6/GHSA-7h2p-2h3r-mgq6.json b/advisories/unreviewed/2022/05/GHSA-7h2p-2h3r-mgq6/GHSA-7h2p-2h3r-mgq6.json index c3ce83c67c3..1a7c44f4438 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h2p-2h3r-mgq6/GHSA-7h2p-2h3r-mgq6.json +++ b/advisories/unreviewed/2022/05/GHSA-7h2p-2h3r-mgq6/GHSA-7h2p-2h3r-mgq6.json @@ -7,12 +7,8 @@ "CVE-2021-20575" ], "details": "IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hjq-w7jv-vgv5/GHSA-7hjq-w7jv-vgv5.json b/advisories/unreviewed/2022/05/GHSA-7hjq-w7jv-vgv5/GHSA-7hjq-w7jv-vgv5.json index f28a2965f06..8dfa4601de1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hjq-w7jv-vgv5/GHSA-7hjq-w7jv-vgv5.json +++ b/advisories/unreviewed/2022/05/GHSA-7hjq-w7jv-vgv5/GHSA-7hjq-w7jv-vgv5.json @@ -7,12 +7,8 @@ "CVE-2018-16496" ], "details": "In Versa Director, the un-authentication request found.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mh2-3h46-3mff/GHSA-7mh2-3h46-3mff.json b/advisories/unreviewed/2022/05/GHSA-7mh2-3h46-3mff/GHSA-7mh2-3h46-3mff.json index a0ee3e02f52..d8e4f952bb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mh2-3h46-3mff/GHSA-7mh2-3h46-3mff.json +++ b/advisories/unreviewed/2022/05/GHSA-7mh2-3h46-3mff/GHSA-7mh2-3h46-3mff.json @@ -7,12 +7,8 @@ "CVE-2021-24331" ], "details": "The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pcq-9p5g-vh97/GHSA-7pcq-9p5g-vh97.json b/advisories/unreviewed/2022/05/GHSA-7pcq-9p5g-vh97/GHSA-7pcq-9p5g-vh97.json index 9faf7b0d679..575be1594a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pcq-9p5g-vh97/GHSA-7pcq-9p5g-vh97.json +++ b/advisories/unreviewed/2022/05/GHSA-7pcq-9p5g-vh97/GHSA-7pcq-9p5g-vh97.json @@ -7,12 +7,8 @@ "CVE-2021-29253" ], "details": "The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vvp-2794-8qxc/GHSA-7vvp-2794-8qxc.json b/advisories/unreviewed/2022/05/GHSA-7vvp-2794-8qxc/GHSA-7vvp-2794-8qxc.json index 4a087811a17..2c50a646a35 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vvp-2794-8qxc/GHSA-7vvp-2794-8qxc.json +++ b/advisories/unreviewed/2022/05/GHSA-7vvp-2794-8qxc/GHSA-7vvp-2794-8qxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82r6-6mqq-4v58/GHSA-82r6-6mqq-4v58.json b/advisories/unreviewed/2022/05/GHSA-82r6-6mqq-4v58/GHSA-82r6-6mqq-4v58.json index 639ef8eaeb4..45d1e69c7a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-82r6-6mqq-4v58/GHSA-82r6-6mqq-4v58.json +++ b/advisories/unreviewed/2022/05/GHSA-82r6-6mqq-4v58/GHSA-82r6-6mqq-4v58.json @@ -7,12 +7,8 @@ "CVE-2018-16494" ], "details": "In VOS and overly permissive \"umask\" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directories. Insecure umask setting was present throughout the Versa servers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84w2-g5p3-84v5/GHSA-84w2-g5p3-84v5.json b/advisories/unreviewed/2022/05/GHSA-84w2-g5p3-84v5/GHSA-84w2-g5p3-84v5.json index d72468e21af..7fad9dfb29d 100644 --- a/advisories/unreviewed/2022/05/GHSA-84w2-g5p3-84v5/GHSA-84w2-g5p3-84v5.json +++ b/advisories/unreviewed/2022/05/GHSA-84w2-g5p3-84v5/GHSA-84w2-g5p3-84v5.json @@ -7,12 +7,8 @@ "CVE-2020-26642" ], "details": "A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85jh-x2q3-f29m/GHSA-85jh-x2q3-f29m.json b/advisories/unreviewed/2022/05/GHSA-85jh-x2q3-f29m/GHSA-85jh-x2q3-f29m.json index b95f694239d..d188207ac75 100644 --- a/advisories/unreviewed/2022/05/GHSA-85jh-x2q3-f29m/GHSA-85jh-x2q3-f29m.json +++ b/advisories/unreviewed/2022/05/GHSA-85jh-x2q3-f29m/GHSA-85jh-x2q3-f29m.json @@ -7,12 +7,8 @@ "CVE-2021-31703" ], "details": "Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88gh-wqj4-3fxr/GHSA-88gh-wqj4-3fxr.json b/advisories/unreviewed/2022/05/GHSA-88gh-wqj4-3fxr/GHSA-88gh-wqj4-3fxr.json index 053db34c27a..277813e03c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-88gh-wqj4-3fxr/GHSA-88gh-wqj4-3fxr.json +++ b/advisories/unreviewed/2022/05/GHSA-88gh-wqj4-3fxr/GHSA-88gh-wqj4-3fxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json b/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json index 1b8c8cdde8d..f27391b1480 100644 --- a/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json +++ b/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json @@ -7,12 +7,8 @@ "CVE-2021-29088" ], "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88vg-7c8f-h3pr/GHSA-88vg-7c8f-h3pr.json b/advisories/unreviewed/2022/05/GHSA-88vg-7c8f-h3pr/GHSA-88vg-7c8f-h3pr.json index 69520849c9e..be667294b3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-88vg-7c8f-h3pr/GHSA-88vg-7c8f-h3pr.json +++ b/advisories/unreviewed/2022/05/GHSA-88vg-7c8f-h3pr/GHSA-88vg-7c8f-h3pr.json @@ -7,12 +7,8 @@ "CVE-2018-16499" ], "details": "In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical Security Requirements).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89hp-893v-jcmm/GHSA-89hp-893v-jcmm.json b/advisories/unreviewed/2022/05/GHSA-89hp-893v-jcmm/GHSA-89hp-893v-jcmm.json index 3e223a7f115..f8e5bca7dc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-89hp-893v-jcmm/GHSA-89hp-893v-jcmm.json +++ b/advisories/unreviewed/2022/05/GHSA-89hp-893v-jcmm/GHSA-89hp-893v-jcmm.json @@ -7,12 +7,8 @@ "CVE-2021-23896" ], "details": "Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cq6-q8qw-2fr2/GHSA-8cq6-q8qw-2fr2.json b/advisories/unreviewed/2022/05/GHSA-8cq6-q8qw-2fr2/GHSA-8cq6-q8qw-2fr2.json index eac206b3725..07935968cdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cq6-q8qw-2fr2/GHSA-8cq6-q8qw-2fr2.json +++ b/advisories/unreviewed/2022/05/GHSA-8cq6-q8qw-2fr2/GHSA-8cq6-q8qw-2fr2.json @@ -7,12 +7,8 @@ "CVE-2021-30193" ], "details": "CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cr8-fvmm-h4p4/GHSA-8cr8-fvmm-h4p4.json b/advisories/unreviewed/2022/05/GHSA-8cr8-fvmm-h4p4/GHSA-8cr8-fvmm-h4p4.json index a0cf28931a7..25aca20e463 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cr8-fvmm-h4p4/GHSA-8cr8-fvmm-h4p4.json +++ b/advisories/unreviewed/2022/05/GHSA-8cr8-fvmm-h4p4/GHSA-8cr8-fvmm-h4p4.json @@ -7,12 +7,8 @@ "CVE-2020-10695" ], "details": "An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hgv-2x29-2prx/GHSA-8hgv-2x29-2prx.json b/advisories/unreviewed/2022/05/GHSA-8hgv-2x29-2prx/GHSA-8hgv-2x29-2prx.json index be9feac442f..3347a0ba74c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hgv-2x29-2prx/GHSA-8hgv-2x29-2prx.json +++ b/advisories/unreviewed/2022/05/GHSA-8hgv-2x29-2prx/GHSA-8hgv-2x29-2prx.json @@ -7,12 +7,8 @@ "CVE-2021-22746" ], "details": "Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22745, and CVE-2021-22747.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hpj-w92q-gf6m/GHSA-8hpj-w92q-gf6m.json b/advisories/unreviewed/2022/05/GHSA-8hpj-w92q-gf6m/GHSA-8hpj-w92q-gf6m.json index 8d30ccb0202..382814ec206 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hpj-w92q-gf6m/GHSA-8hpj-w92q-gf6m.json +++ b/advisories/unreviewed/2022/05/GHSA-8hpj-w92q-gf6m/GHSA-8hpj-w92q-gf6m.json @@ -7,12 +7,8 @@ "CVE-2021-20177" ], "details": "A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hw7-43qp-rq48/GHSA-8hw7-43qp-rq48.json b/advisories/unreviewed/2022/05/GHSA-8hw7-43qp-rq48/GHSA-8hw7-43qp-rq48.json index 11580d604ee..1f5bc369176 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hw7-43qp-rq48/GHSA-8hw7-43qp-rq48.json +++ b/advisories/unreviewed/2022/05/GHSA-8hw7-43qp-rq48/GHSA-8hw7-43qp-rq48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jfh-ph5c-r74h/GHSA-8jfh-ph5c-r74h.json b/advisories/unreviewed/2022/05/GHSA-8jfh-ph5c-r74h/GHSA-8jfh-ph5c-r74h.json index 5ea0a97709e..26109eb8af8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jfh-ph5c-r74h/GHSA-8jfh-ph5c-r74h.json +++ b/advisories/unreviewed/2022/05/GHSA-8jfh-ph5c-r74h/GHSA-8jfh-ph5c-r74h.json @@ -7,12 +7,8 @@ "CVE-2021-22891" ], "details": "A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mc9-pw6m-fph8/GHSA-8mc9-pw6m-fph8.json b/advisories/unreviewed/2022/05/GHSA-8mc9-pw6m-fph8/GHSA-8mc9-pw6m-fph8.json index c69bc102116..72b1d9363bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mc9-pw6m-fph8/GHSA-8mc9-pw6m-fph8.json +++ b/advisories/unreviewed/2022/05/GHSA-8mc9-pw6m-fph8/GHSA-8mc9-pw6m-fph8.json @@ -7,12 +7,8 @@ "CVE-2020-5030" ], "details": "IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pmh-46hf-c4rr/GHSA-8pmh-46hf-c4rr.json b/advisories/unreviewed/2022/05/GHSA-8pmh-46hf-c4rr/GHSA-8pmh-46hf-c4rr.json index ca48656dcc4..85135083536 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pmh-46hf-c4rr/GHSA-8pmh-46hf-c4rr.json +++ b/advisories/unreviewed/2022/05/GHSA-8pmh-46hf-c4rr/GHSA-8pmh-46hf-c4rr.json @@ -7,12 +7,8 @@ "CVE-2020-22020" ], "details": "Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pr6-wcxr-5g9c/GHSA-8pr6-wcxr-5g9c.json b/advisories/unreviewed/2022/05/GHSA-8pr6-wcxr-5g9c/GHSA-8pr6-wcxr-5g9c.json index 601e2b54890..f75f99f8ff7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pr6-wcxr-5g9c/GHSA-8pr6-wcxr-5g9c.json +++ b/advisories/unreviewed/2022/05/GHSA-8pr6-wcxr-5g9c/GHSA-8pr6-wcxr-5g9c.json @@ -7,12 +7,8 @@ "CVE-2021-20576" ], "details": "IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rfm-2pfj-5pq2/GHSA-8rfm-2pfj-5pq2.json b/advisories/unreviewed/2022/05/GHSA-8rfm-2pfj-5pq2/GHSA-8rfm-2pfj-5pq2.json index 15ef4d42f2b..3e2054fb5d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rfm-2pfj-5pq2/GHSA-8rfm-2pfj-5pq2.json +++ b/advisories/unreviewed/2022/05/GHSA-8rfm-2pfj-5pq2/GHSA-8rfm-2pfj-5pq2.json @@ -7,12 +7,8 @@ "CVE-2020-22051" ], "details": "A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wg3-gqcw-9fq9/GHSA-8wg3-gqcw-9fq9.json b/advisories/unreviewed/2022/05/GHSA-8wg3-gqcw-9fq9/GHSA-8wg3-gqcw-9fq9.json index 33fd942af8d..534af228d09 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wg3-gqcw-9fq9/GHSA-8wg3-gqcw-9fq9.json +++ b/advisories/unreviewed/2022/05/GHSA-8wg3-gqcw-9fq9/GHSA-8wg3-gqcw-9fq9.json @@ -7,12 +7,8 @@ "CVE-2020-25710" ], "details": "A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8ww6-p355-pvjq/GHSA-8ww6-p355-pvjq.json b/advisories/unreviewed/2022/05/GHSA-8ww6-p355-pvjq/GHSA-8ww6-p355-pvjq.json index 5ff0dad43db..f0ed77f45f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ww6-p355-pvjq/GHSA-8ww6-p355-pvjq.json +++ b/advisories/unreviewed/2022/05/GHSA-8ww6-p355-pvjq/GHSA-8ww6-p355-pvjq.json @@ -7,12 +7,8 @@ "CVE-2021-33806" ], "details": "The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-922p-pp6v-6fw3/GHSA-922p-pp6v-6fw3.json b/advisories/unreviewed/2022/05/GHSA-922p-pp6v-6fw3/GHSA-922p-pp6v-6fw3.json index 315468ca3d9..5b6c0959d49 100644 --- a/advisories/unreviewed/2022/05/GHSA-922p-pp6v-6fw3/GHSA-922p-pp6v-6fw3.json +++ b/advisories/unreviewed/2022/05/GHSA-922p-pp6v-6fw3/GHSA-922p-pp6v-6fw3.json @@ -7,12 +7,8 @@ "CVE-2020-22039" ], "details": "A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-929g-qc9f-pm5x/GHSA-929g-qc9f-pm5x.json b/advisories/unreviewed/2022/05/GHSA-929g-qc9f-pm5x/GHSA-929g-qc9f-pm5x.json index 1347f81a191..39c702311e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-929g-qc9f-pm5x/GHSA-929g-qc9f-pm5x.json +++ b/advisories/unreviewed/2022/05/GHSA-929g-qc9f-pm5x/GHSA-929g-qc9f-pm5x.json @@ -7,12 +7,8 @@ "CVE-2020-26669" ], "details": "A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92x8-g62q-w3jw/GHSA-92x8-g62q-w3jw.json b/advisories/unreviewed/2022/05/GHSA-92x8-g62q-w3jw/GHSA-92x8-g62q-w3jw.json index 7c63234c537..7625316785f 100644 --- a/advisories/unreviewed/2022/05/GHSA-92x8-g62q-w3jw/GHSA-92x8-g62q-w3jw.json +++ b/advisories/unreviewed/2022/05/GHSA-92x8-g62q-w3jw/GHSA-92x8-g62q-w3jw.json @@ -7,12 +7,8 @@ "CVE-2021-29207" ], "details": "A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-934g-qjpp-c7xg/GHSA-934g-qjpp-c7xg.json b/advisories/unreviewed/2022/05/GHSA-934g-qjpp-c7xg/GHSA-934g-qjpp-c7xg.json index 42cfc92449d..4fc6b503837 100644 --- a/advisories/unreviewed/2022/05/GHSA-934g-qjpp-c7xg/GHSA-934g-qjpp-c7xg.json +++ b/advisories/unreviewed/2022/05/GHSA-934g-qjpp-c7xg/GHSA-934g-qjpp-c7xg.json @@ -7,12 +7,8 @@ "CVE-2020-20453" ], "details": "FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93g9-m7c5-r983/GHSA-93g9-m7c5-r983.json b/advisories/unreviewed/2022/05/GHSA-93g9-m7c5-r983/GHSA-93g9-m7c5-r983.json index 29b369ca327..66d4166a61a 100644 --- a/advisories/unreviewed/2022/05/GHSA-93g9-m7c5-r983/GHSA-93g9-m7c5-r983.json +++ b/advisories/unreviewed/2022/05/GHSA-93g9-m7c5-r983/GHSA-93g9-m7c5-r983.json @@ -7,12 +7,8 @@ "CVE-2020-22016" ], "details": "A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9592-7844-9gm7/GHSA-9592-7844-9gm7.json b/advisories/unreviewed/2022/05/GHSA-9592-7844-9gm7/GHSA-9592-7844-9gm7.json index 7989f87287e..80d648da4f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9592-7844-9gm7/GHSA-9592-7844-9gm7.json +++ b/advisories/unreviewed/2022/05/GHSA-9592-7844-9gm7/GHSA-9592-7844-9gm7.json @@ -7,12 +7,8 @@ "CVE-2021-20348" ], "details": "IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9649-7hjp-5xg6/GHSA-9649-7hjp-5xg6.json b/advisories/unreviewed/2022/05/GHSA-9649-7hjp-5xg6/GHSA-9649-7hjp-5xg6.json index 8fc5815ce95..d57b41756fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-9649-7hjp-5xg6/GHSA-9649-7hjp-5xg6.json +++ b/advisories/unreviewed/2022/05/GHSA-9649-7hjp-5xg6/GHSA-9649-7hjp-5xg6.json @@ -7,12 +7,8 @@ "CVE-2021-27956" ], "details": "Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96c9-2w33-8fq2/GHSA-96c9-2w33-8fq2.json b/advisories/unreviewed/2022/05/GHSA-96c9-2w33-8fq2/GHSA-96c9-2w33-8fq2.json index 78400f341be..40db6e58bbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-96c9-2w33-8fq2/GHSA-96c9-2w33-8fq2.json +++ b/advisories/unreviewed/2022/05/GHSA-96c9-2w33-8fq2/GHSA-96c9-2w33-8fq2.json @@ -7,12 +7,8 @@ "CVE-2021-29682" ], "details": "IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96ww-mfw9-h4gh/GHSA-96ww-mfw9-h4gh.json b/advisories/unreviewed/2022/05/GHSA-96ww-mfw9-h4gh/GHSA-96ww-mfw9-h4gh.json index bca73808953..fb045c884ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-96ww-mfw9-h4gh/GHSA-96ww-mfw9-h4gh.json +++ b/advisories/unreviewed/2022/05/GHSA-96ww-mfw9-h4gh/GHSA-96ww-mfw9-h4gh.json @@ -7,12 +7,8 @@ "CVE-2019-4724" ], "details": "IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-979x-3p5w-qvgc/GHSA-979x-3p5w-qvgc.json b/advisories/unreviewed/2022/05/GHSA-979x-3p5w-qvgc/GHSA-979x-3p5w-qvgc.json index 6bce3ce2a3f..469a9b80c74 100644 --- a/advisories/unreviewed/2022/05/GHSA-979x-3p5w-qvgc/GHSA-979x-3p5w-qvgc.json +++ b/advisories/unreviewed/2022/05/GHSA-979x-3p5w-qvgc/GHSA-979x-3p5w-qvgc.json @@ -7,12 +7,8 @@ "CVE-2020-26678" ], "details": "vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97vm-rx4r-gj94/GHSA-97vm-rx4r-gj94.json b/advisories/unreviewed/2022/05/GHSA-97vm-rx4r-gj94/GHSA-97vm-rx4r-gj94.json index 2c190b63752..064eb97a86f 100644 --- a/advisories/unreviewed/2022/05/GHSA-97vm-rx4r-gj94/GHSA-97vm-rx4r-gj94.json +++ b/advisories/unreviewed/2022/05/GHSA-97vm-rx4r-gj94/GHSA-97vm-rx4r-gj94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-984h-v8xh-q988/GHSA-984h-v8xh-q988.json b/advisories/unreviewed/2022/05/GHSA-984h-v8xh-q988/GHSA-984h-v8xh-q988.json index e7307305995..c4579b59c78 100644 --- a/advisories/unreviewed/2022/05/GHSA-984h-v8xh-q988/GHSA-984h-v8xh-q988.json +++ b/advisories/unreviewed/2022/05/GHSA-984h-v8xh-q988/GHSA-984h-v8xh-q988.json @@ -7,12 +7,8 @@ "CVE-2021-1552" ], "details": "Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98vf-qm54-mrfm/GHSA-98vf-qm54-mrfm.json b/advisories/unreviewed/2022/05/GHSA-98vf-qm54-mrfm/GHSA-98vf-qm54-mrfm.json index 5e712bef117..dcb85d4c521 100644 --- a/advisories/unreviewed/2022/05/GHSA-98vf-qm54-mrfm/GHSA-98vf-qm54-mrfm.json +++ b/advisories/unreviewed/2022/05/GHSA-98vf-qm54-mrfm/GHSA-98vf-qm54-mrfm.json @@ -7,12 +7,8 @@ "CVE-2020-22041" ], "details": "A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c2r-jv32-cj3f/GHSA-9c2r-jv32-cj3f.json b/advisories/unreviewed/2022/05/GHSA-9c2r-jv32-cj3f/GHSA-9c2r-jv32-cj3f.json index 2063512e6ce..de35d684472 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c2r-jv32-cj3f/GHSA-9c2r-jv32-cj3f.json +++ b/advisories/unreviewed/2022/05/GHSA-9c2r-jv32-cj3f/GHSA-9c2r-jv32-cj3f.json @@ -7,12 +7,8 @@ "CVE-2020-21003" ], "details": "Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gxp-8w92-6cxw/GHSA-9gxp-8w92-6cxw.json b/advisories/unreviewed/2022/05/GHSA-9gxp-8w92-6cxw/GHSA-9gxp-8w92-6cxw.json index f1cf6346e17..f1df43a5ffb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gxp-8w92-6cxw/GHSA-9gxp-8w92-6cxw.json +++ b/advisories/unreviewed/2022/05/GHSA-9gxp-8w92-6cxw/GHSA-9gxp-8w92-6cxw.json @@ -7,12 +7,8 @@ "CVE-2021-24316" ], "details": "The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hr6-g366-m3pm/GHSA-9hr6-g366-m3pm.json b/advisories/unreviewed/2022/05/GHSA-9hr6-g366-m3pm/GHSA-9hr6-g366-m3pm.json index 3345e5aac82..60b5373a6ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hr6-g366-m3pm/GHSA-9hr6-g366-m3pm.json +++ b/advisories/unreviewed/2022/05/GHSA-9hr6-g366-m3pm/GHSA-9hr6-g366-m3pm.json @@ -7,12 +7,8 @@ "CVE-2021-30191" ], "details": "CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m2j-xcq6-wjv7/GHSA-9m2j-xcq6-wjv7.json b/advisories/unreviewed/2022/05/GHSA-9m2j-xcq6-wjv7/GHSA-9m2j-xcq6-wjv7.json index 69aa5f1cbbb..817e059493b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m2j-xcq6-wjv7/GHSA-9m2j-xcq6-wjv7.json +++ b/advisories/unreviewed/2022/05/GHSA-9m2j-xcq6-wjv7/GHSA-9m2j-xcq6-wjv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mvm-x44p-xc3j/GHSA-9mvm-x44p-xc3j.json b/advisories/unreviewed/2022/05/GHSA-9mvm-x44p-xc3j/GHSA-9mvm-x44p-xc3j.json index 63fa68c230d..0ef9b7753b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mvm-x44p-xc3j/GHSA-9mvm-x44p-xc3j.json +++ b/advisories/unreviewed/2022/05/GHSA-9mvm-x44p-xc3j/GHSA-9mvm-x44p-xc3j.json @@ -7,12 +7,8 @@ "CVE-2020-35971" ], "details": "A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9ppp-5qxh-r7w5/GHSA-9ppp-5qxh-r7w5.json b/advisories/unreviewed/2022/05/GHSA-9ppp-5qxh-r7w5/GHSA-9ppp-5qxh-r7w5.json index 740d10a1fd6..de235dff37c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ppp-5qxh-r7w5/GHSA-9ppp-5qxh-r7w5.json +++ b/advisories/unreviewed/2022/05/GHSA-9ppp-5qxh-r7w5/GHSA-9ppp-5qxh-r7w5.json @@ -7,12 +7,8 @@ "CVE-2021-30186" ], "details": "CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v4v-7vv2-wr82/GHSA-9v4v-7vv2-wr82.json b/advisories/unreviewed/2022/05/GHSA-9v4v-7vv2-wr82/GHSA-9v4v-7vv2-wr82.json index f5ef5f93a7c..8e36e0a8134 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v4v-7vv2-wr82/GHSA-9v4v-7vv2-wr82.json +++ b/advisories/unreviewed/2022/05/GHSA-9v4v-7vv2-wr82/GHSA-9v4v-7vv2-wr82.json @@ -7,12 +7,8 @@ "CVE-2021-24317" ], "details": "The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x8w-jj9g-vgv3/GHSA-9x8w-jj9g-vgv3.json b/advisories/unreviewed/2022/05/GHSA-9x8w-jj9g-vgv3/GHSA-9x8w-jj9g-vgv3.json index 328d9ae6e2f..c273ace0309 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x8w-jj9g-vgv3/GHSA-9x8w-jj9g-vgv3.json +++ b/advisories/unreviewed/2022/05/GHSA-9x8w-jj9g-vgv3/GHSA-9x8w-jj9g-vgv3.json @@ -7,12 +7,8 @@ "CVE-2021-24320" ], "details": "The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2mf-6c8w-693h/GHSA-c2mf-6c8w-693h.json b/advisories/unreviewed/2022/05/GHSA-c2mf-6c8w-693h/GHSA-c2mf-6c8w-693h.json index b06ab21415d..a4307caf64d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2mf-6c8w-693h/GHSA-c2mf-6c8w-693h.json +++ b/advisories/unreviewed/2022/05/GHSA-c2mf-6c8w-693h/GHSA-c2mf-6c8w-693h.json @@ -7,12 +7,8 @@ "CVE-2020-18230" ], "details": "Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter \"$cfg_switchshow\" of component \" /admin/web_config.php\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c57j-pq55-rh2x/GHSA-c57j-pq55-rh2x.json b/advisories/unreviewed/2022/05/GHSA-c57j-pq55-rh2x/GHSA-c57j-pq55-rh2x.json index 7611358413c..13fd4e4d3d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c57j-pq55-rh2x/GHSA-c57j-pq55-rh2x.json +++ b/advisories/unreviewed/2022/05/GHSA-c57j-pq55-rh2x/GHSA-c57j-pq55-rh2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5g4-f3c5-3jpf/GHSA-c5g4-f3c5-3jpf.json b/advisories/unreviewed/2022/05/GHSA-c5g4-f3c5-3jpf/GHSA-c5g4-f3c5-3jpf.json index fe58e274a44..afce04f2964 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5g4-f3c5-3jpf/GHSA-c5g4-f3c5-3jpf.json +++ b/advisories/unreviewed/2022/05/GHSA-c5g4-f3c5-3jpf/GHSA-c5g4-f3c5-3jpf.json @@ -7,12 +7,8 @@ "CVE-2020-36004" ], "details": "AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5g9-x4gm-2c84/GHSA-c5g9-x4gm-2c84.json b/advisories/unreviewed/2022/05/GHSA-c5g9-x4gm-2c84/GHSA-c5g9-x4gm-2c84.json index c602c203c92..7bf46dc8bee 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5g9-x4gm-2c84/GHSA-c5g9-x4gm-2c84.json +++ b/advisories/unreviewed/2022/05/GHSA-c5g9-x4gm-2c84/GHSA-c5g9-x4gm-2c84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6v8-67cp-6v4p/GHSA-c6v8-67cp-6v4p.json b/advisories/unreviewed/2022/05/GHSA-c6v8-67cp-6v4p/GHSA-c6v8-67cp-6v4p.json index fae11d022ca..8adbeffaf6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6v8-67cp-6v4p/GHSA-c6v8-67cp-6v4p.json +++ b/advisories/unreviewed/2022/05/GHSA-c6v8-67cp-6v4p/GHSA-c6v8-67cp-6v4p.json @@ -7,12 +7,8 @@ "CVE-2006-0459" ], "details": "flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7r9-mwvj-rr98/GHSA-c7r9-mwvj-rr98.json b/advisories/unreviewed/2022/05/GHSA-c7r9-mwvj-rr98/GHSA-c7r9-mwvj-rr98.json index e987054d4e3..408e4339da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7r9-mwvj-rr98/GHSA-c7r9-mwvj-rr98.json +++ b/advisories/unreviewed/2022/05/GHSA-c7r9-mwvj-rr98/GHSA-c7r9-mwvj-rr98.json @@ -7,12 +7,8 @@ "CVE-2020-14329" ], "details": "A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7w7-ggmf-v38v/GHSA-c7w7-ggmf-v38v.json b/advisories/unreviewed/2022/05/GHSA-c7w7-ggmf-v38v/GHSA-c7w7-ggmf-v38v.json index 724de2eb70f..c473d2d9e06 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7w7-ggmf-v38v/GHSA-c7w7-ggmf-v38v.json +++ b/advisories/unreviewed/2022/05/GHSA-c7w7-ggmf-v38v/GHSA-c7w7-ggmf-v38v.json @@ -7,12 +7,8 @@ "CVE-2017-17674" ], "details": "BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c84c-76xv-wmp8/GHSA-c84c-76xv-wmp8.json b/advisories/unreviewed/2022/05/GHSA-c84c-76xv-wmp8/GHSA-c84c-76xv-wmp8.json index 1c5e631c8f7..8fa44fc951f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c84c-76xv-wmp8/GHSA-c84c-76xv-wmp8.json +++ b/advisories/unreviewed/2022/05/GHSA-c84c-76xv-wmp8/GHSA-c84c-76xv-wmp8.json @@ -7,12 +7,8 @@ "CVE-2021-24319" ], "details": "The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c864-88h8-cf2j/GHSA-c864-88h8-cf2j.json b/advisories/unreviewed/2022/05/GHSA-c864-88h8-cf2j/GHSA-c864-88h8-cf2j.json index f389fdd6819..9bd89955682 100644 --- a/advisories/unreviewed/2022/05/GHSA-c864-88h8-cf2j/GHSA-c864-88h8-cf2j.json +++ b/advisories/unreviewed/2022/05/GHSA-c864-88h8-cf2j/GHSA-c864-88h8-cf2j.json @@ -7,12 +7,8 @@ "CVE-2021-24309" ], "details": "The \"Schedule Name\" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the