diff --git a/advisories/github-reviewed/2017/10/GHSA-9959-c6q6-6qp3/GHSA-9959-c6q6-6qp3.json b/advisories/github-reviewed/2017/10/GHSA-9959-c6q6-6qp3/GHSA-9959-c6q6-6qp3.json index d752477d01d..14e8d4c94f5 100644 --- a/advisories/github-reviewed/2017/10/GHSA-9959-c6q6-6qp3/GHSA-9959-c6q6-6qp3.json +++ b/advisories/github-reviewed/2017/10/GHSA-9959-c6q6-6qp3/GHSA-9959-c6q6-6qp3.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T16:30:41Z", "published": "2017-10-24T18:33:36Z", "withdrawn": "2020-06-17T16:30:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects validator", "details": "**Withdrawn:** Duplicate of GHSA-79mx-88w7-8f7q", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T16:30:41Z", diff --git a/advisories/github-reviewed/2017/10/GHSA-fmr4-7g9q-7hc7/GHSA-fmr4-7g9q-7hc7.json b/advisories/github-reviewed/2017/10/GHSA-fmr4-7g9q-7hc7/GHSA-fmr4-7g9q-7hc7.json index b214b569dfa..f96efb45b17 100644 --- a/advisories/github-reviewed/2017/10/GHSA-fmr4-7g9q-7hc7/GHSA-fmr4-7g9q-7hc7.json +++ b/advisories/github-reviewed/2017/10/GHSA-fmr4-7g9q-7hc7/GHSA-fmr4-7g9q-7hc7.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T16:30:43Z", "published": "2017-10-24T18:33:36Z", "withdrawn": "2020-06-17T16:30:43Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects handlebars", "details": "**Withdrawn:** Duplicate of GHSA-9prh-257w-9277", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T16:30:43Z", diff --git a/advisories/github-reviewed/2017/10/GHSA-vxp4-25qp-86qh/GHSA-vxp4-25qp-86qh.json b/advisories/github-reviewed/2017/10/GHSA-vxp4-25qp-86qh/GHSA-vxp4-25qp-86qh.json index 271dd3f1e11..745b8f3dc39 100644 --- a/advisories/github-reviewed/2017/10/GHSA-vxp4-25qp-86qh/GHSA-vxp4-25qp-86qh.json +++ b/advisories/github-reviewed/2017/10/GHSA-vxp4-25qp-86qh/GHSA-vxp4-25qp-86qh.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:15:14Z", "published": "2017-10-24T18:33:36Z", "withdrawn": "2020-06-17T15:15:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects ember", "details": "Withdrawn, accidental duplicate publish.\n\nCross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before 2.2.1 allows remote attackers to inject arbitrary web script or HTML.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -139,9 +135,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:14Z", diff --git a/advisories/github-reviewed/2017/10/GHSA-xqg8-cv3h-xppv/GHSA-xqg8-cv3h-xppv.json b/advisories/github-reviewed/2017/10/GHSA-xqg8-cv3h-xppv/GHSA-xqg8-cv3h-xppv.json index 41ea5387f35..e4325ae02fa 100644 --- a/advisories/github-reviewed/2017/10/GHSA-xqg8-cv3h-xppv/GHSA-xqg8-cv3h-xppv.json +++ b/advisories/github-reviewed/2017/10/GHSA-xqg8-cv3h-xppv/GHSA-xqg8-cv3h-xppv.json @@ -8,9 +8,7 @@ ], "summary": "SQL Injection in sequelize", "details": "Versions 2.0.0-rc-7 and earlier of `sequelize` are affected by a SQL injection vulnerability when user input is passed into the order parameter.\n\n\n\n## Proof of Concept\n\n```javascript\nTest.findAndCountAll({\nwhere: { id :1 },\norder : [['id', 'UNTRUSTED USER INPUT']]\n})\n```\n\n\n## Recommendation\n\nUpdate to version 2.0.0-rc8 or later", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-xwg4-93c6-3h42/GHSA-xwg4-93c6-3h42.json b/advisories/github-reviewed/2017/10/GHSA-xwg4-93c6-3h42/GHSA-xwg4-93c6-3h42.json index 663bc73a1f3..4518422f46b 100644 --- a/advisories/github-reviewed/2017/10/GHSA-xwg4-93c6-3h42/GHSA-xwg4-93c6-3h42.json +++ b/advisories/github-reviewed/2017/10/GHSA-xwg4-93c6-3h42/GHSA-xwg4-93c6-3h42.json @@ -8,9 +8,7 @@ ], "summary": "Directory Traversal in send", "details": "Versions 0.8.3 and earlier of `send` are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory. \n\nFor example, `static(_dirname + '/public')` would allow access to `_dirname + '/public-restricted'`.\n\n\n## Recommendation\n\nUpdate to version 0.8.4 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2017/10/GHSA-xxvw-45rp-3mj2/GHSA-xxvw-45rp-3mj2.json b/advisories/github-reviewed/2017/10/GHSA-xxvw-45rp-3mj2/GHSA-xxvw-45rp-3mj2.json index e46e678aad9..63f83c30ba3 100644 --- a/advisories/github-reviewed/2017/10/GHSA-xxvw-45rp-3mj2/GHSA-xxvw-45rp-3mj2.json +++ b/advisories/github-reviewed/2017/10/GHSA-xxvw-45rp-3mj2/GHSA-xxvw-45rp-3mj2.json @@ -8,9 +8,7 @@ ], "summary": "Deserialization Code Execution in js-yaml", "details": "Versions 2.0.4 and earlier of `js-yaml` are affected by a code execution vulnerability in the YAML deserializer.\n\n## Proof of Concept\n```\nconst yaml = require('js-yaml');\n\nconst x = `test: !!js/function >\nfunction f() { \nconsole.log(1); \n}();`\n\nyaml.load(x);\n```\n\n\n## Recommendation\n\nUpdate js-yaml to version 2.0.5 or later, and ensure that all instances where the `.load()` method is called are updated to use `.safeLoad()` instead.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/06/GHSA-rc8h-3fv6-pxv8/GHSA-rc8h-3fv6-pxv8.json b/advisories/github-reviewed/2018/06/GHSA-rc8h-3fv6-pxv8/GHSA-rc8h-3fv6-pxv8.json index 14e748a027f..f4eccc8d1f8 100644 --- a/advisories/github-reviewed/2018/06/GHSA-rc8h-3fv6-pxv8/GHSA-rc8h-3fv6-pxv8.json +++ b/advisories/github-reviewed/2018/06/GHSA-rc8h-3fv6-pxv8/GHSA-rc8h-3fv6-pxv8.json @@ -8,9 +8,7 @@ ], "summary": "Denial of Service in hapi", "details": "Versions of `hapi` prior to 11.1.3 are affected by a denial of service vulnerability.\n\nThe vulnerability is triggered when certain input is passed into the If-Modified-Since or Last-Modified headers.\n\nThis causes an 'illegal access' exception to be raised, and instead of sending a HTTP 500 error back to the sender, hapi will continue to hold the socket open until timed out (default node timeout is 2 minutes).\n\n\n\n\n\n## Recommendation\n\nUpdate to v11.1.3 or later", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/06/GHSA-vwrf-r5r4-7775/GHSA-vwrf-r5r4-7775.json b/advisories/github-reviewed/2018/06/GHSA-vwrf-r5r4-7775/GHSA-vwrf-r5r4-7775.json index 453b6810dd1..26f58502b1c 100644 --- a/advisories/github-reviewed/2018/06/GHSA-vwrf-r5r4-7775/GHSA-vwrf-r5r4-7775.json +++ b/advisories/github-reviewed/2018/06/GHSA-vwrf-r5r4-7775/GHSA-vwrf-r5r4-7775.json @@ -8,9 +8,7 @@ ], "summary": "Incorrect handling of CORS preflight request headers in hapi", "details": "Versions of `hapi` prior to 11.0.0 implement CORS incorrectly, allowing for configurations that at best return inconsistent headers, and at worst allow cross-origin activities that are expected to be forbidden. \n\nIf the connection has CORS enabled but one route has it off, and the route is not GET, the OPTIONS prefetch request will return the default CORS headers and then the actual request will go through and return no CORS headers. This defeats the purpose of turning CORS on the route.\n\n\n## Recommendation\n\nUpdate to version 11.0.0 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/07/GHSA-hxf5-mg84-pj4m/GHSA-hxf5-mg84-pj4m.json b/advisories/github-reviewed/2018/07/GHSA-hxf5-mg84-pj4m/GHSA-hxf5-mg84-pj4m.json index b05b4ddc54e..669d1c37740 100644 --- a/advisories/github-reviewed/2018/07/GHSA-hxf5-mg84-pj4m/GHSA-hxf5-mg84-pj4m.json +++ b/advisories/github-reviewed/2018/07/GHSA-hxf5-mg84-pj4m/GHSA-hxf5-mg84-pj4m.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:53Z", "published": "2018-07-31T23:03:17Z", "withdrawn": "2020-06-17T15:14:53Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects moment", "details": "Withdrawn, accidental duplicate publish.\n\nThe duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a \"regular expression Denial of Service (ReDoS).\"", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:53Z", diff --git a/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json b/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json index be15513f584..bf7fd678d18 100644 --- a/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json +++ b/advisories/github-reviewed/2018/07/GHSA-v7q8-wvvh-c97p/GHSA-v7q8-wvvh-c97p.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects Zope2", "details": "Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/07/GHSA-wm77-q74p-5763/GHSA-wm77-q74p-5763.json b/advisories/github-reviewed/2018/07/GHSA-wm77-q74p-5763/GHSA-wm77-q74p-5763.json index 28ed1bf7eac..ab4a4bb9a98 100644 --- a/advisories/github-reviewed/2018/07/GHSA-wm77-q74p-5763/GHSA-wm77-q74p-5763.json +++ b/advisories/github-reviewed/2018/07/GHSA-wm77-q74p-5763/GHSA-wm77-q74p-5763.json @@ -3,14 +3,10 @@ "id": "GHSA-wm77-q74p-5763", "modified": "2021-08-09T22:21:02Z", "published": "2018-07-27T17:06:03Z", - "aliases": [ - - ], + "aliases": [], "summary": "Path Traversal in superstatic", "details": "Affected of `superstatic` are vulnerable to path traversal when used on Windows. \n\nAdditionally, it is vulnerable to path traversal on other platforms combined with certain Node.js versions which erroneously normalize `\\\\` to `/` in paths on all platforms (a known example being Node.js v9.9.0).\n\n\n## Recommendation\n\nUpdate to version 5.0.2 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/07/GHSA-wxvm-fh75-mpgr/GHSA-wxvm-fh75-mpgr.json b/advisories/github-reviewed/2018/07/GHSA-wxvm-fh75-mpgr/GHSA-wxvm-fh75-mpgr.json index 5695bbfb085..663600384c0 100644 --- a/advisories/github-reviewed/2018/07/GHSA-wxvm-fh75-mpgr/GHSA-wxvm-fh75-mpgr.json +++ b/advisories/github-reviewed/2018/07/GHSA-wxvm-fh75-mpgr/GHSA-wxvm-fh75-mpgr.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:15:19Z", "published": "2018-07-26T16:24:34Z", "withdrawn": "2020-06-17T15:15:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Critical severity vulnerability that affects dns-sync", "details": "Withdrawn, accidental duplicate publish.\n\nThe dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:19Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-5p9f-55j8-922m/GHSA-5p9f-55j8-922m.json b/advisories/github-reviewed/2018/08/GHSA-5p9f-55j8-922m/GHSA-5p9f-55j8-922m.json index 7e27c26ce1d..690def66b09 100644 --- a/advisories/github-reviewed/2018/08/GHSA-5p9f-55j8-922m/GHSA-5p9f-55j8-922m.json +++ b/advisories/github-reviewed/2018/08/GHSA-5p9f-55j8-922m/GHSA-5p9f-55j8-922m.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:35Z", "published": "2018-08-13T20:49:10Z", "withdrawn": "2020-06-17T15:14:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects doorkeeper", "details": "Withdrawn, accidental duplicate publish.\n\nThe Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:35Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-82x2-g7vr-39wq/GHSA-82x2-g7vr-39wq.json b/advisories/github-reviewed/2018/08/GHSA-82x2-g7vr-39wq/GHSA-82x2-g7vr-39wq.json index 091d64f26b7..3b7677d8592 100644 --- a/advisories/github-reviewed/2018/08/GHSA-82x2-g7vr-39wq/GHSA-82x2-g7vr-39wq.json +++ b/advisories/github-reviewed/2018/08/GHSA-82x2-g7vr-39wq/GHSA-82x2-g7vr-39wq.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:38Z", "published": "2018-08-13T20:48:09Z", "withdrawn": "2020-06-17T15:14:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects web-console", "details": "Withdrawn, accidental duplicate publish.\n\nrequest.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:38Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-8474-rc7c-wrhp/GHSA-8474-rc7c-wrhp.json b/advisories/github-reviewed/2018/08/GHSA-8474-rc7c-wrhp/GHSA-8474-rc7c-wrhp.json index ae7770eeef2..be07757c580 100644 --- a/advisories/github-reviewed/2018/08/GHSA-8474-rc7c-wrhp/GHSA-8474-rc7c-wrhp.json +++ b/advisories/github-reviewed/2018/08/GHSA-8474-rc7c-wrhp/GHSA-8474-rc7c-wrhp.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:40Z", "published": "2018-08-08T22:29:10Z", "withdrawn": "2020-06-17T15:14:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects safemode", "details": "Withdrawn, accidental duplicate publish.\n\nThe safemode rubygem, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:40Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-9wcm-rrvh-qjc8/GHSA-9wcm-rrvh-qjc8.json b/advisories/github-reviewed/2018/08/GHSA-9wcm-rrvh-qjc8/GHSA-9wcm-rrvh-qjc8.json index c9a6b5e8c96..905629ba0c7 100644 --- a/advisories/github-reviewed/2018/08/GHSA-9wcm-rrvh-qjc8/GHSA-9wcm-rrvh-qjc8.json +++ b/advisories/github-reviewed/2018/08/GHSA-9wcm-rrvh-qjc8/GHSA-9wcm-rrvh-qjc8.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:43Z", "published": "2018-08-15T20:03:53Z", "withdrawn": "2020-06-17T15:14:43Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects colorscore", "details": "Withdrawn, accidental duplicate publish.\n\nThe initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:43Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json b/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json index e0b2ed6157b..ee0c46d292b 100644 --- a/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json +++ b/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:48Z", "published": "2018-08-21T19:03:17Z", "withdrawn": "2020-06-17T15:14:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects activerecord", "details": "Withdrawn, accidental duplicate publish.\n\nactiverecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -63,9 +59,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:48Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-hx46-vwmx-wx95/GHSA-hx46-vwmx-wx95.json b/advisories/github-reviewed/2018/08/GHSA-hx46-vwmx-wx95/GHSA-hx46-vwmx-wx95.json index b7d36c4f618..8365f4ef794 100644 --- a/advisories/github-reviewed/2018/08/GHSA-hx46-vwmx-wx95/GHSA-hx46-vwmx-wx95.json +++ b/advisories/github-reviewed/2018/08/GHSA-hx46-vwmx-wx95/GHSA-hx46-vwmx-wx95.json @@ -4,14 +4,10 @@ "modified": "2021-12-02T23:14:01Z", "published": "2018-08-13T20:48:25Z", "withdrawn": "2020-06-17T15:14:51Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects actionpack", "details": "Withdrawn, accidental duplicate publish.\n\nAction Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -91,9 +87,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:51Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-phmw-pv3f-vvx7/GHSA-phmw-pv3f-vvx7.json b/advisories/github-reviewed/2018/08/GHSA-phmw-pv3f-vvx7/GHSA-phmw-pv3f-vvx7.json index 084d326ba1b..27486dca7f4 100644 --- a/advisories/github-reviewed/2018/08/GHSA-phmw-pv3f-vvx7/GHSA-phmw-pv3f-vvx7.json +++ b/advisories/github-reviewed/2018/08/GHSA-phmw-pv3f-vvx7/GHSA-phmw-pv3f-vvx7.json @@ -4,14 +4,10 @@ "modified": "2021-12-02T23:09:12Z", "published": "2018-08-13T20:47:44Z", "withdrawn": "2020-06-17T15:14:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects paperclip", "details": "Withdrawn, accidental duplicate publish.\n\nThe thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:58Z", diff --git a/advisories/github-reviewed/2018/08/GHSA-w655-w578-99pq/GHSA-w655-w578-99pq.json b/advisories/github-reviewed/2018/08/GHSA-w655-w578-99pq/GHSA-w655-w578-99pq.json index b22c86c04e6..6214f5e3006 100644 --- a/advisories/github-reviewed/2018/08/GHSA-w655-w578-99pq/GHSA-w655-w578-99pq.json +++ b/advisories/github-reviewed/2018/08/GHSA-w655-w578-99pq/GHSA-w655-w578-99pq.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:15:17Z", "published": "2018-08-21T17:09:08Z", "withdrawn": "2020-06-17T15:15:17Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects espeak-ruby", "details": "Withdrawn, accidental duplicate publish.\n\nThe espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, save, bytes or bytes_wav method in lib/espeak/speech.rb.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:17Z", diff --git a/advisories/github-reviewed/2018/09/GHSA-m53f-rhq8-q6hf/GHSA-m53f-rhq8-q6hf.json b/advisories/github-reviewed/2018/09/GHSA-m53f-rhq8-q6hf/GHSA-m53f-rhq8-q6hf.json index fcfe458bca7..30e5d8993fb 100644 --- a/advisories/github-reviewed/2018/09/GHSA-m53f-rhq8-q6hf/GHSA-m53f-rhq8-q6hf.json +++ b/advisories/github-reviewed/2018/09/GHSA-m53f-rhq8-q6hf/GHSA-m53f-rhq8-q6hf.json @@ -4,14 +4,10 @@ "modified": "2021-12-03T14:21:39Z", "published": "2018-09-17T21:55:03Z", "withdrawn": "2020-06-17T15:14:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects actionpack", "details": "Withdrawn, accidental duplicate publish.\n\nactionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -91,9 +87,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:56Z", diff --git a/advisories/github-reviewed/2018/09/GHSA-qc8j-m8j3-rjq6/GHSA-qc8j-m8j3-rjq6.json b/advisories/github-reviewed/2018/09/GHSA-qc8j-m8j3-rjq6/GHSA-qc8j-m8j3-rjq6.json index ce341112d4a..1e8d379c07d 100644 --- a/advisories/github-reviewed/2018/09/GHSA-qc8j-m8j3-rjq6/GHSA-qc8j-m8j3-rjq6.json +++ b/advisories/github-reviewed/2018/09/GHSA-qc8j-m8j3-rjq6/GHSA-qc8j-m8j3-rjq6.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:15:01Z", "published": "2018-09-17T21:57:58Z", "withdrawn": "2020-06-17T15:15:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects rails-html-sanitizer", "details": "Withdrawn, accidental duplicate publish.\n\nCross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:01Z", diff --git a/advisories/github-reviewed/2018/09/GHSA-qf5x-qgx7-437h/GHSA-qf5x-qgx7-437h.json b/advisories/github-reviewed/2018/09/GHSA-qf5x-qgx7-437h/GHSA-qf5x-qgx7-437h.json index 6c65b738d65..fc3ebc2fcc0 100644 --- a/advisories/github-reviewed/2018/09/GHSA-qf5x-qgx7-437h/GHSA-qf5x-qgx7-437h.json +++ b/advisories/github-reviewed/2018/09/GHSA-qf5x-qgx7-437h/GHSA-qf5x-qgx7-437h.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:15:04Z", "published": "2018-09-17T21:54:11Z", "withdrawn": "2020-06-17T15:15:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects actionpack", "details": "Withdrawn, accidental duplicate publish.\n\nDirectory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -85,9 +81,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:04Z", diff --git a/advisories/github-reviewed/2018/09/GHSA-vwfg-qj3r-6v3r/GHSA-vwfg-qj3r-6v3r.json b/advisories/github-reviewed/2018/09/GHSA-vwfg-qj3r-6v3r/GHSA-vwfg-qj3r-6v3r.json index c5ae2499627..2b70421b393 100644 --- a/advisories/github-reviewed/2018/09/GHSA-vwfg-qj3r-6v3r/GHSA-vwfg-qj3r-6v3r.json +++ b/advisories/github-reviewed/2018/09/GHSA-vwfg-qj3r-6v3r/GHSA-vwfg-qj3r-6v3r.json @@ -4,14 +4,10 @@ "modified": "2021-12-03T14:24:02Z", "published": "2018-09-17T21:57:47Z", "withdrawn": "2020-06-17T15:15:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects actionpack", "details": "Withdrawn, accidental duplicate publish.\n\nThe http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -91,9 +87,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:11Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-2x83-r56g-cv47/GHSA-2x83-r56g-cv47.json b/advisories/github-reviewed/2018/10/GHSA-2x83-r56g-cv47/GHSA-2x83-r56g-cv47.json index 8ea22af41bb..1b81f581ec5 100644 --- a/advisories/github-reviewed/2018/10/GHSA-2x83-r56g-cv47/GHSA-2x83-r56g-cv47.json +++ b/advisories/github-reviewed/2018/10/GHSA-2x83-r56g-cv47/GHSA-2x83-r56g-cv47.json @@ -8,9 +8,7 @@ ], "summary": "Improper certificate validation in org.apache.httpcomponents:httpclient", "details": "http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-45vg-2v73-vm62/GHSA-45vg-2v73-vm62.json b/advisories/github-reviewed/2018/10/GHSA-45vg-2v73-vm62/GHSA-45vg-2v73-vm62.json index 45d7fca446c..b7560097f2b 100644 --- a/advisories/github-reviewed/2018/10/GHSA-45vg-2v73-vm62/GHSA-45vg-2v73-vm62.json +++ b/advisories/github-reviewed/2018/10/GHSA-45vg-2v73-vm62/GHSA-45vg-2v73-vm62.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects org.springframework:spring-core", "details": "The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:57:30Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-8crv-49fr-2h6j/GHSA-8crv-49fr-2h6j.json b/advisories/github-reviewed/2018/10/GHSA-8crv-49fr-2h6j/GHSA-8crv-49fr-2h6j.json index a66aa4cf5c1..3eb34f559a4 100644 --- a/advisories/github-reviewed/2018/10/GHSA-8crv-49fr-2h6j/GHSA-8crv-49fr-2h6j.json +++ b/advisories/github-reviewed/2018/10/GHSA-8crv-49fr-2h6j/GHSA-8crv-49fr-2h6j.json @@ -93,9 +93,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:25:18Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-9gcm-f4x3-8jpw/GHSA-9gcm-f4x3-8jpw.json b/advisories/github-reviewed/2018/10/GHSA-9gcm-f4x3-8jpw/GHSA-9gcm-f4x3-8jpw.json index 3e72eeb9fdb..1003366de01 100644 --- a/advisories/github-reviewed/2018/10/GHSA-9gcm-f4x3-8jpw/GHSA-9gcm-f4x3-8jpw.json +++ b/advisories/github-reviewed/2018/10/GHSA-9gcm-f4x3-8jpw/GHSA-9gcm-f4x3-8jpw.json @@ -137,9 +137,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:28:30Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-g6f4-j6c2-w3p3/GHSA-g6f4-j6c2-w3p3.json b/advisories/github-reviewed/2018/10/GHSA-g6f4-j6c2-w3p3/GHSA-g6f4-j6c2-w3p3.json index 9551bf5cc79..977e7a84384 100644 --- a/advisories/github-reviewed/2018/10/GHSA-g6f4-j6c2-w3p3/GHSA-g6f4-j6c2-w3p3.json +++ b/advisories/github-reviewed/2018/10/GHSA-g6f4-j6c2-w3p3/GHSA-g6f4-j6c2-w3p3.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:46Z", "published": "2018-10-09T00:39:43Z", "withdrawn": "2020-06-17T15:14:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "High severity vulnerability that affects uglify-js", "details": "Withdrawn, accidental duplicate publish.\n\nThe uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:46Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-r4x3-g983-9g48/GHSA-r4x3-g983-9g48.json b/advisories/github-reviewed/2018/10/GHSA-r4x3-g983-9g48/GHSA-r4x3-g983-9g48.json index 6b58cf0d764..3066dce2626 100644 --- a/advisories/github-reviewed/2018/10/GHSA-r4x3-g983-9g48/GHSA-r4x3-g983-9g48.json +++ b/advisories/github-reviewed/2018/10/GHSA-r4x3-g983-9g48/GHSA-r4x3-g983-9g48.json @@ -4,14 +4,10 @@ "modified": "2021-12-03T14:21:10Z", "published": "2018-10-10T17:29:34Z", "withdrawn": "2020-06-17T16:30:54Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects sprockets", "details": "Withdrawn, accidental duplicate publish.\n\nMultiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -237,9 +233,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T16:30:54Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-r97x-3g8f-gx3m/GHSA-r97x-3g8f-gx3m.json b/advisories/github-reviewed/2018/10/GHSA-r97x-3g8f-gx3m/GHSA-r97x-3g8f-gx3m.json index 72ea0a9cfab..2a0991df851 100644 --- a/advisories/github-reviewed/2018/10/GHSA-r97x-3g8f-gx3m/GHSA-r97x-3g8f-gx3m.json +++ b/advisories/github-reviewed/2018/10/GHSA-r97x-3g8f-gx3m/GHSA-r97x-3g8f-gx3m.json @@ -89,9 +89,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:54:10Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-r9ch-m4fh-fc7q/GHSA-r9ch-m4fh-fc7q.json b/advisories/github-reviewed/2018/10/GHSA-r9ch-m4fh-fc7q/GHSA-r9ch-m4fh-fc7q.json index 4eb3b93f8ff..e30409a6f75 100644 --- a/advisories/github-reviewed/2018/10/GHSA-r9ch-m4fh-fc7q/GHSA-r9ch-m4fh-fc7q.json +++ b/advisories/github-reviewed/2018/10/GHSA-r9ch-m4fh-fc7q/GHSA-r9ch-m4fh-fc7q.json @@ -97,9 +97,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:54:15Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-rr3c-f55v-qhv5/GHSA-rr3c-f55v-qhv5.json b/advisories/github-reviewed/2018/10/GHSA-rr3c-f55v-qhv5/GHSA-rr3c-f55v-qhv5.json index f1bc3e67533..c6cceb084c2 100644 --- a/advisories/github-reviewed/2018/10/GHSA-rr3c-f55v-qhv5/GHSA-rr3c-f55v-qhv5.json +++ b/advisories/github-reviewed/2018/10/GHSA-rr3c-f55v-qhv5/GHSA-rr3c-f55v-qhv5.json @@ -62,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:55:37Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-rrvx-pwf8-p59p/GHSA-rrvx-pwf8-p59p.json b/advisories/github-reviewed/2018/10/GHSA-rrvx-pwf8-p59p/GHSA-rrvx-pwf8-p59p.json index b49bb016bca..15b529dcc8c 100644 --- a/advisories/github-reviewed/2018/10/GHSA-rrvx-pwf8-p59p/GHSA-rrvx-pwf8-p59p.json +++ b/advisories/github-reviewed/2018/10/GHSA-rrvx-pwf8-p59p/GHSA-rrvx-pwf8-p59p.json @@ -101,9 +101,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:55:50Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-v76m-f5cx-8rg4/GHSA-v76m-f5cx-8rg4.json b/advisories/github-reviewed/2018/10/GHSA-v76m-f5cx-8rg4/GHSA-v76m-f5cx-8rg4.json index 46c69802065..e52ec32de8e 100644 --- a/advisories/github-reviewed/2018/10/GHSA-v76m-f5cx-8rg4/GHSA-v76m-f5cx-8rg4.json +++ b/advisories/github-reviewed/2018/10/GHSA-v76m-f5cx-8rg4/GHSA-v76m-f5cx-8rg4.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects DotNetNuke.Core", "details": "Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-vhxc-8jjq-859j/GHSA-vhxc-8jjq-859j.json b/advisories/github-reviewed/2018/10/GHSA-vhxc-8jjq-859j/GHSA-vhxc-8jjq-859j.json index 06d8a1a3592..61f5865fdb8 100644 --- a/advisories/github-reviewed/2018/10/GHSA-vhxc-8jjq-859j/GHSA-vhxc-8jjq-859j.json +++ b/advisories/github-reviewed/2018/10/GHSA-vhxc-8jjq-859j/GHSA-vhxc-8jjq-859j.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:57:53Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-w3gh-g32m-cvhr/GHSA-w3gh-g32m-cvhr.json b/advisories/github-reviewed/2018/10/GHSA-w3gh-g32m-cvhr/GHSA-w3gh-g32m-cvhr.json index 0c78bab8b52..ff414b01ad6 100644 --- a/advisories/github-reviewed/2018/10/GHSA-w3gh-g32m-cvhr/GHSA-w3gh-g32m-cvhr.json +++ b/advisories/github-reviewed/2018/10/GHSA-w3gh-g32m-cvhr/GHSA-w3gh-g32m-cvhr.json @@ -8,9 +8,7 @@ ], "summary": "High severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3", "details": "Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-whw7-h25v-9qvx/GHSA-whw7-h25v-9qvx.json b/advisories/github-reviewed/2018/10/GHSA-whw7-h25v-9qvx/GHSA-whw7-h25v-9qvx.json index 8670f29719d..ea9c1958ae7 100644 --- a/advisories/github-reviewed/2018/10/GHSA-whw7-h25v-9qvx/GHSA-whw7-h25v-9qvx.json +++ b/advisories/github-reviewed/2018/10/GHSA-whw7-h25v-9qvx/GHSA-whw7-h25v-9qvx.json @@ -8,9 +8,7 @@ ], "summary": "Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, and org.apache.cxf.fediz:fediz-spring2", "details": "Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-x825-rjww-2245/GHSA-x825-rjww-2245.json b/advisories/github-reviewed/2018/10/GHSA-x825-rjww-2245/GHSA-x825-rjww-2245.json index b15c3b25fda..e6e1af47a32 100644 --- a/advisories/github-reviewed/2018/10/GHSA-x825-rjww-2245/GHSA-x825-rjww-2245.json +++ b/advisories/github-reviewed/2018/10/GHSA-x825-rjww-2245/GHSA-x825-rjww-2245.json @@ -80,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T22:02:37Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-x8f7-h444-97w4/GHSA-x8f7-h444-97w4.json b/advisories/github-reviewed/2018/10/GHSA-x8f7-h444-97w4/GHSA-x8f7-h444-97w4.json index f842d6ff000..c727d8ad905 100644 --- a/advisories/github-reviewed/2018/10/GHSA-x8f7-h444-97w4/GHSA-x8f7-h444-97w4.json +++ b/advisories/github-reviewed/2018/10/GHSA-x8f7-h444-97w4/GHSA-x8f7-h444-97w4.json @@ -66,9 +66,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-06-16T22:02:45Z", diff --git a/advisories/github-reviewed/2018/10/GHSA-xpwp-rq3x-x6v7/GHSA-xpwp-rq3x-x6v7.json b/advisories/github-reviewed/2018/10/GHSA-xpwp-rq3x-x6v7/GHSA-xpwp-rq3x-x6v7.json index b380e06b2be..7d4351f3edd 100644 --- a/advisories/github-reviewed/2018/10/GHSA-xpwp-rq3x-x6v7/GHSA-xpwp-rq3x-x6v7.json +++ b/advisories/github-reviewed/2018/10/GHSA-xpwp-rq3x-x6v7/GHSA-xpwp-rq3x-x6v7.json @@ -8,9 +8,7 @@ ], "summary": "Critical severity vulnerability that affects recurly-api-client", "details": "The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of \"Uri.EscapeUriString\" that could result in compromise of API keys or other critical resources.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/10/GHSA-xv6v-72hh-g6g2/GHSA-xv6v-72hh-g6g2.json b/advisories/github-reviewed/2018/10/GHSA-xv6v-72hh-g6g2/GHSA-xv6v-72hh-g6g2.json index f8ea5ddb9d8..3bbec33e021 100644 --- a/advisories/github-reviewed/2018/10/GHSA-xv6v-72hh-g6g2/GHSA-xv6v-72hh-g6g2.json +++ b/advisories/github-reviewed/2018/10/GHSA-xv6v-72hh-g6g2/GHSA-xv6v-72hh-g6g2.json @@ -9,9 +9,7 @@ ], "summary": "Moderate severity vulnerability that affects org.owasp.antisamy:antisamy", "details": "OWASP OWASP ANTISAMY version 1.5.7 and earlier contains a Cross Site Scripting (XSS) vulnerability in AntiSamy.scan() - for both SAX & DOM that can result in Cross Site Scripting.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -44,9 +42,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T22:04:31Z", diff --git a/advisories/github-reviewed/2018/11/GHSA-rrfq-g5fq-fc9c/GHSA-rrfq-g5fq-fc9c.json b/advisories/github-reviewed/2018/11/GHSA-rrfq-g5fq-fc9c/GHSA-rrfq-g5fq-fc9c.json index 7a70ff1f6f8..a01dccc3047 100644 --- a/advisories/github-reviewed/2018/11/GHSA-rrfq-g5fq-fc9c/GHSA-rrfq-g5fq-fc9c.json +++ b/advisories/github-reviewed/2018/11/GHSA-rrfq-g5fq-fc9c/GHSA-rrfq-g5fq-fc9c.json @@ -73,9 +73,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:55:42Z", diff --git a/advisories/github-reviewed/2018/11/GHSA-vgrx-w6rg-8fqf/GHSA-vgrx-w6rg-8fqf.json b/advisories/github-reviewed/2018/11/GHSA-vgrx-w6rg-8fqf/GHSA-vgrx-w6rg-8fqf.json index ace4cbbb942..88ea490221a 100644 --- a/advisories/github-reviewed/2018/11/GHSA-vgrx-w6rg-8fqf/GHSA-vgrx-w6rg-8fqf.json +++ b/advisories/github-reviewed/2018/11/GHSA-vgrx-w6rg-8fqf/GHSA-vgrx-w6rg-8fqf.json @@ -8,9 +8,7 @@ ], "summary": "Forgeable Public/Private Tokens in jwt-simple", "details": "Affected versions of the `jwt-simple` package allow users to select what algorithm the server will use to verify a provided JWT. A malicious actor can use this behaviour to arbitrarily modify the contents of a JWT while still passing verification. For the common use case of the JWT, the end result is a complete authentication bypass with minimal effort.\n\n\n\n## Recommendation\n\nUpdate to version 0.3.1 or later.\n\nAdditionally, be sure to always specify an algorithm in calls to `.decode()`.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/11/GHSA-w4x9-4f5x-8jj8/GHSA-w4x9-4f5x-8jj8.json b/advisories/github-reviewed/2018/11/GHSA-w4x9-4f5x-8jj8/GHSA-w4x9-4f5x-8jj8.json index 942fd6a7579..6b07be20a16 100644 --- a/advisories/github-reviewed/2018/11/GHSA-w4x9-4f5x-8jj8/GHSA-w4x9-4f5x-8jj8.json +++ b/advisories/github-reviewed/2018/11/GHSA-w4x9-4f5x-8jj8/GHSA-w4x9-4f5x-8jj8.json @@ -8,9 +8,7 @@ ], "summary": "Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service", "details": "Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2018/12/GHSA-rqj9-cq6j-958r/GHSA-rqj9-cq6j-958r.json b/advisories/github-reviewed/2018/12/GHSA-rqj9-cq6j-958r/GHSA-rqj9-cq6j-958r.json index 7955dd440c4..0512aa31d72 100644 --- a/advisories/github-reviewed/2018/12/GHSA-rqj9-cq6j-958r/GHSA-rqj9-cq6j-958r.json +++ b/advisories/github-reviewed/2018/12/GHSA-rqj9-cq6j-958r/GHSA-rqj9-cq6j-958r.json @@ -57,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:55:32Z", diff --git a/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json b/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json index 80a242fac59..94d74951fd3 100644 --- a/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json +++ b/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json @@ -8,9 +8,7 @@ ], "summary": "Commons FileUpload Denial of service vulnerability", "details": "MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-32f7-cmr3-vpjv/GHSA-32f7-cmr3-vpjv.json b/advisories/github-reviewed/2019/02/GHSA-32f7-cmr3-vpjv/GHSA-32f7-cmr3-vpjv.json index 9979cbdaf1a..59bd924d957 100644 --- a/advisories/github-reviewed/2019/02/GHSA-32f7-cmr3-vpjv/GHSA-32f7-cmr3-vpjv.json +++ b/advisories/github-reviewed/2019/02/GHSA-32f7-cmr3-vpjv/GHSA-32f7-cmr3-vpjv.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:14:32Z", "published": "2019-02-07T18:18:30Z", "withdrawn": "2020-06-17T15:14:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects aioxmpp", "details": "**Withdrawn:** Duplicate of GHSA-6m9g-jr8c-cqw3", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:14:32Z", diff --git a/advisories/github-reviewed/2019/02/GHSA-rhvc-x32h-5526/GHSA-rhvc-x32h-5526.json b/advisories/github-reviewed/2019/02/GHSA-rhvc-x32h-5526/GHSA-rhvc-x32h-5526.json index 23f9c7a25a5..c07ae4db0b8 100644 --- a/advisories/github-reviewed/2019/02/GHSA-rhvc-x32h-5526/GHSA-rhvc-x32h-5526.json +++ b/advisories/github-reviewed/2019/02/GHSA-rhvc-x32h-5526/GHSA-rhvc-x32h-5526.json @@ -8,9 +8,7 @@ ], "summary": "No CSRF Validation in droppy", "details": "Affected versions of `droppy` are vulnerable to cross-site socket forgery. The package does not perform verification for cross-domain websocket requests, and as a result, an attacker can create a web page that opens up a websocket connection on behalf of the user visiting the page. The attacker can then perform any action that the target user could, including adding a new admin account under their control, or deleting others.\n\n\n## Recommendation\n\nUpdate to version 3.5.0 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-rj38-87f3-93p6/GHSA-rj38-87f3-93p6.json b/advisories/github-reviewed/2019/02/GHSA-rj38-87f3-93p6/GHSA-rj38-87f3-93p6.json index b96eaf3d8fa..d6225d8c4d7 100644 --- a/advisories/github-reviewed/2019/02/GHSA-rj38-87f3-93p6/GHSA-rj38-87f3-93p6.json +++ b/advisories/github-reviewed/2019/02/GHSA-rj38-87f3-93p6/GHSA-rj38-87f3-93p6.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in limbus-buildgen", "details": "Affected versions of `limbus-buildgen` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `limbus-buildgen`.\n\n\n## Recommendation\n\nUpdate to version 0.1.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-rqwh-c535-j9hw/GHSA-rqwh-c535-j9hw.json b/advisories/github-reviewed/2019/02/GHSA-rqwh-c535-j9hw/GHSA-rqwh-c535-j9hw.json index 80ffa365217..f4eef553dc0 100644 --- a/advisories/github-reviewed/2019/02/GHSA-rqwh-c535-j9hw/GHSA-rqwh-c535-j9hw.json +++ b/advisories/github-reviewed/2019/02/GHSA-rqwh-c535-j9hw/GHSA-rqwh-c535-j9hw.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in js-given", "details": "Affected versions of `js-given` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `js-given`.\n\n\n## Recommendation\n\nUpdate to version 0.0.18 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-rwvj-jgc4-fqq5/GHSA-rwvj-jgc4-fqq5.json b/advisories/github-reviewed/2019/02/GHSA-rwvj-jgc4-fqq5/GHSA-rwvj-jgc4-fqq5.json index 0ffb119020a..07fd71ef8bc 100644 --- a/advisories/github-reviewed/2019/02/GHSA-rwvj-jgc4-fqq5/GHSA-rwvj-jgc4-fqq5.json +++ b/advisories/github-reviewed/2019/02/GHSA-rwvj-jgc4-fqq5/GHSA-rwvj-jgc4-fqq5.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in cobalt-cli", "details": "Affected versions of `cobalt-cli` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `cobalt-cli`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-v5v3-8jqf-vg27/GHSA-v5v3-8jqf-vg27.json b/advisories/github-reviewed/2019/02/GHSA-v5v3-8jqf-vg27/GHSA-v5v3-8jqf-vg27.json index ec2dc1fa71a..1b58caaf601 100644 --- a/advisories/github-reviewed/2019/02/GHSA-v5v3-8jqf-vg27/GHSA-v5v3-8jqf-vg27.json +++ b/advisories/github-reviewed/2019/02/GHSA-v5v3-8jqf-vg27/GHSA-v5v3-8jqf-vg27.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in aerospike", "details": "Affected versions of `aerospike` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `aerospike`.\n\n\n## Recommendation\n\nUpdate to version 2.4.2 or later", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-vcph-57hv-89c4/GHSA-vcph-57hv-89c4.json b/advisories/github-reviewed/2019/02/GHSA-vcph-57hv-89c4/GHSA-vcph-57hv-89c4.json index 189a7a4f5c9..d538e73018e 100644 --- a/advisories/github-reviewed/2019/02/GHSA-vcph-57hv-89c4/GHSA-vcph-57hv-89c4.json +++ b/advisories/github-reviewed/2019/02/GHSA-vcph-57hv-89c4/GHSA-vcph-57hv-89c4.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in serc.js", "details": "Affected versions of `serc.js` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `serc.js`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-vvwp-3f54-xc39/GHSA-vvwp-3f54-xc39.json b/advisories/github-reviewed/2019/02/GHSA-vvwp-3f54-xc39/GHSA-vvwp-3f54-xc39.json index 24e467bdb95..9dee715d3ad 100644 --- a/advisories/github-reviewed/2019/02/GHSA-vvwp-3f54-xc39/GHSA-vvwp-3f54-xc39.json +++ b/advisories/github-reviewed/2019/02/GHSA-vvwp-3f54-xc39/GHSA-vvwp-3f54-xc39.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in broccoli-closure", "details": "Affected versions of `broccoli-closure` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `broccoli-closure`.\n\n\n## Recommendation\n\nUpdate to version 1.3.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-w364-8vfv-gvf5/GHSA-w364-8vfv-gvf5.json b/advisories/github-reviewed/2019/02/GHSA-w364-8vfv-gvf5/GHSA-w364-8vfv-gvf5.json index e349f01e01e..82a0051fc1c 100644 --- a/advisories/github-reviewed/2019/02/GHSA-w364-8vfv-gvf5/GHSA-w364-8vfv-gvf5.json +++ b/advisories/github-reviewed/2019/02/GHSA-w364-8vfv-gvf5/GHSA-w364-8vfv-gvf5.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in phantomjs-cheniu", "details": "Affected versions of `phantomjs-cheniu` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `phantomjs-cheniu`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nAs this package is just a fork of Medium's [`phantomjs-prebuilt`](https://github.com/Medium/phantomjs) package, the best mitigation is currently to install the `Medium` version of [`phantomjs-prebuilt`](https://github.com/Medium/phantomjs). This can be done via the following command:\n```\nnpm i phantomjs-prebuilt\n```", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-w9mf-24h3-9wxf/GHSA-w9mf-24h3-9wxf.json b/advisories/github-reviewed/2019/02/GHSA-w9mf-24h3-9wxf/GHSA-w9mf-24h3-9wxf.json index 7e9facfe8be..283e5244a10 100644 --- a/advisories/github-reviewed/2019/02/GHSA-w9mf-24h3-9wxf/GHSA-w9mf-24h3-9wxf.json +++ b/advisories/github-reviewed/2019/02/GHSA-w9mf-24h3-9wxf/GHSA-w9mf-24h3-9wxf.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in windows-iedriver", "details": "Affected versions of `windows-iedriver` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `windows-iedriver`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-wg5r-c793-w5w2/GHSA-wg5r-c793-w5w2.json b/advisories/github-reviewed/2019/02/GHSA-wg5r-c793-w5w2/GHSA-wg5r-c793-w5w2.json index 9111d40e033..a90158e3286 100644 --- a/advisories/github-reviewed/2019/02/GHSA-wg5r-c793-w5w2/GHSA-wg5r-c793-w5w2.json +++ b/advisories/github-reviewed/2019/02/GHSA-wg5r-c793-w5w2/GHSA-wg5r-c793-w5w2.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in mystem-wrapper", "details": "Affected versions of `mystem-wrapper` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `mystem-wrapper`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-wr2c-ppj9-f2fv/GHSA-wr2c-ppj9-f2fv.json b/advisories/github-reviewed/2019/02/GHSA-wr2c-ppj9-f2fv/GHSA-wr2c-ppj9-f2fv.json index a23f2710427..fbae9a66937 100644 --- a/advisories/github-reviewed/2019/02/GHSA-wr2c-ppj9-f2fv/GHSA-wr2c-ppj9-f2fv.json +++ b/advisories/github-reviewed/2019/02/GHSA-wr2c-ppj9-f2fv/GHSA-wr2c-ppj9-f2fv.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in webdrvr", "details": "Affected versions of `webdrvr` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `webdrvr`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-x2jc-pwfj-h9p3/GHSA-x2jc-pwfj-h9p3.json b/advisories/github-reviewed/2019/02/GHSA-x2jc-pwfj-h9p3/GHSA-x2jc-pwfj-h9p3.json index cbab87bea0b..3bdb7578059 100644 --- a/advisories/github-reviewed/2019/02/GHSA-x2jc-pwfj-h9p3/GHSA-x2jc-pwfj-h9p3.json +++ b/advisories/github-reviewed/2019/02/GHSA-x2jc-pwfj-h9p3/GHSA-x2jc-pwfj-h9p3.json @@ -8,9 +8,7 @@ ], "summary": "SQL Injection in sequelize", "details": "Affected versions of `sequelize` use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.\n\n\n## Recommendation\n\nUpdate to version 1.7.0-alpha3 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-x3j8-g4v9-67jq/GHSA-x3j8-g4v9-67jq.json b/advisories/github-reviewed/2019/02/GHSA-x3j8-g4v9-67jq/GHSA-x3j8-g4v9-67jq.json index a1b531f71cf..227f76982fd 100644 --- a/advisories/github-reviewed/2019/02/GHSA-x3j8-g4v9-67jq/GHSA-x3j8-g4v9-67jq.json +++ b/advisories/github-reviewed/2019/02/GHSA-x3j8-g4v9-67jq/GHSA-x3j8-g4v9-67jq.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in pennyworth", "details": "Affected versions of `pennyworth` insecurely downloads resources over HTTP. \n\nIn scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised your network or those who have privileged access to your ISP, such as Nation State Actors or Rogue ISP Employees.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-x5ph-4fr4-g7fw/GHSA-x5ph-4fr4-g7fw.json b/advisories/github-reviewed/2019/02/GHSA-x5ph-4fr4-g7fw/GHSA-x5ph-4fr4-g7fw.json index 87cf75fd39b..f36e8bf1fa8 100644 --- a/advisories/github-reviewed/2019/02/GHSA-x5ph-4fr4-g7fw/GHSA-x5ph-4fr4-g7fw.json +++ b/advisories/github-reviewed/2019/02/GHSA-x5ph-4fr4-g7fw/GHSA-x5ph-4fr4-g7fw.json @@ -8,9 +8,7 @@ ], "summary": "Downloads Resources over HTTP in galenframework-cli", "details": "Affected versions of `galenframework-cli` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `galenframework-cli`.\n\n\n## Recommendation\n\nUpdate to version 2.3.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/02/GHSA-xg5r-8j97-2wrj/GHSA-xg5r-8j97-2wrj.json b/advisories/github-reviewed/2019/02/GHSA-xg5r-8j97-2wrj/GHSA-xg5r-8j97-2wrj.json index 9bfe3ae03c3..f88db3a2c10 100644 --- a/advisories/github-reviewed/2019/02/GHSA-xg5r-8j97-2wrj/GHSA-xg5r-8j97-2wrj.json +++ b/advisories/github-reviewed/2019/02/GHSA-xg5r-8j97-2wrj/GHSA-xg5r-8j97-2wrj.json @@ -8,9 +8,7 @@ ], "summary": "Directory Traversal in restafary", "details": "Affected versions of `restafary` are susceptible to a directory traversal vulnerability when a root path is specified in the configuration.\n\n\nProof of Concept\n\n```\ncurl -i -s -k -X 'GET' -H 'Authorization: Basic YWRtaW46cGFzc3dvcmQ=' 'http://localhost:8000/api/v1/fs/..%2f..%2fetc/passwd'\n```\n\n\n## Recommendation\n\nUpdate to version 1.6.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2019/04/GHSA-r53m-pfr5-7v87/GHSA-r53m-pfr5-7v87.json b/advisories/github-reviewed/2019/04/GHSA-r53m-pfr5-7v87/GHSA-r53m-pfr5-7v87.json index a3a962e0505..60818018edd 100644 --- a/advisories/github-reviewed/2019/04/GHSA-r53m-pfr5-7v87/GHSA-r53m-pfr5-7v87.json +++ b/advisories/github-reviewed/2019/04/GHSA-r53m-pfr5-7v87/GHSA-r53m-pfr5-7v87.json @@ -4,14 +4,10 @@ "modified": "2020-06-17T15:15:06Z", "published": "2019-04-18T14:50:19Z", "withdrawn": "2020-06-17T15:15:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Moderate severity vulnerability that affects org.apache.tomcat.embed:tomcat-embed-core", "details": "**Withdrawn:** Duplicate of GHSA-qcxh-w3j9-58qr", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -66,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-17T15:15:06Z", diff --git a/advisories/github-reviewed/2019/09/GHSA-v6cj-r88p-92rm/GHSA-v6cj-r88p-92rm.json b/advisories/github-reviewed/2019/09/GHSA-v6cj-r88p-92rm/GHSA-v6cj-r88p-92rm.json index ec32c6a4674..56d6e6d581f 100644 --- a/advisories/github-reviewed/2019/09/GHSA-v6cj-r88p-92rm/GHSA-v6cj-r88p-92rm.json +++ b/advisories/github-reviewed/2019/09/GHSA-v6cj-r88p-92rm/GHSA-v6cj-r88p-92rm.json @@ -3,9 +3,7 @@ "id": "GHSA-v6cj-r88p-92rm", "modified": "2021-09-20T15:40:54Z", "published": "2019-09-30T19:31:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "Buffer Overflow in centra", "details": "## Denial of Service\n\n### Impact\n\nAffected Centra versions will, when not in stream mode, buffer responses to requests into memory with no size limit. This issue affects anyone requesting content from untrusted sources.\n\n### Patches\n\nVersion 2.4.0 resolves the issue by limiting the size of buffered response body.\n\n### Workarounds\n\nAttempting workarounds isn't recommended. Updating is preferred.\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [ethanent/centra](https://github.com/ethanent/centra).\n\n", "severity": [ diff --git a/advisories/github-reviewed/2020/06/GHSA-6r3c-8xf3-ggrr/GHSA-6r3c-8xf3-ggrr.json b/advisories/github-reviewed/2020/06/GHSA-6r3c-8xf3-ggrr/GHSA-6r3c-8xf3-ggrr.json index cc609742464..7b38cc0de41 100644 --- a/advisories/github-reviewed/2020/06/GHSA-6r3c-8xf3-ggrr/GHSA-6r3c-8xf3-ggrr.json +++ b/advisories/github-reviewed/2020/06/GHSA-6r3c-8xf3-ggrr/GHSA-6r3c-8xf3-ggrr.json @@ -3,14 +3,10 @@ "id": "GHSA-6r3c-8xf3-ggrr", "modified": "2021-09-22T18:37:22Z", "published": "2020-06-24T17:15:26Z", - "aliases": [ - - ], + "aliases": [], "summary": "Directory traversal outside of SENDFILE_ROOT in django-sendfile2", "details": "django-sendfile2 currently relies on the backend to correctly limit file paths to `SENDFILE_ROOT`. This is not the case for the `simple` and `development` backends, it is also not necessarily the case for any of the other backends either (it's just an assumption that was made by the original author).\n\nThis will be fixed in 0.6.0 which is to be released the same day as this advisory is made public.\n\nWhen upgrading, you will need to make sure `SENDFILE_ROOT` is set in your settings module if it wasn't already.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/06/GHSA-9959-6p3m-wxpc/GHSA-9959-6p3m-wxpc.json b/advisories/github-reviewed/2020/06/GHSA-9959-6p3m-wxpc/GHSA-9959-6p3m-wxpc.json index 2bf0d546fb2..98f3ac614f5 100644 --- a/advisories/github-reviewed/2020/06/GHSA-9959-6p3m-wxpc/GHSA-9959-6p3m-wxpc.json +++ b/advisories/github-reviewed/2020/06/GHSA-9959-6p3m-wxpc/GHSA-9959-6p3m-wxpc.json @@ -8,9 +8,7 @@ ], "summary": "Denial of service in Netty", "details": "The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/06/GHSA-g753-jx37-7xwh/GHSA-g753-jx37-7xwh.json b/advisories/github-reviewed/2020/06/GHSA-g753-jx37-7xwh/GHSA-g753-jx37-7xwh.json index b2dce804c70..86d23260099 100644 --- a/advisories/github-reviewed/2020/06/GHSA-g753-jx37-7xwh/GHSA-g753-jx37-7xwh.json +++ b/advisories/github-reviewed/2020/06/GHSA-g753-jx37-7xwh/GHSA-g753-jx37-7xwh.json @@ -3,9 +3,7 @@ "id": "GHSA-g753-jx37-7xwh", "modified": "2021-09-22T18:43:42Z", "published": "2020-06-30T16:05:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "ECDSA signature vulnerability of Minerva timing attack in jsrsasign", "details": "### Impact\nECDSA side-channel attack named [Minerava](https://minerva.crocs.fi.muni.cz/) have been found and it was found that it affects to jsrsasign.\n\nExecution time of thousands signature generation have been observed then EC private key which is scalar value may be recovered since point and scalar multiplication time depends on bits of scalar. In jsrsasign 8.0.13 or later, execution time of EC point and scalar multiplication is almost constant and fixed for the issue.\n\n- Minerva is one of timing attack or side channel attack for EC.\n- If you don't use ECDSA class, you are not affected the vulnerability.\n- The vulnerability is that attacker may guess private key by checking processing time of EC key generation or ECDSA signing.\n- The cause issue is that point multiplication processing time in ECDSA signing is depends on private key value.\n- After 8.0.13, processing time of point multiplication in ECDSA signing have become constant for key value in theory.\n\n### Patches\nUsers using ECDSA signature generation should upgrade to 8.0.13 or later.\n\n### Workarounds\nThere is no workarounds in jsrsasign. Update jsrsasign or use other ECDSA library.\n\n### ACKNOWLEDGEMENT\nThanks to Jan Jancar @J08nY, Petr Svenda and Vladimir Sedlacek of Masaryk University in Czech Republic to find and report this vulnerability.\n\n### References\nhttps://minerva.crocs.fi.muni.cz/\nhttps://www.npmjs.com/advisories/1505\nhttps://github.com/kjur/jsrsasign/issues/411", "severity": [ diff --git a/advisories/github-reviewed/2020/07/GHSA-5x3v-2gxr-59m2/GHSA-5x3v-2gxr-59m2.json b/advisories/github-reviewed/2020/07/GHSA-5x3v-2gxr-59m2/GHSA-5x3v-2gxr-59m2.json index eb57b466898..983b912b1c5 100644 --- a/advisories/github-reviewed/2020/07/GHSA-5x3v-2gxr-59m2/GHSA-5x3v-2gxr-59m2.json +++ b/advisories/github-reviewed/2020/07/GHSA-5x3v-2gxr-59m2/GHSA-5x3v-2gxr-59m2.json @@ -8,9 +8,7 @@ ], "summary": "Directory traversal in Apache RocketMQ", "details": "In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/07/GHSA-wwgf-3xp7-cxj4/GHSA-wwgf-3xp7-cxj4.json b/advisories/github-reviewed/2020/07/GHSA-wwgf-3xp7-cxj4/GHSA-wwgf-3xp7-cxj4.json index 83f59768a64..f1ec91425fb 100644 --- a/advisories/github-reviewed/2020/07/GHSA-wwgf-3xp7-cxj4/GHSA-wwgf-3xp7-cxj4.json +++ b/advisories/github-reviewed/2020/07/GHSA-wwgf-3xp7-cxj4/GHSA-wwgf-3xp7-cxj4.json @@ -3,9 +3,7 @@ "id": "GHSA-wwgf-3xp7-cxj4", "modified": "2021-09-22T20:22:02Z", "published": "2020-07-07T16:33:45Z", - "aliases": [ - - ], + "aliases": [], "summary": "Potentially sensitive data exposure in Symfony Web Socket Bundle", "details": "### Impact\nInside `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::onPublish()`, messages are arbitrarily broadcasted to the related Topic if `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::dispatch()` does not succeed. The `dispatch()` method can be considered to not succeed if (depending on the version of the bundle) the callback defined on a topic route is misconfigured, a `Gos\\Bundle\\WebSocketBundle\\Topic\\TopicInterface` implementation is not found for the callback, a topic which also implements `Gos\\Bundle\\WebSocketBundle\\Topic\\SecuredTopicInterface` rejects the connection, or an Exception is unhandled. This can result in an unintended broadcast to the websocket server potentially with data that should be considered sensitive.\n\n### Patches\nIn 1.10.4, 2.6.1, and 3.3.0, `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::onPublish()` has been changed to no longer broadcast an event's data if `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::dispatch()` fails.\n\n### Workarounds\nUpgrade to 1.10.4, 2.6.1, and 3.3.0\n\nNote, the 1.x branch is considered end of support as of July 1, 2020.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [this repository](https://github.com/GeniusesOfSymfony/WebSocketBundle)", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-9hqj-38j2-5jgm/GHSA-9hqj-38j2-5jgm.json b/advisories/github-reviewed/2020/09/GHSA-9hqj-38j2-5jgm/GHSA-9hqj-38j2-5jgm.json index 5ced890b604..fb25abe7d06 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9hqj-38j2-5jgm/GHSA-9hqj-38j2-5jgm.json +++ b/advisories/github-reviewed/2020/09/GHSA-9hqj-38j2-5jgm/GHSA-9hqj-38j2-5jgm.json @@ -3,14 +3,10 @@ "id": "GHSA-9hqj-38j2-5jgm", "modified": "2020-08-31T18:33:35Z", "published": "2020-09-01T21:19:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in ascii-art", "details": "Versions of `ascii-art` before 1.4.4 are vulnerable to command injection. This is exploitable when user input is passed into the argument of the `ascii-art preview` command. \n\n\nExample Proof of concept:\n`ascii-art preview 'doom\"; touch /tmp/malicious; echo \"'`\n\nGiven that the input is passed on the command line and none of the api methods are vulnerable to this, the likely exploitation vector is when the ascii-art comment is being called programmatically using something like `execFile`.\n\n\n## Recommendation\n\nUpdate to version 1.4.4 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-f5cv-xrv9-r8w7/GHSA-f5cv-xrv9-r8w7.json b/advisories/github-reviewed/2020/09/GHSA-f5cv-xrv9-r8w7/GHSA-f5cv-xrv9-r8w7.json index 61d64672cf8..0358d9543d8 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f5cv-xrv9-r8w7/GHSA-f5cv-xrv9-r8w7.json +++ b/advisories/github-reviewed/2020/09/GHSA-f5cv-xrv9-r8w7/GHSA-f5cv-xrv9-r8w7.json @@ -3,14 +3,10 @@ "id": "GHSA-f5cv-xrv9-r8w7", "modified": "2021-09-24T20:58:36Z", "published": "2020-09-01T21:17:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "NoSQL injection in express-cart", "details": "Versions of `express-cart` before 1.1.8 are vulnerable to NoSQL injection. \n\nThe vulnerability is caused by the lack of user input sanitization in the login handlers. In both cases, the customer login and the admin login, parameters from the JSON body are sent directly into the MongoDB query which allows to insert operators. \n\nThese operators can be used to extract the value of the field blindly in the same manner of a blind SQL injection. In this case, the `$regex` operator is used to guess each character of the token from the start.\n\n\n## Recommendation\n\nUpdate to version 1.1.8 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-xhjx-mfr6-9rr4/GHSA-xhjx-mfr6-9rr4.json b/advisories/github-reviewed/2020/09/GHSA-xhjx-mfr6-9rr4/GHSA-xhjx-mfr6-9rr4.json index d1a9d7ba3db..94dce5859fc 100644 --- a/advisories/github-reviewed/2020/09/GHSA-xhjx-mfr6-9rr4/GHSA-xhjx-mfr6-9rr4.json +++ b/advisories/github-reviewed/2020/09/GHSA-xhjx-mfr6-9rr4/GHSA-xhjx-mfr6-9rr4.json @@ -3,14 +3,10 @@ "id": "GHSA-xhjx-mfr6-9rr4", "modified": "2020-08-31T18:33:52Z", "published": "2020-09-01T21:20:28Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in samsung-remote", "details": "Versions of `samsung-remote` before 1.3.5 are vulnerable to command injection. This vulnerability is exploitable if user input is passed into the `ip` option of the package constructor.\n\n\n## Recommendation\n\nUpdate to version 1.3.5 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/02/GHSA-m56g-3g8v-2rxw/GHSA-m56g-3g8v-2rxw.json b/advisories/github-reviewed/2021/02/GHSA-m56g-3g8v-2rxw/GHSA-m56g-3g8v-2rxw.json index e48fb194835..ee67e1f3308 100644 --- a/advisories/github-reviewed/2021/02/GHSA-m56g-3g8v-2rxw/GHSA-m56g-3g8v-2rxw.json +++ b/advisories/github-reviewed/2021/02/GHSA-m56g-3g8v-2rxw/GHSA-m56g-3g8v-2rxw.json @@ -4,14 +4,10 @@ "modified": "2021-02-11T20:37:00Z", "published": "2021-02-11T20:46:53Z", "withdrawn": "2021-02-11T20:36:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "XSS in Adminer", "details": "**Withdrawn:** Duplicate of GHSA-9pgx-gcph-mpqr.\n\nAdminer before 4.7.9 allows XSS via the history parameter to the default URI.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2022/04/GHSA-cj8x-r9fp-q656/GHSA-cj8x-r9fp-q656.json b/advisories/unreviewed/2022/04/GHSA-cj8x-r9fp-q656/GHSA-cj8x-r9fp-q656.json index 2b45126a628..9c7bc649cb8 100644 --- a/advisories/unreviewed/2022/04/GHSA-cj8x-r9fp-q656/GHSA-cj8x-r9fp-q656.json +++ b/advisories/unreviewed/2022/04/GHSA-cj8x-r9fp-q656/GHSA-cj8x-r9fp-q656.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -95,9 +93,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2263-gvv9-23vp/GHSA-2263-gvv9-23vp.json b/advisories/unreviewed/2022/05/GHSA-2263-gvv9-23vp/GHSA-2263-gvv9-23vp.json index f7105cb751c..df956f13add 100644 --- a/advisories/unreviewed/2022/05/GHSA-2263-gvv9-23vp/GHSA-2263-gvv9-23vp.json +++ b/advisories/unreviewed/2022/05/GHSA-2263-gvv9-23vp/GHSA-2263-gvv9-23vp.json @@ -7,12 +7,8 @@ "CVE-2007-4787" ], "details": "The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2284-5wv4-383m/GHSA-2284-5wv4-383m.json b/advisories/unreviewed/2022/05/GHSA-2284-5wv4-383m/GHSA-2284-5wv4-383m.json index 4a20295866a..c43f601f7b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2284-5wv4-383m/GHSA-2284-5wv4-383m.json +++ b/advisories/unreviewed/2022/05/GHSA-2284-5wv4-383m/GHSA-2284-5wv4-383m.json @@ -7,12 +7,8 @@ "CVE-2007-4726" ], "details": "Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-236p-2rjr-h84v/GHSA-236p-2rjr-h84v.json b/advisories/unreviewed/2022/05/GHSA-236p-2rjr-h84v/GHSA-236p-2rjr-h84v.json index 7d2bc23f934..b8303bad0f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-236p-2rjr-h84v/GHSA-236p-2rjr-h84v.json +++ b/advisories/unreviewed/2022/05/GHSA-236p-2rjr-h84v/GHSA-236p-2rjr-h84v.json @@ -7,12 +7,8 @@ "CVE-2007-5036" ], "details": "Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the \"files filter.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-245g-gjxh-59c2/GHSA-245g-gjxh-59c2.json b/advisories/unreviewed/2022/05/GHSA-245g-gjxh-59c2/GHSA-245g-gjxh-59c2.json index 73f8ff76822..631c09cbc0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-245g-gjxh-59c2/GHSA-245g-gjxh-59c2.json +++ b/advisories/unreviewed/2022/05/GHSA-245g-gjxh-59c2/GHSA-245g-gjxh-59c2.json @@ -7,12 +7,8 @@ "CVE-2007-5079" ], "details": "Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24fw-p524-4547/GHSA-24fw-p524-4547.json b/advisories/unreviewed/2022/05/GHSA-24fw-p524-4547/GHSA-24fw-p524-4547.json index f975308887d..75a3b21210f 100644 --- a/advisories/unreviewed/2022/05/GHSA-24fw-p524-4547/GHSA-24fw-p524-4547.json +++ b/advisories/unreviewed/2022/05/GHSA-24fw-p524-4547/GHSA-24fw-p524-4547.json @@ -7,12 +7,8 @@ "CVE-2007-5018" ], "details": "Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25hg-rr9r-5w7v/GHSA-25hg-rr9r-5w7v.json b/advisories/unreviewed/2022/05/GHSA-25hg-rr9r-5w7v/GHSA-25hg-rr9r-5w7v.json index 7e76d238c09..17992593ea8 100644 --- a/advisories/unreviewed/2022/05/GHSA-25hg-rr9r-5w7v/GHSA-25hg-rr9r-5w7v.json +++ b/advisories/unreviewed/2022/05/GHSA-25hg-rr9r-5w7v/GHSA-25hg-rr9r-5w7v.json @@ -7,12 +7,8 @@ "CVE-2007-4994" ], "details": "Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25jc-28wg-jh86/GHSA-25jc-28wg-jh86.json b/advisories/unreviewed/2022/05/GHSA-25jc-28wg-jh86/GHSA-25jc-28wg-jh86.json index e9b55b39db3..3a424f8284c 100644 --- a/advisories/unreviewed/2022/05/GHSA-25jc-28wg-jh86/GHSA-25jc-28wg-jh86.json +++ b/advisories/unreviewed/2022/05/GHSA-25jc-28wg-jh86/GHSA-25jc-28wg-jh86.json @@ -7,12 +7,8 @@ "CVE-2007-4545" ], "details": "Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) ZIP or (2) RAR archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25mw-r645-vhvc/GHSA-25mw-r645-vhvc.json b/advisories/unreviewed/2022/05/GHSA-25mw-r645-vhvc/GHSA-25mw-r645-vhvc.json index 8dc58bf3742..9230eaa70ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-25mw-r645-vhvc/GHSA-25mw-r645-vhvc.json +++ b/advisories/unreviewed/2022/05/GHSA-25mw-r645-vhvc/GHSA-25mw-r645-vhvc.json @@ -7,12 +7,8 @@ "CVE-2007-5031" ], "details": "The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26g4-r5qf-54qp/GHSA-26g4-r5qf-54qp.json b/advisories/unreviewed/2022/05/GHSA-26g4-r5qf-54qp/GHSA-26g4-r5qf-54qp.json index 3bff4a698af..8d101cf60dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-26g4-r5qf-54qp/GHSA-26g4-r5qf-54qp.json +++ b/advisories/unreviewed/2022/05/GHSA-26g4-r5qf-54qp/GHSA-26g4-r5qf-54qp.json @@ -7,12 +7,8 @@ "CVE-2007-4619" ], "details": "Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26wg-qj4f-57xc/GHSA-26wg-qj4f-57xc.json b/advisories/unreviewed/2022/05/GHSA-26wg-qj4f-57xc/GHSA-26wg-qj4f-57xc.json index 28f8106cace..0b0eab49972 100644 --- a/advisories/unreviewed/2022/05/GHSA-26wg-qj4f-57xc/GHSA-26wg-qj4f-57xc.json +++ b/advisories/unreviewed/2022/05/GHSA-26wg-qj4f-57xc/GHSA-26wg-qj4f-57xc.json @@ -7,12 +7,8 @@ "CVE-2007-4979" ], "details": "SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-278v-98mp-vjv7/GHSA-278v-98mp-vjv7.json b/advisories/unreviewed/2022/05/GHSA-278v-98mp-vjv7/GHSA-278v-98mp-vjv7.json index bc6b80a74b6..61a24cc908e 100644 --- a/advisories/unreviewed/2022/05/GHSA-278v-98mp-vjv7/GHSA-278v-98mp-vjv7.json +++ b/advisories/unreviewed/2022/05/GHSA-278v-98mp-vjv7/GHSA-278v-98mp-vjv7.json @@ -7,12 +7,8 @@ "CVE-2007-4813" ], "details": "Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28w9-f394-mqfw/GHSA-28w9-f394-mqfw.json b/advisories/unreviewed/2022/05/GHSA-28w9-f394-mqfw/GHSA-28w9-f394-mqfw.json index 0ccb1b0d8a1..92d674ba286 100644 --- a/advisories/unreviewed/2022/05/GHSA-28w9-f394-mqfw/GHSA-28w9-f394-mqfw.json +++ b/advisories/unreviewed/2022/05/GHSA-28w9-f394-mqfw/GHSA-28w9-f394-mqfw.json @@ -7,12 +7,8 @@ "CVE-2007-4689" ], "details": "Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2954-hh3h-2236/GHSA-2954-hh3h-2236.json b/advisories/unreviewed/2022/05/GHSA-2954-hh3h-2236/GHSA-2954-hh3h-2236.json index 69c70645ff2..36aca68df6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2954-hh3h-2236/GHSA-2954-hh3h-2236.json +++ b/advisories/unreviewed/2022/05/GHSA-2954-hh3h-2236/GHSA-2954-hh3h-2236.json @@ -7,12 +7,8 @@ "CVE-2007-5331" ], "details": "Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29qc-7h9x-7mpw/GHSA-29qc-7h9x-7mpw.json b/advisories/unreviewed/2022/05/GHSA-29qc-7h9x-7mpw/GHSA-29qc-7h9x-7mpw.json index 4c165e164ee..ad394f0d166 100644 --- a/advisories/unreviewed/2022/05/GHSA-29qc-7h9x-7mpw/GHSA-29qc-7h9x-7mpw.json +++ b/advisories/unreviewed/2022/05/GHSA-29qc-7h9x-7mpw/GHSA-29qc-7h9x-7mpw.json @@ -7,12 +7,8 @@ "CVE-2007-4610" ], "details": "Unrestricted file upload vulnerability in config/upload.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to upload and execute arbitrary PHP files in images/, possibly related to config/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29xj-vxf5-px46/GHSA-29xj-vxf5-px46.json b/advisories/unreviewed/2022/05/GHSA-29xj-vxf5-px46/GHSA-29xj-vxf5-px46.json index 10ad355ee59..7abff59196e 100644 --- a/advisories/unreviewed/2022/05/GHSA-29xj-vxf5-px46/GHSA-29xj-vxf5-px46.json +++ b/advisories/unreviewed/2022/05/GHSA-29xj-vxf5-px46/GHSA-29xj-vxf5-px46.json @@ -7,12 +7,8 @@ "CVE-2007-4718" ], "details": "Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gj3-xrpr-w23r/GHSA-2gj3-xrpr-w23r.json b/advisories/unreviewed/2022/05/GHSA-2gj3-xrpr-w23r/GHSA-2gj3-xrpr-w23r.json index 96f241a1c90..a84a3677861 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gj3-xrpr-w23r/GHSA-2gj3-xrpr-w23r.json +++ b/advisories/unreviewed/2022/05/GHSA-2gj3-xrpr-w23r/GHSA-2gj3-xrpr-w23r.json @@ -7,12 +7,8 @@ "CVE-2007-4944" ], "details": "The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gp6-x3qj-wq4m/GHSA-2gp6-x3qj-wq4m.json b/advisories/unreviewed/2022/05/GHSA-2gp6-x3qj-wq4m/GHSA-2gp6-x3qj-wq4m.json index 42413c5120a..ad3bda5844a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gp6-x3qj-wq4m/GHSA-2gp6-x3qj-wq4m.json +++ b/advisories/unreviewed/2022/05/GHSA-2gp6-x3qj-wq4m/GHSA-2gp6-x3qj-wq4m.json @@ -7,12 +7,8 @@ "CVE-2007-4620" ], "details": "Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h6v-37p4-8p5c/GHSA-2h6v-37p4-8p5c.json b/advisories/unreviewed/2022/05/GHSA-2h6v-37p4-8p5c/GHSA-2h6v-37p4-8p5c.json index 5bb8d60fe37..8bee694cfd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h6v-37p4-8p5c/GHSA-2h6v-37p4-8p5c.json +++ b/advisories/unreviewed/2022/05/GHSA-2h6v-37p4-8p5c/GHSA-2h6v-37p4-8p5c.json @@ -7,12 +7,8 @@ "CVE-2007-5023" ], "details": "Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious \"program.exe\" file in the C: folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mp5-q6v7-w9ff/GHSA-2mp5-q6v7-w9ff.json b/advisories/unreviewed/2022/05/GHSA-2mp5-q6v7-w9ff/GHSA-2mp5-q6v7-w9ff.json index 9870f38fceb..d71443f536e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mp5-q6v7-w9ff/GHSA-2mp5-q6v7-w9ff.json +++ b/advisories/unreviewed/2022/05/GHSA-2mp5-q6v7-w9ff/GHSA-2mp5-q6v7-w9ff.json @@ -7,12 +7,8 @@ "CVE-2007-4845" ], "details": "Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pm5-h4rp-cjq3/GHSA-2pm5-h4rp-cjq3.json b/advisories/unreviewed/2022/05/GHSA-2pm5-h4rp-cjq3/GHSA-2pm5-h4rp-cjq3.json index 6ba569e068c..ddab0fcf04e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pm5-h4rp-cjq3/GHSA-2pm5-h4rp-cjq3.json +++ b/advisories/unreviewed/2022/05/GHSA-2pm5-h4rp-cjq3/GHSA-2pm5-h4rp-cjq3.json @@ -7,12 +7,8 @@ "CVE-2007-4743" ], "details": "The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rfx-7w8r-c9p9/GHSA-2rfx-7w8r-c9p9.json b/advisories/unreviewed/2022/05/GHSA-2rfx-7w8r-c9p9/GHSA-2rfx-7w8r-c9p9.json index 4ac91d9a594..26279b5fb91 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rfx-7w8r-c9p9/GHSA-2rfx-7w8r-c9p9.json +++ b/advisories/unreviewed/2022/05/GHSA-2rfx-7w8r-c9p9/GHSA-2rfx-7w8r-c9p9.json @@ -7,12 +7,8 @@ "CVE-2007-4699" ], "details": "The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other applications to access the key without warning the user, which might allow other applications to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v2g-7jx3-jq4g/GHSA-2v2g-7jx3-jq4g.json b/advisories/unreviewed/2022/05/GHSA-2v2g-7jx3-jq4g/GHSA-2v2g-7jx3-jq4g.json index cb69512d356..5868c76beea 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v2g-7jx3-jq4g/GHSA-2v2g-7jx3-jq4g.json +++ b/advisories/unreviewed/2022/05/GHSA-2v2g-7jx3-jq4g/GHSA-2v2g-7jx3-jq4g.json @@ -7,12 +7,8 @@ "CVE-2007-4722" ], "details": "Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v49-56rv-5c2h/GHSA-2v49-56rv-5c2h.json b/advisories/unreviewed/2022/05/GHSA-2v49-56rv-5c2h/GHSA-2v49-56rv-5c2h.json index 01f47b69d9d..9b1804f6d10 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v49-56rv-5c2h/GHSA-2v49-56rv-5c2h.json +++ b/advisories/unreviewed/2022/05/GHSA-2v49-56rv-5c2h/GHSA-2v49-56rv-5c2h.json @@ -7,12 +7,8 @@ "CVE-2007-5211" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Arbor Networks Peakflow SP 3.5.1 before patch 14, and 3.6.1 before patch 5, when scope accounts are enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving GET or POST requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v6c-8783-rmxx/GHSA-2v6c-8783-rmxx.json b/advisories/unreviewed/2022/05/GHSA-2v6c-8783-rmxx/GHSA-2v6c-8783-rmxx.json index e81c6f4715e..d2619447654 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v6c-8783-rmxx/GHSA-2v6c-8783-rmxx.json +++ b/advisories/unreviewed/2022/05/GHSA-2v6c-8783-rmxx/GHSA-2v6c-8783-rmxx.json @@ -7,12 +7,8 @@ "CVE-2007-5184" ], "details": "Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x3q-v3g7-gh3w/GHSA-2x3q-v3g7-gh3w.json b/advisories/unreviewed/2022/05/GHSA-2x3q-v3g7-gh3w/GHSA-2x3q-v3g7-gh3w.json index ea65dd055e5..e1942bc209b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x3q-v3g7-gh3w/GHSA-2x3q-v3g7-gh3w.json +++ b/advisories/unreviewed/2022/05/GHSA-2x3q-v3g7-gh3w/GHSA-2x3q-v3g7-gh3w.json @@ -7,12 +7,8 @@ "CVE-2007-4710" ], "details": "Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xgw-38g9-836c/GHSA-2xgw-38g9-836c.json b/advisories/unreviewed/2022/05/GHSA-2xgw-38g9-836c/GHSA-2xgw-38g9-836c.json index 93eab32ce21..cdf8e25b9ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xgw-38g9-836c/GHSA-2xgw-38g9-836c.json +++ b/advisories/unreviewed/2022/05/GHSA-2xgw-38g9-836c/GHSA-2xgw-38g9-836c.json @@ -7,12 +7,8 @@ "CVE-2007-4698" ], "details": "Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to conduct cross-site scripting (XSS) attacks by causing JavaScript events to be associated with the wrong frame.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xhr-hc64-p86v/GHSA-2xhr-hc64-p86v.json b/advisories/unreviewed/2022/05/GHSA-2xhr-hc64-p86v/GHSA-2xhr-hc64-p86v.json index 0a2aa186b3c..a54263d8006 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xhr-hc64-p86v/GHSA-2xhr-hc64-p86v.json +++ b/advisories/unreviewed/2022/05/GHSA-2xhr-hc64-p86v/GHSA-2xhr-hc64-p86v.json @@ -7,12 +7,8 @@ "CVE-2007-4807" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath parameter to (1) modules/Discipline/CategoryBreakdownTime.php or (2) modules/Discipline/StudentFieldBreakdown.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-322g-vx47-pfp6/GHSA-322g-vx47-pfp6.json b/advisories/unreviewed/2022/05/GHSA-322g-vx47-pfp6/GHSA-322g-vx47-pfp6.json index af773c199b1..8df70f13559 100644 --- a/advisories/unreviewed/2022/05/GHSA-322g-vx47-pfp6/GHSA-322g-vx47-pfp6.json +++ b/advisories/unreviewed/2022/05/GHSA-322g-vx47-pfp6/GHSA-322g-vx47-pfp6.json @@ -7,12 +7,8 @@ "CVE-2007-4732" ], "details": "Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-324j-grr2-6cg2/GHSA-324j-grr2-6cg2.json b/advisories/unreviewed/2022/05/GHSA-324j-grr2-6cg2/GHSA-324j-grr2-6cg2.json index 0e43b6acd1a..7173024e941 100644 --- a/advisories/unreviewed/2022/05/GHSA-324j-grr2-6cg2/GHSA-324j-grr2-6cg2.json +++ b/advisories/unreviewed/2022/05/GHSA-324j-grr2-6cg2/GHSA-324j-grr2-6cg2.json @@ -7,12 +7,8 @@ "CVE-2007-5095" ], "details": "Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3267-v3qq-c7gf/GHSA-3267-v3qq-c7gf.json b/advisories/unreviewed/2022/05/GHSA-3267-v3qq-c7gf/GHSA-3267-v3qq-c7gf.json index a1556c31f6a..86fad29a729 100644 --- a/advisories/unreviewed/2022/05/GHSA-3267-v3qq-c7gf/GHSA-3267-v3qq-c7gf.json +++ b/advisories/unreviewed/2022/05/GHSA-3267-v3qq-c7gf/GHSA-3267-v3qq-c7gf.json @@ -7,12 +7,8 @@ "CVE-2007-4658" ], "details": "The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32r6-9grj-4wcv/GHSA-32r6-9grj-4wcv.json b/advisories/unreviewed/2022/05/GHSA-32r6-9grj-4wcv/GHSA-32r6-9grj-4wcv.json index 0e658d3d569..2ce042fb024 100644 --- a/advisories/unreviewed/2022/05/GHSA-32r6-9grj-4wcv/GHSA-32r6-9grj-4wcv.json +++ b/advisories/unreviewed/2022/05/GHSA-32r6-9grj-4wcv/GHSA-32r6-9grj-4wcv.json @@ -7,12 +7,8 @@ "CVE-2007-4562" ], "details": "Unspecified vulnerability in Hitachi DABroker before 03-02-/D and Cosminexus DABroker before 02-04-/C and 03-05-/E allows remote attackers to cause a denial of service (connection prevention) by sending \"data unexpectedly through a port.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-336j-w8p8-49cp/GHSA-336j-w8p8-49cp.json b/advisories/unreviewed/2022/05/GHSA-336j-w8p8-49cp/GHSA-336j-w8p8-49cp.json index 7e5dc81bc07..4c35f381325 100644 --- a/advisories/unreviewed/2022/05/GHSA-336j-w8p8-49cp/GHSA-336j-w8p8-49cp.json +++ b/advisories/unreviewed/2022/05/GHSA-336j-w8p8-49cp/GHSA-336j-w8p8-49cp.json @@ -7,12 +7,8 @@ "CVE-2007-5239" ], "details": "Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -164,9 +160,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33qg-r99w-m2x7/GHSA-33qg-r99w-m2x7.json b/advisories/unreviewed/2022/05/GHSA-33qg-r99w-m2x7/GHSA-33qg-r99w-m2x7.json index d6df40ef655..bbb7d0c6588 100644 --- a/advisories/unreviewed/2022/05/GHSA-33qg-r99w-m2x7/GHSA-33qg-r99w-m2x7.json +++ b/advisories/unreviewed/2022/05/GHSA-33qg-r99w-m2x7/GHSA-33qg-r99w-m2x7.json @@ -7,12 +7,8 @@ "CVE-2007-5185" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_script/frontend_render/navigation/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3443-q38f-fwmh/GHSA-3443-q38f-fwmh.json b/advisories/unreviewed/2022/05/GHSA-3443-q38f-fwmh/GHSA-3443-q38f-fwmh.json index 3ed234403cf..9adcdc4ab7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3443-q38f-fwmh/GHSA-3443-q38f-fwmh.json +++ b/advisories/unreviewed/2022/05/GHSA-3443-q38f-fwmh/GHSA-3443-q38f-fwmh.json @@ -7,12 +7,8 @@ "CVE-2007-4822" ], "details": "Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by accessing (1) ap.html and (2) filter_ip.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-346j-7cvj-x28v/GHSA-346j-7cvj-x28v.json b/advisories/unreviewed/2022/05/GHSA-346j-7cvj-x28v/GHSA-346j-7cvj-x28v.json index 24606d70173..2fee770949c 100644 --- a/advisories/unreviewed/2022/05/GHSA-346j-7cvj-x28v/GHSA-346j-7cvj-x28v.json +++ b/advisories/unreviewed/2022/05/GHSA-346j-7cvj-x28v/GHSA-346j-7cvj-x28v.json @@ -7,12 +7,8 @@ "CVE-2007-4640" ], "details": "Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3525-wg4c-6hx4/GHSA-3525-wg4c-6hx4.json b/advisories/unreviewed/2022/05/GHSA-3525-wg4c-6hx4/GHSA-3525-wg4c-6hx4.json index e63bb6294a0..81ca801a882 100644 --- a/advisories/unreviewed/2022/05/GHSA-3525-wg4c-6hx4/GHSA-3525-wg4c-6hx4.json +++ b/advisories/unreviewed/2022/05/GHSA-3525-wg4c-6hx4/GHSA-3525-wg4c-6hx4.json @@ -7,12 +7,8 @@ "CVE-2007-5361" ], "details": "The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-367f-4w4m-gh7p/GHSA-367f-4w4m-gh7p.json b/advisories/unreviewed/2022/05/GHSA-367f-4w4m-gh7p/GHSA-367f-4w4m-gh7p.json index 9d98d5eee4d..1d906085d3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-367f-4w4m-gh7p/GHSA-367f-4w4m-gh7p.json +++ b/advisories/unreviewed/2022/05/GHSA-367f-4w4m-gh7p/GHSA-367f-4w4m-gh7p.json @@ -7,12 +7,8 @@ "CVE-2007-5334" ], "details": "Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -220,9 +216,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36fr-w5h7-5f28/GHSA-36fr-w5h7-5f28.json b/advisories/unreviewed/2022/05/GHSA-36fr-w5h7-5f28/GHSA-36fr-w5h7-5f28.json index 938f4652ae3..26821a4e20a 100644 --- a/advisories/unreviewed/2022/05/GHSA-36fr-w5h7-5f28/GHSA-36fr-w5h7-5f28.json +++ b/advisories/unreviewed/2022/05/GHSA-36fr-w5h7-5f28/GHSA-36fr-w5h7-5f28.json @@ -7,12 +7,8 @@ "CVE-2007-4731" ], "details": "Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36v6-mp2g-5c58/GHSA-36v6-mp2g-5c58.json b/advisories/unreviewed/2022/05/GHSA-36v6-mp2g-5c58/GHSA-36v6-mp2g-5c58.json index 71fe166a184..672c48f4733 100644 --- a/advisories/unreviewed/2022/05/GHSA-36v6-mp2g-5c58/GHSA-36v6-mp2g-5c58.json +++ b/advisories/unreviewed/2022/05/GHSA-36v6-mp2g-5c58/GHSA-36v6-mp2g-5c58.json @@ -7,12 +7,8 @@ "CVE-2007-4601" ], "details": "A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-398g-xgm8-h7c4/GHSA-398g-xgm8-h7c4.json b/advisories/unreviewed/2022/05/GHSA-398g-xgm8-h7c4/GHSA-398g-xgm8-h7c4.json index 31c0f44ac40..14d33fc7014 100644 --- a/advisories/unreviewed/2022/05/GHSA-398g-xgm8-h7c4/GHSA-398g-xgm8-h7c4.json +++ b/advisories/unreviewed/2022/05/GHSA-398g-xgm8-h7c4/GHSA-398g-xgm8-h7c4.json @@ -7,12 +7,8 @@ "CVE-2007-5086" ], "details": "Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4) NtOpenThread, (5) NtTerminateProcess, (6) NtUserFindWindowEx, and (7) NtUserBuildHwndList kernel SSDT hooks in kylif.sys; the (8) NtDuplicateObject (DuplicateHandle) kernel SSDT hook; and possibly other kernel SSDT hooks. NOTE: the NtCreateSection vector is covered by CVE-2007-5043.1. NOTE: the vendor disputes that the DuplicateHandle vector is a vulnerability in their code, stating that \"it is not an error in our code, but an obscure method for manipulating standard Windows routines to circumvent our self-defense mechanisms.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39qg-q887-27xh/GHSA-39qg-q887-27xh.json b/advisories/unreviewed/2022/05/GHSA-39qg-q887-27xh/GHSA-39qg-q887-27xh.json index d27739c82d9..801353f1d83 100644 --- a/advisories/unreviewed/2022/05/GHSA-39qg-q887-27xh/GHSA-39qg-q887-27xh.json +++ b/advisories/unreviewed/2022/05/GHSA-39qg-q887-27xh/GHSA-39qg-q887-27xh.json @@ -7,12 +7,8 @@ "CVE-2007-5223" ], "details": "Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified impact, related to incorrect input validation or other defects involving (1) admin/backupstart.php, (2) a .sql filename under admin/admin/dump/, (3) a .sql filename in the fl parameter to admin/downloadbackup.php, and (4) a .. (dot dot) in the fl parameter to admin/downloadbackup.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c6c-vv76-h53v/GHSA-3c6c-vv76-h53v.json b/advisories/unreviewed/2022/05/GHSA-3c6c-vv76-h53v/GHSA-3c6c-vv76-h53v.json index c08ed777fba..0b8ed761039 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c6c-vv76-h53v/GHSA-3c6c-vv76-h53v.json +++ b/advisories/unreviewed/2022/05/GHSA-3c6c-vv76-h53v/GHSA-3c6c-vv76-h53v.json @@ -7,12 +7,8 @@ "CVE-2007-4872" ], "details": "SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cfm-q6rm-f5w2/GHSA-3cfm-q6rm-f5w2.json b/advisories/unreviewed/2022/05/GHSA-3cfm-q6rm-f5w2/GHSA-3cfm-q6rm-f5w2.json index 782a0cc213d..fd586650597 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cfm-q6rm-f5w2/GHSA-3cfm-q6rm-f5w2.json +++ b/advisories/unreviewed/2022/05/GHSA-3cfm-q6rm-f5w2/GHSA-3cfm-q6rm-f5w2.json @@ -7,12 +7,8 @@ "CVE-2007-4716" ], "details": "Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f4x-wv57-p6jm/GHSA-3f4x-wv57-p6jm.json b/advisories/unreviewed/2022/05/GHSA-3f4x-wv57-p6jm/GHSA-3f4x-wv57-p6jm.json index e39318fd997..22f5589f752 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f4x-wv57-p6jm/GHSA-3f4x-wv57-p6jm.json +++ b/advisories/unreviewed/2022/05/GHSA-3f4x-wv57-p6jm/GHSA-3f4x-wv57-p6jm.json @@ -7,12 +7,8 @@ "CVE-2007-4644" ], "details": "Format string vulnerability in the Cl_GetPackets function in cl_main.c in the client in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote Doomsday servers to execute arbitrary code via format string specifiers in a PSV_CONSOLE_TEXT message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g32-h55j-rh57/GHSA-3g32-h55j-rh57.json b/advisories/unreviewed/2022/05/GHSA-3g32-h55j-rh57/GHSA-3g32-h55j-rh57.json index ce2796e5234..201005508c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g32-h55j-rh57/GHSA-3g32-h55j-rh57.json +++ b/advisories/unreviewed/2022/05/GHSA-3g32-h55j-rh57/GHSA-3g32-h55j-rh57.json @@ -7,12 +7,8 @@ "CVE-2007-4717" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUserSearch.php, and the (3) view parameter in admin/campusProblem.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h7j-gprx-76w7/GHSA-3h7j-gprx-76w7.json b/advisories/unreviewed/2022/05/GHSA-3h7j-gprx-76w7/GHSA-3h7j-gprx-76w7.json index 0d175cdd0b0..36053620a1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h7j-gprx-76w7/GHSA-3h7j-gprx-76w7.json +++ b/advisories/unreviewed/2022/05/GHSA-3h7j-gprx-76w7/GHSA-3h7j-gprx-76w7.json @@ -7,12 +7,8 @@ "CVE-2007-4919" ], "details": "Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hq8-5g44-r923/GHSA-3hq8-5g44-r923.json b/advisories/unreviewed/2022/05/GHSA-3hq8-5g44-r923/GHSA-3hq8-5g44-r923.json index 320274f0324..633b1230e5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hq8-5g44-r923/GHSA-3hq8-5g44-r923.json +++ b/advisories/unreviewed/2022/05/GHSA-3hq8-5g44-r923/GHSA-3hq8-5g44-r923.json @@ -7,12 +7,8 @@ "CVE-2007-4551" ], "details": "PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hvj-9j8h-vgr2/GHSA-3hvj-9j8h-vgr2.json b/advisories/unreviewed/2022/05/GHSA-3hvj-9j8h-vgr2/GHSA-3hvj-9j8h-vgr2.json index e1c59e57246..df2971c7652 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hvj-9j8h-vgr2/GHSA-3hvj-9j8h-vgr2.json +++ b/advisories/unreviewed/2022/05/GHSA-3hvj-9j8h-vgr2/GHSA-3hvj-9j8h-vgr2.json @@ -7,12 +7,8 @@ "CVE-2007-4770" ], "details": "libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \\0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -180,9 +176,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mmj-vfm4-rpfq/GHSA-3mmj-vfm4-rpfq.json b/advisories/unreviewed/2022/05/GHSA-3mmj-vfm4-rpfq/GHSA-3mmj-vfm4-rpfq.json index 4ed0e7f78ea..5d057815579 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mmj-vfm4-rpfq/GHSA-3mmj-vfm4-rpfq.json +++ b/advisories/unreviewed/2022/05/GHSA-3mmj-vfm4-rpfq/GHSA-3mmj-vfm4-rpfq.json @@ -7,12 +7,8 @@ "CVE-2007-5120" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pqv-3gf8-jfg6/GHSA-3pqv-3gf8-jfg6.json b/advisories/unreviewed/2022/05/GHSA-3pqv-3gf8-jfg6/GHSA-3pqv-3gf8-jfg6.json index 19145f3e263..327374177ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pqv-3gf8-jfg6/GHSA-3pqv-3gf8-jfg6.json +++ b/advisories/unreviewed/2022/05/GHSA-3pqv-3gf8-jfg6/GHSA-3pqv-3gf8-jfg6.json @@ -7,12 +7,8 @@ "CVE-2007-4635" ], "details": "Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qmw-8xgv-p6c8/GHSA-3qmw-8xgv-p6c8.json b/advisories/unreviewed/2022/05/GHSA-3qmw-8xgv-p6c8/GHSA-3qmw-8xgv-p6c8.json index 9748d78e392..2886e2c3186 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qmw-8xgv-p6c8/GHSA-3qmw-8xgv-p6c8.json +++ b/advisories/unreviewed/2022/05/GHSA-3qmw-8xgv-p6c8/GHSA-3qmw-8xgv-p6c8.json @@ -7,12 +7,8 @@ "CVE-2007-4907" ], "details": "Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4) customer/product.php, (5) provider/auth.php, and (6) admin/auth.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qrc-q3x7-wr8m/GHSA-3qrc-q3x7-wr8m.json b/advisories/unreviewed/2022/05/GHSA-3qrc-q3x7-wr8m/GHSA-3qrc-q3x7-wr8m.json index 0ba57ca6bd2..ceecbdc6458 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qrc-q3x7-wr8m/GHSA-3qrc-q3x7-wr8m.json +++ b/advisories/unreviewed/2022/05/GHSA-3qrc-q3x7-wr8m/GHSA-3qrc-q3x7-wr8m.json @@ -7,12 +7,8 @@ "CVE-2007-4597" ], "details": "SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v25-95xx-r27w/GHSA-3v25-95xx-r27w.json b/advisories/unreviewed/2022/05/GHSA-3v25-95xx-r27w/GHSA-3v25-95xx-r27w.json index e0dd3a95212..a0213119559 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v25-95xx-r27w/GHSA-3v25-95xx-r27w.json +++ b/advisories/unreviewed/2022/05/GHSA-3v25-95xx-r27w/GHSA-3v25-95xx-r27w.json @@ -7,12 +7,8 @@ "CVE-2007-4544" ], "details": "Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vc7-cff2-46pj/GHSA-3vc7-cff2-46pj.json b/advisories/unreviewed/2022/05/GHSA-3vc7-cff2-46pj/GHSA-3vc7-cff2-46pj.json index a09a40d3233..94048ef7523 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vc7-cff2-46pj/GHSA-3vc7-cff2-46pj.json +++ b/advisories/unreviewed/2022/05/GHSA-3vc7-cff2-46pj/GHSA-3vc7-cff2-46pj.json @@ -7,12 +7,8 @@ "CVE-2007-5194" ], "details": "The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vc9-864w-j6mh/GHSA-3vc9-864w-j6mh.json b/advisories/unreviewed/2022/05/GHSA-3vc9-864w-j6mh/GHSA-3vc9-864w-j6mh.json index 1dd07ff810f..c235996fb76 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vc9-864w-j6mh/GHSA-3vc9-864w-j6mh.json +++ b/advisories/unreviewed/2022/05/GHSA-3vc9-864w-j6mh/GHSA-3vc9-864w-j6mh.json @@ -7,12 +7,8 @@ "CVE-2007-4585" ], "details": "Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wxc-cg64-x24r/GHSA-3wxc-cg64-x24r.json b/advisories/unreviewed/2022/05/GHSA-3wxc-cg64-x24r/GHSA-3wxc-cg64-x24r.json index 471c0f37907..e28acb230cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wxc-cg64-x24r/GHSA-3wxc-cg64-x24r.json +++ b/advisories/unreviewed/2022/05/GHSA-3wxc-cg64-x24r/GHSA-3wxc-cg64-x24r.json @@ -7,12 +7,8 @@ "CVE-2007-4967" ], "details": "Online Armor Personal Firewall 2.0.1.215 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtAllocateVirtualMemory, (2) NtConnectPort, (3) NtCreateFile, (4) NtCreateKey, (5) NtCreatePort, (6) NtDeleteFile, (7) NtDeleteValueKey, (8) NtLoadKey, (9) NtOpenFile, (10) NtOpenProcess, (11) NtOpenThread, (12) NtResumeThread, (13) NtSetContextThread, (14) NtSetValueKey, (15) NtSuspendProcess, (16) NtSuspendThread, and (17) NtTerminateThread.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xp9-vp4p-p2r6/GHSA-3xp9-vp4p-p2r6.json b/advisories/unreviewed/2022/05/GHSA-3xp9-vp4p-p2r6/GHSA-3xp9-vp4p-p2r6.json index 9dee5d7b4ab..f63005c6fb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xp9-vp4p-p2r6/GHSA-3xp9-vp4p-p2r6.json +++ b/advisories/unreviewed/2022/05/GHSA-3xp9-vp4p-p2r6/GHSA-3xp9-vp4p-p2r6.json @@ -7,12 +7,8 @@ "CVE-2007-4910" ], "details": "Unspecified vulnerability in netInvoicing before 2.7.3 has unknown impact and attack vectors, related to \"security check soap\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4232-hhhx-rgv2/GHSA-4232-hhhx-rgv2.json b/advisories/unreviewed/2022/05/GHSA-4232-hhhx-rgv2/GHSA-4232-hhhx-rgv2.json index 17cfec22daa..035eced287d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4232-hhhx-rgv2/GHSA-4232-hhhx-rgv2.json +++ b/advisories/unreviewed/2022/05/GHSA-4232-hhhx-rgv2/GHSA-4232-hhhx-rgv2.json @@ -7,12 +7,8 @@ "CVE-2007-4745" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the sign function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42g6-c5f2-p9f3/GHSA-42g6-c5f2-p9f3.json b/advisories/unreviewed/2022/05/GHSA-42g6-c5f2-p9f3/GHSA-42g6-c5f2-p9f3.json index 9497bed7781..26aa72a73dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-42g6-c5f2-p9f3/GHSA-42g6-c5f2-p9f3.json +++ b/advisories/unreviewed/2022/05/GHSA-42g6-c5f2-p9f3/GHSA-42g6-c5f2-p9f3.json @@ -7,12 +7,8 @@ "CVE-2007-5007" ], "details": "Stack-based buffer overflow in the ir_fetch_seq function in balsa before 2.3.20 might allow remote IMAP servers to execute arbitrary code via a long response to a FETCH command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42gq-297f-29c4/GHSA-42gq-297f-29c4.json b/advisories/unreviewed/2022/05/GHSA-42gq-297f-29c4/GHSA-42gq-297f-29c4.json index 3b47309805c..4d6997221fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-42gq-297f-29c4/GHSA-42gq-297f-29c4.json +++ b/advisories/unreviewed/2022/05/GHSA-42gq-297f-29c4/GHSA-42gq-297f-29c4.json @@ -7,12 +7,8 @@ "CVE-2007-5330" ], "details": "The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of \"handle\" RPC arguments as pointers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4337-x4h9-rx8j/GHSA-4337-x4h9-rx8j.json b/advisories/unreviewed/2022/05/GHSA-4337-x4h9-rx8j/GHSA-4337-x4h9-rx8j.json index da036716216..0fd3ed5c3df 100644 --- a/advisories/unreviewed/2022/05/GHSA-4337-x4h9-rx8j/GHSA-4337-x4h9-rx8j.json +++ b/advisories/unreviewed/2022/05/GHSA-4337-x4h9-rx8j/GHSA-4337-x4h9-rx8j.json @@ -7,12 +7,8 @@ "CVE-2007-4998" ], "details": "cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43w7-6v4p-jxc3/GHSA-43w7-6v4p-jxc3.json b/advisories/unreviewed/2022/05/GHSA-43w7-6v4p-jxc3/GHSA-43w7-6v4p-jxc3.json index f2aeca1bf0f..a9b82ac3110 100644 --- a/advisories/unreviewed/2022/05/GHSA-43w7-6v4p-jxc3/GHSA-43w7-6v4p-jxc3.json +++ b/advisories/unreviewed/2022/05/GHSA-43w7-6v4p-jxc3/GHSA-43w7-6v4p-jxc3.json @@ -7,12 +7,8 @@ "CVE-2007-4993" ], "details": "pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43ww-xqjh-ppmf/GHSA-43ww-xqjh-ppmf.json b/advisories/unreviewed/2022/05/GHSA-43ww-xqjh-ppmf/GHSA-43ww-xqjh-ppmf.json index 903f2f0d570..b8911b14b8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-43ww-xqjh-ppmf/GHSA-43ww-xqjh-ppmf.json +++ b/advisories/unreviewed/2022/05/GHSA-43ww-xqjh-ppmf/GHSA-43ww-xqjh-ppmf.json @@ -7,12 +7,8 @@ "CVE-2007-4657" ], "details": "Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44wr-733h-5gmq/GHSA-44wr-733h-5gmq.json b/advisories/unreviewed/2022/05/GHSA-44wr-733h-5gmq/GHSA-44wr-733h-5gmq.json index a71cb6c5649..92048c12fe7 100644 --- a/advisories/unreviewed/2022/05/GHSA-44wr-733h-5gmq/GHSA-44wr-733h-5gmq.json +++ b/advisories/unreviewed/2022/05/GHSA-44wr-733h-5gmq/GHSA-44wr-733h-5gmq.json @@ -7,12 +7,8 @@ "CVE-2007-4700" ], "details": "Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45rh-4228-3jmv/GHSA-45rh-4228-3jmv.json b/advisories/unreviewed/2022/05/GHSA-45rh-4228-3jmv/GHSA-45rh-4228-3jmv.json index f22958467e8..0f2d3a58e86 100644 --- a/advisories/unreviewed/2022/05/GHSA-45rh-4228-3jmv/GHSA-45rh-4228-3jmv.json +++ b/advisories/unreviewed/2022/05/GHSA-45rh-4228-3jmv/GHSA-45rh-4228-3jmv.json @@ -7,12 +7,8 @@ "CVE-2007-5374" ], "details": "cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-464x-prm7-r3m9/GHSA-464x-prm7-r3m9.json b/advisories/unreviewed/2022/05/GHSA-464x-prm7-r3m9/GHSA-464x-prm7-r3m9.json index 1e082e0dc90..cb8c47370c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-464x-prm7-r3m9/GHSA-464x-prm7-r3m9.json +++ b/advisories/unreviewed/2022/05/GHSA-464x-prm7-r3m9/GHSA-464x-prm7-r3m9.json @@ -7,12 +7,8 @@ "CVE-2007-4901" ], "details": "The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46rr-74pw-3rhx/GHSA-46rr-74pw-3rhx.json b/advisories/unreviewed/2022/05/GHSA-46rr-74pw-3rhx/GHSA-46rr-74pw-3rhx.json index d807a9c3fcd..b23f44e5361 100644 --- a/advisories/unreviewed/2022/05/GHSA-46rr-74pw-3rhx/GHSA-46rr-74pw-3rhx.json +++ b/advisories/unreviewed/2022/05/GHSA-46rr-74pw-3rhx/GHSA-46rr-74pw-3rhx.json @@ -7,12 +7,8 @@ "CVE-2007-4751" ], "details": "RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4853-vw97-h7j3/GHSA-4853-vw97-h7j3.json b/advisories/unreviewed/2022/05/GHSA-4853-vw97-h7j3/GHSA-4853-vw97-h7j3.json index 1587c775ee8..95ee1cab17c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4853-vw97-h7j3/GHSA-4853-vw97-h7j3.json +++ b/advisories/unreviewed/2022/05/GHSA-4853-vw97-h7j3/GHSA-4853-vw97-h7j3.json @@ -7,12 +7,8 @@ "CVE-2007-4642" ], "details": "Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2) Msg_Write function in net_msg.c, or (3) many commands that are not properly handled by the NetSv_ReadCommands function in d_netsv.c; or (4) cause a denial of service (daemon crash) via a chat (PKT_CHAT) message without a final '\\0' character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4937-fcr5-874r/GHSA-4937-fcr5-874r.json b/advisories/unreviewed/2022/05/GHSA-4937-fcr5-874r/GHSA-4937-fcr5-874r.json index 11252389a8a..42853bf8d30 100644 --- a/advisories/unreviewed/2022/05/GHSA-4937-fcr5-874r/GHSA-4937-fcr5-874r.json +++ b/advisories/unreviewed/2022/05/GHSA-4937-fcr5-874r/GHSA-4937-fcr5-874r.json @@ -7,12 +7,8 @@ "CVE-2007-4753" ], "details": "The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP message or (2) a SIP INVITE message with a malformed To header, different vectors than CVE-2007-4553.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-498x-cm9r-crhh/GHSA-498x-cm9r-crhh.json b/advisories/unreviewed/2022/05/GHSA-498x-cm9r-crhh/GHSA-498x-cm9r-crhh.json index c780fb2f998..969c4fa4b9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-498x-cm9r-crhh/GHSA-498x-cm9r-crhh.json +++ b/advisories/unreviewed/2022/05/GHSA-498x-cm9r-crhh/GHSA-498x-cm9r-crhh.json @@ -7,12 +7,8 @@ "CVE-2007-4587" ], "details": "Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the setting of option.nopage.create in tuigwaa.properties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49q9-mrx4-393q/GHSA-49q9-mrx4-393q.json b/advisories/unreviewed/2022/05/GHSA-49q9-mrx4-393q/GHSA-49q9-mrx4-393q.json index 4961ef672af..8cab8423947 100644 --- a/advisories/unreviewed/2022/05/GHSA-49q9-mrx4-393q/GHSA-49q9-mrx4-393q.json +++ b/advisories/unreviewed/2022/05/GHSA-49q9-mrx4-393q/GHSA-49q9-mrx4-393q.json @@ -7,12 +7,8 @@ "CVE-2007-4574" ], "details": "Unspecified vulnerability in the \"stack unwinder fixes\" in kernel in Red Hat Enterprise Linux 5, when running on AMD64 and Intel 64, allows local users to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49qp-q8pv-9fq4/GHSA-49qp-q8pv-9fq4.json b/advisories/unreviewed/2022/05/GHSA-49qp-q8pv-9fq4/GHSA-49qp-q8pv-9fq4.json index 78233a65ccd..938a933ab4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-49qp-q8pv-9fq4/GHSA-49qp-q8pv-9fq4.json +++ b/advisories/unreviewed/2022/05/GHSA-49qp-q8pv-9fq4/GHSA-49qp-q8pv-9fq4.json @@ -7,12 +7,8 @@ "CVE-2007-5329" ], "details": "Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49vq-f4w4-mc8m/GHSA-49vq-f4w4-mc8m.json b/advisories/unreviewed/2022/05/GHSA-49vq-f4w4-mc8m/GHSA-49vq-f4w4-mc8m.json index f6e0959c154..8b838a7621e 100644 --- a/advisories/unreviewed/2022/05/GHSA-49vq-f4w4-mc8m/GHSA-49vq-f4w4-mc8m.json +++ b/advisories/unreviewed/2022/05/GHSA-49vq-f4w4-mc8m/GHSA-49vq-f4w4-mc8m.json @@ -7,12 +7,8 @@ "CVE-2007-4608" ], "details": "PHP remote file inclusion vulnerability in protection.php in ePersonnel RC_2004_02 allows remote attackers to execute arbitrary PHP code via a URL in the logout_page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4ch9-93xg-3f43/GHSA-4ch9-93xg-3f43.json b/advisories/unreviewed/2022/05/GHSA-4ch9-93xg-3f43/GHSA-4ch9-93xg-3f43.json index ea7647cf9c3..42c46071201 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ch9-93xg-3f43/GHSA-4ch9-93xg-3f43.json +++ b/advisories/unreviewed/2022/05/GHSA-4ch9-93xg-3f43/GHSA-4ch9-93xg-3f43.json @@ -7,12 +7,8 @@ "CVE-2007-5055" ], "details": "Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4ch9-hmx5-52hv/GHSA-4ch9-hmx5-52hv.json b/advisories/unreviewed/2022/05/GHSA-4ch9-hmx5-52hv/GHSA-4ch9-hmx5-52hv.json index ce1268f879c..66847416565 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ch9-hmx5-52hv/GHSA-4ch9-hmx5-52hv.json +++ b/advisories/unreviewed/2022/05/GHSA-4ch9-hmx5-52hv/GHSA-4ch9-hmx5-52hv.json @@ -7,12 +7,8 @@ "CVE-2007-4925" ], "details": "The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cxv-wp2w-88h7/GHSA-4cxv-wp2w-88h7.json b/advisories/unreviewed/2022/05/GHSA-4cxv-wp2w-88h7/GHSA-4cxv-wp2w-88h7.json index 87f116862ba..f211187d364 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cxv-wp2w-88h7/GHSA-4cxv-wp2w-88h7.json +++ b/advisories/unreviewed/2022/05/GHSA-4cxv-wp2w-88h7/GHSA-4cxv-wp2w-88h7.json @@ -7,12 +7,8 @@ "CVE-2007-4968" ], "details": "Privatefirewall 5.0.14.2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for (1) NtOpenProcess and (2) NtOpenThread.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4ff5-vmx4-5cxp/GHSA-4ff5-vmx4-5cxp.json b/advisories/unreviewed/2022/05/GHSA-4ff5-vmx4-5cxp/GHSA-4ff5-vmx4-5cxp.json index 7bac9ebff34..e060e27aa65 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ff5-vmx4-5cxp/GHSA-4ff5-vmx4-5cxp.json +++ b/advisories/unreviewed/2022/05/GHSA-4ff5-vmx4-5cxp/GHSA-4ff5-vmx4-5cxp.json @@ -7,12 +7,8 @@ "CVE-2007-4778" ], "details": "Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to (1) archive.php, (2) category.php, or (3) section.php in models/. NOTE: this may be the same as CVE-2007-4777.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fv8-h7r9-m88g/GHSA-4fv8-h7r9-m88g.json b/advisories/unreviewed/2022/05/GHSA-4fv8-h7r9-m88g/GHSA-4fv8-h7r9-m88g.json index d6f9fb4720c..7ecb3b83279 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fv8-h7r9-m88g/GHSA-4fv8-h7r9-m88g.json +++ b/advisories/unreviewed/2022/05/GHSA-4fv8-h7r9-m88g/GHSA-4fv8-h7r9-m88g.json @@ -7,12 +7,8 @@ "CVE-2007-4969" ], "details": "Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtLoadKey, (4) NtOpenKey, (5) NtQueryValueKey, (6) NtSetValueKey, and (7) NtUnloadKey.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gm6-249c-rcvg/GHSA-4gm6-249c-rcvg.json b/advisories/unreviewed/2022/05/GHSA-4gm6-249c-rcvg/GHSA-4gm6-249c-rcvg.json index 148b5de6b77..819c87ab4f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gm6-249c-rcvg/GHSA-4gm6-249c-rcvg.json +++ b/advisories/unreviewed/2022/05/GHSA-4gm6-249c-rcvg/GHSA-4gm6-249c-rcvg.json @@ -7,12 +7,8 @@ "CVE-2007-5030" ], "details": "Multiple integer overflows in Dibbler 0.6.0 allow remote attackers to cause a denial of service (daemon crash) via packets containing options with large lengths, which trigger attempts at excessive memory allocation, as demonstrated by (1) the TSrvMsg constructor in SrvMessages/SrvMsg.cpp; the (2) TClntMsg, (3) TClntOptIAAddress, (4) TClntOptIAPrefix, (5) TOptVendorSpecInfo, and (6) TOptOptionRequest constructors; and the (7) TRelIfaceMgr::decodeRelayRepl, (8) TRelMsg::decodeOpts, and (9) TSrvIfaceMgr::decodeRelayForw methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gqj-v768-rp5w/GHSA-4gqj-v768-rp5w.json b/advisories/unreviewed/2022/05/GHSA-4gqj-v768-rp5w/GHSA-4gqj-v768-rp5w.json index 499160e092e..8100a8dcc0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gqj-v768-rp5w/GHSA-4gqj-v768-rp5w.json +++ b/advisories/unreviewed/2022/05/GHSA-4gqj-v768-rp5w/GHSA-4gqj-v768-rp5w.json @@ -7,12 +7,8 @@ "CVE-2007-4695" ], "details": "Unspecified \"input validation\" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to file uploads.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4h2x-j62x-w4mm/GHSA-4h2x-j62x-w4mm.json b/advisories/unreviewed/2022/05/GHSA-4h2x-j62x-w4mm/GHSA-4h2x-j62x-w4mm.json index 28e7926045b..5cc1e40b529 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h2x-j62x-w4mm/GHSA-4h2x-j62x-w4mm.json +++ b/advisories/unreviewed/2022/05/GHSA-4h2x-j62x-w4mm/GHSA-4h2x-j62x-w4mm.json @@ -7,12 +7,8 @@ "CVE-2007-4690" ], "details": "Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote authenticated users to execute arbitrary code via a crafted AUTH_UNIX RPC packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mmq-vrwv-m78m/GHSA-4mmq-vrwv-m78m.json b/advisories/unreviewed/2022/05/GHSA-4mmq-vrwv-m78m/GHSA-4mmq-vrwv-m78m.json index f4e6522a9f5..49f37a72828 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mmq-vrwv-m78m/GHSA-4mmq-vrwv-m78m.json +++ b/advisories/unreviewed/2022/05/GHSA-4mmq-vrwv-m78m/GHSA-4mmq-vrwv-m78m.json @@ -7,12 +7,8 @@ "CVE-2007-4761" ], "details": "Unrestricted file upload vulnerability in upload.php in Barbo91 1.1 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mv3-grr2-3p4p/GHSA-4mv3-grr2-3p4p.json b/advisories/unreviewed/2022/05/GHSA-4mv3-grr2-3p4p/GHSA-4mv3-grr2-3p4p.json index e70804520fa..9adb573ece4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mv3-grr2-3p4p/GHSA-4mv3-grr2-3p4p.json +++ b/advisories/unreviewed/2022/05/GHSA-4mv3-grr2-3p4p/GHSA-4mv3-grr2-3p4p.json @@ -7,12 +7,8 @@ "CVE-2007-5001" ], "details": "Linux kernel before 2.4.21 allows local users to cause a denial of service (kernel panic) via asynchronous input or output on a FIFO special file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p3x-x6v3-qprv/GHSA-4p3x-x6v3-qprv.json b/advisories/unreviewed/2022/05/GHSA-4p3x-x6v3-qprv/GHSA-4p3x-x6v3-qprv.json index e8f61f08c8a..43b4ad49eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p3x-x6v3-qprv/GHSA-4p3x-x6v3-qprv.json +++ b/advisories/unreviewed/2022/05/GHSA-4p3x-x6v3-qprv/GHSA-4p3x-x6v3-qprv.json @@ -7,12 +7,8 @@ "CVE-2007-5110" ], "details": "Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4phw-xx96-wm6w/GHSA-4phw-xx96-wm6w.json b/advisories/unreviewed/2022/05/GHSA-4phw-xx96-wm6w/GHSA-4phw-xx96-wm6w.json index 6eb221989d2..8963eaba124 100644 --- a/advisories/unreviewed/2022/05/GHSA-4phw-xx96-wm6w/GHSA-4phw-xx96-wm6w.json +++ b/advisories/unreviewed/2022/05/GHSA-4phw-xx96-wm6w/GHSA-4phw-xx96-wm6w.json @@ -7,12 +7,8 @@ "CVE-2007-4918" ], "details": "SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qf2-r366-mwj6/GHSA-4qf2-r366-mwj6.json b/advisories/unreviewed/2022/05/GHSA-4qf2-r366-mwj6/GHSA-4qf2-r366-mwj6.json index 135a0b4bf23..d69ff41e901 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qf2-r366-mwj6/GHSA-4qf2-r366-mwj6.json +++ b/advisories/unreviewed/2022/05/GHSA-4qf2-r366-mwj6/GHSA-4qf2-r366-mwj6.json @@ -7,12 +7,8 @@ "CVE-2007-5230" ], "details": "admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rg2-xc78-49m2/GHSA-4rg2-xc78-49m2.json b/advisories/unreviewed/2022/05/GHSA-4rg2-xc78-49m2/GHSA-4rg2-xc78-49m2.json index c0bd794f0b3..a125cc344fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rg2-xc78-49m2/GHSA-4rg2-xc78-49m2.json +++ b/advisories/unreviewed/2022/05/GHSA-4rg2-xc78-49m2/GHSA-4rg2-xc78-49m2.json @@ -7,12 +7,8 @@ "CVE-2007-5014" ], "details": "Multiple PHP remote file inclusion vulnerabilities in pSlash 0.70 allow remote attackers to execute arbitrary PHP code via a URL in (1) the lvc_admin_dir parameter to modules/visitors2/admin/view-archiver.inc.php or (2) the lvc_include_dir parameter to modules/visitors2/include/menus.inc.php. NOTE: the modules/visitors2/include/config.inc.php vector is already covered by CVE-2006-4373. NOTE: vector 1 is disputed by CVE because PHP encounters a fatal instantiation error on a direct request for the file, before reaching the include statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xvw-fjx2-wmpv/GHSA-4xvw-fjx2-wmpv.json b/advisories/unreviewed/2022/05/GHSA-4xvw-fjx2-wmpv/GHSA-4xvw-fjx2-wmpv.json index d01d5672370..8302eb0f159 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xvw-fjx2-wmpv/GHSA-4xvw-fjx2-wmpv.json +++ b/advisories/unreviewed/2022/05/GHSA-4xvw-fjx2-wmpv/GHSA-4xvw-fjx2-wmpv.json @@ -7,12 +7,8 @@ "CVE-2007-4863" ], "details": "SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-522x-44vv-3p4m/GHSA-522x-44vv-3p4m.json b/advisories/unreviewed/2022/05/GHSA-522x-44vv-3p4m/GHSA-522x-44vv-3p4m.json index 8a5775cab2b..076cbccef1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-522x-44vv-3p4m/GHSA-522x-44vv-3p4m.json +++ b/advisories/unreviewed/2022/05/GHSA-522x-44vv-3p4m/GHSA-522x-44vv-3p4m.json @@ -7,12 +7,8 @@ "CVE-2007-4735" ], "details": "Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-525g-vmwj-vprj/GHSA-525g-vmwj-vprj.json b/advisories/unreviewed/2022/05/GHSA-525g-vmwj-vprj/GHSA-525g-vmwj-vprj.json index 376e9f9e603..0fbbdffec8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-525g-vmwj-vprj/GHSA-525g-vmwj-vprj.json +++ b/advisories/unreviewed/2022/05/GHSA-525g-vmwj-vprj/GHSA-525g-vmwj-vprj.json @@ -7,12 +7,8 @@ "CVE-2007-4646" ], "details": "Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52cc-2mvx-g968/GHSA-52cc-2mvx-g968.json b/advisories/unreviewed/2022/05/GHSA-52cc-2mvx-g968/GHSA-52cc-2mvx-g968.json index 68342b42945..fbadc4330be 100644 --- a/advisories/unreviewed/2022/05/GHSA-52cc-2mvx-g968/GHSA-52cc-2mvx-g968.json +++ b/advisories/unreviewed/2022/05/GHSA-52cc-2mvx-g968/GHSA-52cc-2mvx-g968.json @@ -7,12 +7,8 @@ "CVE-2007-5390" ], "details": "PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53f2-89vw-gfqr/GHSA-53f2-89vw-gfqr.json b/advisories/unreviewed/2022/05/GHSA-53f2-89vw-gfqr/GHSA-53f2-89vw-gfqr.json index b24f4299d5b..d5c6741c4e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-53f2-89vw-gfqr/GHSA-53f2-89vw-gfqr.json +++ b/advisories/unreviewed/2022/05/GHSA-53f2-89vw-gfqr/GHSA-53f2-89vw-gfqr.json @@ -7,12 +7,8 @@ "CVE-2007-4986" ], "details": "Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -132,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53r8-hh23-vgjq/GHSA-53r8-hh23-vgjq.json b/advisories/unreviewed/2022/05/GHSA-53r8-hh23-vgjq/GHSA-53r8-hh23-vgjq.json index 6650c6e8c79..0448616798a 100644 --- a/advisories/unreviewed/2022/05/GHSA-53r8-hh23-vgjq/GHSA-53r8-hh23-vgjq.json +++ b/advisories/unreviewed/2022/05/GHSA-53r8-hh23-vgjq/GHSA-53r8-hh23-vgjq.json @@ -7,12 +7,8 @@ "CVE-2007-4838" ], "details": "Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-552j-r9hx-pgwr/GHSA-552j-r9hx-pgwr.json b/advisories/unreviewed/2022/05/GHSA-552j-r9hx-pgwr/GHSA-552j-r9hx-pgwr.json index d55731a84f4..816c47b269f 100644 --- a/advisories/unreviewed/2022/05/GHSA-552j-r9hx-pgwr/GHSA-552j-r9hx-pgwr.json +++ b/advisories/unreviewed/2022/05/GHSA-552j-r9hx-pgwr/GHSA-552j-r9hx-pgwr.json @@ -7,12 +7,8 @@ "CVE-2007-4548" ], "details": "The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55xh-gq2p-rgv2/GHSA-55xh-gq2p-rgv2.json b/advisories/unreviewed/2022/05/GHSA-55xh-gq2p-rgv2/GHSA-55xh-gq2p-rgv2.json index 12cacf4dfe6..b76b4d8585f 100644 --- a/advisories/unreviewed/2022/05/GHSA-55xh-gq2p-rgv2/GHSA-55xh-gq2p-rgv2.json +++ b/advisories/unreviewed/2022/05/GHSA-55xh-gq2p-rgv2/GHSA-55xh-gq2p-rgv2.json @@ -7,12 +7,8 @@ "CVE-2007-4924" ], "details": "The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \\0 byte to be written to an \"attacker-controlled address.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55xr-4fxj-xx2h/GHSA-55xr-4fxj-xx2h.json b/advisories/unreviewed/2022/05/GHSA-55xr-4fxj-xx2h/GHSA-55xr-4fxj-xx2h.json index 27d81e11af3..93318860f8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-55xr-4fxj-xx2h/GHSA-55xr-4fxj-xx2h.json +++ b/advisories/unreviewed/2022/05/GHSA-55xr-4fxj-xx2h/GHSA-55xr-4fxj-xx2h.json @@ -7,12 +7,8 @@ "CVE-2007-4975" ], "details": "Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56cf-wwvg-6crq/GHSA-56cf-wwvg-6crq.json b/advisories/unreviewed/2022/05/GHSA-56cf-wwvg-6crq/GHSA-56cf-wwvg-6crq.json index a61a8a2bde2..fda01c97827 100644 --- a/advisories/unreviewed/2022/05/GHSA-56cf-wwvg-6crq/GHSA-56cf-wwvg-6crq.json +++ b/advisories/unreviewed/2022/05/GHSA-56cf-wwvg-6crq/GHSA-56cf-wwvg-6crq.json @@ -7,12 +7,8 @@ "CVE-2007-5387" ], "details": "PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the c[components] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56q5-h5jc-2hmw/GHSA-56q5-h5jc-2hmw.json b/advisories/unreviewed/2022/05/GHSA-56q5-h5jc-2hmw/GHSA-56q5-h5jc-2hmw.json index c32331ed2d3..924d96f3192 100644 --- a/advisories/unreviewed/2022/05/GHSA-56q5-h5jc-2hmw/GHSA-56q5-h5jc-2hmw.json +++ b/advisories/unreviewed/2022/05/GHSA-56q5-h5jc-2hmw/GHSA-56q5-h5jc-2hmw.json @@ -7,12 +7,8 @@ "CVE-2007-5101" ], "details": "ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-577v-px3j-2j3h/GHSA-577v-px3j-2j3h.json b/advisories/unreviewed/2022/05/GHSA-577v-px3j-2j3h/GHSA-577v-px3j-2j3h.json index 98034ab1368..78f8b1f5176 100644 --- a/advisories/unreviewed/2022/05/GHSA-577v-px3j-2j3h/GHSA-577v-px3j-2j3h.json +++ b/advisories/unreviewed/2022/05/GHSA-577v-px3j-2j3h/GHSA-577v-px3j-2j3h.json @@ -7,12 +7,8 @@ "CVE-2007-5067" ], "details": "Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-583w-wjg4-5w8f/GHSA-583w-wjg4-5w8f.json b/advisories/unreviewed/2022/05/GHSA-583w-wjg4-5w8f/GHSA-583w-wjg4-5w8f.json index bd43d4fdd29..03f2b963fbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-583w-wjg4-5w8f/GHSA-583w-wjg4-5w8f.json +++ b/advisories/unreviewed/2022/05/GHSA-583w-wjg4-5w8f/GHSA-583w-wjg4-5w8f.json @@ -7,12 +7,8 @@ "CVE-2007-4575" ], "details": "HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to \"exposing static java methods.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5936-8jvv-c3xf/GHSA-5936-8jvv-c3xf.json b/advisories/unreviewed/2022/05/GHSA-5936-8jvv-c3xf/GHSA-5936-8jvv-c3xf.json index 5fe18e54f24..d8281f09e0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5936-8jvv-c3xf/GHSA-5936-8jvv-c3xf.json +++ b/advisories/unreviewed/2022/05/GHSA-5936-8jvv-c3xf/GHSA-5936-8jvv-c3xf.json @@ -7,12 +7,8 @@ "CVE-2007-4959" ], "details": "Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59xc-8cmr-8cm3/GHSA-59xc-8cmr-8cm3.json b/advisories/unreviewed/2022/05/GHSA-59xc-8cmr-8cm3/GHSA-59xc-8cmr-8cm3.json index 9e6595efce5..7ee55c835c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-59xc-8cmr-8cm3/GHSA-59xc-8cmr-8cm3.json +++ b/advisories/unreviewed/2022/05/GHSA-59xc-8cmr-8cm3/GHSA-59xc-8cmr-8cm3.json @@ -7,12 +7,8 @@ "CVE-2007-4628" ], "details": "SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5g83-j23j-wqc6/GHSA-5g83-j23j-wqc6.json b/advisories/unreviewed/2022/05/GHSA-5g83-j23j-wqc6/GHSA-5g83-j23j-wqc6.json index f7e28cb3df0..a9c9ffe3c5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g83-j23j-wqc6/GHSA-5g83-j23j-wqc6.json +++ b/advisories/unreviewed/2022/05/GHSA-5g83-j23j-wqc6/GHSA-5g83-j23j-wqc6.json @@ -7,12 +7,8 @@ "CVE-2007-5225" ], "details": "Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hfr-8v33-67jj/GHSA-5hfr-8v33-67jj.json b/advisories/unreviewed/2022/05/GHSA-5hfr-8v33-67jj/GHSA-5hfr-8v33-67jj.json index 9fe4d047323..24b18c6ead9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hfr-8v33-67jj/GHSA-5hfr-8v33-67jj.json +++ b/advisories/unreviewed/2022/05/GHSA-5hfr-8v33-67jj/GHSA-5hfr-8v33-67jj.json @@ -7,12 +7,8 @@ "CVE-2007-5187" ], "details": "SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jfc-q8qh-r73v/GHSA-5jfc-q8qh-r73v.json b/advisories/unreviewed/2022/05/GHSA-5jfc-q8qh-r73v/GHSA-5jfc-q8qh-r73v.json index 183645000dd..2233fb26586 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jfc-q8qh-r73v/GHSA-5jfc-q8qh-r73v.json +++ b/advisories/unreviewed/2022/05/GHSA-5jfc-q8qh-r73v/GHSA-5jfc-q8qh-r73v.json @@ -7,12 +7,8 @@ "CVE-2007-5015" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3) theme_footer.php, (4) browse_footer.php, (5) account_footer.php, or (6) search_footer.php in core/theme/includes/. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess Limit support.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jj7-qjvp-9qf2/GHSA-5jj7-qjvp-9qf2.json b/advisories/unreviewed/2022/05/GHSA-5jj7-qjvp-9qf2/GHSA-5jj7-qjvp-9qf2.json index 7cb6502a486..bd09319a026 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jj7-qjvp-9qf2/GHSA-5jj7-qjvp-9qf2.json +++ b/advisories/unreviewed/2022/05/GHSA-5jj7-qjvp-9qf2/GHSA-5jj7-qjvp-9qf2.json @@ -7,12 +7,8 @@ "CVE-2007-4791" ], "details": "Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jxw-cpwp-467q/GHSA-5jxw-cpwp-467q.json b/advisories/unreviewed/2022/05/GHSA-5jxw-cpwp-467q/GHSA-5jxw-cpwp-467q.json index 021542456d1..213c71ac377 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jxw-cpwp-467q/GHSA-5jxw-cpwp-467q.json +++ b/advisories/unreviewed/2022/05/GHSA-5jxw-cpwp-467q/GHSA-5jxw-cpwp-467q.json @@ -7,12 +7,8 @@ "CVE-2007-4599" ], "details": "Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mgp-v92x-h349/GHSA-5mgp-v92x-h349.json b/advisories/unreviewed/2022/05/GHSA-5mgp-v92x-h349/GHSA-5mgp-v92x-h349.json index 638cb5d7ca0..ff5e392bec2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mgp-v92x-h349/GHSA-5mgp-v92x-h349.json +++ b/advisories/unreviewed/2022/05/GHSA-5mgp-v92x-h349/GHSA-5mgp-v92x-h349.json @@ -7,12 +7,8 @@ "CVE-2007-5378" ], "details": "Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q2v-rq3q-xc6m/GHSA-5q2v-rq3q-xc6m.json b/advisories/unreviewed/2022/05/GHSA-5q2v-rq3q-xc6m/GHSA-5q2v-rq3q-xc6m.json index 059bfc8bfd9..1632936fe6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q2v-rq3q-xc6m/GHSA-5q2v-rq3q-xc6m.json +++ b/advisories/unreviewed/2022/05/GHSA-5q2v-rq3q-xc6m/GHSA-5q2v-rq3q-xc6m.json @@ -7,12 +7,8 @@ "CVE-2007-5186" ], "details": "PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter, a different vector than CVE-2006-5497. NOTE: this issue was disputed, but the dispute was retracted after additional analysis.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q38-h7gf-fmjx/GHSA-5q38-h7gf-fmjx.json b/advisories/unreviewed/2022/05/GHSA-5q38-h7gf-fmjx/GHSA-5q38-h7gf-fmjx.json index 02711497321..f69d4265321 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q38-h7gf-fmjx/GHSA-5q38-h7gf-fmjx.json +++ b/advisories/unreviewed/2022/05/GHSA-5q38-h7gf-fmjx/GHSA-5q38-h7gf-fmjx.json @@ -7,12 +7,8 @@ "CVE-2007-5338" ], "details": "Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -212,9 +208,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qhj-mc5r-v576/GHSA-5qhj-mc5r-v576.json b/advisories/unreviewed/2022/05/GHSA-5qhj-mc5r-v576/GHSA-5qhj-mc5r-v576.json index d861f665dcf..8740e774912 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qhj-mc5r-v576/GHSA-5qhj-mc5r-v576.json +++ b/advisories/unreviewed/2022/05/GHSA-5qhj-mc5r-v576/GHSA-5qhj-mc5r-v576.json @@ -7,12 +7,8 @@ "CVE-2007-4748" ], "details": "Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qwc-vr8c-3fj4/GHSA-5qwc-vr8c-3fj4.json b/advisories/unreviewed/2022/05/GHSA-5qwc-vr8c-3fj4/GHSA-5qwc-vr8c-3fj4.json index 8251f0a3fc2..0fc24993bfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qwc-vr8c-3fj4/GHSA-5qwc-vr8c-3fj4.json +++ b/advisories/unreviewed/2022/05/GHSA-5qwc-vr8c-3fj4/GHSA-5qwc-vr8c-3fj4.json @@ -7,12 +7,8 @@ "CVE-2007-4538" ], "details": "email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r22-jh36-pj45/GHSA-5r22-jh36-pj45.json b/advisories/unreviewed/2022/05/GHSA-5r22-jh36-pj45/GHSA-5r22-jh36-pj45.json index 3550a4e912c..191873450fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r22-jh36-pj45/GHSA-5r22-jh36-pj45.json +++ b/advisories/unreviewed/2022/05/GHSA-5r22-jh36-pj45/GHSA-5r22-jh36-pj45.json @@ -7,12 +7,8 @@ "CVE-2007-5085" ], "details": "Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain \"access to Geronimo internals\" via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r5q-hrrj-fj38/GHSA-5r5q-hrrj-fj38.json b/advisories/unreviewed/2022/05/GHSA-5r5q-hrrj-fj38/GHSA-5r5q-hrrj-fj38.json index 0ce58dd852a..d9a8ba3225f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r5q-hrrj-fj38/GHSA-5r5q-hrrj-fj38.json +++ b/advisories/unreviewed/2022/05/GHSA-5r5q-hrrj-fj38/GHSA-5r5q-hrrj-fj38.json @@ -7,12 +7,8 @@ "CVE-2007-4645" ], "details": "SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2006-1108.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5rhr-mwvh-qm46/GHSA-5rhr-mwvh-qm46.json b/advisories/unreviewed/2022/05/GHSA-5rhr-mwvh-qm46/GHSA-5rhr-mwvh-qm46.json index b087318c093..4d5f3e27f67 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rhr-mwvh-qm46/GHSA-5rhr-mwvh-qm46.json +++ b/advisories/unreviewed/2022/05/GHSA-5rhr-mwvh-qm46/GHSA-5rhr-mwvh-qm46.json @@ -7,12 +7,8 @@ "CVE-2007-4926" ], "details": "The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v3c-45g9-44rq/GHSA-5v3c-45g9-44rq.json b/advisories/unreviewed/2022/05/GHSA-5v3c-45g9-44rq/GHSA-5v3c-45g9-44rq.json index f3292901bf4..f5fcb68fdb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v3c-45g9-44rq/GHSA-5v3c-45g9-44rq.json +++ b/advisories/unreviewed/2022/05/GHSA-5v3c-45g9-44rq/GHSA-5v3c-45g9-44rq.json @@ -7,12 +7,8 @@ "CVE-2007-5017" ], "details": "Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vpf-j7g9-25wc/GHSA-5vpf-j7g9-25wc.json b/advisories/unreviewed/2022/05/GHSA-5vpf-j7g9-25wc/GHSA-5vpf-j7g9-25wc.json index 874e1ff0428..2bee2b2f567 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vpf-j7g9-25wc/GHSA-5vpf-j7g9-25wc.json +++ b/advisories/unreviewed/2022/05/GHSA-5vpf-j7g9-25wc/GHSA-5vpf-j7g9-25wc.json @@ -7,12 +7,8 @@ "CVE-2007-4641" ], "details": "Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w2h-wvm2-7fx8/GHSA-5w2h-wvm2-7fx8.json b/advisories/unreviewed/2022/05/GHSA-5w2h-wvm2-7fx8/GHSA-5w2h-wvm2-7fx8.json index 5c7efe65867..948deda72be 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w2h-wvm2-7fx8/GHSA-5w2h-wvm2-7fx8.json +++ b/advisories/unreviewed/2022/05/GHSA-5w2h-wvm2-7fx8/GHSA-5w2h-wvm2-7fx8.json @@ -7,12 +7,8 @@ "CVE-2007-4617" ], "details": "Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attackers to cause a denial of service (server thread hang) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wjr-7h39-qr5r/GHSA-5wjr-7h39-qr5r.json b/advisories/unreviewed/2022/05/GHSA-5wjr-7h39-qr5r/GHSA-5wjr-7h39-qr5r.json index 27706d11c08..ff831205fed 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wjr-7h39-qr5r/GHSA-5wjr-7h39-qr5r.json +++ b/advisories/unreviewed/2022/05/GHSA-5wjr-7h39-qr5r/GHSA-5wjr-7h39-qr5r.json @@ -7,12 +7,8 @@ "CVE-2007-5392" ], "details": "Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xrf-9rc2-jr45/GHSA-5xrf-9rc2-jr45.json b/advisories/unreviewed/2022/05/GHSA-5xrf-9rc2-jr45/GHSA-5xrf-9rc2-jr45.json index 29e1f734b0c..5d97f8993e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xrf-9rc2-jr45/GHSA-5xrf-9rc2-jr45.json +++ b/advisories/unreviewed/2022/05/GHSA-5xrf-9rc2-jr45/GHSA-5xrf-9rc2-jr45.json @@ -7,12 +7,8 @@ "CVE-2007-5117" ], "details": "Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-625q-q3gx-4v6j/GHSA-625q-q3gx-4v6j.json b/advisories/unreviewed/2022/05/GHSA-625q-q3gx-4v6j/GHSA-625q-q3gx-4v6j.json index 43e16bfa671..2776d455c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-625q-q3gx-4v6j/GHSA-625q-q3gx-4v6j.json +++ b/advisories/unreviewed/2022/05/GHSA-625q-q3gx-4v6j/GHSA-625q-q3gx-4v6j.json @@ -7,12 +7,8 @@ "CVE-2007-4964" ], "details": "WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62hc-q3qg-gmvg/GHSA-62hc-q3qg-gmvg.json b/advisories/unreviewed/2022/05/GHSA-62hc-q3qg-gmvg/GHSA-62hc-q3qg-gmvg.json index 156d7fe230a..bc467fc6789 100644 --- a/advisories/unreviewed/2022/05/GHSA-62hc-q3qg-gmvg/GHSA-62hc-q3qg-gmvg.json +++ b/advisories/unreviewed/2022/05/GHSA-62hc-q3qg-gmvg/GHSA-62hc-q3qg-gmvg.json @@ -7,12 +7,8 @@ "CVE-2007-4784" ], "details": "The setlocale function in PHP before 5.2.4 allows context-dependent attackers to cause a denial of service (application crash) via a long string in the locale parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62qj-3f3w-pcwh/GHSA-62qj-3f3w-pcwh.json b/advisories/unreviewed/2022/05/GHSA-62qj-3f3w-pcwh/GHSA-62qj-3f3w-pcwh.json index 3076c67da24..497289d0d6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-62qj-3f3w-pcwh/GHSA-62qj-3f3w-pcwh.json +++ b/advisories/unreviewed/2022/05/GHSA-62qj-3f3w-pcwh/GHSA-62qj-3f3w-pcwh.json @@ -7,12 +7,8 @@ "CVE-2007-5022" ], "details": "Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using \"server-initiated prompted scheduling,\" allows remote attackers to read a client's data, aka IC53616.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63cg-c3w8-mfh2/GHSA-63cg-c3w8-mfh2.json b/advisories/unreviewed/2022/05/GHSA-63cg-c3w8-mfh2/GHSA-63cg-c3w8-mfh2.json index f30aa790bb7..beb001ce92b 100644 --- a/advisories/unreviewed/2022/05/GHSA-63cg-c3w8-mfh2/GHSA-63cg-c3w8-mfh2.json +++ b/advisories/unreviewed/2022/05/GHSA-63cg-c3w8-mfh2/GHSA-63cg-c3w8-mfh2.json @@ -7,12 +7,8 @@ "CVE-2007-4532" ], "details": "Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63fv-84qx-hhxv/GHSA-63fv-84qx-hhxv.json b/advisories/unreviewed/2022/05/GHSA-63fv-84qx-hhxv/GHSA-63fv-84qx-hhxv.json index 03180d1e59f..dc1aa9d6678 100644 --- a/advisories/unreviewed/2022/05/GHSA-63fv-84qx-hhxv/GHSA-63fv-84qx-hhxv.json +++ b/advisories/unreviewed/2022/05/GHSA-63fv-84qx-hhxv/GHSA-63fv-84qx-hhxv.json @@ -7,12 +7,8 @@ "CVE-2007-5213" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-642r-w5cm-5w9c/GHSA-642r-w5cm-5w9c.json b/advisories/unreviewed/2022/05/GHSA-642r-w5cm-5w9c/GHSA-642r-w5cm-5w9c.json index 6b8663b8715..721201ea78b 100644 --- a/advisories/unreviewed/2022/05/GHSA-642r-w5cm-5w9c/GHSA-642r-w5cm-5w9c.json +++ b/advisories/unreviewed/2022/05/GHSA-642r-w5cm-5w9c/GHSA-642r-w5cm-5w9c.json @@ -7,12 +7,8 @@ "CVE-2007-5082" ], "details": "Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands with certain opcodes, related to missing validation of a length parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64rq-46g4-hjmc/GHSA-64rq-46g4-hjmc.json b/advisories/unreviewed/2022/05/GHSA-64rq-46g4-hjmc/GHSA-64rq-46g4-hjmc.json index 0a0f52f0f8e..7d5cac59b16 100644 --- a/advisories/unreviewed/2022/05/GHSA-64rq-46g4-hjmc/GHSA-64rq-46g4-hjmc.json +++ b/advisories/unreviewed/2022/05/GHSA-64rq-46g4-hjmc/GHSA-64rq-46g4-hjmc.json @@ -7,12 +7,8 @@ "CVE-2007-5236" ], "details": "Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64x7-xw3h-6782/GHSA-64x7-xw3h-6782.json b/advisories/unreviewed/2022/05/GHSA-64x7-xw3h-6782/GHSA-64x7-xw3h-6782.json index 791b6146398..0ed7c4acfab 100644 --- a/advisories/unreviewed/2022/05/GHSA-64x7-xw3h-6782/GHSA-64x7-xw3h-6782.json +++ b/advisories/unreviewed/2022/05/GHSA-64x7-xw3h-6782/GHSA-64x7-xw3h-6782.json @@ -7,12 +7,8 @@ "CVE-2007-4720" ], "details": "Unspecified vulnerability in the Shared Trace Service in Hitachi JP1/Cm2/Network Node Manager (NNM) 07-10 through 07-10-05, and NNM Starter Edition Enterprise and 250 08-00 through 08-10, allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-657q-86jr-x2g6/GHSA-657q-86jr-x2g6.json b/advisories/unreviewed/2022/05/GHSA-657q-86jr-x2g6/GHSA-657q-86jr-x2g6.json index fecefd1f3e9..7b07f5ca660 100644 --- a/advisories/unreviewed/2022/05/GHSA-657q-86jr-x2g6/GHSA-657q-86jr-x2g6.json +++ b/advisories/unreviewed/2022/05/GHSA-657q-86jr-x2g6/GHSA-657q-86jr-x2g6.json @@ -7,12 +7,8 @@ "CVE-2007-4742" ], "details": "Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-657x-xg3w-fxx6/GHSA-657x-xg3w-fxx6.json b/advisories/unreviewed/2022/05/GHSA-657x-xg3w-fxx6/GHSA-657x-xg3w-fxx6.json index 24dac98aee0..ed2ab3c0efb 100644 --- a/advisories/unreviewed/2022/05/GHSA-657x-xg3w-fxx6/GHSA-657x-xg3w-fxx6.json +++ b/advisories/unreviewed/2022/05/GHSA-657x-xg3w-fxx6/GHSA-657x-xg3w-fxx6.json @@ -7,12 +7,8 @@ "CVE-2007-4752" ], "details": "ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65hv-4q6g-x7mh/GHSA-65hv-4q6g-x7mh.json b/advisories/unreviewed/2022/05/GHSA-65hv-4q6g-x7mh/GHSA-65hv-4q6g-x7mh.json index 86cb8fcfd03..7f7faa4ee5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-65hv-4q6g-x7mh/GHSA-65hv-4q6g-x7mh.json +++ b/advisories/unreviewed/2022/05/GHSA-65hv-4q6g-x7mh/GHSA-65hv-4q6g-x7mh.json @@ -7,12 +7,8 @@ "CVE-2007-5009" ], "details": "PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66vv-jcch-hx6x/GHSA-66vv-jcch-hx6x.json b/advisories/unreviewed/2022/05/GHSA-66vv-jcch-hx6x/GHSA-66vv-jcch-hx6x.json index 8099981ef15..6d013d8a978 100644 --- a/advisories/unreviewed/2022/05/GHSA-66vv-jcch-hx6x/GHSA-66vv-jcch-hx6x.json +++ b/advisories/unreviewed/2022/05/GHSA-66vv-jcch-hx6x/GHSA-66vv-jcch-hx6x.json @@ -7,12 +7,8 @@ "CVE-2007-4769" ], "details": "The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67qq-pvr4-m3rj/GHSA-67qq-pvr4-m3rj.json b/advisories/unreviewed/2022/05/GHSA-67qq-pvr4-m3rj/GHSA-67qq-pvr4-m3rj.json index 706bae9fe94..dfa24468082 100644 --- a/advisories/unreviewed/2022/05/GHSA-67qq-pvr4-m3rj/GHSA-67qq-pvr4-m3rj.json +++ b/advisories/unreviewed/2022/05/GHSA-67qq-pvr4-m3rj/GHSA-67qq-pvr4-m3rj.json @@ -7,12 +7,8 @@ "CVE-2007-4832" ], "details": "Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-686m-vhgm-w87p/GHSA-686m-vhgm-w87p.json b/advisories/unreviewed/2022/05/GHSA-686m-vhgm-w87p/GHSA-686m-vhgm-w87p.json index 6bf314aa553..fc83981b5a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-686m-vhgm-w87p/GHSA-686m-vhgm-w87p.json +++ b/advisories/unreviewed/2022/05/GHSA-686m-vhgm-w87p/GHSA-686m-vhgm-w87p.json @@ -7,12 +7,8 @@ "CVE-2007-4592" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68cr-62wm-28h7/GHSA-68cr-62wm-28h7.json b/advisories/unreviewed/2022/05/GHSA-68cr-62wm-28h7/GHSA-68cr-62wm-28h7.json index b1a1be6d3cb..9bd97a7fb39 100644 --- a/advisories/unreviewed/2022/05/GHSA-68cr-62wm-28h7/GHSA-68cr-62wm-28h7.json +++ b/advisories/unreviewed/2022/05/GHSA-68cr-62wm-28h7/GHSA-68cr-62wm-28h7.json @@ -7,12 +7,8 @@ "CVE-2007-4947" ], "details": "Multiple PHP remote file inclusion vulnerabilities in myphpPagetool 0.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the ptinclude parameter to (1) help1.php, (2) help2.php, (3) help3.php, (4) help4.php, (5) help5.php, (6) help6.php, (7) help7.php, (7) help8.php, (8) help9.php, or (10) index.php in doc/admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69wm-x2jq-jg58/GHSA-69wm-x2jq-jg58.json b/advisories/unreviewed/2022/05/GHSA-69wm-x2jq-jg58/GHSA-69wm-x2jq-jg58.json index b532b294c80..a944132b3e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-69wm-x2jq-jg58/GHSA-69wm-x2jq-jg58.json +++ b/advisories/unreviewed/2022/05/GHSA-69wm-x2jq-jg58/GHSA-69wm-x2jq-jg58.json @@ -7,12 +7,8 @@ "CVE-2007-5371" ], "details": "Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (1) documentDirty or (2) modVariables parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cfv-xhhx-2j6w/GHSA-6cfv-xhhx-2j6w.json b/advisories/unreviewed/2022/05/GHSA-6cfv-xhhx-2j6w/GHSA-6cfv-xhhx-2j6w.json index ef59def7078..aedcfd656f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cfv-xhhx-2j6w/GHSA-6cfv-xhhx-2j6w.json +++ b/advisories/unreviewed/2022/05/GHSA-6cfv-xhhx-2j6w/GHSA-6cfv-xhhx-2j6w.json @@ -7,12 +7,8 @@ "CVE-2007-4616" ], "details": "The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might allow remote attackers to intercept communications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6ghv-vg3v-4jhv/GHSA-6ghv-vg3v-4jhv.json b/advisories/unreviewed/2022/05/GHSA-6ghv-vg3v-4jhv/GHSA-6ghv-vg3v-4jhv.json index 9b9ff191e8f..3a01a0683a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ghv-vg3v-4jhv/GHSA-6ghv-vg3v-4jhv.json +++ b/advisories/unreviewed/2022/05/GHSA-6ghv-vg3v-4jhv/GHSA-6ghv-vg3v-4jhv.json @@ -7,12 +7,8 @@ "CVE-2007-5136" ], "details": "Cross-site scripting (XSS) vulnerability in DFD Cart 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gww-g3x7-j6w4/GHSA-6gww-g3x7-j6w4.json b/advisories/unreviewed/2022/05/GHSA-6gww-g3x7-j6w4/GHSA-6gww-g3x7-j6w4.json index e64aab3b981..7c932925c5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gww-g3x7-j6w4/GHSA-6gww-g3x7-j6w4.json +++ b/advisories/unreviewed/2022/05/GHSA-6gww-g3x7-j6w4/GHSA-6gww-g3x7-j6w4.json @@ -7,12 +7,8 @@ "CVE-2007-5373" ], "details": "ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepassword function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6h87-2fpc-x688/GHSA-6h87-2fpc-x688.json b/advisories/unreviewed/2022/05/GHSA-6h87-2fpc-x688/GHSA-6h87-2fpc-x688.json index 549446fde2d..7eef30a1baf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h87-2fpc-x688/GHSA-6h87-2fpc-x688.json +++ b/advisories/unreviewed/2022/05/GHSA-6h87-2fpc-x688/GHSA-6h87-2fpc-x688.json @@ -7,12 +7,8 @@ "CVE-2007-4643" ], "details": "Integer underflow in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a PKT_CHAT packet with a data length less than 3, which triggers an erroneous malloc, possibly related to the Sv_HandlePacket function in sv_main.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hvh-8rrq-gc2g/GHSA-6hvh-8rrq-gc2g.json b/advisories/unreviewed/2022/05/GHSA-6hvh-8rrq-gc2g/GHSA-6hvh-8rrq-gc2g.json index cb4540923ea..30ae708e0e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hvh-8rrq-gc2g/GHSA-6hvh-8rrq-gc2g.json +++ b/advisories/unreviewed/2022/05/GHSA-6hvh-8rrq-gc2g/GHSA-6hvh-8rrq-gc2g.json @@ -7,12 +7,8 @@ "CVE-2007-4881" ], "details": "SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hwr-3g38-6rhg/GHSA-6hwr-3g38-6rhg.json b/advisories/unreviewed/2022/05/GHSA-6hwr-3g38-6rhg/GHSA-6hwr-3g38-6rhg.json index 7e2bb73bf84..bab96d31eb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hwr-3g38-6rhg/GHSA-6hwr-3g38-6rhg.json +++ b/advisories/unreviewed/2022/05/GHSA-6hwr-3g38-6rhg/GHSA-6hwr-3g38-6rhg.json @@ -7,12 +7,8 @@ "CVE-2007-4555" ], "details": "Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j59-rqw9-r684/GHSA-6j59-rqw9-r684.json b/advisories/unreviewed/2022/05/GHSA-6j59-rqw9-r684/GHSA-6j59-rqw9-r684.json index a4d896254d7..1319b9de347 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j59-rqw9-r684/GHSA-6j59-rqw9-r684.json +++ b/advisories/unreviewed/2022/05/GHSA-6j59-rqw9-r684/GHSA-6j59-rqw9-r684.json @@ -7,12 +7,8 @@ "CVE-2007-4930" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m4m-fpvv-rx8g/GHSA-6m4m-fpvv-rx8g.json b/advisories/unreviewed/2022/05/GHSA-6m4m-fpvv-rx8g/GHSA-6m4m-fpvv-rx8g.json index 2f52eaab7ae..3324517b23f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m4m-fpvv-rx8g/GHSA-6m4m-fpvv-rx8g.json +++ b/advisories/unreviewed/2022/05/GHSA-6m4m-fpvv-rx8g/GHSA-6m4m-fpvv-rx8g.json @@ -7,12 +7,8 @@ "CVE-2007-4962" ], "details": "Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged for code execution by writing to a Startup folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mrg-72v5-5vgp/GHSA-6mrg-72v5-5vgp.json b/advisories/unreviewed/2022/05/GHSA-6mrg-72v5-5vgp/GHSA-6mrg-72v5-5vgp.json index d177365a988..7e6820ceb89 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mrg-72v5-5vgp/GHSA-6mrg-72v5-5vgp.json +++ b/advisories/unreviewed/2022/05/GHSA-6mrg-72v5-5vgp/GHSA-6mrg-72v5-5vgp.json @@ -7,12 +7,8 @@ "CVE-2007-4927" ], "details": "axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p84-8gmv-pxfx/GHSA-6p84-8gmv-pxfx.json b/advisories/unreviewed/2022/05/GHSA-6p84-8gmv-pxfx/GHSA-6p84-8gmv-pxfx.json index 7d2c709f464..02e74365b53 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p84-8gmv-pxfx/GHSA-6p84-8gmv-pxfx.json +++ b/advisories/unreviewed/2022/05/GHSA-6p84-8gmv-pxfx/GHSA-6p84-8gmv-pxfx.json @@ -7,12 +7,8 @@ "CVE-2007-5053" ], "details": "Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php; or a URL in the language_home parameter to (3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, or (7) links/submit_links.php in modules/; related to missing checks in (a) modules/moduleSec.php and (b) include/includeSec.php for inclusion of certain URLs, as demonstrated by an ftps:// URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q3w-rp64-hvgj/GHSA-6q3w-rp64-hvgj.json b/advisories/unreviewed/2022/05/GHSA-6q3w-rp64-hvgj/GHSA-6q3w-rp64-hvgj.json index f6916bf3704..53f7ea62bff 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q3w-rp64-hvgj/GHSA-6q3w-rp64-hvgj.json +++ b/advisories/unreviewed/2022/05/GHSA-6q3w-rp64-hvgj/GHSA-6q3w-rp64-hvgj.json @@ -7,12 +7,8 @@ "CVE-2007-4676" ], "details": "Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q84-636h-pf7j/GHSA-6q84-636h-pf7j.json b/advisories/unreviewed/2022/05/GHSA-6q84-636h-pf7j/GHSA-6q84-636h-pf7j.json index 9db472a76f3..1d44731e2f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q84-636h-pf7j/GHSA-6q84-636h-pf7j.json +++ b/advisories/unreviewed/2022/05/GHSA-6q84-636h-pf7j/GHSA-6q84-636h-pf7j.json @@ -7,12 +7,8 @@ "CVE-2007-4605" ], "details": "PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1503, CVE-2006-1636, and CVE-2006-1747.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qwj-8q5v-r7mw/GHSA-6qwj-8q5v-r7mw.json b/advisories/unreviewed/2022/05/GHSA-6qwj-8q5v-r7mw/GHSA-6qwj-8q5v-r7mw.json index 228b0b7b15e..63cfa4de154 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qwj-8q5v-r7mw/GHSA-6qwj-8q5v-r7mw.json +++ b/advisories/unreviewed/2022/05/GHSA-6qwj-8q5v-r7mw/GHSA-6qwj-8q5v-r7mw.json @@ -7,12 +7,8 @@ "CVE-2007-4537" ], "details": "Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6r3r-3mxq-rg9f/GHSA-6r3r-3mxq-rg9f.json b/advisories/unreviewed/2022/05/GHSA-6r3r-3mxq-rg9f/GHSA-6r3r-3mxq-rg9f.json index 9677e2655cb..473d6aa91e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r3r-3mxq-rg9f/GHSA-6r3r-3mxq-rg9f.json +++ b/advisories/unreviewed/2022/05/GHSA-6r3r-3mxq-rg9f/GHSA-6r3r-3mxq-rg9f.json @@ -7,12 +7,8 @@ "CVE-2007-5121" ], "details": "Cross-site scripting (XSS) vulnerability in JSPWiki 2.5.139-beta allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to wiki-3/Login.jsp and unspecified other components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rfx-645f-j638/GHSA-6rfx-645f-j638.json b/advisories/unreviewed/2022/05/GHSA-6rfx-645f-j638/GHSA-6rfx-645f-j638.json index 174ad631cb5..8b58424a948 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rfx-645f-j638/GHSA-6rfx-645f-j638.json +++ b/advisories/unreviewed/2022/05/GHSA-6rfx-645f-j638/GHSA-6rfx-645f-j638.json @@ -7,12 +7,8 @@ "CVE-2007-4957" ], "details": "Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a .. (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a .. (dot dot) in the (3) repertoire parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rpr-qxfh-rg9p/GHSA-6rpr-qxfh-rg9p.json b/advisories/unreviewed/2022/05/GHSA-6rpr-qxfh-rg9p/GHSA-6rpr-qxfh-rg9p.json index ec1f48913be..91a34b79b72 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rpr-qxfh-rg9p/GHSA-6rpr-qxfh-rg9p.json +++ b/advisories/unreviewed/2022/05/GHSA-6rpr-qxfh-rg9p/GHSA-6rpr-qxfh-rg9p.json @@ -7,12 +7,8 @@ "CVE-2007-5126" ], "details": "Unspecified vulnerability in the client in Symantec Veritas Backup Exec for Windows Servers 11d has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rr9-c96h-w95q/GHSA-6rr9-c96h-w95q.json b/advisories/unreviewed/2022/05/GHSA-6rr9-c96h-w95q/GHSA-6rr9-c96h-w95q.json index 38823bbb2f3..4bbe2625f60 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rr9-c96h-w95q/GHSA-6rr9-c96h-w95q.json +++ b/advisories/unreviewed/2022/05/GHSA-6rr9-c96h-w95q/GHSA-6rr9-c96h-w95q.json @@ -7,12 +7,8 @@ "CVE-2007-4977" ], "details": "Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vxr-3m6r-hc4v/GHSA-6vxr-3m6r-hc4v.json b/advisories/unreviewed/2022/05/GHSA-6vxr-3m6r-hc4v/GHSA-6vxr-3m6r-hc4v.json index 3fa4c7b4ee5..5fe0d14c8ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vxr-3m6r-hc4v/GHSA-6vxr-3m6r-hc4v.json +++ b/advisories/unreviewed/2022/05/GHSA-6vxr-3m6r-hc4v/GHSA-6vxr-3m6r-hc4v.json @@ -7,12 +7,8 @@ "CVE-2007-4593" ], "details": "Unspecified vulnerability in vstor2-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) via unspecified vectors, as demonstrated by the DC2 test suite, possibly a related issue to CVE-2007-4591. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w9j-rffp-r8p4/GHSA-6w9j-rffp-r8p4.json b/advisories/unreviewed/2022/05/GHSA-6w9j-rffp-r8p4/GHSA-6w9j-rffp-r8p4.json index 64f068e0a84..ead7ad77243 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w9j-rffp-r8p4/GHSA-6w9j-rffp-r8p4.json +++ b/advisories/unreviewed/2022/05/GHSA-6w9j-rffp-r8p4/GHSA-6w9j-rffp-r8p4.json @@ -7,12 +7,8 @@ "CVE-2007-5118" ], "details": "Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x5g-m8wv-w9v6/GHSA-6x5g-m8wv-w9v6.json b/advisories/unreviewed/2022/05/GHSA-6x5g-m8wv-w9v6/GHSA-6x5g-m8wv-w9v6.json index eb0d54b34d7..e07dd106498 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x5g-m8wv-w9v6/GHSA-6x5g-m8wv-w9v6.json +++ b/advisories/unreviewed/2022/05/GHSA-6x5g-m8wv-w9v6/GHSA-6x5g-m8wv-w9v6.json @@ -7,12 +7,8 @@ "CVE-2007-5045" ], "details": "Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox \"-chrome\" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7249-8rm8-q744/GHSA-7249-8rm8-q744.json b/advisories/unreviewed/2022/05/GHSA-7249-8rm8-q744/GHSA-7249-8rm8-q744.json index 8d81bbc011e..6eb9a59a9f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7249-8rm8-q744/GHSA-7249-8rm8-q744.json +++ b/advisories/unreviewed/2022/05/GHSA-7249-8rm8-q744/GHSA-7249-8rm8-q744.json @@ -7,12 +7,8 @@ "CVE-2007-4848" ], "details": "Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72h6-r6c5-hw7h/GHSA-72h6-r6c5-hw7h.json b/advisories/unreviewed/2022/05/GHSA-72h6-r6c5-hw7h/GHSA-72h6-r6c5-hw7h.json index 68134682eba..d4e0db6a5d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-72h6-r6c5-hw7h/GHSA-72h6-r6c5-hw7h.json +++ b/advisories/unreviewed/2022/05/GHSA-72h6-r6c5-hw7h/GHSA-72h6-r6c5-hw7h.json @@ -7,12 +7,8 @@ "CVE-2007-4896" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar] parameter, different vectors than CVE-2007-4711.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-737c-wj7m-pqqr/GHSA-737c-wj7m-pqqr.json b/advisories/unreviewed/2022/05/GHSA-737c-wj7m-pqqr/GHSA-737c-wj7m-pqqr.json index 8e36a6903c8..031fed2a89a 100644 --- a/advisories/unreviewed/2022/05/GHSA-737c-wj7m-pqqr/GHSA-737c-wj7m-pqqr.json +++ b/advisories/unreviewed/2022/05/GHSA-737c-wj7m-pqqr/GHSA-737c-wj7m-pqqr.json @@ -7,12 +7,8 @@ "CVE-2007-4730" ], "details": "Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74j2-36vh-4f5f/GHSA-74j2-36vh-4f5f.json b/advisories/unreviewed/2022/05/GHSA-74j2-36vh-4f5f/GHSA-74j2-36vh-4f5f.json index 4f3dba19b53..86f181e62ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-74j2-36vh-4f5f/GHSA-74j2-36vh-4f5f.json +++ b/advisories/unreviewed/2022/05/GHSA-74j2-36vh-4f5f/GHSA-74j2-36vh-4f5f.json @@ -7,12 +7,8 @@ "CVE-2007-5226" ], "details": "irc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a NULL pointer dereference, as demonstrated using a blank /me message from irssi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-767f-2g4f-6vf3/GHSA-767f-2g4f-6vf3.json b/advisories/unreviewed/2022/05/GHSA-767f-2g4f-6vf3/GHSA-767f-2g4f-6vf3.json index ba41157d4ee..cc548ef6208 100644 --- a/advisories/unreviewed/2022/05/GHSA-767f-2g4f-6vf3/GHSA-767f-2g4f-6vf3.json +++ b/advisories/unreviewed/2022/05/GHSA-767f-2g4f-6vf3/GHSA-767f-2g4f-6vf3.json @@ -7,12 +7,8 @@ "CVE-2007-5096" ], "details": "PHP remote file inclusion vulnerability in modules/webmail2/inc/rfc822.php in guanxiCRM Business Solution 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the webmail2_inc_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78gp-g683-v26p/GHSA-78gp-g683-v26p.json b/advisories/unreviewed/2022/05/GHSA-78gp-g683-v26p/GHSA-78gp-g683-v26p.json index d3a3fd7ff8d..b836f10d32b 100644 --- a/advisories/unreviewed/2022/05/GHSA-78gp-g683-v26p/GHSA-78gp-g683-v26p.json +++ b/advisories/unreviewed/2022/05/GHSA-78gp-g683-v26p/GHSA-78gp-g683-v26p.json @@ -7,12 +7,8 @@ "CVE-2007-4771" ], "details": "Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -180,9 +176,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78jp-pvx9-93px/GHSA-78jp-pvx9-93px.json b/advisories/unreviewed/2022/05/GHSA-78jp-pvx9-93px/GHSA-78jp-pvx9-93px.json index 9b7e11591cc..a349790da5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-78jp-pvx9-93px/GHSA-78jp-pvx9-93px.json +++ b/advisories/unreviewed/2022/05/GHSA-78jp-pvx9-93px/GHSA-78jp-pvx9-93px.json @@ -7,12 +7,8 @@ "CVE-2007-4656" ], "details": "backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7943-xmwh-4642/GHSA-7943-xmwh-4642.json b/advisories/unreviewed/2022/05/GHSA-7943-xmwh-4642/GHSA-7943-xmwh-4642.json index 030ac16b79b..d0e633618a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7943-xmwh-4642/GHSA-7943-xmwh-4642.json +++ b/advisories/unreviewed/2022/05/GHSA-7943-xmwh-4642/GHSA-7943-xmwh-4642.json @@ -7,12 +7,8 @@ "CVE-2007-4837" ], "details": "SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79mv-qv9r-5fvw/GHSA-79mv-qv9r-5fvw.json b/advisories/unreviewed/2022/05/GHSA-79mv-qv9r-5fvw/GHSA-79mv-qv9r-5fvw.json index 3b89538d7de..43d1fa474dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-79mv-qv9r-5fvw/GHSA-79mv-qv9r-5fvw.json +++ b/advisories/unreviewed/2022/05/GHSA-79mv-qv9r-5fvw/GHSA-79mv-qv9r-5fvw.json @@ -7,12 +7,8 @@ "CVE-2007-5360" ], "details": "Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c2c-f95x-77w8/GHSA-7c2c-f95x-77w8.json b/advisories/unreviewed/2022/05/GHSA-7c2c-f95x-77w8/GHSA-7c2c-f95x-77w8.json index a4462f06b80..26354752133 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c2c-f95x-77w8/GHSA-7c2c-f95x-77w8.json +++ b/advisories/unreviewed/2022/05/GHSA-7c2c-f95x-77w8/GHSA-7c2c-f95x-77w8.json @@ -7,12 +7,8 @@ "CVE-2007-5054" ], "details": "Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the gsLanguage parameter to (1) search/search.php, (2) poll/inlinepoll.php, (3) poll/showpoll.php, (4) links/showlinks.php, or (5) links/submit_links.php in modules/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fm8-q3qr-gfwv/GHSA-7fm8-q3qr-gfwv.json b/advisories/unreviewed/2022/05/GHSA-7fm8-q3qr-gfwv/GHSA-7fm8-q3qr-gfwv.json index 55b9ede9abe..9a3cc41ebab 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fm8-q3qr-gfwv/GHSA-7fm8-q3qr-gfwv.json +++ b/advisories/unreviewed/2022/05/GHSA-7fm8-q3qr-gfwv/GHSA-7fm8-q3qr-gfwv.json @@ -7,12 +7,8 @@ "CVE-2007-4963" ], "details": "Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of space characters in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged with a separate directory traversal vulnerability to trick a careful user into overwriting arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fpc-57vm-mw85/GHSA-7fpc-57vm-mw85.json b/advisories/unreviewed/2022/05/GHSA-7fpc-57vm-mw85/GHSA-7fpc-57vm-mw85.json index 6ffa5cdd235..0709dcd3491 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fpc-57vm-mw85/GHSA-7fpc-57vm-mw85.json +++ b/advisories/unreviewed/2022/05/GHSA-7fpc-57vm-mw85/GHSA-7fpc-57vm-mw85.json @@ -7,12 +7,8 @@ "CVE-2007-5088" ], "details": "Cross-site scripting (XSS) vulnerability in search/cust_bill_event.cgi in Freeside 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the failed parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g8w-349p-fmqf/GHSA-7g8w-349p-fmqf.json b/advisories/unreviewed/2022/05/GHSA-7g8w-349p-fmqf/GHSA-7g8w-349p-fmqf.json index 2462fa61dce..24c94fb9aeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g8w-349p-fmqf/GHSA-7g8w-349p-fmqf.json +++ b/advisories/unreviewed/2022/05/GHSA-7g8w-349p-fmqf/GHSA-7g8w-349p-fmqf.json @@ -7,12 +7,8 @@ "CVE-2007-5381" ], "details": "Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gc9-rrj7-8wxr/GHSA-7gc9-rrj7-8wxr.json b/advisories/unreviewed/2022/05/GHSA-7gc9-rrj7-8wxr/GHSA-7gc9-rrj7-8wxr.json index 48a99ae87dc..f62d525b380 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gc9-rrj7-8wxr/GHSA-7gc9-rrj7-8wxr.json +++ b/advisories/unreviewed/2022/05/GHSA-7gc9-rrj7-8wxr/GHSA-7gc9-rrj7-8wxr.json @@ -7,12 +7,8 @@ "CVE-2007-5368" ], "details": "Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local users to cause a denial of service (multiple application hang) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7ghw-pvgh-gv4g/GHSA-7ghw-pvgh-gv4g.json b/advisories/unreviewed/2022/05/GHSA-7ghw-pvgh-gv4g/GHSA-7ghw-pvgh-gv4g.json index ac382b63141..83f64826031 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ghw-pvgh-gv4g/GHSA-7ghw-pvgh-gv4g.json +++ b/advisories/unreviewed/2022/05/GHSA-7ghw-pvgh-gv4g/GHSA-7ghw-pvgh-gv4g.json @@ -7,12 +7,8 @@ "CVE-2007-4606" ], "details": "PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1602. NOTE: it is possible that this issue stems from a problem in VWar itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gjw-w759-v9jm/GHSA-7gjw-w759-v9jm.json b/advisories/unreviewed/2022/05/GHSA-7gjw-w759-v9jm/GHSA-7gjw-w759-v9jm.json index 3593c7d8128..938baae0b8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gjw-w759-v9jm/GHSA-7gjw-w759-v9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-7gjw-w759-v9jm/GHSA-7gjw-w759-v9jm.json @@ -7,12 +7,8 @@ "CVE-2007-4942" ], "details": "PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter, a different vector than CVE-2007-4806. NOTE: the provenance of this information is unknown.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7h88-8mg3-r3mp/GHSA-7h88-8mg3-r3mp.json b/advisories/unreviewed/2022/05/GHSA-7h88-8mg3-r3mp/GHSA-7h88-8mg3-r3mp.json index 9c524f6434e..c3ae9d62b9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h88-8mg3-r3mp/GHSA-7h88-8mg3-r3mp.json +++ b/advisories/unreviewed/2022/05/GHSA-7h88-8mg3-r3mp/GHSA-7h88-8mg3-r3mp.json @@ -7,12 +7,8 @@ "CVE-2007-4980" ], "details": "The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jhf-r279-2cjx/GHSA-7jhf-r279-2cjx.json b/advisories/unreviewed/2022/05/GHSA-7jhf-r279-2cjx/GHSA-7jhf-r279-2cjx.json index 282152c8b05..bd5192bf313 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jhf-r279-2cjx/GHSA-7jhf-r279-2cjx.json +++ b/advisories/unreviewed/2022/05/GHSA-7jhf-r279-2cjx/GHSA-7jhf-r279-2cjx.json @@ -7,12 +7,8 @@ "CVE-2007-4615" ], "details": "The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jph-c3pf-xgjr/GHSA-7jph-c3pf-xgjr.json b/advisories/unreviewed/2022/05/GHSA-7jph-c3pf-xgjr/GHSA-7jph-c3pf-xgjr.json index 5133325c964..6ba0290903a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jph-c3pf-xgjr/GHSA-7jph-c3pf-xgjr.json +++ b/advisories/unreviewed/2022/05/GHSA-7jph-c3pf-xgjr/GHSA-7jph-c3pf-xgjr.json @@ -7,12 +7,8 @@ "CVE-2007-4894" ], "details": "Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to \"early database escaping\" and missing validation of \"query string like parameters.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m2r-r8f2-p7vc/GHSA-7m2r-r8f2-p7vc.json b/advisories/unreviewed/2022/05/GHSA-7m2r-r8f2-p7vc/GHSA-7m2r-r8f2-p7vc.json index 1afc57cfe8c..e705670cab3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m2r-r8f2-p7vc/GHSA-7m2r-r8f2-p7vc.json +++ b/advisories/unreviewed/2022/05/GHSA-7m2r-r8f2-p7vc/GHSA-7m2r-r8f2-p7vc.json @@ -7,12 +7,8 @@ "CVE-2007-5335" ], "details": "Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mp6-3h5j-x3x5/GHSA-7mp6-3h5j-x3x5.json b/advisories/unreviewed/2022/05/GHSA-7mp6-3h5j-x3x5/GHSA-7mp6-3h5j-x3x5.json index ad6a14a9f1b..c7b58b61648 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mp6-3h5j-x3x5/GHSA-7mp6-3h5j-x3x5.json +++ b/advisories/unreviewed/2022/05/GHSA-7mp6-3h5j-x3x5/GHSA-7mp6-3h5j-x3x5.json @@ -7,12 +7,8 @@ "CVE-2007-5326" ], "details": "Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mrc-3q8m-ghch/GHSA-7mrc-3q8m-ghch.json b/advisories/unreviewed/2022/05/GHSA-7mrc-3q8m-ghch/GHSA-7mrc-3q8m-ghch.json index 9dd3a704ac9..d98d1d41973 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mrc-3q8m-ghch/GHSA-7mrc-3q8m-ghch.json +++ b/advisories/unreviewed/2022/05/GHSA-7mrc-3q8m-ghch/GHSA-7mrc-3q8m-ghch.json @@ -7,12 +7,8 @@ "CVE-2007-5112" ], "details": "Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers that support remembered (auto-completed) passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pr3-jqjp-q488/GHSA-7pr3-jqjp-q488.json b/advisories/unreviewed/2022/05/GHSA-7pr3-jqjp-q488/GHSA-7pr3-jqjp-q488.json index 156aa59863c..cb494220f2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pr3-jqjp-q488/GHSA-7pr3-jqjp-q488.json +++ b/advisories/unreviewed/2022/05/GHSA-7pr3-jqjp-q488/GHSA-7pr3-jqjp-q488.json @@ -7,12 +7,8 @@ "CVE-2007-4583" ], "details": "Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pwg-fr27-xv9g/GHSA-7pwg-fr27-xv9g.json b/advisories/unreviewed/2022/05/GHSA-7pwg-fr27-xv9g/GHSA-7pwg-fr27-xv9g.json index f7b64375017..b5dc59e670e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pwg-fr27-xv9g/GHSA-7pwg-fr27-xv9g.json +++ b/advisories/unreviewed/2022/05/GHSA-7pwg-fr27-xv9g/GHSA-7pwg-fr27-xv9g.json @@ -7,12 +7,8 @@ "CVE-2007-5177" ], "details": "SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qh9-92w2-gfw9/GHSA-7qh9-92w2-gfw9.json b/advisories/unreviewed/2022/05/GHSA-7qh9-92w2-gfw9/GHSA-7qh9-92w2-gfw9.json index d2aa400fb79..08ad8dfc0e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qh9-92w2-gfw9/GHSA-7qh9-92w2-gfw9.json +++ b/advisories/unreviewed/2022/05/GHSA-7qh9-92w2-gfw9/GHSA-7qh9-92w2-gfw9.json @@ -7,12 +7,8 @@ "CVE-2007-5060" ], "details": "Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qjw-mhgr-v2hx/GHSA-7qjw-mhgr-v2hx.json b/advisories/unreviewed/2022/05/GHSA-7qjw-mhgr-v2hx/GHSA-7qjw-mhgr-v2hx.json index 2ba908898e0..da9a88f74cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qjw-mhgr-v2hx/GHSA-7qjw-mhgr-v2hx.json +++ b/advisories/unreviewed/2022/05/GHSA-7qjw-mhgr-v2hx/GHSA-7qjw-mhgr-v2hx.json @@ -7,12 +7,8 @@ "CVE-2007-5209" ], "details": "Stack-based buffer overflow in DriveLock.exe in CenterTools DriveLock 5.0 allows remote attackers to execute arbitrary code via a long HTTP request to TCP port 6061. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qm2-v5qr-45cg/GHSA-7qm2-v5qr-45cg.json b/advisories/unreviewed/2022/05/GHSA-7qm2-v5qr-45cg/GHSA-7qm2-v5qr-45cg.json index 79efd742e0e..f3e93fd65f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qm2-v5qr-45cg/GHSA-7qm2-v5qr-45cg.json +++ b/advisories/unreviewed/2022/05/GHSA-7qm2-v5qr-45cg/GHSA-7qm2-v5qr-45cg.json @@ -7,12 +7,8 @@ "CVE-2007-5189" ], "details": "Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4) website parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r8p-853r-2hrq/GHSA-7r8p-853r-2hrq.json b/advisories/unreviewed/2022/05/GHSA-7r8p-853r-2hrq/GHSA-7r8p-853r-2hrq.json index 97059de04c4..f37821d9cf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r8p-853r-2hrq/GHSA-7r8p-853r-2hrq.json +++ b/advisories/unreviewed/2022/05/GHSA-7r8p-853r-2hrq/GHSA-7r8p-853r-2hrq.json @@ -7,12 +7,8 @@ "CVE-2007-5210" ], "details": "Arbor Networks Peakflow SP before 3.5.1 patch 14, and 3.6.x before 3.6.1 patch 5, allows remote authenticated users to bypass access restrictions and read or write unspecified data via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rgc-fm6f-m5hp/GHSA-7rgc-fm6f-m5hp.json b/advisories/unreviewed/2022/05/GHSA-7rgc-fm6f-m5hp/GHSA-7rgc-fm6f-m5hp.json index 42fd8f3bc4a..e0037947ffe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rgc-fm6f-m5hp/GHSA-7rgc-fm6f-m5hp.json +++ b/advisories/unreviewed/2022/05/GHSA-7rgc-fm6f-m5hp/GHSA-7rgc-fm6f-m5hp.json @@ -7,12 +7,8 @@ "CVE-2007-5395" ], "details": "Stack-based buffer overflow in the separate_word function in tokenize.c in Link Grammar 4.1b and possibly other versions, as used in AbiWord Link Grammar 4.2.4, allows remote attackers to execute arbitrary code via a long word, as reachable through the separate_sentence function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x34-j27f-hrcf/GHSA-7x34-j27f-hrcf.json b/advisories/unreviewed/2022/05/GHSA-7x34-j27f-hrcf/GHSA-7x34-j27f-hrcf.json index 97ca537c187..b03854d7459 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x34-j27f-hrcf/GHSA-7x34-j27f-hrcf.json +++ b/advisories/unreviewed/2022/05/GHSA-7x34-j27f-hrcf/GHSA-7x34-j27f-hrcf.json @@ -7,12 +7,8 @@ "CVE-2007-5041" ], "details": "G DATA InternetSecurity 2007 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey and (2) NtOpenProcess kernel SSDT hooks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x69-7fj6-rqg6/GHSA-7x69-7fj6-rqg6.json b/advisories/unreviewed/2022/05/GHSA-7x69-7fj6-rqg6/GHSA-7x69-7fj6-rqg6.json index 51044a0e1e1..1f5654acd52 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x69-7fj6-rqg6/GHSA-7x69-7fj6-rqg6.json +++ b/advisories/unreviewed/2022/05/GHSA-7x69-7fj6-rqg6/GHSA-7x69-7fj6-rqg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82vx-g35h-vvp5/GHSA-82vx-g35h-vvp5.json b/advisories/unreviewed/2022/05/GHSA-82vx-g35h-vvp5/GHSA-82vx-g35h-vvp5.json index 8b7d83a7ebe..48c16999ef8 100644 --- a/advisories/unreviewed/2022/05/GHSA-82vx-g35h-vvp5/GHSA-82vx-g35h-vvp5.json +++ b/advisories/unreviewed/2022/05/GHSA-82vx-g35h-vvp5/GHSA-82vx-g35h-vvp5.json @@ -7,12 +7,8 @@ "CVE-2007-5048" ], "details": "Heap-based buffer overflow in Lhaplus before 1.55 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-837m-q839-3678/GHSA-837m-q839-3678.json b/advisories/unreviewed/2022/05/GHSA-837m-q839-3678/GHSA-837m-q839-3678.json index fb193707d2e..fd9ca6f4584 100644 --- a/advisories/unreviewed/2022/05/GHSA-837m-q839-3678/GHSA-837m-q839-3678.json +++ b/advisories/unreviewed/2022/05/GHSA-837m-q839-3678/GHSA-837m-q839-3678.json @@ -7,12 +7,8 @@ "CVE-2007-4802" ], "details": "Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83q2-rwjj-54qx/GHSA-83q2-rwjj-54qx.json b/advisories/unreviewed/2022/05/GHSA-83q2-rwjj-54qx/GHSA-83q2-rwjj-54qx.json index d8335c8a3e9..9ea34c78722 100644 --- a/advisories/unreviewed/2022/05/GHSA-83q2-rwjj-54qx/GHSA-83q2-rwjj-54qx.json +++ b/advisories/unreviewed/2022/05/GHSA-83q2-rwjj-54qx/GHSA-83q2-rwjj-54qx.json @@ -7,12 +7,8 @@ "CVE-2007-4790" ], "details": "Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84j6-5936-c6m5/GHSA-84j6-5936-c6m5.json b/advisories/unreviewed/2022/05/GHSA-84j6-5936-c6m5/GHSA-84j6-5936-c6m5.json index 82acab700a5..4811c54e1b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-84j6-5936-c6m5/GHSA-84j6-5936-c6m5.json +++ b/advisories/unreviewed/2022/05/GHSA-84j6-5936-c6m5/GHSA-84j6-5936-c6m5.json @@ -7,12 +7,8 @@ "CVE-2007-4711" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage, (2) mail, and (3) name parameters in a show action to (a) form.php; the (4) language and (5) anzeigebreite parameters to (b) admin/header.php; and the (6) msg parameter to (c) install.php, different vectors than CVE-2006-0706.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84mm-fgvp-fw92/GHSA-84mm-fgvp-fw92.json b/advisories/unreviewed/2022/05/GHSA-84mm-fgvp-fw92/GHSA-84mm-fgvp-fw92.json index ec4f65d500d..c5302c93127 100644 --- a/advisories/unreviewed/2022/05/GHSA-84mm-fgvp-fw92/GHSA-84mm-fgvp-fw92.json +++ b/advisories/unreviewed/2022/05/GHSA-84mm-fgvp-fw92/GHSA-84mm-fgvp-fw92.json @@ -7,12 +7,8 @@ "CVE-2007-4777" ], "details": "SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85qm-c7q8-mxvh/GHSA-85qm-c7q8-mxvh.json b/advisories/unreviewed/2022/05/GHSA-85qm-c7q8-mxvh/GHSA-85qm-c7q8-mxvh.json index 14d110219fd..35800294cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-85qm-c7q8-mxvh/GHSA-85qm-c7q8-mxvh.json +++ b/advisories/unreviewed/2022/05/GHSA-85qm-c7q8-mxvh/GHSA-85qm-c7q8-mxvh.json @@ -7,12 +7,8 @@ "CVE-2007-4596" ], "details": "The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-867p-v845-fc48/GHSA-867p-v845-fc48.json b/advisories/unreviewed/2022/05/GHSA-867p-v845-fc48/GHSA-867p-v845-fc48.json index 4738ef9a707..f36fcd958c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-867p-v845-fc48/GHSA-867p-v845-fc48.json +++ b/advisories/unreviewed/2022/05/GHSA-867p-v845-fc48/GHSA-867p-v845-fc48.json @@ -7,12 +7,8 @@ "CVE-2007-5133" ], "details": "Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86rv-pvv7-jwp8/GHSA-86rv-pvv7-jwp8.json b/advisories/unreviewed/2022/05/GHSA-86rv-pvv7-jwp8/GHSA-86rv-pvv7-jwp8.json index 8e887550cf5..298e6808501 100644 --- a/advisories/unreviewed/2022/05/GHSA-86rv-pvv7-jwp8/GHSA-86rv-pvv7-jwp8.json +++ b/advisories/unreviewed/2022/05/GHSA-86rv-pvv7-jwp8/GHSA-86rv-pvv7-jwp8.json @@ -7,12 +7,8 @@ "CVE-2007-4560" ], "details": "clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the \"recipient field of sendmail.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8727-gqxc-c8fv/GHSA-8727-gqxc-c8fv.json b/advisories/unreviewed/2022/05/GHSA-8727-gqxc-c8fv/GHSA-8727-gqxc-c8fv.json index e6c49443896..14ea4784b4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8727-gqxc-c8fv/GHSA-8727-gqxc-c8fv.json +++ b/advisories/unreviewed/2022/05/GHSA-8727-gqxc-c8fv/GHSA-8727-gqxc-c8fv.json @@ -7,12 +7,8 @@ "CVE-2007-4535" ], "details": "The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within a certain UDP packet that triggers an assertion error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-876p-mjq3-fwgx/GHSA-876p-mjq3-fwgx.json b/advisories/unreviewed/2022/05/GHSA-876p-mjq3-fwgx/GHSA-876p-mjq3-fwgx.json index 414091c1b6f..1d7d24cb272 100644 --- a/advisories/unreviewed/2022/05/GHSA-876p-mjq3-fwgx/GHSA-876p-mjq3-fwgx.json +++ b/advisories/unreviewed/2022/05/GHSA-876p-mjq3-fwgx/GHSA-876p-mjq3-fwgx.json @@ -7,12 +7,8 @@ "CVE-2007-4747" ], "details": "The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote attackers to perform administrative actions, aka CSCsj31729.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87c6-q52j-wx32/GHSA-87c6-q52j-wx32.json b/advisories/unreviewed/2022/05/GHSA-87c6-q52j-wx32/GHSA-87c6-q52j-wx32.json index bc283e45be6..c348e1d56b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-87c6-q52j-wx32/GHSA-87c6-q52j-wx32.json +++ b/advisories/unreviewed/2022/05/GHSA-87c6-q52j-wx32/GHSA-87c6-q52j-wx32.json @@ -7,12 +7,8 @@ "CVE-2007-4719" ], "details": "SQL injection vulnerability in read.php in 212cafeBoard 6.30 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87jw-wvf5-vq44/GHSA-87jw-wvf5-vq44.json b/advisories/unreviewed/2022/05/GHSA-87jw-wvf5-vq44/GHSA-87jw-wvf5-vq44.json index abaa2589d28..3b3de6de871 100644 --- a/advisories/unreviewed/2022/05/GHSA-87jw-wvf5-vq44/GHSA-87jw-wvf5-vq44.json +++ b/advisories/unreviewed/2022/05/GHSA-87jw-wvf5-vq44/GHSA-87jw-wvf5-vq44.json @@ -7,12 +7,8 @@ "CVE-2007-4578" ], "details": "Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an \"integer cast around\". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87m6-54mv-m2fr/GHSA-87m6-54mv-m2fr.json b/advisories/unreviewed/2022/05/GHSA-87m6-54mv-m2fr/GHSA-87m6-54mv-m2fr.json index 43da078298d..cd4f2efe62b 100644 --- a/advisories/unreviewed/2022/05/GHSA-87m6-54mv-m2fr/GHSA-87m6-54mv-m2fr.json +++ b/advisories/unreviewed/2022/05/GHSA-87m6-54mv-m2fr/GHSA-87m6-54mv-m2fr.json @@ -7,12 +7,8 @@ "CVE-2007-4631" ], "details": "The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-885x-fp24-cx7w/GHSA-885x-fp24-cx7w.json b/advisories/unreviewed/2022/05/GHSA-885x-fp24-cx7w/GHSA-885x-fp24-cx7w.json index 7a7929be3c1..025c6134f0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-885x-fp24-cx7w/GHSA-885x-fp24-cx7w.json +++ b/advisories/unreviewed/2022/05/GHSA-885x-fp24-cx7w/GHSA-885x-fp24-cx7w.json @@ -7,12 +7,8 @@ "CVE-2007-4783" ], "details": "The iconv_substr function in PHP 5.2.4 and earlier allows context-dependent attackers to cause (1) a denial of service (application crash) via a long string in the charset parameter, probably also requiring a long string in the str parameter; or (2) a denial of service (temporary application hang) via a long string in the str parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8877-c39x-fwc7/GHSA-8877-c39x-fwc7.json b/advisories/unreviewed/2022/05/GHSA-8877-c39x-fwc7/GHSA-8877-c39x-fwc7.json index 468569becd0..b74c38bfee2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8877-c39x-fwc7/GHSA-8877-c39x-fwc7.json +++ b/advisories/unreviewed/2022/05/GHSA-8877-c39x-fwc7/GHSA-8877-c39x-fwc7.json @@ -7,12 +7,8 @@ "CVE-2007-5068" ], "details": "SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL commands via the mod parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-887p-hrqh-fpx6/GHSA-887p-hrqh-fpx6.json b/advisories/unreviewed/2022/05/GHSA-887p-hrqh-fpx6/GHSA-887p-hrqh-fpx6.json index 2d560d40fca..85d6dbb8689 100644 --- a/advisories/unreviewed/2022/05/GHSA-887p-hrqh-fpx6/GHSA-887p-hrqh-fpx6.json +++ b/advisories/unreviewed/2022/05/GHSA-887p-hrqh-fpx6/GHSA-887p-hrqh-fpx6.json @@ -7,12 +7,8 @@ "CVE-2007-4763" ], "details": "PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPOF_INCLUDE_PATH parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88qm-qmmh-8xqw/GHSA-88qm-qmmh-8xqw.json b/advisories/unreviewed/2022/05/GHSA-88qm-qmmh-8xqw/GHSA-88qm-qmmh-8xqw.json index 8c294bcf646..a5b8fcd8705 100644 --- a/advisories/unreviewed/2022/05/GHSA-88qm-qmmh-8xqw/GHSA-88qm-qmmh-8xqw.json +++ b/advisories/unreviewed/2022/05/GHSA-88qm-qmmh-8xqw/GHSA-88qm-qmmh-8xqw.json @@ -7,12 +7,8 @@ "CVE-2007-4526" ], "details": "The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89fm-c745-m8wc/GHSA-89fm-c745-m8wc.json b/advisories/unreviewed/2022/05/GHSA-89fm-c745-m8wc/GHSA-89fm-c745-m8wc.json index 6dcc8e380e0..33b27c1db5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-89fm-c745-m8wc/GHSA-89fm-c745-m8wc.json +++ b/advisories/unreviewed/2022/05/GHSA-89fm-c745-m8wc/GHSA-89fm-c745-m8wc.json @@ -7,12 +7,8 @@ "CVE-2007-4470" ], "details": "Multiple stack-based buffer overflows in the Earth Resource Mapping NCSView ActiveX control before 3.4.0.242 in NCSView.dll, as distributed in ER Mapper ECW JPEG 2000 Plug-in before 8.1, allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89hr-m868-h7qm/GHSA-89hr-m868-h7qm.json b/advisories/unreviewed/2022/05/GHSA-89hr-m868-h7qm/GHSA-89hr-m868-h7qm.json index f8eaf2341f2..b55bb988ce9 100644 --- a/advisories/unreviewed/2022/05/GHSA-89hr-m868-h7qm/GHSA-89hr-m868-h7qm.json +++ b/advisories/unreviewed/2022/05/GHSA-89hr-m868-h7qm/GHSA-89hr-m868-h7qm.json @@ -7,12 +7,8 @@ "CVE-2007-4633" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c9q-2qm2-g7xh/GHSA-8c9q-2qm2-g7xh.json b/advisories/unreviewed/2022/05/GHSA-8c9q-2qm2-g7xh/GHSA-8c9q-2qm2-g7xh.json index 44a34ba933a..45615837112 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c9q-2qm2-g7xh/GHSA-8c9q-2qm2-g7xh.json +++ b/advisories/unreviewed/2022/05/GHSA-8c9q-2qm2-g7xh/GHSA-8c9q-2qm2-g7xh.json @@ -7,12 +7,8 @@ "CVE-2007-5013" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Phormer 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) u, (2) p, (3) c, and (4) s parameters, and other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8crg-4vpf-66qq/GHSA-8crg-4vpf-66qq.json b/advisories/unreviewed/2022/05/GHSA-8crg-4vpf-66qq/GHSA-8crg-4vpf-66qq.json index f263515ade0..9e14eddd0fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8crg-4vpf-66qq/GHSA-8crg-4vpf-66qq.json +++ b/advisories/unreviewed/2022/05/GHSA-8crg-4vpf-66qq/GHSA-8crg-4vpf-66qq.json @@ -7,12 +7,8 @@ "CVE-2007-5111" ], "details": "A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (crash) via a string argument to the AddString method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8fr6-p7rj-wmfr/GHSA-8fr6-p7rj-wmfr.json b/advisories/unreviewed/2022/05/GHSA-8fr6-p7rj-wmfr/GHSA-8fr6-p7rj-wmfr.json index 33034368d33..3ab44bf5db4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fr6-p7rj-wmfr/GHSA-8fr6-p7rj-wmfr.json +++ b/advisories/unreviewed/2022/05/GHSA-8fr6-p7rj-wmfr/GHSA-8fr6-p7rj-wmfr.json @@ -7,12 +7,8 @@ "CVE-2007-4727" ], "details": "Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a \"header overflow.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jh7-g9vm-29cw/GHSA-8jh7-g9vm-29cw.json b/advisories/unreviewed/2022/05/GHSA-8jh7-g9vm-29cw/GHSA-8jh7-g9vm-29cw.json index 6b282431bae..ebae825dc79 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jh7-g9vm-29cw/GHSA-8jh7-g9vm-29cw.json +++ b/advisories/unreviewed/2022/05/GHSA-8jh7-g9vm-29cw/GHSA-8jh7-g9vm-29cw.json @@ -7,12 +7,8 @@ "CVE-2007-4708" ], "details": "Format string vulnerability in Address Book in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via the URL handler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jr5-j3c4-59r7/GHSA-8jr5-j3c4-59r7.json b/advisories/unreviewed/2022/05/GHSA-8jr5-j3c4-59r7/GHSA-8jr5-j3c4-59r7.json index f79b7da4bf6..23fd0596678 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jr5-j3c4-59r7/GHSA-8jr5-j3c4-59r7.json +++ b/advisories/unreviewed/2022/05/GHSA-8jr5-j3c4-59r7/GHSA-8jr5-j3c4-59r7.json @@ -7,12 +7,8 @@ "CVE-2007-4680" ], "details": "CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m7p-qrqg-xgvj/GHSA-8m7p-qrqg-xgvj.json b/advisories/unreviewed/2022/05/GHSA-8m7p-qrqg-xgvj/GHSA-8m7p-qrqg-xgvj.json index 052996a56dd..611a0fc8aeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m7p-qrqg-xgvj/GHSA-8m7p-qrqg-xgvj.json +++ b/advisories/unreviewed/2022/05/GHSA-8m7p-qrqg-xgvj/GHSA-8m7p-qrqg-xgvj.json @@ -7,12 +7,8 @@ "CVE-2007-4922" ], "details": "SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php. NOTE: some details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q7q-wh67-pm5j/GHSA-8q7q-wh67-pm5j.json b/advisories/unreviewed/2022/05/GHSA-8q7q-wh67-pm5j/GHSA-8q7q-wh67-pm5j.json index 971d7bc7713..b4bc2b11662 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q7q-wh67-pm5j/GHSA-8q7q-wh67-pm5j.json +++ b/advisories/unreviewed/2022/05/GHSA-8q7q-wh67-pm5j/GHSA-8q7q-wh67-pm5j.json @@ -7,12 +7,8 @@ "CVE-2007-5181" ], "details": "SQL injection vulnerability in detay.asp in Netkamp Emlak Scripti allows remote attackers to execute arbitrary SQL commands via the ilan_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q96-3494-9v8r/GHSA-8q96-3494-9v8r.json b/advisories/unreviewed/2022/05/GHSA-8q96-3494-9v8r/GHSA-8q96-3494-9v8r.json index ae00f8152e0..ec1be3d0528 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q96-3494-9v8r/GHSA-8q96-3494-9v8r.json +++ b/advisories/unreviewed/2022/05/GHSA-8q96-3494-9v8r/GHSA-8q96-3494-9v8r.json @@ -7,12 +7,8 @@ "CVE-2007-5197" ], "details": "Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q99-j5m2-gvjc/GHSA-8q99-j5m2-gvjc.json b/advisories/unreviewed/2022/05/GHSA-8q99-j5m2-gvjc/GHSA-8q99-j5m2-gvjc.json index 4b523d1696d..51bc7e57f56 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q99-j5m2-gvjc/GHSA-8q99-j5m2-gvjc.json +++ b/advisories/unreviewed/2022/05/GHSA-8q99-j5m2-gvjc/GHSA-8q99-j5m2-gvjc.json @@ -7,12 +7,8 @@ "CVE-2007-4850" ], "details": "curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \\x00 sequence, a different vulnerability than CVE-2006-2563.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -132,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r4q-vv4v-f978/GHSA-8r4q-vv4v-f978.json b/advisories/unreviewed/2022/05/GHSA-8r4q-vv4v-f978/GHSA-8r4q-vv4v-f978.json index fd758f2f0cf..a1e78c4f189 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r4q-vv4v-f978/GHSA-8r4q-vv4v-f978.json +++ b/advisories/unreviewed/2022/05/GHSA-8r4q-vv4v-f978/GHSA-8r4q-vv4v-f978.json @@ -7,12 +7,8 @@ "CVE-2007-4987" ], "details": "Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\\0' character to an out-of-bounds address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r9m-gfwr-xx99/GHSA-8r9m-gfwr-xx99.json b/advisories/unreviewed/2022/05/GHSA-8r9m-gfwr-xx99/GHSA-8r9m-gfwr-xx99.json index 962aa242333..c7c077c87fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r9m-gfwr-xx99/GHSA-8r9m-gfwr-xx99.json +++ b/advisories/unreviewed/2022/05/GHSA-8r9m-gfwr-xx99/GHSA-8r9m-gfwr-xx99.json @@ -7,12 +7,8 @@ "CVE-2007-4734" ], "details": "Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rjr-f7jg-55r6/GHSA-8rjr-f7jg-55r6.json b/advisories/unreviewed/2022/05/GHSA-8rjr-f7jg-55r6/GHSA-8rjr-f7jg-55r6.json index 941e4f63231..1bafe61f038 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rjr-f7jg-55r6/GHSA-8rjr-f7jg-55r6.json +++ b/advisories/unreviewed/2022/05/GHSA-8rjr-f7jg-55r6/GHSA-8rjr-f7jg-55r6.json @@ -7,12 +7,8 @@ "CVE-2007-4581" ], "details": "SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL commands via the show parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rpc-f5pg-452p/GHSA-8rpc-f5pg-452p.json b/advisories/unreviewed/2022/05/GHSA-8rpc-f5pg-452p/GHSA-8rpc-f5pg-452p.json index 98256683ac2..b0f6ac66dfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rpc-f5pg-452p/GHSA-8rpc-f5pg-452p.json +++ b/advisories/unreviewed/2022/05/GHSA-8rpc-f5pg-452p/GHSA-8rpc-f5pg-452p.json @@ -7,12 +7,8 @@ "CVE-2007-4553" ], "details": "The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8vgw-qr5q-9wv4/GHSA-8vgw-qr5q-9wv4.json b/advisories/unreviewed/2022/05/GHSA-8vgw-qr5q-9wv4/GHSA-8vgw-qr5q-9wv4.json index b5e92a8c073..09444ca5b48 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vgw-qr5q-9wv4/GHSA-8vgw-qr5q-9wv4.json +++ b/advisories/unreviewed/2022/05/GHSA-8vgw-qr5q-9wv4/GHSA-8vgw-qr5q-9wv4.json @@ -7,12 +7,8 @@ "CVE-2007-5020" ], "details": "Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x9c-m5v9-8766/GHSA-8x9c-m5v9-8766.json b/advisories/unreviewed/2022/05/GHSA-8x9c-m5v9-8766/GHSA-8x9c-m5v9-8766.json index f351a8f8782..5fc28fdb2e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x9c-m5v9-8766/GHSA-8x9c-m5v9-8766.json +++ b/advisories/unreviewed/2022/05/GHSA-8x9c-m5v9-8766/GHSA-8x9c-m5v9-8766.json @@ -7,12 +7,8 @@ "CVE-2007-4565" ], "details": "sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by refusing certain warning messages that are sent over SMTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xmm-2h7f-547x/GHSA-8xmm-2h7f-547x.json b/advisories/unreviewed/2022/05/GHSA-8xmm-2h7f-547x/GHSA-8xmm-2h7f-547x.json index 53ec5bf6ccf..8c26eae3bb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xmm-2h7f-547x/GHSA-8xmm-2h7f-547x.json +++ b/advisories/unreviewed/2022/05/GHSA-8xmm-2h7f-547x/GHSA-8xmm-2h7f-547x.json @@ -7,12 +7,8 @@ "CVE-2007-4873" ], "details": "SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93c8-42xq-w5vw/GHSA-93c8-42xq-w5vw.json b/advisories/unreviewed/2022/05/GHSA-93c8-42xq-w5vw/GHSA-93c8-42xq-w5vw.json index 632e548a903..b2e351e3413 100644 --- a/advisories/unreviewed/2022/05/GHSA-93c8-42xq-w5vw/GHSA-93c8-42xq-w5vw.json +++ b/advisories/unreviewed/2022/05/GHSA-93c8-42xq-w5vw/GHSA-93c8-42xq-w5vw.json @@ -7,12 +7,8 @@ "CVE-2007-5233" ], "details": "SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-954f-qffp-hrxp/GHSA-954f-qffp-hrxp.json b/advisories/unreviewed/2022/05/GHSA-954f-qffp-hrxp/GHSA-954f-qffp-hrxp.json index 079ab8e49a9..507e08725bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-954f-qffp-hrxp/GHSA-954f-qffp-hrxp.json +++ b/advisories/unreviewed/2022/05/GHSA-954f-qffp-hrxp/GHSA-954f-qffp-hrxp.json @@ -7,12 +7,8 @@ "CVE-2007-5043" ], "details": "Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service (avp.exe service outage) via the NtLoadDriver kernel SSDT hook. NOTE: this issue may partially overlap CVE-2006-3074.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9679-f23c-2xcv/GHSA-9679-f23c-2xcv.json b/advisories/unreviewed/2022/05/GHSA-9679-f23c-2xcv/GHSA-9679-f23c-2xcv.json index 8ff0fb14041..dacfb99dc02 100644 --- a/advisories/unreviewed/2022/05/GHSA-9679-f23c-2xcv/GHSA-9679-f23c-2xcv.json +++ b/advisories/unreviewed/2022/05/GHSA-9679-f23c-2xcv/GHSA-9679-f23c-2xcv.json @@ -7,12 +7,8 @@ "CVE-2007-5091" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via the cat_data[color] parameter to (1) preferences/inc/class.uicategories.inc.php and (2) admin/inc/class.uicategories.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-969p-h3hv-f229/GHSA-969p-h3hv-f229.json b/advisories/unreviewed/2022/05/GHSA-969p-h3hv-f229/GHSA-969p-h3hv-f229.json index 8fcca4989f4..d8c06b3101b 100644 --- a/advisories/unreviewed/2022/05/GHSA-969p-h3hv-f229/GHSA-969p-h3hv-f229.json +++ b/advisories/unreviewed/2022/05/GHSA-969p-h3hv-f229/GHSA-969p-h3hv-f229.json @@ -7,12 +7,8 @@ "CVE-2007-4540" ], "details": "Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96gj-w4vg-4vg2/GHSA-96gj-w4vg-4vg2.json b/advisories/unreviewed/2022/05/GHSA-96gj-w4vg-4vg2/GHSA-96gj-w4vg-4vg2.json index cdbb680c9b6..91a0e67fef3 100644 --- a/advisories/unreviewed/2022/05/GHSA-96gj-w4vg-4vg2/GHSA-96gj-w4vg-4vg2.json +++ b/advisories/unreviewed/2022/05/GHSA-96gj-w4vg-4vg2/GHSA-96gj-w4vg-4vg2.json @@ -7,12 +7,8 @@ "CVE-2007-4662" ], "details": "Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96xf-rq95-59wj/GHSA-96xf-rq95-59wj.json b/advisories/unreviewed/2022/05/GHSA-96xf-rq95-59wj/GHSA-96xf-rq95-59wj.json index 1e1e197b158..473a61ef291 100644 --- a/advisories/unreviewed/2022/05/GHSA-96xf-rq95-59wj/GHSA-96xf-rq95-59wj.json +++ b/advisories/unreviewed/2022/05/GHSA-96xf-rq95-59wj/GHSA-96xf-rq95-59wj.json @@ -7,12 +7,8 @@ "CVE-2007-4882" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in TechExcel CustomerWise (formerly TechExcel CRM) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-97rv-8hff-m396/GHSA-97rv-8hff-m396.json b/advisories/unreviewed/2022/05/GHSA-97rv-8hff-m396/GHSA-97rv-8hff-m396.json index cb37fb9e355..1770c972ca5 100644 --- a/advisories/unreviewed/2022/05/GHSA-97rv-8hff-m396/GHSA-97rv-8hff-m396.json +++ b/advisories/unreviewed/2022/05/GHSA-97rv-8hff-m396/GHSA-97rv-8hff-m396.json @@ -7,12 +7,8 @@ "CVE-2007-4549" ], "details": "Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrary code via an ALPass DB (APW) file containing (1) a long file-key or (2) a \"Site Information and Folder entry\" with a ciphertext_length value much larger than the plaintext_length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98cm-68r8-4m8h/GHSA-98cm-68r8-4m8h.json b/advisories/unreviewed/2022/05/GHSA-98cm-68r8-4m8h/GHSA-98cm-68r8-4m8h.json index bd64c12c209..c0c991f7e4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-98cm-68r8-4m8h/GHSA-98cm-68r8-4m8h.json +++ b/advisories/unreviewed/2022/05/GHSA-98cm-68r8-4m8h/GHSA-98cm-68r8-4m8h.json @@ -7,12 +7,8 @@ "CVE-2007-5089" ], "details": "PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SKIN_URL parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99qv-g3mr-cjw3/GHSA-99qv-g3mr-cjw3.json b/advisories/unreviewed/2022/05/GHSA-99qv-g3mr-cjw3/GHSA-99qv-g3mr-cjw3.json index d3d517081f0..2f23c5b243b 100644 --- a/advisories/unreviewed/2022/05/GHSA-99qv-g3mr-cjw3/GHSA-99qv-g3mr-cjw3.json +++ b/advisories/unreviewed/2022/05/GHSA-99qv-g3mr-cjw3/GHSA-99qv-g3mr-cjw3.json @@ -7,12 +7,8 @@ "CVE-2007-5040" ], "details": "Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtCreateThread, (3) NtDeleteValueKey, (4) NtQueryValueKey, (5) NtSetSystemInformation, and (6) NtSetValueKey kernel SSDT hooks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cqp-2x5c-hj4r/GHSA-9cqp-2x5c-hj4r.json b/advisories/unreviewed/2022/05/GHSA-9cqp-2x5c-hj4r/GHSA-9cqp-2x5c-hj4r.json index 47bb23a12ec..94ae16e2e7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cqp-2x5c-hj4r/GHSA-9cqp-2x5c-hj4r.json +++ b/advisories/unreviewed/2022/05/GHSA-9cqp-2x5c-hj4r/GHSA-9cqp-2x5c-hj4r.json @@ -7,12 +7,8 @@ "CVE-2007-4736" ], "details": "SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cv9-wm9c-g4rw/GHSA-9cv9-wm9c-g4rw.json b/advisories/unreviewed/2022/05/GHSA-9cv9-wm9c-g4rw/GHSA-9cv9-wm9c-g4rw.json index 4a3ba81dec1..37964be840c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cv9-wm9c-g4rw/GHSA-9cv9-wm9c-g4rw.json +++ b/advisories/unreviewed/2022/05/GHSA-9cv9-wm9c-g4rw/GHSA-9cv9-wm9c-g4rw.json @@ -7,12 +7,8 @@ "CVE-2007-5098" ], "details": "Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the set_depth parameter to (1) app.lib/product.control/core.php/product.control.config.php, or (2) customer.browse.list.php or (3) customer.browse.search.php in app.lib/product.control/core.php/customer.area/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cw9-v886-c24m/GHSA-9cw9-v886-c24m.json b/advisories/unreviewed/2022/05/GHSA-9cw9-v886-c24m/GHSA-9cw9-v886-c24m.json index ba2b0f60ee0..22895cc7eb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cw9-v886-c24m/GHSA-9cw9-v886-c24m.json +++ b/advisories/unreviewed/2022/05/GHSA-9cw9-v886-c24m/GHSA-9cw9-v886-c24m.json @@ -7,12 +7,8 @@ "CVE-2007-4767" ], "details": "Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \\p sequence, (2) a \\P sequence, or (3) a \\P{x} sequence, which allows context-dependent attackers to cause a denial of service (infinite loop or crash) or execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -196,9 +192,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fj7-4wc3-436h/GHSA-9fj7-4wc3-436h.json b/advisories/unreviewed/2022/05/GHSA-9fj7-4wc3-436h/GHSA-9fj7-4wc3-436h.json index de93eba006f..e59e15a3ee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fj7-4wc3-436h/GHSA-9fj7-4wc3-436h.json +++ b/advisories/unreviewed/2022/05/GHSA-9fj7-4wc3-436h/GHSA-9fj7-4wc3-436h.json @@ -7,12 +7,8 @@ "CVE-2007-4653" ], "details": "SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g37-pxq7-m5jq/GHSA-9g37-pxq7-m5jq.json b/advisories/unreviewed/2022/05/GHSA-9g37-pxq7-m5jq/GHSA-9g37-pxq7-m5jq.json index 22adc44897b..1611cf88593 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g37-pxq7-m5jq/GHSA-9g37-pxq7-m5jq.json +++ b/advisories/unreviewed/2022/05/GHSA-9g37-pxq7-m5jq/GHSA-9g37-pxq7-m5jq.json @@ -7,12 +7,8 @@ "CVE-2007-4566" ], "details": "Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hp8-g457-7pq8/GHSA-9hp8-g457-7pq8.json b/advisories/unreviewed/2022/05/GHSA-9hp8-g457-7pq8/GHSA-9hp8-g457-7pq8.json index 4c2d307fb07..2c16abf9a71 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hp8-g457-7pq8/GHSA-9hp8-g457-7pq8.json +++ b/advisories/unreviewed/2022/05/GHSA-9hp8-g457-7pq8/GHSA-9hp8-g457-7pq8.json @@ -7,12 +7,8 @@ "CVE-2007-4534" ], "details": "Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a chat message and possibly (2) a long name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p3q-ppjf-98hp/GHSA-9p3q-ppjf-98hp.json b/advisories/unreviewed/2022/05/GHSA-9p3q-ppjf-98hp/GHSA-9p3q-ppjf-98hp.json index 38f8402d3cb..aee66a8def8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p3q-ppjf-98hp/GHSA-9p3q-ppjf-98hp.json +++ b/advisories/unreviewed/2022/05/GHSA-9p3q-ppjf-98hp/GHSA-9p3q-ppjf-98hp.json @@ -7,12 +7,8 @@ "CVE-2007-4702" ], "details": "The Application Firewall in Apple Mac OS X 10.5, when \"Block all incoming connections\" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pff-w395-24cx/GHSA-9pff-w395-24cx.json b/advisories/unreviewed/2022/05/GHSA-9pff-w395-24cx/GHSA-9pff-w395-24cx.json index b00248f0bcb..140ed64540c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pff-w395-24cx/GHSA-9pff-w395-24cx.json +++ b/advisories/unreviewed/2022/05/GHSA-9pff-w395-24cx/GHSA-9pff-w395-24cx.json @@ -7,12 +7,8 @@ "CVE-2007-4798" ], "details": "Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in \"unix\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pqr-9rj6-38hr/GHSA-9pqr-9rj6-38hr.json b/advisories/unreviewed/2022/05/GHSA-9pqr-9rj6-38hr/GHSA-9pqr-9rj6-38hr.json index 91961d9aa29..dc080917d2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pqr-9rj6-38hr/GHSA-9pqr-9rj6-38hr.json +++ b/advisories/unreviewed/2022/05/GHSA-9pqr-9rj6-38hr/GHSA-9pqr-9rj6-38hr.json @@ -7,12 +7,8 @@ "CVE-2007-5176" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in GroupLink eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) NA_DISPLAYNAME parameter in helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError parameters in index2.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q3v-wm75-qjw9/GHSA-9q3v-wm75-qjw9.json b/advisories/unreviewed/2022/05/GHSA-9q3v-wm75-qjw9/GHSA-9q3v-wm75-qjw9.json index 1dd5d5621ea..a70220ea6bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q3v-wm75-qjw9/GHSA-9q3v-wm75-qjw9.json +++ b/advisories/unreviewed/2022/05/GHSA-9q3v-wm75-qjw9/GHSA-9q3v-wm75-qjw9.json @@ -7,12 +7,8 @@ "CVE-2007-4782" ], "details": "PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a \"*[1]e\" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q4h-3qxr-p642/GHSA-9q4h-3qxr-p642.json b/advisories/unreviewed/2022/05/GHSA-9q4h-3qxr-p642/GHSA-9q4h-3qxr-p642.json index 8f10a11da2b..c3a969eaa18 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q4h-3qxr-p642/GHSA-9q4h-3qxr-p642.json +++ b/advisories/unreviewed/2022/05/GHSA-9q4h-3qxr-p642/GHSA-9q4h-3qxr-p642.json @@ -7,12 +7,8 @@ "CVE-2007-5244" ], "details": "Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote attackers to execute arbitrary code via a long attach request on TCP port 3050 to the open_marker_file function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q4p-wv38-76g5/GHSA-9q4p-wv38-76g5.json b/advisories/unreviewed/2022/05/GHSA-9q4p-wv38-76g5/GHSA-9q4p-wv38-76g5.json index 2c94b1ecdee..74d14215069 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q4p-wv38-76g5/GHSA-9q4p-wv38-76g5.json +++ b/advisories/unreviewed/2022/05/GHSA-9q4p-wv38-76g5/GHSA-9q4p-wv38-76g5.json @@ -7,12 +7,8 @@ "CVE-2007-4890" ], "details": "Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rc3-8rwr-fr36/GHSA-9rc3-8rwr-fr36.json b/advisories/unreviewed/2022/05/GHSA-9rc3-8rwr-fr36/GHSA-9rc3-8rwr-fr36.json index e4ccb5754bd..db345dcd7d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rc3-8rwr-fr36/GHSA-9rc3-8rwr-fr36.json +++ b/advisories/unreviewed/2022/05/GHSA-9rc3-8rwr-fr36/GHSA-9rc3-8rwr-fr36.json @@ -7,12 +7,8 @@ "CVE-2007-4776" ], "details": "Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are limited usage scenarios under which this would be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vr3-hj2g-5hv8/GHSA-9vr3-hj2g-5hv8.json b/advisories/unreviewed/2022/05/GHSA-9vr3-hj2g-5hv8/GHSA-9vr3-hj2g-5hv8.json index 1924b6d204b..26702c8d34b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vr3-hj2g-5hv8/GHSA-9vr3-hj2g-5hv8.json +++ b/advisories/unreviewed/2022/05/GHSA-9vr3-hj2g-5hv8/GHSA-9vr3-hj2g-5hv8.json @@ -7,12 +7,8 @@ "CVE-2007-4741" ], "details": "Cross-site scripting (XSS) vulnerability in admin/adminusers.php in Claroline before 1.8.6 allows remote authenticated administrators to inject arbitrary web script or HTML via the sort parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x3r-jw9f-j65x/GHSA-9x3r-jw9f-j65x.json b/advisories/unreviewed/2022/05/GHSA-9x3r-jw9f-j65x/GHSA-9x3r-jw9f-j65x.json index 4fb3a46524d..a2539a1e8cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x3r-jw9f-j65x/GHSA-9x3r-jw9f-j65x.json +++ b/advisories/unreviewed/2022/05/GHSA-9x3r-jw9f-j65x/GHSA-9x3r-jw9f-j65x.json @@ -7,12 +7,8 @@ "CVE-2007-4811" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to inject arbitrary web script or HTML via (1) the val parameter to alphabet.php in an alpha.albums action, or the PATH_INFO to (2) random.php or (3) admin/hidden.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c23v-h2r6-3vvw/GHSA-c23v-h2r6-3vvw.json b/advisories/unreviewed/2022/05/GHSA-c23v-h2r6-3vvw/GHSA-c23v-h2r6-3vvw.json index bc2c94572d3..f2711fe0e1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c23v-h2r6-3vvw/GHSA-c23v-h2r6-3vvw.json +++ b/advisories/unreviewed/2022/05/GHSA-c23v-h2r6-3vvw/GHSA-c23v-h2r6-3vvw.json @@ -7,12 +7,8 @@ "CVE-2007-5200" ], "details": "hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3wj-8v4m-pr5f/GHSA-c3wj-8v4m-pr5f.json b/advisories/unreviewed/2022/05/GHSA-c3wj-8v4m-pr5f/GHSA-c3wj-8v4m-pr5f.json index a40f489d945..e96e9f60bf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3wj-8v4m-pr5f/GHSA-c3wj-8v4m-pr5f.json +++ b/advisories/unreviewed/2022/05/GHSA-c3wj-8v4m-pr5f/GHSA-c3wj-8v4m-pr5f.json @@ -7,12 +7,8 @@ "CVE-2007-4819" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4f5-fw2w-g788/GHSA-c4f5-fw2w-g788.json b/advisories/unreviewed/2022/05/GHSA-c4f5-fw2w-g788/GHSA-c4f5-fw2w-g788.json index 2f8fee58824..4a05edf2cc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4f5-fw2w-g788/GHSA-c4f5-fw2w-g788.json +++ b/advisories/unreviewed/2022/05/GHSA-c4f5-fw2w-g788/GHSA-c4f5-fw2w-g788.json @@ -7,12 +7,8 @@ "CVE-2007-5248" ], "details": "Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5xh-656p-g98m/GHSA-c5xh-656p-g98m.json b/advisories/unreviewed/2022/05/GHSA-c5xh-656p-g98m/GHSA-c5xh-656p-g98m.json index cb0a5f519d6..4d36651cbe9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5xh-656p-g98m/GHSA-c5xh-656p-g98m.json +++ b/advisories/unreviewed/2022/05/GHSA-c5xh-656p-g98m/GHSA-c5xh-656p-g98m.json @@ -7,12 +7,8 @@ "CVE-2007-4990" ], "details": "The swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -172,9 +168,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5xr-m2wm-p2c8/GHSA-c5xr-m2wm-p2c8.json b/advisories/unreviewed/2022/05/GHSA-c5xr-m2wm-p2c8/GHSA-c5xr-m2wm-p2c8.json index 1ce1901a882..232f3213e1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5xr-m2wm-p2c8/GHSA-c5xr-m2wm-p2c8.json +++ b/advisories/unreviewed/2022/05/GHSA-c5xr-m2wm-p2c8/GHSA-c5xr-m2wm-p2c8.json @@ -7,12 +7,8 @@ "CVE-2007-5019" ], "details": "Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6g6-2mm5-xfwv/GHSA-c6g6-2mm5-xfwv.json b/advisories/unreviewed/2022/05/GHSA-c6g6-2mm5-xfwv/GHSA-c6g6-2mm5-xfwv.json index d1613b910be..847661eec74 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6g6-2mm5-xfwv/GHSA-c6g6-2mm5-xfwv.json +++ b/advisories/unreviewed/2022/05/GHSA-c6g6-2mm5-xfwv/GHSA-c6g6-2mm5-xfwv.json @@ -7,12 +7,8 @@ "CVE-2007-4629" ], "details": "Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6p3-9pj2-f598/GHSA-c6p3-9pj2-f598.json b/advisories/unreviewed/2022/05/GHSA-c6p3-9pj2-f598/GHSA-c6p3-9pj2-f598.json index 451b5235140..43b9e8dbce5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6p3-9pj2-f598/GHSA-c6p3-9pj2-f598.json +++ b/advisories/unreviewed/2022/05/GHSA-c6p3-9pj2-f598/GHSA-c6p3-9pj2-f598.json @@ -7,12 +7,8 @@ "CVE-2007-4759" ], "details": "Multiple unspecified vulnerabilities in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6vh-98hr-hm8j/GHSA-c6vh-98hr-hm8j.json b/advisories/unreviewed/2022/05/GHSA-c6vh-98hr-hm8j/GHSA-c6vh-98hr-hm8j.json index a143188502a..775bdee1ba4 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6vh-98hr-hm8j/GHSA-c6vh-98hr-hm8j.json +++ b/advisories/unreviewed/2022/05/GHSA-c6vh-98hr-hm8j/GHSA-c6vh-98hr-hm8j.json @@ -7,12 +7,8 @@ "CVE-2007-4697" ], "details": "Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6vm-22w9-5c94/GHSA-c6vm-22w9-5c94.json b/advisories/unreviewed/2022/05/GHSA-c6vm-22w9-5c94/GHSA-c6vm-22w9-5c94.json index ae51c6da8a4..b3f8b46e361 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6vm-22w9-5c94/GHSA-c6vm-22w9-5c94.json +++ b/advisories/unreviewed/2022/05/GHSA-c6vm-22w9-5c94/GHSA-c6vm-22w9-5c94.json @@ -7,12 +7,8 @@ "CVE-2007-4688" ], "details": "The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addresses, via a Node Information Query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7p8-5wh3-55vc/GHSA-c7p8-5wh3-55vc.json b/advisories/unreviewed/2022/05/GHSA-c7p8-5wh3-55vc/GHSA-c7p8-5wh3-55vc.json index d63d24e6e22..890523700a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7p8-5wh3-55vc/GHSA-c7p8-5wh3-55vc.json +++ b/advisories/unreviewed/2022/05/GHSA-c7p8-5wh3-55vc/GHSA-c7p8-5wh3-55vc.json @@ -7,12 +7,8 @@ "CVE-2007-4904" ], "details": "RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c889-7vh4-j454/GHSA-c889-7vh4-j454.json b/advisories/unreviewed/2022/05/GHSA-c889-7vh4-j454/GHSA-c889-7vh4-j454.json index 76c2d15f14d..a78e23ccb45 100644 --- a/advisories/unreviewed/2022/05/GHSA-c889-7vh4-j454/GHSA-c889-7vh4-j454.json +++ b/advisories/unreviewed/2022/05/GHSA-c889-7vh4-j454/GHSA-c889-7vh4-j454.json @@ -7,12 +7,8 @@ "CVE-2007-4572" ], "details": "Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8m3-98wf-r685/GHSA-c8m3-98wf-r685.json b/advisories/unreviewed/2022/05/GHSA-c8m3-98wf-r685/GHSA-c8m3-98wf-r685.json index 24cf6682e18..71a270584da 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8m3-98wf-r685/GHSA-c8m3-98wf-r685.json +++ b/advisories/unreviewed/2022/05/GHSA-c8m3-98wf-r685/GHSA-c8m3-98wf-r685.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8w2-fm4m-3jv9/GHSA-c8w2-fm4m-3jv9.json b/advisories/unreviewed/2022/05/GHSA-c8w2-fm4m-3jv9/GHSA-c8w2-fm4m-3jv9.json index 013aa2558ce..7df476e5247 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8w2-fm4m-3jv9/GHSA-c8w2-fm4m-3jv9.json +++ b/advisories/unreviewed/2022/05/GHSA-c8w2-fm4m-3jv9/GHSA-c8w2-fm4m-3jv9.json @@ -7,12 +7,8 @@ "CVE-2007-4713" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9qh-j7x8-g2xv/GHSA-c9qh-j7x8-g2xv.json b/advisories/unreviewed/2022/05/GHSA-c9qh-j7x8-g2xv/GHSA-c9qh-j7x8-g2xv.json index 4a5c71c1281..317d735cada 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9qh-j7x8-g2xv/GHSA-c9qh-j7x8-g2xv.json +++ b/advisories/unreviewed/2022/05/GHSA-c9qh-j7x8-g2xv/GHSA-c9qh-j7x8-g2xv.json @@ -7,12 +7,8 @@ "CVE-2007-4842" ], "details": "Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc92-gpq9-6xrq/GHSA-cc92-gpq9-6xrq.json b/advisories/unreviewed/2022/05/GHSA-cc92-gpq9-6xrq/GHSA-cc92-gpq9-6xrq.json index 9da3b991292..e4353bdde39 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc92-gpq9-6xrq/GHSA-cc92-gpq9-6xrq.json +++ b/advisories/unreviewed/2022/05/GHSA-cc92-gpq9-6xrq/GHSA-cc92-gpq9-6xrq.json @@ -7,12 +7,8 @@ "CVE-2007-5127" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_username parameter to the default URI under admin/ or (2) the l_emoticonlist parameter to admin/emoticonlist.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf99-wv64-5f46/GHSA-cf99-wv64-5f46.json b/advisories/unreviewed/2022/05/GHSA-cf99-wv64-5f46/GHSA-cf99-wv64-5f46.json index 3282330c59a..ea76c068bbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf99-wv64-5f46/GHSA-cf99-wv64-5f46.json +++ b/advisories/unreviewed/2022/05/GHSA-cf99-wv64-5f46/GHSA-cf99-wv64-5f46.json @@ -7,12 +7,8 @@ "CVE-2007-4971" ], "details": "ProSecurity 1.40 Beta 2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenSection, and (5) NtSetSystemTime.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfx5-4q9c-778g/GHSA-cfx5-4q9c-778g.json b/advisories/unreviewed/2022/05/GHSA-cfx5-4q9c-778g/GHSA-cfx5-4q9c-778g.json index 8e94c35f690..600f149594d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfx5-4q9c-778g/GHSA-cfx5-4q9c-778g.json +++ b/advisories/unreviewed/2022/05/GHSA-cfx5-4q9c-778g/GHSA-cfx5-4q9c-778g.json @@ -7,12 +7,8 @@ "CVE-2007-0664" ], "details": "thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgvm-pqx4-697h/GHSA-cgvm-pqx4-697h.json b/advisories/unreviewed/2022/05/GHSA-cgvm-pqx4-697h/GHSA-cgvm-pqx4-697h.json index 770681a3522..7d2fc3d8424 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgvm-pqx4-697h/GHSA-cgvm-pqx4-697h.json +++ b/advisories/unreviewed/2022/05/GHSA-cgvm-pqx4-697h/GHSA-cgvm-pqx4-697h.json @@ -7,12 +7,8 @@ "CVE-2007-4613" ], "details": "SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plaintext from an SSL stream via a man-in-the-middle attack that injects crafted data and measures the elapsed time before an error response, a different vulnerability than CVE-2006-2461.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chpc-3cm4-f9gq/GHSA-chpc-3cm4-f9gq.json b/advisories/unreviewed/2022/05/GHSA-chpc-3cm4-f9gq/GHSA-chpc-3cm4-f9gq.json index f9689d90767..0dc169dfbf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-chpc-3cm4-f9gq/GHSA-chpc-3cm4-f9gq.json +++ b/advisories/unreviewed/2022/05/GHSA-chpc-3cm4-f9gq/GHSA-chpc-3cm4-f9gq.json @@ -7,12 +7,8 @@ "CVE-2007-4889" ], "details": "The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm2q-rjp7-2xcv/GHSA-cm2q-rjp7-2xcv.json b/advisories/unreviewed/2022/05/GHSA-cm2q-rjp7-2xcv/GHSA-cm2q-rjp7-2xcv.json index 0b1ccb1188c..0d355fd1fd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm2q-rjp7-2xcv/GHSA-cm2q-rjp7-2xcv.json +++ b/advisories/unreviewed/2022/05/GHSA-cm2q-rjp7-2xcv/GHSA-cm2q-rjp7-2xcv.json @@ -7,12 +7,8 @@ "CVE-2007-4938" ], "details": "Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large \"indx truck size\" and nEntriesInuse values, and a certain wLongsPerEntry value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq8v-9fqj-p7rf/GHSA-cq8v-9fqj-p7rf.json b/advisories/unreviewed/2022/05/GHSA-cq8v-9fqj-p7rf/GHSA-cq8v-9fqj-p7rf.json index f04c39c5bae..9d4eb9e41a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq8v-9fqj-p7rf/GHSA-cq8v-9fqj-p7rf.json +++ b/advisories/unreviewed/2022/05/GHSA-cq8v-9fqj-p7rf/GHSA-cq8v-9fqj-p7rf.json @@ -7,12 +7,8 @@ "CVE-2007-4816" ], "details": "Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqcc-jrhh-rjwp/GHSA-cqcc-jrhh-rjwp.json b/advisories/unreviewed/2022/05/GHSA-cqcc-jrhh-rjwp/GHSA-cqcc-jrhh-rjwp.json index c9db4ea256a..050a8af6d9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqcc-jrhh-rjwp/GHSA-cqcc-jrhh-rjwp.json +++ b/advisories/unreviewed/2022/05/GHSA-cqcc-jrhh-rjwp/GHSA-cqcc-jrhh-rjwp.json @@ -7,12 +7,8 @@ "CVE-2007-4809" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code via a URL in the DOC_ROOT parameter to (1) lib/functions.php or (2) lib/header.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqg4-h3p4-q5wg/GHSA-cqg4-h3p4-q5wg.json b/advisories/unreviewed/2022/05/GHSA-cqg4-h3p4-q5wg/GHSA-cqg4-h3p4-q5wg.json index 701135bbaec..08fce778d1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqg4-h3p4-q5wg/GHSA-cqg4-h3p4-q5wg.json +++ b/advisories/unreviewed/2022/05/GHSA-cqg4-h3p4-q5wg/GHSA-cqg4-h3p4-q5wg.json @@ -7,12 +7,8 @@ "CVE-2007-4796" ], "details": "Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqvf-hcrx-5mjg/GHSA-cqvf-hcrx-5mjg.json b/advisories/unreviewed/2022/05/GHSA-cqvf-hcrx-5mjg/GHSA-cqvf-hcrx-5mjg.json index 9b173b0fc12..4209b481ced 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqvf-hcrx-5mjg/GHSA-cqvf-hcrx-5mjg.json +++ b/advisories/unreviewed/2022/05/GHSA-cqvf-hcrx-5mjg/GHSA-cqvf-hcrx-5mjg.json @@ -7,12 +7,8 @@ "CVE-2007-5029" ], "details": "Dibbler 0.6.0 does not verify that certain length parameters are appropriate for buffer sizes, which allows remote attackers to trigger a buffer over-read and cause a denial of service (daemon crash), as demonstrated by incorrect behavior of the TSrvMsg constructor in SrvMessages/SrvMsg.cpp when (1) reading the option code and option length and (2) parsing options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvp9-hwc6-x9xf/GHSA-cvp9-hwc6-x9xf.json b/advisories/unreviewed/2022/05/GHSA-cvp9-hwc6-x9xf/GHSA-cvp9-hwc6-x9xf.json index a221323d1c8..e666ddf1217 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvp9-hwc6-x9xf/GHSA-cvp9-hwc6-x9xf.json +++ b/advisories/unreviewed/2022/05/GHSA-cvp9-hwc6-x9xf/GHSA-cvp9-hwc6-x9xf.json @@ -7,12 +7,8 @@ "CVE-2007-4948" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Webmedia Explorer (webmex) 3.2.2 allow remote attackers to execute arbitrary PHP code via (1) a URL in the path_include parameter to includes/rss.class.php, (2) a URL in the path_template parameter to (a) templates/main.tpl.php or (b) templates/folder_messages_link_message_name.tpl.php, or (4) a URL in the path_templates parameter to templates/sidebar.tpl.php. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess support. NOTE: the includes/core.lib.php vector is already covered by CVE-2006-5252.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwj3-c2q3-qf35/GHSA-cwj3-c2q3-qf35.json b/advisories/unreviewed/2022/05/GHSA-cwj3-c2q3-qf35/GHSA-cwj3-c2q3-qf35.json index be839eedf1d..c4a252eeb6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwj3-c2q3-qf35/GHSA-cwj3-c2q3-qf35.json +++ b/advisories/unreviewed/2022/05/GHSA-cwj3-c2q3-qf35/GHSA-cwj3-c2q3-qf35.json @@ -7,12 +7,8 @@ "CVE-2007-5070" ], "details": "Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail MessagePrinter Object allows remote attackers to execute arbitrary code via a long string in the first argument to the SetFont method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json b/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json index 199af98f5d4..e4c97a69c3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json +++ b/advisories/unreviewed/2022/05/GHSA-f24p-3hqr-7g3q/GHSA-f24p-3hqr-7g3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f29p-62p2-3xv3/GHSA-f29p-62p2-3xv3.json b/advisories/unreviewed/2022/05/GHSA-f29p-62p2-3xv3/GHSA-f29p-62p2-3xv3.json index 6b567d2787c..75e55705c41 100644 --- a/advisories/unreviewed/2022/05/GHSA-f29p-62p2-3xv3/GHSA-f29p-62p2-3xv3.json +++ b/advisories/unreviewed/2022/05/GHSA-f29p-62p2-3xv3/GHSA-f29p-62p2-3xv3.json @@ -7,12 +7,8 @@ "CVE-2007-4836" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3fm-5grc-52pj/GHSA-f3fm-5grc-52pj.json b/advisories/unreviewed/2022/05/GHSA-f3fm-5grc-52pj/GHSA-f3fm-5grc-52pj.json index a5f7577e865..f923b21d3a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3fm-5grc-52pj/GHSA-f3fm-5grc-52pj.json +++ b/advisories/unreviewed/2022/05/GHSA-f3fm-5grc-52pj/GHSA-f3fm-5grc-52pj.json @@ -7,12 +7,8 @@ "CVE-2007-5006" ], "details": "Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3h8-v388-jhxw/GHSA-f3h8-v388-jhxw.json b/advisories/unreviewed/2022/05/GHSA-f3h8-v388-jhxw/GHSA-f3h8-v388-jhxw.json index 6dd9a7247fb..a9d721628fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3h8-v388-jhxw/GHSA-f3h8-v388-jhxw.json +++ b/advisories/unreviewed/2022/05/GHSA-f3h8-v388-jhxw/GHSA-f3h8-v388-jhxw.json @@ -7,12 +7,8 @@ "CVE-2007-4788" ], "details": "Cisco Content Switching Modules (CSM) 4.2 before 4.2.3a, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.2a, allow remote attackers to cause a denial of service (CPU consumption or reboot) via sets of out-of-order TCP packets with unspecified characteristics, aka CSCsd27478.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3rm-wp7q-f7fg/GHSA-f3rm-wp7q-f7fg.json b/advisories/unreviewed/2022/05/GHSA-f3rm-wp7q-f7fg/GHSA-f3rm-wp7q-f7fg.json index c8e20a25476..7d7df8100ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3rm-wp7q-f7fg/GHSA-f3rm-wp7q-f7fg.json +++ b/advisories/unreviewed/2022/05/GHSA-f3rm-wp7q-f7fg/GHSA-f3rm-wp7q-f7fg.json @@ -7,12 +7,8 @@ "CVE-2007-5050" ], "details": "Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3x9-2xrg-95g2/GHSA-f3x9-2xrg-95g2.json b/advisories/unreviewed/2022/05/GHSA-f3x9-2xrg-95g2/GHSA-f3x9-2xrg-95g2.json index 4e214200aa8..3abf9faecda 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3x9-2xrg-95g2/GHSA-f3x9-2xrg-95g2.json +++ b/advisories/unreviewed/2022/05/GHSA-f3x9-2xrg-95g2/GHSA-f3x9-2xrg-95g2.json @@ -7,12 +7,8 @@ "CVE-2007-4725" ], "details": "Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5fc-w8xw-qv8f/GHSA-f5fc-w8xw-qv8f.json b/advisories/unreviewed/2022/05/GHSA-f5fc-w8xw-qv8f/GHSA-f5fc-w8xw-qv8f.json index 158ec3e8fd0..714130cd4d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5fc-w8xw-qv8f/GHSA-f5fc-w8xw-qv8f.json +++ b/advisories/unreviewed/2022/05/GHSA-f5fc-w8xw-qv8f/GHSA-f5fc-w8xw-qv8f.json @@ -7,12 +7,8 @@ "CVE-2007-4874" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5rr-g89r-mhg4/GHSA-f5rr-g89r-mhg4.json b/advisories/unreviewed/2022/05/GHSA-f5rr-g89r-mhg4/GHSA-f5rr-g89r-mhg4.json index 67200e5536a..9703a93d2c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5rr-g89r-mhg4/GHSA-f5rr-g89r-mhg4.json +++ b/advisories/unreviewed/2022/05/GHSA-f5rr-g89r-mhg4/GHSA-f5rr-g89r-mhg4.json @@ -7,12 +7,8 @@ "CVE-2007-5099" ], "details": "PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6qm-fg6r-h5f3/GHSA-f6qm-fg6r-h5f3.json b/advisories/unreviewed/2022/05/GHSA-f6qm-fg6r-h5f3/GHSA-f6qm-fg6r-h5f3.json index 96bd0ba5170..a1692c063e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6qm-fg6r-h5f3/GHSA-f6qm-fg6r-h5f3.json +++ b/advisories/unreviewed/2022/05/GHSA-f6qm-fg6r-h5f3/GHSA-f6qm-fg6r-h5f3.json @@ -7,12 +7,8 @@ "CVE-2007-4554" ], "details": "Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7h5-cxh9-h5wh/GHSA-f7h5-cxh9-h5wh.json b/advisories/unreviewed/2022/05/GHSA-f7h5-cxh9-h5wh/GHSA-f7h5-cxh9-h5wh.json index 50bcc84eeee..fee036ead57 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7h5-cxh9-h5wh/GHSA-f7h5-cxh9-h5wh.json +++ b/advisories/unreviewed/2022/05/GHSA-f7h5-cxh9-h5wh/GHSA-f7h5-cxh9-h5wh.json @@ -7,12 +7,8 @@ "CVE-2007-4696" ], "details": "Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to \"page transitions\" in Safari.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f84q-7gqj-p267/GHSA-f84q-7gqj-p267.json b/advisories/unreviewed/2022/05/GHSA-f84q-7gqj-p267/GHSA-f84q-7gqj-p267.json index 3d5fb974886..8cb2a8148ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-f84q-7gqj-p267/GHSA-f84q-7gqj-p267.json +++ b/advisories/unreviewed/2022/05/GHSA-f84q-7gqj-p267/GHSA-f84q-7gqj-p267.json @@ -7,12 +7,8 @@ "CVE-2007-5071" ], "details": "Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstrated by a filename ending in .php. or a .htaccess file, a different vector than CVE-2005-2733. NOTE: the vulnerability was also present in a 0.5.1 download available in the early morning of 20070923. NOTE: the original 20070920 disclosure provided an incorrect filename, img_upload_cgi.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8pg-vjq9-5m7p/GHSA-f8pg-vjq9-5m7p.json b/advisories/unreviewed/2022/05/GHSA-f8pg-vjq9-5m7p/GHSA-f8pg-vjq9-5m7p.json index bf6f9e1ebe4..e7f199ff93f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8pg-vjq9-5m7p/GHSA-f8pg-vjq9-5m7p.json +++ b/advisories/unreviewed/2022/05/GHSA-f8pg-vjq9-5m7p/GHSA-f8pg-vjq9-5m7p.json @@ -7,12 +7,8 @@ "CVE-2007-4956" ], "details": "Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8q3-mjhv-rr2f/GHSA-f8q3-mjhv-rr2f.json b/advisories/unreviewed/2022/05/GHSA-f8q3-mjhv-rr2f/GHSA-f8q3-mjhv-rr2f.json index 94392108d79..c854b10b71f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8q3-mjhv-rr2f/GHSA-f8q3-mjhv-rr2f.json +++ b/advisories/unreviewed/2022/05/GHSA-f8q3-mjhv-rr2f/GHSA-f8q3-mjhv-rr2f.json @@ -7,12 +7,8 @@ "CVE-2007-4909" ], "details": "Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f934-hc5p-5vxj/GHSA-f934-hc5p-5vxj.json b/advisories/unreviewed/2022/05/GHSA-f934-hc5p-5vxj/GHSA-f934-hc5p-5vxj.json index 74d13878024..9b21aeab7ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-f934-hc5p-5vxj/GHSA-f934-hc5p-5vxj.json +++ b/advisories/unreviewed/2022/05/GHSA-f934-hc5p-5vxj/GHSA-f934-hc5p-5vxj.json @@ -7,12 +7,8 @@ "CVE-2007-5010" ], "details": "Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via the URL to webbatch.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff29-4hvm-m32q/GHSA-ff29-4hvm-m32q.json b/advisories/unreviewed/2022/05/GHSA-ff29-4hvm-m32q/GHSA-ff29-4hvm-m32q.json index e7c0f9a5a9c..b9041144df4 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff29-4hvm-m32q/GHSA-ff29-4hvm-m32q.json +++ b/advisories/unreviewed/2022/05/GHSA-ff29-4hvm-m32q/GHSA-ff29-4hvm-m32q.json @@ -7,12 +7,8 @@ "CVE-2007-5370" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff3h-vr24-34v2/GHSA-ff3h-vr24-34v2.json b/advisories/unreviewed/2022/05/GHSA-ff3h-vr24-34v2/GHSA-ff3h-vr24-34v2.json index 93ffb7f4ad8..cf9eb8e989c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff3h-vr24-34v2/GHSA-ff3h-vr24-34v2.json +++ b/advisories/unreviewed/2022/05/GHSA-ff3h-vr24-34v2/GHSA-ff3h-vr24-34v2.json @@ -7,12 +7,8 @@ "CVE-2007-5034" ], "details": "ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fff3-c2m4-3vrp/GHSA-fff3-c2m4-3vrp.json b/advisories/unreviewed/2022/05/GHSA-fff3-c2m4-3vrp/GHSA-fff3-c2m4-3vrp.json index e88983358d6..d39eb1678c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fff3-c2m4-3vrp/GHSA-fff3-c2m4-3vrp.json +++ b/advisories/unreviewed/2022/05/GHSA-fff3-c2m4-3vrp/GHSA-fff3-c2m4-3vrp.json @@ -7,12 +7,8 @@ "CVE-2007-5103" ], "details": "Directory traversal vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffm7-q4wq-6c5x/GHSA-ffm7-q4wq-6c5x.json b/advisories/unreviewed/2022/05/GHSA-ffm7-q4wq-6c5x/GHSA-ffm7-q4wq-6c5x.json index d99ebb20a21..0c79b7e7d23 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffm7-q4wq-6c5x/GHSA-ffm7-q4wq-6c5x.json +++ b/advisories/unreviewed/2022/05/GHSA-ffm7-q4wq-6c5x/GHSA-ffm7-q4wq-6c5x.json @@ -7,12 +7,8 @@ "CVE-2007-4805" ], "details": "Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffmh-3m8x-67m8/GHSA-ffmh-3m8x-67m8.json b/advisories/unreviewed/2022/05/GHSA-ffmh-3m8x-67m8/GHSA-ffmh-3m8x-67m8.json index 2087ddd1bc9..9f8fc2315bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffmh-3m8x-67m8/GHSA-ffmh-3m8x-67m8.json +++ b/advisories/unreviewed/2022/05/GHSA-ffmh-3m8x-67m8/GHSA-ffmh-3m8x-67m8.json @@ -7,12 +7,8 @@ "CVE-2007-4849" ], "details": "JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to \"legacy modes\" and an inconsistency between dentry permissions and inode permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgc4-c2m2-834g/GHSA-fgc4-c2m2-834g.json b/advisories/unreviewed/2022/05/GHSA-fgc4-c2m2-834g/GHSA-fgc4-c2m2-834g.json index 64f3a6cb823..a8160660c02 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgc4-c2m2-834g/GHSA-fgc4-c2m2-834g.json +++ b/advisories/unreviewed/2022/05/GHSA-fgc4-c2m2-834g/GHSA-fgc4-c2m2-834g.json @@ -7,12 +7,8 @@ "CVE-2007-5396" ], "details": "Format string vulnerability in the ext_yahoo_contact_added function in yahoo.c in Miranda IM 0.7.1 allows remote attackers to execute arbitrary code via a Y7 Buddy Authorization packet with format string specifiers in the contact Yahoo! handle (who).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh9q-jmr7-726h/GHSA-fh9q-jmr7-726h.json b/advisories/unreviewed/2022/05/GHSA-fh9q-jmr7-726h/GHSA-fh9q-jmr7-726h.json index dcea28a7955..1f987493b85 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh9q-jmr7-726h/GHSA-fh9q-jmr7-726h.json +++ b/advisories/unreviewed/2022/05/GHSA-fh9q-jmr7-726h/GHSA-fh9q-jmr7-726h.json @@ -7,12 +7,8 @@ "CVE-2007-5119" ], "details": "JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj59-m886-ch4f/GHSA-fj59-m886-ch4f.json b/advisories/unreviewed/2022/05/GHSA-fj59-m886-ch4f/GHSA-fj59-m886-ch4f.json index 92fb9f773c4..1f31889221e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj59-m886-ch4f/GHSA-fj59-m886-ch4f.json +++ b/advisories/unreviewed/2022/05/GHSA-fj59-m886-ch4f/GHSA-fj59-m886-ch4f.json @@ -7,12 +7,8 @@ "CVE-2007-5087" ], "details": "The ATM module in the Linux kernel before 2.4.35.3, when CLIP support is enabled, allows local users to cause a denial of service (kernel panic) by reading /proc/net/atm/arp before the CLIP module has been loaded.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm57-h9h8-h37f/GHSA-fm57-h9h8-h37f.json b/advisories/unreviewed/2022/05/GHSA-fm57-h9h8-h37f/GHSA-fm57-h9h8-h37f.json index daa23214456..c510987b6c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm57-h9h8-h37f/GHSA-fm57-h9h8-h37f.json +++ b/advisories/unreviewed/2022/05/GHSA-fm57-h9h8-h37f/GHSA-fm57-h9h8-h37f.json @@ -7,12 +7,8 @@ "CVE-2007-5058" ], "details": "Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not properly handled when the Monitor Web Syslog screen is open.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmrq-6vmh-qmmf/GHSA-fmrq-6vmh-qmmf.json b/advisories/unreviewed/2022/05/GHSA-fmrq-6vmh-qmmf/GHSA-fmrq-6vmh-qmmf.json index 28423d95d00..aeb988093a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmrq-6vmh-qmmf/GHSA-fmrq-6vmh-qmmf.json +++ b/advisories/unreviewed/2022/05/GHSA-fmrq-6vmh-qmmf/GHSA-fmrq-6vmh-qmmf.json @@ -7,12 +7,8 @@ "CVE-2006-1079" ], "details": "htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp55-fqvp-f88q/GHSA-fp55-fqvp-f88q.json b/advisories/unreviewed/2022/05/GHSA-fp55-fqvp-f88q/GHSA-fp55-fqvp-f88q.json index bd2fe4225e8..9efd56005df 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp55-fqvp-f88q/GHSA-fp55-fqvp-f88q.json +++ b/advisories/unreviewed/2022/05/GHSA-fp55-fqvp-f88q/GHSA-fp55-fqvp-f88q.json @@ -7,12 +7,8 @@ "CVE-2007-4582" ], "details": "Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpg6-49x7-pcjm/GHSA-fpg6-49x7-pcjm.json b/advisories/unreviewed/2022/05/GHSA-fpg6-49x7-pcjm/GHSA-fpg6-49x7-pcjm.json index af680b46723..63b3cda1516 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpg6-49x7-pcjm/GHSA-fpg6-49x7-pcjm.json +++ b/advisories/unreviewed/2022/05/GHSA-fpg6-49x7-pcjm/GHSA-fpg6-49x7-pcjm.json @@ -7,12 +7,8 @@ "CVE-2007-4584" ], "details": "Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpw6-4rcx-6349/GHSA-fpw6-4rcx-6349.json b/advisories/unreviewed/2022/05/GHSA-fpw6-4rcx-6349/GHSA-fpw6-4rcx-6349.json index 6ac9862aa96..39505c68413 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpw6-4rcx-6349/GHSA-fpw6-4rcx-6349.json +++ b/advisories/unreviewed/2022/05/GHSA-fpw6-4rcx-6349/GHSA-fpw6-4rcx-6349.json @@ -7,12 +7,8 @@ "CVE-2007-5042" ], "details": "Outpost Firewall Pro 4.0.1025.7828 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenProcess, (5) NtOpenSection, (6) NtOpenThread, and (7) NtUnloadDriver kernel SSDT hooks, a partial regression of CVE-2006-7160.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr5g-389p-fr7q/GHSA-fr5g-389p-fr7q.json b/advisories/unreviewed/2022/05/GHSA-fr5g-389p-fr7q/GHSA-fr5g-389p-fr7q.json index 0273583b809..bb88f7c39df 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr5g-389p-fr7q/GHSA-fr5g-389p-fr7q.json +++ b/advisories/unreviewed/2022/05/GHSA-fr5g-389p-fr7q/GHSA-fr5g-389p-fr7q.json @@ -7,12 +7,8 @@ "CVE-2007-4624" ], "details": "Cross-site scripting (XSS) vulnerability in pframe.php in AbleDesign Dynamic Picture Frame 1.00 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr5p-wxp2-3q76/GHSA-fr5p-wxp2-3q76.json b/advisories/unreviewed/2022/05/GHSA-fr5p-wxp2-3q76/GHSA-fr5p-wxp2-3q76.json index 2c29b58b47f..cdab5fa3555 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr5p-wxp2-3q76/GHSA-fr5p-wxp2-3q76.json +++ b/advisories/unreviewed/2022/05/GHSA-fr5p-wxp2-3q76/GHSA-fr5p-wxp2-3q76.json @@ -7,12 +7,8 @@ "CVE-2007-4887" ], "details": "The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frr3-95g2-cm9h/GHSA-frr3-95g2-cm9h.json b/advisories/unreviewed/2022/05/GHSA-frr3-95g2-cm9h/GHSA-frr3-95g2-cm9h.json index 542dc946e94..79a9e1456f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-frr3-95g2-cm9h/GHSA-frr3-95g2-cm9h.json +++ b/advisories/unreviewed/2022/05/GHSA-frr3-95g2-cm9h/GHSA-frr3-95g2-cm9h.json @@ -7,12 +7,8 @@ "CVE-2007-4531" ], "details": "Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many 0x07 or other control characters to the file transfer port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frv7-rf72-j8fp/GHSA-frv7-rf72-j8fp.json b/advisories/unreviewed/2022/05/GHSA-frv7-rf72-j8fp/GHSA-frv7-rf72-j8fp.json index c816c41ff11..83d6d229ead 100644 --- a/advisories/unreviewed/2022/05/GHSA-frv7-rf72-j8fp/GHSA-frv7-rf72-j8fp.json +++ b/advisories/unreviewed/2022/05/GHSA-frv7-rf72-j8fp/GHSA-frv7-rf72-j8fp.json @@ -7,12 +7,8 @@ "CVE-2007-4916" ], "details": "Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw6j-pc4w-5hpr/GHSA-fw6j-pc4w-5hpr.json b/advisories/unreviewed/2022/05/GHSA-fw6j-pc4w-5hpr/GHSA-fw6j-pc4w-5hpr.json index b9a6b41038b..cb05334c7d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw6j-pc4w-5hpr/GHSA-fw6j-pc4w-5hpr.json +++ b/advisories/unreviewed/2022/05/GHSA-fw6j-pc4w-5hpr/GHSA-fw6j-pc4w-5hpr.json @@ -7,12 +7,8 @@ "CVE-2007-4835" ], "details": "SQL injection vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx4h-wx28-j62f/GHSA-fx4h-wx28-j62f.json b/advisories/unreviewed/2022/05/GHSA-fx4h-wx28-j62f/GHSA-fx4h-wx28-j62f.json index ef30f3527db..1da67b56a0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx4h-wx28-j62f/GHSA-fx4h-wx28-j62f.json +++ b/advisories/unreviewed/2022/05/GHSA-fx4h-wx28-j62f/GHSA-fx4h-wx28-j62f.json @@ -7,12 +7,8 @@ "CVE-2007-4888" ], "details": "The \"You are not allowed...\" error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxg4-75m7-4xj5/GHSA-fxg4-75m7-4xj5.json b/advisories/unreviewed/2022/05/GHSA-fxg4-75m7-4xj5/GHSA-fxg4-75m7-4xj5.json index 555e90830e0..de3012161fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxg4-75m7-4xj5/GHSA-fxg4-75m7-4xj5.json +++ b/advisories/unreviewed/2022/05/GHSA-fxg4-75m7-4xj5/GHSA-fxg4-75m7-4xj5.json @@ -7,12 +7,8 @@ "CVE-2007-4985" ], "details": "ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g33f-v493-6g94/GHSA-g33f-v493-6g94.json b/advisories/unreviewed/2022/05/GHSA-g33f-v493-6g94/GHSA-g33f-v493-6g94.json index fbddd2ad355..f983ab2c62c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g33f-v493-6g94/GHSA-g33f-v493-6g94.json +++ b/advisories/unreviewed/2022/05/GHSA-g33f-v493-6g94/GHSA-g33f-v493-6g94.json @@ -7,12 +7,8 @@ "CVE-2007-5350" ], "details": "Unspecified vulnerability in the Windows Advanced Local Procedure Call (ALPC) in the kernel in Microsoft Windows Vista allows local users to gain privileges via unspecified vectors involving \"legacy reply paths.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3g6-4ppq-2qq2/GHSA-g3g6-4ppq-2qq2.json b/advisories/unreviewed/2022/05/GHSA-g3g6-4ppq-2qq2/GHSA-g3g6-4ppq-2qq2.json index 511df1631ef..5195dfa6c7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3g6-4ppq-2qq2/GHSA-g3g6-4ppq-2qq2.json +++ b/advisories/unreviewed/2022/05/GHSA-g3g6-4ppq-2qq2/GHSA-g3g6-4ppq-2qq2.json @@ -7,12 +7,8 @@ "CVE-2007-4914" ], "details": "Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1) class_gw_2checkout.php, (2) class_gw_authorizenet.php, (3) class_gw_nochex.php, (4) class_gw_paypal.php, and (5) class_gw_safshop.php in sources/classes/paymentgateways/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3wp-xgwh-q6mr/GHSA-g3wp-xgwh-q6mr.json b/advisories/unreviewed/2022/05/GHSA-g3wp-xgwh-q6mr/GHSA-g3wp-xgwh-q6mr.json index b6008aa415f..257f45f6820 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3wp-xgwh-q6mr/GHSA-g3wp-xgwh-q6mr.json +++ b/advisories/unreviewed/2022/05/GHSA-g3wp-xgwh-q6mr/GHSA-g3wp-xgwh-q6mr.json @@ -7,12 +7,8 @@ "CVE-2007-5388" ], "details": "Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g46g-pwfg-m9xh/GHSA-g46g-pwfg-m9xh.json b/advisories/unreviewed/2022/05/GHSA-g46g-pwfg-m9xh/GHSA-g46g-pwfg-m9xh.json index bca5088fb0b..f544348c6c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g46g-pwfg-m9xh/GHSA-g46g-pwfg-m9xh.json +++ b/advisories/unreviewed/2022/05/GHSA-g46g-pwfg-m9xh/GHSA-g46g-pwfg-m9xh.json @@ -7,12 +7,8 @@ "CVE-2007-5069" ], "details": "Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6cp-4pc8-6jfr/GHSA-g6cp-4pc8-6jfr.json b/advisories/unreviewed/2022/05/GHSA-g6cp-4pc8-6jfr/GHSA-g6cp-4pc8-6jfr.json index 26d63ff02c9..a427f7b5a2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6cp-4pc8-6jfr/GHSA-g6cp-4pc8-6jfr.json +++ b/advisories/unreviewed/2022/05/GHSA-g6cp-4pc8-6jfr/GHSA-g6cp-4pc8-6jfr.json @@ -7,12 +7,8 @@ "CVE-2007-5132" ], "details": "Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to \"the handling of thread contexts.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g72c-x5vr-f3wv/GHSA-g72c-x5vr-f3wv.json b/advisories/unreviewed/2022/05/GHSA-g72c-x5vr-f3wv/GHSA-g72c-x5vr-f3wv.json index b538463661b..03ac4db6e47 100644 --- a/advisories/unreviewed/2022/05/GHSA-g72c-x5vr-f3wv/GHSA-g72c-x5vr-f3wv.json +++ b/advisories/unreviewed/2022/05/GHSA-g72c-x5vr-f3wv/GHSA-g72c-x5vr-f3wv.json @@ -7,12 +7,8 @@ "CVE-2007-4594" ], "details": "Entrust Entelligence Security Provider (ESP) 8 does not properly validate certificates in certain circumstances involving (1) a chain that omits the root Certification Authority (CA) certificate, or an application that specifies disregarding (2) unknown revocation statuses during path validation or (3) certain errors in the certification path, which might allow context-dependent attackers to spoof certificate authentication. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8fr-x7v7-83c9/GHSA-g8fr-x7v7-83c9.json b/advisories/unreviewed/2022/05/GHSA-g8fr-x7v7-83c9/GHSA-g8fr-x7v7-83c9.json index 53a2cff62d4..067f3e4d66f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8fr-x7v7-83c9/GHSA-g8fr-x7v7-83c9.json +++ b/advisories/unreviewed/2022/05/GHSA-g8fr-x7v7-83c9/GHSA-g8fr-x7v7-83c9.json @@ -7,12 +7,8 @@ "CVE-2007-5348" ], "details": "Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka \"GDI+ VML Buffer Overrun Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8hp-mwjv-42vf/GHSA-g8hp-mwjv-42vf.json b/advisories/unreviewed/2022/05/GHSA-g8hp-mwjv-42vf/GHSA-g8hp-mwjv-42vf.json index 6c83e7f6027..f9933bbe9fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8hp-mwjv-42vf/GHSA-g8hp-mwjv-42vf.json +++ b/advisories/unreviewed/2022/05/GHSA-g8hp-mwjv-42vf/GHSA-g8hp-mwjv-42vf.json @@ -7,12 +7,8 @@ "CVE-2007-4541" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9c5-qwx9-4v48/GHSA-g9c5-qwx9-4v48.json b/advisories/unreviewed/2022/05/GHSA-g9c5-qwx9-4v48/GHSA-g9c5-qwx9-4v48.json index 9a12367245e..5bb93fa8be2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9c5-qwx9-4v48/GHSA-g9c5-qwx9-4v48.json +++ b/advisories/unreviewed/2022/05/GHSA-g9c5-qwx9-4v48/GHSA-g9c5-qwx9-4v48.json @@ -7,12 +7,8 @@ "CVE-2007-4792" ], "details": "Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9qg-5f6g-prc9/GHSA-g9qg-5f6g-prc9.json b/advisories/unreviewed/2022/05/GHSA-g9qg-5f6g-prc9/GHSA-g9qg-5f6g-prc9.json index f89ef756ac4..e2d18a0f71d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9qg-5f6g-prc9/GHSA-g9qg-5f6g-prc9.json +++ b/advisories/unreviewed/2022/05/GHSA-g9qg-5f6g-prc9/GHSA-g9qg-5f6g-prc9.json @@ -7,12 +7,8 @@ "CVE-2007-4706" ], "details": "Heap-based buffer overflow in Apple QuickTime before 7.3.1 allows remote attackers to execute arbitrary code via a crafted QTL file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc5f-h39r-wr75/GHSA-gc5f-h39r-wr75.json b/advisories/unreviewed/2022/05/GHSA-gc5f-h39r-wr75/GHSA-gc5f-h39r-wr75.json index 4787dab4094..cfdfd290d67 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc5f-h39r-wr75/GHSA-gc5f-h39r-wr75.json +++ b/advisories/unreviewed/2022/05/GHSA-gc5f-h39r-wr75/GHSA-gc5f-h39r-wr75.json @@ -7,12 +7,8 @@ "CVE-2007-4898" ], "details": "Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, with administrative access to one wiki in a multiwiki environment, to obtain sensitive information via unknown attack vectors. NOTE: Some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcf4-g49h-9mp5/GHSA-gcf4-g49h-9mp5.json b/advisories/unreviewed/2022/05/GHSA-gcf4-g49h-9mp5/GHSA-gcf4-g49h-9mp5.json index b0c8dd2a074..9e25480cb84 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcf4-g49h-9mp5/GHSA-gcf4-g49h-9mp5.json +++ b/advisories/unreviewed/2022/05/GHSA-gcf4-g49h-9mp5/GHSA-gcf4-g49h-9mp5.json @@ -7,12 +7,8 @@ "CVE-2007-5106" ], "details": "Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf2x-9g2r-6hp6/GHSA-gf2x-9g2r-6hp6.json b/advisories/unreviewed/2022/05/GHSA-gf2x-9g2r-6hp6/GHSA-gf2x-9g2r-6hp6.json index dad3b2c1ed6..753fb5d1945 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf2x-9g2r-6hp6/GHSA-gf2x-9g2r-6hp6.json +++ b/advisories/unreviewed/2022/05/GHSA-gf2x-9g2r-6hp6/GHSA-gf2x-9g2r-6hp6.json @@ -7,12 +7,8 @@ "CVE-2007-4570" ], "details": "Algorithmic complexity vulnerability in the MCS translation daemon in mcstrans 0.2.3 allows local users to cause a denial of service (temporary daemon outage) via a large range of compartments in sensitivity labels.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf8m-65gr-j3wr/GHSA-gf8m-65gr-j3wr.json b/advisories/unreviewed/2022/05/GHSA-gf8m-65gr-j3wr/GHSA-gf8m-65gr-j3wr.json index 6068ea5bf57..405ab90ace8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf8m-65gr-j3wr/GHSA-gf8m-65gr-j3wr.json +++ b/advisories/unreviewed/2022/05/GHSA-gf8m-65gr-j3wr/GHSA-gf8m-65gr-j3wr.json @@ -7,12 +7,8 @@ "CVE-2007-4793" ], "details": "Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg9q-rhfx-24wv/GHSA-gg9q-rhfx-24wv.json b/advisories/unreviewed/2022/05/GHSA-gg9q-rhfx-24wv/GHSA-gg9q-rhfx-24wv.json index d8d1d050b36..7e1c1662814 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg9q-rhfx-24wv/GHSA-gg9q-rhfx-24wv.json +++ b/advisories/unreviewed/2022/05/GHSA-gg9q-rhfx-24wv/GHSA-gg9q-rhfx-24wv.json @@ -7,12 +7,8 @@ "CVE-2007-5063" ], "details": "Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggh7-8g84-pcwc/GHSA-ggh7-8g84-pcwc.json b/advisories/unreviewed/2022/05/GHSA-ggh7-8g84-pcwc/GHSA-ggh7-8g84-pcwc.json index 75a1516feec..aef5f39884d 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggh7-8g84-pcwc/GHSA-ggh7-8g84-pcwc.json +++ b/advisories/unreviewed/2022/05/GHSA-ggh7-8g84-pcwc/GHSA-ggh7-8g84-pcwc.json @@ -7,12 +7,8 @@ "CVE-2007-4861" ], "details": "SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggj7-gjcg-p52j/GHSA-ggj7-gjcg-p52j.json b/advisories/unreviewed/2022/05/GHSA-ggj7-gjcg-p52j/GHSA-ggj7-gjcg-p52j.json index 45a06d2029b..01dffbef5c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggj7-gjcg-p52j/GHSA-ggj7-gjcg-p52j.json +++ b/advisories/unreviewed/2022/05/GHSA-ggj7-gjcg-p52j/GHSA-ggj7-gjcg-p52j.json @@ -7,12 +7,8 @@ "CVE-2007-4586" ], "details": "Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary code, probably during Unicode conversion, as demonstrated by a long string in the first argument to the iis_getservicestate function, related to the ServiceId argument to the (1) fnStartService, (2) fnGetServiceState, (3) fnStopService, and possibly other functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm64-4hqj-9wvv/GHSA-gm64-4hqj-9wvv.json b/advisories/unreviewed/2022/05/GHSA-gm64-4hqj-9wvv/GHSA-gm64-4hqj-9wvv.json index 97c8fdc3dce..b72ff4f2310 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm64-4hqj-9wvv/GHSA-gm64-4hqj-9wvv.json +++ b/advisories/unreviewed/2022/05/GHSA-gm64-4hqj-9wvv/GHSA-gm64-4hqj-9wvv.json @@ -7,12 +7,8 @@ "CVE-2007-4661" ], "details": "The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmpq-39vg-grj4/GHSA-gmpq-39vg-grj4.json b/advisories/unreviewed/2022/05/GHSA-gmpq-39vg-grj4/GHSA-gmpq-39vg-grj4.json index 46d59b968da..256c4c90459 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmpq-39vg-grj4/GHSA-gmpq-39vg-grj4.json +++ b/advisories/unreviewed/2022/05/GHSA-gmpq-39vg-grj4/GHSA-gmpq-39vg-grj4.json @@ -7,12 +7,8 @@ "CVE-2007-5229" ], "details": "Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url and (2) feedburner_comments_url parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpcw-f7pf-95mq/GHSA-gpcw-f7pf-95mq.json b/advisories/unreviewed/2022/05/GHSA-gpcw-f7pf-95mq/GHSA-gpcw-f7pf-95mq.json index 9d1d437cc7e..5492a684798 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpcw-f7pf-95mq/GHSA-gpcw-f7pf-95mq.json +++ b/advisories/unreviewed/2022/05/GHSA-gpcw-f7pf-95mq/GHSA-gpcw-f7pf-95mq.json @@ -7,12 +7,8 @@ "CVE-2007-4824" ], "details": "Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq66-v529-ggp7/GHSA-gq66-v529-ggp7.json b/advisories/unreviewed/2022/05/GHSA-gq66-v529-ggp7/GHSA-gq66-v529-ggp7.json index d95f154e117..3f933656407 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq66-v529-ggp7/GHSA-gq66-v529-ggp7.json +++ b/advisories/unreviewed/2022/05/GHSA-gq66-v529-ggp7/GHSA-gq66-v529-ggp7.json @@ -7,12 +7,8 @@ "CVE-2007-4611" ], "details": "SQL injection vulnerability in viewevent.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq79-35xw-52pq/GHSA-gq79-35xw-52pq.json b/advisories/unreviewed/2022/05/GHSA-gq79-35xw-52pq/GHSA-gq79-35xw-52pq.json index a7c47251455..497a1b7b1f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq79-35xw-52pq/GHSA-gq79-35xw-52pq.json +++ b/advisories/unreviewed/2022/05/GHSA-gq79-35xw-52pq/GHSA-gq79-35xw-52pq.json @@ -7,12 +7,8 @@ "CVE-2007-5337" ], "details": "Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqjh-2785-54rv/GHSA-gqjh-2785-54rv.json b/advisories/unreviewed/2022/05/GHSA-gqjh-2785-54rv/GHSA-gqjh-2785-54rv.json index 0cbda9b9f75..056f0dd7b59 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqjh-2785-54rv/GHSA-gqjh-2785-54rv.json +++ b/advisories/unreviewed/2022/05/GHSA-gqjh-2785-54rv/GHSA-gqjh-2785-54rv.json @@ -7,12 +7,8 @@ "CVE-2007-4757" ], "details": "PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqrv-6h9g-24p5/GHSA-gqrv-6h9g-24p5.json b/advisories/unreviewed/2022/05/GHSA-gqrv-6h9g-24p5/GHSA-gqrv-6h9g-24p5.json index f89ec9e1c34..65c0db4a0af 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqrv-6h9g-24p5/GHSA-gqrv-6h9g-24p5.json +++ b/advisories/unreviewed/2022/05/GHSA-gqrv-6h9g-24p5/GHSA-gqrv-6h9g-24p5.json @@ -7,12 +7,8 @@ "CVE-2007-4758" ], "details": "Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr86-66x3-hw46/GHSA-gr86-66x3-hw46.json b/advisories/unreviewed/2022/05/GHSA-gr86-66x3-hw46/GHSA-gr86-66x3-hw46.json index 1a59f6c5cf3..5922b18e76f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr86-66x3-hw46/GHSA-gr86-66x3-hw46.json +++ b/advisories/unreviewed/2022/05/GHSA-gr86-66x3-hw46/GHSA-gr86-66x3-hw46.json @@ -7,12 +7,8 @@ "CVE-2007-4936" ], "details": "Unspecified vulnerability in Office Efficiencies SafeSquid 4.1.x has unknown impact and attack vectors, related to a \"serious security flaw,\" possibly specific to Linux.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grf4-rjfm-p934/GHSA-grf4-rjfm-p934.json b/advisories/unreviewed/2022/05/GHSA-grf4-rjfm-p934/GHSA-grf4-rjfm-p934.json index d6772e5bec5..d9467434f3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-grf4-rjfm-p934/GHSA-grf4-rjfm-p934.json +++ b/advisories/unreviewed/2022/05/GHSA-grf4-rjfm-p934/GHSA-grf4-rjfm-p934.json @@ -7,12 +7,8 @@ "CVE-2007-5231" ], "details": "Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv44-wp79-c9g9/GHSA-gv44-wp79-c9g9.json b/advisories/unreviewed/2022/05/GHSA-gv44-wp79-c9g9/GHSA-gv44-wp79-c9g9.json index b1c48361f95..afe7f793e10 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv44-wp79-c9g9/GHSA-gv44-wp79-c9g9.json +++ b/advisories/unreviewed/2022/05/GHSA-gv44-wp79-c9g9/GHSA-gv44-wp79-c9g9.json @@ -7,12 +7,8 @@ "CVE-2007-5108" ], "details": "Unspecified vulnerability in IAC Search & Media ask.com toolbar has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. NOTE: this might be the same issue as CVE-2007-5107.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gv4p-444g-3cqq/GHSA-gv4p-444g-3cqq.json b/advisories/unreviewed/2022/05/GHSA-gv4p-444g-3cqq/GHSA-gv4p-444g-3cqq.json index bcfd599ef86..1d23115f087 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv4p-444g-3cqq/GHSA-gv4p-444g-3cqq.json +++ b/advisories/unreviewed/2022/05/GHSA-gv4p-444g-3cqq/GHSA-gv4p-444g-3cqq.json @@ -7,12 +7,8 @@ "CVE-2007-5037" ], "details": "Buffer overflow in the inotifytools_snprintf function in src/inotifytools.c in the inotify-tools library before 3.11 allows context-dependent attackers to execute arbitrary code via a long filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvf5-m6hg-5jhj/GHSA-gvf5-m6hg-5jhj.json b/advisories/unreviewed/2022/05/GHSA-gvf5-m6hg-5jhj/GHSA-gvf5-m6hg-5jhj.json index 65f0306365f..450d8a270cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvf5-m6hg-5jhj/GHSA-gvf5-m6hg-5jhj.json +++ b/advisories/unreviewed/2022/05/GHSA-gvf5-m6hg-5jhj/GHSA-gvf5-m6hg-5jhj.json @@ -7,12 +7,8 @@ "CVE-2007-5044" ], "details": "ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreatePort and (2) NtDeleteFile kernel SSDT hooks, a partial regression of CVE-2007-2083.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gw78-w7cp-x422/GHSA-gw78-w7cp-x422.json b/advisories/unreviewed/2022/05/GHSA-gw78-w7cp-x422/GHSA-gw78-w7cp-x422.json index ee81abdff33..224dff117e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw78-w7cp-x422/GHSA-gw78-w7cp-x422.json +++ b/advisories/unreviewed/2022/05/GHSA-gw78-w7cp-x422/GHSA-gw78-w7cp-x422.json @@ -7,12 +7,8 @@ "CVE-2007-4933" ], "details": "Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as demonstrated with the (1) productscount, (2) colscount, and (3) darkcolor parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwc2-wvg9-qvwv/GHSA-gwc2-wvg9-qvwv.json b/advisories/unreviewed/2022/05/GHSA-gwc2-wvg9-qvwv/GHSA-gwc2-wvg9-qvwv.json index 4f1fa83bc40..493dbcba23c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwc2-wvg9-qvwv/GHSA-gwc2-wvg9-qvwv.json +++ b/advisories/unreviewed/2022/05/GHSA-gwc2-wvg9-qvwv/GHSA-gwc2-wvg9-qvwv.json @@ -7,12 +7,8 @@ "CVE-2007-4740" ], "details": "The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to create registry keys and values via the arguments to the WriteRegistry method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwp9-cp8r-q434/GHSA-gwp9-cp8r-q434.json b/advisories/unreviewed/2022/05/GHSA-gwp9-cp8r-q434/GHSA-gwp9-cp8r-q434.json index 04adabfdb0b..a6c21fef2cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwp9-cp8r-q434/GHSA-gwp9-cp8r-q434.json +++ b/advisories/unreviewed/2022/05/GHSA-gwp9-cp8r-q434/GHSA-gwp9-cp8r-q434.json @@ -7,12 +7,8 @@ "CVE-2007-4830" ], "details": "Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxw8-2q5v-99mc/GHSA-gxw8-2q5v-99mc.json b/advisories/unreviewed/2022/05/GHSA-gxw8-2q5v-99mc/GHSA-gxw8-2q5v-99mc.json index 34aa29882a7..4e06e9e65b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxw8-2q5v-99mc/GHSA-gxw8-2q5v-99mc.json +++ b/advisories/unreviewed/2022/05/GHSA-gxw8-2q5v-99mc/GHSA-gxw8-2q5v-99mc.json @@ -7,12 +7,8 @@ "CVE-2007-4602" ], "details": "SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h34c-mw5f-jrf3/GHSA-h34c-mw5f-jrf3.json b/advisories/unreviewed/2022/05/GHSA-h34c-mw5f-jrf3/GHSA-h34c-mw5f-jrf3.json index 1d1485a9591..b39a91db2a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h34c-mw5f-jrf3/GHSA-h34c-mw5f-jrf3.json +++ b/advisories/unreviewed/2022/05/GHSA-h34c-mw5f-jrf3/GHSA-h34c-mw5f-jrf3.json @@ -7,12 +7,8 @@ "CVE-2007-4650" ], "details": "Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using \"linked items\" in WebDAV and (b) Reupload modules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h42m-cfwq-x7m7/GHSA-h42m-cfwq-x7m7.json b/advisories/unreviewed/2022/05/GHSA-h42m-cfwq-x7m7/GHSA-h42m-cfwq-x7m7.json index 0af9742c25b..f95bf97a151 100644 --- a/advisories/unreviewed/2022/05/GHSA-h42m-cfwq-x7m7/GHSA-h42m-cfwq-x7m7.json +++ b/advisories/unreviewed/2022/05/GHSA-h42m-cfwq-x7m7/GHSA-h42m-cfwq-x7m7.json @@ -7,12 +7,8 @@ "CVE-2007-4939" ], "details": "Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with an \"indx truck size\" of 0xffffffff, and certain wLongsPerEntry and nEntriesInuse values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h593-56f6-7c6g/GHSA-h593-56f6-7c6g.json b/advisories/unreviewed/2022/05/GHSA-h593-56f6-7c6g/GHSA-h593-56f6-7c6g.json index 2a052bd5eb3..51ecacd7326 100644 --- a/advisories/unreviewed/2022/05/GHSA-h593-56f6-7c6g/GHSA-h593-56f6-7c6g.json +++ b/advisories/unreviewed/2022/05/GHSA-h593-56f6-7c6g/GHSA-h593-56f6-7c6g.json @@ -7,12 +7,8 @@ "CVE-2007-4814" ], "details": "Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5jv-54pc-fqch/GHSA-h5jv-54pc-fqch.json b/advisories/unreviewed/2022/05/GHSA-h5jv-54pc-fqch/GHSA-h5jv-54pc-fqch.json index 6998d80f7c1..ddb963db2cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5jv-54pc-fqch/GHSA-h5jv-54pc-fqch.json +++ b/advisories/unreviewed/2022/05/GHSA-h5jv-54pc-fqch/GHSA-h5jv-54pc-fqch.json @@ -7,12 +7,8 @@ "CVE-2007-4817" ], "details": "Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5xx-q7q7-vpqh/GHSA-h5xx-q7q7-vpqh.json b/advisories/unreviewed/2022/05/GHSA-h5xx-q7q7-vpqh/GHSA-h5xx-q7q7-vpqh.json index 887dfa04637..682f3e6e467 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5xx-q7q7-vpqh/GHSA-h5xx-q7q7-vpqh.json +++ b/advisories/unreviewed/2022/05/GHSA-h5xx-q7q7-vpqh/GHSA-h5xx-q7q7-vpqh.json @@ -7,12 +7,8 @@ "CVE-2007-5190" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the action parameter to php-bin/Webclient.php or (2) the Langue parameter to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6f6-m3cj-r7wc/GHSA-h6f6-m3cj-r7wc.json b/advisories/unreviewed/2022/05/GHSA-h6f6-m3cj-r7wc/GHSA-h6f6-m3cj-r7wc.json index a4f86550336..ef3c7e2cc06 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6f6-m3cj-r7wc/GHSA-h6f6-m3cj-r7wc.json +++ b/advisories/unreviewed/2022/05/GHSA-h6f6-m3cj-r7wc/GHSA-h6f6-m3cj-r7wc.json @@ -7,12 +7,8 @@ "CVE-2007-4974" ], "details": "Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6vv-phq2-pfpp/GHSA-h6vv-phq2-pfpp.json b/advisories/unreviewed/2022/05/GHSA-h6vv-phq2-pfpp/GHSA-h6vv-phq2-pfpp.json index bec5162cdeb..c388ff0977f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6vv-phq2-pfpp/GHSA-h6vv-phq2-pfpp.json +++ b/advisories/unreviewed/2022/05/GHSA-h6vv-phq2-pfpp/GHSA-h6vv-phq2-pfpp.json @@ -7,12 +7,8 @@ "CVE-2007-4542" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in mapserv.c in the mapserv CGI program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h749-rwwx-gp8x/GHSA-h749-rwwx-gp8x.json b/advisories/unreviewed/2022/05/GHSA-h749-rwwx-gp8x/GHSA-h749-rwwx-gp8x.json index 53d741dbcea..1fe2f42c759 100644 --- a/advisories/unreviewed/2022/05/GHSA-h749-rwwx-gp8x/GHSA-h749-rwwx-gp8x.json +++ b/advisories/unreviewed/2022/05/GHSA-h749-rwwx-gp8x/GHSA-h749-rwwx-gp8x.json @@ -7,12 +7,8 @@ "CVE-2007-4841" ], "details": "Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid \"%\" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7gj-9j6j-r96x/GHSA-h7gj-9j6j-r96x.json b/advisories/unreviewed/2022/05/GHSA-h7gj-9j6j-r96x/GHSA-h7gj-9j6j-r96x.json index 4c8f616a860..baa87d932ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7gj-9j6j-r96x/GHSA-h7gj-9j6j-r96x.json +++ b/advisories/unreviewed/2022/05/GHSA-h7gj-9j6j-r96x/GHSA-h7gj-9j6j-r96x.json @@ -7,12 +7,8 @@ "CVE-2007-5081" ], "details": "Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9w4-j6rm-hfwg/GHSA-h9w4-j6rm-hfwg.json b/advisories/unreviewed/2022/05/GHSA-h9w4-j6rm-hfwg/GHSA-h9w4-j6rm-hfwg.json index a6bf2e233df..f105cc8ecff 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9w4-j6rm-hfwg/GHSA-h9w4-j6rm-hfwg.json +++ b/advisories/unreviewed/2022/05/GHSA-h9w4-j6rm-hfwg/GHSA-h9w4-j6rm-hfwg.json @@ -7,12 +7,8 @@ "CVE-2007-5025" ], "details": "Unspecified vulnerability in EMC VMware ACE before 1.0.3 Build 54075 allows attackers to have an unknown impact via an unspecified manipulation of \"images stored in virtual machines downloaded by the user.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hc4q-w87j-xx5v/GHSA-hc4q-w87j-xx5v.json b/advisories/unreviewed/2022/05/GHSA-hc4q-w87j-xx5v/GHSA-hc4q-w87j-xx5v.json index 7f947107de1..a099581630e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc4q-w87j-xx5v/GHSA-hc4q-w87j-xx5v.json +++ b/advisories/unreviewed/2022/05/GHSA-hc4q-w87j-xx5v/GHSA-hc4q-w87j-xx5v.json @@ -7,12 +7,8 @@ "CVE-2007-5385" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgjp-wv7w-gjj9/GHSA-hgjp-wv7w-gjj9.json b/advisories/unreviewed/2022/05/GHSA-hgjp-wv7w-gjj9/GHSA-hgjp-wv7w-gjj9.json index d702025b81f..6b8b4a3a1e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgjp-wv7w-gjj9/GHSA-hgjp-wv7w-gjj9.json +++ b/advisories/unreviewed/2022/05/GHSA-hgjp-wv7w-gjj9/GHSA-hgjp-wv7w-gjj9.json @@ -7,12 +7,8 @@ "CVE-2007-4955" ], "details": "PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhg9-24h6-vgfp/GHSA-hhg9-24h6-vgfp.json b/advisories/unreviewed/2022/05/GHSA-hhg9-24h6-vgfp/GHSA-hhg9-24h6-vgfp.json index 74cfbe336ba..d8193f1d8ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhg9-24h6-vgfp/GHSA-hhg9-24h6-vgfp.json +++ b/advisories/unreviewed/2022/05/GHSA-hhg9-24h6-vgfp/GHSA-hhg9-24h6-vgfp.json @@ -7,12 +7,8 @@ "CVE-2007-4762" ], "details": "Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass fields, different vectors than CVE-2007-0092.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjgh-mjrj-x6h8/GHSA-hjgh-mjrj-x6h8.json b/advisories/unreviewed/2022/05/GHSA-hjgh-mjrj-x6h8/GHSA-hjgh-mjrj-x6h8.json index 516bc64de77..c4bf006d117 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjgh-mjrj-x6h8/GHSA-hjgh-mjrj-x6h8.json +++ b/advisories/unreviewed/2022/05/GHSA-hjgh-mjrj-x6h8/GHSA-hjgh-mjrj-x6h8.json @@ -7,12 +7,8 @@ "CVE-2007-5090" ], "details": "Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm63-rvp6-rvmj/GHSA-hm63-rvp6-rvmj.json b/advisories/unreviewed/2022/05/GHSA-hm63-rvp6-rvmj/GHSA-hm63-rvp6-rvmj.json index eab8d04d13f..c528b32a2ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm63-rvp6-rvmj/GHSA-hm63-rvp6-rvmj.json +++ b/advisories/unreviewed/2022/05/GHSA-hm63-rvp6-rvmj/GHSA-hm63-rvp6-rvmj.json @@ -7,12 +7,8 @@ "CVE-2007-4893" ], "details": "wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp4x-jx54-qxcp/GHSA-hp4x-jx54-qxcp.json b/advisories/unreviewed/2022/05/GHSA-hp4x-jx54-qxcp/GHSA-hp4x-jx54-qxcp.json index b717e26484d..99ce26cabca 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp4x-jx54-qxcp/GHSA-hp4x-jx54-qxcp.json +++ b/advisories/unreviewed/2022/05/GHSA-hp4x-jx54-qxcp/GHSA-hp4x-jx54-qxcp.json @@ -7,12 +7,8 @@ "CVE-2007-4528" ], "details": "The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code by loading an arbitrary DLL and calling a function, as demonstrated by kernel32.dll and the WinExec function. NOTE: this issue does not cross privilege boundaries in most contexts, so perhaps it should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpwp-5g25-7cjp/GHSA-hpwp-5g25-7cjp.json b/advisories/unreviewed/2022/05/GHSA-hpwp-5g25-7cjp/GHSA-hpwp-5g25-7cjp.json index 5f30aa1d00c..5a49cb4fe4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpwp-5g25-7cjp/GHSA-hpwp-5g25-7cjp.json +++ b/advisories/unreviewed/2022/05/GHSA-hpwp-5g25-7cjp/GHSA-hpwp-5g25-7cjp.json @@ -7,12 +7,8 @@ "CVE-2007-4803" ], "details": "Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls file, as demonstrated by the (1) File1 and (2) Title1 fields, different vectors than CVE-2006-6287 and CVE-2007-2487.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqrx-9wh5-2757/GHSA-hqrx-9wh5-2757.json b/advisories/unreviewed/2022/05/GHSA-hqrx-9wh5-2757/GHSA-hqrx-9wh5-2757.json index 371e551869f..4431cd8ced8 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqrx-9wh5-2757/GHSA-hqrx-9wh5-2757.json +++ b/advisories/unreviewed/2022/05/GHSA-hqrx-9wh5-2757/GHSA-hqrx-9wh5-2757.json @@ -7,12 +7,8 @@ "CVE-2007-4941" ], "details": "KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large \"indx truck size\" and nEntriesInuse values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hr69-fv9h-fxgr/GHSA-hr69-fv9h-fxgr.json b/advisories/unreviewed/2022/05/GHSA-hr69-fv9h-fxgr/GHSA-hr69-fv9h-fxgr.json index e3196beeac6..971014aaaca 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr69-fv9h-fxgr/GHSA-hr69-fv9h-fxgr.json +++ b/advisories/unreviewed/2022/05/GHSA-hr69-fv9h-fxgr/GHSA-hr69-fv9h-fxgr.json @@ -7,12 +7,8 @@ "CVE-2007-5057" ], "details": "NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrp4-5hx4-fh2v/GHSA-hrp4-5hx4-fh2v.json b/advisories/unreviewed/2022/05/GHSA-hrp4-5hx4-fh2v/GHSA-hrp4-5hx4-fh2v.json index 6eabce40367..9c882408cc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrp4-5hx4-fh2v/GHSA-hrp4-5hx4-fh2v.json +++ b/advisories/unreviewed/2022/05/GHSA-hrp4-5hx4-fh2v/GHSA-hrp4-5hx4-fh2v.json @@ -7,12 +7,8 @@ "CVE-2007-4818" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) addons/plugin.php, (2) addons/sidebar.php, (3) mail/index.php, or (4) mail/mailbox.php in modules/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrp4-6cpf-rhjm/GHSA-hrp4-6cpf-rhjm.json b/advisories/unreviewed/2022/05/GHSA-hrp4-6cpf-rhjm/GHSA-hrp4-6cpf-rhjm.json index 5accc297a6b..555f756d5af 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrp4-6cpf-rhjm/GHSA-hrp4-6cpf-rhjm.json +++ b/advisories/unreviewed/2022/05/GHSA-hrp4-6cpf-rhjm/GHSA-hrp4-6cpf-rhjm.json @@ -7,12 +7,8 @@ "CVE-2007-4664" ], "details": "Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvg6-mg9g-7v8m/GHSA-hvg6-mg9g-7v8m.json b/advisories/unreviewed/2022/05/GHSA-hvg6-mg9g-7v8m/GHSA-hvg6-mg9g-7v8m.json index 6472ca9fbca..030cd1ade26 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvg6-mg9g-7v8m/GHSA-hvg6-mg9g-7v8m.json +++ b/advisories/unreviewed/2022/05/GHSA-hvg6-mg9g-7v8m/GHSA-hvg6-mg9g-7v8m.json @@ -7,12 +7,8 @@ "CVE-2007-4899" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxjf-58cv-mq7r/GHSA-hxjf-58cv-mq7r.json b/advisories/unreviewed/2022/05/GHSA-hxjf-58cv-mq7r/GHSA-hxjf-58cv-mq7r.json index 1bccfd99205..231c22699d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxjf-58cv-mq7r/GHSA-hxjf-58cv-mq7r.json +++ b/advisories/unreviewed/2022/05/GHSA-hxjf-58cv-mq7r/GHSA-hxjf-58cv-mq7r.json @@ -7,12 +7,8 @@ "CVE-2007-5195" ], "details": "Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5196.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxwp-4p6g-pwx5/GHSA-hxwp-4p6g-pwx5.json b/advisories/unreviewed/2022/05/GHSA-hxwp-4p6g-pwx5/GHSA-hxwp-4p6g-pwx5.json index a5b541155bd..67cdb790fb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxwp-4p6g-pwx5/GHSA-hxwp-4p6g-pwx5.json +++ b/advisories/unreviewed/2022/05/GHSA-hxwp-4p6g-pwx5/GHSA-hxwp-4p6g-pwx5.json @@ -7,12 +7,8 @@ "CVE-2007-5026" ], "details": "dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j287-mh8c-4q25/GHSA-j287-mh8c-4q25.json b/advisories/unreviewed/2022/05/GHSA-j287-mh8c-4q25/GHSA-j287-mh8c-4q25.json index 57f5c7b3b72..0e33dba4f05 100644 --- a/advisories/unreviewed/2022/05/GHSA-j287-mh8c-4q25/GHSA-j287-mh8c-4q25.json +++ b/advisories/unreviewed/2022/05/GHSA-j287-mh8c-4q25/GHSA-j287-mh8c-4q25.json @@ -7,12 +7,8 @@ "CVE-2007-4681" ], "details": "Buffer overflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted directory hierarchy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2p8-g6v3-58rx/GHSA-j2p8-g6v3-58rx.json b/advisories/unreviewed/2022/05/GHSA-j2p8-g6v3-58rx/GHSA-j2p8-g6v3-58rx.json index 802aca18067..5bb6123d7d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2p8-g6v3-58rx/GHSA-j2p8-g6v3-58rx.json +++ b/advisories/unreviewed/2022/05/GHSA-j2p8-g6v3-58rx/GHSA-j2p8-g6v3-58rx.json @@ -7,12 +7,8 @@ "CVE-2007-5377" ], "details": "The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2qg-mp2j-cf9c/GHSA-j2qg-mp2j-cf9c.json b/advisories/unreviewed/2022/05/GHSA-j2qg-mp2j-cf9c/GHSA-j2qg-mp2j-cf9c.json index ba6819e42fc..0147cc5592a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2qg-mp2j-cf9c/GHSA-j2qg-mp2j-cf9c.json +++ b/advisories/unreviewed/2022/05/GHSA-j2qg-mp2j-cf9c/GHSA-j2qg-mp2j-cf9c.json @@ -7,12 +7,8 @@ "CVE-2007-4634" ], "details": "Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2vf-pvm4-m5gc/GHSA-j2vf-pvm4-m5gc.json b/advisories/unreviewed/2022/05/GHSA-j2vf-pvm4-m5gc/GHSA-j2vf-pvm4-m5gc.json index 199e9411ea7..4f9ddf21abc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2vf-pvm4-m5gc/GHSA-j2vf-pvm4-m5gc.json +++ b/advisories/unreviewed/2022/05/GHSA-j2vf-pvm4-m5gc/GHSA-j2vf-pvm4-m5gc.json @@ -7,12 +7,8 @@ "CVE-2007-4932" ], "details": "admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j47m-m564-x4jv/GHSA-j47m-m564-x4jv.json b/advisories/unreviewed/2022/05/GHSA-j47m-m564-x4jv/GHSA-j47m-m564-x4jv.json index 4f08913c0f0..79062a1dd93 100644 --- a/advisories/unreviewed/2022/05/GHSA-j47m-m564-x4jv/GHSA-j47m-m564-x4jv.json +++ b/advisories/unreviewed/2022/05/GHSA-j47m-m564-x4jv/GHSA-j47m-m564-x4jv.json @@ -7,12 +7,8 @@ "CVE-2007-5109" ], "details": "Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user parameter and modified (1) regpass and (2) level parameters in a none_Login action, as demonstrated by using a Flash object to automatically make the request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j647-j6p7-jhrq/GHSA-j647-j6p7-jhrq.json b/advisories/unreviewed/2022/05/GHSA-j647-j6p7-jhrq/GHSA-j647-j6p7-jhrq.json index d84c604f6c5..aff3d72590c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j647-j6p7-jhrq/GHSA-j647-j6p7-jhrq.json +++ b/advisories/unreviewed/2022/05/GHSA-j647-j6p7-jhrq/GHSA-j647-j6p7-jhrq.json @@ -7,12 +7,8 @@ "CVE-2007-5325" ], "details": "Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j655-x3rh-vhr4/GHSA-j655-x3rh-vhr4.json b/advisories/unreviewed/2022/05/GHSA-j655-x3rh-vhr4/GHSA-j655-x3rh-vhr4.json index 081ca257661..ee8749c9b7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j655-x3rh-vhr4/GHSA-j655-x3rh-vhr4.json +++ b/advisories/unreviewed/2022/05/GHSA-j655-x3rh-vhr4/GHSA-j655-x3rh-vhr4.json @@ -7,12 +7,8 @@ "CVE-2007-4701" ], "details": "WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6fg-jv37-v833/GHSA-j6fg-jv37-v833.json b/advisories/unreviewed/2022/05/GHSA-j6fg-jv37-v833/GHSA-j6fg-jv37-v833.json index f09018e9465..5e7862d0a07 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6fg-jv37-v833/GHSA-j6fg-jv37-v833.json +++ b/advisories/unreviewed/2022/05/GHSA-j6fg-jv37-v833/GHSA-j6fg-jv37-v833.json @@ -7,12 +7,8 @@ "CVE-2007-5028" ], "details": "Dibbler 0.6.0 on Linux uses weak world-writable permissions for unspecified files in /var/lib/dibbler, which has unknown impact and local attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j79f-87w9-r54g/GHSA-j79f-87w9-r54g.json b/advisories/unreviewed/2022/05/GHSA-j79f-87w9-r54g/GHSA-j79f-87w9-r54g.json index 662c8000e12..f0794eab198 100644 --- a/advisories/unreviewed/2022/05/GHSA-j79f-87w9-r54g/GHSA-j79f-87w9-r54g.json +++ b/advisories/unreviewed/2022/05/GHSA-j79f-87w9-r54g/GHSA-j79f-87w9-r54g.json @@ -7,12 +7,8 @@ "CVE-2007-4808" ], "details": "Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j79j-qx45-g3gp/GHSA-j79j-qx45-g3gp.json b/advisories/unreviewed/2022/05/GHSA-j79j-qx45-g3gp/GHSA-j79j-qx45-g3gp.json index 0b9825f66c4..595fd72efb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j79j-qx45-g3gp/GHSA-j79j-qx45-g3gp.json +++ b/advisories/unreviewed/2022/05/GHSA-j79j-qx45-g3gp/GHSA-j79j-qx45-g3gp.json @@ -7,12 +7,8 @@ "CVE-2007-5056" ], "details": "Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7jp-rgph-7546/GHSA-j7jp-rgph-7546.json b/advisories/unreviewed/2022/05/GHSA-j7jp-rgph-7546/GHSA-j7jp-rgph-7546.json index f9d539b73ad..5aa2236992f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7jp-rgph-7546/GHSA-j7jp-rgph-7546.json +++ b/advisories/unreviewed/2022/05/GHSA-j7jp-rgph-7546/GHSA-j7jp-rgph-7546.json @@ -7,12 +7,8 @@ "CVE-2007-4652" ], "details": "The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8mf-vg8w-fx4p/GHSA-j8mf-vg8w-fx4p.json b/advisories/unreviewed/2022/05/GHSA-j8mf-vg8w-fx4p/GHSA-j8mf-vg8w-fx4p.json index 747e8624551..820af676a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8mf-vg8w-fx4p/GHSA-j8mf-vg8w-fx4p.json +++ b/advisories/unreviewed/2022/05/GHSA-j8mf-vg8w-fx4p/GHSA-j8mf-vg8w-fx4p.json @@ -7,12 +7,8 @@ "CVE-2007-4940" ], "details": "Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large \"indx truck size\" and nEntriesInuse values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9p6-jqgj-3cvv/GHSA-j9p6-jqgj-3cvv.json b/advisories/unreviewed/2022/05/GHSA-j9p6-jqgj-3cvv/GHSA-j9p6-jqgj-3cvv.json index e71ad9caa8c..ebc25b09860 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9p6-jqgj-3cvv/GHSA-j9p6-jqgj-3cvv.json +++ b/advisories/unreviewed/2022/05/GHSA-j9p6-jqgj-3cvv/GHSA-j9p6-jqgj-3cvv.json @@ -7,12 +7,8 @@ "CVE-2007-5104" ], "details": "SQL injection vulnerability in index.php in the Arcade module in bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a play_game action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg89-gj56-fcrp/GHSA-jg89-gj56-fcrp.json b/advisories/unreviewed/2022/05/GHSA-jg89-gj56-fcrp/GHSA-jg89-gj56-fcrp.json index 7ea5d5a4510..8a36a3e7a10 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg89-gj56-fcrp/GHSA-jg89-gj56-fcrp.json +++ b/advisories/unreviewed/2022/05/GHSA-jg89-gj56-fcrp/GHSA-jg89-gj56-fcrp.json @@ -7,12 +7,8 @@ "CVE-2007-4815" ], "details": "Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code via a URL in the Codebase parameter to (1) channeledit.php, (2) post.php, (3) view.php, or (4) viewitem.php in source/mod/rss/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg8x-xffr-qj4m/GHSA-jg8x-xffr-qj4m.json b/advisories/unreviewed/2022/05/GHSA-jg8x-xffr-qj4m/GHSA-jg8x-xffr-qj4m.json index cbe809bcef4..43a030f9f40 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg8x-xffr-qj4m/GHSA-jg8x-xffr-qj4m.json +++ b/advisories/unreviewed/2022/05/GHSA-jg8x-xffr-qj4m/GHSA-jg8x-xffr-qj4m.json @@ -7,12 +7,8 @@ "CVE-2007-4527" ], "details": "Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgv6-592p-p3ch/GHSA-jgv6-592p-p3ch.json b/advisories/unreviewed/2022/05/GHSA-jgv6-592p-p3ch/GHSA-jgv6-592p-p3ch.json index 33b5cd4bec0..454b105e1e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgv6-592p-p3ch/GHSA-jgv6-592p-p3ch.json +++ b/advisories/unreviewed/2022/05/GHSA-jgv6-592p-p3ch/GHSA-jgv6-592p-p3ch.json @@ -7,12 +7,8 @@ "CVE-2007-5224" ], "details": "inc/exif.inc.php in Original Photo Gallery 0.11.2 and earlier allows remote attackers to execute arbitrary programs via the exif_prog parameter, which is specified in an exec function call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgvc-j5h3-xpc7/GHSA-jgvc-j5h3-xpc7.json b/advisories/unreviewed/2022/05/GHSA-jgvc-j5h3-xpc7/GHSA-jgvc-j5h3-xpc7.json index 50ea4cabfc4..b2dbc2eb6ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgvc-j5h3-xpc7/GHSA-jgvc-j5h3-xpc7.json +++ b/advisories/unreviewed/2022/05/GHSA-jgvc-j5h3-xpc7/GHSA-jgvc-j5h3-xpc7.json @@ -7,12 +7,8 @@ "CVE-2007-4691" ], "details": "The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jh59-pxh9-hgg6/GHSA-jh59-pxh9-hgg6.json b/advisories/unreviewed/2022/05/GHSA-jh59-pxh9-hgg6/GHSA-jh59-pxh9-hgg6.json index 5af2929e083..dba727d9711 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh59-pxh9-hgg6/GHSA-jh59-pxh9-hgg6.json +++ b/advisories/unreviewed/2022/05/GHSA-jh59-pxh9-hgg6/GHSA-jh59-pxh9-hgg6.json @@ -7,12 +7,8 @@ "CVE-2007-5384" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to perform actions as administrators via unspecified POST requests, as demonstrated by enabling an inbound remote-assistance HTTPS session on TCP port 51003. NOTE: an authentication bypass can be leveraged to exploit this in the absence of an existing administrative session. NOTE: SpeedTouch 780 might also be affected by some of these issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh86-jq8q-phx4/GHSA-jh86-jq8q-phx4.json b/advisories/unreviewed/2022/05/GHSA-jh86-jq8q-phx4/GHSA-jh86-jq8q-phx4.json index be4b1aea2a3..9d4b356a243 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh86-jq8q-phx4/GHSA-jh86-jq8q-phx4.json +++ b/advisories/unreviewed/2022/05/GHSA-jh86-jq8q-phx4/GHSA-jh86-jq8q-phx4.json @@ -7,12 +7,8 @@ "CVE-2007-5064" ], "details": "Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in DapPlayer_Now.dll, allows remote attackers to execute arbitrary code via a long first argument to the DownURL2 method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmv5-jxh3-2w8r/GHSA-jmv5-jxh3-2w8r.json b/advisories/unreviewed/2022/05/GHSA-jmv5-jxh3-2w8r/GHSA-jmv5-jxh3-2w8r.json index 88932634192..7413f8448a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmv5-jxh3-2w8r/GHSA-jmv5-jxh3-2w8r.json +++ b/advisories/unreviewed/2022/05/GHSA-jmv5-jxh3-2w8r/GHSA-jmv5-jxh3-2w8r.json @@ -7,12 +7,8 @@ "CVE-2007-4953" ], "details": "SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp37-gx4x-vcxx/GHSA-jp37-gx4x-vcxx.json b/advisories/unreviewed/2022/05/GHSA-jp37-gx4x-vcxx/GHSA-jp37-gx4x-vcxx.json index 0822013efee..23ed4df30e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp37-gx4x-vcxx/GHSA-jp37-gx4x-vcxx.json +++ b/advisories/unreviewed/2022/05/GHSA-jp37-gx4x-vcxx/GHSA-jp37-gx4x-vcxx.json @@ -7,12 +7,8 @@ "CVE-2007-4846" ], "details": "SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik go action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpfm-jfvg-56mp/GHSA-jpfm-jfvg-56mp.json b/advisories/unreviewed/2022/05/GHSA-jpfm-jfvg-56mp/GHSA-jpfm-jfvg-56mp.json index 335eed20ea3..46ee04642d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpfm-jfvg-56mp/GHSA-jpfm-jfvg-56mp.json +++ b/advisories/unreviewed/2022/05/GHSA-jpfm-jfvg-56mp/GHSA-jpfm-jfvg-56mp.json @@ -7,12 +7,8 @@ "CVE-2007-4825" ], "details": "Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpj9-pwx9-945j/GHSA-jpj9-pwx9-945j.json b/advisories/unreviewed/2022/05/GHSA-jpj9-pwx9-945j/GHSA-jpj9-pwx9-945j.json index 740efc39db6..80b5f0132e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpj9-pwx9-945j/GHSA-jpj9-pwx9-945j.json +++ b/advisories/unreviewed/2022/05/GHSA-jpj9-pwx9-945j/GHSA-jpj9-pwx9-945j.json @@ -7,12 +7,8 @@ "CVE-2007-5105" ], "details": "Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq55-5f3p-6g42/GHSA-jq55-5f3p-6g42.json b/advisories/unreviewed/2022/05/GHSA-jq55-5f3p-6g42/GHSA-jq55-5f3p-6g42.json index e7725f75dea..3e44185adf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq55-5f3p-6g42/GHSA-jq55-5f3p-6g42.json +++ b/advisories/unreviewed/2022/05/GHSA-jq55-5f3p-6g42/GHSA-jq55-5f3p-6g42.json @@ -7,12 +7,8 @@ "CVE-2007-5320" ], "details": "Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq5c-rgv9-cw8p/GHSA-jq5c-rgv9-cw8p.json b/advisories/unreviewed/2022/05/GHSA-jq5c-rgv9-cw8p/GHSA-jq5c-rgv9-cw8p.json index a526f312bac..48d66677a5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq5c-rgv9-cw8p/GHSA-jq5c-rgv9-cw8p.json +++ b/advisories/unreviewed/2022/05/GHSA-jq5c-rgv9-cw8p/GHSA-jq5c-rgv9-cw8p.json @@ -7,12 +7,8 @@ "CVE-2007-4768" ], "details": "Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a singleton Unicode sequence in a character class in a regex pattern, which is incorrectly optimized.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqfp-qwq6-6w3h/GHSA-jqfp-qwq6-6w3h.json b/advisories/unreviewed/2022/05/GHSA-jqfp-qwq6-6w3h/GHSA-jqfp-qwq6-6w3h.json index 0835fc7e8d2..ef6cef3a915 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqfp-qwq6-6w3h/GHSA-jqfp-qwq6-6w3h.json +++ b/advisories/unreviewed/2022/05/GHSA-jqfp-qwq6-6w3h/GHSA-jqfp-qwq6-6w3h.json @@ -7,12 +7,8 @@ "CVE-2007-4573" ], "details": "The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -176,9 +172,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqpj-4gh4-6gmj/GHSA-jqpj-4gh4-6gmj.json b/advisories/unreviewed/2022/05/GHSA-jqpj-4gh4-6gmj/GHSA-jqpj-4gh4-6gmj.json index 16b1d26f01d..b96df9328c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqpj-4gh4-6gmj/GHSA-jqpj-4gh4-6gmj.json +++ b/advisories/unreviewed/2022/05/GHSA-jqpj-4gh4-6gmj/GHSA-jqpj-4gh4-6gmj.json @@ -7,12 +7,8 @@ "CVE-2007-4614" ], "details": "BEA WebLogic Server 9.1 does not properly handle propagation of an admin server's security policy change log to temporarily unavailable managed servers, which might allow attackers to bypass intended restrictions, a different vulnerability than CVE-2007-0426.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrq6-q73h-9x9r/GHSA-jrq6-q73h-9x9r.json b/advisories/unreviewed/2022/05/GHSA-jrq6-q73h-9x9r/GHSA-jrq6-q73h-9x9r.json index 90adb93fe1d..8682a05bfe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrq6-q73h-9x9r/GHSA-jrq6-q73h-9x9r.json +++ b/advisories/unreviewed/2022/05/GHSA-jrq6-q73h-9x9r/GHSA-jrq6-q73h-9x9r.json @@ -7,12 +7,8 @@ "CVE-2007-4806" ], "details": "PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrr3-vp94-vr6p/GHSA-jrr3-vp94-vr6p.json b/advisories/unreviewed/2022/05/GHSA-jrr3-vp94-vr6p/GHSA-jrr3-vp94-vr6p.json index 61e14483b0b..a436c608d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrr3-vp94-vr6p/GHSA-jrr3-vp94-vr6p.json +++ b/advisories/unreviewed/2022/05/GHSA-jrr3-vp94-vr6p/GHSA-jrr3-vp94-vr6p.json @@ -7,12 +7,8 @@ "CVE-2007-4694" ], "details": "Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv7f-6w9c-xjpv/GHSA-jv7f-6w9c-xjpv.json b/advisories/unreviewed/2022/05/GHSA-jv7f-6w9c-xjpv/GHSA-jv7f-6w9c-xjpv.json index 328194fc418..a972ecce42b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv7f-6w9c-xjpv/GHSA-jv7f-6w9c-xjpv.json +++ b/advisories/unreviewed/2022/05/GHSA-jv7f-6w9c-xjpv/GHSA-jv7f-6w9c-xjpv.json @@ -7,12 +7,8 @@ "CVE-2007-5242" ], "details": "Unspecified vulnerability in (1) SYS$EI1000.EXE and (2) SYS$EI1000_MON.EXE in HP OpenVMS 8.3 and earlier allows remote attackers to cause a denial of service (machine crash) via an \"oversize\" packet, which is not properly discarded if \"the device has no remaining buffers after receipt of the first buffer segment.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvj2-mwv2-mvpr/GHSA-jvj2-mwv2-mvpr.json b/advisories/unreviewed/2022/05/GHSA-jvj2-mwv2-mvpr/GHSA-jvj2-mwv2-mvpr.json index 501a4641d80..83c73c7d880 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvj2-mwv2-mvpr/GHSA-jvj2-mwv2-mvpr.json +++ b/advisories/unreviewed/2022/05/GHSA-jvj2-mwv2-mvpr/GHSA-jvj2-mwv2-mvpr.json @@ -7,12 +7,8 @@ "CVE-2007-5393" ], "details": "Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvj7-2r2w-j8px/GHSA-jvj7-2r2w-j8px.json b/advisories/unreviewed/2022/05/GHSA-jvj7-2r2w-j8px/GHSA-jvj7-2r2w-j8px.json index 4bde1fba9a1..0457428a013 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvj7-2r2w-j8px/GHSA-jvj7-2r2w-j8px.json +++ b/advisories/unreviewed/2022/05/GHSA-jvj7-2r2w-j8px/GHSA-jvj7-2r2w-j8px.json @@ -7,12 +7,8 @@ "CVE-2007-4723" ], "details": "Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a \"/...../\" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwp9-qgrq-hqpw/GHSA-jwp9-qgrq-hqpw.json b/advisories/unreviewed/2022/05/GHSA-jwp9-qgrq-hqpw/GHSA-jwp9-qgrq-hqpw.json index dd480298bf4..9877870f216 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwp9-qgrq-hqpw/GHSA-jwp9-qgrq-hqpw.json +++ b/advisories/unreviewed/2022/05/GHSA-jwp9-qgrq-hqpw/GHSA-jwp9-qgrq-hqpw.json @@ -7,12 +7,8 @@ "CVE-2007-4609" ], "details": "eyeOS uses predictable checksum values in the checknum parameter for access control, which allows remote attackers to register many accounts via doCreateUser actions, add many eyeBoard messages via addMsg actions, and cause a denial of service or conduct certain unauthorized activities, by guessing valid parameter values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwxw-jjwr-v7fp/GHSA-jwxw-jjwr-v7fp.json b/advisories/unreviewed/2022/05/GHSA-jwxw-jjwr-v7fp/GHSA-jwxw-jjwr-v7fp.json index faf4f37865c..c31b86362f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwxw-jjwr-v7fp/GHSA-jwxw-jjwr-v7fp.json +++ b/advisories/unreviewed/2022/05/GHSA-jwxw-jjwr-v7fp/GHSA-jwxw-jjwr-v7fp.json @@ -7,12 +7,8 @@ "CVE-2007-4905" ], "details": "Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a file under files/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx4v-jqqr-2fq3/GHSA-jx4v-jqqr-2fq3.json b/advisories/unreviewed/2022/05/GHSA-jx4v-jqqr-2fq3/GHSA-jx4v-jqqr-2fq3.json index 5125ec5d3ac..c30d910b28d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx4v-jqqr-2fq3/GHSA-jx4v-jqqr-2fq3.json +++ b/advisories/unreviewed/2022/05/GHSA-jx4v-jqqr-2fq3/GHSA-jx4v-jqqr-2fq3.json @@ -7,12 +7,8 @@ "CVE-2007-5027" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx69-94fj-8m45/GHSA-jx69-94fj-8m45.json b/advisories/unreviewed/2022/05/GHSA-jx69-94fj-8m45/GHSA-jx69-94fj-8m45.json index 284cc7aa50c..3b123c07395 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx69-94fj-8m45/GHSA-jx69-94fj-8m45.json +++ b/advisories/unreviewed/2022/05/GHSA-jx69-94fj-8m45/GHSA-jx69-94fj-8m45.json @@ -7,12 +7,8 @@ "CVE-2007-5232" ], "details": "Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -200,9 +196,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2x7-vx33-9v63/GHSA-m2x7-vx33-9v63.json b/advisories/unreviewed/2022/05/GHSA-m2x7-vx33-9v63/GHSA-m2x7-vx33-9v63.json index 40381774719..8baaddb1710 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2x7-vx33-9v63/GHSA-m2x7-vx33-9v63.json +++ b/advisories/unreviewed/2022/05/GHSA-m2x7-vx33-9v63/GHSA-m2x7-vx33-9v63.json @@ -7,12 +7,8 @@ "CVE-2007-4655" ], "details": "Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3jj-f5p8-f89j/GHSA-m3jj-f5p8-f89j.json b/advisories/unreviewed/2022/05/GHSA-m3jj-f5p8-f89j/GHSA-m3jj-f5p8-f89j.json index 9dacc596936..42761fca173 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3jj-f5p8-f89j/GHSA-m3jj-f5p8-f89j.json +++ b/advisories/unreviewed/2022/05/GHSA-m3jj-f5p8-f89j/GHSA-m3jj-f5p8-f89j.json @@ -7,12 +7,8 @@ "CVE-2007-4810" ], "details": "Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m43c-f4x2-7vmm/GHSA-m43c-f4x2-7vmm.json b/advisories/unreviewed/2022/05/GHSA-m43c-f4x2-7vmm/GHSA-m43c-f4x2-7vmm.json index eb368783f03..fee83c3bbf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m43c-f4x2-7vmm/GHSA-m43c-f4x2-7vmm.json +++ b/advisories/unreviewed/2022/05/GHSA-m43c-f4x2-7vmm/GHSA-m43c-f4x2-7vmm.json @@ -7,12 +7,8 @@ "CVE-2007-4912" ], "details": "Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other than iso-8859-1 or utf-8.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m44j-mw65-mfmv/GHSA-m44j-mw65-mfmv.json b/advisories/unreviewed/2022/05/GHSA-m44j-mw65-mfmv/GHSA-m44j-mw65-mfmv.json index 57f8f17f251..c67e95bc275 100644 --- a/advisories/unreviewed/2022/05/GHSA-m44j-mw65-mfmv/GHSA-m44j-mw65-mfmv.json +++ b/advisories/unreviewed/2022/05/GHSA-m44j-mw65-mfmv/GHSA-m44j-mw65-mfmv.json @@ -7,12 +7,8 @@ "CVE-2007-5188" ], "details": "Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4wp-q28r-x97q/GHSA-m4wp-q28r-x97q.json b/advisories/unreviewed/2022/05/GHSA-m4wp-q28r-x97q/GHSA-m4wp-q28r-x97q.json index 21fd3ab00bb..9caa85ce066 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4wp-q28r-x97q/GHSA-m4wp-q28r-x97q.json +++ b/advisories/unreviewed/2022/05/GHSA-m4wp-q28r-x97q/GHSA-m4wp-q28r-x97q.json @@ -7,12 +7,8 @@ "CVE-2007-4821" ], "details": "Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the HttpDownloadFileToTempDir method, a different vulnerability than CVE-2007-3169.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m63r-5v4r-g4rm/GHSA-m63r-5v4r-g4rm.json b/advisories/unreviewed/2022/05/GHSA-m63r-5v4r-g4rm/GHSA-m63r-5v4r-g4rm.json index f3b5a300895..fd718c439e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-m63r-5v4r-g4rm/GHSA-m63r-5v4r-g4rm.json +++ b/advisories/unreviewed/2022/05/GHSA-m63r-5v4r-g4rm/GHSA-m63r-5v4r-g4rm.json @@ -7,12 +7,8 @@ "CVE-2007-4928" ], "details": "The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m649-xm7x-gv2j/GHSA-m649-xm7x-gv2j.json b/advisories/unreviewed/2022/05/GHSA-m649-xm7x-gv2j/GHSA-m649-xm7x-gv2j.json index 51407dcaaa7..bac404fb264 100644 --- a/advisories/unreviewed/2022/05/GHSA-m649-xm7x-gv2j/GHSA-m649-xm7x-gv2j.json +++ b/advisories/unreviewed/2022/05/GHSA-m649-xm7x-gv2j/GHSA-m649-xm7x-gv2j.json @@ -7,12 +7,8 @@ "CVE-2007-5351" ], "details": "Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka \"SMBv2 Signing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6g3-p66g-2jwj/GHSA-m6g3-p66g-2jwj.json b/advisories/unreviewed/2022/05/GHSA-m6g3-p66g-2jwj/GHSA-m6g3-p66g-2jwj.json index db7b8ab596d..f8b93b76397 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6g3-p66g-2jwj/GHSA-m6g3-p66g-2jwj.json +++ b/advisories/unreviewed/2022/05/GHSA-m6g3-p66g-2jwj/GHSA-m6g3-p66g-2jwj.json @@ -7,12 +7,8 @@ "CVE-2007-5347" ], "details": "Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via \"unexpected method calls to HTML objects,\" aka \"DHTML Object Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6mg-wmmr-qwcr/GHSA-m6mg-wmmr-qwcr.json b/advisories/unreviewed/2022/05/GHSA-m6mg-wmmr-qwcr/GHSA-m6mg-wmmr-qwcr.json index 9421d09e9d9..06a902d9260 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6mg-wmmr-qwcr/GHSA-m6mg-wmmr-qwcr.json +++ b/advisories/unreviewed/2022/05/GHSA-m6mg-wmmr-qwcr/GHSA-m6mg-wmmr-qwcr.json @@ -7,12 +7,8 @@ "CVE-2007-5072" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.php files under themes/, as demonstrated by the user_colors[bg_color] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6w5-chv7-65mq/GHSA-m6w5-chv7-65mq.json b/advisories/unreviewed/2022/05/GHSA-m6w5-chv7-65mq/GHSA-m6w5-chv7-65mq.json index 1a58eef5dd0..6e970f88b81 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6w5-chv7-65mq/GHSA-m6w5-chv7-65mq.json +++ b/advisories/unreviewed/2022/05/GHSA-m6w5-chv7-65mq/GHSA-m6w5-chv7-65mq.json @@ -7,12 +7,8 @@ "CVE-2007-4958" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) index.php, (2) i_frames/i_login.php, and (3) i_frames/i_top_tags.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m793-w2w5-4gf3/GHSA-m793-w2w5-4gf3.json b/advisories/unreviewed/2022/05/GHSA-m793-w2w5-4gf3/GHSA-m793-w2w5-4gf3.json index cd93fcf764f..0fce4a2704b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m793-w2w5-4gf3/GHSA-m793-w2w5-4gf3.json +++ b/advisories/unreviewed/2022/05/GHSA-m793-w2w5-4gf3/GHSA-m793-w2w5-4gf3.json @@ -7,12 +7,8 @@ "CVE-2007-5222" ], "details": "SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a \"Firefox ID=\" substring in a Referer HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7q3-8fp8-wfr6/GHSA-m7q3-8fp8-wfr6.json b/advisories/unreviewed/2022/05/GHSA-m7q3-8fp8-wfr6/GHSA-m7q3-8fp8-wfr6.json index 6e814018041..892a0935722 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7q3-8fp8-wfr6/GHSA-m7q3-8fp8-wfr6.json +++ b/advisories/unreviewed/2022/05/GHSA-m7q3-8fp8-wfr6/GHSA-m7q3-8fp8-wfr6.json @@ -7,12 +7,8 @@ "CVE-2007-5102" ], "details": "PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m88w-w7m5-c5r5/GHSA-m88w-w7m5-c5r5.json b/advisories/unreviewed/2022/05/GHSA-m88w-w7m5-c5r5/GHSA-m88w-w7m5-c5r5.json index d216cdfd381..47064baf7ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-m88w-w7m5-c5r5/GHSA-m88w-w7m5-c5r5.json +++ b/advisories/unreviewed/2022/05/GHSA-m88w-w7m5-c5r5/GHSA-m88w-w7m5-c5r5.json @@ -7,12 +7,8 @@ "CVE-2007-4952" ], "details": "SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8gx-vrfw-7pmx/GHSA-m8gx-vrfw-7pmx.json b/advisories/unreviewed/2022/05/GHSA-m8gx-vrfw-7pmx/GHSA-m8gx-vrfw-7pmx.json index c4a65aa259a..c1c6bd619a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8gx-vrfw-7pmx/GHSA-m8gx-vrfw-7pmx.json +++ b/advisories/unreviewed/2022/05/GHSA-m8gx-vrfw-7pmx/GHSA-m8gx-vrfw-7pmx.json @@ -7,12 +7,8 @@ "CVE-2007-5394" ], "details": "Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure, a different vulnerability than CVE-2007-5169 and CVE-2007-6432.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8jp-8qg8-r8j3/GHSA-m8jp-8qg8-r8j3.json b/advisories/unreviewed/2022/05/GHSA-m8jp-8qg8-r8j3/GHSA-m8jp-8qg8-r8j3.json index 61cdadf8319..6ce071217e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8jp-8qg8-r8j3/GHSA-m8jp-8qg8-r8j3.json +++ b/advisories/unreviewed/2022/05/GHSA-m8jp-8qg8-r8j3/GHSA-m8jp-8qg8-r8j3.json @@ -7,12 +7,8 @@ "CVE-2007-4804" ], "details": "Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m936-63jp-34qv/GHSA-m936-63jp-34qv.json b/advisories/unreviewed/2022/05/GHSA-m936-63jp-34qv/GHSA-m936-63jp-34qv.json index a3a1a609e8c..115a4fd08d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-m936-63jp-34qv/GHSA-m936-63jp-34qv.json +++ b/advisories/unreviewed/2022/05/GHSA-m936-63jp-34qv/GHSA-m936-63jp-34qv.json @@ -7,12 +7,8 @@ "CVE-2007-4897" ], "details": "pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a \"memory management flaw\". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m957-2m8p-m75f/GHSA-m957-2m8p-m75f.json b/advisories/unreviewed/2022/05/GHSA-m957-2m8p-m75f/GHSA-m957-2m8p-m75f.json index c6ffb48da98..6bd6703285d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m957-2m8p-m75f/GHSA-m957-2m8p-m75f.json +++ b/advisories/unreviewed/2022/05/GHSA-m957-2m8p-m75f/GHSA-m957-2m8p-m75f.json @@ -7,12 +7,8 @@ "CVE-2007-4704" ], "details": "The Application Firewall in Apple Mac OS X 10.5 does not apply changed settings to processes that are started by launchd until the processes are restarted, which might allow attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9hh-3h7m-8q53/GHSA-m9hh-3h7m-8q53.json b/advisories/unreviewed/2022/05/GHSA-m9hh-3h7m-8q53/GHSA-m9hh-3h7m-8q53.json index ba2a37d8889..f8e6b94adb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9hh-3h7m-8q53/GHSA-m9hh-3h7m-8q53.json +++ b/advisories/unreviewed/2022/05/GHSA-m9hh-3h7m-8q53/GHSA-m9hh-3h7m-8q53.json @@ -7,12 +7,8 @@ "CVE-2007-5059" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL allow remote attackers to inject arbitrary web script or HTML via several vectors, as demonstrated by the (1) uname and (2) pass parameters in a login form, and (3) an unspecified \"url value,\" leading to storage of XSS sequences in the database and display of these sequences in the alert section of the admin panel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc47-cj3j-gp86/GHSA-mc47-cj3j-gp86.json b/advisories/unreviewed/2022/05/GHSA-mc47-cj3j-gp86/GHSA-mc47-cj3j-gp86.json index f8e22c407b3..81fea2ed825 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc47-cj3j-gp86/GHSA-mc47-cj3j-gp86.json +++ b/advisories/unreviewed/2022/05/GHSA-mc47-cj3j-gp86/GHSA-mc47-cj3j-gp86.json @@ -7,12 +7,8 @@ "CVE-2007-4744" ], "details": "PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc93-xgch-6ch5/GHSA-mc93-xgch-6ch5.json b/advisories/unreviewed/2022/05/GHSA-mc93-xgch-6ch5/GHSA-mc93-xgch-6ch5.json index cb8ffe78490..243005e1380 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc93-xgch-6ch5/GHSA-mc93-xgch-6ch5.json +++ b/advisories/unreviewed/2022/05/GHSA-mc93-xgch-6ch5/GHSA-mc93-xgch-6ch5.json @@ -7,12 +7,8 @@ "CVE-2007-4839" ], "details": "Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK33803.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcrw-xhqq-57vc/GHSA-mcrw-xhqq-57vc.json b/advisories/unreviewed/2022/05/GHSA-mcrw-xhqq-57vc/GHSA-mcrw-xhqq-57vc.json index f194ed1ba0b..81b0073e094 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcrw-xhqq-57vc/GHSA-mcrw-xhqq-57vc.json +++ b/advisories/unreviewed/2022/05/GHSA-mcrw-xhqq-57vc/GHSA-mcrw-xhqq-57vc.json @@ -7,12 +7,8 @@ "CVE-2007-4563" ], "details": "Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcvr-7rrj-93w4/GHSA-mcvr-7rrj-93w4.json b/advisories/unreviewed/2022/05/GHSA-mcvr-7rrj-93w4/GHSA-mcvr-7rrj-93w4.json index 9be389e986c..7f4214511c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcvr-7rrj-93w4/GHSA-mcvr-7rrj-93w4.json +++ b/advisories/unreviewed/2022/05/GHSA-mcvr-7rrj-93w4/GHSA-mcvr-7rrj-93w4.json @@ -7,12 +7,8 @@ "CVE-2007-5372" ], "details": "Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the invoice quantity field or (2) the sort field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfm5-4gv4-ph75/GHSA-mfm5-4gv4-ph75.json b/advisories/unreviewed/2022/05/GHSA-mfm5-4gv4-ph75/GHSA-mfm5-4gv4-ph75.json index 8ad93a0ed3b..d84c1bfe7ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfm5-4gv4-ph75/GHSA-mfm5-4gv4-ph75.json +++ b/advisories/unreviewed/2022/05/GHSA-mfm5-4gv4-ph75/GHSA-mfm5-4gv4-ph75.json @@ -7,12 +7,8 @@ "CVE-2007-5066" ], "details": "Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg32-pj9q-4r54/GHSA-mg32-pj9q-4r54.json b/advisories/unreviewed/2022/05/GHSA-mg32-pj9q-4r54/GHSA-mg32-pj9q-4r54.json index 17cb73e3ac2..5118bde895d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg32-pj9q-4r54/GHSA-mg32-pj9q-4r54.json +++ b/advisories/unreviewed/2022/05/GHSA-mg32-pj9q-4r54/GHSA-mg32-pj9q-4r54.json @@ -7,12 +7,8 @@ "CVE-2007-4820" ], "details": "Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgqg-9g67-qvcc/GHSA-mgqg-9g67-qvcc.json b/advisories/unreviewed/2022/05/GHSA-mgqg-9g67-qvcc/GHSA-mgqg-9g67-qvcc.json index efc9c671b4e..0627b5240b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgqg-9g67-qvcc/GHSA-mgqg-9g67-qvcc.json +++ b/advisories/unreviewed/2022/05/GHSA-mgqg-9g67-qvcc/GHSA-mgqg-9g67-qvcc.json @@ -7,12 +7,8 @@ "CVE-2007-4686" ], "details": "Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mj8p-r5gp-w6p8/GHSA-mj8p-r5gp-w6p8.json b/advisories/unreviewed/2022/05/GHSA-mj8p-r5gp-w6p8/GHSA-mj8p-r5gp-w6p8.json index 5b0059406d1..60b0f2563b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj8p-r5gp-w6p8/GHSA-mj8p-r5gp-w6p8.json +++ b/advisories/unreviewed/2022/05/GHSA-mj8p-r5gp-w6p8/GHSA-mj8p-r5gp-w6p8.json @@ -7,12 +7,8 @@ "CVE-2007-4569" ], "details": "backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and \"shutdown with password\" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjh7-5rg5-q2qx/GHSA-mjh7-5rg5-q2qx.json b/advisories/unreviewed/2022/05/GHSA-mjh7-5rg5-q2qx/GHSA-mjh7-5rg5-q2qx.json index 4290558f710..dd7f2812ae5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjh7-5rg5-q2qx/GHSA-mjh7-5rg5-q2qx.json +++ b/advisories/unreviewed/2022/05/GHSA-mjh7-5rg5-q2qx/GHSA-mjh7-5rg5-q2qx.json @@ -7,12 +7,8 @@ "CVE-2007-4781" ], "details": "administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the \"Upload Package File\" functionality, which is accessible when com_installer is the value of the option parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm7q-49q2-pfpg/GHSA-mm7q-49q2-pfpg.json b/advisories/unreviewed/2022/05/GHSA-mm7q-49q2-pfpg/GHSA-mm7q-49q2-pfpg.json index 79141564cec..54c9f2d0cfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm7q-49q2-pfpg/GHSA-mm7q-49q2-pfpg.json +++ b/advisories/unreviewed/2022/05/GHSA-mm7q-49q2-pfpg/GHSA-mm7q-49q2-pfpg.json @@ -7,12 +7,8 @@ "CVE-2007-4921" ], "details": "PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmjq-xf76-8m96/GHSA-mmjq-xf76-8m96.json b/advisories/unreviewed/2022/05/GHSA-mmjq-xf76-8m96/GHSA-mmjq-xf76-8m96.json index dd5d4b90bfa..65132285898 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmjq-xf76-8m96/GHSA-mmjq-xf76-8m96.json +++ b/advisories/unreviewed/2022/05/GHSA-mmjq-xf76-8m96/GHSA-mmjq-xf76-8m96.json @@ -7,12 +7,8 @@ "CVE-2007-5004" ], "details": "Integer overflow in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to execute arbitrary code via a long username and a certain \"useless\" password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mp6x-6v97-mg8p/GHSA-mp6x-6v97-mg8p.json b/advisories/unreviewed/2022/05/GHSA-mp6x-6v97-mg8p/GHSA-mp6x-6v97-mg8p.json index dd9858ad462..fb6177b079a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp6x-6v97-mg8p/GHSA-mp6x-6v97-mg8p.json +++ b/advisories/unreviewed/2022/05/GHSA-mp6x-6v97-mg8p/GHSA-mp6x-6v97-mg8p.json @@ -7,12 +7,8 @@ "CVE-2007-5094" ], "details": "Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string \"MIME\" by itself on a line in the header, and a long Content-Transfer-Encoding header line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr3r-g953-pmjx/GHSA-mr3r-g953-pmjx.json b/advisories/unreviewed/2022/05/GHSA-mr3r-g953-pmjx/GHSA-mr3r-g953-pmjx.json index 451469aebf2..4848b6300ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr3r-g953-pmjx/GHSA-mr3r-g953-pmjx.json +++ b/advisories/unreviewed/2022/05/GHSA-mr3r-g953-pmjx/GHSA-mr3r-g953-pmjx.json @@ -7,12 +7,8 @@ "CVE-2007-4779" ], "details": "Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr86-rf34-87mq/GHSA-mr86-rf34-87mq.json b/advisories/unreviewed/2022/05/GHSA-mr86-rf34-87mq/GHSA-mr86-rf34-87mq.json index 10813a951dd..a3ccd220a41 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr86-rf34-87mq/GHSA-mr86-rf34-87mq.json +++ b/advisories/unreviewed/2022/05/GHSA-mr86-rf34-87mq/GHSA-mr86-rf34-87mq.json @@ -7,12 +7,8 @@ "CVE-2007-5024" ], "details": "EMC VMware Server before 1.0.4 Build 56528 writes passwords in cleartext to unspecified log files, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2005-3620.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrgj-rjgm-ffp5/GHSA-mrgj-rjgm-ffp5.json b/advisories/unreviewed/2022/05/GHSA-mrgj-rjgm-ffp5/GHSA-mrgj-rjgm-ffp5.json index 58d1b70342c..6456d81cbd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrgj-rjgm-ffp5/GHSA-mrgj-rjgm-ffp5.json +++ b/advisories/unreviewed/2022/05/GHSA-mrgj-rjgm-ffp5/GHSA-mrgj-rjgm-ffp5.json @@ -7,12 +7,8 @@ "CVE-2007-4756" ], "details": "Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via \"..\\\" (dot dot backslash) sequences in a filename. NOTE: the \"..\\\" are not displayed when the user lists files. NOTE: this can be leveraged for code execution by writing to a Startup folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrhh-xc2v-m6rc/GHSA-mrhh-xc2v-m6rc.json b/advisories/unreviewed/2022/05/GHSA-mrhh-xc2v-m6rc/GHSA-mrhh-xc2v-m6rc.json index b76d7ccf880..21d490ae10f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrhh-xc2v-m6rc/GHSA-mrhh-xc2v-m6rc.json +++ b/advisories/unreviewed/2022/05/GHSA-mrhh-xc2v-m6rc/GHSA-mrhh-xc2v-m6rc.json @@ -7,12 +7,8 @@ "CVE-2007-4666" ], "details": "Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via \"large network packets with garbage\", aka CORE-1397.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrq4-6g5x-wpwr/GHSA-mrq4-6g5x-wpwr.json b/advisories/unreviewed/2022/05/GHSA-mrq4-6g5x-wpwr/GHSA-mrq4-6g5x-wpwr.json index 54fce6e28a1..9f4f14bfb61 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrq4-6g5x-wpwr/GHSA-mrq4-6g5x-wpwr.json +++ b/advisories/unreviewed/2022/05/GHSA-mrq4-6g5x-wpwr/GHSA-mrq4-6g5x-wpwr.json @@ -7,12 +7,8 @@ "CVE-2007-4536" ], "details": "TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mv5j-4p2p-c774/GHSA-mv5j-4p2p-c774.json b/advisories/unreviewed/2022/05/GHSA-mv5j-4p2p-c774/GHSA-mv5j-4p2p-c774.json index e327a5516c7..951636b6bdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv5j-4p2p-c774/GHSA-mv5j-4p2p-c774.json +++ b/advisories/unreviewed/2022/05/GHSA-mv5j-4p2p-c774/GHSA-mv5j-4p2p-c774.json @@ -7,12 +7,8 @@ "CVE-2007-4797" ], "details": "Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv8f-gg8m-fx2m/GHSA-mv8f-gg8m-fx2m.json b/advisories/unreviewed/2022/05/GHSA-mv8f-gg8m-fx2m/GHSA-mv8f-gg8m-fx2m.json index 14807090830..15049937e87 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv8f-gg8m-fx2m/GHSA-mv8f-gg8m-fx2m.json +++ b/advisories/unreviewed/2022/05/GHSA-mv8f-gg8m-fx2m/GHSA-mv8f-gg8m-fx2m.json @@ -7,12 +7,8 @@ "CVE-2007-4749" ], "details": "The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mv9m-4996-x55r/GHSA-mv9m-4996-x55r.json b/advisories/unreviewed/2022/05/GHSA-mv9m-4996-x55r/GHSA-mv9m-4996-x55r.json index 626d3de0856..b4a777d44fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv9m-4996-x55r/GHSA-mv9m-4996-x55r.json +++ b/advisories/unreviewed/2022/05/GHSA-mv9m-4996-x55r/GHSA-mv9m-4996-x55r.json @@ -7,12 +7,8 @@ "CVE-2007-4983" ], "details": "Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvfx-6wj4-6f8r/GHSA-mvfx-6wj4-6f8r.json b/advisories/unreviewed/2022/05/GHSA-mvfx-6wj4-6f8r/GHSA-mvfx-6wj4-6f8r.json index 7253bd24d37..f5145b91779 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvfx-6wj4-6f8r/GHSA-mvfx-6wj4-6f8r.json +++ b/advisories/unreviewed/2022/05/GHSA-mvfx-6wj4-6f8r/GHSA-mvfx-6wj4-6f8r.json @@ -7,12 +7,8 @@ "CVE-2007-5375" ], "details": "Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a \"mayscript=true\" Java applet through a local relative URI, which may be associated with different IP addresses by the browser and the JVM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mw6p-g59x-wqvw/GHSA-mw6p-g59x-wqvw.json b/advisories/unreviewed/2022/05/GHSA-mw6p-g59x-wqvw/GHSA-mw6p-g59x-wqvw.json index 8764e7067db..c59bfdad403 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw6p-g59x-wqvw/GHSA-mw6p-g59x-wqvw.json +++ b/advisories/unreviewed/2022/05/GHSA-mw6p-g59x-wqvw/GHSA-mw6p-g59x-wqvw.json @@ -7,12 +7,8 @@ "CVE-2007-4654" ], "details": "Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibly a related issue to CVE-2002-1024.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxr6-pgjg-2rxw/GHSA-mxr6-pgjg-2rxw.json b/advisories/unreviewed/2022/05/GHSA-mxr6-pgjg-2rxw/GHSA-mxr6-pgjg-2rxw.json index 999089d444a..330fbde8974 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxr6-pgjg-2rxw/GHSA-mxr6-pgjg-2rxw.json +++ b/advisories/unreviewed/2022/05/GHSA-mxr6-pgjg-2rxw/GHSA-mxr6-pgjg-2rxw.json @@ -7,12 +7,8 @@ "CVE-2007-5212" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the subpage parameter to wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p226-x9mj-rw33/GHSA-p226-x9mj-rw33.json b/advisories/unreviewed/2022/05/GHSA-p226-x9mj-rw33/GHSA-p226-x9mj-rw33.json index ae20cb7d99f..09baee2fa50 100644 --- a/advisories/unreviewed/2022/05/GHSA-p226-x9mj-rw33/GHSA-p226-x9mj-rw33.json +++ b/advisories/unreviewed/2022/05/GHSA-p226-x9mj-rw33/GHSA-p226-x9mj-rw33.json @@ -7,12 +7,8 @@ "CVE-2007-5227" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing a client-side security mechanism that attempts to block XSS sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3p4-rqcf-gp8r/GHSA-p3p4-rqcf-gp8r.json b/advisories/unreviewed/2022/05/GHSA-p3p4-rqcf-gp8r/GHSA-p3p4-rqcf-gp8r.json index 16ad84345b0..53619f7153f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3p4-rqcf-gp8r/GHSA-p3p4-rqcf-gp8r.json +++ b/advisories/unreviewed/2022/05/GHSA-p3p4-rqcf-gp8r/GHSA-p3p4-rqcf-gp8r.json @@ -7,12 +7,8 @@ "CVE-2007-4828" ], "details": "Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development versions before 1.11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p474-5295-x67h/GHSA-p474-5295-x67h.json b/advisories/unreviewed/2022/05/GHSA-p474-5295-x67h/GHSA-p474-5295-x67h.json index b99cef624ea..b01455b8660 100644 --- a/advisories/unreviewed/2022/05/GHSA-p474-5295-x67h/GHSA-p474-5295-x67h.json +++ b/advisories/unreviewed/2022/05/GHSA-p474-5295-x67h/GHSA-p474-5295-x67h.json @@ -7,12 +7,8 @@ "CVE-2007-4552" ], "details": "SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4mm-c9ff-6wpf/GHSA-p4mm-c9ff-6wpf.json b/advisories/unreviewed/2022/05/GHSA-p4mm-c9ff-6wpf/GHSA-p4mm-c9ff-6wpf.json index 31c9d5ca5e6..bc94b8cf6bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4mm-c9ff-6wpf/GHSA-p4mm-c9ff-6wpf.json +++ b/advisories/unreviewed/2022/05/GHSA-p4mm-c9ff-6wpf/GHSA-p4mm-c9ff-6wpf.json @@ -7,12 +7,8 @@ "CVE-2007-5367" ], "details": "Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p559-5q3r-f787/GHSA-p559-5q3r-f787.json b/advisories/unreviewed/2022/05/GHSA-p559-5q3r-f787/GHSA-p559-5q3r-f787.json index d932bc7fd20..58f623bf3b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p559-5q3r-f787/GHSA-p559-5q3r-f787.json +++ b/advisories/unreviewed/2022/05/GHSA-p559-5q3r-f787/GHSA-p559-5q3r-f787.json @@ -7,12 +7,8 @@ "CVE-2007-4903" ], "details": "Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p68h-7w45-x23q/GHSA-p68h-7w45-x23q.json b/advisories/unreviewed/2022/05/GHSA-p68h-7w45-x23q/GHSA-p68h-7w45-x23q.json index 3fc5855c3d7..799954634c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p68h-7w45-x23q/GHSA-p68h-7w45-x23q.json +++ b/advisories/unreviewed/2022/05/GHSA-p68h-7w45-x23q/GHSA-p68h-7w45-x23q.json @@ -7,12 +7,8 @@ "CVE-2007-4982" ], "details": "Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6j7-wg3q-q2c3/GHSA-p6j7-wg3q-q2c3.json b/advisories/unreviewed/2022/05/GHSA-p6j7-wg3q-q2c3/GHSA-p6j7-wg3q-q2c3.json index 8267f65336c..7be8ec30ffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6j7-wg3q-q2c3/GHSA-p6j7-wg3q-q2c3.json +++ b/advisories/unreviewed/2022/05/GHSA-p6j7-wg3q-q2c3/GHSA-p6j7-wg3q-q2c3.json @@ -7,12 +7,8 @@ "CVE-2007-4879" ], "details": "Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -132,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p73q-x72g-c4g9/GHSA-p73q-x72g-c4g9.json b/advisories/unreviewed/2022/05/GHSA-p73q-x72g-c4g9/GHSA-p73q-x72g-c4g9.json index e066599b860..fcc9076b8a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p73q-x72g-c4g9/GHSA-p73q-x72g-c4g9.json +++ b/advisories/unreviewed/2022/05/GHSA-p73q-x72g-c4g9/GHSA-p73q-x72g-c4g9.json @@ -7,12 +7,8 @@ "CVE-2007-4754" ], "details": "Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8cc-h3mm-6pcj/GHSA-p8cc-h3mm-6pcj.json b/advisories/unreviewed/2022/05/GHSA-p8cc-h3mm-6pcj/GHSA-p8cc-h3mm-6pcj.json index 4deac3b40ac..a913f912dae 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8cc-h3mm-6pcj/GHSA-p8cc-h3mm-6pcj.json +++ b/advisories/unreviewed/2022/05/GHSA-p8cc-h3mm-6pcj/GHSA-p8cc-h3mm-6pcj.json @@ -7,12 +7,8 @@ "CVE-2007-5092" ], "details": "Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p95c-gxm3-3qc4/GHSA-p95c-gxm3-3qc4.json b/advisories/unreviewed/2022/05/GHSA-p95c-gxm3-3qc4/GHSA-p95c-gxm3-3qc4.json index da14e34ae7c..5461524b607 100644 --- a/advisories/unreviewed/2022/05/GHSA-p95c-gxm3-3qc4/GHSA-p95c-gxm3-3qc4.json +++ b/advisories/unreviewed/2022/05/GHSA-p95c-gxm3-3qc4/GHSA-p95c-gxm3-3qc4.json @@ -7,12 +7,8 @@ "CVE-2007-5032" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p99r-h7pr-4h3v/GHSA-p99r-h7pr-4h3v.json b/advisories/unreviewed/2022/05/GHSA-p99r-h7pr-4h3v/GHSA-p99r-h7pr-4h3v.json index 4a1a808d8d7..ac788236e75 100644 --- a/advisories/unreviewed/2022/05/GHSA-p99r-h7pr-4h3v/GHSA-p99r-h7pr-4h3v.json +++ b/advisories/unreviewed/2022/05/GHSA-p99r-h7pr-4h3v/GHSA-p99r-h7pr-4h3v.json @@ -7,12 +7,8 @@ "CVE-2007-5122" ], "details": "SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9c7-ggch-xhmv/GHSA-p9c7-ggch-xhmv.json b/advisories/unreviewed/2022/05/GHSA-p9c7-ggch-xhmv/GHSA-p9c7-ggch-xhmv.json index f67f96786e0..157e8586fc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9c7-ggch-xhmv/GHSA-p9c7-ggch-xhmv.json +++ b/advisories/unreviewed/2022/05/GHSA-p9c7-ggch-xhmv/GHSA-p9c7-ggch-xhmv.json @@ -7,12 +7,8 @@ "CVE-2007-4923" ], "details": "PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9jj-rh6w-592g/GHSA-p9jj-rh6w-592g.json b/advisories/unreviewed/2022/05/GHSA-p9jj-rh6w-592g/GHSA-p9jj-rh6w-592g.json index d519ec77e8b..71b7c488204 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9jj-rh6w-592g/GHSA-p9jj-rh6w-592g.json +++ b/advisories/unreviewed/2022/05/GHSA-p9jj-rh6w-592g/GHSA-p9jj-rh6w-592g.json @@ -7,12 +7,8 @@ "CVE-2007-4978" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) Decoder.php and (2) Encoder.php in WBXML/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc8q-cgfc-ww4j/GHSA-pc8q-cgfc-ww4j.json b/advisories/unreviewed/2022/05/GHSA-pc8q-cgfc-ww4j/GHSA-pc8q-cgfc-ww4j.json index a4b8aed1cce..c7b41f32acc 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc8q-cgfc-ww4j/GHSA-pc8q-cgfc-ww4j.json +++ b/advisories/unreviewed/2022/05/GHSA-pc8q-cgfc-ww4j/GHSA-pc8q-cgfc-ww4j.json @@ -7,12 +7,8 @@ "CVE-2007-4712" ], "details": "PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pccm-7w72-qqqc/GHSA-pccm-7w72-qqqc.json b/advisories/unreviewed/2022/05/GHSA-pccm-7w72-qqqc/GHSA-pccm-7w72-qqqc.json index 79a8712e95b..f099dcc07b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-pccm-7w72-qqqc/GHSA-pccm-7w72-qqqc.json +++ b/advisories/unreviewed/2022/05/GHSA-pccm-7w72-qqqc/GHSA-pccm-7w72-qqqc.json @@ -7,12 +7,8 @@ "CVE-2007-4954" ], "details": "PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf99-2jcr-hrxm/GHSA-pf99-2jcr-hrxm.json b/advisories/unreviewed/2022/05/GHSA-pf99-2jcr-hrxm/GHSA-pf99-2jcr-hrxm.json index 5c17489a5df..c6fa9cbcbb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf99-2jcr-hrxm/GHSA-pf99-2jcr-hrxm.json +++ b/advisories/unreviewed/2022/05/GHSA-pf99-2jcr-hrxm/GHSA-pf99-2jcr-hrxm.json @@ -7,12 +7,8 @@ "CVE-2007-4638" ], "details": "Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pff6-h554-gmw5/GHSA-pff6-h554-gmw5.json b/advisories/unreviewed/2022/05/GHSA-pff6-h554-gmw5/GHSA-pff6-h554-gmw5.json index d0035acabdc..17c673e8b23 100644 --- a/advisories/unreviewed/2022/05/GHSA-pff6-h554-gmw5/GHSA-pff6-h554-gmw5.json +++ b/advisories/unreviewed/2022/05/GHSA-pff6-h554-gmw5/GHSA-pff6-h554-gmw5.json @@ -7,12 +7,8 @@ "CVE-2007-4649" ], "details": "MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfhr-6rh9-v34h/GHSA-pfhr-6rh9-v34h.json b/advisories/unreviewed/2022/05/GHSA-pfhr-6rh9-v34h/GHSA-pfhr-6rh9-v34h.json index 786f546f16b..58b31b2721d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfhr-6rh9-v34h/GHSA-pfhr-6rh9-v34h.json +++ b/advisories/unreviewed/2022/05/GHSA-pfhr-6rh9-v34h/GHSA-pfhr-6rh9-v34h.json @@ -7,12 +7,8 @@ "CVE-2007-5061" ], "details": "SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a banners action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfx8-pjvm-pmjj/GHSA-pfx8-pjvm-pmjj.json b/advisories/unreviewed/2022/05/GHSA-pfx8-pjvm-pmjj/GHSA-pfx8-pjvm-pmjj.json index 525ec5a385d..e3c6d48b185 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfx8-pjvm-pmjj/GHSA-pfx8-pjvm-pmjj.json +++ b/advisories/unreviewed/2022/05/GHSA-pfx8-pjvm-pmjj/GHSA-pfx8-pjvm-pmjj.json @@ -7,12 +7,8 @@ "CVE-2007-4577" ], "details": "Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a \"BZip bomb\").", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgcw-c67j-wcfc/GHSA-pgcw-c67j-wcfc.json b/advisories/unreviewed/2022/05/GHSA-pgcw-c67j-wcfc/GHSA-pgcw-c67j-wcfc.json index 70278df67a1..de5a673ab15 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgcw-c67j-wcfc/GHSA-pgcw-c67j-wcfc.json +++ b/advisories/unreviewed/2022/05/GHSA-pgcw-c67j-wcfc/GHSA-pgcw-c67j-wcfc.json @@ -7,12 +7,8 @@ "CVE-2007-5033" ], "details": "Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows remote attackers to inject arbitrary web script or HTML via the selfdes parameter in a profile_info editprofile action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgvh-6hc4-99ch/GHSA-pgvh-6hc4-99ch.json b/advisories/unreviewed/2022/05/GHSA-pgvh-6hc4-99ch/GHSA-pgvh-6hc4-99ch.json index ac3ce74b35c..2297bca7bca 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgvh-6hc4-99ch/GHSA-pgvh-6hc4-99ch.json +++ b/advisories/unreviewed/2022/05/GHSA-pgvh-6hc4-99ch/GHSA-pgvh-6hc4-99ch.json @@ -7,12 +7,8 @@ "CVE-2007-4840" ], "details": "PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phcg-r9vc-9257/GHSA-phcg-r9vc-9257.json b/advisories/unreviewed/2022/05/GHSA-phcg-r9vc-9257/GHSA-phcg-r9vc-9257.json index 5c97c0c9fa0..7ba5aad0a36 100644 --- a/advisories/unreviewed/2022/05/GHSA-phcg-r9vc-9257/GHSA-phcg-r9vc-9257.json +++ b/advisories/unreviewed/2022/05/GHSA-phcg-r9vc-9257/GHSA-phcg-r9vc-9257.json @@ -7,12 +7,8 @@ "CVE-2007-4886" ], "details": "Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phq3-r69w-jcx7/GHSA-phq3-r69w-jcx7.json b/advisories/unreviewed/2022/05/GHSA-phq3-r69w-jcx7/GHSA-phq3-r69w-jcx7.json index 4c96b7e7c1f..aa4d7467966 100644 --- a/advisories/unreviewed/2022/05/GHSA-phq3-r69w-jcx7/GHSA-phq3-r69w-jcx7.json +++ b/advisories/unreviewed/2022/05/GHSA-phq3-r69w-jcx7/GHSA-phq3-r69w-jcx7.json @@ -7,12 +7,8 @@ "CVE-2007-5008" ], "details": "The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain \"password issues\" are not detected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phwm-p823-f2fj/GHSA-phwm-p823-f2fj.json b/advisories/unreviewed/2022/05/GHSA-phwm-p823-f2fj/GHSA-phwm-p823-f2fj.json index 818df8c83e7..8a05893edcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-phwm-p823-f2fj/GHSA-phwm-p823-f2fj.json +++ b/advisories/unreviewed/2022/05/GHSA-phwm-p823-f2fj/GHSA-phwm-p823-f2fj.json @@ -7,12 +7,8 @@ "CVE-2007-4693" ], "details": "The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to \"handling of keyboard focus between secure text fields.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp7x-7hj9-7652/GHSA-pp7x-7hj9-7652.json b/advisories/unreviewed/2022/05/GHSA-pp7x-7hj9-7652/GHSA-pp7x-7hj9-7652.json index 8c8c06996a4..cdc50aab32e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp7x-7hj9-7652/GHSA-pp7x-7hj9-7652.json +++ b/advisories/unreviewed/2022/05/GHSA-pp7x-7hj9-7652/GHSA-pp7x-7hj9-7652.json @@ -7,12 +7,8 @@ "CVE-2007-4604" ], "details": "SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppf2-g285-2xj9/GHSA-ppf2-g285-2xj9.json b/advisories/unreviewed/2022/05/GHSA-ppf2-g285-2xj9/GHSA-ppf2-g285-2xj9.json index 1fddce802fe..0b0062032d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppf2-g285-2xj9/GHSA-ppf2-g285-2xj9.json +++ b/advisories/unreviewed/2022/05/GHSA-ppf2-g285-2xj9/GHSA-ppf2-g285-2xj9.json @@ -7,12 +7,8 @@ "CVE-2007-4766" ], "details": "Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 7.3 allow context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via unspecified escape (backslash) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -196,9 +192,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppvr-qxp5-wrcg/GHSA-ppvr-qxp5-wrcg.json b/advisories/unreviewed/2022/05/GHSA-ppvr-qxp5-wrcg/GHSA-ppvr-qxp5-wrcg.json index d5bc5476dda..b30a09760c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppvr-qxp5-wrcg/GHSA-ppvr-qxp5-wrcg.json +++ b/advisories/unreviewed/2022/05/GHSA-ppvr-qxp5-wrcg/GHSA-ppvr-qxp5-wrcg.json @@ -7,12 +7,8 @@ "CVE-2007-5131" ], "details": "SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppwq-7f2c-mmrh/GHSA-ppwq-7f2c-mmrh.json b/advisories/unreviewed/2022/05/GHSA-ppwq-7f2c-mmrh/GHSA-ppwq-7f2c-mmrh.json index 476b553069f..7fbfacdfc0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppwq-7f2c-mmrh/GHSA-ppwq-7f2c-mmrh.json +++ b/advisories/unreviewed/2022/05/GHSA-ppwq-7f2c-mmrh/GHSA-ppwq-7f2c-mmrh.json @@ -7,12 +7,8 @@ "CVE-2007-4539" ], "details": "The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqfc-g3ww-mmvr/GHSA-pqfc-g3ww-mmvr.json b/advisories/unreviewed/2022/05/GHSA-pqfc-g3ww-mmvr/GHSA-pqfc-g3ww-mmvr.json index 27f8485c3cf..4935b62b329 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqfc-g3ww-mmvr/GHSA-pqfc-g3ww-mmvr.json +++ b/advisories/unreviewed/2022/05/GHSA-pqfc-g3ww-mmvr/GHSA-pqfc-g3ww-mmvr.json @@ -7,12 +7,8 @@ "CVE-2007-5039" ], "details": "Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtQueryValueKey, (4) NtSetSystemInformation, and (5) NtSetValueKey kernel SSDT hooks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqr8-xhq6-rx8f/GHSA-pqr8-xhq6-rx8f.json b/advisories/unreviewed/2022/05/GHSA-pqr8-xhq6-rx8f/GHSA-pqr8-xhq6-rx8f.json index e658f54d1de..6fd5fd8258b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqr8-xhq6-rx8f/GHSA-pqr8-xhq6-rx8f.json +++ b/advisories/unreviewed/2022/05/GHSA-pqr8-xhq6-rx8f/GHSA-pqr8-xhq6-rx8f.json @@ -7,12 +7,8 @@ "CVE-2007-4843" ], "details": "Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw46-jrhv-gmmq/GHSA-pw46-jrhv-gmmq.json b/advisories/unreviewed/2022/05/GHSA-pw46-jrhv-gmmq/GHSA-pw46-jrhv-gmmq.json index 21b364ce8d8..53d88426792 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw46-jrhv-gmmq/GHSA-pw46-jrhv-gmmq.json +++ b/advisories/unreviewed/2022/05/GHSA-pw46-jrhv-gmmq/GHSA-pw46-jrhv-gmmq.json @@ -7,12 +7,8 @@ "CVE-2007-4892" ], "details": "Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwjx-xp95-jf39/GHSA-pwjx-xp95-jf39.json b/advisories/unreviewed/2022/05/GHSA-pwjx-xp95-jf39/GHSA-pwjx-xp95-jf39.json index 114656f1500..92601ec6910 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwjx-xp95-jf39/GHSA-pwjx-xp95-jf39.json +++ b/advisories/unreviewed/2022/05/GHSA-pwjx-xp95-jf39/GHSA-pwjx-xp95-jf39.json @@ -7,12 +7,8 @@ "CVE-2007-5319" ], "details": "Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service (\"unusable\" system console) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwrx-4jvg-2w44/GHSA-pwrx-4jvg-2w44.json b/advisories/unreviewed/2022/05/GHSA-pwrx-4jvg-2w44/GHSA-pwrx-4jvg-2w44.json index a73db59f40b..6c3a809b06d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwrx-4jvg-2w44/GHSA-pwrx-4jvg-2w44.json +++ b/advisories/unreviewed/2022/05/GHSA-pwrx-4jvg-2w44/GHSA-pwrx-4jvg-2w44.json @@ -7,12 +7,8 @@ "CVE-2007-4891" ], "details": "A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q29c-3w39-gpj6/GHSA-q29c-3w39-gpj6.json b/advisories/unreviewed/2022/05/GHSA-q29c-3w39-gpj6/GHSA-q29c-3w39-gpj6.json index a445230af15..584f7a63947 100644 --- a/advisories/unreviewed/2022/05/GHSA-q29c-3w39-gpj6/GHSA-q29c-3w39-gpj6.json +++ b/advisories/unreviewed/2022/05/GHSA-q29c-3w39-gpj6/GHSA-q29c-3w39-gpj6.json @@ -7,12 +7,8 @@ "CVE-2007-4660" ], "details": "Unspecified vulnerability in the chunk_split function in PHP before 5.2.4 has unknown impact and attack vectors, related to an incorrect size calculation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2j2-c4mj-23jx/GHSA-q2j2-c4mj-23jx.json b/advisories/unreviewed/2022/05/GHSA-q2j2-c4mj-23jx/GHSA-q2j2-c4mj-23jx.json index 938d93d5f46..20250b22b95 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2j2-c4mj-23jx/GHSA-q2j2-c4mj-23jx.json +++ b/advisories/unreviewed/2022/05/GHSA-q2j2-c4mj-23jx/GHSA-q2j2-c4mj-23jx.json @@ -7,12 +7,8 @@ "CVE-2007-5228" ], "details": "Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module before 4.7.x-1.5, 4.7.x-2.x before 4.7.x-2.5, and 5.x-1.x before 5.x-1.1 for Drupal allows remote authenticated users with project create or edit permissions to inject arbitrary web script or HTML via unspecified vectors involving a (1) individual or (2) overview form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6cj-qmpc-5g2g/GHSA-q6cj-qmpc-5g2g.json b/advisories/unreviewed/2022/05/GHSA-q6cj-qmpc-5g2g/GHSA-q6cj-qmpc-5g2g.json index a4047f419bf..b3ed5c459ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6cj-qmpc-5g2g/GHSA-q6cj-qmpc-5g2g.json +++ b/advisories/unreviewed/2022/05/GHSA-q6cj-qmpc-5g2g/GHSA-q6cj-qmpc-5g2g.json @@ -7,12 +7,8 @@ "CVE-2007-4972" ], "details": "RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks to the (1) NtCreateKey and (2) NtOpenKey Windows Native API functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q6w7-h4px-vqcm/GHSA-q6w7-h4px-vqcm.json b/advisories/unreviewed/2022/05/GHSA-q6w7-h4px-vqcm/GHSA-q6w7-h4px-vqcm.json index 6a29fdacba9..e351f545cd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6w7-h4px-vqcm/GHSA-q6w7-h4px-vqcm.json +++ b/advisories/unreviewed/2022/05/GHSA-q6w7-h4px-vqcm/GHSA-q6w7-h4px-vqcm.json @@ -7,12 +7,8 @@ "CVE-2007-4683" ], "details": "Directory traversal vulnerability in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to bypass the chroot mechanism via a relative path when changing the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q79j-j4r9-8grp/GHSA-q79j-j4r9-8grp.json b/advisories/unreviewed/2022/05/GHSA-q79j-j4r9-8grp/GHSA-q79j-j4r9-8grp.json index 80a3cd90539..dbf2cb1975c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q79j-j4r9-8grp/GHSA-q79j-j4r9-8grp.json +++ b/advisories/unreviewed/2022/05/GHSA-q79j-j4r9-8grp/GHSA-q79j-j4r9-8grp.json @@ -7,12 +7,8 @@ "CVE-2007-5365" ], "details": "Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8fr-cg9c-26gr/GHSA-q8fr-cg9c-26gr.json b/advisories/unreviewed/2022/05/GHSA-q8fr-cg9c-26gr/GHSA-q8fr-cg9c-26gr.json index f99ca88eaf7..28a48da6ff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8fr-cg9c-26gr/GHSA-q8fr-cg9c-26gr.json +++ b/advisories/unreviewed/2022/05/GHSA-q8fr-cg9c-26gr/GHSA-q8fr-cg9c-26gr.json @@ -7,12 +7,8 @@ "CVE-2007-4651" ], "details": "Unspecified vulnerability in Adobe Connect Enterprise Server 6 allows remote attackers to read certain pages that are restricted to the administrator via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc4h-hwgp-rx7q/GHSA-qc4h-hwgp-rx7q.json b/advisories/unreviewed/2022/05/GHSA-qc4h-hwgp-rx7q/GHSA-qc4h-hwgp-rx7q.json index d3181c1933a..7bee043e040 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc4h-hwgp-rx7q/GHSA-qc4h-hwgp-rx7q.json +++ b/advisories/unreviewed/2022/05/GHSA-qc4h-hwgp-rx7q/GHSA-qc4h-hwgp-rx7q.json @@ -7,12 +7,8 @@ "CVE-2007-5128" ], "details": "SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcgg-qpfm-vxfv/GHSA-qcgg-qpfm-vxfv.json b/advisories/unreviewed/2022/05/GHSA-qcgg-qpfm-vxfv/GHSA-qcgg-qpfm-vxfv.json index 015c94bdeda..a1892882537 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcgg-qpfm-vxfv/GHSA-qcgg-qpfm-vxfv.json +++ b/advisories/unreviewed/2022/05/GHSA-qcgg-qpfm-vxfv/GHSA-qcgg-qpfm-vxfv.json @@ -7,12 +7,8 @@ "CVE-2007-5115" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Ekke Doerre Contenido 42VariablVersion (42VV10) in contenido_hacks in Mods 4 Xoops Contenido eZ publish (pdf4cms) allow remote attackers to execute arbitrary PHP code via a URL in the cfgPathInc parameter to (1) main_upl.php, (2) main_con_editside.php, (3) main_news_rcp.php, (4) main_mod.php, (5) main_tplinput_edit.php, (6) main_con.php, (7) main_tpl.php, (8) main_con_sidelist.php, (9) main_str.php, (10) main_news.php, (11) main_tplinput.php, (12) main_lang.php, (13) main_mod_edit.php, (14) main_lay.php, (15) main_lay_edit.php, (16) main_news_send.php, (17) main_con_edittpl.php, (18) main_stat.php, (19) main_tpl_edit.php, (20) main_news_edit.php, or (21) inc/upl_show_uploads.inc.php; the (a) cfgPathContenido or (b) cfgPathTpl parameter to (22) con_show_sidelist.inc.php, (23) mod_show_modules.inc.php, (24) con_edit_form.inc.php, (25) lay_show_layouts.inc.php, (26) con_show_tree.inc.php, (27) news_show_newsletters.inc.php, (28) str_show_tree.inc.php, (29) tpl_show_templates.inc.php, (30) stat_show_tree.inc.php, (31) con_editcontent.inc.php, or (32) news_show_recipients.inc.php in inc/; or the cfgPathTpl parameter to (33) main_user_md5.php3, or (34) actions_mod.php, (35) actions_lay.php, (36) actions_upl.php, (37) actions_stat.php, (38) actions_news.php, (39) actions_str.php, (40) header.php, (41) actions_con_sidelist.php, (42) main_top.inc.php, (43) actions_tpl.php, or (44) actions_con.php in tpl/. NOTE: vectors 21, 24, 26, 27, 32, 34, 35, 36, 37, 38, 39, 40, 41, 43, and 44 are disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcj3-h9mr-5c65/GHSA-qcj3-h9mr-5c65.json b/advisories/unreviewed/2022/05/GHSA-qcj3-h9mr-5c65/GHSA-qcj3-h9mr-5c65.json index 50964d76db1..d009163c18b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcj3-h9mr-5c65/GHSA-qcj3-h9mr-5c65.json +++ b/advisories/unreviewed/2022/05/GHSA-qcj3-h9mr-5c65/GHSA-qcj3-h9mr-5c65.json @@ -7,12 +7,8 @@ "CVE-2007-4999" ], "details": "libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfqw-7vp2-p8m5/GHSA-qfqw-7vp2-p8m5.json b/advisories/unreviewed/2022/05/GHSA-qfqw-7vp2-p8m5/GHSA-qfqw-7vp2-p8m5.json index 285d515ecb1..0d2303751a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfqw-7vp2-p8m5/GHSA-qfqw-7vp2-p8m5.json +++ b/advisories/unreviewed/2022/05/GHSA-qfqw-7vp2-p8m5/GHSA-qfqw-7vp2-p8m5.json @@ -7,12 +7,8 @@ "CVE-2007-4992" ], "details": "Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execute arbitrary code via a long request to TCP port 3050.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg6g-mgw6-822x/GHSA-qg6g-mgw6-822x.json b/advisories/unreviewed/2022/05/GHSA-qg6g-mgw6-822x/GHSA-qg6g-mgw6-822x.json index 9be86e00154..ee10713d463 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg6g-mgw6-822x/GHSA-qg6g-mgw6-822x.json +++ b/advisories/unreviewed/2022/05/GHSA-qg6g-mgw6-822x/GHSA-qg6g-mgw6-822x.json @@ -7,12 +7,8 @@ "CVE-2007-4984" ], "details": "SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh88-37x3-2c52/GHSA-qh88-37x3-2c52.json b/advisories/unreviewed/2022/05/GHSA-qh88-37x3-2c52/GHSA-qh88-37x3-2c52.json index be40d83ab48..e56347ca794 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh88-37x3-2c52/GHSA-qh88-37x3-2c52.json +++ b/advisories/unreviewed/2022/05/GHSA-qh88-37x3-2c52/GHSA-qh88-37x3-2c52.json @@ -7,12 +7,8 @@ "CVE-2007-4844" ], "details": "X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a \"CWD /\" command, which allows remote FTP servers to cause a denial of service (infinite loop) by (1) repeatedly sending a 550 error response, or (2) sending a 550 error response and then disconnecting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjxj-rc6r-r77w/GHSA-qjxj-rc6r-r77w.json b/advisories/unreviewed/2022/05/GHSA-qjxj-rc6r-r77w/GHSA-qjxj-rc6r-r77w.json index 5195025ff4f..bbef926f496 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjxj-rc6r-r77w/GHSA-qjxj-rc6r-r77w.json +++ b/advisories/unreviewed/2022/05/GHSA-qjxj-rc6r-r77w/GHSA-qjxj-rc6r-r77w.json @@ -7,12 +7,8 @@ "CVE-2007-5208" ], "details": "hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking sendmail.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmp2-8m8m-8v95/GHSA-qmp2-8m8m-8v95.json b/advisories/unreviewed/2022/05/GHSA-qmp2-8m8m-8v95/GHSA-qmp2-8m8m-8v95.json index 5350466f384..0ccb29d2731 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmp2-8m8m-8v95/GHSA-qmp2-8m8m-8v95.json +++ b/advisories/unreviewed/2022/05/GHSA-qmp2-8m8m-8v95/GHSA-qmp2-8m8m-8v95.json @@ -7,12 +7,8 @@ "CVE-2007-5113" ], "details": "report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmrr-7vgr-25wh/GHSA-qmrr-7vgr-25wh.json b/advisories/unreviewed/2022/05/GHSA-qmrr-7vgr-25wh/GHSA-qmrr-7vgr-25wh.json index f249ff96e50..f8ed6276b38 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmrr-7vgr-25wh/GHSA-qmrr-7vgr-25wh.json +++ b/advisories/unreviewed/2022/05/GHSA-qmrr-7vgr-25wh/GHSA-qmrr-7vgr-25wh.json @@ -7,12 +7,8 @@ "CVE-2007-4714" ], "details": "SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp7c-5865-mcx7/GHSA-qp7c-5865-mcx7.json b/advisories/unreviewed/2022/05/GHSA-qp7c-5865-mcx7/GHSA-qp7c-5865-mcx7.json index bf5313c59eb..d4eb706c978 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp7c-5865-mcx7/GHSA-qp7c-5865-mcx7.json +++ b/advisories/unreviewed/2022/05/GHSA-qp7c-5865-mcx7/GHSA-qp7c-5865-mcx7.json @@ -7,12 +7,8 @@ "CVE-2007-4588" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Server Admin Level (NodeWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) nodeworx.php, (3) users.php, (4) lang.php, (5) themes.php, (6) setup.php, (7) siteworx.php, (8) packages.php, (9) backup.php, (10) import.php, (11) scriptworx.php, (12) resellers.php, (13) reseller-packages.php, (14) http.php, (15) mail.php, (16) ftp.php, (17) mysql.php, (18) sshd.php, (19) nfs.php, (20) cron.php, (21) ip.php, (22) firewall.php, (23) updates.php, (24) rrd.php, or (25) cluster.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpg7-hxpw-2pcj/GHSA-qpg7-hxpw-2pcj.json b/advisories/unreviewed/2022/05/GHSA-qpg7-hxpw-2pcj/GHSA-qpg7-hxpw-2pcj.json index e091d195514..30aab9809f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpg7-hxpw-2pcj/GHSA-qpg7-hxpw-2pcj.json +++ b/advisories/unreviewed/2022/05/GHSA-qpg7-hxpw-2pcj/GHSA-qpg7-hxpw-2pcj.json @@ -7,12 +7,8 @@ "CVE-2007-4550" ], "details": "Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an fnm field in a folder-name record in an ALPASS DB (APW) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpgc-j35g-v56h/GHSA-qpgc-j35g-v56h.json b/advisories/unreviewed/2022/05/GHSA-qpgc-j35g-v56h/GHSA-qpgc-j35g-v56h.json index b20a456df76..04a5834dbab 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpgc-j35g-v56h/GHSA-qpgc-j35g-v56h.json +++ b/advisories/unreviewed/2022/05/GHSA-qpgc-j35g-v56h/GHSA-qpgc-j35g-v56h.json @@ -7,12 +7,8 @@ "CVE-2007-4636" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqhq-3w3x-rwxq/GHSA-qqhq-3w3x-rwxq.json b/advisories/unreviewed/2022/05/GHSA-qqhq-3w3x-rwxq/GHSA-qqhq-3w3x-rwxq.json index 05ac27abf94..187fcf44040 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqhq-3w3x-rwxq/GHSA-qqhq-3w3x-rwxq.json +++ b/advisories/unreviewed/2022/05/GHSA-qqhq-3w3x-rwxq/GHSA-qqhq-3w3x-rwxq.json @@ -7,12 +7,8 @@ "CVE-2007-5052" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbitrary web script or HTML via a request to the wiki module with (1) the title parameter or (2) a \"title=\" sequence in the PATH_INFO, or a request to the download module with (3) the cat parameter or (4) a \"cat=\" sequence in the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrvf-w9hh-3g69/GHSA-qrvf-w9hh-3g69.json b/advisories/unreviewed/2022/05/GHSA-qrvf-w9hh-3g69/GHSA-qrvf-w9hh-3g69.json index 2cd24c5eaa3..d42723c9816 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrvf-w9hh-3g69/GHSA-qrvf-w9hh-3g69.json +++ b/advisories/unreviewed/2022/05/GHSA-qrvf-w9hh-3g69/GHSA-qrvf-w9hh-3g69.json @@ -7,12 +7,8 @@ "CVE-2007-4917" ], "details": "Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv2g-g256-5493/GHSA-qv2g-g256-5493.json b/advisories/unreviewed/2022/05/GHSA-qv2g-g256-5493/GHSA-qv2g-g256-5493.json index 929fc4ec028..86497d5f5de 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv2g-g256-5493/GHSA-qv2g-g256-5493.json +++ b/advisories/unreviewed/2022/05/GHSA-qv2g-g256-5493/GHSA-qv2g-g256-5493.json @@ -7,12 +7,8 @@ "CVE-2007-5183" ], "details": "Cross-site scripting (XSS) vulnerability in Mailbox.mws in OdysseySuite, possibly 4.0.729, allows remote attackers to inject arbitrary web script or HTML via the idkey parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv36-qcjj-rxf5/GHSA-qv36-qcjj-rxf5.json b/advisories/unreviewed/2022/05/GHSA-qv36-qcjj-rxf5/GHSA-qv36-qcjj-rxf5.json index 35b7c2577e5..9a6e051758f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv36-qcjj-rxf5/GHSA-qv36-qcjj-rxf5.json +++ b/advisories/unreviewed/2022/05/GHSA-qv36-qcjj-rxf5/GHSA-qv36-qcjj-rxf5.json @@ -7,12 +7,8 @@ "CVE-2007-5078" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager allow remote attackers to inject arbitrary web script or HTML via unspecified \"user-supplied input\" to (1) center.exe or (2) Index.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwj2-7cwg-38q3/GHSA-qwj2-7cwg-38q3.json b/advisories/unreviewed/2022/05/GHSA-qwj2-7cwg-38q3/GHSA-qwj2-7cwg-38q3.json index 9f5a06cde73..1df91f85587 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwj2-7cwg-38q3/GHSA-qwj2-7cwg-38q3.json +++ b/advisories/unreviewed/2022/05/GHSA-qwj2-7cwg-38q3/GHSA-qwj2-7cwg-38q3.json @@ -7,12 +7,8 @@ "CVE-2007-4902" ], "details": "Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qww2-669w-5rff/GHSA-qww2-669w-5rff.json b/advisories/unreviewed/2022/05/GHSA-qww2-669w-5rff/GHSA-qww2-669w-5rff.json index f2b1c5dd870..3a9b8c8e379 100644 --- a/advisories/unreviewed/2022/05/GHSA-qww2-669w-5rff/GHSA-qww2-669w-5rff.json +++ b/advisories/unreviewed/2022/05/GHSA-qww2-669w-5rff/GHSA-qww2-669w-5rff.json @@ -7,12 +7,8 @@ "CVE-2007-4915" ], "details": "The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwx4-rgjp-5rr6/GHSA-qwx4-rgjp-5rr6.json b/advisories/unreviewed/2022/05/GHSA-qwx4-rgjp-5rr6/GHSA-qwx4-rgjp-5rr6.json index 5ce34cba483..76bef483aa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwx4-rgjp-5rr6/GHSA-qwx4-rgjp-5rr6.json +++ b/advisories/unreviewed/2022/05/GHSA-qwx4-rgjp-5rr6/GHSA-qwx4-rgjp-5rr6.json @@ -7,12 +7,8 @@ "CVE-2007-4692" ], "details": "The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qx34-mm7f-757c/GHSA-qx34-mm7f-757c.json b/advisories/unreviewed/2022/05/GHSA-qx34-mm7f-757c/GHSA-qx34-mm7f-757c.json index a25941559c8..3e902108897 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx34-mm7f-757c/GHSA-qx34-mm7f-757c.json +++ b/advisories/unreviewed/2022/05/GHSA-qx34-mm7f-757c/GHSA-qx34-mm7f-757c.json @@ -7,12 +7,8 @@ "CVE-2007-5358" ], "details": "Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qx4f-wxcg-v25j/GHSA-qx4f-wxcg-v25j.json b/advisories/unreviewed/2022/05/GHSA-qx4f-wxcg-v25j/GHSA-qx4f-wxcg-v25j.json index 2bc4e721314..9441fade920 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx4f-wxcg-v25j/GHSA-qx4f-wxcg-v25j.json +++ b/advisories/unreviewed/2022/05/GHSA-qx4f-wxcg-v25j/GHSA-qx4f-wxcg-v25j.json @@ -7,12 +7,8 @@ "CVE-2007-4590" ], "details": "The get_system_info command in Ignite-UX C.7.0 through C.7.3, and DynRootDisk (DRD) A.1.0.16.417 through A.2.0.0.592, on HP-UX B.11.11, B.11.23, and B.11.31 does not inform local users of networking changes made by the command, which has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxvm-wgc6-9m8c/GHSA-qxvm-wgc6-9m8c.json b/advisories/unreviewed/2022/05/GHSA-qxvm-wgc6-9m8c/GHSA-qxvm-wgc6-9m8c.json index 7fe06b3cf9f..a86659b9491 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxvm-wgc6-9m8c/GHSA-qxvm-wgc6-9m8c.json +++ b/advisories/unreviewed/2022/05/GHSA-qxvm-wgc6-9m8c/GHSA-qxvm-wgc6-9m8c.json @@ -7,12 +7,8 @@ "CVE-2007-4847" ], "details": "Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3v5-4874-4557/GHSA-r3v5-4874-4557.json b/advisories/unreviewed/2022/05/GHSA-r3v5-4874-4557/GHSA-r3v5-4874-4557.json index 9cfad7c1184..147bb009e76 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3v5-4874-4557/GHSA-r3v5-4874-4557.json +++ b/advisories/unreviewed/2022/05/GHSA-r3v5-4874-4557/GHSA-r3v5-4874-4557.json @@ -7,12 +7,8 @@ "CVE-2007-4908" ], "details": "Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r59q-696w-6whc/GHSA-r59q-696w-6whc.json b/advisories/unreviewed/2022/05/GHSA-r59q-696w-6whc/GHSA-r59q-696w-6whc.json index a37d2181fc5..be69c412b7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r59q-696w-6whc/GHSA-r59q-696w-6whc.json +++ b/advisories/unreviewed/2022/05/GHSA-r59q-696w-6whc/GHSA-r59q-696w-6whc.json @@ -7,12 +7,8 @@ "CVE-2007-5047" ], "details": "Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-2007-1793.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5mj-33gq-r32r/GHSA-r5mj-33gq-r32r.json b/advisories/unreviewed/2022/05/GHSA-r5mj-33gq-r32r/GHSA-r5mj-33gq-r32r.json index e066d1c92a4..fcdd994ca2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5mj-33gq-r32r/GHSA-r5mj-33gq-r32r.json +++ b/advisories/unreviewed/2022/05/GHSA-r5mj-33gq-r32r/GHSA-r5mj-33gq-r32r.json @@ -7,12 +7,8 @@ "CVE-2007-5221" ], "details": "PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the form parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5vp-hv57-2vcx/GHSA-r5vp-hv57-2vcx.json b/advisories/unreviewed/2022/05/GHSA-r5vp-hv57-2vcx/GHSA-r5vp-hv57-2vcx.json index ecfe1c96d23..bf68c3c10cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5vp-hv57-2vcx/GHSA-r5vp-hv57-2vcx.json +++ b/advisories/unreviewed/2022/05/GHSA-r5vp-hv57-2vcx/GHSA-r5vp-hv57-2vcx.json @@ -7,12 +7,8 @@ "CVE-2007-4561" ], "details": "Heap-based buffer overflow in the RTSP service in Helix DNA Server before 11.1.4 allows remote attackers to execute arbitrary code via an RSTP command containing multiple Require headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r65m-p5h5-gwg7/GHSA-r65m-p5h5-gwg7.json b/advisories/unreviewed/2022/05/GHSA-r65m-p5h5-gwg7/GHSA-r65m-p5h5-gwg7.json index 510a7a1adca..daa5feb4a6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r65m-p5h5-gwg7/GHSA-r65m-p5h5-gwg7.json +++ b/advisories/unreviewed/2022/05/GHSA-r65m-p5h5-gwg7/GHSA-r65m-p5h5-gwg7.json @@ -7,12 +7,8 @@ "CVE-2007-5382" ], "details": "The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6mq-3vv9-38j4/GHSA-r6mq-3vv9-38j4.json b/advisories/unreviewed/2022/05/GHSA-r6mq-3vv9-38j4/GHSA-r6mq-3vv9-38j4.json index 5a199165e6b..01ea71fcefc 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6mq-3vv9-38j4/GHSA-r6mq-3vv9-38j4.json +++ b/advisories/unreviewed/2022/05/GHSA-r6mq-3vv9-38j4/GHSA-r6mq-3vv9-38j4.json @@ -7,12 +7,8 @@ "CVE-2007-5003" ], "details": "Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6r3-r6w4-2j6c/GHSA-r6r3-r6w4-2j6c.json b/advisories/unreviewed/2022/05/GHSA-r6r3-r6w4-2j6c/GHSA-r6r3-r6w4-2j6c.json index 98dadd1d9bc..29e66e056ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6r3-r6w4-2j6c/GHSA-r6r3-r6w4-2j6c.json +++ b/advisories/unreviewed/2022/05/GHSA-r6r3-r6w4-2j6c/GHSA-r6r3-r6w4-2j6c.json @@ -7,12 +7,8 @@ "CVE-2007-4591" ], "details": "vstor-ws60.sys in VMWare Workstation 6.0 allows local users to cause a denial of service (host operating system crash) and possibly gain privileges by sending a small file buffer size value to the FsSetVolumeInformation IOCTL handler with an FsSetFileInformation subcode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6r8-62w8-r2qw/GHSA-r6r8-62w8-r2qw.json b/advisories/unreviewed/2022/05/GHSA-r6r8-62w8-r2qw/GHSA-r6r8-62w8-r2qw.json index 83d74ca0774..28166edf078 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6r8-62w8-r2qw/GHSA-r6r8-62w8-r2qw.json +++ b/advisories/unreviewed/2022/05/GHSA-r6r8-62w8-r2qw/GHSA-r6r8-62w8-r2qw.json @@ -7,12 +7,8 @@ "CVE-2007-4789" ], "details": "Cisco Content Switching Modules (CSM) 4.2 before 4.2.7, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.6, when service termination is enabled, allow remote attackers to cause a denial of service (reboot) via unspecified vectors related to high network utilization, aka CSCsh57876.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6wm-8m7v-6mjf/GHSA-r6wm-8m7v-6mjf.json b/advisories/unreviewed/2022/05/GHSA-r6wm-8m7v-6mjf/GHSA-r6wm-8m7v-6mjf.json index a87dceac99d..b5792747249 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6wm-8m7v-6mjf/GHSA-r6wm-8m7v-6mjf.json +++ b/advisories/unreviewed/2022/05/GHSA-r6wm-8m7v-6mjf/GHSA-r6wm-8m7v-6mjf.json @@ -7,12 +7,8 @@ "CVE-2007-4764" ], "details": "Directory traversal vulnerability in pawfaliki.php in Pawfaliki 0.5.1 allows remote attackers to list arbitrary files via a .. (dot dot) in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r92j-qh57-4mrf/GHSA-r92j-qh57-4mrf.json b/advisories/unreviewed/2022/05/GHSA-r92j-qh57-4mrf/GHSA-r92j-qh57-4mrf.json index 04552605efd..bd2d02162ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-r92j-qh57-4mrf/GHSA-r92j-qh57-4mrf.json +++ b/advisories/unreviewed/2022/05/GHSA-r92j-qh57-4mrf/GHSA-r92j-qh57-4mrf.json @@ -7,12 +7,8 @@ "CVE-2007-4827" ], "details": "Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r96j-qc97-7fj4/GHSA-r96j-qc97-7fj4.json b/advisories/unreviewed/2022/05/GHSA-r96j-qc97-7fj4/GHSA-r96j-qc97-7fj4.json index 305167e3f08..6a02d790ba6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r96j-qc97-7fj4/GHSA-r96j-qc97-7fj4.json +++ b/advisories/unreviewed/2022/05/GHSA-r96j-qc97-7fj4/GHSA-r96j-qc97-7fj4.json @@ -7,12 +7,8 @@ "CVE-2007-4648" ], "details": "The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9pr-94pj-px9j/GHSA-r9pr-94pj-px9j.json b/advisories/unreviewed/2022/05/GHSA-r9pr-94pj-px9j/GHSA-r9pr-94pj-px9j.json index dd0b148afc5..9f81f3d9617 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9pr-94pj-px9j/GHSA-r9pr-94pj-px9j.json +++ b/advisories/unreviewed/2022/05/GHSA-r9pr-94pj-px9j/GHSA-r9pr-94pj-px9j.json @@ -7,12 +7,8 @@ "CVE-2007-5355" ], "details": "The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain, which allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9v7-jgpj-m4mq/GHSA-r9v7-jgpj-m4mq.json b/advisories/unreviewed/2022/05/GHSA-r9v7-jgpj-m4mq/GHSA-r9v7-jgpj-m4mq.json index 8229d1a222f..024301829ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9v7-jgpj-m4mq/GHSA-r9v7-jgpj-m4mq.json +++ b/advisories/unreviewed/2022/05/GHSA-r9v7-jgpj-m4mq/GHSA-r9v7-jgpj-m4mq.json @@ -7,12 +7,8 @@ "CVE-2007-4996" ], "details": "libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of \"an invalid memory location.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9w9-725f-gccq/GHSA-r9w9-725f-gccq.json b/advisories/unreviewed/2022/05/GHSA-r9w9-725f-gccq/GHSA-r9w9-725f-gccq.json index 32edad134f0..5bd483dcc7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9w9-725f-gccq/GHSA-r9w9-725f-gccq.json +++ b/advisories/unreviewed/2022/05/GHSA-r9w9-725f-gccq/GHSA-r9w9-725f-gccq.json @@ -7,12 +7,8 @@ "CVE-2007-4913" ], "details": "ips_kernel/class_upload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files with crafted image filenames to uploads/, where they are saved with a .txt extension and are not executable. NOTE: there are limited usage scenarios under which this would be a vulnerability, but it is being tracked by CVE since the vendor has stated it is security-relevant.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rff5-g5w3-xp43/GHSA-rff5-g5w3-xp43.json b/advisories/unreviewed/2022/05/GHSA-rff5-g5w3-xp43/GHSA-rff5-g5w3-xp43.json index fc5f733de4c..a571c4a7837 100644 --- a/advisories/unreviewed/2022/05/GHSA-rff5-g5w3-xp43/GHSA-rff5-g5w3-xp43.json +++ b/advisories/unreviewed/2022/05/GHSA-rff5-g5w3-xp43/GHSA-rff5-g5w3-xp43.json @@ -7,12 +7,8 @@ "CVE-2007-4607" ], "details": "Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgrj-v98g-6x35/GHSA-rgrj-v98g-6x35.json b/advisories/unreviewed/2022/05/GHSA-rgrj-v98g-6x35/GHSA-rgrj-v98g-6x35.json index 60bc24ad510..ba62432b177 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgrj-v98g-6x35/GHSA-rgrj-v98g-6x35.json +++ b/advisories/unreviewed/2022/05/GHSA-rgrj-v98g-6x35/GHSA-rgrj-v98g-6x35.json @@ -7,12 +7,8 @@ "CVE-2007-4737" ], "details": "Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmmm-3chf-9p74/GHSA-rmmm-3chf-9p74.json b/advisories/unreviewed/2022/05/GHSA-rmmm-3chf-9p74/GHSA-rmmm-3chf-9p74.json index ccad104cbde..ad5501ab519 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmmm-3chf-9p74/GHSA-rmmm-3chf-9p74.json +++ b/advisories/unreviewed/2022/05/GHSA-rmmm-3chf-9p74/GHSA-rmmm-3chf-9p74.json @@ -7,12 +7,8 @@ "CVE-2007-5011" ], "details": "webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpcw-7v9j-cpgw/GHSA-rpcw-7v9j-cpgw.json b/advisories/unreviewed/2022/05/GHSA-rpcw-7v9j-cpgw/GHSA-rpcw-7v9j-cpgw.json index a4153505c9c..baa00170b4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpcw-7v9j-cpgw/GHSA-rpcw-7v9j-cpgw.json +++ b/advisories/unreviewed/2022/05/GHSA-rpcw-7v9j-cpgw/GHSA-rpcw-7v9j-cpgw.json @@ -7,12 +7,8 @@ "CVE-2007-4780" ], "details": "Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpmf-q3w7-3ccm/GHSA-rpmf-q3w7-3ccm.json b/advisories/unreviewed/2022/05/GHSA-rpmf-q3w7-3ccm/GHSA-rpmf-q3w7-3ccm.json index a62938a57ca..e69a080527f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpmf-q3w7-3ccm/GHSA-rpmf-q3w7-3ccm.json +++ b/advisories/unreviewed/2022/05/GHSA-rpmf-q3w7-3ccm/GHSA-rpmf-q3w7-3ccm.json @@ -7,12 +7,8 @@ "CVE-2007-4687" ], "details": "The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq5p-wph9-fqmc/GHSA-rq5p-wph9-fqmc.json b/advisories/unreviewed/2022/05/GHSA-rq5p-wph9-fqmc/GHSA-rq5p-wph9-fqmc.json index 2297301d105..2564e402d8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq5p-wph9-fqmc/GHSA-rq5p-wph9-fqmc.json +++ b/advisories/unreviewed/2022/05/GHSA-rq5p-wph9-fqmc/GHSA-rq5p-wph9-fqmc.json @@ -7,12 +7,8 @@ "CVE-2007-5046" ], "details": "Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq97-q79g-hxg7/GHSA-rq97-q79g-hxg7.json b/advisories/unreviewed/2022/05/GHSA-rq97-q79g-hxg7/GHSA-rq97-q79g-hxg7.json index 16fcf3f7e25..4b51e524226 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq97-q79g-hxg7/GHSA-rq97-q79g-hxg7.json +++ b/advisories/unreviewed/2022/05/GHSA-rq97-q79g-hxg7/GHSA-rq97-q79g-hxg7.json @@ -7,12 +7,8 @@ "CVE-2007-5100" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a before 20070922, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) language/lang_german/lang_admin_album.php, (2) language/lang_english/lang_main_album.php, and (3) language/lang_english/lang_admin_album.php, different vectors than CVE-2007-5009.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqfv-g8fm-xg4w/GHSA-rqfv-g8fm-xg4w.json b/advisories/unreviewed/2022/05/GHSA-rqfv-g8fm-xg4w/GHSA-rqfv-g8fm-xg4w.json index 0d7c1aa8b07..ffd294fed91 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqfv-g8fm-xg4w/GHSA-rqfv-g8fm-xg4w.json +++ b/advisories/unreviewed/2022/05/GHSA-rqfv-g8fm-xg4w/GHSA-rqfv-g8fm-xg4w.json @@ -7,12 +7,8 @@ "CVE-2007-4960" ], "details": "Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, as used in Internet Explorer and possibly Firefox, allows remote attackers to obtain sensitive information via a '\" ' (double-quote space) sequence followed by the -autologin and -loginuri arguments, which cause the handler to post login credentials and software installation details to an arbitrary URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqh2-c6jw-prwf/GHSA-rqh2-c6jw-prwf.json b/advisories/unreviewed/2022/05/GHSA-rqh2-c6jw-prwf/GHSA-rqh2-c6jw-prwf.json index 37aeca6ad78..8a1550ae1a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqh2-c6jw-prwf/GHSA-rqh2-c6jw-prwf.json +++ b/advisories/unreviewed/2022/05/GHSA-rqh2-c6jw-prwf/GHSA-rqh2-c6jw-prwf.json @@ -7,12 +7,8 @@ "CVE-2007-4746" ], "details": "The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows remote attackers to perform administrative actions, aka CSCsj34681.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqhh-9m59-r644/GHSA-rqhh-9m59-r644.json b/advisories/unreviewed/2022/05/GHSA-rqhh-9m59-r644/GHSA-rqhh-9m59-r644.json index be722fbb49c..5458ce39d82 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqhh-9m59-r644/GHSA-rqhh-9m59-r644.json +++ b/advisories/unreviewed/2022/05/GHSA-rqhh-9m59-r644/GHSA-rqhh-9m59-r644.json @@ -7,12 +7,8 @@ "CVE-2007-4826" ], "details": "bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqv5-c4p5-fmv6/GHSA-rqv5-c4p5-fmv6.json b/advisories/unreviewed/2022/05/GHSA-rqv5-c4p5-fmv6/GHSA-rqv5-c4p5-fmv6.json index e6e8793ccd3..0337a625074 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqv5-c4p5-fmv6/GHSA-rqv5-c4p5-fmv6.json +++ b/advisories/unreviewed/2022/05/GHSA-rqv5-c4p5-fmv6/GHSA-rqv5-c4p5-fmv6.json @@ -7,12 +7,8 @@ "CVE-2007-4900" ], "details": "Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary web script or HTML via the username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvj8-8m76-4334/GHSA-rvj8-8m76-4334.json b/advisories/unreviewed/2022/05/GHSA-rvj8-8m76-4334/GHSA-rvj8-8m76-4334.json index f6d114f5e2b..320c2d5f439 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvj8-8m76-4334/GHSA-rvj8-8m76-4334.json +++ b/advisories/unreviewed/2022/05/GHSA-rvj8-8m76-4334/GHSA-rvj8-8m76-4334.json @@ -7,12 +7,8 @@ "CVE-2007-4906" ], "details": "PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvxj-4r57-9666/GHSA-rvxj-4r57-9666.json b/advisories/unreviewed/2022/05/GHSA-rvxj-4r57-9666/GHSA-rvxj-4r57-9666.json index 66fd703dacb..b10f145308a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvxj-4r57-9666/GHSA-rvxj-4r57-9666.json +++ b/advisories/unreviewed/2022/05/GHSA-rvxj-4r57-9666/GHSA-rvxj-4r57-9666.json @@ -7,12 +7,8 @@ "CVE-2007-4546" ], "details": "Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to local filenames corresponding to names in Local File Header fields in this archive, which might allow remote attackers to trick a user into performing a dangerous file overwrite or creation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwhc-g7xj-h37q/GHSA-rwhc-g7xj-h37q.json b/advisories/unreviewed/2022/05/GHSA-rwhc-g7xj-h37q/GHSA-rwhc-g7xj-h37q.json index a5716934d3f..753a1f452a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwhc-g7xj-h37q/GHSA-rwhc-g7xj-h37q.json +++ b/advisories/unreviewed/2022/05/GHSA-rwhc-g7xj-h37q/GHSA-rwhc-g7xj-h37q.json @@ -7,12 +7,8 @@ "CVE-2007-4829" ], "details": "Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has \"..\" sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwvw-fwqw-7f2x/GHSA-rwvw-fwqw-7f2x.json b/advisories/unreviewed/2022/05/GHSA-rwvw-fwqw-7f2x/GHSA-rwvw-fwqw-7f2x.json index a4fa40a51a4..c8f6d200edc 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwvw-fwqw-7f2x/GHSA-rwvw-fwqw-7f2x.json +++ b/advisories/unreviewed/2022/05/GHSA-rwvw-fwqw-7f2x/GHSA-rwvw-fwqw-7f2x.json @@ -7,12 +7,8 @@ "CVE-2007-4564" ], "details": "Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxqf-qrfm-xmj9/GHSA-rxqf-qrfm-xmj9.json b/advisories/unreviewed/2022/05/GHSA-rxqf-qrfm-xmj9/GHSA-rxqf-qrfm-xmj9.json index b548090147b..6b58598f1f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxqf-qrfm-xmj9/GHSA-rxqf-qrfm-xmj9.json +++ b/advisories/unreviewed/2022/05/GHSA-rxqf-qrfm-xmj9/GHSA-rxqf-qrfm-xmj9.json @@ -7,12 +7,8 @@ "CVE-2007-4885" ], "details": "Avnex AV MP3 Player allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v49g-5r22-m7m9/GHSA-v49g-5r22-m7m9.json b/advisories/unreviewed/2022/05/GHSA-v49g-5r22-m7m9/GHSA-v49g-5r22-m7m9.json index b45e6943452..209e2a0c88c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v49g-5r22-m7m9/GHSA-v49g-5r22-m7m9.json +++ b/advisories/unreviewed/2022/05/GHSA-v49g-5r22-m7m9/GHSA-v49g-5r22-m7m9.json @@ -7,12 +7,8 @@ "CVE-2007-5362" ], "details": "Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4x8-qp98-4m68/GHSA-v4x8-qp98-4m68.json b/advisories/unreviewed/2022/05/GHSA-v4x8-qp98-4m68/GHSA-v4x8-qp98-4m68.json index e200788969b..595446f5c29 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4x8-qp98-4m68/GHSA-v4x8-qp98-4m68.json +++ b/advisories/unreviewed/2022/05/GHSA-v4x8-qp98-4m68/GHSA-v4x8-qp98-4m68.json @@ -7,12 +7,8 @@ "CVE-2007-5369" ], "details": "The GetMagicNumberString function in Massive Entertainment World in Conflict 1.000 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a string to the VoIP port (52999/tcp) with an invalid value in the third byte.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5gg-g8c2-9jp8/GHSA-v5gg-g8c2-9jp8.json b/advisories/unreviewed/2022/05/GHSA-v5gg-g8c2-9jp8/GHSA-v5gg-g8c2-9jp8.json index 8ae90be8c94..356a344b65b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5gg-g8c2-9jp8/GHSA-v5gg-g8c2-9jp8.json +++ b/advisories/unreviewed/2022/05/GHSA-v5gg-g8c2-9jp8/GHSA-v5gg-g8c2-9jp8.json @@ -7,12 +7,8 @@ "CVE-2007-5084" ], "details": "Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3) 0x09, (4) 0x1E, (5) 0x32, (6) 0x36, (7) 0x40, and possibly others.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5rr-4m5q-q852/GHSA-v5rr-4m5q-q852.json b/advisories/unreviewed/2022/05/GHSA-v5rr-4m5q-q852/GHSA-v5rr-4m5q-q852.json index 2b638726cc1..bbf6fa43000 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5rr-4m5q-q852/GHSA-v5rr-4m5q-q852.json +++ b/advisories/unreviewed/2022/05/GHSA-v5rr-4m5q-q852/GHSA-v5rr-4m5q-q852.json @@ -7,12 +7,8 @@ "CVE-2007-4785" ], "details": "Sony Micro Vault Fingerprint Access Software, as distributed with Sony Micro Vault USM-F USB flash drives, installs a driver that hides a directory under %WINDIR%, which might allow remote attackers to bypass malware detection by placing files in this directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v682-76g4-2gwm/GHSA-v682-76g4-2gwm.json b/advisories/unreviewed/2022/05/GHSA-v682-76g4-2gwm/GHSA-v682-76g4-2gwm.json index 3154f1a46e4..be9bf5e35b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v682-76g4-2gwm/GHSA-v682-76g4-2gwm.json +++ b/advisories/unreviewed/2022/05/GHSA-v682-76g4-2gwm/GHSA-v682-76g4-2gwm.json @@ -7,12 +7,8 @@ "CVE-2007-5107" ], "details": "Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53 and earlier allows remote attackers to execute arbitrary code via a long ShortFormat property value. NOTE: some of these details are obtained from third party information. NOTE: the researcher claims that this is the same as CVE-2007-5108, but there is insufficient detail for CVE-2007-5108 to be certain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v773-g4hf-qhgj/GHSA-v773-g4hf-qhgj.json b/advisories/unreviewed/2022/05/GHSA-v773-g4hf-qhgj/GHSA-v773-g4hf-qhgj.json index 30ed3976749..6e56c339de8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v773-g4hf-qhgj/GHSA-v773-g4hf-qhgj.json +++ b/advisories/unreviewed/2022/05/GHSA-v773-g4hf-qhgj/GHSA-v773-g4hf-qhgj.json @@ -7,12 +7,8 @@ "CVE-2007-4626" ], "details": "Unspecified vulnerability in Polipo before 1.0.2 allows remote attackers to cause a denial of service (daemon crash) via certain network traffic associated with entities larger than 2 Gb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7j6-cjp7-gqh6/GHSA-v7j6-cjp7-gqh6.json b/advisories/unreviewed/2022/05/GHSA-v7j6-cjp7-gqh6/GHSA-v7j6-cjp7-gqh6.json index 5f132bec277..4aa65502747 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7j6-cjp7-gqh6/GHSA-v7j6-cjp7-gqh6.json +++ b/advisories/unreviewed/2022/05/GHSA-v7j6-cjp7-gqh6/GHSA-v7j6-cjp7-gqh6.json @@ -7,12 +7,8 @@ "CVE-2007-4673" ], "details": "Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v887-j29p-rm67/GHSA-v887-j29p-rm67.json b/advisories/unreviewed/2022/05/GHSA-v887-j29p-rm67/GHSA-v887-j29p-rm67.json index 9db66c17297..b3500460eda 100644 --- a/advisories/unreviewed/2022/05/GHSA-v887-j29p-rm67/GHSA-v887-j29p-rm67.json +++ b/advisories/unreviewed/2022/05/GHSA-v887-j29p-rm67/GHSA-v887-j29p-rm67.json @@ -7,12 +7,8 @@ "CVE-2007-4543" ], "details": "Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the \"guided form.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8fq-gcm6-fx7c/GHSA-v8fq-gcm6-fx7c.json b/advisories/unreviewed/2022/05/GHSA-v8fq-gcm6-fx7c/GHSA-v8fq-gcm6-fx7c.json index 42cdeb6fde5..06e90d3ee21 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8fq-gcm6-fx7c/GHSA-v8fq-gcm6-fx7c.json +++ b/advisories/unreviewed/2022/05/GHSA-v8fq-gcm6-fx7c/GHSA-v8fq-gcm6-fx7c.json @@ -7,12 +7,8 @@ "CVE-2007-5207" ], "details": "guilt 0.27 allows local users to overwrite arbitrary files via a symlink attack on a guilt.log.[PID] temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8vp-mh9x-vq8q/GHSA-v8vp-mh9x-vq8q.json b/advisories/unreviewed/2022/05/GHSA-v8vp-mh9x-vq8q/GHSA-v8vp-mh9x-vq8q.json index 0e391c4d9cb..496ab8dc25b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8vp-mh9x-vq8q/GHSA-v8vp-mh9x-vq8q.json +++ b/advisories/unreviewed/2022/05/GHSA-v8vp-mh9x-vq8q/GHSA-v8vp-mh9x-vq8q.json @@ -7,12 +7,8 @@ "CVE-2007-4547" ], "details": "Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory contents) by reading the extracted files. NOTE: this issue is only a vulnerability if Unreal is run with privileges, or if the extracted files are made accessible to other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcvq-3f23-fr47/GHSA-vcvq-3f23-fr47.json b/advisories/unreviewed/2022/05/GHSA-vcvq-3f23-fr47/GHSA-vcvq-3f23-fr47.json index 64ea9d7ada0..076a971374f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcvq-3f23-fr47/GHSA-vcvq-3f23-fr47.json +++ b/advisories/unreviewed/2022/05/GHSA-vcvq-3f23-fr47/GHSA-vcvq-3f23-fr47.json @@ -7,12 +7,8 @@ "CVE-2007-5386" ], "details": "Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg88-g3m2-5f88/GHSA-vg88-g3m2-5f88.json b/advisories/unreviewed/2022/05/GHSA-vg88-g3m2-5f88/GHSA-vg88-g3m2-5f88.json index 1f56b9631c3..d8ed1f7e58a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg88-g3m2-5f88/GHSA-vg88-g3m2-5f88.json +++ b/advisories/unreviewed/2022/05/GHSA-vg88-g3m2-5f88/GHSA-vg88-g3m2-5f88.json @@ -7,12 +7,8 @@ "CVE-2007-4647" ], "details": "newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgpg-q396-4j8x/GHSA-vgpg-q396-4j8x.json b/advisories/unreviewed/2022/05/GHSA-vgpg-q396-4j8x/GHSA-vgpg-q396-4j8x.json index 24f789e0aa3..eccd35172d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgpg-q396-4j8x/GHSA-vgpg-q396-4j8x.json +++ b/advisories/unreviewed/2022/05/GHSA-vgpg-q396-4j8x/GHSA-vgpg-q396-4j8x.json @@ -7,12 +7,8 @@ "CVE-2007-5051" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) box_width, (2) PEDIGREE_GENERATIONS, and (3) rootid parameters in ancestry.php, and the (4) newpid parameter in timeline.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh65-4p7f-vw9q/GHSA-vh65-4p7f-vw9q.json b/advisories/unreviewed/2022/05/GHSA-vh65-4p7f-vw9q/GHSA-vh65-4p7f-vw9q.json index 3a95b40336e..7a5837b43a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh65-4p7f-vw9q/GHSA-vh65-4p7f-vw9q.json +++ b/advisories/unreviewed/2022/05/GHSA-vh65-4p7f-vw9q/GHSA-vh65-4p7f-vw9q.json @@ -7,12 +7,8 @@ "CVE-2007-4920" ], "details": "SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj4m-2cfx-j3r7/GHSA-vj4m-2cfx-j3r7.json b/advisories/unreviewed/2022/05/GHSA-vj4m-2cfx-j3r7/GHSA-vj4m-2cfx-j3r7.json index 32310d8a5b2..9c02dc99dce 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj4m-2cfx-j3r7/GHSA-vj4m-2cfx-j3r7.json +++ b/advisories/unreviewed/2022/05/GHSA-vj4m-2cfx-j3r7/GHSA-vj4m-2cfx-j3r7.json @@ -7,12 +7,8 @@ "CVE-2007-4794" ], "details": "Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long input parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj5r-hj24-rjhh/GHSA-vj5r-hj24-rjhh.json b/advisories/unreviewed/2022/05/GHSA-vj5r-hj24-rjhh/GHSA-vj5r-hj24-rjhh.json index fc5ed74a60b..ec769779de1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj5r-hj24-rjhh/GHSA-vj5r-hj24-rjhh.json +++ b/advisories/unreviewed/2022/05/GHSA-vj5r-hj24-rjhh/GHSA-vj5r-hj24-rjhh.json @@ -7,12 +7,8 @@ "CVE-2007-4981" ], "details": "Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a document. NOTE: because the details of the attack are uncertain, it is unclear whether this crosses privilege boundaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjhh-42qw-r394/GHSA-vjhh-42qw-r394.json b/advisories/unreviewed/2022/05/GHSA-vjhh-42qw-r394/GHSA-vjhh-42qw-r394.json index f3e88cea252..9cfca497287 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjhh-42qw-r394/GHSA-vjhh-42qw-r394.json +++ b/advisories/unreviewed/2022/05/GHSA-vjhh-42qw-r394/GHSA-vjhh-42qw-r394.json @@ -7,12 +7,8 @@ "CVE-2007-4627" ], "details": "SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm34-m9hg-8jmr/GHSA-vm34-m9hg-8jmr.json b/advisories/unreviewed/2022/05/GHSA-vm34-m9hg-8jmr/GHSA-vm34-m9hg-8jmr.json index 9fb5e8b26ee..6f1506832a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm34-m9hg-8jmr/GHSA-vm34-m9hg-8jmr.json +++ b/advisories/unreviewed/2022/05/GHSA-vm34-m9hg-8jmr/GHSA-vm34-m9hg-8jmr.json @@ -7,12 +7,8 @@ "CVE-2007-5363" ], "details": "PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm48-4vfc-6xpv/GHSA-vm48-4vfc-6xpv.json b/advisories/unreviewed/2022/05/GHSA-vm48-4vfc-6xpv/GHSA-vm48-4vfc-6xpv.json index cb0df26d417..c6a57cfbd8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm48-4vfc-6xpv/GHSA-vm48-4vfc-6xpv.json +++ b/advisories/unreviewed/2022/05/GHSA-vm48-4vfc-6xpv/GHSA-vm48-4vfc-6xpv.json @@ -7,12 +7,8 @@ "CVE-2007-4707" ], "details": "Multiple unspecified vulnerabilities in the Flash media handler in Apple QuickTime before 7.3.1 allow remote attackers to execute arbitrary code or have other unspecified impacts via a crafted QuickTime movie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp6f-h27f-4858/GHSA-vp6f-h27f-4858.json b/advisories/unreviewed/2022/05/GHSA-vp6f-h27f-4858/GHSA-vp6f-h27f-4858.json index 33a820da7f7..7a87aab8d43 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp6f-h27f-4858/GHSA-vp6f-h27f-4858.json +++ b/advisories/unreviewed/2022/05/GHSA-vp6f-h27f-4858/GHSA-vp6f-h27f-4858.json @@ -7,12 +7,8 @@ "CVE-2007-5391" ], "details": "Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpg6-rq2c-r73h/GHSA-vpg6-rq2c-r73h.json b/advisories/unreviewed/2022/05/GHSA-vpg6-rq2c-r73h/GHSA-vpg6-rq2c-r73h.json index a28a2f4f49e..92f55d7cff1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpg6-rq2c-r73h/GHSA-vpg6-rq2c-r73h.json +++ b/advisories/unreviewed/2022/05/GHSA-vpg6-rq2c-r73h/GHSA-vpg6-rq2c-r73h.json @@ -7,12 +7,8 @@ "CVE-2007-5193" ], "details": "The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{RCS}{WorkAreaDir}) under the web document root, which might allow remote attackers to obtain sensitive information when .htaccess restrictions are not applied.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vr3j-wchh-fh5w/GHSA-vr3j-wchh-fh5w.json b/advisories/unreviewed/2022/05/GHSA-vr3j-wchh-fh5w/GHSA-vr3j-wchh-fh5w.json index 4300e66f440..65e3da68895 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr3j-wchh-fh5w/GHSA-vr3j-wchh-fh5w.json +++ b/advisories/unreviewed/2022/05/GHSA-vr3j-wchh-fh5w/GHSA-vr3j-wchh-fh5w.json @@ -7,12 +7,8 @@ "CVE-2007-4750" ], "details": "Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrgp-x938-x8rc/GHSA-vrgp-x938-x8rc.json b/advisories/unreviewed/2022/05/GHSA-vrgp-x938-x8rc/GHSA-vrgp-x938-x8rc.json index 979f618169e..68eb2568a90 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrgp-x938-x8rc/GHSA-vrgp-x938-x8rc.json +++ b/advisories/unreviewed/2022/05/GHSA-vrgp-x938-x8rc/GHSA-vrgp-x938-x8rc.json @@ -7,12 +7,8 @@ "CVE-2007-5065" ], "details": "PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwm5-27p4-hp3w/GHSA-vwm5-27p4-hp3w.json b/advisories/unreviewed/2022/05/GHSA-vwm5-27p4-hp3w/GHSA-vwm5-27p4-hp3w.json index e8da937195b..a1e05b5aef2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwm5-27p4-hp3w/GHSA-vwm5-27p4-hp3w.json +++ b/advisories/unreviewed/2022/05/GHSA-vwm5-27p4-hp3w/GHSA-vwm5-27p4-hp3w.json @@ -7,12 +7,8 @@ "CVE-2007-5038" ], "details": "The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vx68-whc5-qv39/GHSA-vx68-whc5-qv39.json b/advisories/unreviewed/2022/05/GHSA-vx68-whc5-qv39/GHSA-vx68-whc5-qv39.json index 8f0c7a81697..d82e2a31561 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx68-whc5-qv39/GHSA-vx68-whc5-qv39.json +++ b/advisories/unreviewed/2022/05/GHSA-vx68-whc5-qv39/GHSA-vx68-whc5-qv39.json @@ -7,12 +7,8 @@ "CVE-2007-5005" ], "details": "Directory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to upload and overwrite arbitrary files via a ..\\ (dot dot backslash) sequence in the destination filename argument to sub-function 8 in the rxrReceiveFileFromServer command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx7f-xx2w-qxj7/GHSA-vx7f-xx2w-qxj7.json b/advisories/unreviewed/2022/05/GHSA-vx7f-xx2w-qxj7/GHSA-vx7f-xx2w-qxj7.json index ec2d0e92a93..7cdeb485122 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx7f-xx2w-qxj7/GHSA-vx7f-xx2w-qxj7.json +++ b/advisories/unreviewed/2022/05/GHSA-vx7f-xx2w-qxj7/GHSA-vx7f-xx2w-qxj7.json @@ -7,12 +7,8 @@ "CVE-2007-4976" ], "details": "Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx8f-8jqh-8xqr/GHSA-vx8f-8jqh-8xqr.json b/advisories/unreviewed/2022/05/GHSA-vx8f-8jqh-8xqr/GHSA-vx8f-8jqh-8xqr.json index 1dfa50c634d..8a625c11592 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx8f-8jqh-8xqr/GHSA-vx8f-8jqh-8xqr.json +++ b/advisories/unreviewed/2022/05/GHSA-vx8f-8jqh-8xqr/GHSA-vx8f-8jqh-8xqr.json @@ -7,12 +7,8 @@ "CVE-2007-5124" ], "details": "The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.5.3.12 and earlier allows remote attackers to execute arbitrary code via unspecified web script or HTML in an instant message, related to AIM's filtering of \"specific tags and attributes\" and the lack of Local Machine Zone lockdown. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4901.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2cw-q3jf-4xrw/GHSA-w2cw-q3jf-4xrw.json b/advisories/unreviewed/2022/05/GHSA-w2cw-q3jf-4xrw/GHSA-w2cw-q3jf-4xrw.json index 3c56725e48c..fd983f1d87e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2cw-q3jf-4xrw/GHSA-w2cw-q3jf-4xrw.json +++ b/advisories/unreviewed/2022/05/GHSA-w2cw-q3jf-4xrw/GHSA-w2cw-q3jf-4xrw.json @@ -7,12 +7,8 @@ "CVE-2007-5123" ], "details": "SQL injection vulnerability in notas.asp in Novus 1.0 allows remote attackers to execute arbitrary SQL commands via the nota_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w332-rjcw-h5c2/GHSA-w332-rjcw-h5c2.json b/advisories/unreviewed/2022/05/GHSA-w332-rjcw-h5c2/GHSA-w332-rjcw-h5c2.json index 0ca63eea4b3..dbbb92f1225 100644 --- a/advisories/unreviewed/2022/05/GHSA-w332-rjcw-h5c2/GHSA-w332-rjcw-h5c2.json +++ b/advisories/unreviewed/2022/05/GHSA-w332-rjcw-h5c2/GHSA-w332-rjcw-h5c2.json @@ -7,12 +7,8 @@ "CVE-2007-4684" ], "details": "Integer overflow in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a large num_sels argument to the i386_set_ldt system call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3cr-ccmf-mcr5/GHSA-w3cr-ccmf-mcr5.json b/advisories/unreviewed/2022/05/GHSA-w3cr-ccmf-mcr5/GHSA-w3cr-ccmf-mcr5.json index 15cfc98a210..a1642315988 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3cr-ccmf-mcr5/GHSA-w3cr-ccmf-mcr5.json +++ b/advisories/unreviewed/2022/05/GHSA-w3cr-ccmf-mcr5/GHSA-w3cr-ccmf-mcr5.json @@ -7,12 +7,8 @@ "CVE-2007-4709" ], "details": "Directory traversal vulnerability in CFNetwork in Apple Mac OS X 10.5.1 allows remote attackers to overwrite arbitrary files via a crafted HTTP response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w49q-592x-4jf3/GHSA-w49q-592x-4jf3.json b/advisories/unreviewed/2022/05/GHSA-w49q-592x-4jf3/GHSA-w49q-592x-4jf3.json index 6cf4879b2a8..66fbadf9695 100644 --- a/advisories/unreviewed/2022/05/GHSA-w49q-592x-4jf3/GHSA-w49q-592x-4jf3.json +++ b/advisories/unreviewed/2022/05/GHSA-w49q-592x-4jf3/GHSA-w49q-592x-4jf3.json @@ -7,12 +7,8 @@ "CVE-2007-4945" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade allow remote attackers to inject arbitrary web script or HTML via (1) a student's email address, (2) the year parameter to genbrws/Student/cal_month.php3, and other unspecified vectors related to the calendar. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4wh-hh25-pgmf/GHSA-w4wh-hh25-pgmf.json b/advisories/unreviewed/2022/05/GHSA-w4wh-hh25-pgmf/GHSA-w4wh-hh25-pgmf.json index 474d39c47d4..4fc92a454df 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4wh-hh25-pgmf/GHSA-w4wh-hh25-pgmf.json +++ b/advisories/unreviewed/2022/05/GHSA-w4wh-hh25-pgmf/GHSA-w4wh-hh25-pgmf.json @@ -7,12 +7,8 @@ "CVE-2007-5016" ], "details": "SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5wj-83wg-9p94/GHSA-w5wj-83wg-9p94.json b/advisories/unreviewed/2022/05/GHSA-w5wj-83wg-9p94/GHSA-w5wj-83wg-9p94.json index a0038075b2a..b569c2f74d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5wj-83wg-9p94/GHSA-w5wj-83wg-9p94.json +++ b/advisories/unreviewed/2022/05/GHSA-w5wj-83wg-9p94/GHSA-w5wj-83wg-9p94.json @@ -7,12 +7,8 @@ "CVE-2007-4733" ], "details": "The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which allows remote attackers to connect to the web interface by guessing a TCP sequence number, possibly involving spoofing of an ARP packet, a related issue to CVE-1999-0077.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w772-rr97-rmmm/GHSA-w772-rr97-rmmm.json b/advisories/unreviewed/2022/05/GHSA-w772-rr97-rmmm/GHSA-w772-rr97-rmmm.json index 66b8be7f919..86c0951aad5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w772-rr97-rmmm/GHSA-w772-rr97-rmmm.json +++ b/advisories/unreviewed/2022/05/GHSA-w772-rr97-rmmm/GHSA-w772-rr97-rmmm.json @@ -7,12 +7,8 @@ "CVE-2007-5344" ], "details": "Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption, related to uninitialized or deleted objects, a different issue than CVE-2007-3902 and CVE-2007-3903, and a variant of \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w788-2c9w-56g5/GHSA-w788-2c9w-56g5.json b/advisories/unreviewed/2022/05/GHSA-w788-2c9w-56g5/GHSA-w788-2c9w-56g5.json index 5cc727b9e2c..a86a62beb90 100644 --- a/advisories/unreviewed/2022/05/GHSA-w788-2c9w-56g5/GHSA-w788-2c9w-56g5.json +++ b/advisories/unreviewed/2022/05/GHSA-w788-2c9w-56g5/GHSA-w788-2c9w-56g5.json @@ -7,12 +7,8 @@ "CVE-2007-4637" ], "details": "xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7c3-9x6r-wf3m/GHSA-w7c3-9x6r-wf3m.json b/advisories/unreviewed/2022/05/GHSA-w7c3-9x6r-wf3m/GHSA-w7c3-9x6r-wf3m.json index cff0b8dce48..53654c45cb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7c3-9x6r-wf3m/GHSA-w7c3-9x6r-wf3m.json +++ b/advisories/unreviewed/2022/05/GHSA-w7c3-9x6r-wf3m/GHSA-w7c3-9x6r-wf3m.json @@ -7,12 +7,8 @@ "CVE-2007-4946" ], "details": "LetterGrade allows remote attackers to obtain sensitive information (installation path or account existence) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7wf-m6xr-x5x5/GHSA-w7wf-m6xr-x5x5.json b/advisories/unreviewed/2022/05/GHSA-w7wf-m6xr-x5x5/GHSA-w7wf-m6xr-x5x5.json index 29aabefe743..0e621ec822d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7wf-m6xr-x5x5/GHSA-w7wf-m6xr-x5x5.json +++ b/advisories/unreviewed/2022/05/GHSA-w7wf-m6xr-x5x5/GHSA-w7wf-m6xr-x5x5.json @@ -7,12 +7,8 @@ "CVE-2007-4739" ], "details": "reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribute an ostensibly valid Release.gpg file by signing it with an unknown key, related to the update command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9gf-3cjv-vfxp/GHSA-w9gf-3cjv-vfxp.json b/advisories/unreviewed/2022/05/GHSA-w9gf-3cjv-vfxp/GHSA-w9gf-3cjv-vfxp.json index 6ea4d02a108..66f1ef50441 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9gf-3cjv-vfxp/GHSA-w9gf-3cjv-vfxp.json +++ b/advisories/unreviewed/2022/05/GHSA-w9gf-3cjv-vfxp/GHSA-w9gf-3cjv-vfxp.json @@ -7,12 +7,8 @@ "CVE-2007-4862" ], "details": "Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9m3-f92x-pgrv/GHSA-w9m3-f92x-pgrv.json b/advisories/unreviewed/2022/05/GHSA-w9m3-f92x-pgrv/GHSA-w9m3-f92x-pgrv.json index 0abf92c459b..8a9acd28926 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9m3-f92x-pgrv/GHSA-w9m3-f92x-pgrv.json +++ b/advisories/unreviewed/2022/05/GHSA-w9m3-f92x-pgrv/GHSA-w9m3-f92x-pgrv.json @@ -7,12 +7,8 @@ "CVE-2007-5397" ], "details": "Heap-based buffer overflow in the activePDF Server service (aka APServer.exe) in activePDF Server 3.8.4 and 3.8.5.14, and possibly other versions before 3.8.6.16, allows remote attackers to execute arbitrary code via a packet with a size field that is less than the actual size of the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc3r-4g4g-f96h/GHSA-wc3r-4g4g-f96h.json b/advisories/unreviewed/2022/05/GHSA-wc3r-4g4g-f96h/GHSA-wc3r-4g4g-f96h.json index c4f083d42bc..34c58a171ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc3r-4g4g-f96h/GHSA-wc3r-4g4g-f96h.json +++ b/advisories/unreviewed/2022/05/GHSA-wc3r-4g4g-f96h/GHSA-wc3r-4g4g-f96h.json @@ -7,12 +7,8 @@ "CVE-2007-4603" ], "details": "Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc5g-9mmj-hpgg/GHSA-wc5g-9mmj-hpgg.json b/advisories/unreviewed/2022/05/GHSA-wc5g-9mmj-hpgg/GHSA-wc5g-9mmj-hpgg.json index 0fc3c348541..92090af1e48 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc5g-9mmj-hpgg/GHSA-wc5g-9mmj-hpgg.json +++ b/advisories/unreviewed/2022/05/GHSA-wc5g-9mmj-hpgg/GHSA-wc5g-9mmj-hpgg.json @@ -7,12 +7,8 @@ "CVE-2007-5180" ], "details": "Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf86-8369-qhfj/GHSA-wf86-8369-qhfj.json b/advisories/unreviewed/2022/05/GHSA-wf86-8369-qhfj/GHSA-wf86-8369-qhfj.json index c1a4f694768..bf56ab39e22 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf86-8369-qhfj/GHSA-wf86-8369-qhfj.json +++ b/advisories/unreviewed/2022/05/GHSA-wf86-8369-qhfj/GHSA-wf86-8369-qhfj.json @@ -7,12 +7,8 @@ "CVE-2007-4995" ], "details": "Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -144,9 +140,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf9w-558q-7qr6/GHSA-wf9w-558q-7qr6.json b/advisories/unreviewed/2022/05/GHSA-wf9w-558q-7qr6/GHSA-wf9w-558q-7qr6.json index ce75d0e98de..91c7f055b43 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf9w-558q-7qr6/GHSA-wf9w-558q-7qr6.json +++ b/advisories/unreviewed/2022/05/GHSA-wf9w-558q-7qr6/GHSA-wf9w-558q-7qr6.json @@ -7,12 +7,8 @@ "CVE-2007-4630" ], "details": "Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfcw-7j6v-7vgh/GHSA-wfcw-7j6v-7vgh.json b/advisories/unreviewed/2022/05/GHSA-wfcw-7j6v-7vgh/GHSA-wfcw-7j6v-7vgh.json index 89dc76ac17e..7703e169e24 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfcw-7j6v-7vgh/GHSA-wfcw-7j6v-7vgh.json +++ b/advisories/unreviewed/2022/05/GHSA-wfcw-7j6v-7vgh/GHSA-wfcw-7j6v-7vgh.json @@ -7,12 +7,8 @@ "CVE-2007-4595" ], "details": "Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.12 allows remote attackers to inject arbitrary web script or HTML in certain circumstances involving (1) lack of charset specification within a META element or (2) a META element that specifies an unrecognized charset, which trigger automatic character set recognition by the web browser, as demonstrated by improper handling of UTF-7 data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfrw-vjm2-mx9r/GHSA-wfrw-vjm2-mx9r.json b/advisories/unreviewed/2022/05/GHSA-wfrw-vjm2-mx9r/GHSA-wfrw-vjm2-mx9r.json index 1a9768d136d..2af4a9de4ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfrw-vjm2-mx9r/GHSA-wfrw-vjm2-mx9r.json +++ b/advisories/unreviewed/2022/05/GHSA-wfrw-vjm2-mx9r/GHSA-wfrw-vjm2-mx9r.json @@ -7,12 +7,8 @@ "CVE-2007-4685" ], "details": "The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are \"in an unexpected state.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg2q-63hj-6rmg/GHSA-wg2q-63hj-6rmg.json b/advisories/unreviewed/2022/05/GHSA-wg2q-63hj-6rmg/GHSA-wg2q-63hj-6rmg.json index 230ce9e3dc5..fae26ea990c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg2q-63hj-6rmg/GHSA-wg2q-63hj-6rmg.json +++ b/advisories/unreviewed/2022/05/GHSA-wg2q-63hj-6rmg/GHSA-wg2q-63hj-6rmg.json @@ -7,12 +7,8 @@ "CVE-2007-4935" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) admin.php, (2) custom_pages.php, (3) draft.php, (4) faq.php, (5) leagues.php, (6) livedraft.php, (7) login.php, (8) my_team.php, (9) profile.php, (10) signup.php, (11) statistics.php, (12) transactions.php, (13) program_files/admin/custom_pages.php, or (14) program_files/common.php. NOTE: the program_files/livedraft/admin.php and program_files/livedraft/livedraft.php vectors are covered by CVE-2007-4934.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh6g-vxgw-xmjj/GHSA-wh6g-vxgw-xmjj.json b/advisories/unreviewed/2022/05/GHSA-wh6g-vxgw-xmjj/GHSA-wh6g-vxgw-xmjj.json index f7f87b8cdb2..c4b79a4b46a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh6g-vxgw-xmjj/GHSA-wh6g-vxgw-xmjj.json +++ b/advisories/unreviewed/2022/05/GHSA-wh6g-vxgw-xmjj/GHSA-wh6g-vxgw-xmjj.json @@ -7,12 +7,8 @@ "CVE-2007-5328" ], "details": "The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain \"insecure method calls\" to modify the file system and registry, aka \"Privileged function exposure.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wj2j-x7q5-2qcc/GHSA-wj2j-x7q5-2qcc.json b/advisories/unreviewed/2022/05/GHSA-wj2j-x7q5-2qcc/GHSA-wj2j-x7q5-2qcc.json index 9c248d16547..080dd45706b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj2j-x7q5-2qcc/GHSA-wj2j-x7q5-2qcc.json +++ b/advisories/unreviewed/2022/05/GHSA-wj2j-x7q5-2qcc/GHSA-wj2j-x7q5-2qcc.json @@ -7,12 +7,8 @@ "CVE-2007-5366" ], "details": "The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjq5-mq56-4wjf/GHSA-wjq5-mq56-4wjf.json b/advisories/unreviewed/2022/05/GHSA-wjq5-mq56-4wjf/GHSA-wjq5-mq56-4wjf.json index 2916963652d..fa05b7e1bc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjq5-mq56-4wjf/GHSA-wjq5-mq56-4wjf.json +++ b/advisories/unreviewed/2022/05/GHSA-wjq5-mq56-4wjf/GHSA-wjq5-mq56-4wjf.json @@ -7,12 +7,8 @@ "CVE-2007-4625" ], "details": "Polipo before 1.0.2 allows remote HTTP servers to cause a denial of service (daemon crash) by aborting the response to a POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjwj-mgc2-3fvp/GHSA-wjwj-mgc2-3fvp.json b/advisories/unreviewed/2022/05/GHSA-wjwj-mgc2-3fvp/GHSA-wjwj-mgc2-3fvp.json index 03a72413445..5f61387ea92 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjwj-mgc2-3fvp/GHSA-wjwj-mgc2-3fvp.json +++ b/advisories/unreviewed/2022/05/GHSA-wjwj-mgc2-3fvp/GHSA-wjwj-mgc2-3fvp.json @@ -7,12 +7,8 @@ "CVE-2007-4970" ], "details": "ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey, (3) NtDeleteValueKey, (4) NtOpenFile, (5) NtOpenKey, and (6) NtSetValueKey.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmjr-xw5g-fq3h/GHSA-wmjr-xw5g-fq3h.json b/advisories/unreviewed/2022/05/GHSA-wmjr-xw5g-fq3h/GHSA-wmjr-xw5g-fq3h.json index a88a8fc67c4..245a1816e2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmjr-xw5g-fq3h/GHSA-wmjr-xw5g-fq3h.json +++ b/advisories/unreviewed/2022/05/GHSA-wmjr-xw5g-fq3h/GHSA-wmjr-xw5g-fq3h.json @@ -7,12 +7,8 @@ "CVE-2007-4612" ], "details": "CRLF injection vulnerability in contact.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to add arbitrary mail headers via CRLF sequences in the subject parameter. NOTE: this can be leveraged for spam by adding To or Cc headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmmp-2f22-959m/GHSA-wmmp-2f22-959m.json b/advisories/unreviewed/2022/05/GHSA-wmmp-2f22-959m/GHSA-wmmp-2f22-959m.json index 88d171d4098..4d09002c8e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmmp-2f22-959m/GHSA-wmmp-2f22-959m.json +++ b/advisories/unreviewed/2022/05/GHSA-wmmp-2f22-959m/GHSA-wmmp-2f22-959m.json @@ -7,12 +7,8 @@ "CVE-2007-4632" ], "details": "Cisco IOS 12.2E, 12.2F, and 12.2S places a \"no login\" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wprv-pvhv-q9xp/GHSA-wprv-pvhv-q9xp.json b/advisories/unreviewed/2022/05/GHSA-wprv-pvhv-q9xp/GHSA-wprv-pvhv-q9xp.json index 8bee23c7914..765e391cb03 100644 --- a/advisories/unreviewed/2022/05/GHSA-wprv-pvhv-q9xp/GHSA-wprv-pvhv-q9xp.json +++ b/advisories/unreviewed/2022/05/GHSA-wprv-pvhv-q9xp/GHSA-wprv-pvhv-q9xp.json @@ -7,12 +7,8 @@ "CVE-2007-4659" ], "details": "The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpvw-wp3g-rhmf/GHSA-wpvw-wp3g-rhmf.json b/advisories/unreviewed/2022/05/GHSA-wpvw-wp3g-rhmf/GHSA-wpvw-wp3g-rhmf.json index f54d4a31eff..ec2424497b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpvw-wp3g-rhmf/GHSA-wpvw-wp3g-rhmf.json +++ b/advisories/unreviewed/2022/05/GHSA-wpvw-wp3g-rhmf/GHSA-wpvw-wp3g-rhmf.json @@ -7,12 +7,8 @@ "CVE-2007-4703" ], "details": "The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when \"Block incoming connections\" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq8m-4wh9-hvc3/GHSA-wq8m-4wh9-hvc3.json b/advisories/unreviewed/2022/05/GHSA-wq8m-4wh9-hvc3/GHSA-wq8m-4wh9-hvc3.json index 33cec05a44f..2ea65fe8e9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq8m-4wh9-hvc3/GHSA-wq8m-4wh9-hvc3.json +++ b/advisories/unreviewed/2022/05/GHSA-wq8m-4wh9-hvc3/GHSA-wq8m-4wh9-hvc3.json @@ -7,12 +7,8 @@ "CVE-2007-4589" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) siteworx.php, (3) users.php, (4) ftp.php, (5) mysql.php, (6) domains.php, (7) htaccess.php, (8) scriptworx.php, (9) stats.php, (10) backup.php, (11) restore.php, and (12) httpd.php; and unspecified vectors to (13) cron.php and (14) prefs.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqcv-r5jr-3r2x/GHSA-wqcv-r5jr-3r2x.json b/advisories/unreviewed/2022/05/GHSA-wqcv-r5jr-3r2x/GHSA-wqcv-r5jr-3r2x.json index 019e5597fb2..ccbad87220b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqcv-r5jr-3r2x/GHSA-wqcv-r5jr-3r2x.json +++ b/advisories/unreviewed/2022/05/GHSA-wqcv-r5jr-3r2x/GHSA-wqcv-r5jr-3r2x.json @@ -7,12 +7,8 @@ "CVE-2007-4812" ], "details": "Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. NOTE: the crash might actually occur in the alert method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr87-f6g4-8xcg/GHSA-wr87-f6g4-8xcg.json b/advisories/unreviewed/2022/05/GHSA-wr87-f6g4-8xcg/GHSA-wr87-f6g4-8xcg.json index c83aa44b5dd..cc845f56c0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr87-f6g4-8xcg/GHSA-wr87-f6g4-8xcg.json +++ b/advisories/unreviewed/2022/05/GHSA-wr87-f6g4-8xcg/GHSA-wr87-f6g4-8xcg.json @@ -7,12 +7,8 @@ "CVE-2007-5352" ], "details": "Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrq3-rmxj-6f66/GHSA-wrq3-rmxj-6f66.json b/advisories/unreviewed/2022/05/GHSA-wrq3-rmxj-6f66/GHSA-wrq3-rmxj-6f66.json index bb40a329942..de99778bdd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrq3-rmxj-6f66/GHSA-wrq3-rmxj-6f66.json +++ b/advisories/unreviewed/2022/05/GHSA-wrq3-rmxj-6f66/GHSA-wrq3-rmxj-6f66.json @@ -7,12 +7,8 @@ "CVE-2007-4931" ], "details": "HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv5h-grg4-29jw/GHSA-wv5h-grg4-29jw.json b/advisories/unreviewed/2022/05/GHSA-wv5h-grg4-29jw/GHSA-wv5h-grg4-29jw.json index 2c7a8739c31..da69b54b7dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv5h-grg4-29jw/GHSA-wv5h-grg4-29jw.json +++ b/advisories/unreviewed/2022/05/GHSA-wv5h-grg4-29jw/GHSA-wv5h-grg4-29jw.json @@ -7,12 +7,8 @@ "CVE-2007-4760" ], "details": "The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvwx-mgg5-q4p2/GHSA-wvwx-mgg5-q4p2.json b/advisories/unreviewed/2022/05/GHSA-wvwx-mgg5-q4p2/GHSA-wvwx-mgg5-q4p2.json index faabed0e09b..36b1255346e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvwx-mgg5-q4p2/GHSA-wvwx-mgg5-q4p2.json +++ b/advisories/unreviewed/2022/05/GHSA-wvwx-mgg5-q4p2/GHSA-wvwx-mgg5-q4p2.json @@ -7,12 +7,8 @@ "CVE-2007-5083" ], "details": "Multiple integer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands that trigger a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww39-q3qc-xp7c/GHSA-ww39-q3qc-xp7c.json b/advisories/unreviewed/2022/05/GHSA-ww39-q3qc-xp7c/GHSA-ww39-q3qc-xp7c.json index 639384d907c..efb74efdc89 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww39-q3qc-xp7c/GHSA-ww39-q3qc-xp7c.json +++ b/advisories/unreviewed/2022/05/GHSA-ww39-q3qc-xp7c/GHSA-ww39-q3qc-xp7c.json @@ -7,12 +7,8 @@ "CVE-2007-4557" ], "details": "Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id parameter, as demonstrated by a URL within a url field in a STYLE element, possibly due to an incomplete fix for CVE-2004-2103.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwfp-rpqw-m84f/GHSA-wwfp-rpqw-m84f.json b/advisories/unreviewed/2022/05/GHSA-wwfp-rpqw-m84f/GHSA-wwfp-rpqw-m84f.json index b3362ad6dae..3e151faf719 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwfp-rpqw-m84f/GHSA-wwfp-rpqw-m84f.json +++ b/advisories/unreviewed/2022/05/GHSA-wwfp-rpqw-m84f/GHSA-wwfp-rpqw-m84f.json @@ -7,12 +7,8 @@ "CVE-2007-4895" ], "details": "Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwrx-q37g-9vhg/GHSA-wwrx-q37g-9vhg.json b/advisories/unreviewed/2022/05/GHSA-wwrx-q37g-9vhg/GHSA-wwrx-q37g-9vhg.json index 150b02800c3..fef91a99cb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwrx-q37g-9vhg/GHSA-wwrx-q37g-9vhg.json +++ b/advisories/unreviewed/2022/05/GHSA-wwrx-q37g-9vhg/GHSA-wwrx-q37g-9vhg.json @@ -7,12 +7,8 @@ "CVE-2007-4678" ], "details": "AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwwr-px3v-p7c5/GHSA-wwwr-px3v-p7c5.json b/advisories/unreviewed/2022/05/GHSA-wwwr-px3v-p7c5/GHSA-wwwr-px3v-p7c5.json index 99657ec2403..d48079db0f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwwr-px3v-p7c5/GHSA-wwwr-px3v-p7c5.json +++ b/advisories/unreviewed/2022/05/GHSA-wwwr-px3v-p7c5/GHSA-wwwr-px3v-p7c5.json @@ -7,12 +7,8 @@ "CVE-2007-4883" ], "details": "Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a similar issue to CVE-2007-4828.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwx8-6f45-5rmj/GHSA-wwx8-6f45-5rmj.json b/advisories/unreviewed/2022/05/GHSA-wwx8-6f45-5rmj/GHSA-wwx8-6f45-5rmj.json index 04b5da06c57..340de87db73 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwx8-6f45-5rmj/GHSA-wwx8-6f45-5rmj.json +++ b/advisories/unreviewed/2022/05/GHSA-wwx8-6f45-5rmj/GHSA-wwx8-6f45-5rmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwxv-q666-xrw2/GHSA-wwxv-q666-xrw2.json b/advisories/unreviewed/2022/05/GHSA-wwxv-q666-xrw2/GHSA-wwxv-q666-xrw2.json index 16ba9a140e6..3033715708f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwxv-q666-xrw2/GHSA-wwxv-q666-xrw2.json +++ b/advisories/unreviewed/2022/05/GHSA-wwxv-q666-xrw2/GHSA-wwxv-q666-xrw2.json @@ -7,12 +7,8 @@ "CVE-2007-5332" ], "details": "Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx25-59c7-q497/GHSA-wx25-59c7-q497.json b/advisories/unreviewed/2022/05/GHSA-wx25-59c7-q497/GHSA-wx25-59c7-q497.json index a2e47f65154..d2c32f3b583 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx25-59c7-q497/GHSA-wx25-59c7-q497.json +++ b/advisories/unreviewed/2022/05/GHSA-wx25-59c7-q497/GHSA-wx25-59c7-q497.json @@ -7,12 +7,8 @@ "CVE-2007-4934" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxff-hq7w-p8h7/GHSA-wxff-hq7w-p8h7.json b/advisories/unreviewed/2022/05/GHSA-wxff-hq7w-p8h7/GHSA-wxff-hq7w-p8h7.json index 5085543703a..6a3f3a2c731 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxff-hq7w-p8h7/GHSA-wxff-hq7w-p8h7.json +++ b/advisories/unreviewed/2022/05/GHSA-wxff-hq7w-p8h7/GHSA-wxff-hq7w-p8h7.json @@ -7,12 +7,8 @@ "CVE-2007-5237" ], "details": "Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local files via an untrusted application, aka \"two vulnerabilities.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxg8-rr3m-222p/GHSA-wxg8-rr3m-222p.json b/advisories/unreviewed/2022/05/GHSA-wxg8-rr3m-222p/GHSA-wxg8-rr3m-222p.json index 8767b2fb237..acf7495619c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxg8-rr3m-222p/GHSA-wxg8-rr3m-222p.json +++ b/advisories/unreviewed/2022/05/GHSA-wxg8-rr3m-222p/GHSA-wxg8-rr3m-222p.json @@ -7,12 +7,8 @@ "CVE-2007-5000" ], "details": "Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x29x-q874-42cr/GHSA-x29x-q874-42cr.json b/advisories/unreviewed/2022/05/GHSA-x29x-q874-42cr/GHSA-x29x-q874-42cr.json index c7e307f7fb8..18abdfa56af 100644 --- a/advisories/unreviewed/2022/05/GHSA-x29x-q874-42cr/GHSA-x29x-q874-42cr.json +++ b/advisories/unreviewed/2022/05/GHSA-x29x-q874-42cr/GHSA-x29x-q874-42cr.json @@ -7,12 +7,8 @@ "CVE-2007-4929" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2hg-rgmp-3453/GHSA-x2hg-rgmp-3453.json b/advisories/unreviewed/2022/05/GHSA-x2hg-rgmp-3453/GHSA-x2hg-rgmp-3453.json index 85fbdc5a4ca..3dca8b0218c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2hg-rgmp-3453/GHSA-x2hg-rgmp-3453.json +++ b/advisories/unreviewed/2022/05/GHSA-x2hg-rgmp-3453/GHSA-x2hg-rgmp-3453.json @@ -7,12 +7,8 @@ "CVE-2007-4991" ], "details": "The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2j4-38c3-gpq4/GHSA-x2j4-38c3-gpq4.json b/advisories/unreviewed/2022/05/GHSA-x2j4-38c3-gpq4/GHSA-x2j4-38c3-gpq4.json index 8a3ff8dd077..6ab75e6b031 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2j4-38c3-gpq4/GHSA-x2j4-38c3-gpq4.json +++ b/advisories/unreviewed/2022/05/GHSA-x2j4-38c3-gpq4/GHSA-x2j4-38c3-gpq4.json @@ -7,12 +7,8 @@ "CVE-2007-4600" ], "details": "The \"Protect Worksheet\" functionality in Mathsoft Mathcad 12 through 13.1, and PTC Mathcad 14, implements file access restrictions via a protection element in a gzipped XML file, which allows attackers to bypass these restrictions by removing this element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2w3-hrrj-mgr5/GHSA-x2w3-hrrj-mgr5.json b/advisories/unreviewed/2022/05/GHSA-x2w3-hrrj-mgr5/GHSA-x2w3-hrrj-mgr5.json index e592cf75c6a..87efec4543f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2w3-hrrj-mgr5/GHSA-x2w3-hrrj-mgr5.json +++ b/advisories/unreviewed/2022/05/GHSA-x2w3-hrrj-mgr5/GHSA-x2w3-hrrj-mgr5.json @@ -7,12 +7,8 @@ "CVE-2007-4833" ], "details": "Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3q3-v77f-cg26/GHSA-x3q3-v77f-cg26.json b/advisories/unreviewed/2022/05/GHSA-x3q3-v77f-cg26/GHSA-x3q3-v77f-cg26.json index 7d84d868479..0f75f91e6ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3q3-v77f-cg26/GHSA-x3q3-v77f-cg26.json +++ b/advisories/unreviewed/2022/05/GHSA-x3q3-v77f-cg26/GHSA-x3q3-v77f-cg26.json @@ -7,12 +7,8 @@ "CVE-2007-4772" ], "details": "The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -232,9 +228,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x52q-323x-94hm/GHSA-x52q-323x-94hm.json b/advisories/unreviewed/2022/05/GHSA-x52q-323x-94hm/GHSA-x52q-323x-94hm.json index 85b93cb194d..aaa43e91e78 100644 --- a/advisories/unreviewed/2022/05/GHSA-x52q-323x-94hm/GHSA-x52q-323x-94hm.json +++ b/advisories/unreviewed/2022/05/GHSA-x52q-323x-94hm/GHSA-x52q-323x-94hm.json @@ -7,12 +7,8 @@ "CVE-2007-4533" ], "details": "Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a chat message, related to a call to the BroadcastPrintf function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5fh-w6pw-cff3/GHSA-x5fh-w6pw-cff3.json b/advisories/unreviewed/2022/05/GHSA-x5fh-w6pw-cff3/GHSA-x5fh-w6pw-cff3.json index 4c2892d3bff..9b08d3b32e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5fh-w6pw-cff3/GHSA-x5fh-w6pw-cff3.json +++ b/advisories/unreviewed/2022/05/GHSA-x5fh-w6pw-cff3/GHSA-x5fh-w6pw-cff3.json @@ -7,12 +7,8 @@ "CVE-2007-4738" ], "details": "Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the STPHPLIB_DIR parameter to (3) stphpbutton.php, (4) stphpcheckbox.php, (5) stphpcheckboxwithcaption.php, (6) stphpcheckgroup.php, (7) stphpcomponent.php, (8) stphpcontrolwithcaption.php, (9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) stphptable.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, or (34) stphpxmlelement.php, a different set of vectors than CVE-2007-4737. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5wq-3jr3-4r5c/GHSA-x5wq-3jr3-4r5c.json b/advisories/unreviewed/2022/05/GHSA-x5wq-3jr3-4r5c/GHSA-x5wq-3jr3-4r5c.json index 7e0a77a35ad..795abd94d50 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5wq-3jr3-4r5c/GHSA-x5wq-3jr3-4r5c.json +++ b/advisories/unreviewed/2022/05/GHSA-x5wq-3jr3-4r5c/GHSA-x5wq-3jr3-4r5c.json @@ -7,12 +7,8 @@ "CVE-2007-5321" ], "details": "Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6mx-7fcg-2j6w/GHSA-x6mx-7fcg-2j6w.json b/advisories/unreviewed/2022/05/GHSA-x6mx-7fcg-2j6w/GHSA-x6mx-7fcg-2j6w.json index 04991d4db78..857304972da 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6mx-7fcg-2j6w/GHSA-x6mx-7fcg-2j6w.json +++ b/advisories/unreviewed/2022/05/GHSA-x6mx-7fcg-2j6w/GHSA-x6mx-7fcg-2j6w.json @@ -7,12 +7,8 @@ "CVE-2007-5191" ], "details": "mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6p9-6v4p-2w68/GHSA-x6p9-6v4p-2w68.json b/advisories/unreviewed/2022/05/GHSA-x6p9-6v4p-2w68/GHSA-x6p9-6v4p-2w68.json index 351ef2991b9..75121c72ec4 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6p9-6v4p-2w68/GHSA-x6p9-6v4p-2w68.json +++ b/advisories/unreviewed/2022/05/GHSA-x6p9-6v4p-2w68/GHSA-x6p9-6v4p-2w68.json @@ -7,12 +7,8 @@ "CVE-2007-4679" ], "details": "CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6q9-9c2f-h39j/GHSA-x6q9-9c2f-h39j.json b/advisories/unreviewed/2022/05/GHSA-x6q9-9c2f-h39j/GHSA-x6q9-9c2f-h39j.json index 1d22724aaef..7d1cf72ce60 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6q9-9c2f-h39j/GHSA-x6q9-9c2f-h39j.json +++ b/advisories/unreviewed/2022/05/GHSA-x6q9-9c2f-h39j/GHSA-x6q9-9c2f-h39j.json @@ -7,12 +7,8 @@ "CVE-2007-5012" ], "details": "Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to inject arbitrary web script or HTML via the author parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x78h-v7rw-746m/GHSA-x78h-v7rw-746m.json b/advisories/unreviewed/2022/05/GHSA-x78h-v7rw-746m/GHSA-x78h-v7rw-746m.json index a883912caed..165aca3a615 100644 --- a/advisories/unreviewed/2022/05/GHSA-x78h-v7rw-746m/GHSA-x78h-v7rw-746m.json +++ b/advisories/unreviewed/2022/05/GHSA-x78h-v7rw-746m/GHSA-x78h-v7rw-746m.json @@ -7,12 +7,8 @@ "CVE-2007-4966" ], "details": "SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7wp-f8qv-9jfv/GHSA-x7wp-f8qv-9jfv.json b/advisories/unreviewed/2022/05/GHSA-x7wp-f8qv-9jfv/GHSA-x7wp-f8qv-9jfv.json index 6c2cb043f43..06c05b027a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7wp-f8qv-9jfv/GHSA-x7wp-f8qv-9jfv.json +++ b/advisories/unreviewed/2022/05/GHSA-x7wp-f8qv-9jfv/GHSA-x7wp-f8qv-9jfv.json @@ -7,12 +7,8 @@ "CVE-2007-4880" ], "details": "Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9h3-fh68-r937/GHSA-x9h3-fh68-r937.json b/advisories/unreviewed/2022/05/GHSA-x9h3-fh68-r937/GHSA-x9h3-fh68-r937.json index 6ed0b2f3bc5..979571d13d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9h3-fh68-r937/GHSA-x9h3-fh68-r937.json +++ b/advisories/unreviewed/2022/05/GHSA-x9h3-fh68-r937/GHSA-x9h3-fh68-r937.json @@ -7,12 +7,8 @@ "CVE-2007-5198" ], "details": "Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading \"L\" characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9q7-pv5c-35wg/GHSA-x9q7-pv5c-35wg.json b/advisories/unreviewed/2022/05/GHSA-x9q7-pv5c-35wg/GHSA-x9q7-pv5c-35wg.json index 9dc8d4b9a75..d39d679034d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9q7-pv5c-35wg/GHSA-x9q7-pv5c-35wg.json +++ b/advisories/unreviewed/2022/05/GHSA-x9q7-pv5c-35wg/GHSA-x9q7-pv5c-35wg.json @@ -7,12 +7,8 @@ "CVE-2007-4943" ], "details": "Multiple buffer overflows in a certain ActiveX control in sparser.dll in Baofeng Storm 2.8 and earlier allow remote attackers to execute arbitrary code via malformed input in an unknown set of arguments or property values, a different DLL than CVE-2007-4816. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9wj-2qc6-h283/GHSA-x9wj-2qc6-h283.json b/advisories/unreviewed/2022/05/GHSA-x9wj-2qc6-h283/GHSA-x9wj-2qc6-h283.json index 0c6931799af..4daaa71da7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9wj-2qc6-h283/GHSA-x9wj-2qc6-h283.json +++ b/advisories/unreviewed/2022/05/GHSA-x9wj-2qc6-h283/GHSA-x9wj-2qc6-h283.json @@ -7,12 +7,8 @@ "CVE-2007-4834" ], "details": "Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf67-28w8-mv26/GHSA-xf67-28w8-mv26.json b/advisories/unreviewed/2022/05/GHSA-xf67-28w8-mv26/GHSA-xf67-28w8-mv26.json index b5a3eaecfc2..afae22c1751 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf67-28w8-mv26/GHSA-xf67-28w8-mv26.json +++ b/advisories/unreviewed/2022/05/GHSA-xf67-28w8-mv26/GHSA-xf67-28w8-mv26.json @@ -7,12 +7,8 @@ "CVE-2007-4937" ], "details": "CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf6w-j33h-544m/GHSA-xf6w-j33h-544m.json b/advisories/unreviewed/2022/05/GHSA-xf6w-j33h-544m/GHSA-xf6w-j33h-544m.json index c7450a986f7..ed7b706b782 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf6w-j33h-544m/GHSA-xf6w-j33h-544m.json +++ b/advisories/unreviewed/2022/05/GHSA-xf6w-j33h-544m/GHSA-xf6w-j33h-544m.json @@ -7,12 +7,8 @@ "CVE-2007-5383" ], "details": "The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka \"double-slash auth bypass.\" NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf8w-mw4m-rqj9/GHSA-xf8w-mw4m-rqj9.json b/advisories/unreviewed/2022/05/GHSA-xf8w-mw4m-rqj9/GHSA-xf8w-mw4m-rqj9.json index 69c0704a3d8..4895bede885 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf8w-mw4m-rqj9/GHSA-xf8w-mw4m-rqj9.json +++ b/advisories/unreviewed/2022/05/GHSA-xf8w-mw4m-rqj9/GHSA-xf8w-mw4m-rqj9.json @@ -7,12 +7,8 @@ "CVE-2007-4911" ], "details": "JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfc5-m2rq-chwh/GHSA-xfc5-m2rq-chwh.json b/advisories/unreviewed/2022/05/GHSA-xfc5-m2rq-chwh/GHSA-xfc5-m2rq-chwh.json index d7c6279cb4f..56cfea40ce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfc5-m2rq-chwh/GHSA-xfc5-m2rq-chwh.json +++ b/advisories/unreviewed/2022/05/GHSA-xfc5-m2rq-chwh/GHSA-xfc5-m2rq-chwh.json @@ -7,12 +7,8 @@ "CVE-2007-5235" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web script or HTML via the f_email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg35-cm33-292g/GHSA-xg35-cm33-292g.json b/advisories/unreviewed/2022/05/GHSA-xg35-cm33-292g/GHSA-xg35-cm33-292g.json index bfcaf26085e..016f0615f22 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg35-cm33-292g/GHSA-xg35-cm33-292g.json +++ b/advisories/unreviewed/2022/05/GHSA-xg35-cm33-292g/GHSA-xg35-cm33-292g.json @@ -7,12 +7,8 @@ "CVE-2007-4598" ], "details": "IBM SurePOS 500 has (1) a default password of \"12345\" for the manager and (2) blank default passwords for operator accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg36-f7gx-cmx3/GHSA-xg36-f7gx-cmx3.json b/advisories/unreviewed/2022/05/GHSA-xg36-f7gx-cmx3/GHSA-xg36-f7gx-cmx3.json index dcf5139509c..2c69a97dc61 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg36-f7gx-cmx3/GHSA-xg36-f7gx-cmx3.json +++ b/advisories/unreviewed/2022/05/GHSA-xg36-f7gx-cmx3/GHSA-xg36-f7gx-cmx3.json @@ -7,12 +7,8 @@ "CVE-2007-5080" ], "details": "Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg3j-x27h-qh5w/GHSA-xg3j-x27h-qh5w.json b/advisories/unreviewed/2022/05/GHSA-xg3j-x27h-qh5w/GHSA-xg3j-x27h-qh5w.json index bc2c6485c4a..7788e7844ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg3j-x27h-qh5w/GHSA-xg3j-x27h-qh5w.json +++ b/advisories/unreviewed/2022/05/GHSA-xg3j-x27h-qh5w/GHSA-xg3j-x27h-qh5w.json @@ -7,12 +7,8 @@ "CVE-2007-4755" ], "details": "Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh29-778x-wq63/GHSA-xh29-778x-wq63.json b/advisories/unreviewed/2022/05/GHSA-xh29-778x-wq63/GHSA-xh29-778x-wq63.json index dca94c226c1..84718c3193c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh29-778x-wq63/GHSA-xh29-778x-wq63.json +++ b/advisories/unreviewed/2022/05/GHSA-xh29-778x-wq63/GHSA-xh29-778x-wq63.json @@ -7,12 +7,8 @@ "CVE-2007-4831" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh58-hgvj-wm3q/GHSA-xh58-hgvj-wm3q.json b/advisories/unreviewed/2022/05/GHSA-xh58-hgvj-wm3q/GHSA-xh58-hgvj-wm3q.json index 5e009a68793..49dc56a9e7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh58-hgvj-wm3q/GHSA-xh58-hgvj-wm3q.json +++ b/advisories/unreviewed/2022/05/GHSA-xh58-hgvj-wm3q/GHSA-xh58-hgvj-wm3q.json @@ -7,12 +7,8 @@ "CVE-2007-5196" ], "details": "Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xj7p-qq9q-4h6h/GHSA-xj7p-qq9q-4h6h.json b/advisories/unreviewed/2022/05/GHSA-xj7p-qq9q-4h6h/GHSA-xj7p-qq9q-4h6h.json index 1c62a77ae4e..d428d02cf65 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj7p-qq9q-4h6h/GHSA-xj7p-qq9q-4h6h.json +++ b/advisories/unreviewed/2022/05/GHSA-xj7p-qq9q-4h6h/GHSA-xj7p-qq9q-4h6h.json @@ -7,12 +7,8 @@ "CVE-2007-4795" ], "details": "Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp9m-2qw6-h5vm/GHSA-xp9m-2qw6-h5vm.json b/advisories/unreviewed/2022/05/GHSA-xp9m-2qw6-h5vm/GHSA-xp9m-2qw6-h5vm.json index 49371a3992e..4fa3e00d9f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp9m-2qw6-h5vm/GHSA-xp9m-2qw6-h5vm.json +++ b/advisories/unreviewed/2022/05/GHSA-xp9m-2qw6-h5vm/GHSA-xp9m-2qw6-h5vm.json @@ -7,12 +7,8 @@ "CVE-2007-5062" ], "details": "account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpwp-hgm6-qgh5/GHSA-xpwp-hgm6-qgh5.json b/advisories/unreviewed/2022/05/GHSA-xpwp-hgm6-qgh5/GHSA-xpwp-hgm6-qgh5.json index a29eb3b7de6..04108b8b53d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpwp-hgm6-qgh5/GHSA-xpwp-hgm6-qgh5.json +++ b/advisories/unreviewed/2022/05/GHSA-xpwp-hgm6-qgh5/GHSA-xpwp-hgm6-qgh5.json @@ -7,12 +7,8 @@ "CVE-2007-4530" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xq48-pc3g-f75m/GHSA-xq48-pc3g-f75m.json b/advisories/unreviewed/2022/05/GHSA-xq48-pc3g-f75m/GHSA-xq48-pc3g-f75m.json index ad883e67249..2a0346c4228 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq48-pc3g-f75m/GHSA-xq48-pc3g-f75m.json +++ b/advisories/unreviewed/2022/05/GHSA-xq48-pc3g-f75m/GHSA-xq48-pc3g-f75m.json @@ -7,12 +7,8 @@ "CVE-2007-5138" ], "details": "PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq75-f84r-j89w/GHSA-xq75-f84r-j89w.json b/advisories/unreviewed/2022/05/GHSA-xq75-f84r-j89w/GHSA-xq75-f84r-j89w.json index 2e41b7d36f9..e5c3fde16c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq75-f84r-j89w/GHSA-xq75-f84r-j89w.json +++ b/advisories/unreviewed/2022/05/GHSA-xq75-f84r-j89w/GHSA-xq75-f84r-j89w.json @@ -7,12 +7,8 @@ "CVE-2007-4823" ], "details": "Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrgg-cx2j-f5vm/GHSA-xrgg-cx2j-f5vm.json b/advisories/unreviewed/2022/05/GHSA-xrgg-cx2j-f5vm/GHSA-xrgg-cx2j-f5vm.json index 9771a204ea3..356e7cae552 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrgg-cx2j-f5vm/GHSA-xrgg-cx2j-f5vm.json +++ b/advisories/unreviewed/2022/05/GHSA-xrgg-cx2j-f5vm/GHSA-xrgg-cx2j-f5vm.json @@ -7,12 +7,8 @@ "CVE-2007-4715" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code via a URL in the files_dir parameter in (1) es_desp.php, (2) es_custom_menu.php, and (3) es_offer.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvwg-32hp-p5p5/GHSA-xvwg-32hp-p5p5.json b/advisories/unreviewed/2022/05/GHSA-xvwg-32hp-p5p5/GHSA-xvwg-32hp-p5p5.json index 870cee4f297..2ce0ea0051d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvwg-32hp-p5p5/GHSA-xvwg-32hp-p5p5.json +++ b/advisories/unreviewed/2022/05/GHSA-xvwg-32hp-p5p5/GHSA-xvwg-32hp-p5p5.json @@ -7,12 +7,8 @@ "CVE-2007-4799" ], "details": "The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw88-2qqf-j4gv/GHSA-xw88-2qqf-j4gv.json b/advisories/unreviewed/2022/05/GHSA-xw88-2qqf-j4gv/GHSA-xw88-2qqf-j4gv.json index 373770c841a..8ed2747b36d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw88-2qqf-j4gv/GHSA-xw88-2qqf-j4gv.json +++ b/advisories/unreviewed/2022/05/GHSA-xw88-2qqf-j4gv/GHSA-xw88-2qqf-j4gv.json @@ -7,12 +7,8 @@ "CVE-2007-5234" ], "details": "PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers to execute arbitrary PHP code via a URL in the level parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw97-pjh6-x5h5/GHSA-xw97-pjh6-x5h5.json b/advisories/unreviewed/2022/05/GHSA-xw97-pjh6-x5h5/GHSA-xw97-pjh6-x5h5.json index e701233a7ba..9170f348432 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw97-pjh6-x5h5/GHSA-xw97-pjh6-x5h5.json +++ b/advisories/unreviewed/2022/05/GHSA-xw97-pjh6-x5h5/GHSA-xw97-pjh6-x5h5.json @@ -7,12 +7,8 @@ "CVE-2007-4884" ], "details": "Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwj5-gj8r-8hr8/GHSA-xwj5-gj8r-8hr8.json b/advisories/unreviewed/2022/05/GHSA-xwj5-gj8r-8hr8/GHSA-xwj5-gj8r-8hr8.json index 42abe358753..3702ed2340e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwj5-gj8r-8hr8/GHSA-xwj5-gj8r-8hr8.json +++ b/advisories/unreviewed/2022/05/GHSA-xwj5-gj8r-8hr8/GHSA-xwj5-gj8r-8hr8.json @@ -7,12 +7,8 @@ "CVE-2007-4618" ], "details": "Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (disk consumption) via certain malformed HTTP headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxp8-7434-x949/GHSA-xxp8-7434-x949.json b/advisories/unreviewed/2022/05/GHSA-xxp8-7434-x949/GHSA-xxp8-7434-x949.json index e28296bfb6c..10156bc1234 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxp8-7434-x949/GHSA-xxp8-7434-x949.json +++ b/advisories/unreviewed/2022/05/GHSA-xxp8-7434-x949/GHSA-xxp8-7434-x949.json @@ -7,12 +7,8 @@ "CVE-2007-5182" ], "details": "Cross-site scripting (XSS) vulnerability in mail.asp in Netkamp Emlak Scripti allows remote attackers to inject arbitrary web script or HTML via the (1) Email parameter, and possibly the (2) Ad, (3) Soyad, (4) Konu, and (5) Mesaj parameters to iletisim.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-2hqp-7448-qrw3/GHSA-2hqp-7448-qrw3.json b/advisories/unreviewed/2022/09/GHSA-2hqp-7448-qrw3/GHSA-2hqp-7448-qrw3.json index 06cd1522bbe..47869ef2ef5 100644 --- a/advisories/unreviewed/2022/09/GHSA-2hqp-7448-qrw3/GHSA-2hqp-7448-qrw3.json +++ b/advisories/unreviewed/2022/09/GHSA-2hqp-7448-qrw3/GHSA-2hqp-7448-qrw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-963g-g6x3-46cf/GHSA-963g-g6x3-46cf.json b/advisories/unreviewed/2022/09/GHSA-963g-g6x3-46cf/GHSA-963g-g6x3-46cf.json index 9fd0cfb3c44..15b60314900 100644 --- a/advisories/unreviewed/2022/09/GHSA-963g-g6x3-46cf/GHSA-963g-g6x3-46cf.json +++ b/advisories/unreviewed/2022/09/GHSA-963g-g6x3-46cf/GHSA-963g-g6x3-46cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-q775-qv8g-9c7h/GHSA-q775-qv8g-9c7h.json b/advisories/unreviewed/2022/09/GHSA-q775-qv8g-9c7h/GHSA-q775-qv8g-9c7h.json index b1f85feeeee..7eecc8f6e5a 100644 --- a/advisories/unreviewed/2022/09/GHSA-q775-qv8g-9c7h/GHSA-q775-qv8g-9c7h.json +++ b/advisories/unreviewed/2022/09/GHSA-q775-qv8g-9c7h/GHSA-q775-qv8g-9c7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-c46m-w49v-frqh/GHSA-c46m-w49v-frqh.json b/advisories/unreviewed/2022/10/GHSA-c46m-w49v-frqh/GHSA-c46m-w49v-frqh.json index 6cc13c3a439..1017157c9a6 100644 --- a/advisories/unreviewed/2022/10/GHSA-c46m-w49v-frqh/GHSA-c46m-w49v-frqh.json +++ b/advisories/unreviewed/2022/10/GHSA-c46m-w49v-frqh/GHSA-c46m-w49v-frqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-hfc5-wrcg-96p9/GHSA-hfc5-wrcg-96p9.json b/advisories/unreviewed/2022/10/GHSA-hfc5-wrcg-96p9/GHSA-hfc5-wrcg-96p9.json index 6bfe4d012a9..db5d2430f70 100644 --- a/advisories/unreviewed/2022/10/GHSA-hfc5-wrcg-96p9/GHSA-hfc5-wrcg-96p9.json +++ b/advisories/unreviewed/2022/10/GHSA-hfc5-wrcg-96p9/GHSA-hfc5-wrcg-96p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-wx73-x679-vc26/GHSA-wx73-x679-vc26.json b/advisories/unreviewed/2022/10/GHSA-wx73-x679-vc26/GHSA-wx73-x679-vc26.json index 885b8af9430..194ee58cfcb 100644 --- a/advisories/unreviewed/2022/10/GHSA-wx73-x679-vc26/GHSA-wx73-x679-vc26.json +++ b/advisories/unreviewed/2022/10/GHSA-wx73-x679-vc26/GHSA-wx73-x679-vc26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json b/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json index 06ebb0722ac..6dfb0862626 100644 --- a/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json +++ b/advisories/unreviewed/2022/10/GHSA-xqrw-f62h-4ff2/GHSA-xqrw-f62h-4ff2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json b/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json index dafdd0ccab1..26b00789b6b 100644 --- a/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json +++ b/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json b/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json index fcde6f15f30..d22108cacb4 100644 --- a/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json +++ b/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json b/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json index 9963c23d647..bac06bde452 100644 --- a/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json +++ b/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json b/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json index 5baee82b1de..4957dbf5760 100644 --- a/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json +++ b/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json b/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json index 759d5d9e5df..679e3b95dbe 100644 --- a/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json +++ b/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json b/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json index 73a8dbe46de..a7d3cff7ccd 100644 --- a/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json +++ b/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json b/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json index b6689686455..00daf8bac3a 100644 --- a/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json +++ b/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json b/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json index bc565b62436..19e151d2a71 100644 --- a/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json +++ b/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json b/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json index 7e1802e0c24..f21408d929d 100644 --- a/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json +++ b/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json b/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json index 77c75e07a6b..3bf043d9ec8 100644 --- a/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json +++ b/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json b/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json index a569dcd307b..52335b7ee29 100644 --- a/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json +++ b/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json b/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json index b0e0666789d..f31c6c618cc 100644 --- a/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json +++ b/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json b/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json index 75986dc33ce..369aae09eed 100644 --- a/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json +++ b/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json b/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json index 4ae5055fe67..8777a304047 100644 --- a/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json +++ b/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json b/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json index 4236a2f8e1e..4b9d78f421a 100644 --- a/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json +++ b/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json b/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json index 81b4976b4e7..3cd217a586a 100644 --- a/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json +++ b/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json b/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json index 94f4326895a..25dc0f1d878 100644 --- a/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json +++ b/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json b/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json index edd2658824c..14cf37a922d 100644 --- a/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json +++ b/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json b/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json index 13fc25190d7..fd041f39ccb 100644 --- a/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json +++ b/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json b/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json index dc554eb9cfe..93ce1d32338 100644 --- a/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json +++ b/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json b/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json index 87ab755dea9..8b9a85986e2 100644 --- a/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json +++ b/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json b/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json index 3b45245a4a2..b4afccff260 100644 --- a/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json +++ b/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json b/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json index 3be5f7c2254..ef01a9ac217 100644 --- a/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json +++ b/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json b/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json index 422a2af4cf4..5ccaa1a647a 100644 --- a/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json +++ b/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json b/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json index 7fa7bcb458a..2c3901b080c 100644 --- a/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json +++ b/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json b/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json index c8603daecf7..cbc55ada8b8 100644 --- a/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json +++ b/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json b/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json index 6a8ace47aec..2a9154fefa6 100644 --- a/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json +++ b/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json b/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json index 6f81eeb58af..55fc8aab80b 100644 --- a/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json +++ b/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json b/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json index 8c3652da1bb..e8333301b5c 100644 --- a/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json +++ b/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json b/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json index caa3a0b8e2f..11c0b8dbc1e 100644 --- a/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json +++ b/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json b/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json index 5c240db3537..e112c3a1a6e 100644 --- a/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json +++ b/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json b/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json index 88e5a4add8a..bd086c22f20 100644 --- a/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json +++ b/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json b/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json index 6d4f79d8e80..dc1eae122b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json +++ b/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json @@ -7,12 +7,8 @@ "CVE-2024-27665" ], "details": "Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json b/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json index 1411855441f..69b42a86992 100644 --- a/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json +++ b/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json b/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json index 0762832cc8e..2f74aeb8b93 100644 --- a/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json +++ b/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json b/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json index b58260cdb99..652400703dc 100644 --- a/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json +++ b/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json b/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json index 57095ec0d10..cd5a0a39f47 100644 --- a/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json +++ b/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json b/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json index af293d9f663..bb9ae93b2c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json +++ b/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json b/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json index ccb5d25f23b..fada78f788b 100644 --- a/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json +++ b/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json b/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json index 7372368278a..614ee38063e 100644 --- a/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json +++ b/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json b/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json index 4ae786b5472..a8c70b497ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json +++ b/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json b/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json index 7861a1e2e1e..ac4f55b9a7f 100644 --- a/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json +++ b/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json b/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json index 84f1b4dc45e..e59bbe318a1 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json +++ b/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json b/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json index f4edda77edf..83bc0fee043 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json +++ b/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json b/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json index 5a8c5c79fac..06dbc1f463d 100644 --- a/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json +++ b/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json b/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json index 565aace8564..86c25f0e1dd 100644 --- a/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json +++ b/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json b/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json index 8fa26614839..2cf5e2676f3 100644 --- a/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json +++ b/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json b/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json index e2882699fda..f8ab90a0ba3 100644 --- a/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json +++ b/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json b/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json index 20a8f3ec334..8b8b4e57840 100644 --- a/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json +++ b/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json b/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json index 4b89ae540d0..a95ee75d948 100644 --- a/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json +++ b/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json b/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json index 2875bb72131..f83cdb3b484 100644 --- a/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json +++ b/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json b/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json index 5384289efc6..dc483c0f5a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json +++ b/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json b/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json index d83f2ba0c6d..319d0db48ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json +++ b/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json b/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json index dff988a5200..0d39b7cbae2 100644 --- a/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json +++ b/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json b/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json index 0f9fa26f84c..640fb270c82 100644 --- a/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json +++ b/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json b/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json index c1dd6b5709f..0390f530e0f 100644 --- a/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json +++ b/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json b/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json index b5cd7c253b1..cc1e7e29bb4 100644 --- a/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json +++ b/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json b/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json index d2df82eda90..13578c635a6 100644 --- a/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json +++ b/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json b/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json index 65b8a177191..811c9676fe6 100644 --- a/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json +++ b/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json b/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json index a1711e190c9..4ad21c83a34 100644 --- a/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json +++ b/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json b/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json index b1161cc9ccf..8f72f1b28cc 100644 --- a/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json +++ b/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json b/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json index 070182db804..efcf568ee03 100644 --- a/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json +++ b/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json b/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json index 0376a974c19..1cc01132106 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json +++ b/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json b/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json index fea5e039d8e..27662e41ea1 100644 --- a/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json +++ b/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json b/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json index 051d003b179..15f21b356e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json +++ b/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json b/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json index 00a8d437b68..8c755d549a1 100644 --- a/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json +++ b/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json b/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json index 48807250001..c9dc15d569a 100644 --- a/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json +++ b/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json b/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json index 6d8f3fd5078..c043251f37b 100644 --- a/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json +++ b/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json b/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json index d0653141348..c8256f4440e 100644 --- a/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json +++ b/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json b/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json index fb85e66a977..159d3a20185 100644 --- a/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json +++ b/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json b/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json index f9c56f03d34..c0360b15dc8 100644 --- a/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json +++ b/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json b/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json index 86e903ca7c4..1691433d0e1 100644 --- a/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json +++ b/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json b/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json index 3a8b6cdc2f1..4d45dae67d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json +++ b/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json b/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json index b9f4ded1693..56cc16fd35d 100644 --- a/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json +++ b/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json b/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json index 6864ce75526..17ecf912568 100644 --- a/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json +++ b/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json b/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json index cad11186f84..88adeacf96f 100644 --- a/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json +++ b/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json b/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json index d7f03658c7a..8a6b4497eae 100644 --- a/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json +++ b/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json b/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json index dde11b44fd2..d76d1005b6e 100644 --- a/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json +++ b/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json b/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json index 840482200cb..cac7ee2c931 100644 --- a/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json +++ b/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json b/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json index 3e0184d88f7..594a1c5e436 100644 --- a/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json +++ b/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json b/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json index 8bc59f96480..cbdcac0fee7 100644 --- a/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json +++ b/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json b/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json index 68b7659e277..ea9b5ebe9bd 100644 --- a/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json +++ b/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json b/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json index d82916c1683..cd998941d9c 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json +++ b/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json b/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json index 37d4bb32ff2..b66ca1534ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json +++ b/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json b/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json index fe4e18c3b5f..a5a44447300 100644 --- a/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json +++ b/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json b/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json index 7788dd7001f..045d7b92c52 100644 --- a/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json +++ b/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json b/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json index 2b1019cc69d..38c5906efbd 100644 --- a/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json +++ b/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json b/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json index d32bc32f496..8ea3a5f8978 100644 --- a/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json +++ b/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json b/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json index d29e5799e38..fa2ad023c0e 100644 --- a/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json +++ b/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json b/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json index 1d7a13e59b6..b0ec5329bec 100644 --- a/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json +++ b/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json b/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json index 1f3e2e892b3..0575027cfaf 100644 --- a/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json +++ b/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json b/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json index dc378f712a8..e95591bb2ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json +++ b/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json b/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json index 01bc09c36c2..98318bd6027 100644 --- a/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json +++ b/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json b/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json index 64e7a9b5048..d1c9ff41a13 100644 --- a/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json +++ b/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json b/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json index 404cf6adcf7..f2c0a8f4692 100644 --- a/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json +++ b/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json b/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json index c678db68df3..6db27c5838f 100644 --- a/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json +++ b/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json b/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json index 7c4065cecb5..ec349647b17 100644 --- a/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json +++ b/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json b/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json index 6b550cbaf59..ed20128e708 100644 --- a/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json +++ b/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json b/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json index 38e70c5c494..6a19e84f257 100644 --- a/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json +++ b/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json b/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json index 81dc2654832..13020ceb9be 100644 --- a/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json +++ b/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json b/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json index cd92ae62337..d1c5e8d3582 100644 --- a/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json +++ b/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json b/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json index 49431160054..d36dbc0584d 100644 --- a/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json +++ b/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json b/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json index d372fbb30c4..5f7b5c70d16 100644 --- a/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json +++ b/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json b/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json index 65741efcfd0..6c501d9da8c 100644 --- a/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json +++ b/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json b/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json index e54d544319b..486ed0d6695 100644 --- a/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json +++ b/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json b/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json index b7b1efdc758..f0adfddc842 100644 --- a/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json +++ b/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json b/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json index 44d3daba666..189baf6f9a4 100644 --- a/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json +++ b/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json b/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json index 55550f5f3d7..25cabf2ca0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json +++ b/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json b/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json index 8bb26ca00bd..4077344af3d 100644 --- a/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json +++ b/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json b/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json index 896727af6a2..d9b31b935cb 100644 --- a/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json +++ b/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json b/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json index 99e7cb61c9f..71f988f1dd3 100644 --- a/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json +++ b/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json b/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json index fa130031813..4194169a9ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json +++ b/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json b/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json index 09e4ba3c1a4..c4e55271707 100644 --- a/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json +++ b/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json b/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json index 8c0d84e3e38..6c38ae6f1ff 100644 --- a/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json +++ b/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json b/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json index 06a16c28a14..5fb91a05517 100644 --- a/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json +++ b/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json b/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json index 269624c18eb..26142844501 100644 --- a/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json +++ b/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json b/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json index c2ae203f193..db00e97828e 100644 --- a/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json +++ b/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json b/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json index fc307cb0467..e1431ea5185 100644 --- a/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json +++ b/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json b/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json index ce786185f32..6057f55c630 100644 --- a/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json +++ b/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json b/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json index 65647bc7a4b..51d1019570c 100644 --- a/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json +++ b/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json b/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json index 6290c5877ab..54e1a036714 100644 --- a/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json +++ b/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json b/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json index fe601f7ab6b..190714099da 100644 --- a/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json +++ b/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json b/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json index f6ad3399ee8..c20e2841a98 100644 --- a/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json +++ b/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json b/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json index 6ec7822311a..fe7b88fdc3a 100644 --- a/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json +++ b/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json b/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json index f7539154390..3030658ddc8 100644 --- a/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json +++ b/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json b/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json index 5ef4f7618c7..778aa3641ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json +++ b/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json b/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json index db14904baab..24acd3b5d2f 100644 --- a/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json +++ b/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json b/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json index 3c3637ee92f..51fd74eb924 100644 --- a/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json +++ b/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json b/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json index 166ce11b4cc..9ee527619ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json +++ b/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json b/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json index b6bd7261485..0d037fbf1bf 100644 --- a/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json +++ b/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json b/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json index 57ac1e06822..b9203b561db 100644 --- a/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json +++ b/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json b/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json index ba50e3755a1..4e45ebfebd4 100644 --- a/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json +++ b/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json b/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json index d871f3d7a34..b3c80ea7331 100644 --- a/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json +++ b/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json b/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json index abaa6df2496..967d202f9aa 100644 --- a/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json +++ b/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json b/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json index c2f95333234..5ad6b9b0a38 100644 --- a/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json +++ b/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json b/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json index 61c9642e9e2..d800534cb61 100644 --- a/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json +++ b/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json b/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json index 7c1d1754016..4d70b0e4588 100644 --- a/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json +++ b/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json b/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json index 438c41f2730..2e817b409ce 100644 --- a/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json +++ b/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json b/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json index 3def0b43e73..0fc64249741 100644 --- a/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json +++ b/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json b/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json index f2336bb9076..cdf97d1da47 100644 --- a/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json +++ b/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json b/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json index 3c2d9172f2e..5b51d90a313 100644 --- a/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json +++ b/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json b/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json index b56081c5510..650686cd89a 100644 --- a/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json +++ b/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json b/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json index e4ac8f85a3d..2b72d5367d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json +++ b/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json b/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json index 9cae120f0f7..984be57e71e 100644 --- a/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json +++ b/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json b/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json index ca826fbc69b..dad800cda91 100644 --- a/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json +++ b/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json b/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json index c7f0af7d307..d29f316cafe 100644 --- a/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json +++ b/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json @@ -7,12 +7,8 @@ "CVE-2024-3556" ], "details": "Rejected reason: Duplicate of CVE-2024-3557", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json b/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json index e86bbda255b..47de4903339 100644 --- a/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json +++ b/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json b/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json index fca0ce6dc88..5ec0d25c4d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json +++ b/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json b/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json index 2c82166a47f..efb5787916c 100644 --- a/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json +++ b/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json b/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json index 9566ad89c4b..2aab6c83134 100644 --- a/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json +++ b/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json b/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json index d62d3a6e8a6..4bf095106d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json +++ b/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json b/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json index 19754c013cb..d219f1c2ded 100644 --- a/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json +++ b/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json b/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json index 899a3f4a870..1e8f279e621 100644 --- a/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json +++ b/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json b/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json index 2612d71d202..54eb2ace627 100644 --- a/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json +++ b/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json b/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json index dd5edc69850..c582c4c1e5b 100644 --- a/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json +++ b/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json b/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json index c5f2e6bdc4a..6be92d82ebe 100644 --- a/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json +++ b/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json b/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json index 226b4b051b1..66c47e26b7a 100644 --- a/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json +++ b/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json b/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json index 4716c87ea82..c94fabd2ae1 100644 --- a/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json +++ b/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json b/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json index 1a59359d97e..390a5c0b567 100644 --- a/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json +++ b/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json b/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json index 2e426422a3e..023eb232181 100644 --- a/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json +++ b/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json b/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json index a6fa8db5aaf..315f4c84150 100644 --- a/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json +++ b/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json b/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json index 7ac06c845ee..3906ba41163 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json +++ b/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json b/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json index f52e7de9dbb..570edad1812 100644 --- a/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json +++ b/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json b/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json index 12d9c8bcc44..180e747c276 100644 --- a/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json +++ b/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json b/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json index 8834f96ef23..bb236632a8d 100644 --- a/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json +++ b/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json b/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json index 6f1ad10842e..7c7e6cca89a 100644 --- a/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json +++ b/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json b/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json index c77acd8c3e1..8117b67ee2f 100644 --- a/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json +++ b/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json b/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json index 52f9229d1b7..7008fa10e52 100644 --- a/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json +++ b/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json b/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json index f74d1819c2d..559d98721be 100644 --- a/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json +++ b/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json b/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json index 06c9a8383e0..adc9a4717ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json +++ b/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json b/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json index 25646a26f58..9a04e1043b0 100644 --- a/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json +++ b/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json @@ -7,12 +7,8 @@ "CVE-2024-31506" ], "details": "Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the \"id\" parameter in admin/admin_cs.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json b/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json index 3774843d849..fbe3c4d414a 100644 --- a/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json +++ b/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json b/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json index b6a177666b1..1af7c275410 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json +++ b/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json b/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json index 88c95cebf7f..7338454c8f9 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json +++ b/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json b/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json index cd9f27d39c8..2a21056f371 100644 --- a/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json +++ b/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json b/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json index aa0252863b9..da72e7efee0 100644 --- a/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json +++ b/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json b/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json index f4291eb8f44..7e785daf115 100644 --- a/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json +++ b/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json b/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json index 892cc481304..9f281b94892 100644 --- a/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json +++ b/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json b/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json index 4f8e60d7ffc..35f06bba5a6 100644 --- a/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json +++ b/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json b/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json index ce993132572..725fd4bb4ad 100644 --- a/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json +++ b/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json b/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json index 1cf52e5ec0d..dcb689f5b28 100644 --- a/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json +++ b/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json b/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json index 3142b48f49b..3a69dd8e2bd 100644 --- a/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json +++ b/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json b/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json index 61f740e8898..1caf70d1541 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json +++ b/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json b/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json index 7dc3ad1259d..7f86b394196 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json +++ b/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json b/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json index 1b76aca4733..d8fd33fcc19 100644 --- a/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json +++ b/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json b/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json index dd02b62e007..870e1da60d9 100644 --- a/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json +++ b/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json b/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json index 6ee98546b64..a824eaa1afd 100644 --- a/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json +++ b/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json b/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json index 8d9a94c355d..6724fd0dd0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json +++ b/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json b/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json index 70bdc3a3511..aa2fc87c030 100644 --- a/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json +++ b/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json b/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json index 5bc1238b6e9..a4a7344aae0 100644 --- a/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json +++ b/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json b/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json index e0ea94ea134..c201463d6d9 100644 --- a/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json +++ b/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json b/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json index 5ac03ac06cc..3598f017b94 100644 --- a/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json +++ b/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json b/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json index 96699b7a9aa..50f39734a91 100644 --- a/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json +++ b/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json b/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json index ba166cde4a5..7f0650f2983 100644 --- a/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json +++ b/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json b/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json index 8b4f85a437e..b74627f361b 100644 --- a/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json +++ b/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json b/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json index 96e21b23964..6e8d77e6f63 100644 --- a/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json +++ b/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json b/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json index 4ee9a45861a..89ad653fc38 100644 --- a/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json +++ b/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json b/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json index cd473fe1a7f..43a2922153c 100644 --- a/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json +++ b/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json b/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json index c2d35b9048d..2be0181fe20 100644 --- a/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json +++ b/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json b/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json index dfba7271362..448f8882f7d 100644 --- a/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json +++ b/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json b/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json index 125e86393d1..9cd6f6e0105 100644 --- a/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json +++ b/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json b/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json index 880cb157aaf..6eb703edecc 100644 --- a/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json +++ b/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null,