From 89b13187fe27d63246e9dab213fd93daf1a3e703 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 5 Dec 2024 05:07:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../05/GHSA-2c64-vj8g-vwrq/GHSA-2c64-vj8g-vwrq.json | 8 ++------ .../01/GHSA-8w54-22w9-3g8f/GHSA-8w54-22w9-3g8f.json | 4 +--- .../02/GHSA-43q8-3fv7-pr5x/GHSA-43q8-3fv7-pr5x.json | 4 +--- .../02/GHSA-64q9-f38h-9mwx/GHSA-64q9-f38h-9mwx.json | 4 +--- .../02/GHSA-f7qw-5fgj-247x/GHSA-f7qw-5fgj-247x.json | 4 +--- .../02/GHSA-g9mp-8g3h-3c5c/GHSA-g9mp-8g3h-3c5c.json | 12 +++--------- .../02/GHSA-h6gw-r52c-724r/GHSA-h6gw-r52c-724r.json | 4 +--- .../02/GHSA-wcv5-vrvr-3rx2/GHSA-wcv5-vrvr-3rx2.json | 4 +--- .../05/GHSA-2gh8-gr6x-7q26/GHSA-2gh8-gr6x-7q26.json | 4 +--- .../05/GHSA-92cv-wv2c-8899/GHSA-92cv-wv2c-8899.json | 4 +--- .../05/GHSA-mg4v-rf8p-ghqq/GHSA-mg4v-rf8p-ghqq.json | 8 ++------ .../05/GHSA-mmjh-45vj-hfvf/GHSA-mmjh-45vj-hfvf.json | 4 +--- .../05/GHSA-wv88-pf73-x22p/GHSA-wv88-pf73-x22p.json | 8 ++------ .../01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json | 8 ++------ .../05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json | 4 +--- .../12/GHSA-2c7f-7v62-c4p8/GHSA-2c7f-7v62-c4p8.json | 4 +--- .../12/GHSA-2fjf-4mmg-2c65/GHSA-2fjf-4mmg-2c65.json | 4 +--- .../12/GHSA-2vm6-24x2-fw9m/GHSA-2vm6-24x2-fw9m.json | 4 +--- .../12/GHSA-7gx6-8phm-v624/GHSA-7gx6-8phm-v624.json | 8 ++------ .../12/GHSA-8xwq-gmgr-vq48/GHSA-8xwq-gmgr-vq48.json | 4 +--- .../12/GHSA-9983-gjwx-g47w/GHSA-9983-gjwx-g47w.json | 4 +--- .../12/GHSA-c439-xxv3-pcx2/GHSA-c439-xxv3-pcx2.json | 4 +--- .../12/GHSA-cj6g-97j4-jw5f/GHSA-cj6g-97j4-jw5f.json | 4 +--- .../12/GHSA-g3vr-f28g-hxqc/GHSA-g3vr-f28g-hxqc.json | 4 +--- .../12/GHSA-h8g4-jwjc-gf58/GHSA-h8g4-jwjc-gf58.json | 4 +--- .../12/GHSA-h8wr-fwj5-f4pv/GHSA-h8wr-fwj5-f4pv.json | 8 ++------ .../12/GHSA-p6g3-6g2v-fwvr/GHSA-p6g3-6g2v-fwvr.json | 4 +--- .../12/GHSA-q75w-8h5p-w5j9/GHSA-q75w-8h5p-w5j9.json | 4 +--- .../12/GHSA-rvmf-qfpg-9qgj/GHSA-rvmf-qfpg-9qgj.json | 4 +--- .../12/GHSA-wc47-ghmc-28v7/GHSA-wc47-ghmc-28v7.json | 4 +--- .../12/GHSA-wf45-6876-33mc/GHSA-wf45-6876-33mc.json | 4 +--- .../12/GHSA-xpw4-2478-wj8x/GHSA-xpw4-2478-wj8x.json | 4 +--- .../01/GHSA-2jg4-p688-m2mm/GHSA-2jg4-p688-m2mm.json | 8 ++------ .../01/GHSA-2r36-2m2v-4gwc/GHSA-2r36-2m2v-4gwc.json | 8 ++------ .../01/GHSA-2r4c-mwv9-xcr6/GHSA-2r4c-mwv9-xcr6.json | 8 ++------ .../01/GHSA-2rqf-4qh6-w5pg/GHSA-2rqf-4qh6-w5pg.json | 12 +++--------- .../01/GHSA-2v2h-p3pv-rrr5/GHSA-2v2h-p3pv-rrr5.json | 8 ++------ .../01/GHSA-328j-4f66-23cq/GHSA-328j-4f66-23cq.json | 8 ++------ .../01/GHSA-3449-q73h-pp22/GHSA-3449-q73h-pp22.json | 8 ++------ .../01/GHSA-3mfv-hwx7-8f5p/GHSA-3mfv-hwx7-8f5p.json | 12 +++--------- .../01/GHSA-3v8g-66j2-8535/GHSA-3v8g-66j2-8535.json | 12 +++--------- .../01/GHSA-4749-xq6x-59v3/GHSA-4749-xq6x-59v3.json | 8 ++------ .../01/GHSA-4853-c3jq-r576/GHSA-4853-c3jq-r576.json | 8 ++------ .../01/GHSA-4cqg-vc7j-pmhv/GHSA-4cqg-vc7j-pmhv.json | 8 ++------ .../01/GHSA-4grj-8qw5-j9f8/GHSA-4grj-8qw5-j9f8.json | 4 +--- .../01/GHSA-4j35-95ch-4cqq/GHSA-4j35-95ch-4cqq.json | 12 +++--------- .../01/GHSA-4qfv-qxv8-3c5x/GHSA-4qfv-qxv8-3c5x.json | 8 ++------ .../01/GHSA-524v-q4cc-cvmx/GHSA-524v-q4cc-cvmx.json | 12 +++--------- .../01/GHSA-564r-594w-gw2m/GHSA-564r-594w-gw2m.json | 8 ++------ .../01/GHSA-5jch-qmrp-7wwr/GHSA-5jch-qmrp-7wwr.json | 12 +++--------- .../01/GHSA-5r25-9ppq-m6j9/GHSA-5r25-9ppq-m6j9.json | 8 ++------ .../01/GHSA-5w8m-7p89-xq72/GHSA-5w8m-7p89-xq72.json | 8 ++------ .../01/GHSA-63px-fjcc-g465/GHSA-63px-fjcc-g465.json | 12 +++--------- .../01/GHSA-678r-w8gp-8m7g/GHSA-678r-w8gp-8m7g.json | 8 ++------ .../01/GHSA-6p5h-cfjp-f7qc/GHSA-6p5h-cfjp-f7qc.json | 12 +++--------- .../01/GHSA-72jh-3hhf-4gjm/GHSA-72jh-3hhf-4gjm.json | 8 ++------ .../01/GHSA-73mv-wv5r-8r3c/GHSA-73mv-wv5r-8r3c.json | 8 ++------ .../01/GHSA-783c-38cj-6q3h/GHSA-783c-38cj-6q3h.json | 8 ++------ .../01/GHSA-7j6c-7628-j453/GHSA-7j6c-7628-j453.json | 8 ++------ .../01/GHSA-7prp-j2wv-v6p8/GHSA-7prp-j2wv-v6p8.json | 4 +--- .../01/GHSA-8288-g25h-9cfr/GHSA-8288-g25h-9cfr.json | 12 +++--------- .../01/GHSA-877m-32cv-3j4j/GHSA-877m-32cv-3j4j.json | 12 +++--------- .../01/GHSA-8ff8-x2c5-r774/GHSA-8ff8-x2c5-r774.json | 8 ++------ .../01/GHSA-8g4h-r9rw-56cm/GHSA-8g4h-r9rw-56cm.json | 8 ++------ .../01/GHSA-8hcx-pw9g-w24x/GHSA-8hcx-pw9g-w24x.json | 4 +--- .../01/GHSA-92qp-r64g-pmwq/GHSA-92qp-r64g-pmwq.json | 8 ++------ .../01/GHSA-944j-xv2m-j62h/GHSA-944j-xv2m-j62h.json | 12 +++--------- .../01/GHSA-94x2-cp7f-q2pj/GHSA-94x2-cp7f-q2pj.json | 12 +++--------- .../01/GHSA-9fhm-36wm-rpw2/GHSA-9fhm-36wm-rpw2.json | 8 ++------ .../01/GHSA-9hpx-h92w-9fpc/GHSA-9hpx-h92w-9fpc.json | 12 +++--------- .../01/GHSA-9pgj-x6h2-p943/GHSA-9pgj-x6h2-p943.json | 8 ++------ .../01/GHSA-c3cc-88pj-hrxf/GHSA-c3cc-88pj-hrxf.json | 12 +++--------- .../01/GHSA-c52c-f827-gfpg/GHSA-c52c-f827-gfpg.json | 4 +--- .../01/GHSA-c96w-v3hm-68gf/GHSA-c96w-v3hm-68gf.json | 12 +++--------- .../01/GHSA-cc3h-2vcf-c96x/GHSA-cc3h-2vcf-c96x.json | 12 +++--------- .../01/GHSA-cc8q-rrgm-f274/GHSA-cc8q-rrgm-f274.json | 12 +++--------- .../01/GHSA-cjxw-c723-f938/GHSA-cjxw-c723-f938.json | 8 ++------ .../01/GHSA-cq27-9fxq-2g57/GHSA-cq27-9fxq-2g57.json | 8 ++------ .../01/GHSA-crgh-cf58-pq9r/GHSA-crgh-cf58-pq9r.json | 8 ++------ .../01/GHSA-cw3v-mxv2-589m/GHSA-cw3v-mxv2-589m.json | 8 ++------ .../01/GHSA-f2q8-35wx-ww2j/GHSA-f2q8-35wx-ww2j.json | 8 ++------ .../01/GHSA-f674-4px8-qr98/GHSA-f674-4px8-qr98.json | 12 +++--------- .../01/GHSA-f979-4qm9-qvgj/GHSA-f979-4qm9-qvgj.json | 8 ++------ .../01/GHSA-fg3f-mxc7-mxh6/GHSA-fg3f-mxc7-mxh6.json | 8 ++------ .../01/GHSA-fjxj-v58p-v8w6/GHSA-fjxj-v58p-v8w6.json | 12 +++--------- .../01/GHSA-fpjw-hq75-pxx8/GHSA-fpjw-hq75-pxx8.json | 12 +++--------- .../01/GHSA-fv46-9fmf-2p7g/GHSA-fv46-9fmf-2p7g.json | 8 ++------ .../01/GHSA-fv9v-2855-83mf/GHSA-fv9v-2855-83mf.json | 4 +--- .../01/GHSA-g5ff-j87h-3cwg/GHSA-g5ff-j87h-3cwg.json | 12 +++--------- .../01/GHSA-g84v-6fgf-jw3g/GHSA-g84v-6fgf-jw3g.json | 8 ++------ .../01/GHSA-gfmv-c654-mm3g/GHSA-gfmv-c654-mm3g.json | 8 ++------ .../01/GHSA-gm3j-wm5r-799c/GHSA-gm3j-wm5r-799c.json | 4 +--- .../01/GHSA-gpw5-j8cp-9p59/GHSA-gpw5-j8cp-9p59.json | 8 ++------ .../01/GHSA-h2j2-qx54-6hmh/GHSA-h2j2-qx54-6hmh.json | 4 +--- .../01/GHSA-h72m-3m74-9ppq/GHSA-h72m-3m74-9ppq.json | 8 ++------ .../01/GHSA-h7hg-fw2g-58j8/GHSA-h7hg-fw2g-58j8.json | 8 ++------ .../01/GHSA-hgfc-qr57-548r/GHSA-hgfc-qr57-548r.json | 12 +++--------- .../01/GHSA-hhgp-4q6r-hh4c/GHSA-hhgp-4q6r-hh4c.json | 12 +++--------- .../01/GHSA-hr82-qcw6-r4j6/GHSA-hr82-qcw6-r4j6.json | 8 ++------ .../01/GHSA-j7v8-gg92-f664/GHSA-j7v8-gg92-f664.json | 8 ++------ .../01/GHSA-jc6h-x2h7-c6r4/GHSA-jc6h-x2h7-c6r4.json | 8 ++------ .../01/GHSA-m8p9-v77c-rq98/GHSA-m8p9-v77c-rq98.json | 8 ++------ .../01/GHSA-mm5h-c8p7-5v83/GHSA-mm5h-c8p7-5v83.json | 8 ++------ .../01/GHSA-mppp-rwr9-jw9f/GHSA-mppp-rwr9-jw9f.json | 12 +++--------- .../01/GHSA-pfxx-3ww7-5wc8/GHSA-pfxx-3ww7-5wc8.json | 8 ++------ .../01/GHSA-ph3j-2pmh-jj3v/GHSA-ph3j-2pmh-jj3v.json | 12 +++--------- .../01/GHSA-pmh9-v5qm-xh48/GHSA-pmh9-v5qm-xh48.json | 8 ++------ .../01/GHSA-pr4h-pc76-99rf/GHSA-pr4h-pc76-99rf.json | 8 ++------ .../01/GHSA-pv4h-cxpg-pv52/GHSA-pv4h-cxpg-pv52.json | 12 +++--------- .../01/GHSA-pv7h-c97m-6hrh/GHSA-pv7h-c97m-6hrh.json | 8 ++------ .../01/GHSA-pvgx-5rw8-rc6v/GHSA-pvgx-5rw8-rc6v.json | 12 +++--------- .../01/GHSA-q5fm-9w82-2m78/GHSA-q5fm-9w82-2m78.json | 8 ++------ .../01/GHSA-q5r8-fmxw-rxvr/GHSA-q5r8-fmxw-rxvr.json | 8 ++------ .../01/GHSA-q8m2-mp4h-vhmc/GHSA-q8m2-mp4h-vhmc.json | 4 +--- .../01/GHSA-qmgg-g8c3-8959/GHSA-qmgg-g8c3-8959.json | 8 ++------ .../01/GHSA-qqr4-8m2r-fv75/GHSA-qqr4-8m2r-fv75.json | 8 ++------ .../01/GHSA-qrcq-hr7g-x7gm/GHSA-qrcq-hr7g-x7gm.json | 8 ++------ .../01/GHSA-qv4f-fgw8-cv63/GHSA-qv4f-fgw8-cv63.json | 8 ++------ .../01/GHSA-r2fp-jg3h-x57v/GHSA-r2fp-jg3h-x57v.json | 8 ++------ .../01/GHSA-r3hm-jjx3-cjc9/GHSA-r3hm-jjx3-cjc9.json | 12 +++--------- .../01/GHSA-rhgm-4w89-39gg/GHSA-rhgm-4w89-39gg.json | 12 +++--------- .../01/GHSA-rqmw-j65q-j6hh/GHSA-rqmw-j65q-j6hh.json | 8 ++------ .../01/GHSA-rqqg-rcmm-4825/GHSA-rqqg-rcmm-4825.json | 8 ++------ .../01/GHSA-rqww-2fr9-72r5/GHSA-rqww-2fr9-72r5.json | 12 +++--------- .../01/GHSA-rrr6-r9v5-phwp/GHSA-rrr6-r9v5-phwp.json | 8 ++------ .../01/GHSA-rvjh-ch4h-2q94/GHSA-rvjh-ch4h-2q94.json | 12 +++--------- .../01/GHSA-v9r7-j9px-3j3q/GHSA-v9r7-j9px-3j3q.json | 12 +++--------- .../01/GHSA-vcf4-95pq-m6wr/GHSA-vcf4-95pq-m6wr.json | 8 ++------ .../01/GHSA-vcw4-97xh-vjfp/GHSA-vcw4-97xh-vjfp.json | 12 +++--------- .../01/GHSA-vwj8-hgq2-g82x/GHSA-vwj8-hgq2-g82x.json | 12 +++--------- .../01/GHSA-wmw8-xf4h-qxp6/GHSA-wmw8-xf4h-qxp6.json | 12 +++--------- .../01/GHSA-wx3w-5pq8-rxp9/GHSA-wx3w-5pq8-rxp9.json | 8 ++------ .../01/GHSA-x2v2-qh6j-j5r3/GHSA-x2v2-qh6j-j5r3.json | 8 ++------ .../01/GHSA-xcx8-3x77-x2fh/GHSA-xcx8-3x77-x2fh.json | 8 ++------ .../01/GHSA-xj65-m9r8-w48c/GHSA-xj65-m9r8-w48c.json | 8 ++------ .../01/GHSA-xmpv-p68m-37pg/GHSA-xmpv-p68m-37pg.json | 8 ++------ .../01/GHSA-xph7-8872-8h48/GHSA-xph7-8872-8h48.json | 8 ++------ .../01/GHSA-xqv8-5r47-5vxw/GHSA-xqv8-5r47-5vxw.json | 12 +++--------- .../01/GHSA-xxr8-r558-393h/GHSA-xxr8-r558-393h.json | 12 +++--------- .../02/GHSA-3425-gj4f-6wvw/GHSA-3425-gj4f-6wvw.json | 8 ++------ .../02/GHSA-46pp-qwvm-gq6q/GHSA-46pp-qwvm-gq6q.json | 8 ++------ .../02/GHSA-4h43-2654-6c5f/GHSA-4h43-2654-6c5f.json | 8 ++------ .../02/GHSA-5986-54mv-fgm9/GHSA-5986-54mv-fgm9.json | 12 +++--------- .../02/GHSA-5v7p-cf4c-24jq/GHSA-5v7p-cf4c-24jq.json | 4 +--- .../02/GHSA-6fhp-jhwr-cwgh/GHSA-6fhp-jhwr-cwgh.json | 8 ++------ .../02/GHSA-6m6v-cf35-649r/GHSA-6m6v-cf35-649r.json | 4 +--- .../02/GHSA-7r9c-fccw-3vrf/GHSA-7r9c-fccw-3vrf.json | 4 +--- .../02/GHSA-8h76-r3wq-wvqp/GHSA-8h76-r3wq-wvqp.json | 4 +--- .../02/GHSA-8x8f-8g3r-h75g/GHSA-8x8f-8g3r-h75g.json | 4 +--- .../02/GHSA-9wvm-c92g-hvqg/GHSA-9wvm-c92g-hvqg.json | 8 ++------ .../02/GHSA-c2px-hrc4-9534/GHSA-c2px-hrc4-9534.json | 8 ++------ .../02/GHSA-cv9m-jw92-c3v3/GHSA-cv9m-jw92-c3v3.json | 8 ++------ .../02/GHSA-gq5h-jhm6-q233/GHSA-gq5h-jhm6-q233.json | 8 ++------ .../02/GHSA-j947-fh29-79v6/GHSA-j947-fh29-79v6.json | 8 ++------ .../02/GHSA-m7g4-jxhg-grwg/GHSA-m7g4-jxhg-grwg.json | 8 ++------ .../02/GHSA-qrf2-8ggh-7fqc/GHSA-qrf2-8ggh-7fqc.json | 8 ++------ .../02/GHSA-rxmh-549p-v6m7/GHSA-rxmh-549p-v6m7.json | 8 ++------ .../02/GHSA-v8x4-gj4q-pwgq/GHSA-v8x4-gj4q-pwgq.json | 4 +--- .../02/GHSA-vj6w-cj6v-8ff8/GHSA-vj6w-cj6v-8ff8.json | 8 ++------ .../02/GHSA-vxpg-8q82-wmcp/GHSA-vxpg-8q82-wmcp.json | 8 ++------ .../02/GHSA-xfch-762x-q3v9/GHSA-xfch-762x-q3v9.json | 8 ++------ .../03/GHSA-35fm-4q2r-j938/GHSA-35fm-4q2r-j938.json | 4 +--- .../03/GHSA-h9pr-8j9g-2rhq/GHSA-h9pr-8j9g-2rhq.json | 4 +--- .../05/GHSA-22jf-974v-hf7j/GHSA-22jf-974v-hf7j.json | 4 +--- .../05/GHSA-24qp-pvw9-442x/GHSA-24qp-pvw9-442x.json | 8 ++------ .../05/GHSA-259r-6293-4g55/GHSA-259r-6293-4g55.json | 8 ++------ .../05/GHSA-25qv-mpwh-3c2j/GHSA-25qv-mpwh-3c2j.json | 8 ++------ .../05/GHSA-263x-9fgq-56vg/GHSA-263x-9fgq-56vg.json | 8 ++------ .../05/GHSA-26g5-xm46-wmp6/GHSA-26g5-xm46-wmp6.json | 8 ++------ .../05/GHSA-26rr-whcg-5f4g/GHSA-26rr-whcg-5f4g.json | 12 +++--------- .../05/GHSA-29jh-wx23-42f7/GHSA-29jh-wx23-42f7.json | 8 ++------ .../05/GHSA-2c64-8v4j-vw3m/GHSA-2c64-8v4j-vw3m.json | 4 +--- .../05/GHSA-2c8x-w9gg-x7v5/GHSA-2c8x-w9gg-x7v5.json | 8 ++------ .../05/GHSA-2cqq-v6m5-rqq4/GHSA-2cqq-v6m5-rqq4.json | 8 ++------ .../05/GHSA-2g59-pjjw-j55p/GHSA-2g59-pjjw-j55p.json | 4 +--- .../05/GHSA-2g83-fxgw-wvr6/GHSA-2g83-fxgw-wvr6.json | 8 ++------ .../05/GHSA-2gfp-29x3-m5qq/GHSA-2gfp-29x3-m5qq.json | 12 +++--------- .../05/GHSA-2h3v-8xgc-fcxp/GHSA-2h3v-8xgc-fcxp.json | 4 +--- .../05/GHSA-2m7g-78xc-qr55/GHSA-2m7g-78xc-qr55.json | 12 +++--------- .../05/GHSA-2pm7-wcx5-9h5j/GHSA-2pm7-wcx5-9h5j.json | 8 ++------ .../05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json | 4 +--- .../05/GHSA-2pwf-98xm-hgm2/GHSA-2pwf-98xm-hgm2.json | 4 +--- .../05/GHSA-2qf6-f49c-83qc/GHSA-2qf6-f49c-83qc.json | 4 +--- .../05/GHSA-2rh2-h4h3-63w4/GHSA-2rh2-h4h3-63w4.json | 8 ++------ .../05/GHSA-2rpg-qc85-4c9v/GHSA-2rpg-qc85-4c9v.json | 8 ++------ .../05/GHSA-2vx3-hm2p-g49x/GHSA-2vx3-hm2p-g49x.json | 8 ++------ .../05/GHSA-2w7h-pgq5-9g2m/GHSA-2w7h-pgq5-9g2m.json | 8 ++------ .../05/GHSA-2w8x-37m4-26px/GHSA-2w8x-37m4-26px.json | 8 ++------ .../05/GHSA-2wh9-8pg9-7cgx/GHSA-2wh9-8pg9-7cgx.json | 12 +++--------- .../05/GHSA-2whc-42x6-f9r4/GHSA-2whc-42x6-f9r4.json | 8 ++------ .../05/GHSA-2wjg-893f-qh7w/GHSA-2wjg-893f-qh7w.json | 8 ++------ .../05/GHSA-2wx9-w67p-qcqq/GHSA-2wx9-w67p-qcqq.json | 12 +++--------- .../05/GHSA-32fq-43mr-f4fp/GHSA-32fq-43mr-f4fp.json | 8 ++------ .../05/GHSA-33r9-2w5v-33vg/GHSA-33r9-2w5v-33vg.json | 8 ++------ .../05/GHSA-33rm-chj2-wr75/GHSA-33rm-chj2-wr75.json | 8 ++------ .../05/GHSA-34xm-pchf-hr5w/GHSA-34xm-pchf-hr5w.json | 8 ++------ .../05/GHSA-35xc-5p56-vcx8/GHSA-35xc-5p56-vcx8.json | 8 ++------ .../05/GHSA-363j-w49v-cj57/GHSA-363j-w49v-cj57.json | 8 ++------ .../05/GHSA-3656-jvhv-q239/GHSA-3656-jvhv-q239.json | 4 +--- .../05/GHSA-36hq-fr9w-frm9/GHSA-36hq-fr9w-frm9.json | 8 ++------ .../05/GHSA-36pj-pfw6-cc65/GHSA-36pj-pfw6-cc65.json | 8 ++------ .../05/GHSA-37f5-2q74-7wvc/GHSA-37f5-2q74-7wvc.json | 4 +--- .../05/GHSA-37fc-4qqv-26w3/GHSA-37fc-4qqv-26w3.json | 12 +++--------- .../05/GHSA-387h-jhfw-w4cc/GHSA-387h-jhfw-w4cc.json | 12 +++--------- .../05/GHSA-387x-jwqw-43f3/GHSA-387x-jwqw-43f3.json | 12 +++--------- .../05/GHSA-38j5-x223-737f/GHSA-38j5-x223-737f.json | 4 +--- .../05/GHSA-38v6-89r5-874g/GHSA-38v6-89r5-874g.json | 8 ++------ .../05/GHSA-393q-2jgx-p9ph/GHSA-393q-2jgx-p9ph.json | 8 ++------ .../05/GHSA-39v5-jf84-wf9c/GHSA-39v5-jf84-wf9c.json | 12 +++--------- .../05/GHSA-39w3-c286-wqjc/GHSA-39w3-c286-wqjc.json | 8 ++------ .../05/GHSA-3cp8-5f2x-4g4m/GHSA-3cp8-5f2x-4g4m.json | 12 +++--------- .../05/GHSA-3f63-vqp6-r5p2/GHSA-3f63-vqp6-r5p2.json | 4 +--- .../05/GHSA-3g57-8qrr-phw8/GHSA-3g57-8qrr-phw8.json | 8 ++------ .../05/GHSA-3h64-25x5-v8wv/GHSA-3h64-25x5-v8wv.json | 8 ++------ .../05/GHSA-3h95-q6m8-947m/GHSA-3h95-q6m8-947m.json | 8 ++------ .../05/GHSA-3m95-7rcm-xpxr/GHSA-3m95-7rcm-xpxr.json | 8 ++------ .../05/GHSA-3mf2-x699-cxr9/GHSA-3mf2-x699-cxr9.json | 12 +++--------- .../05/GHSA-3mm6-vwmh-qm9c/GHSA-3mm6-vwmh-qm9c.json | 4 +--- .../05/GHSA-3mmx-4r9c-p6f8/GHSA-3mmx-4r9c-p6f8.json | 8 ++------ .../05/GHSA-3mpj-8j86-c69j/GHSA-3mpj-8j86-c69j.json | 12 +++--------- .../05/GHSA-3mrx-5p8g-6q5j/GHSA-3mrx-5p8g-6q5j.json | 4 +--- .../05/GHSA-3pjg-4x3p-x3mq/GHSA-3pjg-4x3p-x3mq.json | 8 ++------ .../05/GHSA-3prv-x9wq-2654/GHSA-3prv-x9wq-2654.json | 8 ++------ .../05/GHSA-3qg9-856j-f4jv/GHSA-3qg9-856j-f4jv.json | 12 +++--------- .../05/GHSA-3qx5-mr88-qhv7/GHSA-3qx5-mr88-qhv7.json | 4 +--- .../05/GHSA-3r3v-7p48-rwmv/GHSA-3r3v-7p48-rwmv.json | 8 ++------ .../05/GHSA-3rh3-mwf4-58r4/GHSA-3rh3-mwf4-58r4.json | 4 +--- .../05/GHSA-3v87-f22j-hcwv/GHSA-3v87-f22j-hcwv.json | 8 ++------ .../05/GHSA-3vf4-p6xq-xxr9/GHSA-3vf4-p6xq-xxr9.json | 12 +++--------- .../05/GHSA-3w3v-6rwc-cvhr/GHSA-3w3v-6rwc-cvhr.json | 8 ++------ .../05/GHSA-3w9v-5f2g-97c5/GHSA-3w9v-5f2g-97c5.json | 4 +--- .../05/GHSA-3wg4-74hw-hxr7/GHSA-3wg4-74hw-hxr7.json | 12 +++--------- .../05/GHSA-3ww8-82c8-5vpr/GHSA-3ww8-82c8-5vpr.json | 12 +++--------- .../05/GHSA-3x3x-fgf2-hxxv/GHSA-3x3x-fgf2-hxxv.json | 12 +++--------- .../05/GHSA-42qf-73xw-h6m8/GHSA-42qf-73xw-h6m8.json | 8 ++------ .../05/GHSA-447w-r8fj-xjcc/GHSA-447w-r8fj-xjcc.json | 12 +++--------- .../05/GHSA-44hm-wr7f-qx65/GHSA-44hm-wr7f-qx65.json | 8 ++------ .../05/GHSA-4588-gggm-24j6/GHSA-4588-gggm-24j6.json | 4 +--- .../05/GHSA-48qf-97ph-fgqc/GHSA-48qf-97ph-fgqc.json | 8 ++------ .../05/GHSA-4cjx-47hq-7hc2/GHSA-4cjx-47hq-7hc2.json | 4 +--- .../05/GHSA-4fj9-68jx-qc49/GHSA-4fj9-68jx-qc49.json | 8 ++------ .../05/GHSA-4fp8-99qh-27p3/GHSA-4fp8-99qh-27p3.json | 8 ++------ .../05/GHSA-4g26-4jfh-95vh/GHSA-4g26-4jfh-95vh.json | 12 +++--------- .../05/GHSA-4gc5-387r-vqmc/GHSA-4gc5-387r-vqmc.json | 12 +++--------- .../05/GHSA-4jqx-c8xq-4m8x/GHSA-4jqx-c8xq-4m8x.json | 8 ++------ .../05/GHSA-4jrw-3q8x-9gpf/GHSA-4jrw-3q8x-9gpf.json | 4 +--- .../05/GHSA-4mm6-cg2p-rq25/GHSA-4mm6-cg2p-rq25.json | 4 +--- .../05/GHSA-4rgw-hq9r-qp9v/GHSA-4rgw-hq9r-qp9v.json | 8 ++------ .../05/GHSA-4w2r-p3vj-jj74/GHSA-4w2r-p3vj-jj74.json | 8 ++------ .../05/GHSA-4wc7-86xc-8837/GHSA-4wc7-86xc-8837.json | 12 +++--------- .../05/GHSA-4xc5-wc24-8f5h/GHSA-4xc5-wc24-8f5h.json | 4 +--- .../05/GHSA-4xp4-9qmj-752r/GHSA-4xp4-9qmj-752r.json | 8 ++------ .../05/GHSA-5263-f497-fhwq/GHSA-5263-f497-fhwq.json | 12 +++--------- .../05/GHSA-5396-497v-5r3r/GHSA-5396-497v-5r3r.json | 8 ++------ .../05/GHSA-54p3-vvrm-gcf3/GHSA-54p3-vvrm-gcf3.json | 4 +--- .../05/GHSA-54v7-6rq4-h28f/GHSA-54v7-6rq4-h28f.json | 8 ++------ .../05/GHSA-55fx-8656-67xw/GHSA-55fx-8656-67xw.json | 8 ++------ .../05/GHSA-55mr-3h98-7hm7/GHSA-55mr-3h98-7hm7.json | 8 ++------ .../05/GHSA-56x3-5r55-c4h6/GHSA-56x3-5r55-c4h6.json | 8 ++------ .../05/GHSA-57mp-jhxv-fr69/GHSA-57mp-jhxv-fr69.json | 8 ++------ .../05/GHSA-586h-8q3m-f5hh/GHSA-586h-8q3m-f5hh.json | 4 +--- .../05/GHSA-58ww-chv2-94cr/GHSA-58ww-chv2-94cr.json | 12 +++--------- .../05/GHSA-5cw9-5hjw-757r/GHSA-5cw9-5hjw-757r.json | 12 +++--------- .../05/GHSA-5f44-2f3g-gf6q/GHSA-5f44-2f3g-gf6q.json | 8 ++------ .../05/GHSA-5fqx-pg59-xr74/GHSA-5fqx-pg59-xr74.json | 4 +--- .../05/GHSA-5g8c-9j8m-c3v5/GHSA-5g8c-9j8m-c3v5.json | 12 +++--------- .../05/GHSA-5gfq-ghv5-4j5q/GHSA-5gfq-ghv5-4j5q.json | 4 +--- .../05/GHSA-5gr4-m4m2-fjjf/GHSA-5gr4-m4m2-fjjf.json | 8 ++------ .../05/GHSA-5h48-37h4-qpr3/GHSA-5h48-37h4-qpr3.json | 8 ++------ .../05/GHSA-5h4f-x39p-f6v8/GHSA-5h4f-x39p-f6v8.json | 4 +--- .../05/GHSA-5hm2-v6x4-c9fc/GHSA-5hm2-v6x4-c9fc.json | 4 +--- .../05/GHSA-5j3x-73cr-cpg5/GHSA-5j3x-73cr-cpg5.json | 8 ++------ .../05/GHSA-5jj7-m67j-9gcq/GHSA-5jj7-m67j-9gcq.json | 12 +++--------- .../05/GHSA-5jwm-jmmx-2mv2/GHSA-5jwm-jmmx-2mv2.json | 4 +--- .../05/GHSA-5phr-5283-mg7g/GHSA-5phr-5283-mg7g.json | 4 +--- .../05/GHSA-5pvq-364g-f88f/GHSA-5pvq-364g-f88f.json | 4 +--- .../05/GHSA-5q25-3rvc-82p6/GHSA-5q25-3rvc-82p6.json | 8 ++------ .../05/GHSA-5qp3-hxwx-86vp/GHSA-5qp3-hxwx-86vp.json | 8 ++------ .../05/GHSA-5rvj-6jpg-mr39/GHSA-5rvj-6jpg-mr39.json | 12 +++--------- .../05/GHSA-5v9m-r264-24vr/GHSA-5v9m-r264-24vr.json | 8 ++------ .../05/GHSA-5vfj-4g27-37g8/GHSA-5vfj-4g27-37g8.json | 4 +--- .../05/GHSA-5www-87m9-2c36/GHSA-5www-87m9-2c36.json | 8 ++------ .../05/GHSA-5x3c-pm5r-fhpx/GHSA-5x3c-pm5r-fhpx.json | 8 ++------ .../05/GHSA-622j-jvjv-7rx6/GHSA-622j-jvjv-7rx6.json | 8 ++------ .../05/GHSA-62hp-w5vm-g7xm/GHSA-62hp-w5vm-g7xm.json | 4 +--- .../05/GHSA-63fp-m4v5-qwjh/GHSA-63fp-m4v5-qwjh.json | 8 ++------ .../05/GHSA-66r3-r672-w6h3/GHSA-66r3-r672-w6h3.json | 12 +++--------- .../05/GHSA-676j-2jjm-jc5c/GHSA-676j-2jjm-jc5c.json | 8 ++------ .../05/GHSA-67c5-vcgx-65h6/GHSA-67c5-vcgx-65h6.json | 4 +--- .../05/GHSA-68vp-967g-wmr4/GHSA-68vp-967g-wmr4.json | 12 +++--------- .../05/GHSA-6c52-8fqm-4g2v/GHSA-6c52-8fqm-4g2v.json | 4 +--- .../05/GHSA-6cv2-qjv3-2vh8/GHSA-6cv2-qjv3-2vh8.json | 12 +++--------- .../05/GHSA-6g65-24hq-98xf/GHSA-6g65-24hq-98xf.json | 12 +++--------- .../05/GHSA-6gcw-2jwm-f6f4/GHSA-6gcw-2jwm-f6f4.json | 8 ++------ .../05/GHSA-6gr9-w5xf-xjq3/GHSA-6gr9-w5xf-xjq3.json | 8 ++------ .../05/GHSA-6m3m-wc9x-2j74/GHSA-6m3m-wc9x-2j74.json | 8 ++------ .../05/GHSA-6pr6-q53r-2q97/GHSA-6pr6-q53r-2q97.json | 4 +--- .../05/GHSA-6wr2-qx99-98mg/GHSA-6wr2-qx99-98mg.json | 4 +--- .../05/GHSA-6x2f-7ggw-rc86/GHSA-6x2f-7ggw-rc86.json | 8 ++------ .../05/GHSA-6x7j-xwg6-qmjx/GHSA-6x7j-xwg6-qmjx.json | 12 +++--------- .../05/GHSA-6xq2-x377-w2pf/GHSA-6xq2-x377-w2pf.json | 8 ++------ .../05/GHSA-6xqg-q7p8-9r82/GHSA-6xqg-q7p8-9r82.json | 8 ++------ .../05/GHSA-6xw2-89hr-qc42/GHSA-6xw2-89hr-qc42.json | 4 +--- .../05/GHSA-724g-6g9v-8462/GHSA-724g-6g9v-8462.json | 8 ++------ .../05/GHSA-73m9-q5p6-vhgf/GHSA-73m9-q5p6-vhgf.json | 12 +++--------- .../05/GHSA-73wq-fqgr-pmvw/GHSA-73wq-fqgr-pmvw.json | 8 ++------ .../05/GHSA-73x4-r3fj-rwhf/GHSA-73x4-r3fj-rwhf.json | 8 ++------ .../05/GHSA-748j-px2m-cwgh/GHSA-748j-px2m-cwgh.json | 4 +--- .../05/GHSA-749r-xj32-vr4x/GHSA-749r-xj32-vr4x.json | 8 ++------ .../05/GHSA-752g-gxpx-gwwv/GHSA-752g-gxpx-gwwv.json | 12 +++--------- .../05/GHSA-75mf-4cr8-98gx/GHSA-75mf-4cr8-98gx.json | 12 +++--------- .../05/GHSA-75q2-28c3-jc72/GHSA-75q2-28c3-jc72.json | 12 +++--------- .../05/GHSA-77c3-rw3f-4vrx/GHSA-77c3-rw3f-4vrx.json | 12 +++--------- .../05/GHSA-78vx-8c5h-72jr/GHSA-78vx-8c5h-72jr.json | 8 ++------ .../05/GHSA-795j-xvg2-56j4/GHSA-795j-xvg2-56j4.json | 12 +++--------- .../05/GHSA-79cm-2gxq-7x9r/GHSA-79cm-2gxq-7x9r.json | 4 +--- .../05/GHSA-79j7-5xqm-355x/GHSA-79j7-5xqm-355x.json | 12 +++--------- .../05/GHSA-7c9h-93j9-gcc2/GHSA-7c9h-93j9-gcc2.json | 8 ++------ .../05/GHSA-7cr3-p339-77q4/GHSA-7cr3-p339-77q4.json | 12 +++--------- .../05/GHSA-7fxh-4w9w-83v2/GHSA-7fxh-4w9w-83v2.json | 8 ++------ .../05/GHSA-7g8m-7qrw-wg8g/GHSA-7g8m-7qrw-wg8g.json | 8 ++------ .../05/GHSA-7hjm-px29-rv4v/GHSA-7hjm-px29-rv4v.json | 12 +++--------- .../05/GHSA-7jgc-fcpj-3rq8/GHSA-7jgc-fcpj-3rq8.json | 4 +--- .../05/GHSA-7jrj-rw38-cw85/GHSA-7jrj-rw38-cw85.json | 8 ++------ .../05/GHSA-7mcw-2h2h-r55h/GHSA-7mcw-2h2h-r55h.json | 8 ++------ .../05/GHSA-7mr2-g8wf-jhrp/GHSA-7mr2-g8wf-jhrp.json | 8 ++------ .../05/GHSA-7p4r-6976-jcwc/GHSA-7p4r-6976-jcwc.json | 12 +++--------- .../05/GHSA-7p8m-6352-g3gr/GHSA-7p8m-6352-g3gr.json | 8 ++------ .../05/GHSA-7pv2-73v2-p784/GHSA-7pv2-73v2-p784.json | 12 +++--------- .../05/GHSA-7rgf-8rpg-r6xc/GHSA-7rgf-8rpg-r6xc.json | 12 +++--------- .../05/GHSA-7rp8-q3gf-qx3q/GHSA-7rp8-q3gf-qx3q.json | 8 ++------ .../05/GHSA-7xqg-h9pv-h2hr/GHSA-7xqg-h9pv-h2hr.json | 4 +--- .../05/GHSA-82cc-2f68-f5qf/GHSA-82cc-2f68-f5qf.json | 12 +++--------- .../05/GHSA-836x-hw9m-wqxh/GHSA-836x-hw9m-wqxh.json | 8 ++------ .../05/GHSA-843h-x42r-c9r8/GHSA-843h-x42r-c9r8.json | 8 ++------ .../05/GHSA-84c9-33xg-rjf7/GHSA-84c9-33xg-rjf7.json | 8 ++------ .../05/GHSA-84f6-jgxp-q5mf/GHSA-84f6-jgxp-q5mf.json | 4 +--- .../05/GHSA-85p7-7gxf-f79f/GHSA-85p7-7gxf-f79f.json | 4 +--- .../05/GHSA-8646-8cww-px2p/GHSA-8646-8cww-px2p.json | 8 ++------ .../05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json | 12 +++--------- .../05/GHSA-8977-r7mx-5hvr/GHSA-8977-r7mx-5hvr.json | 4 +--- .../05/GHSA-89w9-gmvc-mfp8/GHSA-89w9-gmvc-mfp8.json | 8 ++------ .../05/GHSA-8cf3-jcrw-phfq/GHSA-8cf3-jcrw-phfq.json | 8 ++------ .../05/GHSA-8cpc-jvx2-9h3j/GHSA-8cpc-jvx2-9h3j.json | 12 +++--------- .../05/GHSA-8f4w-786j-j288/GHSA-8f4w-786j-j288.json | 8 ++------ .../05/GHSA-8fhg-9q98-67hg/GHSA-8fhg-9q98-67hg.json | 4 +--- .../05/GHSA-8fjh-3j4g-4f5v/GHSA-8fjh-3j4g-4f5v.json | 8 ++------ .../05/GHSA-8g9m-gx79-xjrc/GHSA-8g9m-gx79-xjrc.json | 8 ++------ .../05/GHSA-8gm5-39w5-qgqw/GHSA-8gm5-39w5-qgqw.json | 4 +--- .../05/GHSA-8gv5-8qg3-4cw8/GHSA-8gv5-8qg3-4cw8.json | 8 ++------ .../05/GHSA-8hfp-x3gr-3rfw/GHSA-8hfp-x3gr-3rfw.json | 8 ++------ .../05/GHSA-8hg4-5c5f-597j/GHSA-8hg4-5c5f-597j.json | 8 ++------ .../05/GHSA-8jfm-3q68-9546/GHSA-8jfm-3q68-9546.json | 12 +++--------- .../05/GHSA-8m22-gm6f-5487/GHSA-8m22-gm6f-5487.json | 8 ++------ .../05/GHSA-8mgc-hm3x-352v/GHSA-8mgc-hm3x-352v.json | 12 +++--------- .../05/GHSA-8mpf-jqgm-m3jg/GHSA-8mpf-jqgm-m3jg.json | 4 +--- .../05/GHSA-8mph-qpr3-3458/GHSA-8mph-qpr3-3458.json | 8 ++------ .../05/GHSA-8mrh-3xhr-6mjv/GHSA-8mrh-3xhr-6mjv.json | 8 ++------ .../05/GHSA-8pcr-qrf2-5hpg/GHSA-8pcr-qrf2-5hpg.json | 8 ++------ .../05/GHSA-8pf5-3m37-fjrv/GHSA-8pf5-3m37-fjrv.json | 8 ++------ .../05/GHSA-8rh3-5c87-wh48/GHSA-8rh3-5c87-wh48.json | 4 +--- .../05/GHSA-8rpc-3g9v-q43v/GHSA-8rpc-3g9v-q43v.json | 8 ++------ .../05/GHSA-8vc2-6cvw-975x/GHSA-8vc2-6cvw-975x.json | 8 ++------ .../05/GHSA-8wwf-w8hv-8982/GHSA-8wwf-w8hv-8982.json | 8 ++------ .../05/GHSA-93r2-34ph-r52j/GHSA-93r2-34ph-r52j.json | 8 ++------ .../05/GHSA-93wp-ggwv-r77q/GHSA-93wp-ggwv-r77q.json | 8 ++------ .../05/GHSA-9549-6vm9-3gwr/GHSA-9549-6vm9-3gwr.json | 12 +++--------- .../05/GHSA-9569-cpr5-gfhc/GHSA-9569-cpr5-gfhc.json | 8 ++------ .../05/GHSA-95j6-prcp-6mfp/GHSA-95j6-prcp-6mfp.json | 8 ++------ .../05/GHSA-972q-42q2-6m6q/GHSA-972q-42q2-6m6q.json | 12 +++--------- .../05/GHSA-97g7-pj49-4gvm/GHSA-97g7-pj49-4gvm.json | 8 ++------ .../05/GHSA-98f5-j2qf-rm7w/GHSA-98f5-j2qf-rm7w.json | 12 +++--------- .../05/GHSA-9953-888v-2xw2/GHSA-9953-888v-2xw2.json | 12 +++--------- .../05/GHSA-99pg-966x-c4x3/GHSA-99pg-966x-c4x3.json | 8 ++------ .../05/GHSA-9c28-2wjp-xr55/GHSA-9c28-2wjp-xr55.json | 12 +++--------- .../05/GHSA-9c6c-f33q-qhr3/GHSA-9c6c-f33q-qhr3.json | 4 +--- .../05/GHSA-9cwm-xxr8-vw8q/GHSA-9cwm-xxr8-vw8q.json | 8 ++------ .../05/GHSA-9gvr-mvxw-g2wj/GHSA-9gvr-mvxw-g2wj.json | 8 ++------ .../05/GHSA-9gwv-3vm2-v86h/GHSA-9gwv-3vm2-v86h.json | 12 +++--------- .../05/GHSA-9hpm-fmxg-j5xc/GHSA-9hpm-fmxg-j5xc.json | 4 +--- .../05/GHSA-9j62-mm37-x965/GHSA-9j62-mm37-x965.json | 12 +++--------- .../05/GHSA-9jfc-28w3-mr85/GHSA-9jfc-28w3-mr85.json | 8 ++------ .../05/GHSA-9jfc-hp58-576f/GHSA-9jfc-hp58-576f.json | 12 +++--------- .../05/GHSA-9mjx-fxxr-3w7h/GHSA-9mjx-fxxr-3w7h.json | 12 +++--------- .../05/GHSA-9mwp-5cv9-4623/GHSA-9mwp-5cv9-4623.json | 12 +++--------- .../05/GHSA-9mwq-hjj7-fhx6/GHSA-9mwq-hjj7-fhx6.json | 8 ++------ .../05/GHSA-9p64-f6jw-7f76/GHSA-9p64-f6jw-7f76.json | 12 +++--------- .../05/GHSA-9r5c-96r6-629r/GHSA-9r5c-96r6-629r.json | 8 ++------ .../05/GHSA-9rcf-cw39-wcmj/GHSA-9rcf-cw39-wcmj.json | 8 ++------ .../05/GHSA-9rg4-v77r-32p7/GHSA-9rg4-v77r-32p7.json | 8 ++------ .../05/GHSA-9v29-jj89-qr6f/GHSA-9v29-jj89-qr6f.json | 8 ++------ .../05/GHSA-9vc6-5cgr-2rx3/GHSA-9vc6-5cgr-2rx3.json | 12 +++--------- .../05/GHSA-9w3r-phm7-v8q5/GHSA-9w3r-phm7-v8q5.json | 8 ++------ .../05/GHSA-9x3v-wmxw-5f95/GHSA-9x3v-wmxw-5f95.json | 8 ++------ .../05/GHSA-9x5x-99rm-rq9h/GHSA-9x5x-99rm-rq9h.json | 12 +++--------- .../05/GHSA-9xgg-6j67-8x58/GHSA-9xgg-6j67-8x58.json | 8 ++------ .../05/GHSA-9xjq-pqm7-353q/GHSA-9xjq-pqm7-353q.json | 8 ++------ .../05/GHSA-9xv3-rrw4-9qm8/GHSA-9xv3-rrw4-9qm8.json | 12 +++--------- .../05/GHSA-c2gh-vwcm-fjx7/GHSA-c2gh-vwcm-fjx7.json | 8 ++------ .../05/GHSA-c2jm-rg5v-977c/GHSA-c2jm-rg5v-977c.json | 12 +++--------- .../05/GHSA-c37m-6w24-rcv9/GHSA-c37m-6w24-rcv9.json | 4 +--- .../05/GHSA-c3cc-gm9v-rc3h/GHSA-c3cc-gm9v-rc3h.json | 8 ++------ .../05/GHSA-c4jg-9g74-c7p6/GHSA-c4jg-9g74-c7p6.json | 12 +++--------- .../05/GHSA-c53q-wg6w-6jm7/GHSA-c53q-wg6w-6jm7.json | 8 ++------ .../05/GHSA-c5xx-92gp-xmp6/GHSA-c5xx-92gp-xmp6.json | 8 ++------ .../05/GHSA-c656-hcc6-xc8v/GHSA-c656-hcc6-xc8v.json | 12 +++--------- .../05/GHSA-c66x-5w35-7wmh/GHSA-c66x-5w35-7wmh.json | 4 +--- .../05/GHSA-c6f9-6q47-7q73/GHSA-c6f9-6q47-7q73.json | 8 ++------ .../05/GHSA-c6qp-2qc4-4h58/GHSA-c6qp-2qc4-4h58.json | 12 +++--------- .../05/GHSA-c6rg-vc6c-7fch/GHSA-c6rg-vc6c-7fch.json | 12 +++--------- .../05/GHSA-c778-g7jg-99x4/GHSA-c778-g7jg-99x4.json | 12 +++--------- .../05/GHSA-c798-qcm4-fvhx/GHSA-c798-qcm4-fvhx.json | 4 +--- .../05/GHSA-c7gr-mvmf-xv4h/GHSA-c7gr-mvmf-xv4h.json | 8 ++------ .../05/GHSA-c976-c57v-wjwr/GHSA-c976-c57v-wjwr.json | 12 +++--------- .../05/GHSA-c97p-79cx-vqh9/GHSA-c97p-79cx-vqh9.json | 4 +--- .../05/GHSA-c9fh-ff5v-mffg/GHSA-c9fh-ff5v-mffg.json | 8 ++------ .../05/GHSA-ccrq-mrj7-rq78/GHSA-ccrq-mrj7-rq78.json | 4 +--- .../05/GHSA-cfcf-26xg-6rpv/GHSA-cfcf-26xg-6rpv.json | 12 +++--------- .../05/GHSA-cffw-pvf2-3x8m/GHSA-cffw-pvf2-3x8m.json | 8 ++------ .../05/GHSA-cfv3-vpqw-2xgj/GHSA-cfv3-vpqw-2xgj.json | 12 +++--------- .../05/GHSA-cg3h-8j55-gc4x/GHSA-cg3h-8j55-gc4x.json | 12 +++--------- .../05/GHSA-cgg9-3m27-m426/GHSA-cgg9-3m27-m426.json | 4 +--- .../05/GHSA-cj3j-m7h5-mr79/GHSA-cj3j-m7h5-mr79.json | 8 ++------ .../05/GHSA-cj67-c85m-hjw4/GHSA-cj67-c85m-hjw4.json | 12 +++--------- .../05/GHSA-cpw6-5jfx-2w4c/GHSA-cpw6-5jfx-2w4c.json | 4 +--- .../05/GHSA-cq8f-2gqx-jf55/GHSA-cq8f-2gqx-jf55.json | 12 +++--------- .../05/GHSA-cqw5-qvh9-f85v/GHSA-cqw5-qvh9-f85v.json | 4 +--- .../05/GHSA-cr98-j6fv-34rq/GHSA-cr98-j6fv-34rq.json | 8 ++------ .../05/GHSA-cvm3-233f-g2vf/GHSA-cvm3-233f-g2vf.json | 4 +--- .../05/GHSA-cwvr-8j54-7jwh/GHSA-cwvr-8j54-7jwh.json | 4 +--- .../05/GHSA-cx55-6qpj-fmjq/GHSA-cx55-6qpj-fmjq.json | 12 +++--------- .../05/GHSA-f2cx-w4q6-4qq4/GHSA-f2cx-w4q6-4qq4.json | 8 ++------ .../05/GHSA-f2mx-7p4c-2cvr/GHSA-f2mx-7p4c-2cvr.json | 12 +++--------- .../05/GHSA-f334-mrv2-rrrr/GHSA-f334-mrv2-rrrr.json | 8 ++------ .../05/GHSA-f39g-97j7-v6v7/GHSA-f39g-97j7-v6v7.json | 4 +--- .../05/GHSA-f3fj-9xg7-49g7/GHSA-f3fj-9xg7-49g7.json | 8 ++------ .../05/GHSA-f499-3q8w-php5/GHSA-f499-3q8w-php5.json | 8 ++------ .../05/GHSA-f4g5-8f5m-c4xh/GHSA-f4g5-8f5m-c4xh.json | 8 ++------ .../05/GHSA-f4w7-f52m-fr89/GHSA-f4w7-f52m-fr89.json | 8 ++------ .../05/GHSA-f4wj-qq69-7p3q/GHSA-f4wj-qq69-7p3q.json | 8 ++------ .../05/GHSA-f54w-frwq-8pgx/GHSA-f54w-frwq-8pgx.json | 8 ++------ .../05/GHSA-f5cm-fvx4-j5xj/GHSA-f5cm-fvx4-j5xj.json | 12 +++--------- .../05/GHSA-f5vv-v37r-r859/GHSA-f5vv-v37r-r859.json | 8 ++------ .../05/GHSA-f7gq-46jw-6c9v/GHSA-f7gq-46jw-6c9v.json | 12 +++--------- .../05/GHSA-f897-6cg8-5m2p/GHSA-f897-6cg8-5m2p.json | 8 ++------ .../05/GHSA-f8v4-rq66-62m8/GHSA-f8v4-rq66-62m8.json | 12 +++--------- .../05/GHSA-ffg7-4prh-6h36/GHSA-ffg7-4prh-6h36.json | 8 ++------ .../05/GHSA-fg7q-r8wr-ch8g/GHSA-fg7q-r8wr-ch8g.json | 12 +++--------- .../05/GHSA-fgcr-rpg2-x8hm/GHSA-fgcr-rpg2-x8hm.json | 8 ++------ .../05/GHSA-fh3h-pv2j-78c4/GHSA-fh3h-pv2j-78c4.json | 8 ++------ .../05/GHSA-fhff-fr9c-r455/GHSA-fhff-fr9c-r455.json | 12 +++--------- .../05/GHSA-fhfw-5p8c-4cxr/GHSA-fhfw-5p8c-4cxr.json | 4 +--- .../05/GHSA-fjc2-x947-3pw2/GHSA-fjc2-x947-3pw2.json | 4 +--- .../05/GHSA-fjq4-jc5h-hgrj/GHSA-fjq4-jc5h-hgrj.json | 4 +--- .../05/GHSA-fjxm-8vv5-3pc6/GHSA-fjxm-8vv5-3pc6.json | 12 +++--------- .../05/GHSA-fp83-g5px-h8vv/GHSA-fp83-g5px-h8vv.json | 8 ++------ .../05/GHSA-fpj4-cwfc-v2c6/GHSA-fpj4-cwfc-v2c6.json | 8 ++------ .../05/GHSA-fq7v-76hh-w54m/GHSA-fq7v-76hh-w54m.json | 8 ++------ .../05/GHSA-fq8h-f93c-3m89/GHSA-fq8h-f93c-3m89.json | 8 ++------ .../05/GHSA-fr44-v39f-hp6h/GHSA-fr44-v39f-hp6h.json | 12 +++--------- .../05/GHSA-fv53-hf77-6xc2/GHSA-fv53-hf77-6xc2.json | 8 ++------ .../05/GHSA-fwfc-m344-9jp7/GHSA-fwfc-m344-9jp7.json | 8 ++------ .../05/GHSA-fwx6-r2xv-qqxf/GHSA-fwx6-r2xv-qqxf.json | 12 +++--------- .../05/GHSA-fxvw-6w4h-3mx5/GHSA-fxvw-6w4h-3mx5.json | 8 ++------ .../05/GHSA-g2fg-782m-jxww/GHSA-g2fg-782m-jxww.json | 8 ++------ .../05/GHSA-g37p-pm6w-mgfg/GHSA-g37p-pm6w-mgfg.json | 12 +++--------- .../05/GHSA-g48x-w6wf-g8mh/GHSA-g48x-w6wf-g8mh.json | 8 ++------ .../05/GHSA-g532-jv38-f9x7/GHSA-g532-jv38-f9x7.json | 8 ++------ .../05/GHSA-g5rr-93xh-mwfm/GHSA-g5rr-93xh-mwfm.json | 8 ++------ .../05/GHSA-g7gm-5527-72qc/GHSA-g7gm-5527-72qc.json | 12 +++--------- .../05/GHSA-g85f-5xc2-36cg/GHSA-g85f-5xc2-36cg.json | 12 +++--------- .../05/GHSA-g876-h78r-4r39/GHSA-g876-h78r-4r39.json | 12 +++--------- .../05/GHSA-g8vh-4gxx-phq3/GHSA-g8vh-4gxx-phq3.json | 4 +--- .../05/GHSA-gc3q-39r2-xhvv/GHSA-gc3q-39r2-xhvv.json | 8 ++------ .../05/GHSA-gc9v-4xv7-g396/GHSA-gc9v-4xv7-g396.json | 8 ++------ .../05/GHSA-ggwj-625q-9wgf/GHSA-ggwj-625q-9wgf.json | 8 ++------ .../05/GHSA-gqq4-jjc3-hg4c/GHSA-gqq4-jjc3-hg4c.json | 8 ++------ .../05/GHSA-grh7-765f-g36w/GHSA-grh7-765f-g36w.json | 12 +++--------- .../05/GHSA-gv8f-p965-5v38/GHSA-gv8f-p965-5v38.json | 12 +++--------- .../05/GHSA-gvxh-9x93-wmf5/GHSA-gvxh-9x93-wmf5.json | 4 +--- .../05/GHSA-gw48-mf2p-74mv/GHSA-gw48-mf2p-74mv.json | 4 +--- .../05/GHSA-gx4h-2w44-g9jc/GHSA-gx4h-2w44-g9jc.json | 8 ++------ .../05/GHSA-gxph-xvx9-2vrx/GHSA-gxph-xvx9-2vrx.json | 8 ++------ .../05/GHSA-gxvp-m937-jg9v/GHSA-gxvp-m937-jg9v.json | 8 ++------ .../05/GHSA-h23x-694w-xf68/GHSA-h23x-694w-xf68.json | 4 +--- .../05/GHSA-h25m-p8vh-j2r3/GHSA-h25m-p8vh-j2r3.json | 4 +--- .../05/GHSA-h2c7-f7r2-xmqp/GHSA-h2c7-f7r2-xmqp.json | 12 +++--------- .../05/GHSA-h3cp-cm99-c88r/GHSA-h3cp-cm99-c88r.json | 8 ++------ .../05/GHSA-h43v-fh8q-w87r/GHSA-h43v-fh8q-w87r.json | 4 +--- .../05/GHSA-h4qw-p9q8-p7jg/GHSA-h4qw-p9q8-p7jg.json | 8 ++------ .../05/GHSA-h53c-7gvg-7vxm/GHSA-h53c-7gvg-7vxm.json | 8 ++------ .../05/GHSA-h57m-vxj9-8gpv/GHSA-h57m-vxj9-8gpv.json | 8 ++------ .../05/GHSA-h675-g2pp-pw84/GHSA-h675-g2pp-pw84.json | 8 ++------ .../05/GHSA-h7f2-q3mc-89wm/GHSA-h7f2-q3mc-89wm.json | 8 ++------ .../05/GHSA-h855-j8m9-xmxj/GHSA-h855-j8m9-xmxj.json | 8 ++------ .../05/GHSA-h96v-mqfm-37x5/GHSA-h96v-mqfm-37x5.json | 12 +++--------- .../05/GHSA-h9rp-4c7r-h798/GHSA-h9rp-4c7r-h798.json | 4 +--- .../05/GHSA-hf2f-4243-6465/GHSA-hf2f-4243-6465.json | 4 +--- .../05/GHSA-hf9p-ph6h-r575/GHSA-hf9p-ph6h-r575.json | 8 ++------ .../05/GHSA-hg42-ggpx-469x/GHSA-hg42-ggpx-469x.json | 8 ++------ .../05/GHSA-hg4q-qffw-jqg4/GHSA-hg4q-qffw-jqg4.json | 4 +--- .../05/GHSA-hg7c-gq55-4mpw/GHSA-hg7c-gq55-4mpw.json | 8 ++------ .../05/GHSA-hj35-m38q-fv9m/GHSA-hj35-m38q-fv9m.json | 8 ++------ .../05/GHSA-hj9j-3xxg-6259/GHSA-hj9j-3xxg-6259.json | 4 +--- .../05/GHSA-hjq2-3cgr-hwqf/GHSA-hjq2-3cgr-hwqf.json | 8 ++------ .../05/GHSA-hm8j-79h4-q2c7/GHSA-hm8j-79h4-q2c7.json | 8 ++------ .../05/GHSA-hp3g-5vj7-7hgc/GHSA-hp3g-5vj7-7hgc.json | 4 +--- .../05/GHSA-hpr3-hj82-rh9j/GHSA-hpr3-hj82-rh9j.json | 12 +++--------- .../05/GHSA-hrpm-3rq3-r229/GHSA-hrpm-3rq3-r229.json | 8 ++------ .../05/GHSA-hvm5-xrxv-6g4q/GHSA-hvm5-xrxv-6g4q.json | 8 ++------ .../05/GHSA-j254-mg4h-rvf4/GHSA-j254-mg4h-rvf4.json | 12 +++--------- .../05/GHSA-j2c9-qfcw-93gr/GHSA-j2c9-qfcw-93gr.json | 4 +--- .../05/GHSA-j2qw-vv3p-xrvq/GHSA-j2qw-vv3p-xrvq.json | 12 +++--------- .../05/GHSA-j3v6-6jm3-55fp/GHSA-j3v6-6jm3-55fp.json | 12 +++--------- .../05/GHSA-j47q-mm35-5p3h/GHSA-j47q-mm35-5p3h.json | 8 ++------ .../05/GHSA-j6mp-9cfw-7j4j/GHSA-j6mp-9cfw-7j4j.json | 8 ++------ .../05/GHSA-j6x2-5mpm-9564/GHSA-j6x2-5mpm-9564.json | 8 ++------ .../05/GHSA-j7m4-jjrf-mjvw/GHSA-j7m4-jjrf-mjvw.json | 12 +++--------- .../05/GHSA-j832-g86m-353x/GHSA-j832-g86m-353x.json | 8 ++------ .../05/GHSA-j92r-fc65-r2hf/GHSA-j92r-fc65-r2hf.json | 12 +++--------- .../05/GHSA-j9c6-8ccv-jvv5/GHSA-j9c6-8ccv-jvv5.json | 12 +++--------- .../05/GHSA-jf44-xw2h-9pgq/GHSA-jf44-xw2h-9pgq.json | 12 +++--------- .../05/GHSA-jf8w-2pxr-j438/GHSA-jf8w-2pxr-j438.json | 8 ++------ .../05/GHSA-jg2m-q6h3-v5jg/GHSA-jg2m-q6h3-v5jg.json | 12 +++--------- .../05/GHSA-jghp-h678-hv65/GHSA-jghp-h678-hv65.json | 8 ++------ .../05/GHSA-jhj8-v83r-h3hm/GHSA-jhj8-v83r-h3hm.json | 12 +++--------- .../05/GHSA-jj96-3999-rr48/GHSA-jj96-3999-rr48.json | 12 +++--------- .../05/GHSA-jm2m-m6gc-v7qv/GHSA-jm2m-m6gc-v7qv.json | 8 ++------ .../05/GHSA-jm9r-r7jq-fwxw/GHSA-jm9r-r7jq-fwxw.json | 12 +++--------- .../05/GHSA-jp9c-4gwx-v8x8/GHSA-jp9c-4gwx-v8x8.json | 4 +--- .../05/GHSA-jq3c-8xm9-29m7/GHSA-jq3c-8xm9-29m7.json | 8 ++------ .../05/GHSA-jqj9-4qr2-cgv4/GHSA-jqj9-4qr2-cgv4.json | 12 +++--------- .../05/GHSA-jrf3-5554-9xcf/GHSA-jrf3-5554-9xcf.json | 8 ++------ .../05/GHSA-jrq7-3g58-rfqx/GHSA-jrq7-3g58-rfqx.json | 12 +++--------- .../05/GHSA-jw4h-2vhw-8fwh/GHSA-jw4h-2vhw-8fwh.json | 8 ++------ .../05/GHSA-jwc8-w94r-p4h4/GHSA-jwc8-w94r-p4h4.json | 8 ++------ .../05/GHSA-m2gc-ff6x-q3hw/GHSA-m2gc-ff6x-q3hw.json | 8 ++------ .../05/GHSA-m2v5-5h76-p8cv/GHSA-m2v5-5h76-p8cv.json | 12 +++--------- .../05/GHSA-m2wv-xvc5-4rfq/GHSA-m2wv-xvc5-4rfq.json | 8 ++------ .../05/GHSA-m425-vhp9-h739/GHSA-m425-vhp9-h739.json | 12 +++--------- .../05/GHSA-m47c-vx53-g89g/GHSA-m47c-vx53-g89g.json | 8 ++------ .../05/GHSA-m4q9-95cr-335x/GHSA-m4q9-95cr-335x.json | 8 ++------ .../05/GHSA-m529-gcjc-wm6j/GHSA-m529-gcjc-wm6j.json | 8 ++------ .../05/GHSA-m5g3-vw48-vpcq/GHSA-m5g3-vw48-vpcq.json | 8 ++------ .../05/GHSA-m8c3-2mv9-fqpf/GHSA-m8c3-2mv9-fqpf.json | 12 +++--------- .../05/GHSA-m8rh-p4v3-9rr7/GHSA-m8rh-p4v3-9rr7.json | 8 ++------ .../05/GHSA-m8wr-h83w-q7hq/GHSA-m8wr-h83w-q7hq.json | 12 +++--------- .../05/GHSA-m9j9-976v-fcvv/GHSA-m9j9-976v-fcvv.json | 8 ++------ .../05/GHSA-m9x3-pp92-vvhw/GHSA-m9x3-pp92-vvhw.json | 8 ++------ .../05/GHSA-mchx-p635-vpq8/GHSA-mchx-p635-vpq8.json | 4 +--- .../05/GHSA-mf4g-3m2w-qf36/GHSA-mf4g-3m2w-qf36.json | 12 +++--------- .../05/GHSA-mf78-mcx4-9ph4/GHSA-mf78-mcx4-9ph4.json | 8 ++------ .../05/GHSA-mfx5-qvrm-pvvm/GHSA-mfx5-qvrm-pvvm.json | 12 +++--------- .../05/GHSA-mg37-xw7q-j63c/GHSA-mg37-xw7q-j63c.json | 8 ++------ .../05/GHSA-mgw6-5qjc-mx7w/GHSA-mgw6-5qjc-mx7w.json | 12 +++--------- .../05/GHSA-mh2j-9c96-v8jf/GHSA-mh2j-9c96-v8jf.json | 4 +--- .../05/GHSA-mh9m-r9g2-chhf/GHSA-mh9m-r9g2-chhf.json | 8 ++------ .../05/GHSA-mhxp-j75h-h86w/GHSA-mhxp-j75h-h86w.json | 12 +++--------- .../05/GHSA-mhxv-5q9h-hp9c/GHSA-mhxv-5q9h-hp9c.json | 12 +++--------- .../05/GHSA-mj2h-f2r8-7855/GHSA-mj2h-f2r8-7855.json | 8 ++------ .../05/GHSA-mj46-j682-p569/GHSA-mj46-j682-p569.json | 8 ++------ .../05/GHSA-mm2c-whrj-39qm/GHSA-mm2c-whrj-39qm.json | 12 +++--------- .../05/GHSA-mmvc-933r-7cp3/GHSA-mmvc-933r-7cp3.json | 8 ++------ .../05/GHSA-mmx6-xv2h-w7x8/GHSA-mmx6-xv2h-w7x8.json | 4 +--- .../05/GHSA-mp2c-hhj2-7xjx/GHSA-mp2c-hhj2-7xjx.json | 12 +++--------- .../05/GHSA-mphq-fg36-pppm/GHSA-mphq-fg36-pppm.json | 12 +++--------- .../05/GHSA-mr4g-v4xh-m67m/GHSA-mr4g-v4xh-m67m.json | 8 ++------ .../05/GHSA-mr5j-h8xf-5m2m/GHSA-mr5j-h8xf-5m2m.json | 4 +--- .../05/GHSA-mr8c-273h-jpmh/GHSA-mr8c-273h-jpmh.json | 8 ++------ .../05/GHSA-mrg2-8f7m-jw7f/GHSA-mrg2-8f7m-jw7f.json | 8 ++------ .../05/GHSA-mv2h-6cx9-44g2/GHSA-mv2h-6cx9-44g2.json | 4 +--- .../05/GHSA-mv5f-9r7g-hr97/GHSA-mv5f-9r7g-hr97.json | 12 +++--------- .../05/GHSA-mv6w-p8g3-qr3x/GHSA-mv6w-p8g3-qr3x.json | 8 ++------ .../05/GHSA-p379-f2cq-ghhm/GHSA-p379-f2cq-ghhm.json | 8 ++------ .../05/GHSA-p3m3-mm8m-9fq2/GHSA-p3m3-mm8m-9fq2.json | 8 ++------ .../05/GHSA-p437-qg7q-wh7p/GHSA-p437-qg7q-wh7p.json | 8 ++------ .../05/GHSA-p476-69jg-2436/GHSA-p476-69jg-2436.json | 4 +--- .../05/GHSA-p4c4-gfr7-cmgr/GHSA-p4c4-gfr7-cmgr.json | 8 ++------ .../05/GHSA-p4cx-p88v-xqv9/GHSA-p4cx-p88v-xqv9.json | 12 +++--------- .../05/GHSA-p5pv-c45m-p722/GHSA-p5pv-c45m-p722.json | 8 ++------ .../05/GHSA-p672-97f8-chmq/GHSA-p672-97f8-chmq.json | 4 +--- .../05/GHSA-p6vh-m29c-65m2/GHSA-p6vh-m29c-65m2.json | 12 +++--------- .../05/GHSA-p74p-3c84-fg2v/GHSA-p74p-3c84-fg2v.json | 12 +++--------- .../05/GHSA-p784-84p4-47fp/GHSA-p784-84p4-47fp.json | 8 ++------ .../05/GHSA-p8c7-34p7-r42c/GHSA-p8c7-34p7-r42c.json | 8 ++------ .../05/GHSA-p8wm-pg92-j5jw/GHSA-p8wm-pg92-j5jw.json | 8 ++------ .../05/GHSA-p937-9x7h-c2gp/GHSA-p937-9x7h-c2gp.json | 8 ++------ .../05/GHSA-p9mr-2cw8-4xhj/GHSA-p9mr-2cw8-4xhj.json | 12 +++--------- .../05/GHSA-pc28-mpvf-j77x/GHSA-pc28-mpvf-j77x.json | 12 +++--------- .../05/GHSA-pg2f-rw74-23rg/GHSA-pg2f-rw74-23rg.json | 8 ++------ .../05/GHSA-pg6c-938r-g548/GHSA-pg6c-938r-g548.json | 4 +--- .../05/GHSA-pg83-2xx5-cjhr/GHSA-pg83-2xx5-cjhr.json | 8 ++------ .../05/GHSA-pg9p-rcwh-5gv5/GHSA-pg9p-rcwh-5gv5.json | 8 ++------ .../05/GHSA-pgfj-r964-76qx/GHSA-pgfj-r964-76qx.json | 8 ++------ .../05/GHSA-pgpg-mrjc-8g4g/GHSA-pgpg-mrjc-8g4g.json | 4 +--- .../05/GHSA-pmmh-h8hr-cxm8/GHSA-pmmh-h8hr-cxm8.json | 12 +++--------- .../05/GHSA-pqp4-4hrh-77x4/GHSA-pqp4-4hrh-77x4.json | 8 ++------ .../05/GHSA-pqrq-jm22-v4pv/GHSA-pqrq-jm22-v4pv.json | 8 ++------ .../05/GHSA-pqx5-4w4x-h6j2/GHSA-pqx5-4w4x-h6j2.json | 8 ++------ .../05/GHSA-pr5m-6gvr-rwfr/GHSA-pr5m-6gvr-rwfr.json | 12 +++--------- .../05/GHSA-pvcp-3wfq-3hf4/GHSA-pvcp-3wfq-3hf4.json | 12 +++--------- .../05/GHSA-q2fj-rm78-5v8m/GHSA-q2fj-rm78-5v8m.json | 12 +++--------- .../05/GHSA-q2vv-3q42-xrpx/GHSA-q2vv-3q42-xrpx.json | 12 +++--------- .../05/GHSA-q36r-8fc9-m4r9/GHSA-q36r-8fc9-m4r9.json | 8 ++------ .../05/GHSA-q3gg-vjpp-5cr5/GHSA-q3gg-vjpp-5cr5.json | 8 ++------ .../05/GHSA-q3j4-9cmf-q948/GHSA-q3j4-9cmf-q948.json | 4 +--- .../05/GHSA-q44j-435f-vxcg/GHSA-q44j-435f-vxcg.json | 8 ++------ .../05/GHSA-q4f5-ggvq-wc6p/GHSA-q4f5-ggvq-wc6p.json | 8 ++------ .../05/GHSA-q579-28m6-fmfm/GHSA-q579-28m6-fmfm.json | 4 +--- .../05/GHSA-q5h5-xj4x-2fm4/GHSA-q5h5-xj4x-2fm4.json | 8 ++------ .../05/GHSA-q5jf-fjpf-mq77/GHSA-q5jf-fjpf-mq77.json | 12 +++--------- .../05/GHSA-q776-jqj9-22hh/GHSA-q776-jqj9-22hh.json | 4 +--- .../05/GHSA-q83m-pm48-7pw6/GHSA-q83m-pm48-7pw6.json | 8 ++------ .../05/GHSA-q889-r359-8p38/GHSA-q889-r359-8p38.json | 8 ++------ .../05/GHSA-q8jr-p6p3-r4fm/GHSA-q8jr-p6p3-r4fm.json | 12 +++--------- .../05/GHSA-q8vx-8qj8-5m82/GHSA-q8vx-8qj8-5m82.json | 8 ++------ .../05/GHSA-q928-658m-3ccv/GHSA-q928-658m-3ccv.json | 4 +--- .../05/GHSA-q92p-8v5f-g5x5/GHSA-q92p-8v5f-g5x5.json | 12 +++--------- .../05/GHSA-q954-xhvx-crpg/GHSA-q954-xhvx-crpg.json | 8 ++------ .../05/GHSA-qc9q-6588-8mr6/GHSA-qc9q-6588-8mr6.json | 8 ++------ .../05/GHSA-qcwp-776m-mf57/GHSA-qcwp-776m-mf57.json | 8 ++------ .../05/GHSA-qf25-9mpg-v9fc/GHSA-qf25-9mpg-v9fc.json | 8 ++------ .../05/GHSA-qh22-xhvg-2v6g/GHSA-qh22-xhvg-2v6g.json | 12 +++--------- .../05/GHSA-qj22-33jc-9j2f/GHSA-qj22-33jc-9j2f.json | 4 +--- .../05/GHSA-qjvh-m9j3-g2qw/GHSA-qjvh-m9j3-g2qw.json | 8 ++------ .../05/GHSA-qmr9-3466-4r4h/GHSA-qmr9-3466-4r4h.json | 12 +++--------- .../05/GHSA-qmw2-rrv5-2qxg/GHSA-qmw2-rrv5-2qxg.json | 8 ++------ .../05/GHSA-qp53-7wh8-26w7/GHSA-qp53-7wh8-26w7.json | 8 ++------ .../05/GHSA-qpf9-w85c-45gv/GHSA-qpf9-w85c-45gv.json | 4 +--- .../05/GHSA-qppx-xpxc-rvg5/GHSA-qppx-xpxc-rvg5.json | 12 +++--------- .../05/GHSA-qv29-vvm4-3pc6/GHSA-qv29-vvm4-3pc6.json | 8 ++------ .../05/GHSA-qw57-cmq9-hj8j/GHSA-qw57-cmq9-hj8j.json | 12 +++--------- .../05/GHSA-qwm2-p4xm-jjjq/GHSA-qwm2-p4xm-jjjq.json | 8 ++------ .../05/GHSA-qwpw-7f3q-wc3q/GHSA-qwpw-7f3q-wc3q.json | 8 ++------ .../05/GHSA-r2j5-h2gf-999c/GHSA-r2j5-h2gf-999c.json | 4 +--- .../05/GHSA-r32h-qqj3-9xpg/GHSA-r32h-qqj3-9xpg.json | 8 ++------ .../05/GHSA-r3mw-gv7v-r27r/GHSA-r3mw-gv7v-r27r.json | 8 ++------ .../05/GHSA-r3wh-69g5-qr68/GHSA-r3wh-69g5-qr68.json | 8 ++------ .../05/GHSA-r4rm-j888-6w3w/GHSA-r4rm-j888-6w3w.json | 8 ++------ .../05/GHSA-r5m5-9pgw-6cx2/GHSA-r5m5-9pgw-6cx2.json | 12 +++--------- .../05/GHSA-r627-h27m-xp74/GHSA-r627-h27m-xp74.json | 12 +++--------- .../05/GHSA-r6rj-wrr3-48q3/GHSA-r6rj-wrr3-48q3.json | 8 ++------ .../05/GHSA-r7cx-cqwc-hf28/GHSA-r7cx-cqwc-hf28.json | 8 ++------ .../05/GHSA-r8j8-g8mg-2j28/GHSA-r8j8-g8mg-2j28.json | 8 ++------ .../05/GHSA-r8pv-f253-ph8x/GHSA-r8pv-f253-ph8x.json | 8 ++------ .../05/GHSA-r93x-32gw-w52p/GHSA-r93x-32gw-w52p.json | 12 +++--------- .../05/GHSA-r943-c3mj-3wjm/GHSA-r943-c3mj-3wjm.json | 8 ++------ .../05/GHSA-r9jr-628j-pc37/GHSA-r9jr-628j-pc37.json | 12 +++--------- .../05/GHSA-r9q5-qcf6-7r92/GHSA-r9q5-qcf6-7r92.json | 12 +++--------- .../05/GHSA-rf98-23w8-rpx5/GHSA-rf98-23w8-rpx5.json | 8 ++------ .../05/GHSA-rfvv-px5p-7fmg/GHSA-rfvv-px5p-7fmg.json | 8 ++------ .../05/GHSA-rhr6-3h7f-9h2q/GHSA-rhr6-3h7f-9h2q.json | 8 ++------ .../05/GHSA-rjjg-6x7j-qmpc/GHSA-rjjg-6x7j-qmpc.json | 8 ++------ .../05/GHSA-rm2q-3gmp-74fg/GHSA-rm2q-3gmp-74fg.json | 8 ++------ .../05/GHSA-rm8x-6gj9-f66x/GHSA-rm8x-6gj9-f66x.json | 12 +++--------- .../05/GHSA-rmfj-5qj3-3hmx/GHSA-rmfj-5qj3-3hmx.json | 12 +++--------- .../05/GHSA-rmx2-6f87-q3j9/GHSA-rmx2-6f87-q3j9.json | 12 +++--------- .../05/GHSA-rp2c-496x-gf5c/GHSA-rp2c-496x-gf5c.json | 8 ++------ .../05/GHSA-rp7q-3qmv-ff4c/GHSA-rp7q-3qmv-ff4c.json | 8 ++------ .../05/GHSA-rq5m-vxrx-vvhp/GHSA-rq5m-vxrx-vvhp.json | 12 +++--------- .../05/GHSA-rrjj-h75v-rxm7/GHSA-rrjj-h75v-rxm7.json | 12 +++--------- .../05/GHSA-rrxx-j89p-pqmx/GHSA-rrxx-j89p-pqmx.json | 8 ++------ .../05/GHSA-rvpw-wq7v-3f3v/GHSA-rvpw-wq7v-3f3v.json | 4 +--- .../05/GHSA-v279-8rqm-3xjg/GHSA-v279-8rqm-3xjg.json | 8 ++------ .../05/GHSA-v36c-qc45-j933/GHSA-v36c-qc45-j933.json | 8 ++------ .../05/GHSA-v4cw-9cwh-rv3p/GHSA-v4cw-9cwh-rv3p.json | 12 +++--------- .../05/GHSA-v4h8-98x3-fcrp/GHSA-v4h8-98x3-fcrp.json | 8 ++------ .../05/GHSA-v564-r5jq-5c36/GHSA-v564-r5jq-5c36.json | 8 ++------ .../05/GHSA-v57j-5v82-q88g/GHSA-v57j-5v82-q88g.json | 12 +++--------- .../05/GHSA-v6vf-2wmq-mp2x/GHSA-v6vf-2wmq-mp2x.json | 12 +++--------- .../05/GHSA-v723-8xx7-26gh/GHSA-v723-8xx7-26gh.json | 8 ++------ .../05/GHSA-v888-69w3-vqpv/GHSA-v888-69w3-vqpv.json | 8 ++------ .../05/GHSA-v8gw-v6pg-vfjw/GHSA-v8gw-v6pg-vfjw.json | 8 ++------ .../05/GHSA-v97q-8h6v-ffr3/GHSA-v97q-8h6v-ffr3.json | 12 +++--------- .../05/GHSA-vf63-rh76-xv4g/GHSA-vf63-rh76-xv4g.json | 8 ++------ .../05/GHSA-vfmg-c98f-3jxw/GHSA-vfmg-c98f-3jxw.json | 12 +++--------- .../05/GHSA-vgg8-4wp9-8p4c/GHSA-vgg8-4wp9-8p4c.json | 4 +--- .../05/GHSA-vhv3-2hw6-3q7j/GHSA-vhv3-2hw6-3q7j.json | 8 ++------ .../05/GHSA-vj6g-7r2h-qhcc/GHSA-vj6g-7r2h-qhcc.json | 12 +++--------- .../05/GHSA-vpg2-8g7f-3vh6/GHSA-vpg2-8g7f-3vh6.json | 8 ++------ .../05/GHSA-vpq9-rx6p-23hj/GHSA-vpq9-rx6p-23hj.json | 8 ++------ .../05/GHSA-vqw9-jf4m-h3pm/GHSA-vqw9-jf4m-h3pm.json | 8 ++------ .../05/GHSA-vr78-cpqr-qr3p/GHSA-vr78-cpqr-qr3p.json | 8 ++------ .../05/GHSA-vv2w-c23q-c32q/GHSA-vv2w-c23q-c32q.json | 8 ++------ .../05/GHSA-vvj7-w55j-xgmw/GHSA-vvj7-w55j-xgmw.json | 4 +--- .../05/GHSA-vw2w-pcch-37c6/GHSA-vw2w-pcch-37c6.json | 8 ++------ .../05/GHSA-vw4m-8vvh-crhf/GHSA-vw4m-8vvh-crhf.json | 4 +--- .../05/GHSA-vw86-rxwf-9vhm/GHSA-vw86-rxwf-9vhm.json | 4 +--- .../05/GHSA-vw92-7p2v-77xf/GHSA-vw92-7p2v-77xf.json | 8 ++------ .../05/GHSA-vwhm-7462-cm54/GHSA-vwhm-7462-cm54.json | 12 +++--------- .../05/GHSA-vx7g-39p9-2r2g/GHSA-vx7g-39p9-2r2g.json | 4 +--- .../05/GHSA-vxv7-q37g-hwv2/GHSA-vxv7-q37g-hwv2.json | 4 +--- .../05/GHSA-w26c-gw69-r33c/GHSA-w26c-gw69-r33c.json | 12 +++--------- .../05/GHSA-w28c-prr6-33rc/GHSA-w28c-prr6-33rc.json | 8 ++------ .../05/GHSA-w349-42x9-rx83/GHSA-w349-42x9-rx83.json | 8 ++------ .../05/GHSA-w3v7-w92j-r88x/GHSA-w3v7-w92j-r88x.json | 8 ++------ .../05/GHSA-w524-fgjq-fxjr/GHSA-w524-fgjq-fxjr.json | 8 ++------ .../05/GHSA-w5j7-j9wm-9x8q/GHSA-w5j7-j9wm-9x8q.json | 8 ++------ .../05/GHSA-w674-3mq5-fw7c/GHSA-w674-3mq5-fw7c.json | 12 +++--------- .../05/GHSA-w6h9-j4f8-48wx/GHSA-w6h9-j4f8-48wx.json | 12 +++--------- .../05/GHSA-w6v8-ffc7-5f5p/GHSA-w6v8-ffc7-5f5p.json | 8 ++------ .../05/GHSA-w74x-482v-qgx3/GHSA-w74x-482v-qgx3.json | 8 ++------ .../05/GHSA-w7vx-gpvr-f5cg/GHSA-w7vx-gpvr-f5cg.json | 8 ++------ .../05/GHSA-w8c6-3v55-x3f2/GHSA-w8c6-3v55-x3f2.json | 8 ++------ .../05/GHSA-wg8v-cggr-5vm6/GHSA-wg8v-cggr-5vm6.json | 8 ++------ .../05/GHSA-whf2-4g7v-9wcm/GHSA-whf2-4g7v-9wcm.json | 8 ++------ .../05/GHSA-wjvw-6gq9-r937/GHSA-wjvw-6gq9-r937.json | 4 +--- .../05/GHSA-wmhj-xgr4-2hgx/GHSA-wmhj-xgr4-2hgx.json | 12 +++--------- .../05/GHSA-wrfx-rw96-gwf3/GHSA-wrfx-rw96-gwf3.json | 8 ++------ .../05/GHSA-wv5q-rqrc-8qwj/GHSA-wv5q-rqrc-8qwj.json | 12 +++--------- .../05/GHSA-wvc9-6xq9-f3hx/GHSA-wvc9-6xq9-f3hx.json | 8 ++------ .../05/GHSA-wx46-225g-678j/GHSA-wx46-225g-678j.json | 8 ++------ .../05/GHSA-wx6m-r4jc-mfvw/GHSA-wx6m-r4jc-mfvw.json | 8 ++------ .../05/GHSA-wx86-c74j-r585/GHSA-wx86-c74j-r585.json | 8 ++------ .../05/GHSA-wx8f-7wmv-f3cq/GHSA-wx8f-7wmv-f3cq.json | 8 ++------ .../05/GHSA-wxfw-gh9x-v224/GHSA-wxfw-gh9x-v224.json | 8 ++------ .../05/GHSA-x2jp-jqfx-wrjx/GHSA-x2jp-jqfx-wrjx.json | 8 ++------ .../05/GHSA-x2mw-2wgh-5r92/GHSA-x2mw-2wgh-5r92.json | 4 +--- .../05/GHSA-x33f-8jwv-mmx3/GHSA-x33f-8jwv-mmx3.json | 8 ++------ .../05/GHSA-x3f3-q6x5-f4rj/GHSA-x3f3-q6x5-f4rj.json | 12 +++--------- .../05/GHSA-x552-vw23-hqr2/GHSA-x552-vw23-hqr2.json | 12 +++--------- .../05/GHSA-x63c-rx8f-jqj7/GHSA-x63c-rx8f-jqj7.json | 8 ++------ .../05/GHSA-x6mp-mr6c-vfjv/GHSA-x6mp-mr6c-vfjv.json | 12 +++--------- .../05/GHSA-x72w-3hm9-7xcv/GHSA-x72w-3hm9-7xcv.json | 8 ++------ .../05/GHSA-x77r-9j3c-w6wj/GHSA-x77r-9j3c-w6wj.json | 8 ++------ .../05/GHSA-x88f-9639-h9vx/GHSA-x88f-9639-h9vx.json | 8 ++------ .../05/GHSA-x88v-hq24-c79w/GHSA-x88v-hq24-c79w.json | 12 +++--------- .../05/GHSA-x8hq-gmcw-28cp/GHSA-x8hq-gmcw-28cp.json | 8 ++------ .../05/GHSA-x939-2wmx-j42c/GHSA-x939-2wmx-j42c.json | 12 +++--------- .../05/GHSA-xcr5-rqr5-57fx/GHSA-xcr5-rqr5-57fx.json | 12 +++--------- .../05/GHSA-xg87-92r7-2r8m/GHSA-xg87-92r7-2r8m.json | 4 +--- .../05/GHSA-xh2h-cw6h-x9h5/GHSA-xh2h-cw6h-x9h5.json | 4 +--- .../05/GHSA-xj4p-rw86-6466/GHSA-xj4p-rw86-6466.json | 8 ++------ .../05/GHSA-xj87-q393-fjr7/GHSA-xj87-q393-fjr7.json | 8 ++------ .../05/GHSA-xm3g-p25r-3qrv/GHSA-xm3g-p25r-3qrv.json | 8 ++------ .../05/GHSA-xmx2-q3rp-q8fq/GHSA-xmx2-q3rp-q8fq.json | 8 ++------ .../05/GHSA-xq3m-6r9g-r79r/GHSA-xq3m-6r9g-r79r.json | 12 +++--------- .../05/GHSA-xq88-f43j-jg6v/GHSA-xq88-f43j-jg6v.json | 8 ++------ .../05/GHSA-xqh5-468j-8666/GHSA-xqh5-468j-8666.json | 8 ++------ .../05/GHSA-xqhj-rm5r-mj4q/GHSA-xqhj-rm5r-mj4q.json | 8 ++------ .../05/GHSA-xqwg-mwmp-6pp4/GHSA-xqwg-mwmp-6pp4.json | 8 ++------ .../05/GHSA-xqwg-v65r-hvf2/GHSA-xqwg-v65r-hvf2.json | 4 +--- .../05/GHSA-xvm3-rxj9-vf93/GHSA-xvm3-rxj9-vf93.json | 8 ++------ .../05/GHSA-xw4j-w9j3-qq6q/GHSA-xw4j-w9j3-qq6q.json | 8 ++------ .../05/GHSA-xx46-fhm6-qw2q/GHSA-xx46-fhm6-qw2q.json | 12 +++--------- .../12/GHSA-53m8-xvh9-f42p/GHSA-53m8-xvh9-f42p.json | 4 +--- .../12/GHSA-544j-8m5v-3frm/GHSA-544j-8m5v-3frm.json | 4 +--- .../12/GHSA-5c39-hcvq-5xxc/GHSA-5c39-hcvq-5xxc.json | 4 +--- .../12/GHSA-5p79-g28m-p2cr/GHSA-5p79-g28m-p2cr.json | 4 +--- .../12/GHSA-8vqv-gv6p-pjjr/GHSA-8vqv-gv6p-pjjr.json | 4 +--- .../12/GHSA-f7fg-v9hq-5m57/GHSA-f7fg-v9hq-5m57.json | 4 +--- .../12/GHSA-fchc-223x-3cpc/GHSA-fchc-223x-3cpc.json | 4 +--- .../12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json | 4 +--- .../12/GHSA-m2x4-w9m7-wcwm/GHSA-m2x4-w9m7-wcwm.json | 4 +--- .../12/GHSA-m8q3-f9r8-5rqr/GHSA-m8q3-f9r8-5rqr.json | 4 +--- .../12/GHSA-ph8f-7wjw-g922/GHSA-ph8f-7wjw-g922.json | 4 +--- .../12/GHSA-q39q-7726-rg48/GHSA-q39q-7726-rg48.json | 4 +--- .../01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json | 4 +--- .../01/GHSA-237f-7hfc-5r9q/GHSA-237f-7hfc-5r9q.json | 4 +--- .../01/GHSA-243r-cwrc-8j8h/GHSA-243r-cwrc-8j8h.json | 4 +--- .../01/GHSA-28v3-9vqx-2v5f/GHSA-28v3-9vqx-2v5f.json | 4 +--- .../01/GHSA-3p9v-8h44-8rrr/GHSA-3p9v-8h44-8rrr.json | 4 +--- .../01/GHSA-48w7-7v5c-hxxv/GHSA-48w7-7v5c-hxxv.json | 4 +--- .../01/GHSA-4p53-c8jq-g93h/GHSA-4p53-c8jq-g93h.json | 4 +--- .../01/GHSA-4qr3-39h9-qwp4/GHSA-4qr3-39h9-qwp4.json | 4 +--- .../01/GHSA-4w9j-m79h-8w8m/GHSA-4w9j-m79h-8w8m.json | 4 +--- .../01/GHSA-4xhc-3779-5pc3/GHSA-4xhc-3779-5pc3.json | 4 +--- .../01/GHSA-5fp7-mmp5-2244/GHSA-5fp7-mmp5-2244.json | 4 +--- .../01/GHSA-5qjc-pfh5-rxg4/GHSA-5qjc-pfh5-rxg4.json | 4 +--- .../01/GHSA-62hr-4g8f-hg89/GHSA-62hr-4g8f-hg89.json | 4 +--- .../01/GHSA-6394-jqhh-rg8r/GHSA-6394-jqhh-rg8r.json | 4 +--- .../01/GHSA-64cg-x9wj-m2fx/GHSA-64cg-x9wj-m2fx.json | 4 +--- .../01/GHSA-67gv-rcgx-vp8h/GHSA-67gv-rcgx-vp8h.json | 4 +--- .../01/GHSA-6c7f-v79h-5rvh/GHSA-6c7f-v79h-5rvh.json | 4 +--- .../01/GHSA-747r-gwxx-f5r5/GHSA-747r-gwxx-f5r5.json | 4 +--- .../01/GHSA-7pqh-wvpp-vpr2/GHSA-7pqh-wvpp-vpr2.json | 4 +--- .../01/GHSA-7r7m-9r2x-mccm/GHSA-7r7m-9r2x-mccm.json | 4 +--- .../01/GHSA-8cxj-vc9j-xq64/GHSA-8cxj-vc9j-xq64.json | 4 +--- .../01/GHSA-8wjp-pfrg-xh9q/GHSA-8wjp-pfrg-xh9q.json | 4 +--- .../01/GHSA-94xr-33qr-qf6f/GHSA-94xr-33qr-qf6f.json | 4 +--- .../01/GHSA-9r6q-f96q-7hq4/GHSA-9r6q-f96q-7hq4.json | 4 +--- .../01/GHSA-c9p6-78wf-hfm7/GHSA-c9p6-78wf-hfm7.json | 4 +--- .../01/GHSA-cjcj-g2w6-gp9q/GHSA-cjcj-g2w6-gp9q.json | 4 +--- .../01/GHSA-cmvm-c7qf-pmc5/GHSA-cmvm-c7qf-pmc5.json | 4 +--- .../01/GHSA-fcf9-3423-25fj/GHSA-fcf9-3423-25fj.json | 4 +--- .../01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json | 4 +--- .../01/GHSA-g823-9xxv-px4q/GHSA-g823-9xxv-px4q.json | 4 +--- .../01/GHSA-gpvh-qv7g-wvjp/GHSA-gpvh-qv7g-wvjp.json | 4 +--- .../01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json | 4 +--- .../01/GHSA-h6qp-2x7h-7x2g/GHSA-h6qp-2x7h-7x2g.json | 4 +--- .../01/GHSA-h8wf-2g76-x8c2/GHSA-h8wf-2g76-x8c2.json | 4 +--- .../01/GHSA-hfw6-6cwm-fq2j/GHSA-hfw6-6cwm-fq2j.json | 4 +--- .../01/GHSA-hj4m-mcvw-qf65/GHSA-hj4m-mcvw-qf65.json | 4 +--- .../01/GHSA-hv4h-fc69-69wr/GHSA-hv4h-fc69-69wr.json | 4 +--- .../01/GHSA-j2fh-23pr-vj2r/GHSA-j2fh-23pr-vj2r.json | 4 +--- .../01/GHSA-j35w-mpg6-43xp/GHSA-j35w-mpg6-43xp.json | 4 +--- .../01/GHSA-jpfr-5xm6-9fr4/GHSA-jpfr-5xm6-9fr4.json | 4 +--- .../01/GHSA-p6cx-v2j5-9938/GHSA-p6cx-v2j5-9938.json | 4 +--- .../01/GHSA-phmh-wx44-p7vq/GHSA-phmh-wx44-p7vq.json | 4 +--- .../01/GHSA-pj35-9jc4-v6rm/GHSA-pj35-9jc4-v6rm.json | 4 +--- .../01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json | 4 +--- .../01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json | 8 ++------ .../01/GHSA-rq89-r32x-9rfg/GHSA-rq89-r32x-9rfg.json | 4 +--- .../01/GHSA-rrfh-8c6f-6grw/GHSA-rrfh-8c6f-6grw.json | 4 +--- .../01/GHSA-vg9h-xv3p-f55q/GHSA-vg9h-xv3p-f55q.json | 4 +--- .../01/GHSA-vw2p-6432-5hq4/GHSA-vw2p-6432-5hq4.json | 4 +--- .../01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json | 4 +--- .../01/GHSA-wfcq-ffhc-rj2g/GHSA-wfcq-ffhc-rj2g.json | 4 +--- .../01/GHSA-whgc-pmc8-wmv6/GHSA-whgc-pmc8-wmv6.json | 4 +--- .../01/GHSA-wvc8-26f6-r55r/GHSA-wvc8-26f6-r55r.json | 4 +--- .../01/GHSA-wvp8-6wrp-jww8/GHSA-wvp8-6wrp-jww8.json | 4 +--- .../01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json | 8 ++------ .../01/GHSA-xhxp-5wh5-qg3g/GHSA-xhxp-5wh5-qg3g.json | 4 +--- .../01/GHSA-xj3h-ghff-wj93/GHSA-xj3h-ghff-wj93.json | 4 +--- .../01/GHSA-xjg5-j24f-8p55/GHSA-xjg5-j24f-8p55.json | 4 +--- .../02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json | 4 +--- .../02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json | 4 +--- .../02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json | 4 +--- .../02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json | 4 +--- .../02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json | 4 +--- .../02/GHSA-4g85-9mh4-6cw4/GHSA-4g85-9mh4-6cw4.json | 4 +--- .../02/GHSA-4m9m-xf34-3q86/GHSA-4m9m-xf34-3q86.json | 4 +--- .../02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json | 8 ++------ .../02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json | 4 +--- .../02/GHSA-5qjc-vm5p-c74c/GHSA-5qjc-vm5p-c74c.json | 8 ++------ .../02/GHSA-5rxp-cqh3-j96r/GHSA-5rxp-cqh3-j96r.json | 8 ++------ .../02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json | 4 +--- .../02/GHSA-633w-9qcg-g8vx/GHSA-633w-9qcg-g8vx.json | 4 +--- .../02/GHSA-7hxq-xwr5-7997/GHSA-7hxq-xwr5-7997.json | 8 ++------ .../02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json | 8 ++------ .../02/GHSA-8x54-v777-7269/GHSA-8x54-v777-7269.json | 4 +--- .../02/GHSA-9qfj-r558-84rj/GHSA-9qfj-r558-84rj.json | 4 +--- .../02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json | 8 ++------ .../02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json | 4 +--- .../02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json | 4 +--- .../02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json | 4 +--- .../02/GHSA-cxpc-g33f-3fqv/GHSA-cxpc-g33f-3fqv.json | 4 +--- .../02/GHSA-f3x8-m359-fj94/GHSA-f3x8-m359-fj94.json | 4 +--- .../02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json | 4 +--- .../02/GHSA-ffch-mwmj-f7w4/GHSA-ffch-mwmj-f7w4.json | 4 +--- .../02/GHSA-fj2x-xhhp-fv9q/GHSA-fj2x-xhhp-fv9q.json | 4 +--- .../02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json | 4 +--- .../02/GHSA-jvf7-qpqh-8mxh/GHSA-jvf7-qpqh-8mxh.json | 4 +--- .../02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json | 4 +--- .../02/GHSA-m6h4-j5mx-hc72/GHSA-m6h4-j5mx-hc72.json | 4 +--- .../02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json | 4 +--- .../02/GHSA-p86q-cw52-gp9g/GHSA-p86q-cw52-gp9g.json | 4 +--- .../02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json | 4 +--- .../02/GHSA-qcj5-62mc-73xh/GHSA-qcj5-62mc-73xh.json | 4 +--- .../02/GHSA-qg7c-8rjw-52m9/GHSA-qg7c-8rjw-52m9.json | 4 +--- .../02/GHSA-qvrw-w6hg-g36x/GHSA-qvrw-w6hg-g36x.json | 4 +--- .../02/GHSA-r5pr-2qfg-vfr4/GHSA-r5pr-2qfg-vfr4.json | 4 +--- .../02/GHSA-r7ch-cwp4-rh7c/GHSA-r7ch-cwp4-rh7c.json | 4 +--- .../02/GHSA-rj48-qj2x-783m/GHSA-rj48-qj2x-783m.json | 4 +--- .../02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json | 4 +--- .../02/GHSA-w79r-9m7p-jmqr/GHSA-w79r-9m7p-jmqr.json | 8 ++------ .../02/GHSA-wv7f-jp7g-37rc/GHSA-wv7f-jp7g-37rc.json | 4 +--- .../05/GHSA-47q6-hqqr-mcr3/GHSA-47q6-hqqr-mcr3.json | 8 ++------ .../05/GHSA-hfhf-22gm-76w3/GHSA-hfhf-22gm-76w3.json | 4 +--- .../05/GHSA-pv8h-p384-hhr9/GHSA-pv8h-p384-hhr9.json | 4 +--- .../04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json | 12 +++--------- .../04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json | 12 +++--------- .../04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json | 12 +++--------- .../04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json | 12 +++--------- .../04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json | 12 +++--------- .../04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json | 12 +++--------- .../04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json | 12 +++--------- .../04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json | 12 +++--------- .../04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json | 12 +++--------- .../05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json | 12 +++--------- .../05/GHSA-49cj-cqm8-6m92/GHSA-49cj-cqm8-6m92.json | 12 +++--------- .../05/GHSA-8gpf-qj7v-hp3f/GHSA-8gpf-qj7v-hp3f.json | 12 +++--------- .../05/GHSA-w2x6-62q8-xq6c/GHSA-w2x6-62q8-xq6c.json | 12 +++--------- .../07/GHSA-8754-873p-mcq7/GHSA-8754-873p-mcq7.json | 8 ++------ .../07/GHSA-c462-f76h-gqhf/GHSA-c462-f76h-gqhf.json | 8 ++------ .../07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json | 8 ++------ .../07/GHSA-j4rf-jc84-8583/GHSA-j4rf-jc84-8583.json | 8 ++------ .../07/GHSA-rr6f-mqf5-f7wc/GHSA-rr6f-mqf5-f7wc.json | 8 ++------ .../08/GHSA-c9x2-m7q5-frxf/GHSA-c9x2-m7q5-frxf.json | 4 +--- 879 files changed, 1725 insertions(+), 5175 deletions(-) diff --git a/advisories/github-reviewed/2021/05/GHSA-2c64-vj8g-vwrq/GHSA-2c64-vj8g-vwrq.json b/advisories/github-reviewed/2021/05/GHSA-2c64-vj8g-vwrq/GHSA-2c64-vj8g-vwrq.json index 8ec85dc9e05..0a75f043211 100644 --- a/advisories/github-reviewed/2021/05/GHSA-2c64-vj8g-vwrq/GHSA-2c64-vj8g-vwrq.json +++ b/advisories/github-reviewed/2021/05/GHSA-2c64-vj8g-vwrq/GHSA-2c64-vj8g-vwrq.json @@ -3,14 +3,10 @@ "id": "GHSA-2c64-vj8g-vwrq", "modified": "2023-08-29T22:08:18Z", "published": "2021-05-21T16:11:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "Incorrect handling of credential expiry by /nats-io/nats-server", "details": "(This advisory is canonically https://advisories.nats.io/CVE/CVE-2020-26892.txt )\n\n## Problem Description\n\nNATS nats-server through 2020-10-07 has Incorrect Access Control because of how expired credentials are handled.\n\nThe NATS accounts system has expiration timestamps on credentials; the library had an API which encouraged misuse and an `IsRevoked()` method which misused its own API.\n\nA new `IsClaimRevoked()` method has correct handling and the nats-server has been updated to use this. The old `IsRevoked()` method now always returns true and other client code will have to be updated to avoid calling it.\n\nThe CVE identifier should cover any application using the old JWT API, where the nats-server is one of those applications.\n\n\n## Affected versions\n\n#### JWT library\n\n * all versions prior to 1.1.0\n * fixed after nats-io/jwt PR 103 landed (2020-10-06)\n\n#### NATS Server\n\n * Version 2 prior to 2.1.9\n + 2.0.0 through and including 2.1.8 are vulnerable.\n * fixed with nats-io/nats-server PRs 1632, 1635, 1645\n\n\n## Impact\n\nTime-based credential expiry did not work.\n\n\n## Workaround\n\nHave credentials which only expire after fixes can be deployed.\n\n\n## Solution\n\nUpgrade the JWT dependency in any application using it.\n\nUpgrade the NATS server if using NATS Accounts.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/01/GHSA-8w54-22w9-3g8f/GHSA-8w54-22w9-3g8f.json b/advisories/github-reviewed/2022/01/GHSA-8w54-22w9-3g8f/GHSA-8w54-22w9-3g8f.json index 4132e12951e..361c1d5a679 100644 --- a/advisories/github-reviewed/2022/01/GHSA-8w54-22w9-3g8f/GHSA-8w54-22w9-3g8f.json +++ b/advisories/github-reviewed/2022/01/GHSA-8w54-22w9-3g8f/GHSA-8w54-22w9-3g8f.json @@ -3,9 +3,7 @@ "id": "GHSA-8w54-22w9-3g8f", "modified": "2022-01-31T20:25:54Z", "published": "2022-01-28T23:10:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "Cross-site Scripting and Open Redirect in Products.CMFPlone", "details": "### Impact\nPlone is vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the image_view_fullscreen page in a cache, for example in Varnish.\nThe technique is known as cache poisoning.\nAny later visitor can get redirected when clicking on a link on this page.\nUsually only anonymous users are affected, but this depends on your cache settings.\n\n### Patches\nNo patch is available for the Products.CMFPlone 4 series.\nVersions 5.0 and higher are not affected, but two other packages used by these versions are affected.\n\n`plone.app.contenttypes` has the same problem in all versions, see [advisory](https://github.com/plone/plone.app.contenttypes/security/advisories/GHSA-f7qw-5fgj-247x).\nIn Plone 5.0-5.2, the default Products.ATContentTypes version has the same problem. See [advisory](https://github.com/plone/Products.ATContentTypes/security/advisories/GHSA-g4c2-ghfg-g5rh).\nPlone 5.2.7 and 6.0.0a3 will be released today and will include these fixes.\n\nFor all unpatched versions of the three packages, you can use the following workaround.\n\n### Workaround\nMake sure the image_view_fullscreen page is not stored in the cache.\nIn Plone:\n\n* Login as Manager and go to Site Setup.\n* Go to the 'Caching' control panel. If this does not exist, or 'Enable caching' is not checked, you should normally not be vulnerable.\n* Click on the tab 'Caching operations'.\n* Under 'Legacy template mappings' locate the ruleset 'Content item view'.\n* From the last column ('Templates') remove 'image_view_fullscreen'.\n* Click on Save.\n\n### Reporter\nThis vulnerability was responsibly disclosed to the Plone Security Team by Gustav Hansen, F-Secure Consulting. Thank you!\n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@plone.org](mailto:security@plone.org)\nThis is also the correct address to use when you want to report a possible vulnerability.\nSee [our security report policy](https://plone.org/security/report).", "severity": [ diff --git a/advisories/github-reviewed/2022/02/GHSA-43q8-3fv7-pr5x/GHSA-43q8-3fv7-pr5x.json b/advisories/github-reviewed/2022/02/GHSA-43q8-3fv7-pr5x/GHSA-43q8-3fv7-pr5x.json index cb7de75325c..2aeacde743b 100644 --- a/advisories/github-reviewed/2022/02/GHSA-43q8-3fv7-pr5x/GHSA-43q8-3fv7-pr5x.json +++ b/advisories/github-reviewed/2022/02/GHSA-43q8-3fv7-pr5x/GHSA-43q8-3fv7-pr5x.json @@ -3,9 +3,7 @@ "id": "GHSA-43q8-3fv7-pr5x", "modified": "2022-02-03T23:10:42Z", "published": "2022-02-09T23:37:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Validation of Integrity Check Value in TensorFlow", "details": "### Impact\nThe implementation of [`tf.sparse.split`](https://github.com/tensorflow/tensorflow/blob/5100e359aef5c8021f2e71c7b986420b85ce7b3d/tensorflow/core/kernels/sparse_split_op.cc#L26-L102) does not fully validate the input arguments. Hence, a malicious user can trigger a denial of service via a segfault or a heap OOB read:\n\n```python\nimport tensorflow as tf\ndata = tf.random.uniform([1, 32, 32], dtype=tf.float32)\naxis = [1, 2]\nx = tf.sparse.from_dense(data)\nresult = tf.sparse.split(x,3, axis=axis)\n```\nThe code assumes `axis` is a scalar. This is another instance of [TFSA-2021-190](https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2021-190.md) (CVE-2021-41206).\n\n### Patches\nWe have patched the issue in GitHub commit [61bf91e768173b001d56923600b40d9a95a04ad5](https://github.com/tensorflow/tensorflow/commit/61bf91e768173b001d56923600b40d9a95a04ad5) (merging [#53695](https://github.com/tensorflow/tensorflow/pull/53695)).\n\nThe fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.\n\n### Attribution\nThis vulnerability has been reported externally via a [GitHub issue](https://github.com/tensorflow/tensorflow/issues/53660).", "severity": [ diff --git a/advisories/github-reviewed/2022/02/GHSA-64q9-f38h-9mwx/GHSA-64q9-f38h-9mwx.json b/advisories/github-reviewed/2022/02/GHSA-64q9-f38h-9mwx/GHSA-64q9-f38h-9mwx.json index 42d7be0d620..2d13f51067c 100644 --- a/advisories/github-reviewed/2022/02/GHSA-64q9-f38h-9mwx/GHSA-64q9-f38h-9mwx.json +++ b/advisories/github-reviewed/2022/02/GHSA-64q9-f38h-9mwx/GHSA-64q9-f38h-9mwx.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-02-24T17:31:28Z", diff --git a/advisories/github-reviewed/2022/02/GHSA-f7qw-5fgj-247x/GHSA-f7qw-5fgj-247x.json b/advisories/github-reviewed/2022/02/GHSA-f7qw-5fgj-247x/GHSA-f7qw-5fgj-247x.json index 4c741e4c269..5ce9c2b9773 100644 --- a/advisories/github-reviewed/2022/02/GHSA-f7qw-5fgj-247x/GHSA-f7qw-5fgj-247x.json +++ b/advisories/github-reviewed/2022/02/GHSA-f7qw-5fgj-247x/GHSA-f7qw-5fgj-247x.json @@ -3,9 +3,7 @@ "id": "GHSA-f7qw-5fgj-247x", "modified": "2022-01-31T19:08:58Z", "published": "2022-02-01T00:48:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "Cross-site Scripting and Open Redirect in plone.app.contenttypes", "details": "### Impact\nPlone is vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the image_view_fullscreen page in a cache, for example in Varnish.\nThe technique is known as cache poisoning.\nAny later visitor can get redirected when clicking on a link on this page.\nUsually only anonymous users are affected, but this depends on your cache settings.\n\n### Patches\nNew versions of plone.app.contenttypes have been released.\nVersion 2.2.3 works on Plone 5.2 and will be included in Plone 5.2.7.\nVersion 3.0.0a9 works on Plone 6 and will be included in Plone 6.0.0a3.\n\nNote that the Products.CMFPlone package has the same problem in the 4.3 series.\nIn Plone 5.0-5.2, the default Products.ATContentTypes version has the same problem. See [advisory](https://github.com/plone/Products.ATContentTypes/security/advisories/GHSA-g4c2-ghfg-g5rh).\nFor all unpatched versions of the three packages, you can use the following workaround.\n\n### Workaround\nMake sure the image_view_fullscreen page is not stored in the cache.\nIn Plone:\n\n* Login as Manager and go to Site Setup.\n* Go to the 'Caching' control panel. If this does not exist, or 'Enable caching' is not checked, you should normally not be vulnerable.\n* Click on the tab 'Caching operations'.\n* Under 'Legacy template mappings' locate the ruleset 'Content item view'.\n* From the last column ('Templates') remove 'image_view_fullscreen'.\n* Click on Save.\n\n### Reporter\nThis vulnerability was responsibly disclosed to the Plone Security Team by Gustav Hansen, F-Secure Consulting. Thank you!\n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@plone.org](mailto:security@plone.org)\nThis is also the correct address to use when you want to report a possible vulnerability.\nSee [our security report policy](https://plone.org/security/report).", "severity": [ diff --git a/advisories/github-reviewed/2022/02/GHSA-g9mp-8g3h-3c5c/GHSA-g9mp-8g3h-3c5c.json b/advisories/github-reviewed/2022/02/GHSA-g9mp-8g3h-3c5c/GHSA-g9mp-8g3h-3c5c.json index 0f9003f8a33..0e3fc788859 100644 --- a/advisories/github-reviewed/2022/02/GHSA-g9mp-8g3h-3c5c/GHSA-g9mp-8g3h-3c5c.json +++ b/advisories/github-reviewed/2022/02/GHSA-g9mp-8g3h-3c5c/GHSA-g9mp-8g3h-3c5c.json @@ -3,14 +3,10 @@ "id": "GHSA-g9mp-8g3h-3c5c", "modified": "2023-08-29T20:07:14Z", "published": "2022-02-15T01:57:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "flynn/noise has improper nonce handling yielding potential state DoS", "details": "The Go package `github.com/flynn/noise`, a [Noise Protocol](https://noiseprotocol.org/) implementation, has two bugs in nonce handling in versions prior to v1.0.0.\n\n### Issue 1: Potential nonce overflow\n\nIf 264 (~18.4 quintillion) or more messages are encrypted with `Encrypt` after handshaking, the nonce counter will wrap around, causing multiple messages to be encrypted with the same key and nonce, resulting in a potentially catastrophic weakening of the security properties of the symmetric cipher.\n\nThis has been resolved in the patched version by returning `ErrMaxNonce` from the `CipherState` `Encrypt` and `Decrypt` methods before the reserved maximum nonce is reached. If this error is encountered, the program should handshake again to start with a fresh `CipherState`.\n\n### Issue 2: Potential denial of service via invalid ciphertext\n\nIf an attacker sends an invalid ciphertext into one peer's `Decrypt`, the nonce is incremented unconditionally. This causes a desync of the `CipherState` due to a nonce mismatch between the peers, resulting in a failure to decrypt all subsequent messages. A new handshake will be required to establish a new `CipherState`.\n\nThis has been resolved in the patched version by returning authentication errors from `Decrypt` before incrementing the nonce. \n\n### Patches\n\nFixed in https://github.com/flynn/noise/pull/44, tagged as v1.0.0.\n\n### Acknowledgements\n\nThese issues were discovered during [an audit](https://www.bamsoftware.com/software/dnstt/cure53-turbotunnel-2021.pdf) of a user of this package ([dnstt](https://www.bamsoftware.com/software/dnstt/)). Thanks to UC Berkley for commissioning the audit, and to David Fifield and Nathan Brown for their collaboration on the fixes. The fixed issues are noted in the audit as:\n\n* UCB-02-003 Potential nonce overflow in Noise protocol\n* UCB-02-006 DoS due to unconditional nonce increment", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-05-18T21:46:19Z", diff --git a/advisories/github-reviewed/2022/02/GHSA-h6gw-r52c-724r/GHSA-h6gw-r52c-724r.json b/advisories/github-reviewed/2022/02/GHSA-h6gw-r52c-724r/GHSA-h6gw-r52c-724r.json index e6478f75b14..c9696a9af38 100644 --- a/advisories/github-reviewed/2022/02/GHSA-h6gw-r52c-724r/GHSA-h6gw-r52c-724r.json +++ b/advisories/github-reviewed/2022/02/GHSA-h6gw-r52c-724r/GHSA-h6gw-r52c-724r.json @@ -3,9 +3,7 @@ "id": "GHSA-h6gw-r52c-724r", "modified": "2022-02-03T23:09:44Z", "published": "2022-02-09T23:38:36Z", - "aliases": [ - - ], + "aliases": [], "summary": "NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow", "details": "### Impact \nThe [code for boosted trees in TensorFlow](https://github.com/tensorflow/tensorflow/blob/e0b6e58c328059829c3eb968136f17aa72b6c876/tensorflow/core/kernels/boosted_trees/stats_ops.cc) is still missing validation. This allows malicious users to read and write outside of bounds of heap allocated data as well as trigger denial of service (via dereferencing `nullptr`s or via `CHECK`-failures).\n\nThis follows after CVE-2021-41208 where these APIs were still vulnerable to multiple security issues.\n\n**Note**: Given that the boosted trees implementation in TensorFlow is unmaintained, it is recommend to no longer use these APIs. Instead, please use the downstream [TensorFlow Decision Forests](https://github.com/tensorflow/decision-forests) project which is newer and supports more features. \n \nThese APIs are now deprecated in TensorFlow 2.8. We will remove TensorFlow's boosted trees APIs in subsequent releases.\n \n### Patches\nWe have patched the known issues in multiple GitHub commits.\n \nThe fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.\n\nThis should allow users to use existing boosted trees APIs for a while until they migrate to [TensorFlow Decision Forests](https://github.com/tensorflow/decision-forests), while guaranteeing that known vulnerabilities are fixed.\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.\n\n### Attribution\nThese vulnerabilities have been reported by Yu Tian of Qihoo 360 AIVul Team and Faysal Hossain Shezan from University of Virginia. Some of the issues have been discovered internally after a careful audit of the APIs.", "severity": [ diff --git a/advisories/github-reviewed/2022/02/GHSA-wcv5-vrvr-3rx2/GHSA-wcv5-vrvr-3rx2.json b/advisories/github-reviewed/2022/02/GHSA-wcv5-vrvr-3rx2/GHSA-wcv5-vrvr-3rx2.json index 9604c37172d..02215c11f46 100644 --- a/advisories/github-reviewed/2022/02/GHSA-wcv5-vrvr-3rx2/GHSA-wcv5-vrvr-3rx2.json +++ b/advisories/github-reviewed/2022/02/GHSA-wcv5-vrvr-3rx2/GHSA-wcv5-vrvr-3rx2.json @@ -3,9 +3,7 @@ "id": "GHSA-wcv5-vrvr-3rx2", "modified": "2022-02-03T23:13:13Z", "published": "2022-02-09T23:34:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Integer Overflow or Wraparound in TensorFlow", "details": "### Impact\nThe Grappler component of TensorFlow is vulnerable to a denial of service via `CHECK`-failure (assertion failure) in [constant folding](https://github.com/tensorflow/tensorflow/blob/a1320ec1eac186da1d03f033109191f715b2b130/tensorflow/core/grappler/optimizers/constant_folding.cc#L963-L1035):\n\n```cc\n for (const auto& output_prop : output_props) {\n const PartialTensorShape output_shape(output_prop.shape());\n // ...\n }\n```\n \nThe `output_prop` tensor has a shape that is controlled by user input and this can result in triggering one of the `CHECK`s in the `PartialTensorShape` constructor. This is an instance of [TFSA-2021-198](https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2021-198.md) (CVE-2021-41197).\n\n### Patches\nWe have patched the issue in GitHub commit [be7b286d40bc68cb0b56f702186cc4837d508058](https://github.com/tensorflow/tensorflow/commit/be7b286d40bc68cb0b56f702186cc4837d508058).\n\nThe fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.", "severity": [ diff --git a/advisories/github-reviewed/2022/05/GHSA-2gh8-gr6x-7q26/GHSA-2gh8-gr6x-7q26.json b/advisories/github-reviewed/2022/05/GHSA-2gh8-gr6x-7q26/GHSA-2gh8-gr6x-7q26.json index 677f0bcf854..801977ae0be 100644 --- a/advisories/github-reviewed/2022/05/GHSA-2gh8-gr6x-7q26/GHSA-2gh8-gr6x-7q26.json +++ b/advisories/github-reviewed/2022/05/GHSA-2gh8-gr6x-7q26/GHSA-2gh8-gr6x-7q26.json @@ -8,9 +8,7 @@ ], "summary": "SOAPpy vulnerable to XXE attacks", "details": "SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-92cv-wv2c-8899/GHSA-92cv-wv2c-8899.json b/advisories/github-reviewed/2022/05/GHSA-92cv-wv2c-8899/GHSA-92cv-wv2c-8899.json index eb60ba5d0cc..6d1a748807e 100644 --- a/advisories/github-reviewed/2022/05/GHSA-92cv-wv2c-8899/GHSA-92cv-wv2c-8899.json +++ b/advisories/github-reviewed/2022/05/GHSA-92cv-wv2c-8899/GHSA-92cv-wv2c-8899.json @@ -8,9 +8,7 @@ ], "summary": "Apache MyFaces Cross-site Scripting vulnerability", "details": "Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-mg4v-rf8p-ghqq/GHSA-mg4v-rf8p-ghqq.json b/advisories/github-reviewed/2022/05/GHSA-mg4v-rf8p-ghqq/GHSA-mg4v-rf8p-ghqq.json index 743e4bf5a92..1983db552a7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mg4v-rf8p-ghqq/GHSA-mg4v-rf8p-ghqq.json +++ b/advisories/github-reviewed/2022/05/GHSA-mg4v-rf8p-ghqq/GHSA-mg4v-rf8p-ghqq.json @@ -8,9 +8,7 @@ ], "summary": "Apache Tomcat allows remote attackers to bypass intended access restrictions", "details": "Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -183,9 +181,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-27T21:57:25Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-mmjh-45vj-hfvf/GHSA-mmjh-45vj-hfvf.json b/advisories/github-reviewed/2022/05/GHSA-mmjh-45vj-hfvf/GHSA-mmjh-45vj-hfvf.json index dccf3d463f8..f2517560db5 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mmjh-45vj-hfvf/GHSA-mmjh-45vj-hfvf.json +++ b/advisories/github-reviewed/2022/05/GHSA-mmjh-45vj-hfvf/GHSA-mmjh-45vj-hfvf.json @@ -8,9 +8,7 @@ ], "summary": "Dojo Open Redirect vulnerability", "details": "Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-wv88-pf73-x22p/GHSA-wv88-pf73-x22p.json b/advisories/github-reviewed/2022/05/GHSA-wv88-pf73-x22p/GHSA-wv88-pf73-x22p.json index 30651f02c5d..48c9fbbcc9f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-wv88-pf73-x22p/GHSA-wv88-pf73-x22p.json +++ b/advisories/github-reviewed/2022/05/GHSA-wv88-pf73-x22p/GHSA-wv88-pf73-x22p.json @@ -8,9 +8,7 @@ ], "summary": "Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework", "details": "VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka \"Expression Language Injection.\"", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -147,9 +145,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-07-13T17:45:52Z", diff --git a/advisories/github-reviewed/2023/01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json b/advisories/github-reviewed/2023/01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json index 07fe54b1e4f..b26062b9fd1 100644 --- a/advisories/github-reviewed/2023/01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json +++ b/advisories/github-reviewed/2023/01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json @@ -3,14 +3,10 @@ "id": "GHSA-636f-xm5j-pj9m", "modified": "2023-01-24T18:12:17Z", "published": "2023-01-24T18:12:17Z", - "aliases": [ - - ], + "aliases": [], "summary": "Several quadratic complexity bugs may lead to denial of service in Commonmarker", "details": "## Impact\n\nSeveral quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.\n\nThe following vulnerabilities were addressed:\n\n* [CVE-2023-22483](https://github.com/github/cmark-gfm/security/advisories/GHSA-29g3-96g3-jg6c)\n* [CVE-2023-22484](https://github.com/github/cmark-gfm/security/advisories/GHSA-24f7-9frr-5h2r)\n* [CVE-2023-22485](https://github.com/github/cmark-gfm/security/advisories/GHSA-c944-cv5f-hpvr)\n* [CVE-2023-22486](https://github.com/github/cmark-gfm/security/advisories/GHSA-r572-jvj2-3m8p)\n\nFor more information, consult the release notes for version [`0.23.0.gfm.7`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.7).\n\n## Mitigation\n\nUsers are advised to upgrade to commonmarker version [`0.23.7`](https://rubygems.org/gems/commonmarker/versions/0.23.7).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json b/advisories/github-reviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json index d3c26d0403c..841f7851c10 100644 --- a/advisories/github-reviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json +++ b/advisories/github-reviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json @@ -54,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-05-22T19:37:12Z", diff --git a/advisories/unreviewed/2021/12/GHSA-2c7f-7v62-c4p8/GHSA-2c7f-7v62-c4p8.json b/advisories/unreviewed/2021/12/GHSA-2c7f-7v62-c4p8/GHSA-2c7f-7v62-c4p8.json index 45eaef9d677..fb3c5c2c133 100644 --- a/advisories/unreviewed/2021/12/GHSA-2c7f-7v62-c4p8/GHSA-2c7f-7v62-c4p8.json +++ b/advisories/unreviewed/2021/12/GHSA-2c7f-7v62-c4p8/GHSA-2c7f-7v62-c4p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2fjf-4mmg-2c65/GHSA-2fjf-4mmg-2c65.json b/advisories/unreviewed/2021/12/GHSA-2fjf-4mmg-2c65/GHSA-2fjf-4mmg-2c65.json index 8db67646854..ddd2eb3a81b 100644 --- a/advisories/unreviewed/2021/12/GHSA-2fjf-4mmg-2c65/GHSA-2fjf-4mmg-2c65.json +++ b/advisories/unreviewed/2021/12/GHSA-2fjf-4mmg-2c65/GHSA-2fjf-4mmg-2c65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-2vm6-24x2-fw9m/GHSA-2vm6-24x2-fw9m.json b/advisories/unreviewed/2021/12/GHSA-2vm6-24x2-fw9m/GHSA-2vm6-24x2-fw9m.json index 816b1384b4f..6bc55a4eaf3 100644 --- a/advisories/unreviewed/2021/12/GHSA-2vm6-24x2-fw9m/GHSA-2vm6-24x2-fw9m.json +++ b/advisories/unreviewed/2021/12/GHSA-2vm6-24x2-fw9m/GHSA-2vm6-24x2-fw9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-7gx6-8phm-v624/GHSA-7gx6-8phm-v624.json b/advisories/unreviewed/2021/12/GHSA-7gx6-8phm-v624/GHSA-7gx6-8phm-v624.json index c5ab3d17872..d92eb4b873e 100644 --- a/advisories/unreviewed/2021/12/GHSA-7gx6-8phm-v624/GHSA-7gx6-8phm-v624.json +++ b/advisories/unreviewed/2021/12/GHSA-7gx6-8phm-v624/GHSA-7gx6-8phm-v624.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-8xwq-gmgr-vq48/GHSA-8xwq-gmgr-vq48.json b/advisories/unreviewed/2021/12/GHSA-8xwq-gmgr-vq48/GHSA-8xwq-gmgr-vq48.json index 63f6990eb14..64938c40d1e 100644 --- a/advisories/unreviewed/2021/12/GHSA-8xwq-gmgr-vq48/GHSA-8xwq-gmgr-vq48.json +++ b/advisories/unreviewed/2021/12/GHSA-8xwq-gmgr-vq48/GHSA-8xwq-gmgr-vq48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-9983-gjwx-g47w/GHSA-9983-gjwx-g47w.json b/advisories/unreviewed/2021/12/GHSA-9983-gjwx-g47w/GHSA-9983-gjwx-g47w.json index c7ba05dea44..68fed904021 100644 --- a/advisories/unreviewed/2021/12/GHSA-9983-gjwx-g47w/GHSA-9983-gjwx-g47w.json +++ b/advisories/unreviewed/2021/12/GHSA-9983-gjwx-g47w/GHSA-9983-gjwx-g47w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-c439-xxv3-pcx2/GHSA-c439-xxv3-pcx2.json b/advisories/unreviewed/2021/12/GHSA-c439-xxv3-pcx2/GHSA-c439-xxv3-pcx2.json index a8989eb597d..947a9d203b3 100644 --- a/advisories/unreviewed/2021/12/GHSA-c439-xxv3-pcx2/GHSA-c439-xxv3-pcx2.json +++ b/advisories/unreviewed/2021/12/GHSA-c439-xxv3-pcx2/GHSA-c439-xxv3-pcx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-cj6g-97j4-jw5f/GHSA-cj6g-97j4-jw5f.json b/advisories/unreviewed/2021/12/GHSA-cj6g-97j4-jw5f/GHSA-cj6g-97j4-jw5f.json index 9c774fa8d05..d7e3a3f480e 100644 --- a/advisories/unreviewed/2021/12/GHSA-cj6g-97j4-jw5f/GHSA-cj6g-97j4-jw5f.json +++ b/advisories/unreviewed/2021/12/GHSA-cj6g-97j4-jw5f/GHSA-cj6g-97j4-jw5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-g3vr-f28g-hxqc/GHSA-g3vr-f28g-hxqc.json b/advisories/unreviewed/2021/12/GHSA-g3vr-f28g-hxqc/GHSA-g3vr-f28g-hxqc.json index e3d344ba7af..d405e510712 100644 --- a/advisories/unreviewed/2021/12/GHSA-g3vr-f28g-hxqc/GHSA-g3vr-f28g-hxqc.json +++ b/advisories/unreviewed/2021/12/GHSA-g3vr-f28g-hxqc/GHSA-g3vr-f28g-hxqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h8g4-jwjc-gf58/GHSA-h8g4-jwjc-gf58.json b/advisories/unreviewed/2021/12/GHSA-h8g4-jwjc-gf58/GHSA-h8g4-jwjc-gf58.json index 918ee2a886c..42e2f72eaa2 100644 --- a/advisories/unreviewed/2021/12/GHSA-h8g4-jwjc-gf58/GHSA-h8g4-jwjc-gf58.json +++ b/advisories/unreviewed/2021/12/GHSA-h8g4-jwjc-gf58/GHSA-h8g4-jwjc-gf58.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-h8wr-fwj5-f4pv/GHSA-h8wr-fwj5-f4pv.json b/advisories/unreviewed/2021/12/GHSA-h8wr-fwj5-f4pv/GHSA-h8wr-fwj5-f4pv.json index f208b4b2b3f..1a1e226fabf 100644 --- a/advisories/unreviewed/2021/12/GHSA-h8wr-fwj5-f4pv/GHSA-h8wr-fwj5-f4pv.json +++ b/advisories/unreviewed/2021/12/GHSA-h8wr-fwj5-f4pv/GHSA-h8wr-fwj5-f4pv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2021/12/GHSA-p6g3-6g2v-fwvr/GHSA-p6g3-6g2v-fwvr.json b/advisories/unreviewed/2021/12/GHSA-p6g3-6g2v-fwvr/GHSA-p6g3-6g2v-fwvr.json index 739234e0adc..7415ff2c118 100644 --- a/advisories/unreviewed/2021/12/GHSA-p6g3-6g2v-fwvr/GHSA-p6g3-6g2v-fwvr.json +++ b/advisories/unreviewed/2021/12/GHSA-p6g3-6g2v-fwvr/GHSA-p6g3-6g2v-fwvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-q75w-8h5p-w5j9/GHSA-q75w-8h5p-w5j9.json b/advisories/unreviewed/2021/12/GHSA-q75w-8h5p-w5j9/GHSA-q75w-8h5p-w5j9.json index dd55c1510fd..073cb53bc94 100644 --- a/advisories/unreviewed/2021/12/GHSA-q75w-8h5p-w5j9/GHSA-q75w-8h5p-w5j9.json +++ b/advisories/unreviewed/2021/12/GHSA-q75w-8h5p-w5j9/GHSA-q75w-8h5p-w5j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-rvmf-qfpg-9qgj/GHSA-rvmf-qfpg-9qgj.json b/advisories/unreviewed/2021/12/GHSA-rvmf-qfpg-9qgj/GHSA-rvmf-qfpg-9qgj.json index 53ed4789b7c..89065832029 100644 --- a/advisories/unreviewed/2021/12/GHSA-rvmf-qfpg-9qgj/GHSA-rvmf-qfpg-9qgj.json +++ b/advisories/unreviewed/2021/12/GHSA-rvmf-qfpg-9qgj/GHSA-rvmf-qfpg-9qgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wc47-ghmc-28v7/GHSA-wc47-ghmc-28v7.json b/advisories/unreviewed/2021/12/GHSA-wc47-ghmc-28v7/GHSA-wc47-ghmc-28v7.json index 82d00c78aec..5208839a4d9 100644 --- a/advisories/unreviewed/2021/12/GHSA-wc47-ghmc-28v7/GHSA-wc47-ghmc-28v7.json +++ b/advisories/unreviewed/2021/12/GHSA-wc47-ghmc-28v7/GHSA-wc47-ghmc-28v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-wf45-6876-33mc/GHSA-wf45-6876-33mc.json b/advisories/unreviewed/2021/12/GHSA-wf45-6876-33mc/GHSA-wf45-6876-33mc.json index f344bc8aaf2..fd6b03873d0 100644 --- a/advisories/unreviewed/2021/12/GHSA-wf45-6876-33mc/GHSA-wf45-6876-33mc.json +++ b/advisories/unreviewed/2021/12/GHSA-wf45-6876-33mc/GHSA-wf45-6876-33mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-xpw4-2478-wj8x/GHSA-xpw4-2478-wj8x.json b/advisories/unreviewed/2021/12/GHSA-xpw4-2478-wj8x/GHSA-xpw4-2478-wj8x.json index e9f05ed506e..fe75d59c722 100644 --- a/advisories/unreviewed/2021/12/GHSA-xpw4-2478-wj8x/GHSA-xpw4-2478-wj8x.json +++ b/advisories/unreviewed/2021/12/GHSA-xpw4-2478-wj8x/GHSA-xpw4-2478-wj8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2jg4-p688-m2mm/GHSA-2jg4-p688-m2mm.json b/advisories/unreviewed/2022/01/GHSA-2jg4-p688-m2mm/GHSA-2jg4-p688-m2mm.json index 1f3804816a1..bd8c7aec5d7 100644 --- a/advisories/unreviewed/2022/01/GHSA-2jg4-p688-m2mm/GHSA-2jg4-p688-m2mm.json +++ b/advisories/unreviewed/2022/01/GHSA-2jg4-p688-m2mm/GHSA-2jg4-p688-m2mm.json @@ -7,12 +7,8 @@ "CVE-2021-46447" ], "details": "A cross-site scripting (XSS) vulnerability in H.H.G Multistore v5.1.0 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the State parameter under the Address Book module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2r36-2m2v-4gwc/GHSA-2r36-2m2v-4gwc.json b/advisories/unreviewed/2022/01/GHSA-2r36-2m2v-4gwc/GHSA-2r36-2m2v-4gwc.json index 602cea2cf4d..1960d9d395f 100644 --- a/advisories/unreviewed/2022/01/GHSA-2r36-2m2v-4gwc/GHSA-2r36-2m2v-4gwc.json +++ b/advisories/unreviewed/2022/01/GHSA-2r36-2m2v-4gwc/GHSA-2r36-2m2v-4gwc.json @@ -7,12 +7,8 @@ "CVE-2022-22828" ], "details": "An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2r4c-mwv9-xcr6/GHSA-2r4c-mwv9-xcr6.json b/advisories/unreviewed/2022/01/GHSA-2r4c-mwv9-xcr6/GHSA-2r4c-mwv9-xcr6.json index 54368365b86..7e68eff1320 100644 --- a/advisories/unreviewed/2022/01/GHSA-2r4c-mwv9-xcr6/GHSA-2r4c-mwv9-xcr6.json +++ b/advisories/unreviewed/2022/01/GHSA-2r4c-mwv9-xcr6/GHSA-2r4c-mwv9-xcr6.json @@ -7,12 +7,8 @@ "CVE-2021-46502" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5166d. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-2rqf-4qh6-w5pg/GHSA-2rqf-4qh6-w5pg.json b/advisories/unreviewed/2022/01/GHSA-2rqf-4qh6-w5pg/GHSA-2rqf-4qh6-w5pg.json index df5d75dad9c..67b0179265c 100644 --- a/advisories/unreviewed/2022/01/GHSA-2rqf-4qh6-w5pg/GHSA-2rqf-4qh6-w5pg.json +++ b/advisories/unreviewed/2022/01/GHSA-2rqf-4qh6-w5pg/GHSA-2rqf-4qh6-w5pg.json @@ -7,12 +7,8 @@ "CVE-2021-46538" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_compact_strings at src/mjs_gc.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-2v2h-p3pv-rrr5/GHSA-2v2h-p3pv-rrr5.json b/advisories/unreviewed/2022/01/GHSA-2v2h-p3pv-rrr5/GHSA-2v2h-p3pv-rrr5.json index b15fcecdf58..a422ea105fb 100644 --- a/advisories/unreviewed/2022/01/GHSA-2v2h-p3pv-rrr5/GHSA-2v2h-p3pv-rrr5.json +++ b/advisories/unreviewed/2022/01/GHSA-2v2h-p3pv-rrr5/GHSA-2v2h-p3pv-rrr5.json @@ -7,12 +7,8 @@ "CVE-2021-44120" ], "details": "SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The \"Who are you\" and \"Website Name\" fields are vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-328j-4f66-23cq/GHSA-328j-4f66-23cq.json b/advisories/unreviewed/2022/01/GHSA-328j-4f66-23cq/GHSA-328j-4f66-23cq.json index d1fb5fd6f1e..e182fb6171d 100644 --- a/advisories/unreviewed/2022/01/GHSA-328j-4f66-23cq/GHSA-328j-4f66-23cq.json +++ b/advisories/unreviewed/2022/01/GHSA-328j-4f66-23cq/GHSA-328j-4f66-23cq.json @@ -7,12 +7,8 @@ "CVE-2021-46500" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ArgTypeCheck in src/jsiFunc.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3449-q73h-pp22/GHSA-3449-q73h-pp22.json b/advisories/unreviewed/2022/01/GHSA-3449-q73h-pp22/GHSA-3449-q73h-pp22.json index 5bfd5ba43ab..1cacb8d2713 100644 --- a/advisories/unreviewed/2022/01/GHSA-3449-q73h-pp22/GHSA-3449-q73h-pp22.json +++ b/advisories/unreviewed/2022/01/GHSA-3449-q73h-pp22/GHSA-3449-q73h-pp22.json @@ -7,12 +7,8 @@ "CVE-2021-46526" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-3mfv-hwx7-8f5p/GHSA-3mfv-hwx7-8f5p.json b/advisories/unreviewed/2022/01/GHSA-3mfv-hwx7-8f5p/GHSA-3mfv-hwx7-8f5p.json index 9cbbe31604b..c3eb3378e0f 100644 --- a/advisories/unreviewed/2022/01/GHSA-3mfv-hwx7-8f5p/GHSA-3mfv-hwx7-8f5p.json +++ b/advisories/unreviewed/2022/01/GHSA-3mfv-hwx7-8f5p/GHSA-3mfv-hwx7-8f5p.json @@ -7,12 +7,8 @@ "CVE-2021-46553" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-3v8g-66j2-8535/GHSA-3v8g-66j2-8535.json b/advisories/unreviewed/2022/01/GHSA-3v8g-66j2-8535/GHSA-3v8g-66j2-8535.json index f559609c044..b1b045b8be7 100644 --- a/advisories/unreviewed/2022/01/GHSA-3v8g-66j2-8535/GHSA-3v8g-66j2-8535.json +++ b/advisories/unreviewed/2022/01/GHSA-3v8g-66j2-8535/GHSA-3v8g-66j2-8535.json @@ -7,12 +7,8 @@ "CVE-2021-46550" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-4749-xq6x-59v3/GHSA-4749-xq6x-59v3.json b/advisories/unreviewed/2022/01/GHSA-4749-xq6x-59v3/GHSA-4749-xq6x-59v3.json index 24147868c85..6277c3fb927 100644 --- a/advisories/unreviewed/2022/01/GHSA-4749-xq6x-59v3/GHSA-4749-xq6x-59v3.json +++ b/advisories/unreviewed/2022/01/GHSA-4749-xq6x-59v3/GHSA-4749-xq6x-59v3.json @@ -7,12 +7,8 @@ "CVE-2022-23968" ], "details": "Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included \"believed to affect all previous and later versions as of the date of this posting\" but a 2022-01-26 vendor statement reports \"the latest versions of firmware are not vulnerable to this issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4853-c3jq-r576/GHSA-4853-c3jq-r576.json b/advisories/unreviewed/2022/01/GHSA-4853-c3jq-r576/GHSA-4853-c3jq-r576.json index 80309da2008..8630e790e34 100644 --- a/advisories/unreviewed/2022/01/GHSA-4853-c3jq-r576/GHSA-4853-c3jq-r576.json +++ b/advisories/unreviewed/2022/01/GHSA-4853-c3jq-r576/GHSA-4853-c3jq-r576.json @@ -7,12 +7,8 @@ "CVE-2021-46497" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_UserObjDelete in src/jsiUserObj.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4cqg-vc7j-pmhv/GHSA-4cqg-vc7j-pmhv.json b/advisories/unreviewed/2022/01/GHSA-4cqg-vc7j-pmhv/GHSA-4cqg-vc7j-pmhv.json index 3e67d4bc0e1..d71125d7067 100644 --- a/advisories/unreviewed/2022/01/GHSA-4cqg-vc7j-pmhv/GHSA-4cqg-vc7j-pmhv.json +++ b/advisories/unreviewed/2022/01/GHSA-4cqg-vc7j-pmhv/GHSA-4cqg-vc7j-pmhv.json @@ -7,12 +7,8 @@ "CVE-2021-46448" ], "details": "H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4grj-8qw5-j9f8/GHSA-4grj-8qw5-j9f8.json b/advisories/unreviewed/2022/01/GHSA-4grj-8qw5-j9f8/GHSA-4grj-8qw5-j9f8.json index 7e3ddb327ef..96e45c6448a 100644 --- a/advisories/unreviewed/2022/01/GHSA-4grj-8qw5-j9f8/GHSA-4grj-8qw5-j9f8.json +++ b/advisories/unreviewed/2022/01/GHSA-4grj-8qw5-j9f8/GHSA-4grj-8qw5-j9f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-4j35-95ch-4cqq/GHSA-4j35-95ch-4cqq.json b/advisories/unreviewed/2022/01/GHSA-4j35-95ch-4cqq/GHSA-4j35-95ch-4cqq.json index 9306d6258b5..741b9305aff 100644 --- a/advisories/unreviewed/2022/01/GHSA-4j35-95ch-4cqq/GHSA-4j35-95ch-4cqq.json +++ b/advisories/unreviewed/2022/01/GHSA-4j35-95ch-4cqq/GHSA-4j35-95ch-4cqq.json @@ -7,12 +7,8 @@ "CVE-2021-46548" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-4qfv-qxv8-3c5x/GHSA-4qfv-qxv8-3c5x.json b/advisories/unreviewed/2022/01/GHSA-4qfv-qxv8-3c5x/GHSA-4qfv-qxv8-3c5x.json index 98a46427d9c..46a5c7756fb 100644 --- a/advisories/unreviewed/2022/01/GHSA-4qfv-qxv8-3c5x/GHSA-4qfv-qxv8-3c5x.json +++ b/advisories/unreviewed/2022/01/GHSA-4qfv-qxv8-3c5x/GHSA-4qfv-qxv8-3c5x.json @@ -7,12 +7,8 @@ "CVE-2021-46501" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via SortSubCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-524v-q4cc-cvmx/GHSA-524v-q4cc-cvmx.json b/advisories/unreviewed/2022/01/GHSA-524v-q4cc-cvmx/GHSA-524v-q4cc-cvmx.json index 369284d0db3..6de5ca6104a 100644 --- a/advisories/unreviewed/2022/01/GHSA-524v-q4cc-cvmx/GHSA-524v-q4cc-cvmx.json +++ b/advisories/unreviewed/2022/01/GHSA-524v-q4cc-cvmx/GHSA-524v-q4cc-cvmx.json @@ -7,12 +7,8 @@ "CVE-2022-22938" ], "details": "VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a denial-of-service condition in the Thinprint service running on the host machine where VMware Workstation or Horizon Client for Windows is installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-564r-594w-gw2m/GHSA-564r-594w-gw2m.json b/advisories/unreviewed/2022/01/GHSA-564r-594w-gw2m/GHSA-564r-594w-gw2m.json index 0a1e556cd36..1a7f7ff8e39 100644 --- a/advisories/unreviewed/2022/01/GHSA-564r-594w-gw2m/GHSA-564r-594w-gw2m.json +++ b/advisories/unreviewed/2022/01/GHSA-564r-594w-gw2m/GHSA-564r-594w-gw2m.json @@ -7,12 +7,8 @@ "CVE-2021-44118" ], "details": "SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5jch-qmrp-7wwr/GHSA-5jch-qmrp-7wwr.json b/advisories/unreviewed/2022/01/GHSA-5jch-qmrp-7wwr/GHSA-5jch-qmrp-7wwr.json index 9cb2e11e9b0..e0a1dbe4a07 100644 --- a/advisories/unreviewed/2022/01/GHSA-5jch-qmrp-7wwr/GHSA-5jch-qmrp-7wwr.json +++ b/advisories/unreviewed/2022/01/GHSA-5jch-qmrp-7wwr/GHSA-5jch-qmrp-7wwr.json @@ -7,12 +7,8 @@ "CVE-2021-46554" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-5r25-9ppq-m6j9/GHSA-5r25-9ppq-m6j9.json b/advisories/unreviewed/2022/01/GHSA-5r25-9ppq-m6j9/GHSA-5r25-9ppq-m6j9.json index 10ca09e631f..39d8578e802 100644 --- a/advisories/unreviewed/2022/01/GHSA-5r25-9ppq-m6j9/GHSA-5r25-9ppq-m6j9.json +++ b/advisories/unreviewed/2022/01/GHSA-5r25-9ppq-m6j9/GHSA-5r25-9ppq-m6j9.json @@ -7,12 +7,8 @@ "CVE-2021-46508" ], "details": "There is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-5w8m-7p89-xq72/GHSA-5w8m-7p89-xq72.json b/advisories/unreviewed/2022/01/GHSA-5w8m-7p89-xq72/GHSA-5w8m-7p89-xq72.json index 162db071865..d2ba89f20e5 100644 --- a/advisories/unreviewed/2022/01/GHSA-5w8m-7p89-xq72/GHSA-5w8m-7p89-xq72.json +++ b/advisories/unreviewed/2022/01/GHSA-5w8m-7p89-xq72/GHSA-5w8m-7p89-xq72.json @@ -7,12 +7,8 @@ "CVE-2021-36296" ], "details": "Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-63px-fjcc-g465/GHSA-63px-fjcc-g465.json b/advisories/unreviewed/2022/01/GHSA-63px-fjcc-g465/GHSA-63px-fjcc-g465.json index ebe50ee2a60..9c1f25f93c9 100644 --- a/advisories/unreviewed/2022/01/GHSA-63px-fjcc-g465/GHSA-63px-fjcc-g465.json +++ b/advisories/unreviewed/2022/01/GHSA-63px-fjcc-g465/GHSA-63px-fjcc-g465.json @@ -7,12 +7,8 @@ "CVE-2021-46491" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_CommandPkgOpts at src/jsiCmds.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-678r-w8gp-8m7g/GHSA-678r-w8gp-8m7g.json b/advisories/unreviewed/2022/01/GHSA-678r-w8gp-8m7g/GHSA-678r-w8gp-8m7g.json index e16e68a5f7d..5c2c0442df9 100644 --- a/advisories/unreviewed/2022/01/GHSA-678r-w8gp-8m7g/GHSA-678r-w8gp-8m7g.json +++ b/advisories/unreviewed/2022/01/GHSA-678r-w8gp-8m7g/GHSA-678r-w8gp-8m7g.json @@ -7,12 +7,8 @@ "CVE-2021-46527" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_get_cstring at src/mjs_string.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-6p5h-cfjp-f7qc/GHSA-6p5h-cfjp-f7qc.json b/advisories/unreviewed/2022/01/GHSA-6p5h-cfjp-f7qc/GHSA-6p5h-cfjp-f7qc.json index a187a1a8457..742b14c3a91 100644 --- a/advisories/unreviewed/2022/01/GHSA-6p5h-cfjp-f7qc/GHSA-6p5h-cfjp-f7qc.json +++ b/advisories/unreviewed/2022/01/GHSA-6p5h-cfjp-f7qc/GHSA-6p5h-cfjp-f7qc.json @@ -7,12 +7,8 @@ "CVE-2021-46543" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e810. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-72jh-3hhf-4gjm/GHSA-72jh-3hhf-4gjm.json b/advisories/unreviewed/2022/01/GHSA-72jh-3hhf-4gjm/GHSA-72jh-3hhf-4gjm.json index 6932233585b..c40a59d010f 100644 --- a/advisories/unreviewed/2022/01/GHSA-72jh-3hhf-4gjm/GHSA-72jh-3hhf-4gjm.json +++ b/advisories/unreviewed/2022/01/GHSA-72jh-3hhf-4gjm/GHSA-72jh-3hhf-4gjm.json @@ -7,12 +7,8 @@ "CVE-2021-46494" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueLookupBase in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-73mv-wv5r-8r3c/GHSA-73mv-wv5r-8r3c.json b/advisories/unreviewed/2022/01/GHSA-73mv-wv5r-8r3c/GHSA-73mv-wv5r-8r3c.json index 423214c73ab..870238566e3 100644 --- a/advisories/unreviewed/2022/01/GHSA-73mv-wv5r-8r3c/GHSA-73mv-wv5r-8r3c.json +++ b/advisories/unreviewed/2022/01/GHSA-73mv-wv5r-8r3c/GHSA-73mv-wv5r-8r3c.json @@ -7,12 +7,8 @@ "CVE-2021-46445" ], "details": "H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-783c-38cj-6q3h/GHSA-783c-38cj-6q3h.json b/advisories/unreviewed/2022/01/GHSA-783c-38cj-6q3h/GHSA-783c-38cj-6q3h.json index b155868d72d..b260104f232 100644 --- a/advisories/unreviewed/2022/01/GHSA-783c-38cj-6q3h/GHSA-783c-38cj-6q3h.json +++ b/advisories/unreviewed/2022/01/GHSA-783c-38cj-6q3h/GHSA-783c-38cj-6q3h.json @@ -7,12 +7,8 @@ "CVE-2021-28096" ], "details": "An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7j6c-7628-j453/GHSA-7j6c-7628-j453.json b/advisories/unreviewed/2022/01/GHSA-7j6c-7628-j453/GHSA-7j6c-7628-j453.json index d63bd7a9399..91dd89566b6 100644 --- a/advisories/unreviewed/2022/01/GHSA-7j6c-7628-j453/GHSA-7j6c-7628-j453.json +++ b/advisories/unreviewed/2022/01/GHSA-7j6c-7628-j453/GHSA-7j6c-7628-j453.json @@ -7,12 +7,8 @@ "CVE-2021-46444" ], "details": "H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-7prp-j2wv-v6p8/GHSA-7prp-j2wv-v6p8.json b/advisories/unreviewed/2022/01/GHSA-7prp-j2wv-v6p8/GHSA-7prp-j2wv-v6p8.json index b7a2dc842d5..ddb9ed6e3c6 100644 --- a/advisories/unreviewed/2022/01/GHSA-7prp-j2wv-v6p8/GHSA-7prp-j2wv-v6p8.json +++ b/advisories/unreviewed/2022/01/GHSA-7prp-j2wv-v6p8/GHSA-7prp-j2wv-v6p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8288-g25h-9cfr/GHSA-8288-g25h-9cfr.json b/advisories/unreviewed/2022/01/GHSA-8288-g25h-9cfr/GHSA-8288-g25h-9cfr.json index 6a805ec897a..26057bc8a18 100644 --- a/advisories/unreviewed/2022/01/GHSA-8288-g25h-9cfr/GHSA-8288-g25h-9cfr.json +++ b/advisories/unreviewed/2022/01/GHSA-8288-g25h-9cfr/GHSA-8288-g25h-9cfr.json @@ -7,12 +7,8 @@ "CVE-2021-36346" ], "details": "Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-877m-32cv-3j4j/GHSA-877m-32cv-3j4j.json b/advisories/unreviewed/2022/01/GHSA-877m-32cv-3j4j/GHSA-877m-32cv-3j4j.json index 22da4087734..e1e6c8c0d6f 100644 --- a/advisories/unreviewed/2022/01/GHSA-877m-32cv-3j4j/GHSA-877m-32cv-3j4j.json +++ b/advisories/unreviewed/2022/01/GHSA-877m-32cv-3j4j/GHSA-877m-32cv-3j4j.json @@ -7,12 +7,8 @@ "CVE-2021-46530" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_execute at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-8ff8-x2c5-r774/GHSA-8ff8-x2c5-r774.json b/advisories/unreviewed/2022/01/GHSA-8ff8-x2c5-r774/GHSA-8ff8-x2c5-r774.json index 07e18a0b662..c68a4a994d3 100644 --- a/advisories/unreviewed/2022/01/GHSA-8ff8-x2c5-r774/GHSA-8ff8-x2c5-r774.json +++ b/advisories/unreviewed/2022/01/GHSA-8ff8-x2c5-r774/GHSA-8ff8-x2c5-r774.json @@ -7,12 +7,8 @@ "CVE-2021-46519" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8g4h-r9rw-56cm/GHSA-8g4h-r9rw-56cm.json b/advisories/unreviewed/2022/01/GHSA-8g4h-r9rw-56cm/GHSA-8g4h-r9rw-56cm.json index d377daea908..6eea05903a8 100644 --- a/advisories/unreviewed/2022/01/GHSA-8g4h-r9rw-56cm/GHSA-8g4h-r9rw-56cm.json +++ b/advisories/unreviewed/2022/01/GHSA-8g4h-r9rw-56cm/GHSA-8g4h-r9rw-56cm.json @@ -7,12 +7,8 @@ "CVE-2021-46484" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_IncrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-8hcx-pw9g-w24x/GHSA-8hcx-pw9g-w24x.json b/advisories/unreviewed/2022/01/GHSA-8hcx-pw9g-w24x/GHSA-8hcx-pw9g-w24x.json index f0b2b50906b..809a1dd2c6e 100644 --- a/advisories/unreviewed/2022/01/GHSA-8hcx-pw9g-w24x/GHSA-8hcx-pw9g-w24x.json +++ b/advisories/unreviewed/2022/01/GHSA-8hcx-pw9g-w24x/GHSA-8hcx-pw9g-w24x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-92qp-r64g-pmwq/GHSA-92qp-r64g-pmwq.json b/advisories/unreviewed/2022/01/GHSA-92qp-r64g-pmwq/GHSA-92qp-r64g-pmwq.json index 0fb4f2b4a19..890f03c7cca 100644 --- a/advisories/unreviewed/2022/01/GHSA-92qp-r64g-pmwq/GHSA-92qp-r64g-pmwq.json +++ b/advisories/unreviewed/2022/01/GHSA-92qp-r64g-pmwq/GHSA-92qp-r64g-pmwq.json @@ -7,12 +7,8 @@ "CVE-2021-46097" ], "details": "Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-944j-xv2m-j62h/GHSA-944j-xv2m-j62h.json b/advisories/unreviewed/2022/01/GHSA-944j-xv2m-j62h/GHSA-944j-xv2m-j62h.json index f689236e6c7..192327508e7 100644 --- a/advisories/unreviewed/2022/01/GHSA-944j-xv2m-j62h/GHSA-944j-xv2m-j62h.json +++ b/advisories/unreviewed/2022/01/GHSA-944j-xv2m-j62h/GHSA-944j-xv2m-j62h.json @@ -7,12 +7,8 @@ "CVE-2021-46535" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0xe533e. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-94x2-cp7f-q2pj/GHSA-94x2-cp7f-q2pj.json b/advisories/unreviewed/2022/01/GHSA-94x2-cp7f-q2pj/GHSA-94x2-cp7f-q2pj.json index 83e80401481..039d57e47db 100644 --- a/advisories/unreviewed/2022/01/GHSA-94x2-cp7f-q2pj/GHSA-94x2-cp7f-q2pj.json +++ b/advisories/unreviewed/2022/01/GHSA-94x2-cp7f-q2pj/GHSA-94x2-cp7f-q2pj.json @@ -7,12 +7,8 @@ "CVE-2021-46549" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-9fhm-36wm-rpw2/GHSA-9fhm-36wm-rpw2.json b/advisories/unreviewed/2022/01/GHSA-9fhm-36wm-rpw2/GHSA-9fhm-36wm-rpw2.json index 09a30ca1791..b3396a21056 100644 --- a/advisories/unreviewed/2022/01/GHSA-9fhm-36wm-rpw2/GHSA-9fhm-36wm-rpw2.json +++ b/advisories/unreviewed/2022/01/GHSA-9fhm-36wm-rpw2/GHSA-9fhm-36wm-rpw2.json @@ -7,12 +7,8 @@ "CVE-2021-46495" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-9hpx-h92w-9fpc/GHSA-9hpx-h92w-9fpc.json b/advisories/unreviewed/2022/01/GHSA-9hpx-h92w-9fpc/GHSA-9hpx-h92w-9fpc.json index 0370606d702..3bebefe9a71 100644 --- a/advisories/unreviewed/2022/01/GHSA-9hpx-h92w-9fpc/GHSA-9hpx-h92w-9fpc.json +++ b/advisories/unreviewed/2022/01/GHSA-9hpx-h92w-9fpc/GHSA-9hpx-h92w-9fpc.json @@ -7,12 +7,8 @@ "CVE-2021-46541" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c6ae. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-9pgj-x6h2-p943/GHSA-9pgj-x6h2-p943.json b/advisories/unreviewed/2022/01/GHSA-9pgj-x6h2-p943/GHSA-9pgj-x6h2-p943.json index 7c8dcd9249a..02bb9524fc8 100644 --- a/advisories/unreviewed/2022/01/GHSA-9pgj-x6h2-p943/GHSA-9pgj-x6h2-p943.json +++ b/advisories/unreviewed/2022/01/GHSA-9pgj-x6h2-p943/GHSA-9pgj-x6h2-p943.json @@ -7,12 +7,8 @@ "CVE-2021-46523" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via to_json_or_debug at mjs/src/mjs_json.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c3cc-88pj-hrxf/GHSA-c3cc-88pj-hrxf.json b/advisories/unreviewed/2022/01/GHSA-c3cc-88pj-hrxf/GHSA-c3cc-88pj-hrxf.json index 5d4888ff4ad..860ccc7980c 100644 --- a/advisories/unreviewed/2022/01/GHSA-c3cc-88pj-hrxf/GHSA-c3cc-88pj-hrxf.json +++ b/advisories/unreviewed/2022/01/GHSA-c3cc-88pj-hrxf/GHSA-c3cc-88pj-hrxf.json @@ -7,12 +7,8 @@ "CVE-2021-46545" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x4b44b. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-c52c-f827-gfpg/GHSA-c52c-f827-gfpg.json b/advisories/unreviewed/2022/01/GHSA-c52c-f827-gfpg/GHSA-c52c-f827-gfpg.json index f8287ec1587..7f7d01deea8 100644 --- a/advisories/unreviewed/2022/01/GHSA-c52c-f827-gfpg/GHSA-c52c-f827-gfpg.json +++ b/advisories/unreviewed/2022/01/GHSA-c52c-f827-gfpg/GHSA-c52c-f827-gfpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-c96w-v3hm-68gf/GHSA-c96w-v3hm-68gf.json b/advisories/unreviewed/2022/01/GHSA-c96w-v3hm-68gf/GHSA-c96w-v3hm-68gf.json index 4030a6e460b..f66fe03e94e 100644 --- a/advisories/unreviewed/2022/01/GHSA-c96w-v3hm-68gf/GHSA-c96w-v3hm-68gf.json +++ b/advisories/unreviewed/2022/01/GHSA-c96w-v3hm-68gf/GHSA-c96w-v3hm-68gf.json @@ -7,12 +7,8 @@ "CVE-2021-46490" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via NumberConstructor at src/jsiNumber.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-cc3h-2vcf-c96x/GHSA-cc3h-2vcf-c96x.json b/advisories/unreviewed/2022/01/GHSA-cc3h-2vcf-c96x/GHSA-cc3h-2vcf-c96x.json index a2205fb8878..993b8bb9ceb 100644 --- a/advisories/unreviewed/2022/01/GHSA-cc3h-2vcf-c96x/GHSA-cc3h-2vcf-c96x.json +++ b/advisories/unreviewed/2022/01/GHSA-cc3h-2vcf-c96x/GHSA-cc3h-2vcf-c96x.json @@ -7,12 +7,8 @@ "CVE-2021-46512" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_apply at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-cc8q-rrgm-f274/GHSA-cc8q-rrgm-f274.json b/advisories/unreviewed/2022/01/GHSA-cc8q-rrgm-f274/GHSA-cc8q-rrgm-f274.json index 35117231ef7..dca174c02c1 100644 --- a/advisories/unreviewed/2022/01/GHSA-cc8q-rrgm-f274/GHSA-cc8q-rrgm-f274.json +++ b/advisories/unreviewed/2022/01/GHSA-cc8q-rrgm-f274/GHSA-cc8q-rrgm-f274.json @@ -7,12 +7,8 @@ "CVE-2021-46532" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via exec_expr at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-cjxw-c723-f938/GHSA-cjxw-c723-f938.json b/advisories/unreviewed/2022/01/GHSA-cjxw-c723-f938/GHSA-cjxw-c723-f938.json index 498a5b36eaf..a32c0a79d07 100644 --- a/advisories/unreviewed/2022/01/GHSA-cjxw-c723-f938/GHSA-cjxw-c723-f938.json +++ b/advisories/unreviewed/2022/01/GHSA-cjxw-c723-f938/GHSA-cjxw-c723-f938.json @@ -7,12 +7,8 @@ "CVE-2021-46520" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_jprintf at src/mjs_util.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cq27-9fxq-2g57/GHSA-cq27-9fxq-2g57.json b/advisories/unreviewed/2022/01/GHSA-cq27-9fxq-2g57/GHSA-cq27-9fxq-2g57.json index bc53f0b135f..70065bf8923 100644 --- a/advisories/unreviewed/2022/01/GHSA-cq27-9fxq-2g57/GHSA-cq27-9fxq-2g57.json +++ b/advisories/unreviewed/2022/01/GHSA-cq27-9fxq-2g57/GHSA-cq27-9fxq-2g57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-crgh-cf58-pq9r/GHSA-crgh-cf58-pq9r.json b/advisories/unreviewed/2022/01/GHSA-crgh-cf58-pq9r/GHSA-crgh-cf58-pq9r.json index c93f3c46dc6..7402dcb4be2 100644 --- a/advisories/unreviewed/2022/01/GHSA-crgh-cf58-pq9r/GHSA-crgh-cf58-pq9r.json +++ b/advisories/unreviewed/2022/01/GHSA-crgh-cf58-pq9r/GHSA-crgh-cf58-pq9r.json @@ -7,12 +7,8 @@ "CVE-2022-23888" ], "details": "YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-cw3v-mxv2-589m/GHSA-cw3v-mxv2-589m.json b/advisories/unreviewed/2022/01/GHSA-cw3v-mxv2-589m/GHSA-cw3v-mxv2-589m.json index cc6a0ad5a85..0948ae5029b 100644 --- a/advisories/unreviewed/2022/01/GHSA-cw3v-mxv2-589m/GHSA-cw3v-mxv2-589m.json +++ b/advisories/unreviewed/2022/01/GHSA-cw3v-mxv2-589m/GHSA-cw3v-mxv2-589m.json @@ -7,12 +7,8 @@ "CVE-2022-23887" ], "details": "YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-f2q8-35wx-ww2j/GHSA-f2q8-35wx-ww2j.json b/advisories/unreviewed/2022/01/GHSA-f2q8-35wx-ww2j/GHSA-f2q8-35wx-ww2j.json index 6b9e722e17e..71e3fc62310 100644 --- a/advisories/unreviewed/2022/01/GHSA-f2q8-35wx-ww2j/GHSA-f2q8-35wx-ww2j.json +++ b/advisories/unreviewed/2022/01/GHSA-f2q8-35wx-ww2j/GHSA-f2q8-35wx-ww2j.json @@ -7,12 +7,8 @@ "CVE-2021-46496" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_ObjFree in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-f674-4px8-qr98/GHSA-f674-4px8-qr98.json b/advisories/unreviewed/2022/01/GHSA-f674-4px8-qr98/GHSA-f674-4px8-qr98.json index 9f0fd702fb6..c3736aa5f41 100644 --- a/advisories/unreviewed/2022/01/GHSA-f674-4px8-qr98/GHSA-f674-4px8-qr98.json +++ b/advisories/unreviewed/2022/01/GHSA-f674-4px8-qr98/GHSA-f674-4px8-qr98.json @@ -7,12 +7,8 @@ "CVE-2021-46529" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x8814e. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-f979-4qm9-qvgj/GHSA-f979-4qm9-qvgj.json b/advisories/unreviewed/2022/01/GHSA-f979-4qm9-qvgj/GHSA-f979-4qm9-qvgj.json index 2f745d86945..887832f41fb 100644 --- a/advisories/unreviewed/2022/01/GHSA-f979-4qm9-qvgj/GHSA-f979-4qm9-qvgj.json +++ b/advisories/unreviewed/2022/01/GHSA-f979-4qm9-qvgj/GHSA-f979-4qm9-qvgj.json @@ -7,12 +7,8 @@ "CVE-2021-46377" ], "details": "There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fg3f-mxc7-mxh6/GHSA-fg3f-mxc7-mxh6.json b/advisories/unreviewed/2022/01/GHSA-fg3f-mxc7-mxh6/GHSA-fg3f-mxc7-mxh6.json index 3b74dd92037..c34782ee70b 100644 --- a/advisories/unreviewed/2022/01/GHSA-fg3f-mxc7-mxh6/GHSA-fg3f-mxc7-mxh6.json +++ b/advisories/unreviewed/2022/01/GHSA-fg3f-mxc7-mxh6/GHSA-fg3f-mxc7-mxh6.json @@ -7,12 +7,8 @@ "CVE-2021-46504" ], "details": "There is an Assertion 'vp != resPtr' failed at jsiEval.c in Jsish v3.5.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fjxj-v58p-v8w6/GHSA-fjxj-v58p-v8w6.json b/advisories/unreviewed/2022/01/GHSA-fjxj-v58p-v8w6/GHSA-fjxj-v58p-v8w6.json index 120d7e77db2..61445681734 100644 --- a/advisories/unreviewed/2022/01/GHSA-fjxj-v58p-v8w6/GHSA-fjxj-v58p-v8w6.json +++ b/advisories/unreviewed/2022/01/GHSA-fjxj-v58p-v8w6/GHSA-fjxj-v58p-v8w6.json @@ -7,12 +7,8 @@ "CVE-2021-46537" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x9a30e. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-fpjw-hq75-pxx8/GHSA-fpjw-hq75-pxx8.json b/advisories/unreviewed/2022/01/GHSA-fpjw-hq75-pxx8/GHSA-fpjw-hq75-pxx8.json index 34304105a2c..85beabd9dbe 100644 --- a/advisories/unreviewed/2022/01/GHSA-fpjw-hq75-pxx8/GHSA-fpjw-hq75-pxx8.json +++ b/advisories/unreviewed/2022/01/GHSA-fpjw-hq75-pxx8/GHSA-fpjw-hq75-pxx8.json @@ -7,12 +7,8 @@ "CVE-2022-23456" ], "details": "Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-fv46-9fmf-2p7g/GHSA-fv46-9fmf-2p7g.json b/advisories/unreviewed/2022/01/GHSA-fv46-9fmf-2p7g/GHSA-fv46-9fmf-2p7g.json index 2dffc2b6ef0..8d81fb5fb97 100644 --- a/advisories/unreviewed/2022/01/GHSA-fv46-9fmf-2p7g/GHSA-fv46-9fmf-2p7g.json +++ b/advisories/unreviewed/2022/01/GHSA-fv46-9fmf-2p7g/GHSA-fv46-9fmf-2p7g.json @@ -7,12 +7,8 @@ "CVE-2021-44122" ], "details": "SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fv9v-2855-83mf/GHSA-fv9v-2855-83mf.json b/advisories/unreviewed/2022/01/GHSA-fv9v-2855-83mf/GHSA-fv9v-2855-83mf.json index 7aae7becc6a..1e020773273 100644 --- a/advisories/unreviewed/2022/01/GHSA-fv9v-2855-83mf/GHSA-fv9v-2855-83mf.json +++ b/advisories/unreviewed/2022/01/GHSA-fv9v-2855-83mf/GHSA-fv9v-2855-83mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-g5ff-j87h-3cwg/GHSA-g5ff-j87h-3cwg.json b/advisories/unreviewed/2022/01/GHSA-g5ff-j87h-3cwg/GHSA-g5ff-j87h-3cwg.json index 32e7f142d1d..d68eb89150a 100644 --- a/advisories/unreviewed/2022/01/GHSA-g5ff-j87h-3cwg/GHSA-g5ff-j87h-3cwg.json +++ b/advisories/unreviewed/2022/01/GHSA-g5ff-j87h-3cwg/GHSA-g5ff-j87h-3cwg.json @@ -7,12 +7,8 @@ "CVE-2021-46088" ], "details": "Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the \"Zabbix Admin\" role is able to run custom shell script on the application server in the context of the application user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-g84v-6fgf-jw3g/GHSA-g84v-6fgf-jw3g.json b/advisories/unreviewed/2022/01/GHSA-g84v-6fgf-jw3g/GHSA-g84v-6fgf-jw3g.json index 3a32e57a0cb..8a22566ca67 100644 --- a/advisories/unreviewed/2022/01/GHSA-g84v-6fgf-jw3g/GHSA-g84v-6fgf-jw3g.json +++ b/advisories/unreviewed/2022/01/GHSA-g84v-6fgf-jw3g/GHSA-g84v-6fgf-jw3g.json @@ -7,12 +7,8 @@ "CVE-2022-22791" ], "details": "SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the \"comments\" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gfmv-c654-mm3g/GHSA-gfmv-c654-mm3g.json b/advisories/unreviewed/2022/01/GHSA-gfmv-c654-mm3g/GHSA-gfmv-c654-mm3g.json index 7ec20295158..025d78a4148 100644 --- a/advisories/unreviewed/2022/01/GHSA-gfmv-c654-mm3g/GHSA-gfmv-c654-mm3g.json +++ b/advisories/unreviewed/2022/01/GHSA-gfmv-c654-mm3g/GHSA-gfmv-c654-mm3g.json @@ -7,12 +7,8 @@ "CVE-2021-46511" ], "details": "There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gm3j-wm5r-799c/GHSA-gm3j-wm5r-799c.json b/advisories/unreviewed/2022/01/GHSA-gm3j-wm5r-799c/GHSA-gm3j-wm5r-799c.json index 8e137e0cc85..027a9eb1fdd 100644 --- a/advisories/unreviewed/2022/01/GHSA-gm3j-wm5r-799c/GHSA-gm3j-wm5r-799c.json +++ b/advisories/unreviewed/2022/01/GHSA-gm3j-wm5r-799c/GHSA-gm3j-wm5r-799c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gpw5-j8cp-9p59/GHSA-gpw5-j8cp-9p59.json b/advisories/unreviewed/2022/01/GHSA-gpw5-j8cp-9p59/GHSA-gpw5-j8cp-9p59.json index ab3076aa290..da6ebab4136 100644 --- a/advisories/unreviewed/2022/01/GHSA-gpw5-j8cp-9p59/GHSA-gpw5-j8cp-9p59.json +++ b/advisories/unreviewed/2022/01/GHSA-gpw5-j8cp-9p59/GHSA-gpw5-j8cp-9p59.json @@ -7,12 +7,8 @@ "CVE-2021-46514" ], "details": "There is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-h2j2-qx54-6hmh/GHSA-h2j2-qx54-6hmh.json b/advisories/unreviewed/2022/01/GHSA-h2j2-qx54-6hmh/GHSA-h2j2-qx54-6hmh.json index 4a86fe458ce..ae2691dbd67 100644 --- a/advisories/unreviewed/2022/01/GHSA-h2j2-qx54-6hmh/GHSA-h2j2-qx54-6hmh.json +++ b/advisories/unreviewed/2022/01/GHSA-h2j2-qx54-6hmh/GHSA-h2j2-qx54-6hmh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-h72m-3m74-9ppq/GHSA-h72m-3m74-9ppq.json b/advisories/unreviewed/2022/01/GHSA-h72m-3m74-9ppq/GHSA-h72m-3m74-9ppq.json index 32ac377d021..0dbd6a6d909 100644 --- a/advisories/unreviewed/2022/01/GHSA-h72m-3m74-9ppq/GHSA-h72m-3m74-9ppq.json +++ b/advisories/unreviewed/2022/01/GHSA-h72m-3m74-9ppq/GHSA-h72m-3m74-9ppq.json @@ -7,12 +7,8 @@ "CVE-2021-36294" ], "details": "Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-h7hg-fw2g-58j8/GHSA-h7hg-fw2g-58j8.json b/advisories/unreviewed/2022/01/GHSA-h7hg-fw2g-58j8/GHSA-h7hg-fw2g-58j8.json index 2425ed430ea..3a8a5b9c2a7 100644 --- a/advisories/unreviewed/2022/01/GHSA-h7hg-fw2g-58j8/GHSA-h7hg-fw2g-58j8.json +++ b/advisories/unreviewed/2022/01/GHSA-h7hg-fw2g-58j8/GHSA-h7hg-fw2g-58j8.json @@ -7,12 +7,8 @@ "CVE-2021-46521" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via c_vsnprintf at mjs/src/common/str_util.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-hgfc-qr57-548r/GHSA-hgfc-qr57-548r.json b/advisories/unreviewed/2022/01/GHSA-hgfc-qr57-548r/GHSA-hgfc-qr57-548r.json index 03ac8d78bc4..f008920b663 100644 --- a/advisories/unreviewed/2022/01/GHSA-hgfc-qr57-548r/GHSA-hgfc-qr57-548r.json +++ b/advisories/unreviewed/2022/01/GHSA-hgfc-qr57-548r/GHSA-hgfc-qr57-548r.json @@ -7,12 +7,8 @@ "CVE-2021-46544" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x59e19. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-hhgp-4q6r-hh4c/GHSA-hhgp-4q6r-hh4c.json b/advisories/unreviewed/2022/01/GHSA-hhgp-4q6r-hh4c/GHSA-hhgp-4q6r-hh4c.json index 36b4a5794e8..72e8384c9a1 100644 --- a/advisories/unreviewed/2022/01/GHSA-hhgp-4q6r-hh4c/GHSA-hhgp-4q6r-hh4c.json +++ b/advisories/unreviewed/2022/01/GHSA-hhgp-4q6r-hh4c/GHSA-hhgp-4q6r-hh4c.json @@ -7,12 +7,8 @@ "CVE-2021-46542" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_print at src/mjs_builtin.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-hr82-qcw6-r4j6/GHSA-hr82-qcw6-r4j6.json b/advisories/unreviewed/2022/01/GHSA-hr82-qcw6-r4j6/GHSA-hr82-qcw6-r4j6.json index 3716a4c0961..b08a25289dd 100644 --- a/advisories/unreviewed/2022/01/GHSA-hr82-qcw6-r4j6/GHSA-hr82-qcw6-r4j6.json +++ b/advisories/unreviewed/2022/01/GHSA-hr82-qcw6-r4j6/GHSA-hr82-qcw6-r4j6.json @@ -7,12 +7,8 @@ "CVE-2021-46446" ], "details": "H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j7v8-gg92-f664/GHSA-j7v8-gg92-f664.json b/advisories/unreviewed/2022/01/GHSA-j7v8-gg92-f664/GHSA-j7v8-gg92-f664.json index 33f2860ce93..1cf6c93d40b 100644 --- a/advisories/unreviewed/2022/01/GHSA-j7v8-gg92-f664/GHSA-j7v8-gg92-f664.json +++ b/advisories/unreviewed/2022/01/GHSA-j7v8-gg92-f664/GHSA-j7v8-gg92-f664.json @@ -7,12 +7,8 @@ "CVE-2021-46489" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_DecrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-jc6h-x2h7-c6r4/GHSA-jc6h-x2h7-c6r4.json b/advisories/unreviewed/2022/01/GHSA-jc6h-x2h7-c6r4/GHSA-jc6h-x2h7-c6r4.json index 352fc65c69a..5b6284c14b7 100644 --- a/advisories/unreviewed/2022/01/GHSA-jc6h-x2h7-c6r4/GHSA-jc6h-x2h7-c6r4.json +++ b/advisories/unreviewed/2022/01/GHSA-jc6h-x2h7-c6r4/GHSA-jc6h-x2h7-c6r4.json @@ -7,12 +7,8 @@ "CVE-2021-46513" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via mjs_mk_string at mjs/src/mjs_string.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-m8p9-v77c-rq98/GHSA-m8p9-v77c-rq98.json b/advisories/unreviewed/2022/01/GHSA-m8p9-v77c-rq98/GHSA-m8p9-v77c-rq98.json index 1474cb79f0a..f010de79291 100644 --- a/advisories/unreviewed/2022/01/GHSA-m8p9-v77c-rq98/GHSA-m8p9-v77c-rq98.json +++ b/advisories/unreviewed/2022/01/GHSA-m8p9-v77c-rq98/GHSA-m8p9-v77c-rq98.json @@ -7,12 +7,8 @@ "CVE-2021-36289" ], "details": "Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mm5h-c8p7-5v83/GHSA-mm5h-c8p7-5v83.json b/advisories/unreviewed/2022/01/GHSA-mm5h-c8p7-5v83/GHSA-mm5h-c8p7-5v83.json index 4f85019a8c4..a0b821ee9a5 100644 --- a/advisories/unreviewed/2022/01/GHSA-mm5h-c8p7-5v83/GHSA-mm5h-c8p7-5v83.json +++ b/advisories/unreviewed/2022/01/GHSA-mm5h-c8p7-5v83/GHSA-mm5h-c8p7-5v83.json @@ -7,12 +7,8 @@ "CVE-2021-46428" ], "details": "A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-mppp-rwr9-jw9f/GHSA-mppp-rwr9-jw9f.json b/advisories/unreviewed/2022/01/GHSA-mppp-rwr9-jw9f/GHSA-mppp-rwr9-jw9f.json index ea9740bd86e..6e6e82ac0bb 100644 --- a/advisories/unreviewed/2022/01/GHSA-mppp-rwr9-jw9f/GHSA-mppp-rwr9-jw9f.json +++ b/advisories/unreviewed/2022/01/GHSA-mppp-rwr9-jw9f/GHSA-mppp-rwr9-jw9f.json @@ -7,12 +7,8 @@ "CVE-2021-46547" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-pfxx-3ww7-5wc8/GHSA-pfxx-3ww7-5wc8.json b/advisories/unreviewed/2022/01/GHSA-pfxx-3ww7-5wc8/GHSA-pfxx-3ww7-5wc8.json index a2a4d48b887..7578cea7b11 100644 --- a/advisories/unreviewed/2022/01/GHSA-pfxx-3ww7-5wc8/GHSA-pfxx-3ww7-5wc8.json +++ b/advisories/unreviewed/2022/01/GHSA-pfxx-3ww7-5wc8/GHSA-pfxx-3ww7-5wc8.json @@ -7,12 +7,8 @@ "CVE-2021-46503" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x79732. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-ph3j-2pmh-jj3v/GHSA-ph3j-2pmh-jj3v.json b/advisories/unreviewed/2022/01/GHSA-ph3j-2pmh-jj3v/GHSA-ph3j-2pmh-jj3v.json index 666d0b0eaca..7a524f7f5e6 100644 --- a/advisories/unreviewed/2022/01/GHSA-ph3j-2pmh-jj3v/GHSA-ph3j-2pmh-jj3v.json +++ b/advisories/unreviewed/2022/01/GHSA-ph3j-2pmh-jj3v/GHSA-ph3j-2pmh-jj3v.json @@ -7,12 +7,8 @@ "CVE-2021-46487" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e506. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-pmh9-v5qm-xh48/GHSA-pmh9-v5qm-xh48.json b/advisories/unreviewed/2022/01/GHSA-pmh9-v5qm-xh48/GHSA-pmh9-v5qm-xh48.json index e3f546e150d..41f56467ed6 100644 --- a/advisories/unreviewed/2022/01/GHSA-pmh9-v5qm-xh48/GHSA-pmh9-v5qm-xh48.json +++ b/advisories/unreviewed/2022/01/GHSA-pmh9-v5qm-xh48/GHSA-pmh9-v5qm-xh48.json @@ -7,12 +7,8 @@ "CVE-2021-46522" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0xaff53.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pr4h-pc76-99rf/GHSA-pr4h-pc76-99rf.json b/advisories/unreviewed/2022/01/GHSA-pr4h-pc76-99rf/GHSA-pr4h-pc76-99rf.json index 59dbf1caf3b..ff717d6fa40 100644 --- a/advisories/unreviewed/2022/01/GHSA-pr4h-pc76-99rf/GHSA-pr4h-pc76-99rf.json +++ b/advisories/unreviewed/2022/01/GHSA-pr4h-pc76-99rf/GHSA-pr4h-pc76-99rf.json @@ -7,12 +7,8 @@ "CVE-2021-46510" ], "details": "There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pv4h-cxpg-pv52/GHSA-pv4h-cxpg-pv52.json b/advisories/unreviewed/2022/01/GHSA-pv4h-cxpg-pv52/GHSA-pv4h-cxpg-pv52.json index 3d2ee096910..5c41d9d885b 100644 --- a/advisories/unreviewed/2022/01/GHSA-pv4h-cxpg-pv52/GHSA-pv4h-cxpg-pv52.json +++ b/advisories/unreviewed/2022/01/GHSA-pv4h-cxpg-pv52/GHSA-pv4h-cxpg-pv52.json @@ -7,12 +7,8 @@ "CVE-2021-46540" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_get_mjs at src/mjs_builtin.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-pv7h-c97m-6hrh/GHSA-pv7h-c97m-6hrh.json b/advisories/unreviewed/2022/01/GHSA-pv7h-c97m-6hrh/GHSA-pv7h-c97m-6hrh.json index 6bf10973d39..59c559fc7da 100644 --- a/advisories/unreviewed/2022/01/GHSA-pv7h-c97m-6hrh/GHSA-pv7h-c97m-6hrh.json +++ b/advisories/unreviewed/2022/01/GHSA-pv7h-c97m-6hrh/GHSA-pv7h-c97m-6hrh.json @@ -7,12 +7,8 @@ "CVE-2022-23979" ], "details": "Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-pvgx-5rw8-rc6v/GHSA-pvgx-5rw8-rc6v.json b/advisories/unreviewed/2022/01/GHSA-pvgx-5rw8-rc6v/GHSA-pvgx-5rw8-rc6v.json index f9e7098e6c7..cd56cf34481 100644 --- a/advisories/unreviewed/2022/01/GHSA-pvgx-5rw8-rc6v/GHSA-pvgx-5rw8-rc6v.json +++ b/advisories/unreviewed/2022/01/GHSA-pvgx-5rw8-rc6v/GHSA-pvgx-5rw8-rc6v.json @@ -7,12 +7,8 @@ "CVE-2021-46485" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_ValueIsNumber at src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-q5fm-9w82-2m78/GHSA-q5fm-9w82-2m78.json b/advisories/unreviewed/2022/01/GHSA-q5fm-9w82-2m78/GHSA-q5fm-9w82-2m78.json index 3788153e671..f6c5f611bbf 100644 --- a/advisories/unreviewed/2022/01/GHSA-q5fm-9w82-2m78/GHSA-q5fm-9w82-2m78.json +++ b/advisories/unreviewed/2022/01/GHSA-q5fm-9w82-2m78/GHSA-q5fm-9w82-2m78.json @@ -7,12 +7,8 @@ "CVE-2019-25056" ], "details": "In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-q5r8-fmxw-rxvr/GHSA-q5r8-fmxw-rxvr.json b/advisories/unreviewed/2022/01/GHSA-q5r8-fmxw-rxvr/GHSA-q5r8-fmxw-rxvr.json index a8f8fdd7a36..bdbf403a6eb 100644 --- a/advisories/unreviewed/2022/01/GHSA-q5r8-fmxw-rxvr/GHSA-q5r8-fmxw-rxvr.json +++ b/advisories/unreviewed/2022/01/GHSA-q5r8-fmxw-rxvr/GHSA-q5r8-fmxw-rxvr.json @@ -7,12 +7,8 @@ "CVE-2021-36347" ], "details": "iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-q8m2-mp4h-vhmc/GHSA-q8m2-mp4h-vhmc.json b/advisories/unreviewed/2022/01/GHSA-q8m2-mp4h-vhmc/GHSA-q8m2-mp4h-vhmc.json index 3752f4b8032..3abf336714b 100644 --- a/advisories/unreviewed/2022/01/GHSA-q8m2-mp4h-vhmc/GHSA-q8m2-mp4h-vhmc.json +++ b/advisories/unreviewed/2022/01/GHSA-q8m2-mp4h-vhmc/GHSA-q8m2-mp4h-vhmc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qmgg-g8c3-8959/GHSA-qmgg-g8c3-8959.json b/advisories/unreviewed/2022/01/GHSA-qmgg-g8c3-8959/GHSA-qmgg-g8c3-8959.json index 2aaf8df2308..550e249aaa3 100644 --- a/advisories/unreviewed/2022/01/GHSA-qmgg-g8c3-8959/GHSA-qmgg-g8c3-8959.json +++ b/advisories/unreviewed/2022/01/GHSA-qmgg-g8c3-8959/GHSA-qmgg-g8c3-8959.json @@ -7,12 +7,8 @@ "CVE-2021-46560" ], "details": "The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qqr4-8m2r-fv75/GHSA-qqr4-8m2r-fv75.json b/advisories/unreviewed/2022/01/GHSA-qqr4-8m2r-fv75/GHSA-qqr4-8m2r-fv75.json index 6980a1345ca..532831f584a 100644 --- a/advisories/unreviewed/2022/01/GHSA-qqr4-8m2r-fv75/GHSA-qqr4-8m2r-fv75.json +++ b/advisories/unreviewed/2022/01/GHSA-qqr4-8m2r-fv75/GHSA-qqr4-8m2r-fv75.json @@ -7,12 +7,8 @@ "CVE-2021-46524" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via snquote at mjs/src/mjs_json.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qrcq-hr7g-x7gm/GHSA-qrcq-hr7g-x7gm.json b/advisories/unreviewed/2022/01/GHSA-qrcq-hr7g-x7gm/GHSA-qrcq-hr7g-x7gm.json index 983c47e8377..f0d37a0bb1a 100644 --- a/advisories/unreviewed/2022/01/GHSA-qrcq-hr7g-x7gm/GHSA-qrcq-hr7g-x7gm.json +++ b/advisories/unreviewed/2022/01/GHSA-qrcq-hr7g-x7gm/GHSA-qrcq-hr7g-x7gm.json @@ -7,12 +7,8 @@ "CVE-2022-23889" ], "details": "The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-qv4f-fgw8-cv63/GHSA-qv4f-fgw8-cv63.json b/advisories/unreviewed/2022/01/GHSA-qv4f-fgw8-cv63/GHSA-qv4f-fgw8-cv63.json index ce87a452e77..41b67b31e10 100644 --- a/advisories/unreviewed/2022/01/GHSA-qv4f-fgw8-cv63/GHSA-qv4f-fgw8-cv63.json +++ b/advisories/unreviewed/2022/01/GHSA-qv4f-fgw8-cv63/GHSA-qv4f-fgw8-cv63.json @@ -7,12 +7,8 @@ "CVE-2021-46427" ], "details": "An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-r2fp-jg3h-x57v/GHSA-r2fp-jg3h-x57v.json b/advisories/unreviewed/2022/01/GHSA-r2fp-jg3h-x57v/GHSA-r2fp-jg3h-x57v.json index 4f59c26d903..9d64164930c 100644 --- a/advisories/unreviewed/2022/01/GHSA-r2fp-jg3h-x57v/GHSA-r2fp-jg3h-x57v.json +++ b/advisories/unreviewed/2022/01/GHSA-r2fp-jg3h-x57v/GHSA-r2fp-jg3h-x57v.json @@ -7,12 +7,8 @@ "CVE-2021-46525" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap-use-after-free via mjs_apply at src/mjs_exec.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-r3hm-jjx3-cjc9/GHSA-r3hm-jjx3-cjc9.json b/advisories/unreviewed/2022/01/GHSA-r3hm-jjx3-cjc9/GHSA-r3hm-jjx3-cjc9.json index 2a0d4543fae..6ac96777191 100644 --- a/advisories/unreviewed/2022/01/GHSA-r3hm-jjx3-cjc9/GHSA-r3hm-jjx3-cjc9.json +++ b/advisories/unreviewed/2022/01/GHSA-r3hm-jjx3-cjc9/GHSA-r3hm-jjx3-cjc9.json @@ -7,12 +7,8 @@ "CVE-2021-46531" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x8d28e. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-rhgm-4w89-39gg/GHSA-rhgm-4w89-39gg.json b/advisories/unreviewed/2022/01/GHSA-rhgm-4w89-39gg/GHSA-rhgm-4w89-39gg.json index 9c93cefc142..10d1dbdc39b 100644 --- a/advisories/unreviewed/2022/01/GHSA-rhgm-4w89-39gg/GHSA-rhgm-4w89-39gg.json +++ b/advisories/unreviewed/2022/01/GHSA-rhgm-4w89-39gg/GHSA-rhgm-4w89-39gg.json @@ -7,12 +7,8 @@ "CVE-2021-46486" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArraySpliceCmd at src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-rqmw-j65q-j6hh/GHSA-rqmw-j65q-j6hh.json b/advisories/unreviewed/2022/01/GHSA-rqmw-j65q-j6hh/GHSA-rqmw-j65q-j6hh.json index 6fd777c19fb..ed876ab3a56 100644 --- a/advisories/unreviewed/2022/01/GHSA-rqmw-j65q-j6hh/GHSA-rqmw-j65q-j6hh.json +++ b/advisories/unreviewed/2022/01/GHSA-rqmw-j65q-j6hh/GHSA-rqmw-j65q-j6hh.json @@ -7,12 +7,8 @@ "CVE-2021-46506" ], "details": "There is an Assertion 'v->d.lval != v' failed at src/jsiValue.c in Jsish v3.5.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rqqg-rcmm-4825/GHSA-rqqg-rcmm-4825.json b/advisories/unreviewed/2022/01/GHSA-rqqg-rcmm-4825/GHSA-rqqg-rcmm-4825.json index 747a686de41..da7ae6232a1 100644 --- a/advisories/unreviewed/2022/01/GHSA-rqqg-rcmm-4825/GHSA-rqqg-rcmm-4825.json +++ b/advisories/unreviewed/2022/01/GHSA-rqqg-rcmm-4825/GHSA-rqqg-rcmm-4825.json @@ -7,12 +7,8 @@ "CVE-2021-46498" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_wswebsocketObjFree in src/jsiWebSocket.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rqww-2fr9-72r5/GHSA-rqww-2fr9-72r5.json b/advisories/unreviewed/2022/01/GHSA-rqww-2fr9-72r5/GHSA-rqww-2fr9-72r5.json index c8735eed839..8c87115f172 100644 --- a/advisories/unreviewed/2022/01/GHSA-rqww-2fr9-72r5/GHSA-rqww-2fr9-72r5.json +++ b/advisories/unreviewed/2022/01/GHSA-rqww-2fr9-72r5/GHSA-rqww-2fr9-72r5.json @@ -7,12 +7,8 @@ "CVE-2021-46539" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x45a1f. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-rrr6-r9v5-phwp/GHSA-rrr6-r9v5-phwp.json b/advisories/unreviewed/2022/01/GHSA-rrr6-r9v5-phwp/GHSA-rrr6-r9v5-phwp.json index 487fff2f4cc..35650039cc5 100644 --- a/advisories/unreviewed/2022/01/GHSA-rrr6-r9v5-phwp/GHSA-rrr6-r9v5-phwp.json +++ b/advisories/unreviewed/2022/01/GHSA-rrr6-r9v5-phwp/GHSA-rrr6-r9v5-phwp.json @@ -7,12 +7,8 @@ "CVE-2021-46518" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_disown at src/mjs_core.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rvjh-ch4h-2q94/GHSA-rvjh-ch4h-2q94.json b/advisories/unreviewed/2022/01/GHSA-rvjh-ch4h-2q94/GHSA-rvjh-ch4h-2q94.json index d8f6dce9644..d47d13b2de8 100644 --- a/advisories/unreviewed/2022/01/GHSA-rvjh-ch4h-2q94/GHSA-rvjh-ch4h-2q94.json +++ b/advisories/unreviewed/2022/01/GHSA-rvjh-ch4h-2q94/GHSA-rvjh-ch4h-2q94.json @@ -7,12 +7,8 @@ "CVE-2021-46534" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via getprop_builtin_foreign at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-v9r7-j9px-3j3q/GHSA-v9r7-j9px-3j3q.json b/advisories/unreviewed/2022/01/GHSA-v9r7-j9px-3j3q/GHSA-v9r7-j9px-3j3q.json index fa831ccf7a7..cdaf6a4a136 100644 --- a/advisories/unreviewed/2022/01/GHSA-v9r7-j9px-3j3q/GHSA-v9r7-j9px-3j3q.json +++ b/advisories/unreviewed/2022/01/GHSA-v9r7-j9px-3j3q/GHSA-v9r7-j9px-3j3q.json @@ -7,12 +7,8 @@ "CVE-2021-46516" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_stack_size at mjs/src/mjs_core.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-vcf4-95pq-m6wr/GHSA-vcf4-95pq-m6wr.json b/advisories/unreviewed/2022/01/GHSA-vcf4-95pq-m6wr/GHSA-vcf4-95pq-m6wr.json index 36309d68e1f..8022ef601df 100644 --- a/advisories/unreviewed/2022/01/GHSA-vcf4-95pq-m6wr/GHSA-vcf4-95pq-m6wr.json +++ b/advisories/unreviewed/2022/01/GHSA-vcf4-95pq-m6wr/GHSA-vcf4-95pq-m6wr.json @@ -7,12 +7,8 @@ "CVE-2021-36348" ], "details": "iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-vcw4-97xh-vjfp/GHSA-vcw4-97xh-vjfp.json b/advisories/unreviewed/2022/01/GHSA-vcw4-97xh-vjfp/GHSA-vcw4-97xh-vjfp.json index d16a18b2a28..0bdaa01a16f 100644 --- a/advisories/unreviewed/2022/01/GHSA-vcw4-97xh-vjfp/GHSA-vcw4-97xh-vjfp.json +++ b/advisories/unreviewed/2022/01/GHSA-vcw4-97xh-vjfp/GHSA-vcw4-97xh-vjfp.json @@ -7,12 +7,8 @@ "CVE-2021-46546" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_next at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-vwj8-hgq2-g82x/GHSA-vwj8-hgq2-g82x.json b/advisories/unreviewed/2022/01/GHSA-vwj8-hgq2-g82x/GHSA-vwj8-hgq2-g82x.json index 16c22ccbae0..42e972a2213 100644 --- a/advisories/unreviewed/2022/01/GHSA-vwj8-hgq2-g82x/GHSA-vwj8-hgq2-g82x.json +++ b/advisories/unreviewed/2022/01/GHSA-vwj8-hgq2-g82x/GHSA-vwj8-hgq2-g82x.json @@ -7,12 +7,8 @@ "CVE-2021-46528" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x5361e. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-wmw8-xf4h-qxp6/GHSA-wmw8-xf4h-qxp6.json b/advisories/unreviewed/2022/01/GHSA-wmw8-xf4h-qxp6/GHSA-wmw8-xf4h-qxp6.json index 8e022508d73..5a31da37cf3 100644 --- a/advisories/unreviewed/2022/01/GHSA-wmw8-xf4h-qxp6/GHSA-wmw8-xf4h-qxp6.json +++ b/advisories/unreviewed/2022/01/GHSA-wmw8-xf4h-qxp6/GHSA-wmw8-xf4h-qxp6.json @@ -7,12 +7,8 @@ "CVE-2021-46488" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArrayConcatCmd at src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-wx3w-5pq8-rxp9/GHSA-wx3w-5pq8-rxp9.json b/advisories/unreviewed/2022/01/GHSA-wx3w-5pq8-rxp9/GHSA-wx3w-5pq8-rxp9.json index 6eb3ec4708a..1c0c9c40f95 100644 --- a/advisories/unreviewed/2022/01/GHSA-wx3w-5pq8-rxp9/GHSA-wx3w-5pq8-rxp9.json +++ b/advisories/unreviewed/2022/01/GHSA-wx3w-5pq8-rxp9/GHSA-wx3w-5pq8-rxp9.json @@ -7,12 +7,8 @@ "CVE-2021-46499" ], "details": "Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueCopyMove in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-x2v2-qh6j-j5r3/GHSA-x2v2-qh6j-j5r3.json b/advisories/unreviewed/2022/01/GHSA-x2v2-qh6j-j5r3/GHSA-x2v2-qh6j-j5r3.json index 526e59a0c17..ae0f4d8d84c 100644 --- a/advisories/unreviewed/2022/01/GHSA-x2v2-qh6j-j5r3/GHSA-x2v2-qh6j-j5r3.json +++ b/advisories/unreviewed/2022/01/GHSA-x2v2-qh6j-j5r3/GHSA-x2v2-qh6j-j5r3.json @@ -7,12 +7,8 @@ "CVE-2022-22790" ], "details": "SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the \"Name\" parameter the attacker can return to the root directory and open the host file. The path exposes sensitive files that users upload", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xcx8-3x77-x2fh/GHSA-xcx8-3x77-x2fh.json b/advisories/unreviewed/2022/01/GHSA-xcx8-3x77-x2fh/GHSA-xcx8-3x77-x2fh.json index 82f0126a42d..2f00ffe1b10 100644 --- a/advisories/unreviewed/2022/01/GHSA-xcx8-3x77-x2fh/GHSA-xcx8-3x77-x2fh.json +++ b/advisories/unreviewed/2022/01/GHSA-xcx8-3x77-x2fh/GHSA-xcx8-3x77-x2fh.json @@ -7,12 +7,8 @@ "CVE-2021-46515" ], "details": "There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xj65-m9r8-w48c/GHSA-xj65-m9r8-w48c.json b/advisories/unreviewed/2022/01/GHSA-xj65-m9r8-w48c/GHSA-xj65-m9r8-w48c.json index 5878b7a6569..f0702734a0d 100644 --- a/advisories/unreviewed/2022/01/GHSA-xj65-m9r8-w48c/GHSA-xj65-m9r8-w48c.json +++ b/advisories/unreviewed/2022/01/GHSA-xj65-m9r8-w48c/GHSA-xj65-m9r8-w48c.json @@ -7,12 +7,8 @@ "CVE-2021-36295" ], "details": "Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xmpv-p68m-37pg/GHSA-xmpv-p68m-37pg.json b/advisories/unreviewed/2022/01/GHSA-xmpv-p68m-37pg/GHSA-xmpv-p68m-37pg.json index 8e7bcaf09fb..f45cc12f02a 100644 --- a/advisories/unreviewed/2022/01/GHSA-xmpv-p68m-37pg/GHSA-xmpv-p68m-37pg.json +++ b/advisories/unreviewed/2022/01/GHSA-xmpv-p68m-37pg/GHSA-xmpv-p68m-37pg.json @@ -7,12 +7,8 @@ "CVE-2021-46517" ], "details": "There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xph7-8872-8h48/GHSA-xph7-8872-8h48.json b/advisories/unreviewed/2022/01/GHSA-xph7-8872-8h48/GHSA-xph7-8872-8h48.json index dcfc700915f..d2993b1bfb0 100644 --- a/advisories/unreviewed/2022/01/GHSA-xph7-8872-8h48/GHSA-xph7-8872-8h48.json +++ b/advisories/unreviewed/2022/01/GHSA-xph7-8872-8h48/GHSA-xph7-8872-8h48.json @@ -7,12 +7,8 @@ "CVE-2021-46065" ], "details": "A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-xqv8-5r47-5vxw/GHSA-xqv8-5r47-5vxw.json b/advisories/unreviewed/2022/01/GHSA-xqv8-5r47-5vxw/GHSA-xqv8-5r47-5vxw.json index d92aee5935a..44d3e080131 100644 --- a/advisories/unreviewed/2022/01/GHSA-xqv8-5r47-5vxw/GHSA-xqv8-5r47-5vxw.json +++ b/advisories/unreviewed/2022/01/GHSA-xqv8-5r47-5vxw/GHSA-xqv8-5r47-5vxw.json @@ -7,12 +7,8 @@ "CVE-2021-46492" ], "details": "Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_FunctionInvoke at src/jsiFunc.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-xxr8-r558-393h/GHSA-xxr8-r558-393h.json b/advisories/unreviewed/2022/01/GHSA-xxr8-r558-393h/GHSA-xxr8-r558-393h.json index 1142b81b55b..0e5b2a2f15e 100644 --- a/advisories/unreviewed/2022/01/GHSA-xxr8-r558-393h/GHSA-xxr8-r558-393h.json +++ b/advisories/unreviewed/2022/01/GHSA-xxr8-r558-393h/GHSA-xxr8-r558-393h.json @@ -7,12 +7,8 @@ "CVE-2021-46556" ], "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-3425-gj4f-6wvw/GHSA-3425-gj4f-6wvw.json b/advisories/unreviewed/2022/02/GHSA-3425-gj4f-6wvw/GHSA-3425-gj4f-6wvw.json index 95e66fe4c72..610f119c85e 100644 --- a/advisories/unreviewed/2022/02/GHSA-3425-gj4f-6wvw/GHSA-3425-gj4f-6wvw.json +++ b/advisories/unreviewed/2022/02/GHSA-3425-gj4f-6wvw/GHSA-3425-gj4f-6wvw.json @@ -7,12 +7,8 @@ "CVE-2021-42639" ], "details": "PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-46pp-qwvm-gq6q/GHSA-46pp-qwvm-gq6q.json b/advisories/unreviewed/2022/02/GHSA-46pp-qwvm-gq6q/GHSA-46pp-qwvm-gq6q.json index 6c2f52ab192..64f58edf62a 100644 --- a/advisories/unreviewed/2022/02/GHSA-46pp-qwvm-gq6q/GHSA-46pp-qwvm-gq6q.json +++ b/advisories/unreviewed/2022/02/GHSA-46pp-qwvm-gq6q/GHSA-46pp-qwvm-gq6q.json @@ -7,12 +7,8 @@ "CVE-2021-24814" ], "details": "The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an \"application/json\" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same domain as the admin panel - there is no same-origin restriction).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-4h43-2654-6c5f/GHSA-4h43-2654-6c5f.json b/advisories/unreviewed/2022/02/GHSA-4h43-2654-6c5f/GHSA-4h43-2654-6c5f.json index 0f63b43edaf..14bdd3a80d6 100644 --- a/advisories/unreviewed/2022/02/GHSA-4h43-2654-6c5f/GHSA-4h43-2654-6c5f.json +++ b/advisories/unreviewed/2022/02/GHSA-4h43-2654-6c5f/GHSA-4h43-2654-6c5f.json @@ -7,12 +7,8 @@ "CVE-2021-42753" ], "details": "An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-5986-54mv-fgm9/GHSA-5986-54mv-fgm9.json b/advisories/unreviewed/2022/02/GHSA-5986-54mv-fgm9/GHSA-5986-54mv-fgm9.json index a304bd62186..a4560ebcd6b 100644 --- a/advisories/unreviewed/2022/02/GHSA-5986-54mv-fgm9/GHSA-5986-54mv-fgm9.json +++ b/advisories/unreviewed/2022/02/GHSA-5986-54mv-fgm9/GHSA-5986-54mv-fgm9.json @@ -7,12 +7,8 @@ "CVE-2021-45897" ], "details": "SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-5v7p-cf4c-24jq/GHSA-5v7p-cf4c-24jq.json b/advisories/unreviewed/2022/02/GHSA-5v7p-cf4c-24jq/GHSA-5v7p-cf4c-24jq.json index b695b4de1af..315aba6fd58 100644 --- a/advisories/unreviewed/2022/02/GHSA-5v7p-cf4c-24jq/GHSA-5v7p-cf4c-24jq.json +++ b/advisories/unreviewed/2022/02/GHSA-5v7p-cf4c-24jq/GHSA-5v7p-cf4c-24jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6fhp-jhwr-cwgh/GHSA-6fhp-jhwr-cwgh.json b/advisories/unreviewed/2022/02/GHSA-6fhp-jhwr-cwgh/GHSA-6fhp-jhwr-cwgh.json index 1b9c2b1e0ff..584b9f64d79 100644 --- a/advisories/unreviewed/2022/02/GHSA-6fhp-jhwr-cwgh/GHSA-6fhp-jhwr-cwgh.json +++ b/advisories/unreviewed/2022/02/GHSA-6fhp-jhwr-cwgh/GHSA-6fhp-jhwr-cwgh.json @@ -7,12 +7,8 @@ "CVE-2021-43062" ], "details": "A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6m6v-cf35-649r/GHSA-6m6v-cf35-649r.json b/advisories/unreviewed/2022/02/GHSA-6m6v-cf35-649r/GHSA-6m6v-cf35-649r.json index 7249e20a199..367392008e6 100644 --- a/advisories/unreviewed/2022/02/GHSA-6m6v-cf35-649r/GHSA-6m6v-cf35-649r.json +++ b/advisories/unreviewed/2022/02/GHSA-6m6v-cf35-649r/GHSA-6m6v-cf35-649r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-7r9c-fccw-3vrf/GHSA-7r9c-fccw-3vrf.json b/advisories/unreviewed/2022/02/GHSA-7r9c-fccw-3vrf/GHSA-7r9c-fccw-3vrf.json index a3854dc9fe2..25a836e82ee 100644 --- a/advisories/unreviewed/2022/02/GHSA-7r9c-fccw-3vrf/GHSA-7r9c-fccw-3vrf.json +++ b/advisories/unreviewed/2022/02/GHSA-7r9c-fccw-3vrf/GHSA-7r9c-fccw-3vrf.json @@ -14,9 +14,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-8h76-r3wq-wvqp/GHSA-8h76-r3wq-wvqp.json b/advisories/unreviewed/2022/02/GHSA-8h76-r3wq-wvqp/GHSA-8h76-r3wq-wvqp.json index d4a439921f5..12e532e8e68 100644 --- a/advisories/unreviewed/2022/02/GHSA-8h76-r3wq-wvqp/GHSA-8h76-r3wq-wvqp.json +++ b/advisories/unreviewed/2022/02/GHSA-8h76-r3wq-wvqp/GHSA-8h76-r3wq-wvqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-8x8f-8g3r-h75g/GHSA-8x8f-8g3r-h75g.json b/advisories/unreviewed/2022/02/GHSA-8x8f-8g3r-h75g/GHSA-8x8f-8g3r-h75g.json index d273c7a4a0e..9d7d81c0431 100644 --- a/advisories/unreviewed/2022/02/GHSA-8x8f-8g3r-h75g/GHSA-8x8f-8g3r-h75g.json +++ b/advisories/unreviewed/2022/02/GHSA-8x8f-8g3r-h75g/GHSA-8x8f-8g3r-h75g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-9wvm-c92g-hvqg/GHSA-9wvm-c92g-hvqg.json b/advisories/unreviewed/2022/02/GHSA-9wvm-c92g-hvqg/GHSA-9wvm-c92g-hvqg.json index bb123be5ce5..003fc38451e 100644 --- a/advisories/unreviewed/2022/02/GHSA-9wvm-c92g-hvqg/GHSA-9wvm-c92g-hvqg.json +++ b/advisories/unreviewed/2022/02/GHSA-9wvm-c92g-hvqg/GHSA-9wvm-c92g-hvqg.json @@ -7,12 +7,8 @@ "CVE-2021-42640" ], "details": "PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-c2px-hrc4-9534/GHSA-c2px-hrc4-9534.json b/advisories/unreviewed/2022/02/GHSA-c2px-hrc4-9534/GHSA-c2px-hrc4-9534.json index a9a525523c6..5db1dd8a95c 100644 --- a/advisories/unreviewed/2022/02/GHSA-c2px-hrc4-9534/GHSA-c2px-hrc4-9534.json +++ b/advisories/unreviewed/2022/02/GHSA-c2px-hrc4-9534/GHSA-c2px-hrc4-9534.json @@ -7,12 +7,8 @@ "CVE-2021-42641" ], "details": "PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-cv9m-jw92-c3v3/GHSA-cv9m-jw92-c3v3.json b/advisories/unreviewed/2022/02/GHSA-cv9m-jw92-c3v3/GHSA-cv9m-jw92-c3v3.json index 5264fe18588..19e3407d602 100644 --- a/advisories/unreviewed/2022/02/GHSA-cv9m-jw92-c3v3/GHSA-cv9m-jw92-c3v3.json +++ b/advisories/unreviewed/2022/02/GHSA-cv9m-jw92-c3v3/GHSA-cv9m-jw92-c3v3.json @@ -7,12 +7,8 @@ "CVE-2021-23521" ], "details": "This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target dir allowing writing arbitrary files on the target host. In some cases, this can allow an attacker to execute arbitrary code. The vulnerable code is in the ZipFile::uncompressEntry function in juce_ZipFile.cpp and is executed when the archive is extracted upon calling uncompressTo() on a ZipFile object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-gq5h-jhm6-q233/GHSA-gq5h-jhm6-q233.json b/advisories/unreviewed/2022/02/GHSA-gq5h-jhm6-q233/GHSA-gq5h-jhm6-q233.json index ce9e7121222..4eb08733009 100644 --- a/advisories/unreviewed/2022/02/GHSA-gq5h-jhm6-q233/GHSA-gq5h-jhm6-q233.json +++ b/advisories/unreviewed/2022/02/GHSA-gq5h-jhm6-q233/GHSA-gq5h-jhm6-q233.json @@ -7,12 +7,8 @@ "CVE-2021-42637" ], "details": "PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-j947-fh29-79v6/GHSA-j947-fh29-79v6.json b/advisories/unreviewed/2022/02/GHSA-j947-fh29-79v6/GHSA-j947-fh29-79v6.json index d87bff2fb34..bf5586f7507 100644 --- a/advisories/unreviewed/2022/02/GHSA-j947-fh29-79v6/GHSA-j947-fh29-79v6.json +++ b/advisories/unreviewed/2022/02/GHSA-j947-fh29-79v6/GHSA-j947-fh29-79v6.json @@ -7,12 +7,8 @@ "CVE-2021-42642" ], "details": "PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-m7g4-jxhg-grwg/GHSA-m7g4-jxhg-grwg.json b/advisories/unreviewed/2022/02/GHSA-m7g4-jxhg-grwg/GHSA-m7g4-jxhg-grwg.json index c95b63836ac..327a87404b7 100644 --- a/advisories/unreviewed/2022/02/GHSA-m7g4-jxhg-grwg/GHSA-m7g4-jxhg-grwg.json +++ b/advisories/unreviewed/2022/02/GHSA-m7g4-jxhg-grwg/GHSA-m7g4-jxhg-grwg.json @@ -7,12 +7,8 @@ "CVE-2021-42633" ], "details": "PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-qrf2-8ggh-7fqc/GHSA-qrf2-8ggh-7fqc.json b/advisories/unreviewed/2022/02/GHSA-qrf2-8ggh-7fqc/GHSA-qrf2-8ggh-7fqc.json index 12976c923c8..20923af1348 100644 --- a/advisories/unreviewed/2022/02/GHSA-qrf2-8ggh-7fqc/GHSA-qrf2-8ggh-7fqc.json +++ b/advisories/unreviewed/2022/02/GHSA-qrf2-8ggh-7fqc/GHSA-qrf2-8ggh-7fqc.json @@ -7,12 +7,8 @@ "CVE-2021-43073" ], "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rxmh-549p-v6m7/GHSA-rxmh-549p-v6m7.json b/advisories/unreviewed/2022/02/GHSA-rxmh-549p-v6m7/GHSA-rxmh-549p-v6m7.json index d60bddb1250..b7ef01ee631 100644 --- a/advisories/unreviewed/2022/02/GHSA-rxmh-549p-v6m7/GHSA-rxmh-549p-v6m7.json +++ b/advisories/unreviewed/2022/02/GHSA-rxmh-549p-v6m7/GHSA-rxmh-549p-v6m7.json @@ -7,12 +7,8 @@ "CVE-2021-24043" ], "details": "A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet during an established call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-v8x4-gj4q-pwgq/GHSA-v8x4-gj4q-pwgq.json b/advisories/unreviewed/2022/02/GHSA-v8x4-gj4q-pwgq/GHSA-v8x4-gj4q-pwgq.json index b1a3a5a0bb8..6853cd2cac5 100644 --- a/advisories/unreviewed/2022/02/GHSA-v8x4-gj4q-pwgq/GHSA-v8x4-gj4q-pwgq.json +++ b/advisories/unreviewed/2022/02/GHSA-v8x4-gj4q-pwgq/GHSA-v8x4-gj4q-pwgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-vj6w-cj6v-8ff8/GHSA-vj6w-cj6v-8ff8.json b/advisories/unreviewed/2022/02/GHSA-vj6w-cj6v-8ff8/GHSA-vj6w-cj6v-8ff8.json index c0337af5aaa..cbe6ddee68c 100644 --- a/advisories/unreviewed/2022/02/GHSA-vj6w-cj6v-8ff8/GHSA-vj6w-cj6v-8ff8.json +++ b/advisories/unreviewed/2022/02/GHSA-vj6w-cj6v-8ff8/GHSA-vj6w-cj6v-8ff8.json @@ -7,12 +7,8 @@ "CVE-2022-24301" ], "details": "In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/02/GHSA-vxpg-8q82-wmcp/GHSA-vxpg-8q82-wmcp.json b/advisories/unreviewed/2022/02/GHSA-vxpg-8q82-wmcp/GHSA-vxpg-8q82-wmcp.json index 3f576c74af7..be2c1844cac 100644 --- a/advisories/unreviewed/2022/02/GHSA-vxpg-8q82-wmcp/GHSA-vxpg-8q82-wmcp.json +++ b/advisories/unreviewed/2022/02/GHSA-vxpg-8q82-wmcp/GHSA-vxpg-8q82-wmcp.json @@ -7,12 +7,8 @@ "CVE-2022-24223" ], "details": "AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-xfch-762x-q3v9/GHSA-xfch-762x-q3v9.json b/advisories/unreviewed/2022/02/GHSA-xfch-762x-q3v9/GHSA-xfch-762x-q3v9.json index beccfa986ae..b3f94e74330 100644 --- a/advisories/unreviewed/2022/02/GHSA-xfch-762x-q3v9/GHSA-xfch-762x-q3v9.json +++ b/advisories/unreviewed/2022/02/GHSA-xfch-762x-q3v9/GHSA-xfch-762x-q3v9.json @@ -7,12 +7,8 @@ "CVE-2021-36193" ], "details": "Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-35fm-4q2r-j938/GHSA-35fm-4q2r-j938.json b/advisories/unreviewed/2022/03/GHSA-35fm-4q2r-j938/GHSA-35fm-4q2r-j938.json index 6ab6d5bf443..abd61c10f6b 100644 --- a/advisories/unreviewed/2022/03/GHSA-35fm-4q2r-j938/GHSA-35fm-4q2r-j938.json +++ b/advisories/unreviewed/2022/03/GHSA-35fm-4q2r-j938/GHSA-35fm-4q2r-j938.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-h9pr-8j9g-2rhq/GHSA-h9pr-8j9g-2rhq.json b/advisories/unreviewed/2022/03/GHSA-h9pr-8j9g-2rhq/GHSA-h9pr-8j9g-2rhq.json index aec1501cd6b..28d8df34f05 100644 --- a/advisories/unreviewed/2022/03/GHSA-h9pr-8j9g-2rhq/GHSA-h9pr-8j9g-2rhq.json +++ b/advisories/unreviewed/2022/03/GHSA-h9pr-8j9g-2rhq/GHSA-h9pr-8j9g-2rhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22jf-974v-hf7j/GHSA-22jf-974v-hf7j.json b/advisories/unreviewed/2022/05/GHSA-22jf-974v-hf7j/GHSA-22jf-974v-hf7j.json index be0e11dbb55..70f0c5fa4d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-22jf-974v-hf7j/GHSA-22jf-974v-hf7j.json +++ b/advisories/unreviewed/2022/05/GHSA-22jf-974v-hf7j/GHSA-22jf-974v-hf7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24qp-pvw9-442x/GHSA-24qp-pvw9-442x.json b/advisories/unreviewed/2022/05/GHSA-24qp-pvw9-442x/GHSA-24qp-pvw9-442x.json index dfce9acd21c..99dbb720f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-24qp-pvw9-442x/GHSA-24qp-pvw9-442x.json +++ b/advisories/unreviewed/2022/05/GHSA-24qp-pvw9-442x/GHSA-24qp-pvw9-442x.json @@ -7,12 +7,8 @@ "CVE-2014-0865" ], "details": "RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-259r-6293-4g55/GHSA-259r-6293-4g55.json b/advisories/unreviewed/2022/05/GHSA-259r-6293-4g55/GHSA-259r-6293-4g55.json index 885aef19786..66ca12d9f59 100644 --- a/advisories/unreviewed/2022/05/GHSA-259r-6293-4g55/GHSA-259r-6293-4g55.json +++ b/advisories/unreviewed/2022/05/GHSA-259r-6293-4g55/GHSA-259r-6293-4g55.json @@ -7,12 +7,8 @@ "CVE-2014-8083" ], "details": "SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25qv-mpwh-3c2j/GHSA-25qv-mpwh-3c2j.json b/advisories/unreviewed/2022/05/GHSA-25qv-mpwh-3c2j/GHSA-25qv-mpwh-3c2j.json index 11fc2ebff5c..9f904e6363c 100644 --- a/advisories/unreviewed/2022/05/GHSA-25qv-mpwh-3c2j/GHSA-25qv-mpwh-3c2j.json +++ b/advisories/unreviewed/2022/05/GHSA-25qv-mpwh-3c2j/GHSA-25qv-mpwh-3c2j.json @@ -7,12 +7,8 @@ "CVE-2014-4631" ], "details": "RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-263x-9fgq-56vg/GHSA-263x-9fgq-56vg.json b/advisories/unreviewed/2022/05/GHSA-263x-9fgq-56vg/GHSA-263x-9fgq-56vg.json index 292f05252ee..2dccf0d2157 100644 --- a/advisories/unreviewed/2022/05/GHSA-263x-9fgq-56vg/GHSA-263x-9fgq-56vg.json +++ b/advisories/unreviewed/2022/05/GHSA-263x-9fgq-56vg/GHSA-263x-9fgq-56vg.json @@ -7,12 +7,8 @@ "CVE-2014-5178" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1) creating a topic or (2) posting an answer. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26g5-xm46-wmp6/GHSA-26g5-xm46-wmp6.json b/advisories/unreviewed/2022/05/GHSA-26g5-xm46-wmp6/GHSA-26g5-xm46-wmp6.json index ae13c70e59b..54b6a3aa2b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-26g5-xm46-wmp6/GHSA-26g5-xm46-wmp6.json +++ b/advisories/unreviewed/2022/05/GHSA-26g5-xm46-wmp6/GHSA-26g5-xm46-wmp6.json @@ -7,12 +7,8 @@ "CVE-2014-5300" ], "details": "Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26rr-whcg-5f4g/GHSA-26rr-whcg-5f4g.json b/advisories/unreviewed/2022/05/GHSA-26rr-whcg-5f4g/GHSA-26rr-whcg-5f4g.json index 2cb0a2ec618..0a65650aeb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-26rr-whcg-5f4g/GHSA-26rr-whcg-5f4g.json +++ b/advisories/unreviewed/2022/05/GHSA-26rr-whcg-5f4g/GHSA-26rr-whcg-5f4g.json @@ -7,12 +7,8 @@ "CVE-2013-1740" ], "details": "The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29jh-wx23-42f7/GHSA-29jh-wx23-42f7.json b/advisories/unreviewed/2022/05/GHSA-29jh-wx23-42f7/GHSA-29jh-wx23-42f7.json index 2efc22b099c..cbd5a95b053 100644 --- a/advisories/unreviewed/2022/05/GHSA-29jh-wx23-42f7/GHSA-29jh-wx23-42f7.json +++ b/advisories/unreviewed/2022/05/GHSA-29jh-wx23-42f7/GHSA-29jh-wx23-42f7.json @@ -7,12 +7,8 @@ "CVE-2014-9711" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML via the (1) ReportName (Job Name) parameter to the Explorer report scheduler (cgi-bin/WsCgiExplorerSchedule.exe) in the Job Queue or the col parameter to the (2) Names or (3) Anonymous (explorer_wse/explorer_anon.exe) summary report page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c64-8v4j-vw3m/GHSA-2c64-8v4j-vw3m.json b/advisories/unreviewed/2022/05/GHSA-2c64-8v4j-vw3m/GHSA-2c64-8v4j-vw3m.json index f8cbab1d791..4680924d601 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c64-8v4j-vw3m/GHSA-2c64-8v4j-vw3m.json +++ b/advisories/unreviewed/2022/05/GHSA-2c64-8v4j-vw3m/GHSA-2c64-8v4j-vw3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c8x-w9gg-x7v5/GHSA-2c8x-w9gg-x7v5.json b/advisories/unreviewed/2022/05/GHSA-2c8x-w9gg-x7v5/GHSA-2c8x-w9gg-x7v5.json index 71317fbcb6a..c155aad5970 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c8x-w9gg-x7v5/GHSA-2c8x-w9gg-x7v5.json +++ b/advisories/unreviewed/2022/05/GHSA-2c8x-w9gg-x7v5/GHSA-2c8x-w9gg-x7v5.json @@ -7,12 +7,8 @@ "CVE-2011-1577" ], "details": "Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI GUID partition-table header on removable media.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cqq-v6m5-rqq4/GHSA-2cqq-v6m5-rqq4.json b/advisories/unreviewed/2022/05/GHSA-2cqq-v6m5-rqq4/GHSA-2cqq-v6m5-rqq4.json index a9111bbe886..a3b3b0b4828 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cqq-v6m5-rqq4/GHSA-2cqq-v6m5-rqq4.json +++ b/advisories/unreviewed/2022/05/GHSA-2cqq-v6m5-rqq4/GHSA-2cqq-v6m5-rqq4.json @@ -7,12 +7,8 @@ "CVE-2011-5001" ], "details": "Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g59-pjjw-j55p/GHSA-2g59-pjjw-j55p.json b/advisories/unreviewed/2022/05/GHSA-2g59-pjjw-j55p/GHSA-2g59-pjjw-j55p.json index 83ec9bd3e3d..b185944d117 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g59-pjjw-j55p/GHSA-2g59-pjjw-j55p.json +++ b/advisories/unreviewed/2022/05/GHSA-2g59-pjjw-j55p/GHSA-2g59-pjjw-j55p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g83-fxgw-wvr6/GHSA-2g83-fxgw-wvr6.json b/advisories/unreviewed/2022/05/GHSA-2g83-fxgw-wvr6/GHSA-2g83-fxgw-wvr6.json index 3f6d8126305..f8f915ef38d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g83-fxgw-wvr6/GHSA-2g83-fxgw-wvr6.json +++ b/advisories/unreviewed/2022/05/GHSA-2g83-fxgw-wvr6/GHSA-2g83-fxgw-wvr6.json @@ -7,12 +7,8 @@ "CVE-2014-5121" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gfp-29x3-m5qq/GHSA-2gfp-29x3-m5qq.json b/advisories/unreviewed/2022/05/GHSA-2gfp-29x3-m5qq/GHSA-2gfp-29x3-m5qq.json index a084e19aae4..2fb3c3d72dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gfp-29x3-m5qq/GHSA-2gfp-29x3-m5qq.json +++ b/advisories/unreviewed/2022/05/GHSA-2gfp-29x3-m5qq/GHSA-2gfp-29x3-m5qq.json @@ -7,12 +7,8 @@ "CVE-2014-4246" ], "details": "Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h3v-8xgc-fcxp/GHSA-2h3v-8xgc-fcxp.json b/advisories/unreviewed/2022/05/GHSA-2h3v-8xgc-fcxp/GHSA-2h3v-8xgc-fcxp.json index d4e44817b34..75c63a89632 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h3v-8xgc-fcxp/GHSA-2h3v-8xgc-fcxp.json +++ b/advisories/unreviewed/2022/05/GHSA-2h3v-8xgc-fcxp/GHSA-2h3v-8xgc-fcxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m7g-78xc-qr55/GHSA-2m7g-78xc-qr55.json b/advisories/unreviewed/2022/05/GHSA-2m7g-78xc-qr55/GHSA-2m7g-78xc-qr55.json index 8ca6ab799ac..5c3a928f816 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m7g-78xc-qr55/GHSA-2m7g-78xc-qr55.json +++ b/advisories/unreviewed/2022/05/GHSA-2m7g-78xc-qr55/GHSA-2m7g-78xc-qr55.json @@ -7,12 +7,8 @@ "CVE-2014-4242" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2pm7-wcx5-9h5j/GHSA-2pm7-wcx5-9h5j.json b/advisories/unreviewed/2022/05/GHSA-2pm7-wcx5-9h5j/GHSA-2pm7-wcx5-9h5j.json index 9fbedb916c9..cb51d23e755 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pm7-wcx5-9h5j/GHSA-2pm7-wcx5-9h5j.json +++ b/advisories/unreviewed/2022/05/GHSA-2pm7-wcx5-9h5j/GHSA-2pm7-wcx5-9h5j.json @@ -7,12 +7,8 @@ "CVE-2014-4735" ], "details": "Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json b/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json index 062ccca6100..4e7f9863253 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json +++ b/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pwf-98xm-hgm2/GHSA-2pwf-98xm-hgm2.json b/advisories/unreviewed/2022/05/GHSA-2pwf-98xm-hgm2/GHSA-2pwf-98xm-hgm2.json index 010a337ed9f..779b2a184eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pwf-98xm-hgm2/GHSA-2pwf-98xm-hgm2.json +++ b/advisories/unreviewed/2022/05/GHSA-2pwf-98xm-hgm2/GHSA-2pwf-98xm-hgm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qf6-f49c-83qc/GHSA-2qf6-f49c-83qc.json b/advisories/unreviewed/2022/05/GHSA-2qf6-f49c-83qc/GHSA-2qf6-f49c-83qc.json index 0168ad3e0cb..08aadffaae6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qf6-f49c-83qc/GHSA-2qf6-f49c-83qc.json +++ b/advisories/unreviewed/2022/05/GHSA-2qf6-f49c-83qc/GHSA-2qf6-f49c-83qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rh2-h4h3-63w4/GHSA-2rh2-h4h3-63w4.json b/advisories/unreviewed/2022/05/GHSA-2rh2-h4h3-63w4/GHSA-2rh2-h4h3-63w4.json index b5e3156343e..0a5d92b6676 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rh2-h4h3-63w4/GHSA-2rh2-h4h3-63w4.json +++ b/advisories/unreviewed/2022/05/GHSA-2rh2-h4h3-63w4/GHSA-2rh2-h4h3-63w4.json @@ -7,12 +7,8 @@ "CVE-2014-9433" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idcat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rpg-qc85-4c9v/GHSA-2rpg-qc85-4c9v.json b/advisories/unreviewed/2022/05/GHSA-2rpg-qc85-4c9v/GHSA-2rpg-qc85-4c9v.json index 103d7b5373d..e4729924829 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rpg-qc85-4c9v/GHSA-2rpg-qc85-4c9v.json +++ b/advisories/unreviewed/2022/05/GHSA-2rpg-qc85-4c9v/GHSA-2rpg-qc85-4c9v.json @@ -7,12 +7,8 @@ "CVE-2013-2585" ], "details": "Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId//filenameOriginal/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vx3-hm2p-g49x/GHSA-2vx3-hm2p-g49x.json b/advisories/unreviewed/2022/05/GHSA-2vx3-hm2p-g49x/GHSA-2vx3-hm2p-g49x.json index ec0e9b2d78f..5ea7c4200f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vx3-hm2p-g49x/GHSA-2vx3-hm2p-g49x.json +++ b/advisories/unreviewed/2022/05/GHSA-2vx3-hm2p-g49x/GHSA-2vx3-hm2p-g49x.json @@ -7,12 +7,8 @@ "CVE-2014-7956" ], "details": "Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w7h-pgq5-9g2m/GHSA-2w7h-pgq5-9g2m.json b/advisories/unreviewed/2022/05/GHSA-2w7h-pgq5-9g2m/GHSA-2w7h-pgq5-9g2m.json index bfd44093672..67c0af1fcdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w7h-pgq5-9g2m/GHSA-2w7h-pgq5-9g2m.json +++ b/advisories/unreviewed/2022/05/GHSA-2w7h-pgq5-9g2m/GHSA-2w7h-pgq5-9g2m.json @@ -7,12 +7,8 @@ "CVE-2014-2729" ], "details": "Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w8x-37m4-26px/GHSA-2w8x-37m4-26px.json b/advisories/unreviewed/2022/05/GHSA-2w8x-37m4-26px/GHSA-2w8x-37m4-26px.json index ea9cb409784..621226adeb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w8x-37m4-26px/GHSA-2w8x-37m4-26px.json +++ b/advisories/unreviewed/2022/05/GHSA-2w8x-37m4-26px/GHSA-2w8x-37m4-26px.json @@ -7,12 +7,8 @@ "CVE-2011-4670" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax action, (2) activity_mode parameter in a DetailView action, (3) contact_id and (4) parent_id parameters in an EditView action, (5) day, (6) month, (7) subtab, (8) view, and (9) viewOption parameters in the index action, and (10) start parameter in the ListView action to the Calendar module; (11) return_action and (12) return_module parameters in the EditView action, and (13) query parameter in an index action to the Campaigns module; (14) return_url and (15) workflow_id parameters in an editworkflow action to the com_vtiger_workflow module; (16) display_view parameter in an index action to the Dashboard module; (17) closingdate_end, (18) closingdate_start, (19) date_closed, (20) owner, (21) leadsource, (22) sales_stage, and (23) type parameters in a ListView action to the Potentials module; (24) folderid parameter in a SaveandRun action to the Reports module; (25) returnaction and (26) groupId parameters in a createnewgroup action, (27) mode and (28) parent parameters in a createrole action, (29) src_module in a ModuleManager action, (30) mode and (31) profile_id parameters in a profilePrivileges action, and (32) roleid parameter in a RoleDetailView to the Settings module; and (33) action parameter to the Home module and (34) module parameter to phprint.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wh9-8pg9-7cgx/GHSA-2wh9-8pg9-7cgx.json b/advisories/unreviewed/2022/05/GHSA-2wh9-8pg9-7cgx/GHSA-2wh9-8pg9-7cgx.json index b753cc36484..a55a75c4a7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wh9-8pg9-7cgx/GHSA-2wh9-8pg9-7cgx.json +++ b/advisories/unreviewed/2022/05/GHSA-2wh9-8pg9-7cgx/GHSA-2wh9-8pg9-7cgx.json @@ -7,12 +7,8 @@ "CVE-2014-0866" ], "details": "RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2whc-42x6-f9r4/GHSA-2whc-42x6-f9r4.json b/advisories/unreviewed/2022/05/GHSA-2whc-42x6-f9r4/GHSA-2whc-42x6-f9r4.json index 4720ffcf306..4db1428069a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2whc-42x6-f9r4/GHSA-2whc-42x6-f9r4.json +++ b/advisories/unreviewed/2022/05/GHSA-2whc-42x6-f9r4/GHSA-2whc-42x6-f9r4.json @@ -7,12 +7,8 @@ "CVE-2015-1467" ], "details": "Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wjg-893f-qh7w/GHSA-2wjg-893f-qh7w.json b/advisories/unreviewed/2022/05/GHSA-2wjg-893f-qh7w/GHSA-2wjg-893f-qh7w.json index ef649cb7c55..4c8ac824eda 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wjg-893f-qh7w/GHSA-2wjg-893f-qh7w.json +++ b/advisories/unreviewed/2022/05/GHSA-2wjg-893f-qh7w/GHSA-2wjg-893f-qh7w.json @@ -7,12 +7,8 @@ "CVE-2014-2987" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an admin.uiaccounts.add_user action to index.php or (2) modify settings via the newsettings parameter in an admin.uiconfig.index action to index.php. NOTE: vector 2 can be used to execute arbitrary PHP code by leveraging CVE-2014-2988.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wx9-w67p-qcqq/GHSA-2wx9-w67p-qcqq.json b/advisories/unreviewed/2022/05/GHSA-2wx9-w67p-qcqq/GHSA-2wx9-w67p-qcqq.json index 446e60f61d9..75e549ebc75 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wx9-w67p-qcqq/GHSA-2wx9-w67p-qcqq.json +++ b/advisories/unreviewed/2022/05/GHSA-2wx9-w67p-qcqq/GHSA-2wx9-w67p-qcqq.json @@ -7,12 +7,8 @@ "CVE-2014-4271" ], "details": "Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect availability via unknown vectors related to Agent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32fq-43mr-f4fp/GHSA-32fq-43mr-f4fp.json b/advisories/unreviewed/2022/05/GHSA-32fq-43mr-f4fp/GHSA-32fq-43mr-f4fp.json index 5dde302ee65..e5b521dbc3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-32fq-43mr-f4fp/GHSA-32fq-43mr-f4fp.json +++ b/advisories/unreviewed/2022/05/GHSA-32fq-43mr-f4fp/GHSA-32fq-43mr-f4fp.json @@ -7,12 +7,8 @@ "CVE-2014-3863" ], "details": "Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33r9-2w5v-33vg/GHSA-33r9-2w5v-33vg.json b/advisories/unreviewed/2022/05/GHSA-33r9-2w5v-33vg/GHSA-33r9-2w5v-33vg.json index 03bd5b93267..666b66b3706 100644 --- a/advisories/unreviewed/2022/05/GHSA-33r9-2w5v-33vg/GHSA-33r9-2w5v-33vg.json +++ b/advisories/unreviewed/2022/05/GHSA-33r9-2w5v-33vg/GHSA-33r9-2w5v-33vg.json @@ -7,12 +7,8 @@ "CVE-2015-0247" ], "details": "Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33rm-chj2-wr75/GHSA-33rm-chj2-wr75.json b/advisories/unreviewed/2022/05/GHSA-33rm-chj2-wr75/GHSA-33rm-chj2-wr75.json index d12925d9bc2..524556a0b12 100644 --- a/advisories/unreviewed/2022/05/GHSA-33rm-chj2-wr75/GHSA-33rm-chj2-wr75.json +++ b/advisories/unreviewed/2022/05/GHSA-33rm-chj2-wr75/GHSA-33rm-chj2-wr75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34xm-pchf-hr5w/GHSA-34xm-pchf-hr5w.json b/advisories/unreviewed/2022/05/GHSA-34xm-pchf-hr5w/GHSA-34xm-pchf-hr5w.json index 6962e547d40..2df64ae6b9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-34xm-pchf-hr5w/GHSA-34xm-pchf-hr5w.json +++ b/advisories/unreviewed/2022/05/GHSA-34xm-pchf-hr5w/GHSA-34xm-pchf-hr5w.json @@ -7,12 +7,8 @@ "CVE-2011-4564" ], "details": "Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter in a module action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35xc-5p56-vcx8/GHSA-35xc-5p56-vcx8.json b/advisories/unreviewed/2022/05/GHSA-35xc-5p56-vcx8/GHSA-35xc-5p56-vcx8.json index 7baf8626198..9bfa6b79c51 100644 --- a/advisories/unreviewed/2022/05/GHSA-35xc-5p56-vcx8/GHSA-35xc-5p56-vcx8.json +++ b/advisories/unreviewed/2022/05/GHSA-35xc-5p56-vcx8/GHSA-35xc-5p56-vcx8.json @@ -7,12 +7,8 @@ "CVE-2014-3418" ], "details": "config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-363j-w49v-cj57/GHSA-363j-w49v-cj57.json b/advisories/unreviewed/2022/05/GHSA-363j-w49v-cj57/GHSA-363j-w49v-cj57.json index 7d384184a99..6d115f5b798 100644 --- a/advisories/unreviewed/2022/05/GHSA-363j-w49v-cj57/GHSA-363j-w49v-cj57.json +++ b/advisories/unreviewed/2022/05/GHSA-363j-w49v-cj57/GHSA-363j-w49v-cj57.json @@ -7,12 +7,8 @@ "CVE-2014-2575" ], "details": "Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3656-jvhv-q239/GHSA-3656-jvhv-q239.json b/advisories/unreviewed/2022/05/GHSA-3656-jvhv-q239/GHSA-3656-jvhv-q239.json index 3308a50dc51..a8d895d00ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-3656-jvhv-q239/GHSA-3656-jvhv-q239.json +++ b/advisories/unreviewed/2022/05/GHSA-3656-jvhv-q239/GHSA-3656-jvhv-q239.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36hq-fr9w-frm9/GHSA-36hq-fr9w-frm9.json b/advisories/unreviewed/2022/05/GHSA-36hq-fr9w-frm9/GHSA-36hq-fr9w-frm9.json index 80ef207e7d0..1c05eadbc8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-36hq-fr9w-frm9/GHSA-36hq-fr9w-frm9.json +++ b/advisories/unreviewed/2022/05/GHSA-36hq-fr9w-frm9/GHSA-36hq-fr9w-frm9.json @@ -7,12 +7,8 @@ "CVE-2015-2103" ], "details": "Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36pj-pfw6-cc65/GHSA-36pj-pfw6-cc65.json b/advisories/unreviewed/2022/05/GHSA-36pj-pfw6-cc65/GHSA-36pj-pfw6-cc65.json index 719adb76f7d..3b3185df31a 100644 --- a/advisories/unreviewed/2022/05/GHSA-36pj-pfw6-cc65/GHSA-36pj-pfw6-cc65.json +++ b/advisories/unreviewed/2022/05/GHSA-36pj-pfw6-cc65/GHSA-36pj-pfw6-cc65.json @@ -7,12 +7,8 @@ "CVE-2014-5098" ], "details": "Cross-site scripting (XSS) vulnerability in the Search module before 1.2.2 in Jamroom allows remote attackers to inject arbitrary web script or HTML via the query string to search/results/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37f5-2q74-7wvc/GHSA-37f5-2q74-7wvc.json b/advisories/unreviewed/2022/05/GHSA-37f5-2q74-7wvc/GHSA-37f5-2q74-7wvc.json index ee890d64330..62ce17b41a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-37f5-2q74-7wvc/GHSA-37f5-2q74-7wvc.json +++ b/advisories/unreviewed/2022/05/GHSA-37f5-2q74-7wvc/GHSA-37f5-2q74-7wvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37fc-4qqv-26w3/GHSA-37fc-4qqv-26w3.json b/advisories/unreviewed/2022/05/GHSA-37fc-4qqv-26w3/GHSA-37fc-4qqv-26w3.json index 646a742fefc..ab32bb2a5e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-37fc-4qqv-26w3/GHSA-37fc-4qqv-26w3.json +++ b/advisories/unreviewed/2022/05/GHSA-37fc-4qqv-26w3/GHSA-37fc-4qqv-26w3.json @@ -7,12 +7,8 @@ "CVE-2014-3427" ], "details": "CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-387h-jhfw-w4cc/GHSA-387h-jhfw-w4cc.json b/advisories/unreviewed/2022/05/GHSA-387h-jhfw-w4cc/GHSA-387h-jhfw-w4cc.json index 9f3e7792adc..c966fd6b2aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-387h-jhfw-w4cc/GHSA-387h-jhfw-w4cc.json +++ b/advisories/unreviewed/2022/05/GHSA-387h-jhfw-w4cc/GHSA-387h-jhfw-w4cc.json @@ -7,12 +7,8 @@ "CVE-2014-4205" ], "details": "Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Portal Framework, a different vulnerability than CVE-2014-2491.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-387x-jwqw-43f3/GHSA-387x-jwqw-43f3.json b/advisories/unreviewed/2022/05/GHSA-387x-jwqw-43f3/GHSA-387x-jwqw-43f3.json index 1d0e792b796..5b8b83057f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-387x-jwqw-43f3/GHSA-387x-jwqw-43f3.json +++ b/advisories/unreviewed/2022/05/GHSA-387x-jwqw-43f3/GHSA-387x-jwqw-43f3.json @@ -7,12 +7,8 @@ "CVE-2014-2399" ], "details": "Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38j5-x223-737f/GHSA-38j5-x223-737f.json b/advisories/unreviewed/2022/05/GHSA-38j5-x223-737f/GHSA-38j5-x223-737f.json index 6e6ee42dd4d..06b96d65382 100644 --- a/advisories/unreviewed/2022/05/GHSA-38j5-x223-737f/GHSA-38j5-x223-737f.json +++ b/advisories/unreviewed/2022/05/GHSA-38j5-x223-737f/GHSA-38j5-x223-737f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38v6-89r5-874g/GHSA-38v6-89r5-874g.json b/advisories/unreviewed/2022/05/GHSA-38v6-89r5-874g/GHSA-38v6-89r5-874g.json index 32ae2fa67d3..c133565d7bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-38v6-89r5-874g/GHSA-38v6-89r5-874g.json +++ b/advisories/unreviewed/2022/05/GHSA-38v6-89r5-874g/GHSA-38v6-89r5-874g.json @@ -7,12 +7,8 @@ "CVE-2014-8791" ], "details": "project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-393q-2jgx-p9ph/GHSA-393q-2jgx-p9ph.json b/advisories/unreviewed/2022/05/GHSA-393q-2jgx-p9ph/GHSA-393q-2jgx-p9ph.json index 83d5924999f..16f32afee68 100644 --- a/advisories/unreviewed/2022/05/GHSA-393q-2jgx-p9ph/GHSA-393q-2jgx-p9ph.json +++ b/advisories/unreviewed/2022/05/GHSA-393q-2jgx-p9ph/GHSA-393q-2jgx-p9ph.json @@ -7,12 +7,8 @@ "CVE-2014-2301" ], "details": "OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39v5-jf84-wf9c/GHSA-39v5-jf84-wf9c.json b/advisories/unreviewed/2022/05/GHSA-39v5-jf84-wf9c/GHSA-39v5-jf84-wf9c.json index 6958a51ea5e..abe3b0846ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-39v5-jf84-wf9c/GHSA-39v5-jf84-wf9c.json +++ b/advisories/unreviewed/2022/05/GHSA-39v5-jf84-wf9c/GHSA-39v5-jf84-wf9c.json @@ -7,12 +7,8 @@ "CVE-2014-5176" ], "details": "SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39w3-c286-wqjc/GHSA-39w3-c286-wqjc.json b/advisories/unreviewed/2022/05/GHSA-39w3-c286-wqjc/GHSA-39w3-c286-wqjc.json index 2906278e4ac..40e5a7b9650 100644 --- a/advisories/unreviewed/2022/05/GHSA-39w3-c286-wqjc/GHSA-39w3-c286-wqjc.json +++ b/advisories/unreviewed/2022/05/GHSA-39w3-c286-wqjc/GHSA-39w3-c286-wqjc.json @@ -7,12 +7,8 @@ "CVE-2014-9570" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the access_log page to wp-admin/users.php or (2) simple_security_ip_blacklist[] parameter in an add_blacklist_ip action in the ip_blacklist page to wp-admin/users.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cp8-5f2x-4g4m/GHSA-3cp8-5f2x-4g4m.json b/advisories/unreviewed/2022/05/GHSA-3cp8-5f2x-4g4m/GHSA-3cp8-5f2x-4g4m.json index 7f01631fa67..0a8a7d821f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cp8-5f2x-4g4m/GHSA-3cp8-5f2x-4g4m.json +++ b/advisories/unreviewed/2022/05/GHSA-3cp8-5f2x-4g4m/GHSA-3cp8-5f2x-4g4m.json @@ -7,12 +7,8 @@ "CVE-2014-4204" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f63-vqp6-r5p2/GHSA-3f63-vqp6-r5p2.json b/advisories/unreviewed/2022/05/GHSA-3f63-vqp6-r5p2/GHSA-3f63-vqp6-r5p2.json index 19b8d23849f..0e760c13c55 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f63-vqp6-r5p2/GHSA-3f63-vqp6-r5p2.json +++ b/advisories/unreviewed/2022/05/GHSA-3f63-vqp6-r5p2/GHSA-3f63-vqp6-r5p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g57-8qrr-phw8/GHSA-3g57-8qrr-phw8.json b/advisories/unreviewed/2022/05/GHSA-3g57-8qrr-phw8/GHSA-3g57-8qrr-phw8.json index da15ae61d77..44beabeda8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g57-8qrr-phw8/GHSA-3g57-8qrr-phw8.json +++ b/advisories/unreviewed/2022/05/GHSA-3g57-8qrr-phw8/GHSA-3g57-8qrr-phw8.json @@ -7,12 +7,8 @@ "CVE-2014-5137" ], "details": "Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h64-25x5-v8wv/GHSA-3h64-25x5-v8wv.json b/advisories/unreviewed/2022/05/GHSA-3h64-25x5-v8wv/GHSA-3h64-25x5-v8wv.json index ec4c6fc0a67..b8f481035a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h64-25x5-v8wv/GHSA-3h64-25x5-v8wv.json +++ b/advisories/unreviewed/2022/05/GHSA-3h64-25x5-v8wv/GHSA-3h64-25x5-v8wv.json @@ -7,12 +7,8 @@ "CVE-2011-5110" ], "details": "Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h95-q6m8-947m/GHSA-3h95-q6m8-947m.json b/advisories/unreviewed/2022/05/GHSA-3h95-q6m8-947m/GHSA-3h95-q6m8-947m.json index 559020500c6..8bdc2d4969b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h95-q6m8-947m/GHSA-3h95-q6m8-947m.json +++ b/advisories/unreviewed/2022/05/GHSA-3h95-q6m8-947m/GHSA-3h95-q6m8-947m.json @@ -7,12 +7,8 @@ "CVE-2015-1176" ], "details": "Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3m95-7rcm-xpxr/GHSA-3m95-7rcm-xpxr.json b/advisories/unreviewed/2022/05/GHSA-3m95-7rcm-xpxr/GHSA-3m95-7rcm-xpxr.json index 58a3ae1eb64..c4d0e7d7f98 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m95-7rcm-xpxr/GHSA-3m95-7rcm-xpxr.json +++ b/advisories/unreviewed/2022/05/GHSA-3m95-7rcm-xpxr/GHSA-3m95-7rcm-xpxr.json @@ -7,12 +7,8 @@ "CVE-2014-3759" ], "details": "Multiple SQL injection vulnerabilities in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allow remote attackers to execute arbitrary SQL commands via vectors related to the (1) search or (2) list functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mf2-x699-cxr9/GHSA-3mf2-x699-cxr9.json b/advisories/unreviewed/2022/05/GHSA-3mf2-x699-cxr9/GHSA-3mf2-x699-cxr9.json index 7665632f9f9..5cf98dc0aac 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mf2-x699-cxr9/GHSA-3mf2-x699-cxr9.json +++ b/advisories/unreviewed/2022/05/GHSA-3mf2-x699-cxr9/GHSA-3mf2-x699-cxr9.json @@ -7,12 +7,8 @@ "CVE-2014-0867" ], "details": "rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mm6-vwmh-qm9c/GHSA-3mm6-vwmh-qm9c.json b/advisories/unreviewed/2022/05/GHSA-3mm6-vwmh-qm9c/GHSA-3mm6-vwmh-qm9c.json index 499846ba773..dc31d11b657 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mm6-vwmh-qm9c/GHSA-3mm6-vwmh-qm9c.json +++ b/advisories/unreviewed/2022/05/GHSA-3mm6-vwmh-qm9c/GHSA-3mm6-vwmh-qm9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mmx-4r9c-p6f8/GHSA-3mmx-4r9c-p6f8.json b/advisories/unreviewed/2022/05/GHSA-3mmx-4r9c-p6f8/GHSA-3mmx-4r9c-p6f8.json index 60771a2cb7b..1d42fb14302 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mmx-4r9c-p6f8/GHSA-3mmx-4r9c-p6f8.json +++ b/advisories/unreviewed/2022/05/GHSA-3mmx-4r9c-p6f8/GHSA-3mmx-4r9c-p6f8.json @@ -7,12 +7,8 @@ "CVE-2014-2044" ], "details": "Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mpj-8j86-c69j/GHSA-3mpj-8j86-c69j.json b/advisories/unreviewed/2022/05/GHSA-3mpj-8j86-c69j/GHSA-3mpj-8j86-c69j.json index 004691ef55a..9b30ab54c2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mpj-8j86-c69j/GHSA-3mpj-8j86-c69j.json +++ b/advisories/unreviewed/2022/05/GHSA-3mpj-8j86-c69j/GHSA-3mpj-8j86-c69j.json @@ -7,12 +7,8 @@ "CVE-2015-1574" ], "details": "The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a \"Content-Disposition: ;\" header in an e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mrx-5p8g-6q5j/GHSA-3mrx-5p8g-6q5j.json b/advisories/unreviewed/2022/05/GHSA-3mrx-5p8g-6q5j/GHSA-3mrx-5p8g-6q5j.json index 7db63cba4aa..876e5f6aa26 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mrx-5p8g-6q5j/GHSA-3mrx-5p8g-6q5j.json +++ b/advisories/unreviewed/2022/05/GHSA-3mrx-5p8g-6q5j/GHSA-3mrx-5p8g-6q5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pjg-4x3p-x3mq/GHSA-3pjg-4x3p-x3mq.json b/advisories/unreviewed/2022/05/GHSA-3pjg-4x3p-x3mq/GHSA-3pjg-4x3p-x3mq.json index 481fc74dc21..9e2251c827b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pjg-4x3p-x3mq/GHSA-3pjg-4x3p-x3mq.json +++ b/advisories/unreviewed/2022/05/GHSA-3pjg-4x3p-x3mq/GHSA-3pjg-4x3p-x3mq.json @@ -7,12 +7,8 @@ "CVE-2011-4805" ], "details": "Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3prv-x9wq-2654/GHSA-3prv-x9wq-2654.json b/advisories/unreviewed/2022/05/GHSA-3prv-x9wq-2654/GHSA-3prv-x9wq-2654.json index 6096430bbeb..3277f2f60b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3prv-x9wq-2654/GHSA-3prv-x9wq-2654.json +++ b/advisories/unreviewed/2022/05/GHSA-3prv-x9wq-2654/GHSA-3prv-x9wq-2654.json @@ -7,12 +7,8 @@ "CVE-2015-1437" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Asus RT-N10+ D1 router with firmware 2.1.1.1.70 allow remote attackers to inject arbitrary web script or HTML via the flag parameter to (1) result_of_get_changed_status.asp or (2) error_page.htm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qg9-856j-f4jv/GHSA-3qg9-856j-f4jv.json b/advisories/unreviewed/2022/05/GHSA-3qg9-856j-f4jv/GHSA-3qg9-856j-f4jv.json index f013458bcb8..c84e25cbe9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qg9-856j-f4jv/GHSA-3qg9-856j-f4jv.json +++ b/advisories/unreviewed/2022/05/GHSA-3qg9-856j-f4jv/GHSA-3qg9-856j-f4jv.json @@ -7,12 +7,8 @@ "CVE-2014-3437" ], "details": "The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qx5-mr88-qhv7/GHSA-3qx5-mr88-qhv7.json b/advisories/unreviewed/2022/05/GHSA-3qx5-mr88-qhv7/GHSA-3qx5-mr88-qhv7.json index dde9a9373a7..f788fd9cf16 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qx5-mr88-qhv7/GHSA-3qx5-mr88-qhv7.json +++ b/advisories/unreviewed/2022/05/GHSA-3qx5-mr88-qhv7/GHSA-3qx5-mr88-qhv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r3v-7p48-rwmv/GHSA-3r3v-7p48-rwmv.json b/advisories/unreviewed/2022/05/GHSA-3r3v-7p48-rwmv/GHSA-3r3v-7p48-rwmv.json index 18042e64f3b..44bd6163da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r3v-7p48-rwmv/GHSA-3r3v-7p48-rwmv.json +++ b/advisories/unreviewed/2022/05/GHSA-3r3v-7p48-rwmv/GHSA-3r3v-7p48-rwmv.json @@ -7,12 +7,8 @@ "CVE-2015-0514" ], "details": "EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rh3-mwf4-58r4/GHSA-3rh3-mwf4-58r4.json b/advisories/unreviewed/2022/05/GHSA-3rh3-mwf4-58r4/GHSA-3rh3-mwf4-58r4.json index 20f19fa2f5c..396442b0e7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rh3-mwf4-58r4/GHSA-3rh3-mwf4-58r4.json +++ b/advisories/unreviewed/2022/05/GHSA-3rh3-mwf4-58r4/GHSA-3rh3-mwf4-58r4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v87-f22j-hcwv/GHSA-3v87-f22j-hcwv.json b/advisories/unreviewed/2022/05/GHSA-3v87-f22j-hcwv/GHSA-3v87-f22j-hcwv.json index b9c04b32fad..9e95de91d2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v87-f22j-hcwv/GHSA-3v87-f22j-hcwv.json +++ b/advisories/unreviewed/2022/05/GHSA-3v87-f22j-hcwv/GHSA-3v87-f22j-hcwv.json @@ -7,12 +7,8 @@ "CVE-2011-3978" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vf4-p6xq-xxr9/GHSA-3vf4-p6xq-xxr9.json b/advisories/unreviewed/2022/05/GHSA-3vf4-p6xq-xxr9/GHSA-3vf4-p6xq-xxr9.json index e4d663fe83c..82cf9b1d692 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vf4-p6xq-xxr9/GHSA-3vf4-p6xq-xxr9.json +++ b/advisories/unreviewed/2022/05/GHSA-3vf4-p6xq-xxr9/GHSA-3vf4-p6xq-xxr9.json @@ -7,12 +7,8 @@ "CVE-2011-1530" ], "details": "The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w3v-6rwc-cvhr/GHSA-3w3v-6rwc-cvhr.json b/advisories/unreviewed/2022/05/GHSA-3w3v-6rwc-cvhr/GHSA-3w3v-6rwc-cvhr.json index bdf24117402..851925acdb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w3v-6rwc-cvhr/GHSA-3w3v-6rwc-cvhr.json +++ b/advisories/unreviewed/2022/05/GHSA-3w3v-6rwc-cvhr/GHSA-3w3v-6rwc-cvhr.json @@ -7,12 +7,8 @@ "CVE-2014-4965" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/searchcriteria.action; (2) productname, (3) availability, or (4) status parameter to central/catalog/productlist.action; or unspecified vectors in (5) WebContent/orders/orderlist.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w9v-5f2g-97c5/GHSA-3w9v-5f2g-97c5.json b/advisories/unreviewed/2022/05/GHSA-3w9v-5f2g-97c5/GHSA-3w9v-5f2g-97c5.json index 245cc6b1e0c..b784a28c956 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w9v-5f2g-97c5/GHSA-3w9v-5f2g-97c5.json +++ b/advisories/unreviewed/2022/05/GHSA-3w9v-5f2g-97c5/GHSA-3w9v-5f2g-97c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wg4-74hw-hxr7/GHSA-3wg4-74hw-hxr7.json b/advisories/unreviewed/2022/05/GHSA-3wg4-74hw-hxr7/GHSA-3wg4-74hw-hxr7.json index f36240b0c5c..206b9de0378 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wg4-74hw-hxr7/GHSA-3wg4-74hw-hxr7.json +++ b/advisories/unreviewed/2022/05/GHSA-3wg4-74hw-hxr7/GHSA-3wg4-74hw-hxr7.json @@ -7,12 +7,8 @@ "CVE-2014-2480" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-2481.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3ww8-82c8-5vpr/GHSA-3ww8-82c8-5vpr.json b/advisories/unreviewed/2022/05/GHSA-3ww8-82c8-5vpr/GHSA-3ww8-82c8-5vpr.json index b42324214e3..dc541627ccf 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ww8-82c8-5vpr/GHSA-3ww8-82c8-5vpr.json +++ b/advisories/unreviewed/2022/05/GHSA-3ww8-82c8-5vpr/GHSA-3ww8-82c8-5vpr.json @@ -7,12 +7,8 @@ "CVE-2014-4212" ], "details": "Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x3x-fgf2-hxxv/GHSA-3x3x-fgf2-hxxv.json b/advisories/unreviewed/2022/05/GHSA-3x3x-fgf2-hxxv/GHSA-3x3x-fgf2-hxxv.json index 6fdc5c057f9..ee5a3635e9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x3x-fgf2-hxxv/GHSA-3x3x-fgf2-hxxv.json +++ b/advisories/unreviewed/2022/05/GHSA-3x3x-fgf2-hxxv/GHSA-3x3x-fgf2-hxxv.json @@ -7,12 +7,8 @@ "CVE-2014-4229" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42qf-73xw-h6m8/GHSA-42qf-73xw-h6m8.json b/advisories/unreviewed/2022/05/GHSA-42qf-73xw-h6m8/GHSA-42qf-73xw-h6m8.json index b431a016b7d..3375239f3ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-42qf-73xw-h6m8/GHSA-42qf-73xw-h6m8.json +++ b/advisories/unreviewed/2022/05/GHSA-42qf-73xw-h6m8/GHSA-42qf-73xw-h6m8.json @@ -7,12 +7,8 @@ "CVE-2014-4734" ], "details": "Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-447w-r8fj-xjcc/GHSA-447w-r8fj-xjcc.json b/advisories/unreviewed/2022/05/GHSA-447w-r8fj-xjcc/GHSA-447w-r8fj-xjcc.json index ed8c2eebaf3..2ba20f5f2be 100644 --- a/advisories/unreviewed/2022/05/GHSA-447w-r8fj-xjcc/GHSA-447w-r8fj-xjcc.json +++ b/advisories/unreviewed/2022/05/GHSA-447w-r8fj-xjcc/GHSA-447w-r8fj-xjcc.json @@ -7,12 +7,8 @@ "CVE-2014-0869" ], "details": "The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44hm-wr7f-qx65/GHSA-44hm-wr7f-qx65.json b/advisories/unreviewed/2022/05/GHSA-44hm-wr7f-qx65/GHSA-44hm-wr7f-qx65.json index 5562b4e4145..1c51916f874 100644 --- a/advisories/unreviewed/2022/05/GHSA-44hm-wr7f-qx65/GHSA-44hm-wr7f-qx65.json +++ b/advisories/unreviewed/2022/05/GHSA-44hm-wr7f-qx65/GHSA-44hm-wr7f-qx65.json @@ -7,12 +7,8 @@ "CVE-2014-8390" ], "details": "Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4588-gggm-24j6/GHSA-4588-gggm-24j6.json b/advisories/unreviewed/2022/05/GHSA-4588-gggm-24j6/GHSA-4588-gggm-24j6.json index e738dadc8fe..e9d7418cd49 100644 --- a/advisories/unreviewed/2022/05/GHSA-4588-gggm-24j6/GHSA-4588-gggm-24j6.json +++ b/advisories/unreviewed/2022/05/GHSA-4588-gggm-24j6/GHSA-4588-gggm-24j6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48qf-97ph-fgqc/GHSA-48qf-97ph-fgqc.json b/advisories/unreviewed/2022/05/GHSA-48qf-97ph-fgqc/GHSA-48qf-97ph-fgqc.json index 11d70c10460..3f28d76605e 100644 --- a/advisories/unreviewed/2022/05/GHSA-48qf-97ph-fgqc/GHSA-48qf-97ph-fgqc.json +++ b/advisories/unreviewed/2022/05/GHSA-48qf-97ph-fgqc/GHSA-48qf-97ph-fgqc.json @@ -7,12 +7,8 @@ "CVE-2011-5105" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cjx-47hq-7hc2/GHSA-4cjx-47hq-7hc2.json b/advisories/unreviewed/2022/05/GHSA-4cjx-47hq-7hc2/GHSA-4cjx-47hq-7hc2.json index e9b479727b8..079a7b05701 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cjx-47hq-7hc2/GHSA-4cjx-47hq-7hc2.json +++ b/advisories/unreviewed/2022/05/GHSA-4cjx-47hq-7hc2/GHSA-4cjx-47hq-7hc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fj9-68jx-qc49/GHSA-4fj9-68jx-qc49.json b/advisories/unreviewed/2022/05/GHSA-4fj9-68jx-qc49/GHSA-4fj9-68jx-qc49.json index e0709687e60..8fd4fb15143 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fj9-68jx-qc49/GHSA-4fj9-68jx-qc49.json +++ b/advisories/unreviewed/2022/05/GHSA-4fj9-68jx-qc49/GHSA-4fj9-68jx-qc49.json @@ -7,12 +7,8 @@ "CVE-2015-1614" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) image_metadata_cruncher[alt] or (2) image_metadata_cruncher[caption] parameter in an update action in the image_metadata_cruncher_title page to wp-admin/options.php or (3) custom image meta tag to the image metadata cruncher page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fp8-99qh-27p3/GHSA-4fp8-99qh-27p3.json b/advisories/unreviewed/2022/05/GHSA-4fp8-99qh-27p3/GHSA-4fp8-99qh-27p3.json index 63a43809658..c2093f712d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fp8-99qh-27p3/GHSA-4fp8-99qh-27p3.json +++ b/advisories/unreviewed/2022/05/GHSA-4fp8-99qh-27p3/GHSA-4fp8-99qh-27p3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g26-4jfh-95vh/GHSA-4g26-4jfh-95vh.json b/advisories/unreviewed/2022/05/GHSA-4g26-4jfh-95vh/GHSA-4g26-4jfh-95vh.json index a79c9dbd71d..d5d072fa1f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g26-4jfh-95vh/GHSA-4g26-4jfh-95vh.json +++ b/advisories/unreviewed/2022/05/GHSA-4g26-4jfh-95vh/GHSA-4g26-4jfh-95vh.json @@ -7,12 +7,8 @@ "CVE-2014-9374" ], "details": "Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gc5-387r-vqmc/GHSA-4gc5-387r-vqmc.json b/advisories/unreviewed/2022/05/GHSA-4gc5-387r-vqmc/GHSA-4gc5-387r-vqmc.json index 0c25fc71148..6709d2f489f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gc5-387r-vqmc/GHSA-4gc5-387r-vqmc.json +++ b/advisories/unreviewed/2022/05/GHSA-4gc5-387r-vqmc/GHSA-4gc5-387r-vqmc.json @@ -7,12 +7,8 @@ "CVE-2011-1290" ], "details": "Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS \"style handling,\" nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jqx-c8xq-4m8x/GHSA-4jqx-c8xq-4m8x.json b/advisories/unreviewed/2022/05/GHSA-4jqx-c8xq-4m8x/GHSA-4jqx-c8xq-4m8x.json index 4963f9037c2..48458d3fa5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jqx-c8xq-4m8x/GHSA-4jqx-c8xq-4m8x.json +++ b/advisories/unreviewed/2022/05/GHSA-4jqx-c8xq-4m8x/GHSA-4jqx-c8xq-4m8x.json @@ -7,12 +7,8 @@ "CVE-2014-4333" ], "details": "Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jrw-3q8x-9gpf/GHSA-4jrw-3q8x-9gpf.json b/advisories/unreviewed/2022/05/GHSA-4jrw-3q8x-9gpf/GHSA-4jrw-3q8x-9gpf.json index 5afa6f33923..a498d7f75cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jrw-3q8x-9gpf/GHSA-4jrw-3q8x-9gpf.json +++ b/advisories/unreviewed/2022/05/GHSA-4jrw-3q8x-9gpf/GHSA-4jrw-3q8x-9gpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mm6-cg2p-rq25/GHSA-4mm6-cg2p-rq25.json b/advisories/unreviewed/2022/05/GHSA-4mm6-cg2p-rq25/GHSA-4mm6-cg2p-rq25.json index fa776699545..e5dd726b550 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mm6-cg2p-rq25/GHSA-4mm6-cg2p-rq25.json +++ b/advisories/unreviewed/2022/05/GHSA-4mm6-cg2p-rq25/GHSA-4mm6-cg2p-rq25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rgw-hq9r-qp9v/GHSA-4rgw-hq9r-qp9v.json b/advisories/unreviewed/2022/05/GHSA-4rgw-hq9r-qp9v/GHSA-4rgw-hq9r-qp9v.json index 78ce5a215de..a784dbd5df5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rgw-hq9r-qp9v/GHSA-4rgw-hq9r-qp9v.json +++ b/advisories/unreviewed/2022/05/GHSA-4rgw-hq9r-qp9v/GHSA-4rgw-hq9r-qp9v.json @@ -7,12 +7,8 @@ "CVE-2014-8310" ], "details": "The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w2r-p3vj-jj74/GHSA-4w2r-p3vj-jj74.json b/advisories/unreviewed/2022/05/GHSA-4w2r-p3vj-jj74/GHSA-4w2r-p3vj-jj74.json index c86d3ab97b7..5851ee9dafc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w2r-p3vj-jj74/GHSA-4w2r-p3vj-jj74.json +++ b/advisories/unreviewed/2022/05/GHSA-4w2r-p3vj-jj74/GHSA-4w2r-p3vj-jj74.json @@ -7,12 +7,8 @@ "CVE-2014-7871" ], "details": "SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wc7-86xc-8837/GHSA-4wc7-86xc-8837.json b/advisories/unreviewed/2022/05/GHSA-4wc7-86xc-8837/GHSA-4wc7-86xc-8837.json index f026a6efc6b..46247b9aa09 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wc7-86xc-8837/GHSA-4wc7-86xc-8837.json +++ b/advisories/unreviewed/2022/05/GHSA-4wc7-86xc-8837/GHSA-4wc7-86xc-8837.json @@ -7,12 +7,8 @@ "CVE-2014-4255" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS - Security and Policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xc5-wc24-8f5h/GHSA-4xc5-wc24-8f5h.json b/advisories/unreviewed/2022/05/GHSA-4xc5-wc24-8f5h/GHSA-4xc5-wc24-8f5h.json index d962e0bbb6f..9a23d9b2b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xc5-wc24-8f5h/GHSA-4xc5-wc24-8f5h.json +++ b/advisories/unreviewed/2022/05/GHSA-4xc5-wc24-8f5h/GHSA-4xc5-wc24-8f5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xp4-9qmj-752r/GHSA-4xp4-9qmj-752r.json b/advisories/unreviewed/2022/05/GHSA-4xp4-9qmj-752r/GHSA-4xp4-9qmj-752r.json index d13f860d2a4..0ebb56a9a66 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xp4-9qmj-752r/GHSA-4xp4-9qmj-752r.json +++ b/advisories/unreviewed/2022/05/GHSA-4xp4-9qmj-752r/GHSA-4xp4-9qmj-752r.json @@ -7,12 +7,8 @@ "CVE-2011-3011" ], "details": "BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5263-f497-fhwq/GHSA-5263-f497-fhwq.json b/advisories/unreviewed/2022/05/GHSA-5263-f497-fhwq/GHSA-5263-f497-fhwq.json index 679ab74f57f..b1c51bf2288 100644 --- a/advisories/unreviewed/2022/05/GHSA-5263-f497-fhwq/GHSA-5263-f497-fhwq.json +++ b/advisories/unreviewed/2022/05/GHSA-5263-f497-fhwq/GHSA-5263-f497-fhwq.json @@ -7,12 +7,8 @@ "CVE-2014-1217" ], "details": "Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to change configurations and obtain the database connection string and credentials via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5396-497v-5r3r/GHSA-5396-497v-5r3r.json b/advisories/unreviewed/2022/05/GHSA-5396-497v-5r3r/GHSA-5396-497v-5r3r.json index 6eb10b2e21c..ab73b7c2451 100644 --- a/advisories/unreviewed/2022/05/GHSA-5396-497v-5r3r/GHSA-5396-497v-5r3r.json +++ b/advisories/unreviewed/2022/05/GHSA-5396-497v-5r3r/GHSA-5396-497v-5r3r.json @@ -7,12 +7,8 @@ "CVE-2014-5340" ], "details": "The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54p3-vvrm-gcf3/GHSA-54p3-vvrm-gcf3.json b/advisories/unreviewed/2022/05/GHSA-54p3-vvrm-gcf3/GHSA-54p3-vvrm-gcf3.json index 30c8e479ac7..1b19e706187 100644 --- a/advisories/unreviewed/2022/05/GHSA-54p3-vvrm-gcf3/GHSA-54p3-vvrm-gcf3.json +++ b/advisories/unreviewed/2022/05/GHSA-54p3-vvrm-gcf3/GHSA-54p3-vvrm-gcf3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54v7-6rq4-h28f/GHSA-54v7-6rq4-h28f.json b/advisories/unreviewed/2022/05/GHSA-54v7-6rq4-h28f/GHSA-54v7-6rq4-h28f.json index 6cf786027ad..fd71db911ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-54v7-6rq4-h28f/GHSA-54v7-6rq4-h28f.json +++ b/advisories/unreviewed/2022/05/GHSA-54v7-6rq4-h28f/GHSA-54v7-6rq4-h28f.json @@ -7,12 +7,8 @@ "CVE-2014-9303" ], "details": "EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55fx-8656-67xw/GHSA-55fx-8656-67xw.json b/advisories/unreviewed/2022/05/GHSA-55fx-8656-67xw/GHSA-55fx-8656-67xw.json index 3d59768ce0c..6c2ea1c5d07 100644 --- a/advisories/unreviewed/2022/05/GHSA-55fx-8656-67xw/GHSA-55fx-8656-67xw.json +++ b/advisories/unreviewed/2022/05/GHSA-55fx-8656-67xw/GHSA-55fx-8656-67xw.json @@ -7,12 +7,8 @@ "CVE-2014-0793" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website or (2) latitude parameter in a comment to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55mr-3h98-7hm7/GHSA-55mr-3h98-7hm7.json b/advisories/unreviewed/2022/05/GHSA-55mr-3h98-7hm7/GHSA-55mr-3h98-7hm7.json index 21bd71c3b07..e87f6c622bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-55mr-3h98-7hm7/GHSA-55mr-3h98-7hm7.json +++ b/advisories/unreviewed/2022/05/GHSA-55mr-3h98-7hm7/GHSA-55mr-3h98-7hm7.json @@ -7,12 +7,8 @@ "CVE-2015-2153" ], "details": "The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via a crafted header length in an RPKI-RTR Protocol Data Unit (PDU).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56x3-5r55-c4h6/GHSA-56x3-5r55-c4h6.json b/advisories/unreviewed/2022/05/GHSA-56x3-5r55-c4h6/GHSA-56x3-5r55-c4h6.json index 588101fe574..54edb13b1b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-56x3-5r55-c4h6/GHSA-56x3-5r55-c4h6.json +++ b/advisories/unreviewed/2022/05/GHSA-56x3-5r55-c4h6/GHSA-56x3-5r55-c4h6.json @@ -7,12 +7,8 @@ "CVE-2014-2043" ], "details": "SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57mp-jhxv-fr69/GHSA-57mp-jhxv-fr69.json b/advisories/unreviewed/2022/05/GHSA-57mp-jhxv-fr69/GHSA-57mp-jhxv-fr69.json index e54f7a7e68b..a52472328d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-57mp-jhxv-fr69/GHSA-57mp-jhxv-fr69.json +++ b/advisories/unreviewed/2022/05/GHSA-57mp-jhxv-fr69/GHSA-57mp-jhxv-fr69.json @@ -7,12 +7,8 @@ "CVE-2014-5136" ], "details": "Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-586h-8q3m-f5hh/GHSA-586h-8q3m-f5hh.json b/advisories/unreviewed/2022/05/GHSA-586h-8q3m-f5hh/GHSA-586h-8q3m-f5hh.json index a5773006560..73609b83dd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-586h-8q3m-f5hh/GHSA-586h-8q3m-f5hh.json +++ b/advisories/unreviewed/2022/05/GHSA-586h-8q3m-f5hh/GHSA-586h-8q3m-f5hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58ww-chv2-94cr/GHSA-58ww-chv2-94cr.json b/advisories/unreviewed/2022/05/GHSA-58ww-chv2-94cr/GHSA-58ww-chv2-94cr.json index f0d6fda6117..62e81cf4ad5 100644 --- a/advisories/unreviewed/2022/05/GHSA-58ww-chv2-94cr/GHSA-58ww-chv2-94cr.json +++ b/advisories/unreviewed/2022/05/GHSA-58ww-chv2-94cr/GHSA-58ww-chv2-94cr.json @@ -7,12 +7,8 @@ "CVE-2015-0261" ], "details": "Integer signedness error in the mobility_opt_print function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) or possibly execute arbitrary code via a negative length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cw9-5hjw-757r/GHSA-5cw9-5hjw-757r.json b/advisories/unreviewed/2022/05/GHSA-5cw9-5hjw-757r/GHSA-5cw9-5hjw-757r.json index 6a83345a6de..1cf3952c30a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cw9-5hjw-757r/GHSA-5cw9-5hjw-757r.json +++ b/advisories/unreviewed/2022/05/GHSA-5cw9-5hjw-757r/GHSA-5cw9-5hjw-757r.json @@ -7,12 +7,8 @@ "CVE-2014-4215" ], "details": "Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to CPU performance counters (CPC) drivers, a different vulnerability than CVE-2013-5862.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f44-2f3g-gf6q/GHSA-5f44-2f3g-gf6q.json b/advisories/unreviewed/2022/05/GHSA-5f44-2f3g-gf6q/GHSA-5f44-2f3g-gf6q.json index 04ad8adc50d..8575b6bb301 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f44-2f3g-gf6q/GHSA-5f44-2f3g-gf6q.json +++ b/advisories/unreviewed/2022/05/GHSA-5f44-2f3g-gf6q/GHSA-5f44-2f3g-gf6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fqx-pg59-xr74/GHSA-5fqx-pg59-xr74.json b/advisories/unreviewed/2022/05/GHSA-5fqx-pg59-xr74/GHSA-5fqx-pg59-xr74.json index 5298f060622..72ffff75339 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fqx-pg59-xr74/GHSA-5fqx-pg59-xr74.json +++ b/advisories/unreviewed/2022/05/GHSA-5fqx-pg59-xr74/GHSA-5fqx-pg59-xr74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g8c-9j8m-c3v5/GHSA-5g8c-9j8m-c3v5.json b/advisories/unreviewed/2022/05/GHSA-5g8c-9j8m-c3v5/GHSA-5g8c-9j8m-c3v5.json index c356ad3db66..dcda0855bfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g8c-9j8m-c3v5/GHSA-5g8c-9j8m-c3v5.json +++ b/advisories/unreviewed/2022/05/GHSA-5g8c-9j8m-c3v5/GHSA-5g8c-9j8m-c3v5.json @@ -7,12 +7,8 @@ "CVE-2014-2484" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRFTS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5gfq-ghv5-4j5q/GHSA-5gfq-ghv5-4j5q.json b/advisories/unreviewed/2022/05/GHSA-5gfq-ghv5-4j5q/GHSA-5gfq-ghv5-4j5q.json index ea2a1835050..ab1c1bd23d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gfq-ghv5-4j5q/GHSA-5gfq-ghv5-4j5q.json +++ b/advisories/unreviewed/2022/05/GHSA-5gfq-ghv5-4j5q/GHSA-5gfq-ghv5-4j5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gr4-m4m2-fjjf/GHSA-5gr4-m4m2-fjjf.json b/advisories/unreviewed/2022/05/GHSA-5gr4-m4m2-fjjf/GHSA-5gr4-m4m2-fjjf.json index 2d55d920f09..4769f4b878e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gr4-m4m2-fjjf/GHSA-5gr4-m4m2-fjjf.json +++ b/advisories/unreviewed/2022/05/GHSA-5gr4-m4m2-fjjf/GHSA-5gr4-m4m2-fjjf.json @@ -7,12 +7,8 @@ "CVE-2014-8962" ], "details": "Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h48-37h4-qpr3/GHSA-5h48-37h4-qpr3.json b/advisories/unreviewed/2022/05/GHSA-5h48-37h4-qpr3/GHSA-5h48-37h4-qpr3.json index 03b85e7c60f..8aa231927e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h48-37h4-qpr3/GHSA-5h48-37h4-qpr3.json +++ b/advisories/unreviewed/2022/05/GHSA-5h48-37h4-qpr3/GHSA-5h48-37h4-qpr3.json @@ -7,12 +7,8 @@ "CVE-2014-7987" ], "details": "Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h4f-x39p-f6v8/GHSA-5h4f-x39p-f6v8.json b/advisories/unreviewed/2022/05/GHSA-5h4f-x39p-f6v8/GHSA-5h4f-x39p-f6v8.json index cefdd26f257..8424567db7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h4f-x39p-f6v8/GHSA-5h4f-x39p-f6v8.json +++ b/advisories/unreviewed/2022/05/GHSA-5h4f-x39p-f6v8/GHSA-5h4f-x39p-f6v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hm2-v6x4-c9fc/GHSA-5hm2-v6x4-c9fc.json b/advisories/unreviewed/2022/05/GHSA-5hm2-v6x4-c9fc/GHSA-5hm2-v6x4-c9fc.json index d46ed007588..0ed9c708b36 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hm2-v6x4-c9fc/GHSA-5hm2-v6x4-c9fc.json +++ b/advisories/unreviewed/2022/05/GHSA-5hm2-v6x4-c9fc/GHSA-5hm2-v6x4-c9fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j3x-73cr-cpg5/GHSA-5j3x-73cr-cpg5.json b/advisories/unreviewed/2022/05/GHSA-5j3x-73cr-cpg5/GHSA-5j3x-73cr-cpg5.json index f1eef331dd0..619e6851f4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j3x-73cr-cpg5/GHSA-5j3x-73cr-cpg5.json +++ b/advisories/unreviewed/2022/05/GHSA-5j3x-73cr-cpg5/GHSA-5j3x-73cr-cpg5.json @@ -7,12 +7,8 @@ "CVE-2014-0244" ], "details": "The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jj7-m67j-9gcq/GHSA-5jj7-m67j-9gcq.json b/advisories/unreviewed/2022/05/GHSA-5jj7-m67j-9gcq/GHSA-5jj7-m67j-9gcq.json index 29b80768c47..2e96ec478bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jj7-m67j-9gcq/GHSA-5jj7-m67j-9gcq.json +++ b/advisories/unreviewed/2022/05/GHSA-5jj7-m67j-9gcq/GHSA-5jj7-m67j-9gcq.json @@ -7,12 +7,8 @@ "CVE-2014-4963" ], "details": "Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jwm-jmmx-2mv2/GHSA-5jwm-jmmx-2mv2.json b/advisories/unreviewed/2022/05/GHSA-5jwm-jmmx-2mv2/GHSA-5jwm-jmmx-2mv2.json index d13e29db2fd..ab1ab26476c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jwm-jmmx-2mv2/GHSA-5jwm-jmmx-2mv2.json +++ b/advisories/unreviewed/2022/05/GHSA-5jwm-jmmx-2mv2/GHSA-5jwm-jmmx-2mv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5phr-5283-mg7g/GHSA-5phr-5283-mg7g.json b/advisories/unreviewed/2022/05/GHSA-5phr-5283-mg7g/GHSA-5phr-5283-mg7g.json index 068ff3d8278..6e3307ba853 100644 --- a/advisories/unreviewed/2022/05/GHSA-5phr-5283-mg7g/GHSA-5phr-5283-mg7g.json +++ b/advisories/unreviewed/2022/05/GHSA-5phr-5283-mg7g/GHSA-5phr-5283-mg7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pvq-364g-f88f/GHSA-5pvq-364g-f88f.json b/advisories/unreviewed/2022/05/GHSA-5pvq-364g-f88f/GHSA-5pvq-364g-f88f.json index 22278d87849..53f0870ed2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pvq-364g-f88f/GHSA-5pvq-364g-f88f.json +++ b/advisories/unreviewed/2022/05/GHSA-5pvq-364g-f88f/GHSA-5pvq-364g-f88f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q25-3rvc-82p6/GHSA-5q25-3rvc-82p6.json b/advisories/unreviewed/2022/05/GHSA-5q25-3rvc-82p6/GHSA-5q25-3rvc-82p6.json index 78511620872..40307d8c0f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q25-3rvc-82p6/GHSA-5q25-3rvc-82p6.json +++ b/advisories/unreviewed/2022/05/GHSA-5q25-3rvc-82p6/GHSA-5q25-3rvc-82p6.json @@ -7,12 +7,8 @@ "CVE-2014-5234" ], "details": "Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qp3-hxwx-86vp/GHSA-5qp3-hxwx-86vp.json b/advisories/unreviewed/2022/05/GHSA-5qp3-hxwx-86vp/GHSA-5qp3-hxwx-86vp.json index 427f61f03e9..629651ba8b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qp3-hxwx-86vp/GHSA-5qp3-hxwx-86vp.json +++ b/advisories/unreviewed/2022/05/GHSA-5qp3-hxwx-86vp/GHSA-5qp3-hxwx-86vp.json @@ -7,12 +7,8 @@ "CVE-2014-8315" ], "details": "polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and port in the cms parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5rvj-6jpg-mr39/GHSA-5rvj-6jpg-mr39.json b/advisories/unreviewed/2022/05/GHSA-5rvj-6jpg-mr39/GHSA-5rvj-6jpg-mr39.json index f1776e99187..2b461e29b82 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rvj-6jpg-mr39/GHSA-5rvj-6jpg-mr39.json +++ b/advisories/unreviewed/2022/05/GHSA-5rvj-6jpg-mr39/GHSA-5rvj-6jpg-mr39.json @@ -7,12 +7,8 @@ "CVE-2014-4048" ], "details": "The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (deadlock) by terminating a subscription request before it is complete, which triggers a SIP transaction timeout.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v9m-r264-24vr/GHSA-5v9m-r264-24vr.json b/advisories/unreviewed/2022/05/GHSA-5v9m-r264-24vr/GHSA-5v9m-r264-24vr.json index 2e9522914cb..db8bb707bf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v9m-r264-24vr/GHSA-5v9m-r264-24vr.json +++ b/advisories/unreviewed/2022/05/GHSA-5v9m-r264-24vr/GHSA-5v9m-r264-24vr.json @@ -7,12 +7,8 @@ "CVE-2014-7216" ], "details": "Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vfj-4g27-37g8/GHSA-5vfj-4g27-37g8.json b/advisories/unreviewed/2022/05/GHSA-5vfj-4g27-37g8/GHSA-5vfj-4g27-37g8.json index 6c1529b828f..ba9d0658c17 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vfj-4g27-37g8/GHSA-5vfj-4g27-37g8.json +++ b/advisories/unreviewed/2022/05/GHSA-5vfj-4g27-37g8/GHSA-5vfj-4g27-37g8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5www-87m9-2c36/GHSA-5www-87m9-2c36.json b/advisories/unreviewed/2022/05/GHSA-5www-87m9-2c36/GHSA-5www-87m9-2c36.json index f725b293fbb..3cab0df24ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-5www-87m9-2c36/GHSA-5www-87m9-2c36.json +++ b/advisories/unreviewed/2022/05/GHSA-5www-87m9-2c36/GHSA-5www-87m9-2c36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x3c-pm5r-fhpx/GHSA-5x3c-pm5r-fhpx.json b/advisories/unreviewed/2022/05/GHSA-5x3c-pm5r-fhpx/GHSA-5x3c-pm5r-fhpx.json index cc6c24555ec..11dc21f4750 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x3c-pm5r-fhpx/GHSA-5x3c-pm5r-fhpx.json +++ b/advisories/unreviewed/2022/05/GHSA-5x3c-pm5r-fhpx/GHSA-5x3c-pm5r-fhpx.json @@ -7,12 +7,8 @@ "CVE-2014-9432" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in templates/2k11/admin/overview.inc.tpl in Serendipity before 2.0-rc2 allow remote attackers to inject arbitrary web script or HTML via a blog comment in the QUERY_STRING to serendipity/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-622j-jvjv-7rx6/GHSA-622j-jvjv-7rx6.json b/advisories/unreviewed/2022/05/GHSA-622j-jvjv-7rx6/GHSA-622j-jvjv-7rx6.json index a5d704c48ef..a14245c38c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-622j-jvjv-7rx6/GHSA-622j-jvjv-7rx6.json +++ b/advisories/unreviewed/2022/05/GHSA-622j-jvjv-7rx6/GHSA-622j-jvjv-7rx6.json @@ -7,12 +7,8 @@ "CVE-2015-2072" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2) xs/ide/editor/templates/trace/hanaTraceDetailService.xsjs, aka SAP Note 2069676.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62hp-w5vm-g7xm/GHSA-62hp-w5vm-g7xm.json b/advisories/unreviewed/2022/05/GHSA-62hp-w5vm-g7xm/GHSA-62hp-w5vm-g7xm.json index fcd5b5f5518..c235992f1e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-62hp-w5vm-g7xm/GHSA-62hp-w5vm-g7xm.json +++ b/advisories/unreviewed/2022/05/GHSA-62hp-w5vm-g7xm/GHSA-62hp-w5vm-g7xm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63fp-m4v5-qwjh/GHSA-63fp-m4v5-qwjh.json b/advisories/unreviewed/2022/05/GHSA-63fp-m4v5-qwjh/GHSA-63fp-m4v5-qwjh.json index fd4f00bfde4..cb3305c66a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-63fp-m4v5-qwjh/GHSA-63fp-m4v5-qwjh.json +++ b/advisories/unreviewed/2022/05/GHSA-63fp-m4v5-qwjh/GHSA-63fp-m4v5-qwjh.json @@ -7,12 +7,8 @@ "CVE-2014-3758" ], "details": "Cross-site scripting (XSS) vulnerability in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via vectors related to the import functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66r3-r672-w6h3/GHSA-66r3-r672-w6h3.json b/advisories/unreviewed/2022/05/GHSA-66r3-r672-w6h3/GHSA-66r3-r672-w6h3.json index 6af7926f540..cc523631084 100644 --- a/advisories/unreviewed/2022/05/GHSA-66r3-r672-w6h3/GHSA-66r3-r672-w6h3.json +++ b/advisories/unreviewed/2022/05/GHSA-66r3-r672-w6h3/GHSA-66r3-r672-w6h3.json @@ -7,12 +7,8 @@ "CVE-2014-4214" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-676j-2jjm-jc5c/GHSA-676j-2jjm-jc5c.json b/advisories/unreviewed/2022/05/GHSA-676j-2jjm-jc5c/GHSA-676j-2jjm-jc5c.json index f3daa4de08a..3304caa51af 100644 --- a/advisories/unreviewed/2022/05/GHSA-676j-2jjm-jc5c/GHSA-676j-2jjm-jc5c.json +++ b/advisories/unreviewed/2022/05/GHSA-676j-2jjm-jc5c/GHSA-676j-2jjm-jc5c.json @@ -7,12 +7,8 @@ "CVE-2014-8658" ], "details": "Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the versionComment parameter to pages/doeditpage.action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67c5-vcgx-65h6/GHSA-67c5-vcgx-65h6.json b/advisories/unreviewed/2022/05/GHSA-67c5-vcgx-65h6/GHSA-67c5-vcgx-65h6.json index 2201d1a5212..4eaa03d6459 100644 --- a/advisories/unreviewed/2022/05/GHSA-67c5-vcgx-65h6/GHSA-67c5-vcgx-65h6.json +++ b/advisories/unreviewed/2022/05/GHSA-67c5-vcgx-65h6/GHSA-67c5-vcgx-65h6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68vp-967g-wmr4/GHSA-68vp-967g-wmr4.json b/advisories/unreviewed/2022/05/GHSA-68vp-967g-wmr4/GHSA-68vp-967g-wmr4.json index dcf007dfbda..e8bbe4c6948 100644 --- a/advisories/unreviewed/2022/05/GHSA-68vp-967g-wmr4/GHSA-68vp-967g-wmr4.json +++ b/advisories/unreviewed/2022/05/GHSA-68vp-967g-wmr4/GHSA-68vp-967g-wmr4.json @@ -7,12 +7,8 @@ "CVE-2014-2489" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c52-8fqm-4g2v/GHSA-6c52-8fqm-4g2v.json b/advisories/unreviewed/2022/05/GHSA-6c52-8fqm-4g2v/GHSA-6c52-8fqm-4g2v.json index 24914363f5a..b5cbd5d1fb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c52-8fqm-4g2v/GHSA-6c52-8fqm-4g2v.json +++ b/advisories/unreviewed/2022/05/GHSA-6c52-8fqm-4g2v/GHSA-6c52-8fqm-4g2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cv2-qjv3-2vh8/GHSA-6cv2-qjv3-2vh8.json b/advisories/unreviewed/2022/05/GHSA-6cv2-qjv3-2vh8/GHSA-6cv2-qjv3-2vh8.json index eb70e44c24b..d831d05fcf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cv2-qjv3-2vh8/GHSA-6cv2-qjv3-2vh8.json +++ b/advisories/unreviewed/2022/05/GHSA-6cv2-qjv3-2vh8/GHSA-6cv2-qjv3-2vh8.json @@ -7,12 +7,8 @@ "CVE-2014-4224" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows local users to affect availability via unknown vectors related to sockfs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g65-24hq-98xf/GHSA-6g65-24hq-98xf.json b/advisories/unreviewed/2022/05/GHSA-6g65-24hq-98xf/GHSA-6g65-24hq-98xf.json index 27a2f79b2a9..f436a1a4ade 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g65-24hq-98xf/GHSA-6g65-24hq-98xf.json +++ b/advisories/unreviewed/2022/05/GHSA-6g65-24hq-98xf/GHSA-6g65-24hq-98xf.json @@ -7,12 +7,8 @@ "CVE-2013-7196" ], "details": "static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended \"Only Me\" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gcw-2jwm-f6f4/GHSA-6gcw-2jwm-f6f4.json b/advisories/unreviewed/2022/05/GHSA-6gcw-2jwm-f6f4/GHSA-6gcw-2jwm-f6f4.json index a2e3e00ff80..69559671dbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gcw-2jwm-f6f4/GHSA-6gcw-2jwm-f6f4.json +++ b/advisories/unreviewed/2022/05/GHSA-6gcw-2jwm-f6f4/GHSA-6gcw-2jwm-f6f4.json @@ -7,12 +7,8 @@ "CVE-2014-5451" ], "details": "Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in MODX Revolution 2.3.1-pl and earlier allows remote attackers to inject arbitrary web script or HTML via the \"a\" parameter to manager/. NOTE: this issue exists because of a CVE-2014-2080 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gr9-w5xf-xjq3/GHSA-6gr9-w5xf-xjq3.json b/advisories/unreviewed/2022/05/GHSA-6gr9-w5xf-xjq3/GHSA-6gr9-w5xf-xjq3.json index 12937b4b51d..9f70e5a6005 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gr9-w5xf-xjq3/GHSA-6gr9-w5xf-xjq3.json +++ b/advisories/unreviewed/2022/05/GHSA-6gr9-w5xf-xjq3/GHSA-6gr9-w5xf-xjq3.json @@ -7,12 +7,8 @@ "CVE-2014-7957" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to wp-admin/admin.php, (2) delete a pod in a delete action in the pods page to wp-admin/admin.php, (3) reset pod settings and data via the pods_reset parameter in the pod-settings page to wp-admin/admin.php, (4) deactivate and reset pod data via the pods_reset_deactivate parameter in the pod-settings page to wp-admin/admin.php, (5) delete the admin role via the id parameter in a delete action in the pods-component-roles-and-capabilities page to wp-admin/admin.php, or (6) enable \"roles and capabilities\" in a toggle action in the pods-components page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m3m-wc9x-2j74/GHSA-6m3m-wc9x-2j74.json b/advisories/unreviewed/2022/05/GHSA-6m3m-wc9x-2j74/GHSA-6m3m-wc9x-2j74.json index 0199818a2d4..741e809e16a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m3m-wc9x-2j74/GHSA-6m3m-wc9x-2j74.json +++ b/advisories/unreviewed/2022/05/GHSA-6m3m-wc9x-2j74/GHSA-6m3m-wc9x-2j74.json @@ -7,12 +7,8 @@ "CVE-2014-6308" ], "details": "Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pr6-q53r-2q97/GHSA-6pr6-q53r-2q97.json b/advisories/unreviewed/2022/05/GHSA-6pr6-q53r-2q97/GHSA-6pr6-q53r-2q97.json index 57ddc916174..a6b0d1e5a06 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pr6-q53r-2q97/GHSA-6pr6-q53r-2q97.json +++ b/advisories/unreviewed/2022/05/GHSA-6pr6-q53r-2q97/GHSA-6pr6-q53r-2q97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wr2-qx99-98mg/GHSA-6wr2-qx99-98mg.json b/advisories/unreviewed/2022/05/GHSA-6wr2-qx99-98mg/GHSA-6wr2-qx99-98mg.json index b6a2746b6e9..a548ca84e60 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wr2-qx99-98mg/GHSA-6wr2-qx99-98mg.json +++ b/advisories/unreviewed/2022/05/GHSA-6wr2-qx99-98mg/GHSA-6wr2-qx99-98mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x2f-7ggw-rc86/GHSA-6x2f-7ggw-rc86.json b/advisories/unreviewed/2022/05/GHSA-6x2f-7ggw-rc86/GHSA-6x2f-7ggw-rc86.json index 0e00bd4c992..3b299f05623 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x2f-7ggw-rc86/GHSA-6x2f-7ggw-rc86.json +++ b/advisories/unreviewed/2022/05/GHSA-6x2f-7ggw-rc86/GHSA-6x2f-7ggw-rc86.json @@ -7,12 +7,8 @@ "CVE-2014-9028" ], "details": "Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x7j-xwg6-qmjx/GHSA-6x7j-xwg6-qmjx.json b/advisories/unreviewed/2022/05/GHSA-6x7j-xwg6-qmjx/GHSA-6x7j-xwg6-qmjx.json index e1d1193f703..b140918eb04 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x7j-xwg6-qmjx/GHSA-6x7j-xwg6-qmjx.json +++ b/advisories/unreviewed/2022/05/GHSA-6x7j-xwg6-qmjx/GHSA-6x7j-xwg6-qmjx.json @@ -7,12 +7,8 @@ "CVE-2014-9466" ], "details": "Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the \"folder identifier.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xq2-x377-w2pf/GHSA-6xq2-x377-w2pf.json b/advisories/unreviewed/2022/05/GHSA-6xq2-x377-w2pf/GHSA-6xq2-x377-w2pf.json index 8bc9ef614bc..e5ad0e2ec1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xq2-x377-w2pf/GHSA-6xq2-x377-w2pf.json +++ b/advisories/unreviewed/2022/05/GHSA-6xq2-x377-w2pf/GHSA-6xq2-x377-w2pf.json @@ -7,12 +7,8 @@ "CVE-2015-1428" ], "details": "Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL commands via the sefrengo cookie in a login to backend/main.php or (2) remote authenticated users to execute arbitrary SQL commands via the value_id parameter in a save_value action to backend/main.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xqg-q7p8-9r82/GHSA-6xqg-q7p8-9r82.json b/advisories/unreviewed/2022/05/GHSA-6xqg-q7p8-9r82/GHSA-6xqg-q7p8-9r82.json index 85b880dcac1..8127a419b45 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xqg-q7p8-9r82/GHSA-6xqg-q7p8-9r82.json +++ b/advisories/unreviewed/2022/05/GHSA-6xqg-q7p8-9r82/GHSA-6xqg-q7p8-9r82.json @@ -7,12 +7,8 @@ "CVE-2014-8387" ], "details": "cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xw2-89hr-qc42/GHSA-6xw2-89hr-qc42.json b/advisories/unreviewed/2022/05/GHSA-6xw2-89hr-qc42/GHSA-6xw2-89hr-qc42.json index 16d9bce3437..8a99e8b2d9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xw2-89hr-qc42/GHSA-6xw2-89hr-qc42.json +++ b/advisories/unreviewed/2022/05/GHSA-6xw2-89hr-qc42/GHSA-6xw2-89hr-qc42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-724g-6g9v-8462/GHSA-724g-6g9v-8462.json b/advisories/unreviewed/2022/05/GHSA-724g-6g9v-8462/GHSA-724g-6g9v-8462.json index 34ac16c67fd..e89685b053f 100644 --- a/advisories/unreviewed/2022/05/GHSA-724g-6g9v-8462/GHSA-724g-6g9v-8462.json +++ b/advisories/unreviewed/2022/05/GHSA-724g-6g9v-8462/GHSA-724g-6g9v-8462.json @@ -7,12 +7,8 @@ "CVE-2011-5169" ], "details": "SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73m9-q5p6-vhgf/GHSA-73m9-q5p6-vhgf.json b/advisories/unreviewed/2022/05/GHSA-73m9-q5p6-vhgf/GHSA-73m9-q5p6-vhgf.json index 7d757f4b77b..96cc9e1d416 100644 --- a/advisories/unreviewed/2022/05/GHSA-73m9-q5p6-vhgf/GHSA-73m9-q5p6-vhgf.json +++ b/advisories/unreviewed/2022/05/GHSA-73m9-q5p6-vhgf/GHSA-73m9-q5p6-vhgf.json @@ -7,12 +7,8 @@ "CVE-2014-8419" ], "details": "Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73wq-fqgr-pmvw/GHSA-73wq-fqgr-pmvw.json b/advisories/unreviewed/2022/05/GHSA-73wq-fqgr-pmvw/GHSA-73wq-fqgr-pmvw.json index 5b3858b5487..f73ce684acf 100644 --- a/advisories/unreviewed/2022/05/GHSA-73wq-fqgr-pmvw/GHSA-73wq-fqgr-pmvw.json +++ b/advisories/unreviewed/2022/05/GHSA-73wq-fqgr-pmvw/GHSA-73wq-fqgr-pmvw.json @@ -7,12 +7,8 @@ "CVE-2014-6280" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action or (2) nsextt parameter to oc-admin/index.php or the (3) nsextt parameter in an items_reported action to oc-admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73x4-r3fj-rwhf/GHSA-73x4-r3fj-rwhf.json b/advisories/unreviewed/2022/05/GHSA-73x4-r3fj-rwhf/GHSA-73x4-r3fj-rwhf.json index ef57ec32349..5596f2c059e 100644 --- a/advisories/unreviewed/2022/05/GHSA-73x4-r3fj-rwhf/GHSA-73x4-r3fj-rwhf.json +++ b/advisories/unreviewed/2022/05/GHSA-73x4-r3fj-rwhf/GHSA-73x4-r3fj-rwhf.json @@ -7,12 +7,8 @@ "CVE-2013-2187" ], "details": "Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-748j-px2m-cwgh/GHSA-748j-px2m-cwgh.json b/advisories/unreviewed/2022/05/GHSA-748j-px2m-cwgh/GHSA-748j-px2m-cwgh.json index d465e35cea0..7ba4d0cf5c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-748j-px2m-cwgh/GHSA-748j-px2m-cwgh.json +++ b/advisories/unreviewed/2022/05/GHSA-748j-px2m-cwgh/GHSA-748j-px2m-cwgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-749r-xj32-vr4x/GHSA-749r-xj32-vr4x.json b/advisories/unreviewed/2022/05/GHSA-749r-xj32-vr4x/GHSA-749r-xj32-vr4x.json index 76b957e3962..7979daa28dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-749r-xj32-vr4x/GHSA-749r-xj32-vr4x.json +++ b/advisories/unreviewed/2022/05/GHSA-749r-xj32-vr4x/GHSA-749r-xj32-vr4x.json @@ -7,12 +7,8 @@ "CVE-2013-6229" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) filter parameter to index.php/mail/mail/listfoldermessages/searching/true/selectFolder/INBOX/resultContext/searchResultsTab5 or (2) mailId[] parameter to index.php/mail/mail/movetofolder/fromFolder/INBOX/toFolder/INBOX.Trash. NOTE: the view attachment message process vector is already covered by CVE-2013-2585.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-752g-gxpx-gwwv/GHSA-752g-gxpx-gwwv.json b/advisories/unreviewed/2022/05/GHSA-752g-gxpx-gwwv/GHSA-752g-gxpx-gwwv.json index cc9044ae812..faadc330104 100644 --- a/advisories/unreviewed/2022/05/GHSA-752g-gxpx-gwwv/GHSA-752g-gxpx-gwwv.json +++ b/advisories/unreviewed/2022/05/GHSA-752g-gxpx-gwwv/GHSA-752g-gxpx-gwwv.json @@ -7,12 +7,8 @@ "CVE-2014-4217" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, and 12.1.1.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75mf-4cr8-98gx/GHSA-75mf-4cr8-98gx.json b/advisories/unreviewed/2022/05/GHSA-75mf-4cr8-98gx/GHSA-75mf-4cr8-98gx.json index 072c0bb4c6f..cdafc426e62 100644 --- a/advisories/unreviewed/2022/05/GHSA-75mf-4cr8-98gx/GHSA-75mf-4cr8-98gx.json +++ b/advisories/unreviewed/2022/05/GHSA-75mf-4cr8-98gx/GHSA-75mf-4cr8-98gx.json @@ -7,12 +7,8 @@ "CVE-2014-2205" ], "details": "The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75q2-28c3-jc72/GHSA-75q2-28c3-jc72.json b/advisories/unreviewed/2022/05/GHSA-75q2-28c3-jc72/GHSA-75q2-28c3-jc72.json index c41b7c84f58..97a3e2eb1ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-75q2-28c3-jc72/GHSA-75q2-28c3-jc72.json +++ b/advisories/unreviewed/2022/05/GHSA-75q2-28c3-jc72/GHSA-75q2-28c3-jc72.json @@ -7,12 +7,8 @@ "CVE-2014-3793" ], "details": "VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77c3-rw3f-4vrx/GHSA-77c3-rw3f-4vrx.json b/advisories/unreviewed/2022/05/GHSA-77c3-rw3f-4vrx/GHSA-77c3-rw3f-4vrx.json index 8865e9c8010..dbf8b540910 100644 --- a/advisories/unreviewed/2022/05/GHSA-77c3-rw3f-4vrx/GHSA-77c3-rw3f-4vrx.json +++ b/advisories/unreviewed/2022/05/GHSA-77c3-rw3f-4vrx/GHSA-77c3-rw3f-4vrx.json @@ -7,12 +7,8 @@ "CVE-2014-2495" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise SCM Purchasing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Purchasing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78vx-8c5h-72jr/GHSA-78vx-8c5h-72jr.json b/advisories/unreviewed/2022/05/GHSA-78vx-8c5h-72jr/GHSA-78vx-8c5h-72jr.json index 505e2e633b2..17b45e31ffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-78vx-8c5h-72jr/GHSA-78vx-8c5h-72jr.json +++ b/advisories/unreviewed/2022/05/GHSA-78vx-8c5h-72jr/GHSA-78vx-8c5h-72jr.json @@ -7,12 +7,8 @@ "CVE-2015-2154" ], "details": "The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) length, (2) offset, or (3) base pointer checksum value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-795j-xvg2-56j4/GHSA-795j-xvg2-56j4.json b/advisories/unreviewed/2022/05/GHSA-795j-xvg2-56j4/GHSA-795j-xvg2-56j4.json index 7d072011c08..55ab845aabe 100644 --- a/advisories/unreviewed/2022/05/GHSA-795j-xvg2-56j4/GHSA-795j-xvg2-56j4.json +++ b/advisories/unreviewed/2022/05/GHSA-795j-xvg2-56j4/GHSA-795j-xvg2-56j4.json @@ -7,12 +7,8 @@ "CVE-2014-5127" ], "details": "Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79cm-2gxq-7x9r/GHSA-79cm-2gxq-7x9r.json b/advisories/unreviewed/2022/05/GHSA-79cm-2gxq-7x9r/GHSA-79cm-2gxq-7x9r.json index b91675d1d9f..b040cce558c 100644 --- a/advisories/unreviewed/2022/05/GHSA-79cm-2gxq-7x9r/GHSA-79cm-2gxq-7x9r.json +++ b/advisories/unreviewed/2022/05/GHSA-79cm-2gxq-7x9r/GHSA-79cm-2gxq-7x9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79j7-5xqm-355x/GHSA-79j7-5xqm-355x.json b/advisories/unreviewed/2022/05/GHSA-79j7-5xqm-355x/GHSA-79j7-5xqm-355x.json index 532f0343696..86c659ed12b 100644 --- a/advisories/unreviewed/2022/05/GHSA-79j7-5xqm-355x/GHSA-79j7-5xqm-355x.json +++ b/advisories/unreviewed/2022/05/GHSA-79j7-5xqm-355x/GHSA-79j7-5xqm-355x.json @@ -7,12 +7,8 @@ "CVE-2014-4236" ], "details": "Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.2.0.4 and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7c9h-93j9-gcc2/GHSA-7c9h-93j9-gcc2.json b/advisories/unreviewed/2022/05/GHSA-7c9h-93j9-gcc2/GHSA-7c9h-93j9-gcc2.json index c905b6b2f70..34ebd2dacd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c9h-93j9-gcc2/GHSA-7c9h-93j9-gcc2.json +++ b/advisories/unreviewed/2022/05/GHSA-7c9h-93j9-gcc2/GHSA-7c9h-93j9-gcc2.json @@ -7,12 +7,8 @@ "CVE-2011-5109" ], "details": "Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the SearchField parameter in a search action to (1) category_list.php, (2) Copy_of_calendar_list.php, (3) customer_statistics_list.php, (4) customer_list.php, and (5) task_statistics_list.php in the worldcalendar directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cr3-p339-77q4/GHSA-7cr3-p339-77q4.json b/advisories/unreviewed/2022/05/GHSA-7cr3-p339-77q4/GHSA-7cr3-p339-77q4.json index 4505c31676e..ae3eadb3a07 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cr3-p339-77q4/GHSA-7cr3-p339-77q4.json +++ b/advisories/unreviewed/2022/05/GHSA-7cr3-p339-77q4/GHSA-7cr3-p339-77q4.json @@ -7,12 +7,8 @@ "CVE-2011-4158" ], "details": "Unspecified vulnerability in HP Directories Support for ProLiant Management Processors 3.10 and 3.20 for Integrated Lights-Out iLO2 and iLO3 allows remote authenticated users to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fxh-4w9w-83v2/GHSA-7fxh-4w9w-83v2.json b/advisories/unreviewed/2022/05/GHSA-7fxh-4w9w-83v2/GHSA-7fxh-4w9w-83v2.json index 31525486fc1..e54cd21c208 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fxh-4w9w-83v2/GHSA-7fxh-4w9w-83v2.json +++ b/advisories/unreviewed/2022/05/GHSA-7fxh-4w9w-83v2/GHSA-7fxh-4w9w-83v2.json @@ -7,12 +7,8 @@ "CVE-2014-5464" ], "details": "Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g8m-7qrw-wg8g/GHSA-7g8m-7qrw-wg8g.json b/advisories/unreviewed/2022/05/GHSA-7g8m-7qrw-wg8g/GHSA-7g8m-7qrw-wg8g.json index 138639ffb4f..3fa7f86a06a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g8m-7qrw-wg8g/GHSA-7g8m-7qrw-wg8g.json +++ b/advisories/unreviewed/2022/05/GHSA-7g8m-7qrw-wg8g/GHSA-7g8m-7qrw-wg8g.json @@ -7,12 +7,8 @@ "CVE-2014-5385" ], "details": "com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwords via a brute force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hjm-px29-rv4v/GHSA-7hjm-px29-rv4v.json b/advisories/unreviewed/2022/05/GHSA-7hjm-px29-rv4v/GHSA-7hjm-px29-rv4v.json index ac2d7dcd475..02d1eb4ca52 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hjm-px29-rv4v/GHSA-7hjm-px29-rv4v.json +++ b/advisories/unreviewed/2022/05/GHSA-7hjm-px29-rv4v/GHSA-7hjm-px29-rv4v.json @@ -7,12 +7,8 @@ "CVE-2014-2716" ], "details": "Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jgc-fcpj-3rq8/GHSA-7jgc-fcpj-3rq8.json b/advisories/unreviewed/2022/05/GHSA-7jgc-fcpj-3rq8/GHSA-7jgc-fcpj-3rq8.json index f5fdee26804..bfb1bf1a09f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jgc-fcpj-3rq8/GHSA-7jgc-fcpj-3rq8.json +++ b/advisories/unreviewed/2022/05/GHSA-7jgc-fcpj-3rq8/GHSA-7jgc-fcpj-3rq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jrj-rw38-cw85/GHSA-7jrj-rw38-cw85.json b/advisories/unreviewed/2022/05/GHSA-7jrj-rw38-cw85/GHSA-7jrj-rw38-cw85.json index 459b80be0ac..3cdd42af1a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jrj-rw38-cw85/GHSA-7jrj-rw38-cw85.json +++ b/advisories/unreviewed/2022/05/GHSA-7jrj-rw38-cw85/GHSA-7jrj-rw38-cw85.json @@ -7,12 +7,8 @@ "CVE-2011-3868" ], "details": "Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mcw-2h2h-r55h/GHSA-7mcw-2h2h-r55h.json b/advisories/unreviewed/2022/05/GHSA-7mcw-2h2h-r55h/GHSA-7mcw-2h2h-r55h.json index cf0c7b8fe74..7d78503cdde 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mcw-2h2h-r55h/GHSA-7mcw-2h2h-r55h.json +++ b/advisories/unreviewed/2022/05/GHSA-7mcw-2h2h-r55h/GHSA-7mcw-2h2h-r55h.json @@ -7,12 +7,8 @@ "CVE-2014-100010" ], "details": "Cross-site scripting (XSS) vulnerability in ClanSphere 2011.4 allows remote attackers to inject arbitrary web script or HTML via the where parameter in a list action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mr2-g8wf-jhrp/GHSA-7mr2-g8wf-jhrp.json b/advisories/unreviewed/2022/05/GHSA-7mr2-g8wf-jhrp/GHSA-7mr2-g8wf-jhrp.json index 961e0865ef2..7c5fda6fec8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mr2-g8wf-jhrp/GHSA-7mr2-g8wf-jhrp.json +++ b/advisories/unreviewed/2022/05/GHSA-7mr2-g8wf-jhrp/GHSA-7mr2-g8wf-jhrp.json @@ -7,12 +7,8 @@ "CVE-2014-9020" ], "details": "Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to inject arbitrary web script or HTML via the domainname parameter in a save action. NOTE: this issue was SPLIT from CVE-2014-9021 per ADT1 due to different affected products and codebases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p4r-6976-jcwc/GHSA-7p4r-6976-jcwc.json b/advisories/unreviewed/2022/05/GHSA-7p4r-6976-jcwc/GHSA-7p4r-6976-jcwc.json index 46edcbc638a..03c32a26356 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p4r-6976-jcwc/GHSA-7p4r-6976-jcwc.json +++ b/advisories/unreviewed/2022/05/GHSA-7p4r-6976-jcwc/GHSA-7p4r-6976-jcwc.json @@ -7,12 +7,8 @@ "CVE-2014-8398" ], "details": "Multiple untrusted search path vulnerabilities in Corel FastFlick allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) igfxcmrt32.dll, (2) ipl.dll, (3) MSPStyleLib.dll, (4) uFioUtil.dll, (5) uhDSPlay.dll, (6) uipl.dll, (7) uvipl.dll, (8) VC1DecDll.dll, or (9) VC1DecDll_SSE3.dll file that is located in the same folder as the file being processed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7p8m-6352-g3gr/GHSA-7p8m-6352-g3gr.json b/advisories/unreviewed/2022/05/GHSA-7p8m-6352-g3gr/GHSA-7p8m-6352-g3gr.json index cfa5369bed7..80b6c74a704 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p8m-6352-g3gr/GHSA-7p8m-6352-g3gr.json +++ b/advisories/unreviewed/2022/05/GHSA-7p8m-6352-g3gr/GHSA-7p8m-6352-g3gr.json @@ -7,12 +7,8 @@ "CVE-2014-100011" ], "details": "SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pv2-73v2-p784/GHSA-7pv2-73v2-p784.json b/advisories/unreviewed/2022/05/GHSA-7pv2-73v2-p784/GHSA-7pv2-73v2-p784.json index 81fad5cab2b..58512dad917 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pv2-73v2-p784/GHSA-7pv2-73v2-p784.json +++ b/advisories/unreviewed/2022/05/GHSA-7pv2-73v2-p784/GHSA-7pv2-73v2-p784.json @@ -7,12 +7,8 @@ "CVE-2014-4003" ], "details": "The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rgf-8rpg-r6xc/GHSA-7rgf-8rpg-r6xc.json b/advisories/unreviewed/2022/05/GHSA-7rgf-8rpg-r6xc/GHSA-7rgf-8rpg-r6xc.json index 66f7b1e5291..e0afb07921c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rgf-8rpg-r6xc/GHSA-7rgf-8rpg-r6xc.json +++ b/advisories/unreviewed/2022/05/GHSA-7rgf-8rpg-r6xc/GHSA-7rgf-8rpg-r6xc.json @@ -7,12 +7,8 @@ "CVE-2014-4233" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRREP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rp8-q3gf-qx3q/GHSA-7rp8-q3gf-qx3q.json b/advisories/unreviewed/2022/05/GHSA-7rp8-q3gf-qx3q/GHSA-7rp8-q3gf-qx3q.json index bd3bc911964..db86e0062ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rp8-q3gf-qx3q/GHSA-7rp8-q3gf-qx3q.json +++ b/advisories/unreviewed/2022/05/GHSA-7rp8-q3gf-qx3q/GHSA-7rp8-q3gf-qx3q.json @@ -7,12 +7,8 @@ "CVE-2011-5263" ], "details": "Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the server parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xqg-h9pv-h2hr/GHSA-7xqg-h9pv-h2hr.json b/advisories/unreviewed/2022/05/GHSA-7xqg-h9pv-h2hr/GHSA-7xqg-h9pv-h2hr.json index 3f8e1d14f86..924ecd4c841 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xqg-h9pv-h2hr/GHSA-7xqg-h9pv-h2hr.json +++ b/advisories/unreviewed/2022/05/GHSA-7xqg-h9pv-h2hr/GHSA-7xqg-h9pv-h2hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82cc-2f68-f5qf/GHSA-82cc-2f68-f5qf.json b/advisories/unreviewed/2022/05/GHSA-82cc-2f68-f5qf/GHSA-82cc-2f68-f5qf.json index e2890e9faba..217799decf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-82cc-2f68-f5qf/GHSA-82cc-2f68-f5qf.json +++ b/advisories/unreviewed/2022/05/GHSA-82cc-2f68-f5qf/GHSA-82cc-2f68-f5qf.json @@ -7,12 +7,8 @@ "CVE-2011-3977" ], "details": "Unspecified vulnerability in nxconfigure.sh in NoMachine NX Node 3.x before 3.5.0-4 and NX Server 3.x before 3.5.0-5 allows local users to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-836x-hw9m-wqxh/GHSA-836x-hw9m-wqxh.json b/advisories/unreviewed/2022/05/GHSA-836x-hw9m-wqxh/GHSA-836x-hw9m-wqxh.json index e071b3c5eef..8b2ea6dde0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-836x-hw9m-wqxh/GHSA-836x-hw9m-wqxh.json +++ b/advisories/unreviewed/2022/05/GHSA-836x-hw9m-wqxh/GHSA-836x-hw9m-wqxh.json @@ -7,12 +7,8 @@ "CVE-2014-2206" ], "details": "Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-843h-x42r-c9r8/GHSA-843h-x42r-c9r8.json b/advisories/unreviewed/2022/05/GHSA-843h-x42r-c9r8/GHSA-843h-x42r-c9r8.json index 33b51162c5e..8734a95d9df 100644 --- a/advisories/unreviewed/2022/05/GHSA-843h-x42r-c9r8/GHSA-843h-x42r-c9r8.json +++ b/advisories/unreviewed/2022/05/GHSA-843h-x42r-c9r8/GHSA-843h-x42r-c9r8.json @@ -7,12 +7,8 @@ "CVE-2011-4814" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84c9-33xg-rjf7/GHSA-84c9-33xg-rjf7.json b/advisories/unreviewed/2022/05/GHSA-84c9-33xg-rjf7/GHSA-84c9-33xg-rjf7.json index be2d6d36e73..42214d12f77 100644 --- a/advisories/unreviewed/2022/05/GHSA-84c9-33xg-rjf7/GHSA-84c9-33xg-rjf7.json +++ b/advisories/unreviewed/2022/05/GHSA-84c9-33xg-rjf7/GHSA-84c9-33xg-rjf7.json @@ -7,12 +7,8 @@ "CVE-2014-8313" ], "details": "Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84f6-jgxp-q5mf/GHSA-84f6-jgxp-q5mf.json b/advisories/unreviewed/2022/05/GHSA-84f6-jgxp-q5mf/GHSA-84f6-jgxp-q5mf.json index 4438a3f9dc7..e65afaed1fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-84f6-jgxp-q5mf/GHSA-84f6-jgxp-q5mf.json +++ b/advisories/unreviewed/2022/05/GHSA-84f6-jgxp-q5mf/GHSA-84f6-jgxp-q5mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85p7-7gxf-f79f/GHSA-85p7-7gxf-f79f.json b/advisories/unreviewed/2022/05/GHSA-85p7-7gxf-f79f/GHSA-85p7-7gxf-f79f.json index de4ddc36eb2..e0d3a78c72d 100644 --- a/advisories/unreviewed/2022/05/GHSA-85p7-7gxf-f79f/GHSA-85p7-7gxf-f79f.json +++ b/advisories/unreviewed/2022/05/GHSA-85p7-7gxf-f79f/GHSA-85p7-7gxf-f79f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8646-8cww-px2p/GHSA-8646-8cww-px2p.json b/advisories/unreviewed/2022/05/GHSA-8646-8cww-px2p/GHSA-8646-8cww-px2p.json index 8d51b059ade..37d4410f4a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8646-8cww-px2p/GHSA-8646-8cww-px2p.json +++ b/advisories/unreviewed/2022/05/GHSA-8646-8cww-px2p/GHSA-8646-8cww-px2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json b/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json index e8be552e9d4..5e68ee03c61 100644 --- a/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json +++ b/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json @@ -7,12 +7,8 @@ "CVE-2015-8104" ], "details": "The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -192,9 +188,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8977-r7mx-5hvr/GHSA-8977-r7mx-5hvr.json b/advisories/unreviewed/2022/05/GHSA-8977-r7mx-5hvr/GHSA-8977-r7mx-5hvr.json index 6439ecfee22..5ee0abeb8ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-8977-r7mx-5hvr/GHSA-8977-r7mx-5hvr.json +++ b/advisories/unreviewed/2022/05/GHSA-8977-r7mx-5hvr/GHSA-8977-r7mx-5hvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89w9-gmvc-mfp8/GHSA-89w9-gmvc-mfp8.json b/advisories/unreviewed/2022/05/GHSA-89w9-gmvc-mfp8/GHSA-89w9-gmvc-mfp8.json index 3faa52c61b4..fc6c0684aa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-89w9-gmvc-mfp8/GHSA-89w9-gmvc-mfp8.json +++ b/advisories/unreviewed/2022/05/GHSA-89w9-gmvc-mfp8/GHSA-89w9-gmvc-mfp8.json @@ -7,12 +7,8 @@ "CVE-2014-9185" ], "details": "Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cf3-jcrw-phfq/GHSA-8cf3-jcrw-phfq.json b/advisories/unreviewed/2022/05/GHSA-8cf3-jcrw-phfq/GHSA-8cf3-jcrw-phfq.json index 6c98bb359f0..c380aa614cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cf3-jcrw-phfq/GHSA-8cf3-jcrw-phfq.json +++ b/advisories/unreviewed/2022/05/GHSA-8cf3-jcrw-phfq/GHSA-8cf3-jcrw-phfq.json @@ -7,12 +7,8 @@ "CVE-2014-3806" ], "details": "Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the xml_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cpc-jvx2-9h3j/GHSA-8cpc-jvx2-9h3j.json b/advisories/unreviewed/2022/05/GHSA-8cpc-jvx2-9h3j/GHSA-8cpc-jvx2-9h3j.json index 33d7925b1aa..f73c618c93e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cpc-jvx2-9h3j/GHSA-8cpc-jvx2-9h3j.json +++ b/advisories/unreviewed/2022/05/GHSA-8cpc-jvx2-9h3j/GHSA-8cpc-jvx2-9h3j.json @@ -7,12 +7,8 @@ "CVE-2014-2494" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8f4w-786j-j288/GHSA-8f4w-786j-j288.json b/advisories/unreviewed/2022/05/GHSA-8f4w-786j-j288/GHSA-8f4w-786j-j288.json index 16d96b921c9..e1f70b29a84 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f4w-786j-j288/GHSA-8f4w-786j-j288.json +++ b/advisories/unreviewed/2022/05/GHSA-8f4w-786j-j288/GHSA-8f4w-786j-j288.json @@ -7,12 +7,8 @@ "CVE-2014-3810" ], "details": "SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-4333.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fhg-9q98-67hg/GHSA-8fhg-9q98-67hg.json b/advisories/unreviewed/2022/05/GHSA-8fhg-9q98-67hg/GHSA-8fhg-9q98-67hg.json index 0a030c20d13..32958edbe67 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fhg-9q98-67hg/GHSA-8fhg-9q98-67hg.json +++ b/advisories/unreviewed/2022/05/GHSA-8fhg-9q98-67hg/GHSA-8fhg-9q98-67hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fjh-3j4g-4f5v/GHSA-8fjh-3j4g-4f5v.json b/advisories/unreviewed/2022/05/GHSA-8fjh-3j4g-4f5v/GHSA-8fjh-3j4g-4f5v.json index db2aa9e4780..5cd29cdb565 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fjh-3j4g-4f5v/GHSA-8fjh-3j4g-4f5v.json +++ b/advisories/unreviewed/2022/05/GHSA-8fjh-3j4g-4f5v/GHSA-8fjh-3j4g-4f5v.json @@ -7,12 +7,8 @@ "CVE-2015-4077" ], "details": "The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g9m-gx79-xjrc/GHSA-8g9m-gx79-xjrc.json b/advisories/unreviewed/2022/05/GHSA-8g9m-gx79-xjrc/GHSA-8g9m-gx79-xjrc.json index 4325cdb4b54..ac419b83c3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g9m-gx79-xjrc/GHSA-8g9m-gx79-xjrc.json +++ b/advisories/unreviewed/2022/05/GHSA-8g9m-gx79-xjrc/GHSA-8g9m-gx79-xjrc.json @@ -7,12 +7,8 @@ "CVE-2014-4737" ], "details": "Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to setup/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gm5-39w5-qgqw/GHSA-8gm5-39w5-qgqw.json b/advisories/unreviewed/2022/05/GHSA-8gm5-39w5-qgqw/GHSA-8gm5-39w5-qgqw.json index 6e42f52aa7f..e06eca272c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gm5-39w5-qgqw/GHSA-8gm5-39w5-qgqw.json +++ b/advisories/unreviewed/2022/05/GHSA-8gm5-39w5-qgqw/GHSA-8gm5-39w5-qgqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gv5-8qg3-4cw8/GHSA-8gv5-8qg3-4cw8.json b/advisories/unreviewed/2022/05/GHSA-8gv5-8qg3-4cw8/GHSA-8gv5-8qg3-4cw8.json index 95aa9d5f70c..d86f165bb94 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gv5-8qg3-4cw8/GHSA-8gv5-8qg3-4cw8.json +++ b/advisories/unreviewed/2022/05/GHSA-8gv5-8qg3-4cw8/GHSA-8gv5-8qg3-4cw8.json @@ -7,12 +7,8 @@ "CVE-2015-1050" ], "details": "Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Response Body field when creating a new user account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hfp-x3gr-3rfw/GHSA-8hfp-x3gr-3rfw.json b/advisories/unreviewed/2022/05/GHSA-8hfp-x3gr-3rfw/GHSA-8hfp-x3gr-3rfw.json index fb186e37266..b41ae966316 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hfp-x3gr-3rfw/GHSA-8hfp-x3gr-3rfw.json +++ b/advisories/unreviewed/2022/05/GHSA-8hfp-x3gr-3rfw/GHSA-8hfp-x3gr-3rfw.json @@ -7,12 +7,8 @@ "CVE-2014-5375" ], "details": "The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner matches the submitting user, which allows remote authenticated users to impersonate arbitrary users via the UserId and Owner tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hg4-5c5f-597j/GHSA-8hg4-5c5f-597j.json b/advisories/unreviewed/2022/05/GHSA-8hg4-5c5f-597j/GHSA-8hg4-5c5f-597j.json index 1e3bf1b3371..033e59856b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hg4-5c5f-597j/GHSA-8hg4-5c5f-597j.json +++ b/advisories/unreviewed/2022/05/GHSA-8hg4-5c5f-597j/GHSA-8hg4-5c5f-597j.json @@ -7,12 +7,8 @@ "CVE-2014-8429" ], "details": "Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts via a crafted request to the owner/users page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jfm-3q68-9546/GHSA-8jfm-3q68-9546.json b/advisories/unreviewed/2022/05/GHSA-8jfm-3q68-9546/GHSA-8jfm-3q68-9546.json index 02dad25bb2f..fe7b23d775f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jfm-3q68-9546/GHSA-8jfm-3q68-9546.json +++ b/advisories/unreviewed/2022/05/GHSA-8jfm-3q68-9546/GHSA-8jfm-3q68-9546.json @@ -7,12 +7,8 @@ "CVE-2014-5298" ], "details": "FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that contains uppercase letters, as demonstrated using a PHP program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8m22-gm6f-5487/GHSA-8m22-gm6f-5487.json b/advisories/unreviewed/2022/05/GHSA-8m22-gm6f-5487/GHSA-8m22-gm6f-5487.json index f4691a9e54e..67e8049c23b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m22-gm6f-5487/GHSA-8m22-gm6f-5487.json +++ b/advisories/unreviewed/2022/05/GHSA-8m22-gm6f-5487/GHSA-8m22-gm6f-5487.json @@ -7,12 +7,8 @@ "CVE-2014-7187" ], "details": "Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the \"word_lineno\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mgc-hm3x-352v/GHSA-8mgc-hm3x-352v.json b/advisories/unreviewed/2022/05/GHSA-8mgc-hm3x-352v/GHSA-8mgc-hm3x-352v.json index e4ce385f076..e849309145e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mgc-hm3x-352v/GHSA-8mgc-hm3x-352v.json +++ b/advisories/unreviewed/2022/05/GHSA-8mgc-hm3x-352v/GHSA-8mgc-hm3x-352v.json @@ -7,12 +7,8 @@ "CVE-2014-5339" ], "details": "Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row selections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mpf-jqgm-m3jg/GHSA-8mpf-jqgm-m3jg.json b/advisories/unreviewed/2022/05/GHSA-8mpf-jqgm-m3jg/GHSA-8mpf-jqgm-m3jg.json index bb53938f82c..86fa6cdea7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mpf-jqgm-m3jg/GHSA-8mpf-jqgm-m3jg.json +++ b/advisories/unreviewed/2022/05/GHSA-8mpf-jqgm-m3jg/GHSA-8mpf-jqgm-m3jg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mph-qpr3-3458/GHSA-8mph-qpr3-3458.json b/advisories/unreviewed/2022/05/GHSA-8mph-qpr3-3458/GHSA-8mph-qpr3-3458.json index e83433dd27c..acf485a3f6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mph-qpr3-3458/GHSA-8mph-qpr3-3458.json +++ b/advisories/unreviewed/2022/05/GHSA-8mph-qpr3-3458/GHSA-8mph-qpr3-3458.json @@ -7,12 +7,8 @@ "CVE-2014-4664" ], "details": "Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mrh-3xhr-6mjv/GHSA-8mrh-3xhr-6mjv.json b/advisories/unreviewed/2022/05/GHSA-8mrh-3xhr-6mjv/GHSA-8mrh-3xhr-6mjv.json index 3f8da5aad60..737eca3a3f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mrh-3xhr-6mjv/GHSA-8mrh-3xhr-6mjv.json +++ b/advisories/unreviewed/2022/05/GHSA-8mrh-3xhr-6mjv/GHSA-8mrh-3xhr-6mjv.json @@ -7,12 +7,8 @@ "CVE-2014-2385" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to exclusion/configure or (4) text:EmailServer or (5) newListList:Email parameter to notification/configure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pcr-qrf2-5hpg/GHSA-8pcr-qrf2-5hpg.json b/advisories/unreviewed/2022/05/GHSA-8pcr-qrf2-5hpg/GHSA-8pcr-qrf2-5hpg.json index 60a80f4f390..73f2f312e17 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pcr-qrf2-5hpg/GHSA-8pcr-qrf2-5hpg.json +++ b/advisories/unreviewed/2022/05/GHSA-8pcr-qrf2-5hpg/GHSA-8pcr-qrf2-5hpg.json @@ -7,12 +7,8 @@ "CVE-2014-5297" ], "details": "The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pf5-3m37-fjrv/GHSA-8pf5-3m37-fjrv.json b/advisories/unreviewed/2022/05/GHSA-8pf5-3m37-fjrv/GHSA-8pf5-3m37-fjrv.json index f72e12ac6af..7d3af7b1633 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pf5-3m37-fjrv/GHSA-8pf5-3m37-fjrv.json +++ b/advisories/unreviewed/2022/05/GHSA-8pf5-3m37-fjrv/GHSA-8pf5-3m37-fjrv.json @@ -7,12 +7,8 @@ "CVE-2014-9215" ], "details": "SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by CVE-2012-4034.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rh3-5c87-wh48/GHSA-8rh3-5c87-wh48.json b/advisories/unreviewed/2022/05/GHSA-8rh3-5c87-wh48/GHSA-8rh3-5c87-wh48.json index 4044ffa44b2..5f5b9558236 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rh3-5c87-wh48/GHSA-8rh3-5c87-wh48.json +++ b/advisories/unreviewed/2022/05/GHSA-8rh3-5c87-wh48/GHSA-8rh3-5c87-wh48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rpc-3g9v-q43v/GHSA-8rpc-3g9v-q43v.json b/advisories/unreviewed/2022/05/GHSA-8rpc-3g9v-q43v/GHSA-8rpc-3g9v-q43v.json index 03321c74659..a6a2429f1b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rpc-3g9v-q43v/GHSA-8rpc-3g9v-q43v.json +++ b/advisories/unreviewed/2022/05/GHSA-8rpc-3g9v-q43v/GHSA-8rpc-3g9v-q43v.json @@ -7,12 +7,8 @@ "CVE-2011-5265" ], "details": "Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vc2-6cvw-975x/GHSA-8vc2-6cvw-975x.json b/advisories/unreviewed/2022/05/GHSA-8vc2-6cvw-975x/GHSA-8vc2-6cvw-975x.json index 544ab3a0552..48b4b5bfa16 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vc2-6cvw-975x/GHSA-8vc2-6cvw-975x.json +++ b/advisories/unreviewed/2022/05/GHSA-8vc2-6cvw-975x/GHSA-8vc2-6cvw-975x.json @@ -7,12 +7,8 @@ "CVE-2014-5128" ], "details": "Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wwf-w8hv-8982/GHSA-8wwf-w8hv-8982.json b/advisories/unreviewed/2022/05/GHSA-8wwf-w8hv-8982/GHSA-8wwf-w8hv-8982.json index ea67409eae5..6153cad94ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wwf-w8hv-8982/GHSA-8wwf-w8hv-8982.json +++ b/advisories/unreviewed/2022/05/GHSA-8wwf-w8hv-8982/GHSA-8wwf-w8hv-8982.json @@ -7,12 +7,8 @@ "CVE-2014-8334" ], "details": "The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka \"Path to Backup:\" field) or (2) $backup['mysqldumppath'] variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93r2-34ph-r52j/GHSA-93r2-34ph-r52j.json b/advisories/unreviewed/2022/05/GHSA-93r2-34ph-r52j/GHSA-93r2-34ph-r52j.json index 9d4dd1de0d3..e437b6428fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-93r2-34ph-r52j/GHSA-93r2-34ph-r52j.json +++ b/advisories/unreviewed/2022/05/GHSA-93r2-34ph-r52j/GHSA-93r2-34ph-r52j.json @@ -7,12 +7,8 @@ "CVE-2014-9104" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting established VPN sessions, (2) connect to arbitrary VPN servers, or (3) create VPN profiles and execute arbitrary commands via crafted API requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93wp-ggwv-r77q/GHSA-93wp-ggwv-r77q.json b/advisories/unreviewed/2022/05/GHSA-93wp-ggwv-r77q/GHSA-93wp-ggwv-r77q.json index 5344ce32df7..a33819a7a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-93wp-ggwv-r77q/GHSA-93wp-ggwv-r77q.json +++ b/advisories/unreviewed/2022/05/GHSA-93wp-ggwv-r77q/GHSA-93wp-ggwv-r77q.json @@ -7,12 +7,8 @@ "CVE-2014-0015" ], "details": "cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9549-6vm9-3gwr/GHSA-9549-6vm9-3gwr.json b/advisories/unreviewed/2022/05/GHSA-9549-6vm9-3gwr/GHSA-9549-6vm9-3gwr.json index 887b7715d8b..737579b62b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9549-6vm9-3gwr/GHSA-9549-6vm9-3gwr.json +++ b/advisories/unreviewed/2022/05/GHSA-9549-6vm9-3gwr/GHSA-9549-6vm9-3gwr.json @@ -7,12 +7,8 @@ "CVE-2014-2491" ], "details": "Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Portal Framework, a different vulnerability than CVE-2014-4205.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9569-cpr5-gfhc/GHSA-9569-cpr5-gfhc.json b/advisories/unreviewed/2022/05/GHSA-9569-cpr5-gfhc/GHSA-9569-cpr5-gfhc.json index 59d25f3b7aa..f411e70a8a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9569-cpr5-gfhc/GHSA-9569-cpr5-gfhc.json +++ b/advisories/unreviewed/2022/05/GHSA-9569-cpr5-gfhc/GHSA-9569-cpr5-gfhc.json @@ -7,12 +7,8 @@ "CVE-2014-5097" ], "details": "Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95j6-prcp-6mfp/GHSA-95j6-prcp-6mfp.json b/advisories/unreviewed/2022/05/GHSA-95j6-prcp-6mfp/GHSA-95j6-prcp-6mfp.json index 0d718ee411f..8e6d73a8b58 100644 --- a/advisories/unreviewed/2022/05/GHSA-95j6-prcp-6mfp/GHSA-95j6-prcp-6mfp.json +++ b/advisories/unreviewed/2022/05/GHSA-95j6-prcp-6mfp/GHSA-95j6-prcp-6mfp.json @@ -7,12 +7,8 @@ "CVE-2014-5235" ], "details": "Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via vectors related to unspecified fields in RSS feeds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-972q-42q2-6m6q/GHSA-972q-42q2-6m6q.json b/advisories/unreviewed/2022/05/GHSA-972q-42q2-6m6q/GHSA-972q-42q2-6m6q.json index 6a73dca2703..ed62dadffb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-972q-42q2-6m6q/GHSA-972q-42q2-6m6q.json +++ b/advisories/unreviewed/2022/05/GHSA-972q-42q2-6m6q/GHSA-972q-42q2-6m6q.json @@ -7,12 +7,8 @@ "CVE-2014-8373" ], "details": "The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain privileges via vectors involving the \"Connect (by) Using VMRC\" function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97g7-pj49-4gvm/GHSA-97g7-pj49-4gvm.json b/advisories/unreviewed/2022/05/GHSA-97g7-pj49-4gvm/GHSA-97g7-pj49-4gvm.json index 5b2dd2eaf1a..495e9db9881 100644 --- a/advisories/unreviewed/2022/05/GHSA-97g7-pj49-4gvm/GHSA-97g7-pj49-4gvm.json +++ b/advisories/unreviewed/2022/05/GHSA-97g7-pj49-4gvm/GHSA-97g7-pj49-4gvm.json @@ -7,12 +7,8 @@ "CVE-2014-3857" ], "details": "Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98f5-j2qf-rm7w/GHSA-98f5-j2qf-rm7w.json b/advisories/unreviewed/2022/05/GHSA-98f5-j2qf-rm7w/GHSA-98f5-j2qf-rm7w.json index 2d47057f4ba..f75d135b527 100644 --- a/advisories/unreviewed/2022/05/GHSA-98f5-j2qf-rm7w/GHSA-98f5-j2qf-rm7w.json +++ b/advisories/unreviewed/2022/05/GHSA-98f5-j2qf-rm7w/GHSA-98f5-j2qf-rm7w.json @@ -7,12 +7,8 @@ "CVE-2014-8397" ], "details": "Untrusted search path vulnerability in Corel VideoStudio PRO X7 or FastFlick allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse u32ZLib.dll file that is located in the same folder as the file being processed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9953-888v-2xw2/GHSA-9953-888v-2xw2.json b/advisories/unreviewed/2022/05/GHSA-9953-888v-2xw2/GHSA-9953-888v-2xw2.json index 0b8fea9435a..12b53c2112c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9953-888v-2xw2/GHSA-9953-888v-2xw2.json +++ b/advisories/unreviewed/2022/05/GHSA-9953-888v-2xw2/GHSA-9953-888v-2xw2.json @@ -7,12 +7,8 @@ "CVE-2013-1741" ], "details": "Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99pg-966x-c4x3/GHSA-99pg-966x-c4x3.json b/advisories/unreviewed/2022/05/GHSA-99pg-966x-c4x3/GHSA-99pg-966x-c4x3.json index e3d276ad6e2..627de83bf5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-99pg-966x-c4x3/GHSA-99pg-966x-c4x3.json +++ b/advisories/unreviewed/2022/05/GHSA-99pg-966x-c4x3/GHSA-99pg-966x-c4x3.json @@ -7,12 +7,8 @@ "CVE-2014-8082" ], "details": "lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c28-2wjp-xr55/GHSA-9c28-2wjp-xr55.json b/advisories/unreviewed/2022/05/GHSA-9c28-2wjp-xr55/GHSA-9c28-2wjp-xr55.json index d340e09dac5..1901344c228 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c28-2wjp-xr55/GHSA-9c28-2wjp-xr55.json +++ b/advisories/unreviewed/2022/05/GHSA-9c28-2wjp-xr55/GHSA-9c28-2wjp-xr55.json @@ -7,12 +7,8 @@ "CVE-2014-2730" ], "details": "The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption and persistent application hang) via a crafted XML document containing a large number of nested entity references, as demonstrated by a crafted text/plain e-mail message to Outlook, a similar issue to CVE-2003-1564.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9c6c-f33q-qhr3/GHSA-9c6c-f33q-qhr3.json b/advisories/unreviewed/2022/05/GHSA-9c6c-f33q-qhr3/GHSA-9c6c-f33q-qhr3.json index 8d5795b7de7..4c02e853c23 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c6c-f33q-qhr3/GHSA-9c6c-f33q-qhr3.json +++ b/advisories/unreviewed/2022/05/GHSA-9c6c-f33q-qhr3/GHSA-9c6c-f33q-qhr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cwm-xxr8-vw8q/GHSA-9cwm-xxr8-vw8q.json b/advisories/unreviewed/2022/05/GHSA-9cwm-xxr8-vw8q/GHSA-9cwm-xxr8-vw8q.json index a2a1e49a548..56065428c24 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cwm-xxr8-vw8q/GHSA-9cwm-xxr8-vw8q.json +++ b/advisories/unreviewed/2022/05/GHSA-9cwm-xxr8-vw8q/GHSA-9cwm-xxr8-vw8q.json @@ -7,12 +7,8 @@ "CVE-2014-1455" ], "details": "SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and earlier, allows remote attackers to execute arbitrary SQL commands via the new password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gvr-mvxw-g2wj/GHSA-9gvr-mvxw-g2wj.json b/advisories/unreviewed/2022/05/GHSA-9gvr-mvxw-g2wj/GHSA-9gvr-mvxw-g2wj.json index 4fae2cc4cf4..f916188cbc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gvr-mvxw-g2wj/GHSA-9gvr-mvxw-g2wj.json +++ b/advisories/unreviewed/2022/05/GHSA-9gvr-mvxw-g2wj/GHSA-9gvr-mvxw-g2wj.json @@ -7,12 +7,8 @@ "CVE-2014-3797" ], "details": "Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gwv-3vm2-v86h/GHSA-9gwv-3vm2-v86h.json b/advisories/unreviewed/2022/05/GHSA-9gwv-3vm2-v86h/GHSA-9gwv-3vm2-v86h.json index 61ed5cb589c..e11fe99c96f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gwv-3vm2-v86h/GHSA-9gwv-3vm2-v86h.json +++ b/advisories/unreviewed/2022/05/GHSA-9gwv-3vm2-v86h/GHSA-9gwv-3vm2-v86h.json @@ -7,12 +7,8 @@ "CVE-2014-7986" ], "details": "install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hpm-fmxg-j5xc/GHSA-9hpm-fmxg-j5xc.json b/advisories/unreviewed/2022/05/GHSA-9hpm-fmxg-j5xc/GHSA-9hpm-fmxg-j5xc.json index 164358e9ec1..9809f0b50ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hpm-fmxg-j5xc/GHSA-9hpm-fmxg-j5xc.json +++ b/advisories/unreviewed/2022/05/GHSA-9hpm-fmxg-j5xc/GHSA-9hpm-fmxg-j5xc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j62-mm37-x965/GHSA-9j62-mm37-x965.json b/advisories/unreviewed/2022/05/GHSA-9j62-mm37-x965/GHSA-9j62-mm37-x965.json index 8cec385dee9..8ee990976d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j62-mm37-x965/GHSA-9j62-mm37-x965.json +++ b/advisories/unreviewed/2022/05/GHSA-9j62-mm37-x965/GHSA-9j62-mm37-x965.json @@ -7,12 +7,8 @@ "CVE-2013-1739" ], "details": "Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jfc-28w3-mr85/GHSA-9jfc-28w3-mr85.json b/advisories/unreviewed/2022/05/GHSA-9jfc-28w3-mr85/GHSA-9jfc-28w3-mr85.json index 3de6673cc8b..ba512a720b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jfc-28w3-mr85/GHSA-9jfc-28w3-mr85.json +++ b/advisories/unreviewed/2022/05/GHSA-9jfc-28w3-mr85/GHSA-9jfc-28w3-mr85.json @@ -7,12 +7,8 @@ "CVE-2014-5257" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Forma Lms before 1.2.1 p01 allow remote attackers to inject arbitrary web script or HTML via the (1) id_custom parameter in an amanmenu request or (2) id_game parameter in an alms/games/edit request to appCore/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jfc-hp58-576f/GHSA-9jfc-hp58-576f.json b/advisories/unreviewed/2022/05/GHSA-9jfc-hp58-576f/GHSA-9jfc-hp58-576f.json index de2672da71b..1c860454ed2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jfc-hp58-576f/GHSA-9jfc-hp58-576f.json +++ b/advisories/unreviewed/2022/05/GHSA-9jfc-hp58-576f/GHSA-9jfc-hp58-576f.json @@ -7,12 +7,8 @@ "CVE-2011-4834" ], "details": "The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mjx-fxxr-3w7h/GHSA-9mjx-fxxr-3w7h.json b/advisories/unreviewed/2022/05/GHSA-9mjx-fxxr-3w7h/GHSA-9mjx-fxxr-3w7h.json index 11e99c8ba82..02be16c2561 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mjx-fxxr-3w7h/GHSA-9mjx-fxxr-3w7h.json +++ b/advisories/unreviewed/2022/05/GHSA-9mjx-fxxr-3w7h/GHSA-9mjx-fxxr-3w7h.json @@ -7,12 +7,8 @@ "CVE-2014-0436" ], "details": "Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Web Analysis.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mwp-5cv9-4623/GHSA-9mwp-5cv9-4623.json b/advisories/unreviewed/2022/05/GHSA-9mwp-5cv9-4623/GHSA-9mwp-5cv9-4623.json index ba68f7ed0d7..b0cce870125 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mwp-5cv9-4623/GHSA-9mwp-5cv9-4623.json +++ b/advisories/unreviewed/2022/05/GHSA-9mwp-5cv9-4623/GHSA-9mwp-5cv9-4623.json @@ -7,12 +7,8 @@ "CVE-2015-2075" ], "details": "SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mwq-hjj7-fhx6/GHSA-9mwq-hjj7-fhx6.json b/advisories/unreviewed/2022/05/GHSA-9mwq-hjj7-fhx6/GHSA-9mwq-hjj7-fhx6.json index b8499e4496b..5ddcc10dd35 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mwq-hjj7-fhx6/GHSA-9mwq-hjj7-fhx6.json +++ b/advisories/unreviewed/2022/05/GHSA-9mwq-hjj7-fhx6/GHSA-9mwq-hjj7-fhx6.json @@ -7,12 +7,8 @@ "CVE-2014-3438" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p64-f6jw-7f76/GHSA-9p64-f6jw-7f76.json b/advisories/unreviewed/2022/05/GHSA-9p64-f6jw-7f76/GHSA-9p64-f6jw-7f76.json index 46f6e1a6399..2fbea8730ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p64-f6jw-7f76/GHSA-9p64-f6jw-7f76.json +++ b/advisories/unreviewed/2022/05/GHSA-9p64-f6jw-7f76/GHSA-9p64-f6jw-7f76.json @@ -7,12 +7,8 @@ "CVE-2014-2496" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Test Framework.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r5c-96r6-629r/GHSA-9r5c-96r6-629r.json b/advisories/unreviewed/2022/05/GHSA-9r5c-96r6-629r/GHSA-9r5c-96r6-629r.json index 83a2bf516bf..2e91a7b9983 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r5c-96r6-629r/GHSA-9r5c-96r6-629r.json +++ b/advisories/unreviewed/2022/05/GHSA-9r5c-96r6-629r/GHSA-9r5c-96r6-629r.json @@ -7,12 +7,8 @@ "CVE-2014-2177" ], "details": "The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCuh87126.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rcf-cw39-wcmj/GHSA-9rcf-cw39-wcmj.json b/advisories/unreviewed/2022/05/GHSA-9rcf-cw39-wcmj/GHSA-9rcf-cw39-wcmj.json index 601c9dbfabe..e6b07f162b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rcf-cw39-wcmj/GHSA-9rcf-cw39-wcmj.json +++ b/advisories/unreviewed/2022/05/GHSA-9rcf-cw39-wcmj/GHSA-9rcf-cw39-wcmj.json @@ -7,12 +7,8 @@ "CVE-2014-3111" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Printer Model field to the Printer Management page, (2) Image Name field to the Image Management page, (3) Storage Group Name field to the Storage Management page, (4) Username field to the User Cleanup FOG Configuration page, or (5) Directory Path field to the Directory Cleaner FOG Configuration page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rg4-v77r-32p7/GHSA-9rg4-v77r-32p7.json b/advisories/unreviewed/2022/05/GHSA-9rg4-v77r-32p7/GHSA-9rg4-v77r-32p7.json index 083883cf488..40bb00448a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rg4-v77r-32p7/GHSA-9rg4-v77r-32p7.json +++ b/advisories/unreviewed/2022/05/GHSA-9rg4-v77r-32p7/GHSA-9rg4-v77r-32p7.json @@ -7,12 +7,8 @@ "CVE-2014-0999" ], "details": "Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v29-jj89-qr6f/GHSA-9v29-jj89-qr6f.json b/advisories/unreviewed/2022/05/GHSA-9v29-jj89-qr6f/GHSA-9v29-jj89-qr6f.json index 8b5a1d91b10..3acd3a8bc08 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v29-jj89-qr6f/GHSA-9v29-jj89-qr6f.json +++ b/advisories/unreviewed/2022/05/GHSA-9v29-jj89-qr6f/GHSA-9v29-jj89-qr6f.json @@ -7,12 +7,8 @@ "CVE-2014-0220" ], "details": "Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vc6-5cgr-2rx3/GHSA-9vc6-5cgr-2rx3.json b/advisories/unreviewed/2022/05/GHSA-9vc6-5cgr-2rx3/GHSA-9vc6-5cgr-2rx3.json index 26ecdc4b2c7..014adfd5799 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vc6-5cgr-2rx3/GHSA-9vc6-5cgr-2rx3.json +++ b/advisories/unreviewed/2022/05/GHSA-9vc6-5cgr-2rx3/GHSA-9vc6-5cgr-2rx3.json @@ -7,12 +7,8 @@ "CVE-2014-2388" ], "details": "The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w3r-phm7-v8q5/GHSA-9w3r-phm7-v8q5.json b/advisories/unreviewed/2022/05/GHSA-9w3r-phm7-v8q5/GHSA-9w3r-phm7-v8q5.json index 62031f7bf15..3c79c6d6a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w3r-phm7-v8q5/GHSA-9w3r-phm7-v8q5.json +++ b/advisories/unreviewed/2022/05/GHSA-9w3r-phm7-v8q5/GHSA-9w3r-phm7-v8q5.json @@ -7,12 +7,8 @@ "CVE-2011-5259" ], "details": "SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x3v-wmxw-5f95/GHSA-9x3v-wmxw-5f95.json b/advisories/unreviewed/2022/05/GHSA-9x3v-wmxw-5f95/GHSA-9x3v-wmxw-5f95.json index 8a212cae5c8..2bed4fcb887 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x3v-wmxw-5f95/GHSA-9x3v-wmxw-5f95.json +++ b/advisories/unreviewed/2022/05/GHSA-9x3v-wmxw-5f95/GHSA-9x3v-wmxw-5f95.json @@ -7,12 +7,8 @@ "CVE-2014-0870" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBName parameter to rcore6/frameset.jsp, (4) the Init parameter to algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7) STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x5x-99rm-rq9h/GHSA-9x5x-99rm-rq9h.json b/advisories/unreviewed/2022/05/GHSA-9x5x-99rm-rq9h/GHSA-9x5x-99rm-rq9h.json index 092c6e0d685..2a3603b8b75 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x5x-99rm-rq9h/GHSA-9x5x-99rm-rq9h.json +++ b/advisories/unreviewed/2022/05/GHSA-9x5x-99rm-rq9h/GHSA-9x5x-99rm-rq9h.json @@ -7,12 +7,8 @@ "CVE-2014-6603" ], "details": "The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xgg-6j67-8x58/GHSA-9xgg-6j67-8x58.json b/advisories/unreviewed/2022/05/GHSA-9xgg-6j67-8x58/GHSA-9xgg-6j67-8x58.json index 5ba3e831634..ad6a90c8a0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xgg-6j67-8x58/GHSA-9xgg-6j67-8x58.json +++ b/advisories/unreviewed/2022/05/GHSA-9xgg-6j67-8x58/GHSA-9xgg-6j67-8x58.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xjq-pqm7-353q/GHSA-9xjq-pqm7-353q.json b/advisories/unreviewed/2022/05/GHSA-9xjq-pqm7-353q/GHSA-9xjq-pqm7-353q.json index 8e7aa5c81e4..c942fdb34f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xjq-pqm7-353q/GHSA-9xjq-pqm7-353q.json +++ b/advisories/unreviewed/2022/05/GHSA-9xjq-pqm7-353q/GHSA-9xjq-pqm7-353q.json @@ -7,12 +7,8 @@ "CVE-2014-3210" ], "details": "SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xv3-rrw4-9qm8/GHSA-9xv3-rrw4-9qm8.json b/advisories/unreviewed/2022/05/GHSA-9xv3-rrw4-9qm8/GHSA-9xv3-rrw4-9qm8.json index 4845b08d055..dbd66c659b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xv3-rrw4-9qm8/GHSA-9xv3-rrw4-9qm8.json +++ b/advisories/unreviewed/2022/05/GHSA-9xv3-rrw4-9qm8/GHSA-9xv3-rrw4-9qm8.json @@ -7,12 +7,8 @@ "CVE-2014-8870" ], "details": "Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 for Woltlab Burning Board 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the board_url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2gh-vwcm-fjx7/GHSA-c2gh-vwcm-fjx7.json b/advisories/unreviewed/2022/05/GHSA-c2gh-vwcm-fjx7/GHSA-c2gh-vwcm-fjx7.json index f855e46b088..156ff951bc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2gh-vwcm-fjx7/GHSA-c2gh-vwcm-fjx7.json +++ b/advisories/unreviewed/2022/05/GHSA-c2gh-vwcm-fjx7/GHSA-c2gh-vwcm-fjx7.json @@ -7,12 +7,8 @@ "CVE-2015-1518" ], "details": "SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2jm-rg5v-977c/GHSA-c2jm-rg5v-977c.json b/advisories/unreviewed/2022/05/GHSA-c2jm-rg5v-977c/GHSA-c2jm-rg5v-977c.json index f81754512a4..4e64001f34b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2jm-rg5v-977c/GHSA-c2jm-rg5v-977c.json +++ b/advisories/unreviewed/2022/05/GHSA-c2jm-rg5v-977c/GHSA-c2jm-rg5v-977c.json @@ -7,12 +7,8 @@ "CVE-2014-4211" ], "details": "Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.7 and 11.1.1.8 allows remote attackers to affect integrity via unknown vectors related to Portlet Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c37m-6w24-rcv9/GHSA-c37m-6w24-rcv9.json b/advisories/unreviewed/2022/05/GHSA-c37m-6w24-rcv9/GHSA-c37m-6w24-rcv9.json index 179cce18b94..a435dfd21d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c37m-6w24-rcv9/GHSA-c37m-6w24-rcv9.json +++ b/advisories/unreviewed/2022/05/GHSA-c37m-6w24-rcv9/GHSA-c37m-6w24-rcv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3cc-gm9v-rc3h/GHSA-c3cc-gm9v-rc3h.json b/advisories/unreviewed/2022/05/GHSA-c3cc-gm9v-rc3h/GHSA-c3cc-gm9v-rc3h.json index a3d97199bb5..e126a060d4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3cc-gm9v-rc3h/GHSA-c3cc-gm9v-rc3h.json +++ b/advisories/unreviewed/2022/05/GHSA-c3cc-gm9v-rc3h/GHSA-c3cc-gm9v-rc3h.json @@ -7,12 +7,8 @@ "CVE-2011-3979" ], "details": "Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other versions allows remote attackers to inject arbitrary web script or HTML via the themename parameter in the setasdefault action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4jg-9g74-c7p6/GHSA-c4jg-9g74-c7p6.json b/advisories/unreviewed/2022/05/GHSA-c4jg-9g74-c7p6/GHSA-c4jg-9g74-c7p6.json index bee47487a9e..34f3cc7a3b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4jg-9g74-c7p6/GHSA-c4jg-9g74-c7p6.json +++ b/advisories/unreviewed/2022/05/GHSA-c4jg-9g74-c7p6/GHSA-c4jg-9g74-c7p6.json @@ -7,12 +7,8 @@ "CVE-2014-8085" ], "details": "Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c53q-wg6w-6jm7/GHSA-c53q-wg6w-6jm7.json b/advisories/unreviewed/2022/05/GHSA-c53q-wg6w-6jm7/GHSA-c53q-wg6w-6jm7.json index 856e250c302..bdf96301ed1 100644 --- a/advisories/unreviewed/2022/05/GHSA-c53q-wg6w-6jm7/GHSA-c53q-wg6w-6jm7.json +++ b/advisories/unreviewed/2022/05/GHSA-c53q-wg6w-6jm7/GHSA-c53q-wg6w-6jm7.json @@ -7,12 +7,8 @@ "CVE-2011-5258" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5xx-92gp-xmp6/GHSA-c5xx-92gp-xmp6.json b/advisories/unreviewed/2022/05/GHSA-c5xx-92gp-xmp6/GHSA-c5xx-92gp-xmp6.json index e754f27dd35..548530e6333 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5xx-92gp-xmp6/GHSA-c5xx-92gp-xmp6.json +++ b/advisories/unreviewed/2022/05/GHSA-c5xx-92gp-xmp6/GHSA-c5xx-92gp-xmp6.json @@ -7,12 +7,8 @@ "CVE-2011-5107" ], "details": "Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c656-hcc6-xc8v/GHSA-c656-hcc6-xc8v.json b/advisories/unreviewed/2022/05/GHSA-c656-hcc6-xc8v/GHSA-c656-hcc6-xc8v.json index 0bc9286f38b..55ae3c92e1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c656-hcc6-xc8v/GHSA-c656-hcc6-xc8v.json +++ b/advisories/unreviewed/2022/05/GHSA-c656-hcc6-xc8v/GHSA-c656-hcc6-xc8v.json @@ -7,12 +7,8 @@ "CVE-2014-0211" ], "details": "Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c66x-5w35-7wmh/GHSA-c66x-5w35-7wmh.json b/advisories/unreviewed/2022/05/GHSA-c66x-5w35-7wmh/GHSA-c66x-5w35-7wmh.json index 137ad7465f2..fc5a5b9110d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c66x-5w35-7wmh/GHSA-c66x-5w35-7wmh.json +++ b/advisories/unreviewed/2022/05/GHSA-c66x-5w35-7wmh/GHSA-c66x-5w35-7wmh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6f9-6q47-7q73/GHSA-c6f9-6q47-7q73.json b/advisories/unreviewed/2022/05/GHSA-c6f9-6q47-7q73/GHSA-c6f9-6q47-7q73.json index ee2ee09b5dd..78d8e3d85f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6f9-6q47-7q73/GHSA-c6f9-6q47-7q73.json +++ b/advisories/unreviewed/2022/05/GHSA-c6f9-6q47-7q73/GHSA-c6f9-6q47-7q73.json @@ -7,12 +7,8 @@ "CVE-2014-2179" ], "details": "The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6qp-2qc4-4h58/GHSA-c6qp-2qc4-4h58.json b/advisories/unreviewed/2022/05/GHSA-c6qp-2qc4-4h58/GHSA-c6qp-2qc4-4h58.json index 887cbd81b6d..8bc15aa739b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6qp-2qc4-4h58/GHSA-c6qp-2qc4-4h58.json +++ b/advisories/unreviewed/2022/05/GHSA-c6qp-2qc4-4h58/GHSA-c6qp-2qc4-4h58.json @@ -7,12 +7,8 @@ "CVE-2015-1558" ], "details": "Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6rg-vc6c-7fch/GHSA-c6rg-vc6c-7fch.json b/advisories/unreviewed/2022/05/GHSA-c6rg-vc6c-7fch/GHSA-c6rg-vc6c-7fch.json index 2f790b9077d..a07229e61eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6rg-vc6c-7fch/GHSA-c6rg-vc6c-7fch.json +++ b/advisories/unreviewed/2022/05/GHSA-c6rg-vc6c-7fch/GHSA-c6rg-vc6c-7fch.json @@ -7,12 +7,8 @@ "CVE-2014-4267" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c778-g7jg-99x4/GHSA-c778-g7jg-99x4.json b/advisories/unreviewed/2022/05/GHSA-c778-g7jg-99x4/GHSA-c778-g7jg-99x4.json index 95e57ff6d5e..68aa339873f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c778-g7jg-99x4/GHSA-c778-g7jg-99x4.json +++ b/advisories/unreviewed/2022/05/GHSA-c778-g7jg-99x4/GHSA-c778-g7jg-99x4.json @@ -7,12 +7,8 @@ "CVE-2014-4254" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c798-qcm4-fvhx/GHSA-c798-qcm4-fvhx.json b/advisories/unreviewed/2022/05/GHSA-c798-qcm4-fvhx/GHSA-c798-qcm4-fvhx.json index 2a9133999cf..45fb8e8c5b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c798-qcm4-fvhx/GHSA-c798-qcm4-fvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-c798-qcm4-fvhx/GHSA-c798-qcm4-fvhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7gr-mvmf-xv4h/GHSA-c7gr-mvmf-xv4h.json b/advisories/unreviewed/2022/05/GHSA-c7gr-mvmf-xv4h/GHSA-c7gr-mvmf-xv4h.json index 0b48738dd40..bfb25ce388f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7gr-mvmf-xv4h/GHSA-c7gr-mvmf-xv4h.json +++ b/advisories/unreviewed/2022/05/GHSA-c7gr-mvmf-xv4h/GHSA-c7gr-mvmf-xv4h.json @@ -7,12 +7,8 @@ "CVE-2015-1517" ], "details": "SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a \"Refresh photo set\" action in the batch_manager page to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c976-c57v-wjwr/GHSA-c976-c57v-wjwr.json b/advisories/unreviewed/2022/05/GHSA-c976-c57v-wjwr/GHSA-c976-c57v-wjwr.json index f1fad79782f..865a76f75f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c976-c57v-wjwr/GHSA-c976-c57v-wjwr.json +++ b/advisories/unreviewed/2022/05/GHSA-c976-c57v-wjwr/GHSA-c976-c57v-wjwr.json @@ -7,12 +7,8 @@ "CVE-2014-8396" ], "details": "Untrusted search path vulnerability in Corel PDF Fusion allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll file that is located in the same folder as the file being processed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c97p-79cx-vqh9/GHSA-c97p-79cx-vqh9.json b/advisories/unreviewed/2022/05/GHSA-c97p-79cx-vqh9/GHSA-c97p-79cx-vqh9.json index 7b75ed30bcf..fd873edbb79 100644 --- a/advisories/unreviewed/2022/05/GHSA-c97p-79cx-vqh9/GHSA-c97p-79cx-vqh9.json +++ b/advisories/unreviewed/2022/05/GHSA-c97p-79cx-vqh9/GHSA-c97p-79cx-vqh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9fh-ff5v-mffg/GHSA-c9fh-ff5v-mffg.json b/advisories/unreviewed/2022/05/GHSA-c9fh-ff5v-mffg/GHSA-c9fh-ff5v-mffg.json index 85dc90f1810..4996d94d56d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9fh-ff5v-mffg/GHSA-c9fh-ff5v-mffg.json +++ b/advisories/unreviewed/2022/05/GHSA-c9fh-ff5v-mffg/GHSA-c9fh-ff5v-mffg.json @@ -7,12 +7,8 @@ "CVE-2014-1459" ], "details": "SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_down_id parameter. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccrq-mrj7-rq78/GHSA-ccrq-mrj7-rq78.json b/advisories/unreviewed/2022/05/GHSA-ccrq-mrj7-rq78/GHSA-ccrq-mrj7-rq78.json index e15379fd7a6..40b75ef8b66 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccrq-mrj7-rq78/GHSA-ccrq-mrj7-rq78.json +++ b/advisories/unreviewed/2022/05/GHSA-ccrq-mrj7-rq78/GHSA-ccrq-mrj7-rq78.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfcf-26xg-6rpv/GHSA-cfcf-26xg-6rpv.json b/advisories/unreviewed/2022/05/GHSA-cfcf-26xg-6rpv/GHSA-cfcf-26xg-6rpv.json index 039d3065978..d801c64ba9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfcf-26xg-6rpv/GHSA-cfcf-26xg-6rpv.json +++ b/advisories/unreviewed/2022/05/GHSA-cfcf-26xg-6rpv/GHSA-cfcf-26xg-6rpv.json @@ -7,12 +7,8 @@ "CVE-2014-2485" ], "details": "Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality via unknown vectors related to Integration Business Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cffw-pvf2-3x8m/GHSA-cffw-pvf2-3x8m.json b/advisories/unreviewed/2022/05/GHSA-cffw-pvf2-3x8m/GHSA-cffw-pvf2-3x8m.json index fcbb770ccb3..760aa8dbb3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cffw-pvf2-3x8m/GHSA-cffw-pvf2-3x8m.json +++ b/advisories/unreviewed/2022/05/GHSA-cffw-pvf2-3x8m/GHSA-cffw-pvf2-3x8m.json @@ -7,12 +7,8 @@ "CVE-2014-2715" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\\templates\\logout.tpl.php in the VideoWhisper Webcam plugins for Drupal 7.x allow remote attackers to inject arbitrary web script or HTML via the (1) module or (2) message parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfv3-vpqw-2xgj/GHSA-cfv3-vpqw-2xgj.json b/advisories/unreviewed/2022/05/GHSA-cfv3-vpqw-2xgj/GHSA-cfv3-vpqw-2xgj.json index 98a0fb841d9..9a47401f9e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfv3-vpqw-2xgj/GHSA-cfv3-vpqw-2xgj.json +++ b/advisories/unreviewed/2022/05/GHSA-cfv3-vpqw-2xgj/GHSA-cfv3-vpqw-2xgj.json @@ -7,12 +7,8 @@ "CVE-2014-2486" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2477.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cg3h-8j55-gc4x/GHSA-cg3h-8j55-gc4x.json b/advisories/unreviewed/2022/05/GHSA-cg3h-8j55-gc4x/GHSA-cg3h-8j55-gc4x.json index 78fbe2a1813..28e967db7e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg3h-8j55-gc4x/GHSA-cg3h-8j55-gc4x.json +++ b/advisories/unreviewed/2022/05/GHSA-cg3h-8j55-gc4x/GHSA-cg3h-8j55-gc4x.json @@ -7,12 +7,8 @@ "CVE-2014-4270" ], "details": "Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a different vulnerability than CVE-2014-4269.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgg9-3m27-m426/GHSA-cgg9-3m27-m426.json b/advisories/unreviewed/2022/05/GHSA-cgg9-3m27-m426/GHSA-cgg9-3m27-m426.json index be630e93100..4eb549e35a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgg9-3m27-m426/GHSA-cgg9-3m27-m426.json +++ b/advisories/unreviewed/2022/05/GHSA-cgg9-3m27-m426/GHSA-cgg9-3m27-m426.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj3j-m7h5-mr79/GHSA-cj3j-m7h5-mr79.json b/advisories/unreviewed/2022/05/GHSA-cj3j-m7h5-mr79/GHSA-cj3j-m7h5-mr79.json index 9621312dc33..1a59af44aa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj3j-m7h5-mr79/GHSA-cj3j-m7h5-mr79.json +++ b/advisories/unreviewed/2022/05/GHSA-cj3j-m7h5-mr79/GHSA-cj3j-m7h5-mr79.json @@ -7,12 +7,8 @@ "CVE-2013-7219" ], "details": "SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the answer_id[] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj67-c85m-hjw4/GHSA-cj67-c85m-hjw4.json b/advisories/unreviewed/2022/05/GHSA-cj67-c85m-hjw4/GHSA-cj67-c85m-hjw4.json index d11fee3d051..9066dfc97ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj67-c85m-hjw4/GHSA-cj67-c85m-hjw4.json +++ b/advisories/unreviewed/2022/05/GHSA-cj67-c85m-hjw4/GHSA-cj67-c85m-hjw4.json @@ -7,12 +7,8 @@ "CVE-2014-8612" ], "details": "Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function, when setting the SCTIP_SS_VALUE option, or (2) read arbitrary kernel memory via the stream id to the getsockopt function, when getting the SCTP_SS_PRIORITY option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpw6-5jfx-2w4c/GHSA-cpw6-5jfx-2w4c.json b/advisories/unreviewed/2022/05/GHSA-cpw6-5jfx-2w4c/GHSA-cpw6-5jfx-2w4c.json index 6882b6b1512..ee7ce82d8de 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpw6-5jfx-2w4c/GHSA-cpw6-5jfx-2w4c.json +++ b/advisories/unreviewed/2022/05/GHSA-cpw6-5jfx-2w4c/GHSA-cpw6-5jfx-2w4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq8f-2gqx-jf55/GHSA-cq8f-2gqx-jf55.json b/advisories/unreviewed/2022/05/GHSA-cq8f-2gqx-jf55/GHSA-cq8f-2gqx-jf55.json index bef61736960..808c59e31dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq8f-2gqx-jf55/GHSA-cq8f-2gqx-jf55.json +++ b/advisories/unreviewed/2022/05/GHSA-cq8f-2gqx-jf55/GHSA-cq8f-2gqx-jf55.json @@ -7,12 +7,8 @@ "CVE-2014-4245" ], "details": "Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqw5-qvh9-f85v/GHSA-cqw5-qvh9-f85v.json b/advisories/unreviewed/2022/05/GHSA-cqw5-qvh9-f85v/GHSA-cqw5-qvh9-f85v.json index d967ec702d2..a14f539a4cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqw5-qvh9-f85v/GHSA-cqw5-qvh9-f85v.json +++ b/advisories/unreviewed/2022/05/GHSA-cqw5-qvh9-f85v/GHSA-cqw5-qvh9-f85v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr98-j6fv-34rq/GHSA-cr98-j6fv-34rq.json b/advisories/unreviewed/2022/05/GHSA-cr98-j6fv-34rq/GHSA-cr98-j6fv-34rq.json index 11c9e20e360..93cb19c2300 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr98-j6fv-34rq/GHSA-cr98-j6fv-34rq.json +++ b/advisories/unreviewed/2022/05/GHSA-cr98-j6fv-34rq/GHSA-cr98-j6fv-34rq.json @@ -7,12 +7,8 @@ "CVE-2014-5258" ], "details": "Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvm3-233f-g2vf/GHSA-cvm3-233f-g2vf.json b/advisories/unreviewed/2022/05/GHSA-cvm3-233f-g2vf/GHSA-cvm3-233f-g2vf.json index 53727ad6f25..2c762a018f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvm3-233f-g2vf/GHSA-cvm3-233f-g2vf.json +++ b/advisories/unreviewed/2022/05/GHSA-cvm3-233f-g2vf/GHSA-cvm3-233f-g2vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwvr-8j54-7jwh/GHSA-cwvr-8j54-7jwh.json b/advisories/unreviewed/2022/05/GHSA-cwvr-8j54-7jwh/GHSA-cwvr-8j54-7jwh.json index 6fa601aed83..fe475d89d48 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwvr-8j54-7jwh/GHSA-cwvr-8j54-7jwh.json +++ b/advisories/unreviewed/2022/05/GHSA-cwvr-8j54-7jwh/GHSA-cwvr-8j54-7jwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx55-6qpj-fmjq/GHSA-cx55-6qpj-fmjq.json b/advisories/unreviewed/2022/05/GHSA-cx55-6qpj-fmjq/GHSA-cx55-6qpj-fmjq.json index 752722b9783..e0b6056aba9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx55-6qpj-fmjq/GHSA-cx55-6qpj-fmjq.json +++ b/advisories/unreviewed/2022/05/GHSA-cx55-6qpj-fmjq/GHSA-cx55-6qpj-fmjq.json @@ -7,12 +7,8 @@ "CVE-2014-4206" ], "details": "Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect integrity and availability via unknown vectors related to Data Synchronizer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2cx-w4q6-4qq4/GHSA-f2cx-w4q6-4qq4.json b/advisories/unreviewed/2022/05/GHSA-f2cx-w4q6-4qq4/GHSA-f2cx-w4q6-4qq4.json index dd0abcc4e3e..eb2a291e911 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2cx-w4q6-4qq4/GHSA-f2cx-w4q6-4qq4.json +++ b/advisories/unreviewed/2022/05/GHSA-f2cx-w4q6-4qq4/GHSA-f2cx-w4q6-4qq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2mx-7p4c-2cvr/GHSA-f2mx-7p4c-2cvr.json b/advisories/unreviewed/2022/05/GHSA-f2mx-7p4c-2cvr/GHSA-f2mx-7p4c-2cvr.json index 66b93323f46..ff3b304128f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2mx-7p4c-2cvr/GHSA-f2mx-7p4c-2cvr.json +++ b/advisories/unreviewed/2022/05/GHSA-f2mx-7p4c-2cvr/GHSA-f2mx-7p4c-2cvr.json @@ -7,12 +7,8 @@ "CVE-2014-0647" ], "details": "The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f334-mrv2-rrrr/GHSA-f334-mrv2-rrrr.json b/advisories/unreviewed/2022/05/GHSA-f334-mrv2-rrrr/GHSA-f334-mrv2-rrrr.json index d0a232bc33b..bbc082b722b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f334-mrv2-rrrr/GHSA-f334-mrv2-rrrr.json +++ b/advisories/unreviewed/2022/05/GHSA-f334-mrv2-rrrr/GHSA-f334-mrv2-rrrr.json @@ -7,12 +7,8 @@ "CVE-2014-3428" ], "details": "Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f39g-97j7-v6v7/GHSA-f39g-97j7-v6v7.json b/advisories/unreviewed/2022/05/GHSA-f39g-97j7-v6v7/GHSA-f39g-97j7-v6v7.json index 5ec242d385f..63c41c3c8c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f39g-97j7-v6v7/GHSA-f39g-97j7-v6v7.json +++ b/advisories/unreviewed/2022/05/GHSA-f39g-97j7-v6v7/GHSA-f39g-97j7-v6v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3fj-9xg7-49g7/GHSA-f3fj-9xg7-49g7.json b/advisories/unreviewed/2022/05/GHSA-f3fj-9xg7-49g7/GHSA-f3fj-9xg7-49g7.json index a027290a5d4..21d54b1d383 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3fj-9xg7-49g7/GHSA-f3fj-9xg7-49g7.json +++ b/advisories/unreviewed/2022/05/GHSA-f3fj-9xg7-49g7/GHSA-f3fj-9xg7-49g7.json @@ -7,12 +7,8 @@ "CVE-2014-2879" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f499-3q8w-php5/GHSA-f499-3q8w-php5.json b/advisories/unreviewed/2022/05/GHSA-f499-3q8w-php5/GHSA-f499-3q8w-php5.json index 64024e344d2..46f16711996 100644 --- a/advisories/unreviewed/2022/05/GHSA-f499-3q8w-php5/GHSA-f499-3q8w-php5.json +++ b/advisories/unreviewed/2022/05/GHSA-f499-3q8w-php5/GHSA-f499-3q8w-php5.json @@ -7,12 +7,8 @@ "CVE-2014-6242" ], "details": "Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4g5-8f5m-c4xh/GHSA-f4g5-8f5m-c4xh.json b/advisories/unreviewed/2022/05/GHSA-f4g5-8f5m-c4xh/GHSA-f4g5-8f5m-c4xh.json index 89baaa4bd1c..9e2b26a8c95 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4g5-8f5m-c4xh/GHSA-f4g5-8f5m-c4xh.json +++ b/advisories/unreviewed/2022/05/GHSA-f4g5-8f5m-c4xh/GHSA-f4g5-8f5m-c4xh.json @@ -7,12 +7,8 @@ "CVE-2014-7864" ], "details": "Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) customerName or (2) serverRole parameter in a standbyUpdateInCentral operation to servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4w7-f52m-fr89/GHSA-f4w7-f52m-fr89.json b/advisories/unreviewed/2022/05/GHSA-f4w7-f52m-fr89/GHSA-f4w7-f52m-fr89.json index 83075c226bd..63b2333de84 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4w7-f52m-fr89/GHSA-f4w7-f52m-fr89.json +++ b/advisories/unreviewed/2022/05/GHSA-f4w7-f52m-fr89/GHSA-f4w7-f52m-fr89.json @@ -7,12 +7,8 @@ "CVE-2014-8391" ], "details": "The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4wj-qq69-7p3q/GHSA-f4wj-qq69-7p3q.json b/advisories/unreviewed/2022/05/GHSA-f4wj-qq69-7p3q/GHSA-f4wj-qq69-7p3q.json index b910ca40754..d440bbf8731 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4wj-qq69-7p3q/GHSA-f4wj-qq69-7p3q.json +++ b/advisories/unreviewed/2022/05/GHSA-f4wj-qq69-7p3q/GHSA-f4wj-qq69-7p3q.json @@ -7,12 +7,8 @@ "CVE-2014-8874" ], "details": "The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remote attackers to obtain sensitive information via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f54w-frwq-8pgx/GHSA-f54w-frwq-8pgx.json b/advisories/unreviewed/2022/05/GHSA-f54w-frwq-8pgx/GHSA-f54w-frwq-8pgx.json index f7719c5366f..1693172de9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f54w-frwq-8pgx/GHSA-f54w-frwq-8pgx.json +++ b/advisories/unreviewed/2022/05/GHSA-f54w-frwq-8pgx/GHSA-f54w-frwq-8pgx.json @@ -7,12 +7,8 @@ "CVE-2014-1224" ], "details": "Incomplete blacklist vulnerability in the user registration feature in rexx Recruitment R6.1 and R7 without \"fixes from 2014-01-15\" allows remote attackers to conduct cross-site scripting (XSS) attacks via the oninput event handler in the fname parameter to the default URI in /reg.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5cm-fvx4-j5xj/GHSA-f5cm-fvx4-j5xj.json b/advisories/unreviewed/2022/05/GHSA-f5cm-fvx4-j5xj/GHSA-f5cm-fvx4-j5xj.json index a8033085444..53f7ad90704 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5cm-fvx4-j5xj/GHSA-f5cm-fvx4-j5xj.json +++ b/advisories/unreviewed/2022/05/GHSA-f5cm-fvx4-j5xj/GHSA-f5cm-fvx4-j5xj.json @@ -7,12 +7,8 @@ "CVE-2014-2482" ], "details": "Unspecified vulnerability in the Oracle Concurrent Processing component in Oracle E-Business Suite 12.1.3, 12.2.2, and 12.2.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5vv-v37r-r859/GHSA-f5vv-v37r-r859.json b/advisories/unreviewed/2022/05/GHSA-f5vv-v37r-r859/GHSA-f5vv-v37r-r859.json index 63cdda2ceea..8d79a3de1a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5vv-v37r-r859/GHSA-f5vv-v37r-r859.json +++ b/advisories/unreviewed/2022/05/GHSA-f5vv-v37r-r859/GHSA-f5vv-v37r-r859.json @@ -7,12 +7,8 @@ "CVE-2014-2087" ], "details": "Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7gq-46jw-6c9v/GHSA-f7gq-46jw-6c9v.json b/advisories/unreviewed/2022/05/GHSA-f7gq-46jw-6c9v/GHSA-f7gq-46jw-6c9v.json index ac8be4a6d6d..d88971a069a 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7gq-46jw-6c9v/GHSA-f7gq-46jw-6c9v.json +++ b/advisories/unreviewed/2022/05/GHSA-f7gq-46jw-6c9v/GHSA-f7gq-46jw-6c9v.json @@ -7,12 +7,8 @@ "CVE-2014-2481" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-2480.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f897-6cg8-5m2p/GHSA-f897-6cg8-5m2p.json b/advisories/unreviewed/2022/05/GHSA-f897-6cg8-5m2p/GHSA-f897-6cg8-5m2p.json index cba33369ac9..4b01882e878 100644 --- a/advisories/unreviewed/2022/05/GHSA-f897-6cg8-5m2p/GHSA-f897-6cg8-5m2p.json +++ b/advisories/unreviewed/2022/05/GHSA-f897-6cg8-5m2p/GHSA-f897-6cg8-5m2p.json @@ -7,12 +7,8 @@ "CVE-2014-6616" ], "details": "Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V2.02.0.00 allows remote attackers to inject arbitrary web script or HTML via the DEVICE_NAME parameter to cgi-bin/CFGhttp/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8v4-rq66-62m8/GHSA-f8v4-rq66-62m8.json b/advisories/unreviewed/2022/05/GHSA-f8v4-rq66-62m8/GHSA-f8v4-rq66-62m8.json index 2d5bacd6873..b5cc17b881f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8v4-rq66-62m8/GHSA-f8v4-rq66-62m8.json +++ b/advisories/unreviewed/2022/05/GHSA-f8v4-rq66-62m8/GHSA-f8v4-rq66-62m8.json @@ -7,12 +7,8 @@ "CVE-2014-5392" ], "details": "XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ffg7-4prh-6h36/GHSA-ffg7-4prh-6h36.json b/advisories/unreviewed/2022/05/GHSA-ffg7-4prh-6h36/GHSA-ffg7-4prh-6h36.json index ed876866472..a75181a7a0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffg7-4prh-6h36/GHSA-ffg7-4prh-6h36.json +++ b/advisories/unreviewed/2022/05/GHSA-ffg7-4prh-6h36/GHSA-ffg7-4prh-6h36.json @@ -7,12 +7,8 @@ "CVE-2015-1366" ], "details": "Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg7q-r8wr-ch8g/GHSA-fg7q-r8wr-ch8g.json b/advisories/unreviewed/2022/05/GHSA-fg7q-r8wr-ch8g/GHSA-fg7q-r8wr-ch8g.json index 3b6344ff393..dc94d7edeff 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg7q-r8wr-ch8g/GHSA-fg7q-r8wr-ch8g.json +++ b/advisories/unreviewed/2022/05/GHSA-fg7q-r8wr-ch8g/GHSA-fg7q-r8wr-ch8g.json @@ -7,12 +7,8 @@ "CVE-2014-8868" ], "details": "EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgcr-rpg2-x8hm/GHSA-fgcr-rpg2-x8hm.json b/advisories/unreviewed/2022/05/GHSA-fgcr-rpg2-x8hm/GHSA-fgcr-rpg2-x8hm.json index b56054f4962..2e8f600f238 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgcr-rpg2-x8hm/GHSA-fgcr-rpg2-x8hm.json +++ b/advisories/unreviewed/2022/05/GHSA-fgcr-rpg2-x8hm/GHSA-fgcr-rpg2-x8hm.json @@ -7,12 +7,8 @@ "CVE-2014-1599" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the SFR Box router with firmware NB6-MAIN-R3.3.4 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) dns, (2) dhcp, (3) nat, (4) route, or (5) lan in network/; or (6) wifi/config.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh3h-pv2j-78c4/GHSA-fh3h-pv2j-78c4.json b/advisories/unreviewed/2022/05/GHSA-fh3h-pv2j-78c4/GHSA-fh3h-pv2j-78c4.json index 0d9644d542b..af6761070e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh3h-pv2j-78c4/GHSA-fh3h-pv2j-78c4.json +++ b/advisories/unreviewed/2022/05/GHSA-fh3h-pv2j-78c4/GHSA-fh3h-pv2j-78c4.json @@ -7,12 +7,8 @@ "CVE-2014-2570" ], "details": "Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhff-fr9c-r455/GHSA-fhff-fr9c-r455.json b/advisories/unreviewed/2022/05/GHSA-fhff-fr9c-r455/GHSA-fhff-fr9c-r455.json index a9e9d2dbde3..d718c57f8ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhff-fr9c-r455/GHSA-fhff-fr9c-r455.json +++ b/advisories/unreviewed/2022/05/GHSA-fhff-fr9c-r455/GHSA-fhff-fr9c-r455.json @@ -7,12 +7,8 @@ "CVE-2014-4962" ], "details": "Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhfw-5p8c-4cxr/GHSA-fhfw-5p8c-4cxr.json b/advisories/unreviewed/2022/05/GHSA-fhfw-5p8c-4cxr/GHSA-fhfw-5p8c-4cxr.json index 513011e5462..27ccc650015 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhfw-5p8c-4cxr/GHSA-fhfw-5p8c-4cxr.json +++ b/advisories/unreviewed/2022/05/GHSA-fhfw-5p8c-4cxr/GHSA-fhfw-5p8c-4cxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjc2-x947-3pw2/GHSA-fjc2-x947-3pw2.json b/advisories/unreviewed/2022/05/GHSA-fjc2-x947-3pw2/GHSA-fjc2-x947-3pw2.json index b0708172b57..8e551256a91 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjc2-x947-3pw2/GHSA-fjc2-x947-3pw2.json +++ b/advisories/unreviewed/2022/05/GHSA-fjc2-x947-3pw2/GHSA-fjc2-x947-3pw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjq4-jc5h-hgrj/GHSA-fjq4-jc5h-hgrj.json b/advisories/unreviewed/2022/05/GHSA-fjq4-jc5h-hgrj/GHSA-fjq4-jc5h-hgrj.json index d7ec01230e0..114e5e9ae18 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjq4-jc5h-hgrj/GHSA-fjq4-jc5h-hgrj.json +++ b/advisories/unreviewed/2022/05/GHSA-fjq4-jc5h-hgrj/GHSA-fjq4-jc5h-hgrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjxm-8vv5-3pc6/GHSA-fjxm-8vv5-3pc6.json b/advisories/unreviewed/2022/05/GHSA-fjxm-8vv5-3pc6/GHSA-fjxm-8vv5-3pc6.json index 5e667d69844..c3bb65ca90d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjxm-8vv5-3pc6/GHSA-fjxm-8vv5-3pc6.json +++ b/advisories/unreviewed/2022/05/GHSA-fjxm-8vv5-3pc6/GHSA-fjxm-8vv5-3pc6.json @@ -7,12 +7,8 @@ "CVE-2015-2791" ], "details": "The \"menu sync\" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp83-g5px-h8vv/GHSA-fp83-g5px-h8vv.json b/advisories/unreviewed/2022/05/GHSA-fp83-g5px-h8vv/GHSA-fp83-g5px-h8vv.json index 3fb032ff833..c65bf6064d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp83-g5px-h8vv/GHSA-fp83-g5px-h8vv.json +++ b/advisories/unreviewed/2022/05/GHSA-fp83-g5px-h8vv/GHSA-fp83-g5px-h8vv.json @@ -7,12 +7,8 @@ "CVE-2014-2579" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are enabled, access the database backup functionality via the dbbackup_comp parameter in the generate action to index2.php. NOTE: vector 2 might be a duplicate of CVE-2014-2340, which is for the XCloner Wordpress plugin. NOTE: remote attackers can leverage CVE-2014-2996 with vector 2 to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpj4-cwfc-v2c6/GHSA-fpj4-cwfc-v2c6.json b/advisories/unreviewed/2022/05/GHSA-fpj4-cwfc-v2c6/GHSA-fpj4-cwfc-v2c6.json index eb16e748951..a391af2b04b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpj4-cwfc-v2c6/GHSA-fpj4-cwfc-v2c6.json +++ b/advisories/unreviewed/2022/05/GHSA-fpj4-cwfc-v2c6/GHSA-fpj4-cwfc-v2c6.json @@ -7,12 +7,8 @@ "CVE-2011-4672" ], "details": "Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _partner_list.php, (2) proioncategory_list.php, (3) _rantevou_list.php, (4) syncategory_list.php, (5) synallasomenos_list.php, (6) ypelaton_list.php, and (7) yproion_list.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq7v-76hh-w54m/GHSA-fq7v-76hh-w54m.json b/advisories/unreviewed/2022/05/GHSA-fq7v-76hh-w54m/GHSA-fq7v-76hh-w54m.json index d6618bab1c3..5c25efb337a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq7v-76hh-w54m/GHSA-fq7v-76hh-w54m.json +++ b/advisories/unreviewed/2022/05/GHSA-fq7v-76hh-w54m/GHSA-fq7v-76hh-w54m.json @@ -7,12 +7,8 @@ "CVE-2014-1612" ], "details": "Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq8h-f93c-3m89/GHSA-fq8h-f93c-3m89.json b/advisories/unreviewed/2022/05/GHSA-fq8h-f93c-3m89/GHSA-fq8h-f93c-3m89.json index 3fedf7ebb17..315847b7674 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq8h-f93c-3m89/GHSA-fq8h-f93c-3m89.json +++ b/advisories/unreviewed/2022/05/GHSA-fq8h-f93c-3m89/GHSA-fq8h-f93c-3m89.json @@ -7,12 +7,8 @@ "CVE-2014-8757" ], "details": "LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fr44-v39f-hp6h/GHSA-fr44-v39f-hp6h.json b/advisories/unreviewed/2022/05/GHSA-fr44-v39f-hp6h/GHSA-fr44-v39f-hp6h.json index 73acb6ce2d5..3cddb8aed54 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr44-v39f-hp6h/GHSA-fr44-v39f-hp6h.json +++ b/advisories/unreviewed/2022/05/GHSA-fr44-v39f-hp6h/GHSA-fr44-v39f-hp6h.json @@ -7,12 +7,8 @@ "CVE-2014-9387" ], "details": "SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv53-hf77-6xc2/GHSA-fv53-hf77-6xc2.json b/advisories/unreviewed/2022/05/GHSA-fv53-hf77-6xc2/GHSA-fv53-hf77-6xc2.json index 60920f40715..b8eea7b9f6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv53-hf77-6xc2/GHSA-fv53-hf77-6xc2.json +++ b/advisories/unreviewed/2022/05/GHSA-fv53-hf77-6xc2/GHSA-fv53-hf77-6xc2.json @@ -7,12 +7,8 @@ "CVE-2014-5172" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwfc-m344-9jp7/GHSA-fwfc-m344-9jp7.json b/advisories/unreviewed/2022/05/GHSA-fwfc-m344-9jp7/GHSA-fwfc-m344-9jp7.json index adee2885d00..fd884f1b5db 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwfc-m344-9jp7/GHSA-fwfc-m344-9jp7.json +++ b/advisories/unreviewed/2022/05/GHSA-fwfc-m344-9jp7/GHSA-fwfc-m344-9jp7.json @@ -7,12 +7,8 @@ "CVE-2014-2262" ], "details": "Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwx6-r2xv-qqxf/GHSA-fwx6-r2xv-qqxf.json b/advisories/unreviewed/2022/05/GHSA-fwx6-r2xv-qqxf/GHSA-fwx6-r2xv-qqxf.json index 29d55d7832d..1b3e3794888 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwx6-r2xv-qqxf/GHSA-fwx6-r2xv-qqxf.json +++ b/advisories/unreviewed/2022/05/GHSA-fwx6-r2xv-qqxf/GHSA-fwx6-r2xv-qqxf.json @@ -7,12 +7,8 @@ "CVE-2014-8395" ], "details": "Untrusted search path vulnerability in Corel Painter 2015 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wacommt.dll file that is located in the same folder as the file being processed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxvw-6w4h-3mx5/GHSA-fxvw-6w4h-3mx5.json b/advisories/unreviewed/2022/05/GHSA-fxvw-6w4h-3mx5/GHSA-fxvw-6w4h-3mx5.json index 56c13c80c7f..cebb3dd5014 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxvw-6w4h-3mx5/GHSA-fxvw-6w4h-3mx5.json +++ b/advisories/unreviewed/2022/05/GHSA-fxvw-6w4h-3mx5/GHSA-fxvw-6w4h-3mx5.json @@ -7,12 +7,8 @@ "CVE-2014-1492" ], "details": "The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2fg-782m-jxww/GHSA-g2fg-782m-jxww.json b/advisories/unreviewed/2022/05/GHSA-g2fg-782m-jxww/GHSA-g2fg-782m-jxww.json index 56e1677530b..cedb458d2a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2fg-782m-jxww/GHSA-g2fg-782m-jxww.json +++ b/advisories/unreviewed/2022/05/GHSA-g2fg-782m-jxww/GHSA-g2fg-782m-jxww.json @@ -7,12 +7,8 @@ "CVE-2014-5361" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serverServices.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g37p-pm6w-mgfg/GHSA-g37p-pm6w-mgfg.json b/advisories/unreviewed/2022/05/GHSA-g37p-pm6w-mgfg/GHSA-g37p-pm6w-mgfg.json index c4b2ff32372..95451835805 100644 --- a/advisories/unreviewed/2022/05/GHSA-g37p-pm6w-mgfg/GHSA-g37p-pm6w-mgfg.json +++ b/advisories/unreviewed/2022/05/GHSA-g37p-pm6w-mgfg/GHSA-g37p-pm6w-mgfg.json @@ -7,12 +7,8 @@ "CVE-2014-8312" ], "details": "Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information via a request to the RSDU_CCMS_GET_PROFILE_PARAM RFC function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g48x-w6wf-g8mh/GHSA-g48x-w6wf-g8mh.json b/advisories/unreviewed/2022/05/GHSA-g48x-w6wf-g8mh/GHSA-g48x-w6wf-g8mh.json index 7d7fd6571fc..2be8bedb0b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-g48x-w6wf-g8mh/GHSA-g48x-w6wf-g8mh.json +++ b/advisories/unreviewed/2022/05/GHSA-g48x-w6wf-g8mh/GHSA-g48x-w6wf-g8mh.json @@ -7,12 +7,8 @@ "CVE-2014-2531" ], "details": "SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) Resellers interface, as demonstrated by the \"or\" key in a pgn8state object in an i object in a JSON object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g532-jv38-f9x7/GHSA-g532-jv38-f9x7.json b/advisories/unreviewed/2022/05/GHSA-g532-jv38-f9x7/GHSA-g532-jv38-f9x7.json index 47545aa7f0c..ac47560330f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g532-jv38-f9x7/GHSA-g532-jv38-f9x7.json +++ b/advisories/unreviewed/2022/05/GHSA-g532-jv38-f9x7/GHSA-g532-jv38-f9x7.json @@ -7,12 +7,8 @@ "CVE-2014-2219" ], "details": "Cross-site scripting (XSS) vulnerability in whizzywig/wb.php in CMSimple Classic 3.54 and earlier, possibly as downloaded before February 26, 2014, allows remote attackers to inject arbitrary web script or HTML via the d parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5rr-93xh-mwfm/GHSA-g5rr-93xh-mwfm.json b/advisories/unreviewed/2022/05/GHSA-g5rr-93xh-mwfm/GHSA-g5rr-93xh-mwfm.json index 26bb9ee7d54..db53e1ae85d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5rr-93xh-mwfm/GHSA-g5rr-93xh-mwfm.json +++ b/advisories/unreviewed/2022/05/GHSA-g5rr-93xh-mwfm/GHSA-g5rr-93xh-mwfm.json @@ -7,12 +7,8 @@ "CVE-2014-4187" ], "details": "Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web script or HTML via the Username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7gm-5527-72qc/GHSA-g7gm-5527-72qc.json b/advisories/unreviewed/2022/05/GHSA-g7gm-5527-72qc/GHSA-g7gm-5527-72qc.json index b76b89f5401..f4203f2821f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7gm-5527-72qc/GHSA-g7gm-5527-72qc.json +++ b/advisories/unreviewed/2022/05/GHSA-g7gm-5527-72qc/GHSA-g7gm-5527-72qc.json @@ -7,12 +7,8 @@ "CVE-2014-3419" ], "details": "Infoblox NetMRI before 6.8.5 has a default password of admin for the \"root\" MySQL database account, which makes it easier for local users to obtain access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g85f-5xc2-36cg/GHSA-g85f-5xc2-36cg.json b/advisories/unreviewed/2022/05/GHSA-g85f-5xc2-36cg/GHSA-g85f-5xc2-36cg.json index b1100fdee72..b162ac9136f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g85f-5xc2-36cg/GHSA-g85f-5xc2-36cg.json +++ b/advisories/unreviewed/2022/05/GHSA-g85f-5xc2-36cg/GHSA-g85f-5xc2-36cg.json @@ -7,12 +7,8 @@ "CVE-2014-4047" ], "details": "Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g876-h78r-4r39/GHSA-g876-h78r-4r39.json b/advisories/unreviewed/2022/05/GHSA-g876-h78r-4r39/GHSA-g876-h78r-4r39.json index b53175f79c6..1d40a1954eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-g876-h78r-4r39/GHSA-g876-h78r-4r39.json +++ b/advisories/unreviewed/2022/05/GHSA-g876-h78r-4r39/GHSA-g876-h78r-4r39.json @@ -7,12 +7,8 @@ "CVE-2014-5122" ], "details": "Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8vh-4gxx-phq3/GHSA-g8vh-4gxx-phq3.json b/advisories/unreviewed/2022/05/GHSA-g8vh-4gxx-phq3/GHSA-g8vh-4gxx-phq3.json index 058de010852..a73e1123b0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8vh-4gxx-phq3/GHSA-g8vh-4gxx-phq3.json +++ b/advisories/unreviewed/2022/05/GHSA-g8vh-4gxx-phq3/GHSA-g8vh-4gxx-phq3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc3q-39r2-xhvv/GHSA-gc3q-39r2-xhvv.json b/advisories/unreviewed/2022/05/GHSA-gc3q-39r2-xhvv/GHSA-gc3q-39r2-xhvv.json index fa45ed2150e..6b38f7d3e1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc3q-39r2-xhvv/GHSA-gc3q-39r2-xhvv.json +++ b/advisories/unreviewed/2022/05/GHSA-gc3q-39r2-xhvv/GHSA-gc3q-39r2-xhvv.json @@ -7,12 +7,8 @@ "CVE-2014-8993" ], "details": "Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev40, 7.6.0 before 7.6.0-rev32, and 7.6.1 before 7.6.1-rev11 allows remote attackers to inject arbitrary web script or HTML via a crafted XHTML file with the application/xhtml+xml MIME type.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gc9v-4xv7-g396/GHSA-gc9v-4xv7-g396.json b/advisories/unreviewed/2022/05/GHSA-gc9v-4xv7-g396/GHSA-gc9v-4xv7-g396.json index 01a5b6b24d7..06315165f3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc9v-4xv7-g396/GHSA-gc9v-4xv7-g396.json +++ b/advisories/unreviewed/2022/05/GHSA-gc9v-4xv7-g396/GHSA-gc9v-4xv7-g396.json @@ -7,12 +7,8 @@ "CVE-2014-3100" ], "details": "Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on cryptographic operations, via a long key name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggwj-625q-9wgf/GHSA-ggwj-625q-9wgf.json b/advisories/unreviewed/2022/05/GHSA-ggwj-625q-9wgf/GHSA-ggwj-625q-9wgf.json index 82f638d4572..c8f83282a31 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggwj-625q-9wgf/GHSA-ggwj-625q-9wgf.json +++ b/advisories/unreviewed/2022/05/GHSA-ggwj-625q-9wgf/GHSA-ggwj-625q-9wgf.json @@ -7,12 +7,8 @@ "CVE-2014-0871" ], "details": "RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially sensitive Tomcat stack-trace information via non-printing characters in a cookie to the /classes/ URI, as demonstrated by the \\x00 character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqq4-jjc3-hg4c/GHSA-gqq4-jjc3-hg4c.json b/advisories/unreviewed/2022/05/GHSA-gqq4-jjc3-hg4c/GHSA-gqq4-jjc3-hg4c.json index 8568293f9b3..6149106a073 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqq4-jjc3-hg4c/GHSA-gqq4-jjc3-hg4c.json +++ b/advisories/unreviewed/2022/05/GHSA-gqq4-jjc3-hg4c/GHSA-gqq4-jjc3-hg4c.json @@ -7,12 +7,8 @@ "CVE-2014-0915" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via (1) the KPI display name field or (2) a portlet field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grh7-765f-g36w/GHSA-grh7-765f-g36w.json b/advisories/unreviewed/2022/05/GHSA-grh7-765f-g36w/GHSA-grh7-765f-g36w.json index 911edf87eb3..aef6b0b99cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-grh7-765f-g36w/GHSA-grh7-765f-g36w.json +++ b/advisories/unreviewed/2022/05/GHSA-grh7-765f-g36w/GHSA-grh7-765f-g36w.json @@ -7,12 +7,8 @@ "CVE-2014-2479" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gv8f-p965-5v38/GHSA-gv8f-p965-5v38.json b/advisories/unreviewed/2022/05/GHSA-gv8f-p965-5v38/GHSA-gv8f-p965-5v38.json index f11df8e7c60..414a3c2fd9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv8f-p965-5v38/GHSA-gv8f-p965-5v38.json +++ b/advisories/unreviewed/2022/05/GHSA-gv8f-p965-5v38/GHSA-gv8f-p965-5v38.json @@ -7,12 +7,8 @@ "CVE-2015-1251" ], "details": "Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem in Google Chrome before 43.0.2357.65 allows remote attackers to execute arbitrary code via a crafted document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvxh-9x93-wmf5/GHSA-gvxh-9x93-wmf5.json b/advisories/unreviewed/2022/05/GHSA-gvxh-9x93-wmf5/GHSA-gvxh-9x93-wmf5.json index f100884eba2..db7aa66a20e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvxh-9x93-wmf5/GHSA-gvxh-9x93-wmf5.json +++ b/advisories/unreviewed/2022/05/GHSA-gvxh-9x93-wmf5/GHSA-gvxh-9x93-wmf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw48-mf2p-74mv/GHSA-gw48-mf2p-74mv.json b/advisories/unreviewed/2022/05/GHSA-gw48-mf2p-74mv/GHSA-gw48-mf2p-74mv.json index 3137974c048..2e47a0568cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw48-mf2p-74mv/GHSA-gw48-mf2p-74mv.json +++ b/advisories/unreviewed/2022/05/GHSA-gw48-mf2p-74mv/GHSA-gw48-mf2p-74mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx4h-2w44-g9jc/GHSA-gx4h-2w44-g9jc.json b/advisories/unreviewed/2022/05/GHSA-gx4h-2w44-g9jc/GHSA-gx4h-2w44-g9jc.json index d82537cb42f..e7899db2da5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx4h-2w44-g9jc/GHSA-gx4h-2w44-g9jc.json +++ b/advisories/unreviewed/2022/05/GHSA-gx4h-2w44-g9jc/GHSA-gx4h-2w44-g9jc.json @@ -7,12 +7,8 @@ "CVE-2014-8487" ], "details": "Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) arbitrary messages via the messageId parameter to selfservice/managedevice/getMessageBody or (2) requests via the requestId parameter to selfservice/devicemgmt/getDeviceInfoTab.htm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxph-xvx9-2vrx/GHSA-gxph-xvx9-2vrx.json b/advisories/unreviewed/2022/05/GHSA-gxph-xvx9-2vrx/GHSA-gxph-xvx9-2vrx.json index bc4710a5366..5b3af8a2e10 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxph-xvx9-2vrx/GHSA-gxph-xvx9-2vrx.json +++ b/advisories/unreviewed/2022/05/GHSA-gxph-xvx9-2vrx/GHSA-gxph-xvx9-2vrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxvp-m937-jg9v/GHSA-gxvp-m937-jg9v.json b/advisories/unreviewed/2022/05/GHSA-gxvp-m937-jg9v/GHSA-gxvp-m937-jg9v.json index d766f082996..ca4ce80d574 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxvp-m937-jg9v/GHSA-gxvp-m937-jg9v.json +++ b/advisories/unreviewed/2022/05/GHSA-gxvp-m937-jg9v/GHSA-gxvp-m937-jg9v.json @@ -7,12 +7,8 @@ "CVE-2014-4330" ], "details": "The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h23x-694w-xf68/GHSA-h23x-694w-xf68.json b/advisories/unreviewed/2022/05/GHSA-h23x-694w-xf68/GHSA-h23x-694w-xf68.json index 72694099bc8..e6e62e6eca9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h23x-694w-xf68/GHSA-h23x-694w-xf68.json +++ b/advisories/unreviewed/2022/05/GHSA-h23x-694w-xf68/GHSA-h23x-694w-xf68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h25m-p8vh-j2r3/GHSA-h25m-p8vh-j2r3.json b/advisories/unreviewed/2022/05/GHSA-h25m-p8vh-j2r3/GHSA-h25m-p8vh-j2r3.json index ceb75dd2b88..4a4459ab7f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h25m-p8vh-j2r3/GHSA-h25m-p8vh-j2r3.json +++ b/advisories/unreviewed/2022/05/GHSA-h25m-p8vh-j2r3/GHSA-h25m-p8vh-j2r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2c7-f7r2-xmqp/GHSA-h2c7-f7r2-xmqp.json b/advisories/unreviewed/2022/05/GHSA-h2c7-f7r2-xmqp/GHSA-h2c7-f7r2-xmqp.json index 2341760b5b4..dea1a7333a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2c7-f7r2-xmqp/GHSA-h2c7-f7r2-xmqp.json +++ b/advisories/unreviewed/2022/05/GHSA-h2c7-f7r2-xmqp/GHSA-h2c7-f7r2-xmqp.json @@ -7,12 +7,8 @@ "CVE-2014-5035" ], "details": "The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an XML-RPC message, related to an XML External Entity (XXE) issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3cp-cm99-c88r/GHSA-h3cp-cm99-c88r.json b/advisories/unreviewed/2022/05/GHSA-h3cp-cm99-c88r/GHSA-h3cp-cm99-c88r.json index a81581f2e6f..20d0d1f917e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3cp-cm99-c88r/GHSA-h3cp-cm99-c88r.json +++ b/advisories/unreviewed/2022/05/GHSA-h3cp-cm99-c88r/GHSA-h3cp-cm99-c88r.json @@ -7,12 +7,8 @@ "CVE-2011-5180" ], "details": "Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information. NOTE: this has been disputed by a third party.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h43v-fh8q-w87r/GHSA-h43v-fh8q-w87r.json b/advisories/unreviewed/2022/05/GHSA-h43v-fh8q-w87r/GHSA-h43v-fh8q-w87r.json index 98476752c3e..f879f6f58b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h43v-fh8q-w87r/GHSA-h43v-fh8q-w87r.json +++ b/advisories/unreviewed/2022/05/GHSA-h43v-fh8q-w87r/GHSA-h43v-fh8q-w87r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4qw-p9q8-p7jg/GHSA-h4qw-p9q8-p7jg.json b/advisories/unreviewed/2022/05/GHSA-h4qw-p9q8-p7jg/GHSA-h4qw-p9q8-p7jg.json index 74dd1b70f25..a60b5857e61 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4qw-p9q8-p7jg/GHSA-h4qw-p9q8-p7jg.json +++ b/advisories/unreviewed/2022/05/GHSA-h4qw-p9q8-p7jg/GHSA-h4qw-p9q8-p7jg.json @@ -7,12 +7,8 @@ "CVE-2014-5307" ], "details": "Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h53c-7gvg-7vxm/GHSA-h53c-7gvg-7vxm.json b/advisories/unreviewed/2022/05/GHSA-h53c-7gvg-7vxm/GHSA-h53c-7gvg-7vxm.json index 06e79172d24..8839b4a91cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h53c-7gvg-7vxm/GHSA-h53c-7gvg-7vxm.json +++ b/advisories/unreviewed/2022/05/GHSA-h53c-7gvg-7vxm/GHSA-h53c-7gvg-7vxm.json @@ -7,12 +7,8 @@ "CVE-2011-2737" ], "details": "RSA enVision 3.x and 4.x before 4 SP4 P3 allows remote attackers to read arbitrary files via unspecified vectors, related to an \"arbitrary file retrieval vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h57m-vxj9-8gpv/GHSA-h57m-vxj9-8gpv.json b/advisories/unreviewed/2022/05/GHSA-h57m-vxj9-8gpv/GHSA-h57m-vxj9-8gpv.json index 42e84da9e52..467a2dd3bd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h57m-vxj9-8gpv/GHSA-h57m-vxj9-8gpv.json +++ b/advisories/unreviewed/2022/05/GHSA-h57m-vxj9-8gpv/GHSA-h57m-vxj9-8gpv.json @@ -7,12 +7,8 @@ "CVE-2011-4275" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted copy-and-paste action, (5) the auth_user parameter in a suggest_pwd action to UI.php, (6) the c[menu] parameter to UniversalSearch.php, (7) the description parameter in a SearchFormToAdd_document_list action to UI.php, (8) the category parameter in an errors action to audit.php, or (9) the suggest_pwd parameter to UI.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h675-g2pp-pw84/GHSA-h675-g2pp-pw84.json b/advisories/unreviewed/2022/05/GHSA-h675-g2pp-pw84/GHSA-h675-g2pp-pw84.json index f90c0871e5d..6cc2c39c6f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h675-g2pp-pw84/GHSA-h675-g2pp-pw84.json +++ b/advisories/unreviewed/2022/05/GHSA-h675-g2pp-pw84/GHSA-h675-g2pp-pw84.json @@ -7,12 +7,8 @@ "CVE-2014-4331" ], "details": "Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary web script or HTML via the src parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7f2-q3mc-89wm/GHSA-h7f2-q3mc-89wm.json b/advisories/unreviewed/2022/05/GHSA-h7f2-q3mc-89wm/GHSA-h7f2-q3mc-89wm.json index c6fe19138d7..2a5f8ae994d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7f2-q3mc-89wm/GHSA-h7f2-q3mc-89wm.json +++ b/advisories/unreviewed/2022/05/GHSA-h7f2-q3mc-89wm/GHSA-h7f2-q3mc-89wm.json @@ -7,12 +7,8 @@ "CVE-2014-5460" ], "details": "Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h855-j8m9-xmxj/GHSA-h855-j8m9-xmxj.json b/advisories/unreviewed/2022/05/GHSA-h855-j8m9-xmxj/GHSA-h855-j8m9-xmxj.json index 351dccb346f..9cae896583e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h855-j8m9-xmxj/GHSA-h855-j8m9-xmxj.json +++ b/advisories/unreviewed/2022/05/GHSA-h855-j8m9-xmxj/GHSA-h855-j8m9-xmxj.json @@ -7,12 +7,8 @@ "CVE-2014-5259" ], "details": "Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h96v-mqfm-37x5/GHSA-h96v-mqfm-37x5.json b/advisories/unreviewed/2022/05/GHSA-h96v-mqfm-37x5/GHSA-h96v-mqfm-37x5.json index 8f3c79c3eab..934d04342e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h96v-mqfm-37x5/GHSA-h96v-mqfm-37x5.json +++ b/advisories/unreviewed/2022/05/GHSA-h96v-mqfm-37x5/GHSA-h96v-mqfm-37x5.json @@ -7,12 +7,8 @@ "CVE-2011-2750" ], "details": "NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9rp-4c7r-h798/GHSA-h9rp-4c7r-h798.json b/advisories/unreviewed/2022/05/GHSA-h9rp-4c7r-h798/GHSA-h9rp-4c7r-h798.json index 7d52b887ea9..9798acaae2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9rp-4c7r-h798/GHSA-h9rp-4c7r-h798.json +++ b/advisories/unreviewed/2022/05/GHSA-h9rp-4c7r-h798/GHSA-h9rp-4c7r-h798.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf2f-4243-6465/GHSA-hf2f-4243-6465.json b/advisories/unreviewed/2022/05/GHSA-hf2f-4243-6465/GHSA-hf2f-4243-6465.json index 7c588b3f951..fce589abf38 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf2f-4243-6465/GHSA-hf2f-4243-6465.json +++ b/advisories/unreviewed/2022/05/GHSA-hf2f-4243-6465/GHSA-hf2f-4243-6465.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf9p-ph6h-r575/GHSA-hf9p-ph6h-r575.json b/advisories/unreviewed/2022/05/GHSA-hf9p-ph6h-r575/GHSA-hf9p-ph6h-r575.json index 932d1ec677f..fa9aed83045 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf9p-ph6h-r575/GHSA-hf9p-ph6h-r575.json +++ b/advisories/unreviewed/2022/05/GHSA-hf9p-ph6h-r575/GHSA-hf9p-ph6h-r575.json @@ -7,12 +7,8 @@ "CVE-2014-3737" ], "details": "Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.php, related to the currencyUrl function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg42-ggpx-469x/GHSA-hg42-ggpx-469x.json b/advisories/unreviewed/2022/05/GHSA-hg42-ggpx-469x/GHSA-hg42-ggpx-469x.json index f5f8a33eb9f..f02ead6cf36 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg42-ggpx-469x/GHSA-hg42-ggpx-469x.json +++ b/advisories/unreviewed/2022/05/GHSA-hg42-ggpx-469x/GHSA-hg42-ggpx-469x.json @@ -7,12 +7,8 @@ "CVE-2011-4712" ], "details": "Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg4q-qffw-jqg4/GHSA-hg4q-qffw-jqg4.json b/advisories/unreviewed/2022/05/GHSA-hg4q-qffw-jqg4/GHSA-hg4q-qffw-jqg4.json index 1647fb92bab..20fc6c22f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg4q-qffw-jqg4/GHSA-hg4q-qffw-jqg4.json +++ b/advisories/unreviewed/2022/05/GHSA-hg4q-qffw-jqg4/GHSA-hg4q-qffw-jqg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg7c-gq55-4mpw/GHSA-hg7c-gq55-4mpw.json b/advisories/unreviewed/2022/05/GHSA-hg7c-gq55-4mpw/GHSA-hg7c-gq55-4mpw.json index 6cf045a24ec..e57119fe93c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg7c-gq55-4mpw/GHSA-hg7c-gq55-4mpw.json +++ b/advisories/unreviewed/2022/05/GHSA-hg7c-gq55-4mpw/GHSA-hg7c-gq55-4mpw.json @@ -7,12 +7,8 @@ "CVE-2011-4624" ], "details": "Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj35-m38q-fv9m/GHSA-hj35-m38q-fv9m.json b/advisories/unreviewed/2022/05/GHSA-hj35-m38q-fv9m/GHSA-hj35-m38q-fv9m.json index 7d6b4726c67..3173413c856 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj35-m38q-fv9m/GHSA-hj35-m38q-fv9m.json +++ b/advisories/unreviewed/2022/05/GHSA-hj35-m38q-fv9m/GHSA-hj35-m38q-fv9m.json @@ -7,12 +7,8 @@ "CVE-2015-2076" ], "details": "The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj9j-3xxg-6259/GHSA-hj9j-3xxg-6259.json b/advisories/unreviewed/2022/05/GHSA-hj9j-3xxg-6259/GHSA-hj9j-3xxg-6259.json index 2d689da5ca9..806767b95ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj9j-3xxg-6259/GHSA-hj9j-3xxg-6259.json +++ b/advisories/unreviewed/2022/05/GHSA-hj9j-3xxg-6259/GHSA-hj9j-3xxg-6259.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjq2-3cgr-hwqf/GHSA-hjq2-3cgr-hwqf.json b/advisories/unreviewed/2022/05/GHSA-hjq2-3cgr-hwqf/GHSA-hjq2-3cgr-hwqf.json index de15dd0826a..d3a28d16c31 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjq2-3cgr-hwqf/GHSA-hjq2-3cgr-hwqf.json +++ b/advisories/unreviewed/2022/05/GHSA-hjq2-3cgr-hwqf/GHSA-hjq2-3cgr-hwqf.json @@ -7,12 +7,8 @@ "CVE-2014-2026" ], "details": "Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hm8j-79h4-q2c7/GHSA-hm8j-79h4-q2c7.json b/advisories/unreviewed/2022/05/GHSA-hm8j-79h4-q2c7/GHSA-hm8j-79h4-q2c7.json index 386953e8ac3..d91286aea13 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm8j-79h4-q2c7/GHSA-hm8j-79h4-q2c7.json +++ b/advisories/unreviewed/2022/05/GHSA-hm8j-79h4-q2c7/GHSA-hm8j-79h4-q2c7.json @@ -7,12 +7,8 @@ "CVE-2015-1365" ], "details": "Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp3g-5vj7-7hgc/GHSA-hp3g-5vj7-7hgc.json b/advisories/unreviewed/2022/05/GHSA-hp3g-5vj7-7hgc/GHSA-hp3g-5vj7-7hgc.json index d363f7e1932..beaac3cac03 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp3g-5vj7-7hgc/GHSA-hp3g-5vj7-7hgc.json +++ b/advisories/unreviewed/2022/05/GHSA-hp3g-5vj7-7hgc/GHSA-hp3g-5vj7-7hgc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpr3-hj82-rh9j/GHSA-hpr3-hj82-rh9j.json b/advisories/unreviewed/2022/05/GHSA-hpr3-hj82-rh9j/GHSA-hpr3-hj82-rh9j.json index 308ebff8937..7411d07b1e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpr3-hj82-rh9j/GHSA-hpr3-hj82-rh9j.json +++ b/advisories/unreviewed/2022/05/GHSA-hpr3-hj82-rh9j/GHSA-hpr3-hj82-rh9j.json @@ -7,12 +7,8 @@ "CVE-2015-0493" ], "details": "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0474.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrpm-3rq3-r229/GHSA-hrpm-3rq3-r229.json b/advisories/unreviewed/2022/05/GHSA-hrpm-3rq3-r229/GHSA-hrpm-3rq3-r229.json index e5da640d703..3e3ebca1959 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrpm-3rq3-r229/GHSA-hrpm-3rq3-r229.json +++ b/advisories/unreviewed/2022/05/GHSA-hrpm-3rq3-r229/GHSA-hrpm-3rq3-r229.json @@ -7,12 +7,8 @@ "CVE-2011-3358" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) os, (2) os_build, or (3) platform parameter to (a) bug_report_page.php or (b) bug_update_advanced_page.php, related to use of the Projax library.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvm5-xrxv-6g4q/GHSA-hvm5-xrxv-6g4q.json b/advisories/unreviewed/2022/05/GHSA-hvm5-xrxv-6g4q/GHSA-hvm5-xrxv-6g4q.json index bb4a0b796ad..bf4d7bf6da4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvm5-xrxv-6g4q/GHSA-hvm5-xrxv-6g4q.json +++ b/advisories/unreviewed/2022/05/GHSA-hvm5-xrxv-6g4q/GHSA-hvm5-xrxv-6g4q.json @@ -7,12 +7,8 @@ "CVE-2011-4958" ], "details": "Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j254-mg4h-rvf4/GHSA-j254-mg4h-rvf4.json b/advisories/unreviewed/2022/05/GHSA-j254-mg4h-rvf4/GHSA-j254-mg4h-rvf4.json index d9a09de5965..b53d1fd43eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j254-mg4h-rvf4/GHSA-j254-mg4h-rvf4.json +++ b/advisories/unreviewed/2022/05/GHSA-j254-mg4h-rvf4/GHSA-j254-mg4h-rvf4.json @@ -7,12 +7,8 @@ "CVE-2014-4624" ], "details": "EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2c9-qfcw-93gr/GHSA-j2c9-qfcw-93gr.json b/advisories/unreviewed/2022/05/GHSA-j2c9-qfcw-93gr/GHSA-j2c9-qfcw-93gr.json index fa164b4216a..7b9c5901f3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2c9-qfcw-93gr/GHSA-j2c9-qfcw-93gr.json +++ b/advisories/unreviewed/2022/05/GHSA-j2c9-qfcw-93gr/GHSA-j2c9-qfcw-93gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2qw-vv3p-xrvq/GHSA-j2qw-vv3p-xrvq.json b/advisories/unreviewed/2022/05/GHSA-j2qw-vv3p-xrvq/GHSA-j2qw-vv3p-xrvq.json index 187bd636f93..01af6b23671 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2qw-vv3p-xrvq/GHSA-j2qw-vv3p-xrvq.json +++ b/advisories/unreviewed/2022/05/GHSA-j2qw-vv3p-xrvq/GHSA-j2qw-vv3p-xrvq.json @@ -7,12 +7,8 @@ "CVE-2011-1126" ], "details": "VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j3v6-6jm3-55fp/GHSA-j3v6-6jm3-55fp.json b/advisories/unreviewed/2022/05/GHSA-j3v6-6jm3-55fp/GHSA-j3v6-6jm3-55fp.json index caf8aa5a059..50bd0d1ae4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3v6-6jm3-55fp/GHSA-j3v6-6jm3-55fp.json +++ b/advisories/unreviewed/2022/05/GHSA-j3v6-6jm3-55fp/GHSA-j3v6-6jm3-55fp.json @@ -7,12 +7,8 @@ "CVE-2014-9752" ], "details": "Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course, then accessing it via a direct request to the file in content/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j47q-mm35-5p3h/GHSA-j47q-mm35-5p3h.json b/advisories/unreviewed/2022/05/GHSA-j47q-mm35-5p3h/GHSA-j47q-mm35-5p3h.json index ec4abf406ae..01bab6e0b13 100644 --- a/advisories/unreviewed/2022/05/GHSA-j47q-mm35-5p3h/GHSA-j47q-mm35-5p3h.json +++ b/advisories/unreviewed/2022/05/GHSA-j47q-mm35-5p3h/GHSA-j47q-mm35-5p3h.json @@ -7,12 +7,8 @@ "CVE-2014-5335" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1) changing the administrator password via a crafted request to CMD0/mod_cmd.xml or (2) adding a new SIP user via a crafted request to PBX0/ADMIN/mod_cmd_login.xml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6mp-9cfw-7j4j/GHSA-j6mp-9cfw-7j4j.json b/advisories/unreviewed/2022/05/GHSA-j6mp-9cfw-7j4j/GHSA-j6mp-9cfw-7j4j.json index f6a27fb9df3..544e5c9e283 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6mp-9cfw-7j4j/GHSA-j6mp-9cfw-7j4j.json +++ b/advisories/unreviewed/2022/05/GHSA-j6mp-9cfw-7j4j/GHSA-j6mp-9cfw-7j4j.json @@ -7,12 +7,8 @@ "CVE-2014-1664" ], "details": "The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6x2-5mpm-9564/GHSA-j6x2-5mpm-9564.json b/advisories/unreviewed/2022/05/GHSA-j6x2-5mpm-9564/GHSA-j6x2-5mpm-9564.json index fed1be61662..8fe6658f3b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6x2-5mpm-9564/GHSA-j6x2-5mpm-9564.json +++ b/advisories/unreviewed/2022/05/GHSA-j6x2-5mpm-9564/GHSA-j6x2-5mpm-9564.json @@ -7,12 +7,8 @@ "CVE-2014-0210" ], "details": "Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7m4-jjrf-mjvw/GHSA-j7m4-jjrf-mjvw.json b/advisories/unreviewed/2022/05/GHSA-j7m4-jjrf-mjvw/GHSA-j7m4-jjrf-mjvw.json index 0e598888c83..050550934e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7m4-jjrf-mjvw/GHSA-j7m4-jjrf-mjvw.json +++ b/advisories/unreviewed/2022/05/GHSA-j7m4-jjrf-mjvw/GHSA-j7m4-jjrf-mjvw.json @@ -7,12 +7,8 @@ "CVE-2014-4226" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise FIN Install component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j832-g86m-353x/GHSA-j832-g86m-353x.json b/advisories/unreviewed/2022/05/GHSA-j832-g86m-353x/GHSA-j832-g86m-353x.json index 4f4ed24b30e..c8fbf5f4a12 100644 --- a/advisories/unreviewed/2022/05/GHSA-j832-g86m-353x/GHSA-j832-g86m-353x.json +++ b/advisories/unreviewed/2022/05/GHSA-j832-g86m-353x/GHSA-j832-g86m-353x.json @@ -7,12 +7,8 @@ "CVE-2014-0138" ], "details": "The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j92r-fc65-r2hf/GHSA-j92r-fc65-r2hf.json b/advisories/unreviewed/2022/05/GHSA-j92r-fc65-r2hf/GHSA-j92r-fc65-r2hf.json index 46ce62f002d..18cde0fc182 100644 --- a/advisories/unreviewed/2022/05/GHSA-j92r-fc65-r2hf/GHSA-j92r-fc65-r2hf.json +++ b/advisories/unreviewed/2022/05/GHSA-j92r-fc65-r2hf/GHSA-j92r-fc65-r2hf.json @@ -7,12 +7,8 @@ "CVE-2014-4207" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9c6-8ccv-jvv5/GHSA-j9c6-8ccv-jvv5.json b/advisories/unreviewed/2022/05/GHSA-j9c6-8ccv-jvv5/GHSA-j9c6-8ccv-jvv5.json index f90e7e8a902..2da95d60371 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9c6-8ccv-jvv5/GHSA-j9c6-8ccv-jvv5.json +++ b/advisories/unreviewed/2022/05/GHSA-j9c6-8ccv-jvv5/GHSA-j9c6-8ccv-jvv5.json @@ -7,12 +7,8 @@ "CVE-2014-2400" ], "details": "Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2399.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf44-xw2h-9pgq/GHSA-jf44-xw2h-9pgq.json b/advisories/unreviewed/2022/05/GHSA-jf44-xw2h-9pgq/GHSA-jf44-xw2h-9pgq.json index d13cfbee4a9..e31e3be4660 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf44-xw2h-9pgq/GHSA-jf44-xw2h-9pgq.json +++ b/advisories/unreviewed/2022/05/GHSA-jf44-xw2h-9pgq/GHSA-jf44-xw2h-9pgq.json @@ -7,12 +7,8 @@ "CVE-2014-4228" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jf8w-2pxr-j438/GHSA-jf8w-2pxr-j438.json b/advisories/unreviewed/2022/05/GHSA-jf8w-2pxr-j438/GHSA-jf8w-2pxr-j438.json index 2c927023a7f..8cb842a741d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf8w-2pxr-j438/GHSA-jf8w-2pxr-j438.json +++ b/advisories/unreviewed/2022/05/GHSA-jf8w-2pxr-j438/GHSA-jf8w-2pxr-j438.json @@ -7,12 +7,8 @@ "CVE-2014-9408" ], "details": "Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC address as part of the RC4 setup key, which makes it easier for remote attackers to guess the key via a brute-force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg2m-q6h3-v5jg/GHSA-jg2m-q6h3-v5jg.json b/advisories/unreviewed/2022/05/GHSA-jg2m-q6h3-v5jg/GHSA-jg2m-q6h3-v5jg.json index 82cd418f84e..0d962faf106 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg2m-q6h3-v5jg/GHSA-jg2m-q6h3-v5jg.json +++ b/advisories/unreviewed/2022/05/GHSA-jg2m-q6h3-v5jg/GHSA-jg2m-q6h3-v5jg.json @@ -7,12 +7,8 @@ "CVE-2014-0981" ], "details": "VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jghp-h678-hv65/GHSA-jghp-h678-hv65.json b/advisories/unreviewed/2022/05/GHSA-jghp-h678-hv65/GHSA-jghp-h678-hv65.json index 50d710cd255..34651b1eab1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jghp-h678-hv65/GHSA-jghp-h678-hv65.json +++ b/advisories/unreviewed/2022/05/GHSA-jghp-h678-hv65/GHSA-jghp-h678-hv65.json @@ -7,12 +7,8 @@ "CVE-2014-0864" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhj8-v83r-h3hm/GHSA-jhj8-v83r-h3hm.json b/advisories/unreviewed/2022/05/GHSA-jhj8-v83r-h3hm/GHSA-jhj8-v83r-h3hm.json index 2473d042605..9473591ff75 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhj8-v83r-h3hm/GHSA-jhj8-v83r-h3hm.json +++ b/advisories/unreviewed/2022/05/GHSA-jhj8-v83r-h3hm/GHSA-jhj8-v83r-h3hm.json @@ -7,12 +7,8 @@ "CVE-2014-4251" ], "details": "Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 and 12.1.2.0 allows remote authenticated users to affect integrity via vectors related to plugin 1.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj96-3999-rr48/GHSA-jj96-3999-rr48.json b/advisories/unreviewed/2022/05/GHSA-jj96-3999-rr48/GHSA-jj96-3999-rr48.json index d071f8ce964..20fd7b4e643 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj96-3999-rr48/GHSA-jj96-3999-rr48.json +++ b/advisories/unreviewed/2022/05/GHSA-jj96-3999-rr48/GHSA-jj96-3999-rr48.json @@ -7,12 +7,8 @@ "CVE-2014-3006" ], "details": "Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows remote attackers to change the manager account password and obtain sensitive information via a request to install/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm2m-m6gc-v7qv/GHSA-jm2m-m6gc-v7qv.json b/advisories/unreviewed/2022/05/GHSA-jm2m-m6gc-v7qv/GHSA-jm2m-m6gc-v7qv.json index b3ace3d89be..067bc29a1de 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm2m-m6gc-v7qv/GHSA-jm2m-m6gc-v7qv.json +++ b/advisories/unreviewed/2022/05/GHSA-jm2m-m6gc-v7qv/GHSA-jm2m-m6gc-v7qv.json @@ -7,12 +7,8 @@ "CVE-2011-4559" ], "details": "SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm9r-r7jq-fwxw/GHSA-jm9r-r7jq-fwxw.json b/advisories/unreviewed/2022/05/GHSA-jm9r-r7jq-fwxw/GHSA-jm9r-r7jq-fwxw.json index 660f64ee747..c9f7a53621a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm9r-r7jq-fwxw/GHSA-jm9r-r7jq-fwxw.json +++ b/advisories/unreviewed/2022/05/GHSA-jm9r-r7jq-fwxw/GHSA-jm9r-r7jq-fwxw.json @@ -7,12 +7,8 @@ "CVE-2014-8779" ], "details": "Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp9c-4gwx-v8x8/GHSA-jp9c-4gwx-v8x8.json b/advisories/unreviewed/2022/05/GHSA-jp9c-4gwx-v8x8/GHSA-jp9c-4gwx-v8x8.json index 66f3bbe4c1a..0209fd8f587 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp9c-4gwx-v8x8/GHSA-jp9c-4gwx-v8x8.json +++ b/advisories/unreviewed/2022/05/GHSA-jp9c-4gwx-v8x8/GHSA-jp9c-4gwx-v8x8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq3c-8xm9-29m7/GHSA-jq3c-8xm9-29m7.json b/advisories/unreviewed/2022/05/GHSA-jq3c-8xm9-29m7/GHSA-jq3c-8xm9-29m7.json index f69d1f0985d..73f59bfba59 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq3c-8xm9-29m7/GHSA-jq3c-8xm9-29m7.json +++ b/advisories/unreviewed/2022/05/GHSA-jq3c-8xm9-29m7/GHSA-jq3c-8xm9-29m7.json @@ -7,12 +7,8 @@ "CVE-2014-5376" ], "details": "Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0, when a pre-generated key is used, does not validate that the requesting user matches the actor in the message, which allows remote authenticated users to impersonate arbitrary users via the actor field in a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqj9-4qr2-cgv4/GHSA-jqj9-4qr2-cgv4.json b/advisories/unreviewed/2022/05/GHSA-jqj9-4qr2-cgv4/GHSA-jqj9-4qr2-cgv4.json index fe19f06f514..31f13a47650 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqj9-4qr2-cgv4/GHSA-jqj9-4qr2-cgv4.json +++ b/advisories/unreviewed/2022/05/GHSA-jqj9-4qr2-cgv4/GHSA-jqj9-4qr2-cgv4.json @@ -7,12 +7,8 @@ "CVE-2014-4241" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrf3-5554-9xcf/GHSA-jrf3-5554-9xcf.json b/advisories/unreviewed/2022/05/GHSA-jrf3-5554-9xcf/GHSA-jrf3-5554-9xcf.json index fabc4b74802..7b7d9cc77cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrf3-5554-9xcf/GHSA-jrf3-5554-9xcf.json +++ b/advisories/unreviewed/2022/05/GHSA-jrf3-5554-9xcf/GHSA-jrf3-5554-9xcf.json @@ -7,12 +7,8 @@ "CVE-2015-1032" ], "details": "Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrq7-3g58-rfqx/GHSA-jrq7-3g58-rfqx.json b/advisories/unreviewed/2022/05/GHSA-jrq7-3g58-rfqx/GHSA-jrq7-3g58-rfqx.json index 4a7dfe9686b..45dbdc648d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrq7-3g58-rfqx/GHSA-jrq7-3g58-rfqx.json +++ b/advisories/unreviewed/2022/05/GHSA-jrq7-3g58-rfqx/GHSA-jrq7-3g58-rfqx.json @@ -7,12 +7,8 @@ "CVE-2014-4225" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Patch installation scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw4h-2vhw-8fwh/GHSA-jw4h-2vhw-8fwh.json b/advisories/unreviewed/2022/05/GHSA-jw4h-2vhw-8fwh/GHSA-jw4h-2vhw-8fwh.json index b346d0b4c39..40621b80d46 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw4h-2vhw-8fwh/GHSA-jw4h-2vhw-8fwh.json +++ b/advisories/unreviewed/2022/05/GHSA-jw4h-2vhw-8fwh/GHSA-jw4h-2vhw-8fwh.json @@ -7,12 +7,8 @@ "CVE-2015-5441" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwc8-w94r-p4h4/GHSA-jwc8-w94r-p4h4.json b/advisories/unreviewed/2022/05/GHSA-jwc8-w94r-p4h4/GHSA-jwc8-w94r-p4h4.json index 74caf1ac65e..9c6038a63f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwc8-w94r-p4h4/GHSA-jwc8-w94r-p4h4.json +++ b/advisories/unreviewed/2022/05/GHSA-jwc8-w94r-p4h4/GHSA-jwc8-w94r-p4h4.json @@ -7,12 +7,8 @@ "CVE-2014-8793" ], "details": "Cross-site scripting (XSS) vulnerability in lib/max/Admin/UI/Field/PublisherIdField.php in Revive Adserver before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via the refresh_page parameter to www/admin/report-generate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2gc-ff6x-q3hw/GHSA-m2gc-ff6x-q3hw.json b/advisories/unreviewed/2022/05/GHSA-m2gc-ff6x-q3hw/GHSA-m2gc-ff6x-q3hw.json index 153b15692bd..c826937308d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2gc-ff6x-q3hw/GHSA-m2gc-ff6x-q3hw.json +++ b/advisories/unreviewed/2022/05/GHSA-m2gc-ff6x-q3hw/GHSA-m2gc-ff6x-q3hw.json @@ -7,12 +7,8 @@ "CVE-2014-3783" ], "details": "SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2v5-5h76-p8cv/GHSA-m2v5-5h76-p8cv.json b/advisories/unreviewed/2022/05/GHSA-m2v5-5h76-p8cv/GHSA-m2v5-5h76-p8cv.json index 07f103df005..7349a7e0a28 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2v5-5h76-p8cv/GHSA-m2v5-5h76-p8cv.json +++ b/advisories/unreviewed/2022/05/GHSA-m2v5-5h76-p8cv/GHSA-m2v5-5h76-p8cv.json @@ -7,12 +7,8 @@ "CVE-2014-8394" ], "details": "Multiple untrusted search path vulnerabilities in Corel CAD 2014 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) FxManagedCommands_3.08_9.tx or (2) TD_Mgd_3.08_9.dll file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2wv-xvc5-4rfq/GHSA-m2wv-xvc5-4rfq.json b/advisories/unreviewed/2022/05/GHSA-m2wv-xvc5-4rfq/GHSA-m2wv-xvc5-4rfq.json index 2de164833ea..d26465ecd17 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2wv-xvc5-4rfq/GHSA-m2wv-xvc5-4rfq.json +++ b/advisories/unreviewed/2022/05/GHSA-m2wv-xvc5-4rfq/GHSA-m2wv-xvc5-4rfq.json @@ -7,12 +7,8 @@ "CVE-2014-9331" ], "details": "Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m425-vhp9-h739/GHSA-m425-vhp9-h739.json b/advisories/unreviewed/2022/05/GHSA-m425-vhp9-h739/GHSA-m425-vhp9-h739.json index 249581cf334..11fe518e320 100644 --- a/advisories/unreviewed/2022/05/GHSA-m425-vhp9-h739/GHSA-m425-vhp9-h739.json +++ b/advisories/unreviewed/2022/05/GHSA-m425-vhp9-h739/GHSA-m425-vhp9-h739.json @@ -7,12 +7,8 @@ "CVE-2014-8875" ], "details": "The XML_RPC_cd function in lib/pear/XML/RPC.php in Revive Adserver before 3.0.6 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted XML-RPC request, aka an XML Entity Expansion (XEE) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m47c-vx53-g89g/GHSA-m47c-vx53-g89g.json b/advisories/unreviewed/2022/05/GHSA-m47c-vx53-g89g/GHSA-m47c-vx53-g89g.json index 24af9415102..83d0da25106 100644 --- a/advisories/unreviewed/2022/05/GHSA-m47c-vx53-g89g/GHSA-m47c-vx53-g89g.json +++ b/advisories/unreviewed/2022/05/GHSA-m47c-vx53-g89g/GHSA-m47c-vx53-g89g.json @@ -7,12 +7,8 @@ "CVE-2011-4802" ], "details": "Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4q9-95cr-335x/GHSA-m4q9-95cr-335x.json b/advisories/unreviewed/2022/05/GHSA-m4q9-95cr-335x/GHSA-m4q9-95cr-335x.json index d6ac002da5c..5a3d41e5a0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4q9-95cr-335x/GHSA-m4q9-95cr-335x.json +++ b/advisories/unreviewed/2022/05/GHSA-m4q9-95cr-335x/GHSA-m4q9-95cr-335x.json @@ -7,12 +7,8 @@ "CVE-2015-2217" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Ultimate PHP Board (aka myUPB) before 2.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or (2) avatar parameter to profile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m529-gcjc-wm6j/GHSA-m529-gcjc-wm6j.json b/advisories/unreviewed/2022/05/GHSA-m529-gcjc-wm6j/GHSA-m529-gcjc-wm6j.json index bc289646aa1..a4174dddd4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m529-gcjc-wm6j/GHSA-m529-gcjc-wm6j.json +++ b/advisories/unreviewed/2022/05/GHSA-m529-gcjc-wm6j/GHSA-m529-gcjc-wm6j.json @@ -7,12 +7,8 @@ "CVE-2014-7181" ], "details": "Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the maxbuttons-controller page to wp-admin/admin.php, related to the button creation page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5g3-vw48-vpcq/GHSA-m5g3-vw48-vpcq.json b/advisories/unreviewed/2022/05/GHSA-m5g3-vw48-vpcq/GHSA-m5g3-vw48-vpcq.json index be0645b3bee..7608f1c367b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5g3-vw48-vpcq/GHSA-m5g3-vw48-vpcq.json +++ b/advisories/unreviewed/2022/05/GHSA-m5g3-vw48-vpcq/GHSA-m5g3-vw48-vpcq.json @@ -7,12 +7,8 @@ "CVE-2015-1368" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to api/v1/schedules/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8c3-2mv9-fqpf/GHSA-m8c3-2mv9-fqpf.json b/advisories/unreviewed/2022/05/GHSA-m8c3-2mv9-fqpf/GHSA-m8c3-2mv9-fqpf.json index 54a034cfac1..33a54adaa1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8c3-2mv9-fqpf/GHSA-m8c3-2mv9-fqpf.json +++ b/advisories/unreviewed/2022/05/GHSA-m8c3-2mv9-fqpf/GHSA-m8c3-2mv9-fqpf.json @@ -7,12 +7,8 @@ "CVE-2014-8371" ], "details": "VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8rh-p4v3-9rr7/GHSA-m8rh-p4v3-9rr7.json b/advisories/unreviewed/2022/05/GHSA-m8rh-p4v3-9rr7/GHSA-m8rh-p4v3-9rr7.json index 7af848f7987..7a1787fc85c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8rh-p4v3-9rr7/GHSA-m8rh-p4v3-9rr7.json +++ b/advisories/unreviewed/2022/05/GHSA-m8rh-p4v3-9rr7/GHSA-m8rh-p4v3-9rr7.json @@ -7,12 +7,8 @@ "CVE-2014-8869" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin 1.x before 1.1.2 for Woltlab Burning Board 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) app_android_id or (2) app_kindle_url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8wr-h83w-q7hq/GHSA-m8wr-h83w-q7hq.json b/advisories/unreviewed/2022/05/GHSA-m8wr-h83w-q7hq/GHSA-m8wr-h83w-q7hq.json index 2987d649389..88647ac3f37 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8wr-h83w-q7hq/GHSA-m8wr-h83w-q7hq.json +++ b/advisories/unreviewed/2022/05/GHSA-m8wr-h83w-q7hq/GHSA-m8wr-h83w-q7hq.json @@ -7,12 +7,8 @@ "CVE-2014-4231" ], "details": "Unspecified vulnerability in the Siebel Travel & Transportation component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Diary.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9j9-976v-fcvv/GHSA-m9j9-976v-fcvv.json b/advisories/unreviewed/2022/05/GHSA-m9j9-976v-fcvv/GHSA-m9j9-976v-fcvv.json index 9513b843f3f..35aa04563e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9j9-976v-fcvv/GHSA-m9j9-976v-fcvv.json +++ b/advisories/unreviewed/2022/05/GHSA-m9j9-976v-fcvv/GHSA-m9j9-976v-fcvv.json @@ -7,12 +7,8 @@ "CVE-2013-6993" ], "details": "Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the key parameter in a delete action to wp-admin/tools.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9x3-pp92-vvhw/GHSA-m9x3-pp92-vvhw.json b/advisories/unreviewed/2022/05/GHSA-m9x3-pp92-vvhw/GHSA-m9x3-pp92-vvhw.json index 094d7489b92..204d014ca13 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9x3-pp92-vvhw/GHSA-m9x3-pp92-vvhw.json +++ b/advisories/unreviewed/2022/05/GHSA-m9x3-pp92-vvhw/GHSA-m9x3-pp92-vvhw.json @@ -7,12 +7,8 @@ "CVE-2014-1855" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel before 3.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) capcheck parameter to directories.php or (2) keyword parameter to proxy.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mchx-p635-vpq8/GHSA-mchx-p635-vpq8.json b/advisories/unreviewed/2022/05/GHSA-mchx-p635-vpq8/GHSA-mchx-p635-vpq8.json index 15e6a0dfa0d..1d9c9ddc8d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mchx-p635-vpq8/GHSA-mchx-p635-vpq8.json +++ b/advisories/unreviewed/2022/05/GHSA-mchx-p635-vpq8/GHSA-mchx-p635-vpq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf4g-3m2w-qf36/GHSA-mf4g-3m2w-qf36.json b/advisories/unreviewed/2022/05/GHSA-mf4g-3m2w-qf36/GHSA-mf4g-3m2w-qf36.json index 770d47e0429..bf15edcfd73 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf4g-3m2w-qf36/GHSA-mf4g-3m2w-qf36.json +++ b/advisories/unreviewed/2022/05/GHSA-mf4g-3m2w-qf36/GHSA-mf4g-3m2w-qf36.json @@ -7,12 +7,8 @@ "CVE-2014-2492" ], "details": "Unspecified vulnerability in the Oracle Agile Product Collaboration component in Oracle Supply Chain Products Suite 9.3.3 allows remote attackers to affect integrity via unknown vectors related to Web client (PC).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf78-mcx4-9ph4/GHSA-mf78-mcx4-9ph4.json b/advisories/unreviewed/2022/05/GHSA-mf78-mcx4-9ph4/GHSA-mf78-mcx4-9ph4.json index 0d9243ad2f0..86f0d442c20 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf78-mcx4-9ph4/GHSA-mf78-mcx4-9ph4.json +++ b/advisories/unreviewed/2022/05/GHSA-mf78-mcx4-9ph4/GHSA-mf78-mcx4-9ph4.json @@ -7,12 +7,8 @@ "CVE-2011-5179" ], "details": "Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfx5-qvrm-pvvm/GHSA-mfx5-qvrm-pvvm.json b/advisories/unreviewed/2022/05/GHSA-mfx5-qvrm-pvvm/GHSA-mfx5-qvrm-pvvm.json index aaf76b57013..dd1c3b5ab6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfx5-qvrm-pvvm/GHSA-mfx5-qvrm-pvvm.json +++ b/advisories/unreviewed/2022/05/GHSA-mfx5-qvrm-pvvm/GHSA-mfx5-qvrm-pvvm.json @@ -7,12 +7,8 @@ "CVE-2014-4248" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows local users to affect confidentiality via unknown vectors related to Logging.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mg37-xw7q-j63c/GHSA-mg37-xw7q-j63c.json b/advisories/unreviewed/2022/05/GHSA-mg37-xw7q-j63c/GHSA-mg37-xw7q-j63c.json index 22a5dbcbab7..0b3af3cc9da 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg37-xw7q-j63c/GHSA-mg37-xw7q-j63c.json +++ b/advisories/unreviewed/2022/05/GHSA-mg37-xw7q-j63c/GHSA-mg37-xw7q-j63c.json @@ -7,12 +7,8 @@ "CVE-2014-2340" ], "details": "Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgw6-5qjc-mx7w/GHSA-mgw6-5qjc-mx7w.json b/advisories/unreviewed/2022/05/GHSA-mgw6-5qjc-mx7w/GHSA-mgw6-5qjc-mx7w.json index ebfedc7a914..64afda5c2be 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgw6-5qjc-mx7w/GHSA-mgw6-5qjc-mx7w.json +++ b/advisories/unreviewed/2022/05/GHSA-mgw6-5qjc-mx7w/GHSA-mgw6-5qjc-mx7w.json @@ -7,12 +7,8 @@ "CVE-2014-8316" ], "details": "XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrary files via the xmlParameter parameter in an explorationSpaceUpdate request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mh2j-9c96-v8jf/GHSA-mh2j-9c96-v8jf.json b/advisories/unreviewed/2022/05/GHSA-mh2j-9c96-v8jf/GHSA-mh2j-9c96-v8jf.json index 4b124fb0343..3ab59e98204 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh2j-9c96-v8jf/GHSA-mh2j-9c96-v8jf.json +++ b/advisories/unreviewed/2022/05/GHSA-mh2j-9c96-v8jf/GHSA-mh2j-9c96-v8jf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh9m-r9g2-chhf/GHSA-mh9m-r9g2-chhf.json b/advisories/unreviewed/2022/05/GHSA-mh9m-r9g2-chhf/GHSA-mh9m-r9g2-chhf.json index 64c05f54ddf..67d705c004c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh9m-r9g2-chhf/GHSA-mh9m-r9g2-chhf.json +++ b/advisories/unreviewed/2022/05/GHSA-mh9m-r9g2-chhf/GHSA-mh9m-r9g2-chhf.json @@ -7,12 +7,8 @@ "CVE-2015-1175" ], "details": "Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in the blocklayered module in PrestaShop 1.6.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the layered_price_slider parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhxp-j75h-h86w/GHSA-mhxp-j75h-h86w.json b/advisories/unreviewed/2022/05/GHSA-mhxp-j75h-h86w/GHSA-mhxp-j75h-h86w.json index 9d114d2502a..74fce2366ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhxp-j75h-h86w/GHSA-mhxp-j75h-h86w.json +++ b/advisories/unreviewed/2022/05/GHSA-mhxp-j75h-h86w/GHSA-mhxp-j75h-h86w.json @@ -7,12 +7,8 @@ "CVE-2014-3450" ], "details": "Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhxv-5q9h-hp9c/GHSA-mhxv-5q9h-hp9c.json b/advisories/unreviewed/2022/05/GHSA-mhxv-5q9h-hp9c/GHSA-mhxv-5q9h-hp9c.json index 71275c120ba..6b3f925b114 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhxv-5q9h-hp9c/GHSA-mhxv-5q9h-hp9c.json +++ b/advisories/unreviewed/2022/05/GHSA-mhxv-5q9h-hp9c/GHSA-mhxv-5q9h-hp9c.json @@ -7,12 +7,8 @@ "CVE-2014-2477" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2486.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mj2h-f2r8-7855/GHSA-mj2h-f2r8-7855.json b/advisories/unreviewed/2022/05/GHSA-mj2h-f2r8-7855/GHSA-mj2h-f2r8-7855.json index 724716adebd..084265f687b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj2h-f2r8-7855/GHSA-mj2h-f2r8-7855.json +++ b/advisories/unreviewed/2022/05/GHSA-mj2h-f2r8-7855/GHSA-mj2h-f2r8-7855.json @@ -7,12 +7,8 @@ "CVE-2014-5377" ], "details": "ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mj46-j682-p569/GHSA-mj46-j682-p569.json b/advisories/unreviewed/2022/05/GHSA-mj46-j682-p569/GHSA-mj46-j682-p569.json index c4cdfc08f7c..32685678d81 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj46-j682-p569/GHSA-mj46-j682-p569.json +++ b/advisories/unreviewed/2022/05/GHSA-mj46-j682-p569/GHSA-mj46-j682-p569.json @@ -7,12 +7,8 @@ "CVE-2014-2996" ], "details": "XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have the privileges to execute code. NOTE: this can be leveraged by remote attackers using CVE-2014-2579.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm2c-whrj-39qm/GHSA-mm2c-whrj-39qm.json b/advisories/unreviewed/2022/05/GHSA-mm2c-whrj-39qm/GHSA-mm2c-whrj-39qm.json index 2201605cea5..08760bd1e5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm2c-whrj-39qm/GHSA-mm2c-whrj-39qm.json +++ b/advisories/unreviewed/2022/05/GHSA-mm2c-whrj-39qm/GHSA-mm2c-whrj-39qm.json @@ -7,12 +7,8 @@ "CVE-2014-3629" ], "details": "XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmvc-933r-7cp3/GHSA-mmvc-933r-7cp3.json b/advisories/unreviewed/2022/05/GHSA-mmvc-933r-7cp3/GHSA-mmvc-933r-7cp3.json index 83f4509b79a..9bf4f404440 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmvc-933r-7cp3/GHSA-mmvc-933r-7cp3.json +++ b/advisories/unreviewed/2022/05/GHSA-mmvc-933r-7cp3/GHSA-mmvc-933r-7cp3.json @@ -7,12 +7,8 @@ "CVE-2011-4926" ], "details": "Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmx6-xv2h-w7x8/GHSA-mmx6-xv2h-w7x8.json b/advisories/unreviewed/2022/05/GHSA-mmx6-xv2h-w7x8/GHSA-mmx6-xv2h-w7x8.json index 94bd943a43b..1d284c385f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmx6-xv2h-w7x8/GHSA-mmx6-xv2h-w7x8.json +++ b/advisories/unreviewed/2022/05/GHSA-mmx6-xv2h-w7x8/GHSA-mmx6-xv2h-w7x8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp2c-hhj2-7xjx/GHSA-mp2c-hhj2-7xjx.json b/advisories/unreviewed/2022/05/GHSA-mp2c-hhj2-7xjx/GHSA-mp2c-hhj2-7xjx.json index 77d78fb71c2..60180ea22e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp2c-hhj2-7xjx/GHSA-mp2c-hhj2-7xjx.json +++ b/advisories/unreviewed/2022/05/GHSA-mp2c-hhj2-7xjx/GHSA-mp2c-hhj2-7xjx.json @@ -7,12 +7,8 @@ "CVE-2014-0372" ], "details": "Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to DM Others.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mphq-fg36-pppm/GHSA-mphq-fg36-pppm.json b/advisories/unreviewed/2022/05/GHSA-mphq-fg36-pppm/GHSA-mphq-fg36-pppm.json index 0943adcf0a7..f5e35c7d4f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mphq-fg36-pppm/GHSA-mphq-fg36-pppm.json +++ b/advisories/unreviewed/2022/05/GHSA-mphq-fg36-pppm/GHSA-mphq-fg36-pppm.json @@ -7,12 +7,8 @@ "CVE-2013-5606" ], "details": "The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mr4g-v4xh-m67m/GHSA-mr4g-v4xh-m67m.json b/advisories/unreviewed/2022/05/GHSA-mr4g-v4xh-m67m/GHSA-mr4g-v4xh-m67m.json index 8e8e9dd3131..2056df2235d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr4g-v4xh-m67m/GHSA-mr4g-v4xh-m67m.json +++ b/advisories/unreviewed/2022/05/GHSA-mr4g-v4xh-m67m/GHSA-mr4g-v4xh-m67m.json @@ -7,12 +7,8 @@ "CVE-2014-2512" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr5j-h8xf-5m2m/GHSA-mr5j-h8xf-5m2m.json b/advisories/unreviewed/2022/05/GHSA-mr5j-h8xf-5m2m/GHSA-mr5j-h8xf-5m2m.json index 1e751009ffa..b7e0f7bf43c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr5j-h8xf-5m2m/GHSA-mr5j-h8xf-5m2m.json +++ b/advisories/unreviewed/2022/05/GHSA-mr5j-h8xf-5m2m/GHSA-mr5j-h8xf-5m2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr8c-273h-jpmh/GHSA-mr8c-273h-jpmh.json b/advisories/unreviewed/2022/05/GHSA-mr8c-273h-jpmh/GHSA-mr8c-273h-jpmh.json index 578d0e50394..242f0656b16 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr8c-273h-jpmh/GHSA-mr8c-273h-jpmh.json +++ b/advisories/unreviewed/2022/05/GHSA-mr8c-273h-jpmh/GHSA-mr8c-273h-jpmh.json @@ -7,12 +7,8 @@ "CVE-2011-4918" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote attackers to inject arbitrary web script or HTML via the (1) task parameter to elxis/index.php, and (2) PATH_INFO to elxis/administrator/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrg2-8f7m-jw7f/GHSA-mrg2-8f7m-jw7f.json b/advisories/unreviewed/2022/05/GHSA-mrg2-8f7m-jw7f/GHSA-mrg2-8f7m-jw7f.json index 2cc7e373209..7f3bd1f9cfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrg2-8f7m-jw7f/GHSA-mrg2-8f7m-jw7f.json +++ b/advisories/unreviewed/2022/05/GHSA-mrg2-8f7m-jw7f/GHSA-mrg2-8f7m-jw7f.json @@ -7,12 +7,8 @@ "CVE-2014-9021" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web script or HTML via the (1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr69cAcsPwd, (4) tr69cConnReqPwd, or (5) tr69cDebugEnable parameter to the TR-069 client page (tr69cfg.cgi); the (6) timezone parameter to the Time and date page (sntpcfg.sntp); or the (7) hostname parameter in a save action to the Quick Stats page (psilan.cgi). NOTE: this issue was SPLIT from CVE-2014-9020 per ADT1 due to different affected products and codebases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv2h-6cx9-44g2/GHSA-mv2h-6cx9-44g2.json b/advisories/unreviewed/2022/05/GHSA-mv2h-6cx9-44g2/GHSA-mv2h-6cx9-44g2.json index 66a6996e4f2..84759303abc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv2h-6cx9-44g2/GHSA-mv2h-6cx9-44g2.json +++ b/advisories/unreviewed/2022/05/GHSA-mv2h-6cx9-44g2/GHSA-mv2h-6cx9-44g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv5f-9r7g-hr97/GHSA-mv5f-9r7g-hr97.json b/advisories/unreviewed/2022/05/GHSA-mv5f-9r7g-hr97/GHSA-mv5f-9r7g-hr97.json index 50c8d354901..1a3b6733328 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv5f-9r7g-hr97/GHSA-mv5f-9r7g-hr97.json +++ b/advisories/unreviewed/2022/05/GHSA-mv5f-9r7g-hr97/GHSA-mv5f-9r7g-hr97.json @@ -7,12 +7,8 @@ "CVE-2015-1481" ], "details": "Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mv6w-p8g3-qr3x/GHSA-mv6w-p8g3-qr3x.json b/advisories/unreviewed/2022/05/GHSA-mv6w-p8g3-qr3x/GHSA-mv6w-p8g3-qr3x.json index 0d247e460db..bf34df27563 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv6w-p8g3-qr3x/GHSA-mv6w-p8g3-qr3x.json +++ b/advisories/unreviewed/2022/05/GHSA-mv6w-p8g3-qr3x/GHSA-mv6w-p8g3-qr3x.json @@ -7,12 +7,8 @@ "CVE-2014-1206" ], "details": "SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the owa_email_address parameter in a base.passwordResetRequest action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p379-f2cq-ghhm/GHSA-p379-f2cq-ghhm.json b/advisories/unreviewed/2022/05/GHSA-p379-f2cq-ghhm/GHSA-p379-f2cq-ghhm.json index 33f1ebf663b..c2ce08c0cf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p379-f2cq-ghhm/GHSA-p379-f2cq-ghhm.json +++ b/advisories/unreviewed/2022/05/GHSA-p379-f2cq-ghhm/GHSA-p379-f2cq-ghhm.json @@ -7,12 +7,8 @@ "CVE-2014-7183" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query parameter or (2) QUERY_STRING.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3m3-mm8m-9fq2/GHSA-p3m3-mm8m-9fq2.json b/advisories/unreviewed/2022/05/GHSA-p3m3-mm8m-9fq2/GHSA-p3m3-mm8m-9fq2.json index 8c1679d3cd0..10c750bf906 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3m3-mm8m-9fq2/GHSA-p3m3-mm8m-9fq2.json +++ b/advisories/unreviewed/2022/05/GHSA-p3m3-mm8m-9fq2/GHSA-p3m3-mm8m-9fq2.json @@ -7,12 +7,8 @@ "CVE-2014-1944" ], "details": "Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p437-qg7q-wh7p/GHSA-p437-qg7q-wh7p.json b/advisories/unreviewed/2022/05/GHSA-p437-qg7q-wh7p/GHSA-p437-qg7q-wh7p.json index 0992518fab0..a4f9bab2083 100644 --- a/advisories/unreviewed/2022/05/GHSA-p437-qg7q-wh7p/GHSA-p437-qg7q-wh7p.json +++ b/advisories/unreviewed/2022/05/GHSA-p437-qg7q-wh7p/GHSA-p437-qg7q-wh7p.json @@ -7,12 +7,8 @@ "CVE-2014-9129" ], "details": "Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p476-69jg-2436/GHSA-p476-69jg-2436.json b/advisories/unreviewed/2022/05/GHSA-p476-69jg-2436/GHSA-p476-69jg-2436.json index f90e65819d5..21aaee20c4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p476-69jg-2436/GHSA-p476-69jg-2436.json +++ b/advisories/unreviewed/2022/05/GHSA-p476-69jg-2436/GHSA-p476-69jg-2436.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4c4-gfr7-cmgr/GHSA-p4c4-gfr7-cmgr.json b/advisories/unreviewed/2022/05/GHSA-p4c4-gfr7-cmgr/GHSA-p4c4-gfr7-cmgr.json index ad2e21bf0f5..02c870b0134 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4c4-gfr7-cmgr/GHSA-p4c4-gfr7-cmgr.json +++ b/advisories/unreviewed/2022/05/GHSA-p4c4-gfr7-cmgr/GHSA-p4c4-gfr7-cmgr.json @@ -7,12 +7,8 @@ "CVE-2014-9142" ], "details": "Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4cx-p88v-xqv9/GHSA-p4cx-p88v-xqv9.json b/advisories/unreviewed/2022/05/GHSA-p4cx-p88v-xqv9/GHSA-p4cx-p88v-xqv9.json index 3542661b168..642f343998e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4cx-p88v-xqv9/GHSA-p4cx-p88v-xqv9.json +++ b/advisories/unreviewed/2022/05/GHSA-p4cx-p88v-xqv9/GHSA-p4cx-p88v-xqv9.json @@ -7,12 +7,8 @@ "CVE-2014-0983" ], "details": "Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5pv-c45m-p722/GHSA-p5pv-c45m-p722.json b/advisories/unreviewed/2022/05/GHSA-p5pv-c45m-p722/GHSA-p5pv-c45m-p722.json index e7cd3b1f2b9..8cddc4f90b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5pv-c45m-p722/GHSA-p5pv-c45m-p722.json +++ b/advisories/unreviewed/2022/05/GHSA-p5pv-c45m-p722/GHSA-p5pv-c45m-p722.json @@ -7,12 +7,8 @@ "CVE-2014-1854" ], "details": "SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p672-97f8-chmq/GHSA-p672-97f8-chmq.json b/advisories/unreviewed/2022/05/GHSA-p672-97f8-chmq/GHSA-p672-97f8-chmq.json index db753873e2c..561c3cdca47 100644 --- a/advisories/unreviewed/2022/05/GHSA-p672-97f8-chmq/GHSA-p672-97f8-chmq.json +++ b/advisories/unreviewed/2022/05/GHSA-p672-97f8-chmq/GHSA-p672-97f8-chmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6vh-m29c-65m2/GHSA-p6vh-m29c-65m2.json b/advisories/unreviewed/2022/05/GHSA-p6vh-m29c-65m2/GHSA-p6vh-m29c-65m2.json index dcfb0166efc..968cc02b43d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6vh-m29c-65m2/GHSA-p6vh-m29c-65m2.json +++ b/advisories/unreviewed/2022/05/GHSA-p6vh-m29c-65m2/GHSA-p6vh-m29c-65m2.json @@ -7,12 +7,8 @@ "CVE-2014-4237" ], "details": "Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.2.0.4 and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p74p-3c84-fg2v/GHSA-p74p-3c84-fg2v.json b/advisories/unreviewed/2022/05/GHSA-p74p-3c84-fg2v/GHSA-p74p-3c84-fg2v.json index c1a84d33e5c..8b3f7e2180e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p74p-3c84-fg2v/GHSA-p74p-3c84-fg2v.json +++ b/advisories/unreviewed/2022/05/GHSA-p74p-3c84-fg2v/GHSA-p74p-3c84-fg2v.json @@ -7,12 +7,8 @@ "CVE-2014-4232" ], "details": "Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-2463.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p784-84p4-47fp/GHSA-p784-84p4-47fp.json b/advisories/unreviewed/2022/05/GHSA-p784-84p4-47fp/GHSA-p784-84p4-47fp.json index 441586269dd..6633c48111c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p784-84p4-47fp/GHSA-p784-84p4-47fp.json +++ b/advisories/unreviewed/2022/05/GHSA-p784-84p4-47fp/GHSA-p784-84p4-47fp.json @@ -7,12 +7,8 @@ "CVE-2014-4980" ], "details": "The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8c7-34p7-r42c/GHSA-p8c7-34p7-r42c.json b/advisories/unreviewed/2022/05/GHSA-p8c7-34p7-r42c/GHSA-p8c7-34p7-r42c.json index 00d281a55b7..d9ef0d124f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8c7-34p7-r42c/GHSA-p8c7-34p7-r42c.json +++ b/advisories/unreviewed/2022/05/GHSA-p8c7-34p7-r42c/GHSA-p8c7-34p7-r42c.json @@ -7,12 +7,8 @@ "CVE-2014-1222" ], "details": "Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter in a download action. NOTE: it is likely that this issue is actually in the KCFinder third-party component, and it affects additional products besides Vtiger CRM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8wm-pg92-j5jw/GHSA-p8wm-pg92-j5jw.json b/advisories/unreviewed/2022/05/GHSA-p8wm-pg92-j5jw/GHSA-p8wm-pg92-j5jw.json index 2f87809e124..9f3ebf82028 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8wm-pg92-j5jw/GHSA-p8wm-pg92-j5jw.json +++ b/advisories/unreviewed/2022/05/GHSA-p8wm-pg92-j5jw/GHSA-p8wm-pg92-j5jw.json @@ -7,12 +7,8 @@ "CVE-2014-9019" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin user name or (2) conduct cross-site scripting (XSS) attacks via the sysUserName parameter in a save action to adminpasswd.cgi or (3) change the admin user password via the sysPassword parameter in a save action to adminpasswd.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p937-9x7h-c2gp/GHSA-p937-9x7h-c2gp.json b/advisories/unreviewed/2022/05/GHSA-p937-9x7h-c2gp/GHSA-p937-9x7h-c2gp.json index 304c9f9ac79..4aa4dd762ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-p937-9x7h-c2gp/GHSA-p937-9x7h-c2gp.json +++ b/advisories/unreviewed/2022/05/GHSA-p937-9x7h-c2gp/GHSA-p937-9x7h-c2gp.json @@ -7,12 +7,8 @@ "CVE-2014-8877" ], "details": "The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9mr-2cw8-4xhj/GHSA-p9mr-2cw8-4xhj.json b/advisories/unreviewed/2022/05/GHSA-p9mr-2cw8-4xhj/GHSA-p9mr-2cw8-4xhj.json index b753ca7b664..951a83d775e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9mr-2cw8-4xhj/GHSA-p9mr-2cw8-4xhj.json +++ b/advisories/unreviewed/2022/05/GHSA-p9mr-2cw8-4xhj/GHSA-p9mr-2cw8-4xhj.json @@ -7,12 +7,8 @@ "CVE-2014-4045" ], "details": "The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_expiry is set to zero, allows remote attackers to cause a denial of service (assertion failure and crash) via an unsubscribe request when not subscribed to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc28-mpvf-j77x/GHSA-pc28-mpvf-j77x.json b/advisories/unreviewed/2022/05/GHSA-pc28-mpvf-j77x/GHSA-pc28-mpvf-j77x.json index 0a704f2425e..374e9f8150f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc28-mpvf-j77x/GHSA-pc28-mpvf-j77x.json +++ b/advisories/unreviewed/2022/05/GHSA-pc28-mpvf-j77x/GHSA-pc28-mpvf-j77x.json @@ -7,12 +7,8 @@ "CVE-2014-9707" ], "details": "EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pg2f-rw74-23rg/GHSA-pg2f-rw74-23rg.json b/advisories/unreviewed/2022/05/GHSA-pg2f-rw74-23rg/GHSA-pg2f-rw74-23rg.json index ca0bc71cf45..0953af73890 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg2f-rw74-23rg/GHSA-pg2f-rw74-23rg.json +++ b/advisories/unreviewed/2022/05/GHSA-pg2f-rw74-23rg/GHSA-pg2f-rw74-23rg.json @@ -7,12 +7,8 @@ "CVE-2014-8539" ], "details": "Cross-site scripting (XSS) vulnerability in Simple Email Form 1.8.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the mod_simpleemailform_field2_1 parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg6c-938r-g548/GHSA-pg6c-938r-g548.json b/advisories/unreviewed/2022/05/GHSA-pg6c-938r-g548/GHSA-pg6c-938r-g548.json index 7a5cf55c213..d4c4e9a6581 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg6c-938r-g548/GHSA-pg6c-938r-g548.json +++ b/advisories/unreviewed/2022/05/GHSA-pg6c-938r-g548/GHSA-pg6c-938r-g548.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg83-2xx5-cjhr/GHSA-pg83-2xx5-cjhr.json b/advisories/unreviewed/2022/05/GHSA-pg83-2xx5-cjhr/GHSA-pg83-2xx5-cjhr.json index 23cf2a7fa8b..29f8d901685 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg83-2xx5-cjhr/GHSA-pg83-2xx5-cjhr.json +++ b/advisories/unreviewed/2022/05/GHSA-pg83-2xx5-cjhr/GHSA-pg83-2xx5-cjhr.json @@ -7,12 +7,8 @@ "CVE-2014-5391" ], "details": "Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg9p-rcwh-5gv5/GHSA-pg9p-rcwh-5gv5.json b/advisories/unreviewed/2022/05/GHSA-pg9p-rcwh-5gv5/GHSA-pg9p-rcwh-5gv5.json index 4994b3501e5..92bdeea745f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg9p-rcwh-5gv5/GHSA-pg9p-rcwh-5gv5.json +++ b/advisories/unreviewed/2022/05/GHSA-pg9p-rcwh-5gv5/GHSA-pg9p-rcwh-5gv5.json @@ -7,12 +7,8 @@ "CVE-2014-8778" ], "details": "Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitrary C# code by asserting the (1) System.Security.Permissions.PermissionState.Unrestricted or (2) System.Security.Permissions.SecurityPermissionFlag.AllFlags permission.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgfj-r964-76qx/GHSA-pgfj-r964-76qx.json b/advisories/unreviewed/2022/05/GHSA-pgfj-r964-76qx/GHSA-pgfj-r964-76qx.json index da77678723c..4016dad2b63 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgfj-r964-76qx/GHSA-pgfj-r964-76qx.json +++ b/advisories/unreviewed/2022/05/GHSA-pgfj-r964-76qx/GHSA-pgfj-r964-76qx.json @@ -7,12 +7,8 @@ "CVE-2015-1056" ], "details": "Cross-site scripting (XSS) vulnerability in Brother MFC-J4410DW printer with firmware before L allows remote attackers to inject arbitrary web script or HTML via the url parameter to general/status.html and possibly other pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgpg-mrjc-8g4g/GHSA-pgpg-mrjc-8g4g.json b/advisories/unreviewed/2022/05/GHSA-pgpg-mrjc-8g4g/GHSA-pgpg-mrjc-8g4g.json index 605f5d7fd13..10ca2b2ce6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgpg-mrjc-8g4g/GHSA-pgpg-mrjc-8g4g.json +++ b/advisories/unreviewed/2022/05/GHSA-pgpg-mrjc-8g4g/GHSA-pgpg-mrjc-8g4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmmh-h8hr-cxm8/GHSA-pmmh-h8hr-cxm8.json b/advisories/unreviewed/2022/05/GHSA-pmmh-h8hr-cxm8/GHSA-pmmh-h8hr-cxm8.json index c8db6ffe1a4..426bf3cc2c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmmh-h8hr-cxm8/GHSA-pmmh-h8hr-cxm8.json +++ b/advisories/unreviewed/2022/05/GHSA-pmmh-h8hr-cxm8/GHSA-pmmh-h8hr-cxm8.json @@ -7,12 +7,8 @@ "CVE-2014-2493" ], "details": "Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.2.4.0, and 12.1.2.0.0 allows remote attackers to affect confidentiality and availability via vectors related to ADF Faces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqp4-4hrh-77x4/GHSA-pqp4-4hrh-77x4.json b/advisories/unreviewed/2022/05/GHSA-pqp4-4hrh-77x4/GHSA-pqp4-4hrh-77x4.json index 46878acb422..44555fb229f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqp4-4hrh-77x4/GHSA-pqp4-4hrh-77x4.json +++ b/advisories/unreviewed/2022/05/GHSA-pqp4-4hrh-77x4/GHSA-pqp4-4hrh-77x4.json @@ -7,12 +7,8 @@ "CVE-2014-100004" ], "details": "Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbitrary web script or HTML via the xmlcontrol parameter to the default URI. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqrq-jm22-v4pv/GHSA-pqrq-jm22-v4pv.json b/advisories/unreviewed/2022/05/GHSA-pqrq-jm22-v4pv/GHSA-pqrq-jm22-v4pv.json index 2f91e66ab16..543641b3fc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqrq-jm22-v4pv/GHSA-pqrq-jm22-v4pv.json +++ b/advisories/unreviewed/2022/05/GHSA-pqrq-jm22-v4pv/GHSA-pqrq-jm22-v4pv.json @@ -7,12 +7,8 @@ "CVE-2014-2654" ], "details": "Multiple SQL injection vulnerabilities in MobFox mAdserve 2.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) edit_ad_unit.php, (2) view_adunits.php, or (3) edit_campaign.php in www/cp/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqx5-4w4x-h6j2/GHSA-pqx5-4w4x-h6j2.json b/advisories/unreviewed/2022/05/GHSA-pqx5-4w4x-h6j2/GHSA-pqx5-4w4x-h6j2.json index 390d508bff2..10ee19d4b20 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqx5-4w4x-h6j2/GHSA-pqx5-4w4x-h6j2.json +++ b/advisories/unreviewed/2022/05/GHSA-pqx5-4w4x-h6j2/GHSA-pqx5-4w4x-h6j2.json @@ -7,12 +7,8 @@ "CVE-2014-2024" ], "details": "Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr5m-6gvr-rwfr/GHSA-pr5m-6gvr-rwfr.json b/advisories/unreviewed/2022/05/GHSA-pr5m-6gvr-rwfr/GHSA-pr5m-6gvr-rwfr.json index 74cb51a4422..9ab75bbc622 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr5m-6gvr-rwfr/GHSA-pr5m-6gvr-rwfr.json +++ b/advisories/unreviewed/2022/05/GHSA-pr5m-6gvr-rwfr/GHSA-pr5m-6gvr-rwfr.json @@ -7,12 +7,8 @@ "CVE-2014-0053" ], "details": "The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different researchers and different vulnerability types. See CVE-2014-2857 for the META-INF variant and CVE-2014-2858 for the directory traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvcp-3wfq-3hf4/GHSA-pvcp-3wfq-3hf4.json b/advisories/unreviewed/2022/05/GHSA-pvcp-3wfq-3hf4/GHSA-pvcp-3wfq-3hf4.json index 4a18fa4b579..188ce565b16 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvcp-3wfq-3hf4/GHSA-pvcp-3wfq-3hf4.json +++ b/advisories/unreviewed/2022/05/GHSA-pvcp-3wfq-3hf4/GHSA-pvcp-3wfq-3hf4.json @@ -7,12 +7,8 @@ "CVE-2014-9360" ], "details": "XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2fj-rm78-5v8m/GHSA-q2fj-rm78-5v8m.json b/advisories/unreviewed/2022/05/GHSA-q2fj-rm78-5v8m/GHSA-q2fj-rm78-5v8m.json index eb2dd0ee640..69eabf28af7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2fj-rm78-5v8m/GHSA-q2fj-rm78-5v8m.json +++ b/advisories/unreviewed/2022/05/GHSA-q2fj-rm78-5v8m/GHSA-q2fj-rm78-5v8m.json @@ -7,12 +7,8 @@ "CVE-2014-2042" ], "details": "Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a predictable directory in Uploads/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2vv-3q42-xrpx/GHSA-q2vv-3q42-xrpx.json b/advisories/unreviewed/2022/05/GHSA-q2vv-3q42-xrpx/GHSA-q2vv-3q42-xrpx.json index 9eb2a4a8584..1693b7124ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2vv-3q42-xrpx/GHSA-q2vv-3q42-xrpx.json +++ b/advisories/unreviewed/2022/05/GHSA-q2vv-3q42-xrpx/GHSA-q2vv-3q42-xrpx.json @@ -7,12 +7,8 @@ "CVE-2014-3439" ], "details": "ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q36r-8fc9-m4r9/GHSA-q36r-8fc9-m4r9.json b/advisories/unreviewed/2022/05/GHSA-q36r-8fc9-m4r9/GHSA-q36r-8fc9-m4r9.json index 7113caffb02..befaff532c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q36r-8fc9-m4r9/GHSA-q36r-8fc9-m4r9.json +++ b/advisories/unreviewed/2022/05/GHSA-q36r-8fc9-m4r9/GHSA-q36r-8fc9-m4r9.json @@ -7,12 +7,8 @@ "CVE-2014-8732" ], "details": "Cross-site scripting (XSS) vulnerability in phpMemcachedAdmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3gg-vjpp-5cr5/GHSA-q3gg-vjpp-5cr5.json b/advisories/unreviewed/2022/05/GHSA-q3gg-vjpp-5cr5/GHSA-q3gg-vjpp-5cr5.json index 96e9e198741..220928e0e39 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3gg-vjpp-5cr5/GHSA-q3gg-vjpp-5cr5.json +++ b/advisories/unreviewed/2022/05/GHSA-q3gg-vjpp-5cr5/GHSA-q3gg-vjpp-5cr5.json @@ -7,12 +7,8 @@ "CVE-2014-7139" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin before 2.8.16 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) form or (2) enc parameter in the CF7DBPluginShortCodeBuilder page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3j4-9cmf-q948/GHSA-q3j4-9cmf-q948.json b/advisories/unreviewed/2022/05/GHSA-q3j4-9cmf-q948/GHSA-q3j4-9cmf-q948.json index 4154c1ee0ea..0ca9a023537 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3j4-9cmf-q948/GHSA-q3j4-9cmf-q948.json +++ b/advisories/unreviewed/2022/05/GHSA-q3j4-9cmf-q948/GHSA-q3j4-9cmf-q948.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q44j-435f-vxcg/GHSA-q44j-435f-vxcg.json b/advisories/unreviewed/2022/05/GHSA-q44j-435f-vxcg/GHSA-q44j-435f-vxcg.json index 9b50db5e760..cadceb61783 100644 --- a/advisories/unreviewed/2022/05/GHSA-q44j-435f-vxcg/GHSA-q44j-435f-vxcg.json +++ b/advisories/unreviewed/2022/05/GHSA-q44j-435f-vxcg/GHSA-q44j-435f-vxcg.json @@ -7,12 +7,8 @@ "CVE-2014-8309" ], "details": "SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames via SecEnterprise authentication requests to the Session web service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4f5-ggvq-wc6p/GHSA-q4f5-ggvq-wc6p.json b/advisories/unreviewed/2022/05/GHSA-q4f5-ggvq-wc6p/GHSA-q4f5-ggvq-wc6p.json index a6c66a592ea..e4109b6a1af 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4f5-ggvq-wc6p/GHSA-q4f5-ggvq-wc6p.json +++ b/advisories/unreviewed/2022/05/GHSA-q4f5-ggvq-wc6p/GHSA-q4f5-ggvq-wc6p.json @@ -7,12 +7,8 @@ "CVE-2014-7138" ], "details": "Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q579-28m6-fmfm/GHSA-q579-28m6-fmfm.json b/advisories/unreviewed/2022/05/GHSA-q579-28m6-fmfm/GHSA-q579-28m6-fmfm.json index fbde475ad10..8ea5e88e08e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q579-28m6-fmfm/GHSA-q579-28m6-fmfm.json +++ b/advisories/unreviewed/2022/05/GHSA-q579-28m6-fmfm/GHSA-q579-28m6-fmfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5h5-xj4x-2fm4/GHSA-q5h5-xj4x-2fm4.json b/advisories/unreviewed/2022/05/GHSA-q5h5-xj4x-2fm4/GHSA-q5h5-xj4x-2fm4.json index d6faed30bfe..04cca7a50da 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5h5-xj4x-2fm4/GHSA-q5h5-xj4x-2fm4.json +++ b/advisories/unreviewed/2022/05/GHSA-q5h5-xj4x-2fm4/GHSA-q5h5-xj4x-2fm4.json @@ -7,12 +7,8 @@ "CVE-2014-0980" ], "details": "Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5jf-fjpf-mq77/GHSA-q5jf-fjpf-mq77.json b/advisories/unreviewed/2022/05/GHSA-q5jf-fjpf-mq77/GHSA-q5jf-fjpf-mq77.json index ced1e94c987..e7f6005bac5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5jf-fjpf-mq77/GHSA-q5jf-fjpf-mq77.json +++ b/advisories/unreviewed/2022/05/GHSA-q5jf-fjpf-mq77/GHSA-q5jf-fjpf-mq77.json @@ -7,12 +7,8 @@ "CVE-2014-4222" ], "details": "Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 and 12.1.2.0 allows remote authenticated users to affect confidentiality via vectors related to plugin 1.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q776-jqj9-22hh/GHSA-q776-jqj9-22hh.json b/advisories/unreviewed/2022/05/GHSA-q776-jqj9-22hh/GHSA-q776-jqj9-22hh.json index 8a7cf47b2a9..a719801c138 100644 --- a/advisories/unreviewed/2022/05/GHSA-q776-jqj9-22hh/GHSA-q776-jqj9-22hh.json +++ b/advisories/unreviewed/2022/05/GHSA-q776-jqj9-22hh/GHSA-q776-jqj9-22hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q83m-pm48-7pw6/GHSA-q83m-pm48-7pw6.json b/advisories/unreviewed/2022/05/GHSA-q83m-pm48-7pw6/GHSA-q83m-pm48-7pw6.json index 301238dee14..f3631a4c1cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-q83m-pm48-7pw6/GHSA-q83m-pm48-7pw6.json +++ b/advisories/unreviewed/2022/05/GHSA-q83m-pm48-7pw6/GHSA-q83m-pm48-7pw6.json @@ -7,12 +7,8 @@ "CVE-2015-1026" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText parameter to the Help Desk Roles.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q889-r359-8p38/GHSA-q889-r359-8p38.json b/advisories/unreviewed/2022/05/GHSA-q889-r359-8p38/GHSA-q889-r359-8p38.json index 360b19beeaa..4b7439ce39a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q889-r359-8p38/GHSA-q889-r359-8p38.json +++ b/advisories/unreviewed/2022/05/GHSA-q889-r359-8p38/GHSA-q889-r359-8p38.json @@ -7,12 +7,8 @@ "CVE-2011-4833" ], "details": "Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8jr-p6p3-r4fm/GHSA-q8jr-p6p3-r4fm.json b/advisories/unreviewed/2022/05/GHSA-q8jr-p6p3-r4fm/GHSA-q8jr-p6p3-r4fm.json index 6374ffa1623..2bbb471bd9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8jr-p6p3-r4fm/GHSA-q8jr-p6p3-r4fm.json +++ b/advisories/unreviewed/2022/05/GHSA-q8jr-p6p3-r4fm/GHSA-q8jr-p6p3-r4fm.json @@ -7,12 +7,8 @@ "CVE-2014-4256" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality and integrity via vectors related to WLS - Deployment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q8vx-8qj8-5m82/GHSA-q8vx-8qj8-5m82.json b/advisories/unreviewed/2022/05/GHSA-q8vx-8qj8-5m82/GHSA-q8vx-8qj8-5m82.json index fbd27883128..4eadec5d1e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8vx-8qj8-5m82/GHSA-q8vx-8qj8-5m82.json +++ b/advisories/unreviewed/2022/05/GHSA-q8vx-8qj8-5m82/GHSA-q8vx-8qj8-5m82.json @@ -7,12 +7,8 @@ "CVE-2014-2858" ], "details": "Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a \"configured block.\" NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q928-658m-3ccv/GHSA-q928-658m-3ccv.json b/advisories/unreviewed/2022/05/GHSA-q928-658m-3ccv/GHSA-q928-658m-3ccv.json index b872ae25e34..88642dc3ce5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q928-658m-3ccv/GHSA-q928-658m-3ccv.json +++ b/advisories/unreviewed/2022/05/GHSA-q928-658m-3ccv/GHSA-q928-658m-3ccv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q92p-8v5f-g5x5/GHSA-q92p-8v5f-g5x5.json b/advisories/unreviewed/2022/05/GHSA-q92p-8v5f-g5x5/GHSA-q92p-8v5f-g5x5.json index 649df2af78c..adaa525978b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q92p-8v5f-g5x5/GHSA-q92p-8v5f-g5x5.json +++ b/advisories/unreviewed/2022/05/GHSA-q92p-8v5f-g5x5/GHSA-q92p-8v5f-g5x5.json @@ -7,12 +7,8 @@ "CVE-2014-0998" ], "details": "Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q954-xhvx-crpg/GHSA-q954-xhvx-crpg.json b/advisories/unreviewed/2022/05/GHSA-q954-xhvx-crpg/GHSA-q954-xhvx-crpg.json index 5222ffe6678..eb2c5818fc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q954-xhvx-crpg/GHSA-q954-xhvx-crpg.json +++ b/advisories/unreviewed/2022/05/GHSA-q954-xhvx-crpg/GHSA-q954-xhvx-crpg.json @@ -7,12 +7,8 @@ "CVE-2014-2689" ], "details": "Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc9q-6588-8mr6/GHSA-qc9q-6588-8mr6.json b/advisories/unreviewed/2022/05/GHSA-qc9q-6588-8mr6/GHSA-qc9q-6588-8mr6.json index d5fc6e8f068..73a777de436 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc9q-6588-8mr6/GHSA-qc9q-6588-8mr6.json +++ b/advisories/unreviewed/2022/05/GHSA-qc9q-6588-8mr6/GHSA-qc9q-6588-8mr6.json @@ -7,12 +7,8 @@ "CVE-2014-2737" ], "details": "SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcwp-776m-mf57/GHSA-qcwp-776m-mf57.json b/advisories/unreviewed/2022/05/GHSA-qcwp-776m-mf57/GHSA-qcwp-776m-mf57.json index 7ca2f5af7ce..94beee89e80 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcwp-776m-mf57/GHSA-qcwp-776m-mf57.json +++ b/advisories/unreviewed/2022/05/GHSA-qcwp-776m-mf57/GHSA-qcwp-776m-mf57.json @@ -7,12 +7,8 @@ "CVE-2011-3185" ], "details": "gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf25-9mpg-v9fc/GHSA-qf25-9mpg-v9fc.json b/advisories/unreviewed/2022/05/GHSA-qf25-9mpg-v9fc/GHSA-qf25-9mpg-v9fc.json index ac514060adf..ffc68e93cf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf25-9mpg-v9fc/GHSA-qf25-9mpg-v9fc.json +++ b/advisories/unreviewed/2022/05/GHSA-qf25-9mpg-v9fc/GHSA-qf25-9mpg-v9fc.json @@ -7,12 +7,8 @@ "CVE-2014-8314" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA Developer Edition Revision 70 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) epm/admin/DataGen.xsjs or (2) epm/services/multiply.xsjs in the democontent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh22-xhvg-2v6g/GHSA-qh22-xhvg-2v6g.json b/advisories/unreviewed/2022/05/GHSA-qh22-xhvg-2v6g/GHSA-qh22-xhvg-2v6g.json index fc52a87356e..79a83ba8a19 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh22-xhvg-2v6g/GHSA-qh22-xhvg-2v6g.json +++ b/advisories/unreviewed/2022/05/GHSA-qh22-xhvg-2v6g/GHSA-qh22-xhvg-2v6g.json @@ -7,12 +7,8 @@ "CVE-2014-2857" ], "details": "The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to different researchers per ADT5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj22-33jc-9j2f/GHSA-qj22-33jc-9j2f.json b/advisories/unreviewed/2022/05/GHSA-qj22-33jc-9j2f/GHSA-qj22-33jc-9j2f.json index 4dc849473ab..64c46de2730 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj22-33jc-9j2f/GHSA-qj22-33jc-9j2f.json +++ b/advisories/unreviewed/2022/05/GHSA-qj22-33jc-9j2f/GHSA-qj22-33jc-9j2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjvh-m9j3-g2qw/GHSA-qjvh-m9j3-g2qw.json b/advisories/unreviewed/2022/05/GHSA-qjvh-m9j3-g2qw/GHSA-qjvh-m9j3-g2qw.json index 6d4531285ae..307428e3562 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjvh-m9j3-g2qw/GHSA-qjvh-m9j3-g2qw.json +++ b/advisories/unreviewed/2022/05/GHSA-qjvh-m9j3-g2qw/GHSA-qjvh-m9j3-g2qw.json @@ -7,12 +7,8 @@ "CVE-2013-7204" ], "details": "Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmr9-3466-4r4h/GHSA-qmr9-3466-4r4h.json b/advisories/unreviewed/2022/05/GHSA-qmr9-3466-4r4h/GHSA-qmr9-3466-4r4h.json index 997fd1f500f..60a44872dad 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmr9-3466-4r4h/GHSA-qmr9-3466-4r4h.json +++ b/advisories/unreviewed/2022/05/GHSA-qmr9-3466-4r4h/GHSA-qmr9-3466-4r4h.json @@ -7,12 +7,8 @@ "CVE-2014-4203" ], "details": "Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Property Editing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmw2-rrv5-2qxg/GHSA-qmw2-rrv5-2qxg.json b/advisories/unreviewed/2022/05/GHSA-qmw2-rrv5-2qxg/GHSA-qmw2-rrv5-2qxg.json index 94ba79120f2..ac25b179445 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmw2-rrv5-2qxg/GHSA-qmw2-rrv5-2qxg.json +++ b/advisories/unreviewed/2022/05/GHSA-qmw2-rrv5-2qxg/GHSA-qmw2-rrv5-2qxg.json @@ -7,12 +7,8 @@ "CVE-2014-4347" ], "details": "Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp53-7wh8-26w7/GHSA-qp53-7wh8-26w7.json b/advisories/unreviewed/2022/05/GHSA-qp53-7wh8-26w7/GHSA-qp53-7wh8-26w7.json index c898df0eb4e..94561d00764 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp53-7wh8-26w7/GHSA-qp53-7wh8-26w7.json +++ b/advisories/unreviewed/2022/05/GHSA-qp53-7wh8-26w7/GHSA-qp53-7wh8-26w7.json @@ -7,12 +7,8 @@ "CVE-2015-1179" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in data_point_details.shtm in Mango Automation 2.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dpid, (2) dpxid, or (3) pid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpf9-w85c-45gv/GHSA-qpf9-w85c-45gv.json b/advisories/unreviewed/2022/05/GHSA-qpf9-w85c-45gv/GHSA-qpf9-w85c-45gv.json index 1fd534a3bc2..e61954cb800 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpf9-w85c-45gv/GHSA-qpf9-w85c-45gv.json +++ b/advisories/unreviewed/2022/05/GHSA-qpf9-w85c-45gv/GHSA-qpf9-w85c-45gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qppx-xpxc-rvg5/GHSA-qppx-xpxc-rvg5.json b/advisories/unreviewed/2022/05/GHSA-qppx-xpxc-rvg5/GHSA-qppx-xpxc-rvg5.json index 3bbaea085a3..2435b53cc43 100644 --- a/advisories/unreviewed/2022/05/GHSA-qppx-xpxc-rvg5/GHSA-qppx-xpxc-rvg5.json +++ b/advisories/unreviewed/2022/05/GHSA-qppx-xpxc-rvg5/GHSA-qppx-xpxc-rvg5.json @@ -7,12 +7,8 @@ "CVE-2014-0514" ], "details": "The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qv29-vvm4-3pc6/GHSA-qv29-vvm4-3pc6.json b/advisories/unreviewed/2022/05/GHSA-qv29-vvm4-3pc6/GHSA-qv29-vvm4-3pc6.json index acb7a655d51..ab8724e15b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv29-vvm4-3pc6/GHSA-qv29-vvm4-3pc6.json +++ b/advisories/unreviewed/2022/05/GHSA-qv29-vvm4-3pc6/GHSA-qv29-vvm4-3pc6.json @@ -7,12 +7,8 @@ "CVE-2014-4722" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw57-cmq9-hj8j/GHSA-qw57-cmq9-hj8j.json b/advisories/unreviewed/2022/05/GHSA-qw57-cmq9-hj8j/GHSA-qw57-cmq9-hj8j.json index 2ecbce9db4f..875fc690cb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw57-cmq9-hj8j/GHSA-qw57-cmq9-hj8j.json +++ b/advisories/unreviewed/2022/05/GHSA-qw57-cmq9-hj8j/GHSA-qw57-cmq9-hj8j.json @@ -7,12 +7,8 @@ "CVE-2014-4249" ], "details": "Unspecified vulnerability in the BI Publisher component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Mobile Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwm2-p4xm-jjjq/GHSA-qwm2-p4xm-jjjq.json b/advisories/unreviewed/2022/05/GHSA-qwm2-p4xm-jjjq/GHSA-qwm2-p4xm-jjjq.json index d2b8b1d8016..9b7859bf950 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwm2-p4xm-jjjq/GHSA-qwm2-p4xm-jjjq.json +++ b/advisories/unreviewed/2022/05/GHSA-qwm2-p4xm-jjjq/GHSA-qwm2-p4xm-jjjq.json @@ -7,12 +7,8 @@ "CVE-2015-1482" ], "details": "Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwpw-7f3q-wc3q/GHSA-qwpw-7f3q-wc3q.json b/advisories/unreviewed/2022/05/GHSA-qwpw-7f3q-wc3q/GHSA-qwpw-7f3q-wc3q.json index 353291580f0..71584ae4171 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwpw-7f3q-wc3q/GHSA-qwpw-7f3q-wc3q.json +++ b/advisories/unreviewed/2022/05/GHSA-qwpw-7f3q-wc3q/GHSA-qwpw-7f3q-wc3q.json @@ -7,12 +7,8 @@ "CVE-2014-9522" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML via the (1) author field to guestbook.php or (2) username field to account.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2j5-h2gf-999c/GHSA-r2j5-h2gf-999c.json b/advisories/unreviewed/2022/05/GHSA-r2j5-h2gf-999c/GHSA-r2j5-h2gf-999c.json index 76c851e674f..db23261fc48 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2j5-h2gf-999c/GHSA-r2j5-h2gf-999c.json +++ b/advisories/unreviewed/2022/05/GHSA-r2j5-h2gf-999c/GHSA-r2j5-h2gf-999c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r32h-qqj3-9xpg/GHSA-r32h-qqj3-9xpg.json b/advisories/unreviewed/2022/05/GHSA-r32h-qqj3-9xpg/GHSA-r32h-qqj3-9xpg.json index dde95dcf584..88766a52f29 100644 --- a/advisories/unreviewed/2022/05/GHSA-r32h-qqj3-9xpg/GHSA-r32h-qqj3-9xpg.json +++ b/advisories/unreviewed/2022/05/GHSA-r32h-qqj3-9xpg/GHSA-r32h-qqj3-9xpg.json @@ -7,12 +7,8 @@ "CVE-2015-2102" ], "details": "SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3mw-gv7v-r27r/GHSA-r3mw-gv7v-r27r.json b/advisories/unreviewed/2022/05/GHSA-r3mw-gv7v-r27r/GHSA-r3mw-gv7v-r27r.json index 65f847aef5f..9100c8d1cec 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3mw-gv7v-r27r/GHSA-r3mw-gv7v-r27r.json +++ b/advisories/unreviewed/2022/05/GHSA-r3mw-gv7v-r27r/GHSA-r3mw-gv7v-r27r.json @@ -7,12 +7,8 @@ "CVE-2014-7807" ], "details": "Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3wh-69g5-qr68/GHSA-r3wh-69g5-qr68.json b/advisories/unreviewed/2022/05/GHSA-r3wh-69g5-qr68/GHSA-r3wh-69g5-qr68.json index a8645dbdaa5..f61cf4b3ab5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3wh-69g5-qr68/GHSA-r3wh-69g5-qr68.json +++ b/advisories/unreviewed/2022/05/GHSA-r3wh-69g5-qr68/GHSA-r3wh-69g5-qr68.json @@ -7,12 +7,8 @@ "CVE-2015-1367" ], "details": "SQL injection vulnerability in index.php in CatBot 0.4.2 allows remote attackers to execute arbitrary SQL commands via the lastcatbot parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4rm-j888-6w3w/GHSA-r4rm-j888-6w3w.json b/advisories/unreviewed/2022/05/GHSA-r4rm-j888-6w3w/GHSA-r4rm-j888-6w3w.json index 77fa8b5cd6a..0642dd57f66 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4rm-j888-6w3w/GHSA-r4rm-j888-6w3w.json +++ b/advisories/unreviewed/2022/05/GHSA-r4rm-j888-6w3w/GHSA-r4rm-j888-6w3w.json @@ -7,12 +7,8 @@ "CVE-2014-9178" ], "details": "Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id parameter in the (2) download_project, (3) download_archive, or (4) remove_cat function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5m5-9pgw-6cx2/GHSA-r5m5-9pgw-6cx2.json b/advisories/unreviewed/2022/05/GHSA-r5m5-9pgw-6cx2/GHSA-r5m5-9pgw-6cx2.json index 9435e987d56..e925afdd0a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5m5-9pgw-6cx2/GHSA-r5m5-9pgw-6cx2.json +++ b/advisories/unreviewed/2022/05/GHSA-r5m5-9pgw-6cx2/GHSA-r5m5-9pgw-6cx2.json @@ -7,12 +7,8 @@ "CVE-2014-4728" ], "details": "The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r627-h27m-xp74/GHSA-r627-h27m-xp74.json b/advisories/unreviewed/2022/05/GHSA-r627-h27m-xp74/GHSA-r627-h27m-xp74.json index d0b479abe23..8c76e23176f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r627-h27m-xp74/GHSA-r627-h27m-xp74.json +++ b/advisories/unreviewed/2022/05/GHSA-r627-h27m-xp74/GHSA-r627-h27m-xp74.json @@ -7,12 +7,8 @@ "CVE-2014-4240" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows local users to affect confidentiality and integrity via vectors related to SRREP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6rj-wrr3-48q3/GHSA-r6rj-wrr3-48q3.json b/advisories/unreviewed/2022/05/GHSA-r6rj-wrr3-48q3/GHSA-r6rj-wrr3-48q3.json index d0fcc1c3faa..150a5149803 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6rj-wrr3-48q3/GHSA-r6rj-wrr3-48q3.json +++ b/advisories/unreviewed/2022/05/GHSA-r6rj-wrr3-48q3/GHSA-r6rj-wrr3-48q3.json @@ -7,12 +7,8 @@ "CVE-2015-1376" ], "details": "pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7cx-cqwc-hf28/GHSA-r7cx-cqwc-hf28.json b/advisories/unreviewed/2022/05/GHSA-r7cx-cqwc-hf28/GHSA-r7cx-cqwc-hf28.json index 59d84f0336e..9e95cf904a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7cx-cqwc-hf28/GHSA-r7cx-cqwc-hf28.json +++ b/advisories/unreviewed/2022/05/GHSA-r7cx-cqwc-hf28/GHSA-r7cx-cqwc-hf28.json @@ -7,12 +7,8 @@ "CVE-2014-8081" ], "details": "lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the filter_result_result parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8j8-g8mg-2j28/GHSA-r8j8-g8mg-2j28.json b/advisories/unreviewed/2022/05/GHSA-r8j8-g8mg-2j28/GHSA-r8j8-g8mg-2j28.json index 5a123d87c81..29eea264395 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8j8-g8mg-2j28/GHSA-r8j8-g8mg-2j28.json +++ b/advisories/unreviewed/2022/05/GHSA-r8j8-g8mg-2j28/GHSA-r8j8-g8mg-2j28.json @@ -7,12 +7,8 @@ "CVE-2011-5184" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to nnm/protected/configurationpoll.jsp, (3) nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp, or (5) nnm/protected/traceroute.jsp; or (6) field parameter to nmm/validate. NOTE: this might be a duplicate of CVE-2011-4155 or CVE-2011-4156.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8pv-f253-ph8x/GHSA-r8pv-f253-ph8x.json b/advisories/unreviewed/2022/05/GHSA-r8pv-f253-ph8x/GHSA-r8pv-f253-ph8x.json index ad94354e461..027311edcc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8pv-f253-ph8x/GHSA-r8pv-f253-ph8x.json +++ b/advisories/unreviewed/2022/05/GHSA-r8pv-f253-ph8x/GHSA-r8pv-f253-ph8x.json @@ -7,12 +7,8 @@ "CVE-2014-0232" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r93x-32gw-w52p/GHSA-r93x-32gw-w52p.json b/advisories/unreviewed/2022/05/GHSA-r93x-32gw-w52p/GHSA-r93x-32gw-w52p.json index 0566ca32ab2..012565479de 100644 --- a/advisories/unreviewed/2022/05/GHSA-r93x-32gw-w52p/GHSA-r93x-32gw-w52p.json +++ b/advisories/unreviewed/2022/05/GHSA-r93x-32gw-w52p/GHSA-r93x-32gw-w52p.json @@ -7,12 +7,8 @@ "CVE-2014-4234" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote attackers to affect confidentiality via unknown vectors related to Data, Domain & Function Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r943-c3mj-3wjm/GHSA-r943-c3mj-3wjm.json b/advisories/unreviewed/2022/05/GHSA-r943-c3mj-3wjm/GHSA-r943-c3mj-3wjm.json index bf3e0770436..e181b571432 100644 --- a/advisories/unreviewed/2022/05/GHSA-r943-c3mj-3wjm/GHSA-r943-c3mj-3wjm.json +++ b/advisories/unreviewed/2022/05/GHSA-r943-c3mj-3wjm/GHSA-r943-c3mj-3wjm.json @@ -7,12 +7,8 @@ "CVE-2014-2577" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform Foundation Server before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers to inject arbitrary web script or HTML via the (1) pn parameter to index.fsp/document.pdf, (2) db or (3) referer parameter to index.fsp/index.fsp, or (4) PATH_INFO to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9jr-628j-pc37/GHSA-r9jr-628j-pc37.json b/advisories/unreviewed/2022/05/GHSA-r9jr-628j-pc37/GHSA-r9jr-628j-pc37.json index 04fcb32dcc5..4e663e2d404 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9jr-628j-pc37/GHSA-r9jr-628j-pc37.json +++ b/advisories/unreviewed/2022/05/GHSA-r9jr-628j-pc37/GHSA-r9jr-628j-pc37.json @@ -7,12 +7,8 @@ "CVE-2014-1213" ], "details": "Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption, and eventual crash) or spoof \"ready for update\" messages by performing certain operations on mutexes or events including (1) DataUpdateRequest, (2) MmfMutexSAV-****, (3) MmfMutexSAV-Info, (4) ReadyForUpdateSAV-****, (5) ReadyForUpdateSAV-Info, (6) SAV-****, (7) SAV-Info, (8) StateChange, (9) SuspendedSAV-****, (10) SuspendedSAV-Info, (11) UpdateComplete, (12) UpdateMutex, (13) UpdateRequest, or (14) SophosALMonSessionInstance, as demonstrated by triggering a ReadyForUpdateSAV event and modifying the UpdateComplete, UpdateMutex, and UpdateRequest objects.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9q5-qcf6-7r92/GHSA-r9q5-qcf6-7r92.json b/advisories/unreviewed/2022/05/GHSA-r9q5-qcf6-7r92/GHSA-r9q5-qcf6-7r92.json index 5ac42640834..b5e4a13bf7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9q5-qcf6-7r92/GHSA-r9q5-qcf6-7r92.json +++ b/advisories/unreviewed/2022/05/GHSA-r9q5-qcf6-7r92/GHSA-r9q5-qcf6-7r92.json @@ -7,12 +7,8 @@ "CVE-2014-4210" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf98-23w8-rpx5/GHSA-rf98-23w8-rpx5.json b/advisories/unreviewed/2022/05/GHSA-rf98-23w8-rpx5/GHSA-rf98-23w8-rpx5.json index 7597cc37a2a..47720d79eb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf98-23w8-rpx5/GHSA-rf98-23w8-rpx5.json +++ b/advisories/unreviewed/2022/05/GHSA-rf98-23w8-rpx5/GHSA-rf98-23w8-rpx5.json @@ -7,12 +7,8 @@ "CVE-2014-4346" ], "details": "Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfvv-px5p-7fmg/GHSA-rfvv-px5p-7fmg.json b/advisories/unreviewed/2022/05/GHSA-rfvv-px5p-7fmg/GHSA-rfvv-px5p-7fmg.json index bd0abad75e9..6aa4d301981 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfvv-px5p-7fmg/GHSA-rfvv-px5p-7fmg.json +++ b/advisories/unreviewed/2022/05/GHSA-rfvv-px5p-7fmg/GHSA-rfvv-px5p-7fmg.json @@ -7,12 +7,8 @@ "CVE-2014-8769" ], "details": "tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Distance Vector (AODV) packet, which triggers an out-of-bounds memory access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhr6-3h7f-9h2q/GHSA-rhr6-3h7f-9h2q.json b/advisories/unreviewed/2022/05/GHSA-rhr6-3h7f-9h2q/GHSA-rhr6-3h7f-9h2q.json index 52f0671e456..153f101f81e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhr6-3h7f-9h2q/GHSA-rhr6-3h7f-9h2q.json +++ b/advisories/unreviewed/2022/05/GHSA-rhr6-3h7f-9h2q/GHSA-rhr6-3h7f-9h2q.json @@ -7,12 +7,8 @@ "CVE-2011-4561" ], "details": "Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjjg-6x7j-qmpc/GHSA-rjjg-6x7j-qmpc.json b/advisories/unreviewed/2022/05/GHSA-rjjg-6x7j-qmpc/GHSA-rjjg-6x7j-qmpc.json index 21c91dcaf16..a690886505c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjjg-6x7j-qmpc/GHSA-rjjg-6x7j-qmpc.json +++ b/advisories/unreviewed/2022/05/GHSA-rjjg-6x7j-qmpc/GHSA-rjjg-6x7j-qmpc.json @@ -7,12 +7,8 @@ "CVE-2014-2303" ], "details": "Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rm2q-3gmp-74fg/GHSA-rm2q-3gmp-74fg.json b/advisories/unreviewed/2022/05/GHSA-rm2q-3gmp-74fg/GHSA-rm2q-3gmp-74fg.json index bea269f95d1..1909273be2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm2q-3gmp-74fg/GHSA-rm2q-3gmp-74fg.json +++ b/advisories/unreviewed/2022/05/GHSA-rm2q-3gmp-74fg/GHSA-rm2q-3gmp-74fg.json @@ -7,12 +7,8 @@ "CVE-2014-2589" ], "details": "Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rm8x-6gj9-f66x/GHSA-rm8x-6gj9-f66x.json b/advisories/unreviewed/2022/05/GHSA-rm8x-6gj9-f66x/GHSA-rm8x-6gj9-f66x.json index fe6774e5a00..3645d1058a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm8x-6gj9-f66x/GHSA-rm8x-6gj9-f66x.json +++ b/advisories/unreviewed/2022/05/GHSA-rm8x-6gj9-f66x/GHSA-rm8x-6gj9-f66x.json @@ -7,12 +7,8 @@ "CVE-2014-0209" ], "details": "Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmfj-5qj3-3hmx/GHSA-rmfj-5qj3-3hmx.json b/advisories/unreviewed/2022/05/GHSA-rmfj-5qj3-3hmx/GHSA-rmfj-5qj3-3hmx.json index 7d35494dc60..e35f0c78e3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmfj-5qj3-3hmx/GHSA-rmfj-5qj3-3hmx.json +++ b/advisories/unreviewed/2022/05/GHSA-rmfj-5qj3-3hmx/GHSA-rmfj-5qj3-3hmx.json @@ -7,12 +7,8 @@ "CVE-2014-4253" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect availability via vectors related to WebLogic Server JVM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmx2-6f87-q3j9/GHSA-rmx2-6f87-q3j9.json b/advisories/unreviewed/2022/05/GHSA-rmx2-6f87-q3j9/GHSA-rmx2-6f87-q3j9.json index 0289f059315..a0eacb65d66 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmx2-6f87-q3j9/GHSA-rmx2-6f87-q3j9.json +++ b/advisories/unreviewed/2022/05/GHSA-rmx2-6f87-q3j9/GHSA-rmx2-6f87-q3j9.json @@ -7,12 +7,8 @@ "CVE-2014-4235" ], "details": "Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows remote authenticated users to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp2c-496x-gf5c/GHSA-rp2c-496x-gf5c.json b/advisories/unreviewed/2022/05/GHSA-rp2c-496x-gf5c/GHSA-rp2c-496x-gf5c.json index db1e7256197..ad32ccceaeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp2c-496x-gf5c/GHSA-rp2c-496x-gf5c.json +++ b/advisories/unreviewed/2022/05/GHSA-rp2c-496x-gf5c/GHSA-rp2c-496x-gf5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp7q-3qmv-ff4c/GHSA-rp7q-3qmv-ff4c.json b/advisories/unreviewed/2022/05/GHSA-rp7q-3qmv-ff4c/GHSA-rp7q-3qmv-ff4c.json index 8f1358d45cd..207642fa3a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp7q-3qmv-ff4c/GHSA-rp7q-3qmv-ff4c.json +++ b/advisories/unreviewed/2022/05/GHSA-rp7q-3qmv-ff4c/GHSA-rp7q-3qmv-ff4c.json @@ -7,12 +7,8 @@ "CVE-2015-1180" ], "details": "Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq5m-vxrx-vvhp/GHSA-rq5m-vxrx-vvhp.json b/advisories/unreviewed/2022/05/GHSA-rq5m-vxrx-vvhp/GHSA-rq5m-vxrx-vvhp.json index 95d7c764093..f04a5d829d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq5m-vxrx-vvhp/GHSA-rq5m-vxrx-vvhp.json +++ b/advisories/unreviewed/2022/05/GHSA-rq5m-vxrx-vvhp/GHSA-rq5m-vxrx-vvhp.json @@ -7,12 +7,8 @@ "CVE-2014-2509" ], "details": "Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrjj-h75v-rxm7/GHSA-rrjj-h75v-rxm7.json b/advisories/unreviewed/2022/05/GHSA-rrjj-h75v-rxm7/GHSA-rrjj-h75v-rxm7.json index 92ab86e862c..c311891e6a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrjj-h75v-rxm7/GHSA-rrjj-h75v-rxm7.json +++ b/advisories/unreviewed/2022/05/GHSA-rrjj-h75v-rxm7/GHSA-rrjj-h75v-rxm7.json @@ -7,12 +7,8 @@ "CVE-2014-4257" ], "details": "Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.8.0 allows remote attackers to affect confidentiality via unknown vectors related to Portlet Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrxx-j89p-pqmx/GHSA-rrxx-j89p-pqmx.json b/advisories/unreviewed/2022/05/GHSA-rrxx-j89p-pqmx/GHSA-rrxx-j89p-pqmx.json index c20d8eacf79..628ab94feaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrxx-j89p-pqmx/GHSA-rrxx-j89p-pqmx.json +++ b/advisories/unreviewed/2022/05/GHSA-rrxx-j89p-pqmx/GHSA-rrxx-j89p-pqmx.json @@ -7,12 +7,8 @@ "CVE-2014-7137" ], "details": "Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4) lineid parameter in a deletecontact action, (5) ligne parameter in a swapstatut action, or (6) ref parameter to projet/contact.php; (7) id parameter to compta/bank/fiche.php, (8) contact/info.php, (9) holiday/index.php, (10) product/stock/fiche.php, (11) product/stock/info.php, or (12) in an edit action to product/stock/fiche.php; (13) productid parameter in an addline action to product/stock/massstockmove.php; (14) project_ref parameter to projet/tasks/note.php; (15) ref parameter to element.php, (16) ganttview.php, (17) note.php, or (18) tasks.php in projet/; (19) sall or (20) sref parameter to comm/mailing/liste.php; (21) search_bon, (22) search_ligne, (23) search_societe, or (24) search_code parameter to compta/prelevement/liste.php; (25) search_label parameter to compta/sociales/index.php; (26) search_project parameter to projet/tasks/index.php; (27) search_societe parameter to compta/prelevement/demandes.php; (28) search_statut parameter to user/index.php; (29) socid parameter to compta/recap-compta.php, (30) societe/commerciaux.php, or (31) societe/rib.php; (32) sortorder, (33) sref, (34) sall, or (35) sortfield parameter to product/stock/liste.php; (36) statut parameter to adherents/liste.php or (37) compta/dons/liste.php; (38) tobuy or (39) tosell parameter to product/liste.php; (40) tobuy, (41) tosell, (42) search_categ, or (43) sref parameter to product/reassort.php; (44) type parameter to product/index.php; or the (a) sortorder or (b) sortfield parameter to (45) compta/paiement/cheque/liste.php, (46) compta/prelevement/bons.php, (47) compta/prelevement/rejets.php, (48) product/stats/commande.php, (49) product/stats/commande_fournisseur.php, (50) product/stats/contrat.php, (51) product/stats/facture.php, (52) product/stats/facture_fournisseur.php, (53) product/stats/propal.php, or (54) product/stock/replenishorders.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvpw-wq7v-3f3v/GHSA-rvpw-wq7v-3f3v.json b/advisories/unreviewed/2022/05/GHSA-rvpw-wq7v-3f3v/GHSA-rvpw-wq7v-3f3v.json index 37576068266..0bf9fd24533 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvpw-wq7v-3f3v/GHSA-rvpw-wq7v-3f3v.json +++ b/advisories/unreviewed/2022/05/GHSA-rvpw-wq7v-3f3v/GHSA-rvpw-wq7v-3f3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v279-8rqm-3xjg/GHSA-v279-8rqm-3xjg.json b/advisories/unreviewed/2022/05/GHSA-v279-8rqm-3xjg/GHSA-v279-8rqm-3xjg.json index 1296a2bfc32..1db307c4434 100644 --- a/advisories/unreviewed/2022/05/GHSA-v279-8rqm-3xjg/GHSA-v279-8rqm-3xjg.json +++ b/advisories/unreviewed/2022/05/GHSA-v279-8rqm-3xjg/GHSA-v279-8rqm-3xjg.json @@ -7,12 +7,8 @@ "CVE-2011-3390" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote attackers to inject arbitrary web script or HTML via the (1) informixserver, (2) host, or (3) port parameter in a login action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v36c-qc45-j933/GHSA-v36c-qc45-j933.json b/advisories/unreviewed/2022/05/GHSA-v36c-qc45-j933/GHSA-v36c-qc45-j933.json index dba8443eb06..bac80e20bf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v36c-qc45-j933/GHSA-v36c-qc45-j933.json +++ b/advisories/unreviewed/2022/05/GHSA-v36c-qc45-j933/GHSA-v36c-qc45-j933.json @@ -7,12 +7,8 @@ "CVE-2014-2507" ], "details": "EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to unspecified methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4cw-9cwh-rv3p/GHSA-v4cw-9cwh-rv3p.json b/advisories/unreviewed/2022/05/GHSA-v4cw-9cwh-rv3p/GHSA-v4cw-9cwh-rv3p.json index b2122ee32fa..32689ed66d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4cw-9cwh-rv3p/GHSA-v4cw-9cwh-rv3p.json +++ b/advisories/unreviewed/2022/05/GHSA-v4cw-9cwh-rv3p/GHSA-v4cw-9cwh-rv3p.json @@ -7,12 +7,8 @@ "CVE-2014-4230" ], "details": "Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via vectors related to Open_UI, a different vulnerability than CVE-2014-2468.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4h8-98x3-fcrp/GHSA-v4h8-98x3-fcrp.json b/advisories/unreviewed/2022/05/GHSA-v4h8-98x3-fcrp/GHSA-v4h8-98x3-fcrp.json index 65eda9a7385..6f3399094c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4h8-98x3-fcrp/GHSA-v4h8-98x3-fcrp.json +++ b/advisories/unreviewed/2022/05/GHSA-v4h8-98x3-fcrp/GHSA-v4h8-98x3-fcrp.json @@ -7,12 +7,8 @@ "CVE-2011-2780" ], "details": "Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v564-r5jq-5c36/GHSA-v564-r5jq-5c36.json b/advisories/unreviewed/2022/05/GHSA-v564-r5jq-5c36/GHSA-v564-r5jq-5c36.json index b6774ed90bf..c6daadbd661 100644 --- a/advisories/unreviewed/2022/05/GHSA-v564-r5jq-5c36/GHSA-v564-r5jq-5c36.json +++ b/advisories/unreviewed/2022/05/GHSA-v564-r5jq-5c36/GHSA-v564-r5jq-5c36.json @@ -7,12 +7,8 @@ "CVE-2014-9140" ], "details": "Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v57j-5v82-q88g/GHSA-v57j-5v82-q88g.json b/advisories/unreviewed/2022/05/GHSA-v57j-5v82-q88g/GHSA-v57j-5v82-q88g.json index e9a01873f17..66979b825cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-v57j-5v82-q88g/GHSA-v57j-5v82-q88g.json +++ b/advisories/unreviewed/2022/05/GHSA-v57j-5v82-q88g/GHSA-v57j-5v82-q88g.json @@ -7,12 +7,8 @@ "CVE-2015-1375" ], "details": "pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6vf-2wmq-mp2x/GHSA-v6vf-2wmq-mp2x.json b/advisories/unreviewed/2022/05/GHSA-v6vf-2wmq-mp2x/GHSA-v6vf-2wmq-mp2x.json index 969d2b79a14..6fc425048c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6vf-2wmq-mp2x/GHSA-v6vf-2wmq-mp2x.json +++ b/advisories/unreviewed/2022/05/GHSA-v6vf-2wmq-mp2x/GHSA-v6vf-2wmq-mp2x.json @@ -7,12 +7,8 @@ "CVE-2014-6140" ], "details": "IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v723-8xx7-26gh/GHSA-v723-8xx7-26gh.json b/advisories/unreviewed/2022/05/GHSA-v723-8xx7-26gh/GHSA-v723-8xx7-26gh.json index 54616de719e..736eaaf83be 100644 --- a/advisories/unreviewed/2022/05/GHSA-v723-8xx7-26gh/GHSA-v723-8xx7-26gh.json +++ b/advisories/unreviewed/2022/05/GHSA-v723-8xx7-26gh/GHSA-v723-8xx7-26gh.json @@ -7,12 +7,8 @@ "CVE-2014-5393" ], "details": "Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v888-69w3-vqpv/GHSA-v888-69w3-vqpv.json b/advisories/unreviewed/2022/05/GHSA-v888-69w3-vqpv/GHSA-v888-69w3-vqpv.json index 3772b47044e..96afa3f1715 100644 --- a/advisories/unreviewed/2022/05/GHSA-v888-69w3-vqpv/GHSA-v888-69w3-vqpv.json +++ b/advisories/unreviewed/2022/05/GHSA-v888-69w3-vqpv/GHSA-v888-69w3-vqpv.json @@ -7,12 +7,8 @@ "CVE-2014-4727" ], "details": "Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8gw-v6pg-vfjw/GHSA-v8gw-v6pg-vfjw.json b/advisories/unreviewed/2022/05/GHSA-v8gw-v6pg-vfjw/GHSA-v8gw-v6pg-vfjw.json index 3cb93f58491..5e4beb4b94c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8gw-v6pg-vfjw/GHSA-v8gw-v6pg-vfjw.json +++ b/advisories/unreviewed/2022/05/GHSA-v8gw-v6pg-vfjw/GHSA-v8gw-v6pg-vfjw.json @@ -7,12 +7,8 @@ "CVE-2015-2082" ], "details": "Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary web script or HTML via the txtUserID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v97q-8h6v-ffr3/GHSA-v97q-8h6v-ffr3.json b/advisories/unreviewed/2022/05/GHSA-v97q-8h6v-ffr3/GHSA-v97q-8h6v-ffr3.json index 4103df2f0b0..f453010f46f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v97q-8h6v-ffr3/GHSA-v97q-8h6v-ffr3.json +++ b/advisories/unreviewed/2022/05/GHSA-v97q-8h6v-ffr3/GHSA-v97q-8h6v-ffr3.json @@ -7,12 +7,8 @@ "CVE-2014-4238" ], "details": "Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vf63-rh76-xv4g/GHSA-vf63-rh76-xv4g.json b/advisories/unreviewed/2022/05/GHSA-vf63-rh76-xv4g/GHSA-vf63-rh76-xv4g.json index 6b026308081..10a59655d70 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf63-rh76-xv4g/GHSA-vf63-rh76-xv4g.json +++ b/advisories/unreviewed/2022/05/GHSA-vf63-rh76-xv4g/GHSA-vf63-rh76-xv4g.json @@ -7,12 +7,8 @@ "CVE-2014-6243" ], "details": "Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfmg-c98f-3jxw/GHSA-vfmg-c98f-3jxw.json b/advisories/unreviewed/2022/05/GHSA-vfmg-c98f-3jxw/GHSA-vfmg-c98f-3jxw.json index 830ccdd64db..90c12f49252 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfmg-c98f-3jxw/GHSA-vfmg-c98f-3jxw.json +++ b/advisories/unreviewed/2022/05/GHSA-vfmg-c98f-3jxw/GHSA-vfmg-c98f-3jxw.json @@ -7,12 +7,8 @@ "CVE-2014-9143" ], "details": "Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgg8-4wp9-8p4c/GHSA-vgg8-4wp9-8p4c.json b/advisories/unreviewed/2022/05/GHSA-vgg8-4wp9-8p4c/GHSA-vgg8-4wp9-8p4c.json index 150237405a1..4b40837ba89 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgg8-4wp9-8p4c/GHSA-vgg8-4wp9-8p4c.json +++ b/advisories/unreviewed/2022/05/GHSA-vgg8-4wp9-8p4c/GHSA-vgg8-4wp9-8p4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhv3-2hw6-3q7j/GHSA-vhv3-2hw6-3q7j.json b/advisories/unreviewed/2022/05/GHSA-vhv3-2hw6-3q7j/GHSA-vhv3-2hw6-3q7j.json index 634d4a7ab1b..9a151ff9bef 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhv3-2hw6-3q7j/GHSA-vhv3-2hw6-3q7j.json +++ b/advisories/unreviewed/2022/05/GHSA-vhv3-2hw6-3q7j/GHSA-vhv3-2hw6-3q7j.json @@ -7,12 +7,8 @@ "CVE-2015-1178" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) product_id or (2) category_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj6g-7r2h-qhcc/GHSA-vj6g-7r2h-qhcc.json b/advisories/unreviewed/2022/05/GHSA-vj6g-7r2h-qhcc/GHSA-vj6g-7r2h-qhcc.json index b75a44654e5..20b73f5f793 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj6g-7r2h-qhcc/GHSA-vj6g-7r2h-qhcc.json +++ b/advisories/unreviewed/2022/05/GHSA-vj6g-7r2h-qhcc/GHSA-vj6g-7r2h-qhcc.json @@ -7,12 +7,8 @@ "CVE-2014-4213" ], "details": "Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpg2-8g7f-3vh6/GHSA-vpg2-8g7f-3vh6.json b/advisories/unreviewed/2022/05/GHSA-vpg2-8g7f-3vh6/GHSA-vpg2-8g7f-3vh6.json index 02f508b2103..1c299f7b37c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpg2-8g7f-3vh6/GHSA-vpg2-8g7f-3vh6.json +++ b/advisories/unreviewed/2022/05/GHSA-vpg2-8g7f-3vh6/GHSA-vpg2-8g7f-3vh6.json @@ -7,12 +7,8 @@ "CVE-2014-0749" ], "details": "Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpq9-rx6p-23hj/GHSA-vpq9-rx6p-23hj.json b/advisories/unreviewed/2022/05/GHSA-vpq9-rx6p-23hj/GHSA-vpq9-rx6p-23hj.json index 5d0c28478e2..d224bc03e1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpq9-rx6p-23hj/GHSA-vpq9-rx6p-23hj.json +++ b/advisories/unreviewed/2022/05/GHSA-vpq9-rx6p-23hj/GHSA-vpq9-rx6p-23hj.json @@ -7,12 +7,8 @@ "CVE-2014-1401" ], "details": "Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqw9-jf4m-h3pm/GHSA-vqw9-jf4m-h3pm.json b/advisories/unreviewed/2022/05/GHSA-vqw9-jf4m-h3pm/GHSA-vqw9-jf4m-h3pm.json index 85636dd24b0..defabfba66a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqw9-jf4m-h3pm/GHSA-vqw9-jf4m-h3pm.json +++ b/advisories/unreviewed/2022/05/GHSA-vqw9-jf4m-h3pm/GHSA-vqw9-jf4m-h3pm.json @@ -7,12 +7,8 @@ "CVE-2014-0794" ], "details": "SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a comment.like action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr78-cpqr-qr3p/GHSA-vr78-cpqr-qr3p.json b/advisories/unreviewed/2022/05/GHSA-vr78-cpqr-qr3p/GHSA-vr78-cpqr-qr3p.json index 573daa81279..879963f5c18 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr78-cpqr-qr3p/GHSA-vr78-cpqr-qr3p.json +++ b/advisories/unreviewed/2022/05/GHSA-vr78-cpqr-qr3p/GHSA-vr78-cpqr-qr3p.json @@ -7,12 +7,8 @@ "CVE-2014-4736" ], "details": "SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv2w-c23q-c32q/GHSA-vv2w-c23q-c32q.json b/advisories/unreviewed/2022/05/GHSA-vv2w-c23q-c32q/GHSA-vv2w-c23q-c32q.json index 09c452c1ad4..2f3c7d73b89 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv2w-c23q-c32q/GHSA-vv2w-c23q-c32q.json +++ b/advisories/unreviewed/2022/05/GHSA-vv2w-c23q-c32q/GHSA-vv2w-c23q-c32q.json @@ -7,12 +7,8 @@ "CVE-2014-2508" ], "details": "EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on database actions via vectors involving DQL hints.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvj7-w55j-xgmw/GHSA-vvj7-w55j-xgmw.json b/advisories/unreviewed/2022/05/GHSA-vvj7-w55j-xgmw/GHSA-vvj7-w55j-xgmw.json index f5c6fc44a46..85cc48e2f03 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvj7-w55j-xgmw/GHSA-vvj7-w55j-xgmw.json +++ b/advisories/unreviewed/2022/05/GHSA-vvj7-w55j-xgmw/GHSA-vvj7-w55j-xgmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw2w-pcch-37c6/GHSA-vw2w-pcch-37c6.json b/advisories/unreviewed/2022/05/GHSA-vw2w-pcch-37c6/GHSA-vw2w-pcch-37c6.json index 5d2974b7899..5eaea4a0f95 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw2w-pcch-37c6/GHSA-vw2w-pcch-37c6.json +++ b/advisories/unreviewed/2022/05/GHSA-vw2w-pcch-37c6/GHSA-vw2w-pcch-37c6.json @@ -7,12 +7,8 @@ "CVE-2015-4415" ], "details": "Multiple directory traversal vulnerabilities in func.php in Magnifica Webscripts Anima Gallery 2.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) theme or (2) lang cookie parameter to AnimaGallery/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw4m-8vvh-crhf/GHSA-vw4m-8vvh-crhf.json b/advisories/unreviewed/2022/05/GHSA-vw4m-8vvh-crhf/GHSA-vw4m-8vvh-crhf.json index 8143bc3e9dc..de160152371 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw4m-8vvh-crhf/GHSA-vw4m-8vvh-crhf.json +++ b/advisories/unreviewed/2022/05/GHSA-vw4m-8vvh-crhf/GHSA-vw4m-8vvh-crhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw86-rxwf-9vhm/GHSA-vw86-rxwf-9vhm.json b/advisories/unreviewed/2022/05/GHSA-vw86-rxwf-9vhm/GHSA-vw86-rxwf-9vhm.json index c827dfcff19..26a5277637a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw86-rxwf-9vhm/GHSA-vw86-rxwf-9vhm.json +++ b/advisories/unreviewed/2022/05/GHSA-vw86-rxwf-9vhm/GHSA-vw86-rxwf-9vhm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw92-7p2v-77xf/GHSA-vw92-7p2v-77xf.json b/advisories/unreviewed/2022/05/GHSA-vw92-7p2v-77xf/GHSA-vw92-7p2v-77xf.json index 0983ce40535..6c29bc0d718 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw92-7p2v-77xf/GHSA-vw92-7p2v-77xf.json +++ b/advisories/unreviewed/2022/05/GHSA-vw92-7p2v-77xf/GHSA-vw92-7p2v-77xf.json @@ -7,12 +7,8 @@ "CVE-2014-4964" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for requests that change (2) customer passwords, (3) shop configuration, or (4) product details, as demonstrated by (5) modify a product's price via a crafted request to central/catalog/saveproduct.action or (6) creating a product review via a crafted request to shop/product/createReview.action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwhm-7462-cm54/GHSA-vwhm-7462-cm54.json b/advisories/unreviewed/2022/05/GHSA-vwhm-7462-cm54/GHSA-vwhm-7462-cm54.json index 05d4646bff2..0e14e12371d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwhm-7462-cm54/GHSA-vwhm-7462-cm54.json +++ b/advisories/unreviewed/2022/05/GHSA-vwhm-7462-cm54/GHSA-vwhm-7462-cm54.json @@ -7,12 +7,8 @@ "CVE-2014-4250" ], "details": "Unspecified vulnerability in the Siebel Core - Server OM Frwks component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Object Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vx7g-39p9-2r2g/GHSA-vx7g-39p9-2r2g.json b/advisories/unreviewed/2022/05/GHSA-vx7g-39p9-2r2g/GHSA-vx7g-39p9-2r2g.json index a4032a29af1..97c39e06a74 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx7g-39p9-2r2g/GHSA-vx7g-39p9-2r2g.json +++ b/advisories/unreviewed/2022/05/GHSA-vx7g-39p9-2r2g/GHSA-vx7g-39p9-2r2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxv7-q37g-hwv2/GHSA-vxv7-q37g-hwv2.json b/advisories/unreviewed/2022/05/GHSA-vxv7-q37g-hwv2/GHSA-vxv7-q37g-hwv2.json index d7660f9053d..4b8fe0857ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxv7-q37g-hwv2/GHSA-vxv7-q37g-hwv2.json +++ b/advisories/unreviewed/2022/05/GHSA-vxv7-q37g-hwv2/GHSA-vxv7-q37g-hwv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w26c-gw69-r33c/GHSA-w26c-gw69-r33c.json b/advisories/unreviewed/2022/05/GHSA-w26c-gw69-r33c/GHSA-w26c-gw69-r33c.json index c51154d8c68..0857f6b2277 100644 --- a/advisories/unreviewed/2022/05/GHSA-w26c-gw69-r33c/GHSA-w26c-gw69-r33c.json +++ b/advisories/unreviewed/2022/05/GHSA-w26c-gw69-r33c/GHSA-w26c-gw69-r33c.json @@ -7,12 +7,8 @@ "CVE-2014-9029" ], "details": "Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w28c-prr6-33rc/GHSA-w28c-prr6-33rc.json b/advisories/unreviewed/2022/05/GHSA-w28c-prr6-33rc/GHSA-w28c-prr6-33rc.json index 976824b35d0..5efa744a608 100644 --- a/advisories/unreviewed/2022/05/GHSA-w28c-prr6-33rc/GHSA-w28c-prr6-33rc.json +++ b/advisories/unreviewed/2022/05/GHSA-w28c-prr6-33rc/GHSA-w28c-prr6-33rc.json @@ -7,12 +7,8 @@ "CVE-2014-2988" ], "details": "EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w349-42x9-rx83/GHSA-w349-42x9-rx83.json b/advisories/unreviewed/2022/05/GHSA-w349-42x9-rx83/GHSA-w349-42x9-rx83.json index 89ea378d326..e94f5d9a4ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-w349-42x9-rx83/GHSA-w349-42x9-rx83.json +++ b/advisories/unreviewed/2022/05/GHSA-w349-42x9-rx83/GHSA-w349-42x9-rx83.json @@ -7,12 +7,8 @@ "CVE-2015-0866" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote attackers to inject arbitrary web script or HTML via the (1) fromCustomer, (2) username, or (3) password parameter to HomePage.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3v7-w92j-r88x/GHSA-w3v7-w92j-r88x.json b/advisories/unreviewed/2022/05/GHSA-w3v7-w92j-r88x/GHSA-w3v7-w92j-r88x.json index f0c2ee46ad4..c4285e87cbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3v7-w92j-r88x/GHSA-w3v7-w92j-r88x.json +++ b/advisories/unreviewed/2022/05/GHSA-w3v7-w92j-r88x/GHSA-w3v7-w92j-r88x.json @@ -7,12 +7,8 @@ "CVE-2015-1480" ], "details": "ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w524-fgjq-fxjr/GHSA-w524-fgjq-fxjr.json b/advisories/unreviewed/2022/05/GHSA-w524-fgjq-fxjr/GHSA-w524-fgjq-fxjr.json index 34be3d8f0cd..6b237f0e563 100644 --- a/advisories/unreviewed/2022/05/GHSA-w524-fgjq-fxjr/GHSA-w524-fgjq-fxjr.json +++ b/advisories/unreviewed/2022/05/GHSA-w524-fgjq-fxjr/GHSA-w524-fgjq-fxjr.json @@ -7,12 +7,8 @@ "CVE-2014-3920" ], "details": "Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5j7-j9wm-9x8q/GHSA-w5j7-j9wm-9x8q.json b/advisories/unreviewed/2022/05/GHSA-w5j7-j9wm-9x8q/GHSA-w5j7-j9wm-9x8q.json index 0919f5e2d16..3ccf5ed9525 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5j7-j9wm-9x8q/GHSA-w5j7-j9wm-9x8q.json +++ b/advisories/unreviewed/2022/05/GHSA-w5j7-j9wm-9x8q/GHSA-w5j7-j9wm-9x8q.json @@ -7,12 +7,8 @@ "CVE-2011-5106" ], "details": "Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w674-3mq5-fw7c/GHSA-w674-3mq5-fw7c.json b/advisories/unreviewed/2022/05/GHSA-w674-3mq5-fw7c/GHSA-w674-3mq5-fw7c.json index 5eb0483c5f5..e2106a8c803 100644 --- a/advisories/unreviewed/2022/05/GHSA-w674-3mq5-fw7c/GHSA-w674-3mq5-fw7c.json +++ b/advisories/unreviewed/2022/05/GHSA-w674-3mq5-fw7c/GHSA-w674-3mq5-fw7c.json @@ -7,12 +7,8 @@ "CVE-2014-4046" ], "details": "Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6h9-j4f8-48wx/GHSA-w6h9-j4f8-48wx.json b/advisories/unreviewed/2022/05/GHSA-w6h9-j4f8-48wx/GHSA-w6h9-j4f8-48wx.json index 85aca93084b..182edb79751 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6h9-j4f8-48wx/GHSA-w6h9-j4f8-48wx.json +++ b/advisories/unreviewed/2022/05/GHSA-w6h9-j4f8-48wx/GHSA-w6h9-j4f8-48wx.json @@ -7,12 +7,8 @@ "CVE-2014-2456" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise ELS Enterprise Learning Management component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6v8-ffc7-5f5p/GHSA-w6v8-ffc7-5f5p.json b/advisories/unreviewed/2022/05/GHSA-w6v8-ffc7-5f5p/GHSA-w6v8-ffc7-5f5p.json index 99757ebd435..6ee6638566f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6v8-ffc7-5f5p/GHSA-w6v8-ffc7-5f5p.json +++ b/advisories/unreviewed/2022/05/GHSA-w6v8-ffc7-5f5p/GHSA-w6v8-ffc7-5f5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w74x-482v-qgx3/GHSA-w74x-482v-qgx3.json b/advisories/unreviewed/2022/05/GHSA-w74x-482v-qgx3/GHSA-w74x-482v-qgx3.json index d03a198fd6e..c7c3dc38673 100644 --- a/advisories/unreviewed/2022/05/GHSA-w74x-482v-qgx3/GHSA-w74x-482v-qgx3.json +++ b/advisories/unreviewed/2022/05/GHSA-w74x-482v-qgx3/GHSA-w74x-482v-qgx3.json @@ -7,12 +7,8 @@ "CVE-2015-0516" ], "details": "Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7vx-gpvr-f5cg/GHSA-w7vx-gpvr-f5cg.json b/advisories/unreviewed/2022/05/GHSA-w7vx-gpvr-f5cg/GHSA-w7vx-gpvr-f5cg.json index 223a1af44a4..0f2d16927dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7vx-gpvr-f5cg/GHSA-w7vx-gpvr-f5cg.json +++ b/advisories/unreviewed/2022/05/GHSA-w7vx-gpvr-f5cg/GHSA-w7vx-gpvr-f5cg.json @@ -7,12 +7,8 @@ "CVE-2014-7186" ], "details": "The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the \"redir_stack\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8c6-3v55-x3f2/GHSA-w8c6-3v55-x3f2.json b/advisories/unreviewed/2022/05/GHSA-w8c6-3v55-x3f2/GHSA-w8c6-3v55-x3f2.json index 0e5e07cc63e..a020afd9d53 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8c6-3v55-x3f2/GHSA-w8c6-3v55-x3f2.json +++ b/advisories/unreviewed/2022/05/GHSA-w8c6-3v55-x3f2/GHSA-w8c6-3v55-x3f2.json @@ -7,12 +7,8 @@ "CVE-2014-5338" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) render_status_icons function in htmllib.py or (2) ajax_action function in actions.py.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg8v-cggr-5vm6/GHSA-wg8v-cggr-5vm6.json b/advisories/unreviewed/2022/05/GHSA-wg8v-cggr-5vm6/GHSA-wg8v-cggr-5vm6.json index d19737a6ba1..89b23a001be 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg8v-cggr-5vm6/GHSA-wg8v-cggr-5vm6.json +++ b/advisories/unreviewed/2022/05/GHSA-wg8v-cggr-5vm6/GHSA-wg8v-cggr-5vm6.json @@ -7,12 +7,8 @@ "CVE-2014-0868" ], "details": "RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whf2-4g7v-9wcm/GHSA-whf2-4g7v-9wcm.json b/advisories/unreviewed/2022/05/GHSA-whf2-4g7v-9wcm/GHSA-whf2-4g7v-9wcm.json index 886769dcee9..0c29c8dedb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-whf2-4g7v-9wcm/GHSA-whf2-4g7v-9wcm.json +++ b/advisories/unreviewed/2022/05/GHSA-whf2-4g7v-9wcm/GHSA-whf2-4g7v-9wcm.json @@ -7,12 +7,8 @@ "CVE-2014-9352" ], "details": "Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjvw-6gq9-r937/GHSA-wjvw-6gq9-r937.json b/advisories/unreviewed/2022/05/GHSA-wjvw-6gq9-r937/GHSA-wjvw-6gq9-r937.json index b0c3ebfc44d..f7d18e912ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjvw-6gq9-r937/GHSA-wjvw-6gq9-r937.json +++ b/advisories/unreviewed/2022/05/GHSA-wjvw-6gq9-r937/GHSA-wjvw-6gq9-r937.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmhj-xgr4-2hgx/GHSA-wmhj-xgr4-2hgx.json b/advisories/unreviewed/2022/05/GHSA-wmhj-xgr4-2hgx/GHSA-wmhj-xgr4-2hgx.json index a894142faaa..7f7d4bfd4d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmhj-xgr4-2hgx/GHSA-wmhj-xgr4-2hgx.json +++ b/advisories/unreviewed/2022/05/GHSA-wmhj-xgr4-2hgx/GHSA-wmhj-xgr4-2hgx.json @@ -7,12 +7,8 @@ "CVE-2014-4629" ], "details": "EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via unspecified vectors related to an insecure direct object reference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrfx-rw96-gwf3/GHSA-wrfx-rw96-gwf3.json b/advisories/unreviewed/2022/05/GHSA-wrfx-rw96-gwf3/GHSA-wrfx-rw96-gwf3.json index bfa47e9e57b..78dbd620a2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrfx-rw96-gwf3/GHSA-wrfx-rw96-gwf3.json +++ b/advisories/unreviewed/2022/05/GHSA-wrfx-rw96-gwf3/GHSA-wrfx-rw96-gwf3.json @@ -7,12 +7,8 @@ "CVE-2014-8339" ], "details": "SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ch parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv5q-rqrc-8qwj/GHSA-wv5q-rqrc-8qwj.json b/advisories/unreviewed/2022/05/GHSA-wv5q-rqrc-8qwj/GHSA-wv5q-rqrc-8qwj.json index 2b3321f4936..75defff558f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv5q-rqrc-8qwj/GHSA-wv5q-rqrc-8qwj.json +++ b/advisories/unreviewed/2022/05/GHSA-wv5q-rqrc-8qwj/GHSA-wv5q-rqrc-8qwj.json @@ -7,12 +7,8 @@ "CVE-2014-8311" ], "details": "SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvc9-6xq9-f3hx/GHSA-wvc9-6xq9-f3hx.json b/advisories/unreviewed/2022/05/GHSA-wvc9-6xq9-f3hx/GHSA-wvc9-6xq9-f3hx.json index 05b8d3487aa..1e846a2158d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvc9-6xq9-f3hx/GHSA-wvc9-6xq9-f3hx.json +++ b/advisories/unreviewed/2022/05/GHSA-wvc9-6xq9-f3hx/GHSA-wvc9-6xq9-f3hx.json @@ -7,12 +7,8 @@ "CVE-2014-9144" ], "details": "Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx46-225g-678j/GHSA-wx46-225g-678j.json b/advisories/unreviewed/2022/05/GHSA-wx46-225g-678j/GHSA-wx46-225g-678j.json index 9ff97d63686..292522f2244 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx46-225g-678j/GHSA-wx46-225g-678j.json +++ b/advisories/unreviewed/2022/05/GHSA-wx46-225g-678j/GHSA-wx46-225g-678j.json @@ -7,12 +7,8 @@ "CVE-2014-2040" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer plugin 1.7.0 for WordPress allow remote authenticated users with permissions to add media or edit media to inject arbitrary web script or HTML via unspecified parameters, as demonstrated by the title of an uploaded file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx6m-r4jc-mfvw/GHSA-wx6m-r4jc-mfvw.json b/advisories/unreviewed/2022/05/GHSA-wx6m-r4jc-mfvw/GHSA-wx6m-r4jc-mfvw.json index c780f4d9df7..a08d1f494f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx6m-r4jc-mfvw/GHSA-wx6m-r4jc-mfvw.json +++ b/advisories/unreviewed/2022/05/GHSA-wx6m-r4jc-mfvw/GHSA-wx6m-r4jc-mfvw.json @@ -7,12 +7,8 @@ "CVE-2014-0894" ], "details": "RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx86-c74j-r585/GHSA-wx86-c74j-r585.json b/advisories/unreviewed/2022/05/GHSA-wx86-c74j-r585/GHSA-wx86-c74j-r585.json index 5dc060feba9..58af0beb293 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx86-c74j-r585/GHSA-wx86-c74j-r585.json +++ b/advisories/unreviewed/2022/05/GHSA-wx86-c74j-r585/GHSA-wx86-c74j-r585.json @@ -7,12 +7,8 @@ "CVE-2014-1201" ], "details": "Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx8f-7wmv-f3cq/GHSA-wx8f-7wmv-f3cq.json b/advisories/unreviewed/2022/05/GHSA-wx8f-7wmv-f3cq/GHSA-wx8f-7wmv-f3cq.json index b5ef3e967a1..6d5a21a9e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx8f-7wmv-f3cq/GHSA-wx8f-7wmv-f3cq.json +++ b/advisories/unreviewed/2022/05/GHSA-wx8f-7wmv-f3cq/GHSA-wx8f-7wmv-f3cq.json @@ -7,12 +7,8 @@ "CVE-2014-2735" ], "details": "WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxfw-gh9x-v224/GHSA-wxfw-gh9x-v224.json b/advisories/unreviewed/2022/05/GHSA-wxfw-gh9x-v224/GHSA-wxfw-gh9x-v224.json index 4ef1ac44781..fc115ef0c0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxfw-gh9x-v224/GHSA-wxfw-gh9x-v224.json +++ b/advisories/unreviewed/2022/05/GHSA-wxfw-gh9x-v224/GHSA-wxfw-gh9x-v224.json @@ -7,12 +7,8 @@ "CVE-2011-4063" ], "details": "chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authenticated users to cause a denial of service (daemon crash) via a malformed request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2jp-jqfx-wrjx/GHSA-x2jp-jqfx-wrjx.json b/advisories/unreviewed/2022/05/GHSA-x2jp-jqfx-wrjx/GHSA-x2jp-jqfx-wrjx.json index a9991e2f7e8..e52679455bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2jp-jqfx-wrjx/GHSA-x2jp-jqfx-wrjx.json +++ b/advisories/unreviewed/2022/05/GHSA-x2jp-jqfx-wrjx/GHSA-x2jp-jqfx-wrjx.json @@ -7,12 +7,8 @@ "CVE-2015-0524" ], "details": "SQL injection vulnerability in the Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2mw-2wgh-5r92/GHSA-x2mw-2wgh-5r92.json b/advisories/unreviewed/2022/05/GHSA-x2mw-2wgh-5r92/GHSA-x2mw-2wgh-5r92.json index 474127e0d0f..2313ec26b77 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2mw-2wgh-5r92/GHSA-x2mw-2wgh-5r92.json +++ b/advisories/unreviewed/2022/05/GHSA-x2mw-2wgh-5r92/GHSA-x2mw-2wgh-5r92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x33f-8jwv-mmx3/GHSA-x33f-8jwv-mmx3.json b/advisories/unreviewed/2022/05/GHSA-x33f-8jwv-mmx3/GHSA-x33f-8jwv-mmx3.json index 12f741bab0f..b24daba746b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x33f-8jwv-mmx3/GHSA-x33f-8jwv-mmx3.json +++ b/advisories/unreviewed/2022/05/GHSA-x33f-8jwv-mmx3/GHSA-x33f-8jwv-mmx3.json @@ -7,12 +7,8 @@ "CVE-2015-1384" ], "details": "Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3f3-q6x5-f4rj/GHSA-x3f3-q6x5-f4rj.json b/advisories/unreviewed/2022/05/GHSA-x3f3-q6x5-f4rj/GHSA-x3f3-q6x5-f4rj.json index eb0d15353c4..95a8d93d4f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3f3-q6x5-f4rj/GHSA-x3f3-q6x5-f4rj.json +++ b/advisories/unreviewed/2022/05/GHSA-x3f3-q6x5-f4rj/GHSA-x3f3-q6x5-f4rj.json @@ -7,12 +7,8 @@ "CVE-2014-4239" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Common Agent Container (Cacao).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x552-vw23-hqr2/GHSA-x552-vw23-hqr2.json b/advisories/unreviewed/2022/05/GHSA-x552-vw23-hqr2/GHSA-x552-vw23-hqr2.json index e106e4cd7ad..da4bb050075 100644 --- a/advisories/unreviewed/2022/05/GHSA-x552-vw23-hqr2/GHSA-x552-vw23-hqr2.json +++ b/advisories/unreviewed/2022/05/GHSA-x552-vw23-hqr2/GHSA-x552-vw23-hqr2.json @@ -7,12 +7,8 @@ "CVE-2014-4201" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect availability via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x63c-rx8f-jqj7/GHSA-x63c-rx8f-jqj7.json b/advisories/unreviewed/2022/05/GHSA-x63c-rx8f-jqj7/GHSA-x63c-rx8f-jqj7.json index 219afb19873..0cbaed01826 100644 --- a/advisories/unreviewed/2022/05/GHSA-x63c-rx8f-jqj7/GHSA-x63c-rx8f-jqj7.json +++ b/advisories/unreviewed/2022/05/GHSA-x63c-rx8f-jqj7/GHSA-x63c-rx8f-jqj7.json @@ -7,12 +7,8 @@ "CVE-2011-5181" ], "details": "Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6mp-mr6c-vfjv/GHSA-x6mp-mr6c-vfjv.json b/advisories/unreviewed/2022/05/GHSA-x6mp-mr6c-vfjv/GHSA-x6mp-mr6c-vfjv.json index 075eff232d0..3d67ccf6a50 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6mp-mr6c-vfjv/GHSA-x6mp-mr6c-vfjv.json +++ b/advisories/unreviewed/2022/05/GHSA-x6mp-mr6c-vfjv/GHSA-x6mp-mr6c-vfjv.json @@ -7,12 +7,8 @@ "CVE-2014-2488" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality via unknown vectors related to Core.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x72w-3hm9-7xcv/GHSA-x72w-3hm9-7xcv.json b/advisories/unreviewed/2022/05/GHSA-x72w-3hm9-7xcv/GHSA-x72w-3hm9-7xcv.json index ffb26fd2ca2..e76992864a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x72w-3hm9-7xcv/GHSA-x72w-3hm9-7xcv.json +++ b/advisories/unreviewed/2022/05/GHSA-x72w-3hm9-7xcv/GHSA-x72w-3hm9-7xcv.json @@ -7,12 +7,8 @@ "CVE-2014-3749" ], "details": "SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x77r-9j3c-w6wj/GHSA-x77r-9j3c-w6wj.json b/advisories/unreviewed/2022/05/GHSA-x77r-9j3c-w6wj/GHSA-x77r-9j3c-w6wj.json index a8af05d89cd..4f9e4439174 100644 --- a/advisories/unreviewed/2022/05/GHSA-x77r-9j3c-w6wj/GHSA-x77r-9j3c-w6wj.json +++ b/advisories/unreviewed/2022/05/GHSA-x77r-9j3c-w6wj/GHSA-x77r-9j3c-w6wj.json @@ -7,12 +7,8 @@ "CVE-2014-2178" ], "details": "Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to hijack the authentication of administrators, aka Bug ID CSCuh87145.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x88f-9639-h9vx/GHSA-x88f-9639-h9vx.json b/advisories/unreviewed/2022/05/GHSA-x88f-9639-h9vx/GHSA-x88f-9639-h9vx.json index df47604d3ce..0e71fa75933 100644 --- a/advisories/unreviewed/2022/05/GHSA-x88f-9639-h9vx/GHSA-x88f-9639-h9vx.json +++ b/advisories/unreviewed/2022/05/GHSA-x88f-9639-h9vx/GHSA-x88f-9639-h9vx.json @@ -7,12 +7,8 @@ "CVE-2014-2035" ], "details": "Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.13 build 574 allows remote attackers to inject arbitrary web script or HTML via the i parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x88v-hq24-c79w/GHSA-x88v-hq24-c79w.json b/advisories/unreviewed/2022/05/GHSA-x88v-hq24-c79w/GHSA-x88v-hq24-c79w.json index 51b7d784fcc..c0c1183ff7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x88v-hq24-c79w/GHSA-x88v-hq24-c79w.json +++ b/advisories/unreviewed/2022/05/GHSA-x88v-hq24-c79w/GHSA-x88v-hq24-c79w.json @@ -7,12 +7,8 @@ "CVE-2014-4269" ], "details": "Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a different vulnerability than CVE-2014-4270.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8hq-gmcw-28cp/GHSA-x8hq-gmcw-28cp.json b/advisories/unreviewed/2022/05/GHSA-x8hq-gmcw-28cp/GHSA-x8hq-gmcw-28cp.json index fb86efca0c1..7b3c3cc73b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8hq-gmcw-28cp/GHSA-x8hq-gmcw-28cp.json +++ b/advisories/unreviewed/2022/05/GHSA-x8hq-gmcw-28cp/GHSA-x8hq-gmcw-28cp.json @@ -7,12 +7,8 @@ "CVE-2014-8084" ], "details": "Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ajaxfile parameter in a custom action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x939-2wmx-j42c/GHSA-x939-2wmx-j42c.json b/advisories/unreviewed/2022/05/GHSA-x939-2wmx-j42c/GHSA-x939-2wmx-j42c.json index d33e02ebfd1..55ef83dedf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x939-2wmx-j42c/GHSA-x939-2wmx-j42c.json +++ b/advisories/unreviewed/2022/05/GHSA-x939-2wmx-j42c/GHSA-x939-2wmx-j42c.json @@ -7,12 +7,8 @@ "CVE-2013-3774" ], "details": "Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcr5-rqr5-57fx/GHSA-xcr5-rqr5-57fx.json b/advisories/unreviewed/2022/05/GHSA-xcr5-rqr5-57fx/GHSA-xcr5-rqr5-57fx.json index 0f6116f44d1..d9a4d2fb673 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcr5-rqr5-57fx/GHSA-xcr5-rqr5-57fx.json +++ b/advisories/unreviewed/2022/05/GHSA-xcr5-rqr5-57fx/GHSA-xcr5-rqr5-57fx.json @@ -7,12 +7,8 @@ "CVE-2014-2506" ], "details": "EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg87-92r7-2r8m/GHSA-xg87-92r7-2r8m.json b/advisories/unreviewed/2022/05/GHSA-xg87-92r7-2r8m/GHSA-xg87-92r7-2r8m.json index c58e1438308..7d2c57d3640 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg87-92r7-2r8m/GHSA-xg87-92r7-2r8m.json +++ b/advisories/unreviewed/2022/05/GHSA-xg87-92r7-2r8m/GHSA-xg87-92r7-2r8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh2h-cw6h-x9h5/GHSA-xh2h-cw6h-x9h5.json b/advisories/unreviewed/2022/05/GHSA-xh2h-cw6h-x9h5/GHSA-xh2h-cw6h-x9h5.json index 00254efdfa7..fec20f43584 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh2h-cw6h-x9h5/GHSA-xh2h-cw6h-x9h5.json +++ b/advisories/unreviewed/2022/05/GHSA-xh2h-cw6h-x9h5/GHSA-xh2h-cw6h-x9h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj4p-rw86-6466/GHSA-xj4p-rw86-6466.json b/advisories/unreviewed/2022/05/GHSA-xj4p-rw86-6466/GHSA-xj4p-rw86-6466.json index bd815c4fe7c..f36d597bfaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj4p-rw86-6466/GHSA-xj4p-rw86-6466.json +++ b/advisories/unreviewed/2022/05/GHSA-xj4p-rw86-6466/GHSA-xj4p-rw86-6466.json @@ -7,12 +7,8 @@ "CVE-2015-1415" ], "details": "The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj87-q393-fjr7/GHSA-xj87-q393-fjr7.json b/advisories/unreviewed/2022/05/GHSA-xj87-q393-fjr7/GHSA-xj87-q393-fjr7.json index b37af2bfe65..ea103529d1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj87-q393-fjr7/GHSA-xj87-q393-fjr7.json +++ b/advisories/unreviewed/2022/05/GHSA-xj87-q393-fjr7/GHSA-xj87-q393-fjr7.json @@ -7,12 +7,8 @@ "CVE-2014-8340" ], "details": "SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm3g-p25r-3qrv/GHSA-xm3g-p25r-3qrv.json b/advisories/unreviewed/2022/05/GHSA-xm3g-p25r-3qrv/GHSA-xm3g-p25r-3qrv.json index 9871eeb5cb5..e8d434f2d6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm3g-p25r-3qrv/GHSA-xm3g-p25r-3qrv.json +++ b/advisories/unreviewed/2022/05/GHSA-xm3g-p25r-3qrv/GHSA-xm3g-p25r-3qrv.json @@ -7,12 +7,8 @@ "CVE-2014-6315" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmx2-q3rp-q8fq/GHSA-xmx2-q3rp-q8fq.json b/advisories/unreviewed/2022/05/GHSA-xmx2-q3rp-q8fq/GHSA-xmx2-q3rp-q8fq.json index 9e7bff2fdfb..dba5f8dc866 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmx2-q3rp-q8fq/GHSA-xmx2-q3rp-q8fq.json +++ b/advisories/unreviewed/2022/05/GHSA-xmx2-q3rp-q8fq/GHSA-xmx2-q3rp-q8fq.json @@ -7,12 +7,8 @@ "CVE-2014-7985" ], "details": "Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xq3m-6r9g-r79r/GHSA-xq3m-6r9g-r79r.json b/advisories/unreviewed/2022/05/GHSA-xq3m-6r9g-r79r/GHSA-xq3m-6r9g-r79r.json index 226516e2ef9..1457bdd5208 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq3m-6r9g-r79r/GHSA-xq3m-6r9g-r79r.json +++ b/advisories/unreviewed/2022/05/GHSA-xq3m-6r9g-r79r/GHSA-xq3m-6r9g-r79r.json @@ -7,12 +7,8 @@ "CVE-2014-4202" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect availability via vectors related to WLS - Web Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xq88-f43j-jg6v/GHSA-xq88-f43j-jg6v.json b/advisories/unreviewed/2022/05/GHSA-xq88-f43j-jg6v/GHSA-xq88-f43j-jg6v.json index 7650dd3c013..8ed3fac2c7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq88-f43j-jg6v/GHSA-xq88-f43j-jg6v.json +++ b/advisories/unreviewed/2022/05/GHSA-xq88-f43j-jg6v/GHSA-xq88-f43j-jg6v.json @@ -7,12 +7,8 @@ "CVE-2015-1514" ], "details": "Multiple SQL injection vulnerabilities in FancyFon FAMOC before 3.17.4 allow (1) remote attackers to execute arbitrary SQL commands via the device ID REST parameter (PATH_INFO) to /ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the order parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqh5-468j-8666/GHSA-xqh5-468j-8666.json b/advisories/unreviewed/2022/05/GHSA-xqh5-468j-8666/GHSA-xqh5-468j-8666.json index ecfca73b897..6f18f9e6f0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqh5-468j-8666/GHSA-xqh5-468j-8666.json +++ b/advisories/unreviewed/2022/05/GHSA-xqh5-468j-8666/GHSA-xqh5-468j-8666.json @@ -7,12 +7,8 @@ "CVE-2014-8308" ], "details": "Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqhj-rm5r-mj4q/GHSA-xqhj-rm5r-mj4q.json b/advisories/unreviewed/2022/05/GHSA-xqhj-rm5r-mj4q/GHSA-xqhj-rm5r-mj4q.json index 2fab7a55890..9e3bbf45ebb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqhj-rm5r-mj4q/GHSA-xqhj-rm5r-mj4q.json +++ b/advisories/unreviewed/2022/05/GHSA-xqhj-rm5r-mj4q/GHSA-xqhj-rm5r-mj4q.json @@ -7,12 +7,8 @@ "CVE-2014-0914" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management for IT and Maximo Service Desk allows remote authenticated users to inject arbitrary web script or HTML via the Query Description Field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqwg-mwmp-6pp4/GHSA-xqwg-mwmp-6pp4.json b/advisories/unreviewed/2022/05/GHSA-xqwg-mwmp-6pp4/GHSA-xqwg-mwmp-6pp4.json index e3554309b6e..bd9be0a3dac 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqwg-mwmp-6pp4/GHSA-xqwg-mwmp-6pp4.json +++ b/advisories/unreviewed/2022/05/GHSA-xqwg-mwmp-6pp4/GHSA-xqwg-mwmp-6pp4.json @@ -7,12 +7,8 @@ "CVE-2014-2540" ], "details": "SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqwg-v65r-hvf2/GHSA-xqwg-v65r-hvf2.json b/advisories/unreviewed/2022/05/GHSA-xqwg-v65r-hvf2/GHSA-xqwg-v65r-hvf2.json index 82cc41c5c18..897bedd7bdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqwg-v65r-hvf2/GHSA-xqwg-v65r-hvf2.json +++ b/advisories/unreviewed/2022/05/GHSA-xqwg-v65r-hvf2/GHSA-xqwg-v65r-hvf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvm3-rxj9-vf93/GHSA-xvm3-rxj9-vf93.json b/advisories/unreviewed/2022/05/GHSA-xvm3-rxj9-vf93/GHSA-xvm3-rxj9-vf93.json index 916ecff2b63..61f6c0372f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvm3-rxj9-vf93/GHSA-xvm3-rxj9-vf93.json +++ b/advisories/unreviewed/2022/05/GHSA-xvm3-rxj9-vf93/GHSA-xvm3-rxj9-vf93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw4j-w9j3-qq6q/GHSA-xw4j-w9j3-qq6q.json b/advisories/unreviewed/2022/05/GHSA-xw4j-w9j3-qq6q/GHSA-xw4j-w9j3-qq6q.json index 5970fbe7801..f0af08bf94f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw4j-w9j3-qq6q/GHSA-xw4j-w9j3-qq6q.json +++ b/advisories/unreviewed/2022/05/GHSA-xw4j-w9j3-qq6q/GHSA-xw4j-w9j3-qq6q.json @@ -7,12 +7,8 @@ "CVE-2015-2703" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-WEB before 8.0.0 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via the (1) ws-userip in the ws-encdata parameter to cve-bin/moreBlockInfo.cgi in the Data Security block page or (2) admin_msg parameter to configure/ssl_ui/eva-config/client-cert-import_wsoem.html in the Content Gateway, which is not properly handled in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xx46-fhm6-qw2q/GHSA-xx46-fhm6-qw2q.json b/advisories/unreviewed/2022/05/GHSA-xx46-fhm6-qw2q/GHSA-xx46-fhm6-qw2q.json index 748cd29c9a5..ad310f253fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx46-fhm6-qw2q/GHSA-xx46-fhm6-qw2q.json +++ b/advisories/unreviewed/2022/05/GHSA-xx46-fhm6-qw2q/GHSA-xx46-fhm6-qw2q.json @@ -7,12 +7,8 @@ "CVE-2014-4261" ], "details": "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-53m8-xvh9-f42p/GHSA-53m8-xvh9-f42p.json b/advisories/unreviewed/2022/12/GHSA-53m8-xvh9-f42p/GHSA-53m8-xvh9-f42p.json index 6348c86dd54..9e0473fbb2a 100644 --- a/advisories/unreviewed/2022/12/GHSA-53m8-xvh9-f42p/GHSA-53m8-xvh9-f42p.json +++ b/advisories/unreviewed/2022/12/GHSA-53m8-xvh9-f42p/GHSA-53m8-xvh9-f42p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-544j-8m5v-3frm/GHSA-544j-8m5v-3frm.json b/advisories/unreviewed/2022/12/GHSA-544j-8m5v-3frm/GHSA-544j-8m5v-3frm.json index 9bfb4d3b069..648fed38ade 100644 --- a/advisories/unreviewed/2022/12/GHSA-544j-8m5v-3frm/GHSA-544j-8m5v-3frm.json +++ b/advisories/unreviewed/2022/12/GHSA-544j-8m5v-3frm/GHSA-544j-8m5v-3frm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-5c39-hcvq-5xxc/GHSA-5c39-hcvq-5xxc.json b/advisories/unreviewed/2022/12/GHSA-5c39-hcvq-5xxc/GHSA-5c39-hcvq-5xxc.json index 8d4da320a55..d2387cda2bd 100644 --- a/advisories/unreviewed/2022/12/GHSA-5c39-hcvq-5xxc/GHSA-5c39-hcvq-5xxc.json +++ b/advisories/unreviewed/2022/12/GHSA-5c39-hcvq-5xxc/GHSA-5c39-hcvq-5xxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-5p79-g28m-p2cr/GHSA-5p79-g28m-p2cr.json b/advisories/unreviewed/2022/12/GHSA-5p79-g28m-p2cr/GHSA-5p79-g28m-p2cr.json index cfa9515c8d4..e94b467c844 100644 --- a/advisories/unreviewed/2022/12/GHSA-5p79-g28m-p2cr/GHSA-5p79-g28m-p2cr.json +++ b/advisories/unreviewed/2022/12/GHSA-5p79-g28m-p2cr/GHSA-5p79-g28m-p2cr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-8vqv-gv6p-pjjr/GHSA-8vqv-gv6p-pjjr.json b/advisories/unreviewed/2022/12/GHSA-8vqv-gv6p-pjjr/GHSA-8vqv-gv6p-pjjr.json index 3a6be9d5f3e..1f1c9afab17 100644 --- a/advisories/unreviewed/2022/12/GHSA-8vqv-gv6p-pjjr/GHSA-8vqv-gv6p-pjjr.json +++ b/advisories/unreviewed/2022/12/GHSA-8vqv-gv6p-pjjr/GHSA-8vqv-gv6p-pjjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-f7fg-v9hq-5m57/GHSA-f7fg-v9hq-5m57.json b/advisories/unreviewed/2022/12/GHSA-f7fg-v9hq-5m57/GHSA-f7fg-v9hq-5m57.json index d9a4243c87a..848da438b94 100644 --- a/advisories/unreviewed/2022/12/GHSA-f7fg-v9hq-5m57/GHSA-f7fg-v9hq-5m57.json +++ b/advisories/unreviewed/2022/12/GHSA-f7fg-v9hq-5m57/GHSA-f7fg-v9hq-5m57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-fchc-223x-3cpc/GHSA-fchc-223x-3cpc.json b/advisories/unreviewed/2022/12/GHSA-fchc-223x-3cpc/GHSA-fchc-223x-3cpc.json index 45d9f11a354..22421d7cf78 100644 --- a/advisories/unreviewed/2022/12/GHSA-fchc-223x-3cpc/GHSA-fchc-223x-3cpc.json +++ b/advisories/unreviewed/2022/12/GHSA-fchc-223x-3cpc/GHSA-fchc-223x-3cpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json b/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json index 53012dff17e..031c5618c26 100644 --- a/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json +++ b/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-m2x4-w9m7-wcwm/GHSA-m2x4-w9m7-wcwm.json b/advisories/unreviewed/2022/12/GHSA-m2x4-w9m7-wcwm/GHSA-m2x4-w9m7-wcwm.json index eb222018a96..4b50c7a0202 100644 --- a/advisories/unreviewed/2022/12/GHSA-m2x4-w9m7-wcwm/GHSA-m2x4-w9m7-wcwm.json +++ b/advisories/unreviewed/2022/12/GHSA-m2x4-w9m7-wcwm/GHSA-m2x4-w9m7-wcwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-m8q3-f9r8-5rqr/GHSA-m8q3-f9r8-5rqr.json b/advisories/unreviewed/2022/12/GHSA-m8q3-f9r8-5rqr/GHSA-m8q3-f9r8-5rqr.json index ce97996b2a7..8c4b5c8e484 100644 --- a/advisories/unreviewed/2022/12/GHSA-m8q3-f9r8-5rqr/GHSA-m8q3-f9r8-5rqr.json +++ b/advisories/unreviewed/2022/12/GHSA-m8q3-f9r8-5rqr/GHSA-m8q3-f9r8-5rqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-ph8f-7wjw-g922/GHSA-ph8f-7wjw-g922.json b/advisories/unreviewed/2022/12/GHSA-ph8f-7wjw-g922/GHSA-ph8f-7wjw-g922.json index 52f2446331f..9617ad38fb7 100644 --- a/advisories/unreviewed/2022/12/GHSA-ph8f-7wjw-g922/GHSA-ph8f-7wjw-g922.json +++ b/advisories/unreviewed/2022/12/GHSA-ph8f-7wjw-g922/GHSA-ph8f-7wjw-g922.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-q39q-7726-rg48/GHSA-q39q-7726-rg48.json b/advisories/unreviewed/2022/12/GHSA-q39q-7726-rg48/GHSA-q39q-7726-rg48.json index 70fcf31fa2e..b2492cf9679 100644 --- a/advisories/unreviewed/2022/12/GHSA-q39q-7726-rg48/GHSA-q39q-7726-rg48.json +++ b/advisories/unreviewed/2022/12/GHSA-q39q-7726-rg48/GHSA-q39q-7726-rg48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json b/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json index 25622024bc9..f3b6381356c 100644 --- a/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json +++ b/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-237f-7hfc-5r9q/GHSA-237f-7hfc-5r9q.json b/advisories/unreviewed/2023/01/GHSA-237f-7hfc-5r9q/GHSA-237f-7hfc-5r9q.json index fdc223827a2..253c5e78e9c 100644 --- a/advisories/unreviewed/2023/01/GHSA-237f-7hfc-5r9q/GHSA-237f-7hfc-5r9q.json +++ b/advisories/unreviewed/2023/01/GHSA-237f-7hfc-5r9q/GHSA-237f-7hfc-5r9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-243r-cwrc-8j8h/GHSA-243r-cwrc-8j8h.json b/advisories/unreviewed/2023/01/GHSA-243r-cwrc-8j8h/GHSA-243r-cwrc-8j8h.json index 5f8675170b2..018f0ab3255 100644 --- a/advisories/unreviewed/2023/01/GHSA-243r-cwrc-8j8h/GHSA-243r-cwrc-8j8h.json +++ b/advisories/unreviewed/2023/01/GHSA-243r-cwrc-8j8h/GHSA-243r-cwrc-8j8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-28v3-9vqx-2v5f/GHSA-28v3-9vqx-2v5f.json b/advisories/unreviewed/2023/01/GHSA-28v3-9vqx-2v5f/GHSA-28v3-9vqx-2v5f.json index 83c16deeb0e..28c82ed6f41 100644 --- a/advisories/unreviewed/2023/01/GHSA-28v3-9vqx-2v5f/GHSA-28v3-9vqx-2v5f.json +++ b/advisories/unreviewed/2023/01/GHSA-28v3-9vqx-2v5f/GHSA-28v3-9vqx-2v5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-3p9v-8h44-8rrr/GHSA-3p9v-8h44-8rrr.json b/advisories/unreviewed/2023/01/GHSA-3p9v-8h44-8rrr/GHSA-3p9v-8h44-8rrr.json index 02b7c62d6ee..43283b0fa34 100644 --- a/advisories/unreviewed/2023/01/GHSA-3p9v-8h44-8rrr/GHSA-3p9v-8h44-8rrr.json +++ b/advisories/unreviewed/2023/01/GHSA-3p9v-8h44-8rrr/GHSA-3p9v-8h44-8rrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-48w7-7v5c-hxxv/GHSA-48w7-7v5c-hxxv.json b/advisories/unreviewed/2023/01/GHSA-48w7-7v5c-hxxv/GHSA-48w7-7v5c-hxxv.json index 637b70c02fa..668bf03642e 100644 --- a/advisories/unreviewed/2023/01/GHSA-48w7-7v5c-hxxv/GHSA-48w7-7v5c-hxxv.json +++ b/advisories/unreviewed/2023/01/GHSA-48w7-7v5c-hxxv/GHSA-48w7-7v5c-hxxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4p53-c8jq-g93h/GHSA-4p53-c8jq-g93h.json b/advisories/unreviewed/2023/01/GHSA-4p53-c8jq-g93h/GHSA-4p53-c8jq-g93h.json index 5d73a32589e..f779c086a26 100644 --- a/advisories/unreviewed/2023/01/GHSA-4p53-c8jq-g93h/GHSA-4p53-c8jq-g93h.json +++ b/advisories/unreviewed/2023/01/GHSA-4p53-c8jq-g93h/GHSA-4p53-c8jq-g93h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4qr3-39h9-qwp4/GHSA-4qr3-39h9-qwp4.json b/advisories/unreviewed/2023/01/GHSA-4qr3-39h9-qwp4/GHSA-4qr3-39h9-qwp4.json index be1c51b4fae..16cec8f9cd7 100644 --- a/advisories/unreviewed/2023/01/GHSA-4qr3-39h9-qwp4/GHSA-4qr3-39h9-qwp4.json +++ b/advisories/unreviewed/2023/01/GHSA-4qr3-39h9-qwp4/GHSA-4qr3-39h9-qwp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4w9j-m79h-8w8m/GHSA-4w9j-m79h-8w8m.json b/advisories/unreviewed/2023/01/GHSA-4w9j-m79h-8w8m/GHSA-4w9j-m79h-8w8m.json index 73c62fcc0c3..06adc75e3c3 100644 --- a/advisories/unreviewed/2023/01/GHSA-4w9j-m79h-8w8m/GHSA-4w9j-m79h-8w8m.json +++ b/advisories/unreviewed/2023/01/GHSA-4w9j-m79h-8w8m/GHSA-4w9j-m79h-8w8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4xhc-3779-5pc3/GHSA-4xhc-3779-5pc3.json b/advisories/unreviewed/2023/01/GHSA-4xhc-3779-5pc3/GHSA-4xhc-3779-5pc3.json index 6ccf7080af8..44467e71ae4 100644 --- a/advisories/unreviewed/2023/01/GHSA-4xhc-3779-5pc3/GHSA-4xhc-3779-5pc3.json +++ b/advisories/unreviewed/2023/01/GHSA-4xhc-3779-5pc3/GHSA-4xhc-3779-5pc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-5fp7-mmp5-2244/GHSA-5fp7-mmp5-2244.json b/advisories/unreviewed/2023/01/GHSA-5fp7-mmp5-2244/GHSA-5fp7-mmp5-2244.json index 2eaa576e8eb..47e67547c2c 100644 --- a/advisories/unreviewed/2023/01/GHSA-5fp7-mmp5-2244/GHSA-5fp7-mmp5-2244.json +++ b/advisories/unreviewed/2023/01/GHSA-5fp7-mmp5-2244/GHSA-5fp7-mmp5-2244.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-5qjc-pfh5-rxg4/GHSA-5qjc-pfh5-rxg4.json b/advisories/unreviewed/2023/01/GHSA-5qjc-pfh5-rxg4/GHSA-5qjc-pfh5-rxg4.json index 024f6874d7d..be50324d2ef 100644 --- a/advisories/unreviewed/2023/01/GHSA-5qjc-pfh5-rxg4/GHSA-5qjc-pfh5-rxg4.json +++ b/advisories/unreviewed/2023/01/GHSA-5qjc-pfh5-rxg4/GHSA-5qjc-pfh5-rxg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-62hr-4g8f-hg89/GHSA-62hr-4g8f-hg89.json b/advisories/unreviewed/2023/01/GHSA-62hr-4g8f-hg89/GHSA-62hr-4g8f-hg89.json index ca7c43690f9..25448f6603c 100644 --- a/advisories/unreviewed/2023/01/GHSA-62hr-4g8f-hg89/GHSA-62hr-4g8f-hg89.json +++ b/advisories/unreviewed/2023/01/GHSA-62hr-4g8f-hg89/GHSA-62hr-4g8f-hg89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-6394-jqhh-rg8r/GHSA-6394-jqhh-rg8r.json b/advisories/unreviewed/2023/01/GHSA-6394-jqhh-rg8r/GHSA-6394-jqhh-rg8r.json index 816a37a15a0..5fdc120f5ae 100644 --- a/advisories/unreviewed/2023/01/GHSA-6394-jqhh-rg8r/GHSA-6394-jqhh-rg8r.json +++ b/advisories/unreviewed/2023/01/GHSA-6394-jqhh-rg8r/GHSA-6394-jqhh-rg8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-64cg-x9wj-m2fx/GHSA-64cg-x9wj-m2fx.json b/advisories/unreviewed/2023/01/GHSA-64cg-x9wj-m2fx/GHSA-64cg-x9wj-m2fx.json index e614d00cc77..c75e21da6f0 100644 --- a/advisories/unreviewed/2023/01/GHSA-64cg-x9wj-m2fx/GHSA-64cg-x9wj-m2fx.json +++ b/advisories/unreviewed/2023/01/GHSA-64cg-x9wj-m2fx/GHSA-64cg-x9wj-m2fx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-67gv-rcgx-vp8h/GHSA-67gv-rcgx-vp8h.json b/advisories/unreviewed/2023/01/GHSA-67gv-rcgx-vp8h/GHSA-67gv-rcgx-vp8h.json index e6597a4fdce..deb244b862e 100644 --- a/advisories/unreviewed/2023/01/GHSA-67gv-rcgx-vp8h/GHSA-67gv-rcgx-vp8h.json +++ b/advisories/unreviewed/2023/01/GHSA-67gv-rcgx-vp8h/GHSA-67gv-rcgx-vp8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-6c7f-v79h-5rvh/GHSA-6c7f-v79h-5rvh.json b/advisories/unreviewed/2023/01/GHSA-6c7f-v79h-5rvh/GHSA-6c7f-v79h-5rvh.json index a890e481bb5..be77cb9258d 100644 --- a/advisories/unreviewed/2023/01/GHSA-6c7f-v79h-5rvh/GHSA-6c7f-v79h-5rvh.json +++ b/advisories/unreviewed/2023/01/GHSA-6c7f-v79h-5rvh/GHSA-6c7f-v79h-5rvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-747r-gwxx-f5r5/GHSA-747r-gwxx-f5r5.json b/advisories/unreviewed/2023/01/GHSA-747r-gwxx-f5r5/GHSA-747r-gwxx-f5r5.json index 3218964bb3b..fd3cbacc1fb 100644 --- a/advisories/unreviewed/2023/01/GHSA-747r-gwxx-f5r5/GHSA-747r-gwxx-f5r5.json +++ b/advisories/unreviewed/2023/01/GHSA-747r-gwxx-f5r5/GHSA-747r-gwxx-f5r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7pqh-wvpp-vpr2/GHSA-7pqh-wvpp-vpr2.json b/advisories/unreviewed/2023/01/GHSA-7pqh-wvpp-vpr2/GHSA-7pqh-wvpp-vpr2.json index dbc6c7e1bbf..cdbbff4c1ca 100644 --- a/advisories/unreviewed/2023/01/GHSA-7pqh-wvpp-vpr2/GHSA-7pqh-wvpp-vpr2.json +++ b/advisories/unreviewed/2023/01/GHSA-7pqh-wvpp-vpr2/GHSA-7pqh-wvpp-vpr2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7r7m-9r2x-mccm/GHSA-7r7m-9r2x-mccm.json b/advisories/unreviewed/2023/01/GHSA-7r7m-9r2x-mccm/GHSA-7r7m-9r2x-mccm.json index 98a11597112..ef31c52905c 100644 --- a/advisories/unreviewed/2023/01/GHSA-7r7m-9r2x-mccm/GHSA-7r7m-9r2x-mccm.json +++ b/advisories/unreviewed/2023/01/GHSA-7r7m-9r2x-mccm/GHSA-7r7m-9r2x-mccm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8cxj-vc9j-xq64/GHSA-8cxj-vc9j-xq64.json b/advisories/unreviewed/2023/01/GHSA-8cxj-vc9j-xq64/GHSA-8cxj-vc9j-xq64.json index 30e1945f457..6b96d70084d 100644 --- a/advisories/unreviewed/2023/01/GHSA-8cxj-vc9j-xq64/GHSA-8cxj-vc9j-xq64.json +++ b/advisories/unreviewed/2023/01/GHSA-8cxj-vc9j-xq64/GHSA-8cxj-vc9j-xq64.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8wjp-pfrg-xh9q/GHSA-8wjp-pfrg-xh9q.json b/advisories/unreviewed/2023/01/GHSA-8wjp-pfrg-xh9q/GHSA-8wjp-pfrg-xh9q.json index 8dfa166ea1a..f0799bcc46e 100644 --- a/advisories/unreviewed/2023/01/GHSA-8wjp-pfrg-xh9q/GHSA-8wjp-pfrg-xh9q.json +++ b/advisories/unreviewed/2023/01/GHSA-8wjp-pfrg-xh9q/GHSA-8wjp-pfrg-xh9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-94xr-33qr-qf6f/GHSA-94xr-33qr-qf6f.json b/advisories/unreviewed/2023/01/GHSA-94xr-33qr-qf6f/GHSA-94xr-33qr-qf6f.json index 811592a5619..8cde3beed74 100644 --- a/advisories/unreviewed/2023/01/GHSA-94xr-33qr-qf6f/GHSA-94xr-33qr-qf6f.json +++ b/advisories/unreviewed/2023/01/GHSA-94xr-33qr-qf6f/GHSA-94xr-33qr-qf6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9r6q-f96q-7hq4/GHSA-9r6q-f96q-7hq4.json b/advisories/unreviewed/2023/01/GHSA-9r6q-f96q-7hq4/GHSA-9r6q-f96q-7hq4.json index 6e273d859ab..515167719b5 100644 --- a/advisories/unreviewed/2023/01/GHSA-9r6q-f96q-7hq4/GHSA-9r6q-f96q-7hq4.json +++ b/advisories/unreviewed/2023/01/GHSA-9r6q-f96q-7hq4/GHSA-9r6q-f96q-7hq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-c9p6-78wf-hfm7/GHSA-c9p6-78wf-hfm7.json b/advisories/unreviewed/2023/01/GHSA-c9p6-78wf-hfm7/GHSA-c9p6-78wf-hfm7.json index db991c24b0f..93555a53ddc 100644 --- a/advisories/unreviewed/2023/01/GHSA-c9p6-78wf-hfm7/GHSA-c9p6-78wf-hfm7.json +++ b/advisories/unreviewed/2023/01/GHSA-c9p6-78wf-hfm7/GHSA-c9p6-78wf-hfm7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-cjcj-g2w6-gp9q/GHSA-cjcj-g2w6-gp9q.json b/advisories/unreviewed/2023/01/GHSA-cjcj-g2w6-gp9q/GHSA-cjcj-g2w6-gp9q.json index fd20b53ed2e..6ddd88b0c3a 100644 --- a/advisories/unreviewed/2023/01/GHSA-cjcj-g2w6-gp9q/GHSA-cjcj-g2w6-gp9q.json +++ b/advisories/unreviewed/2023/01/GHSA-cjcj-g2w6-gp9q/GHSA-cjcj-g2w6-gp9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-cmvm-c7qf-pmc5/GHSA-cmvm-c7qf-pmc5.json b/advisories/unreviewed/2023/01/GHSA-cmvm-c7qf-pmc5/GHSA-cmvm-c7qf-pmc5.json index 1325986219e..5a3caf1b04d 100644 --- a/advisories/unreviewed/2023/01/GHSA-cmvm-c7qf-pmc5/GHSA-cmvm-c7qf-pmc5.json +++ b/advisories/unreviewed/2023/01/GHSA-cmvm-c7qf-pmc5/GHSA-cmvm-c7qf-pmc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-fcf9-3423-25fj/GHSA-fcf9-3423-25fj.json b/advisories/unreviewed/2023/01/GHSA-fcf9-3423-25fj/GHSA-fcf9-3423-25fj.json index ec821991a5a..4e4cfded09f 100644 --- a/advisories/unreviewed/2023/01/GHSA-fcf9-3423-25fj/GHSA-fcf9-3423-25fj.json +++ b/advisories/unreviewed/2023/01/GHSA-fcf9-3423-25fj/GHSA-fcf9-3423-25fj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json b/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json index 44fee216c82..e047352e05d 100644 --- a/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json +++ b/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-g823-9xxv-px4q/GHSA-g823-9xxv-px4q.json b/advisories/unreviewed/2023/01/GHSA-g823-9xxv-px4q/GHSA-g823-9xxv-px4q.json index 0ff71514e0a..b0f09743305 100644 --- a/advisories/unreviewed/2023/01/GHSA-g823-9xxv-px4q/GHSA-g823-9xxv-px4q.json +++ b/advisories/unreviewed/2023/01/GHSA-g823-9xxv-px4q/GHSA-g823-9xxv-px4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gpvh-qv7g-wvjp/GHSA-gpvh-qv7g-wvjp.json b/advisories/unreviewed/2023/01/GHSA-gpvh-qv7g-wvjp/GHSA-gpvh-qv7g-wvjp.json index b7f5cba1022..485b2e24cc3 100644 --- a/advisories/unreviewed/2023/01/GHSA-gpvh-qv7g-wvjp/GHSA-gpvh-qv7g-wvjp.json +++ b/advisories/unreviewed/2023/01/GHSA-gpvh-qv7g-wvjp/GHSA-gpvh-qv7g-wvjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json b/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json index d71b712b8f5..cb21acfc4c7 100644 --- a/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json +++ b/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-h6qp-2x7h-7x2g/GHSA-h6qp-2x7h-7x2g.json b/advisories/unreviewed/2023/01/GHSA-h6qp-2x7h-7x2g/GHSA-h6qp-2x7h-7x2g.json index 32371d0f6a2..a66d3e87737 100644 --- a/advisories/unreviewed/2023/01/GHSA-h6qp-2x7h-7x2g/GHSA-h6qp-2x7h-7x2g.json +++ b/advisories/unreviewed/2023/01/GHSA-h6qp-2x7h-7x2g/GHSA-h6qp-2x7h-7x2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-h8wf-2g76-x8c2/GHSA-h8wf-2g76-x8c2.json b/advisories/unreviewed/2023/01/GHSA-h8wf-2g76-x8c2/GHSA-h8wf-2g76-x8c2.json index 5030712c098..1671d9bf80d 100644 --- a/advisories/unreviewed/2023/01/GHSA-h8wf-2g76-x8c2/GHSA-h8wf-2g76-x8c2.json +++ b/advisories/unreviewed/2023/01/GHSA-h8wf-2g76-x8c2/GHSA-h8wf-2g76-x8c2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hfw6-6cwm-fq2j/GHSA-hfw6-6cwm-fq2j.json b/advisories/unreviewed/2023/01/GHSA-hfw6-6cwm-fq2j/GHSA-hfw6-6cwm-fq2j.json index f33fe107205..9c2f76f113c 100644 --- a/advisories/unreviewed/2023/01/GHSA-hfw6-6cwm-fq2j/GHSA-hfw6-6cwm-fq2j.json +++ b/advisories/unreviewed/2023/01/GHSA-hfw6-6cwm-fq2j/GHSA-hfw6-6cwm-fq2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hj4m-mcvw-qf65/GHSA-hj4m-mcvw-qf65.json b/advisories/unreviewed/2023/01/GHSA-hj4m-mcvw-qf65/GHSA-hj4m-mcvw-qf65.json index 7dc53ebc014..d9723d90957 100644 --- a/advisories/unreviewed/2023/01/GHSA-hj4m-mcvw-qf65/GHSA-hj4m-mcvw-qf65.json +++ b/advisories/unreviewed/2023/01/GHSA-hj4m-mcvw-qf65/GHSA-hj4m-mcvw-qf65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hv4h-fc69-69wr/GHSA-hv4h-fc69-69wr.json b/advisories/unreviewed/2023/01/GHSA-hv4h-fc69-69wr/GHSA-hv4h-fc69-69wr.json index 765bd7a36cd..0f850c76bb2 100644 --- a/advisories/unreviewed/2023/01/GHSA-hv4h-fc69-69wr/GHSA-hv4h-fc69-69wr.json +++ b/advisories/unreviewed/2023/01/GHSA-hv4h-fc69-69wr/GHSA-hv4h-fc69-69wr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-j2fh-23pr-vj2r/GHSA-j2fh-23pr-vj2r.json b/advisories/unreviewed/2023/01/GHSA-j2fh-23pr-vj2r/GHSA-j2fh-23pr-vj2r.json index 5ab00c87b04..7d5729a5600 100644 --- a/advisories/unreviewed/2023/01/GHSA-j2fh-23pr-vj2r/GHSA-j2fh-23pr-vj2r.json +++ b/advisories/unreviewed/2023/01/GHSA-j2fh-23pr-vj2r/GHSA-j2fh-23pr-vj2r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-j35w-mpg6-43xp/GHSA-j35w-mpg6-43xp.json b/advisories/unreviewed/2023/01/GHSA-j35w-mpg6-43xp/GHSA-j35w-mpg6-43xp.json index 00c39d244d0..489550fe34a 100644 --- a/advisories/unreviewed/2023/01/GHSA-j35w-mpg6-43xp/GHSA-j35w-mpg6-43xp.json +++ b/advisories/unreviewed/2023/01/GHSA-j35w-mpg6-43xp/GHSA-j35w-mpg6-43xp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jpfr-5xm6-9fr4/GHSA-jpfr-5xm6-9fr4.json b/advisories/unreviewed/2023/01/GHSA-jpfr-5xm6-9fr4/GHSA-jpfr-5xm6-9fr4.json index c7c8b580a57..23038032b3b 100644 --- a/advisories/unreviewed/2023/01/GHSA-jpfr-5xm6-9fr4/GHSA-jpfr-5xm6-9fr4.json +++ b/advisories/unreviewed/2023/01/GHSA-jpfr-5xm6-9fr4/GHSA-jpfr-5xm6-9fr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-p6cx-v2j5-9938/GHSA-p6cx-v2j5-9938.json b/advisories/unreviewed/2023/01/GHSA-p6cx-v2j5-9938/GHSA-p6cx-v2j5-9938.json index 5bad60faa70..aea8d946d92 100644 --- a/advisories/unreviewed/2023/01/GHSA-p6cx-v2j5-9938/GHSA-p6cx-v2j5-9938.json +++ b/advisories/unreviewed/2023/01/GHSA-p6cx-v2j5-9938/GHSA-p6cx-v2j5-9938.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-phmh-wx44-p7vq/GHSA-phmh-wx44-p7vq.json b/advisories/unreviewed/2023/01/GHSA-phmh-wx44-p7vq/GHSA-phmh-wx44-p7vq.json index 5addb355bbd..fd813786e26 100644 --- a/advisories/unreviewed/2023/01/GHSA-phmh-wx44-p7vq/GHSA-phmh-wx44-p7vq.json +++ b/advisories/unreviewed/2023/01/GHSA-phmh-wx44-p7vq/GHSA-phmh-wx44-p7vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-pj35-9jc4-v6rm/GHSA-pj35-9jc4-v6rm.json b/advisories/unreviewed/2023/01/GHSA-pj35-9jc4-v6rm/GHSA-pj35-9jc4-v6rm.json index 65fb398b09d..cc529d0d298 100644 --- a/advisories/unreviewed/2023/01/GHSA-pj35-9jc4-v6rm/GHSA-pj35-9jc4-v6rm.json +++ b/advisories/unreviewed/2023/01/GHSA-pj35-9jc4-v6rm/GHSA-pj35-9jc4-v6rm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json b/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json index 7c8f43b9757..405ad50abd4 100644 --- a/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json +++ b/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json b/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json index 86a37694da4..a9e609cc83b 100644 --- a/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json +++ b/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-rq89-r32x-9rfg/GHSA-rq89-r32x-9rfg.json b/advisories/unreviewed/2023/01/GHSA-rq89-r32x-9rfg/GHSA-rq89-r32x-9rfg.json index 4c401e54425..8e8b8168cfe 100644 --- a/advisories/unreviewed/2023/01/GHSA-rq89-r32x-9rfg/GHSA-rq89-r32x-9rfg.json +++ b/advisories/unreviewed/2023/01/GHSA-rq89-r32x-9rfg/GHSA-rq89-r32x-9rfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-rrfh-8c6f-6grw/GHSA-rrfh-8c6f-6grw.json b/advisories/unreviewed/2023/01/GHSA-rrfh-8c6f-6grw/GHSA-rrfh-8c6f-6grw.json index 4af52936728..43b7b5b9465 100644 --- a/advisories/unreviewed/2023/01/GHSA-rrfh-8c6f-6grw/GHSA-rrfh-8c6f-6grw.json +++ b/advisories/unreviewed/2023/01/GHSA-rrfh-8c6f-6grw/GHSA-rrfh-8c6f-6grw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-vg9h-xv3p-f55q/GHSA-vg9h-xv3p-f55q.json b/advisories/unreviewed/2023/01/GHSA-vg9h-xv3p-f55q/GHSA-vg9h-xv3p-f55q.json index ebbfeef1930..e21c8e58645 100644 --- a/advisories/unreviewed/2023/01/GHSA-vg9h-xv3p-f55q/GHSA-vg9h-xv3p-f55q.json +++ b/advisories/unreviewed/2023/01/GHSA-vg9h-xv3p-f55q/GHSA-vg9h-xv3p-f55q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-vw2p-6432-5hq4/GHSA-vw2p-6432-5hq4.json b/advisories/unreviewed/2023/01/GHSA-vw2p-6432-5hq4/GHSA-vw2p-6432-5hq4.json index ebdef6c78eb..17fcdabaa72 100644 --- a/advisories/unreviewed/2023/01/GHSA-vw2p-6432-5hq4/GHSA-vw2p-6432-5hq4.json +++ b/advisories/unreviewed/2023/01/GHSA-vw2p-6432-5hq4/GHSA-vw2p-6432-5hq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json b/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json index 5e706b94532..a89cb9e8880 100644 --- a/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json +++ b/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-wfcq-ffhc-rj2g/GHSA-wfcq-ffhc-rj2g.json b/advisories/unreviewed/2023/01/GHSA-wfcq-ffhc-rj2g/GHSA-wfcq-ffhc-rj2g.json index 7dab24c89f8..a1f8ac642f9 100644 --- a/advisories/unreviewed/2023/01/GHSA-wfcq-ffhc-rj2g/GHSA-wfcq-ffhc-rj2g.json +++ b/advisories/unreviewed/2023/01/GHSA-wfcq-ffhc-rj2g/GHSA-wfcq-ffhc-rj2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-whgc-pmc8-wmv6/GHSA-whgc-pmc8-wmv6.json b/advisories/unreviewed/2023/01/GHSA-whgc-pmc8-wmv6/GHSA-whgc-pmc8-wmv6.json index 6f06d93cc44..9d62a37d97a 100644 --- a/advisories/unreviewed/2023/01/GHSA-whgc-pmc8-wmv6/GHSA-whgc-pmc8-wmv6.json +++ b/advisories/unreviewed/2023/01/GHSA-whgc-pmc8-wmv6/GHSA-whgc-pmc8-wmv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-wvc8-26f6-r55r/GHSA-wvc8-26f6-r55r.json b/advisories/unreviewed/2023/01/GHSA-wvc8-26f6-r55r/GHSA-wvc8-26f6-r55r.json index 1e4a9174edb..b428a43aa9a 100644 --- a/advisories/unreviewed/2023/01/GHSA-wvc8-26f6-r55r/GHSA-wvc8-26f6-r55r.json +++ b/advisories/unreviewed/2023/01/GHSA-wvc8-26f6-r55r/GHSA-wvc8-26f6-r55r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-wvp8-6wrp-jww8/GHSA-wvp8-6wrp-jww8.json b/advisories/unreviewed/2023/01/GHSA-wvp8-6wrp-jww8/GHSA-wvp8-6wrp-jww8.json index bd02852e4c0..af3f850f3e7 100644 --- a/advisories/unreviewed/2023/01/GHSA-wvp8-6wrp-jww8/GHSA-wvp8-6wrp-jww8.json +++ b/advisories/unreviewed/2023/01/GHSA-wvp8-6wrp-jww8/GHSA-wvp8-6wrp-jww8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json b/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json index d6aed3d98ea..5657b5afdcb 100644 --- a/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json +++ b/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-xhxp-5wh5-qg3g/GHSA-xhxp-5wh5-qg3g.json b/advisories/unreviewed/2023/01/GHSA-xhxp-5wh5-qg3g/GHSA-xhxp-5wh5-qg3g.json index f7daf9339ea..eb5751b3289 100644 --- a/advisories/unreviewed/2023/01/GHSA-xhxp-5wh5-qg3g/GHSA-xhxp-5wh5-qg3g.json +++ b/advisories/unreviewed/2023/01/GHSA-xhxp-5wh5-qg3g/GHSA-xhxp-5wh5-qg3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-xj3h-ghff-wj93/GHSA-xj3h-ghff-wj93.json b/advisories/unreviewed/2023/01/GHSA-xj3h-ghff-wj93/GHSA-xj3h-ghff-wj93.json index 5040b5a25d4..b7786de1908 100644 --- a/advisories/unreviewed/2023/01/GHSA-xj3h-ghff-wj93/GHSA-xj3h-ghff-wj93.json +++ b/advisories/unreviewed/2023/01/GHSA-xj3h-ghff-wj93/GHSA-xj3h-ghff-wj93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-xjg5-j24f-8p55/GHSA-xjg5-j24f-8p55.json b/advisories/unreviewed/2023/01/GHSA-xjg5-j24f-8p55/GHSA-xjg5-j24f-8p55.json index 764018595ea..e081e736c24 100644 --- a/advisories/unreviewed/2023/01/GHSA-xjg5-j24f-8p55/GHSA-xjg5-j24f-8p55.json +++ b/advisories/unreviewed/2023/01/GHSA-xjg5-j24f-8p55/GHSA-xjg5-j24f-8p55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json b/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json index 034bb4efd59..258e6263f18 100644 --- a/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json +++ b/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json b/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json index d3f56a22f95..144512ea3d7 100644 --- a/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json +++ b/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json b/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json index 7a6792e5a2f..d447445e92e 100644 --- a/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json +++ b/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json b/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json index 4a263384acd..c2edc04f1de 100644 --- a/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json +++ b/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json b/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json index f80a00f4477..4202e99c254 100644 --- a/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json +++ b/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-4g85-9mh4-6cw4/GHSA-4g85-9mh4-6cw4.json b/advisories/unreviewed/2023/02/GHSA-4g85-9mh4-6cw4/GHSA-4g85-9mh4-6cw4.json index bd4cc76b9cb..fff4a2ad788 100644 --- a/advisories/unreviewed/2023/02/GHSA-4g85-9mh4-6cw4/GHSA-4g85-9mh4-6cw4.json +++ b/advisories/unreviewed/2023/02/GHSA-4g85-9mh4-6cw4/GHSA-4g85-9mh4-6cw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-4m9m-xf34-3q86/GHSA-4m9m-xf34-3q86.json b/advisories/unreviewed/2023/02/GHSA-4m9m-xf34-3q86/GHSA-4m9m-xf34-3q86.json index bb529ec5908..8897a3565d8 100644 --- a/advisories/unreviewed/2023/02/GHSA-4m9m-xf34-3q86/GHSA-4m9m-xf34-3q86.json +++ b/advisories/unreviewed/2023/02/GHSA-4m9m-xf34-3q86/GHSA-4m9m-xf34-3q86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json b/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json index 57df2deed76..53a5def73a4 100644 --- a/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json +++ b/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json b/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json index dcc4c197b5a..aa77e0924a6 100644 --- a/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json +++ b/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-5qjc-vm5p-c74c/GHSA-5qjc-vm5p-c74c.json b/advisories/unreviewed/2023/02/GHSA-5qjc-vm5p-c74c/GHSA-5qjc-vm5p-c74c.json index 342f7afca29..a30a7f58863 100644 --- a/advisories/unreviewed/2023/02/GHSA-5qjc-vm5p-c74c/GHSA-5qjc-vm5p-c74c.json +++ b/advisories/unreviewed/2023/02/GHSA-5qjc-vm5p-c74c/GHSA-5qjc-vm5p-c74c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-5rxp-cqh3-j96r/GHSA-5rxp-cqh3-j96r.json b/advisories/unreviewed/2023/02/GHSA-5rxp-cqh3-j96r/GHSA-5rxp-cqh3-j96r.json index 07e4bb46802..0426ae914ff 100644 --- a/advisories/unreviewed/2023/02/GHSA-5rxp-cqh3-j96r/GHSA-5rxp-cqh3-j96r.json +++ b/advisories/unreviewed/2023/02/GHSA-5rxp-cqh3-j96r/GHSA-5rxp-cqh3-j96r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json b/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json index 590c721b5f8..b023681312f 100644 --- a/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json +++ b/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-633w-9qcg-g8vx/GHSA-633w-9qcg-g8vx.json b/advisories/unreviewed/2023/02/GHSA-633w-9qcg-g8vx/GHSA-633w-9qcg-g8vx.json index 07c360f829a..d9f89134a3c 100644 --- a/advisories/unreviewed/2023/02/GHSA-633w-9qcg-g8vx/GHSA-633w-9qcg-g8vx.json +++ b/advisories/unreviewed/2023/02/GHSA-633w-9qcg-g8vx/GHSA-633w-9qcg-g8vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-7hxq-xwr5-7997/GHSA-7hxq-xwr5-7997.json b/advisories/unreviewed/2023/02/GHSA-7hxq-xwr5-7997/GHSA-7hxq-xwr5-7997.json index e0010a47a36..f248adc1a5c 100644 --- a/advisories/unreviewed/2023/02/GHSA-7hxq-xwr5-7997/GHSA-7hxq-xwr5-7997.json +++ b/advisories/unreviewed/2023/02/GHSA-7hxq-xwr5-7997/GHSA-7hxq-xwr5-7997.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json b/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json index 01516008e76..2df0843b53e 100644 --- a/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json +++ b/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-8x54-v777-7269/GHSA-8x54-v777-7269.json b/advisories/unreviewed/2023/02/GHSA-8x54-v777-7269/GHSA-8x54-v777-7269.json index a71f7cc2e92..4e6fe552d8b 100644 --- a/advisories/unreviewed/2023/02/GHSA-8x54-v777-7269/GHSA-8x54-v777-7269.json +++ b/advisories/unreviewed/2023/02/GHSA-8x54-v777-7269/GHSA-8x54-v777-7269.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-9qfj-r558-84rj/GHSA-9qfj-r558-84rj.json b/advisories/unreviewed/2023/02/GHSA-9qfj-r558-84rj/GHSA-9qfj-r558-84rj.json index c506182affd..bc51bcc1159 100644 --- a/advisories/unreviewed/2023/02/GHSA-9qfj-r558-84rj/GHSA-9qfj-r558-84rj.json +++ b/advisories/unreviewed/2023/02/GHSA-9qfj-r558-84rj/GHSA-9qfj-r558-84rj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json b/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json index 673e772c9cb..7f35f66c6b0 100644 --- a/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json +++ b/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json b/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json index 85b22426fa7..afc939f79ae 100644 --- a/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json +++ b/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json b/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json index c62120a19ae..9422436fb5e 100644 --- a/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json +++ b/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json b/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json index 4e2250cc37c..50993dbb46f 100644 --- a/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json +++ b/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-cxpc-g33f-3fqv/GHSA-cxpc-g33f-3fqv.json b/advisories/unreviewed/2023/02/GHSA-cxpc-g33f-3fqv/GHSA-cxpc-g33f-3fqv.json index 0e41d8e71ba..a5560e1a15e 100644 --- a/advisories/unreviewed/2023/02/GHSA-cxpc-g33f-3fqv/GHSA-cxpc-g33f-3fqv.json +++ b/advisories/unreviewed/2023/02/GHSA-cxpc-g33f-3fqv/GHSA-cxpc-g33f-3fqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-f3x8-m359-fj94/GHSA-f3x8-m359-fj94.json b/advisories/unreviewed/2023/02/GHSA-f3x8-m359-fj94/GHSA-f3x8-m359-fj94.json index 68b3921aff3..28face7ccc2 100644 --- a/advisories/unreviewed/2023/02/GHSA-f3x8-m359-fj94/GHSA-f3x8-m359-fj94.json +++ b/advisories/unreviewed/2023/02/GHSA-f3x8-m359-fj94/GHSA-f3x8-m359-fj94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json b/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json index 2ee896e99c9..8132acb598a 100644 --- a/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json +++ b/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-ffch-mwmj-f7w4/GHSA-ffch-mwmj-f7w4.json b/advisories/unreviewed/2023/02/GHSA-ffch-mwmj-f7w4/GHSA-ffch-mwmj-f7w4.json index 7d24e1255fc..41f661eb9a6 100644 --- a/advisories/unreviewed/2023/02/GHSA-ffch-mwmj-f7w4/GHSA-ffch-mwmj-f7w4.json +++ b/advisories/unreviewed/2023/02/GHSA-ffch-mwmj-f7w4/GHSA-ffch-mwmj-f7w4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-fj2x-xhhp-fv9q/GHSA-fj2x-xhhp-fv9q.json b/advisories/unreviewed/2023/02/GHSA-fj2x-xhhp-fv9q/GHSA-fj2x-xhhp-fv9q.json index b830ddc024e..ed43dc8332c 100644 --- a/advisories/unreviewed/2023/02/GHSA-fj2x-xhhp-fv9q/GHSA-fj2x-xhhp-fv9q.json +++ b/advisories/unreviewed/2023/02/GHSA-fj2x-xhhp-fv9q/GHSA-fj2x-xhhp-fv9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json b/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json index 05499c245a7..98c5670b86a 100644 --- a/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json +++ b/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-jvf7-qpqh-8mxh/GHSA-jvf7-qpqh-8mxh.json b/advisories/unreviewed/2023/02/GHSA-jvf7-qpqh-8mxh/GHSA-jvf7-qpqh-8mxh.json index 54723b36d63..23f88dbcb1f 100644 --- a/advisories/unreviewed/2023/02/GHSA-jvf7-qpqh-8mxh/GHSA-jvf7-qpqh-8mxh.json +++ b/advisories/unreviewed/2023/02/GHSA-jvf7-qpqh-8mxh/GHSA-jvf7-qpqh-8mxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json b/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json index a0d59f5a457..28c7e92c4f4 100644 --- a/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json +++ b/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-m6h4-j5mx-hc72/GHSA-m6h4-j5mx-hc72.json b/advisories/unreviewed/2023/02/GHSA-m6h4-j5mx-hc72/GHSA-m6h4-j5mx-hc72.json index 6fb75478567..df903ab2dcc 100644 --- a/advisories/unreviewed/2023/02/GHSA-m6h4-j5mx-hc72/GHSA-m6h4-j5mx-hc72.json +++ b/advisories/unreviewed/2023/02/GHSA-m6h4-j5mx-hc72/GHSA-m6h4-j5mx-hc72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json b/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json index 9e60cce9cdd..0d44baff02c 100644 --- a/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json +++ b/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-p86q-cw52-gp9g/GHSA-p86q-cw52-gp9g.json b/advisories/unreviewed/2023/02/GHSA-p86q-cw52-gp9g/GHSA-p86q-cw52-gp9g.json index 273752e9c42..1214bfbaf33 100644 --- a/advisories/unreviewed/2023/02/GHSA-p86q-cw52-gp9g/GHSA-p86q-cw52-gp9g.json +++ b/advisories/unreviewed/2023/02/GHSA-p86q-cw52-gp9g/GHSA-p86q-cw52-gp9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json b/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json index d0a592ed409..2a7cfe6a719 100644 --- a/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json +++ b/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qcj5-62mc-73xh/GHSA-qcj5-62mc-73xh.json b/advisories/unreviewed/2023/02/GHSA-qcj5-62mc-73xh/GHSA-qcj5-62mc-73xh.json index eb5cf485505..8c0c0f8adf1 100644 --- a/advisories/unreviewed/2023/02/GHSA-qcj5-62mc-73xh/GHSA-qcj5-62mc-73xh.json +++ b/advisories/unreviewed/2023/02/GHSA-qcj5-62mc-73xh/GHSA-qcj5-62mc-73xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qg7c-8rjw-52m9/GHSA-qg7c-8rjw-52m9.json b/advisories/unreviewed/2023/02/GHSA-qg7c-8rjw-52m9/GHSA-qg7c-8rjw-52m9.json index 2efa498efce..a0ac03b3880 100644 --- a/advisories/unreviewed/2023/02/GHSA-qg7c-8rjw-52m9/GHSA-qg7c-8rjw-52m9.json +++ b/advisories/unreviewed/2023/02/GHSA-qg7c-8rjw-52m9/GHSA-qg7c-8rjw-52m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qvrw-w6hg-g36x/GHSA-qvrw-w6hg-g36x.json b/advisories/unreviewed/2023/02/GHSA-qvrw-w6hg-g36x/GHSA-qvrw-w6hg-g36x.json index c1f13cab7d1..09bdfa9dab0 100644 --- a/advisories/unreviewed/2023/02/GHSA-qvrw-w6hg-g36x/GHSA-qvrw-w6hg-g36x.json +++ b/advisories/unreviewed/2023/02/GHSA-qvrw-w6hg-g36x/GHSA-qvrw-w6hg-g36x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-r5pr-2qfg-vfr4/GHSA-r5pr-2qfg-vfr4.json b/advisories/unreviewed/2023/02/GHSA-r5pr-2qfg-vfr4/GHSA-r5pr-2qfg-vfr4.json index dbead56819f..34b9ad3da6e 100644 --- a/advisories/unreviewed/2023/02/GHSA-r5pr-2qfg-vfr4/GHSA-r5pr-2qfg-vfr4.json +++ b/advisories/unreviewed/2023/02/GHSA-r5pr-2qfg-vfr4/GHSA-r5pr-2qfg-vfr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-r7ch-cwp4-rh7c/GHSA-r7ch-cwp4-rh7c.json b/advisories/unreviewed/2023/02/GHSA-r7ch-cwp4-rh7c/GHSA-r7ch-cwp4-rh7c.json index b0b8f128b73..6e55bf4f007 100644 --- a/advisories/unreviewed/2023/02/GHSA-r7ch-cwp4-rh7c/GHSA-r7ch-cwp4-rh7c.json +++ b/advisories/unreviewed/2023/02/GHSA-r7ch-cwp4-rh7c/GHSA-r7ch-cwp4-rh7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-rj48-qj2x-783m/GHSA-rj48-qj2x-783m.json b/advisories/unreviewed/2023/02/GHSA-rj48-qj2x-783m/GHSA-rj48-qj2x-783m.json index 7f52b84aeba..cddd73dbb5b 100644 --- a/advisories/unreviewed/2023/02/GHSA-rj48-qj2x-783m/GHSA-rj48-qj2x-783m.json +++ b/advisories/unreviewed/2023/02/GHSA-rj48-qj2x-783m/GHSA-rj48-qj2x-783m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json b/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json index 55816c37d56..a27fbffbf9c 100644 --- a/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json +++ b/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-w79r-9m7p-jmqr/GHSA-w79r-9m7p-jmqr.json b/advisories/unreviewed/2023/02/GHSA-w79r-9m7p-jmqr/GHSA-w79r-9m7p-jmqr.json index 3d817c3276b..4c685f49c3d 100644 --- a/advisories/unreviewed/2023/02/GHSA-w79r-9m7p-jmqr/GHSA-w79r-9m7p-jmqr.json +++ b/advisories/unreviewed/2023/02/GHSA-w79r-9m7p-jmqr/GHSA-w79r-9m7p-jmqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-wv7f-jp7g-37rc/GHSA-wv7f-jp7g-37rc.json b/advisories/unreviewed/2023/02/GHSA-wv7f-jp7g-37rc/GHSA-wv7f-jp7g-37rc.json index d53c334ca46..5448fb322ee 100644 --- a/advisories/unreviewed/2023/02/GHSA-wv7f-jp7g-37rc/GHSA-wv7f-jp7g-37rc.json +++ b/advisories/unreviewed/2023/02/GHSA-wv7f-jp7g-37rc/GHSA-wv7f-jp7g-37rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-47q6-hqqr-mcr3/GHSA-47q6-hqqr-mcr3.json b/advisories/unreviewed/2023/05/GHSA-47q6-hqqr-mcr3/GHSA-47q6-hqqr-mcr3.json index 5366655f6d3..272a4ead53c 100644 --- a/advisories/unreviewed/2023/05/GHSA-47q6-hqqr-mcr3/GHSA-47q6-hqqr-mcr3.json +++ b/advisories/unreviewed/2023/05/GHSA-47q6-hqqr-mcr3/GHSA-47q6-hqqr-mcr3.json @@ -7,12 +7,8 @@ "CVE-2023-34152" ], "details": "A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-hfhf-22gm-76w3/GHSA-hfhf-22gm-76w3.json b/advisories/unreviewed/2023/05/GHSA-hfhf-22gm-76w3/GHSA-hfhf-22gm-76w3.json index 68b66a7256e..e42f018f841 100644 --- a/advisories/unreviewed/2023/05/GHSA-hfhf-22gm-76w3/GHSA-hfhf-22gm-76w3.json +++ b/advisories/unreviewed/2023/05/GHSA-hfhf-22gm-76w3/GHSA-hfhf-22gm-76w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-pv8h-p384-hhr9/GHSA-pv8h-p384-hhr9.json b/advisories/unreviewed/2023/05/GHSA-pv8h-p384-hhr9/GHSA-pv8h-p384-hhr9.json index c645da2821f..c1381f03584 100644 --- a/advisories/unreviewed/2023/05/GHSA-pv8h-p384-hhr9/GHSA-pv8h-p384-hhr9.json +++ b/advisories/unreviewed/2023/05/GHSA-pv8h-p384-hhr9/GHSA-pv8h-p384-hhr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json b/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json index 64a5cad6530..3b0712a698d 100644 --- a/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json +++ b/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json @@ -7,12 +7,8 @@ "CVE-2024-26713" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: Fix iommu initialisation during DLPAR add\n\nWhen a PCI device is dynamically added, the kernel oopses with a NULL\npointer dereference:\n\n BUG: Kernel NULL pointer dereference on read at 0x00000030\n Faulting instruction address: 0xc0000000006bbe5c\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: rpadlpar_io rpaphp rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs xsk_diag bonding nft_compat nf_tables nfnetlink rfkill binfmt_misc dm_multipath rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi ib_ipoib rdma_cm iw_cm ib_cm mlx5_ib ib_uverbs ib_core pseries_rng drm drm_panel_orientation_quirks xfs libcrc32c mlx5_core mlxfw sd_mod t10_pi sg tls ibmvscsi ibmveth scsi_transport_srp vmx_crypto pseries_wdt psample dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 17 PID: 2685 Comm: drmgr Not tainted 6.7.0-203405+ #66\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c0000000006bbe5c LR: c000000000a13e68 CTR: c0000000000579f8\n REGS: c00000009924f240 TRAP: 0300 Not tainted (6.7.0-203405+)\n MSR: 8000000000009033 CR: 24002220 XER: 20040006\n CFAR: c000000000a13e64 DAR: 0000000000000030 DSISR: 40000000 IRQMASK: 0\n ...\n NIP sysfs_add_link_to_group+0x34/0x94\n LR iommu_device_link+0x5c/0x118\n Call Trace:\n iommu_init_device+0x26c/0x318 (unreliable)\n iommu_device_link+0x5c/0x118\n iommu_init_device+0xa8/0x318\n iommu_probe_device+0xc0/0x134\n iommu_bus_notifier+0x44/0x104\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n bus_notify+0x50/0x7c\n device_add+0x640/0x918\n pci_device_add+0x23c/0x298\n of_create_pci_dev+0x400/0x884\n of_scan_pci_dev+0x124/0x1b0\n __of_scan_bus+0x78/0x18c\n pcibios_scan_phb+0x2a4/0x3b0\n init_phb_dynamic+0xb8/0x110\n dlpar_add_slot+0x170/0x3b8 [rpadlpar_io]\n add_slot_store.part.0+0xb4/0x130 [rpadlpar_io]\n kobj_attr_store+0x2c/0x48\n sysfs_kf_write+0x64/0x78\n kernfs_fop_write_iter+0x1b0/0x290\n vfs_write+0x350/0x4a0\n ksys_write+0x84/0x140\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nCommit a940904443e4 (\"powerpc/iommu: Add iommu_ops to report capabilities\nand allow blocking domains\") broke DLPAR add of PCI devices.\n\nThe above added iommu_device structure to pci_controller. During\nsystem boot, PCI devices are discovered and this newly added iommu_device\nstructure is initialized by a call to iommu_device_register().\n\nDuring DLPAR add of a PCI device, a new pci_controller structure is\nallocated but there are no calls made to iommu_device_register()\ninterface.\n\nFix is to register the iommu device during DLPAR add as well.\n\n[mpe: Trim oops and tweak some change log wording]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json b/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json index 898ace29414..e98e245eac5 100644 --- a/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json +++ b/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json @@ -7,12 +7,8 @@ "CVE-2024-26716" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Prevent null pointer dereference in update_port_device_state\n\nCurrently, the function update_port_device_state gets the usb_hub from\nudev->parent by calling usb_hub_to_struct_hub.\nHowever, in case the actconfig or the maxchild is 0, the usb_hub would\nbe NULL and upon further accessing to get port_dev would result in null\npointer dereference.\n\nFix this by introducing an if check after the usb_hub is populated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json b/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json index b0a59f8fe5e..b5f0cb1fbab 100644 --- a/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json +++ b/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json @@ -7,12 +7,8 @@ "CVE-2024-26715" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: Fix NULL pointer dereference in dwc3_gadget_suspend\n\nIn current scenario if Plug-out and Plug-In performed continuously\nthere could be a chance while checking for dwc->gadget_driver in\ndwc3_gadget_suspend, a NULL pointer dereference may occur.\n\nCall Stack:\n\n\tCPU1: CPU2:\n\tgadget_unbind_driver dwc3_suspend_common\n\tdwc3_gadget_stop dwc3_gadget_suspend\n dwc3_disconnect_gadget\n\nCPU1 basically clears the variable and CPU2 checks the variable.\nConsider CPU1 is running and right before gadget_driver is cleared\nand in parallel CPU2 executes dwc3_gadget_suspend where it finds\ndwc->gadget_driver which is not NULL and resumes execution and then\nCPU1 completes execution. CPU2 executes dwc3_disconnect_gadget where\nit checks dwc->gadget_driver is already NULL because of which the\nNULL pointer deference occur.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json b/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json index e0ce1f02cf4..c20a6a9ad0f 100644 --- a/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json +++ b/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json @@ -7,12 +7,8 @@ "CVE-2024-26717" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: i2c-hid-of: fix NULL-deref on failed power up\n\nA while back the I2C HID implementation was split in an ACPI and OF\npart, but the new OF driver never initialises the client pointer which\nis dereferenced on power-up failures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json b/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json index 1daca147843..9a56577220e 100644 --- a/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json +++ b/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json @@ -7,12 +7,8 @@ "CVE-2024-26725" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpll: fix possible deadlock during netlink dump operation\n\nRecently, I've been hitting following deadlock warning during dpll pin\ndump:\n\n[52804.637962] ======================================================\n[52804.638536] WARNING: possible circular locking dependency detected\n[52804.639111] 6.8.0-rc2jiri+ #1 Not tainted\n[52804.639529] ------------------------------------------------------\n[52804.640104] python3/2984 is trying to acquire lock:\n[52804.640581] ffff88810e642678 (nlk_cb_mutex-GENERIC){+.+.}-{3:3}, at: netlink_dump+0xb3/0x780\n[52804.641417]\n but task is already holding lock:\n[52804.642010] ffffffff83bde4c8 (dpll_lock){+.+.}-{3:3}, at: dpll_lock_dumpit+0x13/0x20\n[52804.642747]\n which lock already depends on the new lock.\n\n[52804.643551]\n the existing dependency chain (in reverse order) is:\n[52804.644259]\n -> #1 (dpll_lock){+.+.}-{3:3}:\n[52804.644836] lock_acquire+0x174/0x3e0\n[52804.645271] __mutex_lock+0x119/0x1150\n[52804.645723] dpll_lock_dumpit+0x13/0x20\n[52804.646169] genl_start+0x266/0x320\n[52804.646578] __netlink_dump_start+0x321/0x450\n[52804.647056] genl_family_rcv_msg_dumpit+0x155/0x1e0\n[52804.647575] genl_rcv_msg+0x1ed/0x3b0\n[52804.648001] netlink_rcv_skb+0xdc/0x210\n[52804.648440] genl_rcv+0x24/0x40\n[52804.648831] netlink_unicast+0x2f1/0x490\n[52804.649290] netlink_sendmsg+0x36d/0x660\n[52804.649742] __sock_sendmsg+0x73/0xc0\n[52804.650165] __sys_sendto+0x184/0x210\n[52804.650597] __x64_sys_sendto+0x72/0x80\n[52804.651045] do_syscall_64+0x6f/0x140\n[52804.651474] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[52804.652001]\n -> #0 (nlk_cb_mutex-GENERIC){+.+.}-{3:3}:\n[52804.652650] check_prev_add+0x1ae/0x1280\n[52804.653107] __lock_acquire+0x1ed3/0x29a0\n[52804.653559] lock_acquire+0x174/0x3e0\n[52804.653984] __mutex_lock+0x119/0x1150\n[52804.654423] netlink_dump+0xb3/0x780\n[52804.654845] __netlink_dump_start+0x389/0x450\n[52804.655321] genl_family_rcv_msg_dumpit+0x155/0x1e0\n[52804.655842] genl_rcv_msg+0x1ed/0x3b0\n[52804.656272] netlink_rcv_skb+0xdc/0x210\n[52804.656721] genl_rcv+0x24/0x40\n[52804.657119] netlink_unicast+0x2f1/0x490\n[52804.657570] netlink_sendmsg+0x36d/0x660\n[52804.658022] __sock_sendmsg+0x73/0xc0\n[52804.658450] __sys_sendto+0x184/0x210\n[52804.658877] __x64_sys_sendto+0x72/0x80\n[52804.659322] do_syscall_64+0x6f/0x140\n[52804.659752] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[52804.660281]\n other info that might help us debug this:\n\n[52804.661077] Possible unsafe locking scenario:\n\n[52804.661671] CPU0 CPU1\n[52804.662129] ---- ----\n[52804.662577] lock(dpll_lock);\n[52804.662924] lock(nlk_cb_mutex-GENERIC);\n[52804.663538] lock(dpll_lock);\n[52804.664073] lock(nlk_cb_mutex-GENERIC);\n[52804.664490]\n\nThe issue as follows: __netlink_dump_start() calls control->start(cb)\nwith nlk->cb_mutex held. In control->start(cb) the dpll_lock is taken.\nThen nlk->cb_mutex is released and taken again in netlink_dump(), while\ndpll_lock still being held. That leads to ABBA deadlock when another\nCPU races with the same operation.\n\nFix this by moving dpll_lock taking into dumpit() callback which ensures\ncorrect lock taking order.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json b/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json index d4d0f56ab5e..127352bd3e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json +++ b/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json @@ -7,12 +7,8 @@ "CVE-2024-26724" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: DPLL, Fix possible use after free after delayed work timer triggers\n\nI managed to hit following use after free warning recently:\n\n[ 2169.711665] ==================================================================\n[ 2169.714009] BUG: KASAN: slab-use-after-free in __run_timers.part.0+0x179/0x4c0\n[ 2169.716293] Write of size 8 at addr ffff88812b326a70 by task swapper/4/0\n\n[ 2169.719022] CPU: 4 PID: 0 Comm: swapper/4 Not tainted 6.8.0-rc2jiri+ #2\n[ 2169.720974] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 2169.722457] Call Trace:\n[ 2169.722756] \n[ 2169.723024] dump_stack_lvl+0x58/0xb0\n[ 2169.723417] print_report+0xc5/0x630\n[ 2169.723807] ? __virt_addr_valid+0x126/0x2b0\n[ 2169.724268] kasan_report+0xbe/0xf0\n[ 2169.724667] ? __run_timers.part.0+0x179/0x4c0\n[ 2169.725116] ? __run_timers.part.0+0x179/0x4c0\n[ 2169.725570] __run_timers.part.0+0x179/0x4c0\n[ 2169.726003] ? call_timer_fn+0x320/0x320\n[ 2169.726404] ? lock_downgrade+0x3a0/0x3a0\n[ 2169.726820] ? kvm_clock_get_cycles+0x14/0x20\n[ 2169.727257] ? ktime_get+0x92/0x150\n[ 2169.727630] ? lapic_next_deadline+0x35/0x60\n[ 2169.728069] run_timer_softirq+0x40/0x80\n[ 2169.728475] __do_softirq+0x1a1/0x509\n[ 2169.728866] irq_exit_rcu+0x95/0xc0\n[ 2169.729241] sysvec_apic_timer_interrupt+0x6b/0x80\n[ 2169.729718] \n[ 2169.729993] \n[ 2169.730259] asm_sysvec_apic_timer_interrupt+0x16/0x20\n[ 2169.730755] RIP: 0010:default_idle+0x13/0x20\n[ 2169.731190] Code: c0 08 00 00 00 4d 29 c8 4c 01 c7 4c 29 c2 e9 72 ff ff ff cc cc cc cc 8b 05 9a 7f 1f 02 85 c0 7e 07 0f 00 2d cf 69 43 00 fb f4 c3 66 66 2e 0f 1f 84 00 00 00 00 00 65 48 8b 04 25 c0 93 04 00\n[ 2169.732759] RSP: 0018:ffff888100dbfe10 EFLAGS: 00000242\n[ 2169.733264] RAX: 0000000000000001 RBX: ffff888100d9c200 RCX: ffffffff8241bd62\n[ 2169.733925] RDX: ffffed109a848b15 RSI: 0000000000000004 RDI: ffffffff8127ac55\n[ 2169.734566] RBP: 0000000000000004 R08: 0000000000000000 R09: ffffed109a848b14\n[ 2169.735200] R10: ffff8884d42458a3 R11: 000000000000ba7e R12: ffffffff83d7d3a0\n[ 2169.735835] R13: 1ffff110201b7fc6 R14: 0000000000000000 R15: ffff888100d9c200\n[ 2169.736478] ? ct_kernel_exit.constprop.0+0xa2/0xc0\n[ 2169.736954] ? do_idle+0x285/0x290\n[ 2169.737323] default_idle_call+0x63/0x90\n[ 2169.737730] do_idle+0x285/0x290\n[ 2169.738089] ? arch_cpu_idle_exit+0x30/0x30\n[ 2169.738511] ? mark_held_locks+0x1a/0x80\n[ 2169.738917] ? lockdep_hardirqs_on_prepare+0x12e/0x200\n[ 2169.739417] cpu_startup_entry+0x30/0x40\n[ 2169.739825] start_secondary+0x19a/0x1c0\n[ 2169.740229] ? set_cpu_sibling_map+0xbd0/0xbd0\n[ 2169.740673] secondary_startup_64_no_verify+0x15d/0x16b\n[ 2169.741179] \n\n[ 2169.741686] Allocated by task 1098:\n[ 2169.742058] kasan_save_stack+0x1c/0x40\n[ 2169.742456] kasan_save_track+0x10/0x30\n[ 2169.742852] __kasan_kmalloc+0x83/0x90\n[ 2169.743246] mlx5_dpll_probe+0xf5/0x3c0 [mlx5_dpll]\n[ 2169.743730] auxiliary_bus_probe+0x62/0xb0\n[ 2169.744148] really_probe+0x127/0x590\n[ 2169.744534] __driver_probe_device+0xd2/0x200\n[ 2169.744973] device_driver_attach+0x6b/0xf0\n[ 2169.745402] bind_store+0x90/0xe0\n[ 2169.745761] kernfs_fop_write_iter+0x1df/0x2a0\n[ 2169.746210] vfs_write+0x41f/0x790\n[ 2169.746579] ksys_write+0xc7/0x160\n[ 2169.746947] do_syscall_64+0x6f/0x140\n[ 2169.747333] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n\n[ 2169.748049] Freed by task 1220:\n[ 2169.748393] kasan_save_stack+0x1c/0x40\n[ 2169.748789] kasan_save_track+0x10/0x30\n[ 2169.749188] kasan_save_free_info+0x3b/0x50\n[ 2169.749621] poison_slab_object+0x106/0x180\n[ 2169.750044] __kasan_slab_free+0x14/0x50\n[ 2169.750451] kfree+0x118/0x330\n[ 2169.750792] mlx5_dpll_remove+0xf5/0x110 [mlx5_dpll]\n[ 2169.751271] auxiliary_bus_remove+0x2e/0x40\n[ 2169.751694] device_release_driver_internal+0x24b/0x2e0\n[ 2169.752191] unbind_store+0xa6/0xb0\n[ 2169.752563] kernfs_fo\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json b/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json index dfc01edf6d5..8c5071aa0e6 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json +++ b/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json @@ -7,12 +7,8 @@ "CVE-2024-26714" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: qcom: sc8180x: Mark CO0 BCM keepalive\n\nThe CO0 BCM needs to be up at all times, otherwise some hardware (like\nthe UFS controller) loses its connection to the rest of the SoC,\nresulting in a hang of the platform, accompanied by a spectacular\nlogspam.\n\nMark it as keepalive to prevent such cases.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json b/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json index b5bd9ff625f..f0ee707c286 100644 --- a/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json +++ b/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json @@ -7,12 +7,8 @@ "CVE-2024-26721" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/dsc: Fix the macro that calculates DSCC_/DSCA_ PPS reg address\n\nCommit bd077259d0a9 (\"drm/i915/vdsc: Add function to read any PPS\nregister\") defines a new macro to calculate the DSC PPS register\naddresses with PPS number as an input. This macro correctly calculates\nthe addresses till PPS 11 since the addresses increment by 4. So in that\ncase the following macro works correctly to give correct register\naddress:\n\n_MMIO(_DSCA_PPS_0 + (pps) * 4)\n\nHowever after PPS 11, the register address for PPS 12 increments by 12\nbecause of RC Buffer memory allocation in between. Because of this\ndiscontinuity in the address space, the macro calculates wrong addresses\nfor PPS 12 - 16 resulting into incorrect DSC PPS parameter value\nread/writes causing DSC corruption.\n\nThis fixes it by correcting this macro to add the offset of 12 for PPS\n>=12.\n\nv3: Add correct paranthesis for pps argument (Jani Nikula)\n\n(cherry picked from commit 6074be620c31dc2ae11af96a1a5ea95580976fb5)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json b/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json index 8650a062560..274efca2925 100644 --- a/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json +++ b/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json @@ -7,12 +7,8 @@ "CVE-2024-26711" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad4130: zero-initialize clock init data\n\nThe clk_init_data struct does not have all its members\ninitialized, causing issues when trying to expose the internal\nclock on the CLK pin.\n\nFix this by zero-initializing the clk_init_data struct.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json b/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json index a0018d7f76f..834800b3b06 100644 --- a/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json +++ b/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json @@ -7,12 +7,8 @@ "CVE-2023-23021" ], "details": "Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-49cj-cqm8-6m92/GHSA-49cj-cqm8-6m92.json b/advisories/unreviewed/2024/05/GHSA-49cj-cqm8-6m92/GHSA-49cj-cqm8-6m92.json index e2d805a3f0a..dc7c40b38b4 100644 --- a/advisories/unreviewed/2024/05/GHSA-49cj-cqm8-6m92/GHSA-49cj-cqm8-6m92.json +++ b/advisories/unreviewed/2024/05/GHSA-49cj-cqm8-6m92/GHSA-49cj-cqm8-6m92.json @@ -7,12 +7,8 @@ "CVE-2024-27390" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down()\n\nAs discussed in the past (commit 2d3916f31891 (\"ipv6: fix skb drops\nin igmp6_event_query() and igmp6_event_report()\")) I think the\nsynchronize_net() call in ipv6_mc_down() is not needed.\n\nUnder load, synchronize_net() can last between 200 usec and 5 ms.\n\nKASAN seems to agree as well.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8gpf-qj7v-hp3f/GHSA-8gpf-qj7v-hp3f.json b/advisories/unreviewed/2024/05/GHSA-8gpf-qj7v-hp3f/GHSA-8gpf-qj7v-hp3f.json index b49d7eb652d..9229b82ec51 100644 --- a/advisories/unreviewed/2024/05/GHSA-8gpf-qj7v-hp3f/GHSA-8gpf-qj7v-hp3f.json +++ b/advisories/unreviewed/2024/05/GHSA-8gpf-qj7v-hp3f/GHSA-8gpf-qj7v-hp3f.json @@ -7,12 +7,8 @@ "CVE-2024-27069" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: relax WARN_ON in ovl_verify_area()\n\nsyzbot hit an assertion in copy up data loop which looks like it is\nthe result of a lower file whose size is being changed underneath\noverlayfs.\n\nThis type of use case is documented to cause undefined behavior, so\nreturning EIO error for the copy up makes sense, but it should not be\ncausing a WARN_ON assertion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w2x6-62q8-xq6c/GHSA-w2x6-62q8-xq6c.json b/advisories/unreviewed/2024/05/GHSA-w2x6-62q8-xq6c/GHSA-w2x6-62q8-xq6c.json index 86b5e353f69..63a4e26f6b4 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2x6-62q8-xq6c/GHSA-w2x6-62q8-xq6c.json +++ b/advisories/unreviewed/2024/05/GHSA-w2x6-62q8-xq6c/GHSA-w2x6-62q8-xq6c.json @@ -7,12 +7,8 @@ "CVE-2024-27055" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nworkqueue: Don't call cpumask_test_cpu() with -1 CPU in wq_update_node_max_active()\n\nFor wq_update_node_max_active(), @off_cpu of -1 indicates that no CPU is\ngoing down. The function was incorrectly calling cpumask_test_cpu() with -1\nCPU leading to oopses like the following on some archs:\n\n Unable to handle kernel paging request at virtual address ffff0002100296e0\n ..\n pc : wq_update_node_max_active+0x50/0x1fc\n lr : wq_update_node_max_active+0x1f0/0x1fc\n ...\n Call trace:\n wq_update_node_max_active+0x50/0x1fc\n apply_wqattrs_commit+0xf0/0x114\n apply_workqueue_attrs_locked+0x58/0xa0\n alloc_workqueue+0x5ac/0x774\n workqueue_init_early+0x460/0x540\n start_kernel+0x258/0x684\n __primary_switched+0xb8/0xc0\n Code: 9100a273 35000d01 53067f00 d0016dc1 (f8607a60)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Attempted to kill the idle task!\n ---[ end Kernel panic - not syncing: Attempted to kill the idle task! ]---\n\nFix it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-8754-873p-mcq7/GHSA-8754-873p-mcq7.json b/advisories/unreviewed/2024/07/GHSA-8754-873p-mcq7/GHSA-8754-873p-mcq7.json index 048dd53519a..67508acf5a1 100644 --- a/advisories/unreviewed/2024/07/GHSA-8754-873p-mcq7/GHSA-8754-873p-mcq7.json +++ b/advisories/unreviewed/2024/07/GHSA-8754-873p-mcq7/GHSA-8754-873p-mcq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-c462-f76h-gqhf/GHSA-c462-f76h-gqhf.json b/advisories/unreviewed/2024/07/GHSA-c462-f76h-gqhf/GHSA-c462-f76h-gqhf.json index 0c32f92cf88..5dd99a409a1 100644 --- a/advisories/unreviewed/2024/07/GHSA-c462-f76h-gqhf/GHSA-c462-f76h-gqhf.json +++ b/advisories/unreviewed/2024/07/GHSA-c462-f76h-gqhf/GHSA-c462-f76h-gqhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json b/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json index cba2569f2e7..658dcbfdef6 100644 --- a/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json +++ b/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-j4rf-jc84-8583/GHSA-j4rf-jc84-8583.json b/advisories/unreviewed/2024/07/GHSA-j4rf-jc84-8583/GHSA-j4rf-jc84-8583.json index 4e2d44f32fb..364b05a1ea3 100644 --- a/advisories/unreviewed/2024/07/GHSA-j4rf-jc84-8583/GHSA-j4rf-jc84-8583.json +++ b/advisories/unreviewed/2024/07/GHSA-j4rf-jc84-8583/GHSA-j4rf-jc84-8583.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rr6f-mqf5-f7wc/GHSA-rr6f-mqf5-f7wc.json b/advisories/unreviewed/2024/07/GHSA-rr6f-mqf5-f7wc/GHSA-rr6f-mqf5-f7wc.json index ec6c72fdbb2..ab7ae4e9e8c 100644 --- a/advisories/unreviewed/2024/07/GHSA-rr6f-mqf5-f7wc/GHSA-rr6f-mqf5-f7wc.json +++ b/advisories/unreviewed/2024/07/GHSA-rr6f-mqf5-f7wc/GHSA-rr6f-mqf5-f7wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-c9x2-m7q5-frxf/GHSA-c9x2-m7q5-frxf.json b/advisories/unreviewed/2024/08/GHSA-c9x2-m7q5-frxf/GHSA-c9x2-m7q5-frxf.json index 947db966dd7..0463bce1442 100644 --- a/advisories/unreviewed/2024/08/GHSA-c9x2-m7q5-frxf/GHSA-c9x2-m7q5-frxf.json +++ b/advisories/unreviewed/2024/08/GHSA-c9x2-m7q5-frxf/GHSA-c9x2-m7q5-frxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",